I just recently started getting this pop up while checking my email through AOL (I use AOL email, TCP/IP with cable modem).

It is from Macromedia Flash Player Security which is something I have never seen before. I have attached a picture of the pop up to this post. I don't recognize the "local application" nor the Internet enable location. Google turned up nothing.

I run Windows XP and I ran Adaware and SpyBot and both came back clean.

I did recently have a spoof email phishing for my ebay info, but I did NOT click any links within the email.

TIA
~Kar

Dani AI

Generated

This popup is the Flash Player security sandbox doing exactly what it was designed to do: it stopped a locally stored SWF from talking to an outside site and reported both the local file path and the Internet-enabled location it tried to contact. That dialog is a built‑in protection (not an OS virus dialog) and is triggered when local Flash content attempts network access under the newer Flash local‑file security rules. (community.adobe.com)

How to interpret the two paths the box shows: the “local application” is the SWF or HTML file on disk that initiated the connection; the “Internet‑enabled location” is the remote URL it tried to reach. If the local path points into a program folder, a browser temp, or a P2P/toolbar install, treat it as suspicious and remove or quarantine that file. If the SWF is legitimate (development files or an application you trust), add that file or its folder to Flash’s trusted list using the Global Security Settings (click Settings in the dialog or use the Flash Player Settings Manager / Control Panel → Flash Player → Advanced → Trusted Location Settings). After changing trust you must refresh/restart the player or browser for it to take effect. (macromedia.com)

For machines without easy web access (or for automated deployments) the same trust relationships can be created with Flash trust files: a simple .cfg placed in the FlashPlayerTrust directory (system or user Application Data) lists absolute paths to trust. That is the offline/admin way to allow local apps to use the older rules; exercise caution and only trust folders you control. (community.adobe.com)

Context for this thread: the HijackThis log posted contains MyKazaaGold/MusicBar entries that flagged — those sort of toolbars/P2P components commonly drop local helpers/ads that can invoke Flash. The disappearance of the dialog after a McAfee update is consistent with an AV/quarantine action. Best practice: identify the exact path shown by the Flash dialog, confirm that file has been removed or trusted intentionally, and avoid trusting anything in temp or unknown program folders. For non‑developers, use the release (non‑debug) Flash Player and keep AV up to date to reduce noisy security prompts. (community.adobe.com)

Recommended Answers

All 8 Replies

Download hijackThis. Extract it to its own folder. Then run it and select. Do system scan and save log. Post the contents of the log that pops up.

We will work form there.

ok, no prob, I already have that downloaded. I will post the log.

Download hijackThis. Extract it to its own folder. Then run it and select. Do system scan and save log. Post the contents of the log that pops up.

We will work form there.

Here is the log....

Logfile of HijackThis v1.99.1
Scan saved at 7:34:13 PM, on 4/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\AOL\1110763334\ee\AOLSoftware.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\program files\common files\aol\1110763334\ee\services\antiSpywareApp\ver2_0_25_1\AOLSP Scheduler.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\America Online 9.0\shellmon.exe
c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Documents and Settings\Amy A. Dowell\My Documents\Unzipped\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.accoona.com/search_assistant/accoona_search_assistant.jsp?&utm_id=&utm_content=leftnav&utm_source=&utm_medium=&utm_campaign=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.accoona.com
R3 - URLSearchHook: (no name) - <default> - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: MKGHelper Class - {3DEEC4E2-4125-498E-9263-50A221EF1AAB} - C:\Program Files\MyKazaaGold\MusicBar.dll
O2 - BHO: KGSearchAssistant Class - {4538BEFE-5297-4AAE-B466-C2463D5B927D} - C:\Program Files\MyKazaaGold\MKGSearchAssistant.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: My Kazaa Gold - {2A9316B0-C5F0-4202-ACF7-458D5561AD71} - C:\Program Files\MyKazaaGold\MusicBar.dll
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1110763334\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [My Kazaa Gold] C:\Program Files\MyKazaaGold\MyGoldKazaa.exe /hide
O4 - Startup: Chris Sawyer's Locomotion Registration.lnk = C:\Documents and Settings\Amy A. Dowell\Local Settings\Temp\{6BA86065-027E-4138-A465-8B6DB4507C3C}\{77F45E76-E897-42CA-A9FE-5F56817D875C}\ATR1.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: My Kazaa Gold - {A4A0A07D-3633-4de8-AFB4-44B917596E12} - C:\Program Files\MyKazaaGold\MusicBar.dll
O9 - Extra 'Tools' menuitem: My Kazaa Gold1 - {A4A0A07D-3633-4de8-AFB4-44B917596E12} - C:\Program Files\MyKazaaGold\MusicBar.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O16 - DPF: 6th Street Omaha Poker by pogo -
O16 - DPF: Aces Up! by pogo -
O16 - DPF: Ali Baba Slots TM by pogo -
O16 - DPF: Backgammon by pogo -
O16 - DPF: Battle Phlinx by pogo -
O16 - DPF: Blackjack by pogo -
O16 - DPF: Buckaroo Blackjack TM by pogo -
O16 - DPF: Canasta by pogo -
O16 - DPF: Checkers by pogo -
O16 - DPF: Cribbage by pogo -
O16 - DPF: Dice Derby by pogo -
O16 - DPF: Dominoes by pogo -
O16 - DPF: Double Deuce Poker by pogo -
O16 - DPF: Euchre by pogo -
O16 - DPF: First Class Solitaire by pogo -
O16 - DPF: Fortune Bingo by pogo -
O16 - DPF: Greenback Bayou by pogo -
O16 - DPF: Harvest Mania by pogo -
O16 - DPF: Hearts by pogo -
O16 - DPF: High Stakes Poker by pogo -
O16 - DPF: High Stakes Pool by pogo -
O16 - DPF: Jigsaw Detective by pogo -
O16 - DPF: Jungle Gin by pogo -
O16 - DPF: Lottso by pogo -
O16 - DPF: Mah Jong Garden by pogo -
O16 - DPF: Multiline Slots by pogo -
O16 - DPF: Pai Gow by pogo -
O16 - DPF: Payday FreeCell by pogo -
O16 - DPF: Pebble Beach Golf by pogo -
O16 - DPF: Penguin Blocks by pogo -
O16 - DPF: Perfect Pair Solitaire by pogo -
O16 - DPF: Phlinx by pogo -
O16 - DPF: Pinochle by pogo -
O16 - DPF: Pirate's Gold by pogo -
O16 - DPF: Pop Fu by pogo -
O16 - DPF: PoppaZoppa by pogo -
O16 - DPF: Poppit by pogo -
O16 - DPF: Quick Quack by pogo -
O16 - DPF: QWERTY by pogo -
O16 - DPF: Ride The Tide by pogo -
O16 - DPF: Spades by pogo -
O16 - DPF: Spider Solitaire by pogo -
O16 - DPF: Squelchies by pogo -
O16 - DPF: Stax by pogo -
O16 - DPF: Stellar Sweeper by pogo -
O16 - DPF: Sweet Tooth TM by pogo -
O16 - DPF: Texas Hold'em Poker by pogo -
O16 - DPF: Tri-Peaks by pogo -
O16 - DPF: Tumble Bees by pogo -
O16 - DPF: Turbo 21 TM by pogo -
O16 - DPF: Word Whomp by pogo -
O16 - DPF: Word Whomp Whackdown by pogo -
O16 - DPF: WordJong by pogo -
O16 - DPF: World Class Solitaire by pogo -
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} -
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe

Arg, alrite, ya have a dillemma. You have a program on your computer called MyKazaaGold. Im pretty sure its a paid program. However, it has spyware embedded inside of it. Therefore, the simple answer is to uninstall it. But, not everybody does.

Personally, I'd recommend uninstalling it, and switching to another P2P network, such as Limewire, but that decision is up to ya.

I'm going to treat the following fix as though you are going to remove it. If ya decide not to, post back, and we'll have to revise the fix instructions.
_______________________________

Begin by uninstalling Kazaa through the Add/Remove Programs list.


Now, begin by downloading CCleaner, and specifically choosing the most recent version.

Then, follow these steps:

1. Close all programs so that you are at your desktop.
2. Double-click on the "My Computer" icon.
3. Select the "Tools" menu and click "Folder Options".
4. After the new window appears select the "View" tab.
5. Place a checkmark in the checkbox labeled "Display the contents of system folders".
6. Under the "Hidden files and folders" section select the radio button labeled "Show hidden files and folders".
7. Remove the checkmark from the checkbox labeled "Hide file extensions for known file types".
8. Remove the checkmark from the checkbox labeled "Hide protected operating system files". 9. Press the "Apply" button and then the "OK" button and shutdown My Computer.
10. Now your computer is configured to show all hidden files.

Now, install the program. Open it, and choose the 'Options' tab. Inside, hit the 'Custom' tab, and add the following folders (Note: Not all of these files are on every computer. If one of these isn't present, skip it):

C:\Windows\Temp
C:\Temp
C:\Documents and Settings\<Every user listed>\Local Settings\Temp
C:\Documents and Settings\<Every user listed>\Local Settings\Temporary Internet Files\Content.IE5
C:\Documents and Settings\<Every user listed>\History
C:\Documents and Settings\<Every user listed>\Cookies
C:\Windows\Prefetch

After doing this, move back to the 'Cleaner' tab, and inside this, be sure your open to the 'Windows' tab. Inside, check the box labeled 'Custom Files and Folders'.

Next, after following all of these steps, you're ready to scan. Run scans in both the 'Cleaner' and 'Issues'. Note: It might take several scans in each to remove all of the junk.

After this, follow up by downloading .

  • Install ewido security suite
  • When installing, under "Additional Options" uncheck..
    • Install background guard
    • Install scan via context menu
  • Launch ewido, there should be an icon on your desktop, double-click it.
  • The program will now open to the main screen.
  • When you run ewido for the first time, you will get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  • You will need to update ewido to the latest definition files.
    • On the left hand side of the main screen click Update.
    • Then click on Start Update.
  • The update will start and a progress bar will show the updates being installed. The status bar at the bottom will display "Update successful"

    -=-=-=-=-=-=-==-==-=-= End here to download but not scan -=-=-=-=-=-=-==-==-=-=

  • Click on Scanner
  • Click on Complete System Scan and the scan will begin.
  • You will be prompted to clean the first infection.
  • Select "Perform action on all infections", then proceed.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop or a location where you can find it easily.

After doing these, reboot the computer.

Then, open HJT and fix the following:

R3 - URLSearchHook: (no name) - <default> - (no file)
O2 - BHO: MKGHelper Class - {3DEEC4E2-4125-498E-9263-50A221EF1AAB} - C:\Program Files\MyKazaaGold\MusicBar.dll
O2 - BHO: KGSearchAssistant Class - {4538BEFE-5297-4AAE-B466-C2463D5B927D} - C:\Program Files\MyKazaaGold\MKGSearchAssistant.dll
O3 - Toolbar: My Kazaa Gold - {2A9316B0-C5F0-4202-ACF7-458D5561AD71} - C:\Program Files\MyKazaaGold\MusicBar.dll
O4 - HKCU\..\Run: [My Kazaa Gold] C:\Program Files\MyKazaaGold\MyGoldKazaa.exe /hide
O4 - Startup: Chris Sawyer's Locomotion Registration.lnk = C:\Documents and Settings\Amy A. Dowell\Local Settings\Temp\{6BA86065-027E-4138-A465-8B6DB4507C3C}\{77F45E76-E897-42CA-A9FE-5F56817D875C}\ATR1.EXE
O9 - Extra button: My Kazaa Gold - {A4A0A07D-3633-4de8-AFB4-44B917596E12} - C:\Program Files\MyKazaaGold\MusicBar.dll
O9 - Extra 'Tools' menuitem: My Kazaa Gold1 - {A4A0A07D-3633-4de8-AFB4-44B917596E12} - C:\Program Files\MyKazaaGold\MusicBar.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll

After fixing these, reboot into safe mode, and delete the following folders:

C:\Program Files\MyKazaaGold.

After this, reboot the computer.

Then, post a new HJT log, and the Ewido log.

Thanks.

Jhay,
Thank you for your very detailed step-by-step instructions. Yes, I do have kazaa Gold and I am aware of it's reputation with spyware. I thought with a paid version I would be safe though. Of course, I paid for a 2year membership and I have yet to be able to get it to work. Their tech support (via email) wanted me to uninstall and reinstall and THAT is when I started getting the error - which I should have guessed was cauzed by Kazaa since it was media related - although it was weird that it only came about when I went to check email (which is why I thought it might be related to the ebay spoof).

Interesting enough, I got home last night and saw that my MacAffee had updated, and, lo and behold, the error has not shown itself since. Maybe I'm fixed?

As for Kazaa, well, I can't get it to work, so I'm pissed that I spent money more than anything. How much is Limewire? or iTunes? I used to be pretty good with P2P programs back when they were illegal, lol, but today, they just confuse me.

Thanks again!

Well, I iTunes is great, and legal, but the songs cost 99 cents each. Limewire, is not an illegal program to have on your computer, but downloading copyright material is still illegal, and always will be. I suggest iTunes.

Please post another log...

Ya, agreed. Also, iTunes is a great way to organize files and play them on your computer too.

Lastly, Limewire is free.

Ya, and roger that about posting a new log...

Thanks.

Ussally, when a P2P program is "free", it comes bundled with some unwanted guests. Just a heads up :).

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.