| View previous topic :: View next topic |
| Author |
Message |
JanePurdy Member
Joined: 29 Apr 2008 Posts: 10 Points: 0 Location: CA

|
| Posted: Tue 04/29/2008 3:57pm [Post #1] |
|
|
I appreciate Canuck's input, and am attempting the steps, but am stuck at the Panda Active Scan. I'm receiving an error notice, and it won't scan my computer. It says "updating is incomplete due to an error." Now what? TIA, _________________ Jane, Happily married 15 yrs with 8 gorgeous children! |
|
| |
This post has: 0 recommendations
|
| Back to top |
|
 |
JanePurdy Member
Joined: 29 Apr 2008 Posts: 10 Points: 0 Location: CA

|
| Posted: Tue 04/29/2008 4:06pm [Post #2] |
|
|
Oh, duh, I seem to be working through this as I bounce it off the forum. Sorry for clogging things up! Always did work better with someone to "talk" to. Thanks for your time- _________________ Jane, Happily married 15 yrs with 8 gorgeous children! |
|
| |
This post has: 0 recommendations
|
| Back to top |
|
 |
Canuck Help2Go Administrator

Joined: 22 May 2003 Posts: 6945 Points: 1425 Location: Edmonton, Alberta, Canada

|
| Posted: Tue 04/29/2008 7:38pm [Post #3] |
|
|
If you can't get Panda to work, just go on to the next step. |
|
| |
This post has: 1 recommendation
|
| Back to top |
|
 |
JanePurdy Member
Joined: 29 Apr 2008 Posts: 10 Points: 0 Location: CA

|
| Posted: Tue 04/29/2008 8:31pm [Post #4] |
|
|
I don't mind paying where paying is due, but it seems there is no quick fix anymore! Panda scanned my computer, found 54 minimum security risks and one medium risk, and wants me to buy their program to disinfect it. What do you think? I'll go on to step two, but am willing if it's worth it. I paid good money for my McAfee, any reasons why it didn't catch it? Can I go through McAfee somehow to get rid of it? Seems since they're the hired watchdog, they should help with this. Thanks again for your input, _________________ Jane, Happily married 15 yrs with 8 gorgeous children! |
|
| |
This post has: 0 recommendations
|
| Back to top |
|
 |
Canuck Help2Go Administrator

Joined: 22 May 2003 Posts: 6945 Points: 1425 Location: Edmonton, Alberta, Canada

|
| Posted: Tue 04/29/2008 8:36pm [Post #5] |
|
|
Jane, just go ahead with step 2, don't buy Panda. if you want to, you could copy their report and past it to this post ... but do go ahead with the other steps too. The really important report for us will be the Highjackthis log, but the other programs need to be run first. |
|
| |
This post has: 1 recommendation
|
| Back to top |
|
 |
JanePurdy Member
Joined: 29 Apr 2008 Posts: 10 Points: 0 Location: CA

|
| Posted: Tue 04/29/2008 8:49pm [Post #6] |
|
|
You are infected!
We have detected that the McAfee VirusScan protection on your PC is enabled and up-to-date.
You need better protection for your PC. With Panda solutions you will be protected against more than 3 million viruses, spyware and other threats.
Buy Panda to disinfect and protect your PC!
Export to:
Threats with free disinfection (0)
Threats disinfected with the paid version (57)
Medium danger level (1) adware/eliteba... Adware Latent Show + Info
Low danger level (56) _________________ Jane, Happily married 15 yrs with 8 gorgeous children! |
|
| |
This post has: 0 recommendations
|
| Back to top |
|
 |
Canuck Help2Go Administrator

Joined: 22 May 2003 Posts: 6945 Points: 1425 Location: Edmonton, Alberta, Canada

|
| Posted: Tue 04/29/2008 9:12pm [Post #7] |
|
|
Jane, the chances are good that you have been infected. There is no need to buy Panda, the other steps should clear the infections, or at least show us where they are. I believe the Panda log is different than what you're showing .. don't worry, just continue with next steps. |
|
| |
This post has: 1 recommendation
|
| Back to top |
|
 |
JanePurdy Member
Joined: 29 Apr 2008 Posts: 10 Points: 0 Location: CA

|
| Posted: Tue 04/29/2008 10:03pm [Post #8] |
|
|
Oh, I'm sure I've been infected! I ran the Antispyware, gave a small donation, and it says it cleaned out 10 dangerous files and rebooted. I've not had a recurrence of the trojan horse since it rebooted--I suppose that's a good sign! Can you tell me why my McAfee didn't catch it? What more should I do to be sure I'm protected? Or is it the kind of evolving thing that takes continual improvements, etc.
Thanks for your time, _________________ Jane, Happily married 15 yrs with 8 gorgeous children! |
|
| |
This post has: 0 recommendations
|
| Back to top |
|
 |
Canuck Help2Go Administrator

Joined: 22 May 2003 Posts: 6945 Points: 1425 Location: Edmonton, Alberta, Canada

|
| Posted: Tue 04/29/2008 10:34pm [Post #9] |
|
|
Jane, you referred to this article http://www.help2go.com/component/option,com_forum/Itemi d,32/page,viewtopic/t,27614/ and I suggested you go through it step-by-step. I'm not sure that you have, as you haven't posted a Highjackthis log, so can't really offer you too much advice on what steps you should take in the future. a,b & c below should be run fairly regularly and of course an up-to-date (item d) anti virus program constantly running in the background is a must. If you don't have a firewall I suggest the free Comodo program at http://www.personalfirewall.comodo.com/overview.html .
As far as McAfee not catching this stuff, McAfee is an anti virus program, not an anti spyware program .. spyware and viruses are two different animals.
If you're happy with the results, I wish you happy computing. |
|
| |
This post has: 1 recommendation
|
| Back to top |
|
 |
JanePurdy Member
Joined: 29 Apr 2008 Posts: 10 Points: 0 Location: CA

|
| Posted: Tue 04/29/2008 10:39pm [Post #10] |
|
|
I am following the suggestions on your post, did I miss hijacker somewhere? I just finished the Malware, and it removed 56 or so items--in fact I copied the log, I hope it's not too much to paste here:
Malwarebytes' Anti-Malware 1.11
Database version: 699
Scan type: Quick Scan
Objects scanned: 32584
Time elapsed: 7 minute(s), 21 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 38
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 7
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVer sion\Explorer\Browser Helper Objects\{000000da-0786-4633-87c6-1aa7a4429ef1} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{0656a137-b161-cadd-9777-e37a75 727e78} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{0b682cc1-fb40-4006-a5dd-99edd3 c9095d} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{0e1230f8-ea50-42a9-983c-d22abc 2eeb4c} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9dd4258a-7138-49c4-8d34-587879 a5c7a4} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVer sion\Explorer\Browser Helper Objects\{9dd4258a-7138-49c4-8d34-587879a5c7a4} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b8c0220d-763d-49a4-95f4-61dfde c66ee6} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVer sion\Explorer\Browser Helper Objects\{b8c0220d-763d-49a4-95f4-61dfdec66ee6} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c3bcc488-1ae7-11d4-ab82-0010a4 ec2338} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVer sion\Explorer\Browser Helper Objects\{c3bcc488-1ae7-11d4-ab82-0010a4ec2338} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4 cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cde da3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d 323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a 6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-80 23cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda7 9ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\dpcproxy (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\logons (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SYSTEM\CurrentControlSet\services (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\typelib (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\HOL5_VXIEWER.FULL.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Classes\HOL5_VXIEWER.FULL.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Classes\applications\accessd iver.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\fwbd (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\HolLol (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Inet Delivery (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVer sion\Uninstall\Inet Delivery (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVer sion\Uninstall\mslagent (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Invictus (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\mwc (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVer sion\Uninstall\Golden Palace Casino NEW (Trojan.DNSChanger) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlay er\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVer sion\Explorer\SharedTaskScheduler\{0656a137-b161-cadd-9 777-e37a75727e78} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{0e1230f8-ea50-42a9-983c-d22abc2eeb4c} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVer sion\Run\windows update loader (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVer sion\ADP (Rogue.Multiple) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\ScreenSaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\ScreenSaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Files Infected:
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Users\Jane\g2mdlhlpx.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Jane\AppData\Local\Temp\bx18dxv.dat (Trojan.Agent) -> Quarantined and deleted successfully.
I'll look for that hijacker you mentioned, thanks! _________________ Jane, Happily married 15 yrs with 8 gorgeous children! |
|
| |
This post has: 0 recommendations
|
| Back to top |
|
 |
JanePurdy Member
Joined: 29 Apr 2008 Posts: 10 Points: 0 Location: CA

|
| Posted: Tue 04/29/2008 10:42pm [Post #11] |
|
|
Yup, did a-b-c, ran CCleaner, Super Antispyware and malware. I appreciate your clarifying McAfee, I'll check out that firewall you mentioned.
I am, sincerely, a much happier computee  _________________ Jane, Happily married 15 yrs with 8 gorgeous children! |
|
| |
This post has: 0 recommendations
|
| Back to top |
|
 |
Canuck Help2Go Administrator

Joined: 22 May 2003 Posts: 6945 Points: 1425 Location: Edmonton, Alberta, Canada

|
| Posted: Tue 04/29/2008 10:46pm [Post #12] |
|
|
It looks as though Malwarebytes' Anti-Malware has done a good job of identifying the malware and deleted it all successfully. What you need to run is the programs mentioned here http://www.help2go.com/article217.html the Highjckthis log being the last step. Some of the steps you've already run, so skip those. |
|
| |
This post has: 1 recommendation
|
| Back to top |
|
 |
JanePurdy Member
Joined: 29 Apr 2008 Posts: 10 Points: 0 Location: CA

|
| Posted: Tue 04/29/2008 10:50pm [Post #13] |
|
|
Ah yes, just discovered it. I attempted the housecall but ran into some errors. Apparently they were registered with a secure company but their membership expired, or some such thing--I was being asked whether I wished to download from an unknown site. I went ahead (perhaps foolishly), but then it said there was an error moving files or something, so I exited. So, I'm off to finish Hijackthis...uh, do I want to install the installer, the zip, or the executable? _________________ Jane, Happily married 15 yrs with 8 gorgeous children! |
|
| |
This post has: 0 recommendations
|
| Back to top |
|
 |
Canuck Help2Go Administrator

Joined: 22 May 2003 Posts: 6945 Points: 1425 Location: Edmonton, Alberta, Canada

|
| Posted: Tue 04/29/2008 11:03pm [Post #14] |
|
|
Download the zip to your desktop and then double click on the .zip folder. |
|
| |
This post has: 1 recommendation
|
| Back to top |
|
 |
JanePurdy Member
Joined: 29 Apr 2008 Posts: 10 Points: 0 Location: CA

|
| Posted: Tue 04/29/2008 11:33pm [Post #15] |
|
|
Here's the hijack list, what do you think?
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:30:36 PM, on 4/29/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\mobsync.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe
C:\Program Files\Microsoft Games\SpiderSolitaire\SpiderSolitaire.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Users\Jane\AppData\Local\Temp\Temp1_HiJackThis[1].zi p\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/* http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/* http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/* http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\System32\msconfig.exe" /auto
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Speech Recognition] "C:\Windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [dlmMgr] "C:\Program Files\Common Files\Adobe\ESD\AdobeDownloadManager.exe" restart=1
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O13 - Gopher Prefix:
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.ap ple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie. cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} (Hewlett-Packard Printer Diagnostics) - http://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISWeb Manager.CAB
O16 - DPF: {A796D216-2DE1-4EA8-BABB-FE6E7C959098} (HPSDDX Class) - http://www.hp.com/cpso-support-new/SDD/hpsddObjSigned.c ab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/fl ash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll (file missing)
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
--
End of file - 8780 bytes _________________ Jane, Happily married 15 yrs with 8 gorgeous children! |
|
| |
This post has: 0 recommendations
|
| Back to top |
|
 |
|