Malware?

Discussion in 'Computer Support' started by clyde, Jul 4, 2005.

  1. clyde

    clyde Guest

    Firefox and Pegasus are defaults. When I click on e-mail link *outside*
    Pegasus the screen is flooded with IE windows. Anyone help?

    clyde
     
    clyde, Jul 4, 2005
    #1
    1. Advertising

  2. clyde

    pcbutts1 Guest

    Just goes to show you that what people think is wrong. Download, install,
    update and run all of the following.

    Ad-Aware
    http://www.lavasoftusa.com/software/adaware/

    Spybot search and destroy
    http://www.safer-networking.org/en/download/

    Microsoft Windows AntiSpyware (Beta1)
    http://www.microsoft.com/downloads/...A2-6A57-4C57-A8BD-DBF62EDA9671&displaylang=en

    If none of the above fixes the issue then download Hijack this, run it, save
    a copy of the log file and cut and paste it back here to the group so that
    it can be analyzed.

    HijackThis
    http://www.spywareinfo.com/~merijn/downloads.html

    --


    The best live web video on the internet http://www.seedsv.com/webdemo.htm
    NEW Embedded system W/Linux. We now sell DVR cards.
    See it all at http://www.seedsv.com/products.htm
    Sharpvision simply the best http://www.seedsv.com



    "clyde" <> wrote in message
    news:Xns9689B7A6641EArexdale@207.35.177.134...
    > Firefox and Pegasus are defaults. When I click on e-mail link *outside*
    > Pegasus the screen is flooded with IE windows. Anyone help?
    >
    > clyde
     
    pcbutts1, Jul 5, 2005
    #2
    1. Advertising

  3. clyde

    Amy Johnson Guest

    "pcbutts1" <> wrote in message
    news:ZPjye.400$6%...
    > Just goes to show you that what people think is wrong. Download, install,
    > update and run all of the following.
    >
    > Ad-Aware
    > http://www.lavasoftusa.com/software/adaware/
    >
    > Spybot search and destroy
    > http://www.safer-networking.org/en/download/
    >
    > Microsoft Windows AntiSpyware (Beta1)
    > http://www.microsoft.com/downloads/...A2-6A57-4C57-A8BD-DBF62EDA9671&displaylang=en
    >
    > If none of the above fixes the issue then download Hijack this, run it,
    > save a copy of the log file and cut and paste it back here to the group so
    > that it can be analyzed.
    >
    > HijackThis
    > http://www.spywareinfo.com/~merijn/downloads.html
    >
    > --
    >
    >
    > The best live web video on the internet http://www.seedsv.com/webdemo.htm
    > NEW Embedded system W/Linux. We now sell DVR cards.
    > See it all at http://www.seedsv.com/products.htm
    > Sharpvision simply the best http://www.seedsv.com
    >
    >
    >
    > "clyde" <> wrote in message
    > news:Xns9689B7A6641EArexdale@207.35.177.134...
    >> Firefox and Pegasus are defaults. When I click on e-mail link *outside*
    >> Pegasus the screen is flooded with IE windows. Anyone help?
    >>
    >> clyde

    Logfile of HijackThis v1.99.1
    Scan saved at 5:03:39 AM, on 7/6/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
    C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
    C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\McAfee\McAfee AntiSpyware\MssCli.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Weather Watcher\ww.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    C:\Program Files\Handspring\HOTSYNC.EXE
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\WINDOWS\system32\drivers\KodakCCS.exe
    c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe
    c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
    C:\WINDOWS\System32\svchost.exe
    c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe
    C:\Program Files\Outlook Express\msimn.exe
    C:\Documents and Settings\User\Local Settings\Temporary Internet
    Files\Content.IE5\S3Z3IKDP\HijackThis1991[1].exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    http://www.excite.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    http://www.excite.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
    C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} -
    c:\PROGRA~1\mcafee.com\mps\mcbrhlpr.dll
    O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} -
    c:\program files\mcafee.com\mps\popupkiller.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
    C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -
    c:\program files\google\googletoolbar1.dll
    O2 - BHO: (no name) - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} -
    c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program
    files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
    O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
    Files\Java\jre1.5.0_02\bin\jusched.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
    O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe"
    /checktask
    O4 - HKLM\..\Run: [VirusScan Online]
    "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe
    /embedding
    O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
    Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [_AntiSpyware] C:\Program Files\McAfee\McAfee
    AntiSpyware\MssCli.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O4 - HKLM\..\RunOnce: [XoftSpy] "C:\Program Files\XoftSpy\XoftSpy.exe" -b
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &
    Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [WeatherWatcher] C:\Program Files\Weather Watcher\ww.exe
    O4 - Startup: HotSync Manager.lnk = C:\Program Files\Handspring\HOTSYNC.EXE
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program
    Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program
    Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O8 - Extra context menu item: &Google Search - res://C:\Program
    Files\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: Backward Links - res://C:\Program
    Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program
    Files\Google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: Similar Pages - res://C:\Program
    Files\Google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://C:\Program
    Files\Google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
    C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console -
    {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
    Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
    C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger -
    {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
    Files\Messenger\msmsgs.exe
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -
    O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) -
    O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} -
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating
    System Class) -
    O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) -
    O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} -
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
    http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1097978376171
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.5.0_02) -
    O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) -
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} -
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
    O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} (Java Plug-in 1.5.0) -
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
    O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) -
    O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) -
    O20 - Winlogon Notify: Hints - C:\WINDOWS\
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O20 - Winlogon Notify: WindowsUpdate - C:\WINDOWS\
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. -
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. -
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak
    Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
    O23 - Service: McAfee AntiSpyware Real-Time Scanner (McAfeeAntiSpyware) -
    McAfee, Inc. - c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe
    O23 - Service: McAfee.com McShield (McShield) - Unknown owner -
    c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee,
    Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) -
    McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee
    Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe



    ----== Posted via Newsfeeds.Com - Unlimited-Uncensored-Secure Usenet News==----
    http://www.newsfeeds.com The #1 Newsgroup Service in the World! 120,000+ Newsgroups
    ----= East and West-Coast Server Farms - Total Privacy via Encryption =----
     
    Amy Johnson, Jul 6, 2005
    #3
  4. clyde

    Guest

    "Amy Johnson" <> wrote:

    |>Logfile of HijackThis v1.99.1
    |>Scan saved at 5:03:39 AM, on 7/6/2005
    |>Platform: Windows XP SP2 (WinNT 5.01.2600)
    |>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    A quick look http://hijackthis.de/en :

    O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
    Nasty Trojan-Downloader.Win32.Ieser.a

    O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
    Nasty O4 - HKLM..Run: [ffis] C:WINNTisrvsffisearch.exe

    --
     
    , Jul 6, 2005
    #4
  5. clyde

    pcbutts1 Guest

    Have hijackthis fix the following lines.

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
    O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -
    O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) -
    O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} -
    O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) -
    O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} -
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
    http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1097978376171
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.5.0_02) -
    O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) -
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} -
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
    O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} (Java Plug-in 1.5.0) -
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
    O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) -
    O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) -


    --


    The best live web video on the internet http://www.seedsv.com/webdemo.htm
    NEW Embedded system W/Linux. We now sell DVR cards.
    See it all at http://www.seedsv.com/products.htm
    Sharpvision simply the best http://www.seedsv.com



    "Amy Johnson" <> wrote in message
    news:42cbb0b6$...
    >
    > "pcbutts1" <> wrote in message
    > news:ZPjye.400$6%...
    >> Just goes to show you that what people think is wrong. Download, install,
    >> update and run all of the following.
    >>
    >> Ad-Aware
    >> http://www.lavasoftusa.com/software/adaware/
    >>
    >> Spybot search and destroy
    >> http://www.safer-networking.org/en/download/
    >>
    >> Microsoft Windows AntiSpyware (Beta1)
    >> http://www.microsoft.com/downloads/...A2-6A57-4C57-A8BD-DBF62EDA9671&displaylang=en
    >>
    >> If none of the above fixes the issue then download Hijack this, run it,
    >> save a copy of the log file and cut and paste it back here to the group
    >> so that it can be analyzed.
    >>
    >> HijackThis
    >> http://www.spywareinfo.com/~merijn/downloads.html
    >>
    >> --
    >>
    >>
    >> The best live web video on the internet http://www.seedsv.com/webdemo.htm
    >> NEW Embedded system W/Linux. We now sell DVR cards.
    >> See it all at http://www.seedsv.com/products.htm
    >> Sharpvision simply the best http://www.seedsv.com
    >>
    >>
    >>
    >> "clyde" <> wrote in message
    >> news:Xns9689B7A6641EArexdale@207.35.177.134...
    >>> Firefox and Pegasus are defaults. When I click on e-mail link *outside*
    >>> Pegasus the screen is flooded with IE windows. Anyone help?
    >>>
    >>> clyde

    > Logfile of HijackThis v1.99.1
    > Scan saved at 5:03:39 AM, on 7/6/2005
    > Platform: Windows XP SP2 (WinNT 5.01.2600)
    > MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    >
    > Running processes:
    > C:\WINDOWS\System32\smss.exe
    > C:\WINDOWS\system32\winlogon.exe
    > C:\WINDOWS\system32\services.exe
    > C:\WINDOWS\system32\lsass.exe
    > C:\WINDOWS\system32\svchost.exe
    > C:\WINDOWS\System32\svchost.exe
    > C:\WINDOWS\Explorer.EXE
    > C:\WINDOWS\system32\spoolsv.exe
    > C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    > C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
    > C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
    > C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
    > C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
    > C:\Program Files\QuickTime\qttask.exe
    > C:\Program Files\McAfee\McAfee AntiSpyware\MssCli.exe
    > C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    > C:\Program Files\Weather Watcher\ww.exe
    > C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    > C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    > C:\Program Files\Handspring\HOTSYNC.EXE
    > C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    > C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
    > C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    > C:\WINDOWS\system32\drivers\KodakCCS.exe
    > c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe
    > c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    > C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
    > C:\WINDOWS\System32\svchost.exe
    > c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    > C:\WINDOWS\system32\HPZipm12.exe
    > C:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe
    > C:\Program Files\Internet Explorer\iexplore.exe
    > C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
    > C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe
    > C:\Program Files\Outlook Express\msimn.exe
    > C:\Documents and Settings\User\Local Settings\Temporary Internet
    > Files\Content.IE5\S3Z3IKDP\HijackThis1991[1].exe
    >
    > R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    > http://www.excite.com/
    > R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    > http://www.excite.com/
    > R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    > R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    > R3 - Default URLSearchHook is missing
    > O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
    > C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    > O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} -
    > c:\PROGRA~1\mcafee.com\mps\mcbrhlpr.dll
    > O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} -
    > c:\program files\mcafee.com\mps\popupkiller.dll
    > O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
    > C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    > O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    > O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -
    > c:\program files\google\googletoolbar1.dll
    > O2 - BHO: (no name) - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
    > O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} -
    > c:\progra~1\mcafee.com\vso\mcvsshl.dll
    > O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} -
    > c:\program files\google\googletoolbar1.dll
    > O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
    > O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
    > O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    > O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
    > Files\Java\jre1.5.0_02\bin\jusched.exe
    > O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
    > O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe"
    > /checktask
    > O4 - HKLM\..\Run: [VirusScan Online]
    > "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
    > O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    > O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe
    > /embedding
    > O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
    > O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
    > Files\QuickTime\qttask.exe" -atboottime
    > O4 - HKLM\..\Run: [_AntiSpyware] C:\Program Files\McAfee\McAfee
    > AntiSpyware\MssCli.exe
    > O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    > /STARTUP
    > O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    > O4 - HKLM\..\RunOnce: [XoftSpy] "C:\Program Files\XoftSpy\XoftSpy.exe" -b
    > O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &
    > Destroy\TeaTimer.exe
    > O4 - HKCU\..\Run: [WeatherWatcher] C:\Program Files\Weather Watcher\ww.exe
    > O4 - Startup: HotSync Manager.lnk = C:\Program
    > Files\Handspring\HOTSYNC.EXE
    > O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program
    > Files\HP\Digital Imaging\bin\hpqtra08.exe
    > O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program
    > Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    > O8 - Extra context menu item: &Google Search - res://C:\Program
    > Files\Google\GoogleToolbar1.dll/cmsearch.html
    > O8 - Extra context menu item: Backward Links - res://C:\Program
    > Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    > O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program
    > Files\Google\GoogleToolbar1.dll/cmcache.html
    > O8 - Extra context menu item: Similar Pages - res://C:\Program
    > Files\Google\GoogleToolbar1.dll/cmsimilar.html
    > O8 - Extra context menu item: Translate into English - res://C:\Program
    > Files\Google\GoogleToolbar1.dll/cmtrans.html
    > O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
    > C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    > O9 - Extra 'Tools' menuitem: Sun Java Console -
    > {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
    > Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    > O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
    > C:\Program Files\Messenger\msmsgs.exe
    > O9 - Extra 'Tools' menuitem: Windows Messenger -
    > {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
    > Files\Messenger\msmsgs.exe
    > O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -
    > O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) -
    > O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} -
    > O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating
    > System Class) -
    > O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) -
    > O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} -
    > O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
    > http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1097978376171
    > O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in
    > 1.5.0_02) -
    > O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) -
    > O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} -
    > O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
    > O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} (Java Plug-in 1.5.0) -
    > O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
    > O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj
    > Class) -
    > O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) -
    > O20 - Winlogon Notify: Hints - C:\WINDOWS\
    > O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    > O20 - Winlogon Notify: WindowsUpdate - C:\WINDOWS\
    > O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. -
    > C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    > O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. -
    > C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    > O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak
    > Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
    > O23 - Service: McAfee AntiSpyware Real-Time Scanner (McAfeeAntiSpyware) -
    > McAfee, Inc. - c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe
    > O23 - Service: McAfee.com McShield (McShield) - Unknown owner -
    > c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    > O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) -
    > McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    > O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) -
    > McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    > O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee
    > Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
    > O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    >
    >
    > ----== Posted via Newsfeeds.Com - Unlimited-Uncensored-Secure Usenet
    > News==----
    > http://www.newsfeeds.com The #1 Newsgroup Service in the World! 120,000+
    > Newsgroups
    > ----= East and West-Coast Server Farms - Total Privacy via Encryption
    > =----
     
    pcbutts1, Jul 6, 2005
    #5
  6. clyde

    ellis_jay Guest

    pcbutts1 wrote:
    > Have hijackthis fix the following lines.
    >
    > R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    > R0 - HKCU\Software\Microsoft\Internet
    > Explorer\Toolbar,LinksFolderName = R3 - Default URLSearchHook is
    > missing
    > O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
    > O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
    > O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility)
    > - O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) -
    > O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} -
    > O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader
    > Control) - O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} -
    > O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl
    > Class) -
    >

    http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1097978376171
    > O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in
    > 1.5.0_02) - O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125}
    > (mhLabel Class) -
    > O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} -
    > O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr
    > Class) - O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} (Java
    > Plug-in 1.5.0) - O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
    > O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj
    > Class) - O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class)
    > -
    >
    >
    >
    > "Amy Johnson" <> wrote in message
    > news:42cbb0b6$...
    >>
    >> "pcbutts1" <> wrote in message
    >> news:ZPjye.400$6%...
    >>> Just goes to show you that what people think is wrong. Download,
    >>> install, update and run all of the following.
    >>>
    >>> Ad-Aware
    >>> http://www.lavasoftusa.com/software/adaware/
    >>>
    >>> Spybot search and destroy
    >>> http://www.safer-networking.org/en/download/
    >>>
    >>> Microsoft Windows AntiSpyware (Beta1)
    >>>

    http://www.microsoft.com/downloads/...A2-6A57-4C57-A8BD-DBF62EDA9671&displaylang=en
    >>>
    >>> If none of the above fixes the issue then download Hijack this, run
    >>> it, save a copy of the log file and cut and paste it back here to
    >>> the group so that it can be analyzed.
    >>>
    >>> HijackThis
    >>> http://www.spywareinfo.com/~merijn/downloads.html
    >>>
    >>> --
    >>>
    >>>
    >>> The best live web video on the internet
    >>> http://www.seedsv.com/webdemo.htm NEW Embedded system W/Linux. We
    >>> now sell DVR cards.
    >>> See it all at http://www.seedsv.com/products.htm
    >>> Sharpvision simply the best http://www.seedsv.com
    >>>
    >>>
    >>>
    >>> "clyde" <> wrote in message
    >>> news:Xns9689B7A6641EArexdale@207.35.177.134...
    >>>> Firefox and Pegasus are defaults. When I click on e-mail link
    >>>> *outside* Pegasus the screen is flooded with IE windows. Anyone
    >>>> help?
    >>>>
    >>>> clyde

    >> Logfile of HijackThis v1.99.1
    >> Scan saved at 5:03:39 AM, on 7/6/2005
    >> Platform: Windows XP SP2 (WinNT 5.01.2600)
    >> MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    >>
    >> Running processes:
    >> C:\WINDOWS\System32\smss.exe
    >> C:\WINDOWS\system32\winlogon.exe
    >> C:\WINDOWS\system32\services.exe
    >> C:\WINDOWS\system32\lsass.exe
    >> C:\WINDOWS\system32\svchost.exe
    >> C:\WINDOWS\System32\svchost.exe
    >> C:\WINDOWS\Explorer.EXE
    >> C:\WINDOWS\system32\spoolsv.exe
    >> C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    >> C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
    >> C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
    >> C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
    >> C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
    >> C:\Program Files\QuickTime\qttask.exe
    >> C:\Program Files\McAfee\McAfee AntiSpyware\MssCli.exe
    >> C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    >> C:\Program Files\Weather Watcher\ww.exe
    >> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    >> C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    >> C:\Program Files\Handspring\HOTSYNC.EXE
    >> C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    >> C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
    >> C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    >> C:\WINDOWS\system32\drivers\KodakCCS.exe
    >> c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe
    >> c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    >> C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
    >> C:\WINDOWS\System32\svchost.exe
    >> c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    >> C:\WINDOWS\system32\HPZipm12.exe
    >> C:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe
    >> C:\Program Files\Internet Explorer\iexplore.exe
    >> C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
    >> C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe
    >> C:\Program Files\Outlook Express\msimn.exe
    >> C:\Documents and Settings\User\Local Settings\Temporary Internet
    >> Files\Content.IE5\S3Z3IKDP\HijackThis1991[1].exe
    >>
    >> R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    >> http://www.excite.com/
    >> R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    >> http://www.excite.com/
    >> R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    >> R0 - HKCU\Software\Microsoft\Internet
    >> Explorer\Toolbar,LinksFolderName = R3 - Default URLSearchHook is
    >> missing
    >> O2 - BHO: AcroIEHlprObj Class -
    >> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
    >> Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    >> O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E}
    >> - c:\PROGRA~1\mcafee.com\mps\mcbrhlpr.dll
    >> O2 - BHO: McAfee PopupKiller -
    >> {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program
    >> files\mcafee.com\mps\popupkiller.dll
    >> O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
    >> C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    >> O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no
    >> file) O2 - BHO: Google Toolbar Helper -
    >> {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program
    >> files\google\googletoolbar1.dll
    >> O2 - BHO: (no name) - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no
    >> file) O3 - Toolbar: McAfee VirusScan -
    >> {BA52B914-B692-46c4-B683-905236F6F655} -
    >> c:\progra~1\mcafee.com\vso\mcvsshl.dll
    >> O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} -
    >> c:\program files\google\googletoolbar1.dll
    >> O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
    >> O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
    >> O4 - HKLM\..\Run: [MCAgentExe]
    >> c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run:
    >> [SunJavaUpdateSched] C:\Program
    >> Files\Java\jre1.5.0_02\bin\jusched.exe
    >> O4 - HKLM\..\Run: [MCUpdateExe]
    >> C:\PROGRA~1\mcafee.com\agent\mcupdate.exe O4 - HKLM\..\Run:
    >> [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
    >> O4 - HKLM\..\Run: [VirusScan Online]
    >> "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
    >> O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    >> O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe
    >> /embedding
    >> O4 - HKLM\..\Run: [MPFExe]
    >> C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
    >> O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
    >> Files\QuickTime\qttask.exe" -atboottime
    >> O4 - HKLM\..\Run: [_AntiSpyware] C:\Program Files\McAfee\McAfee
    >> AntiSpyware\MssCli.exe
    >> O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    >> /STARTUP
    >> O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    >> O4 - HKLM\..\RunOnce: [XoftSpy] "C:\Program
    >> Files\XoftSpy\XoftSpy.exe" -b O4 - HKCU\..\Run: [SpybotSD TeaTimer]
    >> C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    >> O4 - HKCU\..\Run: [WeatherWatcher] C:\Program Files\Weather
    >> Watcher\ww.exe O4 - Startup: HotSync Manager.lnk = C:\Program
    >> Files\Handspring\HOTSYNC.EXE
    >> O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program
    >> Files\HP\Digital Imaging\bin\hpqtra08.exe
    >> O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program
    >> Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    >> O8 - Extra context menu item: &Google Search - res://C:\Program
    >> Files\Google\GoogleToolbar1.dll/cmsearch.html
    >> O8 - Extra context menu item: Backward Links - res://C:\Program
    >> Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    >> O8 - Extra context menu item: Cached Snapshot of Page -
    >> res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
    >> O8 - Extra context menu item: Similar Pages - res://C:\Program
    >> Files\Google\GoogleToolbar1.dll/cmsimilar.html
    >> O8 - Extra context menu item: Translate into English -
    >> res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
    >> O9 - Extra button: (no name) -
    >> {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
    >> Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    >> O9 - Extra 'Tools' menuitem: Sun Java Console -
    >> {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
    >> Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    >> O9 - Extra button: Messenger -
    >> {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
    >> Files\Messenger\msmsgs.exe
    >> O9 - Extra 'Tools' menuitem: Windows Messenger -
    >> {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
    >> Files\Messenger\msmsgs.exe
    >> O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop
    >> Utility) - O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC
    >> Class) -
    >> O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} -
    >> O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com
    >> Operating System Class) -
    >> O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader
    >> Control) - O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} -
    >> O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl
    >> Class) -
    >>

    http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1097978376171
    >> O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in
    >> 1.5.0_02) -
    >> O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) -
    >> O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} -
    >> O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr
    >> Class) - O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} (Java
    >> Plug-in 1.5.0) - O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
    >> O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj
    >> Class) -
    >> O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) -
    >> O20 - Winlogon Notify: Hints - C:\WINDOWS\
    >> O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    >> O20 - Winlogon Notify: WindowsUpdate - C:\WINDOWS\
    >> O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT,
    >> s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    >> O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. -
    >> C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    >> O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman
    >> Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
    >> O23 - Service: McAfee AntiSpyware Real-Time Scanner
    >> (McAfeeAntiSpyware) - McAfee, Inc. -
    >> c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe
    >> O23 - Service: McAfee.com McShield (McShield) - Unknown owner -
    >> c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    >> O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) -
    >> McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    >> O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte)
    >> - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    >> O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee
    >> Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
    >> O23 - Service: Pml Driver HPZ12 - HP -
    >> C:\WINDOWS\system32\HPZipm12.exe
    >>
    >>
    >> ----== Posted via Newsfeeds.Com - Unlimited-Uncensored-Secure Usenet
    >> News==----
    >> http://www.newsfeeds.com The #1 Newsgroup Service in the World!
    >> 120,000+ Newsgroups
    >> ----= East and West-Coast Server Farms - Total Privacy via Encryption
    >> =----


    also download and use this freebie:

    http://www.majorgeeks.com/BHODemon_d3550.html

    or download it from here

    http://www.pcworld.com/downloads/file_description/0,fid,23611,00.asp

    along with freebie:

    process explorerer v.9.0





    --

    Their ethics are a short summary of police ordinances: for them the
    most important thing is to be a useful member of the state, and to air
    their opinions in the club of an evening; they have never felt the
    homesickness for something unknown and far away, nor the depths which
    consists in being nothing at all. ___________Soren Kierkegaard

    Ellis_jay
     
    ellis_jay, Jul 13, 2005
    #6
    1. Advertising

Want to reply to this thread or ask your own question?

It takes just 2 minutes to sign up (and it's free!). Just click the sign up button to choose a username and then you can ask your own questions on the forum.
Similar Threads
  1. Echuca

    Malware

    Echuca, Oct 15, 2004, in forum: Firefox
    Replies:
    1
    Views:
    630
    Moz Champion
    Oct 26, 2004
  2. EDWARD DOYLE

    anti malware software

    EDWARD DOYLE, Apr 15, 2004, in forum: Computer Support
    Replies:
    3
    Views:
    5,319
    ┬░Mike┬░
    Apr 15, 2004
  3. Jaypie

    Malware

    Jaypie, Apr 16, 2004, in forum: Computer Support
    Replies:
    5
    Views:
    715
    Jaypie
    Apr 17, 2004
  4. twitchy

    Malware

    twitchy, Dec 28, 2004, in forum: Computer Support
    Replies:
    7
    Views:
    698
    Ron Martell
    Dec 29, 2004
  5. fkasner

    Malware Turning off NAV on boot

    fkasner, Feb 18, 2005, in forum: Computer Support
    Replies:
    7
    Views:
    438
    Vanguard
    Feb 19, 2005
Loading...

Share This Page