| Live Chat & Podcast Sunday at 12:00PM Eastern! |
General Security |
| |
Search | |
| | Thread Tools |
|
05-Jan-2009, 01:17 PM
#1 |
| IE, MSN, and Various Adware & Trojans A few days ago, Internet Explorer started to act extremely weird. It was much more susceptible to freezing up, and then Antivirus 2009 popups and other related fake antivirus program popups started appearing, even on Firefox. It even affected the Windows Live, particularly Hotmail. My family and I could not access our e-mail without either the page freezing up or adware popping up. I have run the Super Anti-Spyware program at least 4 times in the past two days, it comes up with at least 40-50 instances of either Trojan.Fake Alerts or various types of Adware. I have figured out that it has something to do with Internet Explorer, and I have briefly removed it to see if it really was the case. Now I can go onto Firefox without adware popping up, but I still get annoying popups about dating and streaming sites even though Firefox is set to block them. Windows Live is still acting up. I cannot open up Windows Live Messenger (either through double-clicking the desktop icon, clicking on it in the Programs menu, or through the Task Manager). I can go to my inbox without a problem, but if I click on a new message, it takes a long time to show up. A hypothesis I have come to is that Windows Live's servers are having trouble, or something that Super Anti-Spyware didn't catch is causing the trouble. Usually about this time I am able to fix problems on the computer, but at this point I'm stuck. Help, please? ![]() ETA: After installing HJT, here is the log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:30:50, on 1/5/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16762) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\WINDOWS\arservice.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\McAfee\SiteAdvisor\McSACore.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\program files\common files\mcafee\mna\mcnasvc.exe c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\Program Files\McAfee\MSK\MskSrver.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe c:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\ARPWRMSG.EXE C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe C:\WINDOWS\SM1BG.EXE C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Program Files\DNA\btdna.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe C:\Program Files\iPod\bin\iPodService.exe C:\HP\KBD\KBD.EXE C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\MediaMonkey\MediaMonkey.exe c:\windows\system\hpsysdrv.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?fr=mcafee&p=%s R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us.mcafee.com/root/campaign.asp?cid=17198 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: (no name) - {05c906db-231e-4e91-a0b3-8a24432522ca} - C:\WINDOWS\system32\nevihezu.dll (file missing) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: hpWebHelper Class - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O2 - BHO: (no name) - {BBB6E7A1-EDEC-4D73-99C7-6C51F25721BD} - C:\WINDOWS\system32\rqRHwVpN.dll (file missing) O2 - BHO: {314391a1-ae1c-8089-a134-b15fc731aeac} - {caea137c-f51b-431a-9808-c1ea1a193413} - C:\WINDOWS\system32\efjjyk.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe" O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe" O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [dasowerubu] Rundll32.exe "C:\WINDOWS\system32\fiwupaga.dll",s O4 - HKLM\..\Run: [00e3a621] rundll32.exe "C:\WINDOWS\system32\fisalunu.dll",b O4 - HKLM\..\Run: [CPM03d095bd] Rundll32.exe "c:\windows\system32\lepokajo.dll",a O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe" O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKUS\S-1-5-19\..\Run: [dasowerubu] Rundll32.exe "C:\WINDOWS\system32\fiwupaga.dll",s (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [dasowerubu] Rundll32.exe "C:\WINDOWS\system32\fiwupaga.dll",s (User 'NETWORK SERVICE') O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user') O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user') O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Startup: MEMonitor.lnk = C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbar...S_ZSYYYYYYYYUS O8 - Extra context menu item: Download Link Using Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\HP_Administrator\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing) O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: Aces Up! by pogo - http://game1.pogo.com/v/8.1.5.27/app...aces-en_US.cab O16 - DPF: Bingo Luau by pogo - http://game1.pogo.com/v/8.1.7.44/app...ingo-en_US.cab O16 - DPF: Blackjack by pogo - http://game1.pogo.com/v/8.1.7.44/app...jack-en_US.cab O16 - DPF: Blackjack Carnival by pogo - http://game1.pogo.com/v/8.1.1.1/appl...ack2-en_US.cab O16 - DPF: Bowling by pogo - http://game1.pogo.com/v/8.1.2.14/app...ling-en_US.cab O16 - DPF: Canasta by pogo - http://game1.pogo.com/v/8.1.5.27/app...asta-en_US.cab O16 - DPF: Dice City Roller by pogo - http://game1.pogo.com/v/8.1.4.1/appl.../ytz-en_US.cab O16 - DPF: Dice Derby by pogo - http://game1.pogo.com/v/8.1.6.3/appl...flag-en_US.cab O16 - DPF: Dominoes v2 by pogo - http://game1.pogo.com/v/8.1.7.44/app...ino2-en_US.cab O16 - DPF: Double Deuce Poker by pogo - http://game1.pogo.com/v/8.1.1.1/appl...euce-en_US.cab O16 - DPF: First Class Solitaire by pogo - http://game1.pogo.com/v/8.1.7.44/app...ass2-en_US.cab O16 - DPF: Fortune Bingo by pogo - http://game1.pogo.com/v/8.1.1.1/appl...ingo-en_US.cab O16 - DPF: Hangman Hijinks by pogo - http://game3.pogo.com/v/8.1.9.1/appl...gman-en_US.cab O16 - DPF: Hearts by pogo - http://game1.pogo.com/v/8.1.1.13/app...arts-en_US.cab O16 - DPF: High Stakes Pool by pogo - http://game1.pogo.com/v/8.1.9.1/appl...pool-en_US.cab O16 - DPF: Jokers Wild Poker by pogo - http://game1.pogo.com/v/8.1.1.1/appl...wild-en_US.cab O16 - DPF: Jungle Gin by pogo - http://game1.pogo.com/v/8.1.9.1/appl...gin2-en_US.cab O16 - DPF: Lost Temple Poker by pogo - http://game1.pogo.com/v/8.1.1.1/appl...oker-en_US.cab O16 - DPF: Lottso by pogo - http://game3.pogo.com/v/8.1.9.1/appl...ttso-en_US.cab O16 - DPF: Mah Jong Garden by pogo - http://game1.pogo.com/v/8.1.6.21/app...ong2-en_US.cab O16 - DPF: Makeover Madness by pogo - http://game1.pogo.com/v/8.1.7.44/app...hoes-en_US.cab O16 - DPF: Pai Gow by pogo - http://game1.pogo.com/v/8.1.1.1/appl...igow-en_US.cab O16 - DPF: Perfect Pair Solitaire by pogo - http://game1.pogo.com/v/8.1.7.44/app...heel-en_US.cab O16 - DPF: Phlinx by pogo - http://game1.pogo.com/v/8.1.1.1/appl...nger-en_US.cab O16 - DPF: Pinochle by pogo - http://game1.pogo.com/v/8.1.7.44/app...chle-en_US.cab O16 - DPF: Pop Fu by pogo - http://game1.pogo.com/v/8.1.9.1/appl...opfu-en_US.cab O16 - DPF: Poppit by pogo - http://game3.pogo.com/v/8.1.9.11/app...pit2-en_US.cab O16 - DPF: Pseudoku by pogo - http://game3.pogo.com/v/8.1.9.22/app...doku-en_US.cab O16 - DPF: Quick Quack by pogo - http://game1.pogo.com/v/8.1.9.1/appl...reak-en_US.cab O16 - DPF: QWERTY by pogo - http://game1.pogo.com/v/8.1.6.3/appl...ares-en_US.cab O16 - DPF: Spooky Slots - http://game1.pogo.com/v/8.1.2.12/app...ooky-en_US.cab O16 - DPF: Squelchies by pogo - http://game3.pogo.com/v/8.1.9.1/appl...hies-en_US.cab O16 - DPF: Stellar Sweeper by pogo - http://game1.pogo.com/v/8.1.5.27/app...eper-en_US.cab O16 - DPF: Super Dominoes by pogo - http://game1.pogo.com/v/8.1.6.3/appl...mino-en_US.cab O16 - DPF: Sweet Tooth 2 by Pogo - http://game3.pogo.com/v/8.1.7.44/app...oth2-en_US.cab O16 - DPF: Sweet Tooth TM by pogo - http://game1.pogo.com/v/8.1.1.13/app...ooth-en_US.cab O16 - DPF: Texas Hold'em Poker by pogo - http://game1.pogo.com/v/8.1.5.27/app...ldem-en_US.cab O16 - DPF: Thousand Island Solitaire by pogo - http://game3.pogo.com/v/8.1.9.1/appl...brae-en_US.cab O16 - DPF: Tri-Peaks by pogo - http://game1.pogo.com/v/8.1.1.1/appl...eaks-en_US.cab O16 - DPF: Turbo 21 v2 by pogo - http://game1.pogo.com/v/8.1.9.7/appl...bo22-en_US.cab O16 - DPF: Vaults of Atlantis Slots by pogo - http://game1.pogo.com/v/8.1.1.1/appl...lots-en_US.cab O16 - DPF: Wonderland Memories by pogo - http://game1.pogo.com/v/8.1.1.1/appl...ries-en_US.cab O16 - DPF: Word Search Daily by pogo - http://game1.pogo.com/v/8.1.8.23/app...arch-en_US.cab O16 - DPF: Word Whomp by pogo - http://game1.pogo.com/v/8.1.7.44/app...omp2-en_US.cab O16 - DPF: Word Whomp Whackdown by pogo - http://game1.pogo.com/applet-8.0.6.5...down-en_US.cab O16 - DPF: WordJong by pogo - http://game1.pogo.com/applet-8.0.5.3...jong-en_US.cab O16 - DPF: World Class Solitaire by pogo - http://game1.pogo.com/v/8.1.6.21/app...lass-en_US.cab O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/...oUploader5.cab O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab O16 - DPF: {1A595EDD-978A-48C7-B730-AF3B9CC64DAB} (DLManager Class) - https://vmodlms.widerthanam.com/comp...WDLManager.cab O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/noc...1.0.0.15-3.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/sh...1/mcinsctl.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02...s/MSNPUpld.cab O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://picture.vzw.com/activex/Veriz...oadControl.cab O16 - DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} (SpinTop Games Launcher) - http://clubgames.pogo.com/online2/po...esLauncher.cab O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/sof...iveXPlugin.cab O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O20 - AppInit_DLLs: efjjyk.dll C:\WINDOWS\system32\konowahu.dll c:\windows\system32\kigadasi.dll c:\windows\system32\lepokajo.dll O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL O20 - Winlogon Notify: ljJARhiF - ljJARhiF.dll (file missing) O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - (no file) O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - (no file) O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe -- End of file - 18138 bytes Last edited by harukakamiya : 05-Jan-2009 01:35 PM. |
| |
|
05-Jan-2009, 01:27 PM
#3 |
05-Jan-2009, 01:28 PM
#4 | ||||||
| http://www.trendsecure.com/portal/en...ols/hijackthis Don't fix anything, just copy the log after scanning and post it back here. |
|
05-Jan-2009, 01:31 PM
#5 |
| Thanks, I'll move this post! |
|
05-Jan-2009, 02:37 PM
#6 |
| New thread has been started so I'll close this one. http://forums.techguy.org/malware-re...d-general.html |
![]() | |
| Smart Search |
Find your solution! |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |

| Thread Tools | |
| |
| You Are Using: |
Advertisements do not imply our endorsement of that product or service. All times are GMT -5. The time now is 11:34 AM. Copyright © 1996 - 2010 TechGuy, Inc. All rights reserved. | |






