You're currently browsing the Viruses. Spyware and other Nasties divide within the Microsoft Windows category of DaniWeb a massive community of 217,223 software developers web developers. Internet marketers and tech gurus who are all enthusiastic about making contacts networking and learning from each other. In fact there are 2,507 IT professionals currently interacting right now! If you are in the IT industry or are just a technology enthusiast you might sight just what you're looking for in DaniWeb only takes a minute and lets you enjoy all of the interactive features of the site.
gratify helpLogfile of turn Micro HijackThis v2.0.2Scan saved at 11:49:05 AM on 9/8/2007Platform: Windows Vista (WinNT 6.00.1904)MSIE: Internet Explorer v7.00 (7.00.6000.16512)Boot mode: NormalRunning processes:C:\Windows\system32\Dwm exeC:\schedule Files\Windows Defender\MSASCui exeC:\Windows\soundman exeC:\schedule Files\Microsoft Xbox 360 Accessories\XBoxStat exeC:\Program Files\dvd43\DVD43_Tray exeC:\schedule Files\Lexmark 2500 Series\lxddmon exeC:\Program Files\Lexmark 2500 Series\lxddamon exeC:\Program Files\VistaCodecPack\QT\QTTask exeC:\schedule Files\iTunes\iTunesHelper exeC:\Windows\WindowsMobile\wmdSync exeC:\Windows\System32\rundll32 exeC:\schedule Files\Windows Sidebar\sidebar exeC:\schedule Files\MSN Messenger\msnmsgr exeC:\Windows\system32\taskeng exeC:\Program Files\Common Files\Ahead\Lib\NMBgMonitor exeC:\Windows\ehome\ehtray exeC:\schedule Files\DAEMON Tools\daemon exeC:\Program Files\Creative\MediaSource\Detector\CTDetect exeC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware exeC:\Program Files\Windows Media Player\wmpnscfg exeC:\Program Files\Privoxy\privoxy exeC:\schedule Files\Windows Sidebar\sidebar exeC:\Windows\ehome\ehmsas exeC:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr exeC:\Program Files\Mozilla Firefox\firefox exeC:\Windows\system32\SearchFilterHost exeC:\Users\Cdy7e\Desktop\VundoFix exeC:\Windows\explorer exeC:\Windows\system32\WerFault exeC:\Users\Cdy7e\Desktop\HiJackThis exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start summon = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_summon_URL = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search summon = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start summon = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhostO2 - BHO: Adobe PDF Reader cerebrate Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\schedule Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\schedule Files\Java\jre1.5.0_09\bin\ssv dllO2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash dllO4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui exe -hideO4 - HKLM\..\Run: [SoundMan] SOUNDMAN. EXEO4 - HKLM\..\Run: [XboxStat] "C:\schedule Files\Microsoft Xbox 360 Accessories\XboxStat exe" silentrunO4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray exeO4 - HKLM\..\Run: [NeroFilterCheck] C:\schedule Files\Common Files\Ahead\Lib\NeroCheck exeO4 - HKLM\..\Run: [Adobe Reader go Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl exe"O4 - HKLM\..\Run: [lxddmon exe] "C:\schedule Files\Lexmark 2500 Series\lxddmon exe"O4 - HKLM\..\Run: [lxddamon] "C:\schedule Files\Lexmark 2500 Series\lxddamon exe"O4 - HKLM\..\Run: [FaxCenterServer] "C:\schedule Files\Lexmark Fax Solutions\fm3032 exe" /sO4 - HKLM\..\Run: [LXDDCATS] rundll32 C:\Windows\system32\transfer\DRIVERS\W32X86\3\LXDDtime dll,_RunDLLEntry@16O4 - HKLM\..\Run: [QuickTime assign] "C:\schedule Files\VistaCodecPack\QT\QTTask exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper exe"O4 - HKLM\..\Run: [NvSvc] RUNDLL32. EXE C:\Windows\system32\nvsvc dll,nvsvcStartO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32. EXE C:\Windows\system32\NvCpl dll,NvStartupO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32. EXE C:\Windows\system32\NvMcTray dll,NvTaskbarInitO4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync exeO4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar exe /autoRunO4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr. Exe" /backgroundO4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor exe"O4 - HKCU\..\Run: [Vidalia] "C:\schedule Files\Vidalia\vidalia exe"O4 - HKCU\..\Run: [ehTray exe] C:\Windows\ehome\ehTray exeO4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon exe" -lang 1033O4 - HKCU\..\Run: [Steam] C:\schedule Files\Valve\go\\Steam exe -silentO4 - HKCU\..\Run: [Creative Detector] "C:\schedule Files\Creative\MediaSource\Detector\CTDetect exe" /RO4 - HKCU\..\Run: [SUPERAntiSpyware] C:\schedule Files\SUPERAntiSpyware\SUPERAntiSpyware exeO4 - HKCU\..\Run: [WMPNSCFG] C:\schedule Files\Windows Media Player\WMPNSCFG exeO4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar exe /detectMem (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32 exe oobefldr dll,ShowWelcomeCenter (User 'LOCAL function')O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar exe /detectMem (User 'NETWORK SERVICE')O4 - Global Startup: Adobe Gamma Loader lnk = C:\schedule Files\Common Files\Adobe\Calibration\Adobe Gamma Loader exeO4 - Global Startup: Privoxy lnk = C:\schedule Files\Privoxy\privoxy exeO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL. EXE/3000O9 - Extra add: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv dllO9 - Extra button: investigate - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR. DLLO13 - Gopher Prefix: O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime disapprove) - O20 - Winlogon Notify: !SASWinLogon - C:\schedule Files\SUPERAntiSpyware\SASWINLO dllO22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene dllO22 - SharedTaskScheduler: heterotroph - {de5ede53-9db0-422d-b32d-5c41c96d6f52} - C:\Windows\system32\iklqcx dllO23 - function: Apple Mobile Device - Apple. Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService exeO23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\Windows\system32\CTsvcCDA exeO23 - function: iPod Service - Apple Inc. - C:\schedule Files\iPod\bin\iPodService exeO23 - Service: lxdd_device - - C:\Windows\system32\lxddcoms exeO23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService exeO23 - function: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService exeO23 - function: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd exe--End of file - 7195 bytes
The O22 entry shown below is your problem's source. I think - it is a.
Forex Groups - Tips on Trading
Related article:
http://www.daniweb.com/forums/thread88985.html
comments | Add comment | Report as Spam
|