Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

HiJackThisLog


  • This topic is locked This topic is locked

#1
Kitten72003

Kitten72003

    Member

  • Member
  • PipPip
  • 11 posts
So IE isnt working correctly. Half the time it wont open and then if it does after looking at like 3 pages itll freeze. On top of that symantec keeps finding this Msup5.exe that has some trojan in it or something...i dont know.... im computer virus retarded, thats why im here. If you could please help me id greatly appreciate it. Thank you in advance :0)


Logfile of HijackThis v1.99.1
Scan saved at 5:03:52 PM, on 2/23/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\msupd5.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://one.drexel.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost
O2 - BHO: (no name) - {0F28960B-F39A-256B-14E5-8B055568B8C2} - C:\WINDOWS\System32\vjrvcpfo.dll (file missing)
O2 - BHO: (no name) - {29C11DA6-626E-77BE-3DAF-1B133369242C} - C:\WINDOWS\System32\zpuaebdu.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C959489-BED4-E525-8CAA-CDC203EDD8C4} - C:\WINDOWS\System32\nfbycggk.dll (file missing)
O2 - BHO: (no name) - {B4159D06-FF07-A6A0-0D4A-82E55353801F} - C:\WINDOWS\System32\kuglbtra.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Finance</A><] c:\WINDOWS\System32\ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Finance</A></td>
O4 - HKLM\..\Run: [ <td bgcolor=#D3DBE4><img src="http://parked.direct...ges/spacer.gif" height=1 width=174><] c:\WINDOWS\System32\ <td bgcolor=#D3DBE4><img src="http://parked.direct...ges/spacer.gif" height=1 width=174></td>
O4 - HKLM\..\Run: [ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><a href="http://parked.direct...tti.com&side=1" class="category">Travel</a><] c:\WINDOWS\System32\ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><a href="http://parked.direct...tti.com&side=1" class="category">Travel</a></td>
O4 - HKLM\..\Run: [ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Gifts</A><] c:\WINDOWS\System32\ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Gifts</A></td>
O4 - HKLM\..\Run: [ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Home</A><] c:\WINDOWS\System32\ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Home</A></td>
O4 - HKLM\..\Run: [ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Health</A><] c:\WINDOWS\System32\ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Health</A></td>
O4 - HKLM\..\Run: [ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Entertainment</A><] c:\WINDOWS\System32\ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Entertainment</A></td>
O4 - HKLM\..\Run: [ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Shopping</A><] c:\WINDOWS\System32\ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Shopping</A></td>
O4 - HKLM\..\Run: [ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Computing</A><] c:\WINDOWS\System32\ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Computing</A></td>
O4 - HKLM\..\Run: [ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Hobbies</A><] c:\WINDOWS\System32\ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Hobbies</A></td>
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKCU\..\Run: [<meta name="description" content="beneditutti.com is under construction. This page is courtesy of directNIC.c] c:\WINDOWS\System32\<meta name="description" content="beneditutti.com is under construction. This page is courtesy of directNIC.com">
O4 - HKCU\..\Run: [<BODY TOPMARGIN="0" LEFTMARGIN="0" MARGINHEIGHT="0" MARGINWIDTH="0" BGCOLOR="#FFFFFF" TEXT="#000000" vLink=#000] c:\WINDOWS\System32\<BODY TOPMARGIN="0" LEFTMARGIN="0" MARGINHEIGHT="0" MARGINWIDTH="0" BGCOLOR="#FFFFFF" TEXT="#000000" vLink=#0000ff>
O4 - HKCU\..\Run: [ <td background="http://parked.direct.../top_bg.gif"><a href="http://directnic.com"><img src="http://parked.direct...mages/dnic.gif" width="372" height="41" border="0"></a><] c:\WINDOWS\System32\ <td background="http://parked.direct.../top_bg.gif"><a href="http://directnic.com"><img src="http://parked.direct...mages/dnic.gif" width="372" height="41" border="0"></a></td>
O4 - HKCU\..\Run: [ <td align="right" background="http://parked.direct...ges/top_bg.gif" class="head">beneditutti.com is under construction.<] c:\WINDOWS\System32\ <td align="right" background="http://parked.direct...ges/top_bg.gif" class="head">beneditutti.com is under construction.</td>
O4 - HKCU\..\Run: [ <td align="left" background="http://parked.direct...ges/btm_bg.gif" class="wtext"><img src="http://parked.direct...ges/btm_lt.gif" width="24" height="25" align="absmiddle"><] c:\WINDOWS\System32\ <td align="left" background="http://parked.direct...ges/btm_bg.gif" class="wtext"><img src="http://parked.direct...ges/btm_lt.gif" width="24" height="25" align="absmiddle"></td>
O4 - HKCU\..\Run: [ <td align="center" class=search>search the web: <input type=text name="Keywords" value="" class="textfie] c:\WINDOWS\System32\ <td align="center" class=search>search the web: <input type=text name="Keywords" value="" class="textfield">
O4 - HKCU\..\Run: [ <td bgcolor="#333333" valign=top height="16"><a href="http://parked.direct...utti.com&cat=1" class="wheader">Computing</a><] c:\WINDOWS\System32\ <td bgcolor="#333333" valign=top height="16"><a href="http://parked.direct...utti.com&cat=1" class="wheader">Computing</a></td>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct....com&cat=1">Web Hosting</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct....com&cat=1">Web Hosting</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct....com&cat=1">Web Design</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct....com&cat=1">Web Design</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...">Computer</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...omputer</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...cat=1">Computer Hardware</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...cat=1">Computer Hardware</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...">Software</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...oftware</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...cat=1">Computer Game</a><br><] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...cat=1">Computer Game</a><br></td>
O4 - HKCU\..\Run: [ <td bgcolor="#99CC66" valign=top height="16"><a href="http://parked.direct...utti.com&cat=1" class="wheader">Travel</a><] c:\WINDOWS\System32\ <td bgcolor="#99CC66" valign=top height="16"><a href="http://parked.direct...utti.com&cat=1" class="wheader">Travel</a></td>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...at=1">Adventure Travel</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...at=1">Adventure Travel</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...">Vacation</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...acation</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...&cat=1">Airline Ticket</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...&cat=1">Airline Ticket</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...t=1">Hotel</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...">Hotel</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...=1">Travel</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...>Travel</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...">Map</a><br><] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...ap</a><br></td>
O4 - HKCU\..\Run: [ <td bgcolor="#00CC99" valign=top height="16"><a href="http://parked.direct...utti.com&cat=1" class="wheader">Hobbies</a><] c:\WINDOWS\System32\ <td bgcolor="#00CC99" valign=top height="16"><a href="http://parked.direct...utti.com&cat=1" class="wheader">Hobbies</a></td>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...1">Fitness</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...Fitness</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...t=1">Craft</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...">Craft</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...1">Cooking</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...Cooking</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...>Gardening</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...rdening</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...com&cat=1">Home Decorating</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...com&cat=1">Home Decorating</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...ports</a><br><] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...ts</a><br></td>
O4 - HKCU\..\Run: [ <td bgcolor="#999999" valign=top height="16"><a href="http://parked.direct...utti.com&cat=1" class="wheader">Entertainment</a><] c:\WINDOWS\System32\ <td bgcolor="#999999" valign=top height="16"><a href="http://parked.direct...utti.com&cat=1" class="wheader">Entertainment</a></td>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...">Gambling</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...ambling</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...t=1">Movie</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...">Movie</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...t=1">Music</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...">Music</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...at=1">Game</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...1">Game</a><br>
O4 - HKCU\..\Run: [ <td bgcolor="#990000" valign=top height="16"><a href="http://parked.direct...utti.com&cat=1" class="wheader">Finance</a><] c:\WINDOWS\System32\ <td bgcolor="#990000" valign=top height="16"><a href="http://parked.direct...utti.com&cat=1" class="wheader">Finance</a></td>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...at=1">Loan</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...1">Loan</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...>Investing</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...vesting</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...>Insurance</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...surance</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...m&cat=1">Credit Card</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...m&cat=1">Credit Card</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...t=1">Stock</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...">Stock</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...com&cat=1">Real Estate</a><br><] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...com&cat=1">Real Estate</a><br></td>
O4 - HKCU\..\Run: [ <td bgcolor="#3399FF" valign=top height="16"><a href="http://parked.direct...utti.com&cat=1" class="wheader">Gifts</a><] c:\WINDOWS\System32\ <td bgcolor="#3399FF" valign=top height="16"><a href="http://parked.direct...utti.com&cat=1" class="wheader">Gifts</a></td>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...com&cat=1">Gift Basket</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...com&cat=1">Gift Basket</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...com&cat=1">Gift Certificate</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...com&cat=1">Gift Certificate</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...=1">Flower</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...>Flower</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...&cat=1">Wedding Gift</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...&cat=1">Wedding Gift</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...at=1">Wine</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...1">Wine</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...welry</a><br><] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...ry</a><br></td>
O4 - HKCU\..\Run: [ <td bgcolor="#FF6600" valign=top height="16"><a href="http://parked.direct...utti.com&cat=1" class="wheader">Shopping</a><] c:\WINDOWS\System32\ <td bgcolor="#FF6600" valign=top height="16"><a href="http://parked.direct...utti.com&cat=1" class="wheader">Shopping</a></td>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...at=1">Gift</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...1">Gift</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...cat=1">Car</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...=1">Car</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...at=1">Book</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...1">Book</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...lectronics</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...tronics</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...">Toy</a><br><] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...oy</a><br></td>
O4 - HKCU\..\Run: [ <td bgcolor="#333399" valign=top height="16"><a href="http://parked.direct...utti.com&cat=1" class="wheader">Home</a><] c:\WINDOWS\System32\ <td bgcolor="#333399" valign=top height="16"><a href="http://parked.direct...utti.com&cat=1" class="wheader">Home</a></td>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...com&cat=1">Home Loan</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...com&cat=1">Home Loan</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...com&cat=1">Home Improvement</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...com&cat=1">Home Improvement</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...com&cat=1">Home Buying</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...com&cat=1">Home Buying</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...cat=1">Interior Design</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...cat=1">Interior Design</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...at=1">Pets</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...1">Pets</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...ening</a><br><] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...ng</a><br></td>
O4 - HKCU\..\Run: [ <td bgcolor="#FF0033" valign=top height="16"><a href="http://parked.direct...utti.com&cat=1" class="wheader">Health</a><] c:\WINDOWS\System32\ <td bgcolor="#FF0033" valign=top height="16"><a href="http://parked.direct...utti.com&cat=1" class="wheader">Health</a></td>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...com&cat=1">Life Insurance</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...com&cat=1">Life Insurance</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...m&cat=1">Health Insurance</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...m&cat=1">Health Insurance</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...m&cat=1">Weight Loss</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...m&cat=1">Weight Loss</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...>Nutrition</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...trition</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...1">Fitness</a>] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...Fitness</a><br>
O4 - HKCU\..\Run: [   <b>·</b> <a href="http://parked.direct...m&cat=1">Womens Health</a><br><] c:\WINDOWS\System32\   <b>·</b> <a href="http://parked.direct...m&cat=1">Womens Health</a><br></td>
O4 - HKCU\..\Run: [ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Finance</A><] c:\WINDOWS\System32\ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Finance</A></td>
O4 - HKCU\..\Run: [ <td bgcolor=#D3DBE4><img src="http://parked.direct...ges/spacer.gif" height=1 width=174><] c:\WINDOWS\System32\ <td bgcolor=#D3DBE4><img src="http://parked.direct...ges/spacer.gif" height=1 width=174></td>
O4 - HKCU\..\Run: [ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><a href="http://parked.direct...tti.com&side=1" class="category">Travel</a><] c:\WINDOWS\System32\ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><a href="http://parked.direct...tti.com&side=1" class="category">Travel</a></td>
O4 - HKCU\..\Run: [ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Gifts</A><] c:\WINDOWS\System32\ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Gifts</A></td>
O4 - HKCU\..\Run: [ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Home</A><] c:\WINDOWS\System32\ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Home</A></td>
O4 - HKCU\..\Run: [ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Health</A><] c:\WINDOWS\System32\ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Health</A></td>
O4 - HKCU\..\Run: [ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Entertainment</A><] c:\WINDOWS\System32\ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Entertainment</A></td>
O4 - HKCU\..\Run: [ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Shopping</A><] c:\WINDOWS\System32\ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Shopping</A></td>
O4 - HKCU\..\Run: [ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Computing</A><] c:\WINDOWS\System32\ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Computing</A></td>
O4 - HKCU\..\Run: [ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Hobbies</A><] c:\WINDOWS\System32\ <td bgcolor=#F4F6F8 onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'"><img src="http://parked.direct...ages/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle><A href="http://parked.direct...tti.com&side=1" class=category>Hobbies</A></td>
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: D-Link AirPlus G Configuration Utility.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.web...otoUploader.CAB
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - https://www.stopzill...ller/dwnldr.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: crxzylcizmun (MsUpdate5) - Unknown owner - C:\WINDOWS\System32\msupd5.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
  • 0

Advertisements


#2
Kitten72003

Kitten72003

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
.....can someone help me please....
  • 0

#3
don77

don77

    Malware Expert

  • Retired Staff
  • 18,526 posts
Topic closed,
Being helped Here
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP