Levan
2 Jul 2009, 7:07am
Hello and please help!
I had been browsing amazon and my local library with IE 6. I googled to see if a certain radio show was available as a torrent. While reading a resulting page, my computer went down and took a while to reboot (the PC is 10 years old, and I wasn't sure if it was going to reboot or just stay hung).
I hadn't clicked on any links on the torrent description page (got there directly from google), I've never had a torrent app on this PC, and I haven't had any issues in months until now. While I was waiting on my PC to reboot, I turned off my external hard drive.
After it rebooted, I got a message saying windows had recovered from a serious error. Zone Alarm popped up an alert asking if I wanted to grant internet access to " MS RSA Parser ". I clicked no twice and my PC rebooted again. When it came back up, I told Zone Alarm no again, ran my Pest Patrol updater, then started a scan.
Pest Patrol immediately found " Ursnif " in two locations:
C: \Windows\9129837.exe
In Registry : HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\ttool
More Pest Patrol Info:
category: password capture
release date: 7/25/2006
certainty: confirmed
risk: High! This file is now running!
PP recommended that I have it delete the file, so I stopped the scan and chose delete. I then ran a new scan of both my hard drives, and PP didn't find anything.
I haven't rebooted my computer or turned my external hard drive back on, and Zone alarm hasn't given me any new alerts.
Thanks for reading and I hope to hear back soon.
My Hijack this log is below:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:56:09 AM, on 7/2/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2
(6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\System32\PDesk\PDesk.exe
C:\Program Files\Common Files\Symantec
Shared\ccApp.exe
C:\Program Files\Common Files\Symantec
Shared\ccSetMgr.exe
C:\WINDOWS\system32\PRISMSVR.EXE
C:\Program Files\Zone
Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Matrox Graphics
Inc\PowerDesk SE\Matrox.PowerDesk SE.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Eraser\eraser.exe
C:\Program Files\Common
Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\2Wire 802.11g
Wireless\PRISMCFG.exe
C:\Program Files\Common
Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\mgabg.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton
AntiVirus\navapsvc.exe
C:\Program Files\Norton
AntiVirus\AdvTools\NPROTECT.EXE
C:\SUPERFAX\PROGRAM\PICPMON.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec
Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
C:\Program Files\Common Files\Symantec
Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec
Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wuauclt.exe
c:\Program Files\PestPatrol\ppmemcheck.exe
c:\Program Files\PestPatrol\ppcontrol.exe
C:\Program Files\Internet
Explorer\iexplore.exe
C:\Program Files\PestPatrol\PestPatrol.exe
C:\Program Files\Microsoft
Office\Office\WINWORD.EXE
C:\Program Files\Hewlett-Packard\HP
Share-to-Web\hpgs2wnf.exe
C:\Documents and Settings\default\Desktop\PC
Tools\HiJackThis.exe
C:\Program Files\Messenger\msmsgs.exe
R0 - HKLM\Software\Microsoft\Internet
Explorer\Main,Start Page = http://www.rr.com
R0 - HKLM\Software\Microsoft\Internet
Explorer\Main,Local Page =
C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Window Title = Microsoft
Internet Explorer provided by Comcast
R3 - URLSearchHook: Yahoo! Toolbar -
{EF99BD32-C1FB-11D2-892F-0090271D4F88} -
C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\yt.
dll
N3 - Netscape 7: # Mozilla User Preferences
// This is a generated file!
user_pref("Dick
Cox.aim.session.autologin", false);
user_pref("Dick
Cox.aim.session.connectionname", "AIM");
user_pref("Dick Cox.aim.session.password",
"0");
user_pref("Dick
Cox.aim.session.storepassword", false);
user_pref("aim.away.disablesound", false);
user_pref("aim.internal.buddy.MaxBuddies",
220);
user_pref("aim.internal.intproxyprotocol",
1);
user_pref("aim.session.finishedwizard",
true);
user_pref("aim.session.firsttime",
false);
user_pref("aim.session.latestaimscreenname",
"icehelmets");
user_pref("aim.session.migrateBuddyList",
"Dick Cox");
user_pref("aim.session.screenname",
"icehelmets");
user_pref("browser.bookmarks.added_static_roo
t", true);
user_pref("browser.download.dir",
"C:\\WINDOWS\\Desktop");
user_pref("browser.history.last_page_visited"
,
"http://boards.billmaher.com/logout.php?Cat="
);
user_pref("browser.search.defaultengine",
"engine://C%3A%5CPROGRAM%20FILES%5CNETSCAPE%5
CNETSCAPE%206%5Csearchplugins%5CSBWeb_01.src
O2 - BHO: &Yahoo! Toolbar Helper -
{02478D38-C3F9-4efb-9B51-7695ECA05670} -
C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\yt.
dll
O2 - BHO: Adobe PDF Reader Link Helper -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Adobe\Acrobat
7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button -
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} -
C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess -
{5CA3D70E-1895-11CF-8E15-001234567890} -
C:\WINDOWS\system\dla\tfswshx.dll
O2 - BHO: NAV Helper -
{BDF3E430-B101-42AD-A544-FADC6B084872} -
C:\Program Files\Norton
AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus -
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
C:\Program Files\Norton
AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar -
{EF99BD32-C1FB-11D2-892F-0090271D4F88} -
C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\yt.
dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [Matrox Powerdesk]
C:\WINDOWS\System32\PDesk\PDesk.exe
/Autolaunch
O4 - HKLM\..\Run: [ccApp] "C:\Program
Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check]
C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [PRISMSVR.EXE]
"C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [Zone Labs Client]
C:\Program Files\Zone
Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [Matrox PowerDesk SE]
"c:\Program Files\Matrox Graphics
Inc\PowerDesk SE\Matrox.PowerDesk SE.exe"
O4 - HKLM\..\Run: [PPMemCheck]
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [PestPatrol Control Center]
C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [MpsOnn]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\Mp
sOnn.exe
O4 - HKLM\..\Run: [QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe"
-atboottime
O4 - HKCU\..\Run: [Eraser] C:\Program
Files\Eraser\eraser.exe -hide
O4 - HKCU\..\Run: [default] C:\Documents and
Settings\default\default.exe /i
O4 - Startup: rncsys32.exe
O4 - Global Startup: 2Wire Wireless
Client.lnk = C:\Program Files\2Wire 802.11g
Wireless\PRISMCFG.exe
O9 - Extra button: (no name) -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\WINDOWS\SYSTEM32\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console
- {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\WINDOWS\SYSTEM32\MSJAVA.DLL
O9 - Extra button: Yahoo! Services -
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} -
C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM -
{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} -
C:\Program Files\AIM95\aim.exe
O9 - Extra button: (no name) -
{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no
file)
O9 - Extra button: Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows
Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Support -
{1B2897F0-7F93-417D-B240-D720DA9B2339} -
http://www.comcastsupport.com (file missing)
(HKCU)
O9 - Extra button: ComcastHSI -
{291EA4D8-C8BC-4D70-82FB-15FE40113ACF} -
http://www.comcast.net (file missing) (HKCU)
O9 - Extra button: Help -
{E941727A-3ABE-4332-93F2-D20FFF992FC2} -
http://www.comcast.net/memberservices/ (file
missing) (HKCU)
O9 - Extra button: Dell Home -
{EE117DAA-A30B-40FC-945C-38AE1B80C1FA} -
http://www.dellnet.com (file missing) (HKCU)
O10 - Unknown file in Winsock LSP:
c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop:
C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: Win32 Classes -
O16 - DPF:
{62475759-9E84-458E-A1AB-5D2C442ADFDE} -
http://a1540.g.akamai.net/7/1540/52/20040427/
qtinstall.info.apple.com/saba/us/win/QuickTim
eInstaller.exe
O23 - Service: ATI Smart - Unknown owner -
C:\WINDOWS\SYSTEM32\ati2sgag.exe (file
missing)
O23 - Service: Symantec Event Manager
(ccEvtMgr) - Symantec Corporation -
C:\Program Files\Common Files\Symantec
Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation
(ccPwdSvc) - Symantec Corporation -
C:\Program Files\Common Files\Symantec
Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager
(ccSetMgr) - Symantec Corporation -
C:\Program Files\Common Files\Symantec
Shared\ccSetMgr.exe
O23 - Service: EpsonBidirectionalService -
Unknown owner - C:\Program Files\Common
Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2
(EPSONStatusAgent2) - SEIKO EPSON CORPORATION
- C:\Program Files\Common
Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: MGABGEXE - Matrox Graphics
Inc. - C:\WINDOWS\system32\mgabg.exe
O23 - Service: Norton AntiVirus Auto Protect
Service (navapsvc) - Symantec Corporation -
C:\Program Files\Norton
AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection
(NProtectService) - Symantec Corporation -
C:\Program Files\Norton
AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: Pacific Image Comm. Fax Server
- Unknown owner -
C:\SUPERFAX\PROGRAM\PICPMON.EXE
O23 - Service: PCTEL Speaker Phone (Pctspk) -
Unknown owner -
C:\WINDOWS\system32\pctspk.exe
O23 - Service: SAVScan - Symantec Corporation
- C:\Program Files\Norton
AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service
(SBService) - Symantec Corporation -
C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ
.exe
O23 - Service: Symantec Core LC - Symantec
Corporation - C:\Program Files\Common
Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) -
Symantec Corporation - C:\Program
Files\Common Files\Symantec Shared\Security
Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor
(vsmon) - Zone Labs, LLC -
C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
--
End of file - 9074 bytes
I had been browsing amazon and my local library with IE 6. I googled to see if a certain radio show was available as a torrent. While reading a resulting page, my computer went down and took a while to reboot (the PC is 10 years old, and I wasn't sure if it was going to reboot or just stay hung).
I hadn't clicked on any links on the torrent description page (got there directly from google), I've never had a torrent app on this PC, and I haven't had any issues in months until now. While I was waiting on my PC to reboot, I turned off my external hard drive.
After it rebooted, I got a message saying windows had recovered from a serious error. Zone Alarm popped up an alert asking if I wanted to grant internet access to " MS RSA Parser ". I clicked no twice and my PC rebooted again. When it came back up, I told Zone Alarm no again, ran my Pest Patrol updater, then started a scan.
Pest Patrol immediately found " Ursnif " in two locations:
C: \Windows\9129837.exe
In Registry : HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\ttool
More Pest Patrol Info:
category: password capture
release date: 7/25/2006
certainty: confirmed
risk: High! This file is now running!
PP recommended that I have it delete the file, so I stopped the scan and chose delete. I then ran a new scan of both my hard drives, and PP didn't find anything.
I haven't rebooted my computer or turned my external hard drive back on, and Zone alarm hasn't given me any new alerts.
Thanks for reading and I hope to hear back soon.
My Hijack this log is below:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:56:09 AM, on 7/2/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2
(6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\System32\PDesk\PDesk.exe
C:\Program Files\Common Files\Symantec
Shared\ccApp.exe
C:\Program Files\Common Files\Symantec
Shared\ccSetMgr.exe
C:\WINDOWS\system32\PRISMSVR.EXE
C:\Program Files\Zone
Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Matrox Graphics
Inc\PowerDesk SE\Matrox.PowerDesk SE.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Eraser\eraser.exe
C:\Program Files\Common
Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\2Wire 802.11g
Wireless\PRISMCFG.exe
C:\Program Files\Common
Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\mgabg.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton
AntiVirus\navapsvc.exe
C:\Program Files\Norton
AntiVirus\AdvTools\NPROTECT.EXE
C:\SUPERFAX\PROGRAM\PICPMON.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec
Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
C:\Program Files\Common Files\Symantec
Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec
Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wuauclt.exe
c:\Program Files\PestPatrol\ppmemcheck.exe
c:\Program Files\PestPatrol\ppcontrol.exe
C:\Program Files\Internet
Explorer\iexplore.exe
C:\Program Files\PestPatrol\PestPatrol.exe
C:\Program Files\Microsoft
Office\Office\WINWORD.EXE
C:\Program Files\Hewlett-Packard\HP
Share-to-Web\hpgs2wnf.exe
C:\Documents and Settings\default\Desktop\PC
Tools\HiJackThis.exe
C:\Program Files\Messenger\msmsgs.exe
R0 - HKLM\Software\Microsoft\Internet
Explorer\Main,Start Page = http://www.rr.com
R0 - HKLM\Software\Microsoft\Internet
Explorer\Main,Local Page =
C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Window Title = Microsoft
Internet Explorer provided by Comcast
R3 - URLSearchHook: Yahoo! Toolbar -
{EF99BD32-C1FB-11D2-892F-0090271D4F88} -
C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\yt.
dll
N3 - Netscape 7: # Mozilla User Preferences
// This is a generated file!
user_pref("Dick
Cox.aim.session.autologin", false);
user_pref("Dick
Cox.aim.session.connectionname", "AIM");
user_pref("Dick Cox.aim.session.password",
"0");
user_pref("Dick
Cox.aim.session.storepassword", false);
user_pref("aim.away.disablesound", false);
user_pref("aim.internal.buddy.MaxBuddies",
220);
user_pref("aim.internal.intproxyprotocol",
1);
user_pref("aim.session.finishedwizard",
true);
user_pref("aim.session.firsttime",
false);
user_pref("aim.session.latestaimscreenname",
"icehelmets");
user_pref("aim.session.migrateBuddyList",
"Dick Cox");
user_pref("aim.session.screenname",
"icehelmets");
user_pref("browser.bookmarks.added_static_roo
t", true);
user_pref("browser.download.dir",
"C:\\WINDOWS\\Desktop");
user_pref("browser.history.last_page_visited"
,
"http://boards.billmaher.com/logout.php?Cat="
);
user_pref("browser.search.defaultengine",
"engine://C%3A%5CPROGRAM%20FILES%5CNETSCAPE%5
CNETSCAPE%206%5Csearchplugins%5CSBWeb_01.src
O2 - BHO: &Yahoo! Toolbar Helper -
{02478D38-C3F9-4efb-9B51-7695ECA05670} -
C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\yt.
dll
O2 - BHO: Adobe PDF Reader Link Helper -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Adobe\Acrobat
7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button -
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} -
C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess -
{5CA3D70E-1895-11CF-8E15-001234567890} -
C:\WINDOWS\system\dla\tfswshx.dll
O2 - BHO: NAV Helper -
{BDF3E430-B101-42AD-A544-FADC6B084872} -
C:\Program Files\Norton
AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus -
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
C:\Program Files\Norton
AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar -
{EF99BD32-C1FB-11D2-892F-0090271D4F88} -
C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\yt.
dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [Matrox Powerdesk]
C:\WINDOWS\System32\PDesk\PDesk.exe
/Autolaunch
O4 - HKLM\..\Run: [ccApp] "C:\Program
Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check]
C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [PRISMSVR.EXE]
"C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [Zone Labs Client]
C:\Program Files\Zone
Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [Matrox PowerDesk SE]
"c:\Program Files\Matrox Graphics
Inc\PowerDesk SE\Matrox.PowerDesk SE.exe"
O4 - HKLM\..\Run: [PPMemCheck]
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [PestPatrol Control Center]
C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [MpsOnn]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\Mp
sOnn.exe
O4 - HKLM\..\Run: [QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe"
-atboottime
O4 - HKCU\..\Run: [Eraser] C:\Program
Files\Eraser\eraser.exe -hide
O4 - HKCU\..\Run: [default] C:\Documents and
Settings\default\default.exe /i
O4 - Startup: rncsys32.exe
O4 - Global Startup: 2Wire Wireless
Client.lnk = C:\Program Files\2Wire 802.11g
Wireless\PRISMCFG.exe
O9 - Extra button: (no name) -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\WINDOWS\SYSTEM32\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console
- {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\WINDOWS\SYSTEM32\MSJAVA.DLL
O9 - Extra button: Yahoo! Services -
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} -
C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM -
{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} -
C:\Program Files\AIM95\aim.exe
O9 - Extra button: (no name) -
{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no
file)
O9 - Extra button: Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows
Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Support -
{1B2897F0-7F93-417D-B240-D720DA9B2339} -
http://www.comcastsupport.com (file missing)
(HKCU)
O9 - Extra button: ComcastHSI -
{291EA4D8-C8BC-4D70-82FB-15FE40113ACF} -
http://www.comcast.net (file missing) (HKCU)
O9 - Extra button: Help -
{E941727A-3ABE-4332-93F2-D20FFF992FC2} -
http://www.comcast.net/memberservices/ (file
missing) (HKCU)
O9 - Extra button: Dell Home -
{EE117DAA-A30B-40FC-945C-38AE1B80C1FA} -
http://www.dellnet.com (file missing) (HKCU)
O10 - Unknown file in Winsock LSP:
c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop:
C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: Win32 Classes -
O16 - DPF:
{62475759-9E84-458E-A1AB-5D2C442ADFDE} -
http://a1540.g.akamai.net/7/1540/52/20040427/
qtinstall.info.apple.com/saba/us/win/QuickTim
eInstaller.exe
O23 - Service: ATI Smart - Unknown owner -
C:\WINDOWS\SYSTEM32\ati2sgag.exe (file
missing)
O23 - Service: Symantec Event Manager
(ccEvtMgr) - Symantec Corporation -
C:\Program Files\Common Files\Symantec
Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation
(ccPwdSvc) - Symantec Corporation -
C:\Program Files\Common Files\Symantec
Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager
(ccSetMgr) - Symantec Corporation -
C:\Program Files\Common Files\Symantec
Shared\ccSetMgr.exe
O23 - Service: EpsonBidirectionalService -
Unknown owner - C:\Program Files\Common
Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2
(EPSONStatusAgent2) - SEIKO EPSON CORPORATION
- C:\Program Files\Common
Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: MGABGEXE - Matrox Graphics
Inc. - C:\WINDOWS\system32\mgabg.exe
O23 - Service: Norton AntiVirus Auto Protect
Service (navapsvc) - Symantec Corporation -
C:\Program Files\Norton
AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection
(NProtectService) - Symantec Corporation -
C:\Program Files\Norton
AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: Pacific Image Comm. Fax Server
- Unknown owner -
C:\SUPERFAX\PROGRAM\PICPMON.EXE
O23 - Service: PCTEL Speaker Phone (Pctspk) -
Unknown owner -
C:\WINDOWS\system32\pctspk.exe
O23 - Service: SAVScan - Symantec Corporation
- C:\Program Files\Norton
AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service
(SBService) - Symantec Corporation -
C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ
.exe
O23 - Service: Symantec Core LC - Symantec
Corporation - C:\Program Files\Common
Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) -
Symantec Corporation - C:\Program
Files\Common Files\Symantec Shared\Security
Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor
(vsmon) - Zone Labs, LLC -
C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
--
End of file - 9074 bytes