<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Hijack Log and w32.Gaobot!inf virus in Security</title>
<link>http://www.dslreports.com/forum/r10141165</link>
<description></description>
<language>en</language>
<pubDate>Thu, 03 Dec 2009 09:39:05 EDT</pubDate>
<lastBuildDate>Thu, 03 Dec 2009 09:39:05 EDT</lastBuildDate>

<item>
<title>Re: Hijack Log and w32.Gaobot!inf virus</title>
<link>http://www.dslreports.com/forum/remark,10160019</link>
<description><![CDATA[<A HREF="/useremail/u/792347"><b>sonnysims</b></A> : We are in the same boat here. Soundtasks.exe and Soundtctrls.exe running on machines.<br><br>If you scan them for viruses with Trend's Sysclean you get BKDR_SDBOT.M virus on the machine.<br><br>After we remove the registry entries and delete the .EXEs from windows\system32 it seems to cure them. They have to have the patches though or they get reinfected.<br><br>NONE of the anti-virus companies have anything about this. I've submitted soundtasks.exe and soundtctrls.exe to Trend yesterday. Nothing yet, even scanning with their latest 886 pattern.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10160019</guid>
<pubDate>Wed, 05 May 2004 14:24:20 EDT</pubDate>
</item>

<item>
<title>Re: Hijack Log and w32.Gaobot!inf virus</title>
<link>http://www.dslreports.com/forum/remark,10159892</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : We have had all of our Windows 2000 PCs in our office infected with soundtasks.exe which appears to be very similar to the w32.sasser worm<br><br>The only things I could tell it was doing was 1) sending out a large amount of network traffic (trying to infect other computers) 2) modifying the c:\winnt\system32\drivers\etc\hosts file (adding a bunch of anti-virus web sites with loop-back IP to prevent reaching them) and 3) making multiple copies of itself to the root of c:\ drive with random characters as its name (with a .exe extension) all 142 kb in size.<br><br>I killed the process, removed the file (c:\winnt\system32\soundtasks.exe), and removed it from the registry (hkey_local_machine\software\microsoft\windows\currentversion\run\soundtasks) and all of the excessive network traffic seems to have stopped.<br><br>It spreads through the same vulnerability as the w32.sasser worm exploits (I've noticed that once we've patched our PCs with that fix they are not getting re-infected).]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10159892</guid>
<pubDate>Wed, 05 May 2004 14:08:28 EDT</pubDate>
</item>

<item>
<title>Re: Hijack Log and w32.Gaobot!inf virus</title>
<link>http://www.dslreports.com/forum/remark,10157900</link>
<description><![CDATA[<A HREF="/useremail/u/1001846"><b>ccullins</b></A> : You need to take the system off the network and go to your HKLM, software, microsoft, windows, currentversion, run look far an entry 10base-t and delete it, and do the same for runservices. This gets rid of the virus but I have a couple of machinces I have do this to but I have gotten it back once or twice. Still looking for the fix ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10157900</guid>
<pubDate>Wed, 05 May 2004 09:26:49 EDT</pubDate>
</item>

<item>
<title>Re: Hijack Log and w32.Gaobot!inf virus</title>
<link>http://www.dslreports.com/forum/remark,10141879</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> : I think your answer is in this post.<br><br>&raquo;<A HREF="/forum/remark,10126533~mode=flat?hilite=hosts">Re: Comp is under serious attack - HijackThisLog</A><br><SMALL>--<br>Better to remain silent and be thought a fool, than to speak and remove all doubt.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10141879</guid>
<pubDate>Mon, 03 May 2004 17:44:41 EDT</pubDate>
</item>

<item>
<title>Re: Hijack Log and w32.Gaobot!inf virus</title>
<link>http://www.dslreports.com/forum/remark,10141855</link>
<description><![CDATA[<A HREF="/useremail/u/1000831"><b>paddy_cass</b></A> : In relation to the file Msrv32.exe, have scanned system and cannot find this file, have deleted and check regedit but no sign of this file.  <br><br>However i have am still getting virus alert for W32gaobot!inf.  <br><br>Hosts file is the one infected.  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10141855</guid>
<pubDate>Mon, 03 May 2004 17:40:55 EDT</pubDate>
</item>

<item>
<title>Re: Hijack Log and w32.Gaobot!inf virus</title>
<link>http://www.dslreports.com/forum/remark,10141490</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> : When you have got rid of the viruses, have HJT fix these.<br><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = »uk.red.clientapps.yahoo.com/customize/.">uk.docs.yahoo.com/info/bt_side.html">u...<br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = »uk.red.clientapps.yahoo.com/customize/.">uk.search.yahoo.com/">uk.red.clientapp...<br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = »uk.red.clientapps.yahoo.com/customize/.">uk.search.yahoo.com/">uk.red.clientapp...<br>O3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file)<br>O4 - HKLM\..\Run: [Msrv32] Msrv32.exe<br>O4 - HKLM\..\Run: [avserve2.exe] C:\WINDOWS\avserve2.exe<br>O4 - HKLM\..\RunServices: [Msrv32] Msrv32.exe<br><SMALL>--<br>Better to remain silent and be thought a fool, than to speak and remove all doubt.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10141490</guid>
<pubDate>Mon, 03 May 2004 16:55:57 EDT</pubDate>
</item>

<item>
<title>Re: Hijack Log and w32.Gaobot!inf virus</title>
<link>http://www.dslreports.com/forum/remark,10141401</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> : avserve2.exe is the sasser worm<br><br>sasser removal tools can be found here<br><br>&raquo;<A HREF="http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.removal.tool.html" >securityresponse.symantec.com/av&middot;&middot;&middot;ool.html</A><br><br>Or in all in one removal tool from MS<br><br>&raquo;<A HREF="http://support.microsoft.com/?kbid=841720" >support.microsoft.com/?kbid=841720</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10141401</guid>
<pubDate>Mon, 03 May 2004 16:46:39 EDT</pubDate>
</item>

<item>
<title>Re: Hijack Log and w32.Gaobot!inf virus</title>
<link>http://www.dslreports.com/forum/remark,10141374</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> : This will help you remove the phatbot worm<br><br>&raquo;<A HREF="http://www.nacs.uci.edu/security/phatbot.html" >www.nacs.uci.edu/security/phatbot.html</A><br><SMALL>--<br>Better to remain silent and be thought a fool, than to speak and remove all doubt.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10141374</guid>
<pubDate>Mon, 03 May 2004 16:43:59 EDT</pubDate>
</item>

<item>
<title>Re: Hijack Log and w32.Gaobot!inf virus</title>
<link>http://www.dslreports.com/forum/remark,10141361</link>
<description><![CDATA[<A HREF="/useremail/u/936080"><b>darkstar2778</b></A> : You're in good hands now  paddy_cass <A HREF="/useremail/u/1000831"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>....hang tight as I would imagine  John2g <A HREF="/useremail/u/448758"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> is looking around to help you now.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10141361</guid>
<pubDate>Mon, 03 May 2004 16:42:53 EDT</pubDate>
</item>

<item>
<title>Re: Hijack Log and w32.Gaobot!inf virus</title>
<link>http://www.dslreports.com/forum/remark,10141348</link>
<description><![CDATA[<A HREF="/useremail/u/1000831"><b>paddy_cass</b></A> : Have no idea, MSRV.exe is a w32.Gaobot virus.  When i get rid of the current virus by simply deleting the file its associated with it reappears again.<br><br>This is actually the very first hijack log i have ever run.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10141348</guid>
<pubDate>Mon, 03 May 2004 16:41:51 EDT</pubDate>
</item>

<item>
<title>Re: Hijack Log and w32.Gaobot!inf virus</title>
<link>http://www.dslreports.com/forum/remark,10141320</link>
<description><![CDATA[<A HREF="/useremail/u/1000831"><b>paddy_cass</b></A> : yeah, i have 4, does anyone know how to get rid of the virus]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10141320</guid>
<pubDate>Mon, 03 May 2004 16:39:00 EDT</pubDate>
</item>

<item>
<title>Re: Hijack Log and w32.Gaobot!inf virus</title>
<link>http://www.dslreports.com/forum/remark,10141318</link>
<description><![CDATA[<A HREF="/useremail/u/936080"><b>darkstar2778</b></A> : Wait for an expert to come along and help you out (please don't do anything with Hijack This until an expert comments).  This looks off to me:<br><br>O4 - HKLM\..\Run: [Msrv32] Msrv32.exe<br>O4 - HKLM\..\Run: [avserve2.exe] C:\WINDOWS\avserve2.exe<br>O4 - HKLM\..\RunServices: [Msrv32] Msrv32.exe<br><br>I see some things you can fix but will let someone with more experience post.  Do you know what this is:<br><br>O4 - HKLM\..\RunServices: [soundtasks] soundtasks.exe<br><br>EDIT: Please move Hijack This to it own permanent folder (i.e. C:\Hijack This\hijackthis.exe).  This will allow it to make back-ups of any changes you make.  This is important in the event you need to restore items you chose to fix with Hijack This.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10141318</guid>
<pubDate>Mon, 03 May 2004 16:38:53 EDT</pubDate>
</item>

<item>
<title>Re: Hijack Log and w32.Gaobot!inf virus</title>
<link>http://www.dslreports.com/forum/remark,10141305</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> :  <BLOCKQUOTE><SMALL>said by  paddy_cass <A HREF="/useremail/u/1000831"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>Can i also add that the file svchost.exe is continuously running in the background.  Not sure if this is a prob or not but when i attempt to close it it restarts the comnputer.  An RPC violation.<br> <HR></BLOCKQUOTE><br><br>You should have about 4 svchost.exes running.<br><SMALL>--<br>Better to remain silent and be thought a fool, than to speak and remove all doubt.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10141305</guid>
<pubDate>Mon, 03 May 2004 16:37:37 EDT</pubDate>
</item>

<item>
<title>Re: Hijack Log and w32.Gaobot!inf virus</title>
<link>http://www.dslreports.com/forum/remark,10141202</link>
<description><![CDATA[<A HREF="/useremail/u/1000831"><b>paddy_cass</b></A> : Can i also add that the file svchost.exe is continuously running in the background.  Not sure if this is a prob or not but when i attempt to close it it restarts the comnputer.  An RPC violation.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10141202</guid>
<pubDate>Mon, 03 May 2004 16:27:31 EDT</pubDate>
</item>

<item>
<title>Hijack Log and w32.Gaobot!inf virus</title>
<link>http://www.dslreports.com/forum/remark,10141165</link>
<description><![CDATA[<A HREF="/useremail/u/1000831"><b>paddy_cass</b></A> : Need help, yesterday I had the sasser virus. managed to get rid of this after 6 hours.  Scanned using Stinger.<br><br>Got up today put on the computer and viola i have the w32.Gaobot!inf virus.  Can seem to get rid of this.  Symantec programs seem to crash while they are scanning for it.  <br><br>Have run the following hijack log, can u pls check and see if there is anything i should remove:<br><br>Logfile of HijackThis v1.97.7<br>Scan saved at 17:48:35, on 03/05/2004<br>Platform: Windows XP SP1 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\System32\Ati2evxx.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\System32\drivers\CDAC11BA.EXE<br>C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>C:\WINDOWS\system32\pctspk.exe<br>C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe<br>C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>C:\WINDOWS\system32\Ati2evxx.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\windows\system\hpsysdrv.exe<br>C:\HP\KBD\KBD.EXE<br>C:\WINDOWS\system32\dla\tfswctrl.exe<br>C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br>C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe<br>C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br>C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br>C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe<br>C:\Program Files\QuickTime\qttask.exe<br>C:\WINDOWS\System32\soundtasks.exe<br>C:\Program Files\hp center\137903\Program\BackWeb-137903.exe<br>C:\Program Files\BTopenworld NetHelp\bin\mpbtn.exe<br>C:\WINDOWS\system32\ZoneLabs\vsmon.exe<br>C:\Program Files\Norton AntiVirus\navapsvc.exe<br>C:\Program Files\Messenger\msmsgs.exe<br>C:\PROGRA~1\Yahoo!\browser\ycommon.exe<br>C:\Program Files\Yahoo!\browser\ybrwicon.exe<br>C:\Documents and Settings\Owner\Desktop\stinger.exe<br>C:\Program Files\Yahoo!\browser\ybrowser.exe<br>C:\Documents and Settings\Owner\Desktop\HijackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://www.yahoo.com/search/ie.html" >www.yahoo.com/search/ie.html</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://www.yahoo.com" >www.yahoo.com</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://bt.yahoo.com" >bt.yahoo.com</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html" >uk.red.clientapps.yahoo.com/cust&middot;&middot;&middot;ide.html</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sp/*http://uk.search.yahoo.com/" >uk.red.clientapps.yahoo.com/cust&middot;&middot;&middot;hoo.com/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/" >uk.red.clientapps.yahoo.com/cust&middot;&middot;&middot;hoo.com/</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BT Yahoo! Broadband<br>R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = &raquo;<A HREF="http://search.yahoo.com/search?p=%s" >search.yahoo.com/search?p=%s</A><br>O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\common\ycomp5_2_3_0.dll<br>O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx<br>O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll<br>O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll<br>O3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file)<br>O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll<br>O3 - Toolbar: BT Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\common\ycomp5_2_3_0.dll<br>O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx<br>O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe<br>O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE<br>O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE<br>O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe<br>O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe<br>O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe<br>O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe<br>O4 - HKLM\..\Run: [CountrySelection] pctptt.exe<br>O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot<br>O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br>O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [AceGain LiveUpdate] C:\Program Files\AceGain\LiveUpdate\LiveUpdate.exe<br>O4 - HKLM\..\Run: [Msrv32] Msrv32.exe<br>O4 - HKLM\..\Run: [avserve2.exe] C:\WINDOWS\avserve2.exe<br>O4 - HKLM\..\Run: [soundtasks] soundtasks.exe<br>O4 - HKLM\..\RunServices: [Msrv32] Msrv32.exe<br>O4 - HKLM\..\RunServices: [soundtasks] soundtasks.exe<br>O4 - HKCU\..\Run: [Steam] "c:\valve\steam\steam.exe" -silent<br>O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe<br>O4 - Startup: PowerReg Scheduler.exe<br>O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br>O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe<br>O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br>O4 - Global Startup: NetHelp.lnk = C:\Program Files\BTopenworld NetHelp\bin\matcli.exe<br>O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm<br>O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000<br>O9 - Extra button: BT Yahoo! Sidebar (HKLM)<br>O9 - Extra 'Tools' menuitem: BT &Yahoo! Sidebar (HKLM)<br>O9 - Extra button: Money Viewer (HKLM)<br>O9 - Extra button: Messenger (HKLM)<br>O9 - Extra 'Tools' menuitem: Messenger (HKLM)<br>O9 - Extra button: Homepage (HKCU)<br>O9 - Extra button: BT (HKCU)<br>O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dll<br>O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll<br>O16 - DPF: Yahoo! Chat - &raquo;<A HREF="http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab" >us.chat1.yimg.com/us.yimg.com/i/&middot;&middot;&middot;chat.cab</A><br>O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/msgrchkr.cab" >messenger.zone.msn.com/binary/msgrchkr.cab</A><br>O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - &raquo;<A HREF="http://www.apple.com/qtactivex/qtplugin.cab" >www.apple.com/qtactivex/qtplugin.cab</A><br>O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - &raquo;<A HREF="http://dev-www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_41.cab" >dev-www.fileplanet.com/fpdlmgr/c&middot;&middot;&middot;0_41.cab</A><br>O16 - DPF: {65E7DB1D-0101-4100-BD66-C5C78C917F93} (WTDMMPVersion Class) - &raquo;<A HREF="http://www.wildtangent.com/multiplayer/cannonsmmp/wtinst.cab" >www.wildtangent.com/multiplayer/&middot;&middot;&middot;inst.cab</A><br>O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - &raquo;<A HREF="http://launch.gamespyarcade.com/software/launch/alaunch.cab" >launch.gamespyarcade.com/softwar&middot;&middot;&middot;unch.cab</A><br>O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/MessengerStatsClient.cab" >messenger.zone.msn.com/binary/Me&middot;&middot;&middot;ient.cab</A><br>O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - &raquo;<A HREF="http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38033.1795717593" >v4.windowsupdate.microsoft.com/C&middot;&middot;&middot;95717593</A><br>O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - &raquo;<A HREF="http://download.yahoo.com/dl/installs/ymail/ymmapi.dll" >download.yahoo.com/dl/installs/y&middot;&middot;&middot;mapi.dll</A><br>O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} - &raquo;<A HREF="http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab" >photos.yahoo.com/ocx/us/yexplorer1_9us.cab</A><br>O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &raquo;<A HREF="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab" >download.macromedia.com/pub/shoc&middot;&middot;&middot;lash.cab</A><br>O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - &raquo;<A HREF="http://www.gamespot.com/KDX/kdx.cab" >www.gamespot.com/KDX/kdx.cab</A><br>O17 - HKLM\System\CCS\Services\Tcpip\..\{1436D38F-83E0-4D33-AFA2-2BBA2B3FCBEF}: NameServer = 194.74.65.69 194.72.9.38<br><br>Also this from CWShredder:<br><br>Found Hosts file: C:\WINDOWS\system32\drivers\etc\hosts (1112 bytes, A)<br>Shell Registry value: HKLM\..\WinLogon [Shell] Explorer.exe<br>UserInit Registry value: HKLM\..\WinLogon [UserInit] C:\WINDOWS\system32\userinit.exe,<br>Registry value: DefaultPrefix (should be &raquo;<A HREF="http://" ></A>) [] &raquo;<A HREF="http://" ></A><br>Registry value: WWW Prefix (should be &raquo;<A HREF="http://" ></A>) [www] &raquo;<A HREF="http://" ></A><br>Registry value: Mosaic Prefix (should be &raquo;<A HREF="http://" ></A>) [mosaic] &raquo;<A HREF="http://" ></A><br>Registry value: Home Prefix (should be &raquo;<A HREF="http://" ></A>) [home] &raquo;<A HREF="http://" ></A><br>Found Win.ini file: C:\WINDOWS\win.ini (718 bytes, A)<br>Found System.ini file: C:\WINDOWS\system.ini (274 bytes, A)<br><br>Any help with the virus and these logs would be greatly appreciated.  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10141165</guid>
<pubDate>Mon, 03 May 2004 16:23:32 EDT</pubDate>
</item>

</channel>
</rss>
