<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>hijack this log computer 2 in Security</title>
<link>http://www.dslreports.com/forum/r10291149</link>
<description></description>
<language>en</language>
<pubDate>Wed, 09 Dec 2009 05:00:59 EDT</pubDate>
<lastBuildDate>Wed, 09 Dec 2009 05:00:59 EDT</lastBuildDate>

<item>
<title>Re: hijack this log computer 2</title>
<link>http://www.dslreports.com/forum/remark,10292814</link>
<description><![CDATA[<A HREF="/useremail/u/1002718"><b>owood1</b></A> : Thanks John2g. <br>Don't know where the MyWay came from. Did want to get rid of it. There was an entry for MyWay that I removed. None for a MyWay Bar nor could I find anything for the fun web products easy installer.<br><br>Ran SpyBot S&D, Ad-Aware and Spy Ferret with latest updates<br>earler this am. Just ran them again. Both times no problems found.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10292814</guid>
<pubDate>Thu, 20 May 2004 18:03:45 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log computer 2</title>
<link>http://www.dslreports.com/forum/remark,10292200</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> : I would then download Ad-aware or SpyBot S&D, <B>update</B> and then run.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10292200</guid>
<pubDate>Thu, 20 May 2004 16:54:27 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log computer 2</title>
<link>http://www.dslreports.com/forum/remark,10292176</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> : You have Mywebsearch<br><br>Removal<br>Open 'Add/Remove Programs' in the Control Panel. Select the 'My Search Bar' (MySearch variant), 'MyWay Speed Bar' (MyWay) or 'My Web Search Bar' (MyWeb) entry and click 'Remove'. For the MyWeb variant, be sure to also remove 'Fun Web Products Easy Installer'. <br><br>You can then reset your home page (Internet Options->General->Start Page) if it has been changed, and search settings (Internet Options->Programs->Reset web settings). <br><SMALL>--<br>Better to remain silent and be thought a fool, than to speak and remove all doubt.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10292176</guid>
<pubDate>Thu, 20 May 2004 16:52:25 EDT</pubDate>
</item>

<item>
<title>hijack this log computer 2</title>
<link>http://www.dslreports.com/forum/remark,10291149</link>
<description><![CDATA[<A HREF="/useremail/u/1002718"><b>owood1</b></A> : I am following the steps in the 'I think my computer is infected or hijacked FAQ<br><br>Logfile of HijackThis v1.97.7<br>Scan saved at 12:42:00 PM, on 5/20/2004<br>Platform: Windows XP SP1 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)<br><br>Running processes:<br>F:\WINDOWS\System32\smss.exe<br>F:\WINDOWS\system32\winlogon.exe<br>F:\WINDOWS\system32\services.exe<br>F:\WINDOWS\system32\lsass.exe<br>F:\WINDOWS\system32\svchost.exe<br>F:\WINDOWS\System32\svchost.exe<br>F:\WINDOWS\Explorer.EXE<br>F:\WINDOWS\system32\spoolsv.exe<br>F:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>F:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE<br>F:\Program Files\Common Files\Symantec Shared\ccApp.exe<br>F:\Program Files\ScanSoft\OmniPagePro12.0\Opware12.exe<br>F:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe<br>F:\QUICKENW\QWDLLS.EXE<br>F:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe<br>F:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE<br>F:\WINDOWS\System32\nvsvc32.exe<br>F:\WINDOWS\System32\ofps.exe<br>F:\WINDOWS\System32\svchost.exe<br>F:\WINDOWS\System32\Tablet.exe<br>F:\WINDOWS\system32\ZONELABS\vsmon.exe<br>\Ziggy\F\Media\HijackThis.exe<br><br>O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - F:\Program Files\MyWebSearch\SearchAt\1.bin\MWSSRCAS.DLL<br>O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx<br>O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - f:\windows\googletoolbar1.dll<br>O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - F:\Program Files\Norton AntiVirus\NavShExt.dll<br>O2 - BHO: Guard-IE - {D2F719F3-106A-402B-9996-3A5B12ACA564} - F:\Program Files\Failsafe\GuardIE\PnIE.dll<br>O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - F:\WINDOWS\System32\msdxm.ocx<br>O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - F:\Program Files\Norton AntiVirus\NavShExt.dll<br>O3 - Toolbar: Guard-IE - {37C8204D-97C3-4127-BB28-1BFF3FA2F7DA} - F:\Program Files\Failsafe\GuardIE\PnIE.dll<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - f:\windows\googletoolbar1.dll<br>O4 - HKLM\..\Run: [HPDJ Taskbar Utility] F:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe<br>O4 - HKLM\..\Run: [EM_EXEC] F:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE<br>O4 - HKLM\..\Run: [UpdReg] F:\WINDOWS\UpdReg.EXE<br>O4 - HKLM\..\Run: [Jet Detection] "F:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"<br>O4 - HKLM\..\Run: [CloneCDElbyCDFL] "F:\Program Files\CloneCD\ElbyCheck.exe" /L ElbyCDFL<br>O4 - HKLM\..\Run: [ccApp] "F:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [ccRegVfy] "F:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\System32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [NeroCheck] F:\WINDOWS\system32\NeroCheck.exe<br>O4 - HKLM\..\Run: [Opware12] "F:\Program Files\ScanSoft\OmniPagePro12.0\Opware12.exe"<br>O4 - HKLM\..\Run: [myNetWatchman] F:\Program Files\myNetWatchman\NWClient.exe<br>O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br>O4 - HKCU\..\Run: [MsnMsgr] "F:\Program Files\MSN Messenger\MsnMsgr.Exe" /background<br>O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Microsoft Office\Office10\OSA.EXE<br>O4 - Global Startup: Acrobat Assistant.lnk = F:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe<br>O4 - Global Startup: Quicken Startup.lnk = F:\QUICKENW\QWDLLS.EXE<br>O4 - Global Startup: Billminder.lnk = F:\QUICKENW\BILLMIND.EXE<br>O4 - Global Startup: ZoneAlarm.lnk = F:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe<br>O4 - Global Startup: Adobe Gamma Loader.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br>O8 - Extra context menu item: &Google Search - res://f:\windows\GoogleToolbar1.dll/cmsearch.html<br>O8 - Extra context menu item: Backward &Links - res://f:\windows\GoogleToolbar1.dll/cmbacklinks.html<br>O8 - Extra context menu item: Cac&hed Snapshot of Page - res://f:\windows\GoogleToolbar1.dll/cmcache.html<br>O8 - Extra context menu item: Si&milar Pages - res://f:\windows\GoogleToolbar1.dll/cmsimilar.html<br>O8 - Extra context menu item: Translate into English - res://f:\windows\GoogleToolbar1.dll/cmtrans.html<br>O9 - Extra button: Messenger (HKLM)<br>O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)<br>O9 - Extra button: @F:\Program Files\Failsafe\GuardIE\PnIE.dll,-100 (HKLM)<br>O9 - Extra 'Tools' menuitem: @F:\Program Files\Failsafe\GuardIE\PnIE.dll,-100 (HKLM)<br>O12 - Plugin for .spop: F:\Program Files\Internet Explorer\Plugins\NPDocBox.dll<br>O16 - DPF: Yahoo! Pool 2 - &raquo;<A HREF="http://download.games.yahoo.com/games/clients/y/potc_x.cab" >download.games.yahoo.com/games/c&middot;&middot;&middot;tc_x.cab</A><br>O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - &raquo;<A HREF="http://download.macromedia.com/pub/shockwave/cabs/director/swdir.cab" >download.macromedia.com/pub/shoc&middot;&middot;&middot;wdir.cab</A><br>O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - &raquo;<A HREF="http://ak.imgfarm.com/images/nocache/funwebproducts/CursorManiaInitialSetup1.0.0.6.cab" >ak.imgfarm.com/images/nocache/fu&middot;&middot;&middot;.0.6.cab</A><br>O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - &raquo;<A HREF="http://download.yahoo.com/dl/installs/yinst0309.cab" >download.yahoo.com/dl/installs/yinst0309.cab</A><br>O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - &raquo;<A HREF="http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB" >download.microsoft.com/download/&middot;&middot;&middot;9VCM.CAB</A><br>O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - &raquo;<A HREF="http://216.249.24.142/code/PWActiveXImgCtl.CAB" >216.249.24.142/code/PWActiveXImgCtl.CAB</A><br>O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - &raquo;<A HREF="http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37883.5678587963" >v4.windowsupdate.microsoft.com/C&middot;&middot;&middot;78587963</A><br>O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &raquo;<A HREF="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab" >download.macromedia.com/pub/shoc&middot;&middot;&middot;lash.cab</A><br>O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office Tools on the Web Control) - &raquo;<A HREF="http://officeupdate.microsoft.com/TemplateGallery/downloads/outc.cab" >officeupdate.microsoft.com/Templ&middot;&middot;&middot;outc.cab</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10291149</guid>
<pubDate>Thu, 20 May 2004 14:58:01 EDT</pubDate>
</item>

</channel>
</rss>
