<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: HJT Log..... Downloader.Trojan in Security</title>
<link>http://www.dslreports.com/forum/r10769610</link>
<description></description>
<language>en</language>
<pubDate>Tue, 08 Dec 2009 21:29:37 EDT</pubDate>
<lastBuildDate>Tue, 08 Dec 2009 21:29:37 EDT</lastBuildDate>

<item>
<title>Re: HJT Log..... Downloader.Trojan</title>
<link>http://www.dslreports.com/forum/remark,10777268</link>
<description><![CDATA[<A HREF="/useremail/u/836534"><b>assquesme</b></A> : Thanks Jane :D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10777268</guid>
<pubDate>Wed, 14 Jul 2004 19:45:22 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log..... Downloader.Trojan</title>
<link>http://www.dslreports.com/forum/remark,10773209</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Your downloader trojan may have been Gator which is one of the entries below (or a leftover component of it since the other cleaners probably got most of it).<br><br>Scan with only HijackThis open (keep IE closed) and checkmark these items, then press *fix checked*<br><br>O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe" <br><br>O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - »207.188.7.150/173dc026488c18d29402/net..<br><br><B>Reboot</B> your PC and delete this entire folder (if found)<br><br>C:\Program Files\Common Files\<B>CMEII</B> (This is Gator)<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR><A HREF="http://forum.gladiator-antivirus.com">Gladiator Security Forum</A><BR>Proud Member of ASAP (Alliance of Security Analysis Professionals) &raquo;<A HREF="http://www.a-sap.org/" >www.a-sap.org/</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10773209</guid>
<pubDate>Wed, 14 Jul 2004 12:35:32 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log..... Downloader.Trojan</title>
<link>http://www.dslreports.com/forum/remark,10769663</link>
<description><![CDATA[<A HREF="/useremail/u/731068"><b>Sparrow</b></A> : <STRIKE>I am just curious if you have two iexplore.exe files in your C drive in C:\Program Files\Internet Explorer\iexplore.exe. (Right click Start > Explore > Local Disk [C:] > Program Files > Internet Explorer.) <br><br>Are both files the same size? Same versions? Same install date? Nothing else appears to be amiss. I don't ever recall seeing two instances of IE in the Program Files, but it is probably nothing.</STRIKE><br><br>Edit: A dear friend just refreshed my tired ole mind, that you just have two windows open, thus the two IExplore.exe running. On a better day, I would have caught that! :)<br><br>You're okay - I'm not tonight. Sorry for any confusion.<br><SMALL>--<br><A HREF="/faq/security">Security Forum FAQs</A> ..&hearts;.. <A HREF="/faq/10623"> AV Complaints?</A> ..&hearts;.. <A HREF="http://tinyurl.com/2ahyy">Raj karega Khalsa!</A> ..&hearts;.. <A HREF="/forum/seti">Starfire "5 in 4"</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10769663</guid>
<pubDate>Tue, 13 Jul 2004 23:52:35 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log..... Downloader.Trojan</title>
<link>http://www.dslreports.com/forum/remark,10769610</link>
<description><![CDATA[<A HREF="/useremail/u/836534"><b>assquesme</b></A> : Could this be an internal problem with my pc?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10769610</guid>
<pubDate>Tue, 13 Jul 2004 23:43:55 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log..... Downloader.Trojan</title>
<link>http://www.dslreports.com/forum/remark,10769575</link>
<description><![CDATA[<A HREF="/useremail/u/836534"><b>assquesme</b></A> : It was Norton AV . Here is what the disk looks like<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/10769575?c=630135&ret=L2ZvcnVtL3IxMDc2OTYxMC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="36640 bytes" WIDTH=600 HEIGHT=450 SRC="/r0/download/630135.thumb600~f5cdc465d97db8b3c05a1733c3c5146f/mypc.bmp/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10769575</guid>
<pubDate>Tue, 13 Jul 2004 23:39:22 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log..... Downloader.Trojan</title>
<link>http://www.dslreports.com/forum/remark,10769524</link>
<description><![CDATA[<A HREF="/useremail/u/731068"><b>Sparrow</b></A> : Hi  assquesme <A HREF="/useremail/u/836534"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>,<br><br>Which scan picked up the Downloader.Trojan? Was it Spybot? Your log looks clean, but someone else may see something that I don't. <br><br>I'm not sure if it matters, but check in <U>C:\Program Files\Internet Explorer\iexplore.exe</U>. I'm not quite sure why you have two iexplore.exe files. <br><SMALL>--<br><A HREF="/faq/security">Security Forum FAQs</A> ..&hearts;.. <A HREF="/faq/10623"> AV Complaints?</A> ..&hearts;.. <A HREF="http://tinyurl.com/2ahyy">Raj karega Khalsa!</A> ..&hearts;.. <A HREF="/forum/seti">Starfire "5 in 4"</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10769524</guid>
<pubDate>Tue, 13 Jul 2004 23:33:33 EDT</pubDate>
</item>

<item>
<title>HJT Log..... Downloader.Trojan</title>
<link>http://www.dslreports.com/forum/remark,10769357</link>
<description><![CDATA[<A HREF="/useremail/u/836534"><b>assquesme</b></A> : Ok...My problem is I have a teen age son.Anyway I seen to have lost one of my local disk.<br><br>     I ran NAV 04 updated,Trojan hunter updated,Ad-Aware updated. I also scaned with McAfee and F-Secure which this site provided links to.Then I dl and updated CWShredder & Spybot S&D. Nothing but some cookies files were infected<br><br>Logfile of HijackThis v1.98.0<br>Scan saved at 11:05:26 PM, on 7/13/2004<br>Platform: Windows XP  (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 (6.00.2600.0000)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\System32\Ati2evxx.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\system32\Ati2evxx.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\SOUNDMAN.EXE<br>C:\Program Files\DIGStream\digstream.exe<br>C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br>C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>C:\Program Files\Norton AntiVirus\navapsvc.exe<br>C:\Program Files\Norton AntiVirus\SAVScan.exe<br>C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe<br>C:\WINDOWS\system32\ZoneLabs\vsmon.exe<br>C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Messenger\msmsgs.exe<br>C:\Program Files\hijackthis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://msn.com/" >msn.com/</A><br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx<br>O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll<br>O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll<br>O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx<br>O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize<br>O4 - HKLM\..\Run: [MCUpdateExe] C:\Program Files\McAfee.com\Agent\mcupdate.exe /embedding<br>O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe<br>O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe"<br>O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl<br>O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML<br>O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe<br>O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm<br>O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm<br>O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)<br>O16 - DPF: Tri-Peaks by pogo - &raquo;<A HREF="http://peaks.pogo.com/applet/peaks/peaks-ob-assets.cab" >peaks.pogo.com/applet/peaks/peak&middot;&middot;&middot;sets.cab</A><br>O16 - DPF: Yahoo! Gin - &raquo;<A HREF="http://download.games.yahoo.com/games/clients/y/nt1_x.cab" >download.games.yahoo.com/games/c&middot;&middot;&middot;t1_x.cab</A><br>O16 - DPF: Yahoo! NFL GameChannel StatTracker - &raquo;<A HREF="http://aud4.sports.sc5.yahoo.com/java/y/nflgcst1010_x.cab" >aud4.sports.sc5.yahoo.com/java/y&middot;&middot;&middot;10_x.cab</A><br>O16 - DPF: Yahoo! Pool 2 - &raquo;<A HREF="http://download.games.yahoo.com/games/clients/y/potc_x.cab" >download.games.yahoo.com/games/c&middot;&middot;&middot;tc_x.cab</A><br>O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - &raquo;<A HREF="http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe" >a1540.g.akamai.net/7/1540/52/200&middot;&middot;&middot;ller.exe</A><br>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,9/mcinsctl.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;sctl.cab</A><br>O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - &raquo;<A HREF="http://207.188.7.150/173dc026488c18d29402/netzip/RdxIE601.cab" >207.188.7.150/173dc026488c18d294&middot;&middot;&middot;E601.cab</A><br>O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - &raquo;<small>https</small>://<A HREF="https://www.gamespyid.com/alaunch.cab">www.gamespyid.com/alaunch.cab</A><br>O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - &raquo;<A HREF="http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab" >a840.g.akamai.net/7/840/537/2004&middot;&middot;&middot;an53.cab</A><br>O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - &raquo;<A HREF="http://www.nick.com/common/groove/gx/GrooveAX25.cab" >www.nick.com/common/groove/gx/GrooveAX25.cab</A><br>O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - &raquo;<A HREF="http://support.f-secure.com/ols/fscax.cab" >support.f-secure.com/ols/fscax.cab</A><br>O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - &raquo;<A HREF="http://www.pandasoftware.com/activescan/as5/asinst.cab" >www.pandasoftware.com/activescan&middot;&middot;&middot;inst.cab</A><br>O16 - DPF: {A1B09066-C95C-4EF6-8DFD-3DD0AFE610B6} (AOL YGP Screensaver) - &raquo;<A HREF="http://pak02.pictures.aol.com/ygp/aol/plugin/screensaver/YGPPicScreensaver.1.0.2.5.cab" >pak02.pictures.aol.com/ygp/aol/p&middot;&middot;&middot;.2.5.cab</A><br>O16 - DPF: {BB47CA33-8B4D-11D0-9511-00C04FD9152D} (ExteriorSurround Object) - &raquo;<A HREF="http://autos.msn.com/components/ocx/exterior/Outside.cab" >autos.msn.com/components/ocx/ext&middot;&middot;&middot;side.cab</A><br>O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - &raquo;<A HREF="http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4372/mcfscan.cab" >download.mcafee.com/molbin/iss-l&middot;&middot;&middot;scan.cab</A><br>O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - &raquo;<A HREF="http://www.gamespot.com/KDX22/download/kdx.cab" >www.gamespot.com/KDX22/download/kdx.cab</A><br><br>Thanks for the help in advance:D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10769357</guid>
<pubDate>Tue, 13 Jul 2004 23:12:46 EDT</pubDate>
</item>

</channel>
</rss>
