<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: Hijack-This Question in Security</title>
<link>http://www.dslreports.com/forum/r13081022</link>
<description></description>
<language>en</language>
<pubDate>Wed, 02 Dec 2009 11:49:19 EDT</pubDate>
<lastBuildDate>Wed, 02 Dec 2009 11:49:19 EDT</lastBuildDate>

<item>
<title>Re: Hijack-This Question</title>
<link>http://www.dslreports.com/forum/remark,13083355</link>
<description><![CDATA[<A HREF="/useremail/u/841643"><b>Phoenix__1</b></A> : <div class="bquote"><SMALL>said by  NetFixer <A HREF="/useremail/u/1030204"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>What you saw may be related to this post: <A HREF="/forum/remark,13022694">firefox localhost:loopback with Outpost firewall</A>.<br><BR><SMALL>--<BR><A HREF="http://www.nature-pics.com">We can never have enough of nature.</A><BR>We need to witness our own limits transgressed, and some life pasturing freely where we never wander.</SMALL><br> </DIV>Either way, it's gone.  I'm not worried about system cache.  In fact removing it would make things more secure, if I understand correctly.<br><SMALL>--<br>Want to know how to get a free mini mac? Send me a pm.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13083355</guid>
<pubDate>Mon, 04 Apr 2005 09:30:13 EDT</pubDate>
</item>

<item>
<title>Re: Hijack-This Question</title>
<link>http://www.dslreports.com/forum/remark,13083004</link>
<description><![CDATA[<A HREF="/useremail/u/1030204"><b>NetFixer</b></A> : What you saw may be related to this post: <A HREF="/forum/remark,13022694">firefox localhost:loopback with Outpost firewall</A>.<br><BR><SMALL>--<BR><A HREF="http://www.nature-pics.com">We can never have enough of nature.</A><BR>We need to witness our own limits transgressed, and some life pasturing freely where we never wander.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13083004</guid>
<pubDate>Mon, 04 Apr 2005 08:16:18 EDT</pubDate>
</item>

<item>
<title>Re: Hijack-This Question</title>
<link>http://www.dslreports.com/forum/remark,13081307</link>
<description><![CDATA[<A HREF="/useremail/u/841643"><b>Phoenix__1</b></A> : <div class="bquote"><SMALL>said by  Phoenix__1 <A HREF="/useremail/u/841643"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br><div class="bquote"><SMALL>said by  spooler0 <A HREF="/useremail/u/1110758"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>Take a look at IE>Tools>InternetOptions>Connections>LanSettings. See if you don't see it there.<br><br>Write down what you see so you can add it back if you delete it.<br><br>Mine in IE shows up in HJT logs when set to use the Local Proxy.  It does not show up when not using the local proxy with IE.<br><br>It doesn't show up either way in the HJT logs when using Mozilla.<br><br>If in doubt, have HJT "fix" it.  Let HJT save it as a backup.  If all runs fine without it, check you IE settings again to see if it is still there.  If a program you use no longer works without it, restore the backup from HJT.<br> </DIV>I thought about that, so I already did check and there was nothing checked or added in lan settings.  Think I'll remove it and then if things go wrong, restore it.<br><br>It's what I was thinking of doing, but didn't think it would hurt to ask and see if anyone else has seen this before.  I use Firefox, not IE.<br><br>edit:  Surprise!  The setting was in fact in Firefox.  I'm going to remove it and then see what happens.<br> </DIV>Deleted the setting out of Firefox & also using Hijackthis, then rebooted.  It didn't come back and everything is running fine. :)  Still going to probe my system to find how it got there though. :/<br><SMALL>--<br>Want to know how to get a free mini mac? Send me a pm.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13081307</guid>
<pubDate>Sun, 03 Apr 2005 23:02:49 EDT</pubDate>
</item>

<item>
<title>Re: Hijack-This Question</title>
<link>http://www.dslreports.com/forum/remark,13081229</link>
<description><![CDATA[<A HREF="/useremail/u/841643"><b>Phoenix__1</b></A> : <div class="bquote"><SMALL>said by  spooler0 <A HREF="/useremail/u/1110758"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>Take a look at IE>Tools>InternetOptions>Connections>LanSettings. See if you don't see it there.<br><br>Write down what you see so you can add it back if you delete it.<br><br>Mine in IE shows up in HJT logs when set to use the Local Proxy.  It does not show up when not using the local proxy with IE.<br><br>It doesn't show up either way in the HJT logs when using Mozilla.<br><br>If in doubt, have HJT "fix" it.  Let HJT save it as a backup.  If all runs fine without it, check you IE settings again to see if it is still there.  If a program you use no longer works without it, restore the backup from HJT.<br> </DIV>I thought about that, so I already did check and there was nothing checked or added in lan settings.  Think I'll remove it and then if things go wrong, restore it.<br><br>It's what I was thinking of doing, but didn't think it would hurt to ask and see if anyone else has seen this before.  I use Firefox, not IE.<br><br>edit:  Surprise!  The setting was in fact in Firefox.  I'm going to remove it and then see what happens.<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/13081229?c=802176&ret=L2ZvcnVtL3IxMzA4MTAyMi54bWw%3D"><IMG class="apic" BORDER=0 TITLE="121995 bytes" WIDTH=600 HEIGHT=450 SRC="/r0/download/802176.thumb600~bf238ed551b8814ec9060c853eb3fa22/proxy.JPG/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13081229</guid>
<pubDate>Sun, 03 Apr 2005 22:52:02 EDT</pubDate>
</item>

<item>
<title>Re: Hijack-This Question</title>
<link>http://www.dslreports.com/forum/remark,13081117</link>
<description><![CDATA[<A HREF="/useremail/u/1110758"><b>spooler0</b></A> : Take a look at IE>Tools>InternetOptions>Connections>LanSettings. See if you don't see it there.<br><br>Write down what you see so you can add it back if you delete it.<br><br>Mine in IE shows up in HJT logs when set to use the Local Proxy.  It does not show up when not using the local proxy with IE.<br><br>It doesn't show up either way in the HJT logs when using Mozilla.<br><br>If in doubt, have HJT "fix" it.  Let HJT save it as a backup.  If all runs fine without it, check you IE settings again to see if it is still there.  If a program you use no longer works without it, restore the backup from HJT.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13081117</guid>
<pubDate>Sun, 03 Apr 2005 22:37:28 EDT</pubDate>
</item>

<item>
<title>Re: Hijack-This Question</title>
<link>http://www.dslreports.com/forum/remark,13081022</link>
<description><![CDATA[<A HREF="/useremail/u/841643"><b>Phoenix__1</b></A> : I double checked and I "do not think" it is my host file.  I'm not sure what that reg line does or is.<br><SMALL>--<br>Want to know how to get a free mini mac? Send me a pm.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13081022</guid>
<pubDate>Sun, 03 Apr 2005 22:25:34 EDT</pubDate>
</item>

<item>
<title>Re: Hijack-This Question</title>
<link>http://www.dslreports.com/forum/remark,13080923</link>
<description><![CDATA[<A HREF="/useremail/u/841643"><b>Phoenix__1</b></A> : <div class="bquote"><SMALL>said by  spooler0 <A HREF="/useremail/u/1110758"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>Have you checked your host file for any added entries in it?<br><br>Do you use a hosts file?  or do any of the added programs on your HJT list use one?<br> </DIV>YES, I do use a host file.  Enclosed is a copy of my current host file and my old host file.  I was going to merge the two (after I weed out the double post).<br><SMALL>--<br>Want to know how to get a free mini mac? Send me a pm.</SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap WIDTH=33%><A HREF="/r0/download/802152~59e8ed39d00434d49b21a424a2ca06be/host.zip"><IMG  align=absmiddle TITLE="download" SRC="http://i.dslr.net/silk/compress.png" border=0 width=16 height=16><IMG SRC="http://i.dslr.net/1ptrans.gif" WIDTH=10 HEIGHT=1 border=0><big>host.zip</big></A> <small>60,045 bytes</small></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13080923</guid>
<pubDate>Sun, 03 Apr 2005 22:12:39 EDT</pubDate>
</item>

<item>
<title>Re: Hijack-This Question</title>
<link>http://www.dslreports.com/forum/remark,13080850</link>
<description><![CDATA[<A HREF="/useremail/u/1110758"><b>spooler0</b></A> : Have you checked your host file for any added entries in it?<br><br>Do you use a hosts file?  or do any of the added programs on your HJT list use one?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13080850</guid>
<pubDate>Sun, 03 Apr 2005 22:04:46 EDT</pubDate>
</item>

<item>
<title>Re: Hijack-This Question</title>
<link>http://www.dslreports.com/forum/remark,13080767</link>
<description><![CDATA[<A HREF="/useremail/u/841643"><b>Phoenix__1</b></A> : <div class="bquote"><SMALL>said by  spooler0 <A HREF="/useremail/u/1110758"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>how about unzipping your log file?  After that, would you paste the log into your post as text and repost the question?<br><br>Prior to doing so, would you complete ALL the steps in:<br><br>&raquo;<A HREF="/faq/security">Security</A> &raquo;<A HREF="/faq/8428">I think my computer is infected or hijacked. What should I do?</A><br> </DIV>I have done all those and found no problems... This was my only question.  Does anyone here know what that line is?  I did not feel like going through everything else, as I know the answer to everything else.<br><SMALL>--<br>Want to know how to get a free mini mac? Send me a pm.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13080767</guid>
<pubDate>Sun, 03 Apr 2005 21:55:53 EDT</pubDate>
</item>

<item>
<title>Re: Hijack-This Question</title>
<link>http://www.dslreports.com/forum/remark,13080553</link>
<description><![CDATA[<A HREF="/useremail/u/1174938"><b>SurfinGenie</b></A> : Here's your HJThis log unzipped:<br>Logfile of HijackThis v1.99.1<br>Scan saved at 09:18:33 PM, on 04/03/2005<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br><br>Running processes:<br>D:\WINDOWS\System32\smss.exe<br>D:\WINDOWS\system32\winlogon.exe<br>D:\WINDOWS\system32\services.exe<br>D:\WINDOWS\system32\lsass.exe<br>D:\WINDOWS\system32\Ati2evxx.exe<br>D:\WINDOWS\system32\svchost.exe<br>D:\WINDOWS\System32\svchost.exe<br>D:\WINDOWS\system32\spoolsv.exe<br>d:\PROGRA~1\mcafee.com\vso\mcvsrte.exe<br>D:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe<br>D:\WINDOWS\system32\svchost.exe<br>D:\WINDOWS\system32\Fast.exe<br>d:\PROGRA~1\mcafee.com\vso\mcshield.exe<br>D:\WINDOWS\system32\Ati2evxx.exe<br>D:\WINDOWS\Explorer.EXE<br>D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br>D:\Program Files\ATI Multimedia\main\ATIDtct.EXE<br>D:\WINDOWS\system32\taskswitch.exe<br>D:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe<br>D:\PROGRA~1\mcafee.com\agent\mcagent.exe<br>D:\PROGRA~1\mcafee.com\vso\mcvsshld.exe<br>D:\Program Files\Microsoft AntiSpyware\gcasServ.exe<br>D:\Program Files\Java\jre1.5.0_01\bin\jusched.exe<br>D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE<br>D:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe<br>D:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe<br>d:\progra~1\mcafee.com\vso\mcvsescn.exe<br>D:\Program Files\Verizon Online\bin\mpbtn.exe<br>D:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe<br>D:\WINDOWS\system32\rundll32.exe<br>D:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe<br>E:\Program Files\Hijack-This\HijackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://cgi.verizon.net/bookmarks/bmredir.asp?region=all&bw=dsl&cd=6.1&bm=ho_search" >cgi.verizon.net/bookmarks/bmredi&middot;&middot;&middot;o_search</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://cgi.verizon.net/bookmarks/bmredir.asp?region=all&bw=dsl&cd=6.1&bm=ho_home" >cgi.verizon.net/bookmarks/bmredi&middot;&middot;&middot;=ho_home</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://cgi.verizon.net/bookmarks/bmredir.asp?region=all&bw=dsl&cd=6.1&bm=ho_search" >cgi.verizon.net/bookmarks/bmredi&middot;&middot;&middot;o_search</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://cgi.verizon.net/bookmarks/bmredir.asp?region=all&bw=dsl&cd=6.1&bm=ho_home" >cgi.verizon.net/bookmarks/bmredi&middot;&middot;&middot;=ho_home</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online<br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1<br>O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - D:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll<br>O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - D:\Program Files\Ipswitch\WS_FTP Pro\wsbho2k0.dll<br>O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - D:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll<br>O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - d:\progra~1\mcafee.com\vso\mcvsshl.dll<br>O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - D:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll<br>O3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - D:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll<br>O4 - HKLM\..\Run: [ATIPTA] D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br>O4 - HKLM\..\Run: [ATI DeviceDetect] D:\Program Files\ATI Multimedia\main\ATIDtct.EXE<br>O4 - HKLM\..\Run: [BackgroundSwitcher] D:\WINDOWS\system32\bgswitch.exe<br>O4 - HKLM\..\Run: [CoolSwitch] D:\WINDOWS\system32\taskswitch.exe<br>O4 - HKLM\..\Run: [MPFExe] D:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe<br>O4 - HKLM\..\Run: [MCAgentExe] d:\PROGRA~1\mcafee.com\agent\mcagent.exe<br>O4 - HKLM\..\Run: [MCUpdateExe] D:\PROGRA~1\mcafee.com\agent\mcupdate.exe<br>O4 - HKLM\..\Run: [VSOCheckTask] "d:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask<br>O4 - HKLM\..\Run: [VirusScan Online] "d:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"<br>O4 - HKLM\..\Run: [gcasServ] "D:\Program Files\Microsoft AntiSpyware\gcasServ.exe"<br>O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\jre1.5.0_01\bin\jusched.exe<br>O4 - HKLM\..\Run: [EPSON Stylus CX4600 Series] D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE /P26 "EPSON Stylus CX4600 Series" /O6 "USB001" /M "Stylus CX4600"<br>O4 - HKLM\..\Run: [Motive SmartBridge] D:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe<br>O4 - HKCU\..\Run: [ATI Remote Control] D:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe<br>O4 - Global Startup: Verizon Online Support Center.lnk = D:\Program Files\Verizon Online\bin\matcli.exe<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &raquo;<A HREF="http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409" >go.microsoft.com/fwlink/?linkid=&middot;&middot;&middot;id=0x409</A><br>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;sctl.cab</A><br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1111937887028" >v5.windowsupdate.microsoft.com/v&middot;&middot;&middot;37887028</A><br>O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;dmgr.cab</A><br>O16 - DPF: {BDD2F926-8158-4F62-9E0D-B3B75FD1F07F} (McObjectFactory Class) - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/McMySec/en-us/1,0,0,2/mcmysec.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;ysec.cab</A><br>O23 - Service: Ati HotKey Poller - Unknown owner - D:\WINDOWS\system32\Ati2evxx.exe<br>O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe<br>O23 - Service: McAfee.com McShield (McShield) - Unknown owner - d:\PROGRA~1\mcafee.com\vso\mcshield.exe<br>O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - D:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe<br>O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - d:\PROGRA~1\mcafee.com\vso\mcvsrte.exe<br>O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - D:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe<br>O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - D:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13080553</guid>
<pubDate>Sun, 03 Apr 2005 21:28:17 EDT</pubDate>
</item>

<item>
<title>Re: Hijack-This Question</title>
<link>http://www.dslreports.com/forum/remark,13080545</link>
<description><![CDATA[<A HREF="/useremail/u/397876"><b>NunyaBidness</b></A> : logfile outside zip file<br><br>Logfile of HijackThis v1.99.1<br>Scan saved at 09:18:33 PM, on 04/03/2005<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br><br>Running processes:<br>D:\WINDOWS\System32\smss.exe<br>D:\WINDOWS\system32\winlogon.exe<br>D:\WINDOWS\system32\services.exe<br>D:\WINDOWS\system32\lsass.exe<br>D:\WINDOWS\system32\Ati2evxx.exe<br>D:\WINDOWS\system32\svchost.exe<br>D:\WINDOWS\System32\svchost.exe<br>D:\WINDOWS\system32\spoolsv.exe<br>d:\PROGRA~1\mcafee.com\vso\mcvsrte.exe<br>D:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe<br>D:\WINDOWS\system32\svchost.exe<br>D:\WINDOWS\system32\Fast.exe<br>d:\PROGRA~1\mcafee.com\vso\mcshield.exe<br>D:\WINDOWS\system32\Ati2evxx.exe<br>D:\WINDOWS\Explorer.EXE<br>D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br>D:\Program Files\ATI Multimedia\main\ATIDtct.EXE<br>D:\WINDOWS\system32\taskswitch.exe<br>D:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe<br>D:\PROGRA~1\mcafee.com\agent\mcagent.exe<br>D:\PROGRA~1\mcafee.com\vso\mcvsshld.exe<br>D:\Program Files\Microsoft AntiSpyware\gcasServ.exe<br>D:\Program Files\Java\jre1.5.0_01\bin\jusched.exe<br>D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE<br>D:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe<br>D:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe<br>d:\progra~1\mcafee.com\vso\mcvsescn.exe<br>D:\Program Files\Verizon Online\bin\mpbtn.exe<br>D:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe<br>D:\WINDOWS\system32\rundll32.exe<br>D:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe<br>E:\Program Files\Hijack-This\HijackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://cgi.verizon.net/bookmarks/bmredir.asp?region=all&bw=dsl&cd=6.1&bm=ho_search" >cgi.verizon.net/bookmarks/bmredi&middot;&middot;&middot;o_search</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://cgi.verizon.net/bookmarks/bmredir.asp?region=all&bw=dsl&cd=6.1&bm=ho_home" >cgi.verizon.net/bookmarks/bmredi&middot;&middot;&middot;=ho_home</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://cgi.verizon.net/bookmarks/bmredir.asp?region=all&bw=dsl&cd=6.1&bm=ho_search" >cgi.verizon.net/bookmarks/bmredi&middot;&middot;&middot;o_search</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://cgi.verizon.net/bookmarks/bmredir.asp?region=all&bw=dsl&cd=6.1&bm=ho_home" >cgi.verizon.net/bookmarks/bmredi&middot;&middot;&middot;=ho_home</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online<br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1<br>O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - D:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll<br>O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - D:\Program Files\Ipswitch\WS_FTP Pro\wsbho2k0.dll<br>O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - D:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll<br>O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - d:\progra~1\mcafee.com\vso\mcvsshl.dll<br>O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - D:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll<br>O3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - D:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll<br>O4 - HKLM\..\Run: [ATIPTA] D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br>O4 - HKLM\..\Run: [ATI DeviceDetect] D:\Program Files\ATI Multimedia\main\ATIDtct.EXE<br>O4 - HKLM\..\Run: [BackgroundSwitcher] D:\WINDOWS\system32\bgswitch.exe<br>O4 - HKLM\..\Run: [CoolSwitch] D:\WINDOWS\system32\taskswitch.exe<br>O4 - HKLM\..\Run: [MPFExe] D:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe<br>O4 - HKLM\..\Run: [MCAgentExe] d:\PROGRA~1\mcafee.com\agent\mcagent.exe<br>O4 - HKLM\..\Run: [MCUpdateExe] D:\PROGRA~1\mcafee.com\agent\mcupdate.exe<br>O4 - HKLM\..\Run: [VSOCheckTask] "d:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask<br>O4 - HKLM\..\Run: [VirusScan Online] "d:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"<br>O4 - HKLM\..\Run: [gcasServ] "D:\Program Files\Microsoft AntiSpyware\gcasServ.exe"<br>O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\jre1.5.0_01\bin\jusched.exe<br>O4 - HKLM\..\Run: [EPSON Stylus CX4600 Series] D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE /P26 "EPSON Stylus CX4600 Series" /O6 "USB001" /M "Stylus CX4600"<br>O4 - HKLM\..\Run: [Motive SmartBridge] D:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe<br>O4 - HKCU\..\Run: [ATI Remote Control] D:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe<br>O4 - Global Startup: Verizon Online Support Center.lnk = D:\Program Files\Verizon Online\bin\matcli.exe<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &raquo;<A HREF="http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409" >go.microsoft.com/fwlink/?linkid=&middot;&middot;&middot;id=0x409</A><br>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;sctl.cab</A><br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1111937887028" >v5.windowsupdate.microsoft.com/v&middot;&middot;&middot;37887028</A><br>O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;dmgr.cab</A><br>O16 - DPF: {BDD2F926-8158-4F62-9E0D-B3B75FD1F07F} (McObjectFactory Class) - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/McMySec/en-us/1,0,0,2/mcmysec.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;ysec.cab</A><br>O23 - Service: Ati HotKey Poller - Unknown owner - D:\WINDOWS\system32\Ati2evxx.exe<br>O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe<br>O23 - Service: McAfee.com McShield (McShield) - Unknown owner - d:\PROGRA~1\mcafee.com\vso\mcshield.exe<br>O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - D:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe<br>O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - d:\PROGRA~1\mcafee.com\vso\mcvsrte.exe<br>O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - D:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe<br>O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - D:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)<br><SMALL>--<br>Nunya Bidness</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13080545</guid>
<pubDate>Sun, 03 Apr 2005 21:27:15 EDT</pubDate>
</item>

<item>
<title>Re: Hijack-This Question</title>
<link>http://www.dslreports.com/forum/remark,13080542</link>
<description><![CDATA[<A HREF="/useremail/u/1110758"><b>spooler0</b></A> : how about unzipping your log file?  After that, would you paste the log into your post as text and repost the question?<br><br>Prior to doing so, would you complete ALL the steps in:<br><br>&raquo;<A HREF="/faq/security">Security</A> &raquo;<A HREF="/faq/8428">I think my computer is infected or hijacked. What should I do?</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13080542</guid>
<pubDate>Sun, 03 Apr 2005 21:26:49 EDT</pubDate>
</item>

<item>
<title>Hijack-This Question</title>
<link>http://www.dslreports.com/forum/remark,13080524</link>
<description><![CDATA[<A HREF="/useremail/u/841643"><b>Phoenix__1</b></A> : I always from time too time, do a full system for any "bugs" that may have sneaked by.  I also double check everything is working as it should and is updated (though almost everything runs on auto-update any ways).<br><br>So I cam over this one thing in my log & I could use some feedback.<br><br><B>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1</B><br><br>This is something I have never seen before and it is the only thing that seems to stand out.  Anyone have any ideals about this?  I'm also including the full log, for those who still want to see it all.<br><SMALL>--<br>Want to know how to get a free mini mac? Send me a pm.</SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap WIDTH=33%><A HREF="/r0/download/802131~4a123d0175762b3d75bb0519784a8b54/hijackthis.zip"><IMG  align=absmiddle TITLE="download" SRC="http://i.dslr.net/silk/compress.png" border=0 width=16 height=16><IMG SRC="http://i.dslr.net/1ptrans.gif" WIDTH=10 HEIGHT=1 border=0><big>hijackthis.zip</big></A> <small>2,432 bytes</small><br><small>(hijackthis.log)</small></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13080524</guid>
<pubDate>Sun, 03 Apr 2005 21:24:34 EDT</pubDate>
</item>

</channel>
</rss>
