<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: Hijackthis log. I found one nasty. What is it ? in Security</title>
<link>http://www.dslreports.com/forum/r13807483</link>
<description></description>
<language>en</language>
<pubDate>Sat, 05 Dec 2009 06:50:32 EDT</pubDate>
<lastBuildDate>Sat, 05 Dec 2009 06:50:32 EDT</lastBuildDate>

<item>
<title>I upgraded my PC security.</title>
<link>http://www.dslreports.com/forum/remark,13815285</link>
<description><![CDATA[<A HREF="/useremail/u/1170057"><b>email scope</b></A> : I am now using that hosts file, and avg free as well as sp2. On top of the other security I described.<br><br>I reformatted too. <br><br>The pc is slower, but not too much. <br><br>I think a new firewall is too much. It'll slow my pc down too much. <br><br>Thank you Joker, and the rest of you kind people for your help. :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13815285</guid>
<pubDate>Tue, 05 Jul 2005 05:05:55 EDT</pubDate>
</item>

<item>
<title>Re: Hijackthis log. I found one nasty. What is it</title>
<link>http://www.dslreports.com/forum/remark,13812696</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : <div class="bquote"><SMALL>said by  email scope <A HREF="/useremail/u/1170057"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>I use ....the xp firewall. </DIV>That is not a full featured firewall. It only checks incoming connections. You are much better off with a real firewall that checks both incoming and outgoing connections. With a rules based firewall, if a program you have not authorized for internet access tries to go out (worm, adware, or even a legitimate program), you are notified and allowed the chance to either allow it, or to stop it. The XP firewall won't do that as it doesn't check anything going out.<br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>I don't use a anti-virus, I guess I should<HR></BLOCKQUOTE><br><br>Absolutely!<br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>SP2 slows down the pc according to theinquirer.net, and other places, so I don't use it.<HR></BLOCKQUOTE><br><br>SP2 has the security patches to prevent many of the exploits that malware uses to get on your system. You are not secure without it, and will likely become infected again without it, the only question is how long it will take before you run across malware that your system is unnecessarily vulnerable to. The only thing that might be slower with SP2 is that there is a limit to the number of concurrent connections (10) to slow the progress of worms from infected systems. That can affect P2P programs, but not significantly from what I've seen, and there are patches to bypass that limitation if that's what you are referring to. With your system clean, you shouldn't be doing any connecting with your system until you do install SP2. You have no antivirus, no real firewall, and don't have SP2 installed. Your system is a threat to others on the Internet should you become infected. There have even been cases where users have become infected, and with no firewall to stop the outgoing connection, tried to infect other systems, and their ISP rightfully terminated their access until their system was cleaned. I would run, not walk, to Windows Update and install SP2.<br><SMALL>--<br>Proud ASAP member since 2005</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13812696</guid>
<pubDate>Mon, 04 Jul 2005 19:06:01 EDT</pubDate>
</item>

<item>
<title>Re: Hijackthis log. I found one nasty. What is it</title>
<link>http://www.dslreports.com/forum/remark,13812070</link>
<description><![CDATA[<A HREF="/useremail/u/459195"><b>Reverend Ike</b></A> : <div class="bquote"><SMALL>said by  email scope <A HREF="/useremail/u/1170057"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><BR><BR>I don't use IE, so I don't need a hosts file.</DIV>The Hosts file is not IE-dependent.<br><br>The level of user expertise, whether a system has a single user or multiple users, etc. may affect the importance of using a resident AV and/or updating to SP2. However, as <I>general advice</I>, I think most in the Security forum would recommend including both components on the basis that the benefits of each usually outweigh any negative effects. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13812070</guid>
<pubDate>Mon, 04 Jul 2005 17:13:55 EDT</pubDate>
</item>

<item>
<title>Re: Hijackthis log. I found one nasty. What is it</title>
<link>http://www.dslreports.com/forum/remark,13811937</link>
<description><![CDATA[<A HREF="/useremail/u/1170057"><b>email scope</b></A> : I use a limited account, and prevx free. I have a dlink-604 router, and use the xp firewall. I do have spywareblaster, and ad aware. As well as the protection included in the picture.<br><br>I don't use a anti-virus, I guess I should, but I haven't seen the need too. <br>SP2 slows down the pc according to theinquirer.net, and other places, so I don't use it.<br>I don't use IE, so I don't need a hosts file.<br><br>I think my pc is clean. <div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/13811937?c=852940&ret=L2ZvcnVtL3IxMzgwNzQ4My54bWw%3D"><IMG class="apic" BORDER=0 TITLE="79395 bytes" WIDTH=600 HEIGHT=475 SRC="/r0/download/852940.thumb600~f8b3d86dfbf2ef2a8c6488a58003d34c/Net.JPG/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13811937</guid>
<pubDate>Mon, 04 Jul 2005 16:45:29 EDT</pubDate>
</item>

<item>
<title>Re: Hijackthis log. I found one nasty. What is it ?</title>
<link>http://www.dslreports.com/forum/remark,13809258</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : You aren't through quite yet. You need to improve your security.<br><br>Your version of Internet Explorer is old and needs to be updated, and you need to install Service Pack 2 (SP-2). You need to go to Windows Update (Start button > Windows update) and install <B>all</B> critical updates. <B>Not updating your system puts it at risk for MANY exploits</B>.<br><br><B>You need to run an antivirus program</B> and keep it up-to-date.  I don&#146;t see one in your HijackThis log.  If cost is an issue, try AVG 7 Free available at &raquo;<A HREF="http://free.grisoft.com/doc/2/lng/us/tpl/v5" >free.grisoft.com/doc/2/lng/us/tpl/v5</A> or Free avast! 4 Home Edition at &raquo;<A HREF="http://www.avast.com/eng/avast_4_home.html" >www.avast.com/eng/avast_4_home.html</A>.<br><br><B>You also need a software firewall</B>; I don't see one in your HijackThis log.  Two free firewalls are Zone Alarm from zonelabs.com &raquo;<A HREF="http://www.zonelabs.com/store/content/company/products/znalm/freeDownload.jsp" >www.zonelabs.com/store/content/c&middot;&middot;&middot;load.jsp</A> or Kerio Personal Firewall available from &raquo;<A HREF="http://www.kerio.com/us/kpf_home.html" >www.kerio.com/us/kpf_home.html</A>. There is a tutorial on understanding firewalls at &raquo;<A HREF="http://www.bleepingcomputer.com/forums/tutorial60.html" >www.bleepingcomputer.com/forums/&middot;&middot;&middot;l60.html</A>. <br><br>There are several free utilities you can use to help keep malware off your system: <br><br>A HOSTS file will prevent Internet Explorer from communicating with sites associated with adware or spyware. A good regularly updated HOST file is MVPS HOSTS File, available at &raquo;<A HREF="http://www.mvps.org/winhelp2002/hosts.htm" >www.mvps.org/winhelp2002/hosts.htm</A>. <br><br>IE/SPYAD adds sites associated with ads and spyware to your Internet Restricted Zone and you can download that at &raquo;<small>https</small>://<A HREF="https://netfiles.uiuc.edu/ehowes/www/resource.htm#IESPYAD">netfiles.uiuc.edu/ehowes/www/res&middot;&middot;&middot;#IESPYAD</A>.<br><br>A free non-resident utility to prevent the installation of ActiveX-based malware is JavaCool's SpywareBlaster. For real-time protection, there is SpywareGuard. Both are available at &raquo;<A HREF="http://www.javacoolsoftware.com/products.html" >www.javacoolsoftware.com/products.html</A>. <br><br>I recommend reading Tony Klein's article <I>How did I get Infected?</I> at &raquo;<A HREF="http://www.computercops.biz/postlite7736-.html" >www.computercops.biz/postlite7736-.html</A><br><br>Please let me know if your problem appears solved.<br><SMALL>--<br>Proud ASAP member since 2005</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13809258</guid>
<pubDate>Mon, 04 Jul 2005 08:57:28 EDT</pubDate>
</item>

<item>
<title>Re: Hijackthis log. I found one nasty. What is it</title>
<link>http://www.dslreports.com/forum/remark,13807719</link>
<description><![CDATA[<A HREF="/useremail/u/1170057"><b>email scope</b></A> : &raquo;<A HREF="http://www.virustotal.com/flash/index_en.html" >www.virustotal.com/flash/index_en.html</A><br><br>That scanner was busy, so I used this one. It found no nasties. And tds anti trojan found nothing. :)<br><br>Thank you for your help. If I every find anything again. I'll run it through one of those scanners before I post anything here. :D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13807719</guid>
<pubDate>Sun, 03 Jul 2005 23:33:42 EDT</pubDate>
</item>

<item>
<title>Re: Hijackthis log. I found one nasty. What is it ?</title>
<link>http://www.dslreports.com/forum/remark,13807483</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Your log looks fine now (although it is an unusually short log).<br><br>That line may be gone from your HijackThis log, but did you actually delete the file (there was no file path in the line)? In my case, I have several different copies of wmplayer.exe on my system. Unless you searched for and deleted all instances of wmplayer.exe from your system (and you would have actually deleted Windows Media Player's executable if you did that), you should still search for each copy of the file and submit it for the scan to be certain one of them isn't malware.<br><SMALL>--<br>Proud ASAP member since 2005</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13807483</guid>
<pubDate>Sun, 03 Jul 2005 22:46:03 EDT</pubDate>
</item>

<item>
<title>Re: Hijackthis log. I found one nasty. What is it</title>
<link>http://www.dslreports.com/forum/remark,13807480</link>
<description><![CDATA[<A HREF="/useremail/u/113847"><b>ronob</b></A> : <div class="bquote"><SMALL>said by  email scope <A HREF="/useremail/u/1170057"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>wmplayer.exe //ICWLaunch <br>Is gone. I already fixed it. I didn't know I should submit it. That other poster said it was fine. :hmm: <br><br>There's no use in me submitting anything now. It's gone ! :huh:<br> </DIV>"Use Windows Search (Start > Search > For Files or Folders), to search for each instance of wmplayer.exe<br><br>Please submit each instance of wmplayer.exe to the following link for a scan and post the results, along with the full path for any instance that was found to contain malware.<br><br>&raquo;<A HREF="http://virusscan.jotti.org/" >virusscan.jotti.org/</A> "<br><SMALL>--<br>I've been to the end of the internet!</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13807480</guid>
<pubDate>Sun, 03 Jul 2005 22:45:43 EDT</pubDate>
</item>

<item>
<title>Re: Hijackthis log. I found one nasty. What is it</title>
<link>http://www.dslreports.com/forum/remark,13807416</link>
<description><![CDATA[<A HREF="/useremail/u/1170057"><b>email scope</b></A> : Logfile of HijackThis v1.99.1<br>Scan saved at 7:28:47 PM, on 7/3/2005<br>Platform: Windows XP SP1 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\LEXBCES.EXE<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\system32\LEXPPS.EXE<br>C:\Program Files\Prevx Home\PXAgent.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\Prevx Home\SAGUI.exe<br>C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br>C:\Documents and Settings\Dell PC\My Documents\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.yahoo.com/" >www.yahoo.com/</A><br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx<br>O4 - HKLM\..\Run: [PrevxHome] C:\Program Files\Prevx Home\SAGUI.exe<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll<br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1119842952226" >update.microsoft.com/windowsupda&middot;&middot;&middot;42952226</A><br>O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE<br>O23 - Service: Prevx Agent (PrevxAgent) - Unknown owner - C:\Program Files\Prevx Home\PXAgent.exe" -f (file missing)<br>-------------<br><br>wmplayer.exe //ICWLaunch <br>Is gone. I already fixed it. I didn't know I should submit it. That other poster said it was fine. :hmm: <br><br>There's no use in me submitting anything now. It's gone ! :huh:]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13807416</guid>
<pubDate>Sun, 03 Jul 2005 22:33:32 EDT</pubDate>
</item>

<item>
<title>Re: Hijackthis log. I found one nasty. What is it ?</title>
<link>http://www.dslreports.com/forum/remark,13807371</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : R1 is for Internet Explorers Search functions and other characteristics. I don't think wmplayer.exe belongs there. There are also several nasites with the same file name. <br><br>Use Windows Search (Start > Search > For Files or Folders), to search for each instance of wmplayer.exe<br><br>Please submit each instance of wmplayer.exe to the following link for a scan and post the results, along with the full path for any instance that was found to contain malware.<br><br>&raquo;<A HREF="http://virusscan.jotti.org/" >virusscan.jotti.org/</A><br><br>In the meantime:<br><br>Now you need to run HijackThis and click "<B>Do a system scan only</B>." Place a check next to the following entries:<br><br><B>O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm<br>O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm</B><br><br>Close all browser and other windows except for HijackThis, and click "<B>Fix Checked</B>" to have HijackThis fix the entries you checked.<br><br>The two items you fixed were malicious entries that had replaced your default Windows Related links buttons. If you want to restore the Microsoft "Related Links" here is a tool to fix it. &raquo;<A HREF="http://www.mvps.org/winhelp2002/alexa.zip" >www.mvps.org/winhelp2002/alexa.zip</A><br>Unzip, place "related.htm" into your "\WINDOWS\Web" folder Right-click on "RestoreAlexa.reg", select: Merge, and reboot.<br><br>Please restart your system and post a new HijackThis log<br><SMALL>--<br>Proud ASAP member since 2005</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13807371</guid>
<pubDate>Sun, 03 Jul 2005 22:22:42 EDT</pubDate>
</item>

<item>
<title>Re: Hijackthis log. I found one nasty. What is it</title>
<link>http://www.dslreports.com/forum/remark,13807326</link>
<description><![CDATA[<A HREF="/useremail/u/1170057"><b>email scope</b></A> : I couldn't stand it. I had to fix it, so I did, and it's gone. Ha heh. Good riddence too. :o]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13807326</guid>
<pubDate>Sun, 03 Jul 2005 22:14:43 EDT</pubDate>
</item>

<item>
<title>Re: Hijackthis log. I found one nasty. What is it</title>
<link>http://www.dslreports.com/forum/remark,13807199</link>
<description><![CDATA[<A HREF="/useremail/u/1170057"><b>email scope</b></A> : Ok. I see other hijackthis forums say to delete it. More than one...makes me nervous. :huh:<br><br>How would I delete it. Is there a special way ?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13807199</guid>
<pubDate>Sun, 03 Jul 2005 21:55:11 EDT</pubDate>
</item>

<item>
<title>Re: Hijackthis log. I found one nasty. What is it</title>
<link>http://www.dslreports.com/forum/remark,13807177</link>
<description><![CDATA[<A HREF="/useremail/u/855835"><b>CajunTek</b></A> : If you are talking about that automated hijackthis analyzer.. I don't trust'em.. Darned thing wants me to delete my firewall.. :|<br><SMALL>--<br>Lost in Texas</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13807177</guid>
<pubDate>Sun, 03 Jul 2005 21:51:36 EDT</pubDate>
</item>

<item>
<title>Re: Hijackthis log. I found one nasty. What is it</title>
<link>http://www.dslreports.com/forum/remark,13807151</link>
<description><![CDATA[<A HREF="/useremail/u/1170057"><b>email scope</b></A> : <div class="bquote"><SMALL>said by  CajunTek <A HREF="/useremail/u/855835"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><BR><BR>This nasty <br>wmplayer.exe<br>is &raquo;<A HREF="http://www.liutilities.com/products/wintaskspro/processlibrary/wmplayer/" >www.liutilities.com/products/win&middot;&middot;&middot;mplayer/</A><br>windows media player...<br> </DIV>I wonder why other hijackthis forums say to delete it ? Oh, and this comes after wmplayer.exe //ICWLaunch<br>What's the significance of that if any ?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13807151</guid>
<pubDate>Sun, 03 Jul 2005 21:46:17 EDT</pubDate>
</item>

<item>
<title>Re: Hijackthis log. I found one nasty. What is it</title>
<link>http://www.dslreports.com/forum/remark,13807142</link>
<description><![CDATA[<A HREF="/useremail/u/855835"><b>CajunTek</b></A> : This nasty <br>wmplayer.exe<br>is &raquo;<A HREF="http://www.liutilities.com/products/wintaskspro/processlibrary/wmplayer/" >www.liutilities.com/products/win&middot;&middot;&middot;mplayer/</A><br>windows media player...<br><SMALL>--<br>Lost in Texas</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13807142</guid>
<pubDate>Sun, 03 Jul 2005 21:43:42 EDT</pubDate>
</item>

<item>
<title>Hijackthis log. I found one nasty. What is it ?</title>
<link>http://www.dslreports.com/forum/remark,13807127</link>
<description><![CDATA[<A HREF="/useremail/u/1170057"><b>email scope</b></A> : Logfile of HijackThis v1.99.1<br>Scan saved at 6:34:25 PM, on 7/3/2005<br>Platform: Windows XP SP1 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\LEXBCES.EXE<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\system32\LEXPPS.EXE<br>C:\Program Files\Prevx Home\PXAgent.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\Prevx Home\SAGUI.exe<br>C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br>C:\Documents and Settings\Dell PC\My Documents\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.yahoo.com/" >www.yahoo.com/</A><br>R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx<br>O4 - HKLM\..\Run: [PrevxHome] C:\Program Files\Prevx Home\SAGUI.exe<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll<br>O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm<br>O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm<br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1119842952226" >update.microsoft.com/windowsupda&middot;&middot;&middot;42952226</A><br>O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE<br>O23 - Service: Prevx Agent (PrevxAgent) - Unknown owner - C:\Program Files\Prevx Home\PXAgent.exe" -f (file missing)<br>-------------------------<br>R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch<br><br>This is the nasty. How do I fix it ? Is this a Trojan, or Virus ?<br>I found it using this web site: &raquo;<A HREF="http://hijackthis.de/index.php?langselect=english" >hijackthis.de/index.php?langselect=english</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13807127</guid>
<pubDate>Sun, 03 Jul 2005 21:41:02 EDT</pubDate>
</item>

</channel>
</rss>
