<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Hijack in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r22526192</link>
<description></description>
<language>en</language>
<pubDate>Fri, 04 Dec 2009 03:45:14 EDT</pubDate>
<lastBuildDate>Fri, 04 Dec 2009 03:45:14 EDT</lastBuildDate>

<item>
<title>Re: Hijack</title>
<link>http://www.dslreports.com/forum/remark,22537459</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : I'm glad I could help. :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22537459</guid>
<pubDate>Thu, 11 Jun 2009 21:53:52 EDT</pubDate>
</item>

<item>
<title>Re: Hijack</title>
<link>http://www.dslreports.com/forum/remark,22536306</link>
<description><![CDATA[<A HREF="/useremail/u/1563096"><b>The Brain</b></A> : Thanks Joker all clear<br>See ya in Gotham for our next computer duel]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22536306</guid>
<pubDate>Thu, 11 Jun 2009 18:13:25 EDT</pubDate>
</item>

<item>
<title>Re: Hijack</title>
<link>http://www.dslreports.com/forum/remark,22532451</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Hi The Brain<br><br>Your log shows no sign of infection. <br><br> <blockquote><small>quote:</small><hr>Both Mal and Spy found and removed things I find on a daily bases that sptbot finds some thing called doubleclick-computer is running slightly lame and sticky since.<hr></blockquote><br>What they are finding is a tracking cookie. You get that anytime you visit a web site that uses DoubleClick.<br><br>I wouldn't worry about the cookies. Cookies are just text files, and many sites use them. They store everything from user preferences, last post read at forums, language preference, or even the items you order at a site on-line (your "shopping basket"). Other sites use them to track what ads you've already seen, or pages you selected, to try to deliver you similar ads. If cookies are a concern, you can install a program to control them, like Cookie Pal, Cookie Crusher, Cookie Cruncher or others. <br><br>Most of those ad or tracking cookies are third party cookies, and you can block many of those:<br>&raquo;<A HREF="http://www.bobulous.org.uk/misc/third-party-cookies.html" >www.bobulous.org.uk/misc/third-p&middot;&middot;&middot;ies.html</A><br><br>In Firefox, go to Tools > Options > Privacy > Cookies<br>Click the small triangle next to cookies to expand that tab and put a check next to "for the originating website only". This will prevent third party cookies from being installed on your computer.<br><br>In Internet Explorer, go to Tools > Internet Options > Privacy and click on Advanced in the Privacy tab<br>Now put a check next to "Override automatic cookie handling"<br>Set first party cookies to Accept and third party cookies to Block<br>Also put a check to "Always allow session cookies" OK your way out.<br>This won't prevent all tracking cookies from being installed, but will reduce the amount.<br><br><A HREF="http://www.javacoolsoftware.com/products.html">SpywareBlaster</a> can also be used to block ad/tracking cookies in Internet Explorer and Firefox.<br><br>In Opera, open the Tools menu on the menu bar and click Preferences... <br>Select the Advanced tab in the top row of the options dialogue. <br>Select Cookies in the column on the left. <br>Make sure that the button labeled Accept only cookies from the site I visit is the one selected. <br>If you want to be asked before each cookie is set, tick the box labeled Ask me before accepting cookies (but be warned that this will happen a lot). <br>Once you've chosen your settings, click Okay at the bottom of the options dialogue.<br><br>I would point out though that as you are using VNC Server, that it can be a security risk if you don't use a strong password - at least eight characters, including both upper and lower case letters, at least one number, and a special character such as !, @, # (upper case on the numbers).<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22532451</guid>
<pubDate>Thu, 11 Jun 2009 06:06:24 EDT</pubDate>
</item>

<item>
<title>Hijack</title>
<link>http://www.dslreports.com/forum/remark,22526192</link>
<description><![CDATA[<A HREF="/useremail/u/1563096"><b>The Brain</b></A> : Hope Ive posted in the right section<br>Had some kind of Spam hijack<br>Ive done spybot reboted done it again ran Macafee and Malwarebytes -Both Mal and Spy found and removed things I find on a daily bases that sptbot finds some thing called doubleclick-computer is running slightly lame and sticky since.<br>-------------------------------------------------------------<br>Malwarebytes log<br>Malwarebytes' Anti-Malware 1.37<br>Database version: 2256<br>Windows 5.1.2600 Service Pack 3<br><br>10/06/2009 7:10:49 PM<br>mbam-log-2009-06-10 (19-10-49).txt<br><br>Scan type: Quick Scan<br>Objects scanned: 102810<br>Time elapsed: 9 minute(s), 49 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 0<br>Registry Keys Infected: 0<br>Registry Values Infected: 0<br>Registry Data Items Infected: 2<br>Folders Infected: 0<br>Files Infected: 0<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>(No malicious items detected)<br><br>Registry Keys Infected:<br>(No malicious items detected)<br><br>Registry Values Infected:<br>(No malicious items detected)<br><br>Registry Data Items Infected:<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.<br><br>Folders Infected:<br>(No malicious items detected)<br><br>Files Infected:<br>(No malicious items detected)<br>-----------------------------------------------------------<br>Hijackthis Log<br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 7:54:57 PM, on 10/06/2009<br>Platform: Windows XP SP3 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\Program Files\Bonjour\mDNSResponder.exe<br>C:\WINDOWS\system32\cisvc.exe<br>C:\Program Files\Java\jre6\bin\jqs.exe<br>C:\Program Files\McAfee\SiteAdvisor\McSACore.exe<br>C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br>c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br>c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br>C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br>C:\Program Files\McAfee\MPF\MPFSrv.exe<br>c:\PROGRA~1\mcafee.com\agent\mcagent.exe<br>C:\Program Files\McAfee\MSK\MskSrver.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe<br>C:\WINDOWS\SOUNDMAN.EXE<br>C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe<br>C:\Program Files\Microsoft IntelliType Pro\itype.exe<br>C:\Program Files\Microsoft IntelliPoint\ipoint.exe<br>C:\Program Files\Canon\MyPrinter\BJMyPrt.exe<br>C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe<br>C:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\Program Files\Java\jre6\bin\jusched.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\WINDOWS\system32\cidaemon.exe<br>C:\Program Files\Mozilla Firefox\firefox.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = &raquo;<A HREF="http://au.search.yahoo.com/search?fr=mcafee&p=%s" >au.search.yahoo.com/search?fr=mcafee&p=%s</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = <br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = <br>O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br>O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br>O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll<br>O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br>O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br>O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br>O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br>O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br>O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe<br>O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br>O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"<br>O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"<br>O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon<br>O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon<br>O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"<br>O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe<br>O4 - HKLM\..\Run: [RegKillElbyCheck] "C:\Program Files\Elaborate Bytes\DVD Region Killer\ElbyCheck.exe" /L RegKill<br>O4 - HKLM\..\Run: [RegKillTray] "C:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe"<br>O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br>O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey<br>O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide<br>O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized<br>O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')<br>O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')<br>O8 - Extra context menu item: Add to Windows &Live Favorites - &raquo;<A HREF="http://favorites.live.com/quickadd.aspx" >favorites.live.com/quickadd.aspx</A><br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br>O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O15 - Trusted Zone: &raquo;<A HREF="http://*.mcafee.com" >*.mcafee.com</A><br>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - <br>O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcgdmgr/en-au/1,0,0,23/mcgdmgr.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;dmgr.cab</A><br>O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &raquo;<A HREF="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" >fpdownload2.macromedia.com/get/s&middot;&middot;&middot;lash.cab</A><br>O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br>O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br>O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe<br>O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe<br>O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br>O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br>O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe<br>O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br>O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br>O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br>O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe<br>O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe<br>O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br>O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe<br><br>--<br>End of file - 10371 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22526192</guid>
<pubDate>Wed, 10 Jun 2009 06:01:16 EDT</pubDate>
</item>

</channel>
</rss>
