<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Help With Hijack This Log/ Madfinder in Security</title>
<link>http://www.dslreports.com/forum/r8586247</link>
<description></description>
<language>en</language>
<pubDate>Wed, 09 Dec 2009 22:32:05 EDT</pubDate>
<lastBuildDate>Wed, 09 Dec 2009 22:32:05 EDT</lastBuildDate>

<item>
<title>Re: Help With Hijack This Log/ Madfinder</title>
<link>http://www.dslreports.com/forum/remark,8586486</link>
<description><![CDATA[<A HREF="/useremail/u/675365"><b>Bubba</b></A> :  Sorry.....I can't even read a post right<br><br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8586486</guid>
<pubDate>Sun, 23 Nov 2003 19:31:38 EDT</pubDate>
</item>

<item>
<title>Re: Help With Hijack This Log/ Madfinder</title>
<link>http://www.dslreports.com/forum/remark,8586454</link>
<description><![CDATA[<A HREF="/useremail/u/751678"><b>lilhurricane</b></A> : Thank you as well,  anthrorules <A HREF="/useremail/u/874633"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A><br>I am clean!!! :)<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=2 WIDTH=66%><A HREF="/speak/slideshow/8586454?c=473831&ret=L2ZvcnVtL3I4NTg2MjQ3LnhtbA%3D%3D"><IMG TITLE="22015 bytes" BORDER=0 WIDTH=385 HEIGHT=372 SRC="/r0/download/473831~05af55faaf7aa4fde00ef8ab00d221a6/Clean.JPG"></A><br>Hooray!!!</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8586454</guid>
<pubDate>Sun, 23 Nov 2003 19:26:30 EDT</pubDate>
</item>

<item>
<title>Re: Help With Hijack This Log/ Madfinder</title>
<link>http://www.dslreports.com/forum/remark,8586436</link>
<description><![CDATA[<A HREF="/useremail/u/874633"><b>anthrorules</b></A> : Which version of CWShredder are you using?<br><br>If you are using a version older than the one released today, 1.36.0000, than it is definitely a false positive as VampireInfo mentioned.<br><br>This seems to have been fixed in the newest version, 1.36.0000.<br><br>Check your version, and update it if necessary, then run CWShredder again.<br><SMALL>--<br>Earthlink/Direcway SRS - DW4000 | ver. 4.2.1.10 | Proxy/Port 83 | G4R | 1250 | Dell Dimension 4550 - WinXP Pro SP1 - 256MG Ram |ZA+ 4.5 | AVG 7.0 | Trojan Remover | Ad-Aware | SpyBot S&D | MailWasher Pro 3.2</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8586436</guid>
<pubDate>Sun, 23 Nov 2003 19:23:27 EDT</pubDate>
</item>

<item>
<title>Re: Help With Hijack This Log/ Madfinder</title>
<link>http://www.dslreports.com/forum/remark,8586428</link>
<description><![CDATA[<A HREF="/useremail/u/751678"><b>lilhurricane</b></A> : Alright then,  Vampirefo <A HREF="/useremail/u/260736"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>..that was what I thought. I needed reassurance is all, as I believed that to be an issue with XP only. Thanks very, very much!!! :)<br><SMALL>--<br>Proud Member of: <A HREF="/forum/disco">Team Discovery</A> Join Us!! <A HREF="http://www.tdprojecthope.org/">HOPE!!</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8586428</guid>
<pubDate>Sun, 23 Nov 2003 19:22:49 EDT</pubDate>
</item>

<item>
<title>Re: Help With Hijack This Log/ Madfinder</title>
<link>http://www.dslreports.com/forum/remark,8586414</link>
<description><![CDATA[<A HREF="/useremail/u/260736"><b>Vampirefo</b></A> : It's a false alarm, read this thread.<br>&raquo;<A HREF="/forum/remark,8563261~root=security,1~mode=flat">Madfinder: Keeps Coming Back</A><br><SMALL>--<br>TrojanHunter Stands For Privacy!!!!!!!</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8586414</guid>
<pubDate>Sun, 23 Nov 2003 19:20:37 EDT</pubDate>
</item>

<item>
<title>Help With Hijack This Log/ Madfinder</title>
<link>http://www.dslreports.com/forum/remark,8586247</link>
<description><![CDATA[<A HREF="/useremail/u/751678"><b>lilhurricane</b></A> : I downloaded the CWShredder, and it found 1 item Madfinder. It removed it. When I rebooted...there it was again. <br><br>I ran Hijack This and this is what I got.<br><br>Logfile of HijackThis v1.97.5<br>Scan saved at 3:02:59 PM, on 11/23/03<br>Platform: Windows 98 SE (Win9x 4.10.2222A)<br>MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)<br><br>Running processes:<br>C:\WINDOWS\SYSTEM\KERNEL32.DLL<br>C:\WINDOWS\SYSTEM\MSGSRV32.EXE<br>C:\WINDOWS\SYSTEM\MPREXE.EXE<br>C:\WINDOWS\SYSTEM\mmtask.tsk<br>C:\PROGRAM FILES\KERIO\PERSONAL FIREWALL\PERSFW.EXE<br>C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSRTE.EXE<br>C:\WINDOWS\EXPLORER.EXE<br>C:\WINDOWS\SYSTEM\SYSTRAY.EXE<br>C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER\DPPS2.EXE<br>C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE<br>C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHLD.EXE<br>C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSESCN.EXE<br>C:\WINDOWS\STARTER.EXE<br>C:\PROGRAM FILES\SPYWAREGUARD\SGMAIN.EXE<br>C:\WINDOWS\DESKTOP\DISCOVERY\UNITED DEVICES\UD.EXE<br>C:\WINDOWS\SYSTEM\MSTASK.EXE<br>C:\WINDOWS\SYSTEM\WMIEXE.EXE<br>C:\WINDOWS\DESKTOP\DISCOVERY\UNITED DEVICES\UD_1706422.EXE<br>C:\PROGRAM FILES\SPYWAREGUARD\SGBHP.EXE<br>C:\WINDOWS\DESKTOP\DISCOVERY\UNITED DEVICES\UD_1706422_0.DIR\UD_LIGFIT_RELEASE.EXE<br>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE<br>C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Hurricane HSI<br>O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL<br>O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - (no file)<br>O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX<br>O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHL.DLL<br>O4 - HKLM\..\Run: [SystemTray] SysTray.Exe<br>O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER\DPPS2.EXE"<br>O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe<br>O4 - HKLM\..\Run: [VirusScan Online] "C:\PROGRA~1\MCAFEE.COM\VSO\mcvsshld.exe"<br>O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\MCAFEE.COM\VSO\MCMNHDLR.EXE" /checktask<br>O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE<br>O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun<br>O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe<br>O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe<br>O4 - HKLM\..\RunServices: [PersFw] "C:\PROGRAM FILES\KERIO\PERSONAL FIREWALL\PERSFW.EXE"<br>O4 - HKLM\..\RunServices: [McVsRte] C:\PROGRA~1\MCAFEE.COM\VSO\mcvsrte.exe /embedding<br>O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe<br>O4 - Startup: Shortcut to Ud.lnk = C:\WINDOWS\Desktop\DISCOVERY\United Devices\UD.EXE<br>O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present<br>O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - &raquo;<A HREF="http://download.mcafee.com/molbin/Shared/MGBrwFld.cab" >download.mcafee.com/molbin/Share&middot;&middot;&middot;wFld.cab</A><br>O16 - DPF: {6C636F50-7EB2-11D2-883C-CA8C113EA37E} (McAfee Clinic QuickClean Class) - &raquo;<A HREF="http://download.mcafee.com/molbin/Clinic/Clean/QuickClean/MGqcctl.cab" >download.mcafee.com/molbin/Clini&middot;&middot;&middot;cctl.cab</A><br>O16 - DPF: {23047A90-8511-11D2-87A5-20C252C10000} (McAfee Clinic TreeView Class) - &raquo;<A HREF="http://download.mcafee.com/molbin/Shared/MGTree.cab" >download.mcafee.com/molbin/Shared/MGTree.cab</A><br>O16 - DPF: {D30CAFF0-087B-11D3-82D8-006094695CEC} (McAfee PC Clinic FaManager Class) - &raquo;<A HREF="http://download.mcafee.com/molbin/Clinic/FirstAid/FACheck/mgfactl.cab" >download.mcafee.com/molbin/Clini&middot;&middot;&middot;actl.cab</A><br>O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &raquo;<A HREF="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab" >download.macromedia.com/pub/shoc&middot;&middot;&middot;lash.cab</A><br>O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - &raquo;<A HREF="http://download.macromedia.com/pub/shockwave/cabs/director/swdir.cab" >download.macromedia.com/pub/shoc&middot;&middot;&middot;wdir.cab</A><br>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - &raquo;<A HREF="http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,74/mcinsctl.cab" >bin.mcafee.com/molbin/shared/mci&middot;&middot;&middot;sctl.cab</A><br>O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - &raquo;<A HREF="http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,16/mcgdmgr.cab" >bin.mcafee.com/molbin/shared/mcg&middot;&middot;&middot;dmgr.cab</A><br>O16 - DPF: {E9B2DC2F-3659-11D5-811E-00C0F003066B} (Cleaner Class) - &raquo;<A HREF="http://www.panicware.net/activex/pwiclean.cab" >www.panicware.net/activex/pwiclean.cab</A><br>O16 - DPF: {CDB74794-A3BA-4733-B6F6-59BF16D6C15A} - &raquo;<A HREF="http://download.mcafee.com/molbin/mcaeng/mcsmtshp.cab" >download.mcafee.com/molbin/mcaen&middot;&middot;&middot;tshp.cab</A><br>O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - &raquo;<A HREF="http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37864.753900463" >v4.windowsupdate.microsoft.com/C&middot;&middot;&middot;53900463</A><br><br>I would appreciate any advice you can offer. Thank you.<br><SMALL>--<br>Proud Member of: <A HREF="/forum/disco">Team Discovery</A> Join Us!! <A HREF="http://www.tdprojecthope.org/">HOPE!!</A></SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=2 WIDTH=66%><A HREF="/speak/slideshow/8586247?c=473794&ret=L2ZvcnVtL3I4NTg2MjQ3LnhtbA%3D%3D"><IMG TITLE="31076 bytes" BORDER=0 WIDTH=385 HEIGHT=372 SRC="/r0/download/473794~cb90c90aff178b210e04b84ac63368de/madfinder.JPG"></A><br>Found This</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8586247</guid>
<pubDate>Sun, 23 Nov 2003 19:01:17 EDT</pubDate>
</item>

</channel>
</rss>
