<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: Help: My HiJack Results... in Security</title>
<link>http://www.dslreports.com/forum/r8814632</link>
<description></description>
<language>en</language>
<pubDate>Tue, 01 Dec 2009 15:12:24 EDT</pubDate>
<lastBuildDate>Tue, 01 Dec 2009 15:12:24 EDT</lastBuildDate>

<item>
<title>Re: Help: My HiJack Results...</title>
<link>http://www.dslreports.com/forum/remark,8822193</link>
<description><![CDATA[<A HREF="/useremail/u/890655"><b>normmork</b></A> : PLkease read this thread as it will give you a good idea what to do: &raquo;<A HREF="/faq/security">Security</A> &raquo;<A HREF="/faq/8428">I think my computer is infected or hijacked. What should I do?</A> ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8822193</guid>
<pubDate>Thu, 18 Dec 2003 09:53:29 EDT</pubDate>
</item>

<item>
<title>Re: Help: My HiJack Results...</title>
<link>http://www.dslreports.com/forum/remark,8819988</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : Since you have XP now..I would get a free copy of this program and set it up..<br><br>&raquo;<A HREF="http://www.xp-antispy.org/" >www.xp-antispy.org/</A><br><br>What is XP-AntiSpy?<br><br>XP-AntiSpy is a little utility that let's you disable some built-in update and authetication 'features' in WindowsXP.<br>For example, there's a service running in the background wich is called 'Automatic Updates'. I don't know what this service transfers from my machine to other machines on the internet, especially the MS ones. So I play it safe and disable such functions. If you like, you can even disable these function manually, by going through the System and checking or unchecking some checkboxes. This will take you approximately half an hour. But why wasting time when a little neat utility can do the same in 1 minute? This utility was successfully tested by lots of users, and was found to disable all the known 'Suspicious' Functions in WindowsXP. It's customizeable, but comes up with the Default settings, which are recommended. If you like to get more information about those 'functions',read THIS.<br><br>This utility is FREEWARE! This means, you dont have to pay anything for this program and you can give it to anyone who's interested in, as long as you don't sell it. If you find this tool useful, and wanna gimme something back, then click on my sponsors.<br>Thanks. <br><br>Important information: The Domains www.xp-antispy.de und www.xpantispy.de do not belong to the project xp-AntiSpy anymore. The new owner offers only a dialer to download. <br>Please update any links and your bookmarks to www.xp-antispy.org<br>Greetings, -chris-<br><SMALL>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8819988</guid>
<pubDate>Thu, 18 Dec 2003 00:08:05 EDT</pubDate>
</item>

<item>
<title>Re: Help: My HiJack Results...</title>
<link>http://www.dslreports.com/forum/remark,8819955</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : Nevermind...it is all in your posts in this other forum.<br><br>Logfile of HijackThis v1.97.7<br>Scan saved at 5:24:48 AM, on 12/17/2003<br>Platform: Windows XP SP1 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)<br><br>&raquo;<A HREF="/forum/remark,8811459~mode=flat#8811485">Need Help Optimizing My PC...</A><br><SMALL>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8819955</guid>
<pubDate>Thu, 18 Dec 2003 00:03:28 EDT</pubDate>
</item>

<item>
<title>Re: Help: My HiJack Results...</title>
<link>http://www.dslreports.com/forum/remark,8819916</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : What version of Hijack this are you using ???  Sure you have the latest one ??<br><SMALL>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8819916</guid>
<pubDate>Wed, 17 Dec 2003 23:58:01 EDT</pubDate>
</item>

<item>
<title>Re: Help: My HiJack Results...</title>
<link>http://www.dslreports.com/forum/remark,8814632</link>
<description><![CDATA[<A HREF="/useremail/u/590730"><b>Randy Bell</b></A> : Hmmm .. I clicked on that link and it redirected *ME* to my own Start Page .. so I suppose it's harmless .. LOL. ;)<br><SMALL>--<br><I>"But now abide faith, hope, love, these three; but the greatest of these is love." (1 Cor. 13:13)</I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8814632</guid>
<pubDate>Wed, 17 Dec 2003 14:53:10 EDT</pubDate>
</item>

<item>
<title>Re: Help: My HiJack Results...</title>
<link>http://www.dslreports.com/forum/remark,8814613</link>
<description><![CDATA[<A HREF="/useremail/u/590730"><b>Randy Bell</b></A> : I would remove anything by using Add/Remove Programs and removing the app that put it there .. *NOT* by using HijackThis .. were I you.<br><br>I'm no expert, but your HJT logs look OK to me. Looks like you have EarthLink as Start Page and you use NAV.  I'm curious what this "redirector" from "presario.net" is:<br><br>&raquo;<A HREF="http://search.presario.net/scripts/redirectors/presario/srchredir.dll?c=3c99&s=consumer&LC=0409" >search.presario.net/scripts/redi&middot;&middot;&middot;&LC=0409</A><br><br>but other than that I don't see much out of the ordinary. ;)<br><SMALL>--<br><I>"But now abide faith, hope, love, these three; but the greatest of these is love." (1 Cor. 13:13)</I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8814613</guid>
<pubDate>Wed, 17 Dec 2003 14:50:30 EDT</pubDate>
</item>

<item>
<title>Re: Help: My HiJack Results...</title>
<link>http://www.dslreports.com/forum/remark,8814611</link>
<description><![CDATA[<A HREF="/useremail/u/156829"><b>Paul928</b></A> : you might be better of posting this into the security forum....There's some super knowledgeable people over there.....good luck :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8814611</guid>
<pubDate>Wed, 17 Dec 2003 14:50:15 EDT</pubDate>
</item>

<item>
<title>Help: My HiJack Results...</title>
<link>http://www.dslreports.com/forum/remark,8814266</link>
<description><![CDATA[<A HREF="/useremail/u/903320"><b>Xarcell</b></A> : Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\Documents and Settings\Default\My Documents\My Briefcase\HijackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://www.earthlink.net/partner/more/msie/button/search.html" >www.earthlink.net/partner/more/m&middot;&middot;&middot;rch.html</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://www.earthlink.net/partner/more/msie/button/search.html" >www.earthlink.net/partner/more/m&middot;&middot;&middot;rch.html</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://start.earthlink.net/" >start.earthlink.net/</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://start.earthlink.net/" >start.earthlink.net/</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://www.earthlink.net/partner/more/msie/button/search.html" >www.earthlink.net/partner/more/m&middot;&middot;&middot;rch.html</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://search.presario.net/scripts/redirectors/presario/srchredir.dll?c=3c99&s=consumer&LC=0409" >search.presario.net/scripts/redi&middot;&middot;&middot;&LC=0409</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://search.presario.net/scripts/redirectors/presario/srchredir.dll?c=3c99&s=searchbar&LC=0409" >search.presario.net/scripts/redi&middot;&middot;&middot;&LC=0409</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://search.presario.net/scripts/redirectors/presario/srchredir.dll?c=3c99&s=search&LC=0409" >search.presario.net/scripts/redi&middot;&middot;&middot;&LC=0409</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://desktop.presario.net/scripts/redirectors/presario/deskredir.dll?s=consumer&LC=0409&c=3c99" >desktop.presario.net/scripts/red&middot;&middot;&middot;9&c=3c99</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &raquo;<A HREF="http://www.earthlink.net/partner/more/msie/button/search.html" >www.earthlink.net/partner/more/m&middot;&middot;&middot;rch.html</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer<br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm<br>O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll<br>O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx<br>O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll<br>O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present<br>O8 - Extra context menu item: AltaVista Home - &raquo;<A HREF="http://jump.altavista.com/avie5/home" >jump.altavista.com/avie5/home</A><br>O8 - Extra context menu item: AV Search This Term - &raquo;<A HREF="http://jump.altavista.com/avie5/search" >jump.altavista.com/avie5/search</A><br>O8 - Extra context menu item: AV Translate Selection - &raquo;<A HREF="http://jump.altavista.com/avie5/babelfish" >jump.altavista.com/avie5/babelfish</A><br>O8 - Extra context menu item: AV Translate this Web Page - &raquo;<A HREF="http://jump.altavista.com/avie5/babelfish" >jump.altavista.com/avie5/babelfish</A><br>O9 - Extra 'Tools' menuitem: &AltaVista Home (HKLM)<br>O9 - Extra 'Tools' menuitem: &Find Pages Linking to this URL (HKLM)<br>O9 - Extra 'Tools' menuitem: Find Other Pages on this &Host (HKLM)<br>O9 - Extra button: Translate (HKLM)<br>O9 - Extra 'Tools' menuitem: AV &Translate (HKLM)<br>O16 - DPF: {5721FA68-5ABD-40A8-81F1-4136691194BF} (Launcher Class) - &raquo;<small>https</small>://<A HREF="https://www.play.net/components/activex/AXSAL.ocx">www.play.net/components/activex/AXSAL.ocx</A><br>O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - &raquo;<A HREF="http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37971.586412037" >v4.windowsupdate.microsoft.com/C&middot;&middot;&middot;86412037</A><br>O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &raquo;<A HREF="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab" >download.macromedia.com/pub/shoc&middot;&middot;&middot;lash.cab</A><br><br>--------------------------------------------><br><br>See anything I can safely remove?<br><br>I was thinking those "extra tools", extra context menu items", and "extra button ones" could be removed, along with the "presario" ones.<br><br>What ya think?<br><br>-Xarcell]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8814266</guid>
<pubDate>Wed, 17 Dec 2003 14:10:48 EDT</pubDate>
</item>

</channel>
</rss>
