<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>I&#x27;m hijacked? in Security</title>
<link>http://www.dslreports.com/forum/r10681380</link>
<description></description>
<language>en</language>
<pubDate>Wed, 25 Nov 2009 02:44:11 EDT</pubDate>
<lastBuildDate>Wed, 25 Nov 2009 02:44:11 EDT</lastBuildDate>

<item>
<title>Re: I&#x27;m hijacked?</title>
<link>http://www.dslreports.com/forum/remark,10687723</link>
<description><![CDATA[<A HREF="/useremail/u/1030204"><b>NetFixer</b></A> : If you had actually gone to the link <A HREF="http://www.dslreports.com/faq/8428">I think my computer is infected or hijacked. What should I do?</A> and followed the instructions including going to the link <A HREF="http://www.dslreports.com/faq/9721#scan">Go to web based AV scanners</A>, the link at the top of the list &raquo;<A HREF="http://housecall.trendmicro.com/" >housecall.trendmicro.com/</A> should have told you that 'C:\WINDOWS\System32\smss32.exe' was WORM_SPYBOT.FE as was pointed out by John2g. If you do not follow <B>ALL</B> of the steps, it wastes everyone's time.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10687723</guid>
<pubDate>Sun, 04 Jul 2004 14:58:24 EDT</pubDate>
</item>

<item>
<title>Re: I&#x27;m hijacked?</title>
<link>http://www.dslreports.com/forum/remark,10685272</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> : I would run this free AV first<br>&raquo;<A HREF="http://www.mwti.net/antivirus/free_utilities.asp" >www.mwti.net/antivirus/free_utilities.asp</A><br><br>Make sure that the resident protection in your current AV (Symantec) is <B>disabled</B> first.<br><SMALL>--<br>Better to remain silent and be thought a fool, than to speak and remove all doubt.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10685272</guid>
<pubDate>Sun, 04 Jul 2004 05:03:29 EDT</pubDate>
</item>

<item>
<title>Re: I&#x27;m hijacked?</title>
<link>http://www.dslreports.com/forum/remark,10685268</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> : It might pay you to read this<br><br>&raquo;<A HREF="http://be.trendmicro-europe.com/enterprise/security_info/ve_detail.php?id=59817&VName=WORM_SPYBOT.FE&VSect=T" >be.trendmicro-europe.com/enterpr&middot;&middot;&middot;&VSect=T</A><br><SMALL>--<br>Better to remain silent and be thought a fool, than to speak and remove all doubt.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10685268</guid>
<pubDate>Sun, 04 Jul 2004 05:00:37 EDT</pubDate>
</item>

<item>
<title>Re: I&#x27;m hijacked?</title>
<link>http://www.dslreports.com/forum/remark,10685261</link>
<description><![CDATA[<A HREF="/useremail/u/608382"><b>paranoidxe</b></A> : You may or may not be hijacked, but you do have malware on that machine. Download and run Lavasoft Adaware and Spybot..fix what it finds.<br><SMALL>--<br>"Its better to look stupid for 5 minutes and ask a question, than to be stupid for the rest of your life."4g63.20m.com (textsource.org)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10685261</guid>
<pubDate>Sun, 04 Jul 2004 04:54:52 EDT</pubDate>
</item>

<item>
<title>Re: I&#x27;m hijacked?</title>
<link>http://www.dslreports.com/forum/remark,10685242</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> : You didn't use the latest version of HJT. It is here.<br>&raquo;<A HREF="/forum/remark,10670870~mode=flat">HijackThis 1.98.0 - Hotfix Build</A><br><SMALL>--<br>Better to remain silent and be thought a fool, than to speak and remove all doubt.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10685242</guid>
<pubDate>Sun, 04 Jul 2004 04:43:31 EDT</pubDate>
</item>

<item>
<title>Re: I&#x27;m hijacked?</title>
<link>http://www.dslreports.com/forum/remark,10681783</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Okay, here's the contents of the<br>HJT Logfile.<br><br>I've downloaded and followed exactly<br>the contents of www.dslreports.clm/faq/8428<br>"I think my computer is infected or hijacked.<br>What should I do?"<br><br>See original post regarding the AV, AT, AS<br>programs already DL'd, updated, run.<br><br>Thanks for all the suggestions:  (sorry <br>for post length)<br><br>Logfile of HijackThis v1.98.0<br>Scan saved at 1:25:09 PM, on 7/3/2004<br>Platform: Windows XP SP1 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE<br>C:\WINDOWS\system32\crypserv.exe<br>C:\WINDOWS\System32\DVDRAMSV.exe<br>C:\WINDOWS\System32\GEARSEC.EXE<br>C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe<br>C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br>C:\WINDOWS\System32\00THotkey.exe<br>C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe<br>C:\Program Files\Apoint2K\Apoint.exe<br>C:\Program Files\ltmoh\Ltmoh.exe<br>C:\WINDOWS\System32\TPWRTRAY.EXE<br>C:\Program Files\TOSHIBA\TouchED\TouchED.Exe<br>C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe<br>C:\Program Files\Toshiba\ConfigFree\NDSTray.exe<br>C:\WINDOWS\System32\TFNF5.exe<br>C:\WINDOWS\System32\EZSP_PX.EXE<br>C:\toshiba\sysstability\tsyssmon.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\Program Files\QuickTime\qttask.exe<br>C:\Program Files\AIM\aim.exe<br>C:\Program Files\MSN Messenger\msnmsgr.exe<br>C:\Program Files\Yahoo!\Messenger\ypager.exe<br>C:\Program Files\Intuit\QuickBooks Basic\Components\QBAgent\qbdagent2002.exe<br>C:\Program Files\Apoint2K\Apntex.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>C:\Program Files\MSN\MSNCoreFiles\msn6.exe<br>C:\WINDOWS\System32\smss32.exe<br>C:\Program Files\Messenger\msmsgs.exe<br>E:\Spy killer\hijackthis\HijackThis.exe<br><br>F0 - system.ini: Shell=<br>F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,<br>O1 - Hosts: 64.91.255.87 www.dcsresearch.com<br>O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx<br>O2 - BHO: CSMHelperObj Class - {0F660F64-F4C9-477F-8529-44181B717472} - C:\Program Files\AT&T\WnClient\Programs\CSMBHO.dll<br>O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll<br>O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx<br>O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll<br>O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll<br>O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"<br>O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe<br>O4 - HKLM\..\Run: [PmProxy] C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe<br>O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe<br>O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe<br>O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE<br>O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe<br>O4 - HKLM\..\Run: [TFncKy] TFncKy.exe /Type 28<br>O4 - HKLM\..\Run: [NDSTray.exe] "C:\Program Files\Toshiba\ConfigFree\NDSTray.exe"<br>O4 - HKLM\..\Run: [TFNF5] TFNF5.exe<br>O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\EZSP_PX.EXE<br>O4 - HKLM\..\Run: [TSysSMon] c:\toshiba\sysstability\tsyssmon.exe /detect<br>O4 - HKLM\..\Run: [NAV CfgWiz] C:\PROGRA~1\NORTON~1\Cfgwiz.exe /R<br>O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [Microsoft Update] smss32.exe<br>O4 - HKLM\..\RunServices: [Microsoft Update] smss32.exe<br>O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl<br>O4 - HKCU\..\Run: [Microsoft Update] smss32.exe<br>O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background<br>O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet<br>O4 - Global Startup: QuickBooks 2002 Delivery Agent.lnk = C:\Program Files\Intuit\QuickBooks Basic\Components\QBAgent\qbdagent2002.exe<br>O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm<br>O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm<br>O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm<br>O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - (no file)<br>O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - (no file)<br>O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe<br>O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll<br>O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dll<br>O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - &raquo;<A HREF="http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab" >us.dl1.yimg.com/download.yahoo.c&middot;&middot;&middot;lete.cab</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10681783</guid>
<pubDate>Sat, 03 Jul 2004 18:27:40 EDT</pubDate>
</item>

<item>
<title>Re: I&#x27;m hijacked?</title>
<link>http://www.dslreports.com/forum/remark,10681622</link>
<description><![CDATA[<A HREF="/useremail/u/731068"><b>Sparrow</b></A> : You need to read through &raquo;<A HREF="/faq/security">Security</A> &raquo;<A HREF="/faq/8428">I think my computer is infected or hijacked. What should I do?</A><br><br>The FAQ explains all the steps leading to posting a HJT log. Please follow them in the order they are given, and make sure to update any utilities you run. It's a long list, but it should help you. :)<br><SMALL>--<br> <A HREF="/faq/security">Security Forum FAQs</A> .. &hearts; .. <A HREF="http://tinyurl.com/2o6fw">"Raj karega Khalsa!"</A> .. &hearts; .. <A HREF="/forum/seti">Starfire "5 in 4"</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10681622</guid>
<pubDate>Sat, 03 Jul 2004 18:00:51 EDT</pubDate>
</item>

<item>
<title>Re: I&#x27;m hijacked?</title>
<link>http://www.dslreports.com/forum/remark,10681585</link>
<description><![CDATA[<A HREF="/useremail/u/1030204"><b>NetFixer</b></A> : Your attachment is the HijackThis executable, not the log file. Next time just copy and paste the log contents into your forum post instead of including it as an attachment.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10681585</guid>
<pubDate>Sat, 03 Jul 2004 17:55:42 EDT</pubDate>
</item>

<item>
<title>I&#x27;m hijacked?</title>
<link>http://www.dslreports.com/forum/remark,10681380</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Every 13-17 minutes I get a pop-up browser screen with<br>the following:  www.pwned.freehomepage.com/pwn.html, then<br>a Security Warning Box from Media Tickets.<br>I have:<br><br>DL, ran CWShredder<br>DL, ran Spybot<br>Update, ran Ad-Aware<br>DL, ran TDS-3<br>DL, ran HJT, attached is log created<br>  by HJT<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap WIDTH=33%><A HREF="/r0/download/623553~4a123d0175762b3d75bb0519784a8b54/hijackthis.zip"><IMG  align=absmiddle TITLE="download" SRC="http://i.dslr.net/silk/compress.png" border=0 width=16 height=16><IMG SRC="http://i.dslr.net/1ptrans.gif" WIDTH=10 HEIGHT=1 border=0><big>hijackthis.zip</big></A> <small>180,933 bytes</small></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10681380</guid>
<pubDate>Sat, 03 Jul 2004 17:22:01 EDT</pubDate>
</item>

</channel>
</rss>
