<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>HJT Log yupsearch/elitetoolbar in Security</title>
<link>http://www.dslreports.com/forum/r13013120</link>
<description></description>
<language>en</language>
<pubDate>Fri, 27 Nov 2009 16:21:25 EDT</pubDate>
<lastBuildDate>Fri, 27 Nov 2009 16:21:25 EDT</lastBuildDate>

<item>
<title>Re: HJT Log yupsearch/elitetoolbar</title>
<link>http://www.dslreports.com/forum/remark,13017148</link>
<description><![CDATA[<A HREF="/useremail/u/467921"><b>MapleLeaf</b></A> : You are not done yet. There is at least one Elitebar component left:<br><br>O4 - HKLM\..\Run: [etbrun] C:\windows\system32\elitesul32.exe<br><br>You know, things are just a bit slow here because of holidays. Would you like to start a fresh thread with HijackThis log and include link in it to this current thread? It might get better attention from <B>real experts</B>.<br><SMALL>--<br>Remember, I'm pulling for you - we are all in this together...</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13017148</guid>
<pubDate>Sun, 27 Mar 2005 11:35:28 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log yupsearch/elitetoolbar</title>
<link>http://www.dslreports.com/forum/remark,13017092</link>
<description><![CDATA[<A HREF="/useremail/u/540034"><b>fadort</b></A> : seems that right now all is fine but if anyone can find a problem with my highjackthis log please let me know..... I don't want this thing to creep up on me again<br>I fixed everything in safemode....... I ran every protection program I had. <br>Everyone of them that was suggested in that help thread.<br><br>Logfile of HijackThis v1.99.1<br>Scan saved at 11:25:51 AM, on 3/27/2005<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\csrss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\Ati2evxx.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Sygate\SPF\smc.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\system32\Ati2evxx.exe<br>C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\Symantec AntiVirus\DefWatch.exe<br>C:\WINDOWS\System32\oodag.exe<br>C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br>C:\WINDOWS\System32\alg.exe<br>C:\WINDOWS\system32\taskmgr.exe<br>C:\Program Files\DU Meter\DUMeter.exe<br>C:\WINDOWS\DELLMMKB.EXE<br>C:\WINDOWS\System32\ezSP_Px.exe<br>C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br>C:\Program Files\D-Tools\daemon.exe<br>C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe<br>C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE<br>C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe<br>C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe<br>C:\PROGRA~1\SYMANT~1\vptray.exe<br>C:\Program Files\Microsoft Hardware\Mouse\point32.exe<br>C:\WINDOWS\system32\tbctray.exe<br>C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>C:\Program Files\Eraser\eraser.exe<br>C:\Program Files\Netropa\OSD.exe<br>C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe<br>C:\Program Files\MRU-Blaster\scheduler.exe<br>C:\Program Files\SpywareGuard\sgmain.exe<br>C:\Program Files\SpywareGuard\sgbhp.exe<br>C:\PROGRA~1\PopUpCop\PCCloser.exe<br>C:\Program Files\Trillian\trillian.exe<br>C:\nnscript\mirc.exe<br>C:\Documents and Settings\Smokey\Desktop\ThunderMule Kademlia\emule.exe<br>C:\Program Files\Serv-U\ServUAdmin.exe<br>C:\Program Files\Serv-U\ServUDaemon.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\Program Files\Serv-U\ServUTray.exe<br>C:\jackthis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.optonline.net/" >www.optonline.net/</A><br>O1 - Hosts: comments (such as these) may be inserted on individual<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll<br>O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll<br>O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O3 - Toolbar: PopUpCop - {DB43E4E6-FF8A-4018-8C8E-F68587A44A73} - C:\PROGRA~1\PopUpCop\PopUpCop.dll<br>O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe<br>O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br>O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE<br>O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe<br>O4 - HKLM\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe<br>O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe<br>O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers<br>O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL<br>O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033<br>O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [mmtask] C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe<br>O4 - HKLM\..\Run: [ATIPTA] C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe<br>O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe<br>O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\\vptray.exe<br>O4 - HKLM\..\Run: [POINTER] point32.exe<br>O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui<br>O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.0\THGuard.exe"<br>O4 - HKLM\..\Run: [TraySantaCruz] C:\WINDOWS\system32\tbctray.exe<br>O4 - HKLM\..\Run: [etbrun] C:\windows\system32\elitesul32.exe<br>O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl<br>O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h<br>O4 - HKCU\..\Run: [ProtoWall] C:\Program Files\Dudez\ProtoWall\ProtoWall.exe<br>O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe"<br>O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide<br>O4 - HKCU\..\Run: [iolo System Mechanic Utility Bar] "C:\Program Files\iolo\System Mechanic 4 Professional\SMUtilityBar.exe"<br>O4 - HKCU\..\Run: [ServUTrayIcon] C:\Program Files\Serv-U\ServUTray.exe<br>O4 - Startup: MRU-Blaster Scheduler.lnk = C:\Program Files\MRU-Blaster\scheduler.exe<br>O4 - Startup: MRU-Blaster Silent Clean.lnk = C:\Program Files\MRU-Blaster\mrublaster.exe<br>O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe<br>O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\Sony Handheld\HOTSYNC.EXE<br>O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe<br>O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present<br>O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present<br>O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm<br>O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm<br>O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm<br>O8 - Extra context menu item: Open Image in New Window - res://C:\PROGRA~1\PopUpCop\popupcop.dll/imagenew<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll<br>O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL<br>O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll<br>O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll<br>O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe<br>O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe<br>O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O15 - Trusted Zone: &raquo;<A HREF="http://Download.Windowsupdate.com" >Download.Windowsupdate.com</A><br>O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - &raquo;<A HREF="http://support.dell.com/systemprofiler/SysPro.CAB" >support.dell.com/systemprofiler/SysPro.CAB</A><br>O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} (WildTangent Active Launcher) - &raquo;<A HREF="http://install.wildtangent.com/ActiveLauncher/ActiveLauncher.cab" >install.wildtangent.com/ActiveLa&middot;&middot;&middot;cher.cab</A><br>O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - &raquo;<A HREF="http://a1540.g.akamai.net/7/1540/52/20031010/qtinstall.info.apple.com/mickey/us/win/QuickTimeFullInstaller.exe" >a1540.g.akamai.net/7/1540/52/200&middot;&middot;&middot;ller.exe</A><br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093063891894" >v5.windowsupdate.microsoft.com/v&middot;&middot;&middot;63891894</A><br>O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - &raquo;<A HREF="http://www.gamespot.com/KDX/kdx.cab" >www.gamespot.com/KDX/kdx.cab</A><br>O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll<br>O23 - Service: Apache - Unknown owner - C:\Program Files\Apache Group\Apache\Apache.exe" --ntservice (file missing)<br>O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br>O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe<br>O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe<br>O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe<br>O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\System32\oodag.exe<br>O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe<br>O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe<br>O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13017092</guid>
<pubDate>Sun, 27 Mar 2005 11:25:21 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log yupsearch/elitetoolbar</title>
<link>http://www.dslreports.com/forum/remark,13014235</link>
<description><![CDATA[<A HREF="/useremail/u/1058986"><b>PageTurner</b></A> : I found this on the net. The creator of the proggie also will answer questions in a forum linked to the page. It is also available at Major Geeks.  <br><br>I can't comment on the proggie as I have never used it. <br><br>&raquo;<A HREF="http://www.simplytech.it/ETRemover/" >www.simplytech.it/ETRemover/</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13014235</guid>
<pubDate>Sat, 26 Mar 2005 22:28:40 EDT</pubDate>
</item>

<item>
<title>Re: yupsearch/elitetoolbar</title>
<link>http://www.dslreports.com/forum/remark,13013315</link>
<description><![CDATA[<A HREF="/useremail/u/795407"><b>SnowyOne</b></A> : It must have been one of these whatnots <br>1.CWShredder<br>2.About:Buster<br>3.Spybot S&D<br>4.AdAware<br>in the &raquo;<A HREF="/faq/security">Security</A> &raquo;<A HREF="/faq/8428">I think my computer is infected or hijacked. What should I do?</A><br>that cleaned it up :)<br>It's one of the finest resources on the net<br><br>EDIT the FAQ offers the advice of running these tools in safemode. It will take care of the popup issue while your running them.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13013315</guid>
<pubDate>Sat, 26 Mar 2005 20:08:44 EDT</pubDate>
</item>

<item>
<title>Re: yupsearch/elitetoolbar</title>
<link>http://www.dslreports.com/forum/remark,13013304</link>
<description><![CDATA[<A HREF="/useremail/u/540034"><b>fadort</b></A> : no trojan hunters still hunting..... I just ment I fixed the highjackthis posting problem (got newer version, moved location)<br><br>I still have the issue.... I deleted some of the registry entries that symantic said but it tried to add them back again but I had spybot not allow it.<br><br>then some of them weren't even where they were supposed to be so I dunno..... <br>if anyone knows off hand if anything can be fixed with highjackthis let me know...<br><br>I'm going to try running all of these protection programs...... hard to do stuff when popups keep just showing up all the time.<br><br>thanks for the help......]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13013304</guid>
<pubDate>Sat, 26 Mar 2005 20:07:18 EDT</pubDate>
</item>

<item>
<title>Re: yupsearch/elitetoolbar</title>
<link>http://www.dslreports.com/forum/remark,13013286</link>
<description><![CDATA[<A HREF="/useremail/u/1110758"><b>spooler0</b></A> : <div class="bquote"><SMALL>said by  fadort <A HREF="/useremail/u/540034"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><BR><BR>ok used newest and what not. </DIV>So everything is clean now, no?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13013286</guid>
<pubDate>Sat, 26 Mar 2005 20:03:48 EDT</pubDate>
</item>

<item>
<title>Re: yupsearch/elitetoolbar</title>
<link>http://www.dslreports.com/forum/remark,13013235</link>
<description><![CDATA[<A HREF="/useremail/u/540034"><b>fadort</b></A> : ok used newest and what not.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13013235</guid>
<pubDate>Sat, 26 Mar 2005 19:56:24 EDT</pubDate>
</item>

<item>
<title>Re: yupsearch/elitetoolbar</title>
<link>http://www.dslreports.com/forum/remark,13013173</link>
<description><![CDATA[<A HREF="/useremail/u/1173110"><b>sheiny</b></A> : &raquo;<A HREF="http://securityresponse.symantec.com/avcenter/venc/data/adware.elitebar.html" >securityresponse.symantec.com/av&middot;&middot;&middot;bar.html</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13013173</guid>
<pubDate>Sat, 26 Mar 2005 19:48:11 EDT</pubDate>
</item>

<item>
<title>Re: yupsearch/elitetoolbar</title>
<link>http://www.dslreports.com/forum/remark,13013165</link>
<description><![CDATA[<A HREF="/useremail/u/467921"><b>MapleLeaf</b></A> : &#8226;You need the latest <A HREF="http://www.spywareinfo.com/~merijn/index.html">HijackThis 1.99.1</A><br>&#8226;Go through steps described here: &raquo;<A HREF="/faq/security">Security</A> &raquo;<A HREF="/faq/8428">I think my computer is infected or hijacked. What should I do?</A> prior to posting HilackThis log<br>&#8226;Make a folder for HilackThis, don't run it from desktop<br><SMALL>--<br>Remember, I'm pulling for you - we are all in this together...</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13013165</guid>
<pubDate>Sat, 26 Mar 2005 19:47:21 EDT</pubDate>
</item>

<item>
<title>HJT Log yupsearch/elitetoolbar</title>
<link>http://www.dslreports.com/forum/remark,13013120</link>
<description><![CDATA[<A HREF="/useremail/u/540034"><b>fadort</b></A> : I have a problem with that........... real bad<br>seems theres some popups....... messed up my homepage..... for a while I couldn't even open up internet explorer.<br>here's my highjackthis log..... hopefully someone can help.<br>Everything I've tried has failed to help..... I have trojanhunter running right now<br><br>Logfile of HijackThis v1.99.1<br>Scan saved at 7:57:11 PM, on 3/26/2005<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\csrss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\Ati2evxx.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Sygate\SPF\smc.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Apache Group\Apache\Apache.exe<br>C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>C:\Program Files\Symantec AntiVirus\DefWatch.exe<br>C:\WINDOWS\System32\oodag.exe<br>C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br>C:\Program Files\Apache Group\Apache\Apache.exe<br>C:\WINDOWS\system32\Ati2evxx.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\System32\alg.exe<br>C:\Program Files\DU Meter\DUMeter.exe<br>C:\WINDOWS\DELLMMKB.EXE<br>C:\WINDOWS\System32\ezSP_Px.exe<br>C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br>C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe<br>C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE<br>C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe<br>C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe<br>C:\PROGRA~1\SYMANT~1\vptray.exe<br>C:\Program Files\Microsoft Hardware\Mouse\point32.exe<br>C:\WINDOWS\system32\tbctray.exe<br>C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>C:\Program Files\Eraser\eraser.exe<br>C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe<br>C:\Program Files\MRU-Blaster\scheduler.exe<br>C:\Program Files\SpywareGuard\sgmain.exe<br>C:\Program Files\Netropa\OSD.exe<br>C:\Program Files\SpywareGuard\sgbhp.exe<br>C:\PROGRA~1\PopUpCop\PCCloser.exe<br>C:\Program Files\TrojanHunter 4.0\TrojanHunter.exe<br>C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe<br>C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\jackthis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.optonline.net/" >www.optonline.net/</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &raquo;<A HREF="http://searchmiracle.com/sp.php" >searchmiracle.com/sp.php</A><br>O1 - Hosts: comments (such as these) may be inserted on individual<br>O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\ELITET~1\ELITET~2.DLL<br>O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe<br>O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br>O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE<br>O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe<br>O4 - HKLM\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe<br>O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe<br>O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers<br>O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL<br>O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033<br>O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [mmtask] C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe<br>O4 - HKLM\..\Run: [ATIPTA] C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe<br>O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe<br>O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\\vptray.exe<br>O4 - HKLM\..\Run: [POINTER] point32.exe<br>O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui<br>O4 - HKLM\..\Run: [etbrun] C:\windows\system32\elitesul32.exe<br>O4 - HKLM\..\Run: [TraySantaCruz] C:\WINDOWS\system32\tbctray.exe<br>O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.0\THGuard.exe"<br>O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl<br>O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h<br>O4 - HKCU\..\Run: [ProtoWall] C:\Program Files\Dudez\ProtoWall\ProtoWall.exe<br>O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe"<br>O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide<br>O4 - HKCU\..\Run: [iolo System Mechanic Utility Bar] "C:\Program Files\iolo\System Mechanic 4 Professional\SMUtilityBar.exe"<br>O4 - Startup: MRU-Blaster Scheduler.lnk = C:\Program Files\MRU-Blaster\scheduler.exe<br>O4 - Startup: MRU-Blaster Silent Clean.lnk = C:\Program Files\MRU-Blaster\mrublaster.exe<br>O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe<br>O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\Sony Handheld\HOTSYNC.EXE<br>O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe<br>O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present<br>O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present<br>O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm<br>O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm<br>O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm<br>O8 - Extra context menu item: Open Image in New Window - res://C:\PROGRA~1\PopUpCop\popupcop.dll/imagenew<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll<br>O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL<br>O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll<br>O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll<br>O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe<br>O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe<br>O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe<br>O9 - Extra button: (no name) - {E9173ECA-1F4F-41ed-AF1F-8F723DFE3458} - C:\Documents and Settings\Smokey\Local Settings\Temporary Internet Files\Content.IE5\8PIR8TAV\access[1].exe (file missing)<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra button: (no name) - {E9173ECA-1F4F-41ed-AF1F-8F723DFE3458} - C:\Documents and Settings\Smokey\Local Settings\Temporary Internet Files\Content.IE5\8PIR8TAV\access[1].exe (file missing) (HKCU)<br>O15 - Trusted Zone: &raquo;<A HREF="http://Download.Windowsupdate.com" >Download.Windowsupdate.com</A><br>O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - &raquo;<A HREF="http://support.dell.com/systemprofiler/SysPro.CAB" >support.dell.com/systemprofiler/SysPro.CAB</A><br>O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} (WildTangent Active Launcher) - &raquo;<A HREF="http://install.wildtangent.com/ActiveLauncher/ActiveLauncher.cab" >install.wildtangent.com/ActiveLa&middot;&middot;&middot;cher.cab</A><br>O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - &raquo;<A HREF="http://a1540.g.akamai.net/7/1540/52/20031010/qtinstall.info.apple.com/mickey/us/win/QuickTimeFullInstaller.exe" >a1540.g.akamai.net/7/1540/52/200&middot;&middot;&middot;ller.exe</A><br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093063891894" >v5.windowsupdate.microsoft.com/v&middot;&middot;&middot;63891894</A><br>O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - &raquo;<A HREF="http://www.gamespot.com/KDX/kdx.cab" >www.gamespot.com/KDX/kdx.cab</A><br>O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll<br>O23 - Service: Apache - Unknown owner - C:\Program Files\Apache Group\Apache\Apache.exe" --ntservice (file missing)<br>O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br>O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe<br>O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe<br>O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe<br>O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\System32\oodag.exe<br>O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe<br>O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe<br>O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13013120</guid>
<pubDate>Sat, 26 Mar 2005 19:40:21 EDT</pubDate>
</item>

</channel>
</rss>
