Hey All,
My office computer has been plagued with two issues, which I think are both related. It started a week ago when I was doing research on a Flash Audio player. This might be the cause or it may not, but it's the first time I became aware of the issue. I was doing research on flash audio players and when I clicked on a link within google, I instantly got to russian porn popups. Of course, me being at work, I shut them down quickly. I certainly don't want to get in trouble with corporate. I thought it was just a random mistake, UNTIL I started noticing it happen on a regular basis even when I would hit normal sites like TIMEX.COM or any popular site. That's when I got IT involved. So far we run Nortan Security, NOTHING, Spybot, STILL GETTING POPUPS. We did notice that my HOST FILE keeps getting rewitten to resemble below, which is the 2nd problem I'm having.
127.0.0.1 go.mail.ru
127.0.0.1 nova.rambler.ru
127.0.0.1 google.ad
127.0.0.1
www.google.ad127.0.0.1 google.ae
127.0.0.1
www.google.ae127.0.0.1 google.am
127.0.0.1
www.google.am127.0.0.1 google.com.ar
127.0.0.1
www.google.com.ar127.0.0.1 google.as
127.0.0.1
www.google.as127.0.0.1 google.at
127.0.0.1
www.google.at127.0.0.1 google.com.au
127.0.0.1
www.google.com.au127.0.0.1 google.az
127.0.0.1
www.google.az127.0.0.1 google.ba
127.0.0.1
www.google.ba127.0.0.1 google.be
127.0.0.1
www.google.be127.0.0.1 google.bg
127.0.0.1
www.google.bg127.0.0.1 google.bs
127.0.0.1
www.google.bs127.0.0.1 google.com.by
127.0.0.1
www.google.com.by127.0.0.1 google.ca
127.0.0.1
www.google.ca127.0.0.1 google.ch
127.0.0.1
www.google.ch127.0.0.1 google.cn
127.0.0.1
www.google.cn127.0.0.1 google.cz
127.0.0.1
www.google.cz127.0.0.1 google.de
127.0.0.1
www.google.de127.0.0.1 google.dk
127.0.0.1
www.google.dk127.0.0.1 google.ee
127.0.0.1
www.google.ee127.0.0.1 google.es
127.0.0.1
www.google.es127.0.0.1 google.fi
127.0.0.1
www.google.fi127.0.0.1 google.fr
127.0.0.1
www.google.fr127.0.0.1 google.gr
127.0.0.1
www.google.gr127.0.0.1 google.com.hk
127.0.0.1
www.google.com.hk127.0.0.1 google.hr
127.0.0.1
www.google.hr127.0.0.1 google.hu
127.0.0.1
www.google.hu127.0.0.1 google.ie
127.0.0.1
www.google.ie127.0.0.1 google.co.il
127.0.0.1
www.google.co.il127.0.0.1 google.co.in
127.0.0.1
www.google.co.in127.0.0.1 google.is
127.0.0.1
www.google.is127.0.0.1 google.it
127.0.0.1
www.google.it127.0.0.1 google.co.jp
127.0.0.1
www.google.co.jp127.0.0.1 google.kg
127.0.0.1
www.google.kg127.0.0.1 google.co.kr
127.0.0.1
www.google.co.kr127.0.0.1 google.li
127.0.0.1
www.google.li127.0.0.1 google.lt
127.0.0.1
www.google.lt127.0.0.1 google.lu
127.0.0.1
www.google.lu127.0.0.1 google.lv
127.0.0.1
www.google.lv127.0.0.1 google.md
127.0.0.1
www.google.md127.0.0.1 google.com.mx
127.0.0.1
www.google.com.mx127.0.0.1 google.nl
127.0.0.1
www.google.nl127.0.0.1 google.no
127.0.0.1
www.google.no127.0.0.1 google.co.nz
127.0.0.1
www.google.co.nz127.0.0.1 google.com.pe
127.0.0.1
www.google.com.pe127.0.0.1 google.com.ph
127.0.0.1
www.google.com.ph127.0.0.1 google.pl
127.0.0.1
www.google.pl127.0.0.1 google.pt
127.0.0.1
www.google.pt127.0.0.1 google.ro
127.0.0.1
www.google.ro127.0.0.1 google.ru
127.0.0.1
www.google.ru127.0.0.1 google.com.ru
127.0.0.1
www.google.com.ru127.0.0.1 google.com.sa
127.0.0.1
www.google.com.sa127.0.0.1 google.se
127.0.0.1
www.google.se127.0.0.1 google.com.sg
127.0.0.1
www.google.com.sg127.0.0.1 google.si
127.0.0.1
www.google.si127.0.0.1 google.sk
127.0.0.1
www.google.sk127.0.0.1 google.co.th
127.0.0.1
www.google.co.th127.0.0.1 google.com.tj
127.0.0.1
www.google.com.tj127.0.0.1 google.tm
127.0.0.1
www.google.tm127.0.0.1 google.com.tr
127.0.0.1
www.google.com.tr127.0.0.1 google.com.tw
127.0.0.1
www.google.com.tw127.0.0.1 google.com.ua
127.0.0.1
www.google.com.ua127.0.0.1 google.co.uk
127.0.0.1
www.google.co.uk127.0.0.1 google.co.vi
127.0.0.1
www.google.co.vi127.0.0.1 google.com
127.0.0.1
www.google.com127.0.0.1 google.us
127.0.0.1
www.google.us127.0.0.1 google.com.pl
127.0.0.1
www.google.com.pl127.0.0.1 google.co.hu
127.0.0.1
www.google.co.hu127.0.0.1 google.ge
127.0.0.1
www.google.ge127.0.0.1 google.kz
127.0.0.1
www.google.kz127.0.0.1 google.co.uz
127.0.0.1
www.google.co.uz127.0.0.1
www.bing.com127.0.0.1 search.yahoo.com
127.0.0.1 ca.search.yahoo.com
127.0.0.1 ar.search.yahoo.com
127.0.0.1 cl.search.yahoo.com
127.0.0.1 co.search.yahoo.com
127.0.0.1 mx.search.yahoo.com
127.0.0.1 espanol.search.yahoo.com
127.0.0.1 qc.search.yahoo.com
127.0.0.1 ve.search.yahoo.com
127.0.0.1 pe.search.yahoo.com
127.0.0.1 at.search.yahoo.com
127.0.0.1 ct.search.yahoo.com
127.0.0.1 dk.search.yahoo.com
127.0.0.1 fi.search.yahoo.com
127.0.0.1 fr.search.yahoo.com
127.0.0.1 de.search.yahoo.com
127.0.0.1 it.search.yahoo.com
127.0.0.1 nl.search.yahoo.com
127.0.0.1 no.search.yahoo.com
127.0.0.1 ru.search.yahoo.com
127.0.0.1 es.search.yahoo.com
127.0.0.1 se.search.yahoo.com
127.0.0.1 ch.search.yahoo.com
127.0.0.1 uk.search.yahoo.com
127.0.0.1 asia.search.yahoo.com
127.0.0.1 au.search.yahoo.com
127.0.0.1 one.cn.yahoo.com
127.0.0.1 hk.search.yahoo.com
127.0.0.1 in.search.yahoo.com
127.0.0.1 id.search.yahoo.com
127.0.0.1 search.yahoo.co.jp
127.0.0.1 kr.search.yahoo.com
127.0.0.1 malaysia.search.yahoo.com
127.0.0.1 nz.search.yahoo.com
127.0.0.1 ph.search.yahoo.com
127.0.0.1 sg.search.yahoo.com
127.0.0.1 tw.search.yahoo.com
127.0.0.1 th.search.yahoo.com
127.0.0.1 vn.search.yahoo.com
127.0.0.1 images.google.com
127.0.0.1 images.google.ca
127.0.0.1 images.google.co.uk
127.0.0.1 news.google.com
127.0.0.1 news.google.ca
127.0.0.1 news.google.co.uk
127.0.0.1 video.google.com
127.0.0.1 video.google.ca
127.0.0.1 video.google.co.uk
127.0.0.1 blogsearch.google.com
127.0.0.1 blogsearch.google.ca
127.0.0.1 blogsearch.google.co.uk
127.0.0.1 searchservice.myspace.com
127.0.0.1 ask.com
127.0.0.1
www.ask.com127.0.0.1 search.aol.com
127.0.0.1 search.netscape.com
127.0.0.1 yandex.ru
127.0.0.1
www.yandex.ru127.0.0.1 yandex.ua
127.0.0.1
www.yandex.ua127.0.0.1 search.about.com
127.0.0.1
www.verizon.net127.0.0.1 verizon.net
We've tried to save over it, delete it but it keeps coming back. Strangely this is causing all sorts of issues.
Example: when I try to go to google images, all I get is a blank page. We did a Tracert to google images, and it looks like it's rerouting to
127.0.0.1 go.mail.ru . Strange.
Anyway, anybody have an idea of what this might be? IT's solution of couse is to give me a new computer, but I'd rather not have to go through the headache of it, if I can just fix the problem.
Here is my HIJACKTHIS log... (anything look suspicious?)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:39:49 AM, on 9/10/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\Ati2ev
xx.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
iceService
.exe
C:\Program Files\Bonjour\mDNSResponde
r.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\LANDesk\LDClient\Loc
alSch.EXE
C:\WINDOWS\system32\CBA\pd
s.exe
C:\Program Files\LANDesk\LDClient\tmc
svc.exe
C:\PROGRA~1\LANDesk\LDClie
nt\issuser
.exe
C:\Program Files\Java\jre6\bin\jqs.ex
e
C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessServ
ice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\PROGRA~1\LANDesk\LDClie
nt\collect
or.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\LANDesk\LDClie
nt\LDregwa
tch.exe
C:\WINDOWS\system32\svchos
t.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Viewpoint\Common\Vie
wpointServ
ice.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Documents and Settings\All Users\Application Data\csrss.exe
C:\PROGRA~1\LANDesk\LDClie
nt\rcgui.e
xe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTra
y.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\iTunes\iTunesHelper.
exe
C:\Program Files\Java\jre6\bin\jusche
d.exe
C:\WINDOWS\system32\ctfmon
.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\iPod\bin\iPodService
.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EX
E
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingServ
ice.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Microsoft Office\Office12\EXCEL.EXE
C:\Program Files\LANDesk\Shared Files\residentagent.exe
C:\Program Files\LANDesk\LDClient\pol
icy.client
.invoker.e
xe
C:\Program Files\Adobe\Adobe Photoshop CS3\Photoshop.exe
C:\Program Files\Adobe\Adobe Dreamweaver CS3\Dreamweaver.exe
C:\Program Files\LANDesk\LDClient\sof
tmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\cleanm
gr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\regedit.exe
C:\Program Files\Trend Micro\HijackThis\HijackThi
s.exe
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://google.com/R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Common Files\Adobe\Acrobat\Active
X\AcroIEHe
lper.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C
042949C621
6} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-B
A8D5E23E04
5} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0
445EE16191
0} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
t.dll
O2 - BHO: IE Developer Toolbar BHO - {CC7E636D-39AA-49b6-B511-6
5413DA137A
1} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9
C25C1C588A
9} - C:\Program Files\Java\jre6\bin\jp2ssv
.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-E
ABFE594F69
C} - C:\Program Files\Java\jre6\lib\deploy
\jqs\ie\jq
s_plugin.d
ll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0
819E2EAAC9
3} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
t.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2
B52B6139FC
7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTra
y.exe
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotif
ier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.
exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe
" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusche
d.exe"
O4 - HKLM\..\RunOnce: [WDM_SYSAUDIO] "C:\Program Files\LANDesk\LDClient\sof
tmon.exe" /r rundll32.exe streamci.dll,StreamingDevi
ceSetup {A7C7A5B0-5AF3-11D1-9CED-0
0A024BF040
7},{9B3658
90-165F-11
D0-A195-00
20AFD156E4
},{A7C7A5B
1-5AF3-11D
1-9CED-00A
024BF0407}
,C:\WINDOW
S\INF\WDMA
UDIO.inf,W
DM_SYSAUDI
O.Interfac
e.Install
O4 - HKLM\..\RunOnce: [WDM_DRMKAUD0] "C:\Program Files\LANDesk\LDClient\sof
tmon.exe" /r rundll32.exe streamci,StreamingDeviceSe
tup {EEC12DB6-AD9C-4168-8658-B
03DAEF417F
E},{ABD61E
00-9350-47
e2-A632-44
38B90C6641
},{6994AD0
4-93EF-11D
0-A3CC-00A
0C9223196}
,C:\WINDOW
S\INF\WDMA
UDIO.inf,W
DM_DRMKAUD
.Interface
.Install
O4 - HKLM\..\RunOnce: [WDM_DRMKAUD1] "C:\Program Files\LANDesk\LDClient\sof
tmon.exe" /r rundll32.exe streamci,StreamingDeviceSe
tup {EEC12DB6-AD9C-4168-8658-B
03DAEF417F
E},{ABD61E
00-9350-47
e2-A632-44
38B90C6641
},{2EB07EA
0-7E70-11D
0-A5D6-28D
B04C10000}
,C:\WINDOW
S\INF\WDMA
UDIO.inf,W
DM_DRMKAUD
.Interface
.Install
O4 - HKLM\..\RunOnce: [WDM_DRMKAUD2] "C:\Program Files\LANDesk\LDClient\sof
tmon.exe" /r rundll32.exe streamci,StreamingDeviceSe
tup {EEC12DB6-AD9C-4168-8658-B
03DAEF417F
E},{ABD61E
00-9350-47
e2-A632-44
38B90C6641
},{FFBB6E3
F-CCFE-4D8
4-90D9-421
418B03A8E}
,C:\WINDOW
S\INF\WDMA
UDIO.inf,W
DM_DRMKAUD
.Interface
.Install
O4 - HKLM\..\RunOnce: [WDM_KMIXER0] "C:\Program Files\LANDesk\LDClient\sof
tmon.exe" /r rundll32.exe streamci.dll,StreamingDevi
ceSetup {B7EAFDC0-A680-11D0-96D8-0
0AA0051E51
D},{9B3658
90-165F-11
D0-A195-00
20AFD156E4
},{AD809C0
0-7B88-11D
0-A5D6-28D
B04C10000}
,C:\WINDOW
S\INF\WDMA
UDIO.inf,W
DM_KMIXER.
Interface.
Install
O4 - HKLM\..\RunOnce: [WDM_KMIXER1] "C:\Program Files\LANDesk\LDClient\sof
tmon.exe" /r rundll32.exe streamci.dll,StreamingDevi
ceSetup {B7EAFDC0-A680-11D0-96D8-0
0AA0051E51
D},{9B3658
90-165F-11
D0-A195-00
20AFD156E4
},{6994AD0
4-93EF-11D
0-A3CC-00A
0C9223196}
,C:\WINDOW
S\INF\WDMA
UDIO.inf,W
DM_KMIXER.
Interface.
Install
O4 - HKLM\..\RunOnce: [WDM_AEC0] "C:\Program Files\LANDesk\LDClient\sof
tmon.exe" /r rundll32.exe streamci.dll,StreamingDevi
ceSetup {4245FF73-1DB4-11d2-86E4-9
8AE2052415
3},{9B3658
90-165F-11
D0-A195-00
20AFD156E4
},{2EB07EA
0-7E70-11D
0-A5D6-28D
B04C10000}
,C:\WINDOW
S\INF\WDMA
UDIO.inf,W
DM_AEC.Int
erface.Ins
tall
O4 - HKLM\..\RunOnce: [WDM_AEC1] "C:\Program Files\LANDesk\LDClient\sof
tmon.exe" /r rundll32.exe streamci.dll,StreamingDevi
ceSetup {4245FF73-1DB4-11d2-86E4-9
8AE2052415
3},{9B3658
90-165F-11
D0-A195-00
20AFD156E4
},{6994AD0
4-93EF-11D
0-A3CC-00A
0C9223196}
,C:\WINDOW
S\INF\WDMA
UDIO.inf,W
DM_AEC.Int
erface.Ins
tall
O4 - HKLM\..\RunOnce: [WDM_AEC2] "C:\Program Files\LANDesk\LDClient\sof
tmon.exe" /r rundll32.exe streamci.dll,StreamingDevi
ceSetup {4245FF73-1DB4-11d2-86E4-9
8AE2052415
3},{9B3658
90-165F-11
D0-A195-00
20AFD156E4
},{BF963D8
0-C559-11D
0-8A2B-00A
0C9255AC1}
,C:\WINDOW
S\INF\WDMA
UDIO.inf,W
DM_AEC.Int
erface.Ins
tall
O4 - HKLM\..\RunOnce: [WDM_SWMIDI0] "C:\Program Files\LANDesk\LDClient\sof
tmon.exe" /r rundll32.exe streamci.dll,StreamingDevi
ceSetup {6C1B9F60-C0A9-11D0-96D8-0
0AA0051E51
D},{9B3658
90-165F-11
D0-A195-00
20AFD156E4
},{2EB07EA
0-7E70-11D
0-A5D6-28D
B04C10000}
,C:\WINDOW
S\INF\WDMA
UDIO.inf,W
DM_SWMIDI.
Interface.
Install
O4 - HKLM\..\RunOnce: [WDM_SWMIDI1] "C:\Program Files\LANDesk\LDClient\sof
tmon.exe" /r rundll32.exe streamci.dll,StreamingDevi
ceSetup {6C1B9F60-C0A9-11D0-96D8-0
0AA0051E51
D},{9B3658
90-165F-11
D0-A195-00
20AFD156E4
},{DFF220F
3-F70F-11D
0-B917-00A
0C9223196}
,C:\WINDOW
S\INF\WDMA
UDIO.inf,W
DM_SWMIDI.
Interface.
Install
O4 - HKLM\..\RunOnce: [WDM_SWMIDI2] "C:\Program Files\LANDesk\LDClient\sof
tmon.exe" /r rundll32.exe streamci.dll,StreamingDevi
ceSetup {6C1B9F60-C0A9-11D0-96D8-0
0AA0051E51
D},{9B3658
90-165F-11
D0-A195-00
20AFD156E4
},{6994AD0
4-93EF-11D
0-A3CC-00A
0C9223196}
,C:\WINDOW
S\INF\WDMA
UDIO.inf,W
DM_SWMIDI.
Interface.
Install
O4 - HKLM\..\RunOnce: [WDM_WDMAUD] "C:\Program Files\LANDesk\LDClient\sof
tmon.exe" /r rundll32.exe streamci.dll,StreamingDevi
ceSetup {CD171DE3-69E5-11D2-B56D-0
000F875438
0},{9B3658
90-165F-11
D0-A195-00
20AFD156E4
},{3E227E7
6-690D-11D
2-8161-000
0F8775BF1}
,C:\WINDOW
S\INF\WDMA
UDIO.inf,W
DM_WDMAUD.
Interface.
Install
O4 - HKLM\..\RunOnce: [WDM_SPLITTER0] "C:\Program Files\LANDesk\LDClient\sof
tmon.exe" /r rundll32.exe streamci.dll,StreamingDevi
ceSetup {2F412AB5-ED3A-4590-AB24-B
0CE2AA77D3
C},{9B3658
90-165F-11
D0-A195-00
20AFD156E4
},{9EA331F
A-B91B-45F
8-9285-BD2
BC77AFCDE}
,C:\WINDOW
S\INF\WDMA
UDIO.inf,W
DM_SPLITTE
R.Interfac
e.Install
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe
" -atboottime
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSyn
c.exe
O6 - HKCU\Software\Policies\Mic
rosoft\Int
ernet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Mic
rosoft\Int
ernet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\Office12\
EXCEL.EXE/
3000
O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1
D34414EAC0
D} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~2\Offic
e12\REFIEB
AR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-F
CFDF33E833
C} (WUWebControl Class) -
http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1190923203437O16 - DPF: {6E32070A-766D-4EE6-879C-D
C1FA91D2FC
3} (MUWebControl Class) -
http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1190923557937O16 - DPF: {E5F5D008-DD2C-4D32-977D-1
A0ADF03058
B} (JuniperSetupSP1 Control) -
https://juniper.net/dana-cached/setup/JuniperSetupSP1.cabO16 - DPF: {F27237D7-93C8-44C2-AC6E-D
6057B9A918
F} (JuniperSetupClient Control) -
https://juniper.net/dana-cached/sc/JuniperSetupClient.cabO17 - HKLM\System\CCS\Services\T
cpip\Param
eters: Domain = advancemags.com
O17 - HKLM\Software\..\Telephony
: DomainName = advancemags.com
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: Domain = advancemags.com
O17 - HKLM\System\CS2\Services\T
cpip\Param
eters: Domain = advancemags.com
O20 - Winlogon Notify: Csrss - C:\WINDOWS\SYSTEM32\csrss8
.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
iceService
.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2ev
xx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponde
r.exe
O23 - Service: LANDesk(R) Management Agent (CBA8) - LANDesk Software, Ltd. - C:\Program Files\LANDesk\Shared Files\residentagent.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingServ
ice.exe
O23 - Service: Intel Local Scheduler Service - LANDesk Software, Ltd. - C:\Program Files\LANDesk\LDClient\Loc
alSch.EXE
O23 - Service: Intel PDS - LANDesk Software Ltd. - C:\WINDOWS\system32\CBA\pd
s.exe
O23 - Service: LANDesk Targeted Multicast (Intel Targeted Multicast) - LANDesk Software, Ltd. - C:\Program Files\LANDesk\LDClient\tmc
svc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService
.exe
O23 - Service: LANDesk Remote Control Service (ISSUSER) - LANDesk Software, Ltd. - C:\PROGRA~1\LANDesk\LDClie
nt\issuser
.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.ex
e
O23 - Service: Juniper Unified Network Service (JuniperAccessService) - Juniper Networks - C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessServ
ice.exe
O23 - Service: LANDesk Policy Invoker - LANDesk Software, Ltd. - C:\Program Files\LANDesk\LDClient\pol
icy.client
.invoker.e
xe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEU
P~1\LUCOMS
~1.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: LANDesk(R) Software Monitoring Service (Softmon) - LANDesk Software, Ltd. - C:\Program Files\LANDesk\LDClient\sof
tmon.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\Vie
wpointServ
ice.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/rurthe
il/LOCALS~
1/Temp/mso
htmlclip1/
01/clip_im
age001.jpg
--
End of file - 16222 bytes