Hitting any of these urls (which I edited by adding spaces so they won't now work) installs URL redirecting, and some sort of spyware, which McAffee on-access scan at the office catches. Under HJT it comes out in O16 section.
Here are the 3 quotes from search returns while googling
Quote
Removing 'Your personal pages' website [Archive] - MajorGeeks ...
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) -
file://C:\TempEI4\EI40_\msxml4.cab (file://C:TempEI4EI40_msxml4.cab) ...
forum. majorgeeks. com/archive/index. php/t-33461.html - 12k - Cached - Similar pages
Designtechnica Forums - windowws hijack-er
O15 - Trusted Zone: *.greg-search.com O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5}
(XML DOM Document 4.0) - file://C:\TempEI4\EI40_\msxml4.cab ...
forums. designtechnica. com/archive/index.php/t-5285.html - 20k - Cached - Similar pages
Designtechnica Forums - Help.
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) -
file://C:\TempEI4\EI40_\msxml4.cab O17 - HKLM\System\CCS\Services\Tcpip\. ...
forums. designtechnica.com/archive/index.php/t-6038.html - 12k - Cached - Similar pages
[ More results from forums.designtechnica.com ]
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) -
file://C:\TempEI4\EI40_\msxml4.cab (file://C:TempEI4EI40_msxml4.cab) ...
forum. majorgeeks. com/archive/index. php/t-33461.html - 12k - Cached - Similar pages
Designtechnica Forums - windowws hijack-er
O15 - Trusted Zone: *.greg-search.com O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5}
(XML DOM Document 4.0) - file://C:\TempEI4\EI40_\msxml4.cab ...
forums. designtechnica. com/archive/index.php/t-5285.html - 20k - Cached - Similar pages
Designtechnica Forums - Help.
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) -
file://C:\TempEI4\EI40_\msxml4.cab O17 - HKLM\System\CCS\Services\Tcpip\. ...
forums. designtechnica.com/archive/index.php/t-6038.html - 12k - Cached - Similar pages
[ More results from forums.designtechnica.com ]
WHY?????
EDITED: I think it happened when we clicked "Cached" not the direct URL
This post has been edited by tos226: 21 December 2005 - 02:33 PM

Help


Back to top








