Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Not Really Sure What This Is... Strange Music...


  • Please log in to reply
8 replies to this topic

#1 LTJLily17

LTJLily17

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Kettering, Ohio
  • Local time:11:52 PM

Posted 14 March 2008 - 06:59 PM

I've noticed this most while using a co-workers color printer- when I open any application, to print or otherwise, the computer starts playing into music, and a host introduces herself (Kristi Barker) and she begins announcing what seems like a TV show. There is no video to go along with this. She goes from talking about makeup to fashion to home decor. It is really bizarre. Sometimes the audio will even play over itself.

I have restarted the computer several times (it is running very slow) and I ran a virus and spyware scan using CA.

Besides the audio and the slowness, there is nothing else giving me any clues ot what this might be.

Has anyone heard of anything like this?

BC AdBot (Login to Remove)

 


#2 LTJLily17

LTJLily17
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Kettering, Ohio
  • Local time:11:52 PM

Posted 17 March 2008 - 03:54 PM

Apparently, when IE7 is opened sometimes the homepage is hijacked to some website that sells purses.

Anyone have any idea how I could find out what is infecting this computer?

#3 PropagandaPanda

PropagandaPanda


  • Malware Response Team
  • 10,433 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:52 PM

Posted 17 March 2008 - 04:46 PM

Please state your operating system.

I have seen a similar malware infection in the past.

Please download SuperAntiSpyware. (Only if you have XP. I'm unsure if it is compatible with other operating systems.)

Update the database and run a scan.

Post back with the log file.

Edited by PropagandaPanda, 17 March 2008 - 04:46 PM.


#4 don77

don77

    Forum Regular


  • Members
  • 3,212 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Boston Mass
  • Local time:10:52 PM

Posted 17 March 2008 - 06:32 PM

I've noticed this most while using a co-workers color printer- when I open any application,


This is a work machine ?

#5 LTJLily17

LTJLily17
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Kettering, Ohio
  • Local time:11:52 PM

Posted 17 March 2008 - 07:19 PM

Thank you very much for your replies!

I have downloaded the program you recommended and am running a scan now.

This machine is running XP, by the way- sorry I forgot to mention that. We have CA antivirus installed on it, but it seems it's not living up to my expectations. It was the free Anti-Virus offered through our ISP.

Yes, it is a work machine, and I, unfortunately, am the IT Dept. We run a Linux based operation here, and any infections and other crazy issues we have with Windows based machines I am lost on. I read the rules and whatnot, and I'm not violating any of them, correct? We are a small, family owned company, and I'm basically learning as I go here.

I really appreciate all the help I've recieved from this site :thumbsup:

I will post the results when it is finished, but any type of virus scan on this computer seems to take quite awhile. This machine has about 100gb hard drive space being used.

#6 LTJLily17

LTJLily17
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Kettering, Ohio
  • Local time:11:52 PM

Posted 17 March 2008 - 07:24 PM

Okay, here it is:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 03/17/2008 at 08:21 PM

Application Version : 4.0.1154

Core Rules Database Version : 3421
Trace Rules Database Version: 1413

Scan type : Quick Scan
Total Scan Time : 00:12:25

Memory items scanned : 440
Memory threats detected : 0
Registry items scanned : 295
Registry threats detected : 18
File items scanned : 4812
File threats detected : 112

Trojan.Unclassified/EGO
HKLM\Software\Microsoft\Internet Explorer\Toolbar#{6F935236-97C7-42A0-AD79-AD299EB60E83}
HKCR\CLSID\{6F935236-97C7-42A0-AD79-AD299EB60E83}
HKCR\CLSID\{6F935236-97C7-42A0-AD79-AD299EB60E83}
HKCR\CLSID\{6F935236-97C7-42A0-AD79-AD299EB60E83}\InprocServer32
HKCR\CLSID\{6F935236-97C7-42A0-AD79-AD299EB60E83}\InprocServer32#ThreadingModel
HKCR\CLSID\{6F935236-97C7-42A0-AD79-AD299EB60E83}\ProgID
HKCR\CLSID\{6F935236-97C7-42A0-AD79-AD299EB60E83}\Programmable
HKCR\CLSID\{6F935236-97C7-42A0-AD79-AD299EB60E83}\TypeLib
HKCR\CLSID\{6F935236-97C7-42A0-AD79-AD299EB60E83}\VersionIndependentProgID
HKCR\enlfxgw.1
HKCR\enlfxgw
HKCR\TypeLib\{C52AEDCE-6B60-4680-9E80-94BB7F86DC70}
HKCR\TypeLib\{C52AEDCE-6B60-4680-9E80-94BB7F86DC70}\1.0
HKCR\TypeLib\{C52AEDCE-6B60-4680-9E80-94BB7F86DC70}\1.0\0
HKCR\TypeLib\{C52AEDCE-6B60-4680-9E80-94BB7F86DC70}\1.0\0\win32
HKCR\TypeLib\{C52AEDCE-6B60-4680-9E80-94BB7F86DC70}\1.0\FLAGS
HKCR\TypeLib\{C52AEDCE-6B60-4680-9E80-94BB7F86DC70}\1.0\HELPDIR
C:\WINDOWS\ENLFXGW.DLL

Adware.Tracking Cookie
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@doubleclick[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@ehg-bestbuy.hitbox[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@linksynergy[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@208.122.40[3].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@viaatomvideo.112.2o7[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@209.9.174[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@pro-market[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@ads.revsci[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@buycom.122.2o7[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@waterfrontmedia.112.2o7[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@zedo[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@www.googleadservices[4].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@ehg-newotm.hitbox[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@heavycom.122.2o7[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@fastclick[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@media.adrevolver[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@hitbox[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@ehg-meevee.hitbox[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@eyewonder[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@247realmedia[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@dealtime[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@www.googleadservices[5].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@www.adminitrack[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@homestore.122.2o7[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@sales.liveperson[3].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@mason.112.2o7[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@charmingshoppes.112.2o7[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@overture[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@silo.thefind[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@imrworldwide[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@apmebf[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@enhance[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@maxifind[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@partner2profit[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@www.burstnet[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@adminitrack[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@banners.nrn[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@www.googleadservices[6].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@bp.specificclick[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@shopica[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@www.clickmanage[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@ecnext.advertserve[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@findwhat[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@stat.dealtime[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@specificclick[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@adrevolver[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@tribalfusion[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@starz.122.2o7[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@msnportal.112.2o7[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@mediaplex[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@www.googleadservices[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@ehg-techtarget.hitbox[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@2o7[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@adopt.specificclick[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@interclick[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@sales.liveperson[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@www5.teenhelpservices[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@casalemedia[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@vhost.oddcast[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@burstnet[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@questionmarket[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@counter.hitslink[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@perf.overture[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@tacoda[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@ads.vidsense[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@podshow.112.2o7[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@realmedia[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@indexstats[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@ehg-mindshare.hitbox[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@classifiedventures1.112.2o7[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@revsci[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@traffic.buyservices[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@adopt.euroclick[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@www.googleadservices[9].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@paypal.112.2o7[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@bs.serving-sys[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@atdmt[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@stat.onestat[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@t4.trackalyzer[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@roiservice[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@208.122.40[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@www.googleadservices[3].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@ads.pointroll[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@adbrite[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@xiti[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@toseeka[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@media.adrevolver[3].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@ads.bleepingcomputer[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@www.googleadservices[8].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@ad.yieldmanager[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@statse.webtrendslive[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@adecn[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@www.couponmountain[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@count.trackula[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@phg.hitbox[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@www.oberon-media[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@advertising[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@serving-sys[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@nextag[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@www.burstbeacon[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@keywordmax[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@clickbank[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@publicrecordfinder[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@www.googleadservices[7].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@www.googleadservices[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@azjmp[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@server.iad.liveperson[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@www.shopica[2].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@track.cbs[1].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@server.iad.liveperson[3].txt
C:\Documents and Settings\Sharon Cassano\Cookies\sharon_cassano@statcounter[2].txt

Unclassified.Unknown Origin
HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad#zip [ {c030be51-082c-4bea-add8-a8098c96e8ba} ]



I suppose I should have deleted the cookies and Temp files first- sorry for all the space I'm taking up :thumbsup:

#7 don77

don77

    Forum Regular


  • Members
  • 3,212 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Boston Mass
  • Local time:10:52 PM

Posted 18 March 2008 - 09:38 PM

Please download SmitfraudFix

Double-click SmitfraudFix.exe
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc...processutil.htm

#8 LTJLily17

LTJLily17
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Kettering, Ohio
  • Local time:11:52 PM

Posted 19 March 2008 - 08:26 PM

Here is what I got from that:

SmitFraudFix v2.305

Scan done at 21:23:02.21, Wed 03/19/2008
Run from C:\Documents and Settings\Sharon Cassano\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\cmd.exe

hosts


C:\


C:\WINDOWS


C:\WINDOWS\system


C:\WINDOWS\Web


C:\WINDOWS\system32


C:\WINDOWS\system32\LogFiles


C:\Documents and Settings\Sharon Cassano


C:\Documents and Settings\Sharon Cassano\Application Data


Start Menu


C:\DOCUME~1\SHARON~1\FAVORI~1


Desktop


C:\Program Files


Corrupted keys


Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


IEDFix
!!!Attention, following keys are not inevitably infected!!!

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


VACFix
!!!Attention, following keys are not inevitably infected!!!

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

[!] Suspicious: SrvMon.dll
SSODL: SrvMon - {615123e0-f4d0-4595-9dd4-c61aa6ce3c88}


Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


Rustock



DNS

Description: SiS 900-Based PCI Fast Ethernet Adapter - Packet Scheduler Miniport
DNS Server Search Order: 192.168.0.254

HKLM\SYSTEM\CCS\Services\Tcpip\..\{E7C2DD2A-5FDC-40F5-8C6B-4ADE8A6A32A1}: DhcpNameServer=192.168.0.254
HKLM\SYSTEM\CS1\Services\Tcpip\..\{E7C2DD2A-5FDC-40F5-8C6B-4ADE8A6A32A1}: DhcpNameServer=192.168.0.254
HKLM\SYSTEM\CS2\Services\Tcpip\..\{E7C2DD2A-5FDC-40F5-8C6B-4ADE8A6A32A1}: DhcpNameServer=192.168.0.254
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.254
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.254
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.254


Scanning for wininet.dll infection


End

Thank you for your help so far!

#9 don77

don77

    Forum Regular


  • Members
  • 3,212 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Boston Mass
  • Local time:10:52 PM

Posted 20 March 2008 - 12:52 PM

Still hearing voices ? Hmm that doesn't sound right :thumbsup:

strange sounds still coming from the computer ?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users