[Hijack log] -



Hijack log

Discuss Hijack log



Posted by: Diego Garcia

Is there anything here that needs deleting ? Seems to be a lot of running processes (If they have crept in to a Startup folder, can I delete them). I do not use Desktop Messenger, also I am suspicious of Backweb. I have run Ad-aware, customised as advised in this forum.

Logfile of HijackThis v1.97.7
Scan saved at 15:13:24, on 1.6.04
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Speed Disk\nopdb.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\USB Storage RW\shwicon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\Logtime\Logtimew.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hijack\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html[/url]
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://srch-gb7.hpwis.com/[/url]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/Program%20Files/Portal/MyPage.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url]http://gb7.hpwis.com/[/url]
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [url]http://srch-gb7.hpwis.com/[/url]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://gb7.hpwis.com/[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://srch-gb7.hpwis.com/[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://srch-gb7.hpwis.com/[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url]http://gb7.hpwis.com/[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [url]http://srch-gb7.hpwis.com/[/url]
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = [url]http://gb7.hpwis.com/[/url]
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - c:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KYE_Showicon] "C:\Program Files\USB Storage RW\shwicon.exe" -t"KYE\USB Storage RW"
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\Coloreal\coloreal.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [Logtime] "C:\Program Files\Logtime\Logtimew.exe" -m
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - Global Startup: Corel Family and Friends Reminders.LNK = C:\Program Files\Corel\Print House Magic\cffrem.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(2).lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV0
2.EXE
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\googletoolbar.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\googletoolbar.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\googletoolbar.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\googletoolbar.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\googletoolbar.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Money Viewer (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: [url]http://www.alliance-leicester.co.uk[/url]
O15 - Trusted Zone: [url]http://www.bankofengland.co.uk[/url]
O15 - Trusted Zone: [url]http://www.bbc.co.uk[/url]
O15 - Trusted Zone: [url]http://www.bestinvest.co.uk[/url]
O15 - Trusted Zone: [url]http://tucows.blueyonder.co.uk[/url]
O15 - Trusted Zone: [url]http://www.tucows.blueyonder.co.uk[/url]
O15 - Trusted Zone: [url]http://www.btopenworld.com[/url]
O15 - Trusted Zone: [url]http://www.ciac.org[/url]
O15 - Trusted Zone: [url]http://msi.com.tw[/url]
O15 - Trusted Zone: [url]http://www.msi.com.tw[/url]
O15 - Trusted Zone: [url]http://www.realtek.com.tw[/url]
O15 - Trusted Zone: [url]http://www.consignia-online.com[/url]
O15 - Trusted Zone: [url]http://www.eazy-ware.com[/url]
O15 - Trusted Zone: [url]http://www.ebay.co.uk[/url]
O15 - Trusted Zone: [url]http://www.google.co.uk[/url]
O15 - Trusted Zone: [url]http://*.companieshouse.gov.uk[/url]
O15 - Trusted Zone: [url]www.inlandrevenue.gov.uk[/url]
O15 - Trusted Zone: [url]www.meto.gov.uk[/url]
O15 - Trusted Zone: [url]http://www.grisoft.cz[/url]
O15 - Trusted Zone: [url]http://www.hallmark.com[/url]
O15 - Trusted Zone: [url]http://welcome.hp.com[/url]
O15 - Trusted Zone: [url]http://www.hp.com[/url]
O15 - Trusted Zone: [url]www.iii.co.uk[/url]
O15 - Trusted Zone: [url]http://www.karenware.com[/url]
O15 - Trusted Zone: [url]http://www.dr.keyboard.net[/url]
O15 - Trusted Zone: [url]http://doe-is.llnl.gov[/url]
O15 - Trusted Zone: [url]http://www.logitech.com[/url]
O15 - Trusted Zone: [url]http://www.nec.co.uk[/url]
O15 - Trusted Zone: [url]http://www.ntgateway.com[/url]
O15 - Trusted Zone: [url]http://download.nvidia.com[/url]
O15 - Trusted Zone: [url]http://uk.real.com[/url]
O15 - Trusted Zone: [url]http://www.forms.real.com[/url]
O15 - Trusted Zone: [url]http://www.royalmail.com[/url]
O15 - Trusted Zone: [url]http://www.sneakemail.com[/url]
O15 - Trusted Zone: [url]http://dlres.java.sun.com[/url]
O15 - Trusted Zone: [url]http://www.symantec.com[/url]
O15 - Trusted Zone: [url]http://www.theofficeexperts.com[/url]
O15 - Trusted Zone: [url]http://www.theregister.co.uk[/url]
O15 - Trusted Zone: [url]http://www.threadneedle.co.uk[/url]
O15 - Trusted Zone: [url]http://www.tomshardware.com[/url]
O15 - Trusted Zone: [url]http://www.viewsoniceurope.com[/url]
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - [url]http://office.microsoft.com/officeupdate/content/opuc.cab[/url]
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - [url]http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38094.0889467593[/url]
O17 - HKLM\System\CCS\Services\Tcpip\..\{3813537B-2080-452D-A81A-845BE1D77838}: NameServer = 213.1.119.99 213.1.119.100



Posted by: Lobos

Run hijack this put a check next to these close all browsers and hit fix

[b]Make sure not to miss one


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*[url]http://uk.docs.yahoo.com/info/bt_side.html[/url][/url]

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://srch-gb7.hpwis.com/[/url]

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/Program%20Files/Portal/MyPage.htm

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url]http://gb7.hpwis.com/[/url]

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [url]http://srch-gb7.hpwis.com/[/url]

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://gb7.hpwis.com/[/url]

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://srch-gb7.hpwis.com/[/url]

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://srch-gb7.hpwis.com/[/url]

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url]http://gb7.hpwis.com/[/url]

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [url]http://srch-gb7.hpwis.com/[/url]

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = [url]http://gb7.hpwis.com/[/url]

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)


O4 - HKLM\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe

O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe

O4 - HKLM\..\Run: [Logtime] "C:\Program Files\Logtime\Logtimew.exe" -m

O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe

O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE


if you put these here then leave them but otherwise fix them

all O15


[/b]-----------------------------------------------------------------------------------------------------------------------------------

come back and post another log



Lobos



Posted by: Diego Garcia

Thanks for that Lobos.
R0 .../Portal/MyPage.htm is my Home page for IE6, I do not want Yahoo.

Logfile of HijackThis v1.97.7
Scan saved at 21:39:12, on 1.6.04
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Speed Disk\nopdb.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\USB Storage RW\shwicon.exe
C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\backWeb-8876480.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\Logtime\Logtimew.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Hijack\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

file:///C:/Program%20Files/Portal/MyPage.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title =

Microsoft Internet Explorer
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -

C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} -

c:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} -

c:\program files\google\googletoolbar.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -

C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} -

c:\program files\google\googletoolbar.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KYE_Showicon] "C:\Program Files\USB Storage

RW\shwicon.exe" -t"KYE\USB Storage RW"
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS

Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\Coloreal\coloreal.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE

C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE

C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe

/STARTUP
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone

Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE

C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Global Startup: Corel Family and Friends Reminders.LNK =

C:\Program Files\Corel\Print House Magic\cffrem.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(2).lnk =

C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV0
2.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program

Files\Google\googletoolbar.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program

Files\Google\googletoolbar.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page -

res://C:\Program Files\Google\googletoolbar.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program

Files\Google\googletoolbar.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program

Files\Google\googletoolbar.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Money Viewer (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .bcf: C:\Program Files\Internet

Explorer\Plugins\NPBelv32.dll
O12 - Plugin for .spop: C:\Program Files\Internet

Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: [url]http://www.alliance-leicester.co.uk[/url]
O15 - Trusted Zone: [url]http://www.bankofengland.co.uk[/url]
O15 - Trusted Zone: [url]http://www.bbc.co.uk[/url]
O15 - Trusted Zone: [url]http://www.bestinvest.co.uk[/url]
O15 - Trusted Zone: [url]http://tucows.blueyonder.co.uk[/url]
O15 - Trusted Zone: [url]http://www.tucows.blueyonder.co.uk[/url]
O15 - Trusted Zone: [url]http://www.btopenworld.com[/url]
O15 - Trusted Zone: [url]http://www.ciac.org[/url]
O15 - Trusted Zone: [url]http://msi.com.tw[/url]
O15 - Trusted Zone: [url]http://www.msi.com.tw[/url]
O15 - Trusted Zone: [url]http://www.realtek.com.tw[/url]
O15 - Trusted Zone: [url]http://www.consignia-online.com[/url]
O15 - Trusted Zone: [url]http://www.eazy-ware.com[/url]
O15 - Trusted Zone: [url]http://www.ebay.co.uk[/url]
O15 - Trusted Zone: [url]http://www.google.co.uk[/url]
O15 - Trusted Zone: [url]http://*.companieshouse.gov.uk[/url]
O15 - Trusted Zone: [url]www.inlandrevenue.gov.uk[/url]
O15 - Trusted Zone: [url]www.meto.gov.uk[/url]
O15 - Trusted Zone: [url]http://www.grisoft.cz[/url]
O15 - Trusted Zone: [url]http://www.hallmark.com[/url]
O15 - Trusted Zone: [url]http://welcome.hp.com[/url]
O15 - Trusted Zone: [url]http://www.hp.com[/url]
O15 - Trusted Zone: [url]www.iii.co.uk[/url]
O15 - Trusted Zone: [url]http://www.karenware.com[/url]
O15 - Trusted Zone: [url]http://www.dr.keyboard.net[/url]
O15 - Trusted Zone: [url]http://doe-is.llnl.gov[/url]
O15 - Trusted Zone: [url]http://www.logitech.com[/url]
O15 - Trusted Zone: [url]http://www.nec.co.uk[/url]
O15 - Trusted Zone: [url]http://www.ntgateway.com[/url]
O15 - Trusted Zone: [url]http://download.nvidia.com[/url]
O15 - Trusted Zone: [url]http://uk.real.com[/url]
O15 - Trusted Zone: [url]http://www.forms.real.com[/url]
O15 - Trusted Zone: [url]http://www.royalmail.com[/url]
O15 - Trusted Zone: [url]http://www.sneakemail.com[/url]
O15 - Trusted Zone: [url]http://dlres.java.sun.com[/url]
O15 - Trusted Zone: [url]http://www.symantec.com[/url]
O15 - Trusted Zone: [url]http://www.theofficeexperts.com[/url]
O15 - Trusted Zone: [url]http://www.theregister.co.uk[/url]
O15 - Trusted Zone: [url]http://www.threadneedle.co.uk[/url]
O15 - Trusted Zone: [url]http://www.tomshardware.com[/url]
O15 - Trusted Zone: [url]http://www.viewsoniceurope.com[/url]
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update

Installation Engine) -

[url]http://office.microsoft.com/officeupdate/content/opuc.cab[/url]
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -

[url]http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38094.0[/url]

889467593