|
-
September 16th, 2005, 08:05 PM
#6
O9 - Extra button: AbsolutePoker.com - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: AbsolutePoker.com - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
These jump out right away.
O21 - SSODL: sTEtAzr - {C8368FDD-629C-2577-FA5F-BD4AADB14AC0} - C:\WINDOWS\System32\pyxnj.dll
This is fishy, but I am not sure what it is, so take care. It didn't show up on google.
O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\cool.cab
O16 - DPF: {33331111-1111-1111-1111-622221193458} - file://c:\ex.cab
O16 - DPF: {64311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
Suspicious. A quick search shows the last one is trojan related.
I would start looking at these.
Take care when playing with the registry like this. You can do damage. I have just had a quick look at this. The first group I would go ahead with, and I would do away with the "eied_s7.cab". The rest call for some more digging.
Good luck.
/beat me Jinx
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|