Item Search
     
BG-Wiki Search
Page 4 of 4 FirstFirst ... 2 3 4
Results 61 to 77 of 77
  1. #61
    Fishing Guru
    Join Date
    Jan 2007
    Posts
    4,722
    BG Level
    7

    Re: wzcsvbxm.dll warning - ALSO CHANGE YOUR PASSWORDS

    Quote Originally Posted by stix
    Quote Originally Posted by Yarko
    Quote Originally Posted by stix
    I haven't been following any of the recent hacks at all...but from what I've seen if they all involve keyloggers, wouldn't it just be much, much safer to save your username and PW in POL? I don't think i've ever entered them with my keyboard at least....ever. Assuming most of you guys play on your own consoles/computers just wondering why that isn't considered a solution.

    and I haven't typed my password for ages now, since it was saved. But I got hacked nonetheless today
    Ok, so if it's not a keylogger, what is it?
    How about you read some of the recent threads.

  2. #62
    Melee Summoner
    Join Date
    May 2008
    Posts
    26
    BG Level
    1
    FFXI Server
    Alexander

    Re: wzcsvbxm.dll warning - ALSO CHANGE YOUR PASSWORDS

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 5:13:11 PM, on 6/24/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.20815)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\sm56hlpr.exe
    C:\Program Files\Eset\nod32kui.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Process Lasso\processgovernor.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
    C:\Program Files\Process Lasso\ProcessLasso.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Eset\nod32krn.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Sygate\SPF\smc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
    C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    C:\Documents and Settings\Administrator\My Documents\ffassist2_b17-8\FFAssist2.exe
    C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\pol.e xe
    C:\Program Files\uTorrent\utorrent.exe
    C:\Program Files\Combined Community Codec Pack\Zoom Player\zplayer.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\s wg.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
    O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
    O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
    O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [ProcessGovernor] C:\Program Files\Process Lasso\processgovernor.exe
    O4 - HKLM\..\Run: [Clean System Memory 120 Sec. After Startup] C:\Windows\system32\CleanMem.exe 120
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
    O4 - HKCU\..\Run: [WallpaperChanger] C:\Program Files\Wallpaper Master\Wallpaper.exe
    O4 - HKCU\..\Run: [ProcessSupervisorGUI] C:\Program Files\Process Lasso\ProcessLasso.exe /tray
    O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.v bs" (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 6318443656
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
    O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe

    --
    End of file - 6448 bytes


    This is my log. D:

  3. #63
    Smells like Onions
    Join Date
    Jun 2008
    Posts
    3
    BG Level
    0

    Re: wzcsvbxm.dll warning - ALSO CHANGE YOUR PASSWORDS

    Quote Originally Posted by cdgreguh
    Quote Originally Posted by stix
    Quote Originally Posted by Yarko
    Quote Originally Posted by stix
    I haven't been following any of the recent hacks at all...but from what I've seen if they all involve keyloggers, wouldn't it just be much, much safer to save your username and PW in POL? I don't think i've ever entered them with my keyboard at least....ever. Assuming most of you guys play on your own consoles/computers just wondering why that isn't considered a solution.

    and I haven't typed my password for ages now, since it was saved. But I got hacked nonetheless today
    Ok, so if it's not a keylogger, what is it?
    How about you read some of the recent threads.
    Well I could search through about a half a dozen random and disorganized stickies/threads I see on the first page or someone who might care about the spread of such attacks in the community could maybe give me (and anyone else reading) a one sentence answer. 's all good though.

  4. #64
    Doctor Shantotto Supporter
    Join Date
    Apr 2006
    Posts
    132
    BG Level
    3
    FFXI Server
    Odin

    Re: wzcsvbxm.dll Warning!

    Quote Originally Posted by senoska
    Quote Originally Posted by Ashira
    Especially now with the onscreen keyboard... reposition the POL window if you must for more security.

    And for fuck's sake, update your damn browsers and flash plugins. /sigh
    Repositioning won't do anything as the keyboard location is static, if you know the X,Y of the POL window you can hook the mouse and snag a password. You can use your Keyboard on the software keyboard. I suggest using a mix of keyboard(left right up down keys) and mouse commands to type in your password.
    POL Window is resizable. That should mess up the readings yea?

  5. #65
    Melee Summoner
    Join Date
    Jul 2007
    Posts
    33
    BG Level
    1
    FFXI Server
    Leviathan

    Re: wzcsvbxm.dll warning - ALSO CHANGE YOUR PASSWORDS

    I was recently hacked and just got my account back yesterday.

    Using Mafai's suggested CurrProcess, I have located wzcsvbxm.dll within my POL module.

    I'm not very computer savvy, so any advice as to how I could delete this?

  6. #66
    WASTE OF CURRENCY
    I CAN'T I CAN'T I CAN'T

    Join Date
    Feb 2006
    Posts
    9,065
    BG Level
    8
    FFXIV Character
    Izzy Izumi
    FFXIV Server
    Sargatanas
    FFXI Server
    Phoenix
    WoW Realm
    Arthas

    Re: wzcsvbxm.dll warning - ALSO CHANGE YOUR PASSWORDS

    Quote Originally Posted by Jontale
    I was recently hacked and just got my account back yesterday.

    Using Mafai's suggested CurrProcess, I have located wzcsvbxm.dll within my POL module.

    I'm not very computer savvy, so any advice as to how I could delete this?
    Format Q_Q

    ...why do people even ask?

  7. #67
    My Little Ixion
    Join Date
    Aug 2007
    Posts
    8,016
    BG Level
    8
    FFXIV Character
    Olorin Bustyoas
    FFXIV Server
    Sargatanas
    FFXI Server
    Ramuh

    Re: wzcsvbxm.dll warning - ALSO CHANGE YOUR PASSWORDS

    I said it in LS chat a couple days ago.. I'm gonna repartition my HD, install a dual-boot of Ubuntu and ONLY use a web browser from that environment. Screw this shit.

  8. #68
    CoP Dynamis
    Join Date
    Jul 2006
    Posts
    249
    BG Level
    4

    Re: wzcsvbxm.dll warning - ALSO CHANGE YOUR PASSWORDS

    Quote Originally Posted by senoska
    Not sure if this is related, but I was playing FFXI fine, started it today:

    just randomly started getting this error:
    http://img58.imageshack.us/img58/1189/ffxierrorpv4.jpg

    Thinking it was a directx issue I tried to reinstall Dx9 and I got this:
    http://img95.imageshack.us/img95/3759/setuprq3.jpg

    Are you running in full-screen mode? I think I had this problem running the game on my mac whenever the game launched from the pol viewer. Changed it to windowed mode and it ran just fine.

  9. #69
    CoP Dynamis
    Join Date
    Jul 2006
    Posts
    249
    BG Level
    4

    Re: wzcsvbxm.dll warning - ALSO CHANGE YOUR PASSWORDS

    Quote Originally Posted by The Blackrose
    Quote Originally Posted by Kurgan
    WinPcap is used by Ethereal/Wireshark.

    Can't remember what other programs are distributed with it.
    I believe Cain and Abel comes packaged with it too.

    Quote Originally Posted by Suterusu
    Type it on a stand alone box. Copy to a flash drive/lolfloppy. Copy paste onto the onscreen keyboard. Just a thought.
    Because no one ever reads the copy buffer, amirite?
    Not sure if this it even helps, but I always type in my password in random order. I'll enter one letter of the password and click in the input box where the next letter I want to add will go.

    For instance, if my password is "s3TuPb0mB", I might type in "sTP0B," then click between the letters to add in "3ubm."

  10. #70
    Hydra
    Join Date
    Mar 2007
    Posts
    144
    BG Level
    3

    Re: wzcsvbxm.dll warning - ALSO CHANGE YOUR PASSWORDS

    i think i might be at risk, would un installing pol and reinstalling help?

  11. #71
    Salvage Bans
    Join Date
    Aug 2005
    Posts
    930
    BG Level
    5
    FFXIV Character
    Vigilia Dulaurier
    FFXIV Server
    Ragnarok
    FFXI Server
    Asura

    Re: wzcsvbxm.dll warning - ALSO CHANGE YOUR PASSWORDS

    Quote Originally Posted by bungie
    i think i might be at risk, would un installing pol and reinstalling help?
    If your PC has been infected just wipe your HDD clean, format everything and reinstall from scratch. Uninstalling and reinstalling POL won't get rid of a virus elsewhere in your PC.

  12. #72
    CoP Dynamis
    Join Date
    Jun 2007
    Posts
    287
    BG Level
    4

    Re: wzcsvbxm.dll warning - ALSO CHANGE YOUR PASSWORDS

    Quote Originally Posted by Olo401
    I said it in LS chat a couple days ago.. I'm gonna repartition my HD, install a dual-boot of Ubuntu and ONLY use a web browser from that environment. Screw this shit.
    you have other options. you can run a separate OS of your choice in a VM session and do your web browsing from there. that way you dont have to dualboot and can still do your web browsing while FFXI is open with no worries.

    http://www.vmware.com/
    http://www.virtualbox.org/
    http://bochs.sourceforge.net/
    http://www.thefreecountry.com/emulators/pc.shtml

  13. #73
    Psalm
    Guest

    Quote Originally Posted by Monkor View Post
    Are you running in full-screen mode? I think I had this problem running the game on my mac whenever the game launched from the pol viewer. Changed it to windowed mode and it ran just fine.
    I had this same problem and found useing windower fixed it or just to play on ps3.

  14. #74
    Psalm
    Guest

    also last wedn. my account was hacked aswell. Got my password reset and log in to find everything that could be sold was gone. Account currently in rollback. But ive run hjt report, virus scan, trend micro house call, currprocess for pol and never found the smart.dll or the wzcsvbxm.dll file. I'll post the currprocess in another post for someone who knows alot more then me to take a look at. My question tho now is should I just reformat my pc or since I cant find these virus's am I still safe to play on pc? I NOW have firefox with no script adblock and updated flash. I used to use IE had trend micro and firewall on and honestly thought that would be good. I was wrong and paid dearly.


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:55:19 AM, on 7/27/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16674)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
    C:\WINDOWS\stsystra.exe
    C:\Program Files\Dell\Media Experience\DMXLauncher.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
    C:\Program Files\DellSupport\DSAgnt.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\pol.e xe
    C:\Documents and Settings\Rick\Desktop\cprocess\CProcess.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
    O4 - HKLM\..\Run: [ShowLOMControl] 
    O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
    O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
    O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Rick\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
    O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Rick\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
    O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1203981728546
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
    O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
    O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
    O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
    O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

    --
    End of file - 8008 bytes

  15. #75
    Psalm
    Guest

    and here is the currprocess I ran on pol



    Created by using CurrProcess

    Process Name pol.exe
    ProcessID 2892
    Priority Normal
    Product Name PlayOnline Viewer
    Version 1.18.07
    Description PlayOnline Viewer
    Company SQUARE ENIX CO., LTD.
    Window Title PlayOnline Viewer Ver.1.18.10c
    File Size 1,691,648
    File Created Date 2/27/2005 1:47:24 AM
    File Modified Date 3/14/2008 1:09:57 AM
    Filename C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\pol.e xe
    Base Address 0x00400000
    Created On 7/27/2008 12:10:31 PM
    Visible Windows 1
    Hidden Windows 4
    User Name DELL\Rick
    Mem Usage 35480 K
    Mem Usage Peak 38132 K
    Page Faults 15631
    Pagefile Usage 70124 K
    Pagefile Peak Usage 73116 K
    File Attributes A

    Module Name Base Address Module Size Version Description Company Product Name Modified Date File Size Filename File Attributes
    pol.exe 0x00400000 0x001A0000 1.18.07 PlayOnline Viewer SQUARE ENIX CO., LTD. PlayOnline Viewer 3/13/2008 9:09:57 PM 1,691,648 C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\pol.e xe A
    ntdll.dll 0x7C900000 0x000B0000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) NT Layer DLL Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 708,096 C:\WINDOWS\system32\ntdll.dll A
    kernel32.dll 0x7C800000 0x000F5000 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) Windows NT BASE API Client DLL Microsoft Corporation Microsoft® Windows® Operating System 4/16/2007 11:52:53 AM 984,576 C:\WINDOWS\system32\kernel32.dll A
    PolHook.dll 0x10000000 0x00010000 1.18.07 PlayOnline Viewer polhook Module SQUARE ENIX CO., LTD. PlayOnline Viewer 3/13/2008 9:10:04 PM 61,440 C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\PolHo ok.dll A
    USER32.dll 0x7E410000 0x00090000 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) Windows XP USER API Client DLL Microsoft Corporation Microsoft® Windows® Operating System 3/8/2007 11:36:28 AM 577,536 C:\WINDOWS\system32\USER32.dll A
    GDI32.dll 0x77F10000 0x00047000 5.1.2600.3316 (xpsp_sp2_gdr.080219-1316) GDI Client DLL Microsoft Corporation Microsoft® Windows® Operating System 2/20/2008 2:51:05 AM 282,624 C:\WINDOWS\system32\GDI32.dll A
    IMM32.DLL 0x76390000 0x0001D000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows XP IMM32 API Client DLL Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 110,080 C:\WINDOWS\system32\IMM32.DLL A
    ADVAPI32.dll 0x77DD0000 0x0009B000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Advanced Windows 32 Base API Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 616,960 C:\WINDOWS\system32\ADVAPI32.dll A
    RPCRT4.dll 0x77E70000 0x00091000 5.1.2600.3173 (xpsp_sp2_qfe.070709-0052) Remote Procedure Call Runtime Microsoft Corporation Microsoft® Windows® Operating System 7/9/2007 9:16:16 AM 582,656 C:\WINDOWS\system32\RPCRT4.dll A
    WINMM.dll 0x76B40000 0x0002D000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) MCI API DLL Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 176,128 C:\WINDOWS\system32\WINMM.dll A
    DDRAW.dll 0x73760000 0x00049000 5.03.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft DirectDraw Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 266,240 C:\WINDOWS\system32\DDRAW.dll A
    msvcrt.dll 0x77C10000 0x00058000 7.0.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows NT CRT DLL Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 343,040 C:\WINDOWS\system32\msvcrt.dll A
    DCIMAN32.dll 0x73BC0000 0x00006000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) DCI Manager Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 8,704 C:\WINDOWS\system32\DCIMAN32.dll A
    ole32.dll 0x774E0000 0x0013D000 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528) Microsoft OLE for Windows Microsoft Corporation Microsoft® Windows® Operating System 7/26/2005 12:39:48 AM 1,285,120 C:\WINDOWS\system32\ole32.dll A
    OLEAUT32.dll 0x77120000 0x0008B000 5.1.2600.3266 Microsoft Corporation 12/4/2007 2:38:13 PM 550,912 C:\WINDOWS\system32\OLEAUT32.dll A
    LPK.DLL 0x629C0000 0x00009000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Language Pack Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 22,016 C:\WINDOWS\system32\LPK.DLL A
    USP10.dll 0x74D90000 0x0006B000 1.0420.2600.2180 (xpsp_sp2_rtm.040803-2158) Uniscribe Unicode script processor Microsoft Corporation Microsoft(R) Uniscribe Unicode script processor 8/10/2004 6:00:00 AM 406,528 C:\WINDOWS\system32\USP10.dll A
    uxtheme.dll 0x5AD70000 0x00038000 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) Microsoft UxTheme Library Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 218,624 C:\WINDOWS\system32\uxtheme.dll A
    MSCTF.dll 0x74720000 0x0004B000 5.1.2600.3319 (xpsp_sp2_gdr.080222-1435) MSCTF Server DLL Microsoft Corporation Microsoft® Windows® Operating System 2/26/2008 7:59:50 AM 294,912 C:\WINDOWS\system32\MSCTF.dll A
    CLBCATQ.DLL 0x76FD0000 0x0007F000 2001.12.4414.308 Microsoft Corporation COM Services 7/26/2005 12:39:43 AM 498,688 C:\WINDOWS\system32\CLBCATQ.DLL A
    COMRes.dll 0x77050000 0x000C5000 2001.12.4414.258 Microsoft Corporation COM Services 8/10/2004 6:00:00 AM 792,064 C:\WINDOWS\system32\COMRes.dll A
    VERSION.dll 0x77C00000 0x00008000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Version Checking and File Installation Libraries Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 18,944 C:\WINDOWS\system32\VERSION.dll A
    xpsp2res.dll 0x20000000 0x002C5000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Service Pack 2 Messages Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 2,897,920 C:\WINDOWS\system32\xpsp2res.dll A
    SHLWAPI.dll 0x77F60000 0x00076000 6.00.2900.3268 (xpsp_sp2_gdr.071206-1518) Shell Light-weight Utility Library Microsoft Corporation Microsoft® Windows® Operating System 12/6/2007 9:07:13 PM 474,112 C:\WINDOWS\system32\SHLWAPI.dll A
    comctl32.dll 0x773D0000 0x00103000 6.0 (xpsp.060825-0040) User Experience Controls Library Microsoft Corporation Microsoft® Windows® Operating System 8/25/2006 11:45:55 AM 1,054,208 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll A
    COMCTL32.dll 0x5D090000 0x0009A000 5.82 (xpsp.060825-0040) Common Controls Library Microsoft Corporation Microsoft® Windows® Operating System 8/25/2006 11:45:58 AM 617,472 C:\WINDOWS\system32\COMCTL32.dll A
    dsound.dll 0x73F10000 0x0005C000 5.3.2600.2180 (xpsp_sp2_rtm.040803-2158) DirectSound Microsoft Corporation Microsoft(R) Windows(R) Operating System 8/10/2004 6:00:00 AM 367,616 C:\WINDOWS\system32\dsound.dll A
    msctfime.ime 0x755C0000 0x0002E000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft Text Frame Work Service IME Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 177,152 C:\WINDOWS\system32\msctfime.ime A
    msi.dll 0x7D1E0000 0x002BE000 3.1.4000.4039 Windows Installer Microsoft Corporation Windows Installer - Unicode 4/18/2007 12:12:23 PM 2,854,400 C:\WINDOWS\system32\msi.dll A
    polcore.dll 0x01270000 0x0044F000 1.18.07 PlayOnline Viewer POLCore Module SQUARE ENIX CO., LTD. PlayOnline Viewer 7/9/2008 11:06:01 PM 544,768 C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\viewe r\com\polcore.dll A
    DINPUT8.dll 0x6CE10000 0x00038000 5.03.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft DirectInput Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 181,760 C:\WINDOWS\system32\DINPUT8.dll A
    WS2_32.dll 0x71AB0000 0x00017000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows Socket 2.0 32-Bit DLL Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 82,944 C:\WINDOWS\system32\WS2_32.dll A
    WS2HELP.dll 0x71AA0000 0x00008000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows Socket 2.0 Helper for Windows NT Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 19,968 C:\WINDOWS\system32\WS2HELP.dll A
    app.dll 0x019D0000 0x00B88000 1.18.07 PlayOnline Viewer App Module SQUARE ENIX CO., LTD. PlayOnline Viewer 7/9/2008 11:05:53 PM 4,299,264 C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\viewe r\com\app.dll A
    iphlpapi.dll 0x76D60000 0x00019000 5.1.2600.2912 (xpsp_sp2_gdr.060519-0003) IP Helper API Microsoft Corporation Microsoft® Windows® Operating System 5/19/2006 8:59:41 AM 94,720 C:\WINDOWS\system32\iphlpapi.dll A
    SHELL32.dll 0x7C9C0000 0x00817000 6.00.2900.3241 (xpsp_sp2_qfe.071025-1245) Windows Shell Common Dll Microsoft Corporation Microsoft® Windows® Operating System 10/25/2007 11:34:01 PM 8,460,288 C:\WINDOWS\system32\SHELL32.dll A
    HID.DLL 0x688F0000 0x00009000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Hid User Library Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 20,992 C:\WINDOWS\system32\HID.DLL A
    SETUPAPI.dll 0x77920000 0x000F3000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows Setup API Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 983,552 C:\WINDOWS\system32\SETUPAPI.dll A
    WINTRUST.dll 0x76C30000 0x0002E000 5.131.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft Trust Verification APIs Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 176,640 C:\WINDOWS\system32\WINTRUST.dll A
    CRYPT32.dll 0x77A80000 0x00094000 5.131.2600.2180 (xpsp_sp2_rtm.040803-2158) Crypto API32 Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 597,504 C:\WINDOWS\system32\CRYPT32.dll A
    MSASN1.dll 0x77B20000 0x00012000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ASN.1 Runtime APIs Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 57,344 C:\WINDOWS\system32\MSASN1.dll A
    IMAGEHLP.dll 0x76C90000 0x00028000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows NT Image Helper Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 144,384 C:\WINDOWS\system32\IMAGEHLP.dll A
    rsaenh.dll 0x0FFD0000 0x00028000 5.1.2600.2161 (xpsp.040706-1629) Microsoft Enhanced Cryptographic Provider Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 152,576 C:\WINDOWS\system32\rsaenh.dll A
    userenv.dll 0x769C0000 0x000B3000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Userenv Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 723,456 C:\WINDOWS\system32\userenv.dll A
    Secur32.dll 0x77FE0000 0x00011000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Security Support Provider Interface Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 55,808 C:\WINDOWS\system32\Secur32.dll A
    NETAPI32.dll 0x5B860000 0x00054000 5.1.2600.2976 (xpsp_sp2_gdr.060817-0106) Net Win32 API DLL Microsoft Corporation Microsoft® Windows® Operating System 8/17/2006 8:28:27 AM 332,288 C:\WINDOWS\system32\NETAPI32.dll A
    cryptnet.dll 0x75E60000 0x00013000 5.131.2600.2180 (xpsp_sp2_rtm.040803-2158) Crypto Network Related API Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 63,488 C:\WINDOWS\system32\cryptnet.dll A
    WLDAP32.dll 0x76F60000 0x0002C000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Win32 LDAP API DLL Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 172,032 C:\WINDOWS\system32\WLDAP32.dll A
    WINHTTP.dll 0x4D4F0000 0x00058000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows HTTP Services Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 351,232 C:\WINDOWS\system32\WINHTTP.dll A
    SensApi.dll 0x722B0000 0x00005000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) SENS Connectivity API DLL Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 6,656 C:\WINDOWS\system32\SensApi.dll A
    D3DIM700.DLL 0x73940000 0x000D0000 5.03.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft Direct3D Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 825,344 C:\WINDOWS\system32\D3DIM700.DLL A
    wdmaud.drv 0x72D20000 0x00009000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) WDM Audio driver mapper Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 23,552 C:\WINDOWS\system32\wdmaud.drv A
    msacm32.drv 0x72D10000 0x00008000 5.1.2600.0 (xpclient.010817-1148) Microsoft Sound Mapper Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 20,480 C:\WINDOWS\system32\msacm32.drv A
    MSACM32.dll 0x77BE0000 0x00015000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft ACM Audio Filter Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 71,680 C:\WINDOWS\system32\MSACM32.dll A
    midimap.dll 0x77BD0000 0x00007000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft MIDI Mapper Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 18,944 C:\WINDOWS\system32\midimap.dll A
    KsUser.dll 0x73EE0000 0x00004000 5.3.2600.2180 (xpsp_sp2_rtm.040803-2158) User CSA Library Microsoft Corporation Microsoft(R) Windows(R) Operating System 8/4/2004 1:56:44 AM 4,096 C:\WINDOWS\system32\KsUser.dll A

  16. #76
    Campaign
    Join Date
    Mar 2006
    Posts
    6,192
    BG Level
    8

    There's a very good reason why we all say not to use IE.

    Yes, reformat your PC before playing. Get firefox & noscript and keep flash etc up to date.

  17. #77
    Chram
    Join Date
    Apr 2007
    Posts
    2,624
    BG Level
    7

    since I have some people who asked me about this today (I guess it wasn't clear yet that wzcvbxm.dll is a trojan heh) here's a link to information about it courtesy of trend micro

    it is a trojan, appears to be an auto-run hook, may self-contain the keylogger; may just provide a service so the keylogger can run. (unfortunately, trend micro is mostly concerned about system melting malware, so something that just scoops MMO passes doesn't cause much alarm over there.)

    IF YOU HAVE WZCVBXM.DLL, remove it first (trend micro has some suggestions on how) and then change your passwords promptly. it is a trojan.

Page 4 of 4 FirstFirst ... 2 3 4

Similar Threads

  1. ZIGMA CHANGE YOUR AVATAR.
    By Epical in forum FFXI: Everything
    Replies: 21
    Last Post: 2006-08-28, 02:31