<?xml version="1.0" encoding="utf-8"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>DaniWeb IT Discussion Community - Viruses, Spyware and other Nasties</title>
		<link>http://www.daniweb.com/forums/</link>
		<description><![CDATA[Our Viruses, Spyware and other Nasties forum is the place for Q&A-style discussions related to Windows security. Post a HijackThis log here if you think you've got viruses, spyware, adware, malware, or other unwanted guests.]]></description>
		<language>en-US</language>
		<lastBuildDate>Fri, 20 Nov 2009 22:01:39 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://www.daniweb.com/alphaimages/misc/rss.jpg</url>
			<title>DaniWeb IT Discussion Community - Viruses, Spyware and other Nasties</title>
			<link>http://www.daniweb.com/forums/</link>
		</image>
		<item>
			<title><![CDATA[IE, Firefox & computer random shut down]]></title>
			<link>http://www.daniweb.com/forums/thread239951.html</link>
			<pubDate>Fri, 20 Nov 2009 07:40:04 GMT</pubDate>
			<description><![CDATA[Hi, 
I have been having problems with random shut downs. I was only using IE and it started, so I installed Firefox and it was ok but now it's doing it there also. Sometimes it shuts Firefox down 2-4 times in a row(then I give up) and then will totally shut computer down. It restarts and wants to...]]></description>
			<content:encoded><![CDATA[<div>Hi,<br />
I have been having problems with random shut downs. I was only using IE and it started, so I installed Firefox and it was ok but now it's doing it there also. Sometimes it shuts Firefox down 2-4 times in a row(then I give up) and then will totally shut computer down. It restarts and wants to run disc check.<br />
Sometimes I might go to do something in my computer, say play a game and it will do it.<br />
I ran across this forum while searching for help. I went and got HijackThis and ran it. Below is the log.   Appreciate any help you could give.<br />
Thanks,<br />
Patty<br />
<br />
<br />
<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 11:17:15 PM, on 11/19/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16915)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Ahead\InCD\InCDsrv.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe<br />
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
C:\Program Files\iWin Games\iWinTrusted.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br />
C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br />
C:\WINDOWS\System32\taskswitch.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br />
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br />
C:\Program Files\ATI Multimedia\main\ATIDtct.EXE<br />
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe<br />
C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe<br />
C:\Program Files\AVG\AVG8\avgcsrvx.exe<br />
C:\WINDOWS\system32\devldr32.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe<br />
C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe<br />
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac<br />
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe<br />
C:\Program Files\Logitech\SetPoint\SetPoint.exe<br />
C:\WINDOWS\STK02N\STK02NM.exe<br />
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE<br />
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe<br />
C:\WINDOWS\system32\HPZipm12.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: IBBHO Class - {12BA043E-293E-4CE4-A8C7-8460934FE801} - C:\Program Files\IncrediBar\bin\IBBHO.dll (file missing)<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br />
O2 - BHO: IEHlprObj Class - {8CA5ED52-F3FB-4414-A105-2E3491156990} - C:\Program Files\iWin Games\iWinGamesHookIE.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: IncrediBar - {D8073790-84C7-4602-BF77-C6ACBF1612E4} - C:\Program Files\IncrediBar\bin\IBTBar.dll (file missing)<br />
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe<br />
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp<br />
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe<br />
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe<br />
O4 - HKLM\..\Run: [ccApp] &quot;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&quot;<br />
O4 - HKLM\..\Run: [ATIPTA] &quot;C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&quot;<br />
O4 - HKLM\..\Run: [ATI DeviceDetect] &quot;C:\Program Files\ATI Multimedia\main\ATIDtct.EXE&quot;<br />
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [StartCCC] &quot;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&quot; MSRun<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe<br />
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [OM2_Monitor] &quot;C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe&quot; -NoStart<br />
O4 - HKUS\S-1-5-18\..\RunOnce: [Printing Migration] rundll32.exe C:\WINDOWS\System32\spool\migrate.dll,ProcessWin9xNetworkPrinters (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\RunOnce: [Printing Migration] rundll32.exe C:\WINDOWS\System32\spool\migrate.dll,ProcessWin9xNetworkPrinters (User 'Default user')<br />
O4 - Global Startup: hpoddt01.exe.lnk = ?<br />
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe<br />
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe<br />
O4 - Global Startup: STK02N 2.4 PNP Monitor.lnk = ?<br />
O8 - Extra context menu item: &amp;Search - <a rel="nofollow" class="t" href="http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJman000" target="_blank">http://edits.mywebsearch.com/toolbar...tml?p=ZJman000</a><br />
O8 - Extra context menu item: Add to Google Photos Screensa&amp;ver - res://C:\WINDOWS\system32\GPhotos.scr/200<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: IncrediBar - {023FA804-DCE1-4817-94ED-6BA4200F9AF2} - C:\Program Files\IncrediBar\bin\IBTBar.dll (file missing)<br />
O9 - Extra button: Wallpaper - {c23dd370-cb79-11d2-898a-00c04f80a47f} - C:\PROGRA~1\INTERN~1\Toolbar\toolbar.hta (file missing)<br />
O9 - Extra 'Tools' menuitem: &amp;Toolbar Wallpaper - {c23dd370-cb79-11d2-898a-00c04f80a47f} - C:\PROGRA~1\INTERN~1\Toolbar\toolbar.hta (file missing)<br />
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Patty.MINE\Start Menu\Programs\IMVU\Run IMVU.lnk<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll<br />
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - <a rel="nofollow" class="t" href="http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab" target="_blank">http://a1540.g.akamai.net/7/1540/52/...x/qtplugin.cab</a><br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - <a rel="nofollow" class="t" href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" target="_blank">http://upload.facebook.com/controls/...oUploader5.cab</a><br />
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - <a rel="nofollow" class="t" href="http://www.pcpitstop.com/betapit/PCPitStop.CAB" target="_blank">http://www.pcpitstop.com/betapit/PCPitStop.CAB</a><br />
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Laura%20Jones%20and%20the%20Secret%20Legacy%20of%20Nikola%20Tesla/Images/stg_drm.ocx<br />
O16 - DPF: {21F16767-8DA7-4113-BEB0-F161B313407F} - <a rel="nofollow" class="t" href="http://www.myfamily.com/plugins/ue/Install_UE.exe" target="_blank">http://www.myfamily.com/plugins/ue/Install_UE.exe</a><br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll<br />
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - <a rel="nofollow" class="t" href="http://disney.go.com/pirates/online/testActiveX/built/signed/DisneyOnlineGames.cab" target="_blank">http://disney.go.com/pirates/online/...nlineGames.cab</a><br />
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - <a rel="nofollow" class="t" href="http://www1.snapfish.com/SnapfishActivia.cab" target="_blank">http://www1.snapfish.com/SnapfishActivia.cab</a><br />
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - <a rel="nofollow" class="t" href="http://a1540.g.akamai.net/7/1540/52/20021017/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe" target="_blank">http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe</a><br />
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - <a rel="nofollow" class="t" href="http://lads.myspace.com/upload/MySpaceUploader1006.cab" target="_blank">http://lads.myspace.com/upload/MySpaceUploader1006.cab</a><br />
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} - <a rel="nofollow" class="t" href="http://ipgweb.cce.hp.com/rdqna/downloads/sysinfo.cab" target="_blank">http://ipgweb.cce.hp.com/rdqna/downloads/sysinfo.cab</a><br />
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - <a rel="nofollow" class="t" href="http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase370.cab" target="_blank">http://cdn.scan.onecare.live.com/res...lscbase370.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a rel="nofollow" class="t" href="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093403994969" target="_blank">http://v5.windowsupdate.microsoft.co...?1093403994969</a><br />
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - <a rel="nofollow" class="t" href="http://download.divx.com/player/DivXBrowserPlugin.cab" target="_blank">http://download.divx.com/player/DivXBrowserPlugin.cab</a><br />
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - <a rel="nofollow" class="t" href="http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab" target="_blank">http://h20270.www2.hp.com/ediags/gmn...tDetection.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a rel="nofollow" class="t" href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1129599250118" target="_blank">http://update.microsoft.com/microsof...?1129599250118</a><br />
O16 - DPF: {75565ED2-1560-4F15-B841-20358DE6A0D1} (ImageControl Class) - <a rel="nofollow" class="t" href="http://content.ancestry.com/asfiles/files/install/MFImgVwr.cab" target="_blank">http://content.ancestry.com/asfiles/...l/MFImgVwr.cab</a><br />
O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - <a rel="nofollow" class="t" href="http://ww2.cascade.k12.or.us/remote/msrdp.cab" target="_blank">http://ww2.cascade.k12.or.us/remote/msrdp.cab</a><br />
O16 - DPF: {775879E2-7309-4619-BB02-AADE41F4B690} (CPlayFirstdreamControl Object) - <a rel="nofollow" class="t" href="http://games.bigfishgames.com/en_dream-chronicles/online/dreamweb.1.0.0.9.cab" target="_blank">http://games.bigfishgames.com/en_dre...eb.1.0.0.9.cab</a><br />
O16 - DPF: {7D731A83-6C80-4EA4-9646-5E06A0513274} (Sandlot Loader Control) - <a rel="nofollow" class="t" href="http://www.shockwave.com/content/snailmail/sis/slgwebinstall.cab" target="_blank">http://www.shockwave.com/content/sna...webinstall.cab</a><br />
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - <a rel="nofollow" class="t" href="http://zone.msn.com/bingame/luxr/default/mjolauncher.cab" target="_blank">http://zone.msn.com/bingame/luxr/def...jolauncher.cab</a><br />
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - <a rel="nofollow" class="t" href="http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab" target="_blank">http://dm.screensavers.com/dm/instal...sinstaller.cab</a><br />
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - <a rel="nofollow" class="t" href="http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll" target="_blank">http://us.dl1.yimg.com/download.yaho...ymmapi_416.dll</a><br />
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - <a rel="nofollow" class="t" href="http://offers.e-centives.com/cif/download/bin/actxcab.cab" target="_blank">http://offers.e-centives.com/cif/dow...in/actxcab.cab</a><br />
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - <a rel="nofollow" class="t" href="https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx" target="_blank">https://h17000.www1.hp.com/ewfrf-JAV...oadManager.ocx</a><br />
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - <a rel="nofollow" class="t" href="http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab" target="_blank">http://cdn2.zone.msn.com/binFramewor...o.cab56649.cab</a><br />
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} (Create &amp; Print ActiveX Plug-in) - <a rel="nofollow" class="t" href="http://ak.imgag.com/imgag/cp/install/AxCtp2.cab" target="_blank">http://ak.imgag.com/imgag/cp/install/AxCtp2.cab</a><br />
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - <a rel="nofollow" class="t" href="https://disney.go.com/games/downloads/gamemanager/DIGGameManager.cab" target="_blank">https://disney.go.com/games/download...ameManager.cab</a><br />
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Mortimer%20Beckett/Images/armhelper.ocx<br />
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - <br />
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - <a rel="nofollow" class="t" href="http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe" target="_blank">http://a532.g.akamai.net/f/532/6712/.../installer.exe</a><br />
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} - <a rel="nofollow" class="t" href="http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab" target="_blank">http://mvnet.xlontech.net/qm/fox/061...ie06101001.cab</a><br />
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - <a rel="nofollow" class="t" href="http://www.driveragent.com/files/driveragent.cab" target="_blank">http://www.driveragent.com/files/driveragent.cab</a><br />
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - <a rel="nofollow" class="t" href="http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326" target="_blank">http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe<br />
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe<br />
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe<br />
O23 - Service: iWinTrusted - iWin Inc. - C:\Program Files\iWin Games\iWinTrusted.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe<br />
<br />
--<br />
End of file - 14444 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>record59</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread239951.html</guid>
		</item>
		<item>
			<title>Huge issue</title>
			<link>http://www.daniweb.com/forums/thread239925.html</link>
			<pubDate>Fri, 20 Nov 2009 05:29:29 GMT</pubDate>
			<description><![CDATA[Okay, so I can start up my computer in safe mode with networking and  follow the steps in the "Read me before posting a request" thread. However, once I reboot, my computer pretty much locks up.  any help would be greatly apprcieated. 
 
Malwarebytes' Anti-Malware 1.41 
Database version: 3197...]]></description>
			<content:encoded><![CDATA[<div>Okay, so I can start up my computer in safe mode with networking and  follow the steps in the &quot;Read me before posting a request&quot; thread. However, once I reboot, my computer pretty much locks up.  any help would be greatly apprcieated.<br />
<br />
Malwarebytes' Anti-Malware 1.41<br />
Database version: 3197<br />
Windows 5.1.2600 Service Pack 3 (Safe Mode)<br />
<br />
11/19/2009 2:01:09 PM<br />
mbam-log-2009-11-19 (14-01-09).txt<br />
<br />
Scan type: Full Scan (C:\|)<br />
Objects scanned: 218491<br />
Time elapsed: 38 minute(s), 21 second(s)<br />
<br />
Memory Processes Infected: 0<br />
Memory Modules Infected: 0<br />
Registry Keys Infected: 0<br />
Registry Values Infected: 0<br />
Registry Data Items Infected: 0<br />
Folders Infected: 0<br />
Files Infected: 0<br />
<br />
Memory Processes Infected:<br />
(No malicious items detected)<br />
<br />
Memory Modules Infected:<br />
(No malicious items detected)<br />
<br />
Registry Keys Infected:<br />
(No malicious items detected)<br />
<br />
Registry Values Infected:<br />
(No malicious items detected)<br />
<br />
Registry Data Items Infected:<br />
(No malicious items detected)<br />
<br />
Folders Infected:<br />
(No malicious items detected)<br />
<br />
Files Infected:<br />
(No malicious items detected)<br />
<br />
ESETSmartInstaller@High as CAB hook log:<br />
OnlineScanner.ocx - registred OK<br />
# version=7<br />
# iexplore.exe=7.00.6000.16915 (vista_gdr.090826-0339)<br />
# OnlineScanner.ocx=1.0.0.6211<br />
# api_version=3.0.2<br />
# EOSSerial=35a1823d93d4d3408880ed39dfa54579<br />
# end=finished<br />
# remove_checked=false<br />
# archives_checked=false<br />
# unwanted_checked=true<br />
# unsafe_checked=false<br />
# antistealth_checked=true<br />
# utc_time=2009-11-19 09:59:29<br />
# local_time=2009-11-19 03:59:29 (-0600, Central Standard Time)<br />
# country=&quot;United States&quot;<br />
# lang=1033<br />
# osver=5.1.2600 NT Service Pack 3<br />
# compatibility_mode=8192 67108863 100 0 0 0 0 0<br />
# scanned=74106<br />
# found=0<br />
# cleaned=0<br />
# scan_time=1676<br />
<br />
DDS (Ver_09-10-26.01) - NTFSx86 NETWORK <br />
Run by r000063 at 16:56:58.85 on Thu 11/19/2009<br />
Internet Explorer: 7.0.5730.11<br />
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.502.260 [GMT -6:00]<br />
<br />
AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning enabled* (Updated)   {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}<br />
<br />
============== Running Processes ===============<br />
<br />
C:\WINDOWS\system32\svchost -k DcomLaunch<br />
svchost.exe<br />
C:\WINDOWS\system32\svchost.exe -k netsvcs<br />
svchost.exe<br />
svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Documents and Settings\r000063\Desktop\dds.scr<br />
<br />
============== Pseudo HJT Report ===============<br />
<br />
uStart Page = hxxp://www.google.com/ig?hl=en<br />
uSearch Page = hxxp://www.google.com/hws/sb/dell-usuk-rel/en/side.html?channel=us<br />
uSearch Bar = hxxp://www.google.com/hws/sb/dell-usuk-rel/en/side.html?channel=us<br />
uDefault_Page_URL = <a rel="nofollow" class="t" href="http://www.google.com/ig/dell?hl=en&amp;client=dell-usuk-rel&amp;channel=us" target="_blank">http://www.google.com/ig/dell?hl=en&amp;...rel&amp;channel=us</a><br />
uInternet Settings,ProxyOverride = *.local<br />
mSearchAssistant = hxxp://www.google.com/hws/sb/dell-usuk-rel/en/side.html?channel=us<br />
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll<br />
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll<br />
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan enterprise\scriptcl.dll<br />
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll<br />
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File<br />
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe<br />
uRun: [H/PC Connection Agent] &quot;c:\progra~1\mi3aa1~1\wcescomm.exe&quot;<br />
mRun: [Apoint] c:\program files\apoint\Apoint.exe<br />
mRun: [igfxtray] c:\windows\system32\igfxtray.exe<br />
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe<br />
mRun: [igfxpers] c:\windows\system32\igfxpers.exe<br />
mRun: [SunJavaUpdateSched] &quot;c:\program files\java\jre1.6.0_05\bin\jusched.exe&quot;<br />
mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe<br />
mRun: [SigmatelSysTrayApp] stsystra.exe<br />
mRun: [DVDLauncher] &quot;c:\program files\cyberlink\powerdvd\DVDLauncher.exe&quot;<br />
mRun: [AdaptecDirectCD] &quot;c:\program files\roxio\easy cd creator 5\directcd\DirectCD.exe&quot;<br />
mRun: [Adobe Reader Speed Launcher] &quot;c:\program files\adobe\reader 8.0\reader\Reader_sl.exe&quot;<br />
mRun: [ShStatEXE] &quot;c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE&quot; /STANDALONE<br />
mRun: [McAfeeUpdaterUI] &quot;c:\program files\mcafee\common framework\UdaterUI.exe&quot; /StartedFromRunKey<br />
mRun: [GoBoingo] c:\program files\boingo\goboingo\GoBoingo.lnk<br />
mRun: [QuickTime Task] &quot;c:\program files\quicktime\qttask.exe&quot; -atboottime<br />
mRun: [iTunesHelper] &quot;c:\program files\itunes\iTunesHelper.exe&quot;<br />
mRun: [Malwarebytes Anti-Malware (reboot)] &quot;c:\program files\malwarebytes' anti-malware\mbam.exe&quot; /runcleanupscript<br />
mRun: [CaISSDT] &quot;c:\program files\ca\etrust internet security suite\caissdt.exe&quot;<br />
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent<br />
mRunOnce: [eISS_licreg] &quot;c:\program files\ca\etrust internet security suite\licreg.exe&quot; /s<br />
mRunOnce: [AOLRebootNeeded] regsvr32.exe /s<br />
dRunOnce: [TSClientMSIUninstaller] cmd.exe /C &quot;cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs&quot;<br />
dRunOnce: [TSClientAXDisabler] cmd.exe /C &quot;%systemroot%\Installer\TSClientMsiTrans\tscdsbl.bat&quot;<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ciscos~1.lnk - c:\program files\cisco systems\vpn client\vpngui.exe<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe<br />
IE: &amp;Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html<br />
IE: &amp;Translate English Word - c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html<br />
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html<br />
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000<br />
IE: Lookup on Merriam Webster - file://c:\program files\iespell\Merriam Webster.HTM<br />
IE: Lookup on Wikipedia - file://c:\program files\iespell\wikipedia.HTM<br />
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html<br />
IE: Translate Page into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html<br />
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe<br />
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe<br />
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll<br />
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll<br />
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL<br />
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab<br />
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204<br />
DPF: {32505657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/0/A/9/0A9F8B32-9F8C-4D74-A130-E4CAB36EB01F/wmvadvd.cab<br />
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1258664590328<br />
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab<br />
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab<br />
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab<br />
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://attwm.webex.com/client/T25L10NSP41EP15-attwm/webex/ieatgpc.cab<br />
DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5806/mcfscan.cab<br />
Notify: igfxcui - igfxdev.dll<br />
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll<br />
<br />
============= SERVICES / DRIVERS ===============<br />
<br />
S2 AM.EventService;Access Manager Event Service;c:\program files\remote services\AM.utEventServer.exe [2007-2-19 28672]<br />
S2 AM.ScriptService;Access Manager Script Service;c:\program files\remote services\AM.blScriptEngine.exe [2007-2-19 28672]<br />
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-9-15 24652]<br />
S3 AM.InstallService;Access Manager Install Service;c:\program files\remote services\AM.InstallService.exe [2007-2-19 81920]<br />
S3 BW2NDIS5;BW2NDIS5 NDIS Protocol Driver;c:\windows\system32\drivers\bw2ndis5.sys --&gt; c:\windows\system32\drivers\BW2NDIS5.sys [?]<br />
S3 MCI Wireless Engine;MCI Wireless Engine;c:\program files\remote services\wengine2\BWEngine.exe [2007-2-1 823296]<br />
S3 MCI WMonitor;MCI WMonitor;c:\program files\remote services\wengine2\WMonitor.exe [2007-2-1 73728]<br />
S3 ProService8.2C;ProService for 8.2C;c:\dlc\bin\prosrvc.exe [2006-7-20 30208]<br />
<br />
=============== Created Last 30 ================<br />
<br />
2009-11-19 21:28:43	0	d-----w-	c:\program files\ESET<br />
2009-11-19 21:07:44	0	d-----w-	c:\program files\CA<br />
2009-11-19 20:04:56	0	d-----w-	c:\windows\McAfee.com<br />
2009-11-19 20:04:53	0	d-----w-	c:\windows\LastGood.Tmp<br />
2009-11-19 18:49:18	0	d-----w-	c:\docume~1\r000063\applic~1\Malwarebytes<br />
2009-11-19 18:49:09	38224	----a-w-	c:\windows\system32\drivers\mbamswissarmy.sys<br />
2009-11-19 18:49:07	19160	----a-w-	c:\windows\system32\drivers\mbam.sys<br />
2009-11-19 18:49:07	0	d-----w-	c:\docume~1\alluse~1\applic~1\Malwarebytes<br />
2009-11-19 18:49:06	0	d-----w-	c:\program files\Malwarebytes' Anti-Malware<br />
2009-11-17 16:11:45	3247	----a-w-	c:\windows\system32\wbem\Outlook_01ca67a0a8484abe.mof<br />
2009-11-11 00:30:15	0	d-----w-	c:\program files\iPod<br />
2009-11-11 00:29:49	0	d-----w-	c:\program files\iTunes<br />
2009-11-11 00:29:49	0	d-----w-	c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD}<br />
2009-10-21 04:18:56	1435648	------w-	c:\windows\system32\dllcache\query.dll<br />
2009-10-21 04:10:58	58880	------w-	c:\windows\system32\dllcache\msasn1.dll<br />
<br />
==================== Find3M  ====================<br />
<br />
2009-10-21 04:08:54	3598336	----a-w-	c:\windows\system32\dllcache\mshtml.dll<br />
2009-09-11 14:18:39	136192	----a-w-	c:\windows\system32\msv1_0.dll<br />
2009-09-11 14:18:39	136192	------w-	c:\windows\system32\dllcache\msv1_0.dll<br />
2009-09-04 21:03:36	58880	----a-w-	c:\windows\system32\msasn1.dll<br />
2009-08-31 16:16:29	110416	----a-w-	c:\windows\hpoins11.dat<br />
2009-08-28 10:28:59	70656	------w-	c:\windows\system32\dllcache\ie4uinit.exe<br />
2009-08-28 10:28:59	13824	------w-	c:\windows\system32\dllcache\ieudinit.exe<br />
2009-08-27 05:18:44	634648	------w-	c:\windows\system32\dllcache\iexplore.exe<br />
2009-08-27 05:18:41	161792	------w-	c:\windows\system32\dllcache\ieakui.dll<br />
2009-08-26 08:00:21	247326	----a-w-	c:\windows\system32\strmdll.dll<br />
2009-08-26 08:00:21	247326	------w-	c:\windows\system32\dllcache\strmdll.dll<br />
<br />
============= FINISH: 16:57:20.23 ===============</div>  <br /> <div style="padding:5px">     <fieldset class="fieldset"> <legend>Attached Files</legend> <table cellpadding="0" cellspacing="5" border="0"> <tr> <td><img class="inlineimg" src="http://www.daniweb.com/forums/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td> <td><a href="http://www.daniweb.com/forums/attachment.php?attachmentid=12644&amp;d=1258694958">Attach.txt</a> (16.5 KB)</td> </tr> </table> </fieldset>  </div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>jvcycling</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread239925.html</guid>
		</item>
		<item>
			<title>LOP in fection</title>
			<link>http://www.daniweb.com/forums/thread239838.html</link>
			<pubDate>Thu, 19 Nov 2009 20:28:10 GMT</pubDate>
			<description>Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 20:27:40, on 19/11/2009 
Platform: Windows XP SP3 (WinNT 5.01.2600) 
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) 
Boot mode: Normal 
 
Running processes: 
C:\WINDOWS\System32\smss.exe 
C:\WINDOWS\system32\winlogon.exe...</description>
			<content:encoded><![CDATA[<div>Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 20:27:40, on 19/11/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Analog Devices\Core\smax4pnp.exe<br />
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe<br />
C:\WINDOWS\vsnp2uvc.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
C:\Program Files\DNA\btdna.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\iPod Access for Windows\iPAHelper.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\DAP\DAP.EXE<br />
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe<br />
C:\Program Files\Pando Networks\Media Booster\PMB.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br />
C:\WINDOWS\System32\TUProgSt.exe<br />
C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br />
C:\Program Files\BT Business Hub\Wireless Configuration\WirelessDaemon.exe<br />
C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
C:\Program Files\AVG\AVG8\avgcsrvx.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Java\jre6\bin\jucheck.exe<br />
C:\Program Files\Windows Live\Contacts\wlcomm.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\SpybotSD.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\WINDOWS\system32\taskmgr.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = &gt;&gt;&gt; 'Full Speed' Enabled &lt;&lt;&lt;<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O2 - BHO: DAPIELoader Class - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRA~1\DAP\DAPIEL~1.DLL<br />
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O3 - Toolbar: &amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [ATIPTA] &quot;C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&quot;<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [GrooveMonitor] &quot;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&quot;<br />
O4 - HKLM\..\Run: [Love default global mess] C:\Documents and Settings\All Users\Application Data\great coal love default\Joy Up.exe<br />
O4 - HKLM\..\Run: [snp2uvc] C:\WINDOWS\vsnp2uvc.exe<br />
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br />
O4 - HKCU\..\Run: [msnmsgr] &quot;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&quot; /background<br />
O4 - HKCU\..\Run: [BitTorrent DNA] &quot;C:\Program Files\DNA\btdna.exe&quot;<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [Blah Sixth] C:\DOCUME~1\RISHIS~1\APPLIC~1\DATAEN~1\REMOTE CLOCK.exe<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;<br />
O4 - HKCU\..\Run: [DownloadAccelerator] &quot;C:\Program Files\DAP\DAP.EXE&quot; /STARTUP<br />
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe<br />
O8 - Extra context menu item: &amp;Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm<br />
O8 - Extra context menu item: &amp;Download with &amp;DAP - C:\Program Files\DAP\dapextie.htm<br />
O8 - Extra context menu item: Download &amp;all with DAP - C:\Program Files\DAP\dapextie2.htm<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O10 - Broken Internet access because of LSP provider 'c:\program files\bonjour\mdnsnsp.dll' missing<br />
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - <a rel="nofollow" class="t" href="http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab" target="_blank">http://messenger.zone.msn.com/binary...r.cab56986.cab</a><br />
O16 - DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} - <a rel="nofollow" class="t" href="http://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/mjss/MJSS.cab109791.cab" target="_blank">http://messenger.zone.msn.com/Messen....cab109791.cab</a><br />
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - <a rel="nofollow" class="t" href="http://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab" target="_blank">http://messenger.zone.msn.com/Messen.../GAME_UNO1.cab</a><br />
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - <a rel="nofollow" class="t" href="http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab" target="_blank">http://messenger.zone.msn.com/binary...t.cab56907.cab</a><br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll<br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe<br />
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: iPAHelper.exe - Unknown owner - C:\Program Files\iPod Access for Windows\iPAHelper.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe<br />
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe<br />
O23 - Service: Wireless Adapter Configurator - Unknown owner - C:\Program Files\BT Business Hub\Wireless Configuration\WirelessDaemon.exe<br />
<br />
--<br />
End of file - 11370 bytes<br />
<br />
<br />
help pls, ive done 3 virus scan checks with malware anti bytes, avg. I've used ccleaner.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>rishi123</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread239838.html</guid>
		</item>
		<item>
			<title>blocage des page web</title>
			<link>http://www.daniweb.com/forums/thread239788.html</link>
			<pubDate>Thu, 19 Nov 2009 15:40:41 GMT</pubDate>
			<description><![CDATA[aujourd'hui j'ai constaté que vers 15 h chaque que je connecte, mes pages web sont bloquer par "OpensDNS" "this domain is blocked". "Egalement ma boite E-mail. Je vous remercie de votre aide, qui m'éclairerais]]></description>
			<content:encoded><![CDATA[<div>aujourd'hui j'ai constaté que vers 15 h chaque que je connecte, mes pages web sont bloquer par &quot;OpensDNS&quot; &quot;this domain is blocked&quot;. &quot;Egalement ma boite E-mail. Je vous remercie de votre aide, qui m'éclairerais</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>beddou4</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread239788.html</guid>
		</item>
		<item>
			<title>Help with hijackthis log</title>
			<link>http://www.daniweb.com/forums/thread239782.html</link>
			<pubDate>Thu, 19 Nov 2009 15:29:02 GMT</pubDate>
			<description>Can I please have a second set of eyes look through my log for anything that jomps out at you? Much appreciated! 
 
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 10:11:48 AM, on 11/19/2009 
Platform: Windows XP SP3 (WinNT 5.01.2600) 
MSIE: Internet Explorer v7.00 (7.00.6000.16915) 
Boot...</description>
			<content:encoded><![CDATA[<div>Can I please have a second set of eyes look through my log for anything that jomps out at you? Much appreciated!<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 10:11:48 AM, on 11/19/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16915)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\WINDOWS\ATKKBService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe<br />
C:\WINDOWS\system32\CTsvcCDA.EXE<br />
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\Program Files\LogMeIn\x86\RaMaint.exe<br />
C:\Program Files\LogMeIn\x86\LogMeIn.exe<br />
C:\Program Files\LogMeIn\x86\LMIGuardian.exe<br />
c:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe<br />
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe<br />
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe<br />
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe<br />
C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\SearchIndexer.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Analog Devices\Core\smax4pnp.exe<br />
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe<br />
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe<br />
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe<br />
C:\Program Files\QuickTime\QTTask.exe<br />
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe<br />
C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\LogMeIn\x86\LMIGuardian.exe<br />
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe<br />
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe<br />
C:\Program Files\Messenger\msmsgs.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br />
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe<br />
C:\Program Files\Windows Desktop Search\WindowsSearch.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe<br />
C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe<br />
C:\Program Files\Java\jre6\bin\jucheck.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
F:\WINDOWS\ironkey.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\WINDOWS\system32\SearchProtocolHost.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br />
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe<br />
O4 - HKLM\..\Run: [SoundMAX] &quot;C:\Program Files\Analog Devices\SoundMAX\Smax4.exe&quot; /tray<br />
O4 - HKLM\..\Run: [ATIPTA] &quot;C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&quot;<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [ATICCC] &quot;C:\Program Files\ATI Technologies\ATI.ACE\cli.exe&quot; runtime -Delay<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] &quot;C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe&quot;<br />
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe  startup<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [LogMeIn GUI] &quot;C:\Program Files\LogMeIn\x86\LogMeInSystray.exe&quot;<br />
O4 - HKLM\..\Run: [EEventManager] C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [BkupTray] &quot;C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe&quot;<br />
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R<br />
O4 - HKCU\..\Run: [MSMSGS] &quot;C:\Program Files\Messenger\msmsgs.exe&quot; /background<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [updateMgr] &quot;C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe&quot; AcPro7_1_0 -reboot 1<br />
O4 - HKCU\..\Run: [EPSON WorkForce 600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEKA.EXE /FU &quot;C:\WINDOWS\TEMP\E_S331.tmp&quot; /EF &quot;HKCU&quot;<br />
O4 - Startup: PMB Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe<br />
O4 - Startup: Shortcut to time sync.bat.lnk = C:\Documents and Settings\Joe\My Documents\time sync.bat<br />
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?<br />
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe<br />
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br />
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe<br />
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe<br />
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O15 - Trusted Zone: <a rel="nofollow" class="t" href="http://www.franklincovey.com" target="_blank">http://www.franklincovey.com</a><br />
O15 - Trusted Zone: <a rel="nofollow" class="t" href="http://www.kyw1060.com" target="_blank">http://www.kyw1060.com</a><br />
O15 - Trusted IP range: <a rel="nofollow" class="t" href="http://195.95.*.*" target="_blank">http://195.95.*.*</a><br />
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - <a rel="nofollow" class="t" href="http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab" target="_blank">http://wwwimages.adobe.com/www.adobe...bat/nos/gp.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a rel="nofollow" class="t" href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - <a rel="nofollow" class="t" href="https://secure.logmein.com/activex/ractrl.cab?lmi=100" target="_blank">https://secure.logmein.com/activex/ractrl.cab?lmi=100</a><br />
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ********.com<br />
O17 - HKLM\Software\..\Telephony: DomainName = ********.com<br />
O17 - HKLM\System\CCS\Services\Tcpip\..\{C28702F5-B482-474F-ACBA-6BA377AC7B79}: NameServer = 192.168.0.12,192.168.0.10<br />
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ********.com<br />
O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2006\HelpAsyncPluggableProtocol.dll<br />
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)<br />
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe<br />
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe<br />
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE<br />
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe<br />
O23 - Service: Google Update Service (gupdate1c9915591436c19) (gupdate1c9915591436c19) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe<br />
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe<br />
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe<br />
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe<br />
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe<br />
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe<br />
O23 - Service: QuickBooksDB19 - Intuit, Inc. - C:\PROGRA~1\Intuit\QUICKB~1\QBDBMgrN.exe<br />
O23 - Service: SlingAgentService - Sling Media Inc. - C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe<br />
<br />
--<br />
End of file - 12949 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>lanmike09</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread239782.html</guid>
		</item>
		<item>
			<title>News Story OMG! Gumblar gets busy</title>
			<link>http://www.daniweb.com/news/story239735.html</link>
			<pubDate>Thu, 19 Nov 2009 12:25:32 GMT</pubDate>
			<description>I just had a Jaws moment. You know, you think it is safe to go back in the water and then a bloody great shark bites your legs off. Except in this case you can replace the sea with the Internet and the shark with the equally dangerous Gumblar (http://www.daniweb.com/blogs/entry4339.html). 
...</description>
			<content:encoded><![CDATA[<div>I just had a Jaws moment. You know, you think it is safe to go back in the water and then a bloody great shark bites your legs off. Except in this case you can replace the sea with the Internet and the shark with the <a rel="nofollow" class="t" href="http://www.daniweb.com/blogs/entry4339.html" target="_blank">equally dangerous Gumblar</a>.<br />
<br />
According to the <a rel="nofollow" class="t" href="http://www.scansafe.com/gtr" target="_blank">latest ScanSafe numbers</a>, Gumblar was responsible for a whopping 29% of all the web malware blocks it saw during October. Gumblar, in case you were wondering, is the collective name for a family of website compromises which are particularly nasty. Using a variety of routes to infection, Gumblar will install traffic sniffers and backdoors on computers, and exploit stolen FTP data to compromise web servers and sites. <br />
 <br />
During the course of October it began to put a backdoor botnet to use as a malware host, something very rarely seen as botnets are usually used to distribute and attack rather than host malware. To make matters even more worrisome, Gumblar has been dynamically constructing the hosted malware at the time of access to ensure users are delivered different exploits dependent on factors such as browser type for example. Throw in the use of dynamic obfuscation and you start to understand why Gumblar is proving to be such a troublesome beast. Once a Gumblar family exploit has been successfully installed via a visit to a compromised site, it is able to intercept all web traffic in both directions.<br />
<br />
&quot;Gumblar is arguably one of the most insidious threats facing both Web surfers and website operators today&quot; Mary Landesman, senior security researcher at ScanSafe, argues &quot;disturbingly, in early November, we detected that the backdoor left in place on the compromised websites by the Gumblar attackers was being leveraged by other groups of attackers meaning that the sites were under their control. This exacerbates the seriousness of the situation&quot;.<br />
<br />
Landesman admits that the implications of this evolutionary departure from the norm displayed by Gumblar when it comes to installing PHP backdoors on compromised websites and using them as the actual malware host are rather staggering. &quot;When a typical outbreak of website compromises occur, there are generally only a few actual malware domains involved&quot; Landesman explains, adding &quot;in the case of Gumblar, conservatively there are at least 2,000 backdoored websites serving as actual malware hosts. As a result, there is no single or few points at which to target efforts to shutdown the source of malware&quot;.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>happygeek</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread239735.html</guid>
		</item>
		<item>
			<title>Hijack this log</title>
			<link>http://www.daniweb.com/forums/thread239307.html</link>
			<pubDate>Tue, 17 Nov 2009 23:19:03 GMT</pubDate>
			<description>Please review this log from windows XP</description>
			<content:encoded><![CDATA[<div>Please review this log from windows XP</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>jgc3912</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread239307.html</guid>
		</item>
		<item>
			<title>rootkit problem</title>
			<link>http://www.daniweb.com/forums/thread239293.html</link>
			<pubDate>Tue, 17 Nov 2009 21:44:15 GMT</pubDate>
			<description>Have got vista 
got told that I had a MBR 3 weeks ago got charged £45 to get rid of it and re-istall my OS 
last week avg found I had trojans and rootkits on so went back to shop he said comp full of them, only paid £15 and he just wiped my hard drive and I re-installed it myself, I assume my Os...</description>
			<content:encoded><![CDATA[<div>Have got vista<br />
got told that I had a MBR 3 weeks ago got charged £45 to get rid of it and re-istall my OS<br />
last week avg found I had trojans and rootkits on so went back to shop he said comp full of them, only paid £15 and he just wiped my hard drive and I re-installed it myself, I assume my Os disk was okay<br />
<br />
put avg 9 and malware bytes, mawarebytes made my hard drive make a funny noise, so removed it, everything okay till ran rootkit scan and it found one<br />
<br />
kept off sites that are dodgy, only been on justin tv watching sports<br />
<br />
avg says i have &quot;C:\Windows\system32\drivers\mbamswissarmy.sys&quot;;&quot;Hidden driver&quot;;&quot;Object is hidden&quot; and asks me if I really want to delete it, do I deleted it<br />
<br />
dont want to spend anymore money getting it fixed so any help would be appreciated. dont mind paying small amount, am sick to death of it</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>cc2009</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread239293.html</guid>
		</item>
		<item>
			<title>combofix</title>
			<link>http://www.daniweb.com/forums/thread239155.html</link>
			<pubDate>Tue, 17 Nov 2009 08:11:06 GMT</pubDate>
			<description>i would like to know how to edit my registry after combofix scan and how to detect the infected files.</description>
			<content:encoded><![CDATA[<div>i would like to know how to edit my registry after combofix scan and how to detect the infected files.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>omondi100</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread239155.html</guid>
		</item>
		<item>
			<title>The Shield Deluxe 2010 antivirus question.</title>
			<link>http://www.daniweb.com/forums/thread239111.html</link>
			<pubDate>Tue, 17 Nov 2009 04:30:35 GMT</pubDate>
			<description>Anybody know much about this av program.  It is cheap but rated an editors choice.</description>
			<content:encoded><![CDATA[<div>Anybody know much about this av program.  It is cheap but rated an editors choice.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>ingeborgdot@yah</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread239111.html</guid>
		</item>
		<item>
			<title>laptop keyboard virus or internal problem????</title>
			<link>http://www.daniweb.com/forums/thread238977.html</link>
			<pubDate>Mon, 16 Nov 2009 17:00:35 GMT</pubDate>
			<description><![CDATA[This problem with my laptop keyboard has been going on for a while now.  
Initially I press "s" key, it goes erratic and types "sssssssssssssssssssssss"  
 
Now when I try to log in it wont let me type my password untill its been on for 30mins and the screen saver is activated. Once it lets me on...]]></description>
			<content:encoded><![CDATA[<div>This problem with my laptop keyboard has been going on for a while now. <br />
Initially I press &quot;s&quot; key, it goes erratic and types &quot;sssssssssssssssssssssss&quot; <br />
<br />
Now when I try to log in it wont let me type my password untill its been on for 30mins and the screen saver is activated. Once it lets me on the following things happen:<br />
1) sometimes when i try to open a browser, it opens the properties box of internet explorer instead (then I'll have to start the whole process of re starting and waiting for half hour for screensaver before it types my password and lets me on)<br />
<br />
2) It will open the browser normally but then say after 20 mins of browsing, the file, edit etc taskbar only, starts to flicker incessantly and laptop makes booting noises (whatever that is). After that it stops to type and then i'll repeat the whole process of switching off on, wait 30mins for screensaver, then it logs me on and the whole thing has been going on for quite a while. <br />
<br />
I had a while back before these problems started spilled oil onto the keyboard around the &quot;s&quot; key which is what I thought might have been causing the problem. But since then I have cleaned the keys, used a wireless keyboard and the problem still persists and its worse now so I dont think the oil is the issue. <br />
<br />
basically I need HELP!!! What on earth is wrong with my laptop? <br />
<br />
It is a Toshiba Satellite Pro A210 Model no: PSAFHE- 01500PEN <br />
AMD Turion 64 X2 mobile technology and vista<br />
<br />
Does anyone have any solutions to sugest please?</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>gad10</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread238977.html</guid>
		</item>
		<item>
			<title>TROJAN?VIRUS?SPYWARE OR IS IT MALWARE?  help please</title>
			<link>http://www.daniweb.com/forums/thread238787.html</link>
			<pubDate>Mon, 16 Nov 2009 01:21:32 GMT</pubDate>
			<description><![CDATA[Anyways guys, i have a desk top, and a laptop, but right now lets just talk  about the laptop, My laptop will not let me install most antivirus programs, such as avira, AVG and and a few others, But the ones that i'm able to install is, AVAST, NOD 32, but both of them are not detecting any threats,...]]></description>
			<content:encoded><![CDATA[<div>Anyways guys, i have a desk top, and a laptop, but right now lets just talk  about the laptop, My laptop will not let me install most antivirus programs, such as avira, AVG and and a few others, But the ones that i'm able to install is, AVAST, NOD 32, but both of them are not detecting any threats, And my MALWAREBYTES program won't up date, So i update it on my DESKTOP, and copy all the files to a usb from, the PROGRAMS, DATA, APP, and user folders, and then replace all of the files on the laptop, and thats the only way i can update it, but still, it is not detecting anything, same with spybot search and destroy, Does not detect anything either,<br />
Why it is troubling me is this, Everytime i plug in a USB, there are these files in them thats hidden, Named =   WINAMP.EXE,RUDLLE.exe,MALWAREBYTES.EXE, and the names keep on changing everytime i delete them with unlocker.<br />
Even when i take out the stuf i have in them and reformatt it 10 times, They keep on popping back, I'll delete them,  take my usb out,   and when i put it back in  the USB hub, what do you know, the EXE files are back, just  a different name, always IN capital letters.... CAN SOMEBODY HELP ME PLEASE, AND TELL WHAT THIS COULD BE... THANKS</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>POVSTA</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread238787.html</guid>
		</item>
		<item>
			<title>Need top notch Geek to fix my computer</title>
			<link>http://www.daniweb.com/forums/thread238783.html</link>
			<pubDate>Mon, 16 Nov 2009 00:22:59 GMT</pubDate>
			<description><![CDATA[Well it's come to the point where trying to get others to fix my computer via HJ This isn't working. 
 
I have serious issues, & I don't know why since essentially I'm well protected, although I still have to speak to Linksys re: my wireless router. 
 
So I'm looking for a trusted company who...]]></description>
			<content:encoded><![CDATA[<div>Well it's come to the point where trying to get others to fix my computer via HJ This isn't working.<br />
<br />
I have serious issues, &amp; I don't know why since essentially I'm well protected, although I still have to speak to Linksys re: my wireless router.<br />
<br />
So I'm looking for a trusted company who employs Geeks, &amp; I don't mean the Geeks that think they are Geeks &amp; really in the end they ruin the computer (gotta luv those ones), but the ones who are gifted with hacking &amp; solving problems skills.<br />
<br />
A company that won't rest until they solve the problem &amp; charge a flat rate.<br />
<br />
This is done remotely of course.<br />
<br />
Can someone recommend a few companies like that.<br />
<br />
Thank you<br />
<br />
<br />
Michelle</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>ep2002</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread238783.html</guid>
		</item>
		<item>
			<title>Error Loading....</title>
			<link>http://www.daniweb.com/forums/thread238659.html</link>
			<pubDate>Sun, 15 Nov 2009 14:09:50 GMT</pubDate>
			<description>Hi everyone, for starters I am a computer amature! So please be gentle and DO speak to me like a child as I am easly confused by technically phrases.  
haha :) 
 
Upon loading my pc I am getting an Error Loading C:\WINDOWS\jgntesy.dll 
I have no clue whats thats about and a few days ago Windows...</description>
			<content:encoded><![CDATA[<div>Hi everyone, for starters I am a computer amature! So please be gentle and DO speak to me like a child as I am easly confused by technically phrases. <br />
haha :)<br />
<br />
Upon loading my pc I am getting an Error Loading C:\WINDOWS\jgntesy.dll<br />
I have no clue whats thats about and a few days ago Windows movie maker isnt working and my media player isnt either. <br />
Movie Maker is givng me this error: class not registered<br />
Media Palyer-  is giving me this error message:  A number of queued files cannot be played. To find information about the problem, click the Now Playing tab, and then click the icon next to each file in the List pane.<br />
<br />
I used Hijackthis and this is the computer log it gave me<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 14:06:22, on 15/11/2009<br />
Platform: Windows 2003 SP2 (WinNT 5.02.3790)<br />
MSIE: Internet Explorer v7.00 (7.00.5730.0013)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\PROGRA~2\AVG\AVG8\avgwdsvc.exe<br />
C:\Program Files (x86)\Bonjour\mDNSResponder.exe<br />
C:\WINDOWS\SysWOW64\HPZipm12.exe<br />
C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe<br />
C:\PROGRA~2\AVG\AVG8\avgemc.exe<br />
C:\Program Files (x86)\AVG\AVG8\avgcsrvx.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\WINDOWS\vsnp2std.exe<br />
C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe<br />
C:\WINDOWS\SysWOW64\ctfmon.exe<br />
C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe<br />
C:\Program Files (x86)\Skype\Phone\Skype.exe<br />
C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Update\1.2.183.13\GoogleCrashHandler.exe<br />
C:\Program Files (x86)\Nokia\Nokia PC Suite 6\PCSync2.exe<br />
C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe<br />
C:\Program Files (x86)\Nokia\Nokia PC Suite 6\PCSuite.exe<br />
C:\WINDOWS\system32\atwtusb.exe<br />
C:\Program Files (x86)\PC Connectivity Solution\Transports\NclRSSrv.exe<br />
C:\WINDOWS\system32\WTMKM.exe<br />
C:\WINDOWS\Twain_32\SQ930 USB 2.0 Video Camera\SnapTrap.exe<br />
C:\WINDOWS\FixCamera.exe<br />
C:\WINDOWS\tsnp2std.exe<br />
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe<br />
C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe<br />
C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe<br />
C:\PROGRA~2\AVG\AVG8\avgtray.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe<br />
C:\Program Files (x86)\Common Files\Nokia\MPAPI\MPAPI3s.exe<br />
C:\Program Files (x86)\Mozilla Firefox\firefox.exe<br />
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe<br />
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe<br />
C:\Program Files (x86)\Movie Maker\moviemk.exe<br />
C:\Program Files (x86)\Windows Media Player\wmplayer.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG8\Toolbar\IEToolbar.dll<br />
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)<br />
R3 - URLSearchHook: (no name) - *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG8\avgssie.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll<br />
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG8\Toolbar\IEToolbar.dll<br />
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll<br />
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG8\Toolbar\IEToolbar.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [atwtusb] atwtusb.exe<br />
O4 - HKLM\..\Run: [MacrokeyManager] WTMKM.exe<br />
O4 - HKLM\..\Run: [STICAP] C:\WINDOWS\Twain_32\SQ930 USB 2.0 Video Camera\SnapTrap.exe<br />
O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe<br />
O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe<br />
O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe&quot;  -osboot<br />
O4 - HKLM\..\Run: [DiscWizardMonitor.exe] C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe<br />
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~2\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [Pqisokoxevokoxa] rundll32.exe &quot;C:\WINDOWS\jgntesy.dll&quot;,Startup<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files (x86)\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [Livestream Procaster] &quot;C:\Program Files (x86)\Procaster\Procaster.exe&quot; -autorun<br />
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [AlcoholAutomount] &quot;C:\Program Files (x86)\Alcohol Soft\Alcohol 120\axcmd.exe&quot; /automount<br />
O4 - HKCU\..\Run: [Google Update] &quot;C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe&quot; /c<br />
O4 - HKCU\..\Run: [NokiaPCInternetAccess] &quot;C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe&quot; /b<br />
O4 - HKCU\..\Run: [Skype] &quot;C:\Program Files (x86)\Skype\Phone\Skype.exe&quot; /nosplash /minimized<br />
O4 - HKCU\..\Run: [Nokia.PCSync] &quot;C:\Program Files (x86)\Nokia\Nokia PC Suite 6\PCSync2.exe&quot; /NoDialog<br />
O4 - HKCU\..\Run: [PC Suite Tray] &quot;C:\Program Files (x86)\Nokia\Nokia PC Suite 6\PCSuite.exe&quot; -onlytray<br />
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')<br />
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')<br />
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O15 - ESC Trusted Zone: <a rel="nofollow" class="t" href="http://runonce.msn.com" target="_blank">http://runonce.msn.com</a><br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?linkid=39204" target="_blank">http://go.microsoft.com/fwlink/?linkid=39204</a><br />
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - <a rel="nofollow" class="t" href="http://go.divx.com/plugin/DivXBrowserPlugin.cab" target="_blank">http://go.divx.com/plugin/DivXBrowserPlugin.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG8\avgpp.dll<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL<br />
O22 - SharedTaskScheduler: DdastigiReg - {D0A9CCD6-5BCE-4B82-B17B-A351426F0A06} - C:\WINDOWS\SysWOW64\ddastigi.dll<br />
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgemc.exe<br />
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe<br />
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe (file missing)<br />
O23 - Service: Event Log (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe (file missing)<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: HTTP SSL (HTTPFilter) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)<br />
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe (file missing)<br />
O23 - Service: Distributed Transaction Coordinator (MSDTC) - Unknown owner - C:\WINDOWS\system32\msdtc.exe (file missing)<br />
O23 - Service: Net Logon (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)<br />
O23 - Service: NT LM Security Support Provider (NtLmSsp) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\WINDOWS\system32\nvsvc64.exe (file missing)<br />
O23 - Service: Plug and Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe (file missing)<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: IPSEC Services (PolicyAgent) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)<br />
O23 - Service: Protected Storage (ProtectedStorage) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)<br />
O23 - Service: Remote Desktop Help Session Manager (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe (file missing)<br />
O23 - Service: Security Accounts Manager (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)<br />
O23 - Service: ServiceLayer - Nokia. - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe<br />
O23 - Service: Seagate Scheduler2 Service (SgtSch2Svc) - Seagate - C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe<br />
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe<br />
O23 - Service: Virtual Disk Service (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)<br />
O23 - Service: Volume Shadow Copy (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe (file missing)<br />
O23 - Service: WMI Performance Adapter (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe (file missing)<br />
O23 - Service: Windows Search (WSearch) - Unknown owner - C:\WINDOWS\system32\SearchIndexer.exe (file missing)<br />
<br />
--<br />
End of file - 11537 bytes<br />
<br />
<br />
I dont go on any weird sites, but I do download alot of programs. But I research the programs prior to downloading them. <br />
Can anyone help me ??<br />
Thanks so much<br />
Jen</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Jen123</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread238659.html</guid>
		</item>
		<item>
			<title>Internet Explorer 7 keeps opening up</title>
			<link>http://www.daniweb.com/forums/thread238644.html</link>
			<pubDate>Sun, 15 Nov 2009 12:55:30 GMT</pubDate>
			<description>Hi 
 
im new to this board.i did some research and came across this forum.hope u can help me.just recently my internet explorer 7 keeps opening up even thogh its pre-installed with vista.i dont even use it i use firefox.........iv ran all virus software nothing seems to be fixing my problem can u...</description>
			<content:encoded><![CDATA[<div>Hi<br />
<br />
im new to this board.i did some research and came across this forum.hope u can help me.just recently my internet explorer 7 keeps opening up even thogh its pre-installed with vista.i dont even use it i use firefox.........iv ran all virus software nothing seems to be fixing my problem can u please help?<br />
<br />
thanks in advance</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>dmx0007</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread238644.html</guid>
		</item>
		<item>
			<title>News Story How to destroy a botnet</title>
			<link>http://www.daniweb.com/news/story238483.html</link>
			<pubDate>Sat, 14 Nov 2009 11:52:14 GMT</pubDate>
			<description>Botnets are, without any shadow of a doubt, one of the biggest scourges (http://www.itpro.co.uk/blogs/daveyw/2009/09/30/death-taxes-and-botnets/) of IT security today. From sending spam to launching DDoS attacks (http://www.daniweb.com/news/story238033.html) and distributing malware, botnets can be...</description>
			<content:encoded><![CDATA[<div>Botnets are, without any shadow of a doubt, one of the <a rel="nofollow" class="t" href="http://www.itpro.co.uk/blogs/daveyw/2009/09/30/death-taxes-and-botnets/" target="_blank">biggest scourges</a> of IT security today. From sending spam to <a rel="nofollow" class="t" href="http://www.daniweb.com/news/story238033.html" target="_blank">launching DDoS attacks</a> and distributing malware, botnets can be found <a rel="nofollow" class="t" href="http://www.daniweb.com/blogs/showentry.php?entryid=1021" target="_blank">at the centre</a> of most of the security problems facing computer users right now. <br />
<br />
So wouldn't it be fun if you could take down, knock over and destroy a botnet? The good news is that it seems you can, with a little determination and a lot of inside knowledge.<br />
<br />
Researchers at the FireEye Malware Intelligence Lab have been working hard at gathering the necessary knowledge with regards to one Botnet, known as Ozdok or perhaps more commonly Mega-D. Having got to grips with the command and control architecture, along with the fallback mechanisms used to keep the botnet alive should they come under attack, FireEye decided the time was right to strike. This meant moving out of the lab and the purely theoretical realm of botnet takedown and into the real world, which involves getting various agencies working together with an intent to destroy a botnet. So FireEye contacted ISPs, registries and registrars and set about the task in hand.<br />
<br />
Atif Mushtaq <a rel="nofollow" class="t" href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html" target="_blank">writes</a> that &quot;all the major Ozdok command and control servers... have been taken down.  As it turns out, no matter how many fallback mechanisms are in place, if they aren't all implemented properly, the botnet is vulnerable&quot;.<br />
<br />
It wasn't easy, but within a 24 hour period it would appear that it is possible to shutdown a botnet by working against all the fallback mechanisms that have been identified, and doing so with such speed that the botnet herders are unable to mount any kind of defence strategy to keep running.<br />
<br />
FireEye approached the challenge methodically, by first preparing enough evidence of botnet activity (including those domains and hosts responsible) to allow ISPs to take the abuse notifications that followed seriously. Apparently this initial work paid off with only 4 hosts not being taken down promptly as a result, and those have been reported to relevant authorities to try and get them investigated and removed. Registrars were also contacted to request domain were suspended so as to break the primary command and control chain. Some of these were successful, although many appear to be still up and running. So not so much success there, although FireEye has managed to reroute Mega-D zombies to a sinkhole server rather than the real Command and Control centres.<br />
<br />
In itself this is good news as it means FireEye can collect data about those zombies and identify victims, who can then be given help to clean their machines. In the first 24 hours of this determined takedown effort FireEye has seen 264,784 unique IPs connect to the sinkhole server.<br />
<br />
According to Mathew Nisbet, Malware Data Analyst with MessageLabs, the effort has been worthwhile. Nisbet <a rel="nofollow" class="t" href="http://www.messagelabs.co.uk/resources/blog.aspx?link=http://www.symantec.com/connect/blogs/mega-d-aka-ozdok-crippled" target="_blank">says</a> &quot;our monitoring shows a huge decline in this previously prolific botnet’s activity&quot; continuing &quot;normally between 600 and 1600 IP’s are seen each day&quot; but after the takedown attempt it &quot;plummeted down to less than 50&quot;.<br />
<br />
Sure, Mega-D was not obliterated by this attack and it is still spewing out a handful of spams every day. It should be remembered that Mega-D has been taken down before and <a rel="nofollow" class="t" href="http://www.itwire.com/content/view/22195/53/" target="_blank">bounced back</a>. However, this time it has been effectively crippled and that's important given how fiercely competitive the botnet market is. Clients will move elsewhere and it is doubtful if Mega-D will be able to recover to anything like the position it previously held in the underground botnet for hire league tables.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>happygeek</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread238483.html</guid>
		</item>
		<item>
			<title>Adobe Flash Player froze AOL</title>
			<link>http://www.daniweb.com/forums/thread238372.html</link>
			<pubDate>Fri, 13 Nov 2009 20:00:57 GMT</pubDate>
			<description>Hello, 
 
Last evening I was trying to print from my computer and was prompted to download Adobe Flash Player (from Adobe site) in order to be able to print this particular item.  After downloading and installing Adobe Flash Player, I noticed a problem with AOL.    I am able to sign onto AOL,...</description>
			<content:encoded><![CDATA[<div>Hello,<br />
<br />
Last evening I was trying to print from my computer and was prompted to download Adobe Flash Player (from Adobe site) in order to be able to print this particular item.  After downloading and installing Adobe Flash Player, I noticed a problem with AOL.    I am able to sign onto AOL, however the Adobe page I was downloading from in still there and I cannot access my mail or anything else on this AOL account. I cannot close the Adobe download page.  If I try to open my mail, my favorites, etc. I get the hour glass and AOL keeps saying &quot;not responding&quot;.  I did uninstall Adobe, rebooted and the problem still exists.  All other email accounts on my AOL are working fine.  Any help would be greatly appreciated.  Thank you.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Inlovewithnight</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread238372.html</guid>
		</item>
		<item>
			<title>Internet explorer/Firefox both redirect</title>
			<link>http://www.daniweb.com/forums/thread238364.html</link>
			<pubDate>Fri, 13 Nov 2009 19:18:12 GMT</pubDate>
			<description>I need help with a Toshiba laptop that is having difficulties with IE/Firefox redirecting to advertising sites. I have tried numerous programs to kill this and have had no luck. 
 
Here is the most recent HJT log. Thanks in advance for your help. 
 
Logfile of Trend Micro HijackThis v2.0.2 
Scan...</description>
			<content:encoded><![CDATA[<div>I need help with a Toshiba laptop that is having difficulties with IE/Firefox redirecting to advertising sites. I have tried numerous programs to kill this and have had no luck.<br />
<br />
Here is the most recent HJT log. Thanks in advance for your help.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 1:59:34 PM, on 11/13/2009<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18828)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\System32\smss.exe<br />
C:\Windows\system32\csrss.exe<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\csrss.exe<br />
C:\Windows\system32\winlogon.exe<br />
C:\Windows\system32\services.exe<br />
C:\Windows\system32\lsass.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe<br />
C:\Windows\system32\svchost.exe<br />
C:\Windows\System32\svchost.exe<br />
C:\Windows\System32\svchost.exe<br />
C:\Windows\System32\svchost.exe<br />
C:\Windows\system32\svchost.exe<br />
C:\Windows\system32\svchost.exe<br />
C:\Windows\system32\SLsvc.exe<br />
C:\Windows\system32\svchost.exe<br />
C:\Windows\system32\svchost.exe<br />
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\svchost.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\agrsmsvc.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe<br />
C:\Windows\System32\hkcmd.exe<br />
C:\Windows\System32\igfxpers.exe<br />
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe<br />
C:\Program Files\Toshiba\SmoothView\SmoothView.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\ItSecMng.exe<br />
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe<br />
C:\Program Files\Toshiba\Utilities\KeNotify.exe<br />
C:\Windows\RtHDVCpl.exe<br />
C:\Program Files\Alwil Software\Avast4\ashDisp.exe<br />
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe<br />
C:\Program Files\LogMeIn\x86\RaMaint.exe<br />
C:\Program Files\LogMeIn\x86\LogMeIn.exe<br />
C:\Program Files\LogMeIn\x86\LMIGuardian.exe<br />
C:\Toshiba\IVP\ISM\pinger.exe<br />
C:\Windows\system32\svchost.exe<br />
C:\Program Files\Spyware Doctor\pctsAuxs.exe<br />
C:\Program Files\Spyware Doctor\pctsSvc.exe<br />
C:\Windows\system32\igfxsrvc.exe<br />
C:\Windows\system32\svchost.exe<br />
C:\Program Files\Spyware Doctor\pctsTray.exe<br />
c:\Toshiba\IVP\swupdate\swupdtmr.exe<br />
C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe<br />
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe<br />
C:\Windows\system32\TODDSrv.exe<br />
C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe<br />
C:\Program Files\LogMeIn\x86\LMIGuardian.exe<br />
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe<br />
C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe<br />
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe<br />
C:\Windows\System32\svchost.exe<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
C:\Program Files\Synaptics\SynTP\SynToshiba.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br />
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe<br />
C:\Toshiba\IVP\ISM\ivpsvmgr.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Users\kemmerling\Downloads\HijackThis.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://forecast.weather.gov/MapClick.php?CityName=Kill+Devil+Hills&amp;state=NC&amp;site=MHX&amp;textField1=36.016&amp;textField2=-75.6675" target="_blank">http://forecast.weather.gov/MapClick...ield2=-75.6675</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://www.toshibadirect.com/dpdstart" target="_blank">http://www.toshibadirect.com/dpdstart</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll<br />
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE<br />
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe<br />
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START<br />
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe<br />
O4 - HKLM\..\Run: [HWSetup] \HWSetup.exe hwSetUP<br />
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL<br />
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe<br />
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
O4 - HKLM\..\Run: [LogMeIn GUI] &quot;C:\Program Files\LogMeIn\x86\LogMeInSystray.exe&quot;<br />
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe&quot; /starttray<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [jswtrayutil] &quot;C:\Program Files\Jumpstart\jswtrayutil.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [ISTray] &quot;C:\Program Files\Spyware Doctor\pctsTray.exe&quot;<br />
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe<br />
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O13 - Gopher Prefix: <br />
O16 - DPF: PackageCab - <a rel="nofollow" class="t" href="http://ak.imgag.com/imgag/cp/install/AxCtp2.cab" target="_blank">http://ak.imgag.com/imgag/cp/install/AxCtp2.cab</a><br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll<br />
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - <a rel="nofollow" class="t" href="http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab" target="_blank">http://download.bitdefender.com/reso...an8/oscan8.cab</a><br />
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - <a rel="nofollow" class="t" href="http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab" target="_blank">http://acs.pandasoftware.com/actives.../as2stubie.cab</a><br />
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll<br />
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
O23 - Service: Browser Defender Update Service - Threat Expert Ltd. - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe<br />
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe<br />
O23 - Service: Google Update Service (gupdate1c98bd192b2a0a3) (gupdate1c98bd192b2a0a3) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Jumpstart Wifi Protected Setup (jswpsapi) - Atheros Communications, Inc. - C:\Program Files\Jumpstart\jswpsapi.exe<br />
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe<br />
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe<br />
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe<br />
O23 - Service: pinger - Unknown owner - C:\Toshiba\IVP\ISM\pinger.exe<br />
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe<br />
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe<br />
O23 - Service: Swupdtmr - Unknown owner - c:\Toshiba\IVP\swupdate\swupdtmr.exe<br />
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe<br />
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe<br />
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe<br />
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe<br />
O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe<br />
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe<br />
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
<br />
--<br />
End of file - 13071 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>scraddock</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread238364.html</guid>
		</item>
		<item>
			<title>Google Redirect and occasional blue screen on startup</title>
			<link>http://www.daniweb.com/forums/thread238304.html</link>
			<pubDate>Fri, 13 Nov 2009 15:40:02 GMT</pubDate>
			<description><![CDATA[It appears I have been nailed by the same crap that so many people on this forum have gotten.  Any help would be greatly appreciated.  Here's the hijack this log: 
 
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 10:19:18 AM, on 11/13/2009 
Platform: Windows XP SP3 (WinNT 5.01.2600) 
MSIE:...]]></description>
			<content:encoded><![CDATA[<div>It appears I have been nailed by the same crap that so many people on this forum have gotten.  Any help would be greatly appreciated.  Here's the hijack this log:<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 10:19:18 AM, on 11/13/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16915)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\IFXTCS.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe<br />
C:\WINDOWS\system32\cisvc.exe<br />
C:\Program Files\HPQ\IAM\bin\asghost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\RUNDLL32.EXE<br />
C:\Program Files\Analog Devices\Core\smax4pnp.exe<br />
C:\WINDOWS\system32\AccelerometerSt.exe<br />
C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE<br />
C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe<br />
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe<br />
C:\WINDOWS\SMINST\Scheduler.exe<br />
C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe<br />
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe<br />
C:\Program Files\Common Files\SolidWorks Installation Manager\Scheduler\sldIMScheduler.exe<br />
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe<br />
C:\Program Files\Rockwell Automation\Rockwell Automation USB CIP Driver Package\UsbCipHelper\UsbCipHelper.exe<br />
C:\Program Files\Messenger\msmsgs.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe<br />
C:\Program Files\Windows Desktop Search\WindowsSearch.exe<br />
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\IFXSPMGT.exe<br />
C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\oracle\product\10.2.0\client_1\bin\omtsreco.exe<br />
C:\Program Files\ProtectTools\Embedded Security Software\PSDsrvc.EXE<br />
C:\Program Files\Common Files\Rockwell\RsvcHost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe<br />
C:\WINDOWS\system32\SearchIndexer.exe<br />
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
C:\WINDOWS\system32\mqsvc.exe<br />
C:\Program Files\Trend Micro\Client Server Security Agent\OfcPfwSvc.exe<br />
C:\WINDOWS\system32\mqtgsvc.exe<br />
C:\WINDOWS\TEMP\QC5F9B.EXE<br />
C:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXE<br />
C:\WINDOWS\system32\cidaemon.exe<br />
C:\WINDOWS\system32\cidaemon.exe<br />
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE<br />
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\Acrobat.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\WINDOWS\system32\SearchProtocolHost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\WINDOWS\system32\SearchProtocolHost.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://www.charter.net/google/index.php?q=" target="_blank">http://www.charter.net/google/index.php?q=</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.charter.net/" target="_blank">http://www.charter.net/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=74005" target="_blank">http://go.microsoft.com/fwlink/?LinkId=74005</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Powered by Charter Communications<br />
O1 - Hosts: ::1 localhost<br />
O1 - Hosts: 91.212.127.227 awareremover2009.microsoft.com<br />
O1 - Hosts: 91.212.127.227 awareremover2009.com<br />
O1 - Hosts: 91.212.127.227 <a rel="nofollow" class="t" href="http://www.awareremover2009.com" target="_blank">www.awareremover2009.com</a><br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Charter Toolbar - {4E7BD74F-2B8D-469E-85AB-AF21F3D9AE2F} - C:\PROGRA~1\CHARTE~1\CHARTE~1.DLL<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O2 - BHO: HP Credential Manager for ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\HPQ\IAM\Bin\ItIeAddIN.dll<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll<br />
O3 - Toolbar: Charter Toolbar - {4E7BD74F-2B8D-469E-85AB-AF21F3D9AE2F} - C:\PROGRA~1\CHARTE~1\CHARTE~1.DLL<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect<br />
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll<br />
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe<br />
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray<br />
O4 - HKLM\..\Run: [AccelerometerSysTrayApplet] C:\WINDOWS\system32\AccelerometerSt.exe<br />
O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start<br />
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe<br />
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\HPQ\IAM\Bin\AsTsVcc.dll,RegisterModule<br />
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start<br />
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe<br />
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard.exe<br />
O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_XP.exe<br />
O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe<br />
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe<br />
O4 - HKLM\..\Run: [OfficeScanNT Monitor] &quot;C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe&quot; -HideWindow<br />
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] &quot;C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe&quot;<br />
O4 - HKLM\..\Run: [SolidWorks_CheckForUpdates] &quot;C:\Program Files\Common Files\SolidWorks Installation Manager\Scheduler\sldIMScheduler.exe&quot; /scheduler<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [UsbCipHelper] C:\Program Files\Rockwell Automation\Rockwell Automation USB CIP Driver Package\UsbCipHelper\UsbCipHelper.exe<br />
O4 - HKCU\..\Run: [MSMSGS] &quot;C:\Program Files\Messenger\msmsgs.exe&quot; /background<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?<br />
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br />
O4 - Global Startup: Bluetooth.lnk = ?<br />
O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe<br />
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe<br />
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com<br />
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = wardleonard.com<br />
O17 - HKLM\Software\..\Telephony: DomainName = wardleonard.com<br />
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = wardleonard.com<br />
O20 - Winlogon Notify: OneCard - C:\Program Files\HPQ\IAM\Bin\AsWlnPkg.dll<br />
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe<br />
O23 - Service: SW Distributed TS Coordinator Service (CoordinatorServiceHost) - Dassault Systèmes SolidWorks Corp. - C:\Program Files\SolidWorks\SolidWorks\swScheduler\DTSCoordinatorService.exe<br />
O23 - Service: dnWhoDisp - Rockwell Automation, Inc. - C:\Program Files\Rockwell Software\RSLINX\dnwhodisp.exe<br />
O23 - Service: FactoryTalk Activation Helper (FTActivationBoost) - Rockwell Automation Inc. - C:\Program Files\Rockwell Software\FactoryTalk Activation\Tools\FTActivationBoost.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: Harmony - Rockwell Automation, Inc. - C:\Program Files\Rockwell Software\RSCommon\RSOBSERV.EXE<br />
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\WINDOWS\system32\IFXSPMGT.exe<br />
O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\WINDOWS\system32\IFXTCS.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: Trend Micro Client/Server Security Agent RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: Trend Micro Client/Server Security Agent Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\OfcPfwSvc.exe<br />
O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exe<br />
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\oracle\product\10.2.0\client_1\bin\omtsreco.exe<br />
O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe<br />
O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - C:\Program Files\ProtectTools\Embedded Security Software\PSDsrvc.EXE<br />
O23 - Service: FactoryTalk Diagnostics Local Reader (RNADiagnosticsService) - Rockwell Automation Inc. - C:\Program Files\Common Files\Rockwell\RNADiagnosticsSrv.exe<br />
O23 - Service: FactoryTalk Diagnostics CE Receiver (RNADiagReceiver) - Rockwell Automation, Inc. - C:\Program Files\Common Files\Rockwell\RNADiagReceiver.exe<br />
O23 - Service: RSLinx Classic (RSLinx) - Rockwell Automation, Inc. - C:\PROGRA~1\ROCKWE~1\RSLinx\RSLINX.EXE<br />
O23 - Service: Rockwell Application Services (RsvcHost) - Rockwell Automation, Inc. - C:\Program Files\Common Files\Rockwell\RsvcHost.exe<br />
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe<br />
O23 - Service: Trend Micro Client/Server Security Agent Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe<br />
<br />
--<br />
End of file - 14039 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>nhaggard</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread238304.html</guid>
		</item>
		<item>
			<title>hijackthis log</title>
			<link>http://www.daniweb.com/forums/thread238256.html</link>
			<pubDate>Fri, 13 Nov 2009 10:57:49 GMT</pubDate>
			<description><![CDATA[could anyone take a look at this and tell me if there's anything unusual? things have been a bit slow lately but i dont know if that's connection issues or potential viruses.   
(i also ran a full scan with malware bytes and it came up clean). 
 
thanks! 
 
Logfile of Trend Micro HijackThis v2.0.2...]]></description>
			<content:encoded><![CDATA[<div>could anyone take a look at this and tell me if there's anything unusual? things have been a bit slow lately but i dont know if that's connection issues or potential viruses.  <br />
(i also ran a full scan with malware bytes and it came up clean).<br />
<br />
thanks!<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 5:16:30 AM, on 11/13/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16915)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br />
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\McAfee\Common Framework\FrameworkService.exe<br />
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe<br />
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe<br />
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br />
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\WgaTray.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe<br />
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe<br />
C:\WINDOWS\system32\igfxtray.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\Program Files\ltmoh\Ltmoh.exe<br />
C:\WINDOWS\AGRSMMSG.exe<br />
C:\Program Files\QuickTime\qttask.exe<br />
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE<br />
C:\Program Files\McAfee\Common Framework\UdaterUI.exe<br />
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe<br />
C:\Program Files\McAfee\Common Framework\McTray.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\WINDOWS\system32\dlcfcoms.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.yahoo.com/" target="_blank">http://www.yahoo.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by Cox High Speed Internet<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll<br />
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br />
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [IntelZeroConfig] &quot;C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe&quot;<br />
O4 - HKLM\..\Run: [IntelWireless] &quot;C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe&quot; /tf Intel PROSet/Wireless<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe<br />
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [DLCFCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCFtime.dll,_RunDLLEntry@16<br />
O4 - HKLM\..\Run: [ShStatEXE] &quot;C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE&quot; /STANDALONE<br />
O4 - HKLM\..\Run: [McAfeeUpdaterUI] &quot;C:\Program Files\McAfee\Common Framework\UdaterUI.exe&quot; /StartedFromRunKey<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon<br />
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [Microsoft Default Manager] &quot;C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe&quot; -resume<br />
O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;  -osboot<br />
O4 - HKLM\..\Run: [Adobe Photo Downloader] &quot;C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe&quot;<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O23 - Service: dlcf_device -   - C:\WINDOWS\system32\dlcfcoms.exe<br />
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe<br />
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe<br />
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe<br />
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br />
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br />
<br />
--<br />
End of file - 8298 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>slowbee</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread238256.html</guid>
		</item>
		<item>
			<title>MalwareBytes Anti-Malware WARNING.</title>
			<link>http://www.daniweb.com/forums/thread238202.html</link>
			<pubDate>Fri, 13 Nov 2009 04:37:52 GMT</pubDate>
			<description><![CDATA[Due to a bug in Malwarebytes, you may see in MBAM's log following entries: 
*HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\atapi (Rootkit) 
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\atapi (Rootkit) 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\atapi (Rootkit)* 
*_DO NOT_* remove...]]></description>
			<content:encoded><![CDATA[<div>Due to a bug in Malwarebytes, you may see in MBAM's log following entries:<br />
<span style="font-weight:bold">HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\atapi (Rootkit)<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\atapi (Rootkit)<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\atapi (Rootkit)</span><br />
<span style="font-weight:bold"><span style="text-decoration:underline">DO NOT</span></span> remove those entries!<br />
<span style="font-weight:bold">If you do, your computer will become UN-bootable.</span><br />
The issue has been fixed in the latest MBAM update, so, please make sure you <span style="font-weight:bold"><span style="color:Red">update MBAM before you run it</span></span>.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>crunchie</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread238202.html</guid>
		</item>
		<item>
			<title>News Story DDoS for sale</title>
			<link>http://www.daniweb.com/news/story238033.html</link>
			<pubDate>Thu, 12 Nov 2009 13:53:18 GMT</pubDate>
			<description>According to the latest McAfee Labs Third Quarter Threats Report 2009 (http://www.mcafee.com/us/local_content/reports/7315rpt_threat_1009.pdf) instances of Distributed Denial of Service attacks are growing in popularity.  
 
In the last quarter the McAfee Labs observed many new attacks demanding...</description>
			<content:encoded><![CDATA[<div>According to the latest McAfee Labs <a rel="nofollow" class="t" href="http://www.mcafee.com/us/local_content/reports/7315rpt_threat_1009.pdf" target="_blank">Third Quarter Threats Report 2009</a> instances of Distributed Denial of Service attacks are growing in popularity. <br />
<br />
In the last quarter the McAfee Labs observed many new attacks demanding ransom money including those aimed at sports betting companies which were taken out of action during key sporting events to cause losses in the millions. Such attacks have not only been used to make money, but also silence political opinion.<br />
<br />
But perhaps the growth of DDoS as a service, whereby cybercriminals offer botnets capable of launching such attacks to the highest bidder is the biggest worry. &quot;These botnets are capable of knocking even some of the most-protected sites offline&quot; the report concludes and, of course, the whole concept of DDoS as a Service means that anyone can create a devastating attack provided they have the money to buy the botnet time. <br />
<br />
The concern being that not only does it remove the technical requirement from the would be attack equation, but it also reduces the amount of money that they have to invest. It only costs a fraction of the price of establishing <a rel="nofollow" class="t" href="http://www.daniweb.com/blogs/entry3487.html" target="_blank">a viable DDoS attack botnet</a> to rent one for an hour or two. <br />
<br />
Other highlights of the report include:<br />
<br />
Despite the Pirate Bay shutdown, there has been a 300% increase in the creation of file sharing websites. <br />
<br />
Spam reached its highest level in history, breaking the previous record set in the second quarter of 2009 by 10 percent. Spam now comprises 92 percent of all e-mail. When compared with the third quarter of 2008, spam jumped 24 percent.<br />
 <br />
Web-based attacks are the newest hot threat vector, and 55% of all malicious URLs are hosted in the US.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>newsguy</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread238033.html</guid>
		</item>
		<item>
			<title><![CDATA[Can't access microsoft.com, antivirus webpages, sometimes showing fake instead]]></title>
			<link>http://www.daniweb.com/forums/thread237846.html</link>
			<pubDate>Wed, 11 Nov 2009 21:35:10 GMT</pubDate>
			<description><![CDATA[I can't access microsoft.com, hotmail.com, hijack this webpage, and sometimes other seemingly random webpages like bbc news, met office, gametrailers etc. Most other webpages work fine though 
 
I've tried MalwareBytes AntiMalware, but found nothing. I've run hijack and didn't see anything...]]></description>
			<content:encoded><![CDATA[<div>I can't access microsoft.com, hotmail.com, hijack this webpage, and sometimes other seemingly random webpages like bbc news, met office, gametrailers etc. Most other webpages work fine though<br />
<br />
I've tried MalwareBytes AntiMalware, but found nothing. I've run hijack and didn't see anything suspicious, but got rid of everything that was not necessary just in case. Also deleted all cookies, updated windows,winSocksfix, checked the hosts file, run spybot, and run &quot;net stop dnscache&quot; without any results.<br />
<br />
The interesting thing is that yesterday, I had the same problem, but the difference was that some webpages would redirect me to fake webs, i.e. hijackthis webpage was replaced with a generic &quot;antivirus.com - what you need it, when you need it&quot;, and the same thing with the met office webpage. Then I started doing all the hijackThis, spybot scanning etc etc but nothing worked, and suddenly it was gone. All webpages were loading fine again. I pretended I had probably fixed it without realizing but I knew something was not quite right =)<br />
<br />
But now again the same problem =( no generic &quot;what you need, when you need it&quot; webs this time though</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>alejito</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread237846.html</guid>
		</item>
		<item>
			<title>Windows System Defender</title>
			<link>http://www.daniweb.com/forums/thread237712.html</link>
			<pubDate>Wed, 11 Nov 2009 09:43:29 GMT</pubDate>
			<description>Hi all 
 
We have a problem on one of the computers at work, the malicious program “Windows System Defender” has found its way onto on of the computers. 
 
I’ve tried using, Spy-bot, Ad-aware, Malwarebytes, AVG, HijackThis but everything just shuts down once it starts scanning. 
 
The task manager...</description>
			<content:encoded><![CDATA[<div>Hi all<br />
<br />
We have a problem on one of the computers at work, the malicious program “Windows System Defender” has found its way onto on of the computers.<br />
<br />
I’ve tried using, Spy-bot, Ad-aware, Malwarebytes, AVG, HijackThis but everything just shuts down once it starts scanning.<br />
<br />
The task manager won’t open, I have disabled the process for Windows System Defender, going through the msconfig command. I’ve also tried booting up in safe mode but it wont do that either.<br />
<br />
What steps shall I take next?</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>atky2004</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread237712.html</guid>
		</item>
		<item>
			<title>Nothing working</title>
			<link>http://www.daniweb.com/forums/thread237684.html</link>
			<pubDate>Wed, 11 Nov 2009 07:33:19 GMT</pubDate>
			<description>Hello,  I am trying to help a friend with her computer. It is infected quite well it seems. Lots of warnings popping up ie. Net worm, Rootkit, Trojan, Backdoor, and so on. I have tried to run Mbam, HJT, and more normally and in safe mode. Nothing will start up. Please advise. 
 
Thanks</description>
			<content:encoded><![CDATA[<div>Hello,  I am trying to help a friend with her computer. It is infected quite well it seems. Lots of warnings popping up ie. Net worm, Rootkit, Trojan, Backdoor, and so on. I have tried to run Mbam, HJT, and more normally and in safe mode. Nothing will start up. Please advise.<br />
<br />
Thanks</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Stonehands</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread237684.html</guid>
		</item>
		<item>
			<title>Computer is super slow</title>
			<link>http://www.daniweb.com/forums/thread237643.html</link>
			<pubDate>Wed, 11 Nov 2009 04:16:09 GMT</pubDate>
			<description>Not sure what the problem is but both browsers are super slow. There is an error message that pops up when the computer boots. I have attached it a print screen of the same. I have no idea if this is related to it. 
 
 
The message reads :  
c:\docume~1\alluse~1\applic~1\kikububu\kikububu.dll</description>
			<content:encoded><![CDATA[<div>Not sure what the problem is but both browsers are super slow. There is an error message that pops up when the computer boots. I have attached it a print screen of the same. I have no idea if this is related to it.<br />
<br />
<br />
The message reads : <br />
c:\docume~1\alluse~1\applic~1\kikububu\kikububu.dll</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>rocky420</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread237643.html</guid>
		</item>
		<item>
			<title><![CDATA["Antivirus System Pro"]]></title>
			<link>http://www.daniweb.com/forums/thread237635.html</link>
			<pubDate>Wed, 11 Nov 2009 02:51:24 GMT</pubDate>
			<description>i started getting this fake alert.  from my brief research, it seems to be a trojan.  i ran a full McAfee virus scan and it said it found  a trojan and quarantined it but it still pops up.  i tried using spy doctor as well as adaware but the trojan seems to block the programs from opening up.   
...</description>
			<content:encoded><![CDATA[<div>i started getting this fake alert.  from my brief research, it seems to be a trojan.  i ran a full McAfee virus scan and it said it found  a trojan and quarantined it but it still pops up.  i tried using spy doctor as well as adaware but the trojan seems to block the programs from opening up.  <br />
<br />
i need help removing this thing.<br />
<br />
<br />
thanks in advance</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>stranoblaze</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread237635.html</guid>
		</item>
		<item>
			<title>Malware,virus,spyware help ?????no clue</title>
			<link>http://www.daniweb.com/forums/thread237451.html</link>
			<pubDate>Tue, 10 Nov 2009 10:10:53 GMT</pubDate>
			<description>Hey guys, i just realised today my antivirus wasnt working, I have avg8 installed, Its been working fine till now,  I click on scan does nothing, update does nothing, So i tried to reinstall, But still same Problem, So i tried a System Restore, Still the same, Next up i tried, To Install, NOD32...</description>
			<content:encoded><![CDATA[<div>Hey guys, i just realised today my antivirus wasnt working, I have avg8 installed, Its been working fine till now,  I click on scan does nothing, update does nothing, So i tried to reinstall, But still same Problem, So i tried a System Restore, Still the same, Next up i tried, To Install, NOD32 instead, this time, it won't even install, And same with AVIRA, and couple other anti virus programs, I'm sure i have a virus or malware or one of the other problems, But i have no idea or clue on how to takle this problem... Soo this is where you guys come in with your Expertise....  Any help or advice would be very much appreciated, THANKS IN ADVANCE GUYS, Hope to hear a solution...</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>POVSTA</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread237451.html</guid>
		</item>
		<item>
			<title><![CDATA[AVG Free says "incompatible software"]]></title>
			<link>http://www.daniweb.com/forums/thread237367.html</link>
			<pubDate>Tue, 10 Nov 2009 03:24:17 GMT</pubDate>
			<description><![CDATA[Hi, 
 
Can I get some help with finding some software on my machine that was flagged by AVG Free's v. 9?  The message said to remove CF746002-94FB-101B-8C12-02608C454BFF, but I cannot find this string anywhere.  I ran HijackThis, and here's the log, but I didn't see it in there.   In one forum, I...]]></description>
			<content:encoded><![CDATA[<div>Hi,<br />
<br />
Can I get some help with finding some software on my machine that was flagged by AVG Free's v. 9?  The message said to remove CF746002-94FB-101B-8C12-02608C454BFF, but I cannot find this string anywhere.  I ran HijackThis, and here's the log, but I didn't see it in there.   In one forum, I saw where another user had this problem and the bottom line advice was to ignore it and hit the skip button when AVG setup flagged this string.  What next?<br />
<br />
Tom<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 20:17:52, on 11/9/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
C:\WINDOWS\System32\nvsvc32.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br />
C:\Program Files\AVG\AVG8\avgcsrvx.exe<br />
C:\WINDOWS\System32\NILaunch.exe<br />
C:\Program Files\ltmoh\Ltmoh.exe<br />
C:\WINDOWS\System32\ezSP_Px.exe<br />
C:\WINDOWS\System32\00THotkey.exe<br />
C:\WINDOWS\system32\TPWRTRAY.EXE<br />
C:\WINDOWS\system32\TFNF5.exe<br />
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe<br />
C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
C:\Program Files\QuickTime\qttask.exe<br />
C:\Program Files\Yahoo!\Common\YMailAdvisor.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br />
C:\Program Files\Windows NT\Accessories\wordpad.exe<br />
C:\Program Files\AVG\AVG8\avgscanx.exe<br />
C:\Program Files\AVG\AVG8\avgcsrvx.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.yahoo.com/" target="_blank">http://www.yahoo.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll<br />
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\YTSingleInstance.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll<br />
O3 - Toolbar: &amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize<br />
O4 - HKLM\..\Run: [Net-It Launcher] C:\WINDOWS\System32\NILaunch.exe<br />
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe<br />
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe<br />
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe<br />
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe<br />
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE<br />
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe<br />
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe /Type 20<br />
O4 - HKLM\..\Run: [PRISMSVR.EXE] &quot;C:\WINDOWS\system32\PRISMSVR.EXE&quot; /APPLY<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [YMailAdvisor] &quot;C:\Program Files\Yahoo!\Common\YMailAdvisor.exe&quot;<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [updateMgr] &quot;C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe&quot; AcRdB7_0_8 -reboot 1<br />
O4 - HKCU\..\Run: [GetModule26] &quot;C:\Program Files\GetModule\GetModule26.exe&quot;<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll<br />
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com<br />
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - <a rel="nofollow" class="t" href="http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab" target="_blank">http://housecall65.trendmicro.com/ho...vex/hcImpl.cab</a><br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll<br />
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - <a rel="nofollow" class="t" href="http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab" target="_blank">http://download.mcafee.com/molbin/sh...1/mcinsctl.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a rel="nofollow" class="t" href="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1255572372908" target="_blank">http://update.microsoft.com/windowsu...?1255572372908</a><br />
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - <a rel="nofollow" class="t" href="http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab" target="_blank">http://download.mcafee.com/molbin/sh...26/mcgdmgr.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a rel="nofollow" class="t" href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O20 - AppInit_DLLs: karna.dat<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe<br />
<br />
--<br />
End of file - 5999 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>four mile</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread237367.html</guid>
		</item>
		<item>
			<title>XP Help - Explorer.exe problems</title>
			<link>http://www.daniweb.com/forums/thread237343.html</link>
			<pubDate>Tue, 10 Nov 2009 00:48:48 GMT</pubDate>
			<description>Whenever I load up windows, explorer.exe will not start. I can open up task manager and launch it from there, but it will close within the next ten seconds.  I have done a Malware Bytes Anti Malware scan, and it turns out I have a vundo infection.   
* 
Here is my HijackThis log:* 
 
Logfile of...</description>
			<content:encoded><![CDATA[<div>Whenever I load up windows, explorer.exe will not start. I can open up task manager and launch it from there, but it will close within the next ten seconds.  I have done a Malware Bytes Anti Malware scan, and it turns out I have a vundo infection.  <br />
<span style="font-weight:bold"><br />
Here is my HijackThis log:</span><br />
<br />
Logfile of HijackThis v1.99.1<br />
Scan saved at 7:41:02 PM, on 11/9/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe<br />
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe<br />
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Canon\CAL\CALMAIN.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Documents and Settings\Kevin's Desktop\My Documents\Downloads\FixVundo.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Internet Content Filter\mfp.exe<br />
C:\WINDOWS\system32\dwwin.exe<br />
C:\WINDOWS\system32\taskmgr.exe<br />
C:\Program Files\HijackThis\imabunny.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://www.google.com/ig/dell?hl=en&amp;client=dell-usuk&amp;channel=us&amp;ibd=1060929" target="_blank">http://www.google.com/ig/dell?hl=en&amp;...us&amp;ibd=1060929</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.dell.com" target="_blank">http://www.dell.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = <a rel="nofollow" class="t" href="http://www.google.com/ig/dell?hl=en&amp;client=dell-usuk&amp;channel=us&amp;ibd=1060929" target="_blank">http://www.google.com/ig/dell?hl=en&amp;...us&amp;ibd=1060929</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
F2 - REG:system.ini: UserInit=C:\WINDOWS\\system32\\userinit.exe<br />
O1 - Hosts: ::1 localhost<br />
O1 - Hosts: 91.206.201.8 oemantivir.microsoft.com<br />
O1 - Hosts: 91.206.201.8 oemantivir.com<br />
O1 - Hosts: 91.206.201.8 <a rel="nofollow" class="t" href="http://www.oemantivir.com" target="_blank">www.oemantivir.com</a><br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (file missing)<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll (file missing)<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (file missing)<br />
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll<br />
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (file missing)<br />
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll<br />
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe<br />
O4 - HKLM\..\Run: [itype] &quot;C:\Program Files\Microsoft IntelliType Pro\itype.exe&quot;<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\m8F5I5cAG.exe&quot; /runcleanupscript<br />
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br />
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe<br />
O4 - HKCU\..\RunOnce: [UniblueRegistryBooster] &quot;C:\Program Files\Uniblue\RegistryBooster 2010\launcher.exe&quot; delay 20000<br />
O8 - Extra context menu item: Add to Windows &amp;Live Favorites - <a rel="nofollow" class="t" href="http://favorites.live.com/quickadd.aspx" target="_blank">http://favorites.live.com/quickadd.aspx</a><br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll<br />
O10 - Broken Internet access because of LSP provider 'icf.dll' missing<br />
O16 - DPF: CabBuilder - <a rel="nofollow" class="t" href="http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab" target="_blank">http://kiw.imgag.com/imgag/kiw/toolb...lerControl.cab</a><br />
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - <a rel="nofollow" class="t" href="http://www.srtest.com/srl_bin/sysreqlab_srl.cab" target="_blank">http://www.srtest.com/srl_bin/sysreqlab_srl.cab</a><br />
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - <a rel="nofollow" class="t" href="http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab" target="_blank">http://messenger.zone.msn.com/EN-US/.../GAME_UNO1.cab</a><br />
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - <a rel="nofollow" class="t" href="http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab" target="_blank">http://messenger.zone.msn.com/binary...o.cab56649.cab</a><br />
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - <a rel="nofollow" class="t" href="http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab" target="_blank">http://messenger.zone.msn.com/binary...t.cab56907.cab</a><br />
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - <a rel="nofollow" class="t" href="http://messenger.zone.msn.com/binary/WoF.cab57176.cab" target="_blank">http://messenger.zone.msn.com/binary/WoF.cab57176.cab</a><br />
O17 - HKLM\System\CCS\Services\Tcpip\..\{CDD0115A-5FED-479B-B841-811C9B5803F3}: NameServer = 192.168.0.1<br />
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL<br />
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll<br />
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL<br />
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL<br />
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL ,sozewema.dll c:\windows\system32\ralasife.dll<br />
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll<br />
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll<br />
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll<br />
O21 - SSODL: yahidetuj - {ff0c3b8e-1f28-4d76-8cc5-7f6674b75d1d} - (no file)<br />
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe<br />
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe&quot; -service -config &quot;C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)<br />
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe<br />
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe<br />
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
<br />
Any help would be appreciated.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>FirstTimeUser</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread237343.html</guid>
		</item>
		<item>
			<title>cannot connect to microsoft</title>
			<link>http://www.daniweb.com/forums/thread237090.html</link>
			<pubDate>Mon, 09 Nov 2009 01:15:23 GMT</pubDate>
			<description>long story short 
   i cannot connect to microsoft or other antivirus/spyware sites. all other sites are ok it seems 
 i visited a site that was under attack and opened a podcast and my computer locked up and after restart it would not work. pretty much just a black screen. 
 i replaced the hard...</description>
			<content:encoded><![CDATA[<div>long story short<br />
   i cannot connect to microsoft or other antivirus/spyware sites. all other sites are ok it seems<br />
 i visited a site that was under attack and opened a podcast and my computer locked up and after restart it would not work. pretty much just a black screen.<br />
 i replaced the hard drive and loaded the original OS, drivers, etc from the original disc's. then installed windows XP upgrade.<br />
<br />
  i am able to connect to microsoft after following these steps as previously instructed:<br />
<br />
1. Click Start &gt; Run.<br />
2. In the Run box, type the following: cmd<br />
3. Click OK.<br />
4. Type the following and then press Enter. cd..<br />
5. Repeat the previous step until you get to the root level, or C:\&gt;. Note that if your root drive is not C, the letter will be different.<br />
6. At C:\&gt; type the following: net stop dnscache<br />
7. Press Enter. This disables the domain blocking feature of Conficker and you should now be able to reach security Web sites. <br />
<br />
 another symptom is also to update from microsoft it is necessary to RUN &quot;services.msc&quot; and restart &quot;automatic updates&quot; and &quot;background intelligence transfer service&quot;<br />
 <br />
 i ran microsoft security essentials program and it removed worm conficker so it said......(problem still occurs).<br />
 i ran malwarebytes and it and it found nothing (log below)<br />
<br />
Malwarebytes' Anti-Malware 1.41<br />
Database version: 3129<br />
Windows 5.1.2600 Service Pack 3<br />
<br />
11/8/2009 11:57:55 AM<br />
mbam-log-2009-11-08 (11-57-54).txt<br />
<br />
Scan type: Full Scan (C:\|)<br />
Objects scanned: 128135<br />
Time elapsed: 27 minute(s), 13 second(s)<br />
<br />
Memory Processes Infected: 0<br />
Memory Modules Infected: 0<br />
Registry Keys Infected: 0<br />
Registry Values Infected: 0<br />
Registry Data Items Infected: 0<br />
Folders Infected: 0<br />
Files Infected: 0<br />
<br />
Memory Processes Infected:<br />
(No malicious items detected)<br />
<br />
Memory Modules Infected:<br />
(No malicious items detected)<br />
<br />
Registry Keys Infected:<br />
(No malicious items detected)<br />
<br />
Registry Values Infected:<br />
(No malicious items detected)<br />
<br />
Registry Data Items Infected:<br />
(No malicious items detected)<br />
<br />
Folders Infected:<br />
(No malicious items detected)<br />
<br />
Files Infected:<br />
(No malicious items detected)<br />
<br />
<br />
then I ran Windows Live OneCare Safety Scanner and Malicious Software Removal Tool.<br />
  <br />
 I still have to  bypass the dns and restart auto update and BITS <br />
<br />
if i run &quot;regredit&quot; there in every folder there is a file named &quot;default&quot; with no value dat 0000  is this normal?<br />
<br />
 thanks again for any help<br />
NW</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>nw5052001</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread237090.html</guid>
		</item>
		<item>
			<title>Online Virus Scan Question</title>
			<link>http://www.daniweb.com/forums/thread237033.html</link>
			<pubDate>Sun, 08 Nov 2009 19:18:45 GMT</pubDate>
			<description><![CDATA[A webmaster I've been dealing with about an allegedly virus-laden file claims that many online malware scan sites are invalid for scanning Win XP/SP3 files because the sites use Linux versions of A-V engines; i.e., it's necessary to use a Windows-specific program for a valid scan.  Two examples...]]></description>
			<content:encoded><![CDATA[<div>A webmaster I've been dealing with about an allegedly virus-laden file claims that many online malware scan sites are invalid for scanning Win XP/SP3 files because the sites use Linux versions of A-V engines; i.e., it's necessary to use a Windows-specific program for a valid scan.  Two examples online that use 20 to 30 well-known and lesser-known A-V engines to scan files are <a rel="nofollow" class="t" href="http://virusscan.jotti.org/" target="_blank">http://virusscan.jotti.org/</a> and <a rel="nofollow" class="t" href="http://www.virustotal.com" target="_blank">http://www.virustotal.com</a>.  Is there any truth to the webmaster's claim?</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>genegold</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread237033.html</guid>
		</item>
		<item>
			<title>Explorer window - virus?</title>
			<link>http://www.daniweb.com/forums/thread236960.html</link>
			<pubDate>Sun, 08 Nov 2009 10:42:58 GMT</pubDate>
			<description>Hi, this is my first post so please be patient if it get this wrong!! 
 
I keep getting a pop-up window quoting MD5| and then a string of numbers but with a different url in the top of the window each time.  I recently got sent a load of messages which McAfee picked up as having viruses in them,...</description>
			<content:encoded><![CDATA[<div>Hi, this is my first post so please be patient if it get this wrong!!<br />
<br />
I keep getting a pop-up window quoting MD5| and then a string of numbers but with a different url in the top of the window each time.  I recently got sent a load of messages which McAfee picked up as having viruses in them, have scanned and quarantined but still get the same annoying window popping up.<br />
A jpeg of one of the windows is attached.<br />
<br />
Any help would be really appreciated.</div>  <br /> <div style="padding:5px">    <fieldset class="fieldset"> <legend>Attached Images</legend> <table cellpadding="0" cellspacing="5" border="0"> <tr> <td><img class="inlineimg" src="http://www.daniweb.com/forums/images/attach/jpg.gif" alt="File Type: jpg" width="16" height="16" border="0" style="vertical-align:baseline" /></td> <td><a href="http://www.daniweb.com/forums/attachment.php?attachmentid=12493&amp;d=1257676910" target="_blank">md5.jpg</a> (17.0 KB)</td> </tr> </table> </fieldset>   </div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>carlstone</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread236960.html</guid>
		</item>
		<item>
			<title>Windows 7 persistent URL redirect</title>
			<link>http://www.daniweb.com/forums/thread236927.html</link>
			<pubDate>Sun, 08 Nov 2009 04:28:45 GMT</pubDate>
			<description>Hello, 
 
I have read some URL redirect entries here and tried to clean my system the same way. At times things seem to be clean for a minute and then all of a sudden Windows defender finds things which claims to have been cleaned. I would appreciate your help in giving me directions for cleaning...</description>
			<content:encoded><![CDATA[<div>Hello,<br />
<br />
I have read some URL redirect entries here and tried to clean my system the same way. At times things seem to be clean for a minute and then all of a sudden Windows defender finds things which claims to have been cleaned. I would appreciate your help in giving me directions for cleaning my system. Please let me know if you need more information.  <br />
I have run Malwarebyte, spybot, ccleaner, superantispyware, and ESET online cleaning. I have included logs from Malwarebyte, ESET,and hijackthis .<br />
<br />
<br />
Malwarebytes' Anti-Malware 1.41<br />
Database version: 3118<br />
Windows 6.1.7600<br />
<br />
11/7/2009 3:00:07 PM<br />
mbam-log-2009-11-07 (15-00-07).txt<br />
<br />
Scan type: Full Scan (C:\|)<br />
Objects scanned: 159559<br />
Time elapsed: 17 minute(s), 8 second(s)<br />
<br />
Memory Processes Infected: 0<br />
Memory Modules Infected: 0<br />
Registry Keys Infected: 0<br />
Registry Values Infected: 0<br />
Registry Data Items Infected: 0<br />
Folders Infected: 0<br />
Files Infected: 0<br />
<br />
Memory Processes Infected:<br />
(No malicious items detected)<br />
<br />
Memory Modules Infected:<br />
(No malicious items detected)<br />
<br />
Registry Keys Infected:<br />
(No malicious items detected)<br />
<br />
Registry Values Infected:<br />
(No malicious items detected)<br />
<br />
Registry Data Items Infected:<br />
(No malicious items detected)<br />
<br />
Folders Infected:<br />
(No malicious items detected)<br />
<br />
Files Infected:<br />
(No malicious items detected)<br />
<br />
<br />
ESETSmartInstaller@High as CAB hook log:<br />
OnlineScanner.ocx - registred OK<br />
esets_scanner_update returned -1 esets_gle=53251<br />
# version=7<br />
# iexplore.exe=8.00.7600.16385 (win7_rtm.090713-1255)<br />
# OnlineScanner.ocx=1.0.0.6211<br />
# api_version=3.0.2<br />
# EOSSerial=3b4b5e9e5d6973479fb4020466b4dafb<br />
# end=finished<br />
# remove_checked=true<br />
# archives_checked=true<br />
# unwanted_checked=true<br />
# unsafe_checked=false<br />
# antistealth_checked=true<br />
# utc_time=2009-11-07 01:28:06<br />
# local_time=2009-11-07 08:28:06 (-0500, Eastern Standard Time)<br />
# country=&quot;United States&quot;<br />
# lang=1033<br />
# osver=6.1.7600 NT <br />
# compatibility_mode=5893 16776573 100 94 0 9143468 0 0<br />
# compatibility_mode=8192 67108863 100 0 0 0 0 0<br />
# scanned=61214<br />
# found=1<br />
# cleaned=0<br />
# scan_time=1809<br />
C:\Windows\System32\drivers\atapi.sys	Win32/Olmarik.OF virus (unable to clean)	00000000000000000000000000000000<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 10:55:37 PM, on 11/7/2009<br />
Platform: Unknown Windows (WinNT 6.01.3504)<br />
MSIE: Internet Explorer v8.00 (8.00.7600.16385)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\system32\taskhost.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\GPSoftware\Directory Opus\dopusrt.exe<br />
C:\Windows\system32\igfxsrvc.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe<br />
C:\Windows\system32\taskhost.exe<br />
C:\Program Files\GPSoftware\Directory Opus\dopus.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Windows\system32\SearchProtocolHost.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://m.www.yahoo.com/" target="_blank">http://m.www.yahoo.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O4 - HKCU\..\Run: [Directory Opus Desktop Dblclk] &quot;C:\Program Files\GPSoftware\Directory Opus\dopusrt.exe&quot; /dblclk<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - <a rel="nofollow" class="t" href="http://download.eset.com/special/eos-beta/OnlineScanner.cab" target="_blank">http://download.eset.com/special/eos...ineScanner.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a rel="nofollow" class="t" href="http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...nt/swflash.cab</a><br />
O17 - HKLM\System\CCS\Services\Tcpip\..\{FC6A1E96-FC3B-4A15-8AAA-78B97D849F2F}: NameServer = 68.87.77.134,68.87.72.134<br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll<br />
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe<br />
O23 - Service: Acronis Nonstop Backup service (afcdpsrv) - Acronis - C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe<br />
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe<br />
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe<br />
<br />
--<br />
End of file - 4306 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>skyhydro</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread236927.html</guid>
		</item>
		<item>
			<title>virus</title>
			<link>http://www.daniweb.com/forums/thread236911.html</link>
			<pubDate>Sun, 08 Nov 2009 02:31:32 GMT</pubDate>
			<description><![CDATA[C:\Documents and Settings\THULSI KANTH\fjekvm.exe\[UPX...... 
hii friends plz do help tis........ in my system virus has been detected for      
every 5 min.... for this all d time i cleared it.. but again it s showing lik tat.....i.e...above mentioned....]]></description>
			<content:encoded><![CDATA[<div>C:\Documents and Settings\THULSI KANTH\fjekvm.exe\[UPX......<br />
hii friends plz do help tis........ in my system virus has been detected for     <br />
every 5 min.... for this all d time i cleared it.. but again it s showing lik tat.....i.e...above mentioned....</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>ctk_satz</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread236911.html</guid>
		</item>
		<item>
			<title>WIN LOGON ? Trojan</title>
			<link>http://www.daniweb.com/forums/thread236878.html</link>
			<pubDate>Sat, 07 Nov 2009 22:35:22 GMT</pubDate>
			<description>I had an attempted entry for WIN LOGON (have McAfee security via AOL...yes I do...), and despite multiple attempts to deny entry, it was persistent and I inadvertently clicked it in. 
 
Is it a trojan or ?? and should I remove it? 
 
Thanks</description>
			<content:encoded><![CDATA[<div>I had an attempted entry for WIN LOGON (have McAfee security via AOL...yes I do...), and despite multiple attempts to deny entry, it was persistent and I inadvertently clicked it in.<br />
<br />
Is it a trojan or ?? and should I remove it?<br />
<br />
Thanks</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>dmember</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread236878.html</guid>
		</item>
		<item>
			<title>Spy/Malware infestation</title>
			<link>http://www.daniweb.com/forums/thread236812.html</link>
			<pubDate>Sat, 07 Nov 2009 15:56:45 GMT</pubDate>
			<description>Hi there, 
 
I am suffering an issue at the moment where if I search on a serach engine and click on a result the web redirects me to another site, this will happen 3/4/5 times before directing to the correct site.  After a while I will also get another page open - www.malware-online.com and a pop...</description>
			<content:encoded><![CDATA[<div>Hi there,<br />
<br />
I am suffering an issue at the moment where if I search on a serach engine and click on a result the web redirects me to another site, this will happen 3/4/5 times before directing to the correct site.  After a while I will also get another page open - <a rel="nofollow" class="t" href="http://www.malware-online.com" target="_blank">www.malware-online.com</a> and a pop to say i need to upgrade my antivirus.  This freezes the pc untill it opens a 'winodws explorer' window within IE.  The only way to get rid of this (if your quick enough) is through task manager.<br />
I have run a virus scan (mcafee) and also run spybot and adaware, both normally and in safemode but it is still happening. <br />
<br />
Would someone be able to have a look at this HJT log and let me know if there is anything in there that might explain what is happening?<br />
<br />
Thank you in advance :)<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 15:47:47, on 07/11/2009<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18828)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
c:\PROGRA~1\mcafee.com\agent\mcagent.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe<br />
C:\Program Files\Toshiba\Toshiba Online Product Information\TOPI.exe<br />
C:\Windows\System32\igfxtray.exe<br />
C:\Windows\System32\hkcmd.exe<br />
C:\Windows\System32\igfxpers.exe<br />
C:\Program Files\Apoint2K\Apoint.exe<br />
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe<br />
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe<br />
C:\Program Files\Toshiba\SmoothView\SmoothView.exe<br />
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe<br />
C:\Program Files\Toshiba\HDMICtrlMan\HDMICtrlMan.exe<br />
C:\Program Files\MouseDriver\MouseDriver.exe<br />
C:\Program Files\PowerISO\PWRISOVM.EXE<br />
C:\Program Files\Toshiba TEMPRO\TemproTray.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
E:\itunes\iTunesHelper.exe<br />
C:\Program Files\HP\HP Software Update\hpwuschd2.exe<br />
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br />
C:\Windows\system32\igfxsrvc.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe<br />
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe<br />
C:\Windows\system32\igfxext.exe<br />
C:\Program Files\Toshiba\HDMICtrlMan\HCMSoundChanger.exe<br />
C:\Program Files\Apoint2K\HidFind.exe<br />
C:\Program Files\Apoint2K\Apntex.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Users\Mark Hogben\Downloads\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.virginmedia.com/" target="_blank">http://www.virginmedia.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!<br />
<br />
\Companion\Installs\cpn\yt.dll<br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!<br />
<br />
\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common <br />
<br />
Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft <br />
<br />
Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web <br />
<br />
Printing\hpswp_BHO.dll<br />
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!<br />
<br />
\Companion\Installs\cpn\yt.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START<br />
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe<br />
O4 - HKLM\..\Run: [cfFncEnabler.exe] cfFncEnabler.exe<br />
O4 - HKLM\..\Run: [Google EULA Launcher] c:\Program Files\Google\Google EULA\GoogleEULALauncher.exe IE PA<br />
O4 - HKLM\..\Run: [Toshiba TEMPO] C:\Program Files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe<br />
O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup<br />
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe<br />
O4 - HKLM\..\Run: [Camera Assistant Software] &quot;C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe&quot; /start<br />
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE<br />
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe<br />
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe<br />
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe<br />
O4 - HKLM\..\Run: [HDMICtrlMan] C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe<br />
O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [MouseDriverD9] C:\Program Files\MouseDriver\MouseDriver.exe<br />
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe<br />
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE<br />
O4 - HKLM\..\Run: [Toshiba TEMPRO] C:\Program Files\Toshiba TEMPRO\TemproTray.exe<br />
O4 - HKLM\..\Run: [mcagent_exe] &quot;C:\Program Files\McAfee.com\Agent\mcagent.exe&quot; /runkey<br />
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;E:\itunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe<br />
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] &quot;C:\Program Files\Common <br />
<br />
Files\Ahead\Lib\NMBgMonitor.exe&quot;<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [Steam] &quot;c:\program files\steam\steam.exe&quot; -silent<br />
O4 - HKCU\..\Run: [TomTomHOME.exe] &quot;C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe&quot; -s<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKUS\S-1-5-18\..\Run: [TOSHIBA Online Product Information] C:\Program Files\TOSHIBA\Toshiba Online Product <br />
<br />
Information\topi.exe (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [TOSHIBA Online Product Information] C:\Program Files\TOSHIBA\Toshiba Online Product <br />
<br />
Information\topi.exe (User 'Default user')<br />
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (User 'Default user')<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O8 - Extra context menu item: Add to Google Photos Screensa&amp;ver - res://C:\Windows\system32\GPhotos.scr/200<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: eBay.co.uk - Buy It Sell It Love It - {76577871-04EC-495E-A12B-91F7C3600AFA} - <br />
<br />
<a rel="nofollow" class="t" href="http://rover.ebay.com/rover/1/710-44557-9400-3/4" target="_blank">http://rover.ebay.com/rover/1/710-44557-9400-3/4</a> (file missing)<br />
O9 - Extra button: Amazon.co.uk - {8A918C1D-E123-4E36-B562-5C1519E434CE} - <a rel="nofollow" class="t" href="http://www.amazon.co.uk/exec/obidos/redirect-" target="_blank">http://www.amazon.co.uk/exec/obidos/redirect-</a><br />
<br />
home?tag=Toshibaukbholink-21&amp;site=home (file missing)<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web <br />
<br />
Printing\hpswp_BHO.dll<br />
O13 - Gopher Prefix: <br />
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device <br />
<br />
Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google <br />
<br />
Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common <br />
<br />
Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe<br />
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br />
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe<br />
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe<br />
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Flash Memory <br />
<br />
Card Driver\o2flash.exe<br />
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe<br />
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe<br />
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search &amp; <br />
<br />
Destroy\SDWinSec.exe<br />
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe<br />
O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program <br />
<br />
Files\Toshiba TEMPRO\TemproSvc.exe<br />
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD <br />
<br />
PLAYER\TNaviSrv.exe<br />
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe<br />
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe<br />
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe<br />
O23 - Service: TOSHIBA Bluetooth Service - Unknown owner - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe <br />
<br />
(file missing)<br />
O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe<br />
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead <br />
<br />
Systems\DVD\ULCDRSvr.exe<br />
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe<br />
<br />
--<br />
End of file - 12503 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Hoggy12</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread236812.html</guid>
		</item>
		<item>
			<title>Strange Virus</title>
			<link>http://www.daniweb.com/forums/thread236774.html</link>
			<pubDate>Sat, 07 Nov 2009 12:37:04 GMT</pubDate>
			<description>Hi ive been trying to fix my pc for months and i think i have a strange virus  that boots  off an on my pc consistantly every 10 secs.. ill try to type  this short since it might shut off while im writing thisnow .. 
 
ive replaced the heat sink fan and power unit   which got my pc to work for 4...</description>
			<content:encoded><![CDATA[<div>Hi ive been trying to fix my pc for months and i think i have a strange virus  that boots  off an on my pc consistantly every 10 secs.. ill try to type  this short since it might shut off while im writing thisnow ..<br />
<br />
ive replaced the heat sink fan and power unit   which got my pc to work for 4 dys before it  started to  do the whole loop on an off thing again untill i ahve  to manaully shut it off from the power supply( XION atx power supply im using ) .<br />
<br />
Im trying to see if i can get my pc clean so that i can figure out what hardware issue is causing my pc to do this another site mention that it could be a  virus or worm that &quot; reboots on &amp; off randomly pc &quot;..   heres my hijacklog file<br />
<br />
let me know what i need to take out also i notice before all this started to happen.. ive installed a malware bytes program to get rid of spyware not sure if that would do it but please if guys can let me know that would great thanks!<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 7:21:28 AM, on 11/7/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\system32\DeltaIITray.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br />
C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br />
C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\AVG\AVG8\avgcsrvx.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Documents and Settings\Jc\My Documents\HJT\HiJackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = <a rel="nofollow" class="t" href="http://windowsupdate.microsoft.com/" target="_blank">http://windowsupdate.microsoft.com/</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r<br />
O4 - HKLM\..\Run: [DeltaIITaskbarApp] C:\WINDOWS\system32\DeltaIITray.exe<br />
O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;  -osboot<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [M-Audio Taskbar Icon] C:\WINDOWS\System32\DeltaIITray.exe<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKCU\..\Run: [Performance Center] C:\Program Files\Ascentive\Performance Center\APCMain.exe -m<br />
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden<br />
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] &quot;C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe&quot;<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - <a rel="nofollow" class="t" href="http://inst.c-wss.com/m010g/EN/install/gtdownlr.cab" target="_blank">http://inst.c-wss.com/m010g/EN/install/gtdownlr.cab</a><br />
O16 - DPF: {264AED84-12F1-4CA1-8AA7-EB939AE58D8D} (STCWeb Control) - <a rel="nofollow" class="t" href="https://cvpn.onss.com/CACHE/webvpn/stc/1/binaries/stcweb.cab" target="_blank">https://cvpn.onss.com/CACHE/webvpn/s...ies/stcweb.cab</a><br />
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - <a rel="nofollow" class="t" href="http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab" target="_blank">http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a rel="nofollow" class="t" href="http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1199676726031" target="_blank">http://www.update.microsoft.com/wind...?1199676726031</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
O23 - Service: Cisco AnyConnect VPN Agent (vpnagent) - Cisco Systems, Inc. - C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe<br />
<br />
--<br />
End of file - 5952 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>pimpwack</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread236774.html</guid>
		</item>
		<item>
			<title>Click on Search Results and redirected to non-related page</title>
			<link>http://www.daniweb.com/forums/thread236588.html</link>
			<pubDate>Fri, 06 Nov 2009 15:30:18 GMT</pubDate>
			<description>Every I conduct a search for something using Google, I get the true results listed but when I click on the result I am redirected to a page on Virus software, travel sites or something similar. I can open the results if I right click the link and get it to open in a new tab. 
 
Additionally, unless...</description>
			<content:encoded><![CDATA[<div>Every I conduct a search for something using Google, I get the true results listed but when I click on the result I am redirected to a page on Virus software, travel sites or something similar. I can open the results if I right click the link and get it to open in a new tab.<br />
<br />
Additionally, unless I run IE8 on Admin Mode for Vista, I continually crash. <br />
<br />
I have run McAfee and gotten 300+ instances of Virnut.n.gen repaired and had 7 instances of Artemis! quarantined. <br />
<br />
My HijackThis Log:<br />
<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 10:20:56 AM, on 11/6/2009<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18828)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
c:\PROGRA~1\mcafee.com\agent\mcagent.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\System32\wpcumi.exe<br />
C:\Program Files\Microsoft LifeChat\LifeChat.exe<br />
C:\Program Files\QuickTime\QTTask.exe<br />
D:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\X3watch\x3watch.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Program Files\Electronic Arts\EADM\Core.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Windows\Explorer.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe<br />
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Windows Mail\WinMail.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\msfeedssync.exe<br />
L:\Downloads\HijackThis.exe<br />
<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll<br />
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Spybot - Search &amp; Destroy\SDHelper.dll<br />
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe<br />
O4 - HKLM\..\Run: [MSConfig] &quot;C:\Windows\System32\msconfig.exe&quot; /auto<br />
O4 - HKLM\..\Run: [NeroCheck] C:\Windows\system32\NeroCheck.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [LifeChat] &quot;C:\Program Files\Microsoft LifeChat\LifeChat.exe&quot;<br />
O4 - HKLM\..\Run: [mcagent_exe] &quot;C:\Program Files\McAfee.com\Agent\mcagent.exe&quot; /runkey<br />
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;D:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [x3watch] C:\Program Files\X3watch\x3watch.exe<br />
O4 - HKLM\..\Run: [Regedit32] C:\Windows\system32\regedit.exe<br />
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [igndlm.exe] D:\Download Manager\DLM.exe /windowsstart /startifwork<br />
O4 - HKCU\..\Run: [EA Core] &quot;C:\Program Files\Electronic Arts\EADM\Core.exe&quot; -silent<br />
O4 - HKCU\..\Run: [DAEMON Tools Lite] &quot;D:\DAEMON Tools Lite\daemon.exe&quot; -autorun<br />
O4 - HKCU\..\Run: [A00F59FC2A.exe] C:\Users\Michael\AppData\Local\Temp\_A00F59FC2A.exe<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKCU\..\Run: [ter8m] RUNDLL32.EXE C:\Windows\TEMP\msxm192z.dll,w<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-18\..\Run: [ter8m] RUNDLL32.EXE C:\Windows\TEMP\msxm192z.dll,w (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [ter8m] RUNDLL32.EXE C:\Windows\TEMP\msxm192z.dll,w (User 'Default user')<br />
O4 - Startup: 9298734.lnk = C:\Users\Michael\AppData\Local\Temp\SMScvhost.exe<br />
O4 - Startup: santa.bat<br />
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O15 - Trusted Zone: <a rel="nofollow" class="t" href="http://www.convergysworkathome.com" target="_blank">http://www.convergysworkathome.com</a><br />
O16 - DPF: vzTCPConfig - <a rel="nofollow" class="t" href="http://www2.verizon.net/help/fios_settings/include/vzTCPConfig.CAB" target="_blank">http://www2.verizon.net/help/fios_se...zTCPConfig.CAB</a><br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - <a rel="nofollow" class="t" href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" target="_blank">http://upload.facebook.com/controls/...oUploader5.cab</a><br />
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - <a rel="nofollow" class="t" href="http://www.pcpitstop.com/betapit/PCPitStop.CAB" target="_blank">http://www.pcpitstop.com/betapit/PCPitStop.CAB</a><br />
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - <a rel="nofollow" class="t" href="http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/MyFunCardsInitialSetup1.0.1.1.cab" target="_blank">http://ak.exe.imgfarm.com/images/noc...tup1.0.1.1.cab</a><br />
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - <a rel="nofollow" class="t" href="http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab" target="_blank">http://www.fileplanet.com/fpdlmgr/ca..._2.3.6.108.cab</a><br />
O16 - DPF: {549F957E-2F89-11D6-8CFE-00C04F52B225} (CMV5 Class) - <a rel="nofollow" class="t" href="http://couponmom.coupons.smartsource.com/download/cscmv5X.cab" target="_blank">http://couponmom.coupons.smartsource...ad/cscmv5X.cab</a><br />
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - <a rel="nofollow" class="t" href="http://upload.facebook.com/controls/FacebookPhotoUploader3.cab" target="_blank">http://upload.facebook.com/controls/...oUploader3.cab</a><br />
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - <a rel="nofollow" class="t" href="http://download.divx.com/player/DivXBrowserPlugin.cab" target="_blank">http://download.divx.com/player/DivXBrowserPlugin.cab</a><br />
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - <a rel="nofollow" class="t" href="http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab" target="_blank">http://upload.facebook.com/controls/...Uploader55.cab</a><br />
O16 - DPF: {A084A130-28AE-4B32-B51A-1C8CE164BC88} (WNICheck2 Class) - <a rel="nofollow" class="t" href="http://www.convergysworkathome.com/AppHardT.CAB" target="_blank">http://www.convergysworkathome.com/AppHardT.CAB</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a rel="nofollow" class="t" href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - <a rel="nofollow" class="t" href="http://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab" target="_blank">http://upload.facebook.com/controls/...ploader4_5.cab</a><br />
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - <a rel="nofollow" class="t" href="http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll" target="_blank">http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll</a><br />
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O20 - AppInit_DLLs: C:\Windows\system32\kbdnet.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: fastnetsrv  Service (fastnetsrv) - Netopsystems A - C:\Windows\system32\FastNetSrv.exe<br />
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - D:\MAGIX\Common\Database\bin\fbserver.exe<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe<br />
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe<br />
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br />
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe<br />
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\McShield.exe<br />
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe<br />
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe<br />
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe<br />
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe<br />
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe<br />
<br />
--<br />
End of file - 10428 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>MPRatamacue</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread236588.html</guid>
		</item>
		<item>
			<title>Connecting to a-connect Virus.</title>
			<link>http://www.daniweb.com/forums/thread236578.html</link>
			<pubDate>Fri, 06 Nov 2009 14:38:24 GMT</pubDate>
			<description>I have an Acer 5720 Travelmate Laptop. Recently ugraded my Vodafone E220 Datacard to the latest software. Whenever I connect to the Internet id drops the connection and try to connect to A-CONNECT ( bunkown to me). Somebody told me that it is a possible virus.  But I have KASPERSKY Internet...</description>
			<content:encoded><![CDATA[<div>I have an Acer 5720 Travelmate Laptop. Recently ugraded my Vodafone E220 Datacard to the latest software. Whenever I connect to the Internet id drops the connection and try to connect to A-CONNECT ( bunkown to me). Somebody told me that it is a possible virus.  But I have KASPERSKY Internet Security ( anti-virus loaded). HELP ! ! ! !  how can I delete/remove this virus.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Lungis</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread236578.html</guid>
		</item>
		<item>
			<title>Multiple Viruses</title>
			<link>http://www.daniweb.com/forums/thread236570.html</link>
			<pubDate>Fri, 06 Nov 2009 14:06:13 GMT</pubDate>
			<description><![CDATA[I've clicked on some link and now I have multiple critical viruses.  Trojans, key logger variant, etc.  I'm not able to access the registry, I think damage has been done to it.  What can I do?  Reformatting the computer isn't a problem for me.  There's nothing on it that I need to keep.  Is this...]]></description>
			<content:encoded><![CDATA[<div>I've clicked on some link and now I have multiple critical viruses.  Trojans, key logger variant, etc.  I'm not able to access the registry, I think damage has been done to it.  What can I do?  Reformatting the computer isn't a problem for me.  There's nothing on it that I need to keep.  Is this the best option?  If so, how do I do it?</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>munecka</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread236570.html</guid>
		</item>
		<item>
			<title>HIjackthis log/can someone help</title>
			<link>http://www.daniweb.com/forums/thread236485.html</link>
			<pubDate>Fri, 06 Nov 2009 05:35:47 GMT</pubDate>
			<description>Here is my Hijack this log  can somone check it out and tell me what is safe to get rid of.  I think I know of a few but figured i had better check with the people who know best.  Thanks  Ryun 
 
 Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 11:34:39 PM, on 11/5/2009 
Platform: Windows...</description>
			<content:encoded><![CDATA[<div>Here is my Hijack this log  can somone check it out and tell me what is safe to get rid of.  I think I know of a few but figured i had better check with the people who know best.  Thanks  Ryun<br />
<br />
 Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 11:34:39 PM, on 11/5/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Tall Emu\Online Armor\OAcat.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Tall Emu\Online Armor\oasrv.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
C:\Program Files\DigitalPersona\Bin\DpHost.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\system32\lxdicoms.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe<br />
C:\Program Files\DigitalPersona\Bin\DPFUSMgr.exe<br />
C:\windows\system\hpsysdrv.exe<br />
C:\WINDOWS\system32\dla\tfswctrl.exe<br />
C:\WINDOWS\System32\igfxtray.exe<br />
C:\WINDOWS\System32\hkcmd.exe<br />
C:\WINDOWS\system32\ps2.exe<br />
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE<br />
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe<br />
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe<br />
C:\PROGRA~1\Yahoo!\browser\ycommon.exe<br />
C:\WINDOWS\SM1BG.EXE<br />
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe<br />
C:\Program Files\DigitalPersona\Bin\DPAgnt.exe<br />
C:\Program Files\QuickTime\qttask.exe<br />
C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe<br />
C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Tall Emu\Online Armor\oaui.exe<br />
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe<br />
C:\Program Files\Microsoft ActiveSync\wcescomm.exe<br />
C:\Program Files\Tall Emu\Online Armor\OAhlp.exe<br />
C:\PROGRA~1\MI3AA1~1\rapimgr.exe<br />
C:\Program Files\Java\jre6\bin\jucheck.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.hotmail.com/" target="_blank">http://www.hotmail.com/</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = ,<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll<br />
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\PROGRA~1\Yahoo!\Common\YIeTagBm.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [StorageGuard] &quot;C:\Program Files\VERITAS Software\Update Manager\sgtray.exe&quot; /r<br />
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe<br />
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe<br />
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe<br />
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE<br />
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe<br />
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe<br />
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE<br />
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe<br />
O4 - HKLM\..\Run: [DPAgnt] C:\Program Files\DigitalPersona\Bin\DPAgnt.exe<br />
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [QAGENT] C:\Program Files\QUICKENW\QAGENT.EXE<br />
O4 - HKLM\..\Run: [FaxCenterServer] &quot;C:\Program Files\\Lexmark Fax Solutions\fm3032.exe&quot; /s<br />
O4 - HKLM\..\Run: [lxdimon.exe] &quot;C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe&quot;<br />
O4 - HKLM\..\Run: [lxdiamon] &quot;C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [@OnlineArmor GUI] &quot;C:\Program Files\Tall Emu\Online Armor\oaui.exe&quot;<br />
O4 - HKLM\..\Run: [avgnt] &quot;C:\Program Files\Avira\AntiVir Desktop\avgnt.exe&quot; /min<br />
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
O4 - HKCU\..\Run: [LGBLiveUpdate] C:\WINDOWS\system32\lgbpd.exe<br />
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe<br />
O4 - HKCU\..\Run: [H/PC Connection Agent] &quot;C:\Program Files\Microsoft ActiveSync\wcescomm.exe&quot;<br />
O4 - HKCU\..\Run: [TomTomHOME.exe] &quot;C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe&quot;<br />
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br />
O4 - Global Startup: AT&amp;T Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe<br />
O4 - Global Startup: Event Reminder.lnk = C:\Program Files\The Print Shop 23\Remind.exe<br />
O4 - Global Startup: Harmony Monitor.lnk = C:\Program Files\Logitech\Harmony Remote\EasyZapperMonitor.exe<br />
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe<br />
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll<br />
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll<br />
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll<br />
O9 - Extra button: AT&amp;T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll<br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?linkid=39204" target="_blank">http://go.microsoft.com/fwlink/?linkid=39204</a><br />
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - <a rel="nofollow" class="t" href="http://photos.walmart.com/WalmartActivia.cab" target="_blank">http://photos.walmart.com/WalmartActivia.cab</a><br />
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - <a rel="nofollow" class="t" href="http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab" target="_blank">http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a rel="nofollow" class="t" href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1252243607234" target="_blank">http://update.microsoft.com/microsof...?1252243607234</a><br />
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - <a rel="nofollow" class="t" href="http://download.eset.com/special/eos/OnlineScanner.cab" target="_blank">http://download.eset.com/special/eos/OnlineScanner.cab</a><br />
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - <a rel="nofollow" class="t" href="http://autos.msn.com/components/ocx/survid/MSSurVid.cab" target="_blank">http://autos.msn.com/components/ocx/survid/MSSurVid.cab</a><br />
O16 - DPF: {BB47CA33-8B4D-11D0-9511-00C04FD9152D} (ExteriorSurround Object) - <a rel="nofollow" class="t" href="http://autos.msn.com/components/ocx/exterior/Outside.cab" target="_blank">http://autos.msn.com/components/ocx/...or/Outside.cab</a><br />
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) - <a rel="nofollow" class="t" href="http://www.photodex.com/pxplay.cab" target="_blank">http://www.photodex.com/pxplay.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a rel="nofollow" class="t" href="https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab" target="_blank">https://download.macromedia.com/pub/...sh/swflash.cab</a><br />
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
O23 - Service: Windows XP FUS Manager (DPFUSMgr) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DPFUSMgr.exe<br />
O23 - Service: Biometric Authentication Service (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHost.exe<br />
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: lxdiCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdiserv.exe<br />
O23 - Service: lxdi_device -   - C:\WINDOWS\system32\lxdicoms.exe<br />
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe<br />
O23 - Service: Online Armor Helper Service (OAcat) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\OAcat.exe<br />
O23 - Service: Online Armor (SvcOnlineArmor) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\oasrv.exe<br />
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe<br />
<br />
--<br />
End of file - 8982 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>ryun</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread236485.html</guid>
		</item>
		<item>
			<title>Computer acting up, veruy slow (Please Help)</title>
			<link>http://www.daniweb.com/forums/thread236420.html</link>
			<pubDate>Thu, 05 Nov 2009 23:45:34 GMT</pubDate>
			<description><![CDATA[Ok, here are the issues I'm having & yes I run a lot of anti programs including Advanced System Care which some say they love & a few people say caused problems. 
 
Honestly I can't remember when the problems started, at least 4-6 months ago & it may have started after I bought the ASC, but I just...]]></description>
			<content:encoded><![CDATA[<div>Ok, here are the issues I'm having &amp; yes I run a lot of anti programs including Advanced System Care which some say they love &amp; a few people say caused problems.<br />
<br />
Honestly I can't remember when the problems started, at least 4-6 months ago &amp; it may have started after I bought the ASC, but I just exited out of it &amp; still no change.<br />
<br />
1. I click on &quot;my computer&quot;, &amp; it takes about 20-30 seconds to let me have access to the window. That's even after rebooting which I just did.<br />
<br />
That also happens with Fx, but when I've rebooted, everything is very quick until I leave the computer &amp; come back, then it takes several minutes to let me have access.<br />
<br />
Also in the last several days I'm having problems with TB (thunderbird) &amp; I didn't have hanging problems with TB b4.<br />
<br />
2. This is the most frustrating thing.<br />
<br />
At first I thought it was the site, but then it started happening on 3 different sites &amp; after bitching &amp; arguing, I have to admit it may very well be on my end.<br />
<br />
Either:<br />
<br />
a) <a rel="nofollow" class="t" href="http://www.cj.com" target="_blank">www.cj.com</a><br />
<br />
when I login into the membership area (main index page is fine), the CSS files don't load so I can't do anything within the site. Others don't have this problem. That's on both Fx &amp; IE.<br />
<br />
b) <a rel="nofollow" class="t" href="http://www.odesk.com" target="_blank">www.odesk.com</a><br />
<br />
When I go to edit one of our job postings, it won't let me save it saying the start date is wrong even though it's not.<br />
<br />
After weeks of them testing it, it works fine in Fx for them, but not for me. I just tried it again &amp; Fx just came out w/ an update &amp; still can't do it.<br />
<br />
In IE it works fine &lt;sigh&gt;<br />
<br />
c) <a rel="nofollow" class="t" href="http://www.freedomvoice.com" target="_blank">www.freedomvoice.com</a><br />
<br />
Tried to upload audio files &amp; make changes to my acct., can't do it in Fx, only in IE.<br />
<br />
They say they tested it &amp; there's nothing wrong. Now I didn't try it out after shutting down Fx which I should have done &amp; I don't want to touch anything to test it b/c it's the way I want it now.<br />
<br />
My assistant also had this problem in Safari &amp; Fx, but he's on a MAC &amp; you know most coders can't code properly for MACs, so that doesn't really tell me much.<br />
<br />
d) <a rel="nofollow" class="t" href="http://www.Hyperoffice.com" target="_blank">www.Hyperoffice.com</a><br />
<br />
I add a new day in the notes area &amp; instead of it taking me back to the last window, it takes me all the way back to the folders area.<br />
<br />
It's intermittent &amp; they claim there's no problem on their end.<br />
<br />
I do have to say one thing. Most if not all of these sites are poorly coded I think. I'm not a coder, but I know how sites work &amp; I can tell when it's garbage code.<br />
<br />
The thing is, no one else is having the problem. I have the latest version of Fx, I hate IE, sometimes the site works on IE, but I don't use IE daily enough to know if it's just Fx or what is going on.<br />
<br />
It's stressing me out, wasting my time, PLEASE HELP!<br />
<br />
Thanks<br />
<br />
<br />
Michelle<br />
----------------------------------------------<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 9:35:59 PM, on 10/28/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
C:\WINDOWS\ATKKBService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe<br />
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br />
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe<br />
C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe<br />
C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe<br />
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\oDesk\oDeskCommonPrefs.exe<br />
C:\Program Files\Shelltoys\Personal Assistant\assistant.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe<br />
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe<br />
C:\Program Files\Microsoft ActiveSync\wcescomm.exe<br />
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe<br />
C:\PROGRA~1\MICROS~3\rapimgr.exe<br />
C:\Garmin\gStart.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\Program Files\WinZip\WZQKPICK.EXE<br />
C:\Program Files\oDesk\oDeskTeam.exe<br />
C:\Program Files\oDesk\oDeskShare.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe<br />
C:\WINDOWS\system32\NOTEPAD.EXE<br />
C:\WINDOWS\system32\notepad.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Mozilla Thunderbird\thunderbird.exe<br />
C:\WINDOWS\System32\vssvc.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.ask.com/?o=101677&amp;l=dis" target="_blank">http://www.ask.com/?o=101677&amp;l=dis</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br />
O4 - HKLM\..\Run: [ATIPTA] &quot;C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&quot;<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [pdfFactory Dispatcher v3] &quot;C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe&quot; /source=HKLM<br />
O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [StartCCC] &quot;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&quot; MSRun<br />
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe /autorun<br />
O4 - HKLM\..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe<br />
O4 - HKLM\..\Run: [avgnt] &quot;C:\Program Files\Avira\AntiVir Desktop\avgnt.exe&quot; /min<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKLM\..\Run: [Prefs] C:\Program Files\oDesk\oDeskLaunch.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Program Files\ASUS\SmartDoctor\\SmartDoctor.exe /start<br />
O4 - HKCU\..\Run: [Personal Assistant] C:\Program Files\Shelltoys\Personal Assistant\assistant.exe<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKCU\..\Run: [eFax 4.4] &quot;C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe&quot; /R<br />
O4 - HKCU\..\Run: [Messenger (Yahoo!)] &quot;C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe&quot; -quiet<br />
O4 - HKCU\..\Run: [H/PC Connection Agent] &quot;C:\Program Files\Microsoft ActiveSync\wcescomm.exe&quot;<br />
O4 - HKCU\..\Run: [ccleaner] &quot;C:\Program Files\CCleaner\CCleaner.exe&quot; /AUTO<br />
O4 - HKCU\..\Run: [Advanced SystemCare 3] &quot;C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe&quot; /startup<br />
O4 - HKCU\..\Run: [gStart] C:\Garmin\gStart.exe<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O4 - Global Startup: Quick View Plus.lnk = ?<br />
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br />
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll<br />
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll<br />
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe<br />
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll<br />
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} (Java Plug-in 1.6.0_13) -<br />
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - <a rel="nofollow" class="t" href="http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll" target="_blank">http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll</a><br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\570\G2AWinLogon.dll<br />
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe<br />
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: CarboniteService - Carbonite, Inc. (<a rel="nofollow" class="t" href="http://www.carbonite.com" target="_blank">www.carbonite.com</a>) - C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe<br />
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe<br />
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe<br />
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\570\g2aservice.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe<br />
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
<br />
--<br />
End of file - 11271 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>ep2002</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread236420.html</guid>
		</item>
		<item>
			<title>Windows Vista and A Virus?</title>
			<link>http://www.daniweb.com/forums/thread236110.html</link>
			<pubDate>Thu, 05 Nov 2009 02:00:42 GMT</pubDate>
			<description>I am running Windows Vista home edition.  Recently I think a virus or something has ruined my computer.  I can no longer download any program from the web and many of the programs that reside on my hard drive will not function.  I am led to believe their is a registry problem.  Microsofts...</description>
			<content:encoded><![CDATA[<div>I am running Windows Vista home edition.  Recently I think a virus or something has ruined my computer.  I can no longer download any program from the web and many of the programs that reside on my hard drive will not function.  I am led to believe their is a registry problem.  Microsofts suggestions of doing restores just made the entire situation worse.  Any help appreciated.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>khwhitaker</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread236110.html</guid>
		</item>
		<item>
			<title>Taskbar changes color and internet disconnect</title>
			<link>http://www.daniweb.com/forums/thread236104.html</link>
			<pubDate>Thu, 05 Nov 2009 01:23:20 GMT</pubDate>
			<description><![CDATA[Hi to everyone I'm new here!!!! Initially my problem  started with no sound after reboot & internet disconnection after few minutes of reboot. Now since I turn windows audio service to automatic, sound related issue seems to be gone. I tried everything that I know from google searching like...]]></description>
			<content:encoded><![CDATA[<div>Hi to everyone I'm new here!!!! Initially my problem  started with no sound after reboot &amp; internet disconnection after few minutes of reboot. Now since I turn windows audio service to automatic, sound related issue seems to be gone. I tried everything that I know from google searching like scanning with Malwarebyte's Ant-Malware, Trend-mico's HouseCall, Combofix etc. but the issue of taskbar color change due to which I loose my internet connection still exist:angry:<br />
<br />
Here are all log reports: <br />
<br />
<span style="font-weight:bold">Logfile of Trend Micro HijackThis v2.0.2</span><br />
Scan saved at 3:44:30 AM, on 11/5/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe<br />
C:\WINDOWS\system32\RUNDLL32.EXE<br />
C:\Program Files\Alwil Software\Avast4\ashDisp.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
D:\My IMP. Program files\Capture\Capture.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe<br />
C:\Program Files\Intel\IDU\awServ.exe<br />
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe<br />
C:\WINDOWS\system32\fsproflt.exe<br />
E:\Program Files\UGS\Imageware Licensing\12.00.000\bin\lmgrd.exe<br />
E:\Program Files\UGS\Imageware Licensing\12.00.000\bin\iwlmd.exe<br />
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://search.conduit.com?SearchSource=10&amp;ctid=CT1978305" target="_blank">http://search.conduit.com?SearchSour...ctid=CT1978305</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
O2 - BHO: (no name) - AutorunsDisabled - (no file)<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll<br />
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GrooveShellExtensions.dll<br />
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll<br />
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll<br />
O4 - HKLM\..\Run: [DiskeeperSystray] &quot;C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe&quot;<br />
O4 - HKLM\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe<br />
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [avast!] &quot;C:\Program Files\Alwil Software\Avast4\ashDisp.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKCU\..\Run: [NVIDIA nTune] &quot;C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe&quot; clear<br />
O4 - HKCU\..\Run: [Capture .NET] &quot;D:\My IMP. Program files\Capture\Capture.exe&quot;<br />
O4 - Startup: AutorunsDisabled<br />
O4 - Global Startup: AutorunsDisabled<br />
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present<br />
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present<br />
O8 - Extra context menu item: Add to Google Photos Screensa&amp;ver - res://C:\WINDOWS\system32\GPhotos.scr/200<br />
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - AutorunsDisabled - (no file)<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O16 - DPF: {2EDF75C0-5ABD-49f9-BAB6-220476A32034} (System Requirements Lab) - <a rel="nofollow" class="t" href="http://intel-drv-cdn.systemrequirementslab.com/multi/bin/sysreqlab_srlx.cab" target="_blank">http://intel-drv-cdn.systemrequireme...eqlab_srlx.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a rel="nofollow" class="t" href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1249759713703" target="_blank">http://update.microsoft.com/microsof...?1249759713703</a><br />
O17 - HKLM\System\CCS\Services\Tcpip\..\{EB49111A-80B5-405E-9E80-12F82DCD5FA6}: NameServer = 203.192.198.7,203.192.198.5<br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GrooveSystemServices.dll<br />
O20 - AppInit_DLLs: C:\WINDOWS\system32\acaptuser32.dll<br />
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe<br />
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
O23 - Service: Admin Works Agent X8 (AWService) - OSA Technologies Inc., An Avocent Company - C:\Program Files\Intel\IDU\awServ.exe<br />
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: FSPro Filter Service (fsproflt) - FSPro Labs - C:\WINDOWS\system32\fsproflt.exe<br />
O23 - Service: Imageware 12 License Manager - GLOBEtrotter Software Inc. - E:\Program Files\UGS\Imageware Licensing\12.00.000\bin\lmgrd.exe<br />
O23 - Service: InstallShield Licensing Service - Macrovision                                                     - C:\Program Files\Common Files\InstallShield Shared\Service\InstallShield Licensing Service.exe<br />
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - E:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe<br />
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe<br />
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe<br />
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe<br />
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe<br />
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
O23 - Service: ZL - Unknown owner - C:\DOCUME~1\NAVNATH\LOCALS~1\Temp\ZL.exe (file missing)<br />
<br />
--<br />
End of file - 8835 bytes<br />
<br />
<br />
<br />
<br />
<span style="font-weight:bold">ComboFix 09-11-04.02</span> - NAVNATH 11/05/2009  0:13.1.2 - NTFSx86<br />
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.2038.1543 [GMT 5.5:30]<br />
Running from: c:\documents and settings\NAVNATH\Desktop\ComboFix.exe<br />
AV: avast! antivirus 4.8.1356 [VPS 091103-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}<br />
.<br />
<br />
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br />
<br />
C:\Documents<br />
C:\Recycle<br />
c:\recycler\S-1-5-21-0306782404-0403296150-468932291-1673<br />
c:\recycler\S-1-5-21-1690392628-9639070320-204829838-7964<br />
c:\recycler\S-1-5-21-4340829974-8025113630-805332040-7178<br />
c:\recycler\S-1-5-21-4404245323-2510926375-959924715-4889<br />
c:\recycler\S-1-5-21-4526544003-9131078385-546885970-0446<br />
c:\recycler\S-1-5-21-4642916222-7686821538-614090642-3753<br />
c:\recycler\S-1-5-21-5504431452-5768450549-560062291-7959<br />
c:\recycler\S-1-5-21-7762691254-4116871461-074637373-8948<br />
c:\recycler\S-1-5-21-7804478225-5844174979-977742103-8620<br />
c:\recycler\S-1-5-21-7872991201-0422058234-947134708-6514<br />
c:\recycler\S-1-5-21-796845957-1614895754-682003330-500<br />
c:\recycler\S-1-5-21-8752049922-5241934417-628490504-9581<br />
c:\windows\system32\28463<br />
c:\windows\system32\tmp1.tmp<br />
c:\windows\system32\tmp2.tmp<br />
c:\windows\system32\tmp3.tmp<br />
c:\windows\system32\tmp61.tmp<br />
c:\windows\system32\tmp62.tmp<br />
<br />
.<br />
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br />
<br />
-------\Legacy_OREANS32<br />
-------\Service_oreans32<br />
<br />
<br />
(((((((((((((((((((((((((   Files Created from 2009-10-04 to 2009-11-04  )))))))))))))))))))))))))))))))<br />
.<br />
<br />
2009-11-04 14:40 . 2009-11-04 14:40	--------	d-----w-	c:\documents and settings\NAVNATH\Application Data\Malwarebytes<br />
2009-11-04 14:40 . 2009-09-10 09:24	38224	----a-w-	c:\windows\system32\drivers\mbamswissarmy.sys<br />
2009-11-04 14:39 . 2009-11-04 14:39	--------	d-----w-	c:\documents and settings\All Users\Application Data\Malwarebytes<br />
2009-11-04 14:39 . 2009-09-10 09:23	19160	----a-w-	c:\windows\system32\drivers\mbam.sys<br />
2009-11-02 20:43 . 2009-11-02 20:43	--------	d-----w-	c:\windows\system32\wbem\Repository<br />
2009-11-02 13:16 . 2009-11-02 13:16	319488	----a-w-	c:\windows\HideWin.exe<br />
2009-11-01 13:56 . 2009-11-01 14:05	--------	d-----w-	c:\program files\SystemRequirementsLab<br />
2009-10-31 19:19 . 2009-10-31 19:45	--------	d-----w-	c:\documents and settings\NAVNATH\Application Data\GetRightToGo<br />
2009-10-30 00:17 . 2009-10-30 00:11	93360	----a-w-	c:\windows\system32\drivers\SBREDrv.sys<br />
2009-10-30 00:17 . 2009-10-30 00:17	151392	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\DownloadGuardBHO.dll<br />
2009-10-30 00:17 . 2009-10-30 00:17	428936	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\DownloadGuard.exe<br />
2009-10-30 00:17 . 2009-10-30 00:17	862040	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe<br />
2009-10-30 00:17 . 2009-10-30 00:17	554280	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\sbap.dll<br />
2009-10-30 00:17 . 2009-10-30 00:17	15880	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe<br />
2009-10-30 00:17 . 2009-10-30 00:17	206944	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll<br />
2009-10-30 00:17 . 2009-10-30 00:17	390288	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll<br />
2009-10-30 00:17 . 2009-10-30 00:17	537576	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\aawapi.dll<br />
2009-10-30 00:17 . 2009-10-30 00:17	212480	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\VipreBridge.dll<br />
2009-10-30 00:16 . 2009-10-30 00:17	283944	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Vipre.dll<br />
2009-10-30 00:16 . 2009-10-30 00:16	370744	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll<br />
2009-10-30 00:16 . 2009-10-30 00:16	163728	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll<br />
2009-10-30 00:16 . 2009-10-30 00:16	194104	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Savapibridge.dll<br />
2009-10-30 00:16 . 2009-10-30 00:16	1223976	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBTE.dll<br />
2009-10-30 00:16 . 2009-10-30 00:16	242984	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBRE.dll<br />
2009-10-30 00:13 . 2009-10-30 00:14	5908024	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll<br />
2009-10-30 00:13 . 2009-10-30 00:13	327000	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll<br />
2009-10-30 00:13 . 2009-10-30 00:13	87496	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll<br />
2009-10-30 00:13 . 2009-10-30 00:13	933120	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll<br />
2009-10-30 00:13 . 2009-10-30 00:13	640608	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AutoLaunch.exe<br />
2009-10-30 00:11 . 2009-10-30 00:11	815760	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe<br />
2009-10-30 00:11 . 2009-10-30 00:11	822904	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe<br />
2009-10-30 00:11 . 2009-10-30 00:11	1638104	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe<br />
2009-10-30 00:11 . 2009-10-30 00:11	788368	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe<br />
2009-10-30 00:11 . 2009-10-30 00:11	1179232	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe<br />
2009-10-30 00:11 . 2009-10-30 00:11	93360	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\SBREDrv.sys<br />
2009-10-30 00:08 . 2009-10-03 08:15	2924848	-c--a-w-	c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe<br />
2009-10-27 08:52 . 2009-10-27 08:52	--------	d-----w-	c:\documents and settings\NAVNATH\Application Data\OpenWith.org Cache<br />
2009-10-25 22:43 . 2009-10-30 00:08	--------	dc-h--w-	c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}<br />
2009-10-15 10:20 . 2009-10-15 10:20	--------	d-----w-	c:\documents and settings\NAVNATH\Local Settings\Application Data\Activision<br />
2009-10-15 10:16 . 2009-10-21 16:12	138464	----a-w-	c:\windows\system32\drivers\PnkBstrK.sys<br />
2009-10-15 10:16 . 2009-10-15 10:16	22328	----a-w-	c:\documents and settings\NAVNATH\Application Data\PnkBstrK.sys<br />
2009-10-15 10:16 . 2009-10-21 16:12	111928	----a-w-	c:\windows\system32\PnkBstrB.exe<br />
2009-10-15 10:16 . 2009-11-03 07:43	66872	----a-w-	c:\windows\system32\PnkBstrA.exe<br />
2009-10-15 10:16 . 2009-10-15 10:16	682280	----a-w-	c:\windows\system32\pbsvc.exe<br />
<br />
.<br />
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br />
2009-11-04 18:48 . 2008-12-12 08:51	664	----a-w-	c:\windows\system32\d3d9caps.dat<br />
2009-11-01 18:23 . 2008-07-10 17:03	--------	d-----w-	c:\program files\Intel<br />
2009-11-01 11:22 . 2009-09-19 19:17	--------	d-----w-	c:\documents and settings\NAVNATH\Application Data\Azureus<br />
2009-10-31 19:54 . 2008-07-10 17:11	--------	d--h--w-	c:\program files\InstallShield Installation Information<br />
2009-10-31 19:53 . 2009-08-11 18:55	--------	d-----w-	c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters<br />
2009-10-31 18:34 . 2009-09-19 19:16	--------	d-----w-	c:\program files\Vuze<br />
2009-10-30 00:17 . 2009-02-08 09:47	15880	----a-w-	c:\windows\system32\lsdelete.exe<br />
2009-10-30 00:08 . 2009-02-06 18:01	--------	d-----w-	c:\documents and settings\All Users\Application Data\Lavasoft<br />
2009-10-21 16:59 . 2009-09-10 00:31	--------	d-----w-	c:\documents and settings\All Users\Application Data\Autorun Eater<br />
2009-10-02 10:14 . 2009-10-02 10:14	--------	d-----w-	c:\documents and settings\All Users\Application Data\PC Suite<br />
2009-10-02 10:14 . 2009-10-02 10:14	--------	d-----w-	c:\documents and settings\NAVNATH\Application Data\PC Suite<br />
2009-10-02 10:09 . 2009-10-02 10:09	--------	d-----w-	c:\program files\Samsung<br />
2009-10-02 10:08 . 2009-10-02 10:08	--------	d-----w-	c:\program files\PC Connectivity Solution<br />
2009-10-02 10:08 . 2009-10-02 10:08	--------	d-----w-	c:\program files\DIFX<br />
2009-10-02 10:08 . 2009-10-02 10:08	--------	d-----w-	c:\documents and settings\NAVNATH\Application Data\Samsung<br />
2009-10-02 10:08 . 2009-10-02 10:08	--------	d-----w-	c:\program files\MarkAny<br />
2009-09-24 06:25 . 2009-09-24 06:25	184320	----a-w-	c:\windows\system32\Ncs2Setp.dll<br />
2009-09-24 06:13 . 2009-09-24 06:13	768632	----a-w-	c:\windows\system32\ncs2dmix.dll<br />
2009-09-24 06:12 . 2009-09-24 06:12	539256	----a-w-	c:\windows\system32\accesor.dll<br />
2009-09-24 05:50 . 2009-09-24 05:50	141944	----a-w-	c:\windows\system32\ncs2instutility.dll<br />
2009-09-24 05:39 . 2009-09-24 05:39	1677944	----a-w-	c:\windows\system32\ncscolib.dll<br />
2009-09-23 12:55 . 2009-02-08 08:49	64288	----a-w-	c:\windows\system32\drivers\Lbd.sys<br />
2009-09-21 08:50 . 2009-09-21 08:50	28632	----a-w-	c:\windows\system32\drivers\iqvw32.sys<br />
2009-09-19 19:17 . 2009-09-19 19:17	--------	d-----w-	c:\documents and settings\All Users\Application Data\Azureus<br />
2009-09-19 19:16 . 2009-09-19 19:16	--------	d-----w-	c:\program files\Common Files\i4j_jres<br />
2009-09-19 18:38 . 2009-08-27 18:32	--------	d-----w-	c:\documents and settings\NAVNATH\Application Data\uTorrent<br />
2009-09-15 10:59 . 2009-08-03 10:29	1279968	----a-w-	c:\windows\system32\aswBoot.exe<br />
2009-09-15 10:56 . 2009-08-03 10:29	93424	----a-w-	c:\windows\system32\drivers\aswmon.sys<br />
2009-09-15 10:56 . 2009-08-03 10:29	94160	----a-w-	c:\windows\system32\drivers\aswmon2.sys<br />
2009-09-15 10:55 . 2009-08-03 10:29	114768	----a-w-	c:\windows\system32\drivers\aswSP.sys<br />
2009-09-15 10:55 . 2009-08-03 10:29	20560	----a-w-	c:\windows\system32\drivers\aswFsBlk.sys<br />
2009-09-15 10:54 . 2009-08-03 10:29	52368	----a-w-	c:\windows\system32\drivers\aswTdi.sys<br />
2009-09-15 10:54 . 2009-08-03 10:29	23152	----a-w-	c:\windows\system32\drivers\aswRdr.sys<br />
2009-09-15 10:53 . 2009-08-03 10:29	27408	----a-w-	c:\windows\system32\drivers\aavmker4.sys<br />
2009-09-15 10:53 . 2009-08-03 10:29	97480	----a-w-	c:\windows\system32\AvastSS.scr<br />
2009-09-10 01:15 . 2009-09-10 01:15	--------	d-----w-	c:\documents and settings\NAVNATH\Application Data\Thinstall<br />
2009-09-10 00:31 . 2009-09-10 00:31	--------	d-----w-	c:\program files\Autorun Eater<br />
2009-09-09 00:16 . 2009-09-09 00:16	--------	d-----w-	c:\program files\Common Files\xing shared<br />
2009-09-09 00:16 . 2009-09-09 00:15	--------	d-----w-	c:\program files\Common Files\Real<br />
2009-09-09 00:15 . 2006-07-11 13:05	348160	----a-w-	c:\windows\system32\msvcr71.dll<br />
2009-09-09 00:15 . 2009-09-09 00:15	--------	d-----w-	c:\program files\Real<br />
2009-09-06 20:39 . 2009-09-06 20:34	--------	d-----w-	c:\documents and settings\All Users\Application Data\Yahoo! Companion<br />
2009-09-06 20:37 . 2009-09-06 20:31	--------	d-----w-	c:\documents and settings\All Users\Application Data\Yahoo!<br />
2009-09-06 20:34 . 2009-09-06 20:31	--------	d-----w-	c:\program files\Yahoo!<br />
2009-09-06 20:34 . 2009-09-06 20:34	--------	d-----w-	c:\documents and settings\NAVNATH\Application Data\Yahoo!<br />
2009-09-06 04:33 . 2009-06-01 18:29	--------	d-----w-	c:\program files\Google<br />
2009-08-18 11:46 . 2008-07-14 16:13	831488	----a-w-	c:\windows\RtlExUpd.dll<br />
2009-08-14 11:14 . 2009-08-14 11:14	6379936	----a-w-	c:\windows\screensaver_radiance.exe<br />
2009-08-14 11:14 . 2009-08-14 11:14	28672	----a-w-	c:\windows\gscr.dll<br />
2009-08-14 11:14 . 2009-08-14 11:14	127904	----a-w-	c:\windows\screensaver_radiance.scr<br />
2009-08-13 14:13 . 2009-08-11 18:57	54	----a-w-	c:\windows\system32\rp_stats.dat<br />
2009-08-13 14:13 . 2009-08-11 18:57	39	----a-w-	c:\windows\system32\rp_rules.dat<br />
2009-08-08 19:50 . 2009-08-08 19:50	3317272	----a-w-	c:\documents and settings\All Users\Application Data\SpeedBit\DAP\Offers\VA3_DapSo.exe<br />
2009-08-08 19:46 . 2009-08-08 19:46	50688	----a-w-	c:\windows\system32\wbhelp2.dll<br />
2008-07-10 18:08 . 2008-07-10 18:08	23	--sha-w-	c:\windows\system32\adbfbea2_d.dll<br />
.<br />
<br />
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br />
.<br />
*Note* empty entries &amp; legit default entries are not shown <br />
REGEDIT4<br />
<br />
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />
&quot;NVIDIA nTune&quot;=&quot;c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe&quot; [2007-07-03 81920]<br />
&quot;Capture .NET&quot;=&quot;d:\my imp. program files\Capture\Capture.exe&quot; [2009-03-24 790528]<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />
&quot;DiskeeperSystray&quot;=&quot;c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe&quot; [2006-06-07 319488]<br />
&quot;TaskSwitchXP&quot;=&quot;c:\program files\TaskSwitchXP\TaskSwitchXP.exe&quot; [2007-05-09 106904]<br />
&quot;NvCplDaemon&quot;=&quot;c:\windows\system32\NvCpl.dll&quot; [2009-02-18 13680640]<br />
&quot;NvMediaCenter&quot;=&quot;c:\windows\system32\NvMcTray.dll&quot; [2009-02-18 86016]<br />
&quot;avast!&quot;=&quot;c:\program files\Alwil Software\Avast4\ashDisp.exe&quot; [2009-09-15 81000]<br />
&quot;QuickTime Task&quot;=&quot;c:\program files\QuickTime\qttask.exe&quot; [2008-09-06 413696]<br />
&quot;AlcWzrd&quot;=&quot;ALCWZRD.EXE&quot; - c:\windows\ALCWZRD.EXE [2008-06-19 2808832]<br />
&quot;nwiz&quot;=&quot;nwiz.exe&quot; - c:\windows\system32\nwiz.exe [2009-02-18 1657376]<br />
<br />
c:\documents and settings\NAVNATH\Start Menu\Programs\Startup\AutorunsDisabled<br />
SolidWorks Task Scheduler Engine.lnk - c:\program files\SolidWorks\swScheduler\swBOEngine.exe [2007-9-9 488728]<br />
<br />
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]<br />
&quot;NoResolveTrack&quot;= 1 (0x1)<br />
&quot;NoFileAssociate&quot;= 0 (0x0)<br />
<br />
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]<br />
&quot;NoRecentDocsNetHood&quot;= 01000000<br />
&quot;NoStrCmpLogical&quot;= 01000000<br />
&quot;NoSMMyPictures&quot;= 01000000<br />
<br />
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]<br />
&quot;AppInit_DLLs&quot;=c:\windows\system32\acaptuser32.dll<br />
<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]<br />
@=&quot;Service&quot;<br />
<br />
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Application Data^Microsoft^Shortcuts^icwsetup.exe]<br />
path=c:\documents and settings\All Users\Application Data\Microsoft\Shortcuts\icwsetup.exe<br />
backup=c:\windows\pss\icwsetup.exeCommon Startup<br />
<br />
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]<br />
&quot;PLFlash DeviceIoControl Service&quot;=2 (0x2)<br />
&quot;wuauserv&quot;=2 (0x2)<br />
&quot;gusvc&quot;=3 (0x3)<br />
<br />
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]<br />
&quot;EnableFirewall&quot;= 0 (0x0)<br />
&quot;DisableNotifications&quot;= 1 (0x1)<br />
<br />
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br />
&quot;%windir%\\system32\\sessmgr.exe&quot;=<br />
&quot;c:\\Program Files\\Autodesk\\3dsMax8\\3dsmax.exe&quot;=<br />
&quot;c:\\Program Files\\Autodesk\\backburner\\monitor.exe&quot;=<br />
&quot;c:\\Program Files\\Autodesk\\backburner\\manager.exe&quot;=<br />
&quot;c:\\Program Files\\Autodesk\\backburner\\server.exe&quot;=<br />
&quot;c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE&quot;=<br />
&quot;c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE&quot;=<br />
&quot;c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE&quot;=<br />
&quot;e:\\Program Files\\uTorrent\\uTorrent.exe&quot;=<br />
&quot;c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe&quot;=<br />
&quot;c:\\Program Files\\Vuze\\Azureus.exe&quot;=<br />
&quot;e:\\Program Files\\Samsung\\Samsung New PC Studio\\npsasvr.exe&quot;=<br />
&quot;e:\\Program Files\\Samsung\\Samsung New PC Studio\\npsvsvr.exe&quot;=<br />
<br />
R0 FSProFilter;FSPro File Filter;c:\windows\system32\drivers\FSPFltd.sys [3/19/2009 5:52 PM 43792]<br />
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2/8/2009 2:19 PM 64288]<br />
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [8/3/2009 3:59 PM 114768]<br />
R1 LUMDriver;LUMDriver;c:\windows\system32\drivers\LUMDriver.sys [4/24/2007 10:22 PM 16688]<br />
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [8/3/2009 3:59 PM 20560]<br />
R2 fsproflt;FSPro Filter Service;c:\windows\system32\fsproflt.exe [3/19/2009 5:52 PM 73392]<br />
R2 Imageware 12 License Manager;Imageware 12 License Manager;e:\program files\UGS\Imageware Licensing\12.00.000\bin\lmgrd.exe [9/25/2002 2:40 AM 597504]<br />
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;e:\program files\Lavasoft\Ad-Aware\AAWService.exe [9/24/2009 4:47 PM 1179232]<br />
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [10/2/2009 3:38 PM 36608]<br />
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [11/7/2007 1:52 AM 34064]<br />
S3 ZL;ZL;c:\docume~1\NAVNATH\LOCALS~1\Temp\ZL.exe --&gt; c:\docume~1\NAVNATH\LOCALS~1\Temp\ZL.exe [?]<br />
S4 BBDemon;Backbone Service;&quot;e:\program files\Dassault Systemes\B17\intel_a\code\bin\CATSysDemon.exe&quot; -service --&gt; e:\program files\Dassault Systemes\B17\intel_a\code\bin\CATSysDemon.exe [?]<br />
S4 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [10/2/2009 3:38 PM 233472]<br />
S4 gupdate1ca20fd77090518;Google Update Service (gupdate1ca20fd77090518);c:\program files\Google\Update\GoogleUpdate.exe [8/20/2009 12:17 AM 133104]<br />
<br />
--- Other Services/Drivers In Memory ---<br />
<br />
*NewlyCreated* - MBR<br />
*Deregistered* - mbr<br />
.<br />
Contents of the 'Scheduled Tasks' folder<br />
<br />
2009-08-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job<br />
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-19 18:47]<br />
<br />
2009-08-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job<br />
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-19 18:47]<br />
<br />
2009-08-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-796845957-1614895754-682003330-1003Core.job<br />
- c:\documents and settings\NAVNATH\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-08 18:56]<br />
<br />
2009-08-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-796845957-1614895754-682003330-1003UA.job<br />
- c:\documents and settings\NAVNATH\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-08 18:56]<br />
.<br />
.<br />
------- Supplementary Scan -------<br />
.<br />
uStart Page = hxxp://search.conduit.com?SearchSource=10&amp;ctid=CT1978305<br />
uDefault_Search_URL = hxxp://www.google.com/ie<br />
uInternet Connection Wizard,ShellNext = iexplore<br />
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s<br />
IE: &amp;Clean Traces<br />
IE: &amp;Download with &amp;DAP<br />
IE: Add to Google Photos Screensa&amp;ver - c:\windows\system32\GPhotos.scr/200<br />
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
IE: Download &amp;all with DAP<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
TCP: {EB49111A-80B5-405E-9E80-12F82DCD5FA6} = 203.192.198.7,203.192.198.5<br />
DPF: {2EDF75C0-5ABD-49f9-BAB6-220476A32034} - hxxp://intel-drv-cdn.systemrequirementslab.com/multi/bin/sysreqlab_srlx.cab<br />
.<br />
- - - - ORPHANS REMOVED - - - -<br />
<br />
HKLM-Run-Internet Connection Wizard Setup Tool - c:\program files\Internet Explorer\Connection Wizard\icwsetup.exe<br />
HKLM-Run-NPSStartup - (no file)<br />
Notify-WgaLogon - (no file)<br />
AddRemove-{B52F8C4B-FE88-4B59-9B80-1C93669D7DEB}_is1 - c:\program files\OpenWith.org<br />
<br />
<br />
<br />
**************************************************************************<br />
<br />
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, <a rel="nofollow" class="t" href="http://www.gmer.net" target="_blank">http://www.gmer.net</a><br />
Rootkit scan 2009-11-05 00:18<br />
Windows 5.1.2600 Service Pack 2 NTFS<br />
<br />
scanning hidden processes ...  <br />
<br />
scanning hidden autostart entries ... <br />
<br />
scanning hidden files ...  <br />
<br />
scan completed successfully<br />
hidden files: 0<br />
<br />
**************************************************************************<br />
<br />
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, <a rel="nofollow" class="t" href="http://www.gmer.net" target="_blank">http://www.gmer.net</a><br />
<br />
device: opened successfully<br />
user: MBR read successfully<br />
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll &gt;&gt;UNKNOWN [0x89E3F1E8]&lt;&lt; <br />
kernel: MBR read successfully<br />
detected MBR rootkit hooks:<br />
\Driver\atapi -&gt; 0x89e3f1e8<br />
Warning: possible MBR rootkit infection !<br />
user &amp; kernel MBR OK <br />
Use &quot;Recovery Console&quot; command &quot;fixmbr&quot; to clear infection !<br />
<br />
**************************************************************************<br />
.<br />
--------------------- DLLs Loaded Under Running Processes ---------------------<br />
<br />
- - - - - - - &gt; 'explorer.exe'(3476)<br />
c:\windows\system32\nview.dll<br />
c:\windows\system32\PortableDeviceApi.dll<br />
c:\windows\system32\Audiodev.dll<br />
c:\windows\system32\WMVCore.DLL<br />
c:\windows\system32\WMASF.DLL<br />
c:\windows\system32\WPDShServiceObj.dll<br />
c:\windows\system32\PortableDeviceTypes.dll<br />
.<br />
------------------------ Other Running Processes ------------------------<br />
.<br />
c:\program files\Alwil Software\Avast4\aswUpdSv.exe<br />
c:\program files\Alwil Software\Avast4\ashServ.exe<br />
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe<br />
c:\program files\Intel\IDU\awServ.exe<br />
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe<br />
c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe<br />
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe<br />
c:\windows\system32\locator.exe<br />
c:\program files\Alwil Software\Avast4\ashMaiSv.exe<br />
c:\windows\system32\wbem\unsecapp.exe<br />
c:\program files\Alwil Software\Avast4\ashWebSv.exe<br />
c:\windows\system32\wscntfy.exe<br />
c:\windows\system32\RUNDLL32.EXE<br />
c:\windows\system32\rundll32.exe<br />
e:\program files\Lavasoft\Ad-Aware\AAWTray.exe<br />
.<br />
**************************************************************************<br />
.<br />
Completion time: 2009-11-04  0:20 - machine was rebooted<br />
ComboFix-quarantined-files.txt  2009-11-04 18:50<br />
<br />
Pre-Run: 17,365,811,200 bytes free<br />
Post-Run: 17,272,356,864 bytes free<br />
<br />
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe<br />
[boot loader]<br />
timeout=2<br />
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS<br />
[operating systems]<br />
c:\cmdcons\BOOTSECT.DAT=&quot;Microsoft Windows Recovery Console&quot; /cmdcons<br />
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS=&quot;Microsoft Windows XP Professional&quot; /noexecute=optin /fastdetect<br />
<br />
<br />
<br />
<br />
<span style="font-weight:bold">Malwarebytes' Anti-Malware 1.41</span><br />
Database version: 3099<br />
Windows 5.1.2600 Service Pack 2<br />
<br />
11/4/2009 8:59:07 PM<br />
mbam-log-2009-11-04 (20-59-07).txt<br />
<br />
Scan type: Full Scan (C:\|D:\|E:\|F:\|)<br />
Objects scanned: 333445<br />
Time elapsed: 44 minute(s), 9 second(s)<br />
<br />
Memory Processes Infected: 0<br />
Memory Modules Infected: 0<br />
Registry Keys Infected: 2<br />
Registry Values Infected: 0<br />
Registry Data Items Infected: 3<br />
Folders Infected: 1<br />
Files Infected: 7<br />
<br />
Memory Processes Infected:<br />
(No malicious items detected)<br />
<br />
Memory Modules Infected:<br />
(No malicious items detected)<br />
<br />
Registry Keys Infected:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28abc5c0-4fcb-11cf-aax5-21cx1c987224} (Generic.Bot.H) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DbgMgr (Malware.Trace) -&gt; Quarantined and deleted successfully.<br />
<br />
Registry Values Infected:<br />
(No malicious items detected)<br />
<br />
Registry Data Items Infected:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -&gt; Bad: (1) Good: (0) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -&gt; Bad: (1) Good: (0) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -&gt; Bad: (1) Good: (0) -&gt; Quarantined and deleted successfully.<br />
<br />
Folders Infected:<br />
C:\Recycle\P-1-3-64-8794238531-8742492-9897532 (Trojan.Agent) -&gt; Quarantined and deleted successfully.<br />
<br />
Files Infected:<br />
C:\Documents and Settings\NAVNATH\restorer64_a.exe (SpamTool.Agent) -&gt; Quarantined and deleted successfully.<br />
C:\System Volume Information\_restore{D480C6E8-D1B9-432F-BEE0-48857CFACC20}\RP448\A0145821.exe (SpamTool.Agent) -&gt; Quarantined and deleted successfully.<br />
C:\WINDOWS\system32\restorer64_a.exe (SpamTool.Agent) -&gt; Quarantined and deleted successfully.<br />
F:\System Volume Information\_restore{D480C6E8-D1B9-432F-BEE0-48857CFACC20}\RP442\A0143716.exe (Trojan.Downloader) -&gt; Quarantined and deleted successfully.<br />
C:\Recycle\P-1-3-64-8794238531-8742492-9897532\Desktop.ini (Trojan.Agent) -&gt; Quarantined and deleted successfully.<br />
C:\Documents and Settings\NAVNATH\Start Menu\Programs\Startup\zavupd32.exe (Trojan.Agent) -&gt; Quarantined and deleted successfully.<br />
C:\Documents and Settings\NAVNATH\Application Data\wiaserva.log (Malware.Trace) -&gt; Quarantined and deleted successfully.<br />
<br />
<br />
Hope expert here take some time to analyze these logs.<br />
<br />
Thank you.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>navnath.j84</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread236104.html</guid>
		</item>
		<item>
			<title>Firefox tabs keep popping up</title>
			<link>http://www.daniweb.com/forums/thread235859.html</link>
			<pubDate>Wed, 04 Nov 2009 05:27:59 GMT</pubDate>
			<description>Everytime I open my firefox browser additional tabs keep popping up.  Not just one or two, but 20.  when I try to close the tabs more keep popping up.  I have to close the entire browser in order to stop it.  Each tab is directed to the firefox help and support site.   
 
I also have the same...</description>
			<content:encoded><![CDATA[<div>Everytime I open my firefox browser additional tabs keep popping up.  Not just one or two, but 20.  when I try to close the tabs more keep popping up.  I have to close the entire browser in order to stop it.  Each tab is directed to the firefox help and support site.  <br />
<br />
I also have the same issues with internet explorer.  Everytime I open a browser, Windows Help and Support window keeps popping up. When I close the window it just keeps popping up.  When I use the task manager to close the process, it gives me an additional 10 seconds before the window pops up.  <br />
<br />
I thoroughly checked the F1 key...it's not stuck.  I don't know what to do...Please Help!!!  I have included the hijackthis log, Kapersky's online scan, malwarebytes log, and the unistall log.   The Dekard's system scanner seems to be down so I cannot provide that log.<br />
<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 2:14:15 PM, on 10/24/2009<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18828)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\System32\igfxtray.exe<br />
C:\Windows\System32\hkcmd.exe<br />
C:\Windows\System32\igfxpers.exe<br />
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe<br />
C:\Windows\system32\igfxsrvc.exe<br />
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe<br />
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe<br />
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\TOSHIBA\TECO\TEco.exe<br />
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe<br />
C:\Windows\System32\wpcumi.exe<br />
C:\Program Files\AVG\AVG8\avgtray.exe<br />
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe<br />
C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe<br />
C:\Program Files\IObit\IObit Security 360\is360tray.exe<br />
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Windows\system32\igfxext.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe<br />
C:\Windows\helppane.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Windows\system32\SearchProtocolHost.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = <a rel="nofollow" class="t" href="http://search.yahoo.com/search?fr=mcafee&amp;p=%s" target="_blank">http://search.yahoo.com/search?fr=mcafee&amp;p=%s</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br />
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br />
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe<br />
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE<br />
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe<br />
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe<br />
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [TWebCamera] &quot;%ProgramFiles%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe&quot; autorun<br />
O4 - HKLM\..\Run: [SmartFaceVWatcher] %ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe<br />
O4 - HKLM\..\Run: [Teco] &quot;%ProgramFiles%\TOSHIBA\TECO\Teco.exe&quot; /r<br />
O4 - HKLM\..\Run: [NDSTray.exe] &quot;C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe&quot;<br />
O4 - HKLM\..\Run: [cfFncEnabler.exe] &quot;C:\Program Files\TOSHIBA\ConfigFree\cfFncEnabler.exe&quot;<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe<br />
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [TPCHWMsg] %ProgramFiles%\TOSHIBA\TPHM\TPCHWMsg.exe<br />
O4 - HKLM\..\Run: [ToshibaServiceStation] C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe /hide:60<br />
O4 - HKLM\..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe<br />
O4 - HKLM\..\Run: [IObit Security 360] C:\Program Files\IObit\IObit Security 360\IS360tray.exe<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL<br />
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe<br />
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - <a rel="nofollow" class="t" href="http://download.divx.com/player/DivXBrowserPlugin.cab" target="_blank">http://download.divx.com/player/DivXBrowserPlugin.cab</a><br />
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - <a rel="nofollow" class="t" href="http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab" target="_blank">http://upload.facebook.com/controls/...Uploader55.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a rel="nofollow" class="t" href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O20 - AppInit_DLLs: avgrsstx.dll<br />
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL<br />
O23 - Service: McAfee Application Installer Cleanup (0261041256269811) (0261041256269811mcinstcleanup) - McAfee, Inc. - C:\Windows\TEMP\026104~1.EXE<br />
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe<br />
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: TOSHIBA Web Camera Service (camsvc) - TOSHIBA - C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe<br />
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe<br />
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe<br />
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe<br />
O23 - Service: IS360service - IObit - C:\Program Files\IObit\IObit Security 360\IS360srv.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe<br />
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe<br />
O23 - Service: TOSHIBA Modem region select service (RSELSVC) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\RSelect\RSelSvc.exe<br />
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe<br />
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe<br />
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe<br />
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe<br />
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe<br />
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe<br />
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe<br />
<br />
--<br />
End of file - 10587 bytes<br />
<br />
<br />
<br />
<br />
KASPERSKY ONLINE SCANNER<br />
<br />
Tuesday, November 3, 2009<br />
Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 2 (build 6002)<br />
Kaspersky Online Scanner version: 7.0.26.13<br />
Last database update: Wednesday, November 04, 2009 02:06:14<br />
Records in database: 3123431<br />
 <br />
 <br />
Scan settings <br />
scan using the following database extended <br />
Scan archives yes <br />
Scan e-mail databases yes <br />
 <br />
Scan area My Computer <br />
C:\<br />
D:\  <br />
 <br />
Scan statistics <br />
Objects scanned 128961 <br />
Threats found 0 <br />
Infected objects found 0 <br />
Suspicious objects found 0 <br />
Scan duration 01:28:20 <br />
<br />
No threats found. Scanned area is clean. <br />
Selected area has been scanned. <br />
<br />
<br />
<br />
<br />
<br />
Malwarebytes' Anti-Malware 1.41<br />
Database version: 3097<br />
Windows 6.0.6002 Service Pack 2<br />
<br />
11/3/2009 8:21:06 PM<br />
mbam-log-2009-11-03 (20-21-06).txt<br />
<br />
Scan type: Full Scan (C:\|)<br />
Objects scanned: 251060<br />
Time elapsed: 42 minute(s), 29 second(s)<br />
<br />
Memory Processes Infected: 0<br />
Memory Modules Infected: 0<br />
Registry Keys Infected: 0<br />
Registry Values Infected: 0<br />
Registry Data Items Infected: 0<br />
Folders Infected: 0<br />
Files Infected: 0<br />
<br />
Memory Processes Infected:<br />
(No malicious items detected)<br />
<br />
Memory Modules Infected:<br />
(No malicious items detected)<br />
<br />
Registry Keys Infected:<br />
(No malicious items detected)<br />
<br />
Registry Values Infected:<br />
(No malicious items detected)<br />
<br />
Registry Data Items Infected:<br />
(No malicious items detected)<br />
<br />
Folders Infected:<br />
(No malicious items detected)<br />
<br />
Files Infected:<br />
(No malicious items detected)<br />
<br />
<br />
Uninstall Log<br />
<br />
2007 Microsoft Office Suite Service Pack 1 (SP1)<br />
2007 Microsoft Office Suite Service Pack 1 (SP1)<br />
2007 Microsoft Office Suite Service Pack 1 (SP1)<br />
2007 Microsoft Office Suite Service Pack 1 (SP1)<br />
2007 Microsoft Office Suite Service Pack 1 (SP1)<br />
2007 Microsoft Office Suite Service Pack 1 (SP1)<br />
2007 Microsoft Office Suite Service Pack 1 (SP1)<br />
2007 Microsoft Office Suite Service Pack 1 (SP1)<br />
2007 Microsoft Office Suite Service Pack 1 (SP1)<br />
2007 Microsoft Office Suite Service Pack 1 (SP1)<br />
Acrobat.com<br />
Adobe AIR<br />
Adobe AIR<br />
Adobe Flash Player 10 ActiveX<br />
Adobe Flash Player 10 Plugin<br />
Adobe Reader 9.1.3<br />
AnswerWorks 5.0 English Runtime<br />
CCleaner (remove only)<br />
Compatibility Pack for the 2007 Office system<br />
ConvertHelper 2.2<br />
Direct DiscRecorder<br />
DivX Web Player<br />
DVD MovieFactory for TOSHIBA<br />
EOS USB WIA Driver<br />
HijackThis 2.0.2<br />
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)<br />
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)<br />
Intel PROSet Wireless<br />
Intel(R) Graphics Media Accelerator Driver<br />
Intel® Matrix Storage Manager<br />
IObit Security 360<br />
Java(TM) 6 Update 11<br />
K-Lite Mega Codec Pack 5.0.5<br />
Malwarebytes' Anti-Malware<br />
McAfee SiteAdvisor<br />
Microsoft .NET Framework 3.5 SP1<br />
Microsoft .NET Framework 3.5 SP1<br />
Microsoft Office Excel MUI (English) 2007<br />
Microsoft Office Home and Student 2007<br />
Microsoft Office Home and Student 2007<br />
Microsoft Office OneNote MUI (English) 2007<br />
Microsoft Office PowerPoint MUI (English) 2007<br />
Microsoft Office PowerPoint Viewer 2007 (English)<br />
Microsoft Office Proof (English) 2007<br />
Microsoft Office Proof (French) 2007<br />
Microsoft Office Proof (Spanish) 2007<br />
Microsoft Office Proofing (English) 2007<br />
Microsoft Office Shared MUI (English) 2007<br />
Microsoft Office Shared Setup Metadata MUI (English) 2007<br />
Microsoft Office Suite Activation Assistant<br />
Microsoft Office Word MUI (English) 2007<br />
Microsoft Visual C++ 2005 Redistributable<br />
Microsoft Works<br />
Mozilla Firefox (3.5.3)<br />
MSXML 4.0 SP2 (KB941833)<br />
MSXML 4.0 SP2 (KB954430)<br />
PartyPoker<br />
Picasa 3<br />
PlayReady PC runtime<br />
Quicken 2010<br />
Realtek 8136 8168 8169 Ethernet Driver<br />
Realtek High Definition Audio Driver<br />
Realtek USB 2.0 Card Reader<br />
Skype Launcher<br />
SUPERAntiSpyware Free Edition<br />
Synaptics Pointing Device Driver<br />
TOSHIBA Agreement Notification Utility<br />
Toshiba Application and Driver Installer<br />
TOSHIBA Assist<br />
TOSHIBA ConfigFree<br />
TOSHIBA Disc Creator<br />
TOSHIBA DVD PLAYER<br />
TOSHIBA eco Utility<br />
TOSHIBA eco Utility<br />
TOSHIBA Extended Tiles for Windows Mobility Center<br />
TOSHIBA Face Recognition<br />
TOSHIBA Face Recognition<br />
TOSHIBA Hardware Setup<br />
TOSHIBA HDD/SSD Alert<br />
TOSHIBA HDD/SSD Alert<br />
TOSHIBA Internal Modem Region Select Utility<br />
TOSHIBA PC Health Monitor<br />
Toshiba Quality Application<br />
TOSHIBA Recovery Disc Creator<br />
Toshiba Registration<br />
Toshiba Resources Page<br />
TOSHIBA SD Memory Utilities<br />
TOSHIBA Service Station<br />
TOSHIBA Software Modem<br />
TOSHIBA Speech System Applications<br />
TOSHIBA Speech System SR Engine(U.S.) Version1.0<br />
TOSHIBA Speech System TTS Engine(U.S.) Version1.0<br />
TOSHIBA Supervisor Password<br />
TOSHIBA Value Added Package<br />
TOSHIBA Web Camera Application<br />
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)<br />
Update for Office 2007 (KB946691)<br />
VC80CRTRedist - 8.0.50727.762<br />
WildTangent Games<br />
<br />
<br />
<br />
<br />
I hope you can help....Thanks</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>jsbrewer</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread235859.html</guid>
		</item>
		<item>
			<title><![CDATA[Shopica redirect I can't get rid of!!]]></title>
			<link>http://www.daniweb.com/forums/thread235751.html</link>
			<pubDate>Tue, 03 Nov 2009 20:07:50 GMT</pubDate>
			<description>I have thrown everything at the search redirect (most commonly takes me to shopica.com) I have found some things running everything anti-virus/spyware/malware I can at it.  PLease help!!  My hijack this is pasted below.  Thanks! 
 
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 3:00:39 PM,...</description>
			<content:encoded><![CDATA[<div>I have thrown everything at the search redirect (most commonly takes me to shopica.com) I have found some things running everything anti-virus/spyware/malware I can at it.  PLease help!!  My hijack this is pasted below.  Thanks!<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 3:00:39 PM, on 11/3/2009<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18828)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\RtHDVCpl.exe<br />
C:\Program Files\Spare Backup\SpareBackup.exe<br />
C:\Windows\System32\igfxtray.exe<br />
C:\Windows\System32\igfxpers.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br />
C:\Program Files\Symantec AntiVirus\VPTray.exe<br />
C:\Windows\system32\igfxsrvc.exe<br />
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe<br />
C:\Program Files\Pure Networks\Network Magic\nmapp.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Alwil Software\Avast4\ashDisp.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Windows\system32\hkcmd.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Windows\system32\igfxsrvc.exe<br />
C:\PROGRA~1\NYKO\GAMEPA~1\ngpmap.exe<br />
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe<br />
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe<br />
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe<br />
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe<br />
C:\Windows\Explorer.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.yahoo.com/" target="_blank">http://www.yahoo.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.gateway.com/g/startpage.html?Ch=Retail&amp;SubCH=nofound&amp;Br=GTW&amp;Loc=ENG_US&amp;Sys=DTP&amp;M=GT5620" target="_blank">http://www.gateway.com/g/startpage.h...s=DTP&amp;M=GT5620</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll<br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll<br />
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll<br />
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br />
O4 - HKLM\..\Run: [Spare Backup] &quot;C:\Program Files\Spare Backup\SpareBackup.exe&quot; /silent<br />
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [Skytel] Skytel.exe<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [ccApp] &quot;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&quot;<br />
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe<br />
O4 - HKLM\..\Run: [nmctxth] &quot;C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe&quot;<br />
O4 - HKLM\..\Run: [nmapp] &quot;C:\Program Files\Pure Networks\Network Magic\nmapp.exe&quot; -autorun -nosplash<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe<br />
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE<br />
O8 - Extra context menu item: &amp;AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll<br />
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe<br />
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br />
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe<br />
O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe<br />
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe<br />
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe<br />
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe<br />
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe<br />
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe<br />
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe<br />
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
<br />
--<br />
End of file - 8680 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>jw22</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread235751.html</guid>
		</item>
		<item>
			<title><![CDATA["...not a valid win32 app..."  HiJack This Log]]></title>
			<link>http://www.daniweb.com/forums/thread235747.html</link>
			<pubDate>Tue, 03 Nov 2009 19:50:06 GMT</pubDate>
			<description>Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 2:38:36 PM, on 11/3/2009 
Platform: Windows Vista SP2 (WinNT 6.00.1906) 
MSIE: Internet Explorer v8.00 (8.00.6001.18828) 
Boot mode: Normal 
 
Running processes: 
C:\Windows\system32\Dwm.exe 
C:\Windows\system32\taskeng.exe...</description>
			<content:encoded><![CDATA[<div>Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 2:38:36 PM, on 11/3/2009<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18828)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe<br />
C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe<br />
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe<br />
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe<br />
C:\Program Files\HP\QuickPlay\QPService.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Garmin\MyGarminAgent.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe<br />
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\Uniblue\ProcessQuickLink 2\ProcessQuickLink2.exe<br />
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe<br />
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Users\Stephen J Bailey\AppData\Roaming\CBS Interactive\CNET TechTracker\TechTracker.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE<br />
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Program Files\Hewlett-Packard\HP Advisor\SSDK04.exe<br />
C:\Users\Stephen J Bailey\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Stephen J Bailey\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://att.my.yahoo.com/" target="_blank">http://att.my.yahoo.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=73&amp;bd=Pavilion&amp;pf=laptop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...lion&amp;pf=laptop</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=73&amp;bd=Pavilion&amp;pf=laptop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...lion&amp;pf=laptop</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
R3 - URLSearchHook: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHot1.dll<br />
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll<br />
O2 - BHO: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHot1.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\hssie\HssIE.dll<br />
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O3 - Toolbar: &amp;RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll<br />
O3 - Toolbar: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHot1.dll<br />
O3 - Toolbar: &amp;Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll<br />
O3 - Toolbar: &amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe<br />
O4 - HKLM\..\Run: [SansaDispatch] C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe<br />
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe<br />
O4 - HKLM\..\Run: [QPService] &quot;C:\Program Files\HP\QuickPlay\QPService.exe&quot;<br />
O4 - HKLM\..\Run: [Google Desktop Search] &quot;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&quot; /startup<br />
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [MyGarminAgent] C:\Program Files\Garmin\MyGarminAgent.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe<br />
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden<br />
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKCU\..\Run: [Uniblue ProcessQuickLink 2] &quot;C:\Program Files\Uniblue\ProcessQuickLink 2\ProcessQuickLink2.exe&quot; /autostart<br />
O4 - HKCU\..\Run: [RoboForm] &quot;C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe&quot;<br />
O4 - HKCU\..\Run: [Google Update] &quot;C:\Users\Stephen J Bailey\AppData\Local\Google\Update\GoogleUpdate.exe&quot; /c<br />
O4 - HKCU\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\aro.exe -rem<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - Startup: CNET TechTracker.lnk = Stephen J Bailey\AppData\Roaming\CBS Interactive\CNET TechTracker\TechTracker.exe<br />
O4 - Startup: MemTurbo.lnk = C:\Program Files\MemTurbo 4\MemTurbo.exe<br />
O4 - Global Startup: Bluetooth.lnk = ?<br />
O4 - Global Startup: Event Reminder.lnk = C:\Program Files\PrintMaster Platinum 17\Remind.exe<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html<br />
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html<br />
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html<br />
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html<br />
O8 - Extra context menu item: Send image to &amp;Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm<br />
O8 - Extra context menu item: Send page to &amp;Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html<br />
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html<br />
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html<br />
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html<br />
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html<br />
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL<br />
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O13 - Gopher Prefix: <br />
O16 - DPF: Garmin Communicator Plug-In - <a rel="nofollow" class="t" href="https://my.garmin.com/mygarmin/m/GarminAxControl.CAB" target="_blank">https://my.garmin.com/mygarmin/m/GarminAxControl.CAB</a><br />
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - <a rel="nofollow" class="t" href="http://echat.bellsouth.net/sdccommon/download/tgctlcm.cab" target="_blank">http://echat.bellsouth.net/sdccommon...ad/tgctlcm.cab</a><br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - <a rel="nofollow" class="t" href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" target="_blank">http://upload.facebook.com/controls/...oUploader5.cab</a><br />
O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} (Hewlett-Packard Online Support Services) - <a rel="nofollow" class="t" href="https://h20364.www2.hp.com/CSMWeb/Customer/cabs/HPISDataManager.CAB" target="_blank">https://h20364.www2.hp.com/CSMWeb/Cu...ataManager.CAB</a><br />
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - <a rel="nofollow" class="t" href="http://lads.myspace.com/upload/MySpaceUploader1006.cab" target="_blank">http://lads.myspace.com/upload/MySpaceUploader1006.cab</a><br />
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - <a rel="nofollow" class="t" href="https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab" target="_blank">https://h20436.www2.hp.com/ediags/de...e/HPDEXAXO.cab</a><br />
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - <a rel="nofollow" class="t" href="http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab" target="_blank">http://h20270.www2.hp.com/ediags/gmn...tDetection.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - <a rel="nofollow" class="t" href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - <a rel="nofollow" class="t" href="http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-latest.cab" target="_blank">http://dlm.tools.akamai.com/dlmanage...vex-latest.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br />
O23 - Service: Google Update Service (gupdate1c9917e8702590f) (gupdate1c9917e8702590f) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe<br />
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe<br />
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
O23 - Service: Hotspot Shield Helper Service (HssSrv) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe<br />
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe<br />
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe<br />
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe<br />
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe<br />
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe<br />
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe<br />
<br />
--<br />
End of file - 16809 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>fishbait</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread235747.html</guid>
		</item>
		<item>
			<title>open source installer</title>
			<link>http://www.daniweb.com/forums/thread235668.html</link>
			<pubDate>Tue, 03 Nov 2009 13:44:12 GMT</pubDate>
			<description>Hi all, 
 
 
I am looking for an open source installer to install some application software (java based s/w programme) and i do not want to commit any sort of change in registry. 
 
The installer should perform following actions: 
 
1. License Terms: Accept/Reject selection by user 
2. User must...</description>
			<content:encoded><![CDATA[<div>Hi all,<br />
<br />
<br />
I am looking for an open source installer to install some application software (java based s/w programme) and i do not want to commit any sort of change in registry.<br />
<br />
The installer should perform following actions:<br />
<br />
1. License Terms: Accept/Reject selection by user<br />
2. User must select installation folder, default is c:\......\......<br />
3. Run a bat file/script to install mysql, activemq.<br />
4. Run a bat file/script to configure the toolset<br />
5. Install application as an independent platform <br />
6. Catch errors and display to user<br />
7. Display confirmation<br />
<br />
<br />
Please let me know if anyone has got any relevant information and or such installer. I have tried some like NSIS, GhostInstaller, Nvin installer, Witem installer etc. I would like to focus on open source java installers. If anyone has used any of them, I would welcome its reviews. Thanks in advance. <br />
<br />
<br />
Best regards.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>rajuchacha007</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread235668.html</guid>
		</item>
		<item>
			<title>Please Help: url.urtbk,vundo,artemis!</title>
			<link>http://www.daniweb.com/forums/thread235561.html</link>
			<pubDate>Tue, 03 Nov 2009 05:12:50 GMT</pubDate>
			<description><![CDATA[Hi, 
 
I am running Microsoft Windows XP Media Center Edition Version 2002 Service Pack 2.  I am also running McAfee Security Center.  I was running Internet Explorer 7 then recently switched to IE8 then switched to Mozilla Firefox.  I then started getting  "artemis!..." and "vundo..." quarantine...]]></description>
			<content:encoded><![CDATA[<div>Hi,<br />
<br />
I am running Microsoft Windows XP Media Center Edition Version 2002 Service Pack 2.  I am also running McAfee Security Center.  I was running Internet Explorer 7 then recently switched to IE8 then switched to Mozilla Firefox.  I then started getting  &quot;artemis!...&quot; and &quot;vundo...&quot; quarantine messages intermittently and after scans by McAfee.  I thought perhaps that it was related to the web browser change and so I switched back to IE 7, but I am still getting these messages.  I have run McAfee scan numerous times and it quarantines both &quot;artemis!...&quot; and &quot;vundo...&quot; however it continues to show up even after it is removed.  <br />
<br />
Also, recently, IE7 would start numerous new tabs on its own.  The new tabs are empty pages but have &quot;url.urtbk...&quot; on the address bar.  IE7 would  also close/exit without warning and pop-ups would appear out of nowhere even though the pop-up blocker is enabled.<br />
<br />
Reading some threads on the internet, I tried to download malwarebytes anti-malware, however, an error message at the end of the installation process comes up and I am unable to start the program. <br />
<br />
I aplogize that my knowledge on this material is limited but I would really appreciate any help/advice/suggestions on how I could clean this up and also on how I could prevent this from happening again.<br />
<br />
Thank you,<br />
Gerard</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>gdecastro3</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread235561.html</guid>
		</item>
		<item>
			<title>can anybody help?????????</title>
			<link>http://www.daniweb.com/forums/thread235425.html</link>
			<pubDate>Mon, 02 Nov 2009 18:04:44 GMT</pubDate>
			<description>hi all, i am having trouble wit my pc its gone so slow and also i keep getting a lot of bsod crashes. if i reboot my pc will also not come back on sometimes. here is my hijack this log. any advice/help would be greatly appreciated 
 
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 20:27:16,...</description>
			<content:encoded><![CDATA[<div>hi all, i am having trouble wit my pc its gone so slow and also i keep getting a lot of bsod crashes. if i reboot my pc will also not come back on sometimes. here is my hijack this log. any advice/help would be greatly appreciated<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 20:27:16, on 01/11/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\Motive\McciCMService.exe<br />
C:\WINDOWS\System32\nvsvc32.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\SOUNDMAN.EXE<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe<br />
C:\Program Files\uTorrent\uTorrent.exe<br />
C:\Program Files\PeerGuardian2\pg2.exe<br />
C:\Program Files\3\3Connect\AutoUpdateSrv.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = <a rel="nofollow" class="t" href="http://uk.red.clientapps.yahoo.com/c...o/bt_side.html" target="_blank">http://uk.red.clientapps.yahoo.com/c...o/bt_side.html</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a rel="nofollow" class="t" href="http://uk.red.clientapps.yahoo.com/c...o/bt_side.html" target="_blank">http://uk.red.clientapps.yahoo.com/c...o/bt_side.html</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = <a rel="nofollow" class="t" href="http://uk.red.clientapps.yahoo.com/c...rch.yahoo.com/" target="_blank">http://uk.red.clientapps.yahoo.com/c...rch.yahoo.com/</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =<br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &quot;C:\Program Files\Outlook Express\msimn.exe&quot; //mailurl:mailto:melissa_x_15_x@hotmaiil.comm<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br />
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - (no file)<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll<br />
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - (no file)<br />
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll<br />
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br />
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br />
O4 - HKLM\..\Run: [PAC207_Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe<br />
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent<br />
O4 - HKLM\..\Run: [ccApp] &quot;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&quot;<br />
O4 - HKLM\..\Run: [osCheck] &quot;C:\Program Files\Norton 360\osCheck.exe&quot;<br />
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] &quot;C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe&quot;<br />
O4 - HKCU\..\Run: [uTorrent] &quot;C:\Program Files\uTorrent\uTorrent.exe&quot;<br />
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')<br />
O4 - Global Startup: Update Agent.lnk = ?<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - <a rel="nofollow" class="t" href="https://support.microsoft.com/OAS/ActiveX/MSDcode.cab" target="_blank">https://support.microsoft.com/OAS/ActiveX/MSDcode.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a rel="nofollow" class="t" href="http://www.update.microsoft.com/wind...?1220611311186" target="_blank">http://www.update.microsoft.com/wind...?1220611311186</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a rel="nofollow" class="t" href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)<br />
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)<br />
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe<br />
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE<br />
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe<br />
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe<br />
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe<br />
<br />
--<br />
End of file - 7910 bytes<br />
<br />
thanks</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>rob247</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread235425.html</guid>
		</item>
		<item>
			<title>Any help you can provide would be greatly appreciated...</title>
			<link>http://www.daniweb.com/forums/thread235209.html</link>
			<pubDate>Mon, 02 Nov 2009 02:19:13 GMT</pubDate>
			<description>I am not so computer savvy -- just enough to be dangerous to myself.  My computer locked up when I upgraded to Internet Explorer 8, so I resorted to reinstalling the original system disks.  I am fine running Mozilla, but I am still locking up in Internet Explorer.  I have run a Hijackthis log, and...</description>
			<content:encoded><![CDATA[<div>I am not so computer savvy -- just enough to be dangerous to myself.  My computer locked up when I upgraded to Internet Explorer 8, so I resorted to reinstalling the original system disks.  I am fine running Mozilla, but I am still locking up in Internet Explorer.  I have run a Hijackthis log, and am hoping someone might see what is causing my problems.  Here is my log:<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 9:08:02 PM, on 11/1/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\eHome\ehRecvr.exe<br />
C:\WINDOWS\eHome\ehSched.exe<br />
C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe<br />
C:\WINDOWS\ehome\ehtray.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe<br />
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe<br />
C:\Program Files\firedog advisor\faAgnt.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe<br />
C:\WINDOWS\eHome\ehmsas.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\HP\KBD\KBD.EXE<br />
C:\WINDOWS\SOUNDMAN.EXE<br />
C:\WINDOWS\ALCMTR.EXE<br />
C:\WINDOWS\ALCWZRD.EXE<br />
c:\windows\system\hpsysdrv.exe<br />
C:\Program Files\Java\jre1.5.0\bin\jusched.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br />
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe<br />
C:\Program Files\Microsoft Windows OneCare Live\winss.exe<br />
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\WINDOWS\system32\SearchIndexer.exe<br />
C:\WINDOWS\system32\SearchProtocolHost.exe<br />
C:\Program Files\Windows Desktop Search\WindowsSearch.exe<br />
C:\Documents and Settings\HP_Administrator.KARI\My Documents\Downloads\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=Q405&amp;bd=pavilion&amp;pf=desktop&amp;parm1=seconduser" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...rm1=seconduser</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iesearch&amp;locale=EN_US&amp;c=Q405&amp;bd=pavilion&amp;pf=desktop&amp;parm1=seconduser" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...rm1=seconduser</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.yahoo.com/" target="_blank">http://www.yahoo.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a rel="nofollow" class="t" href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iesearch&amp;locale=EN_US&amp;c=Q405&amp;bd=pavilion&amp;pf=desktop&amp;parm1=seconduser" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...rm1=seconduser</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll<br />
O3 - Toolbar: &amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll<br />
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe<br />
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe<br />
O4 - HKLM\..\Run: [HPBootOp] &quot;C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe&quot; /run<br />
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe<br />
O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;  -osboot<br />
O4 - HKLM\..\Run: [OneCareUI] &quot;C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe&quot;<br />
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br />
O4 - HKCU\..\Run: [firedogadvisor] &quot;C:\Program Files\firedog advisor\faAgnt.exe&quot; /startup<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKUS\S-1-5-21-335469381-2751086778-1406216904-500\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Administrator')<br />
O4 - HKUS\S-1-5-21-335469381-2751086778-1406216904-500\..\Run: [firedogadvisor] &quot;C:\Program Files\firedog advisor\faAgnt.exe&quot; /startup (User 'Administrator')<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe<br />
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm<br />
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - <a rel="nofollow" class="t" href="http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab" target="_blank">http://h20270.www2.hp.com/ediags/gmn...Detection2.cab</a><br />
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
<br />
--<br />
End of file - 7192 bytes<br />
<br />
<br />
Thanks for any help you can provide.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>karime2thestars</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread235209.html</guid>
		</item>
		<item>
			<title>newbie in need of help!</title>
			<link>http://www.daniweb.com/forums/thread235162.html</link>
			<pubDate>Sun, 01 Nov 2009 20:27:49 GMT</pubDate>
			<description>hi all, i am having trouble wit my pc its gone so slow and also i keep getting a lot of bsod crashes. if i reboot my pc will also not come back on sometimes. here is my hijack this log. any advice/help would be greatly appreciated 
 
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 20:27:16,...</description>
			<content:encoded><![CDATA[<div>hi all, i am having trouble wit my pc its gone so slow and also i keep getting a lot of bsod crashes. if i reboot my pc will also not come back on sometimes. here is my hijack this log. any advice/help would be greatly appreciated<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 20:27:16, on 01/11/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\Motive\McciCMService.exe<br />
C:\WINDOWS\System32\nvsvc32.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\SOUNDMAN.EXE<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe<br />
C:\Program Files\uTorrent\uTorrent.exe<br />
C:\Program Files\PeerGuardian2\pg2.exe<br />
C:\Program Files\3\3Connect\AutoUpdateSrv.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = <a rel="nofollow" class="t" href="http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html" target="_blank">http://uk.red.clientapps.yahoo.com/c...o/bt_side.html</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a rel="nofollow" class="t" href="http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html" target="_blank">http://uk.red.clientapps.yahoo.com/c...o/bt_side.html</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = <a rel="nofollow" class="t" href="http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/" target="_blank">http://uk.red.clientapps.yahoo.com/c...rch.yahoo.com/</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &quot;C:\Program Files\Outlook Express\msimn.exe&quot; //mailurl:mailto:melissa_x_15_x@hotmaiil.comm<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br />
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - (no file)<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll<br />
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - (no file)<br />
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll<br />
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br />
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br />
O4 - HKLM\..\Run: [PAC207_Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe<br />
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent<br />
O4 - HKLM\..\Run: [ccApp] &quot;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&quot;<br />
O4 - HKLM\..\Run: [osCheck] &quot;C:\Program Files\Norton 360\osCheck.exe&quot;<br />
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] &quot;C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe&quot;<br />
O4 - HKCU\..\Run: [uTorrent] &quot;C:\Program Files\uTorrent\uTorrent.exe&quot;<br />
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')<br />
O4 - Global Startup: Update Agent.lnk = ?<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - <a rel="nofollow" class="t" href="https://support.microsoft.com/OAS/ActiveX/MSDcode.cab" target="_blank">https://support.microsoft.com/OAS/ActiveX/MSDcode.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a rel="nofollow" class="t" href="http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1220611311186" target="_blank">http://www.update.microsoft.com/wind...?1220611311186</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a rel="nofollow" class="t" href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)<br />
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)<br />
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe<br />
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE<br />
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe<br />
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe<br />
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe<br />
<br />
--<br />
End of file - 7910 bytes<br />
<br />
thanks</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>rob247</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread235162.html</guid>
		</item>
		<item>
			<title>Winlogon keeps popping on startup, need help immediately</title>
			<link>http://www.daniweb.com/forums/thread235154.html</link>
			<pubDate>Sun, 01 Nov 2009 19:39:55 GMT</pubDate>
			<description>I received a message from a friend yesterday thru MSN messenger, he sent me a screensaver link and I thought it was a screensaver he made from the pictures we took.  After I downloaded the file and clicked on it, nothing happened.  So today I turned on my computer, and a Winlogon properties keeps...</description>
			<content:encoded><![CDATA[<div>I received a message from a friend yesterday thru MSN messenger, he sent me a screensaver link and I thought it was a screensaver he made from the pictures we took.  After I downloaded the file and clicked on it, nothing happened.  So today I turned on my computer, and a Winlogon properties keeps popping on my desktop.  I have to click the close button for several times until it disappears.  <br />
<br />
I checked on some malware pages, and noticed that this is some kind of virus that could hack into emails and files.  Do anyone know what I can do before the winlogon turns into something that can cause problems to my comp.  <br />
<br />
Spec:  Windows Vista Home Premium 64-bit<br />
This is the image of the winlogon on the startup: <a rel="nofollow" class="t" href="http://img689.imageshack.us/img689/8487/winlogon.jpg" target="_blank">http://img689.imageshack.us/img689/8487/winlogon.jpg</a><br />
<br />
The file I downloaded yesterday is DSC00148.SCR</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Jshammy</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread235154.html</guid>
		</item>
		<item>
			<title>My Computer has quit responding - HELP</title>
			<link>http://www.daniweb.com/forums/thread234826.html</link>
			<pubDate>Sat, 31 Oct 2009 05:35:07 GMT</pubDate>
			<description><![CDATA[I did install the HijackThis and ran it on my pc. I'm attaching the log file from HijackThis and hope you can help me figure out what the heck has invaded my pc. 
 
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 1:19:52 AM, on 10/31/2009 
Platform: Windows XP SP3 (WinNT 5.01.2600) 
MSIE:...]]></description>
			<content:encoded><![CDATA[<div>I did install the HijackThis and ran it on my pc. I'm attaching the log file from HijackThis and hope you can help me figure out what the heck has invaded my pc.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 1:19:52 AM, on 10/31/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br />
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Symantec AntiVirus\DefWatch.exe<br />
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe<br />
C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\oracle\ora92\bin\omtsreco.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\HPZipm12.exe<br />
C:\Program Files\Common Files\ICWM\Printer\RDIConverterService.exe<br />
C:\Program Files\Symantec AntiVirus\SavRoam.exe<br />
C:\Program Files\IBM_DS4000\client\monitor\SMmonitor.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br />
C:\Program Files\RealVNC\VNC4\WinVNC4.exe<br />
C:\WINDOWS\system32\SearchIndexer.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe<br />
C:\WINDOWS\SMINST\Scheduler.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br />
C:\PROGRA~1\SYMANT~1\VPTray.exe<br />
C:\Program Files\QuickTime\qttask.exe<br />
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe<br />
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe<br />
C:\Program Files\WinZip\WZQKPICK.EXE<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\rdpclip.exe<br />
C:\WINDOWS\system32\logon.scr<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="https://timeandlabor.paychex.com/secure/login.asp" target="_blank">https://timeandlabor.paychex.com/secure/login.asp</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by -== The Chronicle Telegram ==-<br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [RoxioDragToDisc] &quot;C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe&quot;<br />
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard.exe<br />
O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_XP.exe<br />
O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe<br />
O4 - HKLM\..\Run: [ccApp] &quot;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&quot;<br />
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe<br />
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] &quot;C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe&quot;<br />
O4 - HKLM\..\Run: [HP Software Update] &quot;c:\Program Files\HP\HP Software Update\HPWuSchd2.exe&quot;<br />
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe AcPro7_0_0 -reboot 1<br />
O4 - HKCU\..\Run: [msnmsgr] &quot;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&quot; /background<br />
O4 - HKUS\S-1-5-21-3844150997-2177148820-966483055-1135\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden (User '?')<br />
O4 - HKUS\S-1-5-21-3844150997-2177148820-966483055-1135\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')<br />
O4 - HKUS\S-1-5-21-3844150997-2177148820-966483055-1135\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe AcPro7_0_0 -reboot 1 (User '?')<br />
O4 - HKUS\S-1-5-21-3844150997-2177148820-966483055-1135\..\Run: [msnmsgr] &quot;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&quot; /background (User '?')<br />
O4 - S-1-5-21-3844150997-2177148820-966483055-1135 Startup: VZAccess Manager.lnk = C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (User '?')<br />
O4 - Startup: VZAccess Manager.lnk = C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe<br />
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe<br />
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe<br />
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE<br />
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll<br />
O16 - DPF: {2202D225-22C1-4B8C-A4B8-6A7E7B7E1524} (ICWMInstallObj Class) - <a rel="nofollow" class="t" href="https://qwestconferencing.qwest.com/confmgr/installs/ICWMInstall.cab" target="_blank">https://qwestconferencing.qwest.com/...CWMInstall.cab</a><br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll<br />
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - <a rel="nofollow" class="t" href="http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.4.cab" target="_blank">http://dlm.tools.akamai.com/dlmanage...ex-2.2.4.4.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a rel="nofollow" class="t" href="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1227045211921" target="_blank">http://update.microsoft.com/windowsu...?1227045211921</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a rel="nofollow" class="t" href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - <a rel="nofollow" class="t" href="https://advpubtechsupport.webex.com/client/T27L/support/ieatgpc.cab" target="_blank">https://advpubtechsupport.webex.com/...rt/ieatgpc.cab</a><br />
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Elyria.ChronicleTelegram.com<br />
O17 - HKLM\Software\..\Telephony: DomainName = Elyria.ChronicleTelegram.com<br />
O17 - HKLM\System\CCS\Services\Tcpip\..\{52DCEAAA-3F53-40B8-90AA-ADE490D8AEF5}: NameServer = 10.1.1.21,10.1.1.17<br />
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Elyria.ChronicleTelegram.com<br />
O17 - HKLM\System\CS1\Services\Tcpip\..\{52DCEAAA-3F53-40B8-90AA-ADE490D8AEF5}: NameServer = 10.1.1.21,10.1.1.17<br />
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = Elyria.ChronicleTelegram.com<br />
O17 - HKLM\System\CS2\Services\Tcpip\..\{52DCEAAA-3F53-40B8-90AA-ADE490D8AEF5}: NameServer = 10.1.1.21,10.1.1.17<br />
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br />
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\oracle\ora92\bin\omtsreco.exe<br />
O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\oracle\ora92\BIN\ONRSD.EXE<br />
O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: RDI Document Conversion Helper (RDIConverterPrintHelper) - Web Meeting - C:\Program Files\Common Files\ICWM\Printer\RDIConverterService.exe<br />
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe<br />
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe<br />
O23 - Service: IBM DS Storage Manager 10 Event Monitor (SMmonitor) - Unknown owner - C:\Program Files\IBM_DS4000\client\monitor\SMmonitor.exe<br />
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br />
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br />
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe<br />
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br />
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe</div>  <br /> <div style="padding:5px">     <fieldset class="fieldset"> <legend>Attached Files</legend> <table cellpadding="0" cellspacing="5" border="0"> <tr> <td><img class="inlineimg" src="http://www.daniweb.com/forums/images/attach/doc.gif" alt="File Type: doc" width="16" height="16" border="0" style="vertical-align:baseline" /></td> <td><a href="http://www.daniweb.com/forums/attachment.php?attachmentid=12391&amp;d=1256967156">hijackthis.doc</a> (13.0 KB)</td> </tr> </table> </fieldset>  </div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>desperate2</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234826.html</guid>
		</item>
		<item>
			<title>Help with Hijackthis log</title>
			<link>http://www.daniweb.com/forums/thread234789.html</link>
			<pubDate>Sat, 31 Oct 2009 00:27:18 GMT</pubDate>
			<description>I would appriate any help with this hijackthis log. 
 
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 7:24:43 PM, on 10/5/2009 
Platform: Windows XP SP3 (WinNT 5.01.2600) 
MSIE: Internet Explorer v8.00 (8.00.6001.18702) 
Boot mode: Normal 
 
Running processes: 
C:\WINDOWS\System32\smss.exe</description>
			<content:encoded><![CDATA[<div>I would appriate any help with this hijackthis log.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 7:24:43 PM, on 10/5/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\csrss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe<br />
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe<br />
C:\Program Files\Spyware Doctor\pctsAuxs.exe<br />
C:\Program Files\Spyware Doctor\pctsSvc.exe<br />
C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br />
C:\Program Files\Spyware Doctor\pctsTray.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\System32\alg.exe<br />
C:\WINDOWS\system32\taskmgr.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\WINDOWS\system32\NOTEPAD.EXE<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\system32\wbem\wmiprvse.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a rel="nofollow" class="t" href="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html" target="_blank">http://us.rd.yahoo.com/customize/ie/...ch/search.html</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll<br />
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br />
O4 - HKLM\..\Run: [ISTray] &quot;C:\Program Files\Spyware Doctor\pctsTray.exe&quot;<br />
O4 - HKLM\..\Run: [dellsupportcenter] &quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&quot; /P dellsupportcenter<br />
O4 - HKLM\..\Run: [egui] &quot;C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe&quot; /hide /waitservice<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll<br />
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - <a rel="nofollow" class="t" href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" target="_blank">http://upload.facebook.com/controls/...oUploader5.cab</a><br />
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll<br />
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://sslvpn.fmcna.com/f5-w-687474703a2f2f4652452d55532d4c582d4730382e64632e666d636e612e636f6d$$/iNotes6W.cab<br />
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - <a rel="nofollow" class="t" href="http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab" target="_blank">http://download.mcafee.com/molbin/sh...0/mcinsctl.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a rel="nofollow" class="t" href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1123890750815" target="_blank">http://update.microsoft.com/microsof...?1123890750815</a><br />
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Program Files\AutoCAD 2000i\AcDcToday.ocx<br />
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - <a rel="nofollow" class="t" href="http://www.installengine.com/engine/isetup.cab" target="_blank">http://www.installengine.com/engine/isetup.cab</a><br />
O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN File Upload Control) - <a rel="nofollow" class="t" href="http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab" target="_blank">http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab</a><br />
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (Yahoo! MailTo) - <a rel="nofollow" class="t" href="http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll" target="_blank">http://us.dl1.yimg.com/download.yaho...ymmapi_416.dll</a><br />
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} (EPUImageControl Class) - <a rel="nofollow" class="t" href="http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-29-0.cab" target="_blank">http://tools.ebayimg.com/eps/wl/acti..._v1-0-29-0.cab</a><br />
O16 - DPF: {C432C4BD-3566-411C-8F3C-E5E0D3AE5D33} (CBrowser Class) - <a rel="nofollow" class="t" href="http://viewers.multicastmedia.com/common/mbrowser/MINIBrowser.CAB" target="_blank">http://viewers.multicastmedia.com/co...INIBrowser.CAB</a><br />
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} - file://C:\Program Files\AutoCAD 2000i\InstFred.ocx<br />
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2000i\AcPreview.ocx<br />
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - <a rel="nofollow" class="t" href="http://fdl.msn.com/public/chat/msnchat45.cab" target="_blank">http://fdl.msn.com/public/chat/msnchat45.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)<br />
O20 - AppInit_DLLs: c:\windows\system32\horijige.dll,bapozoni.dll<br />
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll<br />
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Browser Defender Update Service - Threat Expert Ltd. - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe<br />
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE<br />
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe<br />
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe<br />
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe<br />
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe<br />
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br />
<br />
--<br />
End of file - 9042 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>magnific1</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234789.html</guid>
		</item>
		<item>
			<title>Do I have Nasties?</title>
			<link>http://www.daniweb.com/forums/thread234731.html</link>
			<pubDate>Fri, 30 Oct 2009 16:37:43 GMT</pubDate>
			<description>Hello.....I had some nasties on this laptop that had no protection....I installed Kaspersky Anti-Virus and cleaned things up a bit....ran ATF Cleaner and Malwarebytes Ani-Malware- see log below....also see my HJT below.....can someone please take a look and see if I am still infected?  Thanks very...</description>
			<content:encoded><![CDATA[<div>Hello.....I had some nasties on this laptop that had no protection....I installed Kaspersky Anti-Virus and cleaned things up a bit....ran ATF Cleaner and Malwarebytes Ani-Malware- see log below....also see my HJT below.....can someone please take a look and see if I am still infected?  Thanks very much.....JD<br />
<br />
Malwarebytes' Anti-Malware 1.41<br />
Database version: 3060<br />
Windows 6.0.6002 Service Pack 2<br />
<br />
10/30/2009 12:00:10 PM<br />
mbam-log-2009-10-30 (12-00-10).txt<br />
<br />
Scan type: Full Scan (C:\|D:\|)<br />
Objects scanned: 295055<br />
Time elapsed: 1 hour(s), 59 minute(s), 30 second(s)<br />
<br />
Memory Processes Infected: 0<br />
Memory Modules Infected: 0<br />
Registry Keys Infected: 29<br />
Registry Values Infected: 1<br />
Registry Data Items Infected: 0<br />
Folders Infected: 1<br />
Files Infected: 19<br />
<br />
Memory Processes Infected:<br />
(No malicious items detected)<br />
<br />
Memory Modules Infected:<br />
(No malicious items detected)<br />
<br />
Registry Keys Infected:<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.ShopperReports) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.ShopperReports) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7370f91f-6994-4595-9949-601fa2261c8d} (Trojan.BHO) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{35a5b43b-cb8a-49ca-a9f4-d3b308d2e3cc} (Trojan.FakeAlert) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Servises (Malware.Trace) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fioo32 (Worm.KoobFace) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_FIO32 (Worm.KoobFace) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SfX (Rootkit.Agent) -&gt; Quarantined and deleted successfully.<br />
<br />
Registry Values Infected:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\fioo32 (Worm.KoobFace) -&gt; Quarantined and deleted successfully.<br />
<br />
Registry Data Items Infected:<br />
(No malicious items detected)<br />
<br />
Folders Infected:<br />
C:\ProgramData\Microsoft\Windows\Start Menu\CS (Rogue.CyberSecurity) -&gt; Quarantined and deleted successfully.<br />
<br />
Files Infected:<br />
C:\Users\Doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BZ5XLYRE\v2prx[1].exe (Trojan.Agent) -&gt; Quarantined and deleted successfully.<br />
C:\Users\Doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GPY2VTJ6\tw.04[1].exe (Trojan.Dropper) -&gt; Quarantined and deleted successfully.<br />
C:\Users\Doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GPY2VTJ6\pp.12[1].exe (Worm.Koobface) -&gt; Quarantined and deleted successfully.<br />
C:\Users\Doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GPY2VTJ6\pp.12[2].exe (Worm.Koobface) -&gt; Quarantined and deleted successfully.<br />
C:\Users\Doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V2HDA3EY\fb.72[1].exe (Trojan.Backdoor) -&gt; Quarantined and deleted successfully.<br />
C:\Users\Doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V2HDA3EY\fb.72[2].exe (Trojan.Backdoor) -&gt; Quarantined and deleted successfully.<br />
C:\Users\Doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V2HDA3EY\fb.72[3].exe (Trojan.Backdoor) -&gt; Quarantined and deleted successfully.<br />
C:\Users\Doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V2HDA3EY\pp.12[2].exe (Worm.Koobface) -&gt; Quarantined and deleted successfully.<br />
C:\Users\Doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V2HDA3EY\v2prx[1].exe (Trojan.Agent) -&gt; Quarantined and deleted successfully.<br />
C:\Users\Doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V2HDA3EY\Inst_312s1[1].exe (Rogue.AlphaAV) -&gt; Quarantined and deleted successfully.<br />
C:\Users\Doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V8KQNIMM\v2prx[1].exe (Trojan.Agent) -&gt; Quarantined and deleted successfully.<br />
C:\Windows\010112010146116101.xxe (KoobFace.Trace) -&gt; Quarantined and deleted successfully.<br />
C:\Windows\0101120101464955.xxe (KoobFace.Trace) -&gt; Quarantined and deleted successfully.<br />
C:\Windows\0101120101465055.xxe (KoobFace.Trace) -&gt; Quarantined and deleted successfully.<br />
C:\Windows\0101120101465248.xxe (KoobFace.Trace) -&gt; Quarantined and deleted successfully.<br />
C:\Windows\bk23567.dat (KoobFace.Trace) -&gt; Quarantined and deleted successfully.<br />
C:\Windows\fdgg34353edfgdfdf (KoobFace.Trace) -&gt; Quarantined and deleted successfully.<br />
C:\Windows\tw23567.dat (Worm.KoobFace) -&gt; Quarantined and deleted successfully.<br />
C:\Program Files\Mozilla Firefox\ftemp.exe (Trojan.Dropper) -&gt; Quarantined and deleted successfully.<br />
<br />
<br />
<br />
<br />
<br />
Logfile of HijackThis v1.99.1<br />
Scan saved at 12:22:22 PM, on 10/30/2009<br />
Platform: Unknown Windows (WinNT 6.00.1906 SP2)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18828)<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\taskeng.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Windows\RtHDVCpl.exe<br />
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe<br />
C:\Program Files\HP\QuickPlay\QPService.exe<br />
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe<br />
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe<br />
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe<br />
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Windows\System32\igfxtray.exe<br />
C:\Windows\System32\hkcmd.exe<br />
C:\Windows\System32\igfxpers.exe<br />
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Windows\system32\igfxsrvc.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Program Files\HijackThis\HijackThis.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=73&amp;bd=Pavilion&amp;pf=laptop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...lion&amp;pf=laptop</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=73&amp;bd=Pavilion&amp;pf=laptop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...lion&amp;pf=laptop</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search &amp; Destroy\SDHelper.dll<br />
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\ievkbd.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll<br />
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br />
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe<br />
O4 - HKLM\..\Run: [QPService] &quot;C:\Program Files\HP\QuickPlay\QPService.exe&quot;<br />
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start<br />
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe<br />
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe<br />
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [AVP] &quot;C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe&quot;<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKCU\..\Run: [MsnMsgr] &quot;C:\Program Files\MSN Messenger\MsnMsgr.Exe&quot; /background<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O4 - Global Startup: McAfee Security Scan.lnk = ?<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra button: &amp;Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL<br />
O9 - Extra button: URLs c&amp;heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search &amp; Destroy\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp;&amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search &amp; Destroy\SDHelper.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll<br />
O11 - Options group: [INTERNATIONAL] International<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a rel="nofollow" class="t" href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll<br />
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL<br />
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll<br />
O20 - Winlogon Notify: igfxcui - C:\Windows\SYSTEM32\igfxdev.dll<br />
O20 - Winlogon Notify: klogon - C:\Windows\system32\klogon.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe&quot; -r (file missing)<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe<br />
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe<br />
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)<br />
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe<br />
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)<br />
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe<br />
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)<br />
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe<br />
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>jd51edwin</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234731.html</guid>
		</item>
		<item>
			<title>HELP! - userinit.exe - application error</title>
			<link>http://www.daniweb.com/forums/thread234706.html</link>
			<pubDate>Fri, 30 Oct 2009 14:59:36 GMT</pubDate>
			<description>I am a tech for a school district. We are having issues with users logging in and getting this error: userinit.exe - application error The application failed to initialize properly. Click on ok to terminate the application. 
 
Once they click on Ok their Icons do not appear, some get text but no...</description>
			<content:encoded><![CDATA[<div>I am a tech for a school district. We are having issues with users logging in and getting this error: userinit.exe - application error The application failed to initialize properly. Click on ok to terminate the application.<br />
<br />
Once they click on Ok their Icons do not appear, some get text but no icon and some get nothing at all on their desktops. If you try to log off with c-a-d then it brings up the box but doesn't let you use any of the options on the screen because the icons aren't there.<br />
<br />
We have tried several fixes, one of them being ComboFix, it worked on a couple of the computers but it is not a fix all on all of them district wide. We have also wiped the computers and reloaded them from scratch and as soon as you get through and log in they get the error again. HELP....I need suggestions.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>techchic</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234706.html</guid>
		</item>
		<item>
			<title><![CDATA[Browser redirects[thread moved]]]></title>
			<link>http://www.daniweb.com/forums/thread234644.html</link>
			<pubDate>Fri, 30 Oct 2009 05:39:42 GMT</pubDate>
			<description>Hi Gerbil, 
 
I have the same problem like nmslagle, keep having the address redirected to fake address. can you help to check my log, below is my log. 
I use FireFox as my browser.  
 
Thanks 
 
 
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 13:31:21, on 10/30/2009</description>
			<content:encoded><![CDATA[<div>Hi Gerbil,<br />
<br />
I have the same problem like nmslagle, keep having the address redirected to fake address. can you help to check my log, below is my log.<br />
I use FireFox as my browser. <br />
<br />
Thanks<br />
<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 13:31:21, on 10/30/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16674)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\ibmpmsvc.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Navision\Client\INSTAL~1.EXE<br />
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe<br />
C:\WINDOWS\system32\msiexec.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\inetsrv\inetinfo.exe<br />
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe<br />
C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe<br />
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe<br />
C:\Program Files\Sophos\Remote Management System\RouterNT.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\TPHDEXLG.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\WINDOWS\system32\tp4mon.exe<br />
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe<br />
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe<br />
C:\WINDOWS\system32\TpShocks.exe<br />
C:\WINDOWS\system32\igfxtray.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\Program Files\Analog Devices\Core\smax4pnp.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe<br />
C:\Program Files\Sophos\AutoUpdate\ALMon.exe<br />
C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe<br />
C:\Program Files\Digital Line Detect\DLG.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\igfxsrvc.exe<br />
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe<br />
C:\Program Files\Lenovo\Zoom\TpScrex.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Documents and Settings\FSantoso4859\Desktop\12549\imaBunny.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=74005" target="_blank">http://go.microsoft.com/fwlink/?LinkId=74005</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Program Files\Common Files\svchost.exe,<br />
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Sophos Web Content Scanner - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll<br />
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll<br />
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll<br />
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL<br />
O4 - HKLM\..\Run: [TrackPointSrv] tp4mon.exe<br />
O4 - HKLM\..\Run: [IMJPMIG8.1] &quot;C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE&quot; /Spoil /RemAdvDef /Migration32<br />
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC<br />
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC<br />
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName<br />
O4 - HKLM\..\Run: [GrooveMonitor] &quot;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&quot;<br />
O4 - HKLM\..\Run: [PSQLLauncher] &quot;C:\Program Files\ThinkVantage Fingerprint Software\launcher.exe&quot; /startup<br />
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe<br />
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe<br />
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray<br />
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor<br />
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog<br />
O4 - HKLM\..\Run: [Waiting1690] C:\Windows\stid1690.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [msnmsgr] &quot;C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe&quot; /background<br />
O4 - HKCU\..\Run: [Sony Ericsson PC Suite] &quot;C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe&quot; /systray /nologon<br />
O4 - HKCU\..\Run: [Messenger (Yahoo!)] &quot;C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE&quot; -quiet<br />
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')<br />
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE<br />
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe<br />
O4 - Global Startup: Bluetooth.lnk = ?<br />
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe<br />
O4 - Global Startup: VPN Client.lnk = ?<br />
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm<br />
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Send to &amp;Bluetooth Device... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm<br />
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe<br />
O9 - Extra 'Tools' menuitem: &amp;FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - <a rel="nofollow" class="t" href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" target="_blank">http://upload.facebook.com/controls/...oUploader5.cab</a><br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll<br />
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = TecturaCorp.net<br />
O17 - HKLM\Software\..\Telephony: DomainName = TecturaCorp.net<br />
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = TecturaCorp.net<br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O20 - AppInit_DLLs: C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe<br />
O23 - Service: Cisco Systems, Inc. Installer service (CiscoVpnInstallService) - Unknown owner - C:\Navision\Client\INSTAL~1.EXE<br />
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe<br />
O23 - Service: Logical Disk Manager Administrative Service dmadminHKHKG-SXF4859N1-SQL (dmadminHKHKG-SXF4859N1-SQL) - Unknown owner - C:\WINDOWS\system32\1033u.exe (file missing)<br />
O23 - Service: Logical Disk Manager dmserverHKHKG-SXF4859N1-SQL (dmserverHKHKG-SXF4859N1-SQL) - Unknown owner - C:\WINDOWS\system32\ahuiu.exe<br />
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)<br />
O23 - Service: Remote Desktop Help Session Manager RDSessMgrlanmanworkstation (RDSessMgrlanmanworkstation) - Unknown owner - C:\WINDOWS\system32\1037sb.exe (file missing)<br />
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe<br />
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe<br />
O23 - Service: Sophos Agent - Sophos Plc - C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe<br />
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe<br />
O23 - Service: Sophos Message Router - Sophos Plc - C:\Program Files\Sophos\Remote Management System\RouterNT.exe<br />
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe<br />
<br />
--<br />
End of file - 12549 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>ferrysb</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234644.html</guid>
		</item>
		<item>
			<title>Solutions:Read this</title>
			<link>http://www.daniweb.com/forums/thread234581.html</link>
			<pubDate>Fri, 30 Oct 2009 04:15:17 GMT</pubDate>
			<description>If you are worried about your computer infected with a virus, I would highly recommend that you install the following open source programs: 
 
Microsoft Security Essentials- download it from microsoft website. It will get rid of viruses, spywares, etc... 
or  
avast- free antivirus 
or ...</description>
			<content:encoded><![CDATA[<div>If you are worried about your computer infected with a virus, I would highly recommend that you install the following open source programs:<br />
<br />
Microsoft Security Essentials- download it from microsoft website. It will get rid of viruses, spywares, etc...<br />
or <br />
avast- free antivirus<br />
or <br />
comodo-free<br />
Remember you should only have 1 antivirus running in your computer.<br />
<br />
Secunia- search for it on google.com This program will search for vulnerabilities inside your computer.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>jake43</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234581.html</guid>
		</item>
		<item>
			<title>Help with slow computer</title>
			<link>http://www.daniweb.com/forums/thread234456.html</link>
			<pubDate>Thu, 29 Oct 2009 15:55:50 GMT</pubDate>
			<description>Is there anything in the HJT log that shows a problem? 
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 10:54:36 AM, on 10/29/2009 
Platform: Windows XP SP3 (WinNT 5.01.2600) 
MSIE: Internet Explorer v8.00 (8.00.6001.18702) 
Boot mode: Normal 
 
Running processes:...</description>
			<content:encoded><![CDATA[<div>Is there anything in the HJT log that shows a problem?<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 10:54:36 AM, on 10/29/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\system32\acs.exe<br />
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe<br />
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe<br />
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe<br />
C:\WINDOWS\system32\DVDRAMSV.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe<br />
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe<br />
C:\WINDOWS\system32\TODDSrv.exe<br />
C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\ddwmon.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\WINDOWS\AGRSMMSG.exe<br />
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe<br />
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\IncrediMail\bin\IMApp.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
c:\program files\aol toolbar\AolTbServer.exe<br />
C:\Program Files\IncrediMail\bin\IncMail.exe<br />
C:\PROGRA~1\FOXITS~1\FOXITP~2\FOXITP~1.EXE<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = <a rel="nofollow" class="t" href="http://toolbar.inbox.com/search/dispatcher.aspx?tp=aus&amp;qkw=%s&amp;tbid=%tb_id%language" target="_blank">http://toolbar.inbox.com/search/disp...tb_id%language</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com" target="_blank">http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = <a rel="nofollow" class="t" href="http://toolbar.inbox.com/search/ie.aspx?tbid=80114" target="_blank">http://toolbar.inbox.com/search/ie.aspx?tbid=80114</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = <a rel="nofollow" class="t" href="http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80114" target="_blank">http://toolbar.inbox.com/help/sa_cus...spx?tbid=80114</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <a rel="nofollow" class="t" href="http://toolbar.inbox.com/search/ie.aspx?tbid=80114" target="_blank">http://toolbar.inbox.com/search/ie.aspx?tbid=80114</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <a rel="nofollow" class="t" href="http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80114" target="_blank">http://toolbar.inbox.com/help/sa_cus...spx?tbid=80114</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = <a rel="nofollow" class="t" href="http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com" target="_blank">http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com</a><br />
R3 - URLSearchHook: IAOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL Toolbar\aoltb.dll<br />
R3 - URLSearchHook: AIM Toolbar Search Class - {03402F96-3DC7-4285-BC50-9E81FEFAFE43} - C:\Program Files\AIM Toolbar\aimtb.dll<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: AOL Toolbar Loader - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL Toolbar\aoltb.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL Toolbar\aoltb.dll<br />
O4 - HKLM\..\Run: [DDWMon] C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe<br />
O4 - HKLM\..\Run: [avgnt] &quot;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe&quot; /min<br />
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKCU\..\Run: [BIBLauncher] C:\Program Files\Business-in-a-Box\BIBLauncher.exe<br />
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')<br />
O8 - Extra context menu item: &amp;Add animation to IncrediMail Style Box - C:\Program Files\IncrediMail\bin\resources\WebMenuImg.htm<br />
O8 - Extra context menu item: &amp;AIM Toolbar Search - C:\Documents and Settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html<br />
O8 - Extra context menu item: &amp;AOL Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart<br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - <a rel="nofollow" class="t" href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" target="_blank">http://upload.facebook.com/controls/...oUploader5.cab</a><br />
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - <a rel="nofollow" class="t" href="http://pcpitstop.com/betapit/PCPitStop.CAB" target="_blank">http://pcpitstop.com/betapit/PCPitStop.CAB</a><br />
O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) - <a rel="nofollow" class="t" href="http://www.myheritage.com/Genoogle/Components/ActiveX/SearchEngineQuery.dll" target="_blank">http://www.myheritage.com/Genoogle/C...ngineQuery.dll</a><br />
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - <a rel="nofollow" class="t" href="http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab" target="_blank">http://h20270.www2.hp.com/ediags/gmn...Detection2.cab</a><br />
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll<br />
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll<br />
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe<br />
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe<br />
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe<br />
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe<br />
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe<br />
O23 - Service: Google Update Service (gupdate1c9ce6113f51c30) (gupdate1c9ce6113f51c30) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe<br />
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe<br />
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\WINDOWS\system32\TODDSrv.exe<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
<br />
--<br />
End of file - 9492 bytes<br />
Is there anything here that would be causing my computer to bog down or lock up?</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Scoop1957</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234456.html</guid>
		</item>
		<item>
			<title>News Story Trick or Treat Security Scares</title>
			<link>http://www.daniweb.com/news/story234435.html</link>
			<pubDate>Thu, 29 Oct 2009 13:36:34 GMT</pubDate>
			<description>You probably call it Halloween, for myself and other pagans it is Samhain (http://en.wikipedia.org/wiki/Samhain), but for the cyber-gangs it is phishing time. Seasonally-themed spam is on the up at this time of the year, Halloween related messages accounting for 0.5% of the daily spam traffic by...</description>
			<content:encoded><![CDATA[<div>You probably call it Halloween, for myself and other pagans it is <a rel="nofollow" class="t" href="http://en.wikipedia.org/wiki/Samhain" target="_blank">Samhain</a>, but for the cyber-gangs it is phishing time. Seasonally-themed spam is on the up at this time of the year, Halloween related messages accounting for 0.5% of the daily spam traffic by volume in mid-October according to the latest <a rel="nofollow" class="t" href="http://www.messagelabs.com/intelligence.aspx" target="_blank">Symantec MessageLabs Intelligence Report</a>. <br />
<br />
Currently, with the 'Witch's New Year' Sabbath itself coming this weekend, there are some 500 million emails circulating worldwide and the majority of the Halloween spam is originating from the <a rel="nofollow" class="t" href="http://www.itwire.com/content/view/19931/53/" target="_blank">Rustock</a> and Donbot <a rel="nofollow" class="t" href="http://www.itwire.com/content/view/24603/1231/" target="_blank">botnets</a>. Most of this would appear to be pointing towards pharmaceutical sites and rogue/counterfeit software sites.<br />
<br />
&quot;As is typical with spammers this time of year, we are seeing them try to capitalize on the holiday season&quot; said MessageLabs Intelligence Senior Analyst, Paul Wood. &quot;Although they may be a bit overzealous, spamming is a numbers game and the spammers have certainly succeeded with volume thus far. Perhaps their early-bird approach is an attempt to compete with the other botnets and get in early to maximize their chances of success.&quot;<br />
<br />
This month has also seen a batch of intercepted event-related advance-fee fraud spams, mostly relating to the 2010 football World Cup in South Africa which try and get the target to pay an up front fee in order to supposedly receive their prize draw winnings. <br />
<br />
The October phishing activity has been 1 in every 293.7 emails, an increase of 0.11% since September but a drop of 10.5% if looked at as a proportion of all email-borne threats.<br />
<br />
When it comes to viruses, October has seen the global ratio of email-borne viruses in email traffic from new and previously unknown bad sources increase by just 0.18% from September to 1 in every 230.8 emails. However, only 19.2% of email-borne malware contained links to malicious websites, which is a huge drop of some 20.6% from the previous month. <br />
<br />
Geographically speaking, Denmark was the most spammed country with levels of 96.2 percent of all email, with the US on 94% and <a rel="nofollow" class="t" href="http://www.daniweb.com/news/story229532.html" target="_blank">the UK on 93.3%</a> while China tops the virus activity charts though, with 1 in every 80.7 emails being infected.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>happygeek</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234435.html</guid>
		</item>
		<item>
			<title>Infected D: drive</title>
			<link>http://www.daniweb.com/forums/thread234351.html</link>
			<pubDate>Thu, 29 Oct 2009 08:06:50 GMT</pubDate>
			<description>Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 1:06:18 AM, on 10/29/2009 
Platform: Windows Vista SP2 (WinNT 6.00.1906) 
MSIE: Internet Explorer v8.00 (8.00.6001.18813) 
Boot mode: Normal 
 
Running processes: 
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe...</description>
			<content:encoded><![CDATA[<div>Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 1:06:18 AM, on 10/29/2009<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18813)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe<br />
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe<br />
C:\Program Files (x86)\HP\QuickPlay\QPService.exe<br />
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe<br />
C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe<br />
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe<br />
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe<br />
C:\Program Files (x86)\Java\jre1.6.0_05\bin\jusched.exe<br />
C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe<br />
C:\Program Files (x86)\Winamp\winampa.exe<br />
C:\Program Files (x86)\AVG\AVG8\avgtray.exe<br />
C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe<br />
C:\Program Files (x86)\Java\jre1.6.0_05\bin\javaw.exe<br />
C:\Program Files (x86)\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE<br />
C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe<br />
C:\Program Files (x86)\Java\jre1.6.0_05\bin\jucheck.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=83&amp;bd=Pavilion&amp;pf=cnnb" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...vilion&amp;pf=cnnb</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.imeem.com/minggg" target="_blank">http://www.imeem.com/minggg</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=83&amp;bd=Pavilion&amp;pf=cnnb" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...vilion&amp;pf=cnnb</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=83&amp;bd=Pavilion&amp;pf=cnnb" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...vilion&amp;pf=cnnb</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll<br />
F2 - REG:system.ini: UserInit=userinit.exe<br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG8\avgssie.dll<br />
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\Program Files (x86)\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll<br />
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~2\COMMON~1\SYMANT~1\IDS\IPSBHO.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll<br />
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll<br />
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\Program Files (x86)\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll<br />
O4 - HKLM\..\Run: [UCam_Menu] &quot;C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe&quot; &quot;C:\Program Files (x86)\CyberLink\YouCam&quot; update &quot;Software\CyberLink\YouCam\2.0&quot;<br />
O4 - HKLM\..\Run: [QPService] &quot;C:\Program Files (x86)\HP\QuickPlay\QPService.exe&quot;<br />
O4 - HKLM\..\Run: [QlbCtrl.exe] &quot;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe&quot; /Start<br />
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files (x86)\Java\jre1.6.0_05\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [ZoneAlarm Client] &quot;C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe&quot;<br />
O4 - HKLM\..\Run: [WinampAgent] &quot;C:\Program Files (x86)\Winamp\winampa.exe&quot;<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~2\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [Ltayozanij] rundll32.exe &quot;C:\Users\Nghia\AppData\Local\difgry.dll&quot;,Startup<br />
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden<br />
O4 - HKCU\..\Run: [Messenger (Yahoo!)] &quot;C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe&quot; -quiet<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {BD68328E-1222-4A62-BA16-E6F42CA49A64} (WMInstallMgr Control) - <a rel="nofollow" class="t" href="http://gf.wemade.com/comsso/active/WMInstallMgr.cab" target="_blank">http://gf.wemade.com/comsso/active/WMInstallMgr.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG8\avgpp.dll<br />
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Unknown owner - C:\Windows\system32\agr64svc.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)<br />
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgemc.exe<br />
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe<br />
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files (x86)\Common Files\Symantec Shared\VAScanner\comHost.exe<br />
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)<br />
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe<br />
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe<br />
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe<br />
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)<br />
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - c:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_4.EXE<br />
O23 - Service: LiveUpdate Notice - Symantec Corporation - c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)<br />
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe<br />
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe<br />
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe<br />
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe<br />
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)<br />
O23 - Service: Audio Service (STacSV) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_58be29c0\STacSV64.exe (file missing)<br />
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~2\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe<br />
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe<br />
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\SysWOW64\ZoneLabs\vsmon.exe<br />
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)<br />
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)<br />
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)<br />
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
<br />
--<br />
End of file - 13101 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>miagi</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234351.html</guid>
		</item>
		<item>
			<title>Some Kind Of AVG virus</title>
			<link>http://www.daniweb.com/forums/thread234288.html</link>
			<pubDate>Thu, 29 Oct 2009 03:48:19 GMT</pubDate>
			<description>hey so i think i got this virus from downloading a game from frostwire a few weeks back. i checked it for viruses with my avg and  it said there was nothing and when i opeded it nothing happen. so i did a scan immeditly and it said there was like 2 or 3 infections and i tried to remove them but...</description>
			<content:encoded><![CDATA[<div>hey so i think i got this virus from downloading a game from frostwire a few weeks back. i checked it for viruses with my avg and  it said there was nothing and when i opeded it nothing happen. so i did a scan immeditly and it said there was like 2 or 3 infections and i tried to remove them but wasn't able to. it was telling me i wasn't able to get into the virus vault and is still saying that. and now my computer seems to be getting slower, and sometimes even freezes.<br />
<br />
so i tried deleting AVG and going with a differn't anti virus program but i am still unable to delete AVG  it keeps saying  avgrsx.exe or avgnsx.exe or avgwdsvc.exe problem has occured.<br />
<br />
and in the past two days or so my computer has been clicking icons on my desktop for no reason like 50-100 times. and then becomes just won't work.<br />
<br />
anyone got any idea's of what it could be?<br />
any help would be greatly appretiated. <br />
thanks.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>jones905</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234288.html</guid>
		</item>
		<item>
			<title>Crunchie Please Help!!!</title>
			<link>http://www.daniweb.com/forums/thread234255.html</link>
			<pubDate>Thu, 29 Oct 2009 01:48:10 GMT</pubDate>
			<description><![CDATA[Ok, here are the issues I'm having & yes I run a lot of anti programs including Advanced System Care which some say they love & a few people say caused problems. 
 
Honestly I can't remember when the problems started, at least 4-6 months ago & it may have started after I bought the ASC, but I just...]]></description>
			<content:encoded><![CDATA[<div>Ok, here are the issues I'm having &amp; yes I run a lot of anti programs including Advanced System Care which some say they love &amp; a few people say caused problems.<br />
<br />
Honestly I can't remember when the problems started, at least 4-6 months ago &amp; it may have started after I bought the ASC, but I just exited out of it &amp; still no change.<br />
<br />
1. I click on &quot;my computer&quot;, &amp; it takes about 20-30 seconds to let me have access to the window. That's even after rebooting which I just did.<br />
<br />
That also happens with Fx, but when I've rebooted, everything is very quick until I leave the computer &amp; come back, then it takes several minutes to let me have access.<br />
<br />
Also in the last several days I'm having problems with TB (thunderbird) &amp; I didn't have hanging problems with TB b4.<br />
<br />
2. This is the most frustrating thing.<br />
<br />
At first I thought it was the site, but then it started happening on 3 different sites &amp; after bitching &amp; arguing, I have to admit it may very well be on my end. :(<br />
<br />
Either:<br />
<br />
a) <a rel="nofollow" class="t" href="http://www.cj.com" target="_blank">www.cj.com</a><br />
<br />
when I login into the membership area (main index page is fine), the CSS files don't load so I can't do anything within the site. Others don't have this problem. That's on both Fx &amp; IE.<br />
<br />
b) <a rel="nofollow" class="t" href="http://www.odesk.com" target="_blank">www.odesk.com</a><br />
<br />
When I go to edit one of our job postings, it won't let me save it saying the start date is wrong even though it's not.<br />
<br />
After weeks of them testing it, it works fine in Fx for them, but not for me. I just tried it again &amp; Fx just came out w/ an update &amp; still can't do it.<br />
<br />
In IE it works fine &lt;sigh&gt;<br />
<br />
c) <a rel="nofollow" class="t" href="http://www.freedomvoice.com" target="_blank">www.freedomvoice.com</a><br />
<br />
Tried to upload audio files &amp; make changes to my acct., can't do it in Fx, only in IE.<br />
<br />
They say they tested it &amp; there's nothing wrong. Now I didn't try it out after shutting down Fx which I should have done &amp; I don't want to touch anything to test it b/c it's the way I want it now.<br />
<br />
My assistant also had this problem in Safari &amp; Fx, but he's on a MAC &amp; you know most coders can't code properly for MACs, so that doesn't really tell me much.<br />
<br />
d) <a rel="nofollow" class="t" href="http://www.Hyperoffice.com" target="_blank">www.Hyperoffice.com</a><br />
<br />
I add a new day in the notes area &amp; instead of it taking me back to the last window, it takes me all the way back to the folders area.<br />
<br />
It's intermittent &amp; they claim there's no problem on their end.<br />
<br />
I do have to say one thing. Most if not all of these sites are poorly coded I think. I'm not a coder, but I know how sites work &amp; I can tell when it's garbage code.<br />
<br />
The thing is, no one else is having the problem. I have the latest version of Fx, I hate IE, sometimes the site works on IE, but I don't use IE daily enough to know if it's just Fx or what is going on.<br />
<br />
It's stressing me out, wasting my time, PLEASE HELP!<br />
<br />
Thanks :)<br />
<br />
<br />
Michelle<br />
----------------------------------------------<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 9:35:59 PM, on 10/28/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
C:\WINDOWS\ATKKBService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe<br />
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br />
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe<br />
C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe<br />
C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe<br />
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\oDesk\oDeskCommonPrefs.exe<br />
C:\Program Files\Shelltoys\Personal Assistant\assistant.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe<br />
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe<br />
C:\Program Files\Microsoft ActiveSync\wcescomm.exe<br />
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe<br />
C:\PROGRA~1\MICROS~3\rapimgr.exe<br />
C:\Garmin\gStart.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\Program Files\WinZip\WZQKPICK.EXE<br />
C:\Program Files\oDesk\oDeskTeam.exe<br />
C:\Program Files\oDesk\oDeskShare.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe<br />
C:\WINDOWS\system32\NOTEPAD.EXE<br />
C:\WINDOWS\system32\notepad.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Mozilla Thunderbird\thunderbird.exe<br />
C:\WINDOWS\System32\vssvc.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.ask.com/?o=101677&amp;l=dis" target="_blank">http://www.ask.com/?o=101677&amp;l=dis</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br />
O4 - HKLM\..\Run: [ATIPTA] &quot;C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&quot;<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [pdfFactory Dispatcher v3] &quot;C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe&quot; /source=HKLM<br />
O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [StartCCC] &quot;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&quot; MSRun<br />
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe /autorun<br />
O4 - HKLM\..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe<br />
O4 - HKLM\..\Run: [avgnt] &quot;C:\Program Files\Avira\AntiVir Desktop\avgnt.exe&quot; /min<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKLM\..\Run: [Prefs] C:\Program Files\oDesk\oDeskLaunch.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Program Files\ASUS\SmartDoctor\\SmartDoctor.exe  /start<br />
O4 - HKCU\..\Run: [Personal Assistant] C:\Program Files\Shelltoys\Personal Assistant\assistant.exe<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKCU\..\Run: [eFax 4.4] &quot;C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe&quot; /R<br />
O4 - HKCU\..\Run: [Messenger (Yahoo!)] &quot;C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe&quot; -quiet<br />
O4 - HKCU\..\Run: [H/PC Connection Agent] &quot;C:\Program Files\Microsoft ActiveSync\wcescomm.exe&quot;<br />
O4 - HKCU\..\Run: [ccleaner] &quot;C:\Program Files\CCleaner\CCleaner.exe&quot; /AUTO<br />
O4 - HKCU\..\Run: [Advanced SystemCare 3] &quot;C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe&quot; /startup<br />
O4 - HKCU\..\Run: [gStart] C:\Garmin\gStart.exe<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O4 - Global Startup: Quick View Plus.lnk = ?<br />
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br />
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll<br />
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll<br />
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe<br />
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll<br />
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} (Java Plug-in 1.6.0_13) - <br />
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - <a rel="nofollow" class="t" href="http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll" target="_blank">http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll</a><br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\570\G2AWinLogon.dll<br />
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe<br />
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: CarboniteService - Carbonite, Inc. (<a rel="nofollow" class="t" href="http://www.carbonite.com" target="_blank">www.carbonite.com</a>) - C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe<br />
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe<br />
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe<br />
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\570\g2aservice.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe<br />
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
<br />
--<br />
End of file - 11271 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>ep2002</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234255.html</guid>
		</item>
		<item>
			<title>I need help!!!!</title>
			<link>http://www.daniweb.com/forums/thread234220.html</link>
			<pubDate>Wed, 28 Oct 2009 22:46:54 GMT</pubDate>
			<description>Please, help me!! I need take information about a virus Trojan.Win32.Cosmu.</description>
			<content:encoded><![CDATA[<div>Please, help me!! I need take information about a virus Trojan.Win32.Cosmu.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Alex91</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234220.html</guid>
		</item>
		<item>
			<title>Laptop Running very Slow recently</title>
			<link>http://www.daniweb.com/forums/thread234191.html</link>
			<pubDate>Wed, 28 Oct 2009 19:43:20 GMT</pubDate>
			<description>Hi all, 
I am hoping someone maybe able to help me. 
I have a Acer Aspire 9301AWSMi laptop,and has been running very slow recently. 
 
It is second hand, but was running fine up until about 2 months ago. 
 
This is the Hijackthis log: 
 
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at...</description>
			<content:encoded><![CDATA[<div>Hi all,<br />
I am hoping someone maybe able to help me.<br />
I have a Acer Aspire 9301AWSMi laptop,and has been running very slow recently.<br />
<br />
It is second hand, but was running fine up until about 2 months ago.<br />
<br />
This is the Hijackthis log:<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 20:45:58, on 28/10/2009<br />
Platform: Windows Vista  (WinNT 6.00.1904)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16916)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\RtHDVCpl.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\Launch Manager\LManager.exe<br />
C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\AVG\AVG9\avgtray.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe<br />
C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE<br />
C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE<br />
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE<br />
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe<br />
C:\Users\admin\AppData\Local\Temp\RtkBtMnt.exe<br />
C:\Acer\Empowering Technology\eDataSecurity\x86\MsnVane.exe<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\Windows\system32\taskeng.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://uk.rd.yahoo.com/customize/ycomp/defaults/sp/*http://uk.yahoo.com" target="_blank">http://uk.rd.yahoo.com/customize/yco...//uk.yahoo.com</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.tiscali.co.uk/broadband" target="_blank">http://www.tiscali.co.uk/broadband</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://en.uk.acer.yahoo.com" target="_blank">http://en.uk.acer.yahoo.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://en.uk.acer.yahoo.com" target="_blank">http://en.uk.acer.yahoo.com</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = <a rel="nofollow" class="t" href="http://uk.rd.yahoo.com/customize/ycomp/defaults/su/*http://uk.yahoo.com" target="_blank">http://uk.rd.yahoo.com/customize/yco...//uk.yahoo.com</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
R3