<?xml version="1.0" encoding="utf-8"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>DaniWeb IT Discussion Community - Viruses, Spyware and other Nasties</title>
		<link>http://www.daniweb.com/forums/</link>
		<description><![CDATA[Our Viruses, Spyware and other Nasties forum is the place for Q&A-style discussions related to Windows security. Post a HijackThis log here if you think you've got viruses, spyware, adware, malware, or other unwanted guests.]]></description>
		<language>en-US</language>
		<lastBuildDate>Sat, 07 Nov 2009 19:06:21 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://www.daniweb.com/alphaimages/misc/rss.jpg</url>
			<title>DaniWeb IT Discussion Community - Viruses, Spyware and other Nasties</title>
			<link>http://www.daniweb.com/forums/</link>
		</image>
		<item>
			<title>Spy/Malware infestation</title>
			<link>http://www.daniweb.com/forums/thread236812.html</link>
			<pubDate>Sat, 07 Nov 2009 15:56:45 GMT</pubDate>
			<description>Hi there, 
 
I am suffering an issue at the moment where if I search on a serach engine and click on a result the web redirects me to another site, this will happen 3/4/5 times before directing to the correct site.  After a while I will also get another page open - www.malware-online.com and a pop...</description>
			<content:encoded><![CDATA[<div>Hi there,<br />
<br />
I am suffering an issue at the moment where if I search on a serach engine and click on a result the web redirects me to another site, this will happen 3/4/5 times before directing to the correct site.  After a while I will also get another page open - <a rel="nofollow" class="t" href="http://www.malware-online.com" target="_blank">www.malware-online.com</a> and a pop to say i need to upgrade my antivirus.  This freezes the pc untill it opens a 'winodws explorer' window within IE.  The only way to get rid of this (if your quick enough) is through task manager.<br />
I have run a virus scan (mcafee) and also run spybot and adaware, both normally and in safemode but it is still happening. <br />
<br />
Would someone be able to have a look at this HJT log and let me know if there is anything in there that might explain what is happening?<br />
<br />
Thank you in advance :)<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 15:47:47, on 07/11/2009<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18828)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
c:\PROGRA~1\mcafee.com\agent\mcagent.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe<br />
C:\Program Files\Toshiba\Toshiba Online Product Information\TOPI.exe<br />
C:\Windows\System32\igfxtray.exe<br />
C:\Windows\System32\hkcmd.exe<br />
C:\Windows\System32\igfxpers.exe<br />
C:\Program Files\Apoint2K\Apoint.exe<br />
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe<br />
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe<br />
C:\Program Files\Toshiba\SmoothView\SmoothView.exe<br />
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe<br />
C:\Program Files\Toshiba\HDMICtrlMan\HDMICtrlMan.exe<br />
C:\Program Files\MouseDriver\MouseDriver.exe<br />
C:\Program Files\PowerISO\PWRISOVM.EXE<br />
C:\Program Files\Toshiba TEMPRO\TemproTray.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
E:\itunes\iTunesHelper.exe<br />
C:\Program Files\HP\HP Software Update\hpwuschd2.exe<br />
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br />
C:\Windows\system32\igfxsrvc.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe<br />
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe<br />
C:\Windows\system32\igfxext.exe<br />
C:\Program Files\Toshiba\HDMICtrlMan\HCMSoundChanger.exe<br />
C:\Program Files\Apoint2K\HidFind.exe<br />
C:\Program Files\Apoint2K\Apntex.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Users\Mark Hogben\Downloads\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.virginmedia.com/" target="_blank">http://www.virginmedia.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!<br />
<br />
\Companion\Installs\cpn\yt.dll<br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!<br />
<br />
\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common <br />
<br />
Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft <br />
<br />
Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web <br />
<br />
Printing\hpswp_BHO.dll<br />
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!<br />
<br />
\Companion\Installs\cpn\yt.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START<br />
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe<br />
O4 - HKLM\..\Run: [cfFncEnabler.exe] cfFncEnabler.exe<br />
O4 - HKLM\..\Run: [Google EULA Launcher] c:\Program Files\Google\Google EULA\GoogleEULALauncher.exe IE PA<br />
O4 - HKLM\..\Run: [Toshiba TEMPO] C:\Program Files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe<br />
O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup<br />
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe<br />
O4 - HKLM\..\Run: [Camera Assistant Software] &quot;C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe&quot; /start<br />
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE<br />
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe<br />
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe<br />
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe<br />
O4 - HKLM\..\Run: [HDMICtrlMan] C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe<br />
O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [MouseDriverD9] C:\Program Files\MouseDriver\MouseDriver.exe<br />
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe<br />
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE<br />
O4 - HKLM\..\Run: [Toshiba TEMPRO] C:\Program Files\Toshiba TEMPRO\TemproTray.exe<br />
O4 - HKLM\..\Run: [mcagent_exe] &quot;C:\Program Files\McAfee.com\Agent\mcagent.exe&quot; /runkey<br />
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;E:\itunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe<br />
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] &quot;C:\Program Files\Common <br />
<br />
Files\Ahead\Lib\NMBgMonitor.exe&quot;<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [Steam] &quot;c:\program files\steam\steam.exe&quot; -silent<br />
O4 - HKCU\..\Run: [TomTomHOME.exe] &quot;C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe&quot; -s<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKUS\S-1-5-18\..\Run: [TOSHIBA Online Product Information] C:\Program Files\TOSHIBA\Toshiba Online Product <br />
<br />
Information\topi.exe (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [TOSHIBA Online Product Information] C:\Program Files\TOSHIBA\Toshiba Online Product <br />
<br />
Information\topi.exe (User 'Default user')<br />
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (User 'Default user')<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O8 - Extra context menu item: Add to Google Photos Screensa&amp;ver - res://C:\Windows\system32\GPhotos.scr/200<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: eBay.co.uk - Buy It Sell It Love It - {76577871-04EC-495E-A12B-91F7C3600AFA} - <br />
<br />
<a rel="nofollow" class="t" href="http://rover.ebay.com/rover/1/710-44557-9400-3/4" target="_blank">http://rover.ebay.com/rover/1/710-44557-9400-3/4</a> (file missing)<br />
O9 - Extra button: Amazon.co.uk - {8A918C1D-E123-4E36-B562-5C1519E434CE} - <a rel="nofollow" class="t" href="http://www.amazon.co.uk/exec/obidos/redirect-" target="_blank">http://www.amazon.co.uk/exec/obidos/redirect-</a><br />
<br />
home?tag=Toshibaukbholink-21&amp;site=home (file missing)<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web <br />
<br />
Printing\hpswp_BHO.dll<br />
O13 - Gopher Prefix: <br />
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device <br />
<br />
Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google <br />
<br />
Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common <br />
<br />
Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe<br />
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br />
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe<br />
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe<br />
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Flash Memory <br />
<br />
Card Driver\o2flash.exe<br />
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe<br />
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe<br />
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search &amp; <br />
<br />
Destroy\SDWinSec.exe<br />
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe<br />
O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program <br />
<br />
Files\Toshiba TEMPRO\TemproSvc.exe<br />
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD <br />
<br />
PLAYER\TNaviSrv.exe<br />
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe<br />
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe<br />
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe<br />
O23 - Service: TOSHIBA Bluetooth Service - Unknown owner - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe <br />
<br />
(file missing)<br />
O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe<br />
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead <br />
<br />
Systems\DVD\ULCDRSvr.exe<br />
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe<br />
<br />
--<br />
End of file - 12503 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Hoggy12</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread236812.html</guid>
		</item>
		<item>
			<title>Strange Virus</title>
			<link>http://www.daniweb.com/forums/thread236774.html</link>
			<pubDate>Sat, 07 Nov 2009 12:37:04 GMT</pubDate>
			<description>Hi ive been trying to fix my pc for months and i think i have a strange virus  that boots  off an on my pc consistantly every 10 secs.. ill try to type  this short since it might shut off while im writing thisnow .. 
 
ive replaced the heat sink fan and power unit   which got my pc to work for 4...</description>
			<content:encoded><![CDATA[<div>Hi ive been trying to fix my pc for months and i think i have a strange virus  that boots  off an on my pc consistantly every 10 secs.. ill try to type  this short since it might shut off while im writing thisnow ..<br />
<br />
ive replaced the heat sink fan and power unit   which got my pc to work for 4 dys before it  started to  do the whole loop on an off thing again untill i ahve  to manaully shut it off from the power supply( XION atx power supply im using ) .<br />
<br />
Im trying to see if i can get my pc clean so that i can figure out what hardware issue is causing my pc to do this another site mention that it could be a  virus or worm that &quot; reboots on &amp; off randomly pc &quot;..   heres my hijacklog file<br />
<br />
let me know what i need to take out also i notice before all this started to happen.. ive installed a malware bytes program to get rid of spyware not sure if that would do it but please if guys can let me know that would great thanks!<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 7:21:28 AM, on 11/7/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\system32\DeltaIITray.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br />
C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br />
C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\AVG\AVG8\avgcsrvx.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Documents and Settings\Jc\My Documents\HJT\HiJackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = <a rel="nofollow" class="t" href="http://windowsupdate.microsoft.com/" target="_blank">http://windowsupdate.microsoft.com/</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r<br />
O4 - HKLM\..\Run: [DeltaIITaskbarApp] C:\WINDOWS\system32\DeltaIITray.exe<br />
O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;  -osboot<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [M-Audio Taskbar Icon] C:\WINDOWS\System32\DeltaIITray.exe<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKCU\..\Run: [Performance Center] C:\Program Files\Ascentive\Performance Center\APCMain.exe -m<br />
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden<br />
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] &quot;C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe&quot;<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - <a rel="nofollow" class="t" href="http://inst.c-wss.com/m010g/EN/install/gtdownlr.cab" target="_blank">http://inst.c-wss.com/m010g/EN/install/gtdownlr.cab</a><br />
O16 - DPF: {264AED84-12F1-4CA1-8AA7-EB939AE58D8D} (STCWeb Control) - <a rel="nofollow" class="t" href="https://cvpn.onss.com/CACHE/webvpn/stc/1/binaries/stcweb.cab" target="_blank">https://cvpn.onss.com/CACHE/webvpn/s...ies/stcweb.cab</a><br />
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - <a rel="nofollow" class="t" href="http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab" target="_blank">http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a rel="nofollow" class="t" href="http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1199676726031" target="_blank">http://www.update.microsoft.com/wind...?1199676726031</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
O23 - Service: Cisco AnyConnect VPN Agent (vpnagent) - Cisco Systems, Inc. - C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe<br />
<br />
--<br />
End of file - 5952 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>pimpwack</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread236774.html</guid>
		</item>
		<item>
			<title>Click on Search Results and redirected to non-related page</title>
			<link>http://www.daniweb.com/forums/thread236588.html</link>
			<pubDate>Fri, 06 Nov 2009 15:30:18 GMT</pubDate>
			<description>Every I conduct a search for something using Google, I get the true results listed but when I click on the result I am redirected to a page on Virus software, travel sites or something similar. I can open the results if I right click the link and get it to open in a new tab. 
 
Additionally, unless...</description>
			<content:encoded><![CDATA[<div>Every I conduct a search for something using Google, I get the true results listed but when I click on the result I am redirected to a page on Virus software, travel sites or something similar. I can open the results if I right click the link and get it to open in a new tab.<br />
<br />
Additionally, unless I run IE8 on Admin Mode for Vista, I continually crash. <br />
<br />
I have run McAfee and gotten 300+ instances of Virnut.n.gen repaired and had 7 instances of Artemis! quarantined. <br />
<br />
My HijackThis Log:<br />
<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 10:20:56 AM, on 11/6/2009<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18828)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
c:\PROGRA~1\mcafee.com\agent\mcagent.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\System32\wpcumi.exe<br />
C:\Program Files\Microsoft LifeChat\LifeChat.exe<br />
C:\Program Files\QuickTime\QTTask.exe<br />
D:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\X3watch\x3watch.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Program Files\Electronic Arts\EADM\Core.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Windows\Explorer.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe<br />
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Windows Mail\WinMail.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\msfeedssync.exe<br />
L:\Downloads\HijackThis.exe<br />
<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll<br />
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Spybot - Search &amp; Destroy\SDHelper.dll<br />
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe<br />
O4 - HKLM\..\Run: [MSConfig] &quot;C:\Windows\System32\msconfig.exe&quot; /auto<br />
O4 - HKLM\..\Run: [NeroCheck] C:\Windows\system32\NeroCheck.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [LifeChat] &quot;C:\Program Files\Microsoft LifeChat\LifeChat.exe&quot;<br />
O4 - HKLM\..\Run: [mcagent_exe] &quot;C:\Program Files\McAfee.com\Agent\mcagent.exe&quot; /runkey<br />
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;D:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [x3watch] C:\Program Files\X3watch\x3watch.exe<br />
O4 - HKLM\..\Run: [Regedit32] C:\Windows\system32\regedit.exe<br />
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [igndlm.exe] D:\Download Manager\DLM.exe /windowsstart /startifwork<br />
O4 - HKCU\..\Run: [EA Core] &quot;C:\Program Files\Electronic Arts\EADM\Core.exe&quot; -silent<br />
O4 - HKCU\..\Run: [DAEMON Tools Lite] &quot;D:\DAEMON Tools Lite\daemon.exe&quot; -autorun<br />
O4 - HKCU\..\Run: [A00F59FC2A.exe] C:\Users\Michael\AppData\Local\Temp\_A00F59FC2A.exe<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKCU\..\Run: [ter8m] RUNDLL32.EXE C:\Windows\TEMP\msxm192z.dll,w<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-18\..\Run: [ter8m] RUNDLL32.EXE C:\Windows\TEMP\msxm192z.dll,w (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [ter8m] RUNDLL32.EXE C:\Windows\TEMP\msxm192z.dll,w (User 'Default user')<br />
O4 - Startup: 9298734.lnk = C:\Users\Michael\AppData\Local\Temp\SMScvhost.exe<br />
O4 - Startup: santa.bat<br />
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O15 - Trusted Zone: <a rel="nofollow" class="t" href="http://www.convergysworkathome.com" target="_blank">http://www.convergysworkathome.com</a><br />
O16 - DPF: vzTCPConfig - <a rel="nofollow" class="t" href="http://www2.verizon.net/help/fios_settings/include/vzTCPConfig.CAB" target="_blank">http://www2.verizon.net/help/fios_se...zTCPConfig.CAB</a><br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - <a rel="nofollow" class="t" href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" target="_blank">http://upload.facebook.com/controls/...oUploader5.cab</a><br />
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - <a rel="nofollow" class="t" href="http://www.pcpitstop.com/betapit/PCPitStop.CAB" target="_blank">http://www.pcpitstop.com/betapit/PCPitStop.CAB</a><br />
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - <a rel="nofollow" class="t" href="http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/MyFunCardsInitialSetup1.0.1.1.cab" target="_blank">http://ak.exe.imgfarm.com/images/noc...tup1.0.1.1.cab</a><br />
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - <a rel="nofollow" class="t" href="http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab" target="_blank">http://www.fileplanet.com/fpdlmgr/ca..._2.3.6.108.cab</a><br />
O16 - DPF: {549F957E-2F89-11D6-8CFE-00C04F52B225} (CMV5 Class) - <a rel="nofollow" class="t" href="http://couponmom.coupons.smartsource.com/download/cscmv5X.cab" target="_blank">http://couponmom.coupons.smartsource...ad/cscmv5X.cab</a><br />
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - <a rel="nofollow" class="t" href="http://upload.facebook.com/controls/FacebookPhotoUploader3.cab" target="_blank">http://upload.facebook.com/controls/...oUploader3.cab</a><br />
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - <a rel="nofollow" class="t" href="http://download.divx.com/player/DivXBrowserPlugin.cab" target="_blank">http://download.divx.com/player/DivXBrowserPlugin.cab</a><br />
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - <a rel="nofollow" class="t" href="http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab" target="_blank">http://upload.facebook.com/controls/...Uploader55.cab</a><br />
O16 - DPF: {A084A130-28AE-4B32-B51A-1C8CE164BC88} (WNICheck2 Class) - <a rel="nofollow" class="t" href="http://www.convergysworkathome.com/AppHardT.CAB" target="_blank">http://www.convergysworkathome.com/AppHardT.CAB</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a rel="nofollow" class="t" href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - <a rel="nofollow" class="t" href="http://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab" target="_blank">http://upload.facebook.com/controls/...ploader4_5.cab</a><br />
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - <a rel="nofollow" class="t" href="http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll" target="_blank">http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll</a><br />
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O20 - AppInit_DLLs: C:\Windows\system32\kbdnet.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: fastnetsrv  Service (fastnetsrv) - Netopsystems A - C:\Windows\system32\FastNetSrv.exe<br />
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - D:\MAGIX\Common\Database\bin\fbserver.exe<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe<br />
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe<br />
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br />
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe<br />
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\McShield.exe<br />
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe<br />
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe<br />
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe<br />
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe<br />
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe<br />
<br />
--<br />
End of file - 10428 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>MPRatamacue</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread236588.html</guid>
		</item>
		<item>
			<title>Connecting to a-connect Virus.</title>
			<link>http://www.daniweb.com/forums/thread236578.html</link>
			<pubDate>Fri, 06 Nov 2009 14:38:24 GMT</pubDate>
			<description>I have an Acer 5720 Travelmate Laptop. Recently ugraded my Vodafone E220 Datacard to the latest software. Whenever I connect to the Internet id drops the connection and try to connect to A-CONNECT ( bunkown to me). Somebody told me that it is a possible virus.  But I have KASPERSKY Internet...</description>
			<content:encoded><![CDATA[<div>I have an Acer 5720 Travelmate Laptop. Recently ugraded my Vodafone E220 Datacard to the latest software. Whenever I connect to the Internet id drops the connection and try to connect to A-CONNECT ( bunkown to me). Somebody told me that it is a possible virus.  But I have KASPERSKY Internet Security ( anti-virus loaded). HELP ! ! ! !  how can I delete/remove this virus.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Lungis</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread236578.html</guid>
		</item>
		<item>
			<title>Multiple Viruses</title>
			<link>http://www.daniweb.com/forums/thread236570.html</link>
			<pubDate>Fri, 06 Nov 2009 14:06:13 GMT</pubDate>
			<description><![CDATA[I've clicked on some link and now I have multiple critical viruses.  Trojans, key logger variant, etc.  I'm not able to access the registry, I think damage has been done to it.  What can I do?  Reformatting the computer isn't a problem for me.  There's nothing on it that I need to keep.  Is this...]]></description>
			<content:encoded><![CDATA[<div>I've clicked on some link and now I have multiple critical viruses.  Trojans, key logger variant, etc.  I'm not able to access the registry, I think damage has been done to it.  What can I do?  Reformatting the computer isn't a problem for me.  There's nothing on it that I need to keep.  Is this the best option?  If so, how do I do it?</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>munecka</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread236570.html</guid>
		</item>
		<item>
			<title>HIjackthis log/can someone help</title>
			<link>http://www.daniweb.com/forums/thread236485.html</link>
			<pubDate>Fri, 06 Nov 2009 05:35:47 GMT</pubDate>
			<description>Here is my Hijack this log  can somone check it out and tell me what is safe to get rid of.  I think I know of a few but figured i had better check with the people who know best.  Thanks  Ryun 
 
 Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 11:34:39 PM, on 11/5/2009 
Platform: Windows...</description>
			<content:encoded><![CDATA[<div>Here is my Hijack this log  can somone check it out and tell me what is safe to get rid of.  I think I know of a few but figured i had better check with the people who know best.  Thanks  Ryun<br />
<br />
 Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 11:34:39 PM, on 11/5/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Tall Emu\Online Armor\OAcat.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Tall Emu\Online Armor\oasrv.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
C:\Program Files\DigitalPersona\Bin\DpHost.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\system32\lxdicoms.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe<br />
C:\Program Files\DigitalPersona\Bin\DPFUSMgr.exe<br />
C:\windows\system\hpsysdrv.exe<br />
C:\WINDOWS\system32\dla\tfswctrl.exe<br />
C:\WINDOWS\System32\igfxtray.exe<br />
C:\WINDOWS\System32\hkcmd.exe<br />
C:\WINDOWS\system32\ps2.exe<br />
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE<br />
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe<br />
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe<br />
C:\PROGRA~1\Yahoo!\browser\ycommon.exe<br />
C:\WINDOWS\SM1BG.EXE<br />
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe<br />
C:\Program Files\DigitalPersona\Bin\DPAgnt.exe<br />
C:\Program Files\QuickTime\qttask.exe<br />
C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe<br />
C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Tall Emu\Online Armor\oaui.exe<br />
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe<br />
C:\Program Files\Microsoft ActiveSync\wcescomm.exe<br />
C:\Program Files\Tall Emu\Online Armor\OAhlp.exe<br />
C:\PROGRA~1\MI3AA1~1\rapimgr.exe<br />
C:\Program Files\Java\jre6\bin\jucheck.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.hotmail.com/" target="_blank">http://www.hotmail.com/</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = ,<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll<br />
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\PROGRA~1\Yahoo!\Common\YIeTagBm.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [StorageGuard] &quot;C:\Program Files\VERITAS Software\Update Manager\sgtray.exe&quot; /r<br />
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe<br />
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe<br />
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe<br />
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE<br />
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe<br />
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe<br />
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE<br />
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe<br />
O4 - HKLM\..\Run: [DPAgnt] C:\Program Files\DigitalPersona\Bin\DPAgnt.exe<br />
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [QAGENT] C:\Program Files\QUICKENW\QAGENT.EXE<br />
O4 - HKLM\..\Run: [FaxCenterServer] &quot;C:\Program Files\\Lexmark Fax Solutions\fm3032.exe&quot; /s<br />
O4 - HKLM\..\Run: [lxdimon.exe] &quot;C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe&quot;<br />
O4 - HKLM\..\Run: [lxdiamon] &quot;C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [@OnlineArmor GUI] &quot;C:\Program Files\Tall Emu\Online Armor\oaui.exe&quot;<br />
O4 - HKLM\..\Run: [avgnt] &quot;C:\Program Files\Avira\AntiVir Desktop\avgnt.exe&quot; /min<br />
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
O4 - HKCU\..\Run: [LGBLiveUpdate] C:\WINDOWS\system32\lgbpd.exe<br />
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe<br />
O4 - HKCU\..\Run: [H/PC Connection Agent] &quot;C:\Program Files\Microsoft ActiveSync\wcescomm.exe&quot;<br />
O4 - HKCU\..\Run: [TomTomHOME.exe] &quot;C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe&quot;<br />
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br />
O4 - Global Startup: AT&amp;T Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe<br />
O4 - Global Startup: Event Reminder.lnk = C:\Program Files\The Print Shop 23\Remind.exe<br />
O4 - Global Startup: Harmony Monitor.lnk = C:\Program Files\Logitech\Harmony Remote\EasyZapperMonitor.exe<br />
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe<br />
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll<br />
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll<br />
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll<br />
O9 - Extra button: AT&amp;T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll<br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?linkid=39204" target="_blank">http://go.microsoft.com/fwlink/?linkid=39204</a><br />
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - <a rel="nofollow" class="t" href="http://photos.walmart.com/WalmartActivia.cab" target="_blank">http://photos.walmart.com/WalmartActivia.cab</a><br />
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - <a rel="nofollow" class="t" href="http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab" target="_blank">http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a rel="nofollow" class="t" href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1252243607234" target="_blank">http://update.microsoft.com/microsof...?1252243607234</a><br />
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - <a rel="nofollow" class="t" href="http://download.eset.com/special/eos/OnlineScanner.cab" target="_blank">http://download.eset.com/special/eos/OnlineScanner.cab</a><br />
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - <a rel="nofollow" class="t" href="http://autos.msn.com/components/ocx/survid/MSSurVid.cab" target="_blank">http://autos.msn.com/components/ocx/survid/MSSurVid.cab</a><br />
O16 - DPF: {BB47CA33-8B4D-11D0-9511-00C04FD9152D} (ExteriorSurround Object) - <a rel="nofollow" class="t" href="http://autos.msn.com/components/ocx/exterior/Outside.cab" target="_blank">http://autos.msn.com/components/ocx/...or/Outside.cab</a><br />
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) - <a rel="nofollow" class="t" href="http://www.photodex.com/pxplay.cab" target="_blank">http://www.photodex.com/pxplay.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a rel="nofollow" class="t" href="https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab" target="_blank">https://download.macromedia.com/pub/...sh/swflash.cab</a><br />
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
O23 - Service: Windows XP FUS Manager (DPFUSMgr) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DPFUSMgr.exe<br />
O23 - Service: Biometric Authentication Service (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHost.exe<br />
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: lxdiCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdiserv.exe<br />
O23 - Service: lxdi_device -   - C:\WINDOWS\system32\lxdicoms.exe<br />
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe<br />
O23 - Service: Online Armor Helper Service (OAcat) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\OAcat.exe<br />
O23 - Service: Online Armor (SvcOnlineArmor) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\oasrv.exe<br />
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe<br />
<br />
--<br />
End of file - 8982 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>ryun</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread236485.html</guid>
		</item>
		<item>
			<title>Computer acting up, veruy slow (Please Help)</title>
			<link>http://www.daniweb.com/forums/thread236420.html</link>
			<pubDate>Thu, 05 Nov 2009 23:45:34 GMT</pubDate>
			<description><![CDATA[Ok, here are the issues I'm having & yes I run a lot of anti programs including Advanced System Care which some say they love & a few people say caused problems. 
 
Honestly I can't remember when the problems started, at least 4-6 months ago & it may have started after I bought the ASC, but I just...]]></description>
			<content:encoded><![CDATA[<div>Ok, here are the issues I'm having &amp; yes I run a lot of anti programs including Advanced System Care which some say they love &amp; a few people say caused problems.<br />
<br />
Honestly I can't remember when the problems started, at least 4-6 months ago &amp; it may have started after I bought the ASC, but I just exited out of it &amp; still no change.<br />
<br />
1. I click on &quot;my computer&quot;, &amp; it takes about 20-30 seconds to let me have access to the window. That's even after rebooting which I just did.<br />
<br />
That also happens with Fx, but when I've rebooted, everything is very quick until I leave the computer &amp; come back, then it takes several minutes to let me have access.<br />
<br />
Also in the last several days I'm having problems with TB (thunderbird) &amp; I didn't have hanging problems with TB b4.<br />
<br />
2. This is the most frustrating thing.<br />
<br />
At first I thought it was the site, but then it started happening on 3 different sites &amp; after bitching &amp; arguing, I have to admit it may very well be on my end.<br />
<br />
Either:<br />
<br />
a) <a rel="nofollow" class="t" href="http://www.cj.com" target="_blank">www.cj.com</a><br />
<br />
when I login into the membership area (main index page is fine), the CSS files don't load so I can't do anything within the site. Others don't have this problem. That's on both Fx &amp; IE.<br />
<br />
b) <a rel="nofollow" class="t" href="http://www.odesk.com" target="_blank">www.odesk.com</a><br />
<br />
When I go to edit one of our job postings, it won't let me save it saying the start date is wrong even though it's not.<br />
<br />
After weeks of them testing it, it works fine in Fx for them, but not for me. I just tried it again &amp; Fx just came out w/ an update &amp; still can't do it.<br />
<br />
In IE it works fine &lt;sigh&gt;<br />
<br />
c) <a rel="nofollow" class="t" href="http://www.freedomvoice.com" target="_blank">www.freedomvoice.com</a><br />
<br />
Tried to upload audio files &amp; make changes to my acct., can't do it in Fx, only in IE.<br />
<br />
They say they tested it &amp; there's nothing wrong. Now I didn't try it out after shutting down Fx which I should have done &amp; I don't want to touch anything to test it b/c it's the way I want it now.<br />
<br />
My assistant also had this problem in Safari &amp; Fx, but he's on a MAC &amp; you know most coders can't code properly for MACs, so that doesn't really tell me much.<br />
<br />
d) <a rel="nofollow" class="t" href="http://www.Hyperoffice.com" target="_blank">www.Hyperoffice.com</a><br />
<br />
I add a new day in the notes area &amp; instead of it taking me back to the last window, it takes me all the way back to the folders area.<br />
<br />
It's intermittent &amp; they claim there's no problem on their end.<br />
<br />
I do have to say one thing. Most if not all of these sites are poorly coded I think. I'm not a coder, but I know how sites work &amp; I can tell when it's garbage code.<br />
<br />
The thing is, no one else is having the problem. I have the latest version of Fx, I hate IE, sometimes the site works on IE, but I don't use IE daily enough to know if it's just Fx or what is going on.<br />
<br />
It's stressing me out, wasting my time, PLEASE HELP!<br />
<br />
Thanks<br />
<br />
<br />
Michelle<br />
----------------------------------------------<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 9:35:59 PM, on 10/28/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
C:\WINDOWS\ATKKBService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe<br />
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br />
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe<br />
C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe<br />
C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe<br />
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\oDesk\oDeskCommonPrefs.exe<br />
C:\Program Files\Shelltoys\Personal Assistant\assistant.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe<br />
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe<br />
C:\Program Files\Microsoft ActiveSync\wcescomm.exe<br />
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe<br />
C:\PROGRA~1\MICROS~3\rapimgr.exe<br />
C:\Garmin\gStart.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\Program Files\WinZip\WZQKPICK.EXE<br />
C:\Program Files\oDesk\oDeskTeam.exe<br />
C:\Program Files\oDesk\oDeskShare.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe<br />
C:\WINDOWS\system32\NOTEPAD.EXE<br />
C:\WINDOWS\system32\notepad.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Mozilla Thunderbird\thunderbird.exe<br />
C:\WINDOWS\System32\vssvc.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.ask.com/?o=101677&amp;l=dis" target="_blank">http://www.ask.com/?o=101677&amp;l=dis</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br />
O4 - HKLM\..\Run: [ATIPTA] &quot;C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&quot;<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [pdfFactory Dispatcher v3] &quot;C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe&quot; /source=HKLM<br />
O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [StartCCC] &quot;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&quot; MSRun<br />
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe /autorun<br />
O4 - HKLM\..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe<br />
O4 - HKLM\..\Run: [avgnt] &quot;C:\Program Files\Avira\AntiVir Desktop\avgnt.exe&quot; /min<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKLM\..\Run: [Prefs] C:\Program Files\oDesk\oDeskLaunch.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Program Files\ASUS\SmartDoctor\\SmartDoctor.exe /start<br />
O4 - HKCU\..\Run: [Personal Assistant] C:\Program Files\Shelltoys\Personal Assistant\assistant.exe<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKCU\..\Run: [eFax 4.4] &quot;C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe&quot; /R<br />
O4 - HKCU\..\Run: [Messenger (Yahoo!)] &quot;C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe&quot; -quiet<br />
O4 - HKCU\..\Run: [H/PC Connection Agent] &quot;C:\Program Files\Microsoft ActiveSync\wcescomm.exe&quot;<br />
O4 - HKCU\..\Run: [ccleaner] &quot;C:\Program Files\CCleaner\CCleaner.exe&quot; /AUTO<br />
O4 - HKCU\..\Run: [Advanced SystemCare 3] &quot;C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe&quot; /startup<br />
O4 - HKCU\..\Run: [gStart] C:\Garmin\gStart.exe<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O4 - Global Startup: Quick View Plus.lnk = ?<br />
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br />
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll<br />
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll<br />
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe<br />
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll<br />
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} (Java Plug-in 1.6.0_13) -<br />
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - <a rel="nofollow" class="t" href="http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll" target="_blank">http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll</a><br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\570\G2AWinLogon.dll<br />
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe<br />
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: CarboniteService - Carbonite, Inc. (<a rel="nofollow" class="t" href="http://www.carbonite.com" target="_blank">www.carbonite.com</a>) - C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe<br />
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe<br />
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe<br />
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\570\g2aservice.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe<br />
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
<br />
--<br />
End of file - 11271 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>ep2002</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread236420.html</guid>
		</item>
		<item>
			<title>Windows Vista and A Virus?</title>
			<link>http://www.daniweb.com/forums/thread236110.html</link>
			<pubDate>Thu, 05 Nov 2009 02:00:42 GMT</pubDate>
			<description>I am running Windows Vista home edition.  Recently I think a virus or something has ruined my computer.  I can no longer download any program from the web and many of the programs that reside on my hard drive will not function.  I am led to believe their is a registry problem.  Microsofts...</description>
			<content:encoded><![CDATA[<div>I am running Windows Vista home edition.  Recently I think a virus or something has ruined my computer.  I can no longer download any program from the web and many of the programs that reside on my hard drive will not function.  I am led to believe their is a registry problem.  Microsofts suggestions of doing restores just made the entire situation worse.  Any help appreciated.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>khwhitaker</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread236110.html</guid>
		</item>
		<item>
			<title>Taskbar changes color and internet disconnect</title>
			<link>http://www.daniweb.com/forums/thread236104.html</link>
			<pubDate>Thu, 05 Nov 2009 01:23:20 GMT</pubDate>
			<description><![CDATA[Hi to everyone I'm new here!!!! Initially my problem  started with no sound after reboot & internet disconnection after few minutes of reboot. Now since I turn windows audio service to automatic, sound related issue seems to be gone. I tried everything that I know from google searching like...]]></description>
			<content:encoded><![CDATA[<div>Hi to everyone I'm new here!!!! Initially my problem  started with no sound after reboot &amp; internet disconnection after few minutes of reboot. Now since I turn windows audio service to automatic, sound related issue seems to be gone. I tried everything that I know from google searching like scanning with Malwarebyte's Ant-Malware, Trend-mico's HouseCall, Combofix etc. but the issue of taskbar color change due to which I loose my internet connection still exist:angry:<br />
<br />
Here are all log reports: <br />
<br />
<span style="font-weight:bold">Logfile of Trend Micro HijackThis v2.0.2</span><br />
Scan saved at 3:44:30 AM, on 11/5/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe<br />
C:\WINDOWS\system32\RUNDLL32.EXE<br />
C:\Program Files\Alwil Software\Avast4\ashDisp.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
D:\My IMP. Program files\Capture\Capture.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe<br />
C:\Program Files\Intel\IDU\awServ.exe<br />
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe<br />
C:\WINDOWS\system32\fsproflt.exe<br />
E:\Program Files\UGS\Imageware Licensing\12.00.000\bin\lmgrd.exe<br />
E:\Program Files\UGS\Imageware Licensing\12.00.000\bin\iwlmd.exe<br />
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://search.conduit.com?SearchSource=10&amp;ctid=CT1978305" target="_blank">http://search.conduit.com?SearchSour...ctid=CT1978305</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
O2 - BHO: (no name) - AutorunsDisabled - (no file)<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll<br />
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GrooveShellExtensions.dll<br />
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll<br />
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll<br />
O4 - HKLM\..\Run: [DiskeeperSystray] &quot;C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe&quot;<br />
O4 - HKLM\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe<br />
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [avast!] &quot;C:\Program Files\Alwil Software\Avast4\ashDisp.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKCU\..\Run: [NVIDIA nTune] &quot;C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe&quot; clear<br />
O4 - HKCU\..\Run: [Capture .NET] &quot;D:\My IMP. Program files\Capture\Capture.exe&quot;<br />
O4 - Startup: AutorunsDisabled<br />
O4 - Global Startup: AutorunsDisabled<br />
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present<br />
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present<br />
O8 - Extra context menu item: Add to Google Photos Screensa&amp;ver - res://C:\WINDOWS\system32\GPhotos.scr/200<br />
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - AutorunsDisabled - (no file)<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O16 - DPF: {2EDF75C0-5ABD-49f9-BAB6-220476A32034} (System Requirements Lab) - <a rel="nofollow" class="t" href="http://intel-drv-cdn.systemrequirementslab.com/multi/bin/sysreqlab_srlx.cab" target="_blank">http://intel-drv-cdn.systemrequireme...eqlab_srlx.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a rel="nofollow" class="t" href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1249759713703" target="_blank">http://update.microsoft.com/microsof...?1249759713703</a><br />
O17 - HKLM\System\CCS\Services\Tcpip\..\{EB49111A-80B5-405E-9E80-12F82DCD5FA6}: NameServer = 203.192.198.7,203.192.198.5<br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GrooveSystemServices.dll<br />
O20 - AppInit_DLLs: C:\WINDOWS\system32\acaptuser32.dll<br />
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe<br />
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
O23 - Service: Admin Works Agent X8 (AWService) - OSA Technologies Inc., An Avocent Company - C:\Program Files\Intel\IDU\awServ.exe<br />
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: FSPro Filter Service (fsproflt) - FSPro Labs - C:\WINDOWS\system32\fsproflt.exe<br />
O23 - Service: Imageware 12 License Manager - GLOBEtrotter Software Inc. - E:\Program Files\UGS\Imageware Licensing\12.00.000\bin\lmgrd.exe<br />
O23 - Service: InstallShield Licensing Service - Macrovision                                                     - C:\Program Files\Common Files\InstallShield Shared\Service\InstallShield Licensing Service.exe<br />
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - E:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe<br />
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe<br />
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe<br />
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe<br />
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe<br />
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
O23 - Service: ZL - Unknown owner - C:\DOCUME~1\NAVNATH\LOCALS~1\Temp\ZL.exe (file missing)<br />
<br />
--<br />
End of file - 8835 bytes<br />
<br />
<br />
<br />
<br />
<span style="font-weight:bold">ComboFix 09-11-04.02</span> - NAVNATH 11/05/2009  0:13.1.2 - NTFSx86<br />
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.2038.1543 [GMT 5.5:30]<br />
Running from: c:\documents and settings\NAVNATH\Desktop\ComboFix.exe<br />
AV: avast! antivirus 4.8.1356 [VPS 091103-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}<br />
.<br />
<br />
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br />
<br />
C:\Documents<br />
C:\Recycle<br />
c:\recycler\S-1-5-21-0306782404-0403296150-468932291-1673<br />
c:\recycler\S-1-5-21-1690392628-9639070320-204829838-7964<br />
c:\recycler\S-1-5-21-4340829974-8025113630-805332040-7178<br />
c:\recycler\S-1-5-21-4404245323-2510926375-959924715-4889<br />
c:\recycler\S-1-5-21-4526544003-9131078385-546885970-0446<br />
c:\recycler\S-1-5-21-4642916222-7686821538-614090642-3753<br />
c:\recycler\S-1-5-21-5504431452-5768450549-560062291-7959<br />
c:\recycler\S-1-5-21-7762691254-4116871461-074637373-8948<br />
c:\recycler\S-1-5-21-7804478225-5844174979-977742103-8620<br />
c:\recycler\S-1-5-21-7872991201-0422058234-947134708-6514<br />
c:\recycler\S-1-5-21-796845957-1614895754-682003330-500<br />
c:\recycler\S-1-5-21-8752049922-5241934417-628490504-9581<br />
c:\windows\system32\28463<br />
c:\windows\system32\tmp1.tmp<br />
c:\windows\system32\tmp2.tmp<br />
c:\windows\system32\tmp3.tmp<br />
c:\windows\system32\tmp61.tmp<br />
c:\windows\system32\tmp62.tmp<br />
<br />
.<br />
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br />
<br />
-------\Legacy_OREANS32<br />
-------\Service_oreans32<br />
<br />
<br />
(((((((((((((((((((((((((   Files Created from 2009-10-04 to 2009-11-04  )))))))))))))))))))))))))))))))<br />
.<br />
<br />
2009-11-04 14:40 . 2009-11-04 14:40	--------	d-----w-	c:\documents and settings\NAVNATH\Application Data\Malwarebytes<br />
2009-11-04 14:40 . 2009-09-10 09:24	38224	----a-w-	c:\windows\system32\drivers\mbamswissarmy.sys<br />
2009-11-04 14:39 . 2009-11-04 14:39	--------	d-----w-	c:\documents and settings\All Users\Application Data\Malwarebytes<br />
2009-11-04 14:39 . 2009-09-10 09:23	19160	----a-w-	c:\windows\system32\drivers\mbam.sys<br />
2009-11-02 20:43 . 2009-11-02 20:43	--------	d-----w-	c:\windows\system32\wbem\Repository<br />
2009-11-02 13:16 . 2009-11-02 13:16	319488	----a-w-	c:\windows\HideWin.exe<br />
2009-11-01 13:56 . 2009-11-01 14:05	--------	d-----w-	c:\program files\SystemRequirementsLab<br />
2009-10-31 19:19 . 2009-10-31 19:45	--------	d-----w-	c:\documents and settings\NAVNATH\Application Data\GetRightToGo<br />
2009-10-30 00:17 . 2009-10-30 00:11	93360	----a-w-	c:\windows\system32\drivers\SBREDrv.sys<br />
2009-10-30 00:17 . 2009-10-30 00:17	151392	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\DownloadGuardBHO.dll<br />
2009-10-30 00:17 . 2009-10-30 00:17	428936	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\DownloadGuard.exe<br />
2009-10-30 00:17 . 2009-10-30 00:17	862040	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe<br />
2009-10-30 00:17 . 2009-10-30 00:17	554280	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\sbap.dll<br />
2009-10-30 00:17 . 2009-10-30 00:17	15880	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe<br />
2009-10-30 00:17 . 2009-10-30 00:17	206944	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll<br />
2009-10-30 00:17 . 2009-10-30 00:17	390288	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll<br />
2009-10-30 00:17 . 2009-10-30 00:17	537576	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\aawapi.dll<br />
2009-10-30 00:17 . 2009-10-30 00:17	212480	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\VipreBridge.dll<br />
2009-10-30 00:16 . 2009-10-30 00:17	283944	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Vipre.dll<br />
2009-10-30 00:16 . 2009-10-30 00:16	370744	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll<br />
2009-10-30 00:16 . 2009-10-30 00:16	163728	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll<br />
2009-10-30 00:16 . 2009-10-30 00:16	194104	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Savapibridge.dll<br />
2009-10-30 00:16 . 2009-10-30 00:16	1223976	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBTE.dll<br />
2009-10-30 00:16 . 2009-10-30 00:16	242984	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBRE.dll<br />
2009-10-30 00:13 . 2009-10-30 00:14	5908024	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll<br />
2009-10-30 00:13 . 2009-10-30 00:13	327000	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll<br />
2009-10-30 00:13 . 2009-10-30 00:13	87496	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll<br />
2009-10-30 00:13 . 2009-10-30 00:13	933120	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll<br />
2009-10-30 00:13 . 2009-10-30 00:13	640608	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AutoLaunch.exe<br />
2009-10-30 00:11 . 2009-10-30 00:11	815760	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe<br />
2009-10-30 00:11 . 2009-10-30 00:11	822904	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe<br />
2009-10-30 00:11 . 2009-10-30 00:11	1638104	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe<br />
2009-10-30 00:11 . 2009-10-30 00:11	788368	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe<br />
2009-10-30 00:11 . 2009-10-30 00:11	1179232	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe<br />
2009-10-30 00:11 . 2009-10-30 00:11	93360	----a-w-	c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\SBREDrv.sys<br />
2009-10-30 00:08 . 2009-10-03 08:15	2924848	-c--a-w-	c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe<br />
2009-10-27 08:52 . 2009-10-27 08:52	--------	d-----w-	c:\documents and settings\NAVNATH\Application Data\OpenWith.org Cache<br />
2009-10-25 22:43 . 2009-10-30 00:08	--------	dc-h--w-	c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}<br />
2009-10-15 10:20 . 2009-10-15 10:20	--------	d-----w-	c:\documents and settings\NAVNATH\Local Settings\Application Data\Activision<br />
2009-10-15 10:16 . 2009-10-21 16:12	138464	----a-w-	c:\windows\system32\drivers\PnkBstrK.sys<br />
2009-10-15 10:16 . 2009-10-15 10:16	22328	----a-w-	c:\documents and settings\NAVNATH\Application Data\PnkBstrK.sys<br />
2009-10-15 10:16 . 2009-10-21 16:12	111928	----a-w-	c:\windows\system32\PnkBstrB.exe<br />
2009-10-15 10:16 . 2009-11-03 07:43	66872	----a-w-	c:\windows\system32\PnkBstrA.exe<br />
2009-10-15 10:16 . 2009-10-15 10:16	682280	----a-w-	c:\windows\system32\pbsvc.exe<br />
<br />
.<br />
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br />
2009-11-04 18:48 . 2008-12-12 08:51	664	----a-w-	c:\windows\system32\d3d9caps.dat<br />
2009-11-01 18:23 . 2008-07-10 17:03	--------	d-----w-	c:\program files\Intel<br />
2009-11-01 11:22 . 2009-09-19 19:17	--------	d-----w-	c:\documents and settings\NAVNATH\Application Data\Azureus<br />
2009-10-31 19:54 . 2008-07-10 17:11	--------	d--h--w-	c:\program files\InstallShield Installation Information<br />
2009-10-31 19:53 . 2009-08-11 18:55	--------	d-----w-	c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters<br />
2009-10-31 18:34 . 2009-09-19 19:16	--------	d-----w-	c:\program files\Vuze<br />
2009-10-30 00:17 . 2009-02-08 09:47	15880	----a-w-	c:\windows\system32\lsdelete.exe<br />
2009-10-30 00:08 . 2009-02-06 18:01	--------	d-----w-	c:\documents and settings\All Users\Application Data\Lavasoft<br />
2009-10-21 16:59 . 2009-09-10 00:31	--------	d-----w-	c:\documents and settings\All Users\Application Data\Autorun Eater<br />
2009-10-02 10:14 . 2009-10-02 10:14	--------	d-----w-	c:\documents and settings\All Users\Application Data\PC Suite<br />
2009-10-02 10:14 . 2009-10-02 10:14	--------	d-----w-	c:\documents and settings\NAVNATH\Application Data\PC Suite<br />
2009-10-02 10:09 . 2009-10-02 10:09	--------	d-----w-	c:\program files\Samsung<br />
2009-10-02 10:08 . 2009-10-02 10:08	--------	d-----w-	c:\program files\PC Connectivity Solution<br />
2009-10-02 10:08 . 2009-10-02 10:08	--------	d-----w-	c:\program files\DIFX<br />
2009-10-02 10:08 . 2009-10-02 10:08	--------	d-----w-	c:\documents and settings\NAVNATH\Application Data\Samsung<br />
2009-10-02 10:08 . 2009-10-02 10:08	--------	d-----w-	c:\program files\MarkAny<br />
2009-09-24 06:25 . 2009-09-24 06:25	184320	----a-w-	c:\windows\system32\Ncs2Setp.dll<br />
2009-09-24 06:13 . 2009-09-24 06:13	768632	----a-w-	c:\windows\system32\ncs2dmix.dll<br />
2009-09-24 06:12 . 2009-09-24 06:12	539256	----a-w-	c:\windows\system32\accesor.dll<br />
2009-09-24 05:50 . 2009-09-24 05:50	141944	----a-w-	c:\windows\system32\ncs2instutility.dll<br />
2009-09-24 05:39 . 2009-09-24 05:39	1677944	----a-w-	c:\windows\system32\ncscolib.dll<br />
2009-09-23 12:55 . 2009-02-08 08:49	64288	----a-w-	c:\windows\system32\drivers\Lbd.sys<br />
2009-09-21 08:50 . 2009-09-21 08:50	28632	----a-w-	c:\windows\system32\drivers\iqvw32.sys<br />
2009-09-19 19:17 . 2009-09-19 19:17	--------	d-----w-	c:\documents and settings\All Users\Application Data\Azureus<br />
2009-09-19 19:16 . 2009-09-19 19:16	--------	d-----w-	c:\program files\Common Files\i4j_jres<br />
2009-09-19 18:38 . 2009-08-27 18:32	--------	d-----w-	c:\documents and settings\NAVNATH\Application Data\uTorrent<br />
2009-09-15 10:59 . 2009-08-03 10:29	1279968	----a-w-	c:\windows\system32\aswBoot.exe<br />
2009-09-15 10:56 . 2009-08-03 10:29	93424	----a-w-	c:\windows\system32\drivers\aswmon.sys<br />
2009-09-15 10:56 . 2009-08-03 10:29	94160	----a-w-	c:\windows\system32\drivers\aswmon2.sys<br />
2009-09-15 10:55 . 2009-08-03 10:29	114768	----a-w-	c:\windows\system32\drivers\aswSP.sys<br />
2009-09-15 10:55 . 2009-08-03 10:29	20560	----a-w-	c:\windows\system32\drivers\aswFsBlk.sys<br />
2009-09-15 10:54 . 2009-08-03 10:29	52368	----a-w-	c:\windows\system32\drivers\aswTdi.sys<br />
2009-09-15 10:54 . 2009-08-03 10:29	23152	----a-w-	c:\windows\system32\drivers\aswRdr.sys<br />
2009-09-15 10:53 . 2009-08-03 10:29	27408	----a-w-	c:\windows\system32\drivers\aavmker4.sys<br />
2009-09-15 10:53 . 2009-08-03 10:29	97480	----a-w-	c:\windows\system32\AvastSS.scr<br />
2009-09-10 01:15 . 2009-09-10 01:15	--------	d-----w-	c:\documents and settings\NAVNATH\Application Data\Thinstall<br />
2009-09-10 00:31 . 2009-09-10 00:31	--------	d-----w-	c:\program files\Autorun Eater<br />
2009-09-09 00:16 . 2009-09-09 00:16	--------	d-----w-	c:\program files\Common Files\xing shared<br />
2009-09-09 00:16 . 2009-09-09 00:15	--------	d-----w-	c:\program files\Common Files\Real<br />
2009-09-09 00:15 . 2006-07-11 13:05	348160	----a-w-	c:\windows\system32\msvcr71.dll<br />
2009-09-09 00:15 . 2009-09-09 00:15	--------	d-----w-	c:\program files\Real<br />
2009-09-06 20:39 . 2009-09-06 20:34	--------	d-----w-	c:\documents and settings\All Users\Application Data\Yahoo! Companion<br />
2009-09-06 20:37 . 2009-09-06 20:31	--------	d-----w-	c:\documents and settings\All Users\Application Data\Yahoo!<br />
2009-09-06 20:34 . 2009-09-06 20:31	--------	d-----w-	c:\program files\Yahoo!<br />
2009-09-06 20:34 . 2009-09-06 20:34	--------	d-----w-	c:\documents and settings\NAVNATH\Application Data\Yahoo!<br />
2009-09-06 04:33 . 2009-06-01 18:29	--------	d-----w-	c:\program files\Google<br />
2009-08-18 11:46 . 2008-07-14 16:13	831488	----a-w-	c:\windows\RtlExUpd.dll<br />
2009-08-14 11:14 . 2009-08-14 11:14	6379936	----a-w-	c:\windows\screensaver_radiance.exe<br />
2009-08-14 11:14 . 2009-08-14 11:14	28672	----a-w-	c:\windows\gscr.dll<br />
2009-08-14 11:14 . 2009-08-14 11:14	127904	----a-w-	c:\windows\screensaver_radiance.scr<br />
2009-08-13 14:13 . 2009-08-11 18:57	54	----a-w-	c:\windows\system32\rp_stats.dat<br />
2009-08-13 14:13 . 2009-08-11 18:57	39	----a-w-	c:\windows\system32\rp_rules.dat<br />
2009-08-08 19:50 . 2009-08-08 19:50	3317272	----a-w-	c:\documents and settings\All Users\Application Data\SpeedBit\DAP\Offers\VA3_DapSo.exe<br />
2009-08-08 19:46 . 2009-08-08 19:46	50688	----a-w-	c:\windows\system32\wbhelp2.dll<br />
2008-07-10 18:08 . 2008-07-10 18:08	23	--sha-w-	c:\windows\system32\adbfbea2_d.dll<br />
.<br />
<br />
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br />
.<br />
*Note* empty entries &amp; legit default entries are not shown <br />
REGEDIT4<br />
<br />
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />
&quot;NVIDIA nTune&quot;=&quot;c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe&quot; [2007-07-03 81920]<br />
&quot;Capture .NET&quot;=&quot;d:\my imp. program files\Capture\Capture.exe&quot; [2009-03-24 790528]<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />
&quot;DiskeeperSystray&quot;=&quot;c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe&quot; [2006-06-07 319488]<br />
&quot;TaskSwitchXP&quot;=&quot;c:\program files\TaskSwitchXP\TaskSwitchXP.exe&quot; [2007-05-09 106904]<br />
&quot;NvCplDaemon&quot;=&quot;c:\windows\system32\NvCpl.dll&quot; [2009-02-18 13680640]<br />
&quot;NvMediaCenter&quot;=&quot;c:\windows\system32\NvMcTray.dll&quot; [2009-02-18 86016]<br />
&quot;avast!&quot;=&quot;c:\program files\Alwil Software\Avast4\ashDisp.exe&quot; [2009-09-15 81000]<br />
&quot;QuickTime Task&quot;=&quot;c:\program files\QuickTime\qttask.exe&quot; [2008-09-06 413696]<br />
&quot;AlcWzrd&quot;=&quot;ALCWZRD.EXE&quot; - c:\windows\ALCWZRD.EXE [2008-06-19 2808832]<br />
&quot;nwiz&quot;=&quot;nwiz.exe&quot; - c:\windows\system32\nwiz.exe [2009-02-18 1657376]<br />
<br />
c:\documents and settings\NAVNATH\Start Menu\Programs\Startup\AutorunsDisabled<br />
SolidWorks Task Scheduler Engine.lnk - c:\program files\SolidWorks\swScheduler\swBOEngine.exe [2007-9-9 488728]<br />
<br />
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]<br />
&quot;NoResolveTrack&quot;= 1 (0x1)<br />
&quot;NoFileAssociate&quot;= 0 (0x0)<br />
<br />
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]<br />
&quot;NoRecentDocsNetHood&quot;= 01000000<br />
&quot;NoStrCmpLogical&quot;= 01000000<br />
&quot;NoSMMyPictures&quot;= 01000000<br />
<br />
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]<br />
&quot;AppInit_DLLs&quot;=c:\windows\system32\acaptuser32.dll<br />
<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]<br />
@=&quot;Service&quot;<br />
<br />
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Application Data^Microsoft^Shortcuts^icwsetup.exe]<br />
path=c:\documents and settings\All Users\Application Data\Microsoft\Shortcuts\icwsetup.exe<br />
backup=c:\windows\pss\icwsetup.exeCommon Startup<br />
<br />
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]<br />
&quot;PLFlash DeviceIoControl Service&quot;=2 (0x2)<br />
&quot;wuauserv&quot;=2 (0x2)<br />
&quot;gusvc&quot;=3 (0x3)<br />
<br />
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]<br />
&quot;EnableFirewall&quot;= 0 (0x0)<br />
&quot;DisableNotifications&quot;= 1 (0x1)<br />
<br />
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br />
&quot;%windir%\\system32\\sessmgr.exe&quot;=<br />
&quot;c:\\Program Files\\Autodesk\\3dsMax8\\3dsmax.exe&quot;=<br />
&quot;c:\\Program Files\\Autodesk\\backburner\\monitor.exe&quot;=<br />
&quot;c:\\Program Files\\Autodesk\\backburner\\manager.exe&quot;=<br />
&quot;c:\\Program Files\\Autodesk\\backburner\\server.exe&quot;=<br />
&quot;c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE&quot;=<br />
&quot;c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE&quot;=<br />
&quot;c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE&quot;=<br />
&quot;e:\\Program Files\\uTorrent\\uTorrent.exe&quot;=<br />
&quot;c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe&quot;=<br />
&quot;c:\\Program Files\\Vuze\\Azureus.exe&quot;=<br />
&quot;e:\\Program Files\\Samsung\\Samsung New PC Studio\\npsasvr.exe&quot;=<br />
&quot;e:\\Program Files\\Samsung\\Samsung New PC Studio\\npsvsvr.exe&quot;=<br />
<br />
R0 FSProFilter;FSPro File Filter;c:\windows\system32\drivers\FSPFltd.sys [3/19/2009 5:52 PM 43792]<br />
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2/8/2009 2:19 PM 64288]<br />
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [8/3/2009 3:59 PM 114768]<br />
R1 LUMDriver;LUMDriver;c:\windows\system32\drivers\LUMDriver.sys [4/24/2007 10:22 PM 16688]<br />
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [8/3/2009 3:59 PM 20560]<br />
R2 fsproflt;FSPro Filter Service;c:\windows\system32\fsproflt.exe [3/19/2009 5:52 PM 73392]<br />
R2 Imageware 12 License Manager;Imageware 12 License Manager;e:\program files\UGS\Imageware Licensing\12.00.000\bin\lmgrd.exe [9/25/2002 2:40 AM 597504]<br />
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;e:\program files\Lavasoft\Ad-Aware\AAWService.exe [9/24/2009 4:47 PM 1179232]<br />
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [10/2/2009 3:38 PM 36608]<br />
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [11/7/2007 1:52 AM 34064]<br />
S3 ZL;ZL;c:\docume~1\NAVNATH\LOCALS~1\Temp\ZL.exe --&gt; c:\docume~1\NAVNATH\LOCALS~1\Temp\ZL.exe [?]<br />
S4 BBDemon;Backbone Service;&quot;e:\program files\Dassault Systemes\B17\intel_a\code\bin\CATSysDemon.exe&quot; -service --&gt; e:\program files\Dassault Systemes\B17\intel_a\code\bin\CATSysDemon.exe [?]<br />
S4 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [10/2/2009 3:38 PM 233472]<br />
S4 gupdate1ca20fd77090518;Google Update Service (gupdate1ca20fd77090518);c:\program files\Google\Update\GoogleUpdate.exe [8/20/2009 12:17 AM 133104]<br />
<br />
--- Other Services/Drivers In Memory ---<br />
<br />
*NewlyCreated* - MBR<br />
*Deregistered* - mbr<br />
.<br />
Contents of the 'Scheduled Tasks' folder<br />
<br />
2009-08-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job<br />
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-19 18:47]<br />
<br />
2009-08-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job<br />
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-19 18:47]<br />
<br />
2009-08-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-796845957-1614895754-682003330-1003Core.job<br />
- c:\documents and settings\NAVNATH\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-08 18:56]<br />
<br />
2009-08-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-796845957-1614895754-682003330-1003UA.job<br />
- c:\documents and settings\NAVNATH\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-08 18:56]<br />
.<br />
.<br />
------- Supplementary Scan -------<br />
.<br />
uStart Page = hxxp://search.conduit.com?SearchSource=10&amp;ctid=CT1978305<br />
uDefault_Search_URL = hxxp://www.google.com/ie<br />
uInternet Connection Wizard,ShellNext = iexplore<br />
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s<br />
IE: &amp;Clean Traces<br />
IE: &amp;Download with &amp;DAP<br />
IE: Add to Google Photos Screensa&amp;ver - c:\windows\system32\GPhotos.scr/200<br />
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
IE: Download &amp;all with DAP<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
TCP: {EB49111A-80B5-405E-9E80-12F82DCD5FA6} = 203.192.198.7,203.192.198.5<br />
DPF: {2EDF75C0-5ABD-49f9-BAB6-220476A32034} - hxxp://intel-drv-cdn.systemrequirementslab.com/multi/bin/sysreqlab_srlx.cab<br />
.<br />
- - - - ORPHANS REMOVED - - - -<br />
<br />
HKLM-Run-Internet Connection Wizard Setup Tool - c:\program files\Internet Explorer\Connection Wizard\icwsetup.exe<br />
HKLM-Run-NPSStartup - (no file)<br />
Notify-WgaLogon - (no file)<br />
AddRemove-{B52F8C4B-FE88-4B59-9B80-1C93669D7DEB}_is1 - c:\program files\OpenWith.org<br />
<br />
<br />
<br />
**************************************************************************<br />
<br />
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, <a rel="nofollow" class="t" href="http://www.gmer.net" target="_blank">http://www.gmer.net</a><br />
Rootkit scan 2009-11-05 00:18<br />
Windows 5.1.2600 Service Pack 2 NTFS<br />
<br />
scanning hidden processes ...  <br />
<br />
scanning hidden autostart entries ... <br />
<br />
scanning hidden files ...  <br />
<br />
scan completed successfully<br />
hidden files: 0<br />
<br />
**************************************************************************<br />
<br />
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, <a rel="nofollow" class="t" href="http://www.gmer.net" target="_blank">http://www.gmer.net</a><br />
<br />
device: opened successfully<br />
user: MBR read successfully<br />
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll &gt;&gt;UNKNOWN [0x89E3F1E8]&lt;&lt; <br />
kernel: MBR read successfully<br />
detected MBR rootkit hooks:<br />
\Driver\atapi -&gt; 0x89e3f1e8<br />
Warning: possible MBR rootkit infection !<br />
user &amp; kernel MBR OK <br />
Use &quot;Recovery Console&quot; command &quot;fixmbr&quot; to clear infection !<br />
<br />
**************************************************************************<br />
.<br />
--------------------- DLLs Loaded Under Running Processes ---------------------<br />
<br />
- - - - - - - &gt; 'explorer.exe'(3476)<br />
c:\windows\system32\nview.dll<br />
c:\windows\system32\PortableDeviceApi.dll<br />
c:\windows\system32\Audiodev.dll<br />
c:\windows\system32\WMVCore.DLL<br />
c:\windows\system32\WMASF.DLL<br />
c:\windows\system32\WPDShServiceObj.dll<br />
c:\windows\system32\PortableDeviceTypes.dll<br />
.<br />
------------------------ Other Running Processes ------------------------<br />
.<br />
c:\program files\Alwil Software\Avast4\aswUpdSv.exe<br />
c:\program files\Alwil Software\Avast4\ashServ.exe<br />
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe<br />
c:\program files\Intel\IDU\awServ.exe<br />
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe<br />
c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe<br />
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe<br />
c:\windows\system32\locator.exe<br />
c:\program files\Alwil Software\Avast4\ashMaiSv.exe<br />
c:\windows\system32\wbem\unsecapp.exe<br />
c:\program files\Alwil Software\Avast4\ashWebSv.exe<br />
c:\windows\system32\wscntfy.exe<br />
c:\windows\system32\RUNDLL32.EXE<br />
c:\windows\system32\rundll32.exe<br />
e:\program files\Lavasoft\Ad-Aware\AAWTray.exe<br />
.<br />
**************************************************************************<br />
.<br />
Completion time: 2009-11-04  0:20 - machine was rebooted<br />
ComboFix-quarantined-files.txt  2009-11-04 18:50<br />
<br />
Pre-Run: 17,365,811,200 bytes free<br />
Post-Run: 17,272,356,864 bytes free<br />
<br />
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe<br />
[boot loader]<br />
timeout=2<br />
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS<br />
[operating systems]<br />
c:\cmdcons\BOOTSECT.DAT=&quot;Microsoft Windows Recovery Console&quot; /cmdcons<br />
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS=&quot;Microsoft Windows XP Professional&quot; /noexecute=optin /fastdetect<br />
<br />
<br />
<br />
<br />
<span style="font-weight:bold">Malwarebytes' Anti-Malware 1.41</span><br />
Database version: 3099<br />
Windows 5.1.2600 Service Pack 2<br />
<br />
11/4/2009 8:59:07 PM<br />
mbam-log-2009-11-04 (20-59-07).txt<br />
<br />
Scan type: Full Scan (C:\|D:\|E:\|F:\|)<br />
Objects scanned: 333445<br />
Time elapsed: 44 minute(s), 9 second(s)<br />
<br />
Memory Processes Infected: 0<br />
Memory Modules Infected: 0<br />
Registry Keys Infected: 2<br />
Registry Values Infected: 0<br />
Registry Data Items Infected: 3<br />
Folders Infected: 1<br />
Files Infected: 7<br />
<br />
Memory Processes Infected:<br />
(No malicious items detected)<br />
<br />
Memory Modules Infected:<br />
(No malicious items detected)<br />
<br />
Registry Keys Infected:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28abc5c0-4fcb-11cf-aax5-21cx1c987224} (Generic.Bot.H) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DbgMgr (Malware.Trace) -&gt; Quarantined and deleted successfully.<br />
<br />
Registry Values Infected:<br />
(No malicious items detected)<br />
<br />
Registry Data Items Infected:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -&gt; Bad: (1) Good: (0) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -&gt; Bad: (1) Good: (0) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -&gt; Bad: (1) Good: (0) -&gt; Quarantined and deleted successfully.<br />
<br />
Folders Infected:<br />
C:\Recycle\P-1-3-64-8794238531-8742492-9897532 (Trojan.Agent) -&gt; Quarantined and deleted successfully.<br />
<br />
Files Infected:<br />
C:\Documents and Settings\NAVNATH\restorer64_a.exe (SpamTool.Agent) -&gt; Quarantined and deleted successfully.<br />
C:\System Volume Information\_restore{D480C6E8-D1B9-432F-BEE0-48857CFACC20}\RP448\A0145821.exe (SpamTool.Agent) -&gt; Quarantined and deleted successfully.<br />
C:\WINDOWS\system32\restorer64_a.exe (SpamTool.Agent) -&gt; Quarantined and deleted successfully.<br />
F:\System Volume Information\_restore{D480C6E8-D1B9-432F-BEE0-48857CFACC20}\RP442\A0143716.exe (Trojan.Downloader) -&gt; Quarantined and deleted successfully.<br />
C:\Recycle\P-1-3-64-8794238531-8742492-9897532\Desktop.ini (Trojan.Agent) -&gt; Quarantined and deleted successfully.<br />
C:\Documents and Settings\NAVNATH\Start Menu\Programs\Startup\zavupd32.exe (Trojan.Agent) -&gt; Quarantined and deleted successfully.<br />
C:\Documents and Settings\NAVNATH\Application Data\wiaserva.log (Malware.Trace) -&gt; Quarantined and deleted successfully.<br />
<br />
<br />
Hope expert here take some time to analyze these logs.<br />
<br />
Thank you.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>navnath.j84</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread236104.html</guid>
		</item>
		<item>
			<title>Firefox tabs keep popping up</title>
			<link>http://www.daniweb.com/forums/thread235859.html</link>
			<pubDate>Wed, 04 Nov 2009 05:27:59 GMT</pubDate>
			<description>Everytime I open my firefox browser additional tabs keep popping up.  Not just one or two, but 20.  when I try to close the tabs more keep popping up.  I have to close the entire browser in order to stop it.  Each tab is directed to the firefox help and support site.   
 
I also have the same...</description>
			<content:encoded><![CDATA[<div>Everytime I open my firefox browser additional tabs keep popping up.  Not just one or two, but 20.  when I try to close the tabs more keep popping up.  I have to close the entire browser in order to stop it.  Each tab is directed to the firefox help and support site.  <br />
<br />
I also have the same issues with internet explorer.  Everytime I open a browser, Windows Help and Support window keeps popping up. When I close the window it just keeps popping up.  When I use the task manager to close the process, it gives me an additional 10 seconds before the window pops up.  <br />
<br />
I thoroughly checked the F1 key...it's not stuck.  I don't know what to do...Please Help!!!  I have included the hijackthis log, Kapersky's online scan, malwarebytes log, and the unistall log.   The Dekard's system scanner seems to be down so I cannot provide that log.<br />
<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 2:14:15 PM, on 10/24/2009<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18828)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\System32\igfxtray.exe<br />
C:\Windows\System32\hkcmd.exe<br />
C:\Windows\System32\igfxpers.exe<br />
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe<br />
C:\Windows\system32\igfxsrvc.exe<br />
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe<br />
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe<br />
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\TOSHIBA\TECO\TEco.exe<br />
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe<br />
C:\Windows\System32\wpcumi.exe<br />
C:\Program Files\AVG\AVG8\avgtray.exe<br />
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe<br />
C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe<br />
C:\Program Files\IObit\IObit Security 360\is360tray.exe<br />
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Windows\system32\igfxext.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe<br />
C:\Windows\helppane.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Windows\system32\SearchProtocolHost.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = <a rel="nofollow" class="t" href="http://search.yahoo.com/search?fr=mcafee&amp;p=%s" target="_blank">http://search.yahoo.com/search?fr=mcafee&amp;p=%s</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br />
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br />
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe<br />
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE<br />
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe<br />
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe<br />
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [TWebCamera] &quot;%ProgramFiles%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe&quot; autorun<br />
O4 - HKLM\..\Run: [SmartFaceVWatcher] %ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe<br />
O4 - HKLM\..\Run: [Teco] &quot;%ProgramFiles%\TOSHIBA\TECO\Teco.exe&quot; /r<br />
O4 - HKLM\..\Run: [NDSTray.exe] &quot;C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe&quot;<br />
O4 - HKLM\..\Run: [cfFncEnabler.exe] &quot;C:\Program Files\TOSHIBA\ConfigFree\cfFncEnabler.exe&quot;<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe<br />
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [TPCHWMsg] %ProgramFiles%\TOSHIBA\TPHM\TPCHWMsg.exe<br />
O4 - HKLM\..\Run: [ToshibaServiceStation] C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe /hide:60<br />
O4 - HKLM\..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe<br />
O4 - HKLM\..\Run: [IObit Security 360] C:\Program Files\IObit\IObit Security 360\IS360tray.exe<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL<br />
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe<br />
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - <a rel="nofollow" class="t" href="http://download.divx.com/player/DivXBrowserPlugin.cab" target="_blank">http://download.divx.com/player/DivXBrowserPlugin.cab</a><br />
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - <a rel="nofollow" class="t" href="http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab" target="_blank">http://upload.facebook.com/controls/...Uploader55.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a rel="nofollow" class="t" href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O20 - AppInit_DLLs: avgrsstx.dll<br />
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL<br />
O23 - Service: McAfee Application Installer Cleanup (0261041256269811) (0261041256269811mcinstcleanup) - McAfee, Inc. - C:\Windows\TEMP\026104~1.EXE<br />
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe<br />
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: TOSHIBA Web Camera Service (camsvc) - TOSHIBA - C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe<br />
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe<br />
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe<br />
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe<br />
O23 - Service: IS360service - IObit - C:\Program Files\IObit\IObit Security 360\IS360srv.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe<br />
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe<br />
O23 - Service: TOSHIBA Modem region select service (RSELSVC) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\RSelect\RSelSvc.exe<br />
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe<br />
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe<br />
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe<br />
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe<br />
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe<br />
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe<br />
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe<br />
<br />
--<br />
End of file - 10587 bytes<br />
<br />
<br />
<br />
<br />
KASPERSKY ONLINE SCANNER<br />
<br />
Tuesday, November 3, 2009<br />
Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 2 (build 6002)<br />
Kaspersky Online Scanner version: 7.0.26.13<br />
Last database update: Wednesday, November 04, 2009 02:06:14<br />
Records in database: 3123431<br />
 <br />
 <br />
Scan settings <br />
scan using the following database extended <br />
Scan archives yes <br />
Scan e-mail databases yes <br />
 <br />
Scan area My Computer <br />
C:\<br />
D:\  <br />
 <br />
Scan statistics <br />
Objects scanned 128961 <br />
Threats found 0 <br />
Infected objects found 0 <br />
Suspicious objects found 0 <br />
Scan duration 01:28:20 <br />
<br />
No threats found. Scanned area is clean. <br />
Selected area has been scanned. <br />
<br />
<br />
<br />
<br />
<br />
Malwarebytes' Anti-Malware 1.41<br />
Database version: 3097<br />
Windows 6.0.6002 Service Pack 2<br />
<br />
11/3/2009 8:21:06 PM<br />
mbam-log-2009-11-03 (20-21-06).txt<br />
<br />
Scan type: Full Scan (C:\|)<br />
Objects scanned: 251060<br />
Time elapsed: 42 minute(s), 29 second(s)<br />
<br />
Memory Processes Infected: 0<br />
Memory Modules Infected: 0<br />
Registry Keys Infected: 0<br />
Registry Values Infected: 0<br />
Registry Data Items Infected: 0<br />
Folders Infected: 0<br />
Files Infected: 0<br />
<br />
Memory Processes Infected:<br />
(No malicious items detected)<br />
<br />
Memory Modules Infected:<br />
(No malicious items detected)<br />
<br />
Registry Keys Infected:<br />
(No malicious items detected)<br />
<br />
Registry Values Infected:<br />
(No malicious items detected)<br />
<br />
Registry Data Items Infected:<br />
(No malicious items detected)<br />
<br />
Folders Infected:<br />
(No malicious items detected)<br />
<br />
Files Infected:<br />
(No malicious items detected)<br />
<br />
<br />
Uninstall Log<br />
<br />
2007 Microsoft Office Suite Service Pack 1 (SP1)<br />
2007 Microsoft Office Suite Service Pack 1 (SP1)<br />
2007 Microsoft Office Suite Service Pack 1 (SP1)<br />
2007 Microsoft Office Suite Service Pack 1 (SP1)<br />
2007 Microsoft Office Suite Service Pack 1 (SP1)<br />
2007 Microsoft Office Suite Service Pack 1 (SP1)<br />
2007 Microsoft Office Suite Service Pack 1 (SP1)<br />
2007 Microsoft Office Suite Service Pack 1 (SP1)<br />
2007 Microsoft Office Suite Service Pack 1 (SP1)<br />
2007 Microsoft Office Suite Service Pack 1 (SP1)<br />
Acrobat.com<br />
Adobe AIR<br />
Adobe AIR<br />
Adobe Flash Player 10 ActiveX<br />
Adobe Flash Player 10 Plugin<br />
Adobe Reader 9.1.3<br />
AnswerWorks 5.0 English Runtime<br />
CCleaner (remove only)<br />
Compatibility Pack for the 2007 Office system<br />
ConvertHelper 2.2<br />
Direct DiscRecorder<br />
DivX Web Player<br />
DVD MovieFactory for TOSHIBA<br />
EOS USB WIA Driver<br />
HijackThis 2.0.2<br />
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)<br />
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)<br />
Intel PROSet Wireless<br />
Intel(R) Graphics Media Accelerator Driver<br />
Intel® Matrix Storage Manager<br />
IObit Security 360<br />
Java(TM) 6 Update 11<br />
K-Lite Mega Codec Pack 5.0.5<br />
Malwarebytes' Anti-Malware<br />
McAfee SiteAdvisor<br />
Microsoft .NET Framework 3.5 SP1<br />
Microsoft .NET Framework 3.5 SP1<br />
Microsoft Office Excel MUI (English) 2007<br />
Microsoft Office Home and Student 2007<br />
Microsoft Office Home and Student 2007<br />
Microsoft Office OneNote MUI (English) 2007<br />
Microsoft Office PowerPoint MUI (English) 2007<br />
Microsoft Office PowerPoint Viewer 2007 (English)<br />
Microsoft Office Proof (English) 2007<br />
Microsoft Office Proof (French) 2007<br />
Microsoft Office Proof (Spanish) 2007<br />
Microsoft Office Proofing (English) 2007<br />
Microsoft Office Shared MUI (English) 2007<br />
Microsoft Office Shared Setup Metadata MUI (English) 2007<br />
Microsoft Office Suite Activation Assistant<br />
Microsoft Office Word MUI (English) 2007<br />
Microsoft Visual C++ 2005 Redistributable<br />
Microsoft Works<br />
Mozilla Firefox (3.5.3)<br />
MSXML 4.0 SP2 (KB941833)<br />
MSXML 4.0 SP2 (KB954430)<br />
PartyPoker<br />
Picasa 3<br />
PlayReady PC runtime<br />
Quicken 2010<br />
Realtek 8136 8168 8169 Ethernet Driver<br />
Realtek High Definition Audio Driver<br />
Realtek USB 2.0 Card Reader<br />
Skype Launcher<br />
SUPERAntiSpyware Free Edition<br />
Synaptics Pointing Device Driver<br />
TOSHIBA Agreement Notification Utility<br />
Toshiba Application and Driver Installer<br />
TOSHIBA Assist<br />
TOSHIBA ConfigFree<br />
TOSHIBA Disc Creator<br />
TOSHIBA DVD PLAYER<br />
TOSHIBA eco Utility<br />
TOSHIBA eco Utility<br />
TOSHIBA Extended Tiles for Windows Mobility Center<br />
TOSHIBA Face Recognition<br />
TOSHIBA Face Recognition<br />
TOSHIBA Hardware Setup<br />
TOSHIBA HDD/SSD Alert<br />
TOSHIBA HDD/SSD Alert<br />
TOSHIBA Internal Modem Region Select Utility<br />
TOSHIBA PC Health Monitor<br />
Toshiba Quality Application<br />
TOSHIBA Recovery Disc Creator<br />
Toshiba Registration<br />
Toshiba Resources Page<br />
TOSHIBA SD Memory Utilities<br />
TOSHIBA Service Station<br />
TOSHIBA Software Modem<br />
TOSHIBA Speech System Applications<br />
TOSHIBA Speech System SR Engine(U.S.) Version1.0<br />
TOSHIBA Speech System TTS Engine(U.S.) Version1.0<br />
TOSHIBA Supervisor Password<br />
TOSHIBA Value Added Package<br />
TOSHIBA Web Camera Application<br />
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)<br />
Update for Office 2007 (KB946691)<br />
VC80CRTRedist - 8.0.50727.762<br />
WildTangent Games<br />
<br />
<br />
<br />
<br />
I hope you can help....Thanks</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>jsbrewer</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread235859.html</guid>
		</item>
		<item>
			<title><![CDATA[Shopica redirect I can't get rid of!!]]></title>
			<link>http://www.daniweb.com/forums/thread235751.html</link>
			<pubDate>Tue, 03 Nov 2009 20:07:50 GMT</pubDate>
			<description>I have thrown everything at the search redirect (most commonly takes me to shopica.com) I have found some things running everything anti-virus/spyware/malware I can at it.  PLease help!!  My hijack this is pasted below.  Thanks! 
 
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 3:00:39 PM,...</description>
			<content:encoded><![CDATA[<div>I have thrown everything at the search redirect (most commonly takes me to shopica.com) I have found some things running everything anti-virus/spyware/malware I can at it.  PLease help!!  My hijack this is pasted below.  Thanks!<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 3:00:39 PM, on 11/3/2009<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18828)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\RtHDVCpl.exe<br />
C:\Program Files\Spare Backup\SpareBackup.exe<br />
C:\Windows\System32\igfxtray.exe<br />
C:\Windows\System32\igfxpers.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br />
C:\Program Files\Symantec AntiVirus\VPTray.exe<br />
C:\Windows\system32\igfxsrvc.exe<br />
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe<br />
C:\Program Files\Pure Networks\Network Magic\nmapp.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Alwil Software\Avast4\ashDisp.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Windows\system32\hkcmd.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Windows\system32\igfxsrvc.exe<br />
C:\PROGRA~1\NYKO\GAMEPA~1\ngpmap.exe<br />
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe<br />
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe<br />
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe<br />
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe<br />
C:\Windows\Explorer.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.yahoo.com/" target="_blank">http://www.yahoo.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.gateway.com/g/startpage.html?Ch=Retail&amp;SubCH=nofound&amp;Br=GTW&amp;Loc=ENG_US&amp;Sys=DTP&amp;M=GT5620" target="_blank">http://www.gateway.com/g/startpage.h...s=DTP&amp;M=GT5620</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll<br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll<br />
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll<br />
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br />
O4 - HKLM\..\Run: [Spare Backup] &quot;C:\Program Files\Spare Backup\SpareBackup.exe&quot; /silent<br />
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [Skytel] Skytel.exe<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [ccApp] &quot;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&quot;<br />
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe<br />
O4 - HKLM\..\Run: [nmctxth] &quot;C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe&quot;<br />
O4 - HKLM\..\Run: [nmapp] &quot;C:\Program Files\Pure Networks\Network Magic\nmapp.exe&quot; -autorun -nosplash<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe<br />
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE<br />
O8 - Extra context menu item: &amp;AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll<br />
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe<br />
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br />
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe<br />
O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe<br />
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe<br />
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe<br />
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe<br />
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe<br />
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe<br />
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe<br />
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
<br />
--<br />
End of file - 8680 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>jw22</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread235751.html</guid>
		</item>
		<item>
			<title><![CDATA["...not a valid win32 app..."  HiJack This Log]]></title>
			<link>http://www.daniweb.com/forums/thread235747.html</link>
			<pubDate>Tue, 03 Nov 2009 19:50:06 GMT</pubDate>
			<description>Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 2:38:36 PM, on 11/3/2009 
Platform: Windows Vista SP2 (WinNT 6.00.1906) 
MSIE: Internet Explorer v8.00 (8.00.6001.18828) 
Boot mode: Normal 
 
Running processes: 
C:\Windows\system32\Dwm.exe 
C:\Windows\system32\taskeng.exe...</description>
			<content:encoded><![CDATA[<div>Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 2:38:36 PM, on 11/3/2009<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18828)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe<br />
C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe<br />
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe<br />
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe<br />
C:\Program Files\HP\QuickPlay\QPService.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Garmin\MyGarminAgent.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe<br />
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\Uniblue\ProcessQuickLink 2\ProcessQuickLink2.exe<br />
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe<br />
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Users\Stephen J Bailey\AppData\Roaming\CBS Interactive\CNET TechTracker\TechTracker.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE<br />
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Program Files\Hewlett-Packard\HP Advisor\SSDK04.exe<br />
C:\Users\Stephen J Bailey\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Stephen J Bailey\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://att.my.yahoo.com/" target="_blank">http://att.my.yahoo.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=73&amp;bd=Pavilion&amp;pf=laptop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...lion&amp;pf=laptop</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=73&amp;bd=Pavilion&amp;pf=laptop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...lion&amp;pf=laptop</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
R3 - URLSearchHook: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHot1.dll<br />
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll<br />
O2 - BHO: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHot1.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\hssie\HssIE.dll<br />
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O3 - Toolbar: &amp;RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll<br />
O3 - Toolbar: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHot1.dll<br />
O3 - Toolbar: &amp;Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll<br />
O3 - Toolbar: &amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe<br />
O4 - HKLM\..\Run: [SansaDispatch] C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe<br />
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe<br />
O4 - HKLM\..\Run: [QPService] &quot;C:\Program Files\HP\QuickPlay\QPService.exe&quot;<br />
O4 - HKLM\..\Run: [Google Desktop Search] &quot;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&quot; /startup<br />
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [MyGarminAgent] C:\Program Files\Garmin\MyGarminAgent.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe<br />
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden<br />
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKCU\..\Run: [Uniblue ProcessQuickLink 2] &quot;C:\Program Files\Uniblue\ProcessQuickLink 2\ProcessQuickLink2.exe&quot; /autostart<br />
O4 - HKCU\..\Run: [RoboForm] &quot;C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe&quot;<br />
O4 - HKCU\..\Run: [Google Update] &quot;C:\Users\Stephen J Bailey\AppData\Local\Google\Update\GoogleUpdate.exe&quot; /c<br />
O4 - HKCU\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\aro.exe -rem<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - Startup: CNET TechTracker.lnk = Stephen J Bailey\AppData\Roaming\CBS Interactive\CNET TechTracker\TechTracker.exe<br />
O4 - Startup: MemTurbo.lnk = C:\Program Files\MemTurbo 4\MemTurbo.exe<br />
O4 - Global Startup: Bluetooth.lnk = ?<br />
O4 - Global Startup: Event Reminder.lnk = C:\Program Files\PrintMaster Platinum 17\Remind.exe<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html<br />
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html<br />
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html<br />
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html<br />
O8 - Extra context menu item: Send image to &amp;Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm<br />
O8 - Extra context menu item: Send page to &amp;Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html<br />
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html<br />
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html<br />
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html<br />
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html<br />
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL<br />
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O13 - Gopher Prefix: <br />
O16 - DPF: Garmin Communicator Plug-In - <a rel="nofollow" class="t" href="https://my.garmin.com/mygarmin/m/GarminAxControl.CAB" target="_blank">https://my.garmin.com/mygarmin/m/GarminAxControl.CAB</a><br />
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - <a rel="nofollow" class="t" href="http://echat.bellsouth.net/sdccommon/download/tgctlcm.cab" target="_blank">http://echat.bellsouth.net/sdccommon...ad/tgctlcm.cab</a><br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - <a rel="nofollow" class="t" href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" target="_blank">http://upload.facebook.com/controls/...oUploader5.cab</a><br />
O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} (Hewlett-Packard Online Support Services) - <a rel="nofollow" class="t" href="https://h20364.www2.hp.com/CSMWeb/Customer/cabs/HPISDataManager.CAB" target="_blank">https://h20364.www2.hp.com/CSMWeb/Cu...ataManager.CAB</a><br />
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - <a rel="nofollow" class="t" href="http://lads.myspace.com/upload/MySpaceUploader1006.cab" target="_blank">http://lads.myspace.com/upload/MySpaceUploader1006.cab</a><br />
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - <a rel="nofollow" class="t" href="https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab" target="_blank">https://h20436.www2.hp.com/ediags/de...e/HPDEXAXO.cab</a><br />
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - <a rel="nofollow" class="t" href="http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab" target="_blank">http://h20270.www2.hp.com/ediags/gmn...tDetection.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - <a rel="nofollow" class="t" href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - <a rel="nofollow" class="t" href="http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-latest.cab" target="_blank">http://dlm.tools.akamai.com/dlmanage...vex-latest.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br />
O23 - Service: Google Update Service (gupdate1c9917e8702590f) (gupdate1c9917e8702590f) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe<br />
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe<br />
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
O23 - Service: Hotspot Shield Helper Service (HssSrv) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe<br />
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe<br />
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe<br />
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe<br />
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe<br />
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe<br />
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe<br />
<br />
--<br />
End of file - 16809 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>fishbait</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread235747.html</guid>
		</item>
		<item>
			<title>open source installer</title>
			<link>http://www.daniweb.com/forums/thread235668.html</link>
			<pubDate>Tue, 03 Nov 2009 13:44:12 GMT</pubDate>
			<description>Hi all, 
 
 
I am looking for an open source installer to install some application software (java based s/w programme) and i do not want to commit any sort of change in registry. 
 
The installer should perform following actions: 
 
1. License Terms: Accept/Reject selection by user 
2. User must...</description>
			<content:encoded><![CDATA[<div>Hi all,<br />
<br />
<br />
I am looking for an open source installer to install some application software (java based s/w programme) and i do not want to commit any sort of change in registry.<br />
<br />
The installer should perform following actions:<br />
<br />
1. License Terms: Accept/Reject selection by user<br />
2. User must select installation folder, default is c:\......\......<br />
3. Run a bat file/script to install mysql, activemq.<br />
4. Run a bat file/script to configure the toolset<br />
5. Install application as an independent platform <br />
6. Catch errors and display to user<br />
7. Display confirmation<br />
<br />
<br />
Please let me know if anyone has got any relevant information and or such installer. I have tried some like NSIS, GhostInstaller, Nvin installer, Witem installer etc. I would like to focus on open source java installers. If anyone has used any of them, I would welcome its reviews. Thanks in advance. <br />
<br />
<br />
Best regards.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>rajuchacha007</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread235668.html</guid>
		</item>
		<item>
			<title>Please Help: url.urtbk,vundo,artemis!</title>
			<link>http://www.daniweb.com/forums/thread235561.html</link>
			<pubDate>Tue, 03 Nov 2009 05:12:50 GMT</pubDate>
			<description><![CDATA[Hi, 
 
I am running Microsoft Windows XP Media Center Edition Version 2002 Service Pack 2.  I am also running McAfee Security Center.  I was running Internet Explorer 7 then recently switched to IE8 then switched to Mozilla Firefox.  I then started getting  "artemis!..." and "vundo..." quarantine...]]></description>
			<content:encoded><![CDATA[<div>Hi,<br />
<br />
I am running Microsoft Windows XP Media Center Edition Version 2002 Service Pack 2.  I am also running McAfee Security Center.  I was running Internet Explorer 7 then recently switched to IE8 then switched to Mozilla Firefox.  I then started getting  &quot;artemis!...&quot; and &quot;vundo...&quot; quarantine messages intermittently and after scans by McAfee.  I thought perhaps that it was related to the web browser change and so I switched back to IE 7, but I am still getting these messages.  I have run McAfee scan numerous times and it quarantines both &quot;artemis!...&quot; and &quot;vundo...&quot; however it continues to show up even after it is removed.  <br />
<br />
Also, recently, IE7 would start numerous new tabs on its own.  The new tabs are empty pages but have &quot;url.urtbk...&quot; on the address bar.  IE7 would  also close/exit without warning and pop-ups would appear out of nowhere even though the pop-up blocker is enabled.<br />
<br />
Reading some threads on the internet, I tried to download malwarebytes anti-malware, however, an error message at the end of the installation process comes up and I am unable to start the program. <br />
<br />
I aplogize that my knowledge on this material is limited but I would really appreciate any help/advice/suggestions on how I could clean this up and also on how I could prevent this from happening again.<br />
<br />
Thank you,<br />
Gerard</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>gdecastro3</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread235561.html</guid>
		</item>
		<item>
			<title>can anybody help?????????</title>
			<link>http://www.daniweb.com/forums/thread235425.html</link>
			<pubDate>Mon, 02 Nov 2009 18:04:44 GMT</pubDate>
			<description>hi all, i am having trouble wit my pc its gone so slow and also i keep getting a lot of bsod crashes. if i reboot my pc will also not come back on sometimes. here is my hijack this log. any advice/help would be greatly appreciated 
 
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 20:27:16,...</description>
			<content:encoded><![CDATA[<div>hi all, i am having trouble wit my pc its gone so slow and also i keep getting a lot of bsod crashes. if i reboot my pc will also not come back on sometimes. here is my hijack this log. any advice/help would be greatly appreciated<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 20:27:16, on 01/11/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\Motive\McciCMService.exe<br />
C:\WINDOWS\System32\nvsvc32.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\SOUNDMAN.EXE<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe<br />
C:\Program Files\uTorrent\uTorrent.exe<br />
C:\Program Files\PeerGuardian2\pg2.exe<br />
C:\Program Files\3\3Connect\AutoUpdateSrv.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = <a rel="nofollow" class="t" href="http://uk.red.clientapps.yahoo.com/c...o/bt_side.html" target="_blank">http://uk.red.clientapps.yahoo.com/c...o/bt_side.html</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a rel="nofollow" class="t" href="http://uk.red.clientapps.yahoo.com/c...o/bt_side.html" target="_blank">http://uk.red.clientapps.yahoo.com/c...o/bt_side.html</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = <a rel="nofollow" class="t" href="http://uk.red.clientapps.yahoo.com/c...rch.yahoo.com/" target="_blank">http://uk.red.clientapps.yahoo.com/c...rch.yahoo.com/</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =<br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &quot;C:\Program Files\Outlook Express\msimn.exe&quot; //mailurl:mailto:melissa_x_15_x@hotmaiil.comm<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br />
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - (no file)<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll<br />
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - (no file)<br />
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll<br />
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br />
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br />
O4 - HKLM\..\Run: [PAC207_Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe<br />
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent<br />
O4 - HKLM\..\Run: [ccApp] &quot;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&quot;<br />
O4 - HKLM\..\Run: [osCheck] &quot;C:\Program Files\Norton 360\osCheck.exe&quot;<br />
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] &quot;C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe&quot;<br />
O4 - HKCU\..\Run: [uTorrent] &quot;C:\Program Files\uTorrent\uTorrent.exe&quot;<br />
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')<br />
O4 - Global Startup: Update Agent.lnk = ?<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - <a rel="nofollow" class="t" href="https://support.microsoft.com/OAS/ActiveX/MSDcode.cab" target="_blank">https://support.microsoft.com/OAS/ActiveX/MSDcode.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a rel="nofollow" class="t" href="http://www.update.microsoft.com/wind...?1220611311186" target="_blank">http://www.update.microsoft.com/wind...?1220611311186</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a rel="nofollow" class="t" href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)<br />
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)<br />
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe<br />
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE<br />
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe<br />
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe<br />
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe<br />
<br />
--<br />
End of file - 7910 bytes<br />
<br />
thanks</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>rob247</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread235425.html</guid>
		</item>
		<item>
			<title>Any help you can provide would be greatly appreciated...</title>
			<link>http://www.daniweb.com/forums/thread235209.html</link>
			<pubDate>Mon, 02 Nov 2009 02:19:13 GMT</pubDate>
			<description>I am not so computer savvy -- just enough to be dangerous to myself.  My computer locked up when I upgraded to Internet Explorer 8, so I resorted to reinstalling the original system disks.  I am fine running Mozilla, but I am still locking up in Internet Explorer.  I have run a Hijackthis log, and...</description>
			<content:encoded><![CDATA[<div>I am not so computer savvy -- just enough to be dangerous to myself.  My computer locked up when I upgraded to Internet Explorer 8, so I resorted to reinstalling the original system disks.  I am fine running Mozilla, but I am still locking up in Internet Explorer.  I have run a Hijackthis log, and am hoping someone might see what is causing my problems.  Here is my log:<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 9:08:02 PM, on 11/1/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\eHome\ehRecvr.exe<br />
C:\WINDOWS\eHome\ehSched.exe<br />
C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe<br />
C:\WINDOWS\ehome\ehtray.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe<br />
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe<br />
C:\Program Files\firedog advisor\faAgnt.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe<br />
C:\WINDOWS\eHome\ehmsas.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\HP\KBD\KBD.EXE<br />
C:\WINDOWS\SOUNDMAN.EXE<br />
C:\WINDOWS\ALCMTR.EXE<br />
C:\WINDOWS\ALCWZRD.EXE<br />
c:\windows\system\hpsysdrv.exe<br />
C:\Program Files\Java\jre1.5.0\bin\jusched.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br />
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe<br />
C:\Program Files\Microsoft Windows OneCare Live\winss.exe<br />
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\WINDOWS\system32\SearchIndexer.exe<br />
C:\WINDOWS\system32\SearchProtocolHost.exe<br />
C:\Program Files\Windows Desktop Search\WindowsSearch.exe<br />
C:\Documents and Settings\HP_Administrator.KARI\My Documents\Downloads\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=Q405&amp;bd=pavilion&amp;pf=desktop&amp;parm1=seconduser" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...rm1=seconduser</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iesearch&amp;locale=EN_US&amp;c=Q405&amp;bd=pavilion&amp;pf=desktop&amp;parm1=seconduser" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...rm1=seconduser</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.yahoo.com/" target="_blank">http://www.yahoo.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a rel="nofollow" class="t" href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iesearch&amp;locale=EN_US&amp;c=Q405&amp;bd=pavilion&amp;pf=desktop&amp;parm1=seconduser" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...rm1=seconduser</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll<br />
O3 - Toolbar: &amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll<br />
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe<br />
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe<br />
O4 - HKLM\..\Run: [HPBootOp] &quot;C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe&quot; /run<br />
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe<br />
O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;  -osboot<br />
O4 - HKLM\..\Run: [OneCareUI] &quot;C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe&quot;<br />
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br />
O4 - HKCU\..\Run: [firedogadvisor] &quot;C:\Program Files\firedog advisor\faAgnt.exe&quot; /startup<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKUS\S-1-5-21-335469381-2751086778-1406216904-500\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Administrator')<br />
O4 - HKUS\S-1-5-21-335469381-2751086778-1406216904-500\..\Run: [firedogadvisor] &quot;C:\Program Files\firedog advisor\faAgnt.exe&quot; /startup (User 'Administrator')<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe<br />
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm<br />
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - <a rel="nofollow" class="t" href="http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab" target="_blank">http://h20270.www2.hp.com/ediags/gmn...Detection2.cab</a><br />
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
<br />
--<br />
End of file - 7192 bytes<br />
<br />
<br />
Thanks for any help you can provide.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>karime2thestars</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread235209.html</guid>
		</item>
		<item>
			<title>newbie in need of help!</title>
			<link>http://www.daniweb.com/forums/thread235162.html</link>
			<pubDate>Sun, 01 Nov 2009 20:27:49 GMT</pubDate>
			<description>hi all, i am having trouble wit my pc its gone so slow and also i keep getting a lot of bsod crashes. if i reboot my pc will also not come back on sometimes. here is my hijack this log. any advice/help would be greatly appreciated 
 
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 20:27:16,...</description>
			<content:encoded><![CDATA[<div>hi all, i am having trouble wit my pc its gone so slow and also i keep getting a lot of bsod crashes. if i reboot my pc will also not come back on sometimes. here is my hijack this log. any advice/help would be greatly appreciated<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 20:27:16, on 01/11/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\Motive\McciCMService.exe<br />
C:\WINDOWS\System32\nvsvc32.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\SOUNDMAN.EXE<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe<br />
C:\Program Files\uTorrent\uTorrent.exe<br />
C:\Program Files\PeerGuardian2\pg2.exe<br />
C:\Program Files\3\3Connect\AutoUpdateSrv.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = <a rel="nofollow" class="t" href="http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html" target="_blank">http://uk.red.clientapps.yahoo.com/c...o/bt_side.html</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a rel="nofollow" class="t" href="http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html" target="_blank">http://uk.red.clientapps.yahoo.com/c...o/bt_side.html</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = <a rel="nofollow" class="t" href="http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/" target="_blank">http://uk.red.clientapps.yahoo.com/c...rch.yahoo.com/</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &quot;C:\Program Files\Outlook Express\msimn.exe&quot; //mailurl:mailto:melissa_x_15_x@hotmaiil.comm<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br />
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - (no file)<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll<br />
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - (no file)<br />
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll<br />
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br />
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br />
O4 - HKLM\..\Run: [PAC207_Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe<br />
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent<br />
O4 - HKLM\..\Run: [ccApp] &quot;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&quot;<br />
O4 - HKLM\..\Run: [osCheck] &quot;C:\Program Files\Norton 360\osCheck.exe&quot;<br />
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] &quot;C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe&quot;<br />
O4 - HKCU\..\Run: [uTorrent] &quot;C:\Program Files\uTorrent\uTorrent.exe&quot;<br />
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')<br />
O4 - Global Startup: Update Agent.lnk = ?<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - <a rel="nofollow" class="t" href="https://support.microsoft.com/OAS/ActiveX/MSDcode.cab" target="_blank">https://support.microsoft.com/OAS/ActiveX/MSDcode.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a rel="nofollow" class="t" href="http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1220611311186" target="_blank">http://www.update.microsoft.com/wind...?1220611311186</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a rel="nofollow" class="t" href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)<br />
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)<br />
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe<br />
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE<br />
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe<br />
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe<br />
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe<br />
<br />
--<br />
End of file - 7910 bytes<br />
<br />
thanks</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>rob247</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread235162.html</guid>
		</item>
		<item>
			<title>Winlogon keeps popping on startup, need help immediately</title>
			<link>http://www.daniweb.com/forums/thread235154.html</link>
			<pubDate>Sun, 01 Nov 2009 19:39:55 GMT</pubDate>
			<description>I received a message from a friend yesterday thru MSN messenger, he sent me a screensaver link and I thought it was a screensaver he made from the pictures we took.  After I downloaded the file and clicked on it, nothing happened.  So today I turned on my computer, and a Winlogon properties keeps...</description>
			<content:encoded><![CDATA[<div>I received a message from a friend yesterday thru MSN messenger, he sent me a screensaver link and I thought it was a screensaver he made from the pictures we took.  After I downloaded the file and clicked on it, nothing happened.  So today I turned on my computer, and a Winlogon properties keeps popping on my desktop.  I have to click the close button for several times until it disappears.  <br />
<br />
I checked on some malware pages, and noticed that this is some kind of virus that could hack into emails and files.  Do anyone know what I can do before the winlogon turns into something that can cause problems to my comp.  <br />
<br />
Spec:  Windows Vista Home Premium 64-bit<br />
This is the image of the winlogon on the startup: <a rel="nofollow" class="t" href="http://img689.imageshack.us/img689/8487/winlogon.jpg" target="_blank">http://img689.imageshack.us/img689/8487/winlogon.jpg</a><br />
<br />
The file I downloaded yesterday is DSC00148.SCR</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Jshammy</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread235154.html</guid>
		</item>
		<item>
			<title>My Computer has quit responding - HELP</title>
			<link>http://www.daniweb.com/forums/thread234826.html</link>
			<pubDate>Sat, 31 Oct 2009 05:35:07 GMT</pubDate>
			<description><![CDATA[I did install the HijackThis and ran it on my pc. I'm attaching the log file from HijackThis and hope you can help me figure out what the heck has invaded my pc. 
 
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 1:19:52 AM, on 10/31/2009 
Platform: Windows XP SP3 (WinNT 5.01.2600) 
MSIE:...]]></description>
			<content:encoded><![CDATA[<div>I did install the HijackThis and ran it on my pc. I'm attaching the log file from HijackThis and hope you can help me figure out what the heck has invaded my pc.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 1:19:52 AM, on 10/31/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br />
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Symantec AntiVirus\DefWatch.exe<br />
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe<br />
C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\oracle\ora92\bin\omtsreco.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\HPZipm12.exe<br />
C:\Program Files\Common Files\ICWM\Printer\RDIConverterService.exe<br />
C:\Program Files\Symantec AntiVirus\SavRoam.exe<br />
C:\Program Files\IBM_DS4000\client\monitor\SMmonitor.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br />
C:\Program Files\RealVNC\VNC4\WinVNC4.exe<br />
C:\WINDOWS\system32\SearchIndexer.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe<br />
C:\WINDOWS\SMINST\Scheduler.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br />
C:\PROGRA~1\SYMANT~1\VPTray.exe<br />
C:\Program Files\QuickTime\qttask.exe<br />
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe<br />
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe<br />
C:\Program Files\WinZip\WZQKPICK.EXE<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\rdpclip.exe<br />
C:\WINDOWS\system32\logon.scr<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="https://timeandlabor.paychex.com/secure/login.asp" target="_blank">https://timeandlabor.paychex.com/secure/login.asp</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by -== The Chronicle Telegram ==-<br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [RoxioDragToDisc] &quot;C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe&quot;<br />
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard.exe<br />
O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_XP.exe<br />
O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe<br />
O4 - HKLM\..\Run: [ccApp] &quot;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&quot;<br />
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe<br />
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] &quot;C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe&quot;<br />
O4 - HKLM\..\Run: [HP Software Update] &quot;c:\Program Files\HP\HP Software Update\HPWuSchd2.exe&quot;<br />
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe AcPro7_0_0 -reboot 1<br />
O4 - HKCU\..\Run: [msnmsgr] &quot;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&quot; /background<br />
O4 - HKUS\S-1-5-21-3844150997-2177148820-966483055-1135\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden (User '?')<br />
O4 - HKUS\S-1-5-21-3844150997-2177148820-966483055-1135\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')<br />
O4 - HKUS\S-1-5-21-3844150997-2177148820-966483055-1135\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe AcPro7_0_0 -reboot 1 (User '?')<br />
O4 - HKUS\S-1-5-21-3844150997-2177148820-966483055-1135\..\Run: [msnmsgr] &quot;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&quot; /background (User '?')<br />
O4 - S-1-5-21-3844150997-2177148820-966483055-1135 Startup: VZAccess Manager.lnk = C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (User '?')<br />
O4 - Startup: VZAccess Manager.lnk = C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe<br />
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe<br />
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe<br />
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE<br />
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll<br />
O16 - DPF: {2202D225-22C1-4B8C-A4B8-6A7E7B7E1524} (ICWMInstallObj Class) - <a rel="nofollow" class="t" href="https://qwestconferencing.qwest.com/confmgr/installs/ICWMInstall.cab" target="_blank">https://qwestconferencing.qwest.com/...CWMInstall.cab</a><br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll<br />
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - <a rel="nofollow" class="t" href="http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.4.cab" target="_blank">http://dlm.tools.akamai.com/dlmanage...ex-2.2.4.4.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a rel="nofollow" class="t" href="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1227045211921" target="_blank">http://update.microsoft.com/windowsu...?1227045211921</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a rel="nofollow" class="t" href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - <a rel="nofollow" class="t" href="https://advpubtechsupport.webex.com/client/T27L/support/ieatgpc.cab" target="_blank">https://advpubtechsupport.webex.com/...rt/ieatgpc.cab</a><br />
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Elyria.ChronicleTelegram.com<br />
O17 - HKLM\Software\..\Telephony: DomainName = Elyria.ChronicleTelegram.com<br />
O17 - HKLM\System\CCS\Services\Tcpip\..\{52DCEAAA-3F53-40B8-90AA-ADE490D8AEF5}: NameServer = 10.1.1.21,10.1.1.17<br />
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Elyria.ChronicleTelegram.com<br />
O17 - HKLM\System\CS1\Services\Tcpip\..\{52DCEAAA-3F53-40B8-90AA-ADE490D8AEF5}: NameServer = 10.1.1.21,10.1.1.17<br />
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = Elyria.ChronicleTelegram.com<br />
O17 - HKLM\System\CS2\Services\Tcpip\..\{52DCEAAA-3F53-40B8-90AA-ADE490D8AEF5}: NameServer = 10.1.1.21,10.1.1.17<br />
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br />
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\oracle\ora92\bin\omtsreco.exe<br />
O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\oracle\ora92\BIN\ONRSD.EXE<br />
O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: RDI Document Conversion Helper (RDIConverterPrintHelper) - Web Meeting - C:\Program Files\Common Files\ICWM\Printer\RDIConverterService.exe<br />
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe<br />
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe<br />
O23 - Service: IBM DS Storage Manager 10 Event Monitor (SMmonitor) - Unknown owner - C:\Program Files\IBM_DS4000\client\monitor\SMmonitor.exe<br />
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br />
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br />
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe<br />
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br />
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe</div>  <br /> <div style="padding:5px">     <fieldset class="fieldset"> <legend>Attached Files</legend> <table cellpadding="0" cellspacing="5" border="0"> <tr> <td><img class="inlineimg" src="http://www.daniweb.com/forums/images/attach/doc.gif" alt="File Type: doc" width="16" height="16" border="0" style="vertical-align:baseline" /></td> <td><a href="http://www.daniweb.com/forums/attachment.php?attachmentid=12391&amp;d=1256967156">hijackthis.doc</a> (13.0 KB)</td> </tr> </table> </fieldset>  </div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>desperate2</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234826.html</guid>
		</item>
		<item>
			<title>Help with Hijackthis log</title>
			<link>http://www.daniweb.com/forums/thread234789.html</link>
			<pubDate>Sat, 31 Oct 2009 00:27:18 GMT</pubDate>
			<description>I would appriate any help with this hijackthis log. 
 
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 7:24:43 PM, on 10/5/2009 
Platform: Windows XP SP3 (WinNT 5.01.2600) 
MSIE: Internet Explorer v8.00 (8.00.6001.18702) 
Boot mode: Normal 
 
Running processes: 
C:\WINDOWS\System32\smss.exe</description>
			<content:encoded><![CDATA[<div>I would appriate any help with this hijackthis log.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 7:24:43 PM, on 10/5/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\csrss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe<br />
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe<br />
C:\Program Files\Spyware Doctor\pctsAuxs.exe<br />
C:\Program Files\Spyware Doctor\pctsSvc.exe<br />
C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br />
C:\Program Files\Spyware Doctor\pctsTray.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\System32\alg.exe<br />
C:\WINDOWS\system32\taskmgr.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\WINDOWS\system32\NOTEPAD.EXE<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\system32\wbem\wmiprvse.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a rel="nofollow" class="t" href="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html" target="_blank">http://us.rd.yahoo.com/customize/ie/...ch/search.html</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll<br />
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br />
O4 - HKLM\..\Run: [ISTray] &quot;C:\Program Files\Spyware Doctor\pctsTray.exe&quot;<br />
O4 - HKLM\..\Run: [dellsupportcenter] &quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&quot; /P dellsupportcenter<br />
O4 - HKLM\..\Run: [egui] &quot;C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe&quot; /hide /waitservice<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll<br />
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - <a rel="nofollow" class="t" href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" target="_blank">http://upload.facebook.com/controls/...oUploader5.cab</a><br />
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll<br />
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://sslvpn.fmcna.com/f5-w-687474703a2f2f4652452d55532d4c582d4730382e64632e666d636e612e636f6d$$/iNotes6W.cab<br />
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - <a rel="nofollow" class="t" href="http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab" target="_blank">http://download.mcafee.com/molbin/sh...0/mcinsctl.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a rel="nofollow" class="t" href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1123890750815" target="_blank">http://update.microsoft.com/microsof...?1123890750815</a><br />
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Program Files\AutoCAD 2000i\AcDcToday.ocx<br />
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - <a rel="nofollow" class="t" href="http://www.installengine.com/engine/isetup.cab" target="_blank">http://www.installengine.com/engine/isetup.cab</a><br />
O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN File Upload Control) - <a rel="nofollow" class="t" href="http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab" target="_blank">http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab</a><br />
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (Yahoo! MailTo) - <a rel="nofollow" class="t" href="http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll" target="_blank">http://us.dl1.yimg.com/download.yaho...ymmapi_416.dll</a><br />
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} (EPUImageControl Class) - <a rel="nofollow" class="t" href="http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-29-0.cab" target="_blank">http://tools.ebayimg.com/eps/wl/acti..._v1-0-29-0.cab</a><br />
O16 - DPF: {C432C4BD-3566-411C-8F3C-E5E0D3AE5D33} (CBrowser Class) - <a rel="nofollow" class="t" href="http://viewers.multicastmedia.com/common/mbrowser/MINIBrowser.CAB" target="_blank">http://viewers.multicastmedia.com/co...INIBrowser.CAB</a><br />
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} - file://C:\Program Files\AutoCAD 2000i\InstFred.ocx<br />
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2000i\AcPreview.ocx<br />
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - <a rel="nofollow" class="t" href="http://fdl.msn.com/public/chat/msnchat45.cab" target="_blank">http://fdl.msn.com/public/chat/msnchat45.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)<br />
O20 - AppInit_DLLs: c:\windows\system32\horijige.dll,bapozoni.dll<br />
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll<br />
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Browser Defender Update Service - Threat Expert Ltd. - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe<br />
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE<br />
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe<br />
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe<br />
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe<br />
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe<br />
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br />
<br />
--<br />
End of file - 9042 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>magnific1</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234789.html</guid>
		</item>
		<item>
			<title>Do I have Nasties?</title>
			<link>http://www.daniweb.com/forums/thread234731.html</link>
			<pubDate>Fri, 30 Oct 2009 16:37:43 GMT</pubDate>
			<description>Hello.....I had some nasties on this laptop that had no protection....I installed Kaspersky Anti-Virus and cleaned things up a bit....ran ATF Cleaner and Malwarebytes Ani-Malware- see log below....also see my HJT below.....can someone please take a look and see if I am still infected?  Thanks very...</description>
			<content:encoded><![CDATA[<div>Hello.....I had some nasties on this laptop that had no protection....I installed Kaspersky Anti-Virus and cleaned things up a bit....ran ATF Cleaner and Malwarebytes Ani-Malware- see log below....also see my HJT below.....can someone please take a look and see if I am still infected?  Thanks very much.....JD<br />
<br />
Malwarebytes' Anti-Malware 1.41<br />
Database version: 3060<br />
Windows 6.0.6002 Service Pack 2<br />
<br />
10/30/2009 12:00:10 PM<br />
mbam-log-2009-10-30 (12-00-10).txt<br />
<br />
Scan type: Full Scan (C:\|D:\|)<br />
Objects scanned: 295055<br />
Time elapsed: 1 hour(s), 59 minute(s), 30 second(s)<br />
<br />
Memory Processes Infected: 0<br />
Memory Modules Infected: 0<br />
Registry Keys Infected: 29<br />
Registry Values Infected: 1<br />
Registry Data Items Infected: 0<br />
Folders Infected: 1<br />
Files Infected: 19<br />
<br />
Memory Processes Infected:<br />
(No malicious items detected)<br />
<br />
Memory Modules Infected:<br />
(No malicious items detected)<br />
<br />
Registry Keys Infected:<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.ShopperReports) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.ShopperReports) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7370f91f-6994-4595-9949-601fa2261c8d} (Trojan.BHO) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{35a5b43b-cb8a-49ca-a9f4-d3b308d2e3cc} (Trojan.FakeAlert) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Servises (Malware.Trace) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fioo32 (Worm.KoobFace) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_FIO32 (Worm.KoobFace) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SfX (Rootkit.Agent) -&gt; Quarantined and deleted successfully.<br />
<br />
Registry Values Infected:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\fioo32 (Worm.KoobFace) -&gt; Quarantined and deleted successfully.<br />
<br />
Registry Data Items Infected:<br />
(No malicious items detected)<br />
<br />
Folders Infected:<br />
C:\ProgramData\Microsoft\Windows\Start Menu\CS (Rogue.CyberSecurity) -&gt; Quarantined and deleted successfully.<br />
<br />
Files Infected:<br />
C:\Users\Doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BZ5XLYRE\v2prx[1].exe (Trojan.Agent) -&gt; Quarantined and deleted successfully.<br />
C:\Users\Doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GPY2VTJ6\tw.04[1].exe (Trojan.Dropper) -&gt; Quarantined and deleted successfully.<br />
C:\Users\Doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GPY2VTJ6\pp.12[1].exe (Worm.Koobface) -&gt; Quarantined and deleted successfully.<br />
C:\Users\Doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GPY2VTJ6\pp.12[2].exe (Worm.Koobface) -&gt; Quarantined and deleted successfully.<br />
C:\Users\Doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V2HDA3EY\fb.72[1].exe (Trojan.Backdoor) -&gt; Quarantined and deleted successfully.<br />
C:\Users\Doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V2HDA3EY\fb.72[2].exe (Trojan.Backdoor) -&gt; Quarantined and deleted successfully.<br />
C:\Users\Doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V2HDA3EY\fb.72[3].exe (Trojan.Backdoor) -&gt; Quarantined and deleted successfully.<br />
C:\Users\Doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V2HDA3EY\pp.12[2].exe (Worm.Koobface) -&gt; Quarantined and deleted successfully.<br />
C:\Users\Doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V2HDA3EY\v2prx[1].exe (Trojan.Agent) -&gt; Quarantined and deleted successfully.<br />
C:\Users\Doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V2HDA3EY\Inst_312s1[1].exe (Rogue.AlphaAV) -&gt; Quarantined and deleted successfully.<br />
C:\Users\Doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V8KQNIMM\v2prx[1].exe (Trojan.Agent) -&gt; Quarantined and deleted successfully.<br />
C:\Windows\010112010146116101.xxe (KoobFace.Trace) -&gt; Quarantined and deleted successfully.<br />
C:\Windows\0101120101464955.xxe (KoobFace.Trace) -&gt; Quarantined and deleted successfully.<br />
C:\Windows\0101120101465055.xxe (KoobFace.Trace) -&gt; Quarantined and deleted successfully.<br />
C:\Windows\0101120101465248.xxe (KoobFace.Trace) -&gt; Quarantined and deleted successfully.<br />
C:\Windows\bk23567.dat (KoobFace.Trace) -&gt; Quarantined and deleted successfully.<br />
C:\Windows\fdgg34353edfgdfdf (KoobFace.Trace) -&gt; Quarantined and deleted successfully.<br />
C:\Windows\tw23567.dat (Worm.KoobFace) -&gt; Quarantined and deleted successfully.<br />
C:\Program Files\Mozilla Firefox\ftemp.exe (Trojan.Dropper) -&gt; Quarantined and deleted successfully.<br />
<br />
<br />
<br />
<br />
<br />
Logfile of HijackThis v1.99.1<br />
Scan saved at 12:22:22 PM, on 10/30/2009<br />
Platform: Unknown Windows (WinNT 6.00.1906 SP2)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18828)<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\taskeng.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Windows\RtHDVCpl.exe<br />
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe<br />
C:\Program Files\HP\QuickPlay\QPService.exe<br />
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe<br />
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe<br />
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe<br />
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Windows\System32\igfxtray.exe<br />
C:\Windows\System32\hkcmd.exe<br />
C:\Windows\System32\igfxpers.exe<br />
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Windows\system32\igfxsrvc.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Program Files\HijackThis\HijackThis.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=73&amp;bd=Pavilion&amp;pf=laptop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...lion&amp;pf=laptop</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=73&amp;bd=Pavilion&amp;pf=laptop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...lion&amp;pf=laptop</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search &amp; Destroy\SDHelper.dll<br />
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\ievkbd.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll<br />
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br />
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe<br />
O4 - HKLM\..\Run: [QPService] &quot;C:\Program Files\HP\QuickPlay\QPService.exe&quot;<br />
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start<br />
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe<br />
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe<br />
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [AVP] &quot;C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe&quot;<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKCU\..\Run: [MsnMsgr] &quot;C:\Program Files\MSN Messenger\MsnMsgr.Exe&quot; /background<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O4 - Global Startup: McAfee Security Scan.lnk = ?<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra button: &amp;Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL<br />
O9 - Extra button: URLs c&amp;heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search &amp; Destroy\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp;&amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search &amp; Destroy\SDHelper.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll<br />
O11 - Options group: [INTERNATIONAL] International<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a rel="nofollow" class="t" href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll<br />
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL<br />
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll<br />
O20 - Winlogon Notify: igfxcui - C:\Windows\SYSTEM32\igfxdev.dll<br />
O20 - Winlogon Notify: klogon - C:\Windows\system32\klogon.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe&quot; -r (file missing)<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe<br />
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe<br />
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)<br />
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe<br />
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)<br />
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe<br />
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)<br />
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe<br />
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>jd51edwin</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234731.html</guid>
		</item>
		<item>
			<title>HELP! - userinit.exe - application error</title>
			<link>http://www.daniweb.com/forums/thread234706.html</link>
			<pubDate>Fri, 30 Oct 2009 14:59:36 GMT</pubDate>
			<description>I am a tech for a school district. We are having issues with users logging in and getting this error: userinit.exe - application error The application failed to initialize properly. Click on ok to terminate the application. 
 
Once they click on Ok their Icons do not appear, some get text but no...</description>
			<content:encoded><![CDATA[<div>I am a tech for a school district. We are having issues with users logging in and getting this error: userinit.exe - application error The application failed to initialize properly. Click on ok to terminate the application.<br />
<br />
Once they click on Ok their Icons do not appear, some get text but no icon and some get nothing at all on their desktops. If you try to log off with c-a-d then it brings up the box but doesn't let you use any of the options on the screen because the icons aren't there.<br />
<br />
We have tried several fixes, one of them being ComboFix, it worked on a couple of the computers but it is not a fix all on all of them district wide. We have also wiped the computers and reloaded them from scratch and as soon as you get through and log in they get the error again. HELP....I need suggestions.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>techchic</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234706.html</guid>
		</item>
		<item>
			<title><![CDATA[Browser redirects[thread moved]]]></title>
			<link>http://www.daniweb.com/forums/thread234644.html</link>
			<pubDate>Fri, 30 Oct 2009 05:39:42 GMT</pubDate>
			<description>Hi Gerbil, 
 
I have the same problem like nmslagle, keep having the address redirected to fake address. can you help to check my log, below is my log. 
I use FireFox as my browser.  
 
Thanks 
 
 
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 13:31:21, on 10/30/2009</description>
			<content:encoded><![CDATA[<div>Hi Gerbil,<br />
<br />
I have the same problem like nmslagle, keep having the address redirected to fake address. can you help to check my log, below is my log.<br />
I use FireFox as my browser. <br />
<br />
Thanks<br />
<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 13:31:21, on 10/30/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16674)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\ibmpmsvc.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Navision\Client\INSTAL~1.EXE<br />
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe<br />
C:\WINDOWS\system32\msiexec.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\inetsrv\inetinfo.exe<br />
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe<br />
C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe<br />
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe<br />
C:\Program Files\Sophos\Remote Management System\RouterNT.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\TPHDEXLG.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\WINDOWS\system32\tp4mon.exe<br />
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe<br />
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe<br />
C:\WINDOWS\system32\TpShocks.exe<br />
C:\WINDOWS\system32\igfxtray.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\Program Files\Analog Devices\Core\smax4pnp.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe<br />
C:\Program Files\Sophos\AutoUpdate\ALMon.exe<br />
C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe<br />
C:\Program Files\Digital Line Detect\DLG.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\igfxsrvc.exe<br />
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe<br />
C:\Program Files\Lenovo\Zoom\TpScrex.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Documents and Settings\FSantoso4859\Desktop\12549\imaBunny.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=74005" target="_blank">http://go.microsoft.com/fwlink/?LinkId=74005</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Program Files\Common Files\svchost.exe,<br />
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Sophos Web Content Scanner - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll<br />
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll<br />
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll<br />
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL<br />
O4 - HKLM\..\Run: [TrackPointSrv] tp4mon.exe<br />
O4 - HKLM\..\Run: [IMJPMIG8.1] &quot;C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE&quot; /Spoil /RemAdvDef /Migration32<br />
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC<br />
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC<br />
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName<br />
O4 - HKLM\..\Run: [GrooveMonitor] &quot;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&quot;<br />
O4 - HKLM\..\Run: [PSQLLauncher] &quot;C:\Program Files\ThinkVantage Fingerprint Software\launcher.exe&quot; /startup<br />
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe<br />
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe<br />
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray<br />
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor<br />
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog<br />
O4 - HKLM\..\Run: [Waiting1690] C:\Windows\stid1690.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [msnmsgr] &quot;C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe&quot; /background<br />
O4 - HKCU\..\Run: [Sony Ericsson PC Suite] &quot;C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe&quot; /systray /nologon<br />
O4 - HKCU\..\Run: [Messenger (Yahoo!)] &quot;C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE&quot; -quiet<br />
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')<br />
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE<br />
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe<br />
O4 - Global Startup: Bluetooth.lnk = ?<br />
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe<br />
O4 - Global Startup: VPN Client.lnk = ?<br />
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm<br />
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Send to &amp;Bluetooth Device... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm<br />
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe<br />
O9 - Extra 'Tools' menuitem: &amp;FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - <a rel="nofollow" class="t" href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" target="_blank">http://upload.facebook.com/controls/...oUploader5.cab</a><br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll<br />
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = TecturaCorp.net<br />
O17 - HKLM\Software\..\Telephony: DomainName = TecturaCorp.net<br />
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = TecturaCorp.net<br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O20 - AppInit_DLLs: C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe<br />
O23 - Service: Cisco Systems, Inc. Installer service (CiscoVpnInstallService) - Unknown owner - C:\Navision\Client\INSTAL~1.EXE<br />
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe<br />
O23 - Service: Logical Disk Manager Administrative Service dmadminHKHKG-SXF4859N1-SQL (dmadminHKHKG-SXF4859N1-SQL) - Unknown owner - C:\WINDOWS\system32\1033u.exe (file missing)<br />
O23 - Service: Logical Disk Manager dmserverHKHKG-SXF4859N1-SQL (dmserverHKHKG-SXF4859N1-SQL) - Unknown owner - C:\WINDOWS\system32\ahuiu.exe<br />
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)<br />
O23 - Service: Remote Desktop Help Session Manager RDSessMgrlanmanworkstation (RDSessMgrlanmanworkstation) - Unknown owner - C:\WINDOWS\system32\1037sb.exe (file missing)<br />
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe<br />
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe<br />
O23 - Service: Sophos Agent - Sophos Plc - C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe<br />
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe<br />
O23 - Service: Sophos Message Router - Sophos Plc - C:\Program Files\Sophos\Remote Management System\RouterNT.exe<br />
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe<br />
<br />
--<br />
End of file - 12549 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>ferrysb</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234644.html</guid>
		</item>
		<item>
			<title>Solutions:Read this</title>
			<link>http://www.daniweb.com/forums/thread234581.html</link>
			<pubDate>Fri, 30 Oct 2009 04:15:17 GMT</pubDate>
			<description>If you are worried about your computer infected with a virus, I would highly recommend that you install the following open source programs: 
 
Microsoft Security Essentials- download it from microsoft website. It will get rid of viruses, spywares, etc... 
or  
avast- free antivirus 
or ...</description>
			<content:encoded><![CDATA[<div>If you are worried about your computer infected with a virus, I would highly recommend that you install the following open source programs:<br />
<br />
Microsoft Security Essentials- download it from microsoft website. It will get rid of viruses, spywares, etc...<br />
or <br />
avast- free antivirus<br />
or <br />
comodo-free<br />
Remember you should only have 1 antivirus running in your computer.<br />
<br />
Secunia- search for it on google.com This program will search for vulnerabilities inside your computer.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>jake43</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234581.html</guid>
		</item>
		<item>
			<title>Help with slow computer</title>
			<link>http://www.daniweb.com/forums/thread234456.html</link>
			<pubDate>Thu, 29 Oct 2009 15:55:50 GMT</pubDate>
			<description>Is there anything in the HJT log that shows a problem? 
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 10:54:36 AM, on 10/29/2009 
Platform: Windows XP SP3 (WinNT 5.01.2600) 
MSIE: Internet Explorer v8.00 (8.00.6001.18702) 
Boot mode: Normal 
 
Running processes:...</description>
			<content:encoded><![CDATA[<div>Is there anything in the HJT log that shows a problem?<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 10:54:36 AM, on 10/29/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\system32\acs.exe<br />
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe<br />
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe<br />
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe<br />
C:\WINDOWS\system32\DVDRAMSV.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe<br />
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe<br />
C:\WINDOWS\system32\TODDSrv.exe<br />
C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\ddwmon.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\WINDOWS\AGRSMMSG.exe<br />
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe<br />
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\IncrediMail\bin\IMApp.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
c:\program files\aol toolbar\AolTbServer.exe<br />
C:\Program Files\IncrediMail\bin\IncMail.exe<br />
C:\PROGRA~1\FOXITS~1\FOXITP~2\FOXITP~1.EXE<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = <a rel="nofollow" class="t" href="http://toolbar.inbox.com/search/dispatcher.aspx?tp=aus&amp;qkw=%s&amp;tbid=%tb_id%language" target="_blank">http://toolbar.inbox.com/search/disp...tb_id%language</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com" target="_blank">http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = <a rel="nofollow" class="t" href="http://toolbar.inbox.com/search/ie.aspx?tbid=80114" target="_blank">http://toolbar.inbox.com/search/ie.aspx?tbid=80114</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = <a rel="nofollow" class="t" href="http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80114" target="_blank">http://toolbar.inbox.com/help/sa_cus...spx?tbid=80114</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <a rel="nofollow" class="t" href="http://toolbar.inbox.com/search/ie.aspx?tbid=80114" target="_blank">http://toolbar.inbox.com/search/ie.aspx?tbid=80114</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <a rel="nofollow" class="t" href="http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80114" target="_blank">http://toolbar.inbox.com/help/sa_cus...spx?tbid=80114</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = <a rel="nofollow" class="t" href="http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com" target="_blank">http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com</a><br />
R3 - URLSearchHook: IAOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL Toolbar\aoltb.dll<br />
R3 - URLSearchHook: AIM Toolbar Search Class - {03402F96-3DC7-4285-BC50-9E81FEFAFE43} - C:\Program Files\AIM Toolbar\aimtb.dll<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: AOL Toolbar Loader - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL Toolbar\aoltb.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL Toolbar\aoltb.dll<br />
O4 - HKLM\..\Run: [DDWMon] C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe<br />
O4 - HKLM\..\Run: [avgnt] &quot;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe&quot; /min<br />
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKCU\..\Run: [BIBLauncher] C:\Program Files\Business-in-a-Box\BIBLauncher.exe<br />
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')<br />
O8 - Extra context menu item: &amp;Add animation to IncrediMail Style Box - C:\Program Files\IncrediMail\bin\resources\WebMenuImg.htm<br />
O8 - Extra context menu item: &amp;AIM Toolbar Search - C:\Documents and Settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html<br />
O8 - Extra context menu item: &amp;AOL Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart<br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - <a rel="nofollow" class="t" href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" target="_blank">http://upload.facebook.com/controls/...oUploader5.cab</a><br />
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - <a rel="nofollow" class="t" href="http://pcpitstop.com/betapit/PCPitStop.CAB" target="_blank">http://pcpitstop.com/betapit/PCPitStop.CAB</a><br />
O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) - <a rel="nofollow" class="t" href="http://www.myheritage.com/Genoogle/Components/ActiveX/SearchEngineQuery.dll" target="_blank">http://www.myheritage.com/Genoogle/C...ngineQuery.dll</a><br />
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - <a rel="nofollow" class="t" href="http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab" target="_blank">http://h20270.www2.hp.com/ediags/gmn...Detection2.cab</a><br />
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll<br />
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll<br />
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe<br />
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe<br />
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe<br />
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe<br />
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe<br />
O23 - Service: Google Update Service (gupdate1c9ce6113f51c30) (gupdate1c9ce6113f51c30) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe<br />
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe<br />
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\WINDOWS\system32\TODDSrv.exe<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
<br />
--<br />
End of file - 9492 bytes<br />
Is there anything here that would be causing my computer to bog down or lock up?</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Scoop1957</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234456.html</guid>
		</item>
		<item>
			<title>News Story Trick or Treat Security Scares</title>
			<link>http://www.daniweb.com/news/story234435.html</link>
			<pubDate>Thu, 29 Oct 2009 13:36:34 GMT</pubDate>
			<description>You probably call it Halloween, for myself and other pagans it is Samhain (http://en.wikipedia.org/wiki/Samhain), but for the cyber-gangs it is phishing time. Seasonally-themed spam is on the up at this time of the year, Halloween related messages accounting for 0.5% of the daily spam traffic by...</description>
			<content:encoded><![CDATA[<div>You probably call it Halloween, for myself and other pagans it is <a rel="nofollow" class="t" href="http://en.wikipedia.org/wiki/Samhain" target="_blank">Samhain</a>, but for the cyber-gangs it is phishing time. Seasonally-themed spam is on the up at this time of the year, Halloween related messages accounting for 0.5% of the daily spam traffic by volume in mid-October according to the latest <a rel="nofollow" class="t" href="http://www.messagelabs.com/intelligence.aspx" target="_blank">Symantec MessageLabs Intelligence Report</a>. <br />
<br />
Currently, with the 'Witch's New Year' Sabbath itself coming this weekend, there are some 500 million emails circulating worldwide and the majority of the Halloween spam is originating from the <a rel="nofollow" class="t" href="http://www.itwire.com/content/view/19931/53/" target="_blank">Rustock</a> and Donbot <a rel="nofollow" class="t" href="http://www.itwire.com/content/view/24603/1231/" target="_blank">botnets</a>. Most of this would appear to be pointing towards pharmaceutical sites and rogue/counterfeit software sites.<br />
<br />
&quot;As is typical with spammers this time of year, we are seeing them try to capitalize on the holiday season&quot; said MessageLabs Intelligence Senior Analyst, Paul Wood. &quot;Although they may be a bit overzealous, spamming is a numbers game and the spammers have certainly succeeded with volume thus far. Perhaps their early-bird approach is an attempt to compete with the other botnets and get in early to maximize their chances of success.&quot;<br />
<br />
This month has also seen a batch of intercepted event-related advance-fee fraud spams, mostly relating to the 2010 football World Cup in South Africa which try and get the target to pay an up front fee in order to supposedly receive their prize draw winnings. <br />
<br />
The October phishing activity has been 1 in every 293.7 emails, an increase of 0.11% since September but a drop of 10.5% if looked at as a proportion of all email-borne threats.<br />
<br />
When it comes to viruses, October has seen the global ratio of email-borne viruses in email traffic from new and previously unknown bad sources increase by just 0.18% from September to 1 in every 230.8 emails. However, only 19.2% of email-borne malware contained links to malicious websites, which is a huge drop of some 20.6% from the previous month. <br />
<br />
Geographically speaking, Denmark was the most spammed country with levels of 96.2 percent of all email, with the US on 94% and <a rel="nofollow" class="t" href="http://www.daniweb.com/news/story229532.html" target="_blank">the UK on 93.3%</a> while China tops the virus activity charts though, with 1 in every 80.7 emails being infected.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>happygeek</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234435.html</guid>
		</item>
		<item>
			<title>Infected D: drive</title>
			<link>http://www.daniweb.com/forums/thread234351.html</link>
			<pubDate>Thu, 29 Oct 2009 08:06:50 GMT</pubDate>
			<description>Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 1:06:18 AM, on 10/29/2009 
Platform: Windows Vista SP2 (WinNT 6.00.1906) 
MSIE: Internet Explorer v8.00 (8.00.6001.18813) 
Boot mode: Normal 
 
Running processes: 
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe...</description>
			<content:encoded><![CDATA[<div>Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 1:06:18 AM, on 10/29/2009<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18813)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe<br />
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe<br />
C:\Program Files (x86)\HP\QuickPlay\QPService.exe<br />
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe<br />
C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe<br />
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe<br />
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe<br />
C:\Program Files (x86)\Java\jre1.6.0_05\bin\jusched.exe<br />
C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe<br />
C:\Program Files (x86)\Winamp\winampa.exe<br />
C:\Program Files (x86)\AVG\AVG8\avgtray.exe<br />
C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe<br />
C:\Program Files (x86)\Java\jre1.6.0_05\bin\javaw.exe<br />
C:\Program Files (x86)\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE<br />
C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe<br />
C:\Program Files (x86)\Java\jre1.6.0_05\bin\jucheck.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=83&amp;bd=Pavilion&amp;pf=cnnb" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...vilion&amp;pf=cnnb</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.imeem.com/minggg" target="_blank">http://www.imeem.com/minggg</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=83&amp;bd=Pavilion&amp;pf=cnnb" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...vilion&amp;pf=cnnb</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=83&amp;bd=Pavilion&amp;pf=cnnb" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...vilion&amp;pf=cnnb</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll<br />
F2 - REG:system.ini: UserInit=userinit.exe<br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG8\avgssie.dll<br />
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\Program Files (x86)\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll<br />
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~2\COMMON~1\SYMANT~1\IDS\IPSBHO.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll<br />
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll<br />
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\Program Files (x86)\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll<br />
O4 - HKLM\..\Run: [UCam_Menu] &quot;C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe&quot; &quot;C:\Program Files (x86)\CyberLink\YouCam&quot; update &quot;Software\CyberLink\YouCam\2.0&quot;<br />
O4 - HKLM\..\Run: [QPService] &quot;C:\Program Files (x86)\HP\QuickPlay\QPService.exe&quot;<br />
O4 - HKLM\..\Run: [QlbCtrl.exe] &quot;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe&quot; /Start<br />
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files (x86)\Java\jre1.6.0_05\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [ZoneAlarm Client] &quot;C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe&quot;<br />
O4 - HKLM\..\Run: [WinampAgent] &quot;C:\Program Files (x86)\Winamp\winampa.exe&quot;<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~2\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [Ltayozanij] rundll32.exe &quot;C:\Users\Nghia\AppData\Local\difgry.dll&quot;,Startup<br />
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden<br />
O4 - HKCU\..\Run: [Messenger (Yahoo!)] &quot;C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe&quot; -quiet<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {BD68328E-1222-4A62-BA16-E6F42CA49A64} (WMInstallMgr Control) - <a rel="nofollow" class="t" href="http://gf.wemade.com/comsso/active/WMInstallMgr.cab" target="_blank">http://gf.wemade.com/comsso/active/WMInstallMgr.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG8\avgpp.dll<br />
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Unknown owner - C:\Windows\system32\agr64svc.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)<br />
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgemc.exe<br />
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe<br />
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files (x86)\Common Files\Symantec Shared\VAScanner\comHost.exe<br />
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)<br />
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe<br />
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe<br />
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe<br />
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)<br />
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - c:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_4.EXE<br />
O23 - Service: LiveUpdate Notice - Symantec Corporation - c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)<br />
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe<br />
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe<br />
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe<br />
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe<br />
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)<br />
O23 - Service: Audio Service (STacSV) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_58be29c0\STacSV64.exe (file missing)<br />
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~2\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe<br />
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe<br />
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\SysWOW64\ZoneLabs\vsmon.exe<br />
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)<br />
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)<br />
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)<br />
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
<br />
--<br />
End of file - 13101 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>miagi</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234351.html</guid>
		</item>
		<item>
			<title>Some Kind Of AVG virus</title>
			<link>http://www.daniweb.com/forums/thread234288.html</link>
			<pubDate>Thu, 29 Oct 2009 03:48:19 GMT</pubDate>
			<description>hey so i think i got this virus from downloading a game from frostwire a few weeks back. i checked it for viruses with my avg and  it said there was nothing and when i opeded it nothing happen. so i did a scan immeditly and it said there was like 2 or 3 infections and i tried to remove them but...</description>
			<content:encoded><![CDATA[<div>hey so i think i got this virus from downloading a game from frostwire a few weeks back. i checked it for viruses with my avg and  it said there was nothing and when i opeded it nothing happen. so i did a scan immeditly and it said there was like 2 or 3 infections and i tried to remove them but wasn't able to. it was telling me i wasn't able to get into the virus vault and is still saying that. and now my computer seems to be getting slower, and sometimes even freezes.<br />
<br />
so i tried deleting AVG and going with a differn't anti virus program but i am still unable to delete AVG  it keeps saying  avgrsx.exe or avgnsx.exe or avgwdsvc.exe problem has occured.<br />
<br />
and in the past two days or so my computer has been clicking icons on my desktop for no reason like 50-100 times. and then becomes just won't work.<br />
<br />
anyone got any idea's of what it could be?<br />
any help would be greatly appretiated. <br />
thanks.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>jones905</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234288.html</guid>
		</item>
		<item>
			<title>Crunchie Please Help!!!</title>
			<link>http://www.daniweb.com/forums/thread234255.html</link>
			<pubDate>Thu, 29 Oct 2009 01:48:10 GMT</pubDate>
			<description><![CDATA[Ok, here are the issues I'm having & yes I run a lot of anti programs including Advanced System Care which some say they love & a few people say caused problems. 
 
Honestly I can't remember when the problems started, at least 4-6 months ago & it may have started after I bought the ASC, but I just...]]></description>
			<content:encoded><![CDATA[<div>Ok, here are the issues I'm having &amp; yes I run a lot of anti programs including Advanced System Care which some say they love &amp; a few people say caused problems.<br />
<br />
Honestly I can't remember when the problems started, at least 4-6 months ago &amp; it may have started after I bought the ASC, but I just exited out of it &amp; still no change.<br />
<br />
1. I click on &quot;my computer&quot;, &amp; it takes about 20-30 seconds to let me have access to the window. That's even after rebooting which I just did.<br />
<br />
That also happens with Fx, but when I've rebooted, everything is very quick until I leave the computer &amp; come back, then it takes several minutes to let me have access.<br />
<br />
Also in the last several days I'm having problems with TB (thunderbird) &amp; I didn't have hanging problems with TB b4.<br />
<br />
2. This is the most frustrating thing.<br />
<br />
At first I thought it was the site, but then it started happening on 3 different sites &amp; after bitching &amp; arguing, I have to admit it may very well be on my end. :(<br />
<br />
Either:<br />
<br />
a) <a rel="nofollow" class="t" href="http://www.cj.com" target="_blank">www.cj.com</a><br />
<br />
when I login into the membership area (main index page is fine), the CSS files don't load so I can't do anything within the site. Others don't have this problem. That's on both Fx &amp; IE.<br />
<br />
b) <a rel="nofollow" class="t" href="http://www.odesk.com" target="_blank">www.odesk.com</a><br />
<br />
When I go to edit one of our job postings, it won't let me save it saying the start date is wrong even though it's not.<br />
<br />
After weeks of them testing it, it works fine in Fx for them, but not for me. I just tried it again &amp; Fx just came out w/ an update &amp; still can't do it.<br />
<br />
In IE it works fine &lt;sigh&gt;<br />
<br />
c) <a rel="nofollow" class="t" href="http://www.freedomvoice.com" target="_blank">www.freedomvoice.com</a><br />
<br />
Tried to upload audio files &amp; make changes to my acct., can't do it in Fx, only in IE.<br />
<br />
They say they tested it &amp; there's nothing wrong. Now I didn't try it out after shutting down Fx which I should have done &amp; I don't want to touch anything to test it b/c it's the way I want it now.<br />
<br />
My assistant also had this problem in Safari &amp; Fx, but he's on a MAC &amp; you know most coders can't code properly for MACs, so that doesn't really tell me much.<br />
<br />
d) <a rel="nofollow" class="t" href="http://www.Hyperoffice.com" target="_blank">www.Hyperoffice.com</a><br />
<br />
I add a new day in the notes area &amp; instead of it taking me back to the last window, it takes me all the way back to the folders area.<br />
<br />
It's intermittent &amp; they claim there's no problem on their end.<br />
<br />
I do have to say one thing. Most if not all of these sites are poorly coded I think. I'm not a coder, but I know how sites work &amp; I can tell when it's garbage code.<br />
<br />
The thing is, no one else is having the problem. I have the latest version of Fx, I hate IE, sometimes the site works on IE, but I don't use IE daily enough to know if it's just Fx or what is going on.<br />
<br />
It's stressing me out, wasting my time, PLEASE HELP!<br />
<br />
Thanks :)<br />
<br />
<br />
Michelle<br />
----------------------------------------------<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 9:35:59 PM, on 10/28/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
C:\WINDOWS\ATKKBService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe<br />
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br />
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe<br />
C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe<br />
C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe<br />
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\oDesk\oDeskCommonPrefs.exe<br />
C:\Program Files\Shelltoys\Personal Assistant\assistant.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe<br />
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe<br />
C:\Program Files\Microsoft ActiveSync\wcescomm.exe<br />
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe<br />
C:\PROGRA~1\MICROS~3\rapimgr.exe<br />
C:\Garmin\gStart.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\Program Files\WinZip\WZQKPICK.EXE<br />
C:\Program Files\oDesk\oDeskTeam.exe<br />
C:\Program Files\oDesk\oDeskShare.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe<br />
C:\WINDOWS\system32\NOTEPAD.EXE<br />
C:\WINDOWS\system32\notepad.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Mozilla Thunderbird\thunderbird.exe<br />
C:\WINDOWS\System32\vssvc.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.ask.com/?o=101677&amp;l=dis" target="_blank">http://www.ask.com/?o=101677&amp;l=dis</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br />
O4 - HKLM\..\Run: [ATIPTA] &quot;C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&quot;<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [pdfFactory Dispatcher v3] &quot;C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe&quot; /source=HKLM<br />
O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [StartCCC] &quot;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&quot; MSRun<br />
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe /autorun<br />
O4 - HKLM\..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe<br />
O4 - HKLM\..\Run: [avgnt] &quot;C:\Program Files\Avira\AntiVir Desktop\avgnt.exe&quot; /min<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKLM\..\Run: [Prefs] C:\Program Files\oDesk\oDeskLaunch.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Program Files\ASUS\SmartDoctor\\SmartDoctor.exe  /start<br />
O4 - HKCU\..\Run: [Personal Assistant] C:\Program Files\Shelltoys\Personal Assistant\assistant.exe<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKCU\..\Run: [eFax 4.4] &quot;C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe&quot; /R<br />
O4 - HKCU\..\Run: [Messenger (Yahoo!)] &quot;C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe&quot; -quiet<br />
O4 - HKCU\..\Run: [H/PC Connection Agent] &quot;C:\Program Files\Microsoft ActiveSync\wcescomm.exe&quot;<br />
O4 - HKCU\..\Run: [ccleaner] &quot;C:\Program Files\CCleaner\CCleaner.exe&quot; /AUTO<br />
O4 - HKCU\..\Run: [Advanced SystemCare 3] &quot;C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe&quot; /startup<br />
O4 - HKCU\..\Run: [gStart] C:\Garmin\gStart.exe<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O4 - Global Startup: Quick View Plus.lnk = ?<br />
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br />
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll<br />
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll<br />
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe<br />
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll<br />
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} (Java Plug-in 1.6.0_13) - <br />
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - <a rel="nofollow" class="t" href="http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll" target="_blank">http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll</a><br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\570\G2AWinLogon.dll<br />
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe<br />
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: CarboniteService - Carbonite, Inc. (<a rel="nofollow" class="t" href="http://www.carbonite.com" target="_blank">www.carbonite.com</a>) - C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe<br />
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe<br />
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe<br />
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\570\g2aservice.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe<br />
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
<br />
--<br />
End of file - 11271 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>ep2002</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234255.html</guid>
		</item>
		<item>
			<title>I need help!!!!</title>
			<link>http://www.daniweb.com/forums/thread234220.html</link>
			<pubDate>Wed, 28 Oct 2009 22:46:54 GMT</pubDate>
			<description>Please, help me!! I need take information about a virus Trojan.Win32.Cosmu.</description>
			<content:encoded><![CDATA[<div>Please, help me!! I need take information about a virus Trojan.Win32.Cosmu.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Alex91</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234220.html</guid>
		</item>
		<item>
			<title>Laptop Running very Slow recently</title>
			<link>http://www.daniweb.com/forums/thread234191.html</link>
			<pubDate>Wed, 28 Oct 2009 19:43:20 GMT</pubDate>
			<description>Hi all, 
I am hoping someone maybe able to help me. 
I have a Acer Aspire 9301AWSMi laptop,and has been running very slow recently. 
 
It is second hand, but was running fine up until about 2 months ago. 
 
This is the Hijackthis log: 
 
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at...</description>
			<content:encoded><![CDATA[<div>Hi all,<br />
I am hoping someone maybe able to help me.<br />
I have a Acer Aspire 9301AWSMi laptop,and has been running very slow recently.<br />
<br />
It is second hand, but was running fine up until about 2 months ago.<br />
<br />
This is the Hijackthis log:<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 20:45:58, on 28/10/2009<br />
Platform: Windows Vista  (WinNT 6.00.1904)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16916)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\RtHDVCpl.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\Launch Manager\LManager.exe<br />
C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\AVG\AVG9\avgtray.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe<br />
C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE<br />
C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE<br />
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE<br />
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe<br />
C:\Users\admin\AppData\Local\Temp\RtkBtMnt.exe<br />
C:\Acer\Empowering Technology\eDataSecurity\x86\MsnVane.exe<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\Windows\system32\taskeng.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://uk.rd.yahoo.com/customize/ycomp/defaults/sp/*http://uk.yahoo.com" target="_blank">http://uk.rd.yahoo.com/customize/yco...//uk.yahoo.com</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.tiscali.co.uk/broadband" target="_blank">http://www.tiscali.co.uk/broadband</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://en.uk.acer.yahoo.com" target="_blank">http://en.uk.acer.yahoo.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://en.uk.acer.yahoo.com" target="_blank">http://en.uk.acer.yahoo.com</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = <a rel="nofollow" class="t" href="http://uk.rd.yahoo.com/customize/ycomp/defaults/su/*http://uk.yahoo.com" target="_blank">http://uk.rd.yahoo.com/customize/yco...//uk.yahoo.com</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br />
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll<br />
O3 - Toolbar: &amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe<br />
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe<br />
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe<br />
O4 - HKLM\..\Run: [MSConfig] &quot;C:\Windows\system32\msconfig.exe&quot; /auto<br />
O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;  -osboot<br />
O4 - HKLM\..\Run: [PC Pitstop Optimize Scheduler] C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe -boot<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [msnmsgr] &quot;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&quot; /background<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - Startup: Belkin Network USB Hub Control Center.lnk = C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe<br />
O4 - Global Startup: Empowering Technology Launcher.lnk = ?<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (file missing)<br />
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (file missing)<br />
O9 - Extra button: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - <a rel="nofollow" class="t" href="http://www.williamhillcasino.com" target="_blank">http://www.williamhillcasino.com</a> (file missing) (HKCU)<br />
O9 - Extra 'Tools' menuitem: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - <a rel="nofollow" class="t" href="http://www.williamhillcasino.com" target="_blank">http://www.williamhillcasino.com</a> (file missing) (HKCU)<br />
O13 - Gopher Prefix: <br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O20 - AppInit_DLLs: avgrsstx.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgfws9.exe<br />
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)<br />
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe<br />
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe<br />
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe<br />
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe<br />
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe<br />
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe<br />
<br />
--<br />
End of file - 9900 bytes<br />
<br />
<br />
Thanks</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Watson306</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234191.html</guid>
		</item>
		<item>
			<title>Malware -hacked by blaze 2008</title>
			<link>http://www.daniweb.com/forums/thread234088.html</link>
			<pubDate>Wed, 28 Oct 2009 08:18:07 GMT</pubDate>
			<description>my computers internet browser has been hacked by blaze 2008 
what is the solution for this malware attack .</description>
			<content:encoded><![CDATA[<div>my computers internet browser has been hacked by blaze 2008<br />
what is the solution for this malware attack .</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>ckoigi</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234088.html</guid>
		</item>
		<item>
			<title>Help please</title>
			<link>http://www.daniweb.com/forums/thread234076.html</link>
			<pubDate>Wed, 28 Oct 2009 07:27:21 GMT</pubDate>
			<description>i downloaded a song through limewire and the song required a license to be played. 
 
i tried to acquire the license and brought me to a page that advised me to download a mediaplayer. 
 
I continued with the process and cancelled the download of the mediaplayer but the download pushed through. 
...</description>
			<content:encoded><![CDATA[<div>i downloaded a song through limewire and the song required a license to be played.<br />
<br />
i tried to acquire the license and brought me to a page that advised me to download a mediaplayer.<br />
<br />
I continued with the process and cancelled the download of the mediaplayer but the download pushed through.<br />
<br />
I managed to take note of the data.<br />
<br />
I found them in my prefetch folder and eventually lost.<br />
<br />
C:\System Volume Information\_restore{40654d66-afb1-4435-998f-455e009153fa}\rp349\a0246806.exe ------ Deal Assistant<br />
<br />
Thanks.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>clark0516</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234076.html</guid>
		</item>
		<item>
			<title>Unable to get into CP or Properties</title>
			<link>http://www.daniweb.com/forums/thread234060.html</link>
			<pubDate>Wed, 28 Oct 2009 06:11:11 GMT</pubDate>
			<description>Hey guys, I recently started having some issues with my pc. I am running Win XP SP3 and running McAfee anti-virus program. It loads fine and I am able to get online but I no longer have the link to Control Panel on my start menu and I cannot access it from the command line. When I try to use the...</description>
			<content:encoded><![CDATA[<div>Hey guys, I recently started having some issues with my pc. I am running Win XP SP3 and running McAfee anti-virus program. It loads fine and I am able to get online but I no longer have the link to Control Panel on my start menu and I cannot access it from the command line. When I try to use the run command it gives me a pop-up that says 'This operation has been cancelled due to restrictions in effect on this computer. Please contact your system administrator&quot; even thought I am logged on as the administrator account. This happens when I try to get into the control panel or access my display properties from the desktop. I have already run a full scan with McAfee and MBA-M and fixed the issues that were found but I am still having this issue. Here is a log from HJT, any help or suggestions would be greatly appriciated.<br />
<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 11:15:13 PM, on 10/27/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Maxtor\Schedule2\schedul2.exe<br />
C:\WINDOWS\system32\CTsvcCDA.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe<br />
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br />
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\system32\PnkBstrA.exe<br />
C:\WINDOWS\system32\PnkBstrB.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\rundll32.exe<br />
c:\PROGRA~1\mcafee.com\agent\mcagent.exe<br />
C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe<br />
C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe<br />
C:\Program Files\Razer\Lachesis\razerhid.exe<br />
C:\WINDOWS\system32\RUNDLL32.EXE<br />
C:\Program Files\Razer\Lachesis\OSD.exe<br />
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDPop3.exe<br />
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe<br />
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDCountdown.exe<br />
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDMedia.exe<br />
C:\Program Files\Creative\Sound Blaster X-Fi\Console Launcher\CTAPR2.exe<br />
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\WINDOWS\system32\Rundll32.exe<br />
C:\Program Files\QuickTime\qttask.exe<br />
C:\Program Files\Razer\Lachesis\razertra.exe<br />
C:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe<br />
C:\Program Files\Razer\Lachesis\razerofa.exe<br />
C:\Program Files\Common Files\Maxtor\Schedule2\schedhlp.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Maxtor\MaxBlast\TimounterMonitor.exe<br />
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe<br />
C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe<br />
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe<br />
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe<br />
C:\Program Files\Java\jre6\bin\jucheck.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Documents and Settings\Administrator.OPTIMUS\Desktop\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)<br />
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll<br />
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll<br />
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [Launch LCDMon] &quot;C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe&quot;<br />
O4 - HKLM\..\Run: [Launch LGDCore] &quot;C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe&quot; /SHOWHIDE<br />
O4 - HKLM\..\Run: [Lachesis] C:\Program Files\Razer\Lachesis\razerhid.exe<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [mcagent_exe] &quot;C:\Program Files\McAfee.com\Agent\mcagent.exe&quot; /runkey<br />
O4 - HKLM\..\Run: [CTAPR2] &quot;C:\Program Files\Creative\Sound Blaster X-Fi\Console Launcher\CTAPR2.exe&quot; /r<br />
O4 - HKLM\..\Run: [VolPanel] &quot;C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe&quot; /r<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [SPIRun] Rundll32 SPIRun.dll,RunDLLEntry<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe<br />
O4 - HKLM\..\Run: [NBKeyScan] &quot;C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe&quot;<br />
O4 - HKLM\..\Run: [MaxBlastMonitor.exe] C:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe<br />
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Maxtor\MaxBlast\TimounterMonitor.exe<br />
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] &quot;C:\Program Files\Common Files\Maxtor\Schedule2\schedhlp.exe&quot;<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] &quot;C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe&quot;<br />
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork<br />
O4 - HKCU\..\Run: [DW6] &quot;C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe&quot;<br />
O4 - HKUS\S-1-5-21-57989841-1580818891-725345543-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Matthew')<br />
O4 - HKUS\S-1-5-21-57989841-1580818891-725345543-1003\..\Run: [Aim6]  (User 'Matthew')<br />
O4 - HKUS\S-1-5-21-57989841-1580818891-725345543-1003\..\Run: [Google Update] &quot;C:\Documents and Settings\Matthew\Local Settings\Application Data\Google\Update\GoogleUpdate.exe&quot; /c (User 'Matthew')<br />
O4 - HKUS\S-1-5-21-57989841-1580818891-725345543-1003\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork (User 'Matthew')<br />
O4 - HKUS\S-1-5-21-57989841-1580818891-725345543-1003\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (User 'Matthew')<br />
O4 - HKUS\S-1-5-21-57989841-1580818891-725345543-1003\..\Run: [Fraps] C:\PROGRAM FILES\FRAPS\FRAPS.EXE (User 'Matthew')<br />
O4 - HKUS\S-1-5-21-57989841-1580818891-725345543-1005\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Crystal')<br />
O4 - Global Startup: McAfee Security Scan.lnk = ?<br />
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?linkid=67633" target="_blank">http://go.microsoft.com/fwlink/?linkid=67633</a><br />
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} (Bebo Uploader Control) - <a rel="nofollow" class="t" href="http://www.bebo.com/files/BeboUploader.5.1.4.cab" target="_blank">http://www.bebo.com/files/BeboUploader.5.1.4.cab</a><br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?linkid=39204" target="_blank">http://go.microsoft.com/fwlink/?linkid=39204</a><br />
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - <a rel="nofollow" class="t" href="http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.7.109.cab" target="_blank">http://www.fileplanet.com/fpdlmgr/ca..._2.3.7.109.cab</a><br />
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} (MySpace Uploader Control) - <a rel="nofollow" class="t" href="http://lads.myspace.com/upload/MySpaceUploader2.cab" target="_blank">http://lads.myspace.com/upload/MySpaceUploader2.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a rel="nofollow" class="t" href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - <a rel="nofollow" class="t" href="http://www.creative.com/softwareupdate/su2/ocx/15106/CTPID.cab" target="_blank">http://www.creative.com/softwareupda...5106/CTPID.cab</a><br />
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O23 - Service: McAfee Application Installer Cleanup (0320551256121118) (0320551256121118mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\032055~1.EXE (file missing)<br />
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Maxtor\Schedule2\schedul2.exe<br />
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe<br />
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe<br />
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br />
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe<br />
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe<br />
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe<br />
<br />
--<br />
End of file - 12461 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>dR Occam</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread234060.html</guid>
		</item>
		<item>
			<title>hacked by sam 2008-feb-14 all the time</title>
			<link>http://www.daniweb.com/forums/thread233935.html</link>
			<pubDate>Tue, 27 Oct 2009 18:06:25 GMT</pubDate>
			<description>whenever i open the internet a caption at the end of the e icon appears thus;- Hacked by sam 2008-feb-14 . please help me on how to remove it since my anti virus and spyware are not equal to the task.</description>
			<content:encoded><![CDATA[<div>whenever i open the internet a caption at the end of the e icon appears thus;- Hacked by sam 2008-feb-14 . please help me on how to remove it since my anti virus and spyware are not equal to the task.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>bwanajim</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread233935.html</guid>
		</item>
		<item>
			<title>Control Panel not working</title>
			<link>http://www.daniweb.com/forums/thread233725.html</link>
			<pubDate>Tue, 27 Oct 2009 05:07:14 GMT</pubDate>
			<description>Hello Sir,  
 
On my laptop control panel is not working and also all the other programs are taking a ot of time to open and my internet explorer was showing as internet exploiter. 
Pls help. I dont want to format my laptop for some reasons. 
 
thanks in advance for your quick response and favoured...</description>
			<content:encoded><![CDATA[<div>Hello Sir, <br />
<br />
On my laptop control panel is not working and also all the other programs are taking a ot of time to open and my internet explorer was showing as internet exploiter.<br />
Pls help. I dont want to format my laptop for some reasons.<br />
<br />
thanks in advance for your quick response and favoured help.<br />
<br />
Sanjay</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>sheetalme</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread233725.html</guid>
		</item>
		<item>
			<title><![CDATA[Popups, Mbam.exe deleted, Anti virus websites "cannot be displayed":  Please help!]]></title>
			<link>http://www.daniweb.com/forums/thread233337.html</link>
			<pubDate>Mon, 26 Oct 2009 04:52:52 GMT</pubDate>
			<description><![CDATA[As the title states, mbam.exe is deleted from my hard drive even when I newly install malwarebytes, I'm getting many popups, and every antivirus website "cannot be displayed"   I will put up my Hijackthis file.   Thank you so much for the help!       
 
 
 
Logfile of Trend Micro HijackThis v2.0.2...]]></description>
			<content:encoded><![CDATA[<div>As the title states, mbam.exe is deleted from my hard drive even when I newly install malwarebytes, I'm getting many popups, and every antivirus website &quot;cannot be displayed&quot;   I will put up my Hijackthis file.   Thank you so much for the help!      <br />
<br />
<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 11:47:11 PM, on 10/25/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe<br />
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe<br />
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe<br />
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe<br />
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe<br />
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\UPHClean\uphclean.exe<br />
C:\WINDOWS\system32\CCM\CcmExec.exe<br />
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
C:\Program Files\Citrix\ICA Client\ssonsvr.exe<br />
C:\Program Files\Network Associates\Common Framework\UdaterUI.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe<br />
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe<br />
C:\Program Files\Network Associates\Common Framework\McTray.exe<br />
C:\WINDOWS\AGRSMMSG.exe<br />
C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE<br />
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe<br />
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe<br />
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe<br />
C:\WINDOWS\system32\hphmon05.exe<br />
C:\Program Files\Hewlett-Packard\ToolBoxFX\bin\HPTLBXFX.exe<br />
C:\Program Files\Hewlett-Packard\HP UT\bin\hppusg.exe<br />
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe<br />
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\WINDOWS\system32\igfxsrvc.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\WINDOWS\system32\HPZipm12.exe<br />
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE<br />
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe<br />
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe<br />
C:\Program Files\Logitech\QuickCam\Quickcam.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe<br />
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
c:\program files\logitech\quickcam\lu\lulnchr.exe<br />
c:\program files\common files\logitech\lu\lulnchr.exe<br />
c:\program files\common files\logitech\lu\LogitechUpdate.exe<br />
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\MSN\Toolbar\3.0.0988.2\msntask.exe<br />
C:\Program Files\McAfee\VirusScan Enterprise\EntVUtil.EXE<br />
C:\Program Files\McAfee\VirusScan Enterprise\EntVUtil.EXE<br />
C:\Program Files\McAfee\VirusScan Enterprise\EntVUtil.EXE<br />
C:\WINDOWS\Explorer.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://toolbar.ask.com/toolbarv/askRedirect?o=20008&amp;gct=&amp;gc=1&amp;q=" target="_blank">http://toolbar.ask.com/toolbarv/askR...8&amp;gct=&amp;gc=1&amp;q=</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = <a rel="nofollow" class="t" href="http://toolbar.ask.com/toolbarv/askRedirect?o=20008&amp;gct=&amp;gc=1&amp;q=" target="_blank">http://toolbar.ask.com/toolbarv/askR...8&amp;gct=&amp;gc=1&amp;q=</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = <a rel="nofollow" class="t" href="http://toolbar.ask.com/toolbarv/askRedirect?o=20008&amp;gct=&amp;gc=1&amp;q=%s" target="_blank">http://toolbar.ask.com/toolbarv/askR...gct=&amp;gc=1&amp;q=%s</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 10.*.*.*;127.0.0.1;*.hanson-america.net;*.hanson-eu.net;*.hanson-ap.net;*.hgm.han;;;;&lt;local&gt;;*.local<br />
R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll<br />
F2 - REG:system.ini: Shell=Explorer.exe logon.exe<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll<br />
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br />
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll<br />
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll<br />
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll<br />
O4 - HKLM\..\Run: [McAfeeUpdaterUI] &quot;C:\Program Files\Network Associates\Common Framework\UdaterUI.exe&quot; /StartedFromRunKey<br />
O4 - HKLM\..\Run: [Client Access Service] &quot;C:\Program Files\IBM\Client Access\cwbsvstr.exe&quot;<br />
O4 - HKLM\..\Run: [Client Access Help Update] &quot;C:\Program Files\IBM\Client Access\cwbinhlp.exe&quot;<br />
O4 - HKLM\..\Run: [Client Access Check Version] &quot;C:\Program Files\IBM\Client Access\cwbckver.exe&quot; LOGIN<br />
O4 - HKLM\..\Run: [Client Access Express Welcome] &quot;C:\Program Files\IBM\Client Access\cwbwlwiz.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe<br />
O4 - HKLM\..\Run: [RoxioDragToDisc] &quot;C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe&quot;<br />
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe<br />
O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start<br />
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\HPQ\IAM\Bin\AsTsVcc.dll,RegisterModule<br />
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe<br />
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe<br />
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe<br />
O4 - HKLM\..\Run: [HP Component Manager] &quot;C:\Program Files\HP\hpcoretech\hpcmpmgr.exe&quot;<br />
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe<br />
O4 - HKLM\..\Run: [ToolBoxFX] &quot;C:\Program Files\Hewlett-Packard\ToolBoxFX\bin\HPTLBXFX.exe&quot; /enum:on /alerts:on /systrayIcon:on<br />
O4 - HKLM\..\Run: [HPUsageTracking] &quot;C:\Program Files\Hewlett-Packard\HP UT\bin\hppusg.exe&quot; &quot;C:\Program Files\Hewlett-Packard\HP UT\&quot;<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [ShStatEXE] &quot;C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE&quot; /STANDALONE<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [LogitechCommunicationsManager] &quot;C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe&quot;<br />
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] &quot;C:\Program Files\Logitech\QuickCam\Quickcam.exe&quot; /hide<br />
O4 - HKLM\..\Run: [gayamoyak] Rundll32.exe &quot;c:\windows\system32\lupuwufe.dll&quot;,a<br />
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;<br />
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe<br />
O4 - Global Startup: VPN Client.lnk = ?<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll<br />
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?linkid=58813" target="_blank">http://go.microsoft.com/fwlink/?linkid=58813</a><br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?linkid=39204" target="_blank">http://go.microsoft.com/fwlink/?linkid=39204</a><br />
O16 - DPF: {62CEC9E0-3811-4C36-A94E-4F7565DCD23F} (DDSC Class) - <a rel="nofollow" class="t" href="http://hansononline/hbma/Portal/resources/msddsc.cab" target="_blank">http://hansononline/hbma/Portal/resources/msddsc.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a rel="nofollow" class="t" href="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1171470851375" target="_blank">http://update.microsoft.com/windowsu...?1171470851375</a><br />
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - <a rel="nofollow" class="t" href="https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx" target="_blank">https://h17000.www1.hp.com/ewfrf-JAV...oadManager.ocx</a><br />
O16 - DPF: {CAFECAFE-0013-0001-0021-ABCDEFABCDEF} (JInitiator 1.3.1.21) - <a rel="nofollow" class="t" href="http://usirapp01.hanson-america.net:8010/jinitiator/oajinit.exe" target="_blank">http://usirapp01.hanson-america.net:...or/oajinit.exe</a><br />
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = grouphc.net<br />
O17 - HKLM\Software\..\Telephony: DomainName = grouphc.net<br />
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = grouphc.net<br />
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = grouphc.net<br />
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll<br />
O20 - AppInit_DLLs: C:\WINDOWS\system32\APSHook.dll c:\windows\system32\lupuwufe.dll,dukazewe.dll<br />
O20 - Winlogon Notify: OneCard - C:\Program Files\HPQ\IAM\Bin\AsWlnPkg.dll<br />
O21 - SSODL: zetafogig - {ac55fe80-304d-4b4b-ae1a-878ce1f78584} - c:\windows\system32\lupuwufe.dll<br />
O22 - SharedTaskScheduler: mujuzedij - {ac55fe80-304d-4b4b-ae1a-878ce1f78584} - c:\windows\system32\lupuwufe.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe<br />
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe<br />
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe<br />
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe<br />
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe<br />
<br />
--<br />
End of file - 13508 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>iceicle1324</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread233337.html</guid>
		</item>
		<item>
			<title>My keys have gone mad, please help me.</title>
			<link>http://www.daniweb.com/forums/thread233157.html</link>
			<pubDate>Sun, 25 Oct 2009 12:58:58 GMT</pubDate>
			<description><![CDATA[Hello, 
Since a few days I have been having problems with some of the keys on my laptop. I'm not sure if the problem is due to a virus or a configuration problem, but I can't remeber either downloading o changing anythng prior to the problems occuring. This is what has happened; whenever I press...]]></description>
			<content:encoded><![CDATA[<div>Hello,<br />
Since a few days I have been having problems with some of the keys on my laptop. I'm not sure if the problem is due to a virus or a configuration problem, but I can't remeber either downloading o changing anythng prior to the problems occuring. This is what has happened; whenever I press the keys 8, u, i, j, m or b any number of things will happen. Instead of just typing the key I press a sequence of letters is typed (without me doing anything) or commands are executed. Each key has a limited number of different responses (I don't get a new, random, respons everytime), but I have not yet been able to find any pattern in the way a specific key chooses between these limited options. In other words, I know the dfferent possible responses for pressing &quot;i&quot;, but I don't know which one will be used. Below you can see some of the different responses:<br />
i: &quot;qetgio&quot;, &quot;tgio¨&quot;, etc. Also enters shorcut menus while in Office (same result as pressing Alt while in Office), etc<br />
u: &quot;24ryu0&quot;, &quot;å&quot;, &quot;yu0&quot;, etc. Also opens Excel, Internet Explorer, Window's option &quot;Run&quot; and activates Caps Lock, etc. <br />
j: &quot;wdfhjl&quot;, &quot;Ä&lt; WDF&quot;, etc. Also acts as &quot;Delete&quot; button, etc.<br />
8: &quot;135789&quot;, &quot;´P&quot;, etc. Also acts as &quot;Delete&quot; button, etc.<br />
m: &quot;zxvnm&quot;, &quot;m,&quot;, etc. <br />
b: &quot;sackb.&quot;, etc. Also acts as &quot;Ctrl+P&quot;, etc<br />
I would be very grateful for any kind of help that will allow me to use my computer normaly again.<br />
Sebastian</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>s_irminger</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread233157.html</guid>
		</item>
		<item>
			<title><![CDATA[Virus where control panel won't open]]></title>
			<link>http://www.daniweb.com/forums/thread233096.html</link>
			<pubDate>Sun, 25 Oct 2009 06:51:10 GMT</pubDate>
			<description><![CDATA[I downloaded a torrent and got a virus. Google links take me to bizaare places. "unauthorized changes were made to widows." My start up programs change. And most bothersome, my control panel won't open. Also, most recently, I can't print (or even create PDF's) 
 
I was reading the forums here and...]]></description>
			<content:encoded><![CDATA[<div>I downloaded a torrent and got a virus. Google links take me to bizaare places. &quot;unauthorized changes were made to widows.&quot; My start up programs change. And most bothersome, my control panel won't open. Also, most recently, I can't print (or even create PDF's)<br />
<br />
I was reading the forums here and came across <a rel="nofollow" class="t" href="http://www.daniweb.com/forums/thread98509.html" target="_blank">http://www.daniweb.com/forums/thread98509.html</a> which the person had very similar symptoms but I didn't want to assume that it was the same virus and follow the same steps as he did.<br />
<br />
Here's the hack this log <br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 2:37:41 AM, on 10/25/2009<br />
Platform: Windows Vista  (WinNT 6.00.1904)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16916)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\csrss.exe<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\csrss.exe<br />
C:\Windows\system32\services.exe<br />
C:\Windows\system32\lsass.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\winlogon.exe<br />
C:\Windows\system32\svchost.exe<br />
C:\Windows\system32\svchost.exe<br />
C:\Windows\System32\svchost.exe<br />
C:\Windows\System32\svchost.exe<br />
C:\Windows\System32\svchost.exe<br />
C:\Windows\system32\svchost.exe<br />
C:\Windows\system32\AUDIODG.EXE<br />
C:\Windows\system32\SLsvc.exe<br />
C:\Windows\system32\svchost.exe<br />
C:\Windows\system32\svchost.exe<br />
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
C:\Windows\system32\sdra64.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\tsnpstd3.exe<br />
C:\Desktop\ThreatFire\TFTray.exe<br />
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe<br />
C:\Windows\vsnpstd3.exe<br />
C:\Program Files\NVIDIA Corporation\NvMixer\NvMixerTray.exe<br />
C:\Windows\mixer.exe<br />
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe<br />
C:\Program Files\Alwil Software\Avast4\ashDisp.exe<br />
C:\Program Files\RocketDock\RocketDock.exe<br />
C:\Program Files\DNA\btdna.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\svchost.exe<br />
C:\Program Files\Prevx\prevx.exe<br />
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe<br />
C:\Windows\system32\svchost.exe<br />
C:\Windows\System32\svchost.exe<br />
C:\Windows\System32\svchost.exe<br />
C:\Windows\system32\svchost.exe<br />
C:\Windows\system32\svchost.exe<br />
C:\Desktop\ThreatFire\TFService.exe<br />
C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
C:\Windows\System32\svchost.exe<br />
C:\Windows\system32\WUDFHost.exe<br />
C:\Program Files\Prevx\prevx.exe<br />
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
C:\Windows\system32\svchost.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\svchost.exe<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe<br />
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE<br />
C:\Windows\system32\vssvc.exe<br />
C:\Windows\System32\svchost.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe<br />
C:\Windows\System32\mobsync.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.yahoo.com/" target="_blank">http://www.yahoo.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,C:\Windows\system32\sdra64.exe,<br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (file missing)<br />
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br />
O2 - BHO: ads_optimizer - {9C8A568E-4201-478a-8536-526CF371D2E2} - C:\Windows\system32\nssD06D.dll (file missing)<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll<br />
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O3 - Toolbar: &amp;RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (file missing)<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [tsnpstd3] C:\Windows\tsnpstd3.exe<br />
O4 - HKLM\..\Run: [ThreatFire] C:\Desktop\ThreatFire\TFTray.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [snpstd3] C:\Windows\vsnpstd3.exe<br />
O4 - HKLM\..\Run: [NvMixerTray] C:\Program Files\NVIDIA Corporation\NvMixer\NvMixerTray.exe<br />
O4 - HKLM\..\Run: [manager] &quot;C:\Windows\System32\drivers\setup\manager.exe&quot;<br />
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe<br />
O4 - HKLM\..\Run: [CmPCIaudio] RunDll32 CMICNFG3.CPL,CMICtrlWnd<br />
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup<br />
O4 - HKLM\..\Run: [RoxWatchTray] &quot;C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] &quot;C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] &quot;C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\Run: [MSConfig] &quot;C:\Windows\System32\msconfig.exe&quot; /auto<br />
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
O4 - HKCU\..\Run: [RocketDock] &quot;C:\Program Files\RocketDock\RocketDock.exe&quot;<br />
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] &quot;C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe&quot; ASO-616B5711-6DAE-4795-A05F-39A1E5104020<br />
O4 - HKCU\..\Run: [BitTorrent DNA] &quot;C:\Program Files\DNA\btdna.exe&quot;<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;<br />
O4 - HKCU\..\Run: [ISUSPM] &quot;C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe&quot; -scheduler<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br />
O4 - Global Startup: VPN Client.lnk = ?<br />
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html<br />
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html<br />
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html (file missing)<br />
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html (file missing)<br />
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html (file missing)<br />
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html (file missing)<br />
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html (file missing)<br />
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html (file missing)<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - <a rel="nofollow" class="t" href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" target="_blank">http://upload.facebook.com/controls/...oUploader5.cab</a><br />
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - <a rel="nofollow" class="t" href="http://www.worldwinner.com/games/v47/shared/FunGamesLoader.cab" target="_blank">http://www.worldwinner.com/games/v47...amesLoader.cab</a><br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll<br />
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - <a rel="nofollow" class="t" href="http://gfx2.hotmail.com/mail/w2/resources/VistaMSNPUplden-us.cab" target="_blank">http://gfx2.hotmail.com/mail/w2/reso...PUplden-us.cab</a><br />
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - <a rel="nofollow" class="t" href="http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab" target="_blank">http://www.worldwinner.com/games/v46.../bejeweled.cab</a><br />
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - <a rel="nofollow" class="t" href="http://www.worldwinner.com/games/shared/wwlaunch.cab" target="_blank">http://www.worldwinner.com/games/shared/wwlaunch.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a rel="nofollow" class="t" href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - <a rel="nofollow" class="t" href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL<br />
O20 - AppInit_DLLs: acaptuser32.dll<br />
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
O23 - Service: CSIScanner - Prevx - C:\Program Files\Prevx\prevx.exe<br />
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe<br />
O23 - Service: ThreatFire - PC Tools - C:\Desktop\ThreatFire\TFService.exe<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
<br />
--<br />
End of file - 14034 bytes<br />
<br />
<br />
Someone please assist I'm in college and really need my comp as i go for graphic design.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Colloquist</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread233096.html</guid>
		</item>
		<item>
			<title>Random Audio Commercials?</title>
			<link>http://www.daniweb.com/forums/thread233070.html</link>
			<pubDate>Sun, 25 Oct 2009 04:43:39 GMT</pubDate>
			<description><![CDATA[Random audio commercials play when I have no browsers or windows open. I have tried looking thrugh my processes screen for cpu usage, but it changes so fast I can't catch it. Any advice would be helpful. Also, any files I can delete to allow my computer to run better would also be helpful. This is...]]></description>
			<content:encoded><![CDATA[<div>Random audio commercials play when I have no browsers or windows open. I have tried looking thrugh my processes screen for cpu usage, but it changes so fast I can't catch it. Any advice would be helpful. Also, any files I can delete to allow my computer to run better would also be helpful. This is my HJT report. <br />
<br />
<br />
Logfile of HijackThis v1.99.1<br />
Scan saved at 12:41:46 AM, on 10/25/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16915)<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\ehome\ehtray.exe<br />
C:\Program Files\Digital Media Reader\readericon45G.exe<br />
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe<br />
C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe<br />
C:\Program Files\QuickTime\qttask.exe<br />
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
C:\Program Files\Yahoo!\Common\YMailAdvisor.exe<br />
C:\Program Files\Intel\IntelDH\CCU\CCU_Engine.exe<br />
C:\Program Files\Google\Google Desktop Search\gcdtmp377\GoogleDesktopSetupHelper.exe<br />
C:\Program Files\Logitech\QuickCam\Quickcam.exe<br />
C:\Program Files\Razer\Lachesis\razerhid.exe<br />
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe<br />
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe<br />
C:\Program Files\Skype\Phone\Skype.exe<br />
C:\Program Files\NBC Direct\DirectPlayerCore.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br />
C:\Program Files\Logitech\SetPoint\SetPoint.exe<br />
C:\Program Files\Intel\IntelDH\CCU\AlertService.exe<br />
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe<br />
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE<br />
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe<br />
C:\Program Files\OpenOffice.org 3\program\soffice.exe<br />
C:\Program Files\OpenOffice.org 3\program\soffice.bin<br />
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe<br />
C:\WINDOWS\arservice.exe<br />
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
C:\Program Files\Razer\Lachesis\razerofa.exe<br />
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe<br />
C:\WINDOWS\eHome\ehRecvr.exe<br />
C:\WINDOWS\eHome\ehSched.exe<br />
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe<br />
C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br />
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS<br />
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe<br />
C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WLService.exe<br />
C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WUSB54GSC.exe<br />
C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WMP54GSv1_1.exe<br />
C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe<br />
C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe<br />
C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe<br />
C:\Program Files\Skype\Plugin Manager\skypePM.exe<br />
C:\Program Files\AVG\AVG8\avgcsrvx.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\WINDOWS\system32\rsvp.exe<br />
C:\PROGRA~1\COMMON~1\AOL\115885~1\EE\AOLHOS~1.EXE<br />
C:\PROGRA~1\COMMON~1\AOL\115885~1\EE\AOLServiceHost.exe<br />
C:\WINDOWS\system32\wmdtc.exe<br />
C:\Program Files\Pando Networks\Media Booster\pmb.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\WINDOWS\eHome\ehmsas.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\FastNetSrv.exe<br />
C:\Program Files\Java\jre6\bin\jucheck.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\Program Files\Windows Live\Contacts\wlcomm.exe<br />
C:\Program Files\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\Owner.KATRINA\Desktop\HijackThis.exe<br />
C:\WINDOWS\system32\lsm32.sys<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a rel="nofollow" class="t" href="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html" target="_blank">http://us.rd.yahoo.com/customize/ie/...ch/search.html</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll<br />
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll<br />
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll<br />
O3 - Toolbar: &amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe<br />
O4 - HKLM\..\Run: [Google Desktop Search] &quot;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&quot; /startup<br />
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe<br />
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE<br />
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe<br />
O4 - HKLM\..\Run: [IntelAudioStudio] &quot;C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe&quot; BOOT<br />
O4 - HKLM\..\Run: [CCUTRAYICON] C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe<br />
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [YMailAdvisor] &quot;C:\Program Files\Yahoo!\Common\YMailAdvisor.exe&quot;<br />
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] &quot;C:\Program Files\Logitech\QuickCam\Quickcam.exe&quot; /hide<br />
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE<br />
O4 - HKLM\..\Run: [Lachesis] C:\Program Files\Razer\Lachesis\razerhid.exe<br />
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe<br />
O4 - HKCU\..\Run: [Power2GoExpress] NA<br />
O4 - HKCU\..\Run: [Yahoo! Pager] &quot;C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe&quot; -quiet<br />
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe<br />
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe<br />
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
O4 - HKCU\..\Run: [Skype] &quot;C:\Program Files\Skype\Phone\Skype.exe&quot; /nosplash /minimized<br />
O4 - HKCU\..\Run: [DirectPlayerCore] &quot;C:\Program Files\NBC Direct\DirectPlayerCore.exe&quot;<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - Startup: GameSpot Download Manager.lnk = C:\Program Files\GameSpot\GameSpotDownloadManager_Win32.exe<br />
O4 - Startup: Logitech . Product Registration.lnk = C:\Program Files\Common Files\logishrd\eReg\SetPoint\eReg.exe<br />
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe<br />
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe<br />
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe<br />
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe<br />
O8 - Extra context menu item: &amp;AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html<br />
O8 - Extra context menu item: Add to Windows &amp;Live Favorites - http://favorites.live.com/quickadd.aspx<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll<br />
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll<br />
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O11 - Options group: [INTERNATIONAL] International*<br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab<br />
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab<br />
O16 - DPF: {28E2EDF1-2383-4BA9-9A8C-980D1414B3B0} (ctrlNev1.ctrlNev) - http://www2.neveron.com/ctrlNev1.CAB<br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll<br />
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab<br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1187720086703<br />
O16 - DPF: {64D01C7F-810D-446E-A07E-16C764235644} (AtlAtomadersCtlAttrib Class) - http://zone.msn.com/bingame/amad/default/atomaders.cab<br />
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab<br />
O16 - DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} (compid Class) - http://support.gateway.com/support/serialharvest/gwCID.CAB<br />
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab<br />
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab<br />
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll<br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL<br />
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)<br />
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll<br />
O20 - Winlogon Notify: LBTWlgn - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll<br />
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll<br />
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll<br />
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br />
O23 - Service: Intel(R) Alert Service (AlertService) - Intel Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe<br />
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe<br />
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe<br />
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: Intel(R) Quick Resume technology (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe<br />
O23 - Service: fastnetsrv  Service (fastnetsrv) - Netopsystems A - C:\WINDOWS\system32\FastNetSrv.exe<br />
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br />
O23 - Service: Google Update Service (gupdate1c9d6e8a832a76c) (gupdate1c9d6e8a832a76c) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe&quot; /svc (file missing)<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe<br />
O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe&quot; -service -config &quot;C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)<br />
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe<br />
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe<br />
O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe<br />
O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS<br />
O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
O23 - Service: WMP54GSSVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe&quot; &quot;WMP54GSv1_1.exe (file missing)<br />
O23 - Service: WUSB54GSCSVC - Unknown owner - C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WLService.exe&quot; &quot;WUSB54GSC.exe (file missing)</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>firebat757</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread233070.html</guid>
		</item>
		<item>
			<title>Windows Vista .dll errors apon opening any program and boot</title>
			<link>http://www.daniweb.com/forums/thread233030.html</link>
			<pubDate>Sun, 25 Oct 2009 00:03:20 GMT</pubDate>
			<description>Can anyone help me with my computer issue. I have a Windows Vista computer and am getting error messages on boot of the pc and when opening every program.  
 
Error: 
 
c:\Progra~2\jedubaji.dll is either not designed to run on Windows or it contains an error. Try installing the program again using...</description>
			<content:encoded><![CDATA[<div>Can anyone help me with my computer issue. I have a Windows Vista computer and am getting error messages on boot of the pc and when opening every program. <br />
<br />
Error:<br />
<br />
c:\Progra~2\jedubaji.dll is either not designed to run on Windows or it contains an error. Try installing the program again using hte original installation media or contact your system administrator or the software vendor for support. <br />
<br />
On the top right hand corner of the error shows multiple different Bad image errors after pressing okay multiple times.<br />
<br />
ie4uinit.exe - Bad image (then the above error for each of these)<br />
rundll32.exe - Bad image<br />
AtBroker.exe<br />
SkyTel.exe<br />
Dwm.exe<br />
explorer.exe<br />
Spmgr.exe<br />
OSK.exe<br />
SynTPEnh.exe<br />
ISBMgr.exe<br />
AppMonUtility.exe<br />
IAAnotif.exe<br />
HpqSRmon.exe<br />
LaunchVHSD.exe<br />
hpwuSchd2.exe<br />
Reminderapp.exe<br />
RtHDVCpl.exe<br />
VCAB.exe<br />
Vista VAIO Survey.exe<br />
<br />
<br />
I have looked on other Vista machines and do not find a jedubaji.dll file on them. I've seen like error messages before and just copied from one pc to the other and fixed it but do not see this .dll file. I have also run a virus scan on the computer with no luck. Thanks.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>tootsiepell</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread233030.html</guid>
		</item>
		<item>
			<title>malware bites problem</title>
			<link>http://www.daniweb.com/forums/thread233010.html</link>
			<pubDate>Sat, 24 Oct 2009 21:18:22 GMT</pubDate>
			<description>So today I got about 12 virus from a link, which was stupid of me but now i know.  I disconnected my internet cord so nothing else could be downloaded. anyways I tried to run malwarebytes which was already installed on my computer so I click the shortcut, but it says that it cannot find the exe to...</description>
			<content:encoded><![CDATA[<div>So today I got about 12 virus from a link, which was stupid of me but now i know.  I disconnected my internet cord so nothing else could be downloaded. anyways I tried to run malwarebytes which was already installed on my computer so I click the shortcut, but it says that it cannot find the exe to start it.  I also started to get popups saying my computer was at risk and all these fake antivirus programs could help me and what not.  Then my desktop turned black except for the taskbar at the bottom so my computer was still functional.  <br />
eventually I thought of closing the explorer.exe and reopening it which brought my desktop back but I saw that some shortcuts were created and it looked like it was linking to porn sites.  I have avira antivirus so I ran a scan and it only showed a couple of warnings so that was no help.  I looked through my C drive looking for any files or folders that were created around 1 oclock which is when I first got the warnings.  I found around 20 or more files in temp. folders or areas similar to it, things like installer.exe, the icons for the pornsites that were on my desktop. I deleted those and the popups stopped.  <br />
Once everthing seemed ok, I uninstalled malwarebites and restarted my computer, tried to reinstall it and when I check the &quot;run malwarebites&quot; at the end of the instalation, I get this error<br />
<br />
Unable to execute file C:\etc\etc\mbam.exe<br />
CreateProcess failed; Code 2<br />
The System cannot find the file specified<br />
<br />
, also since I restarted my computer I have gotten popups again but these ones are advertising newspaper websites with articles, one of then was even for google.<br />
<br />
Also--I know that bittorrent is going to show up in the logfile but I have not used that in at least a year now<br />
<br />
thankyou everyone for any help that you can provide.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 5:16:02 PM, on 10/24/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16827)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe<br />
C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\WINDOWS\eHome\ehRecvr.exe<br />
C:\WINDOWS\eHome\ehSched.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Alias\Maya7.0\docs\wrapper.exe<br />
C:\Program Files\Alias\Maya7.0\docs\jre\bin\java.exe<br />
C:\WINDOWS\system32\PnkBstrA.exe<br />
C:\WINDOWS\system32\PnkBstrB.exe<br />
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe<br />
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv4.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\ehome\ehtray.exe<br />
C:\Program Files\Digital Media Reader\shwiconem.exe<br />
C:\WINDOWS\eHome\ehmsas.exe<br />
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIALA.EXE<br />
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe<br />
C:\WINDOWS\system32\RUNDLL32.EXE<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Downloads\fraps\ \Games and vieds\Daemon tooks lite\DAEMON Tools Lite\daemon.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Documents and Settings\Chris\Application Data\Juniper Networks\Setup Client\JuniperSetupClient.exe<br />
C:\Documents and Settings\Chris\Application Data\Juniper Networks\UAC Host Checker\uacHostChecker.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://finance.yahoo.com/q?s=LVS" target="_blank">http://finance.yahoo.com/q?s=LVS</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.gatewaybiz.com" target="_blank">http://www.gatewaybiz.com</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
O2 - BHO: Skype add-on (mastermind) - {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe<br />
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br />
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe<br />
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe<br />
O4 - HKLM\..\Run: [IntelAudioStudio] &quot;C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe&quot; BOOT<br />
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe<br />
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE<br />
O4 - HKLM\..\Run: [RemoteControl] &quot;C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe&quot;<br />
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe<br />
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u<br />
O4 - HKLM\..\Run: [Adobe Photo Downloader] &quot;C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [EPSON Stylus CX5800F Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIALA.EXE /P27 &quot;EPSON Stylus CX5800F Series&quot; /O6 &quot;USB001&quot; /M &quot;Stylus CX5800F&quot;<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [avgnt] &quot;C:\Program Files\Avira\AntiVir Desktop\avgnt.exe&quot; /min<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [91168126] C:\Documents and Settings\All Users\Application Data\91168126\91168126.exe<br />
O4 - HKLM\..\Run: [natobunod] Rundll32.exe &quot;c:\windows\system32\zowevele.dll&quot;,a<br />
O4 - HKLM\..\Run: [31191924] C:\DOCUME~1\ALLUSE~1\APPLIC~1\31191924\31191924.exe<br />
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;<br />
O4 - HKCU\..\Run: [BitTorrent] &quot;C:\Program Files\BitTorrent\bittorrent.exe&quot; --force_start_minimized<br />
O4 - HKCU\..\Run: [Google Update] &quot;C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Update\GoogleUpdate.exe&quot; /c<br />
O4 - HKCU\..\Run: [DAEMON Tools Lite] &quot;C:\Downloads\fraps\ \Games and vieds\Daemon tooks lite\DAEMON Tools Lite\daemon.exe&quot; -autorun<br />
O4 - Global Startup: Adobe Gamma Loader.lnk = ?<br />
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Skype - {77bf5300-1474-4ec7-9980-d32b190e9b07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - <a rel="nofollow" class="t" href="http://www.musicnotes.com/download/mnviewer.cab" target="_blank">http://www.musicnotes.com/download/mnviewer.cab</a><br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkID=39204" target="_blank">http://go.microsoft.com/fwlink/?LinkID=39204</a><br />
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - <a rel="nofollow" class="t" href="http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab" target="_blank">http://www.nvidia.com/content/Driver...reqlab_nvd.cab</a><br />
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - <a rel="nofollow" class="t" href="http://www.eset.eu/buxus/docs/OnlineScanner.cab" target="_blank">http://www.eset.eu/buxus/docs/OnlineScanner.cab</a><br />
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Futuremark SystemInfo) - <a rel="nofollow" class="t" href="http://service.futuremark.com/virtualmark/tc/FMSI.cab" target="_blank">http://service.futuremark.com/virtualmark/tc/FMSI.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a rel="nofollow" class="t" href="http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...nt/swflash.cab</a><br />
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupControlXP Class) - <a rel="nofollow" class="t" href="https://juniper.net/dana-cached/setup/JuniperSetupSP1.cab" target="_blank">https://juniper.net/dana-cached/setu...erSetupSP1.cab</a><br />
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - <a rel="nofollow" class="t" href="http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5041/mcfscan.cab" target="_blank">http://download.mcafee.com/molbin/is...41/mcfscan.cab</a><br />
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} (JuniperSetupClientControl Class) - <a rel="nofollow" class="t" href="https://uac.gmu.edu/dana-cached/sc/JuniperSetupClient.cab" target="_blank">https://uac.gmu.edu/dana-cached/sc/J...etupClient.cab</a><br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O20 - AppInit_DLLs: kufezayu.dll c:\windows\system32\zowevele.dll<br />
O20 - Winlogon Notify: iifdDtQj - iifdDtQj.dll (file missing)<br />
O21 - SSODL: sotivodiw - {c64d3466-309c-4de8-a8ee-937b8bc56aae} - c:\windows\system32\zowevele.dll<br />
O22 - SharedTaskScheduler: jugezatag - {c64d3466-309c-4de8-a8ee-937b8bc56aae} - c:\windows\system32\zowevele.dll<br />
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe<br />
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Maya 7.0 Documentation Server (maya70docserver) - Unknown owner - C:\Program Files\Alias\Maya7.0\docs\wrapper.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe<br />
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe<br />
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS<br />
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (file missing)<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\<br />
O23 - Service: WUSB54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe<br />
<br />
--<br />
End of file - 11953 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Helpmycomp.</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread233010.html</guid>
		</item>
		<item>
			<title>Peace Of Mind re Trojans</title>
			<link>http://www.daniweb.com/forums/thread232776.html</link>
			<pubDate>Sat, 24 Oct 2009 02:34:45 GMT</pubDate>
			<description>Howdy 
 
I ran my scheduled anti virus scan using Virgin PC Guard and it detected a trojan called trojan.js.agent.se and when the scan finished the trojan was quarantined.  
 
When I googled the trojan, I read an article saying to delete all my temporary internet files, which I have done. 
 
I have...</description>
			<content:encoded><![CDATA[<div>Howdy<br />
<br />
I ran my scheduled anti virus scan using Virgin PC Guard and it detected a trojan called trojan.js.agent.se and when the scan finished the trojan was quarantined. <br />
<br />
When I googled the trojan, I read an article saying to delete all my temporary internet files, which I have done.<br />
<br />
I have now re run the virus scan and nothing was detected. I have also run scans using Spybot, Superantispyware and Malwarebytes Anti-Malware and none of these scans detected anything. This is good right??<br />
<br />
Could someone confirm that this trojan has gone and everything is back to normal??<br />
<br />
Thanks :)</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>McDaddy17</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread232776.html</guid>
		</item>
		<item>
			<title>Crontrol Panel not accessable</title>
			<link>http://www.daniweb.com/forums/thread232774.html</link>
			<pubDate>Sat, 24 Oct 2009 02:28:41 GMT</pubDate>
			<description><![CDATA[hi guys help me out with this one,I'm using windows Vista and recently when i tried to acces control panel from the start menu, i get a message "application not found",however i can access using window explorer,i cannot acces regedit it saying path not found,some of my programs are corrupted what...]]></description>
			<content:encoded><![CDATA[<div>hi guys help me out with this one,I'm using windows Vista and recently when i tried to acces control panel from the start menu, i get a message &quot;application not found&quot;,however i can access using window explorer,i cannot acces regedit it saying path not found,some of my programs are corrupted what do i do,i'm using avast antivirus</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Ms Technology</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread232774.html</guid>
		</item>
		<item>
			<title>help please ... trojan.vundo... hijackthis log...</title>
			<link>http://www.daniweb.com/forums/thread232403.html</link>
			<pubDate>Thu, 22 Oct 2009 18:56:21 GMT</pubDate>
			<description>Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 1:45:31 PM, on 10/22/2009 
Platform: Windows XP SP2 (WinNT 5.01.2600) 
MSIE: Internet Explorer v8.00 (8.00.6001.18702) 
Boot mode: Safe mode with network support 
 
Running processes: 
C:\WINDOWS\System32\smss.exe...</description>
			<content:encoded><![CDATA[<div>Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 1:45:31 PM, on 10/22/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Safe mode with network support<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\WINDOWS\system32\NOTEPAD.EXE<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://www.google.com/ig/dell?hl=en&amp;client=dell-usuk-rel&amp;channel=us&amp;ibd=2070709" target="_blank">http://www.google.com/ig/dell?hl=en&amp;...us&amp;ibd=2070709</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.yahoo.com/" target="_blank">http://www.yahoo.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = <a rel="nofollow" class="t" href="http://www.google.com/ig/dell?hl=en&amp;client=dell-usuk-rel&amp;channel=us&amp;ibd=2070709" target="_blank">http://www.google.com/ig/dell?hl=en&amp;...us&amp;ibd=2070709</a><br />
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll<br />
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe<br />
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe<br />
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe<br />
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br />
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br />
O4 - HKLM\..\Run: [ISUSScheduler] &quot;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&quot; -start<br />
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe<br />
O4 - HKLM\..\Run: [UPSMON] C:\Program Files\UPSMON\UPSMON.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [ccApp] &quot;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&quot;<br />
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe<br />
O4 - HKLM\..\Run: [nozekihaw] Rundll32.exe &quot;c:\windows\system32\gohifodi.dll&quot;,a<br />
O4 - HKLM\..\Run: [16757733] C:\DOCUME~1\ALLUSE~1\APPLIC~1\16757733\16757733.exe<br />
O4 - HKCU\..\Run: [DellSupport] &quot;C:\Program Files\DellSupport\DSAgnt.exe&quot; /startup<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [ISUSPM] &quot;C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe&quot; -scheduler<br />
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {FB298ECE-4D17-414A-A5E8-FABC938796B2} (ActiveWebParts Illustration Viewer) - <a rel="nofollow" class="t" href="http://www.kohlerplus.com/_bin/AWSDrawingViewer.cab" target="_blank">http://www.kohlerplus.com/_bin/AWSDrawingViewer.cab</a><br />
O20 - AppInit_DLLs: repozuyi.dll c:\windows\system32\gohifodi.dll<br />
O21 - SSODL: zorulazot - {fc602be9-2959-4ecf-8a24-0d8c909c4b0f} - c:\windows\system32\gohifodi.dll<br />
O22 - SharedTaskScheduler: jugezatag - {fc602be9-2959-4ecf-8a24-0d8c909c4b0f} - c:\windows\system32\gohifodi.dll<br />
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br />
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe<br />
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br />
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe<br />
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br />
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br />
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br />
O23 - Service: UPSMONService - Unknown owner - C:\Program Files\UPSMON\UPSMON_Service.Exe<br />
<br />
--<br />
End of file - 6810 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>mustgofastang</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread232403.html</guid>
		</item>
		<item>
			<title>trojan in windows.old</title>
			<link>http://www.daniweb.com/forums/thread232100.html</link>
			<pubDate>Wed, 21 Oct 2009 23:06:18 GMT</pubDate>
			<description>Upon installing windows 7 i immediately intsalled avast antivirus and did a full scan. A trojan horse was found in the old vista files which after update have been changed to windows.old, will this trojan horse still be active from there?</description>
			<content:encoded><![CDATA[<div>Upon installing windows 7 i immediately intsalled avast antivirus and did a full scan. A trojan horse was found in the old vista files which after update have been changed to windows.old, will this trojan horse still be active from there?</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>craiggale</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread232100.html</guid>
		</item>
		<item>
			<title>windows police,help</title>
			<link>http://www.daniweb.com/forums/thread232077.html</link>
			<pubDate>Wed, 21 Oct 2009 20:41:12 GMT</pubDate>
			<description>I got hit with the windows police pro virus,and it has locked up everything,i cant get into control panel,task manager,hell not even the calculator,i have tried every command listed for restarting task manager or regedit,but cannt get access,i cant even log into safe mode,i dont know what else to...</description>
			<content:encoded><![CDATA[<div>I got hit with the windows police pro virus,and it has locked up everything,i cant get into control panel,task manager,hell not even the calculator,i have tried every command listed for restarting task manager or regedit,but cannt get access,i cant even log into safe mode,i dont know what else to try,now im posting on an old computer,I am completely stumped here,i was able to run a virus program that has deleted a lot of viruses,but I am still locked out please any help would be great,thanks</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>mike34</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread232077.html</guid>
		</item>
		<item>
			<title>Cannot Access Control Panel</title>
			<link>http://www.daniweb.com/forums/thread232011.html</link>
			<pubDate>Wed, 21 Oct 2009 15:30:24 GMT</pubDate>
			<description><![CDATA[Hi, 
 
I am back with a problem as I promised!! 
 
I recently reinstalled my computer and hence I was stuck with the awesomely annoying and non functional Symantec's Norton Antivirus and Internet Security. I forgot to get rid of it and install a program that works. Later last night I realized that...]]></description>
			<content:encoded><![CDATA[<div>Hi,<br />
<br />
I am back with a problem as I promised!!<br />
<br />
I recently reinstalled my computer and hence I was stuck with the awesomely annoying and non functional Symantec's Norton Antivirus and Internet Security. I forgot to get rid of it and install a program that works. Later last night I realized that my computer was acting funny - the control panel does open up instead an error message does telling me I do not have enough privileges! Hell, I am the Administrator! The same was the result when I tried to access 'regedit', 'msconfig' and 'firewall.cpl' . I also noticed these three processes - khatra.exe, gHost.exe and Xplorer.exe<br />
<br />
The first thing I did was install MBAM and on scanning it, the result was of course a list of trojans and tracking cookies. I selected all and deleted them. On restart I was able to access registry.<br />
<br />
I then hunted my registry and deleted anything pertaining to those three keywords. Then I ran the Panda Online Scan, looked at the results and then manually deleted the infected files. Most of them were '.cab' files stored in 'Windows' and 'System32' . I cleared all of them out.<br />
<br />
I then installed AVG and scanned, the scan shows that there are no infections but I am not able to access control panel still. Also when I have AVG installed I cannot access the internet. Updating of Virus definition or MABM update was not possible as well.<br />
<br />
Please advice. I am pasting the MBAM and HJT log.<br />
<br />
Thank you.<br />
<br />
=============================================<br />
<br />
Malwarebytes' Anti-Malware 1.41<br />
Database version: 2775<br />
Windows 5.1.2600 Service Pack 2<br />
<br />
2009-10-21 20:59:39<br />
mbam-log-2009-10-21 (20-59-39).txt<br />
<br />
Scan type: Quick Scan<br />
Objects scanned: 97454<br />
Time elapsed: 4 minute(s), 51 second(s)<br />
<br />
Memory Processes Infected: 0<br />
Memory Modules Infected: 0<br />
Registry Keys Infected: 0<br />
Registry Values Infected: 0<br />
Registry Data Items Infected: 0<br />
Folders Infected: 0<br />
Files Infected: 0<br />
<br />
Memory Processes Infected:<br />
(No malicious items detected)<br />
<br />
Memory Modules Infected:<br />
(No malicious items detected)<br />
<br />
Registry Keys Infected:<br />
(No malicious items detected)<br />
<br />
Registry Values Infected:<br />
(No malicious items detected)<br />
<br />
Registry Data Items Infected:<br />
(No malicious items detected)<br />
<br />
Folders Infected:<br />
(No malicious items detected)<br />
<br />
Files Infected:<br />
(No malicious items detected)<br />
<br />
<br />
-------------------------------------------------------------------------------<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 20:54:13, on 2009-10-21<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe<br />
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br />
C:\WINDOWS\Explorer.EXE<br />
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe<br />
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe<br />
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe<br />
C:\PROGRA~1\DrWeb\spidernt.exe<br />
C:\Program Files\iTunes\iTunes.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about<b></b>:blank<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Exploiter<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKCU\..\Run: [uTorrent] &quot;C:\Program Files\uTorrent\uTorrent.exe&quot;<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - <a rel="nofollow" class="t" href="http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab" target="_blank">http://acs.pandasoftware.com/actives.../as2stubie.cab</a><br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br />
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: Sony Ericsson OMSI download service (OMSI download service) - Unknown owner - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe<br />
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe<br />
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br />
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br />
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe<br />
<br />
--<br />
End of file - 6729 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>plastered</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread232011.html</guid>
		</item>
		<item>
			<title>IE not working</title>
			<link>http://www.daniweb.com/forums/thread231973.html</link>
			<pubDate>Wed, 21 Oct 2009 13:23:58 GMT</pubDate>
			<description>Ive been havin a series of problems with my laptop, i am currently working of a colleagues laptop at present.  My IE is not letting me surf the web, although plug gins, i.e my partypoker account appears to be running smoothly.  This may appear to be a virus but my Avg dosent pick it up.  On...</description>
			<content:encoded><![CDATA[<div>Ive been havin a series of problems with my laptop, i am currently working of a colleagues laptop at present.  My IE is not letting me surf the web, although plug gins, i.e my partypoker account appears to be running smoothly.  This may appear to be a virus but my Avg dosent pick it up.  On connection to the IE the home page does not appear, all it says is 'Windows cannot find <a rel="nofollow" class="t" href="http://." target="_blank">http://.</a>....and then the address. can anyone help<br />
Dave</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>gosssimus</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread231973.html</guid>
		</item>
		<item>
			<title>Hijack Help!</title>
			<link>http://www.daniweb.com/forums/thread231480.html</link>
			<pubDate>Mon, 19 Oct 2009 20:25:37 GMT</pubDate>
			<description><![CDATA[Hi- 
My brother gave me his old laptop, but it's really slow. I got a Hijack This report to see what could be slowing it down but I don't know much about computers. Can anyone take a look at this and help me out? 
 
---- 
 
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 4:21:20 PM, on...]]></description>
			<content:encoded><![CDATA[<div>Hi-<br />
My brother gave me his old laptop, but it's really slow. I got a Hijack This report to see what could be slowing it down but I don't know much about computers. Can anyone take a look at this and help me out?<br />
<br />
----<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 4:21:20 PM, on 10/19/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16915)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Windows Defender\MsMpEng.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\system32\HPZipm12.exe<br />
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br />
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe<br />
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\AVG\AVG8\avgcsrvx.exe<br />
C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Documents and Settings\keith crowling\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe<br />
C:\Documents and Settings\keith crowling\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\keith crowling\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\keith crowling\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\keith crowling\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\keith crowling\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\keith crowling\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\HijackThis.exe<br />
C:\Documents and Settings\keith crowling\My Documents\Downloads\HijackThis.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.myspace.com/" target="_blank">http://www.myspace.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll<br />
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [ISUSPM Startup] &quot;C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe&quot; -startup<br />
O4 - HKLM\..\Run: [ISUSScheduler] &quot;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&quot; -start<br />
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start<br />
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe<br />
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe<br />
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u<br />
O4 - HKLM\..\Run: [Microsoft Default Manager] &quot;C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe&quot; -resume<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;  -osboot<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] &quot;c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&quot; -t (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] &quot;c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&quot; -t (User 'Default user')<br />
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)<br />
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=64&amp;bd=presario&amp;pf=laptop<br />
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - <a rel="nofollow" class="t" href="http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab" target="_blank">http://a1540.g.akamai.net/7/1540/52/...x/qtplugin.cab</a><br />
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - <a rel="nofollow" class="t" href="http://lads.myspace.com/upload/MySpaceUploader1006.cab" target="_blank">http://lads.myspace.com/upload/MySpaceUploader1006.cab</a><br />
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - <a rel="nofollow" class="t" href="http://download.divx.com/player/DivXBrowserPlugin.cab" target="_blank">http://download.divx.com/player/DivXBrowserPlugin.cab</a><br />
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - <a rel="nofollow" class="t" href="http://www.popcap.com/webgames/popcaploader_v10.cab" target="_blank">http://www.popcap.com/webgames/popcaploader_v10.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O22 - SharedTaskScheduler: exegeses - {1817ab5d-25bf-4d5e-ba90-6e5fe658fc5f} - (no file)<br />
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe<br />
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe<br />
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br />
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (file missing)<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (file missing)<br />
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br />
O23 - Service: Norton Protection Center Service (NSCService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE (file missing)<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)<br />
<br />
--<br />
End of file - 9882 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>ebohhhhh</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread231480.html</guid>
		</item>
		<item>
			<title>IE 7 Redirect Problems</title>
			<link>http://www.daniweb.com/forums/thread231460.html</link>
			<pubDate>Mon, 19 Oct 2009 19:04:27 GMT</pubDate>
			<description>Hi guys, when ever im on google and search for something my searches sometimes redirect me to a weird website.. starts with zn322 something... i did a HiJackThis and here is my log 
 
 
Logfile of HijackThis v1.99.1 
Scan saved at 3:04:02 PM, on 10/19/2009 
Platform: Windows XP SP3 (WinNT...</description>
			<content:encoded><![CDATA[<div>Hi guys, when ever im on google and search for something my searches sometimes redirect me to a weird website.. starts with zn322 something... i did a HiJackThis and here is my log<br />
<br />
<br />
Logfile of HijackThis v1.99.1<br />
Scan saved at 3:04:02 PM, on 10/19/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16915)<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\windows\system\hpsysdrv.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\HP\KBD\KBD.EXE<br />
C:\WINDOWS\AGRSMMSG.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\WINDOWS\SOUNDMAN.EXE<br />
C:\WINDOWS\ALCWZRD.EXE<br />
C:\WINDOWS\ALCMTR.EXE<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\WINDOWS\system32\msiexec.exe<br />
C:\Documents and Settings\Compaq_Owner\Desktop\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.google.ca/" target="_blank">http://www.google.ca/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE<br />
O4 - HKLM\..\Run: [UpdateManager] &quot;C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe&quot; /r<br />
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE<br />
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe<br />
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE<br />
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe<br />
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe<br />
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe<br />
O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;  -osboot<br />
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br />
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br />
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE<br />
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br />
O4 - HKLM\..\Run: [NI.UWAS5LP_0001_0811] &quot;C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\Content.IE5\0TUFO5QF\WAS5Scan[1].exe&quot;<br />
O4 - HKLM\..\Run: [msnsyslog] C:\WINDOWS\msnappm.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [Nmehehizajif] rundll32.exe &quot;C:\WINDOWS\acatubetogu.dll&quot;,Startup<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKLM\..\Run: [ccApp] &quot;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&quot;<br />
O4 - HKLM\..\Run: [osCheck] &quot;C:\Program Files\Norton AntiVirus\osCheck.exe&quot;<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [Spyware Cleaner] &quot;C:\Program Files\Spyware Cleaner\SpywareCleaner.Exe&quot; /boot<br />
O4 - HKCU\..\Run: [Red Swoosh EDN Client] C:\Program Files\RSSoft\RSEDNClient.exe<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll<br />
O11 - Options group: [INTERNATIONAL] International*<br />
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - <a rel="nofollow" class="t" href="http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab" target="_blank">http://messenger.zone.msn.com/binary...r.cab31267.cab</a><br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - <a rel="nofollow" class="t" href="http://upload.facebook.com/controls/FacebookPhotoUploader5.cab" target="_blank">http://upload.facebook.com/controls/...oUploader5.cab</a><br />
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - <a rel="nofollow" class="t" href="http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab" target="_blank">http://messenger.zone.msn.com/binary...t.cab31267.cab</a><br />
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - <a rel="nofollow" class="t" href="http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab" target="_blank">http://messenger.zone.msn.com/binary...r.cab31267.cab</a><br />
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - <a rel="nofollow" class="t" href="http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab" target="_blank">http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab</a><br />
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - <a rel="nofollow" class="t" href="http://upload.facebook.com/controls/FacebookPhotoUploader.cab" target="_blank">http://upload.facebook.com/controls/...toUploader.cab</a><br />
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - <a rel="nofollow" class="t" href="http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab" target="_blank">http://messenger.zone.msn.com/binary...t.cab31267.cab</a><br />
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - <a rel="nofollow" class="t" href="http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab" target="_blank">http://messenger.zone.msn.com/binary...o.cab32846.cab</a><br />
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL<br />
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL<br />
O18 - Filter: text/html - (no CLSID) - (no file)<br />
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)<br />
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll<br />
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll<br />
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&quot; /h ccCommon (file missing)<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&quot; /h ccCommon (file missing)<br />
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&quot; /h ccCommon (file missing)<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe&quot; -service -config &quot;C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE<br />
O23 - Service: LiveUpdate Notice - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&quot; /h ccCommon (file missing)<br />
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Gozal</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread231460.html</guid>
		</item>
		<item>
			<title><![CDATA[windows bar gone, pictures don't open, internet wont load anything and more...]]></title>
			<link>http://www.daniweb.com/forums/thread231324.html</link>
			<pubDate>Mon, 19 Oct 2009 07:18:37 GMT</pubDate>
			<description><![CDATA[Hey everyone, just found this site and it looks fantastic. 
 
I've got a pretty major problem. I'm writing this from my housemates computer because i can't get into anything on mine. I'll start my list of issues. 
 
When my computer starts up there is no windows bar, none at all, there is a thin...]]></description>
			<content:encoded><![CDATA[<div>Hey everyone, just found this site and it looks fantastic.<br />
<br />
I've got a pretty major problem. I'm writing this from my housemates computer because i can't get into anything on mine. I'll start my list of issues.<br />
<br />
When my computer starts up there is no windows bar, none at all, there is a thin line at the bottom of the screen to suggest it has just been dragged down. But i can't drag it back, and when i right click the &quot;Lock The Taskbar&quot; function is greyed out. Also the windows button on the keyboard does nothing.<br />
<br />
Sounds: My system and warning sounds seem to work, but nothing else does, Windows Media Player, PowerDVD, whatever else.<br />
<br />
Internet: I can open both firefox and IE, but neither of them will load anything, they wont even try. As soon as i hit enter the page cannot be found.<br />
<br />
Pictures: no pictures will open, whatever i do i can't get them on the screen.<br />
<br />
At this point i gave up, not having anything to help me. (AVG antivirus wont open and i don't have spyware cleaners, every one i ever got caused me more problems than good). <br />
<br />
Anyway, any help you can give me would be great. Thankyou<br />
<br />
 Cheers,<br />
<br />
Jamus</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>jamus01</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread231324.html</guid>
		</item>
		<item>
			<title>MSN virus..</title>
			<link>http://www.daniweb.com/forums/thread231319.html</link>
			<pubDate>Mon, 19 Oct 2009 06:42:33 GMT</pubDate>
			<description>Hey.. i got some msn virus .. it sends email with link called    find-reason-of-being-blocked.com.. can anyone help me?</description>
			<content:encoded><![CDATA[<div>Hey.. i got some msn virus .. it sends email with link called    find-reason-of-being-blocked.com.. can anyone help me?</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Petrusino</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread231319.html</guid>
		</item>
		<item>
			<title>Need Help My Friend</title>
			<link>http://www.daniweb.com/forums/thread231281.html</link>
			<pubDate>Mon, 19 Oct 2009 02:07:14 GMT</pubDate>
			<description><![CDATA[Hey..it's me southern again...my computer is running great thanks to all your help, I maintain it regularly, and so far no problems..However my dads computer had a nervous breakdown, and we can't figure out what happened...he's running Vista, the computer shut down and would not boot back up, he...]]></description>
			<content:encoded><![CDATA[<div>Hey..it's me southern again...my computer is running great thanks to all your help, I maintain it regularly, and so far no problems..However my dads computer had a nervous breakdown, and we can't figure out what happened...he's running Vista, the computer shut down and would not boot back up, he had to reinstall XP just to get it to come back up, now it can't recognize the isp, so no online, and it is acting crazy, super slow, icons missing...he has 4 Gig of memory, so that's not an issue...what info do you need from me?..I will get it to you...thanks for your time...again...<br />
Southern</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>SouthernBark30</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread231281.html</guid>
		</item>
		<item>
			<title>Help!!</title>
			<link>http://www.daniweb.com/forums/thread231099.html</link>
			<pubDate>Sun, 18 Oct 2009 05:54:33 GMT</pubDate>
			<description>havin some issues, windows is slow, cannot access utilities, xp pro reverted back to 95, taskbar dissapeared, no anti virus or malware software will load. Any hair i had left is gone, any ideas??</description>
			<content:encoded><![CDATA[<div>havin some issues, windows is slow, cannot access utilities, xp pro reverted back to 95, taskbar dissapeared, no anti virus or malware software will load. Any hair i had left is gone, any ideas??</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>fordnatic</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread231099.html</guid>
		</item>
		<item>
			<title>Fun times with Windows Police Pro.</title>
			<link>http://www.daniweb.com/forums/thread230882.html</link>
			<pubDate>Sat, 17 Oct 2009 07:01:33 GMT</pubDate>
			<description><![CDATA[Hey. First of all, I guess I should apologise for making another thread on this nasty little piece of malware, given that there's a few already on here. But, none of the info in any of them could help me, and I was loath to hijack one of them with my own complaint, so here I am. 
 
I'm running XP,...]]></description>
			<content:encoded><![CDATA[<div>Hey. First of all, I guess I should apologise for making another thread on this nasty little piece of malware, given that there's a few already on here. But, none of the info in any of them could help me, and I was loath to hijack one of them with my own complaint, so here I am.<br />
<br />
I'm running XP, SP2.<br />
<br />
I'm writing from my laptop at the moment, as it's virtually shut down my tower PC.<br />
<br />
I picked it up a few days ago, and after a good few hours of struggling with it, I've managed to get rid of the annoying popups, and the actual interface is gone too. However, the rootkit and the nasty little trojans that came with it are still on the PC. The task manager no longer shows any programs running that shouldn't be, initially there was &quot;WindowsPolicePro.exe&quot; and &quot;svchast.exe&quot;. Having said that, there are two streams of random numbers in there, along the lines of &quot;0.038538587632.exe&quot;. These can be closed down by ending the process tree, but doing that seems to have no effect on the computer. To begin with, these were listed as having been started by me, under my user name, but now they're listed as &quot;SYSTEM&quot;. I don't know if that means anything or nothing, but it bothers me.<br />
<br />
The computer itself has been slowed down by this to such a degree that it's essentially non-functional. It takes almost 10 minutes to boot up. More irritating, however, is that it's now completely unable to open any exe files, at all. Nothing works, Windows just states that I haven't got the permissions to open the file. This includes regedit and msconfig. I can get into My Documents, and My Computer, but I can't open or view any files. Nor can I open my AV, or any anti-spyware. Unfortunately, this also means that I can't provide any logs for HijackThis, or MalwareBytes, for which I apologise. I don't have a flash drive to get them onto the affected PC, either :(.<br />
<br />
I also can't get the damn thing into Safe Mode. I don't know if that's down to the virus or not, but as soon as I get into the mode selection screen, my keyboard stops working, and I have to hit the reset button on the front of the tower.<br />
<br />
I think that's all the information I can provide, I know it isn't what's mentioned in the sticky at the top of the forum, but I can't conform to that at the moment :(.<br />
<br />
I have one more question: As mentioned above, I have no flash drive, but I do have a USB HD that I use to back stuff up from time to time. In the event that I can't fix this, and have to reformat, would it be possible to connect that up and transfer some files onto it before I restart the machine over? Or would the virus just infect the external HD too? I don't even know if it will let me do that in it's current state, but it's worth a try, I guess.<br />
<br />
Thank you for reading my long essay. Any help at all would be much, much appreciated. Thanks again!</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Asezat</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread230882.html</guid>
		</item>
		<item>
			<title>Trojan.BAT.Shutdown.ab</title>
			<link>http://www.daniweb.com/forums/thread230874.html</link>
			<pubDate>Sat, 17 Oct 2009 05:38:26 GMT</pubDate>
			<description>Kaspersky is unable to remove the above. What way?</description>
			<content:encoded><![CDATA[<div>Kaspersky is unable to remove the above. What way?</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>help distressed</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread230874.html</guid>
		</item>
		<item>
			<title>Win32/Renos problem</title>
			<link>http://www.daniweb.com/forums/thread230806.html</link>
			<pubDate>Fri, 16 Oct 2009 19:55:33 GMT</pubDate>
			<description><![CDATA[Hello,  
 
I recently (past 2 days) have become infected from a virus from an online "download" site. 
 
I was looking for a program for my class at school and downloaded a program that apparently housed a virus. 
 
Now the problem: 
I can access any website by typing in the exact URL, and the...]]></description>
			<content:encoded><![CDATA[<div>Hello, <br />
<br />
I recently (past 2 days) have become infected from a virus from an online &quot;download&quot; site.<br />
<br />
I was looking for a program for my class at school and downloaded a program that apparently housed a virus.<br />
<br />
Now the problem:<br />
I can access any website by typing in the exact URL, and the website will work fine - however use of google, yahoo, or any search engine for that matter brings up irrelevant ads, i.e. searching &quot;Hello&quot; on google will bring up thousands of pages, yet if I click on any one of them, I will be redirected to irrelevant ad pages.<br />
<br />
Nothing else seems to be crucially wrong except:<br />
<br />
I have downloaded Hijackthis, MBAM, and have tried ETES online scanner, as well as several other virus and malicious software removal tools with all of them simply shutting off after about one minute of runtime, with the exception of windows defender - which will run a full scan completely and will find nothing.<br />
<br />
After the first use of any virus scanner besides windows defender, the second use will come up with &quot;Windows cannot open the specified path, you may not have privelage&quot; - This has nothing to do with &quot;Run as administrator&quot; - I have tried that, and I am on the admin account of the computer.<br />
<br />
Secondly - Windows defender has found Win32/Renos.(string) multpile times, and deleted it multiple times. When I realized it was not going away I found the path of it's origin and deleted &quot;B.Exe&quot;, &quot;A.Exe&quot;, &quot;A.log&quot; And one other program ... I can't remember.<br />
<br />
Now the program appears to have stopped interfering with windows defender - I don't get &quot;Trojan found&quot; anymore, yet the ads and the problem with virus scanners still exist.<br />
<br />
Note: I CANNOT GET A LOG as of right now. Hijackthis will not stay open long enough to finish a scan and create a log, nor will any others!<br />
<br />
If you can help - Thanks.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Win32/Renos</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread230806.html</guid>
		</item>
		<item>
			<title>XR bots</title>
			<link>http://www.daniweb.com/forums/thread230538.html</link>
			<pubDate>Thu, 15 Oct 2009 23:41:50 GMT</pubDate>
			<description><![CDATA[Does anyone know what XR bots are and how I can keep people from uploading them to my IP?  I don't want to get  "hit off" or have my Router fried. Thanks. 
 
PS. This is also know as a DDoS attack, I need a free solution.]]></description>
			<content:encoded><![CDATA[<div>Does anyone know what XR bots are and how I can keep people from uploading them to my IP?  I don't want to get  &quot;hit off&quot; or have my Router fried. Thanks.<br />
<br />
PS. This is also know as a DDoS attack, I need a free solution.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Tarakata</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread230538.html</guid>
		</item>
		<item>
			<title>A virus or something bad</title>
			<link>http://www.daniweb.com/forums/thread230529.html</link>
			<pubDate>Thu, 15 Oct 2009 22:28:03 GMT</pubDate>
			<description>Hi everyone, im having some problems with my computer, my friend has made this website in flash(http://h1.ripway.com/dan08/Team_Vaska.html), he embeded, his flash window into html, but the problem doesnt come from there. Me and my friend have a program written in python, and there is nothing that...</description>
			<content:encoded><![CDATA[<div>Hi everyone, im having some problems with my computer, my friend has made this website in flash(<a rel="nofollow" class="t" href="http://h1.ripway.com/dan08/Team_Vaska.html" target="_blank">http://h1.ripway.com/dan08/Team_Vaska.html</a>), he embeded, his flash window into html, but the problem doesnt come from there. Me and my friend have a program written in python, and there is nothing that can damage a computer. And my program is in the my other friend's website. We also wanted to know how many visitors we had and stuff, so we made an account on easycounter.com and followed the steps to put it working. So we added to lines to the html file.<br />
My computer, yesterday got a virus:<br />
 <pre style="margin:20px; line-height:13px">C:\Documents and Settings\Sergey\Local Settings\Application Data\Opera\Opera\cache\opr0166N contains Exploit-ObscuredHtml Trojan.&nbsp; The file was successfully deleted.</pre>But as it says there it was deleted.. not at all. when i try to access that webpage (<a rel="nofollow" class="t" href="http://h1.ripway.com/dan08/Team_Vaska.html" target="_blank">http://h1.ripway.com/dan08/Team_Vaska.html</a>), it give me an firefox error:<br />
 <pre style="margin:20px; line-height:13px">The connection to the server was reset while the page was loading.<br />
<br />
<br />
&nbsp; &nbsp; *&nbsp;  The site could be temporarily unavailable or too busy. Try again in a few<br />
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; moments.<br />
<br />
&nbsp; &nbsp; *&nbsp;  If you are unable to load any pages, check your computer's network<br />
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; connection.<br />
<br />
&nbsp; &nbsp; *&nbsp;  If your computer or network is protected by a firewall or proxy, make sure<br />
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; that Firefox is permitted to access the Web.</pre>When i try to open it with, opera it simply doesnt load. Well, on my computer i have installed, McAfee VirusScan Enterprise, AntiSpyware Enterprise 8.5.0i and AVG free 8.5, i also have internet explorer 8.<br />
I ran hijackthis, and i got the following log:<br />
 <pre style="margin:20px; line-height:13px">Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 22:46:44, on 15/10/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Virgin Broadband\PCguard\Fws.exe<br />
C:\Program Files\Intel\WiFi\bin\S24EvMon.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe<br />
C:\Program Files\Intel\WiFi\bin\EvtEng.exe<br />
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE<br />
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe<br />
C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br />
C:\Program Files\McAfee\Common Framework\FrameworkService.exe<br />
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe<br />
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
c:\Program Files\Microsoft LifeCam\MSCamS32.exe<br />
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\Program Files\Raxco\PerfectDisk\PDAgent.exe<br />
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe<br />
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\Program Files\Intel\WiFi\bin\WLKeeper.exe<br />
C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
C:\Program Files\AVG\AVG8\avgcsrvx.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Raxco\PerfectDisk\PDEngine.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe<br />
C:\Program Files\Dell\QuickSet\Quickset.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe<br />
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe<br />
C:\Program Files\Digital Line Detect\DLG.exe<br />
C:\WINDOWS\system32\wbem\unsecapp.exe<br />
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe<br />
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\McAfee\Common Framework\UdaterUI.exe<br />
C:\Program Files\Wave Systems Corp\SecureUpgrade.exe<br />
C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
C:\WINDOWS\vVX1000.exe<br />
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe<br />
C:\Program Files\Skype\Phone\Skype.exe<br />
C:\Program Files\Skype\Plugin Manager\skypePM.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)<br />
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br />
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll<br />
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br />
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe<br />
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\Quickset.exe<br />
O4 - HKLM\..\Run: [StartupDelayer] &quot;C:\Program Files\r2 Studios\Startup Delayer\Startup Launcher.exe&quot;<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [Google Desktop Search] &quot;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&quot; /startup<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [ISUSPM] &quot;C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe&quot; -scheduler<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')<br />
O8 - Extra context menu item: &amp;������� � Microsoft Excel - res://c:\program files\microsoft office 2003\office11\excel.exe/3000<br />
O8 - Extra context menu item: Add to Google Photos Screensa&amp;ver - res://C:\WINDOWS\system32\GPhotos.scr/200<br />
O9 - Extra button: Ni?aai?iua iaoa?eaeu - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - <br />
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6662.cab<br />
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - <br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab<br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O20 - AppInit_DLLs: dhbvpj.dll C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL<br />
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O20 - Winlogon Notify: gemsafe - C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe<br />
O23 - Service: Intel� PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: Google Desktop Manager 5.9.906.4286 (GoogleDesktopManager-060409-093314) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br />
O23 - Service: Google Update Service (gupdate1c98640c76a657c) (gupdate1c98640c76a657c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: Inkjet Printer/Scanner Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe<br />
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe<br />
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe<br />
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe<br />
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe<br />
O23 - Service: Intel� PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe<br />
O23 - Service: Virgin Broadband PCguard Update Service (RPSUpdaterR) - Radialpoint Inc. - C:\Program Files\Virgin Broadband\PCguard\rpsupdaterR.exe<br />
O23 - Service: PCguard Firewall (RP_FWS) - Virgin Media - C:\Program Files\Virgin Broadband\PCguard\Fws.exe<br />
O23 - Service: Intel� PROSet/Wireless WiFi Service (S24EventMonitor) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe<br />
O23 - Service: SecureStorageService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe<br />
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe<br />
O23 - Service: NTRU TSS v1.2.1.25 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe<br />
O23 - Service: TdmService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe<br />
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe<br />
O23 - Service: WaveEnrollmentService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Authentication Manager\WaveEnrollmentService.exe<br />
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\WLKeeper.exe<br />
<br />
--<br />
End of file - 11970 bytes</pre><br />
Can please anyone help me out with this, thanks everyone, Dan08.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Dan08</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread230529.html</guid>
		</item>
		<item>
			<title>Please read this! I need your help!!</title>
			<link>http://www.daniweb.com/forums/thread230266.html</link>
			<pubDate>Thu, 15 Oct 2009 02:46:22 GMT</pubDate>
			<description><![CDATA[Our computer detected a speedhack, but we dont know where it came from. The internet connection became faster but as i want to play an online game like freestyle. It always say "speedhack is detected on pc" .  
 
How can i disable that speedhack? 
 
Please help me. I don't know what to do!]]></description>
			<content:encoded><![CDATA[<div>Our computer detected a speedhack, but we dont know where it came from. The internet connection became faster but as i want to play an online game like freestyle. It always say &quot;speedhack is detected on pc&quot; . <br />
<br />
How can i disable that speedhack?<br />
<br />
Please help me. I don't know what to do!</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>sabielyn</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread230266.html</guid>
		</item>
		<item>
			<title>Explorer.exe disappears</title>
			<link>http://www.daniweb.com/forums/thread230228.html</link>
			<pubDate>Thu, 15 Oct 2009 00:06:04 GMT</pubDate>
			<description><![CDATA[Ok... so i have tried everything to fix this and nothing works. 
 
When i right click on the desktop, explorer goes away completely(no taskbar, icons ect.) and when i try and run it from task manager, it says the file can't be found. 
So i tried to run it through CMD, and it says access is denied....]]></description>
			<content:encoded><![CDATA[<div>Ok... so i have tried everything to fix this and nothing works.<br />
<br />
When i right click on the desktop, explorer goes away completely(no taskbar, icons ect.) and when i try and run it from task manager, it says the file can't be found.<br />
So i tried to run it through CMD, and it says access is denied.<br />
<br />
After this, i opened google chrome through task manager and download explorer.exe from my key chain, deleted explorer through cmd and replaced it with the new one.<br />
it worked!<br />
And then i right click and it did it again.<br />
And again.<br />
And again.<br />
<br />
Along with this, Trend Micro HiJack this does the same thing, i run it, halfway through scan it fails, then the file is unusable.<br />
<br />
I am currently running AVAST anti virus <br />
and i am throughly confused.<br />
<br />
Any help would be great! <br />
<br />
-Zander</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Zandermander</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread230228.html</guid>
		</item>
		<item>
			<title>Browser link redirect</title>
			<link>http://www.daniweb.com/forums/thread230227.html</link>
			<pubDate>Wed, 14 Oct 2009 23:59:38 GMT</pubDate>
			<description>Several months ago, I must have gotten some spyware on my computer which was somewhat disruptive in that it installed something called Windows Police Pro.  I was able to get around it and then ran Ad-Aware and other Spyware programs to get rid of it.  However, I seem to have a problem where links...</description>
			<content:encoded><![CDATA[<div>Several months ago, I must have gotten some spyware on my computer which was somewhat disruptive in that it installed something called Windows Police Pro.  I was able to get around it and then ran Ad-Aware and other Spyware programs to get rid of it.  However, I seem to have a problem where links in Google and Yahoo will occassionally redirect to bogus sites and after hitting back a couple of times, I am able to get to the correct site.<br />
<br />
Other things that seem to happen is that each time I start the computer, a scan disk goes to run but never runs and I will get a missing paging file error.  Below is my log from Hijack this.  Can you please help me out with what items I should choose to have Hijack this Fix?<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 7:50:35 PM, on 10/14/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe<br />
C:\WINDOWS\system32\RUNDLL32.EXE<br />
C:\Program Files\TomTom HOME 2\HOMERunner.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe<br />
C:\WINDOWS\system32\drivers\KodakCCS.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\System32\HPZipm12.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://www.yahoo.com/?fr=fp-yie8" target="_blank">http://www.yahoo.com/?fr=fp-yie8</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.yahoo.com/" target="_blank">http://www.yahoo.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = <a rel="nofollow" class="t" href="http://www.yahoo.com" target="_blank">http://www.yahoo.com</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost<br />
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br />
O3 - Toolbar: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre1.dll<br />
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit<br />
O4 - HKCU\..\Run: [TomTomHOME.exe] &quot;C:\Program Files\TomTom HOME 2\HOMERunner.exe&quot;<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [calc] rundll32.exe C:\DOCUME~1\NETWOR~1.NTA\ntuser.dll,_IWMPEvents@0<br />
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')<br />
O4 - S-1-5-18 Startup: scandisk.lnk = ? (User 'SYSTEM')<br />
O4 - .DEFAULT Startup: scandisk.lnk = ? (User 'Default user')<br />
O4 - Startup: scandisk.lnk = ?<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O16 - DPF: vzTCPConfig - <a rel="nofollow" class="t" href="http://www2.verizon.net/help/dsl_settings/include/vzTCPConfig.CAB" target="_blank">http://www2.verizon.net/help/dsl_set...zTCPConfig.CAB</a><br />
O16 - DPF: Yahoo! Bingo - <a rel="nofollow" class="t" href="http://download2.games.yahoo.com/games/clients/y/xt0_x.cab" target="_blank">http://download2.games.yahoo.com/gam...ts/y/xt0_x.cab</a><br />
O16 - DPF: Yahoo! Chess - <a rel="nofollow" class="t" href="http://origin.games.yahoo.net/games/clients/y/ct5_x.cab" target="_blank">http://origin.games.yahoo.net/games/clients/y/ct5_x.cab</a><br />
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - <a rel="nofollow" class="t" href="https://activatemydsl.verizon.n