<?xml version="1.0" encoding="utf-8"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>DaniWeb IT Discussion Community - Viruses, Spyware and other Nasties</title>
		<link>http://www.daniweb.com/forums</link>
		<description><![CDATA[Our Viruses, Spyware and other Nasties forum is the place for Q&A-style discussions related to Windows security. Post a HijackThis log here if you think you've got viruses, spyware, adware, malware, or other unwanted guests.]]></description>
		<language>en-US</language>
		<lastBuildDate>Sun, 06 Jul 2008 07:43:46 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://www.daniweb.com/forums/myimages/misc/rss.jpg</url>
			<title>DaniWeb IT Discussion Community - Viruses, Spyware and other Nasties</title>
			<link>http://www.daniweb.com/forums</link>
		</image>
		<item>
			<title>critical errors log</title>
			<link>http://www.daniweb.com/forums/thread132862.html</link>
			<pubDate>Sat, 05 Jul 2008 23:42:29 GMT</pubDate>
			<description><![CDATA[hi... can anyone help me, everytime i open a folder or click on anything on navigation toolbar it showing critical error please download antivirus... how can i get rid ofem"? can some one please review my log and let me know if u see a virus?

Logfile of HijackThis v1.99.1
Scan saved at 6:37:38 AM,...]]></description>
			<content:encoded><![CDATA[<div>hi... can anyone help me, everytime i open a folder or click on anything on navigation toolbar it showing critical error please download antivirus... how can i get rid ofem&quot;? can some one please review my log and let me know if u see a virus?<br />
<br />
Logfile of HijackThis v1.99.1<br />
Scan saved at 6:37:38 AM, on 7/6/2008<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe<br />
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Acer\eManager\anbmServ.exe<br />
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe<br />
C:\WINDOWS\system32\HPZipm12.exe<br />
e:\Registry Defragmentation\RegManServ.exe<br />
E:\Spyware Doctor\pctsAuxs.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Documents and Settings\momogi\My Documents\My Music\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://global.acer.com/" target="_blank">http://global.acer.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://global.acer.com" target="_blank">http://global.acer.com</a><br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = <a rel="nofollow" class="t" href="http://global.acer.com/" target="_blank">http://global.acer.com/</a><br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: AVG Safe Search - {1C1B8A44-61FE-411E-8F33-813A4E2E2984} - C:\WINDOWS\system32\avgsafe.dll<br />
O2 - BHO: (no name) - {206E52E0-D52E-11D4-AD54-0000E86C26F6} - E:\FreshDevices\FreshDownload\FDCatch.dll<br />
O2 - BHO: QFX Software KeyScrambler - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - e:\KeyScrambler\KeyScramblerIE.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - e:\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\MICROS~1\Office12\GRA8E1~1.DLL<br />
O3 - Toolbar: FreshDownload Bar - {ED0E8CA5-42FB-4B18-997B-769E0408E79D} - E:\FreshDevices\FreshDownload\fdiebar.dll<br />
O4 - HKLM\..\Run: [kav] &quot;C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe&quot;<br />
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br />
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent<br />
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName<br />
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC<br />
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
O4 - HKLM\..\Run: [ISTray] &quot;E:\Spyware Doctor\pctsTray.exe&quot;<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] e:\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\MICROS~1\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\MICROS~1\Office12\ONBttnIE.dll<br />
O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - e:\KeyScrambler\KeyScramblerIE.dll<br />
O9 - Extra 'Tools' menuitem: &amp;KeyScrambler... - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - e:\KeyScrambler\KeyScramblerIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\MICROS~1\Office12\REFIEBAR.DLL<br />
O9 - Extra button: FreshDownload - {A49BD554-CB54-48ED-98D7-9751FA3D5FA8} - E:\FreshDevices\FreshDownload\fd.exe<br />
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\momogi\Start Menu\Programs\IMVU\Run IMVU.lnk<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - e:\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - e:\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - E:\MICROS~1\Office12\GR99D3~1.DLL<br />
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll<br />
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL<br />
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll<br />
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll<br />
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe&quot; -r (file missing)<br />
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe<br />
O23 - Service: Auto Power-on &amp; Shut-down Service (PCAutoPowerOnService) - Unknown owner - e:\Auto Power-on\PCAutoPowerOnService.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: Registry Management Service (RegManServ) - Unknown owner - e:\Registry Defragmentation\RegManServ.exe<br />
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - E:\Spyware Doctor\pctsAuxs.exe<br />
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - E:\Spyware Doctor\pctsSvc.exe</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>momog1</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread132862.html</guid>
		</item>
		<item>
			<title>Invisible file/folder</title>
			<link>http://www.daniweb.com/forums/thread132860.html</link>
			<pubDate>Sat, 05 Jul 2008 23:11:22 GMT</pubDate>
			<description><![CDATA[The night before last I had a very bad experience, and only managed to avoid a complete wipe and reload by the skin of my teeth.
I was downloading a file from a site I had used before, and my AV software trapped something called "Downloader". I stopped the download immediately. I then noticed that...]]></description>
			<content:encoded><![CDATA[<div>The night before last I had a very bad experience, and only managed to avoid a complete wipe and reload by the skin of my teeth.<br />
I was downloading a file from a site I had used before, and my AV software trapped something called &quot;Downloader&quot;. I stopped the download immediately. I then noticed that all the items in the system tray have been blanked out and replaced with &quot;&lt;&quot; signs (like you get when it's hiding icons). I couldn't bring up Task Manager, and my other running software (Spy Sweeper) also reported a strange file it was quarantining.<br />
I then found that my internet access seemed to have disappeared and that there was only minimal activity showing. I tried a reboot and Spy Sweeper popped up during the start up sequence to say it was deleting a file. However, when I logged back in the situation was the same - no system tray icons, no internet, no Task Manager. Help, I thought.<br />
At that stage, I thought I might be in real trouble. I ran HijackThis but couldn't see anything obvious.<br />
I had a thought to check if this was also happening on other accounts, so I managed to log out and log in to the alternative account. <br />
Everything seemed fine, and then a window popped up (from WinPatrol) asking if I approved &quot;c:\Documents and Settings\&lt;name&gt;\svchost.exe&quot; as an addition to the startup folder. Oh, oh! Answer definitely NO. Is this the problem? Log back into my account and check the running processes.<br />
Since I couldn't get Task Manager to come up, this could have been a problem, but WinPatrol allows me to check the startup processes and the running tasks. I could see the real svchost.exe (from Microsoft) plus an extra one without an owner. I disabled this and things came back to normal!!! When I looked at the HijackThis log I spotted that process (a bit late).<br />
And now the kicker. When I look in my Documents and Setting folder there is no svchost.exe file (I have 'show hidden files' on in explorer). So apparently the system can run a file I can't see in explorer. I would like to be able to get rid of this file, but how? <br />
I have run adsspy but this doesn't show anything. While it was running it showed itself scanning a directory called &quot;c:\Documents and Settings\&lt;name&gt;\!&quot; (with a &quot;!&quot;), that seemed to contain mostly zip files. I can't see anything called &quot;!&quot; under explorer, so what is this folder?<br />
So what is going on?</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>normanallen</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread132860.html</guid>
		</item>
		<item>
			<title>Virus problems??</title>
			<link>http://www.daniweb.com/forums/thread132808.html</link>
			<pubDate>Sat, 05 Jul 2008 13:56:56 GMT</pubDate>
			<description>Hi all, compters been acting very strange recently. Tried running AVG 8.0 and it detected nothing, also ran Ccleaner and A-squared which both detected nothing. Im not really too good with computers so any help would be greatly appreciated, thanks.

Im running Windows XP SP3, firefox 3, AVG...</description>
			<content:encoded><![CDATA[<div>Hi all, compters been acting very strange recently. Tried running AVG 8.0 and it detected nothing, also ran Ccleaner and A-squared which both detected nothing. Im not really too good with computers so any help would be greatly appreciated, thanks.<br />
<br />
Im running Windows XP SP3, firefox 3, AVG 8.<br />
<br />
Hijack this log file:<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 13:41:58, on 05/07/2008<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16674)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\a-squared Free\a2service.exe<br />
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe<br />
C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
C:\Program Files\COMODO\Firewall\cfp.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\COMODO\Firewall\cmdagent.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Belkin\Belkin 802.11g Wireless PCI Card Configuration Utility\utility.exe<br />
C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br />
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent<br />
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [COMODO Firewall Pro] &quot;C:\Program Files\COMODO\Firewall\cfp.exe&quot; -h<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')<br />
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br />
O4 - Global Startup: Belkin 802.11g Wireless PCI Card Configuration Utility.lnk = ?<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll<br />
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - <a rel="nofollow" class="t" href="http://go.divx.com/plugin/DivXBrowserPlugin.cab" target="_blank">http://go.divx.com/plugin/DivXBrowserPlugin.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a rel="nofollow" class="t" href="http://www.update.microsoft.com/micr...?1184524691697" target="_blank">http://www.update.microsoft.com/micr...?1184524691697</a><br />
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - <a rel="nofollow" class="t" href="http://www.crucial.com/controls/cpcScanner.cab" target="_blank">http://www.crucial.com/controls/cpcScanner.cab</a><br />
O20 - AppInit_DLLs: avgrsstx.dll C:\WINDOWS\system32\guard32.dll<br />
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe<br />
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe<br />
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
<br />
--<br />
End of file - 5155 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>stereotypical</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread132808.html</guid>
		</item>
		<item>
			<title><![CDATA[popups won't stop]]></title>
			<link>http://www.daniweb.com/forums/thread132550.html</link>
			<pubDate>Thu, 03 Jul 2008 21:55:59 GMT</pubDate>
			<description><![CDATA[I'm running a computer with Windows XP, using Firefox as my browser, and I keep getting new windows opening with ads- but they're opening using Internet Explorer, not Firefox.  Both Firefox and Explorer are set to block pop-ups at the highest level.   I am using Avast antivirus, and I have run a...]]></description>
			<content:encoded><![CDATA[<div>I'm running a computer with Windows XP, using Firefox as my browser, and I keep getting new windows opening with ads- but they're opening using Internet Explorer, not Firefox.  Both Firefox and Explorer are set to block pop-ups at the highest level.   I am using Avast antivirus, and I have run a few scans with Adaware, which found all types of stuff, but hasn't stopped the popups (or actually new IE windows opening).  Any ideas?  I uninstalled Internet Explorer, and that didn't help either.  Do I need an exorcist?:S <br />
Paul</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>pafek</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread132550.html</guid>
		</item>
		<item>
			<title>help on virus</title>
			<link>http://www.daniweb.com/forums/thread132390.html</link>
			<pubDate>Thu, 03 Jul 2008 04:30:14 GMT</pubDate>
			<description>Hello Good Morning,
my system is infected with Virus,
Exactly dont know the name of that and the drives C and D gone and the icons in the startup are gone(My computer,networkplaces etc)
can any one help me in getting back the icons and name of the virus.
and i tried to find the autorun.inf file...</description>
			<content:encoded><![CDATA[<div>Hello Good Morning,<br />
my system is infected with Virus,<br />
Exactly dont know the name of that and the drives C and D gone and the icons in the startup are gone(My computer,networkplaces etc)<br />
can any one help me in getting back the icons and name of the virus.<br />
and i tried to find the autorun.inf file also but no autorun.inf file i find <br />
<br />
please anyone help me <br />
Thanks in advance.<br />
<br />
Rakesh Nagekar</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Rakesh Nagekar</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread132390.html</guid>
		</item>
		<item>
			<title>control panel probs?</title>
			<link>http://www.daniweb.com/forums/thread132303.html</link>
			<pubDate>Wed, 02 Jul 2008 15:33:09 GMT</pubDate>
			<description><![CDATA[Hello.

sorry, but i am still new to this.
have DL'd AVG and ran it.
have DL'd Hijackthis and ran to get a log.

so far what happens is i try to open control panel and it says windows explorer has stopped running and it looks for a problem then restarts but no control panel opens.

any help is...]]></description>
			<content:encoded><![CDATA[<div>Hello.<br />
<br />
sorry, but i am still new to this.<br />
have DL'd AVG and ran it.<br />
have DL'd Hijackthis and ran to get a log.<br />
<br />
so far what happens is i try to open control panel and it says windows explorer has stopped running and it looks for a problem then restarts but no control panel opens.<br />
<br />
any help is greatly appreciated. thank you.<br />
<br />
here is log of hijackthis:<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 11:13:32 AM, on 7/2/2008<br />
Platform: Windows Vista SP1 (WinNT 6.00.1905)<br />
MSIE: Internet Explorer v7.00 (7.00.6001.18000)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Windows\RtHDVCpl.exe<br />
C:\Acer\Empowering Technology\SysMonitor.exe<br />
C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe<br />
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe<br />
C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe<br />
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE<br />
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE<br />
C:\Windows\System32\mobsync.exe<br />
C:\Program Files\AVG\AVG8\avgtray.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = <a rel="nofollow" class="t" href="http://internetsearchservice.com" target="_blank">http://internetsearchservice.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = <a rel="nofollow" class="t" href="http://internetsearchservice.com" target="_blank">http://internetsearchservice.com</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://internetsearchservice.com" target="_blank">http://internetsearchservice.com</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = <a rel="nofollow" class="t" href="http://internetsearchservice.com/ie6.html" target="_blank">http://internetsearchservice.com/ie6.html</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://internetsearchservice.com" target="_blank">http://internetsearchservice.com</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about<b></b>:blank<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://en.us.acer.yahoo.com" target="_blank">http://en.us.acer.yahoo.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://internetsearchservice.com" target="_blank">http://internetsearchservice.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a rel="nofollow" class="t" href="http://internetsearchservice.com/ie6.html" target="_blank">http://internetsearchservice.com/ie6.html</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://internetsearchservice.com" target="_blank">http://internetsearchservice.com</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://en.us.acer.yahoo.com" target="_blank">http://en.us.acer.yahoo.com</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <a rel="nofollow" class="t" href="http://internetsearchservice.com" target="_blank">http://internetsearchservice.com</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <a rel="nofollow" class="t" href="http://internetsearchservice.com" target="_blank">http://internetsearchservice.com</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = <a rel="nofollow" class="t" href="http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com" target="_blank">http://us.rd.yahoo.com/customize/yco.../www.yahoo.com</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O2 - BHO: 214075 helper - {8E96D546-8096-42B2-8EBF-16AC5A119A59} - C:\Windows\system32\214075\214075.dll<br />
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL<br />
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O3 - Toolbar: Internet Service - {F99D0C20-F8E1-43B6-AB24-3F16BFAEA77B} - C:\Program Files\Web Technologies\iebr.dll (file missing)<br />
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br />
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe<br />
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe<br />
O4 - HKLM\..\Run: [PCMMediaSharing] C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe<br />
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe<br />
O4 - HKLM\..\Run: [Acer Product Registration] &quot;C:\Program Files\Acer Registration\ACE1.exe&quot; /startup<br />
O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer Assist\launcher.exe<br />
O4 - HKLM\..\Run: [Apanel] C:\ACERSW\config\NewSetApanel.cmd<br />
O4 - HKLM\..\Run: [PlayMovie] &quot;C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe&quot;<br />
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [StartCCC] &quot;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\Web Technologies\wcs.exe<br />
O4 - HKLM\..\Policies\Explorer\Run: [start] C:\Program Files\Web Technologies\iebtm.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe<br />
O4 - Global Startup: Empowering Technology Launcher.lnk = ?<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe<br />
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe<br />
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - <a rel="nofollow" class="t" href="http://www.iexplorergate.com/redirect.php" target="_blank">http://www.iexplorergate.com/redirect.php</a> (file missing)<br />
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - <a rel="nofollow" class="t" href="http://www.iexplorergate.com/redirect.php" target="_blank">http://www.iexplorergate.com/redirect.php</a> (file missing)<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - <a rel="nofollow" class="t" href="http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-3/CursorManiaFWBInitialSetup1.0.1.0.cab" target="_blank">http://ak.exe.imgfarm.com/images/noc...tup1.0.1.0.cab</a><br />
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - <a rel="nofollow" class="t" href="http://www.srtest.com/srl_bin/sysreqlab3.cab" target="_blank">http://www.srtest.com/srl_bin/sysreqlab3.cab</a><br />
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - <a rel="nofollow" class="t" href="http://download.bitdefender.com/resources/scan8/oscan8.cab" target="_blank">http://download.bitdefender.com/reso...an8/oscan8.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O20 - AppInit_DLLs: avgrsstx.dll<br />
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe<br />
O23 - Service: Acer TV Share Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer TV Share\Kernel\DMSTV\CLMSServer.exe<br />
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe<br />
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe<br />
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)<br />
O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe<br />
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe<br />
<br />
--<br />
End of file - 10185 bytes<br />
<br />
<br />
Again I thank you all for your help.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>oyameister</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread132303.html</guid>
		</item>
		<item>
			<title>Please Help me prevent virus</title>
			<link>http://www.daniweb.com/forums/thread132283.html</link>
			<pubDate>Wed, 02 Jul 2008 12:58:38 GMT</pubDate>
			<description><![CDATA[*My Problem:*
I have lots of virus & Trojan horses in my Pen drive. I don't have any valuable data though.  

If I plug in the drive in my USB port, the viruses do something & I loose my internet connectivity & it also occupies more space memory. Without knowing what to do, I have formated my...]]></description>
			<content:encoded><![CDATA[<div><b>My Problem:</b><br />
I have lots of virus &amp; Trojan horses in my Pen drive. I don't have any valuable data though.  <br />
<br />
If I plug in the drive in my USB port, the viruses do something &amp; I loose my internet connectivity &amp; it also occupies more space memory. Without knowing what to do, I have formated my hard-drive &amp; reinstalled Win XP and various softwares. So now my computer is free from virus.<br />
<b><br />
Question:</b><br />
   How would I delete the virus in my pen drive &amp; at the same time protect my computer. (I don't need the data in it)<br />
<br />
Please help</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Prabakar</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread132283.html</guid>
		</item>
		<item>
			<title>I just got a pretty nasty one, any help would be appreciated.</title>
			<link>http://www.daniweb.com/forums/thread132232.html</link>
			<pubDate>Wed, 02 Jul 2008 07:27:12 GMT</pubDate>
			<description><![CDATA[So the issue is everytime I open windows explorer my desktop turns into an obvious virus back ground that has the link saying your computer has fatal errors from spyware and wants me to install an "antivirus" program to remove it. Also I can't open task manager. I just scanned with AVG, it removed...]]></description>
			<content:encoded><![CDATA[<div>So the issue is everytime I open windows explorer my desktop turns into an obvious virus back ground that has the link saying your computer has fatal errors from spyware and wants me to install an &quot;antivirus&quot; program to remove it. Also I can't open task manager. I just scanned with AVG, it removed like 37 different files, and my background was good again, but as soon as I opened windows explorer it reverted. Windows restore doesn't work either, so I'm sure it's unloaded into several different places then, seeing as it won't go away. Anyone ever have this particular virus before? If so any help would be greatly appreciated. Or if anyone can tell which of the top antiviruses you guys use that would be great too. I've used Norton Ghost, definitely not a fan, I've tried NOD32 which seems to be the most popular among techies, but it got really annoying asking you to update every 3 seconds.<br />
<br />
So Thanks for your time if you read all of this and I'm open to most suggestions, other than wiping my hdd.</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Clinton1989</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread132232.html</guid>
		</item>
		<item>
			<title><![CDATA[for my mom's computer (you will see some spyware here)]]></title>
			<link>http://www.daniweb.com/forums/thread132213.html</link>
			<pubDate>Wed, 02 Jul 2008 06:24:09 GMT</pubDate>
			<description>Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:18:03 AM, on 7/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running...</description>
			<content:encoded><![CDATA[<div>Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 1:18:03 AM, on 7/2/2008<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16674)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe<br />
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe<br />
C:\Program Files\Analog Devices\Core\smax4pnp.exe<br />
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe<br />
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br />
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\cisvc.exe<br />
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe<br />
C:\Program Files\Dell Support Center\bin\sprtcmd.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe<br />
C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Program Files\Messenger\msmsgs.exe<br />
C:\Program Files\DellSupport\DSAgnt.exe<br />
C:\Program Files\Digital Line Detect\DLG.exe<br />
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe<br />
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = <a rel="nofollow" class="t" href="http://bfc.myway.com/search/de_srchlft.html?p=DS" target="_blank">http://bfc.myway.com/search/de_srchlft.html?p=DS</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com" target="_blank">http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://www.yahoo.com/" target="_blank">http://www.yahoo.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com" target="_blank">http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a rel="nofollow" class="t" href="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html" target="_blank">http://us.rd.yahoo.com/customize/ie/...ch/search.html</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com" target="_blank">http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.dell4me.com/mywaybiz" target="_blank">http://www.dell4me.com/mywaybiz</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = <a rel="nofollow" class="t" href="http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com" target="_blank">http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com</a><br />
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll<br />
R3 - URLSearchHook: (no name) -  - (no file)<br />
R3 - URLSearchHook: (no name) - {D73F49B6-B51B-4d32-A3B7-BD04B8342F53} - C:\Program Files\MorpheusBar\SrchAstt\1.bin\MBSRCAS.DLL<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: MorpheusToolbar BHO - {3F3714A1-89A4-46be-8AF3-D0C9D1FB03F9} - C:\Program Files\MorpheusBar\bar\1.bin\MORPHBAR.DLL<br />
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll<br />
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll<br />
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll<br />
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll<br />
O2 - BHO: (no name) - {D73F49B1-B51B-4d32-A3B7-BD04B8342F53} - C:\Program Files\MorpheusBar\SrchAstt\1.bin\MBSRCAS.DLL<br />
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll<br />
O3 - Toolbar: Morpheus Toolbar - {3F3714A9-89A4-46be-8AF3-D0C9D1FB03F9} - C:\Program Files\MorpheusBar\bar\1.bin\MORPHBAR.DLL<br />
O3 - Toolbar: &amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;  -osboot<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe<br />
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe<br />
O4 - HKLM\..\Run: [ISUSScheduler] &quot;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&quot; -start<br />
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br />
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe Photo Downloader] &quot;C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe&quot;<br />
O4 - HKLM\..\Run: [dscactivate] &quot;C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe&quot;<br />
O4 - HKLM\..\Run: [DellSupportCenter] &quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&quot; /P DellSupportCenter<br />
O4 - HKLM\..\Run: [ccApp] &quot;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&quot;<br />
O4 - HKLM\..\Run: [osCheck] &quot;C:\Program Files\Norton AntiVirus\osCheck.exe&quot;<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
O4 - HKCU\..\Run: [MSMSGS] &quot;C:\Program Files\Messenger\msmsgs.exe&quot; /background<br />
O4 - HKCU\..\Run: [DellSupport] &quot;C:\Program Files\DellSupport\DSAgnt.exe&quot; /startup<br />
O4 - HKCU\..\Run: [BitTorrent] &quot;C:\Program Files\BitTorrent\bittorrent.exe&quot; --force_start_minimized<br />
O4 - HKCU\..\Run: [DellSupportCenter] &quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&quot; /P DellSupportCenter<br />
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9e.exe<br />
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe<br />
O4 - Global Startup: Digital Line Detect.lnk = ?<br />
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll<br />
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmesus.dll<br />
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmesus.dll<br />
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br />
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Mary Sickels\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - <a rel="nofollow" class="t" href="http://housecall60.trendmicro.com/housecall/xscan60.cab" target="_blank">http://housecall60.trendmicro.com/housecall/xscan60.cab</a><br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll<br />
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - <a rel="nofollow" class="t" href="http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab" target="_blank">http://download.mcafee.com/molbin/sh...0/mcinsctl.cab</a><br />
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - <a rel="nofollow" class="t" href="http://by113fd.bay113.hotmail.msn.com/resources/MsnPUpld.cab" target="_blank">http://by113fd.bay113.hotmail.msn.co...s/MsnPUpld.cab</a><br />
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - <a rel="nofollow" class="t" href="https://webdl.symantec.com/activex/symdlmgr.cab" target="_blank">https://webdl.symantec.com/activex/symdlmgr.cab</a><br />
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - <a rel="nofollow" class="t" href="http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab" target="_blank">http://housecall65.trendmicro.com/ho...vex/hcImpl.cab</a><br />
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - <a rel="nofollow" class="t" href="http://zone.msn.com/bingame/chnz/default/mjolauncher.cab" target="_blank">http://zone.msn.com/bingame/chnz/def...jolauncher.cab</a><br />
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - <a rel="nofollow" class="t" href="http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab" target="_blank">http://messenger.zone.msn.com/binary...t.cab31267.cab</a><br />
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - <a rel="nofollow" class="t" href="http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab" target="_blank">http://cdn2.zone.msn.com/binFramewor...o.cab34246.cab</a><br />
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - <a rel="nofollow" class="t" href="http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab" target="_blank">http://download.mcafee.com/molbin/sh...23/mcgdmgr.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a rel="nofollow" class="t" href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - <a rel="nofollow" class="t" href="https://music.msn.com/client/msnmusax3313.cab" target="_blank">https://music.msn.com/client/msnmusax3313.cab</a><br />
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - <a rel="nofollow" class="t" href="http://chat.msn.com/controls/msnchat45.cab" target="_blank">http://chat.msn.com/controls/msnchat45.cab</a><br />
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe<br />
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe<br />
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe<br />
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE<br />
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe<br />
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br />
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe<br />
<br />
--<br />
End of file - 12770 bytes<br />
<br />
<br />
<br />
let me know which ones to shut off pls and thank you HIGHLY APPRECIATED (this computer runs slower than what it should for sure)</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>acejames1</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread132213.html</guid>
		</item>
		<item>
			<title><![CDATA[Can't find the C Drive, Have a virus alert messsage HELP!!!]]></title>
			<link>http://www.daniweb.com/forums/thread132161.html</link>
			<pubDate>Tue, 01 Jul 2008 23:02:22 GMT</pubDate>
			<description>Hi: I was able to download and run Hijack this;
The log is below. Any help appreciated!


Logfile of HijackThis v1.99.1
Scan saved at 18:52: VIRUS ALERT!, on 7/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:</description>
			<content:encoded><![CDATA[<div>Hi: I was able to download and run Hijack this;<br />
The log is below. Any help appreciated!<br />
<br />
<br />
Logfile of HijackThis v1.99.1<br />
Scan saved at 18:52: VIRUS ALERT!, on 7/1/2008<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\csrss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe<br />
C:\WINDOWS\system32\cisvc.exe<br />
C:\Program Files\Symantec AntiVirus\DefWatch.exe<br />
C:\QS1\QIA\QIA.EXE<br />
C:\Program Files\Symantec AntiVirus\SavRoam.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\Program Files\Spyware Doctor\pctsAuxs.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Spyware Doctor\pctsSvc.exe<br />
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br />
C:\PROGRA~1\SYMANT~1\VPTray.exe<br />
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Spyware Doctor\pctsTray.exe<br />
C:\Program Files\Messenger\msmsgs.exe<br />
C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br />
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
C:\Program Files\UltraVNC\WinVNC.exe<br />
C:\Program Files\OpenOffice.org 2.2\program\soffice.exe<br />
C:\Program Files\OpenOffice.org 2.2\program\soffice.BIN<br />
C:\WINDOWS\System32\alg.exe<br />
C:\QS1\QIA\QIA.EXE<br />
C:\QS1\Qs1com.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\WINDOWS\system32\cidaemon.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE<br />
C:\QS1\Qs1com.exe<br />
C:\Program Files\HijackThis\HijackThis.exe<br />
<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O3 - Toolbar: nmwegbsf - {686B4BF6-E46C-4194-B3EA-09A5BAAF4A60} - C:\WINDOWS\nmwegbsf.dll (file missing)<br />
O4 - HKLM\..\Run: [ATIPTA] &quot;C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&quot;<br />
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\SetRefresh.exe<br />
O4 - HKLM\..\Run: [WinVNC] &quot;C:\Program Files\UltraVNC\WinVNC.exe&quot; -servicehelper<br />
O4 - HKLM\..\Run: [ccApp] &quot;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&quot;<br />
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [CANON DR2080C SVC] rundll32.exe DR2KSVC.dll,EntryPointUserMessage<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [ISTray] &quot;C:\Program Files\Spyware Doctor\pctsTray.exe&quot;<br />
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u<br />
O4 - HKCU\..\Run: [MSMSGS] &quot;C:\Program Files\Messenger\msmsgs.exe&quot; /background<br />
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe<br />
O4 - Startup: OpenOffice.org 2.2.lnk = C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe<br />
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = internal.pvpsc.com<br />
O17 - HKLM\Software\..\Telephony: DomainName = internal.pvpsc.com<br />
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = internal.pvpsc.com<br />
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll<br />
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll<br />
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll<br />
O21 - SSODL: erpobmsw - {2DAA8EF4-B9F9-4C3C-B39A-131FECA55EF7} - C:\WINDOWS\erpobmsw.dll (file missing)<br />
O21 - SSODL: adgpfoxs - {D5527369-78D5-4A9F-8A93-8148D95207F5} - C:\WINDOWS\adgpfoxs.dll (file missing)<br />
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe<br />
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br />
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br />
O23 - Service: QS/1 Install Agent (QIA) - QS/1® - C:\QS1\QIA\QIA.EXE<br />
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe<br />
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe<br />
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe<br />
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br />
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br />
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br />
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\UltraVNC\WinVNC.exe&quot; -service (file missing)</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>SENLEO</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread132161.html</guid>
		</item>
		<item>
			<title>Please review HIJACK Log</title>
			<link>http://www.daniweb.com/forums/thread132116.html</link>
			<pubDate>Tue, 01 Jul 2008 16:57:59 GMT</pubDate>
			<description><![CDATA[Hi - Can someone please review my log and let me know if you see a virus?  My computer has been running slow and it's happened before and Daniweb was able to help.  Unfortunately, it happened several years ago and don't remember the steps to get rid of my problem.

Thank you.

Logfile of Trend...]]></description>
			<content:encoded><![CDATA[<div>Hi - Can someone please review my log and let me know if you see a virus?  My computer has been running slow and it's happened before and Daniweb was able to help.  Unfortunately, it happened several years ago and don't remember the steps to get rid of my problem.<br />
<br />
Thank you.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 9:40:39 PM, on 6/30/2008<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16674)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\csrss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br />
C:\WINDOWS\system32\LEXBCES.EXE<br />
C:\WINDOWS\system32\LEXPPS.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe<br />
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br />
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe<br />
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe<br />
C:\WINDOWS\system32\dla\tfswctrl.exe<br />
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br />
C:\Program Files\Dell\Media Experience\DMXLauncher.exe<br />
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe<br />
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe<br />
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br />
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe<br />
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe<br />
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe<br />
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\Program Files\BroadJump\Client Foundation\CFD.exe<br />
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe<br />
C:\Program Files\Dell Support Center\bin\sprtcmd.exe<br />
C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe<br />
C:\Program Files\MSN Messenger\MsnMsgr.Exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Program Files\DellSupport\DSAgnt.exe<br />
C:\Program Files\Spyware Doctor\swdoctor.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br />
C:\Program Files\Spyware Doctor\sdhelp.exe<br />
C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br />
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe<br />
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe<br />
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe<br />
C:\WINDOWS\system32\wdfmgr.exe<br />
C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\MSN Messenger\usnsvc.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\PROGRA~1\Yahoo!\browser\ycommon.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe<br />
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE<br />
C:\Documents and Settings\Cristina Russo\My Documents\Hijack This\HijackThis.exe<br />
C:\WINDOWS\system32\wbem\wmiprvse.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a rel="nofollow" class="t" href="http://red.clientapps.yahoo.com/cust...search/ie.html" target="_blank">http://red.clientapps.yahoo.com/cust...search/ie.html</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br />
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search &amp; Destroy\SDHelper.dll<br />
O2 - BHO: (no name) - {54D7F34A-F7F8-4F09-A7B5-4EA223FDA812} - C:\WINDOWS\system32\vtsqn.dll (file missing)<br />
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll<br />
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll<br />
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll<br />
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\common\YIeTagBm.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll<br />
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll<br />
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O3 - Toolbar: &amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll<br />
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [IntelMeM] &quot;C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe&quot;<br />
O4 - HKLM\..\Run: [DVDLauncher] &quot;C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe<br />
O4 - HKLM\..\Run: [ISUSPM Startup] &quot;C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe&quot; -startup<br />
O4 - HKLM\..\Run: [ISUSScheduler] &quot;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&quot; -start<br />
O4 - HKLM\..\Run: [DMXLauncher] &quot;C:\Program Files\Dell\Media Experience\DMXLauncher.exe&quot;<br />
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe<br />
O4 - HKLM\..\Run: [MMTray] &quot;C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe&quot;<br />
O4 - HKLM\..\Run: [pccguide.exe] &quot;C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe&quot;<br />
O4 - HKLM\..\Run: [Google Desktop Search] &quot;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&quot; /startup<br />
O4 - HKLM\..\Run: [Lexmark X1100 Series] &quot;C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe&quot;<br />
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe<br />
O4 - HKLM\..\Run: [ccApp] &quot;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&quot;<br />
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [BJCFD] &quot;C:\Program Files\BroadJump\Client Foundation\CFD.exe&quot;<br />
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe<br />
O4 - HKLM\..\Run: [dscactivate] &quot;C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe&quot;<br />
O4 - HKLM\..\Run: [DellSupportCenter] &quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&quot; /P DellSupportCenter<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKCU\..\Run: [OE_OEM] &quot;C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe&quot;<br />
O4 - HKCU\..\Run: [MsnMsgr] &quot;C:\Program Files\MSN Messenger\MsnMsgr.Exe&quot; /background<br />
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
O4 - HKCU\..\Run: [DellSupport] &quot;C:\Program Files\DellSupport\DSAgnt.exe&quot; /startup<br />
O4 - HKCU\..\Run: [Spyware Doctor] &quot;C:\Program Files\Spyware Doctor\swdoctor.exe&quot; /Q<br />
O4 - HKCU\..\Run: [DellSupportCenter] &quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&quot; /P DellSupportCenter<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] &quot;C:\Program Files\Spyware Doctor\swdoctor.exe&quot; /Q (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [Spyware Doctor] &quot;C:\Program Files\Spyware Doctor\swdoctor.exe&quot; /Q (User 'Default user')<br />
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br />
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br />
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe<br />
O8 - Extra context menu item: &amp;Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm<br />
O8 - Extra context menu item: Add to Windows &amp;Live Favorites - <a rel="nofollow" class="t" href="http://favorites.live.com/quickadd.aspx" target="_blank">http://favorites.live.com/quickadd.aspx</a><br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll<br />
O9 - Extra button: SBC Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll<br />
O15 - Trusted Zone: <a rel="nofollow" class="t" href="http://*.turbotax.com" target="_blank">http://*.turbotax.com</a><br />
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - <a rel="nofollow" class="t" href="http://security.symantec.com/sscv6/S...in/AvSniff.cab" target="_blank">http://security.symantec.com/sscv6/S...in/AvSniff.cab</a><br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll<br />
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - <a rel="nofollow" class="t" href="http://lads.myspace.com/upload/MySpaceUploader.cab" target="_blank">http://lads.myspace.com/upload/MySpaceUploader.cab</a><br />
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - <a rel="nofollow" class="t" href="http://security.symantec.com/sscv6/S.../bin/cabsa.cab" target="_blank">http://security.symantec.com/sscv6/S.../bin/cabsa.cab</a><br />
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - <a rel="nofollow" class="t" href="http://cdn2.zone.msn.com/binFramewor...o.cab56649.cab" target="_blank">http://cdn2.zone.msn.com/binFramewor...o.cab56649.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O18 - Filter hijack: text/html - (no CLSID) - (no file)<br />
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll<br />
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br />
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br />
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br />
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe<br />
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br />
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe<br />
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Unknown owner - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe<br />
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe<br />
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br />
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe<br />
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe<br />
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe<br />
<br />
--<br />
End of file - 13880 byte</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Feb20</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread132116.html</guid>
		</item>
		<item>
			<title>Explorer.exe keeps crashing and restarting</title>
			<link>http://www.daniweb.com/forums/thread132090.html</link>
			<pubDate>Tue, 01 Jul 2008 14:12:17 GMT</pubDate>
			<description>Explorer.exe keeps crashing and restarting forcing me to do everything from the command prompt. I run XP sp2.
Here is my Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:36:56, on 01/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00...</description>
			<content:encoded><![CDATA[<div>Explorer.exe keeps crashing and restarting forcing me to do everything from the command prompt. I run XP sp2.<br />
Here is my Hijackthis log:<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 14:36:56, on 01/07/2008<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16640)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe<br />
C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe<br />
C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe<br />
C:\WINDOWS\system32\cisvc.exe<br />
C:\Program Files\Comodo\Firewall\cmdagent.exe<br />
C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe<br />
C:\Program Files\Macrium\Reflect\ReflectService.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\UAService7.exe<br />
C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe<br />
C:\WINDOWS\system32\cidaemon.exe<br />
C:\WINDOWS\system32\taskmgr.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\WINDOWS\system32\cmd.exe<br />
C:\Documents and Settings\Barty\My Documents\My Received Files\HiJackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.google.co.uk/" target="_blank">http://www.google.co.uk/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://www.google.co.uk/" target="_blank">http://www.google.co.uk/</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://www.google.co.uk/" target="_blank">http://www.google.co.uk/</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 195.175.37.71:80<br />
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,,SKEYS /I,C:\WINDOWS\system32\MPK\MPK.exe<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: FlashFetcher - {16E8A050-74CE-43D5-8DC0-BADD7347B2DD} - C:\Program Files\GeoVid\FlashFetcher\FlashFetcher.dll<br />
O2 - BHO: (no name) - {348FE907-249E-4C65-A838-F34A193FE1D1} - (no file)<br />
O2 - BHO: MyBHO Class - {46B9D770-1B7D-45D1-81B4-AC07B2F127EF} - C:\PROGRA~1\FLASHS~1\FlashBHO.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll<br />
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: (no name) - {97C65EA3-54E2-450E-9804-8C6974B0869F} - C:\WINDOWS\system32\yayxvWOi.dll<br />
O2 - BHO: (no name) - {A260787B-911C-49A1-AE73-EC76A3CEC27E} - C:\WINDOWS\system32\qoMeCrrQ.dll<br />
O2 - BHO: Catcher Class - {ADECBED6-0366-4377-A739-E69DFBA04663} - C:\Program Files\Moyea\FLV Downloader\MoyeaCth.dll<br />
O4 - HKLM\..\Run: [NBKeyScan] &quot;C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe&quot;<br />
O4 - HKLM\..\Run: [HydraVisionDesktopManager] C:\Program Files\ATI Technologies\ATI HydraVision\HydraDM.exe<br />
O4 - HKLM\..\Run: [COMODO Firewall Pro] &quot;C:\Program Files\Comodo\Firewall\cfp.exe&quot; -h<br />
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe<br />
O4 - HKCU\..\Run: [UnHackMe Monitor] C:\Program Files\UnHackMe\hackmon.exe<br />
O4 - HKCU\..\Run: [AutoPowerOn] C:\Program Files\AutoPowerOn\AutoPowerOn.exe<br />
O4 - HKCU\..\Run: [BandwidthMonitor] C:\Program Files\BandwidthMonitor\BWMonitor.exe<br />
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: FlashFetcher - {07174FC7-B4C1-4643-9C03-B4D2148EB057} - C:\Program Files\GeoVid\FlashFetcher\FlashFetcher.dll<br />
O9 - Extra 'Tools' menuitem: FlashFetcher - {07174FC7-B4C1-4643-9C03-B4D2148EB057} - C:\Program Files\GeoVid\FlashFetcher\FlashFetcher.dll<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra button: NeoTrace It! - {9885224C-1217-4c5f-83C2-00002E6CEF2B} - C:\WINDOWS\system32\shdocvw.dll (HKCU)<br />
O16 - DPF: RaptisoftGameLoader - <a rel="nofollow" class="t" href="http://www.miniclip.com/haphazard/raptisoftgameloader.cab" target="_blank">http://www.miniclip.com/haphazard/ra...gameloader.cab</a><br />
O16 - DPF: {2019DC25-D1C0-11D6-97B3-0008A124F542} (StreamPlug Class) - <a rel="nofollow" class="t" href="http://www.streamplug.com/StreamPlug/beta/SP.cab" target="_blank">http://www.streamplug.com/StreamPlug/beta/SP.cab</a><br />
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - <a rel="nofollow" class="t" href="http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab" target="_blank">http://messenger.zone.msn.com/binary...r.cab31267.cab</a><br />
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - <a rel="nofollow" class="t" href="http://baddassbartlett.spaces.live.com//PhotoUpload/MsnPUpld.cab" target="_blank">http://baddassbartlett.spaces.live.c...d/MsnPUpld.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a rel="nofollow" class="t" href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1152447668109" target="_blank">http://update.microsoft.com/microsof...?1152447668109</a><br />
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - <a rel="nofollow" class="t" href="http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab" target="_blank">http://messenger.zone.msn.com/binary...t.cab31267.cab</a><br />
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - <a rel="nofollow" class="t" href="http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab" target="_blank">http://messenger.msn.com/download/Ms...Downloader.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a rel="nofollow" class="t" href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - <a rel="nofollow" class="t" href="http://by106fd.bay106.hotmail.msn.com/activex/HMAtchmt.ocx" target="_blank">http://by106fd.bay106.hotmail.msn.co...x/HMAtchmt.ocx</a><br />
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - <a rel="nofollow" class="t" href="https://secure.logmein.com/activex/ractrl.cab?lmi=100" target="_blank">https://secure.logmein.com/activex/ractrl.cab?lmi=100</a><br />
O20 - AppInit_DLLs:    ,wbsys.dll C:\WINDOWS\system32\guard32.dll<br />
O20 - Winlogon Notify: qoMeCrrQ - C:\WINDOWS\SYSTEM32\qoMeCrrQ.dll<br />
O20 - Winlogon Notify: winpsa32 - C:\WINDOWS\SYSTEM32\winpsa32.dll<br />
O23 - Service: AntiVir PersonalEdition Premium MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe<br />
O23 - Service: AntiVir PersonalEdition Premium Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe<br />
O23 - Service: AntiVir PersonalEdition Premium Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe<br />
O23 - Service: AntiVir PersonalEdition Premium MailGuard helper service (AVEService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe<br />
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\Comodo\Firewall\cmdagent.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe<br />
O23 - Service: Macrium Reflect Image Mounting Service (ReflectService) - Unknown owner - C:\Program Files\Macrium\Reflect\ReflectService.exe<br />
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe<br />
<br />
--<br />
End of file - 9332 bytes<br />
<br />
Help would be lovely as my computer has been rendered into a useless block</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Barlam</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread132090.html</guid>
		</item>
		<item>
			<title>Browsers fail, yet internet and network working</title>
			<link>http://www.daniweb.com/forums/thread132046.html</link>
			<pubDate>Tue, 01 Jul 2008 09:48:54 GMT</pubDate>
			<description><![CDATA[I have similar experiences to the post with the same titme (May 2008) I therefore attach 3 HJT files. The problem & its history:
OS Windows XP Pro SP2 with Bit Defender Internet security 2008. Internet connection is ADSL via ISP provided modem (that includes hardware firewall) - Neuf box...]]></description>
			<content:encoded><![CDATA[<div>I have similar experiences to the post with the same titme (May 2008) I therefore attach 3 HJT files. The problem &amp; its history:<br />
OS Windows XP Pro SP2 with Bit Defender Internet security 2008. Internet connection is ADSL via ISP provided modem (that includes hardware firewall) - Neuf box (French).<br />
As I have had an AOL mail address for many years I retained this when AOL France was bought by Neuf Cegetel. THe AOL web broser programme does not permit uploading files other than JPG and saving e-mails on local PC difficult, therefore I have continued to keep the AOL programmes loaded on PC.<br />
With AOL 9.0 it was not possible to access the internet (not a problem as I always use Firefox) but each time AOL 9.0 was closed it downloaded a file, installed it then shut down. When AOL released version 9.1 I downliaded this and was then able to access internet with Firefox, IE6 &amp; AOL, that was until AOL installed automatically their VR update. After that, I was not able to view ant internet sites with either Firefox or IE6 although Firefox tells me that thee page is loaded, I can ping and AOL emails can be read. I have reloaded Firefox in both English &amp; French versions 2.0.0.14 and now version 3.0 (no joy). Turning off both Bit defender &amp; Windows firewall has no effect.<br />
Finally, I removed AOL 9.1 and reinstalled AOL 9.0. THis then had the same problem as before (no internet access). I now therefore have no internet access at all! However, I found that I could get internet access in both Firefox &amp; IE6 when booting the PC in safe mode. I tried downloading AOL 9.1 but it only sees a PC with the system resources available in safe mode (not enough to run the programme).<br />
I suspect therefore that the problem is 'simply' one of configuration but I have so far not managed to find any effective solution from various different forums. I am hoping therefore that a Daniweb geek will pull a trump from a hand of computer fix-it solution!<br />
(This post is sent from another PC with Windows XP Pro SP1, with Firefow, IE6 &amp; AOL 9.0 all working together, but the AOL programme still tries to add a file each time it is closed. I look forward to the day of no AOL programmes on my PCs.</div>  <br /> <div style="padding:5px">     <fieldset class="fieldset"> <legend>Attached Files</legend> <table cellpadding="0" cellspacing="5" border="0"> <tr> <td><img class="inlineimg" src="http://www.daniweb.com/forums//forums/myimages/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td> <td><a href="http://www.daniweb.com/forums/attachment.php?attachmentid=6483&amp;d=1214905258">startuplist.txt</a> (8.3 KB)</td> </tr><tr> <td><img class="inlineimg" src="http://www.daniweb.com/forums//forums/myimages/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td> <td><a href="http://www.daniweb.com/forums/attachment.php?attachmentid=6484&amp;d=1214905270">uninstall_list.txt</a> (7.9 KB)</td> </tr><tr> <td><img class="inlineimg" src="http://www.daniweb.com/forums//forums/myimages/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td> <td><a href="http://www.daniweb.com/forums/attachment.php?attachmentid=6485&amp;d=1214905701">hijackthislog.txt</a> (7.4 KB)</td> </tr> </table> </fieldset>  </div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>Brian Boyes</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread132046.html</guid>
			<enclosure url="http://www.daniweb.com/forums/attachment.php/6483/startuplist.txt" length="8472" type="plain/text" />
		</item>
		<item>
			<title>A dozen IEXPLORE.EXE processes</title>
			<link>http://www.daniweb.com/forums/thread132022.html</link>
			<pubDate>Tue, 01 Jul 2008 06:43:22 GMT</pubDate>
			<description><![CDATA[Do I have a virus or is there some sort of conflict on my system? I was simply browsing the net and I noticed my usage maxing out at a 100%. This is the third time I've noticed a number of these processes running at the same time. I took some screen shots.]]></description>
			<content:encoded><![CDATA[<div>Do I have a virus or is there some sort of conflict on my system? I was simply browsing the net and I noticed my usage maxing out at a 100%. This is the third time I've noticed a number of these processes running at the same time. I took some screen shots.</div>  <br /> <div style="padding:5px">    <fieldset class="fieldset"> <legend>Attached Images</legend> <table cellpadding="0" cellspacing="5" border="0"> <tr> <td><img class="inlineimg" src="http://www.daniweb.com/forums//forums/myimages/attach/jpg.gif" alt="File Type: jpg" width="16" height="16" border="0" style="vertical-align:baseline" /></td> <td><a href="http://www.daniweb.com/forums/attachment.php?attachmentid=6479&amp;d=1214894511" class="thickbox" title="processes.JPG" rel="attach638038">processes.JPG</a> (104.8 KB)</td> </tr><tr> <td><img class="inlineimg" src="http://www.daniweb.com/forums//forums/myimages/attach/jpg.gif" alt="File Type: jpg" width="16" height="16" border="0" style="vertical-align:baseline" /></td> <td><a href="http://www.daniweb.com/forums/attachment.php?attachmentid=6480&amp;d=1214894522" class="thickbox" title="system.JPG" rel="attach638038">system.JPG</a> (175.3 KB)</td> </tr> </table> </fieldset>   </div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>knight fyre</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread132022.html</guid>
			<enclosure url="http://www.daniweb.com/forums/attachment.php/6479/processes.JPG" length="107290" type="image/jpeg" />
		</item>
		<item>
			<title>I cannot read</title>
			<link>http://www.daniweb.com/forums/thread132048.html</link>
			<pubDate>Tue, 01 Jul 2008 01:43:35 GMT</pubDate>
			<description>Hi, 

Here is my HiJack This log. Any help is greatly appreciated! Thanks! 

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:40:39 PM, on 6/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal</description>
			<content:encoded><![CDATA[<div>Hi, <br />
<br />
Here is my HiJack This log. Any help is greatly appreciated! Thanks! <br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 9:40:39 PM, on 6/30/2008<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16674)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\csrss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br />
C:\WINDOWS\system32\LEXBCES.EXE<br />
C:\WINDOWS\system32\LEXPPS.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe<br />
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br />
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe<br />
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe<br />
C:\WINDOWS\system32\dla\tfswctrl.exe<br />
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br />
C:\Program Files\Dell\Media Experience\DMXLauncher.exe<br />
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe<br />
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe<br />
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br />
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe<br />
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe<br />
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe<br />
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\Program Files\BroadJump\Client Foundation\CFD.exe<br />
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe<br />
C:\Program Files\Dell Support Center\bin\sprtcmd.exe<br />
C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe<br />
C:\Program Files\MSN Messenger\MsnMsgr.Exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Program Files\DellSupport\DSAgnt.exe<br />
C:\Program Files\Spyware Doctor\swdoctor.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br />
C:\Program Files\Spyware Doctor\sdhelp.exe<br />
C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br />
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe<br />
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe<br />
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe<br />
C:\WINDOWS\system32\wdfmgr.exe<br />
C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\MSN Messenger\usnsvc.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\PROGRA~1\Yahoo!\browser\ycommon.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe<br />
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE<br />
C:\Documents and Settings\Cristina  Russo\My Documents\Hijack This\HijackThis.exe<br />
C:\WINDOWS\system32\wbem\wmiprvse.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a rel="nofollow" class="t" href="http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html" target="_blank">http://red.clientapps.yahoo.com/cust...search/ie.html</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" class="t" href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br />
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search &amp; Destroy\SDHelper.dll<br />
O2 - BHO: (no name) - {54D7F34A-F7F8-4F09-A7B5-4EA223FDA812} - C:\WINDOWS\system32\vtsqn.dll (file missing)<br />
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll<br />
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll<br />
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll<br />
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\common\YIeTagBm.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll<br />
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll<br />
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O3 - Toolbar: &amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll<br />
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [IntelMeM] &quot;C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe&quot;<br />
O4 - HKLM\..\Run: [DVDLauncher] &quot;C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe<br />
O4 - HKLM\..\Run: [ISUSPM Startup] &quot;C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe&quot; -startup<br />
O4 - HKLM\..\Run: [ISUSScheduler] &quot;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&quot; -start<br />
O4 - HKLM\..\Run: [DMXLauncher] &quot;C:\Program Files\Dell\Media Experience\DMXLauncher.exe&quot;<br />
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe<br />
O4 - HKLM\..\Run: [MMTray] &quot;C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe&quot;<br />
O4 - HKLM\..\Run: [pccguide.exe] &quot;C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe&quot;<br />
O4 - HKLM\..\Run: [Google Desktop Search] &quot;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&quot; /startup<br />
O4 - HKLM\..\Run: [Lexmark X1100 Series] &quot;C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe&quot;<br />
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe<br />
O4 - HKLM\..\Run: [ccApp] &quot;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&quot;<br />
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [BJCFD] &quot;C:\Program Files\BroadJump\Client Foundation\CFD.exe&quot;<br />
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe<br />
O4 - HKLM\..\Run: [dscactivate] &quot;C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe&quot;<br />
O4 - HKLM\..\Run: [DellSupportCenter] &quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&quot; /P DellSupportCenter<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKCU\..\Run: [OE_OEM] &quot;C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe&quot;<br />
O4 - HKCU\..\Run: [MsnMsgr] &quot;C:\Program Files\MSN Messenger\MsnMsgr.Exe&quot; /background<br />
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
O4 - HKCU\..\Run: [DellSupport] &quot;C:\Program Files\DellSupport\DSAgnt.exe&quot; /startup<br />
O4 - HKCU\..\Run: [Spyware Doctor] &quot;C:\Program Files\Spyware Doctor\swdoctor.exe&quot; /Q<br />
O4 - HKCU\..\Run: [DellSupportCenter] &quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&quot; /P DellSupportCenter<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] &quot;C:\Program Files\Spyware Doctor\swdoctor.exe&quot; /Q (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [Spyware Doctor] &quot;C:\Program Files\Spyware Doctor\swdoctor.exe&quot; /Q (User 'Default user')<br />
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br />
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br />
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe<br />
O8 - Extra context menu item: &amp;Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm<br />
O8 - Extra context menu item: Add to Windows &amp;Live Favorites - <a rel="nofollow" class="t" href="http://favorites.live.com/quickadd.aspx" target="_blank">http://favorites.live.com/quickadd.aspx</a><br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll<br />
O9 - Extra button: SBC Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll<br />
O15 - Trusted Zone: <a rel="nofollow" class="t" href="http://*.turbotax.com" target="_blank">http://*.turbotax.com</a><br />
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - <a rel="nofollow" class="t" href="http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab" target="_blank">http://security.symantec.com/sscv6/S...in/AvSniff.cab</a><br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll<br />
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - <a rel="nofollow" class="t" href="http://lads.myspace.com/upload/MySpaceUploader.cab" target="_blank">http://lads.myspace.com/upload/MySpaceUploader.cab</a><br />
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - <a rel="nofollow" class="t" href="http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab" target="_blank">http://security.symantec.com/sscv6/S.../bin/cabsa.cab</a><br />
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - <a rel="nofollow" class="t" href="http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab" target="_blank">http://cdn2.zone.msn.com/binFramewor...o.cab56649.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O18 - Filter hijack: text/html - (no CLSID) - (no file)<br />
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll<br />
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br />
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br />
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br />
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe<br />
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br />
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe<br />
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Unknown owner - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe<br />
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe<br />
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br />
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe<br />
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe<br />
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe<br />
<br />
--<br />
End of file - 13880 bytes</div> ]]></content:encoded>
			<category domain="http://www.daniweb.com/forums/forum64.html">Viruses, Spyware and other Nasties</category>
			<dc:creator>cris06</dc:creator>
			<guid isPermaLink="true">http://www.daniweb.com/forums/thread132048.html</guid>
		</item>
	</channel>
</rss>
