<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title><![CDATA[Tech Support Guy Forums - Malware Removal & HijackThis Logs]]></title>
		<link>http://forums.techguy.org</link>
		<description>Security and removal help with spyware, HijackThis logs, etc.</description>
		<language>en</language>
		<lastBuildDate>Fri, 20 Nov 2009 22:37:22 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>30</ttl>
		<image>
			<url>http://static.techguy.org/v38/images/misc/rss.jpg</url>
			<title><![CDATA[Tech Support Guy Forums - Malware Removal & HijackThis Logs]]></title>
			<link>http://forums.techguy.org</link>
		</image>
		<item>
			<title><![CDATA[Help needed with System Defender & Redirecting search browser]]></title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/879029-help-needed-system-defender-redirecting.html</link>
			<pubDate>Fri, 20 Nov 2009 22:10:20 GMT</pubDate>
			<description><![CDATA[Hey all,  
  
i got caught out by system defender the other day & it took over my whole system & blocked my internet connection for a while.  
  
I got back on the net & after having gala coming up as a search tool I've managed to delete some dll &...]]></description>
			<content:encoded><![CDATA[<div>Hey all, <br />
 <br />
i got caught out by system defender the other day &amp; it took over my whole system &amp; blocked my internet connection for a while. <br />
 <br />
I got back on the net &amp; after having gala coming up as a search tool I've managed to delete some dll &amp; exe files &amp; think i have got rid of some bits but when i do a spybot or hijackthis scan it still has things it cant get rid off. It still does random searches &amp; guides me to different sites &amp; has also blocked access to some of my folders so i cant get in &amp; delete the problem.<br />
 <br />
Any help would be appreciated, Here's my hijackthis log<br />
 <br />
Thanks</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://static.techguy.org/v38/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="{attachment-server}attachment.php?attachmentid=159884&amp;d=1258754976">hijackthis.log</a> (7.9 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>BaileyD</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/879029-help-needed-system-defender-redirecting.html</guid>
		</item>
		<item>
			<title>0x804E1BF8 Blue Screen on Boot Up</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/879028-0x804e1bf8-blue-screen-boot-up.html</link>
			<pubDate>Fri, 20 Nov 2009 21:57:19 GMT</pubDate>
			<description><![CDATA[It's worth noting that it's not my computer. I was called in to take a look at it, as I'm somewhat experienced with computers. When I first booted it up, it gave me this error. I rebooted in last known good config mode, and it booted normally. I got...]]></description>
			<content:encoded><![CDATA[<div>It's worth noting that it's not my computer. I was called in to take a look at it, as I'm somewhat experienced with computers. When I first booted it up, it gave me this error. I rebooted in last known good config mode, and it booted normally. I got avast!, malwarebytes, and a free spyware removal tool. I ran all three, encountered a few problems, and solved them. Rebooted normally, no problems. Unfortunately, something was interferring with avast's protection services. When troubleshooting that, I was told that it may be because it wasn't updated recently. I ran windows update, rebooted, and got the error. Tried LKG config, got the error. I'm currently using Safe Mode with networking, and have the Windows XP + SP1 Dell disk handy. What could be my issue?<br />
 <br />
 <br />
<div style="margin:20px; margin-top:5px; ">
	<div class="smallfont" style="margin-bottom:2px">Quote:</div>
	<table cellpadding="6" cellspacing="0" border="0" width="100%">
	<tr>
		<td class="alt2">
			<hr />
			
				Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 5:02:00 PM, on 11/20/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Safe mode with network support<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Documents and Settings\mary\Desktop\HijackThis.exe<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://www.dell4me.com/myway" target="_blank">http://www.dell4me.com/myway</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://forums.techguy.org/malware-removal-hijackthis-logs/879028-0x804e1bf8-blue-screen-boot-up.html#post7045713" target="_blank">http://forums.techguy.org/malware-re...ml#post7045713</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
O1 - Hosts: ::1 localhost<br />
O1 - Hosts: 94.232.248.66 browser-security.microsoft.com<br />
O1 - Hosts: 94.232.248.66 antivaresys.com<br />
O1 - Hosts: 94.232.248.66 <a href="http://www.antivaresys.com" target="_blank">www.antivaresys.com</a><br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll<br />
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)<br />
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe<br />
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br />
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL<br />
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE<br />
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe<br />
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br />
O4 - HKLM\..\Run: [ISUSScheduler] &quot;C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe&quot; -start<br />
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br />
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
O4 - Global Startup: Digital Line Detect.lnk = ?<br />
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll<br />
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - <a href="http://wwws.musicmatch.com/mmz/openWebRadio.html" target="_blank">http://wwws.musicmatch.com/mmz/openWebRadio.html</a> (file missing)<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a href="http://go.microsoft.com/fwlink/?LinkId=39204&amp;clcid=0x409" target="_blank">http://go.microsoft.com/fwlink/?Link...04&amp;clcid=0x409</a><br />
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - <a href="https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab" target="_blank">https://www-secure.symantec.com/tech...a/LSSupCtl.cab</a><br />
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - <a href="http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab" target="_blank">http://us.chat1.yimg.com/us.yimg.com...45/yacscom.cab</a><br />
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - <a href="http://software-dl.real.com/01b7a9f9d8069c4b8b05/netzip/RdxIE601.cab" target="_blank">http://software-dl.real.com/01b7a9f9...p/RdxIE601.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1119414867953" target="_blank">http://update.microsoft.com/windowsu...?1119414867953</a><br />
O16 - DPF: {6632A7E9-FE1F-43D2-A04A-A15951ED63E0} - <a href="http://mediaplayer.walmart.com/installer/install.cab" target="_blank">http://mediaplayer.walmart.com/installer/install.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1129519391243" target="_blank">http://update.microsoft.com/microsof...?1129519391243</a><br />
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - <a href="http://chat.yahoo.com/cab/yacsui.cab" target="_blank">http://chat.yahoo.com/cab/yacsui.cab</a><br />
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - <a href="https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab" target="_blank">https://www-secure.symantec.com/tech...l/SymAData.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...nt/swflash.cab</a><br />
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe<br />
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe (file missing)<br />
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe<br />
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe<br />
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE<br />
O23 - Service: Lexar Secure II (LxrSII1s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrSII1s.exe<br />
O23 - Service: M-Audio Micro Installer (MAudioMicroService) - Avid Technology, Inc. - C:\Program Files\M-Audio\M-Audio Micro\MAUSBMRInst.exe<br />
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe<br />
--<br />
End of file - 7468 bytes
			
			<hr />
		</td>
	</tr>
	</table>
</div></div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>MaryMorrison</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/879028-0x804e1bf8-blue-screen-boot-up.html</guid>
		</item>
		<item>
			<title>Need help purging Vundo.IG</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/879025-need-help-purging-vundo-ig.html</link>
			<pubDate>Fri, 20 Nov 2009 21:45:23 GMT</pubDate>
			<description>Hello,  
 
I picked up Vundo.IG when I went to NFL.com of all places. Now I am stuck with it... 
 
I am rather new to computers and things of the sort. 
 
Here is my HighJackThis! log: 
 
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at...</description>
			<content:encoded><![CDATA[<div>Hello, <br />
<br />
I picked up Vundo.IG when I went to NFL.com of all places. Now I am stuck with it...<br />
<br />
I am rather new to computers and things of the sort.<br />
<br />
Here is my HighJackThis! log:<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 4:39:36 PM, on 11/20/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16915)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\ibmpmsvc.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe<br />
C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe<br />
C:\WINDOWS\system32\acs.exe<br />
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe<br />
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe<br />
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe<br />
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe<br />
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe<br />
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe<br />
C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br />
C:\WINDOWS\System32\TPHDEXLG.exe<br />
C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe<br />
C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe<br />
c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe<br />
C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe<br />
C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE<br />
C:\Program Files\Common Files\Lenovo\Logger\logmon.exe<br />
C:\WINDOWS\system32\SearchIndexer.exe<br />
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe<br />
C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
c:\program files\lenovo\system update\suservice.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe<br />
C:\Program Files\AVG\AVG8\avgcsrvx.exe<br />
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe<br />
C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe<br />
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe<br />
C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe<br />
C:\WINDOWS\system32\TpShocks.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe<br />
C:\Program Files\Lenovo\Zoom\TpScrex.exe<br />
C:\Program Files\Lenovo\AwayTask\AwaySch.EXE<br />
C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe<br />
C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe<br />
C:\Program Files\Lenovo\Client Security Solution\cssauth.exe<br />
C:\WINDOWS\system32\igfxsrvc.exe<br />
C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\Windows Desktop Search\WindowsSearch.exe<br />
C:\Program Files\Lenovo\Client Security Solution\tvtpwm_tray.exe<br />
C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://z3.************.com/GTA_TGA/index.php?" target="_blank">http://z3.************.com/GTA_TGA/index.php?</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://lenovo.live.com" target="_blank">http://lenovo.live.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br />
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br />
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O2 - BHO: ThinkVantage Password Manager - {F040E541-A427-4CF7-85D8-75E3E0F476C5} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll<br />
O3 - Toolbar: &amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor<br />
O4 - HKLM\..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe /r<br />
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe<br />
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe<br />
O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE<br />
O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe<br />
O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe<br />
O4 - HKLM\..\Run: [cssauth] &quot;C:\Program Files\Lenovo\Client Security Solution\cssauth.exe&quot; silent<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] &quot;C:\Program Files\BitDefender\BitDefender 2010\IEShow.exe&quot;<br />
O4 - HKLM\..\Run: [BDAgent] &quot;C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe&quot;<br />
O4 - HKLM\..\RunOnce: [wextract_cleanup0] rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 &quot;C:\DOCUME~1\Tanis\LOCALS~1\Temp\IXP000.TMP\&quot;<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [MsnMsgr] &quot;C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe&quot; /background<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] &quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&quot; -t (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] &quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&quot; -t (User 'Default user')<br />
O4 - Global Startup: Microsoft Office Fast Start.lnk = C:\MSOffice\Office\FASTBOOT.EXE<br />
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {0045D4BC-5189-4b67-969C-83BB1906C421} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll<br />
O9 - Extra 'Tools' menuitem: ThinkVantage Password Manager... - {0045D4BC-5189-4b67-969C-83BB1906C421} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O20 - AppInit_DLLs: higiripe.dll c:\windows\system32\hudivika.dll<br />
O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O22 - SharedTaskScheduler: jugezatag - {ac422578-d141-4bcc-bc22-bf81dd932dc3} - c:\windows\system32\hudivika.dll (file missing)<br />
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo  - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe<br />
O23 - Service: Atheros Configuration Service (acs) - Atheros - C:\WINDOWS\system32\acs.exe<br />
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo  - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe<br />
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. <a href="http://www.bitdefender.com" target="_blank">http://www.bitdefender.com</a> - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe<br />
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe<br />
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe<br />
O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE<br />
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe<br />
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe<br />
O23 - Service: QuickBooks Database Manager Service (QBCFMonitorService) - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe<br />
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe<br />
O23 - Service: QuickBooksDB17 - iAnywhere Solutions, Inc. - C:\PROGRA~1\Intuit\QUICKB~1\QBDBMgrN.exe<br />
O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\program files\lenovo\system update\suservice.exe<br />
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe<br />
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe<br />
O23 - Service: TVT Backup Protection Service - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe<br />
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe<br />
O23 - Service: TVT Scheduler - Lenovo Group Limited - c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe<br />
O23 - Service: tvtnetwk - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe<br />
<br />
--<br />
End of file - 12901 bytes<br />
<br />
I hear that removal of this thing is a complicated and long process that is different with every computer; I am more than willing to do it what is needed. It destroyed Malware Bytes and prevents it from running the .exe anymore, same with AVG.<br />
<br />
Any and all help is appreciated in advance.</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>RavenOfOld</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/879025-need-help-purging-vundo-ig.html</guid>
		</item>
		<item>
			<title><![CDATA[Maybe I'm clean, maybe not?]]></title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/879022-maybe-im-clean-maybe-not.html</link>
			<pubDate>Fri, 20 Nov 2009 21:25:47 GMT</pubDate>
			<description><![CDATA[I run AVGFree, downloaded some software the other day and got hit with a virus warning.  win32.virtut I believe.  From what I've read this is impossible to remove.  But, I've been working on it.   
 
I had AVG, Spybot, and adaware all present...]]></description>
			<content:encoded><![CDATA[<div>I run AVGFree, downloaded some software the other day and got hit with a virus warning.  win32.virtut I believe.  From what I've read this is impossible to remove.  But, I've been working on it.  <br />
<br />
I had AVG, Spybot, and adaware all present different infections to me in different scans.  I forget all of them.  Notepad.exe was infected, as well as a couple other executables.  Also I was getting 115.tmp, BtwSrv.dll (or maybe exe) and fastnetsrv.exe showing up and reinstalling them after deletes.  <br />
<br />
I ran WinPatrol and noticed I had BtwSrv and Fastnetsrv in the services.  I stopped those services and deleted the files.  They haven't respawned yet, although the services still show up in winpatrol as File not found, and Disabled, respectively.<br />
<br />
I'm getting no real virus symptoms, and right now all my scans are showing up clean.  Computer is running okay from what I can tell.  <br />
<br />
Here is my hijack this log:<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 4:25:15 PM, on 11/20/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
C:\WINDOWS\system32\RUNDLL32.EXE<br />
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\MediaMall\PlayOn.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe<br />
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe<br />
C:\Program Files\MediaMall\MediaMallServer.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\NeoSmart Technologies\ToolTipFixer\ToolTipFixer.exe<br />
C:\Program Files\TVersity\Media Server\MediaServer.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br />
C:\Documents and Settings\ab\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\ab\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\ab\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\ab\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\BillP Studios\WinPatrol\WinPatrolEx.exe<br />
C:\Documents and Settings\ab\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://218.93.205.24/nospam/" target="_blank">http://218.93.205.24/nospam/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = <a href="http://go.microsoft.com/fwlink/?LinkId=74005" target="_blank">http://go.microsoft.com/fwlink/?LinkId=74005</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe<br />
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [PlayOn] C:\Program Files\MediaMall\PlayOn.exe<br />
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] &quot;C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe&quot;<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')<br />
O4 - Global Startup: HPAiODevice(hp psc 700 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe<br />
O8 - Extra context menu item: Add to Google Photos Screensa&amp;ver - res://C:\WINDOWS\system32\GPhotos.scr/200<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - <a href="http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab" target="_blank">http://www.nvidia.com/content/Driver...reqlab_nvd.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1255571346671" target="_blank">http://update.microsoft.com/microsof...?1255571346671</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1258560071156" target="_blank">http://www.update.microsoft.com/micr...?1258560071156</a><br />
O20 - AppInit_DLLs: C:\WINDOWS\system32\rdolib.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
O23 - Service: MediaMall Server - MediaMall Technologies, Inc. - C:\Program Files\MediaMall\MediaMallServer.exe<br />
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009.SP4\RpcAgentSrv.exe<br />
O23 - Service: NST ToolTipFixer (TTFixerService) - NeoSmart Technologies - C:\Program Files\NeoSmart Technologies\ToolTipFixer\ToolTipFixer.exe<br />
O23 - Service: TVersityMediaServer - Unknown owner - C:\Program Files\TVersity\Media Server\MediaServer.exe<br />
<br />
--<br />
End of file - 9433 bytes<br />
<br />
All help is VERY appreciated!</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>virusmaybe</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/879022-maybe-im-clean-maybe-not.html</guid>
		</item>
		<item>
			<title>Combofix - office /windows screwed up</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/879021-combofix-office-windows-screwed-up.html</link>
			<pubDate>Fri, 20 Nov 2009 21:21:10 GMT</pubDate>
			<description><![CDATA[Dell Latitude 630 - Windows XP Office 2007 
  
Tried repairing install - doesn't complete. 
  
  
I had an issue which looked like a malware one and a friend told me combofix was the best solution. I evidently did not use it correctly. Now Oulook...]]></description>
			<content:encoded><![CDATA[<div>Dell Latitude 630 - Windows XP Office 2007<br />
 <br />
Tried repairing install - doesn't complete.<br />
 <br />
 <br />
I had an issue which looked like a malware one and a friend told me combofix was the best solution. I evidently did not use it correctly. Now Oulook will not open at all. ERROR READS <i>&quot;cannot open your default e-mail folders. an unexpected error has occured. MAPI was unable to load the information services mspst.dll. be sure the service is correctly installed and configured.&quot; </i>. <br />
Word and Excel Open in safe mode. IE keeps crashing and Search in windows explorer does not work (SHOWS UP BLANK). <br />
 <br />
Attahced  is the Combofix log. A new restore point was not created so I could not go back.<br />
 <br />
Also attached a hijack this file from today.<br />
 <br />
I would appreciate any help.<br />
 <br />
beekski</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://static.techguy.org/v38/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="{attachment-server}attachment.php?attachmentid=159881&amp;d=1258752024">hijackthis1120352.log</a> (16.9 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://static.techguy.org/v38/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="{attachment-server}attachment.php?attachmentid=159882&amp;d=1258752037">ComboFix.txt</a> (37.4 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>beekski</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/879021-combofix-office-windows-screwed-up.html</guid>
		</item>
		<item>
			<title>google redirect and security hijack</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/879015-google-redirect-security-hijack.html</link>
			<pubDate>Fri, 20 Nov 2009 21:08:45 GMT</pubDate>
			<description>looking at some others posts...I started out with the super antispy scan.  
  
here is the log: 
SUPERAntiSpyware Scan Log 
http://www.superantispyware.com 
Generated 11/19/2009 at 07:35 PM 
Application Version : 4.30.1004 
Core Rules Database...</description>
			<content:encoded><![CDATA[<div>looking at some others posts...I started out with the super antispy scan. <br />
 <br />
here is the log:<br />
SUPERAntiSpyware Scan Log<br />
<a href="http://www.superantispyware.com" target="_blank">http://www.superantispyware.com</a><br />
Generated 11/19/2009 at 07:35 PM<br />
Application Version : 4.30.1004<br />
Core Rules Database Version : 4294<br />
Trace Rules Database Version: 2165<br />
Scan type       : Complete Scan<br />
Total Scan Time : 03:25:55<br />
Memory items scanned      : 627<br />
Memory threats detected   : 0<br />
Registry items scanned    : 6540<br />
Registry threats detected : 57<br />
File items scanned        : 190449<br />
File threats detected     : 66<br />
Adware.E404 Helper/Variant-AR<br />
 HKU\S-1-5-21-1547161642-1060284298-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6A26574A-DD6D-4382-8C76-0DF06C478D3A}<br />
Adware.Tracking Cookie<br />
 C:\Documents and Settings\Shelley\Cookies\shelley@ad.wsod[2].txt<br />
 C:\Documents and Settings\Shelley\Cookies\shelley@content.yieldmanager[3].txt<br />
 C:\Documents and Settings\Shelley\Cookies\shelley@content.yieldmanager[4].txt<br />
 C:\Documents and Settings\Shelley\Cookies\shelley@chitika[1].txt<br />
 C:\Documents and Settings\Shelley\Cookies\shelley@ad.yieldmanager[1].txt<br />
 C:\Documents and Settings\Shelley\Cookies\shelley@doubleclick[1].txt<br />
 C:\Documents and Settings\Shelley\Cookies\shelley@atdmt[1].txt<br />
 C:\Documents and Settings\Shelley\Cookies\shelley@collective-media[1].txt<br />
 C:\Documents and Settings\Shelley\Cookies\shelley@mediaplex[1].txt<br />
 C:\Documents and Settings\Shelley\Cookies\shelley@ads.techguy[2].txt<br />
 C:\Documents and Settings\Shelley\Cookies\shelley@statse.webtrendslive[2].txt<br />
 C:\Documents and Settings\Shelley\Cookies\shelley@apmebf[1].txt<br />
 C:\Documents and Settings\Shelley\Cookies\shelley@invitemedia[1].txt<br />
 C:\Documents and Settings\Shelley\Cookies\shelley@find.myrecipes[1].txt<br />
 C:\Documents and Settings\Shelley\Cookies\shelley@ads.webkinz[2].txt<br />
 C:\Documents and Settings\Shelley\Cookies\shelley@content.yieldmanager[2].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@a1.interclick[2].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@ad.wsod[2].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@ads.bridgetrack[1].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@ads.contactmusic[1].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@ads.pgatour[2].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@ads.undertone[1].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@apartmentfinder[1].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@beacon.dmsinsights[2].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@cdn4.specificclick[2].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@chitika[2].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@clicksor[2].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@content.yieldmanager[2].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@counter.surfcounters[2].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@dmtracker[1].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@e-2dj6wfkowpc5ifp.stats.esomniture[1].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@e-2dj6wjlikndzgco.stats.esomniture[2].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@e-2dj6wjnyakcjako.stats.esomniture[2].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@eyewonder[1].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@imrworldwide[1].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@interclick[2].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@kontera[1].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@landing.hitfarm[1].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@myroitracking[1].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@overture[2].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@pointroll[2].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@revsci[2].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@sdc.okistats[1].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@server.iad.liveperson[1].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@server.iad.liveperson[3].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@server.iad.liveperson[4].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@server.iad.liveperson[5].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@sitestat.mayoclinic[1].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@specificclick[1].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@stats.cmarket[2].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@stats4.clicktracks[2].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@stracka[1].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@tacoda[2].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@toseeka[1].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@trackalyzer[1].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@traffic.buyservices[1].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@www.apartmentfinder[1].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@www.findstuff[2].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@www.googleadservices[1].txt<br />
 C:\Documents and Settings\Steve\Cookies\steve@www.stracka[1].txt<br />
Rogue.Component/Trace<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\CRYPTOGRAPHIC SERVICES (CRYPTSVC) <br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\CRYPTOGRAPHIC SERVICES (CRYPTSVC) #Type<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\CRYPTOGRAPHIC SERVICES (CRYPTSVC) #Start<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\CRYPTOGRAPHIC SERVICES (CRYPTSVC) #ErrorControl<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\CRYPTOGRAPHIC SERVICES (CRYPTSVC) #ImagePath<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\CRYPTOGRAPHIC SERVICES (CRYPTSVC) #DisplayName<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\CRYPTOGRAPHIC SERVICES (CRYPTSVC) #ObjectName<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\CRYPTOGRAPHIC SERVICES (CRYPTSVC) #FailureActions<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\CRYPTOGRAPHIC SERVICES (CRYPTSVC) \Security<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\CRYPTOGRAPHIC SERVICES (CRYPTSVC) \Security#Security<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\CRYPTOGRAPHIC SERVICES (CRYPTSVC) \Enum<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\CRYPTOGRAPHIC SERVICES (CRYPTSVC) \Enum#0<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\CRYPTOGRAPHIC SERVICES (CRYPTSVC) \Enum#Count<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\CRYPTOGRAPHIC SERVICES (CRYPTSVC) \Enum#NextInstance<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\IPOD SERVICE (IPOD SERVICE) <br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\IPOD SERVICE (IPOD SERVICE) #Type<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\IPOD SERVICE (IPOD SERVICE) #Start<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\IPOD SERVICE (IPOD SERVICE) #ErrorControl<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\IPOD SERVICE (IPOD SERVICE) #ImagePath<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\IPOD SERVICE (IPOD SERVICE) #DisplayName<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\IPOD SERVICE (IPOD SERVICE) #ObjectName<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\IPOD SERVICE (IPOD SERVICE) #FailureActions<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\IPOD SERVICE (IPOD SERVICE) \Security<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\IPOD SERVICE (IPOD SERVICE) \Security#Security<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\IPOD SERVICE (IPOD SERVICE) \Enum<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\IPOD SERVICE (IPOD SERVICE) \Enum#0<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\IPOD SERVICE (IPOD SERVICE) \Enum#Count<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\IPOD SERVICE (IPOD SERVICE) \Enum#NextInstance<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE REAL-TIME SCANNER (MCSHIELD) <br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE REAL-TIME SCANNER (MCSHIELD) #Type<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE REAL-TIME SCANNER (MCSHIELD) #Start<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE REAL-TIME SCANNER (MCSHIELD) #ErrorControl<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE REAL-TIME SCANNER (MCSHIELD) #ImagePath<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE REAL-TIME SCANNER (MCSHIELD) #DisplayName<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE REAL-TIME SCANNER (MCSHIELD) #ObjectName<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE REAL-TIME SCANNER (MCSHIELD) #FailureActions<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE REAL-TIME SCANNER (MCSHIELD) \Security<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE REAL-TIME SCANNER (MCSHIELD) \Security#Security<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE REAL-TIME SCANNER (MCSHIELD) \Enum<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE REAL-TIME SCANNER (MCSHIELD) \Enum#0<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE REAL-TIME SCANNER (MCSHIELD) \Enum#Count<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE REAL-TIME SCANNER (MCSHIELD) \Enum#NextInstance<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE SERVICES (MCMSCSVC) <br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE SERVICES (MCMSCSVC) #Type<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE SERVICES (MCMSCSVC) #Start<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE SERVICES (MCMSCSVC) #ErrorControl<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE SERVICES (MCMSCSVC) #ImagePath<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE SERVICES (MCMSCSVC) #DisplayName<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE SERVICES (MCMSCSVC) #ObjectName<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE SERVICES (MCMSCSVC) #FailureActions<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE SERVICES (MCMSCSVC) \Security<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE SERVICES (MCMSCSVC) \Security#Security<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE SERVICES (MCMSCSVC) \Enum<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE SERVICES (MCMSCSVC) \Enum#0<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE SERVICES (MCMSCSVC) \Enum#Count<br />
 HKLM\System\CURRENTCONTROLSET\SERVICES\MCAFEE SERVICES (MCMSCSVC) \Enum#NextInstance<br />
Rogue.WindowsEnterpriseDefender<br />
 C:\DOCUMENTS AND SETTINGS\ALL USERS\B19387C\WSB193.EXE<br />
 C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\NYYHRPQC\XP_A8B09[1].EXE<br />
Browser Hijacker.Favorites<br />
 C:\RECYCLER\S-1-5-21-1547161642-1060284298-725345543-1004\DC62.URL<br />
 C:\RECYCLER\S-1-5-21-1547161642-1060284298-725345543-1004\DC63.URL<br />
 C:\RECYCLER\S-1-5-21-1547161642-1060284298-725345543-1004\DC64.URL<br />
Trojan.Agent/Gen-Zbot<br />
 C:\WINDOWS\TEMP\_ISTMP2.DIR\INSUTL.DLL<br />
<br />
 <br />
 <br />
 <br />
What do I do next?</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>shelen</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/879015-google-redirect-security-hijack.html</guid>
		</item>
		<item>
			<title>taskmgr.exe uses 100% CPU</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/879005-taskmgr-exe-uses-100-cpu.html</link>
			<pubDate>Fri, 20 Nov 2009 20:10:21 GMT</pubDate>
			<description>When i start up the task manager it sucks up all my cpu usage and my computer becomes so slow. It started about a week ago but i cant figure out what caused it. I have run antivirus and spyware scans but cant find anything. Please help</description>
			<content:encoded><![CDATA[<div>When i start up the task manager it sucks up all my cpu usage and my computer becomes so slow. It started about a week ago but i cant figure out what caused it. I have run antivirus and spyware scans but cant find anything. Please help</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>chris_m</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/879005-taskmgr-exe-uses-100-cpu.html</guid>
		</item>
		<item>
			<title>Computer seems to be hijacked.  Please review log.</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/879002-computer-seems-hijacked-please-review.html</link>
			<pubDate>Fri, 20 Nov 2009 20:01:53 GMT</pubDate>
			<description><![CDATA[Getting alot of pup ups on my brother in law's computer.  He apparently installed several bogus virus scan programs when they prompted him during web surfing.  I think I removed the two applications, but it looks like there is still some scum in his...]]></description>
			<content:encoded><![CDATA[<div>Getting alot of pup ups on my brother in law's computer.  He apparently installed several bogus virus scan programs when they prompted him during web surfing.  I think I removed the two applications, but it looks like there is still some scum in his hijack log..  Please review and let me know what should be removed.. and thanks so much for your assistance..<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 12:58:56 PM, on 11/20/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16762)<br />
Boot mode: Safe mode with network support<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\TeamViewer3\TeamViewer.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\WINDOWS\system32\igfxsrvc.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://www.dell4me.com/myway" target="_blank">http://www.dell4me.com/myway</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.dell4me.com/myway" target="_blank">http://www.dell4me.com/myway</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://www.yahoo.com/" target="_blank">http://www.yahoo.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html" target="_blank">http://us.rd.yahoo.com/customize/ie/...ch/search.html</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = <a href="http://www.dellnet.com/" target="_blank">http://www.dellnet.com/</a><br />
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\5.bin\MWSSRCAS.DLL<br />
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\5.bin\MWSBAR.DLL<br />
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.9.0\ViewBarBHO.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll<br />
O3 - Toolbar: Protection Bar - {84938242-5C5B-4A55-B6B9-A1507543B418} - C:\Program Files\Video Access ActiveX Object\iesplugin.dll (file missing)<br />
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\5.bin\MWSBAR.DLL<br />
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll<br />
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.9.0\IEViewBar.dll<br />
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe<br />
O4 - HKLM\..\Run: [Adobe Photo Downloader] &quot;C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe&quot;<br />
O4 - HKLM\..\Run: [winupdate86.exe] C:\WINDOWS\system32\winupdate86.exe<br />
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br />
O4 - HKCU\..\Run: [DellSupport] &quot;C:\Program Files\Dell Support\DSAgnt.exe&quot; /startup<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKLM\..\Policies\Explorer\Run: [5Na9Fo4RbV] C:\Documents and Settings\All Users\Application Data\srkxkfsf\gvylctkp.exe<br />
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')<br />
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] &quot;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&quot; /background (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe<br />
O4 - Global Startup: WG111v2 Smart Wizard Wireless Setting.lnk = ?<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - <a href="http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab" target="_blank">http://messenger.zone.msn.com/binary...r.cab31267.cab</a><br />
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - <a href="http://zone.msn.com/binFrameWork/v10/StagingUI.cab40641.cab" target="_blank">http://zone.msn.com/binFrameWork/v10...I.cab40641.cab</a><br />
O16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) - <a href="https://www.plaxo.com/down/release/PlaxoInstall.cab" target="_blank">https://www.plaxo.com/down/release/PlaxoInstall.cab</a><br />
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - <a href="http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab" target="_blank">http://zone.msn.com/BinFrameWork/v10...y.cab32846.cab</a><br />
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - <a href="http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab" target="_blank">http://zone.msn.com/binframework/v10...t.cab32846.cab</a><br />
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - <a href="http://www.webshots.com/samplers/WSDownloader.ocx" target="_blank">http://www.webshots.com/samplers/WSDownloader.ocx</a><br />
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - <a href="http://www.maricopa.gov/assessor/gis/plugin/mgaxctrl.cab" target="_blank">http://www.maricopa.gov/assessor/gis...n/mgaxctrl.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1111942182750" target="_blank">http://v5.windowsupdate.microsoft.co...?1111942182750</a><br />
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - <a href="http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab" target="_blank">http://security.symantec.com/sscv6/S.../bin/cabsa.cab</a><br />
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - <a href="http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab" target="_blank">http://messenger.zone.msn.com/binary...t.cab31267.cab</a><br />
O16 - DPF: {90051A81-3018-4826-8B38-DD60B6B53F9C} (Snapfish File Upload ActiveX Control) - <a href="http://www.costcophotocenter.com/CostcoUpload.cab" target="_blank">http://www.costcophotocenter.com/CostcoUpload.cab</a><br />
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - <a href="http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab" target="_blank">http://cdn2.zone.msn.com/binFramewor...o.cab34246.cab</a><br />
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - <a href="http://zone.msn.com/binframework/v10/StProxy.cab41227.cab" target="_blank">http://zone.msn.com/binframework/v10...y.cab41227.cab</a><br />
O16 - DPF: {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} (ZPA_Backgammon Object) - <a href="http://zone.msn.com/bingame/zpagames/ZPA_Backgammon.cab40641.cab" target="_blank">http://zone.msn.com/bingame/zpagames...n.cab40641.cab</a><br />
O20 - AppInit_DLLs: winmm.dll<br />
O22 - SharedTaskScheduler: cam - {634be415-da12-496b-b89e-329b73c4807f} - C:\WINDOWS\system32\tvomnc.dll (file missing)<br />
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\5.bin\mwssvc.exe<br />
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
<br />
--<br />
End of file - 8050 bytes</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>musiclover</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/879002-computer-seems-hijacked-please-review.html</guid>
		</item>
		<item>
			<title>Comodo Pro Firewall Latest Update Trojan?</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878999-comodo-pro-firewall-latest-update.html</link>
			<pubDate>Fri, 20 Nov 2009 19:50:04 GMT</pubDate>
			<description><![CDATA[Hi, 
 
Has anyone else had this problem?  
 
The latest update to the free Comodo Firewall Pro (early November 2009) triggers my Webroot antivirus program, warning me that I am installing "Mal/Gampass-B." My Norton 2010 gives no such warning, nor...]]></description>
			<content:encoded><![CDATA[<div>Hi,<br />
<br />
Has anyone else had this problem? <br />
<br />
The latest update to the free Comodo Firewall Pro (early November 2009) triggers my Webroot antivirus program, warning me that I am installing &quot;Mal/Gampass-B.&quot; My Norton 2010 gives no such warning, nor does Superantispyware.<br />
<br />
I am not familiar with this virus. The Comodo site FAQ was of no help, nor could I find any one else with the issue posting via Google. After about a week (today) I went ahead and installed the update, overriding Webroot.<br />
<br />
There doesn't seem to be a problem, but I'm concerned I may have made a bad update decision.<br />
<br />
Thanks for any insight,<br />
<br />
Out Of Date Bob</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>bobsedge</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878999-comodo-pro-firewall-latest-update.html</guid>
		</item>
		<item>
			<title><![CDATA[PC running at a snail's pace!!!]]></title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878965-pc-running-snails-pace.html</link>
			<pubDate>Fri, 20 Nov 2009 16:26:36 GMT</pubDate>
			<description><![CDATA[Hello.  Recently, my PC went from functioning at a very high speed to what seems like a dial-up connection.  My PC's slow processing speed only occurs when I go online.  It works perfectly when opening up word docs, pictures, etc. 
  
I called...]]></description>
			<content:encoded><![CDATA[<div>Hello.  Recently, my PC went from functioning at a very high speed to what seems like a dial-up connection.  My PC's slow processing speed only occurs when I go online.  It works perfectly when opening up word docs, pictures, etc.<br />
 <br />
I called Verizon and they did a line test and said everything was fine.  I also have rebooted my modem and router several times.  I've also cleared my browsing history and removed Limewire from my PC b/c I was told that file sharing prgrms can slow things down.  I'm wondering if I have contracted a nasty virus or malware.  Any suggestions?  Thank you!</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>Rippa</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878965-pc-running-snails-pace.html</guid>
		</item>
		<item>
			<title><![CDATA[Computer won't shut down properly]]></title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878955-computer-wont-shut-down-properly.html</link>
			<pubDate>Fri, 20 Nov 2009 15:51:13 GMT</pubDate>
			<description><![CDATA[My computer will not shut down properly. I takes forever to get to the 3 choices box for "turn off" "restart" or "log off." Then it freezes again at the "windows is shutting down saving you settings" screen. I tried   various fixes I found after...]]></description>
			<content:encoded><![CDATA[<div>My computer will not shut down properly. I takes forever to get to the 3 choices box for &quot;turn off&quot; &quot;restart&quot; or &quot;log off.&quot; Then it freezes again at the &quot;windows is shutting down saving you settings&quot; screen. I tried   various fixes I found after searching this site but nothing worked. The entire thread with excruciating detail ;)  is here:<br />
<br />
<a href="http://forums.techguy.org/windows-xp/878090-computer-wont-shut-down-properly.html" target="_blank">http://forums.techguy.org/windows-xp...-properly.html</a><br />
<br />
<b>Phantom010</b> suggested I have an expert look at the HJT report (below) <b>line 020</b> which contained a suspicious entry:<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 6:20:03 PM, on 11/19/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br />
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\a-squared Free\a2service.exe<br />
C:\Program Files\a-squared Free\a2service.exe<br />
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Executive Software\Diskeeper\DkService.exe<br />
C:\Program Files\Google\Update\GoogleUpdate.exe<br />
F:\UPHClean\uphclean.exe<br />
C:\WINDOWS\System32\ups.exe<br />
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe<br />
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe<br />
C:\Program Files\TaskPlus\taskplus0.exe<br />
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe<br />
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\dla\tfswctrl.exe<br />
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe<br />
C:\Program Files\Clavier+\Clavier.exe<br />
C:\Program Files\OpenDNS Updater\OpenDNSUpdater.exe<br />
C:\QUICKENW\QWDLLS.EXE<br />
C:\Documents and Settings\Robert Hickey\Start Menu\Programs\Karen's Power Tools\PTReplicator.exe<br />
C:\Program Files\YCIII\YankClip.exe<br />
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe<br />
F:\Mozilla Firefox\firefox.exe<br />
F:\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://www.dell4me.com/myway" target="_blank">http://www.dell4me.com/myway</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\QUICKENW\inet\common\BLANK.HTM<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\QUICKENW\inet\common\BLANK.HTM<br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = <a href="http://www.dell4me.com/myway" target="_blank">http://www.dell4me.com/myway</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll<br />
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll<br />
O3 - Toolbar: &amp;RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll<br />
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
O4 - HKLM\..\Run: [ZoneAlarm Client] &quot;C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe&quot;<br />
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot<br />
O4 - HKLM\..\Run: [TaskPlus] C:\Program Files\TaskPlus\taskplus0.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe<br />
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br />
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe<br />
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe<br />
O4 - HKCU\..\Run: [FreeRAM XP] &quot;C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe&quot; -win<br />
O4 - HKCU\..\Run: [Clavier+] C:\Program Files\Clavier+\Clavier.exe<br />
O4 - HKCU\..\Run: [OpenDNS Updater] &quot;C:\Program Files\OpenDNS Updater\OpenDNSUpdater.exe&quot; /autostart<br />
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE<br />
O4 - Startup: Karen's Replicator.lnk = C:\Documents and Settings\Robert Hickey\Start Menu\Programs\Karen's Power Tools\PTReplicator.exe<br />
O4 - Startup: Yankee Clipper III.lnk = C:\Program Files\YCIII\YankClip.exe<br />
O4 - Global Startup: APC UPS Status.lnk = C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe<br />
O4 - Global Startup: Quicken Startup.lnk = C:\QUICKENW\QWDLLS.EXE<br />
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present<br />
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html<br />
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html<br />
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll<br />
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html<br />
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html<br />
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html<br />
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html<br />
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html<br />
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html<br />
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} -<br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a href="http://go.microsoft.com/fwlink/?linkid=39204" target="_blank">http://go.microsoft.com/fwlink/?linkid=39204</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://www.update.microsoft.com/micr...?1188091841437" target="_blank">http://www.update.microsoft.com/micr...?1188091841437</a><br />
O17 - HKLM\System\CCS\Services\Tcpip\..\{1B94F129-1B7E-4020-BD9D-35B1F28F445E}: NameServer = 208.67.222.222,208.67.220.220<br />
<b>O20 - Winlogon Notify: yaywwwWM - C:\WINDOWS\</b><br />
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe<br />
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe<br />
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br />
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe<br />
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe<br />
O23 - Service: OpenDNS Updater (OpenDNS Updater.exe) - Dell Computer Corporation - (no file)<br />
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe<br />
<br />
--<br />
End of file - 9643 bytes<br />
<br />
Thank you for any help you can provide.<br />
<br />
Robert</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>robhic</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878955-computer-wont-shut-down-properly.html</guid>
		</item>
		<item>
			<title>Massive spyware/virus problem - bank details stolen!!</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878940-massive-spyware-virus-problem-bank.html</link>
			<pubDate>Fri, 20 Nov 2009 14:47:34 GMT</pubDate>
			<description><![CDATA[Hi, 
  
I've got a huge problem with a virus and/or spyware on my PC. The first problem it started causing was, when I search on google.co.uk and then click on a link it always brings up google.com in the address bar and then takes me to straight to...]]></description>
			<content:encoded><![CDATA[<div>Hi,<br />
 <br />
I've got a huge problem with a virus and/or spyware on my PC. The first problem it started causing was, when I search on google.co.uk and then click on a link it always brings up google.com in the address bar and then takes me to straight to an advert page. I've been trying to get rid of it using various anti-malware packages (spybot, AMB and Super anti-spyware) but when I try and search with them it just closes the program and then it won't let me back in to it. Even if I try and download it again and reinstall it. If I run AVG it find a virus called TrojanHorse PSW.Agent.ACTI but can't remove it.<br />
 <br />
The major problem I have is someone has got hold of my internet banking logon and actually set up a standing order from my account of £1000 per week! Luckily the bank picked it up straight away! I'm assuming that this is down to the virus/spyware. <br />
 <br />
I have tried to do a scan with HijackThis but again, as soon as I click scan it just closes and then I can't open the program anymore.<br />
 <br />
Please, please, please help!!!<br />
 <br />
Many Thanks in advance</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>clairecherry77</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878940-massive-spyware-virus-problem-bank.html</guid>
		</item>
		<item>
			<title>is there anything wrong with my computer? HJT log,</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878934-there-anything-wrong-my-computer.html</link>
			<pubDate>Fri, 20 Nov 2009 14:18:16 GMT</pubDate>
			<description>Hi! i wonder if my computer is under any risk of a key logger or trojan etc, could you please check this log if you can find anything and replay to me as soon as possible.. please help!:( 
  
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at...</description>
			<content:encoded><![CDATA[<div>Hi! i wonder if my computer is under any risk of a key logger or trojan etc, could you please check this log if you can find anything and replay to me as soon as possible.. please help!:(<br />
 <br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 15:17:49, on 2009-11-20<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16915)<br />
Boot mode: Normal<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program\Bonjour\mDNSResponder.exe<br />
C:\Program\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\system32\PnkBstrA.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program\Java\jre6\bin\jusched.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program\Logitech\Video\LogiTray.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\Program\Logitech\Video\FxSvr2.exe<br />
C:\WINDOWS\system32\RUNDLL32.EXE<br />
C:\Program\NETGEAR\WN311B\Utility\WN311B.exe<br />
C:\Program\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMHID.exe<br />
C:\Program\AirPort\APAgent.exe<br />
C:\Program\Delade filer\Nokia\MPlatform\NokiaMServer.exe<br />
C:\Program\iTunes\iTunesHelper.exe<br />
C:\Program\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMTray.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program\iPod\bin\iPodService.exe<br />
C:\Program\MSN Messenger\msnmsgr.exe<br />
C:\Documents and Settings\pc\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe<br />
C:\Program\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program\Nokia\PC Connectivity Solution\ServiceLayer.exe<br />
C:\Program\Nokia\PC Connectivity Solution\Transports\NclUSBSrv.exe<br />
C:\Program\Nokia\PC Connectivity Solution\Transports\NclRSSrv.exe<br />
C:\Program\Java\jre6\bin\jucheck.exe<br />
C:\Program\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtblfs.exe<br />
C:\Program\Lavasoft\Ad-Aware\AAWService.exe<br />
C:\Program\Lavasoft\Ad-Aware\AAWTray.exe<br />
C:\Program\Internet Explorer\iexplore.exe<br />
C:\Program\Trend Micro\HijackThis\HijackThis.exe<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.tennis.se/" target="_blank">http://www.tennis.se/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar<br />
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe<br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program\Kaspersky Lab\Kaspersky Anti-Virus 2010\ievkbd.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll<br />
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program\Logitech\Video\ISStart.exe <br />
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program\Logitech\Video\LogiTray.exe<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE<br />
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br />
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [AS00_WN311B] C:\Program\NETGEAR\WN311B\Utility\WN311B.exe -hide<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [SteelSeries World of Warcraft MMO Gaming Mouse] C:\Program\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMHID.exe<br />
O4 - HKLM\..\Run: [AirPort Base Station Agent] &quot;C:\Program\AirPort\APAgent.exe&quot;<br />
O4 - HKLM\..\Run: [NokiaMServer] C:\Program\Delade filer\Nokia\MPlatform\NokiaMServer /watchfiles<br />
O4 - HKLM\..\Run: [Nokia FastStart] &quot;C:\Program\Nokia\Nokia Music\NokiaMusic.exe&quot; /command:faststart<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [AVP] &quot;C:\Program\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe&quot;<br />
O4 - HKLM\..\Run: [MS_MASTER] RUNDLL32.EXE C:\WINDOWS\system32\xml_inc.dll,i<br />
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe<br />
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] C:\Program\Logitech\Video\ManifestEngine.exe boot<br />
O4 - HKCU\..\Run: [msnmsgr] &quot;C:\Program\MSN Messenger\msnmsgr.exe&quot; /background<br />
O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU &quot;C:\DOCUME~1\pc\LOKALA~1\Temp\E_SF.tmp&quot; /EF &quot;HKCU&quot;<br />
O4 - HKCU\..\Run: [Octoshape Streaming Services] &quot;C:\Documents and Settings\pc\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe&quot; -inv:bootrun<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJÄNST')<br />
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')<br />
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br />
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe<br />
O4 - Global Startup: Microsoft Office.lnk = C:\Program\Microsoft Office\Office10\OSA.EXE<br />
O8 - Extra context menu item: E&amp;xportera till Microsoft Excel - res://C:\Program\MICROS~2\Office10\EXCEL.EXE/3000<br />
O9 - Extra button: &amp;Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll<br />
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe<br />
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe<br />
O9 - Extra button: URLs c&amp;heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe<br />
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - <a href="http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab" target="_blank">http://messenger.zone.msn.com/binary...r.cab31267.cab</a><br />
O16 - DPF: {4E218431-2F07-40BD-A9D3-035324C1F13F} (DyynoX Class) - <a href="http://stage.dyyno.com/tng/dyyno-client/DyynoCAB.CAB" target="_blank">http://stage.dyyno.com/tng/dyyno-client/DyynoCAB.CAB</a><br />
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - <a href="http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab" target="_blank">http://download.bitdefender.com/reso...an8/oscan8.cab</a><br />
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - <a href="https://webdl.symantec.com/activex/symdlmgr.cab" target="_blank">https://webdl.symantec.com/activex/symdlmgr.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1170697391546" target="_blank">http://update.microsoft.com/microsof...?1170697391546</a><br />
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - <a href="http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab" target="_blank">http://messenger.zone.msn.com/binary...t.cab31267.cab</a><br />
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - <a href="http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab" target="_blank">http://acs.pandasoftware.com/actives.../as2stubie.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O20 - AppInit_DLLs: C:\Program\KASPER~1\KASPER~1\mzvkbd3.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Automatisk LiveUpdate-schemaläggare - Unknown owner - C:\Program\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)<br />
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe<br />
O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:\Program\Bonjour\mDNSResponder.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program\Java\jre6\bin\jqs.exe<br />
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program\Lavasoft\Ad-Aware\AAWService.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe<br />
O23 - Service: ServiceLayer - Nokia. - C:\Program\Nokia\PC Connectivity Solution\ServiceLayer.exe<br />
--<br />
End of file - 10491 bytes</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>fantastic12</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878934-there-anything-wrong-my-computer.html</guid>
		</item>
		<item>
			<title>tdlcmd.dll infected can not remove -HJT Log</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878922-tdlcmd-dll-infected-can-not.html</link>
			<pubDate>Fri, 20 Nov 2009 13:35:20 GMT</pubDate>
			<description>Hi there, 
I use AVG 9 and it continually brings up an infection warning about tdlcmd.dll. I can remove the infection but it will reappear. I found another forum saying they successfully removed the infection with Windows Defender, however i have...</description>
			<content:encoded><![CDATA[<div>Hi there,<br />
I use AVG 9 and it continually brings up an infection warning about tdlcmd.dll. I can remove the infection but it will reappear. I found another forum saying they successfully removed the infection with Windows Defender, however i have done this and the infection still reappears. Another thread was answered and Combofix was used to remove it, however i don't want to get ahead of myself, can you please assist with removal of this?<br />
<br />
HJT Log file:<br />
-------------------<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 12:25:37 AM, on 21/11/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16915)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Google\Update\1.2.183.13\GoogleCrashHandler.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\Program Files\Lexmark 9300 Series\lxcqmon.exe<br />
C:\Program Files\Lexmark 9300 Series\ezprint.exe<br />
C:\Program Files\Microsoft IntelliType Pro\itype.exe<br />
C:\Program Files\Microsoft IntelliPoint\ipoint.exe<br />
C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\DNA\btdna.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe<br />
C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\Documents and Settings\Adam Smith\Local Settings\Application Data\Google\Update\1.2.183.13\GoogleCrashHandler.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\WINDOWS\system32\lxcqcoms.exe<br />
C:\WINDOWS\system32\IoctlSvc.exe<br />
C:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\MOHAGame\pb\PnkBstrA.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe<br />
C:\WINDOWS\System32\StkASv2K.exe<br />
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe<br />
C:\WINDOWS\system32\SearchIndexer.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Documents and Settings\Adam Smith\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\Adam Smith\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\Documents and Settings\Adam Smith\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\Adam Smith\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\Adam Smith\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\WINDOWS\system32\SearchProtocolHost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: FCBHOBHO Class - {8B3868B4-EBA8-48FA-A19B-E1DFB99066FA} - C:\Program Files\Flash Capture\fcbho.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O2 - BHO: Cooliris Plug-In for Internet Explorer - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\cooliris.dll<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br />
O4 - HKLM\..\Run: [lxcqmon.exe] &quot;C:\Program Files\Lexmark 9300 Series\lxcqmon.exe&quot;<br />
O4 - HKLM\..\Run: [EzPrint] &quot;C:\Program Files\Lexmark 9300 Series\ezprint.exe&quot;<br />
O4 - HKLM\..\Run: [LXCQCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCQtime.dll,_RunDLLEntry@16<br />
O4 - HKLM\..\Run: [itype] &quot;C:\Program Files\Microsoft IntelliType Pro\itype.exe&quot;<br />
O4 - HKLM\..\Run: [IntelliPoint] &quot;C:\Program Files\Microsoft IntelliPoint\ipoint.exe&quot;<br />
O4 - HKLM\..\Run: [StartCCC] &quot;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&quot; MSRun<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;  -osboot<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [Windows Defender] &quot;C:\Program Files\Windows Defender\MSASCui.exe&quot; -hide<br />
O4 - HKCU\..\Run: [Google Update] &quot;C:\Documents and Settings\Adam Smith\Local Settings\Application Data\Google\Update\GoogleUpdate.exe&quot; /c<br />
O4 - HKCU\..\Run: [BitTorrent DNA] &quot;C:\Program Files\DNA\btdna.exe&quot;<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')<br />
O8 - Extra context menu item: Save F&amp;lash with FlashCapture - res://C:\Program Files\Flash Capture\fciext.dll/FCIEXT.htm<br />
O9 - Extra button: Launch Cooliris - {3437D640-C91A-458f-89F5-B9095EA4C28B} - C:\Program Files\PicLensIE\cooliris.dll<br />
O9 - Extra button: FlashCapture - {753BBC4B-CC73-4fb8-A5B5-CA09C804C1DD} - C:\Program Files\Flash Capture\fciext.dll<br />
O9 - Extra button: Extract Flash Video with Bytescout... - {B4321882-BDAD-440D-B124-75233240F897} - C:\Program Files\Bytescout Movies Extractor Scout\flashextract_ie.html (file missing)<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - <a href="http://upload.facebook.com/controls/FacebookPhotoUploader5.cab" target="_blank">http://upload.facebook.com/controls/...oUploader5.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1212559071437" target="_blank">http://www.update.microsoft.com/micr...?1212559071437</a><br />
O16 - DPF: {EAC139A9-D22D-4C29-8D1C-252BE63750F9} - <a href="http://www.cooliris.com/shared/plinstll.cab" target="_blank">http://www.cooliris.com/shared/plinstll.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Google Update Service (gupdate1ca0c05933fc922) (gupdate1ca0c05933fc922) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: lxcq_device -   - C:\WINDOWS\system32\lxcqcoms.exe<br />
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe<br />
O23 - Service: PunkBuster (PnkBstrA) - Unknown owner - C:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\MOHAGame\pb\PnkBstrA.exe<br />
O23 - Service: Syntek STK1160 Service (StkASSrv) - Syntek America Inc. - C:\WINDOWS\System32\StkASv2K.exe<br />
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe<br />
<br />
--<br />
End of file - 10873 bytes</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>Trigger2991</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878922-tdlcmd-dll-infected-can-not.html</guid>
		</item>
		<item>
			<title>Uninstall Dealio toolbar</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878914-uninstall-dealio-toolbar.html</link>
			<pubDate>Fri, 20 Nov 2009 12:12:58 GMT</pubDate>
			<description>How can I get rid of the Dealio Toolbar in a XP systerm. 
When I try to uninstall using the control panel it fails. 
Error message says it is unable to find a file in  Windows\installer folder. 
I tried running a search and XP was unable to find it....</description>
			<content:encoded><![CDATA[<div>How can I get rid of the Dealio Toolbar in a XP systerm.<br />
When I try to uninstall using the control panel it fails.<br />
Error message says it is unable to find a file in  Windows\installer folder.<br />
I tried running a search and XP was unable to find it.<br />
It is not really a problem, just something I would like to be rid of.<br />
I can not find a Program folder of it either.<br />
I am cleaning up my computer for an anticipated upgrade to Windows 7 64 bit.</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>laffnbear</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878914-uninstall-dealio-toolbar.html</guid>
		</item>
		<item>
			<title>could you please check my HJT log!</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878912-could-you-please-check-my.html</link>
			<pubDate>Fri, 20 Nov 2009 11:42:57 GMT</pubDate>
			<description>Hi! could you just help me check if my HJT log is clean from keyloggers trojans etc. thanks in advice!  
  
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 12:38:55, on 2009-11-20 
Platform: Windows XP SP3 (WinNT 5.01.2600) 
MSIE: Internet...</description>
			<content:encoded><![CDATA[<div>Hi! could you just help me check if my HJT log is clean from keyloggers trojans etc. thanks in advice! <br />
 <br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 12:38:55, on 2009-11-20<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16915)<br />
Boot mode: Normal<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program\Bonjour\mDNSResponder.exe<br />
C:\Program\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\system32\PnkBstrA.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program\Java\jre6\bin\jusched.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program\Logitech\Video\LogiTray.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\Program\Logitech\Video\FxSvr2.exe<br />
C:\WINDOWS\system32\RUNDLL32.EXE<br />
C:\Program\NETGEAR\WN311B\Utility\WN311B.exe<br />
C:\Program\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMHID.exe<br />
C:\Program\AirPort\APAgent.exe<br />
C:\Program\Delade filer\Nokia\MPlatform\NokiaMServer.exe<br />
C:\Program\iTunes\iTunesHelper.exe<br />
C:\Program\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMTray.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program\iPod\bin\iPodService.exe<br />
C:\Program\MSN Messenger\msnmsgr.exe<br />
C:\Documents and Settings\pc\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe<br />
C:\Program\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program\Nokia\PC Connectivity Solution\ServiceLayer.exe<br />
C:\Program\Nokia\PC Connectivity Solution\Transports\NclUSBSrv.exe<br />
C:\Program\Nokia\PC Connectivity Solution\Transports\NclRSSrv.exe<br />
C:\Program\Java\jre6\bin\jucheck.exe<br />
C:\Program\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtblfs.exe<br />
C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe<br />
C:\Program\Internet Explorer\iexplore.exe<br />
C:\Program\Lavasoft\Ad-Aware\AAWService.exe<br />
C:\Program\Lavasoft\Ad-Aware\AAWTray.exe<br />
C:\Program\Internet Explorer\iexplore.exe<br />
C:\Program\Trend Micro\HijackThis\HijackThis.exe<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.tennis.se/" target="_blank">http://www.tennis.se/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar<br />
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe<br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program\Kaspersky Lab\Kaspersky Anti-Virus 2010\ievkbd.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll<br />
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program\Logitech\Video\ISStart.exe <br />
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program\Logitech\Video\LogiTray.exe<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE<br />
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br />
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [AS00_WN311B] C:\Program\NETGEAR\WN311B\Utility\WN311B.exe -hide<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [SteelSeries World of Warcraft MMO Gaming Mouse] C:\Program\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMHID.exe<br />
O4 - HKLM\..\Run: [AirPort Base Station Agent] &quot;C:\Program\AirPort\APAgent.exe&quot;<br />
O4 - HKLM\..\Run: [NokiaMServer] C:\Program\Delade filer\Nokia\MPlatform\NokiaMServer /watchfiles<br />
O4 - HKLM\..\Run: [Nokia FastStart] &quot;C:\Program\Nokia\Nokia Music\NokiaMusic.exe&quot; /command:faststart<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [AVP] &quot;C:\Program\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe&quot;<br />
O4 - HKLM\..\Run: [MS_MASTER] RUNDLL32.EXE C:\WINDOWS\system32\xml_inc.dll,i<br />
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe<br />
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] C:\Program\Logitech\Video\ManifestEngine.exe boot<br />
O4 - HKCU\..\Run: [msnmsgr] &quot;C:\Program\MSN Messenger\msnmsgr.exe&quot; /background<br />
O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU &quot;C:\DOCUME~1\pc\LOKALA~1\Temp\E_SF.tmp&quot; /EF &quot;HKCU&quot;<br />
O4 - HKCU\..\Run: [Octoshape Streaming Services] &quot;C:\Documents and Settings\pc\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe&quot; -inv:bootrun<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJÄNST')<br />
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')<br />
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br />
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe<br />
O4 - Global Startup: Microsoft Office.lnk = C:\Program\Microsoft Office\Office10\OSA.EXE<br />
O8 - Extra context menu item: E&amp;xportera till Microsoft Excel - res://C:\Program\MICROS~2\Office10\EXCEL.EXE/3000<br />
O9 - Extra button: &amp;Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll<br />
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe<br />
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe<br />
O9 - Extra button: URLs c&amp;heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe<br />
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - <a href="http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab" target="_blank">http://messenger.zone.msn.com/binary...r.cab31267.cab</a><br />
O16 - DPF: {4E218431-2F07-40BD-A9D3-035324C1F13F} (DyynoX Class) - <a href="http://stage.dyyno.com/tng/dyyno-client/DyynoCAB.CAB" target="_blank">http://stage.dyyno.com/tng/dyyno-client/DyynoCAB.CAB</a><br />
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - <a href="http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab" target="_blank">http://download.bitdefender.com/reso...an8/oscan8.cab</a><br />
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - <a href="https://webdl.symantec.com/activex/symdlmgr.cab" target="_blank">https://webdl.symantec.com/activex/symdlmgr.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1170697391546" target="_blank">http://update.microsoft.com/microsof...?1170697391546</a><br />
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - <a href="http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab" target="_blank">http://messenger.zone.msn.com/binary...t.cab31267.cab</a><br />
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - <a href="http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab" target="_blank">http://acs.pandasoftware.com/actives.../as2stubie.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O20 - AppInit_DLLs: C:\Program\KASPER~1\KASPER~1\mzvkbd3.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Automatisk LiveUpdate-schemaläggare - Unknown owner - C:\Program\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)<br />
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe<br />
O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:\Program\Bonjour\mDNSResponder.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program\Java\jre6\bin\jqs.exe<br />
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program\Lavasoft\Ad-Aware\AAWService.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe<br />
O23 - Service: ServiceLayer - Nokia. - C:\Program\Nokia\PC Connectivity Solution\ServiceLayer.exe<br />
--<br />
End of file - 10621 bytes</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>fantastic12</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878912-could-you-please-check-my.html</guid>
		</item>
		<item>
			<title>Jump problem</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878900-jump-problem.html</link>
			<pubDate>Fri, 20 Nov 2009 09:58:39 GMT</pubDate>
			<description>I again have a Jump hyperlinking problem with google. I have attempted the methods displayed before in previous problems, however it has been a little more difficult as there are a few customised lines of C++ within my system that i have created. 
I...</description>
			<content:encoded><![CDATA[<div>I again have a Jump hyperlinking problem with google. I have attempted the methods displayed before in previous problems, however it has been a little more difficult as there are a few customised lines of C++ within my system that i have created.<br />
I have created a log, shown below.<br />
 <br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 09:47:29, on 20/11/2009<br />
Platform: Windows Vista SP1 (WinNT 6.00.1905)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18813)<br />
Boot mode: Normal<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\taskeng.exe<br />
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe<br />
C:\Windows\System32\hkcmd.exe<br />
C:\Windows\RtHDVCpl.exe<br />
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe<br />
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe<br />
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe<br />
C:\Program Files\TOSHIBA\Registration\ToshibaRegistration.exe<br />
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe<br />
C:\Windows\system32\igfxsrvc.exe<br />
C:\Windows\system32\igfxext.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\AVG\AVG9\avgtray.exe<br />
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Windows\system32\taskmgr.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Windows\system32\rundll32.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\Program Files\Windows Live\Contacts\wlcomm.exe<br />
C:\Windows\msa.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\Program Files\iTunes\iTunes.exe<br />
C:\Program Files\Soulseek\slsk.exe<br />
C:\Program Files\Microsoft Office\Office12\MSPUB.EXE<br />
C:\Program Files\PFConfig\pfconfig.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\AVG\AVG9\avgui.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.searchslate.com/wp.ashx?ref=home&amp;id=145" target="_blank">http://www.searchslate.com/wp.ashx?ref=home&amp;id=145</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = city.library:8080<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (file missing)<br />
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O3 - Toolbar: &amp;Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll<br />
O3 - Toolbar: &amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (file missing)<br />
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe<br />
O4 - HKLM\..\Run: [cfFncEnabler.exe] cfFncEnabler.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Google Desktop Search] &quot;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&quot; /startup<br />
O4 - HKLM\..\Run: [Google EULA Launcher] c:\Program Files\Google\Google EULA\GoogleEULALauncher.exe IE PA<br />
O4 - HKLM\..\Run: [Toshiba TEMPO] C:\Program Files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe<br />
O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup<br />
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br />
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE<br />
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe<br />
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe<br />
O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe<br />
O4 - HKLM\..\Run: [Camera Assistant Software] &quot;C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe&quot; /start<br />
O4 - HKLM\..\Run: [fssui] &quot;C:\Program Files\Windows Live\Family Safety\fsui.exe&quot; -autorun<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [O2Start] C:\Program Files\O2CM-CE\O2 Connection Manager\tscui.exe /s<br />
O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;  -osboot<br />
O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup<br />
O4 - HKLM\..\Run: [VirtualCloneDrive] &quot;C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe&quot; /s<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKLM\..\RunOnce: [iis_reg_mmc_inetmgr_1] regsvr32 /s %windir%\system32\inetsrv\inetmgr.dll<br />
O4 - HKLM\..\RunOnce: [iis_reg_mmc_inetmgr_5] regsvr32 /s %windir%\system32\inetsrv\cnfgprts.ocx<br />
O4 - HKLM\..\RunOnce: [MyWebSearch bar Uninstall] rundll32 C:\PROGRA~1\UNINST~1.DLL,O -3<br />
O4 - HKCU\..\Run: [TOSCDSPD] TOSCDSPD.EXE<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [msnmsgr] &quot;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&quot; /background<br />
O4 - HKCU\..\Run: [Google Update] &quot;C:\Users\Andy\AppData\Local\Google\Update\GoogleUpdate.exe&quot; /c<br />
O4 - HKCU\..\Run: [Speech Recognition] &quot;C:\Windows\Speech\Common\sapisvr.exe&quot; -SpeechUX -Startup<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;<br />
O4 - HKCU\..\Run: [BitTorrent DNA] &quot;C:\Program Files\DNA\btdna.exe&quot;<br />
O4 - HKCU\..\Run: [Steam] &quot;C:\Program Files\Steam\Steam.exe&quot; -silent<br />
O4 - HKCU\..\Run: [NokiaOviSuite2] C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe -tray<br />
O4 - HKCU\..\Run: [SSHNAS] rundll32.exe C:\Windows\system32\sshnas.dll,DllWork<br />
O4 - HKCU\..\Run: [MailBlocker] C:\Users\Andy\AppData\Local\Temp\b.exe<br />
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\Windows\system32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -&quot;Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; GTB5; FunWebProducts; (R1 1.6); SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; OfficeLiveConnector.1.3; OfficeLivePatch.0.0; .NET CLR 3.5.30729; .NET CLR 3.0.30618)&quot; -&quot;<a href="http://www.shockwave.com/gamelanding/sunsetracer2.jsp" target="_blank">http://www.shockwave.com/gamelanding/sunsetracer2.jsp</a>&quot;<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (User 'Default user')<br />
O4 - Startup: Froggy.lnk = C:\Program Files\Froggy\Froggy.exe<br />
O4 - Startup: TRDCReminder.lnk = C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe<br />
O8 - Extra context menu item: Add to Google Photos Screensa&amp;ver - res://C:\Windows\system32\GPhotos.scr/200<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: eBay.co.uk - Buy It Sell It Love It - {76577871-04EC-495E-A12B-91F7C3600AFA} - <a href="http://rover.ebay.com/rover/1/710-44557-9400-3/4" target="_blank">http://rover.ebay.com/rover/1/710-44557-9400-3/4</a> (file missing)<br />
O9 - Extra button: Amazon.co.uk - {8A918C1D-E123-4E36-B562-5C1519E434CE} - <a href="http://www.amazon.co.uk/exec/obidos/redirect-home?tag=Toshibaukbholink-21&amp;site=home" target="_blank">http://www.amazon.co.uk/exec/obidos/...k-21&amp;site=home</a> (file missing)<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O13 - Gopher Prefix: <br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL,avgrsstx.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe<br />
O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br />
O23 - Service: Google Update Service (gupdate1c98b034dffb440) (gupdate1c98b034dffb440) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe<br />
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe<br />
O23 - Service: Notebook Performance Tuning Service  (TempoMonitoringService) - Toshiba Europe GmbH - C:\Program Files\Toshiba TEMPRO\TempoSVC.exe<br />
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe<br />
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe<br />
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe<br />
O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe<br />
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe<br />
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>dayumm</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878900-jump-problem.html</guid>
		</item>
		<item>
			<title>Windows cannot find evg or rkyb.exe</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878891-windows-cannot-find-evg-rkyb.html</link>
			<pubDate>Fri, 20 Nov 2009 08:46:10 GMT</pubDate>
			<description><![CDATA[Sir, 
I have this problem. 
  
Everytime I start my computer I get this message. 
  
"Windows cannot find 'C/Document and settings/Subhash/evg.exe.' make sure you typed the name correctly, then try again. To search for a file, click start button...]]></description>
			<content:encoded><![CDATA[<div>Sir,<br />
I have this problem.<br />
 <br />
Everytime I start my computer I get this message.<br />
 <br />
&quot;Windows cannot find 'C/Document and settings/Subhash/evg.exe.' make sure you typed the name correctly, then try again. To search for a file, click start button then click search.&quot;<br />
I have scanned my computer with Norton internet security and Malwarebyte anti malware with hidden and system files showing option. I have also disabled system restore during the process. After scanning I have restarted my computer and again at startup i got following message,<br />
 <br />
&quot;Windows cannot find ''C/Document and settings/Subhash/rkyb.exe.' make sure you typed the name correctly, then try again. To search for a file, click start button then click search.&quot;<br />
 <br />
I think this must be a malware and so I have scanned my computer with Hijackthis and I am posting herewith the log file of my scan.<br />
 <br />
Hijackthis logfile:<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 1:51:40 PM, on 11/20/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br />
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\explorer.exe<br />
C:\WINDOWS\AGRSMMSG.exe<br />
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe<br />
C:\Program Files\Toshiba\Tvs\TvsTray.exe<br />
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe<br />
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe<br />
C:\WINDOWS\system32\TDispVol.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe<br />
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\WINDOWS\system32\TPSMain.exe<br />
C:\Program Files\Synaptics\SynTP\Toshiba.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Internet Download Manager\IDMan.exe<br />
C:\WINDOWS\system32\RAMASST.exe<br />
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe<br />
C:\WINDOWS\system32\TPSBattM.exe<br />
C:\WINDOWS\system32\DVDRAMSV.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe<br />
C:\Program Files\Norton Ghost\Agent\VProSvc.exe<br />
C:\Program Files\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe<br />
C:\WINDOWS\System32\TUProgSt.exe<br />
C:\Program Files\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe<br />
C:\Program Files\Internet Download Manager\IEMonitor.exe<br />
D:\Subhash\Softwares\Virus removal\hijackthis.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about<b></b>:blank<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe<br />
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL<br />
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\coIEPlg.dll<br />
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\IPSBHO.DLL<br />
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\coIEPlg.dll<br />
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe<br />
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe<br />
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe<br />
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe<br />
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe<br />
O4 - HKLM\..\Run: [TDispVol] TDispVol.exe<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [IntelZeroConfig] &quot;C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe&quot;<br />
O4 - HKLM\..\Run: [IntelWireless] &quot;C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe&quot; /tf Intel PROSet/Wireless<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect<br />
O4 - HKLM\..\Run: [NVRotateSysTray] rundll32.exe C:\WINDOWS\system32\nvsysrot.dll,Enable<br />
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe<br />
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe&quot; /starttray<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot<br />
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe<br />
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm<br />
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm<br />
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1258626923296" target="_blank">http://update.microsoft.com/windowsu...?1258626923296</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1258627689078" target="_blank">http://www.update.microsoft.com/micr...?1258627689078</a><br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL<br />
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\coIEPlg.dll<br />
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe<br />
O23 - Service: DVD-RAM_Service - Matsu****a Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe<br />
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br />
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe<br />
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe<br />
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br />
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br />
O23 - Service: SymSnapService - Symantec - C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe<br />
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe<br />
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe<br />
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe<br />
--<br />
End of file - 9189 bytes<br />
 <br />
I have also scan for startuplist with hijackthis and posting herewith its log if it can help u to analyze.<br />
 <br />
Hijackthis startup list:<br />
StartupList report, 11/20/2009, 1:55:01 PM<br />
StartupList version: 1.52.2<br />
Started from : D:\Subhash\Softwares\Virus removal\hijackthis.EXE<br />
Detected: Windows XP SP3 (WinNT 5.01.2600)<br />
Detected: Internet Explorer v8.00 (8.00.6001.18702)<br />
* Using default options<br />
==================================================<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br />
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\explorer.exe<br />
C:\WINDOWS\AGRSMMSG.exe<br />
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe<br />
C:\Program Files\Toshiba\Tvs\TvsTray.exe<br />
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe<br />
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe<br />
C:\WINDOWS\system32\TDispVol.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe<br />
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\WINDOWS\system32\TPSMain.exe<br />
C:\Program Files\Synaptics\SynTP\Toshiba.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Internet Download Manager\IDMan.exe<br />
C:\WINDOWS\system32\RAMASST.exe<br />
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe<br />
C:\WINDOWS\system32\TPSBattM.exe<br />
C:\WINDOWS\system32\DVDRAMSV.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe<br />
C:\Program Files\Norton Ghost\Agent\VProSvc.exe<br />
C:\Program Files\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe<br />
C:\WINDOWS\System32\TUProgSt.exe<br />
C:\Program Files\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe<br />
C:\Program Files\Internet Download Manager\IEMonitor.exe<br />
D:\Subhash\Softwares\Virus removal\hijackthis.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\WINDOWS\system32\NOTEPAD.EXE<br />
--------------------------------------------------<br />
Listing of startup folders:<br />
Shell folders Common Startup:<br />
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]<br />
RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe<br />
--------------------------------------------------<br />
Checking Windows NT UserInit:<br />
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]<br />
UserInit = C:\WINDOWS\system32\userinit.exe<br />
--------------------------------------------------<br />
Autorun entries from Registry:<br />
HKLM\Software\Microsoft\Windows\CurrentVersion\Run<br />
AGRSMMSG = AGRSMMSG.exe<br />
NDSTray.exe = NDSTray.exe<br />
Tvs = C:\Program Files\Toshiba\Tvs\TvsTray.exe<br />
THotkey = C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe<br />
TFncKy = TFncKy.exe<br />
TDispVol = TDispVol.exe<br />
SynTPEnh = C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
IntelZeroConfig = &quot;C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe&quot;<br />
IntelWireless = &quot;C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe&quot; /tf Intel PROSet/Wireless<br />
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
nwiz = nwiz.exe /installquiet /keeploaded /nodetect<br />
NVRotateSysTray = rundll32.exe C:\WINDOWS\system32\nvsysrot.dll,Enable<br />
TPSMain = TPSMain.exe<br />
Malwarebytes' Anti-Malware = &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe&quot; /starttray<br />
RTHDCPL = RTHDCPL.EXE<br />
--------------------------------------------------<br />
Autorun entries from Registry:<br />
HKCU\Software\Microsoft\Windows\CurrentVersion\Run<br />
TOSCDSPD = C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe<br />
ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe<br />
IDMan = C:\Program Files\Internet Download Manager\IDMan.exe /onboot<br />
--------------------------------------------------<br />
Autorun entries in Registry subkeys of:<br />
HKLM\Software\Microsoft\Windows\CurrentVersion\Run<br />
[OptionalComponents]<br />
= <br />
--------------------------------------------------<br />
Shell &amp; screensaver key from C:\WINDOWS\SYSTEM.INI:<br />
Shell=*INI section not found*<br />
SCRNSAVE.EXE=*INI section not found*<br />
drivers=*INI section not found*<br />
Shell &amp; screensaver key from Registry:<br />
Shell=Explorer.exe<br />
SCRNSAVE.EXE=*Registry value not found*<br />
drivers=*Registry value not found*<br />
Policies Shell key:<br />
HKCU\..\Policies: Shell=*Registry key not found*<br />
HKLM\..\Policies: Shell=*Registry value not found*<br />
--------------------------------------------------<br />
 <br />
Enumerating Browser Helper Objects:<br />
IDM Helper - C:\Program Files\Internet Download Manager\IDMIECC.dll - {0055C089-8582-441B-A0BF-17B458C2A3A8}<br />
AcroIEHelperStub - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll - {18DF081C-E8AD-4283-A596-FA578C2EBDC3}<br />
(no name) - C:\WINDOWS\System32\DLA\DLASHX_W.DLL - {5CA3D70E-1895-11CF-8E15-001234567890}<br />
Symantec NCO BHO - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\coIEPlg.dll - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}<br />
Symantec Intrusion Prevention - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\IPSBHO.DLL - {6D53EC84-6AAE-4787-AEEE-F4628F01010C}<br />
(no name) - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL - {72853161-30C5-4D22-B7F9-0BBC1D38A37E}<br />
(no name) - C:\Program Files\Java\jre6\bin\jp2ssv.dll - {DBC80044-A445-435b-BC74-9C25C1C588A9}<br />
JQSIEStartDetectorImpl - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll - {E7E6F031-17CE-4C07-BC86-EABFE594F69C}<br />
--------------------------------------------------<br />
Enumerating Task Scheduler jobs:<br />
1-Click Maintenance.job<br />
User_Feed_Synchronization-{99003FB3-A6DF-4B0F-B6F6-C7C6883E459E}.job<br />
--------------------------------------------------<br />
Enumerating Download Program Files:<br />
[WUWebControl Class]<br />
InProcServer32 = C:\WINDOWS\system32\wuweb.dll<br />
CODEBASE = <a href="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1258626923296" target="_blank">http://update.microsoft.com/windowsu...?1258626923296</a><br />
[MUWebControl Class]<br />
InProcServer32 = C:\WINDOWS\system32\muweb.dll<br />
CODEBASE = <a href="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1258627689078" target="_blank">http://www.update.microsoft.com/micr...?1258627689078</a><br />
--------------------------------------------------<br />
Enumerating ShellServiceObjectDelayLoad items:<br />
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll<br />
CDBurn: C:\WINDOWS\system32\SHELL32.dll<br />
WebCheck: C:\WINDOWS\system32\webcheck.dll<br />
SysTray: C:\WINDOWS\system32\stobject.dll<br />
WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll<br />
--------------------------------------------------<br />
End of report, 7,520 bytes<br />
Report generated in 0.047 seconds<br />
Command line options:<br />
/verbose - to add additional info on each section<br />
/complete - to include empty sections and unsuspicious data<br />
/full - to include several rarely-important sections<br />
/force9x - to include Win9x-only startups even if running on WinNT<br />
/forcent - to include WinNT-only startups even if running on Win9x<br />
/forceall - to include all Win9x and WinNT startups, regardless of platform<br />
/history - to list version history only<br />
 <br />
I am editing this because I have somthing new information which i want to share is that every time I scan my Laptop with Malwarebyte it detects 2 infected files out of which one is to be deleted on reboot. After reboot I got the same message with different exe name like ifs.exe, cvs.exe etc etc its random i think. This repeates everytime i scan my laptop with malwarebyte. For your convienience I am attaching herwith last log of Malwarebyte scan.<br />
 <br />
Malwarebyte full scan log:<br />
 <br />
Malwarebytes' Anti-Malware 1.41<br />
Database version: 2775<br />
Windows 5.1.2600 Service Pack 3<br />
11/20/2009 4:48:03 PM<br />
mbam-log-2009-11-20 (16-48-03).txt<br />
Scan type: Full Scan (C:\|D:\|E:\|F:\|G:\|H:\|)<br />
Objects scanned: 176481<br />
Time elapsed: 52 minute(s), 58 second(s)<br />
Memory Processes Infected: 0<br />
Memory Modules Infected: 0<br />
Registry Keys Infected: 0<br />
Registry Values Infected: 1<br />
Registry Data Items Infected: 0<br />
Folders Infected: 0<br />
Files Infected: 1<br />
Memory Processes Infected:<br />
(No malicious items detected)<br />
Memory Modules Infected:<br />
(No malicious items detected)<br />
Registry Keys Infected:<br />
(No malicious items detected)<br />
Registry Values Infected:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Trojan.Agent) -&gt; Quarantined and deleted successfully.<br />
Registry Data Items Infected:<br />
(No malicious items detected)<br />
Folders Infected:<br />
(No malicious items detected)<br />
Files Infected:<br />
C:\WINDOWS\system32\secupdat.dat (Backdoor.Bot) -&gt; Delete on reboot.<br />
 <br />
I am thanking in anticipation for your invaluable help. and eagerly waiting for your response.</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>drsubhash81</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878891-windows-cannot-find-evg-rkyb.html</guid>
		</item>
		<item>
			<title>Virus infection</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878884-virus-infection.html</link>
			<pubDate>Fri, 20 Nov 2009 07:43:01 GMT</pubDate>
			<description>Please help me clean my laptop from suspicious infection. 
I scanned my laptop many times and found nothing with my AVG scanner but I am suffereing strange behaviour from time to time. 
every time I use any office Excel or Word document I found many...</description>
			<content:encoded><![CDATA[<div>Please help me clean my laptop from suspicious infection.<br />
I scanned my laptop many times and found nothing with my AVG scanner but I am suffereing strange behaviour from time to time.<br />
every time I use any office Excel or Word document I found many TMP files with strange name starts to appear inside the same folder I am saving my Excel work in.<br />
Also my laptop is slow in openeing it takes time to show the network monitors down in the icon bar even if I am not connected to the net.<br />
<br />
Please help me clean my Laptop - <b>IS MY HIJACKIT LOG CLEAN ?</b><br />
<br />
Thanks n advance.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 11:42:46 AM, on 11/20/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16915)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
c:\drivers\audio\r205445\stacsv.exe<br />
C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe<br />
C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\DellTPad\Apoint.exe<br />
C:\Program Files\IDT\WDM\sttray.exe<br />
C:\WINDOWS\system32\AESTFltr.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\Program Files\DellTPad\ApMsgFwd.exe<br />
C:\WINDOWS\system32\igfxsrvc.exe<br />
C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe<br />
C:\Program Files\Wave Systems Corp\SecureUpgrade.exe<br />
C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe<br />
C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe<br />
C:\Program Files\DellTPad\HidFind.exe<br />
C:\Program Files\DellTPad\Apntex.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
C:\WINDOWS\PixArt\PAC7302\Monitor.exe<br />
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Desktop Sidebar\dsidebar.exe<br />
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Intel\ASF Agent\ASFAgent.exe<br />
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\WINDOWS\system32\crypserv.exe<br />
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe<br />
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe<br />
C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe<br />
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe<br />
C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe<br />
C:\WINDOWS\system32\CCM\CcmExec.exe<br />
C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe<br />
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Microsoft Office\Office12\EXCEL.EXE<br />
C:\Program Files\AVG\AVG8\avgcsrvx.exe<br />
C:\Landmark\DWS\COMPASS\bin\cfw32.exe<br />
C:\WINDOWS\system32\rtdsk50.exe<br />
C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br />
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE<br />
C:\Program Files\Etisalat USB Modem E220\Etisalat USB Modem E220.exe<br />
C:\Program Files\VideoLAN\VLC\vlc.exe<br />
C:\Program Files\Orbitdownloader\orbitdm.exe<br />
C:\Program Files\Orbitdownloader\orbitnet.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE<br />
C:\Program Files\AVG\AVG8\avgcsrvx.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://www.yahoo.com/search/ie.html" target="_blank">http://www.yahoo.com/search/ie.html</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://search.orbitdownloader.com" target="_blank">http://search.orbitdownloader.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local<br />
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)<br />
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br />
F2 - REG:system.ini: UserInit=userinit.exe,<br />
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br />
O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - C:\Program Files\Desktop Sidebar\sbhelp.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll<br />
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe<br />
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe<br />
O4 - HKLM\..\Run: [AESTFltr] %SystemRoot%\system32\AESTFltr.exe /NoDlg<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [ChangeTPMAuth] C:\Program Files\Wave Systems Corp\Common\ChangeTPMAuth.exe /T:NTRU12<br />
O4 - HKLM\..\Run: [WavXMgr] C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe<br />
O4 - HKLM\..\Run: [SecureUpgrade] &quot;C:\Program Files\Wave Systems Corp\SecureUpgrade.exe&quot;<br />
O4 - HKLM\..\Run: [EmbassySecurityCheck] &quot;C:\Program Files\Wave Systems Corp\EMBASSY Security Setup\EMBASSYSecurityCheck.exe&quot;<br />
O4 - HKLM\..\Run: [DellControlPoint] &quot;C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe&quot;<br />
O4 - HKLM\..\Run: [USCService] C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [RoxWatchTray] &quot;C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe&quot;<br />
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe<br />
O4 - HKCU\..\Run: [ISUSPM] &quot;C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe&quot; -scheduler<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
O4 - HKCU\..\Run: [DvbRec] C:\Program Files\DVB\DVBPlayer\IPReceiver.exe AutoLoad<br />
O4 - HKCU\..\Run: [SIDEBAR] &quot;C:\Program Files\Desktop Sidebar\dsidebar.exe&quot;<br />
O4 - Global Startup: Bluetooth.lnk = ?<br />
O4 - Global Startup: Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe<br />
O8 - Extra context menu item: &amp;Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201<br />
O8 - Extra context menu item: &amp;Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204<br />
O8 - Extra context menu item: Do&amp;wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203<br />
O8 - Extra context menu item: Down&amp;load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Send to &amp;Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm<br />
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br />
O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll<br />
O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll<br />
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe<br />
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O12 - Plugin for .OPT: C:\Program Files\Stellent\IBPM\IBPMVwr.dll<br />
O16 - DPF: Arab Bank Online Banking Service - <a href="https://www.arabi-online.com/abr/english/1.1.20.8/mainpages/ibs.cab" target="_blank">https://www.arabi-online.com/abr/eng...npages/ibs.cab</a><br />
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - <a href="http://go.microsoft.com/fwlink/?linkid=58813" target="_blank">http://go.microsoft.com/fwlink/?linkid=58813</a><br />
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - <a href="http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab" target="_blank">http://download.bitdefender.com/reso...an8/oscan8.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1241519897426" target="_blank">http://update.microsoft.com/microsof...?1241519897426</a><br />
O16 - DPF: {D6E0B119-DCF2-4CD6-8DFB-7CFF1B70F7FF} (TeamOn Import Object) - <a href="https://bis.eu.blackberry.com/html/web/client_tools/TOImport.cab" target="_blank">https://bis.eu.blackberry.com/html/w...s/TOImport.cab</a><br />
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - <a href="https://www.myweatherford.ca/dana-cached/setup/JuniperSetupSP1.cab" target="_blank">https://www.myweatherford.ca/dana-ca...erSetupSP1.cab</a><br />
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - <a href="http://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab" target="_blank">http://gfx2.hotmail.com/mail/w4/pr01...l/MSNPUpld.cab</a><br />
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - <a href="https://secure.logmein.com/activex/RACtrl.cab" target="_blank">https://secure.logmein.com/activex/RACtrl.cab</a><br />
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = wft.root.loc<br />
O17 - HKLM\Software\..\Telephony: DomainName = wft.root.loc<br />
O17 - HKLM\System\CCS\Services\Tcpip\..\{1DD33840-13D2-4472-A4CD-9DBB95C021AE}: NameServer = 213.131.65.20,213.131.66.246<br />
O17 - HKLM\System\CCS\Services\Tcpip\..\{4C8B3052-1BC6-4F6D-8D5A-69A9157852DE}: NameServer = 195.229.241.222 213.42.20.20<br />
O17 - HKLM\System\CS1\Services\Tcpip\..\{1DD33840-13D2-4472-A4CD-9DBB95C021AE}: NameServer = 213.131.65.20,213.131.66.246<br />
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = wft.root.loc<br />
O17 - HKLM\System\CS2\Services\Tcpip\..\{1DD33840-13D2-4472-A4CD-9DBB95C021AE}: NameServer = 213.131.65.20,213.131.66.246<br />
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = wft.root.loc<br />
O17 - HKLM\System\CS3\Services\Tcpip\..\{1DD33840-13D2-4472-A4CD-9DBB95C021AE}: NameServer = 213.131.65.20,213.131.66.246<br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe<br />
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe<br />
O23 - Service: Dell ControlPoint Button Service (buttonsvc32) - Dell Inc. - C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe<br />
O23 - Service: Credential Vault Host Control Service - Broadcom Corporation - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe<br />
O23 - Service: Credential Vault Host Storage - Broadcom Corporation - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe<br />
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe<br />
O23 - Service: Dell ControlPoint System Manager (dcpsysmgrsvc) - Dell Inc. - C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe<br />
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE<br />
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE<br />
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe<br />
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe<br />
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe<br />
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe<br />
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe<br />
O23 - Service: SecureStorageService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe<br />
O23 - Service: Audio Service (STacSV) - IDT, Inc. - c:\drivers\audio\r205445\stacsv.exe<br />
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe<br />
O23 - Service: NTRU TSS v1.2.1.28 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe<br />
O23 - Service: TdmService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe<br />
<br />
--<br />
End of file - 16880 bytes</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator><![CDATA[Tito's]]></dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878884-virus-infection.html</guid>
		</item>
		<item>
			<title>Freeing up computer space/making computer faster</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878875-freeing-up-computer-space-making.html</link>
			<pubDate>Fri, 20 Nov 2009 06:23:39 GMT</pubDate>
			<description>hey..im new to this and need help with my computer. i want to free up space but dont know how, i tried disk clean-up, ccleaner and still not that many space was freeup up also i want my computer to be alot faster because lately its bein very slow.</description>
			<content:encoded><![CDATA[<div>hey..im new to this and need help with my computer. i want to free up space but dont know how, i tried disk clean-up, ccleaner and still not that many space was freeup up also i want my computer to be alot faster because lately its bein very slow.</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>eman3602</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878875-freeing-up-computer-space-making.html</guid>
		</item>
		<item>
			<title>Virus infection</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878853-virus-infection.html</link>
			<pubDate>Fri, 20 Nov 2009 04:11:11 GMT</pubDate>
			<description><![CDATA[When trying to load programs in mystart menu a screen pops up on my screen and says "Open With" on the top bar and had a list of "recommended programs"  My windows DLLs seems to have become corrupt by a virus.]]></description>
			<content:encoded><![CDATA[<div>When trying to load programs in mystart menu a screen pops up on my screen and says &quot;Open With&quot; on the top bar and had a list of &quot;recommended programs&quot;  My windows DLLs seems to have become corrupt by a virus.</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>shoke</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878853-virus-infection.html</guid>
		</item>
		<item>
			<title>iexplore.exe error</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878848-iexplore-exe-error.html</link>
			<pubDate>Fri, 20 Nov 2009 03:10:18 GMT</pubDate>
			<description>I am new to this forum and I am looking for help.  I have two problems. 
 
1. I keep receiving this randomly and it started after the 2nd: 
 
 iexplore.exe - Application Error 
The application failed to initialize properly (0xc0000142).  Click OK to...</description>
			<content:encoded><![CDATA[<div>I am new to this forum and I am looking for help.  I have two problems.<br />
<br />
1. I keep receiving this randomly and it started after the 2nd:<br />
<br />
 iexplore.exe - Application Error<br />
The application failed to initialize properly (0xc0000142).  Click OK to terminate the application.<br />
<br />
2. Random keys on my keyboard are not working whatsoever. Even when I try F2 or F8 while booting. This is all being typed w/ a virtual keyboard. Think it may be virus because it seems just one or twok keys were broken and bam 50% just don't work, tried reinstalling drivers.<br />
<br />
Please help,<br />
peace &amp; LOVE,<br />
Stevo<br />
<br />
Grateful Dead Family<br />
<br />
Here's Hijack log<br />
___________________________<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 2:29:17 PM, on 11/17/2009<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v7.00 (7.00.6002.18005)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Windows\RtHDVCpl.exe<br />
C:\Program Files\Alwil Software\Avast4\ashDisp.exe<br />
C:\Windows\System32\hkcmd.exe<br />
C:\Windows\System32\igfxpers.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\Winamp\winampa.exe<br />
C:\Windows\system32\igfxsrvc.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Users\Stevo\AppData\Local\Temp\RtkBtMnt.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Program Files\GPSoftware\Directory Opus\dopusrt.exe<br />
C:\Program Files\Palm\Hotsync.exe<br />
C:\Program Files\GPSoftware\Directory Opus\dopus.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://homepage.acer.com/rdr.aspx?b=ACAW&amp;l=0409&amp;s=2&amp;o=vp32&amp;d=1108&amp;m=aspire_5735" target="_blank">http://homepage.acer.com/rdr.aspx?b=...&amp;m=aspire_5735</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://homepage.acer.com/rdr.aspx?b=ACAW&amp;l=0409&amp;s=2&amp;o=vp32&amp;d=1108&amp;m=aspire_5735" target="_blank">http://homepage.acer.com/rdr.aspx?b=...&amp;m=aspire_5735</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://homepage.acer.com/rdr.aspx?b=ACAW&amp;l=0409&amp;s=2&amp;o=vp32&amp;d=1108&amp;m=aspire_5735" target="_blank">http://homepage.acer.com/rdr.aspx?b=...&amp;m=aspire_5735</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - (no file)<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)<br />
O4 - HKLM\..\Run: [SynTPEnh] &quot;C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&quot;<br />
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br />
O4 - HKLM\..\Run: [Skytel] Skytel.exe<br />
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [Windows Defender] &quot;C:\Program Files\Windows Defender\MSASCui.exe&quot; -hide<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\Run: [WinampAgent] &quot;C:\Program Files\Winamp\winampa.exe&quot;<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [VirtualCloneDrive] &quot;C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe&quot; /s<br />
O4 - HKCU\..\Run: [BitTorrent] &quot;C:\Program Files\BitTorrent\bittorrent.exe&quot;<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [PeerBlock] C:\Program Files\PeerBlock\peerblock.exe<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKCU\..\Run: [Directory Opus Desktop Dblclk] &quot;C:\Program Files\GPSoftware\Directory Opus\dopusrt.exe&quot; /dblclk<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - Startup: Directory Opus.lnk = C:\Program Files\GPSoftware\Directory Opus\dopus.exe<br />
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE<br />
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br />
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\Palm\Hotsync.exe<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe<br />
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe<br />
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe<br />
<br />
--<br />
End of file - 7133 bytes</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>stevoGDF</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878848-iexplore-exe-error.html</guid>
		</item>
		<item>
			<title>word document virus- W97M.THUS.FAMILY</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878835-word-document-virus-w97m-thus.html</link>
			<pubDate>Fri, 20 Nov 2009 02:32:09 GMT</pubDate>
			<description>This virus has gotten into our imac word program.  It is cleared when we send the cord document to another computer with a virus protection program but how do we remove it from the mac.  Alos what about all the stored word documents on the mac. 
...</description>
			<content:encoded><![CDATA[<div>This virus has gotten into our imac word program.  It is cleared when we send the cord document to another computer with a virus protection program but how do we remove it from the mac.  Alos what about all the stored word documents on the mac.<br />
<br />
On a related note what virus software is recommended by you in the know?<br />
<br />
thanks</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>enigma09</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878835-word-document-virus-w97m-thus.html</guid>
		</item>
		<item>
			<title>Cannot access google please help</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878812-cannot-access-google-please-help.html</link>
			<pubDate>Fri, 20 Nov 2009 00:03:14 GMT</pubDate>
			<description><![CDATA[Hello there all, this is my very FIRST post and i'm not sure if its in the right section or not. if its not please put it where it belongs. well like the title says, i absolutely CANNOT access google or gmail or bing.com, i also cant seem to sign...]]></description>
			<content:encoded><![CDATA[<div>Hello there all, this is my very FIRST post and i'm not sure if its in the right section or not. if its not please put it where it belongs. well like the title says, i absolutely CANNOT access google or gmail or bing.com, i also cant seem to sign into youtube but CAN watch any and all videos. i CAN get to google thru the ip address but cannot go anywhere else in google without it saying server timed out or link is broken. this just started doing this like a few weeks ago. i know this has been asked before and i think i found the solution here at this link <br />
<a href="http://forums.techguy.org/networking/814754-solved-cant-access-google.html" target="_blank">http://forums.techguy.org/networking...ss-google.html</a><br />
<br />
now my problem is when i do what JohnWill said to do which is <b>S</b>tart, <b>R</b>un, <b>NOTEPAD c:\Windows\system32\drivers\etc\HOSTS </b><font size="2">i get a WHOLE list of things which i will post below. </font>and im not sure what to do with this list. therein lies my problem. its been answered but i dont know how or what to do. also im sorry for the long post, i just finally found some REAL help. also if this helps i dont know why but when it was working it kept coming up as google canada for some reason. THANK YOU VERY MUCH FOR YOUR TIME AND CONSIDERATION<br />
<br />
74.125.45.100 4-open-davinci.com<br />
74.125.45.100 securitysoftwarepayments.com<br />
74.125.45.100 privatesecuredpayments.com<br />
74.125.45.100 secure.privatesecuredpayments.com<br />
74.125.45.100 getantivirusplusnow.com<br />
74.125.45.100 secure-plus-payments.com<br />
74.125.45.100 <a href="http://www.getantivirusplusnow.com" target="_blank">www.getantivirusplusnow.com</a><br />
74.125.45.100 <a href="http://www.secure-plus-payments.com" target="_blank">www.secure-plus-payments.com</a><br />
74.125.45.100 <a href="http://www.getavplusnow.com" target="_blank">www.getavplusnow.com</a><br />
74.125.45.100 <a href="http://www.securesoftwarebill.com" target="_blank">www.securesoftwarebill.com</a><br />
74.125.45.100 secure.paysecuresystem.com<br />
64.86.17.56 google.ae<br />
64.86.17.56 google.as<br />
64.86.17.56 google.at<br />
64.86.17.56 google.az<br />
64.86.17.56 google.ba<br />
64.86.17.56 google.be<br />
64.86.17.56 google.bg<br />
64.86.17.56 google.bs<br />
64.86.17.56 google.ca<br />
64.86.17.56 google.cd<br />
64.86.17.56 google.com.gh<br />
64.86.17.56 google.com.hk<br />
64.86.17.56 google.com.jm<br />
64.86.17.56 google.com.mx<br />
64.86.17.56 google.com.my<br />
64.86.17.56 google.com.na<br />
64.86.17.56 google.com.nf<br />
64.86.17.56 google.com.ng<br />
64.86.17.56 google.ch<br />
64.86.17.56 google.com.np<br />
64.86.17.56 google.com.<acronym title="Page Ranking">pr</acronym><br />
64.86.17.56 google.com.qa<br />
64.86.17.56 google.com.sg<br />
64.86.17.56 google.com.tj<br />
64.86.17.56 google.com.tw<br />
64.86.17.56 google.dj<br />
64.86.17.56 google.de<br />
64.86.17.56 google.dk<br />
64.86.17.56 google.dm<br />
64.86.17.56 google.ee<br />
64.86.17.56 google.fi<br />
64.86.17.56 google.fm<br />
64.86.17.56 google.fr<br />
64.86.17.56 google.ge<br />
64.86.17.56 google.gg<br />
64.86.17.56 google.gm<br />
64.86.17.56 google.gr<br />
64.86.17.56 google.ht<br />
64.86.17.56 google.ie<br />
64.86.17.56 google.im<br />
64.86.17.56 google.in<br />
64.86.17.56 google.it<br />
64.86.17.56 google.ki<br />
64.86.17.56 google.la<br />
64.86.17.56 google.li<br />
64.86.17.56 google.lv<br />
64.86.17.56 google.ma<br />
64.86.17.56 google.ms<br />
64.86.17.56 google.mu<br />
64.86.17.56 google.mw<br />
64.86.17.56 google.nl<br />
64.86.17.56 google.no<br />
64.86.17.56 google.nr<br />
64.86.17.56 google.nu<br />
64.86.17.56 google.pl<br />
64.86.17.56 google.pn<br />
64.86.17.56 google.pt<br />
64.86.17.56 google.ro<br />
64.86.17.56 google.ru<br />
64.86.17.56 google.rw<br />
64.86.17.56 google.sc<br />
64.86.17.56 google.se<br />
64.86.17.56 google.sh<br />
64.86.17.56 google.si<br />
64.86.17.56 google.sm<br />
64.86.17.56 google.sn<br />
64.86.17.56 google.st<br />
64.86.17.56 google.tl<br />
64.86.17.56 google.tm<br />
64.86.17.56 google.tt<br />
64.86.17.56 google.us<br />
64.86.17.56 google.vu<br />
64.86.17.56 google.ws<br />
64.86.17.56 google.co.ck<br />
64.86.17.56 google.co.id<br />
64.86.17.56 google.co.il<br />
64.86.17.56 google.co.in<br />
64.86.17.56 google.co.jp<br />
64.86.17.56 google.co.kr<br />
64.86.17.56 google.co.ls<br />
64.86.17.56 google.co.ma<br />
64.86.17.56 google.co.nz<br />
64.86.17.56 google.co.tz<br />
64.86.17.56 google.co.ug<br />
64.86.17.56 google.co.uk<br />
64.86.17.56 google.co.za<br />
64.86.17.56 google.co.zm<br />
64.86.17.56 google.com<br />
64.86.17.56 google.com.af<br />
64.86.17.56 google.com.ag<br />
64.86.17.56 google.com.ar<br />
64.86.17.56 google.com.au<br />
64.86.17.56 google.com.bn<br />
64.86.17.56 google.com.br<br />
64.86.17.56 google.com.by<br />
64.86.17.56 google.com.bz<br />
64.86.17.56 google.com.cu<br />
64.86.17.56 google.com.ec<br />
64.86.17.56 google.com.fj<br />
64.86.17.56 <a href="http://www.google.ae" target="_blank">www.google.ae</a><br />
64.86.17.56 <a href="http://www.google.as" target="_blank">www.google.as</a><br />
64.86.17.56 <a href="http://www.google.at" target="_blank">www.google.at</a><br />
64.86.17.56 <a href="http://www.google.az" target="_blank">www.google.az</a><br />
64.86.17.56 <a href="http://www.google.ba" target="_blank">www.google.ba</a><br />
64.86.17.56 <a href="http://www.google.be" target="_blank">www.google.be</a><br />
64.86.17.56 <a href="http://www.google.bg" target="_blank">www.google.bg</a><br />
64.86.17.56 <a href="http://www.google.bs" target="_blank">www.google.bs</a><br />
64.86.17.56 <a href="http://www.google.ca" target="_blank">www.google.ca</a><br />
64.86.17.56 <a href="http://www.google.cd" target="_blank">www.google.cd</a><br />
64.86.17.56 <a href="http://www.google.com.gh" target="_blank">www.google.com.gh</a><br />
64.86.17.56 <a href="http://www.google.com.hk" target="_blank">www.google.com.hk</a><br />
64.86.17.56 <a href="http://www.google.com.jm" target="_blank">www.google.com.jm</a><br />
64.86.17.56 <a href="http://www.google.com.mx" target="_blank">www.google.com.mx</a><br />
64.86.17.56 <a href="http://www.google.com.my" target="_blank">www.google.com.my</a><br />
64.86.17.56 <a href="http://www.google.com.na" target="_blank">www.google.com.na</a><br />
64.86.17.56 <a href="http://www.google.com.nf" target="_blank">www.google.com.nf</a><br />
64.86.17.56 <a href="http://www.google.com.ng" target="_blank">www.google.com.ng</a><br />
64.86.17.56 <a href="http://www.google.ch" target="_blank">www.google.ch</a><br />
64.86.17.56 <a href="http://www.google.com.np" target="_blank">www.google.com.np</a><br />
64.86.17.56 <a href="http://www.google.com.pr" target="_blank">www.google.com.pr</a><br />
64.86.17.56 <a href="http://www.google.com.qa" target="_blank">www.google.com.qa</a><br />
64.86.17.56 <a href="http://www.google.com.sg" target="_blank">www.google.com.sg</a><br />
64.86.17.56 <a href="http://www.google.com.tj" target="_blank">www.google.com.tj</a><br />
64.86.17.56 <a href="http://www.google.com.tw" target="_blank">www.google.com.tw</a><br />
64.86.17.56 <a href="http://www.google.dj" target="_blank">www.google.dj</a><br />
64.86.17.56 <a href="http://www.google.de" target="_blank">www.google.de</a><br />
64.86.17.56 <a href="http://www.google.dk" target="_blank">www.google.dk</a><br />
64.86.17.56 <a href="http://www.google.dm" target="_blank">www.google.dm</a><br />
64.86.17.56 <a href="http://www.google.ee" target="_blank">www.google.ee</a><br />
64.86.17.56 <a href="http://www.google.fi" target="_blank">www.google.fi</a><br />
64.86.17.56 <a href="http://www.google.fm" target="_blank">www.google.fm</a><br />
64.86.17.56 <a href="http://www.google.fr" target="_blank">www.google.fr</a><br />
64.86.17.56 <a href="http://www.google.ge" target="_blank">www.google.ge</a><br />
64.86.17.56 <a href="http://www.google.gg" target="_blank">www.google.gg</a><br />
64.86.17.56 <a href="http://www.google.gm" target="_blank">www.google.gm</a><br />
64.86.17.56 <a href="http://www.google.gr" target="_blank">www.google.gr</a><br />
64.86.17.56 <a href="http://www.google.ht" target="_blank">www.google.ht</a><br />
64.86.17.56 <a href="http://www.google.ie" target="_blank">www.google.ie</a><br />
64.86.17.56 <a href="http://www.google.im" target="_blank">www.google.im</a><br />
64.86.17.56 <a href="http://www.google.in" target="_blank">www.google.in</a><br />
64.86.17.56 <a href="http://www.google.it" target="_blank">www.google.it</a><br />
64.86.17.56 <a href="http://www.google.ki" target="_blank">www.google.ki</a><br />
64.86.17.56 <a href="http://www.google.la" target="_blank">www.google.la</a><br />
64.86.17.56 <a href="http://www.google.li" target="_blank">www.google.li</a><br />
64.86.17.56 <a href="http://www.google.lv" target="_blank">www.google.lv</a><br />
64.86.17.56 <a href="http://www.google.ma" target="_blank">www.google.ma</a><br />
64.86.17.56 <a href="http://www.google.ms" target="_blank">www.google.ms</a><br />
64.86.17.56 <a href="http://www.google.mu" target="_blank">www.google.mu</a><br />
64.86.17.56 <a href="http://www.google.mw" target="_blank">www.google.mw</a><br />
64.86.17.56 <a href="http://www.google.nl" target="_blank">www.google.nl</a><br />
64.86.17.56 <a href="http://www.google.no" target="_blank">www.google.no</a><br />
64.86.17.56 <a href="http://www.google.nr" target="_blank">www.google.nr</a><br />
64.86.17.56 <a href="http://www.google.nu" target="_blank">www.google.nu</a><br />
64.86.17.56 <a href="http://www.google.pl" target="_blank">www.google.pl</a><br />
64.86.17.56 <a href="http://www.google.pn" target="_blank">www.google.pn</a><br />
64.86.17.56 <a href="http://www.google.pt" target="_blank">www.google.pt</a><br />
64.86.17.56 <a href="http://www.google.ro" target="_blank">www.google.ro</a><br />
64.86.17.56 <a href="http://www.google.ru" target="_blank">www.google.ru</a><br />
64.86.17.56 <a href="http://www.google.rw" target="_blank">www.google.rw</a><br />
64.86.17.56 <a href="http://www.google.sc" target="_blank">www.google.sc</a><br />
64.86.17.56 <a href="http://www.google.se" target="_blank">www.google.se</a><br />
64.86.17.56 <a href="http://www.google.sh" target="_blank">www.google.sh</a><br />
64.86.17.56 <a href="http://www.google.si" target="_blank">www.google.si</a><br />
64.86.17.56 <a href="http://www.google.sm" target="_blank">www.google.sm</a><br />
64.86.17.56 <a href="http://www.google.sn" target="_blank">www.google.sn</a><br />
64.86.17.56 <a href="http://www.google.st" target="_blank">www.google.st</a><br />
64.86.17.56 <a href="http://www.google.tl" target="_blank">www.google.tl</a><br />
64.86.17.56 <a href="http://www.google.tm" target="_blank">www.google.tm</a><br />
64.86.17.56 <a href="http://www.google.tt" target="_blank">www.google.tt</a><br />
64.86.17.56 <a href="http://www.google.us" target="_blank">www.google.us</a><br />
64.86.17.56 <a href="http://www.google.vu" target="_blank">www.google.vu</a><br />
64.86.17.56 <a href="http://www.google.ws" target="_blank">www.google.ws</a><br />
64.86.17.56 <a href="http://www.google.co.ck" target="_blank">www.google.co.ck</a><br />
64.86.17.56 <a href="http://www.google.co.id" target="_blank">www.google.co.id</a><br />
64.86.17.56 <a href="http://www.google.co.il" target="_blank">www.google.co.il</a><br />
64.86.17.56 <a href="http://www.google.co.in" target="_blank">www.google.co.in</a><br />
64.86.17.56 <a href="http://www.google.co.jp" target="_blank">www.google.co.jp</a><br />
64.86.17.56 <a href="http://www.google.co.kr" target="_blank">www.google.co.kr</a><br />
64.86.17.56 <a href="http://www.google.co.ls" target="_blank">www.google.co.ls</a><br />
64.86.17.56 <a href="http://www.google.co.ma" target="_blank">www.google.co.ma</a><br />
64.86.17.56 <a href="http://www.google.co.nz" target="_blank">www.google.co.nz</a><br />
64.86.17.56 <a href="http://www.google.co.tz" target="_blank">www.google.co.tz</a><br />
64.86.17.56 <a href="http://www.google.co.ug" target="_blank">www.google.co.ug</a><br />
64.86.17.56 <a href="http://www.google.co.uk" target="_blank">www.google.co.uk</a><br />
64.86.17.56 <a href="http://www.google.co.za" target="_blank">www.google.co.za</a><br />
64.86.17.56 <a href="http://www.google.co.zm" target="_blank">www.google.co.zm</a><br />
64.86.17.56 <a href="http://www.google.com" target="_blank">www.google.com</a><br />
64.86.17.56 <a href="http://www.google.com.af" target="_blank">www.google.com.af</a><br />
64.86.17.56 <a href="http://www.google.com.ag" target="_blank">www.google.com.ag</a><br />
64.86.17.56 <a href="http://www.google.com.ar" target="_blank">www.google.com.ar</a><br />
64.86.17.56 <a href="http://www.google.com.au" target="_blank">www.google.com.au</a><br />
64.86.17.56 <a href="http://www.google.com.bn" target="_blank">www.google.com.bn</a><br />
64.86.17.56 <a href="http://www.google.com.br" target="_blank">www.google.com.br</a><br />
64.86.17.56 <a href="http://www.google.com.by" target="_blank">www.google.com.by</a><br />
64.86.17.56 <a href="http://www.google.com.bz" target="_blank">www.google.com.bz</a><br />
64.86.17.56 <a href="http://www.google.com.cu" target="_blank">www.google.com.cu</a><br />
64.86.17.56 <a href="http://www.google.com.ec" target="_blank">www.google.com.ec</a><br />
64.86.17.56 <a href="http://www.google.com.fj" target="_blank">www.google.com.fj</a><br />
64.86.17.56 google.com<br />
64.86.17.56 <a href="http://www.google.com" target="_blank">www.google.com</a><br />
64.86.17.56 bing.com<br />
64.86.17.56 <a href="http://www.bing.com" target="_blank">www.bing.com</a><br />
64.86.17.56 search.yahoo.com<br />
64.86.17.56 <a href="http://www.search.yahoo.com" target="_blank">www.search.yahoo.com</a><br />
64.86.17.56 search.live.com<br />
64.86.17.56 search.msn.com<br />
64.86.17.56 googleads.g.doubleclick.net<br />
64.86.17.56 <a href="http://www.googleads.g.doubleclick.net" target="_blank">www.googleads.g.doubleclick.net</a><br />
64.86.17.56 pubads.g.doubleclick.net<br />
64.86.17.56 <a href="http://www.pubads.g.doubleclick.net" target="_blank">www.pubads.g.doubleclick.net</a><br />
64.86.17.56 partner.googleadservices.com<br />
64.86.17.56 <a href="http://www.partner.googleadservices.com" target="_blank">www.partner.googleadservices.com</a><br />
64.86.17.56 <a href="http://www.partner.googleadservices.com" target="_blank">www.partner.googleadservices.com</a></div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>JayR56</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878812-cannot-access-google-please-help.html</guid>
		</item>
		<item>
			<title>Exception Processing Message c0000013 Parameters</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878763-exception-processing-message-c0000013-parameters.html</link>
			<pubDate>Thu, 19 Nov 2009 20:19:11 GMT</pubDate>
			<description><![CDATA[Pop up message keeps coming up titled Windows - No Disk that says "Exception Processing Message c0000013 Parameters 75b6bf7c 75b6bf7c 75b6bf7c" with the buttons Cancel, Try Again, or Continue. 
  
I'm running Windows XP Pro on an HP 
  
HiJackThis...]]></description>
			<content:encoded><![CDATA[<div>Pop up message keeps coming up titled Windows - No Disk that says &quot;Exception Processing Message c0000013 Parameters 75b6bf7c 75b6bf7c 75b6bf7c&quot; with the buttons Cancel, Try Again, or Continue.<br />
 <br />
I'm running Windows XP Pro on an HP<br />
 <br />
HiJackThis Log:<br />
 <br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 11:36:36 AM, on 11/19/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Iconix eMailID\OutlookClient\IconixOutlookUpdaterService.exe<br />
C:\Program Files\Common Files\Iconix\IconixService.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe<br />
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe<br />
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe<br />
C:\WINDOWS\system32\RUNDLL32.EXE<br />
C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe<br />
C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\AWS\WeatherBug\Weather.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe<br />
C:\Program Files\SUPERAntiSpyware\c1e037b2-b421-4796-83fd-df2ff03809e9.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\iTunes\iTunes.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\distnoted.exe<br />
C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://www.yahoo.com/?fr=fp-yie8" target="_blank">http://www.yahoo.com/?fr=fp-yie8</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.yahoo.com/" target="_blank">http://www.yahoo.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R3 - URLSearchHook: (no name) - CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)<br />
R3 - URLSearchHook: (no name) - EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: IconixBHOClass Class - {761233B6-F228-49E4-8F6B-668499D4E55A} - C:\Program Files\Iconix\IEAddOn\IconixBHO_41.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll<br />
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll<br />
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)<br />
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)<br />
O3 - Toolbar: (no name) - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - (no file)<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] &quot;C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe&quot;<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [IconixOEAddOn] &quot;C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;<br />
O4 - HKCU\..\Run: [Advanced SystemCare 3] &quot;C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe&quot; /startup<br />
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\c1e037b2-b421-4796-83fd-df2ff03809e9.exe<br />
O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'Default user')<br />
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br />
O4 - Global Startup: Free WebSite Tools.lnk = ?<br />
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br />
O8 - Extra context menu item: &amp;Search - <a href="http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZSYYYYYYYYUS" target="_blank">http://edits.mywebsearch.com/toolbar...p=ZSYYYYYYYYUS</a><br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Google AdSense Preview Tool - <a href="http://pagead2.googlesyndication.com/pagead/preview/en/preview.html" target="_blank">http://pagead2.googlesyndication.com...n/preview.html</a><br />
O9 - Extra button: (no name) - {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - C:\Program Files\Iconix\IEAddOn\IconixBHO_41.dll<br />
O9 - Extra 'Tools' menuitem: Email ID Preferences - {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - C:\Program Files\Iconix\IEAddOn\IconixBHO_41.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {BC3F6B6D-2E49-4603-B028-7411655713F3} - C:\Program Files\Iconix\IEAddOn\IconixBHO_41.dll<br />
O9 - Extra 'Tools' menuitem: About Email ID - {BC3F6B6D-2E49-4603-B028-7411655713F3} - C:\Program Files\Iconix\IEAddOn\IconixBHO_41.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O15 - Trusted Zone: <a href="http://*.mcafee.com" target="_blank">http://*.mcafee.com</a> (HKLM)<br />
O15 - Trusted Zone: <a href="http://betavscan.mcafeeasap.com" target="_blank">http://betavscan.mcafeeasap.com</a> (HKLM)<br />
O15 - Trusted Zone: <a href="http://vs.mcafeeasap.com" target="_blank">http://vs.mcafeeasap.com</a> (HKLM)<br />
O15 - Trusted Zone: <a href="http://www.mcafeeasap.com" target="_blank">http://www.mcafeeasap.com</a> (HKLM)<br />
O15 - ESC Trusted Zone: <a href="http://*.mcafee.com" target="_blank">http://*.mcafee.com</a> (HKLM)<br />
O15 - ESC Trusted Zone: <a href="http://betavscan.mcafeeasap.com" target="_blank">http://betavscan.mcafeeasap.com</a> (HKLM)<br />
O15 - ESC Trusted Zone: <a href="http://vs.mcafeeasap.com" target="_blank">http://vs.mcafeeasap.com</a> (HKLM)<br />
O15 - ESC Trusted Zone: <a href="http://www.mcafeeasap.com" target="_blank">http://www.mcafeeasap.com</a> (HKLM)<br />
O16 - DPF: {001000AF-2DEF-0206-10B6-DC5BA692C858} (Xvidnc Class) - <a href="http://gate.x10.com/control/xvidnx.cab" target="_blank">http://gate.x10.com/control/xvidnx.cab</a><br />
O16 - DPF: {0075546E-5D3D-11D2-A3E5-0060971304D8} (WTX_Installer Class) - <a href="http://www.webtrends.com/Download/Browser/Plugins/WordUtils/v6.0/Microsoft/wtx_setup.dll" target="_blank">http://www.webtrends.com/Download/Br.../wtx_setup.dll</a><br />
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - <a href="http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab" target="_blank">http://appldnld.apple.com.edgesuite....x/qtplugin.cab</a><br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - <a href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" target="_blank">http://upload.facebook.com/controls/...oUploader5.cab</a><br />
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - <a href="http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab" target="_blank">http://h20270.www2.hp.com/ediags/gmn...taller_gmn.cab</a><br />
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - <a href="http://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/citrix/wficat-no-eula.cab" target="_blank">http://a516.g.akamai.net/f/516/25175...at-no-eula.cab</a><br />
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} - <a href="http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab" target="_blank">http://wdownload.weatherbug.com/mini...ransporter.cab</a>?<br />
O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KXHCM10 Control) - <a href="http://cam3.hiddenvalleylots.com/kxhcm10.ocx" target="_blank">http://cam3.hiddenvalleylots.com/kxhcm10.ocx</a><br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll<br />
O16 - DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B} (WebIQ Engine Application Object) - <a href="http://webiq005.webiqonline.com/WebIQ/DataServer/Pub/DataServer.dll?Handler=GetEngineDistribution&amp;EDID={896A23A1-5821-4609-A6C6-6D5536C585C9" target="_blank">http://webiq005.webiqonline.com/WebI...6-6D5536C585C9</a>}<br />
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - <a href="https://support.microsoft.com/OAS/ActiveX/odc.cab" target="_blank">https://support.microsoft.com/OAS/ActiveX/odc.cab</a><br />
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - <a href="http://lads.myspace.com/upload/MySpaceUploader1006.cab" target="_blank">http://lads.myspace.com/upload/MySpaceUploader1006.cab</a><br />
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} - <a href="http://ipgweb.cce.hp.com/rdqcpc/downloads/sysinfo.cab" target="_blank">http://ipgweb.cce.hp.com/rdqcpc/downloads/sysinfo.cab</a><br />
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - <a href="http://www.linkedin.com/cab/LinkedInContactFinderControl.cab" target="_blank">http://www.linkedin.com/cab/LinkedIn...derControl.cab</a><br />
O16 - DPF: {4CCA4E6B-9259-11D9-AC6E-444553544200} (FixController Control) - <a href="http://h30155.www3.hp.com/ediags/dd/install/HPInstallMgr_v01.cab" target="_blank">http://h30155.www3.hp.com/ediags/dd/...allMgr_v01.cab</a><br />
O16 - DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} (ContactExtractor Class) - <a href="http://www.facebook.com/controls/contactx.dll" target="_blank">http://www.facebook.com/controls/contactx.dll</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1148331376183" target="_blank">http://update.microsoft.com/microsof...?1148331376183</a><br />
O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - <a href="http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab" target="_blank">http://www.kodakgallery.com/download...2/axofupld.cab</a><br />
O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - <a href="http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab" target="_blank">http://www.kodakgallery.com/download...2/axofupld.cab</a><br />
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - <a href="http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab" target="_blank">http://upload.facebook.com/controls/...Uploader55.cab</a><br />
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - <a href="http://ipgweb.cce.hp.com/rdqcpc/downloads/msxml4.cab" target="_blank">http://ipgweb.cce.hp.com/rdqcpc/downloads/msxml4.cab</a><br />
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - <a href="http://mdev.temple.edu/webcams/AxisCamControl.ocx" target="_blank">http://mdev.temple.edu/webcams/AxisCamControl.ocx</a><br />
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - <a href="https://rtc1.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB" target="_blank">https://rtc1.webresponse.one.microso.../TLIEFlash.CAB</a><br />
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - <a href="http://offers.e-centives.com/cif/download/bin/actxcab.cab" target="_blank">http://offers.e-centives.com/cif/dow...in/actxcab.cab</a><br />
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - <a href="https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx" target="_blank">https://h17000.www1.hp.com/ewfrf-JAV...oadManager.ocx</a><br />
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - <a href="http://www.imgag.com/cp/install/Crusher.cab" target="_blank">http://www.imgag.com/cp/install/Crusher.cab</a><br />
O16 - DPF: {C8E7CBFB-9F2E-42C7-B4CB-D4B7FC89A363} (Gather Photo Uploader Control) - <a href="http://www.gather.com/imageuploader/GatherUploader5.cab" target="_blank">http://www.gather.com/imageuploader/GatherUploader5.cab</a><br />
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - <a href="https://prweb.webex.com/client/T25L/event/ieatgpc.cab" target="_blank">https://prweb.webex.com/client/T25L/event/ieatgpc.cab</a><br />
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - <a href="http://upload.mediamax.com/Upload/XUpload.ocx" target="_blank">http://upload.mediamax.com/Upload/XUpload.ocx</a><br />
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - <a href="http://driveragent.com/files/driveragent.cab" target="_blank">http://driveragent.com/files/driveragent.cab</a><br />
O16 - DPF: {EAA105FE-7BBD-4196-8B96-D46743894195} (MjpegControl Class) - <a href="http://www.hiddenvalleylots.com/CameraStream/mjpegcontrol.cab" target="_blank">http://www.hiddenvalleylots.com/Came...pegcontrol.cab</a><br />
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - <a href="http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll" target="_blank">http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll</a><br />
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = greenscene.local<br />
O17 - HKLM\Software\..\Telephony: DomainName = greenscene.local<br />
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = greenscene.local<br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: Iconix Outlook Addin Updater Service (IconixOutlookUpdaterService) - Iconix Inc. - C:\Program Files\Iconix eMailID\OutlookClient\IconixOutlookUpdaterService.exe<br />
O23 - Service: Iconix Update Service (IconixService) - Unknown owner - C:\Program Files\Common Files\Iconix\IconixService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
--<br />
End of file - 16614 bytes</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>mariermn</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878763-exception-processing-message-c0000013-parameters.html</guid>
		</item>
		<item>
			<title>Desperate - Lenovo T60 Response time is in minutes</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878750-desperate-lenovo-t60-response-time.html</link>
			<pubDate>Thu, 19 Nov 2009 19:51:31 GMT</pubDate>
			<description>My laptop was running normally and one day, while in FaceBook, the laptop froze.  I let it sit for about 30 minutes before powering it down manually.  I do not know what happened, except that it would not boot up.  I finally got is rebooted,...</description>
			<content:encoded><![CDATA[<div>My laptop was running normally and one day, while in FaceBook, the laptop froze.  I let it sit for about 30 minutes before powering it down manually.  I do not know what happened, except that it would not boot up.  I finally got is rebooted, restored system files and reapplied updates.<br />
<br />
Now, my IE8 browser freezes my laptop for up to a minute.  I cannot switch between programs, I cannot switch tabs, it just sits there with a the hourglass displayed.  Eventually, it will come back, but the response time is very slow.<br />
<br />
When I open IE8, I have to kill the process up to three times before IE8 loads.  I am afraid that I have an virus on my machine and do not know what to do.  For security, I am running AVG Free, Adware, SpyBot.  I am also using Glary Utilities for memory management, but to be honest, I do not know if it is working or not.<br />
<br />
I have defragged my hard drive and I am sure that it is ok.  I have run CHKDSK and no errors are being reported.<br />
<br />
I am using Windows XP, IE8, Office 2007, and that is about it.  I have installed the latest version of HiJackThis and have copied the log here.<br />
<br />
Please note that whenever I am in Facebook, the response time on my laptop is horrific.  Right now, for example, I am not in Facebook, but when I am typing in this form, at times, the response time forces a two - three second pause between letters being typed and being displayed.<br />
<br />
Here is the log:<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 11:40:06 AM, on 11/19/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\ibmpmsvc.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\system32\IPSSVC.EXE<br />
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe<br />
C:\WINDOWS\system32\acs.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe<br />
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe<br />
C:\WINDOWS\System32\TPHDEXLG.exe<br />
C:\WINDOWS\system32\TpKmpSVC.exe<br />
C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe<br />
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe<br />
C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe<br />
C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE<br />
C:\WINDOWS\system32\SearchIndexer.exe<br />
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe<br />
C:\Program Files\AVG\AVG9\avgemc.exe<br />
C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE<br />
c:\program files\lenovo\system update\suservice.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe<br />
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe<br />
C:\Program Files\Lenovo\Client Security Solution\cssauth.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe<br />
C:\Program Files\Lenovo\Client Security Solution\tvtpwm_tray.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe<br />
C:\WINDOWS\system32\TpShocks.exe<br />
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe<br />
C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe<br />
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe<br />
C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br />
C:\Program Files\Lenovo\Zoom\TpScrex.exe<br />
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Lenovo\AwayTask\AwaySch.EXE<br />
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe<br />
C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe<br />
C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe<br />
C:\Program Files\Lenovo\SafeGuard PrivateDisk\pdservice.exe<br />
C:\WINDOWS\system32\taskswitch.exe<br />
C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe<br />
C:\PROGRA~1\THINKV~1\PrdCtr\LPMLCHK.exe<br />
C:\Program Files\Analog Devices\Core\smax4pnp.exe<br />
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
C:\Program Files\LENOVO\Message Center Plus\MCPLaunch.exe<br />
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files\Logitech\Logitech Vid\vid.exe<br />
C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe<br />
C:\Program Files\Digital Line Detect\DLG.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Program Files\Common Files\Lenovo\Logger\logmon.exe<br />
C:\Program Files\WinZip\WZQKPICK.EXE<br />
C:\Program Files\FastStone Capture\FSCapture.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br />
C:\Program Files\Glary Utilities\Integrator.exe<br />
C:\Program Files\Glary Utilities\memdefrag.exe<br />
C:\Program Files\Skype\Phone\Skype.exe<br />
C:\Program Files\Skype\Plugin Manager\skypePM.exe<br />
C:\WINDOWS\system32\taskmgr.exe<br />
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe<br />
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Documents and Settings\Keith Roberts\Local Settings\Application Data\Yahoo!\BrowserPlus\2.4.21\BrowserPlusCore.exe<br />
C:\WINDOWS\system32\notepad.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\WINDOWS\system32\SearchProtocolHost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.foxnews.com/" target="_blank">http://www.foxnews.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)<br />
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O2 - BHO: {68ec5222-186e-85aa-0db4-fee65e3a5f1d} - {d1f5a3e5-6eef-4bd0-aa58-e6812225ce86} - (no file)<br />
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O3 - Toolbar: &amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor<br />
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe<br />
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper<br />
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe<br />
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe<br />
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe<br />
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray<br />
O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe<br />
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br />
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br />
O4 - HKLM\..\Run: [ISUSScheduler] &quot;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&quot; -start<br />
O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE<br />
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe<br />
O4 - HKLM\..\Run: [DiskeeperSystray] &quot;C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe&quot;<br />
O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe<br />
O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe<br />
O4 - HKLM\..\Run: [PDService.exe] &quot;C:\Program Files\Lenovo\SafeGuard PrivateDisk\pdservice.exe&quot;<br />
O4 - HKLM\..\Run: [cssauth] &quot;C:\Program Files\Lenovo\Client Security Solution\cssauth.exe&quot; silent<br />
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe /r<br />
O4 - HKLM\..\Run: [LPMailChecker] C:\PROGRA~1\THINKV~1\PrdCtr\LPMLCHK.exe<br />
O4 - HKLM\..\Run: [StartCCC] &quot;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&quot;<br />
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [Message Center Plus] C:\Program Files\LENOVO\Message Center Plus\MCPLaunch.exe /start<br />
O4 - HKLM\..\Run: [Microsoft Default Manager] &quot;C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe&quot; -resume<br />
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] &quot;C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe&quot; /hide<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKCU\..\Run: [Logitech Vid] &quot;C:\Program Files\Logitech\Logitech Vid\vid.exe&quot; -bootmode<br />
O4 - HKCU\..\Run: [Skype] &quot;C:\Program Files\Skype\Phone\Skype.exe&quot; /nosplash /minimized<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKCU\..\Run: [ccleaner] &quot;C:\Program Files\CCleaner\ccleaner.exe&quot; /AUTO<br />
O4 - HKCU\..\Run: [Glary Memory Optimizer] &quot;C:\Program Files\Glary Utilities\memdefrag.exe&quot; /autostart<br />
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] &quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&quot; -t (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] &quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&quot; -t (User 'Default user')<br />
O4 - S-1-5-18 Startup: FastStone Capture.lnk = C:\Program Files\FastStone Capture\FSCapture.exe (User 'SYSTEM')<br />
O4 - S-1-5-18 Startup: Logitech . Product Registration.lnk = C:\Program Files\Logitech\Logitech WebCam Software\eReg.exe (User 'SYSTEM')<br />
O4 - .DEFAULT Startup: FastStone Capture.lnk = C:\Program Files\FastStone Capture\FSCapture.exe (User 'Default user')<br />
O4 - .DEFAULT Startup: Logitech . Product Registration.lnk = C:\Program Files\Logitech\Logitech WebCam Software\eReg.exe (User 'Default user')<br />
O4 - Startup: FastStone Capture.lnk = C:\Program Files\FastStone Capture\FSCapture.exe<br />
O4 - Startup: Logitech . Product Registration.lnk = C:\Program Files\Logitech\Logitech WebCam Software\eReg.exe<br />
O4 - Global Startup: Bluetooth.lnk = ?<br />
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe<br />
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE<br />
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present<br />
O8 - Extra context menu item: Add to Google Photos Screensa&amp;ver - res://C:\WINDOWS\system32\GPhotos.scr/200<br />
O8 - Extra context menu item: Add to Windows &amp;Live Favorites - <a href="http://favorites.live.com/quickadd.aspx" target="_blank">http://favorites.live.com/quickadd.aspx</a><br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Send to &amp;Bluetooth Device... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm<br />
O9 - Extra button: (no name) - {0045D4BC-5189-4b67-969C-83BB1906C421} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll<br />
O9 - Extra 'Tools' menuitem: ThinkVantage Password Manager... - {0045D4BC-5189-4b67-969C-83BB1906C421} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe<br />
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)<br />
O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com/welcome/thinkpad<br />
O15 - Trusted Zone: <a href="http://elearning.bucec.com" target="_blank">http://elearning.bucec.com</a><br />
O15 - Trusted Zone: <a href="http://seeker.dice.com" target="_blank">http://seeker.dice.com</a><br />
O15 - Trusted Zone: <a href="http://www.dice.com" target="_blank">http://www.dice.com</a><br />
O15 - Trusted Zone: <a href="http://*.dice.com" target="_blank">http://*.dice.com</a><br />
O15 - Trusted Zone: <a href="http://download.windowsupdate.com" target="_blank">http://download.windowsupdate.com</a><br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - <a href="http://upload.facebook.com/controls/FacebookPhotoUploader5.cab" target="_blank">http://upload.facebook.com/controls/...oUploader5.cab</a><br />
O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} (IASRunner Class) - <a href="http://www-307.ibm.com/pc/support/acpir.cab" target="_blank">http://www-307.ibm.com/pc/support/acpir.cab</a><br />
O16 - DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B} (WebIQ Engine Application Object) - http://webiq005.webiqonline.com/WebIQ/DataServer/Pub/DataServer.dll?Handler=GetEngineDistribution&amp;EDID={896A23A1-5821-4609-A6C6-6D5536C585C9}<br />
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - <a href="http://lads.myspace.com/upload/MySpaceUploader1006.cab" target="_blank">http://lads.myspace.com/upload/MySpaceUploader1006.cab</a><br />
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - <a href="http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab" target="_blank">http://download.bitdefender.com/reso...an8/oscan8.cab</a><br />
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - <a href="http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab" target="_blank">http://security.symantec.com/sscv6/S.../bin/cabsa.cab</a><br />
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - <a href="https://webdl.symantec.com/activex/symdlmgr.cab" target="_blank">https://webdl.symantec.com/activex/symdlmgr.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1177981606875" target="_blank">http://update.microsoft.com/microsof...?1177981606875</a><br />
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - <a href="https://www-307.ibm.com/pc/support/access/aslibmain/content/IbmEgath.cab" target="_blank">https://www-307.ibm.com/pc/support/a...t/IbmEgath.cab</a><br />
O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - <a href="http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab" target="_blank">http://zone.msn.com/bingame/zpagames...1.cab60096.cab</a><br />
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (MSN Games – Texas Holdem Poker) - <a href="http://zone.msn.com/bingame/zpagames/zpa_txhe.cab79352.cab" target="_blank">http://zone.msn.com/bingame/zpagames...e.cab79352.cab</a><br />
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - <a href="http://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab" target="_blank">http://cdn2.zone.msn.com/binFramewor....cab102118.cab</a><br />
O16 - DPF: {BE415DD9-C50D-46AA-9B5D-37F2EEBBBFE6} (acpRunner Class) - <a href="https://www-307.ibm.com/pc/support/access/aslibmain/content/AcpControl.cab" target="_blank">https://www-307.ibm.com/pc/support/a...AcpControl.cab</a><br />
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - <a href="http://zone.msn.com/bingame/dim2/default/popcaploader_v6.cab" target="_blank">http://zone.msn.com/bingame/dim2/def...ploader_v6.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - <a href="http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5687/mcfscan.cab" target="_blank">http://download.mcafee.com/molbin/is...87/mcfscan.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL<br />
O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O20 - Winlogon Notify: AwayNotify - C:\Program Files\Lenovo\AwayTask\AwayNotify.dll<br />
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo  - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe<br />
O23 - Service: Atheros Configuration Service (acs) - Atheros - C:\WINDOWS\system32\acs.exe<br />
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo  - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe<br />
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)<br />
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE<br />
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe<br />
O23 - Service: Power Manager DBC Service - Unknown owner - C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE<br />
O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\program files\lenovo\system update\suservice.exe<br />
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe<br />
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe<br />
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe<br />
O23 - Service: TSS Core Service (TSSCoreService) - IBM - C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe<br />
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe<br />
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe<br />
O23 - Service: tvtnetwk - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
<br />
--<br />
End of file - 24355 bytes<br />
<br />
<br />
Thanks!</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>KeithRoberts</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878750-desperate-lenovo-t60-response-time.html</guid>
		</item>
		<item>
			<title><![CDATA[Prank cd open & closing. Cannot wipe it out]]></title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878742-prank-cd-open-closing-cannot.html</link>
			<pubDate>Thu, 19 Nov 2009 19:19:14 GMT</pubDate>
			<description><![CDATA[Hi All,:o 
How can I get rid of the CD Open & Closing PRANK? 
If the Prank was for a few days, it would be a nice Prank, but this is a pain nasty forever and I have not been able to Wipe it out. 
Please...]]></description>
			<content:encoded><![CDATA[<div>Hi All,:o<br />
How can I get rid of the CD Open &amp; Closing PRANK?<br />
If the Prank was for a few days, it would be a nice Prank, but this is a pain nasty forever and I have not been able to Wipe it out.<br />
Please HHHHHHHHHeeeeeeeeeeeeeeeeeeLLLLLLLLLLLLLLLLLLLLLppppppppppppppppppp!</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>MrInquisitive</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878742-prank-cd-open-closing-cannot.html</guid>
		</item>
		<item>
			<title>Quirky PC Behavior</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878730-quirky-pc-behavior.html</link>
			<pubDate>Thu, 19 Nov 2009 18:41:07 GMT</pubDate>
			<description>Did a TrendMicro TVscan in Safe Mode. 
Found: 
  
Copyright (c) 1990 - 2006 Trend Micro Inc. 
Report Date : 11/18/2009 17:06:58 
VSAPI Engine Version : 8.952-1009 
VSCANTM Version : 2.00-1000 (Official Build) 
VSGetVirusPatternInformation is invoked...</description>
			<content:encoded><![CDATA[<div>Did a TrendMicro TVscan in Safe Mode.<br />
Found:<br />
 <br />
Copyright (c) 1990 - 2006 Trend Micro Inc.<br />
Report Date : 11/18/2009 17:06:58<br />
VSAPI Engine Version : 8.952-1009<br />
VSCANTM Version : 2.00-1000 (Official Build)<br />
VSGetVirusPatternInformation is invoked<br />
 <br />
Virus Pattern Version : 633 (493659/533699 Patterns) (2009/11/17) (663350)<br />
VSGetVirusPatternInformation is invoked<br />
 <br />
Virus Pattern Version : 855 (40040/533699 Patterns) (2009/11/11) (85500)<br />
Command Line: C:\Program Files\Trend Micro\Internet Security\TVScan32.exe -S -SSAPTN -VSSPYWARE+ -c -d2 -I -Fail to Clean [ PAK_Generic.001](    1) Success Delete [ PAK_Generic.001](    1) from 181255 files have been read.<br />
181255 files have been checked.<br />
181200 files have been scanned.<br />
291653 files have been scanned. (including files in archived)<br />
1 files containing viruses.<br />
Found 1 viruses totally.<br />
Maybe 0 viruses totally.<br />
Stop At: 11/18/2009 18:34:46 1 hour 27 minutes 44 seconds (5263.63 seconds) has elapsed.(29.040 msec/file)<br />
 <br />
<b>Note: Some links do not respond when pressed, IE8 sometimes crashes for no apparent reason while surfing, Netflix logo suddenly appeared in WMC and was able to watch movies (couple months during spring/summer) now when I press play movie, WMC crashes. Use TrendMicro Int. Security 16, scan with Malwarebytes, and Superantispyware Pro. Any help will be appreciated. Won't go near registry without support. Not an expert but can make my way with certain things alone and others if explained. Many thanks.</b><br />
 <br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 12:15:18 PM, on 11/19/2009<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18828)<br />
Boot mode: Normal<br />
Running processes:<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\DellTPad\Apoint.exe<br />
C:\Windows\OEM02Mon.exe<br />
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe<br />
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br />
C:\Program Files\Dell\MediaDirect\PCMService.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Program Files\DellTPad\ApMsgFwd.exe<br />
C:\Program Files\Dell Support Center\bin\sprtcmd.exe<br />
C:\Program Files\DellTPad\HidFind.exe<br />
C:\Program Files\DellTPad\Apntex.exe<br />
C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe<br />
C:\Program Files\Dell Photo AIO Printer 966\memcard.exe<br />
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe<br />
C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe<br />
C:\Program Files\Common Files\aol\1234026709\ee\aolsoftware.exe<br />
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Windows\WindowsMobile\wmdc.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\Digital Line Detect\DLG.exe<br />
C:\Program Files\Logitech\SetPoint\SetPoint.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Program Files\Dell\QuickSet\quickset.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE<br />
C:\Program Files\AOL 9.0\waol.exe<br />
C:\Program Files\AOL 9.0\shellmon.exe<br />
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe<br />
C:\Program Files\internet explorer\iexplore.exe<br />
C:\Program Files\internet explorer\iexplore.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Verizon Broadband Toolbar - {A057A204-BACC-4D26-8398-26FADCF27386} - C:\PROGRA~1\VERIZO~1\VERIZO~1.DLL<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll<br />
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O3 - Toolbar: &amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O3 - Toolbar: Verizon Broadband Toolbar - {A057A204-BACC-4D26-8398-26FADCF27386} - C:\PROGRA~1\VERIZO~1\VERIZO~1.DLL<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe<br />
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe<br />
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe<br />
O4 - HKLM\..\Run: [DELL Webcam Manager] &quot;C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe&quot; /s<br />
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br />
O4 - HKLM\..\Run: [ISUSScheduler] &quot;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&quot; -start<br />
O4 - HKLM\..\Run: [PCMService] &quot;C:\Program Files\Dell\MediaDirect\PCMService.exe&quot;<br />
O4 - HKLM\..\Run: [%PROVIDERID%] &quot;bin\sprtcmd.exe&quot; /P %PROVIDERID%<br />
O4 - HKLM\..\Run: [VolPanel] &quot;C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe&quot; /r<br />
O4 - HKLM\..\Run: [SPIRunE] Rundll32 SPIRunE.dll,RunDLLEntry<br />
O4 - HKLM\..\Run: [DellSupportCenter] &quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&quot; /P DellSupportCenter<br />
O4 - HKLM\..\Run: [FaxCenterServer] &quot;C:\Program Files\Dell PC Fax\fm3032.exe&quot; /s<br />
O4 - HKLM\..\Run: [dlcqmon.exe] &quot;C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe&quot;<br />
O4 - HKLM\..\Run: [MemoryCardManager] &quot;C:\Program Files\Dell Photo AIO Printer 966\memcard.exe&quot;<br />
O4 - HKLM\..\Run: [DLCQCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16<br />
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE<br />
O4 - HKLM\..\Run: [LogitechCommunicationsManager] &quot;C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe&quot;<br />
O4 - HKLM\..\Run: [LVCOMSX] &quot;C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe&quot;<br />
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1234026709\ee\AOLSoftware.exe<br />
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe<br />
O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;  -osboot<br />
O4 - HKLM\..\Run: [VerizonServicepoint.exe] &quot;C:\Program Files\Verizon\VSP\VerizonServicepoint.exe&quot; /AUTORUN<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start<br />
O4 - HKLM\..\Run: [UfSeAgnt.exe] &quot;C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe&quot;<br />
O4 - HKLM\..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;<br />
O4 - HKCU\..\Run: [OE] &quot;C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe&quot;<br />
O4 - HKCU\..\Run: [Aim] &quot;C:\Program Files\AIM\aim.exe&quot; /d locale=en-US<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKCU\..\Run: [AOL Fast Start] &quot;C:\Program Files\AOL 9.0\AOL.EXE&quot; -b<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] &quot;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&quot; /background (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] &quot;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&quot; /background (User 'Default user')<br />
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe<br />
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe<br />
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe<br />
O8 - Extra context menu item: Add to Windows &amp;Live Favorites - <a href="http://favorites.live.com/quickadd.aspx" target="_blank">http://favorites.live.com/quickadd.aspx</a><br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll<br />
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll<br />
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O13 - Gopher Prefix: <br />
O16 - DPF: vzTCPConfig - <a href="http://www2.verizon.net/help/fios_settings_POTT20009/include/vzTCPConfig.CAB" target="_blank">http://www2.verizon.net/help/fios_se...zTCPConfig.CAB</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1255058452048" target="_blank">http://update.microsoft.com/windowsu...?1255058452048</a><br />
O16 - DPF: {A3256902-51FA-45A0-8A97-FC1143C169D9} (Diagnostics ActiveX WebControl) - <a href="http://support.microsoft.com/mats/DiagWebControl.cab" target="_blank">http://support.microsoft.com/mats/DiagWebControl.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL<br />
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL<br />
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe<br />
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe<br />
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe<br />
O23 - Service: dlcq_device -   - C:\Windows\system32\dlcqcoms.exe<br />
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Premier\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe<br />
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe<br />
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe<br />
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br />
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe<br />
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe<br />
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe<br />
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe<br />
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe<br />
--<br />
End of file - 13976 bytes</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>ProfTC</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878730-quirky-pc-behavior.html</guid>
		</item>
		<item>
			<title><![CDATA[Windows XP -  Explorer: Access Denied, Can't run AVs or browse to online scanners.]]></title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878720-windows-xp-explorer-access-denied.html</link>
			<pubDate>Thu, 19 Nov 2009 17:58:12 GMT</pubDate>
			<description><![CDATA[Hi all, 
  
I'm slightly embarrassed to be posting here as a 10 year support tech, but I have been crippled by a virus/trojan which has disabled my PC's functionality. It started when I was at work; a roomate infected the PC and left it running all...]]></description>
			<content:encoded><![CDATA[<div>Hi all,<br />
 <br />
I'm slightly embarrassed to be posting here as a 10 year support tech, but I have been crippled by a virus/trojan which has disabled my PC's functionality. It started when I was at work; a roomate infected the PC and left it running all day becoming more and more infected until I got home. <br />
 <br />
Explorer does not run, I can't browse to any hard drive or cd-rom, and when attempting to install SAS, StopZilla, Symantec (already installed but crashes on run), or any other AV software I receive the message &quot;Your system administrator has set policies to prevent this installation&quot; <br />
 <br />
I have attempted going to safe mode to no avail, the problem persists there as well. A work-around I've found is opening the dos shell from task manager which still works, but I can't get into the control panel to change or look at any administration settings or group policies due to explorer not openning when I attempt to run it. <br />
 <br />
I was able to download a bitdefender recovery CD which got over a hundred malware files disinfected, I quarunteened the ones it couldn't repair. However the version of linux bitdefender boots off of cannot recognize my on-board ethernet card and I was unable to update the virus definitions, and the basic problems of not being able to run any AV software, navigate to any AV-related site, or even manually execute explorer.exe still remain.<br />
 <br />
If anyone can help me, I am desperate for assistance with this as I have important programs loaded on this computer which I no longer have the install disk for and I don't want to reinstall windows due to the amount of accumulated data/etc that I would lose. <br />
 <br />
Can anyone recommend another boot-cd which might have more up-to-date virus definitions or some other means of getting Antivirus (and mayhap even explorer) running so I can clean this PC?</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>mmason1983</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878720-windows-xp-explorer-access-denied.html</guid>
		</item>
		<item>
			<title>Search Redirects</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878670-search-redirects.html</link>
			<pubDate>Thu, 19 Nov 2009 14:46:41 GMT</pubDate>
			<description><![CDATA[Hi,  
  
Was wondering if anyone can help me with a problem I've been having. 
I usually search with Yahoo, but it seems no matter what search engine I use, I get redirected way too often.  I can hardly click on any link without getting redirected. ...]]></description>
			<content:encoded><![CDATA[<div>Hi, <br />
 <br />
Was wondering if anyone can help me with a problem I've been having.<br />
I usually search with Yahoo, but it seems no matter what search engine I use, I get redirected way too often.  I can hardly click on any link without getting redirected.  If I try to go to another page of search results, I also get redirected.  McAfee has found nothing.  I don't know if it's related, but also IE will not close about 50% of the time, usually requiring a &quot;end task&quot;.<br />
 <br />
Thanks and any help is appreciated.  I've taken the liberty to paste a hijack this log:<br />
 <br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 8:51:48 AM, on 11/18/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16915)<br />
Boot mode: Normal<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\explorer.exe<br />
C:\Program Files\Write DVD!\saimon.exe<br />
C:\WINDOWS\system32\CTHELPER.EXE<br />
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe<br />
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\WINDOWS\System32\CTsvcCDA.exe<br />
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe<br />
C:\Program Files\McAfee.com\Agent\mcagent.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Creative\ShareDLL\CtNotify.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\WINDOWS\Twain_32\CA561A\SnapDetect.exe<br />
C:\Program Files\Kodak EasyShare software\bin\EasyShare.exe<br />
C:\Program Files\Creative\ShareDLL\MediaDet.exe<br />
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe<br />
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br />
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
F:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\MOHAGame\pb\PnkBstrA.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\System32\MsPMSPSv.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe<br />
C:\Program Files\AIM\aim.exe<br />
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\HijackThis\HijackThis.exe<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://sandiego.cox.net/" target="_blank">http://sandiego.cox.net/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://websearch.drsnsrch.com/sidesearch.cgi?id" target="_blank">http://websearch.drsnsrch.com/sidesearch.cgi?id</a>=<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = <a href="http://search.yahoo.com/search?fr=mcafee&amp;p=%s" target="_blank">http://search.yahoo.com/search?fr=mcafee&amp;p=%s</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
F2 - REG:system.ini: Shell=explorer.exe                                                                                                                                                                                                                                          &quot;<br />
F2 - REG:system.ini: UserInit=userinit.exe<br />
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll<br />
O2 - BHO: (no name) - {82721259-9894-00E7-7255-99ca3230262a} - C:\Program Files\Common Files\System\tab-mmcs.dll<br />
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run<br />
O4 - HKLM\..\Run: [Narrator] C:\WINDOWS\System32\vuvvor.exe<br />
O4 - HKLM\..\Run: [Write DVD-R!] C:\Program Files\Write DVD!\saimon.exe<br />
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE<br />
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE<br />
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe<br />
O4 - HKLM\..\Run: [Jet Detection] &quot;C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe&quot;<br />
O4 - HKLM\..\Run: [zwmhuvof] C:\WINDOWS\System32\cswatqu.exe<br />
O4 - HKLM\..\Run: [ATICCC] &quot;C:\Program Files\ATI Technologies\ATI.ACE\cli.exe&quot; runtime -Delay<br />
O4 - HKLM\..\Run: [MaxMenuMgr] &quot;C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe&quot;<br />
O4 - HKLM\..\Run: [mcagent_exe] &quot;C:\Program Files\McAfee.com\Agent\mcagent.exe&quot; /runkey<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKCU\..\Run: [I053RfeEQ] jetcript.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [Walgreens PhotoShow Media Manager] C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O4 - Global Startup: Icatch(VI) SnapDetect.lnk = ?<br />
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak EasyShare software\bin\EasyShare.exe<br />
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present<br />
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present<br />
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1<br />
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe<br />
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O9 - Extra button: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (file missing)<br />
O9 - Extra 'Tools' menuitem: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (file missing)<br />
O16 - DPF: Yahoo! Pool 2 - <a href="http://download.games.yahoo.com/games/clients/y/potg_x.cab" target="_blank">http://download.games.yahoo.com/game...s/y/potg_x.cab</a><br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a href="http://go.microsoft.com/fwlink/?linkid=36467&amp;clcid=0x409" target="_blank">http://go.microsoft.com/fwlink/?link...67&amp;clcid=0x409</a><br />
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - <a href="http://www.miniclip.com/supergerball/miniclipGameLoader.dll" target="_blank">http://www.miniclip.com/supergerball...GameLoader.dll</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1104478570500" target="_blank">http://v5.windowsupdate.microsoft.co...?1104478570500</a><br />
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - <a href="http://zone.msn.com/binFramework/v10/ZIntro.cab33902.cab" target="_blank">http://zone.msn.com/binFramework/v10...o.cab33902.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe<br />
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe<br />
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: KodakDigitalDisplayService - Orb Networks - C:\Program Files\Digital Display\OrbKodakLauncher\DllStartupService.exe<br />
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe<br />
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br />
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe<br />
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
O23 - Service: PunkBuster (PnkBstrA) - Unknown owner - F:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\MOHAGame\pb\PnkBstrA.exe<br />
--<br />
End of file - 10475 bytes</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>champ123</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878670-search-redirects.html</guid>
		</item>
		<item>
			<title>Blue Screen</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878664-blue-screen.html</link>
			<pubDate>Thu, 19 Nov 2009 14:30:51 GMT</pubDate>
			<description>Hi, I have a blue screen.  All the icons are there but I cannot use system restore, cannot start in safe mode, computer running slow, can only access internet through explorer and as I am quite ignorant of computer usage and absolutely stuck about...</description>
			<content:encoded><![CDATA[<div>Hi, I have a blue screen.  All the icons are there but I cannot use system restore, cannot start in safe mode, computer running slow, can only access internet through explorer and as I am quite ignorant of computer usage and absolutely stuck about what to do.  I have Macafee and have installed spyware doctor but so far nothing.  Any help would be greatly appreciated.  Thank you:o</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>jiltyp</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878664-blue-screen.html</guid>
		</item>
		<item>
			<title>Inability to get autoupdates</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878655-inability-get-autoupdates.html</link>
			<pubDate>Thu, 19 Nov 2009 13:46:04 GMT</pubDate>
			<description>Earlier in the year, my girlfriend had a virus alert whilst accessing Facebook. She apparently managed to remove it using AVG 8.0 Free. Since that date, her PC will not do the following: 
  
Windows Updates - this will not run automatically or if...</description>
			<content:encoded><![CDATA[<div>Earlier in the year, my girlfriend had a virus alert whilst accessing Facebook. She apparently managed to remove it using AVG 8.0 Free. Since that date, her PC will not do the following:<br />
 <br />
Windows Updates - this will not run automatically or if manually instigated. Returns the error code 80072EFD<br />
 <br />
Windows Defender - will not run automatically (returns the same error code as Windows Updates). Can however access the Defender website and download the latest signatures.<br />
 <br />
Belarc Advisor will is unable to check for latest updates.<br />
 <br />
AVG 9.0 Free will only update if forced, auto updates do not appear to be working.<br />
 <br />
Windows OneCare will not download and run.<br />
 <br />
I have scanned the PC with the following, all with no errors:<br />
 <br />
AVG 9.0 Free<br />
Spybot Search &amp; Destroy<br />
Windows Defender<br />
TM Housecall<br />
TM CWShredder<br />
TM Rootkit Buster<br />
TM RUBotted<br />
 <br />
Running Windows Vista Home Basic SP2<br />
Fujitsu Siemens Amilo Laptop<br />
Intel processor T1400 @ 1.73GHz<br />
1GB Ram<br />
32 Bit operating system.<br />
 <br />
I have attached HijackThis StartupList &amp; Scan Report. Would very much appreciate it there appear to be any pointers in the attached.</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://static.techguy.org/v38/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="{attachment-server}attachment.php?attachmentid=159793&amp;d=1258638298">startuplist.txt</a> (48.8 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://static.techguy.org/v38/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="{attachment-server}attachment.php?attachmentid=159794&amp;d=1258638311">hijackthis.log</a> (9.7 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>bricoors</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878655-inability-get-autoupdates.html</guid>
		</item>
		<item>
			<title>Never Ending Errors</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878650-never-ending-errors.html</link>
			<pubDate>Thu, 19 Nov 2009 13:34:32 GMT</pubDate>
			<description>Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item. . . 
  
Getting the above error and no matter what i try nothing can fix it yet; tryed command start cmd; run normal / run as...</description>
			<content:encoded><![CDATA[<div>Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item. . .<br />
 <br />
Getting the above error and no matter what i try nothing can fix it yet; tryed command start cmd; run normal / run as admin / removed A V G  virus scan had hoped to get a better free scanner but can t thanks to the above error that just happened out the blue; i am the only user for this pc and the box for the normal use is greyed out and turning off the U A C doesn t help so what have i missed ! ?     Thanks to the above error can t download a dang thing i hope these logs help  -  thanks a bunch . . .<br />
 <br />
 <br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 8:11:48 AM, on 11/19/2009<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v7.00 (7.00.6002.18005)<br />
Boot mode: Normal<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\hp\support\hpsysdrv.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe<br />
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe<br />
C:\Program Files\Verizon\Online Backup &amp; Sharing\Auto Update\OnlineBackup.UpdateSystemTray.exe<br />
C:\Program Files\Verizon\McciTrayApp.exe<br />
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Program Files\Verizon\Online Backup &amp; Sharing\System Tray\OnlineBackup.SystemTray.exe<br />
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe<br />
C:\Program Files\Internet Explorer\IEUser.exe<br />
C:\Windows\system32\NOTEPAD.EXE<br />
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe<br />
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe<br />
C:\Windows\system32\NOTEPAD.EXE<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=91&amp;bd=bestbuy&amp;pf=cndt" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...estbuy&amp;pf=cndt</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.verizon.com/" target="_blank">http://www.verizon.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=91&amp;bd=bestbuy&amp;pf=cndt" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...estbuy&amp;pf=cndt</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=91&amp;bd=bestbuy&amp;pf=cndt" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...estbuy&amp;pf=cndt</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O1 - Hosts: 1 localhost<br />
O1 - Hosts: 8.5.0.53 hoylegames.sierra.com<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)<br />
O2 - BHO: IEHlprObj Class - {8CA5ED52-F3FB-4414-A105-2E3491156990} - C:\Program Files\iWin Games\iWinGamesHookIE.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Verizon Broadband Toolbar - {A057A204-BACC-4D26-8398-26FADCF27386} - C:\PROGRA~1\VERIZO~1\VERIZO~1.DLL<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\hssie\HssIE.dll<br />
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll<br />
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O3 - Toolbar: Verizon Broadband Toolbar - {A057A204-BACC-4D26-8398-26FADCF27386} - C:\PROGRA~1\VERIZO~1\VERIZO~1.DLL<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe<br />
O4 - HKLM\..\Run: [UpdateP2GoShortCut] &quot;c:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe&quot; &quot;c:\Program Files\CyberLink\Power2Go&quot; UpdateWithCreateOnce &quot;SOFTWARE\CyberLink\Power2Go\6.0&quot;<br />
O4 - HKLM\..\Run: [UpdatePDIRShortCut] &quot;c:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe&quot; &quot;c:\Program Files\CyberLink\PowerDirector&quot; UpdateWithCreateOnce &quot;SOFTWARE\CyberLink\PowerDirector\7.0&quot;<br />
O4 - HKLM\..\Run: [UpdatePSTShortCut] &quot;c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe&quot; &quot;c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe&quot; UpdateWithCreateOnce &quot;Software\CyberLink\PowerStarter&quot;<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [VerizonServicepoint.exe] &quot;C:\Program Files\Verizon\VSP\VerizonServicepoint.exe&quot; /AUTORUN<br />
O4 - HKLM\..\Run: [Online Backup Auto Update] &quot;C:\Program Files\Verizon\Online Backup &amp; Sharing\Auto Update\OnlineBackup.UpdateSystemTray.exe&quot;<br />
O4 - HKLM\..\Run: [Verizon_McciTrayApp] &quot;C:\Program Files\Verizon\McciTrayApp.exe&quot;<br />
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime Alternative\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] &quot;C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe&quot; /hide<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O4 - Global Startup: Online Backup Tray.lnk = ?<br />
O4 - Global Startup: PeerGuardian 2 Loader.lnk = C:\Program Files\PeerGuardian2\pg2loader.exe<br />
O8 - Extra context menu item: Download Video by Free YouTuBe Utility - C:\Program Files\Free YouTuBe Utility\IEydown.htm<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll<br />
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O13 - Gopher Prefix: <br />
O15 - Trusted IP range: <a href="http://192.168.1.1" target="_blank">http://192.168.1.1</a><br />
O15 - ESC Trusted IP range: <a href="http://192.168.1.1" target="_blank">http://192.168.1.1</a><br />
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - <a href="http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab" target="_blank">http://appldnld.apple.com.edgesuite....x/qtplugin.cab</a><br />
O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} (Hewlett-Packard Online Support Services) - <a href="https://h20364.www2.hp.com/CSMWeb/Customer/cabs/HPISDataManager.CAB" target="_blank">https://h20364.www2.hp.com/CSMWeb/Cu...ataManager.CAB</a><br />
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - <a href="https://wimpro2.cce.hp.com/ChatEntry/downloads/sysinfo.cab" target="_blank">https://wimpro2.cce.hp.com/ChatEntry...ds/sysinfo.cab</a><br />
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - <a href="http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab" target="_blank">http://h20270.www2.hp.com/ediags/gmn...Detection2.cab</a><br />
O16 - DPF: {A031D222-B496-11D2-9CC8-00105A10AAF6} - <a href="http://hoylegames.sierra.com/cab/WONWebLauncherControl.cab" target="_blank">http://hoylegames.sierra.com/cab/WON...herControl.cab</a><br />
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - <a href="http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab" target="_blank">http://wwwimages.adobe.com/www.adobe...bat/nos/gp.cab</a><br />
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - <a href="http://137.229.242.21/activex/AMC.cab" target="_blank">http://137.229.242.21/activex/AMC.cab</a><br />
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll<br />
O23 - Service: Filesystem Watcher (FilesystemWatcher) - DigiData Corp. - C:\Program Files\Verizon\Online Backup &amp; Sharing\Filesystem Watcher\DigiData.FilesystemWatcher.Service.Watcher.exe<br />
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe<br />
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe<br />
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe<br />
O23 - Service: Hotspot Shield Routing Service (HssSrv) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe<br />
O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE<br />
O23 - Service: iWinTrusted - iWin Inc. - C:\Program Files\iWin Games\iWinTrusted.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe<br />
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe<br />
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe<br />
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe<br />
O23 - Service: Online Armor Helper Service (OAcat) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\OAcat.exe<br />
O23 - Service: Online Backup Communication Server (OnlineBackupCommFrameworkService) - Unknown owner - C:\Program Files\Verizon\Online Backup &amp; Sharing\Communication\OnlineBackup.CommunicationFrameworkService.exe<br />
O23 - Service: Online Backup Scheduler (OnlineBackupSchedulerService) - Unknown owner - C:\Program Files\Verizon\Online Backup &amp; Sharing\Scheduler\OnlineBackup.SchedulerService.exe<br />
O23 - Service: Verizon PC Security Checkup Service (Radialpoint Security Services) - Verizon - C:\Program Files\Verizon\PC Security Checkup\RpsSecurityAwareR.exe<br />
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search &amp; Destroy\SDWinSec.exe<br />
O23 - Service: Online Armor (SvcOnlineArmor) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\oasrv.exe<br />
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe<br />
O23 - Service: DigiData Vault Proxy Service (VaultProxy) - DigiData Corp. - C:\Program Files\Verizon\Online Backup &amp; Sharing\DigiData.Vault.VaultExplorer.Service.exe<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe<br />
--<br />
End of file - 12587 bytes</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>LeftBehind</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878650-never-ending-errors.html</guid>
		</item>
		<item>
			<title>wuauclt.exe using 99% of pc</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878647-wuauclt-exe-using-99-pc.html</link>
			<pubDate>Thu, 19 Nov 2009 13:17:07 GMT</pubDate>
			<description>I have a problem with wuauclt.exe on my PC it cannot be removed and cannot be stopped in task manager. well it can but it reappears 2 seconds later. I originally had a virus called zwunzi on there. I downloaded and updated malwarebytes Malware...</description>
			<content:encoded><![CDATA[<div>I have a problem with wuauclt.exe on my PC it cannot be removed and cannot be stopped in task manager. well it can but it reappears 2 seconds later. I originally had a virus called zwunzi on there. I downloaded and updated malwarebytes Malware remover, this removed zwunzi only for me to find out the real problem was wuauclt. it is using all my pc's ram, memory and 90 percent of my internet connection. It constantly downloads and I cant block it. it is now in the last 30 minutes started disabling my firewall and my avira antivirus free. I am trying to find a way to remove this manually as i cannot afford a program to remove it. P.S this has been happening for about a week with the processing power anyway that was the only simptom until yesterday.<br />
<br />
thankyou very much hi-jackthis log below<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 3:36:01 PM, on 18/11/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\System32\igfxtray.exe<br />
C:\WINDOWS\System32\hkcmd.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe<br />
C:\Program Files\Microsoft IntelliType Pro\itype.exe<br />
C:\Program Files\Microsoft IntelliPoint\ipoint.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Documents and Settings\alyssa\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\WINDOWS\system32\taskmgr.exe<br />
C:\Documents and Settings\alyssa\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\Documents and Settings\alyssa\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Program Files\Outlook Express\msimn.exe<br />
C:\Program Files\Messenger\msmsgs.exe<br />
C:\Documents and Settings\alyssa\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.facebook.com/" target="_blank">http://www.facebook.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe<br />
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start<br />
O4 - HKLM\..\Run: [itype] &quot;C:\Program Files\Microsoft IntelliType Pro\itype.exe&quot;<br />
O4 - HKLM\..\Run: [IntelliPoint] &quot;C:\Program Files\Microsoft IntelliPoint\ipoint.exe&quot;<br />
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
O4 - HKLM\..\Run: [avgnt] &quot;C:\Program Files\Avira\AntiVir Desktop\avgnt.exe&quot; /min<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br />
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKCU\..\RunOnce: [UniblueRegistryBooster] &quot;C:\Program Files\Uniblue\RegistryBooster\launcher.exe&quot; delay 20000<br />
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')<br />
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm<br />
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm<br />
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm<br />
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Send To &amp;Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a href="http://go.microsoft.com/fwlink/?linkid=39204" target="_blank">http://go.microsoft.com/fwlink/?linkid=39204</a><br />
O17 - HKLM\System\CCS\Services\Tcpip\..\{90B61B93-0EDC-431E-8A61-3D35D9F05E8F}: NameServer = 203.49.70.20 139.134.2.190<br />
O21 - SSODL: SysTray - {E61B5E20-DE35-11CF-9C87-1579789127E1} - C:\WINDOWS\system32\csrss.cpl (file missing)<br />
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe<br />
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe<br />
<br />
--<br />
End of file - 6415 bytes</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>BreNNoX</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878647-wuauclt-exe-using-99-pc.html</guid>
		</item>
		<item>
			<title><![CDATA[Windows Vista going nuts, unstoppable multiple "enter" key strokes]]></title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878638-windows-vista-going-nuts-unstoppable.html</link>
			<pubDate>Thu, 19 Nov 2009 12:03:06 GMT</pubDate>
			<description><![CDATA[Hi, really hoping someone can help. 
  
With increasing regularity, my pc is behaving as if the "enter"key is bing held down, e.g. 
On launching IE8, multiple screens will open 
On deleting an address book entry from Outlook, the PC continued to...]]></description>
			<content:encoded><![CDATA[<div>Hi, really hoping someone can help.<br />
 <br />
With increasing regularity, my pc is behaving as if the &quot;enter&quot;key is bing held down, e.g.<br />
On launching IE8, multiple screens will open<br />
On deleting an address book entry from Outlook, the PC continued to delete until the entire address book was emptied.<br />
This can happen at startup or any other time.<br />
Have scanned before &amp; since this problem with Norton 360, restored to an earlier version of my set-up, changed keyboard &amp; mouse.<br />
My only fix has been a forced shutdown and reboot, which workis about half the time. <br />
 <br />
I found Pantom0o10's earlier posts on similar topics and folowed the advice re: hijackthis. My logfile is below...<br />
 <br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 19:22:00, on 19/11/2009<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18828)<br />
Boot mode: Normal<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\Explorer.EXE<br />
C:\hp\support\hpsysdrv.exe<br />
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe<br />
C:\WINDOWS\RtHDVCpl.exe<br />
C:\Windows\system32\schtasks.exe<br />
C:\Program Files\HP\HP Officejet Pro K550 Series\Toolbox\HPWUTBX.exe<br />
C:\WINDOWS\System32\rundll32.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Logitech\QuickCam\Quickcam.exe<br />
C:\Program Files\HP\HP Software Update\hpwuschd2.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\WINDOWS\ehome\ehtray.exe<br />
C:\Program Files\Tracks Eraser\te.exe<br />
C:\Program Files\Genie-Soft\GBMHome8\GBMAgent.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\WINDOWS\System32\rundll32.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe<br />
C:\hp\kbd\kbd.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = <a href="http://local.swarmcast.net:8001/proxy.pac" target="_blank">http://local.swarmcast.net:8001/proxy.pac</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll<br />
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll<br />
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe<br />
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE<br />
O4 - HKLM\..\Run: [OsdMaestro] &quot;C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe&quot;<br />
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateReg] &quot;C:\Windows\system32\jureg.exe&quot;<br />
O4 - HKLM\..\Run: [HPWUTOOLBOX] C:\Program Files\HP\HP Officejet Pro K550 Series\Toolbox\HPWUTBX.exe &quot;-i&quot;<br />
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe<br />
O4 - HKLM\..\Run: [GBMHome8Agent] C:\Program Files\Genie-Soft\GBMHome8\GBMAgent.exe<br />
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon<br />
O4 - HKLM\..\Run: [snpstd] C:\Windows\vsnpstd.exe<br />
O4 - HKLM\..\Run: [ccApp] &quot;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&quot;<br />
O4 - HKLM\..\Run: [osCheck] &quot;C:\Program Files\Norton 360\osCheck.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] &quot;C:\Program Files\Logitech\QuickCam\Quickcam.exe&quot; /hide<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [Tracks Eraser] C:\Program Files\Tracks Eraser\te.exe min<br />
O4 - HKCU\..\Run: [GBMHome8Agent] C:\Program Files\Genie-Soft\GBMHome8\GBMAgent.exe<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - <a href="https://hkg-pxy02.insidemedia.net/whalecom0863e9d572ac8ea50aec673b5b2d55be95fa5dcf81e70d590a/whalecom0/dwa7W.cab" target="_blank">https://hkg-pxy02.insidemedia.net/wh...com0/dwa7W.cab</a><br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe<br />
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe<br />
O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe<br />
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE<br />
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe<br />
O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe<br />
O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe<br />
O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe<br />
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe<br />
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe<br />
O23 - Service: SmartProtection Agent Service (SmartProtection Service) - Unknown owner - C:\Program Files\SmartProtectionUSB\SmartProtectionService.exe<br />
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe<br />
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe<br />
--<br />
End of file - 10338 bytes<br />
:eek:</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>strats</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878638-windows-vista-going-nuts-unstoppable.html</guid>
		</item>
		<item>
			<title>AVG wont work Safety shield now poping up</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878611-avg-wont-work-safety-shield.html</link>
			<pubDate>Thu, 19 Nov 2009 09:19:56 GMT</pubDate>
			<description>Installed AVG yesterday, now it is telling me the anti-virus and spyware database is out of date, web shield and resident shield not active. Will stry to download new updates but at the last moment it states download failed. 
Also every time I...</description>
			<content:encoded><![CDATA[<div>Installed AVG yesterday, now it is telling me the anti-virus and spyware database is out of date, web shield and resident shield not active. Will stry to download new updates but at the last moment it states download failed.<br />
Also every time I restart my computer a program called safety shield anti-virus is re-installed on my computer. keeps poping up with warnings and links to buy the program. I delete it from my program files but it keeps reappering every time i restart.<br />
I'm at my wits end</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>hey_louis</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878611-avg-wont-work-safety-shield.html</guid>
		</item>
		<item>
			<title>keylogger?</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878607-keylogger.html</link>
			<pubDate>Thu, 19 Nov 2009 08:31:06 GMT</pubDate>
			<description>PLEASE HELP! i asked last time to no avail, come on guys, please :) thanks to all 
  
Logfile of HijackThis v1.99.1 
Scan saved at 7:29:33 PM, on 19/11/2009 
Platform: Unknown Windows (WinNT 6.00.1906 SP2) 
MSIE: Internet Explorer v8.00...</description>
			<content:encoded><![CDATA[<div>PLEASE HELP! i asked last time to no avail, come on guys, please :) thanks to all<br />
 <br />
Logfile of HijackThis v1.99.1<br />
Scan saved at 7:29:33 PM, on 19/11/2009<br />
Platform: Unknown Windows (WinNT 6.00.1906 SP2)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18828)<br />
 <br />
Running processes:<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\ASUS\GamerOSD\GamerOSD.exe<br />
C:\Windows\RtHDVCpl.exe<br />
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe<br />
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe<br />
C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe<br />
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe<br />
C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Windows\system32\conime.exe<br />
C:\Program Files\Windows Media Player\wmplayer.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\Program Files\Windows Live\Contacts\wlcomm.exe<br />
C:\program files\mozilla firefox\firefox.exe<br />
C:\Windows\SYSTEM32\WISPTIS.EXE<br />
C:\Program Files\Hijackthis\HijackThis.exe<br />
 <br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll<br />
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll<br />
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll<br />
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll<br />
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [ASUSGamerOSD] C:\Program Files\ASUS\GamerOSD\GamerOSD.exe<br />
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br />
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] &quot;C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe&quot; -launchedbylogin<br />
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] &quot;C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] &quot;C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe_ID0ENQBO] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE<br />
O4 - HKLM\..\Run: [GrooveMonitor] &quot;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&quot;<br />
O4 - HKLM\..\Run: [Corel File Shell Monitor] C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe<br />
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe<br />
O4 - HKLM\..\Run: [avgnt] &quot;C:\Program Files\Avira\AntiVir Desktop\avgnt.exe&quot; /min<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\Run: [Corel Photo Downloader] &quot;C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe&quot; -startup<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
O4 - HKCU\..\Run: [msnmsgr] &quot;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&quot; /background<br />
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe<br />
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll<br />
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll<br />
O11 - Options group: [INTERNATIONAL] International<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll<br />
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL<br />
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll<br />
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL<br />
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL<br />
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL<br />
O23 - Service: Adobe Version Cue CS4 - Unknown owner - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe&quot; -win32service (file missing)<br />
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
O23 - Service: ATK Fast User Switch Service (ATKFUSService) - ASUSTeK COMPUTER INC. - C:\Windows\system32\ATKFUSService.exe<br />
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)<br />
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe<br />
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe<br />
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe<br />
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe<br />
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>dillemma</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878607-keylogger.html</guid>
		</item>
		<item>
			<title>Novice Computer user. need help to remove virus/trojan!</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878605-novice-computer-user-need-help.html</link>
			<pubDate>Thu, 19 Nov 2009 08:12:02 GMT</pubDate>
			<description><![CDATA[Hi i need help to remove this thing on my computer called "ÖØÒª×ÊÁÏ.exe (http://www.computing.net/process/%C3%96%C3%98%C3%92%C2%AA%C3%97%C3%8A%C3%81%C3%8F)" everytime i try to delete it it reappears. Ocassionally theres also a random popup that...]]></description>
			<content:encoded><![CDATA[<div>Hi i need help to remove this thing on my computer called &quot;<a href="http://www.computing.net/process/%C3%96%C3%98%C3%92%C2%AA%C3%97%C3%8A%C3%81%C3%8F" target="_blank">ÖØÒª×ÊÁÏ.exe</a>&quot; everytime i try to delete it it reappears. Ocassionally theres also a random popup that directs me to a website called &quot;www.ctv...something&quot;, and it also spams heaps of it once in a while - so i have to use task manager to end iexplorer.<br />
<br />
When i go to my task manager list...i also see programs such as &quot;severe.exe&quot;, &quot;conime.exe&quot;, and when i try to end process it just automatically reappears<br />
<br />
<br />
PLEASEEE, can anyone explain in simple terms how to remove it. Im a beginner with computers but would really appreciate it if someone can help me remove this stupid thing.<br />
<br />
Kind Regards,<br />
David</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>citrusjuice</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878605-novice-computer-user-need-help.html</guid>
		</item>
		<item>
			<title>Cpu at 100%</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878593-cpu-100-a.html</link>
			<pubDate>Thu, 19 Nov 2009 05:41:17 GMT</pubDate>
			<description>any help would be appreciated 
fred 
  
Logfile of HijackThis v1.99.0 
Scan saved at 12:32:33 AM, on 11/19/2009 
Platform: Windows XP SP2 (WinNT 5.01.2600) 
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) 
Running processes:...</description>
			<content:encoded><![CDATA[<div>any help would be appreciated<br />
fred<br />
 <br />
Logfile of HijackThis v1.99.0<br />
Scan saved at 12:32:33 AM, on 11/19/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe<br />
C:\Program Files\Project Lab\DDS\DDS.EXE<br />
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe<br />
C:\WINDOWS\system32\bgsvcgen.exe<br />
C:\WINDOWS\system32\CTSvcCDA.EXE<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe<br />
C:\WINDOWS\system32\PnkBstrA.exe<br />
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe<br />
C:\Program Files\Unlocker\UnlockerAssistant.exe<br />
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe<br />
C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe<br />
C:\Program Files\Cyberlink\Shared Files\brs.exe<br />
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe<br />
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\MsPMSPSv.exe<br />
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe<br />
C:\WINDOWS\system32\CTHELPER.EXE<br />
C:\Program Files\Messenger\msmsgs.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\ATI Multimedia\main\ATIDtct.EXE<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Program Files\Electronic Arts\EADM\Core.exe<br />
C:\Program Files\palmOne\Hotsync.exe<br />
C:\Program Files\palmOne\LifeDriveMgrTray.exe<br />
C:\Program Files\palmOne\PalmOneLiveConnect.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\WINDOWS\system32\taskmgr.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\shredder for iexplorer\Hijack this\HijackThis.exe<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll<br />
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll<br />
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent<br />
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r<br />
O4 - HKLM\..\Run: [CCD Manager] &quot;C:\Program Files\Project Lab\DDS\DDS.EXE&quot;<br />
O4 - HKLM\..\Run: [AVP] &quot;C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe&quot;<br />
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe<br />
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe<br />
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] &quot;C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe&quot;<br />
O4 - HKLM\..\Run: [UnlockerAssistant] &quot;C:\Program Files\Unlocker\UnlockerAssistant.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] &quot;C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] &quot;C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe&quot;<br />
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe<br />
O4 - HKLM\..\Run: [RemoteControl9] &quot;C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe&quot;<br />
O4 - HKLM\..\Run: [PDVD9LanguageShortcut] &quot;C:\Program Files\CyberLink\PowerDVD9\Language\Language.exe&quot;<br />
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe<br />
O4 - HKLM\..\Run: [EPSON Stylus Photo R320 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9FA.EXE /P30 &quot;EPSON Stylus Photo R320 Series&quot; /O6 &quot;USB003&quot; /M &quot;Stylus Photo R320&quot;<br />
O4 - HKLM\..\Run: [Google Quick Search Box] &quot;C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe&quot;  /autorun<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r<br />
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE<br />
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL<br />
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE<br />
O4 - HKCU\..\Run: [MSMSGS] &quot;C:\Program Files\Messenger\msmsgs.exe&quot; /background<br />
O4 - HKCU\..\Run: [PopRock] C:\DOCUME~1\FRED~1.FRE\LOCALS~1\Temp\a.exe<br />
O4 - HKCU\..\Run: [AlcoholAutomount] &quot;C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe&quot; /automount<br />
O4 - HKCU\..\Run: [NordBull] C:\WINDOWS\msb.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;<br />
O4 - HKCU\..\Run: [EA Core] &quot;C:\Program Files\Electronic Arts\EADM\Core.exe&quot; -silent<br />
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br />
O4 - Startup: LifeDrive™ Manager.lnk = C:\Program Files\palmOne\LifeDriveMgrTray.exe<br />
O4 - Startup: palmOne Registration.lnk = C:\Program Files\palmOne\register.exe<br />
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe<br />
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm<br />
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html<br />
O9 - Extra button: &amp;Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\WINDOWS\system32\shdocvw.dll<br />
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\dtv\EXPLBAR.DLL<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: URLs c&amp;heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\WINDOWS\system32\shdocvw.dll<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O12 - Plugin for .php: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll<br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2\kloehk.dll acaptuser32.dll<br />
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll<br />
O23 - Service: Acronis Scheduler2 Service - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe<br />
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe<br />
O23 - Service: Kaspersky Internet Security - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe<br />
O23 - Service: B's Recorder GOLD Library General Service - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe<br />
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.EXE<br />
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: Google Software Updater - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe<br />
O23 - Service: PnkBstrA - Unknown - C:\WINDOWS\system32\PnkBstrA.exe<br />
O23 - Service: Start BT in service - Unknown - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe<br />
O23 - Service: StarWind AE Service - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>fred1029</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878593-cpu-100-a.html</guid>
		</item>
		<item>
			<title>Small Box : An Error Has Occurred in Internet Explorer.</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878590-small-box-error-has-occurred.html</link>
			<pubDate>Thu, 19 Nov 2009 05:28:15 GMT</pubDate>
			<description>Hey, Tech Guy . Will you please help mee. 
 
well i am having some troubles with my computer , because every now and then i try to open any kind of folder (Including: my Documents, my pictures, my music.) it appears an annoying small box telling me:...</description>
			<content:encoded><![CDATA[<div>Hey, Tech Guy . Will you please help mee.<br />
<br />
well i am having some troubles with my computer , because every now and then i try to open any kind of folder (Including: my Documents, my pictures, my music.) it appears an annoying small box telling me: &quot;An Error Has Occurred in Internet Explorer. Internet Explorer Will Now Close. If You Continue To Experience Problems, Please Restart The Computer&quot; ( I had Restarted the Computer a Lot Of Times!!).  I've thought it's a virus ( But i really don't know!!). I've tried Hijackthis but when i download it when i try to open the folder it appears the same annoying small box message. I've tried to eliminate my Internet Explorer but it happens the same cause i can't open any kind of folder. I still can open my mozilla fox browser.</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>mistery</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878590-small-box-error-has-occurred.html</guid>
		</item>
		<item>
			<title>Blank popup page appears every 1 minute while in google mail</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878571-blank-popup-page-appears-every.html</link>
			<pubDate>Thu, 19 Nov 2009 03:07:43 GMT</pubDate>
			<description><![CDATA[While running google mail, I am getting a popup page appearing every 1 minute or so.   The page is blank - for the most part - it only says "Copywrite 2002-2009 Google Inc."   
  
This only happens while logged into gmail and at no other time.  ...]]></description>
			<content:encoded><![CDATA[<div>While running google mail, I am getting a popup page appearing every 1 minute or so.   The page is blank - for the most part - it only says &quot;Copywrite 2002-2009 Google Inc.&quot;  <br />
 <br />
This only happens while logged into gmail and at no other time.   This began on Monday this week.   Prior to this, we've experienced no issues running this on this computer.  I've ran gmail on other pc's in the house, since this started occuring, and do not experience any of the same issues.<br />
 <br />
the URL of the popup page is:<br />
 <br />
<a href="http://mail.google.com/a/sweetpsweets.com/?ui=2&amp;view=js&amp;name=js&amp;ver=Jd8O_KZeLH0.en.&amp;am=!Sg304q2GSliZBb_iwfc6WlbSTz3e8mG8Q_I47nYY4DQE#http://b.mail.google.com/a/sweetpsweets.com/channel/test?VER=6&amp;it=13750&amp;at=xn3j34hncs4zpq1p4s42kg3ivninit&amp;TYPE=html&amp;zx=jftn7ke6h7jv&amp;DOMAIN=mail.google.com&amp;t=1" target="_blank">http://mail.google.com/a/sweetpsweet...google.com&amp;t=1</a><br />
 <br />
We are running Window XP HE with service pack 3 and IE version 8 and am running McAfee Internet Security Suite for virus protection.  The last full system scan I ran yesterday, turned up no virus.<br />
 <br />
Here is a copy of my HJT log - - I'm not certain its a virus, however nothing else I have run to scan this pc has turned up anything.  Overall, the system performance on this PC is extreamly slow - - so there may be other things in here as well.   Primarily this is the kids PC - so who knows what things they may have clicked on while browsing our wonderful WWW.   Please help if you can.<br />
 <br />
Thanks<br />
 <br />
HJT Log:<br />
 <br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 8:39:44 PM, on 11/18/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe<br />
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe<br />
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br />
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
C:\WINDOWS\System32\nvsvc32.exe<br />
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe<br />
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe<br />
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe<br />
c:\PROGRA~1\mcafee.com\agent\mcagent.exe<br />
C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe<br />
C:\WINDOWS\BCMSMMSG.exe<br />
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe<br />
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\PROGRA~1\Yahoo!\browser\ycommon.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe<br />
C:\WINDOWS\System32\wbem\wmiapsrv.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\WINDOWS\SoftwareDistribution\Download\Install\SQLServer2005ExpressSP3-KB955706-x86-ENU.exe<br />
h:\6c03686b68991bbda9c977b779\hotfix.exe<br />
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe<br />
C:\WINDOWS\System32\msiexec.exe<br />
C:\WINDOWS\System32\dllhost.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
h:\6c03686b68991bbda9c977b779\HotFixExpress\Files\SQLEXPR.EXE<br />
h:\b0e450ae855997ef9a\setup.exe<br />
C:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\setup.exe<br />
C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe<br />
C:\WINDOWS\System32\MsiExec.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Documents and Settings\Asken Family\Local Settings\Temporary Internet Files\Content.IE5\QT7IEQP1\HijackThis[1].exe<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.yahoo.com/" target="_blank">http://www.yahoo.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll<br />
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll<br />
O2 - BHO: EWPBrowseObject Class - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll<br />
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll<br />
O2 - BHO: Easy Gif Animator Toolbar Helper - {96372AB6-15EB-4316-B497-71C741BC548C} - C:\Program Files\Easy Gif Animator Extension\v3.3.0.2\EasyGifAnimator_Toolbar.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll<br />
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll<br />
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O3 - Toolbar: Easy Gif Animator Toolbar - {35065594-9169-4A34-B167-FC4865038E53} - C:\Program Files\Easy Gif Animator Extension\v3.3.0.2\EasyGifAnimator_Toolbar.dll<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe<br />
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe<br />
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe<br />
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon<br />
O4 - HKLM\..\Run: [SSBkgdUpdate] &quot;C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe&quot; -Embedding -boot<br />
O4 - HKLM\..\Run: [OpwareSE4] &quot;C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [Symantec PIF AlertEng] &quot;C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe&quot; /a /m &quot;C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll&quot;<br />
O4 - HKLM\..\Run: [HotSync] &quot;C:\Program Files\PalmSource\Desktop\HotSync.exe&quot; -AllUsers<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [mcagent_exe] &quot;C:\Program Files\McAfee.com\Agent\mcagent.exe&quot; /runkey<br />
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide<br />
O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;  -osboot<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
O4 - HKCU\..\Run: [ResChanger2004] NONE<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;<br />
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1<br />
O4 - HKCU\..\Run: [TomTomHOME.exe] &quot;C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe&quot;<br />
O4 - HKCU\..\Run: [PopRock] C:\DOCUME~1\ASKENF~1\LOCALS~1\Temp\b.exe<br />
O4 - HKCU\..\Run: [DWQueuedReporting] &quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&quot; -t<br />
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1100465 -&quot;Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; GTB6; InfoPath.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)&quot; -&quot;<a href="http://www.hotwheels.com/games/motox/index.aspx" target="_blank">http://www.hotwheels.com/games/motox/index.aspx</a>&quot;<br />
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] &quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&quot; -t (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] &quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&quot; -t (User 'Default user')<br />
O4 - Startup: PowerReg Scheduler V3.exe<br />
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\Palm\Hotsync.exe<br />
O4 - Global Startup: Smart Wizard Wireless Settings.lnk = ?<br />
O8 - Extra context menu item: &amp;Search - <a href="http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZKxdm021NUUS" target="_blank">http://edits.mywebsearch.com/toolbar...p=ZKxdm021NUUS</a><br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html<br />
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html<br />
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html<br />
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html<br />
O8 - Extra context menu item: Namo SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm<br />
O9 - Extra button: AT&amp;T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\WINDOWS\System32\shdocvw.dll<br />
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\WINDOWS\System32\shdocvw.dll<br />
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)<br />
O9 - Extra button: Namo SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm<br />
O9 - Extra 'Tools' menuitem: Namo SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - <a href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" target="_blank">http://upload.facebook.com/controls/...oUploader5.cab</a><br />
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - <a href="http://download.ewido.net/ewidoOnlineScan.cab" target="_blank">http://download.ewido.net/ewidoOnlineScan.cab</a><br />
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - <a href="http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-3/WebfettiInitialSetup1.0.1.0.cab" target="_blank">http://ak.exe.imgfarm.com/images/noc...tup1.0.1.0.cab</a><br />
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - <a href="http://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/citrix/wficat-no-eula.cab" target="_blank">http://a516.g.akamai.net/f/516/25175...at-no-eula.cab</a><br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll<br />
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - <a href="http://disney.go.com/pirates/online/testActiveX/built/signed/DisneyOnlineGames.cab" target="_blank">http://disney.go.com/pirates/online/...nlineGames.cab</a><br />
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - <a href="https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab" target="_blank">https://www-secure.symantec.com/tech...bs/tgctlsr.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1156013257654" target="_blank">http://update.microsoft.com/microsof...?1156013257654</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1156013249138" target="_blank">http://update.microsoft.com/microsof...?1156013249138</a><br />
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - <a href="http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab" target="_blank">http://upload.facebook.com/controls/...Uploader55.cab</a><br />
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - <a href="http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab" target="_blank">http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll<br />
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)<br />
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll<br />
O23 - Service: McAfee Application Installer Cleanup (0126721258553532) (0126721258553532mcinstcleanup) - McAfee, Inc. - C:\WINDOWS\TEMP\012672~1.EXE<br />
O23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (file missing)<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe<br />
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br />
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe<br />
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe<br />
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br />
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe<br />
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe<br />
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe<br />
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe<br />
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe<br />
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
--<br />
End of file - 17686 bytes</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>rba1122</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878571-blank-popup-page-appears-every.html</guid>
		</item>
		<item>
			<title>Just cleaned up a Security Tool infection and PC is still SLOWWWW</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878567-just-cleaned-up-security-tool.html</link>
			<pubDate>Thu, 19 Nov 2009 02:49:14 GMT</pubDate>
			<description><![CDATA[Hi Guys, 
 
I just cleaned Security Tool off a friends computer but the thing is going SLOWWWW! I'm wondering if there's still bad some stuff left on it. Unrelated(?) problem - this thing's been having network problems and when I went into the...]]></description>
			<content:encoded><![CDATA[<div>Hi Guys,<br />
<br />
I just cleaned Security Tool off a friends computer but the thing is going SLOWWWW! I'm wondering if there's still bad some stuff left on it. Unrelated(?) problem - this thing's been having network problems and when I went into the network diagnostics to look at a network log file, instead of a log file coming up, Dreamweaver CS3 popped up and said that the trial was expired and prompted for the software key.<br />
<br />
<br />
Pasting the hjt logs in replies, starting with the startup log</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>BanditFlyer</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878567-just-cleaned-up-security-tool.html</guid>
		</item>
		<item>
			<title>IE slow with pop-ups - believe I have a virus!</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878562-ie-slow-pop-ups-believe.html</link>
			<pubDate>Thu, 19 Nov 2009 02:25:42 GMT</pubDate>
			<description>Hi, 
I downloaded a file and since opening it have had problems with IE.  pop ups constantly appearing etc. I know - my bad. 
I have Nortons 360 and have performed multiple scans but it is not detecting anything other than a cookie.  Cookie is...</description>
			<content:encoded><![CDATA[<div>Hi,<br />
I downloaded a file and since opening it have had problems with IE.  pop ups constantly appearing etc. I know - my bad.<br />
I have Nortons 360 and have performed multiple scans but it is not detecting anything other than a cookie.  Cookie is quarantined, but when I run another scan another cookie if found and so on and so forth.  The virus is also preventing me from accessing the support option on Norton's<br />
I have changed my Privacy tab on Internet Options to block all cookies and pop-up blocker was already turned on but still getting pop-ups.<br />
On searching google for advice it recommended I run hijackthis and post log which I have attached.<br />
 <br />
I have an HP Intel Pentium Dual CPU E2180 @ 2.00 GHz runting Microsoft Windows XP Media Centre Edition Version 2002 SP3<br />
 <br />
Hope you can help as I'm not sure what else to do.<br />
Many thanks,</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://static.techguy.org/v38/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="{attachment-server}attachment.php?attachmentid=159787&amp;d=1258597475">hijackthis.log</a> (12.5 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>cinderella99999</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878562-ie-slow-pop-ups-believe.html</guid>
		</item>
		<item>
			<title>new type of rootkit????</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878556-new-type-rootkit.html</link>
			<pubDate>Thu, 19 Nov 2009 02:04:18 GMT</pubDate>
			<description>My desktop got hit again and I was wondering if anyone has seen this type of filechk.000 file recovery before. My daughter was reading the blue screen of death error message to me over the phone as I was at work. 
She mention that the error was for...</description>
			<content:encoded><![CDATA[<div>My desktop got hit again and I was wondering if anyone has seen this type of filechk.000 file recovery before. My daughter was reading the blue screen of death error message to me over the phone as I was at work.<br />
She mention that the error was for a NTFS file error. <br />
My computers all use fat-32 file sytems. <br />
This is what got my attention.<br />
What happens is this, when I boot up the computer, the screen goes blank. Absolutely no video. this even occurs in safemode.<br />
But I can view the drive and scan it.<br />
When I do scan the drive, the scan process freezes up when it hits certain dll files in the windows\system32 subfolder.<br />
Anyone have any ideas?<br />
 <br />
<a href="http://img690.imageshack.us/img690/3976/filechk000.png" target="_blank">http://img690.imageshack.us/img690/3976/filechk000.png</a></div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>wannabeageek</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878556-new-type-rootkit.html</guid>
		</item>
		<item>
			<title>Acting like a virus but virus scan not detecting anything</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878552-acting-like-virus-but-virus.html</link>
			<pubDate>Thu, 19 Nov 2009 01:35:01 GMT</pubDate>
			<description>My computer is acting weird and I suspect it has a virus...BUT I run norton and it says it has no viruses...what else can I do to find them?</description>
			<content:encoded><![CDATA[<div>My computer is acting weird and I suspect it has a virus...BUT I run norton and it says it has no viruses...what else can I do to find them?</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>aprilstorm</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878552-acting-like-virus-but-virus.html</guid>
		</item>
		<item>
			<title>Please Reveiw my Hijack This review i got some bad pops and invisble talking ads HELP</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878544-please-reveiw-my-hijack-review.html</link>
			<pubDate>Thu, 19 Nov 2009 00:27:32 GMT</pubDate>
			<description>Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 5:26:46 PM Thomas, on 11/18/2009 
Platform: Windows XP SP3 (WinNT 5.01.2600) 
MSIE: Internet Explorer v8.00 (8.00.6001.18702) 
Boot mode: Normal 
 
Running processes:...</description>
			<content:encoded><![CDATA[<div>Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 5:26:46 PM Thomas, on 11/18/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\SYSTEM32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe<br />
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\System32\nvsvc32.exe<br />
C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\PnkBstrA.exe<br />
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
c:\WINDOWS\system32\ZuneBusEnum.exe<br />
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe<br />
C:\Program Files\Microsoft Windows OneCare Live\winss.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\WINDOWS\system32\RUNDLL32.EXE<br />
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br />
C:\Program Files\Belkin\F5D7050v3\Belkinwcui.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe<br />
C:\WINDOWS\System32\regsvr32.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Zune\ZuneLauncher.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files\DNA\btdna.exe<br />
C:\Program Files\uTorrent\uTorrent.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe<br />
C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe<br />
C:\Documents and Settings\Blair\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\WINDOWS\system32\calc.exe<br />
C:\WINDOWS\system32\calc.exe<br />
C:\Documents and Settings\Blair\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\Documents and Settings\Blair\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://www.yahoo.com/?fr=fp-yie8" target="_blank">http://www.yahoo.com/?fr=fp-yie8</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.ask.com?o=15153&amp;l=dis" target="_blank">http://www.ask.com?o=15153&amp;l=dis</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\twext.exe,<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: MessengerUpdate - {5948A52A-BA3A-49A8-BCAF-D578502BDA9D} - C:\Documents and Settings\Blair\Application Data\Messenger\Drivers\MsgUpdate.dll<br />
O2 - BHO: gooochi browser enhancer - {C1BE886E-24B7-BA6C-B588-8A0204E07F42} - C:\WINDOWS\system32\zacvkghkoiknhspx.dll<br />
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: (no name) - {6A52539E-43B5-41D3-A6EE-08D0D423C33F} - (no file)<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [Windows Defender] &quot;C:\Program Files\Windows Defender\MSASCui.exe&quot; -hide<br />
O4 - HKLM\..\Run: [ISUSScheduler] &quot;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&quot; -start<br />
O4 - HKLM\..\Run: [F5D7050v3] C:\Program Files\Belkin\F5D7050v3\Belkinwcui.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [OneCareUI] &quot;C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe&quot;<br />
O4 - HKLM\..\Run: [mxjlixtphbztkos] C:\WINDOWS\System32\regsvr32.exe /s &quot;C:\WINDOWS\system32\zacvkghkoiknhspx.dll&quot;<br />
O4 - HKLM\..\Run: [Zune Launcher] &quot;c:\Program Files\Zune\ZuneLauncher.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKCU\..\Run: [Messenger (Yahoo!)] &quot;C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe&quot; -quiet<br />
O4 - HKCU\..\Run: [Google Update] &quot;C:\Documents and Settings\Blair\Local Settings\Application Data\Google\Update\GoogleUpdate.exe&quot; /c<br />
O4 - HKCU\..\Run: [BitTorrent DNA] &quot;C:\Program Files\DNA\btdna.exe&quot;<br />
O4 - HKCU\..\Run: [uTorrent] &quot;C:\Program Files\uTorrent\uTorrent.exe&quot;<br />
O4 - HKCU\..\Run: [IgfxSys] rundll32.exe &quot;C:\Documents and Settings\Blair\Application Data\Messenger\Drivers\IgfxSys.dll&quot;,StartProtector<br />
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103472 -&quot;Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; yie8)&quot; -&quot;http://www.shockwave.com/contentPlay/shockwave.jsp?dwin=1&amp;id=jigsawpuzzles&quot;<br />
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] &quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&quot; -t (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] &quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&quot; -t (User 'Default user')<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Risk/Images/stg_drm.ocx<br />
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - <a href="http://lads.myspace.com/upload/MySpaceUploader1006.cab" target="_blank">http://lads.myspace.com/upload/MySpaceUploader1006.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1226270518125" target="_blank">http://www.update.microsoft.com/wind...?1226270518125</a><br />
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - <a href="http://download.shockwave.com/pub/otoy/OTOYAX.cab" target="_blank">http://download.shockwave.com/pub/otoy/OTOYAX.cab</a><br />
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} (MySpace Uploader Control) - <a href="http://lads.myspace.com/upload/MySpaceUploader2.cab" target="_blank">http://lads.myspace.com/upload/MySpaceUploader2.cab</a><br />
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Risk/Images/armhelper.ocx<br />
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - <br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O20 - AppInit_DLLs: C:\WINDOWS\System32\d3d832.dll<br />
O20 - Winlogon Notify: 40ac760b511 - C:\WINDOWS\System32\d3d832.dll (file missing)<br />
O20 - Winlogon Notify: __c00AFAE5 - C:\WINDOWS\<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Belkin Wireless USB Network Adapter (Belkin Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Google Update Service (gupdate1ca1ec1eef47500) (gupdate1ca1ec1eef47500) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe<br />
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe<br />
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
<br />
--<br />
End of file - 9654 bytes</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>blairthomas</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878544-please-reveiw-my-hijack-review.html</guid>
		</item>
		<item>
			<title>Urgent malware removal help. Please!!</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878543-urgent-malware-removal-help-please.html</link>
			<pubDate>Thu, 19 Nov 2009 00:12:08 GMT</pubDate>
			<description><![CDATA[I really need help with this malware, the main threat is somewhere hidden in my system 32 folder and it keeps making and running exe's with random worded names that slows down my computer. It corrupts some of my downloads, as well as closes some...]]></description>
			<content:encoded><![CDATA[<div>I really need help with this malware, the main threat is somewhere hidden in my system 32 folder and it keeps making and running exe's with random worded names that slows down my computer. It corrupts some of my downloads, as well as closes some antivirus programs along with disabling my regedit and taskmanager. When i do get an antivirus to work, it doesn't pick up the main threat. Almost like it is well hidden. Please someone give me steps into removing this malware, it is really harming my computer and i do not wish to pay money just to get it fixed. Please!<br />
<br />
Hopefully someone can help and thank you for your time<br />
<br />
Also i can provide additional computer info if needed</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>HiizumiAkina</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878543-urgent-malware-removal-help-please.html</guid>
		</item>
		<item>
			<title>Help!!</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878540-help.html</link>
			<pubDate>Wed, 18 Nov 2009 23:55:52 GMT</pubDate>
			<description>Have had various problems in the last few weeks ranging from DCOM service launcher failure to google redirects and believe I have now gotten system defender. Just ran malwarebytes anti-malware full scan that found over 700 infected files (WOW!!). I...</description>
			<content:encoded><![CDATA[<div>Have had various problems in the last few weeks ranging from DCOM service launcher failure to google redirects and believe I have now gotten system defender. Just ran malwarebytes anti-malware full scan that found over 700 infected files (WOW!!). I properly deleted them and am ready for the next step. <br />
<br />
Here is my logfile:<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 6:27:09 PM, on 11/18/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\WINDOWS\stsystra.exe<br />
C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br />
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Ares\Ares.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_A10IC2.EXE<br />
C:\Program Files\HOTALBUMMyBOX\MediaChecker.exe<br />
c:\program files\common files\installshield\updateservice\isuspm.exe<br />
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Java\jre6\bin\jucheck.exe<br />
C:\Documents and Settings\All Users\89ee9b1\WS89ee.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Documents and Settings\Dan Gentner\My Documents\Downloads\HijackThis.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL<br />
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br />
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)<br />
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br />
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe<br />
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br />
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br />
O4 - HKLM\..\Run: [ISUSScheduler] &quot;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&quot; -start<br />
O4 - HKLM\..\Run: [MBBalloon] C:\Program Files\HOTALBUMMyBOX\MBBalloon.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKLM\..\Run: [System Defender] &quot;C:\Documents and Settings\All Users\Application Data\89368\WS72c.exe&quot; /s /d<br />
O4 - HKCU\..\Run: [ares] &quot;C:\Program Files\Ares\Ares.exe&quot; -h<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [EPSON Stylus C80 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_A10IC2.EXE /P23 &quot;EPSON Stylus C80 Series&quot; /O6 &quot;USB001&quot; /M &quot;Stylus C80&quot;<br />
O4 - Global Startup: MediaChecker.lnk = C:\Program Files\HOTALBUMMyBOX\MediaChecker.exe<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O20 - AppInit_DLLs: gjyktd.dll xumylh.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: Belkin Wireless USB Network Adapter (Belkin Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
<br />
--<br />
End of file - 7517 bytes</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>Dantana21</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878540-help.html</guid>
		</item>
		<item>
			<title>Slow After Updating AdAware</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878526-slow-after-updating-adaware.html</link>
			<pubDate>Wed, 18 Nov 2009 22:52:38 GMT</pubDate>
			<description>I updated AdAware today. It took an unusually long time to scan afterward - like it was on some kind of loop, scanning the same files over and over. I finally stopped it after 75 minutes - it never had taken more than 10 minutes to scan before. Then...</description>
			<content:encoded><![CDATA[<div>I updated AdAware today. It took an unusually long time to scan afterward - like it was on some kind of loop, scanning the same files over and over. I finally stopped it after 75 minutes - it never had taken more than 10 minutes to scan before. Then I tried to do a spyware scan with my installed Computer Associates security suite. This also went into an endless scan loop. I had better luck with Malwarebytes, but this didn't find any problems. Is this a problem resulting from the AdAware update? I have included a HijackThis log, if that is any help. Thanks in advance.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 5:46:08 PM, on 11/18/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe<br />
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe<br />
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe<br />
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe<br />
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe<br />
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe<br />
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe<br />
C:\WINDOWS\explorer2.exe<br />
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe<br />
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe<br />
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe<br />
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe<br />
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe<br />
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe<br />
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe<br />
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\DD\HiJackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.yahoo.com/" target="_blank">http://www.yahoo.com/</a><br />
F2 - REG:system.ini: Shell=explorer2.exe<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll<br />
O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;  -osboot<br />
O4 - HKLM\..\Run: [QOELOADER] &quot;C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe&quot;<br />
O4 - HKLM\..\Run: [cctray] &quot;C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe&quot;<br />
O4 - HKLM\..\Run: [CAVRID] &quot;C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe&quot;<br />
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe<br />
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe<br />
O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe<br />
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe<br />
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe<br />
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe<br />
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe<br />
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe<br />
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe<br />
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe<br />
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe<br />
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe<br />
<br />
--<br />
End of file - 5155 bytes</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>debodun</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878526-slow-after-updating-adaware.html</guid>
		</item>
		<item>
			<title>aim and windows media player help?</title>
			<link>http://forums.techguy.org/malware-removal-hijackthis-logs/878523-aim-windows-media-player-help.html</link>
			<pubDate>Wed, 18 Nov 2009 22:43:20 GMT</pubDate>
			<description>okay, here is my perdicament. whenever i open up aim it is fine. i click sign in, and during the sign in it will close. no error message or anything. just closes and does this everytime. i am also having problems of the same nature with windows...</description>
			<content:encoded><![CDATA[<div>okay, here is my perdicament. whenever i open up aim it is fine. i click sign in, and during the sign in it will close. no error message or anything. just closes and does this everytime. i am also having problems of the same nature with windows media player. sometimes it will work fine the whole time, sometimes it works for a little bit then crashes with an error message, and sometimes it will just not even start and just give me an error message. and i have tried un installing and re installing both of them and i still have the problem. i have the most current versions of both. any help will be appreciated. here is my log:<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 5:34:56 PM, on 11/18/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br />
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\PeoplePC\ISP6200\Browser\Bartshel.exe<br />
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
C:\Program Files\Microsoft IntelliType Pro\itype.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Program Files\Microsoft IntelliPoint\ipoint.exe<br />
C:\Program Files\Ad Muncher\AdMunch.exe<br />
C:\Program Files\CallWave\IAM.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\PROGRA~1\PeoplePC\ISP6200\Browser\PPShared.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe<br />
C:\WINDOWS\system32\HPZipm12.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Documents and Settings\Rhiannon\Desktop\HijackThis.exe<br />
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE<br />
C:\Program Files\Windows NT\Accessories\wordpad.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=64&amp;bd=PRESARIO&amp;pf=desktop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...RIO&amp;pf=desktop</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iesearch&amp;locale=EN_US&amp;c=64&amp;bd=PRESARIO&amp;pf=desktop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...RIO&amp;pf=desktop</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iesearch&amp;locale=EN_US&amp;c=64&amp;bd=PRESARIO&amp;pf=desktop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...RIO&amp;pf=desktop</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iesearch&amp;locale=EN_US&amp;c=64&amp;bd=PRESARIO&amp;pf=desktop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...RIO&amp;pf=desktop</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=64&amp;bd=PRESARIO&amp;pf=desktop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...RIO&amp;pf=desktop</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iesearch&amp;locale=EN_US&amp;c=64&amp;bd=PRESARIO&amp;pf=desktop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...RIO&amp;pf=desktop</a><br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll<br />
O2 - BHO: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - c:\program files\peoplepc\toolbar\PPCToolbar.dll<br />
O2 - BHO: hpWebHelper Class - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll<br />
O3 - Toolbar: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - c:\program files\peoplepc\toolbar\PPCToolbar.dll<br />
O4 - HKLM\..\Run: [NvCplDaemon] &quot;RUNDLL32.EXE&quot; C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [ccApp] &quot;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&quot;<br />
O4 - HKLM\..\Run: [osCheck] &quot;C:\Program Files\Norton Internet Security\osCheck.exe&quot;<br />
O4 - HKLM\..\Run: [SpySweeper] &quot;C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe&quot; /startintray<br />
O4 - HKLM\..\Run: [Bart Station] &quot;C:\Program Files\PeoplePC\ISP6200\BIN\PPCOLink.exe&quot; -STATION<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [HP Software Update] &quot;C:\Program Files\HP\HP Software Update\HPWuSchd2.exe&quot;<br />
O4 - HKLM\..\Run: [Symantec PIF AlertEng] &quot;C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe&quot; /a /m &quot;C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll&quot;<br />
O4 - HKLM\..\Run: [nwiz] &quot;nwiz.exe&quot; /install<br />
O4 - HKLM\..\Run: [itype] &quot;C:\Program Files\Microsoft IntelliType Pro\itype.exe&quot;<br />
O4 - HKLM\..\Run: [IntelliPoint] &quot;C:\Program Files\Microsoft IntelliPoint\ipoint.exe&quot;<br />
O4 - HKLM\..\Run: [Ad Muncher] &quot;C:\Program Files\Ad Muncher\AdMunch.exe&quot; /bt<br />
O4 - HKCU\..\Run: [Aim] &quot;C:\Program Files\AIM\aim.exe&quot; /d locale=en-US<br />
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')<br />
O4 - Startup: FrostWire On Startup.lnk = C:\Program Files\FrostWire\FrostWire.exe<br />
O4 - Startup: rncsys32.exe<br />
O4 - Global Startup: CallWave.lnk = C:\Program Files\CallWave\IAM.exe<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O8 - Extra context menu item: block frame with ad muncher - <a href="http://www.admuncher.com/request_will_be_intercepted_by/Ad_Muncher/browserextensions.pl?exbrowser=ie&amp;exversion=1.0&amp;pass=2682U383&amp;id=menu_ie_frame" target="_blank">http://www.admuncher.com/request_wil...=menu_ie_frame</a><br />
O8 - Extra context menu item: block image with ad muncher - <a href="http://www.admuncher.com/request_will_be_intercepted_by/Ad_Muncher/browserextensions.pl?exbrowser=ie&amp;exversion=1.0&amp;pass=2682U383&amp;id=menu_ie_image" target="_blank">http://www.admuncher.com/request_wil...=menu_ie_image</a><br />
O8 - Extra context menu item: block link with ad muncher - <a href="http://www.admuncher.com/request_will_be_intercepted_by/Ad_Muncher/browserextensions.pl?exbrowser=ie&amp;exversion=1.0&amp;pass=2682U383&amp;id=menu_ie_link" target="_blank">http://www.admuncher.com/request_wil...d=menu_ie_link</a><br />
O8 - Extra context menu item: don't filter page with ad muncher - <a href="http://www.admuncher.com/request_will_be_intercepted_by/Ad_Muncher/browserextensions.pl?exbrowser=ie&amp;exversion=1.0&amp;pass=2682U383&amp;id=menu_ie_exclude" target="_blank">http://www.admuncher.com/request_wil...enu_ie_exclude</a><br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000<br />
O8 - Extra context menu item: report page to the ad muncher developers - <a href="http://www.admuncher.com/request_will_be_intercepted_by/Ad_Muncher/browserextensions.pl?exbrowser=ie&amp;exversion=1.0&amp;pass=2682U383&amp;id=menu_ie_report" target="_blank">http://www.admuncher.com/request_wil...menu_ie_report</a><br />
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm<br />
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O11 - Options group: [java_sun] Java (Sun)<br />
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - <a href="http://fdl.msn.com/public/chat/msnchat45.cab" target="_blank">http://fdl.msn.com/public/chat/msnchat45.cab</a><br />
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br />
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\<br />
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe<br />
O23 - Service: Java Quick Starter (javaquickstarterservice) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br />
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe<br />
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe<br />
O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-malware-removal-hijackthis-logs/"><![CDATA[Malware Removal & HijackThis Logs]]></category>
			<dc:creator>syntaxerror</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/malware-removal-hijackthis-logs/878523-aim-windows-media-player-help.html</guid>
		</item>
	</channel>
</rss>
