Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

951.

Solve : Good site blocked by McAfe Antivirus. True??

Answer»

I got a call from a relative to tell me that MalwareBytes.org, a good site. was  blocked by McAfe Anti VIRUS. That just can not ber true, -Right?

I dont see anything wrong with it. Unless macafee doesnt want anyone to buy anything other then them    Or mabye it was a fake site or something. Mabye theyve been hacked or soemthing.  All of whcih I doubtThere was an issue a while back with McAfee blocking the Malwarebytes.exe but it was srraightened out with a McAfee update. Is there AV up-to-date?

If so it could be an infection trying to re-direct them away from the Malwarebytes web site and not blocking the actual URL. He got the McAfe on sale at Cost-Co and now we know why it was on sale!
MalwareBytes is a respected ORG, so why would anyone in his right mind try to block it?  That was very bad PR. Could you imagine Microsoft putting a block on the Apple site? Hard to believe!This highlights one of the main reasons I myself don't use any AV solution. Blacklists simply don't work.

http://www.codinghorror.com/blog/archives/001009.html


I don't think it's a blacklist issue.

Nice article but I think he is a little off on a few points:

Quote

Ask yourself this: why don't Mac users run anti-virus software? Why don't UNIX users run anti-virus software? Because they don't need to.

It's because malware writers haven't put any effort into attacking a Mac. Too much work with no reward. But Mac viruses are rising, slowly but there new ones being released.

Quote
At its heart, anti-virus software is little more than a glorified blacklist. It maintains an internal list of evil applications and their unique byte signatures, and if it sees one on your system, kills it for you. Sure, anti-virus VENDORS will dazzle you with their ad copy, their heuristic this and statistical that; they'll tell you (with a straight face, even) that their software is far more than a simple blacklist. It's a blacklist with lipstick. It's the prettiest, shiniest, most kissable blacklist you've ever seen!

Not true. Behavior/heuristic detection is a very good resource. That's why users have to turn off their AV before using some of the specialized tools in malware REMOVAL. They behave just like some malware and will be terminated.

But hey, who am I to try and tell a PROGRAMMER that software is better than something that can be done with DOS or manually.

So you are 100% sure that McAfee is blocking access to the MalwareBytes Web site?yeah I pretty much disagreed with the same two points- but as far as Admin/limited this was made pre-vista and I think that MS addressed that issue at least partly with UAC and related security features.

As far as hueristics I think they work fairly well, especially in that they will find new "strains" of previously profiled viruses- and even can be set so that they detect any virus using a module or loader distributed between malware authors; Additionally I find it interesting how he says blacklists don't work and yet offers no reasonable ALTERNATIVE other then that now essentially made the default- run as a limited user. I think Vista and now Windows 7 have addressed the whole "running as admin" issue fairly well.

952.

Solve : Virus preventing access to antivirus sites and programs.?

Answer»

I am running WINDOWS XP sp3.  I have a virus that is preventing firefox and IE from accessing online virus scan site, such as trans micro and kaspesky.  I found another thread describing similar problems and I followed the steps recommended in it as far as I could.  When the virus first hit my computer, McAfee did recognize the threat and tried to delete it, but for some reason it wasn't able to, it told me to manually remove it from Add/Remove Programs, I tried but I couldn't get to the program, I kept being redirected to a google shearch for Win32.DNSChanger.   After running virus scans with McAfee and AVG, I removed a handful of trojans and spyware, the most significant one being a Win32.DNSChanger.  This made it so that I was able to at least access files on my computer again. 

When I tried to download MBAM and SAS, i had trouble trying to get them to install. I now have them installed but I cannot get them to run.  I believe that virus is preventing them from running but I could be wrong.

Only other symptoms are that everything seems to be running very slowly, and my system is unstable (random freezes from time to time). Any help would be greatly appreciated!

I downloaded and ran RSIT and I will attach the files.  I was unable to run MBAM or SAS so no logs from them are available.



Note:  I believe that the virus hit my computer around 3:00pm yesterday (2/14/2009).






[attachment deleted by admin]Welcome to CH.

The real-time protection of two antivirus programs may conflict with each other and cause the following:

1) False Alarms: When the anti virus software tells you that your PC has a virus when it actually doesn't.
2) Conflicts: Your system may lock up due to both products attempting to access the same file at the same time.
3) Performance: More that one antivirus will cause your PC to become slow and it may even crash or blue screen.

Please uninstall either AVG or McAfee before continuing.

----------

Click Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices.

* Scroll down to Non-plug and Play Drivers and click the plus icon to open those drivers.
* Search for any of the following:

- Seneka.sys
- clbdriver.sys
- TDSSserv.sys

* Let me know if you find them or not.
* If you do find it, right click on it, and select Disable. Do not try to uninstall them.
* Now reboot the computer.

----------

Open HijackThis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

O2 - BHO: Win32-DNSChanger - {930E7881-D9F3-4293-A24B-23A80C013378} - C:\WINDOWS\system32\fejokt.dll (file missing)
O2 - BHO: {0894219f-015e-8d3b-1aa4-d72ce575ec3e} - {e3ce575e-c27d-4aa1-b3d8-e510f9124980} - C:\WINDOWS\system32\ibpwie.dll (file missing)
O4 - HKLM\..\Run: [Jgubofa] rundll32.exe \"C:\WINDOWS\Vqanun.dll\",e
O4 - HKLM\..\Run: [Ssemonusohoma] rundll32.exe \"C:\WINDOWS\etofisaw.dll\",e
O4 - Startup: PowerReg Scheduler.exe
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL ibpwie.dll
O20 - Winlogon Notify: crypt - crypts.dll (file missing)
.
Important: Close all windows except for HijackThis and then click Fix checked.

Exit HijackThis.

----------

Download Malwarebytes' Anti-Malware (MBAM)

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to the following:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
    • Then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select Perform quick scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy and Paste the entire report in your next reply.
    Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.1) AVG uninstalled.

    2) I didn't find any of the .sys

    3) done

    4) I was able to get MBAM to run by renaming it and changing its extension to .bat (a recommendation I found on another forum).  I will copy and paste the log of that run.  After I restarted I was able to open MBAM with its original name, I rescanned and it detected nothing. 


    MBAM log:


    Malwarebytes' Anti-Malware 1.34
    Database version: 1764
    Windows 5.1.2600 Service Pack 3

    2/15/2009 7:09:23 PM
    mbam-log-2009-02-15 (19-09-23).txt

    Scan type: Quick Scan
    Objects scanned: 82318
    Time elapsed: 11 minute(s), 11 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 16
    Registry Values Infected: 2
    Registry Data ITEMS Infected: 0
    Folders Infected: 0
    Files Infected: 27

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e3ce575e-c27d-4aa1-b3d8-e510f9124980} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{e3ce575e-c27d-4aa1-b3d8-e510f9124980} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\lmaspois (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\lmaspois.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{7a85cdf5-284b-4496-a9a7-dd82fee9dcec} (Rogue.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{fcd4b2f5-8793-4e1f-8774-6e520cf6cd79} (Rogue.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{930e7881-d9f3-4293-a24b-23a80c013378} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Typelib\{a8954909-1f0f-41a5-a7fa-3b376d69e226} (Rogue.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{930e7881-d9f3-4293-a24b-23a80c013378} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{930e7881-d9f3-4293-a24b-23a80c013378} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt (Trojan.Downloader) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\jgubofa (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ssemonusohoma (Trojan.Agent) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\WINDOWS\system32\ibpwie.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\UACmxejuctn.dll (Rootkit.TDSS) -> Delete on reboot.
    C:\WINDOWS\system32\UACtvvmlrqj.dll (Trojan.TDSS) -> Delete on reboot.
    C:\WINDOWS\system32\UACubopxlvk.dll (Rootkit.TDSS) -> Delete on reboot.
    C:\WINDOWS\system32\UACylrdciqr.dll (Rootkit.TDSS) -> Delete on reboot.
    C:\WINDOWS\system32\drivers\UACrpbprdnt.sys (Rootkit.TDSS) -> Delete on reboot.
    C:\Documents and Settings\James Stokes\Local Settings\Temp\UACb7e4.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
    C:\Documents and Settings\James Stokes\Local Settings\Temp\E6C3.tmp (Trojan.Backdoor) -> Quarantined and deleted successfully.
    C:\WINDOWS\Temp\UACc9d3.tmp (Rootkit.TDSS) -> Delete on reboot.
    C:\Documents and Settings\James Stokes\Local Settings\Temporary Internet Files\Content.IE5\2R0VBIDQ\pifccddur[1].txt (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Documents and Settings\James Stokes\Local Settings\Temporary Internet Files\Content.IE5\CX7S0RXV\upd105320[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Documents and Settings\James Stokes\Favorites\Cheap Software.url (Rogue.Link) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\sf.ico (Malware.Trace) -> Quarantined and deleted successfully.
    C:\Documents and Settings\James Stokes\Favorites\MP3 Download.url (Rogue.Link) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\m3.ico (Malware.Trace) -> Quarantined and deleted successfully.
    C:\Documents and Settings\James Stokes\Favorites\Search Online.url (Rogue.Link) -> Quarantined and deleted successfully.
    C:\Documents and Settings\James Stokes\Favorites\VIP Casino.url (Rogue.Link) -> Quarantined and deleted successfully.
    C:\Documents and Settings\James Stokes\Favorites\Cheap Pharmacy Online.url (Rogue.Link) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\c.ico (Malware.Trace) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\m.ico (Malware.Trace) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\p.ico (Malware.Trace) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\s.ico (Malware.Trace) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) -> Delete on reboot.
    C:\Documents and Settings\James Stokes\Favorites\SMS TRAP.url (Rogue.Link) -> Quarantined and deleted successfully.
    C:\WINDOWS\ios.dat (Malware.Trace) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\UACdbqltltx.dat (Trojan.Agent) -> Delete on reboot.
    C:\WINDOWS\system32\UACmevxfqhr.log (Trojan.Agent) -> Delete on reboot.


    Download ComboFix© by sUBs from one of the below links. Be sure top SAVE it to the Desktop.

    Link #1
    Link #2

    **Note:  It is important that it is saved directly to your Desktop

    Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

    Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
     
    Double click combofix.exe & follow the prompts.
    When finished ComboFix will produce a log for you.
    Post the ComboFix log in your next reply.

    Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

    Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

    If you have problems with ComboFix usage, see How to use ComboFixComboFix Log:


    ComboFix 09-02-15.01 - James Stokes 2009-02-15 20:42:29.1 - NTFSx86
    Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.2046.1297 [GMT -5:00]
    Running from: c:\documents and settings\James Stokes\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\James Stokes\Desktop\ComboFix.exe
    AV: McAfee VirusScan *On-access scanning disabled* (Updated)
    FW: McAfee Personal Firewall *enabled*
     * Created a new restore point
    .

    (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\IE4 Error Log.txt
    c:\windows\system32\DKmnpXyb.ini
    c:\windows\system32\DKmnpXyb.ini2
    c:\windows\system32\WGiSvyay.ini
    c:\windows\system32\WGiSvyay.ini2
    c:\windows\Tasks\nbzpxgnw.job

    .
    (((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Service_UACd.sys


    (((((((((((((((((((((((((   Files Created from 2009-01-16 to 2009-02-16  )))))))))))))))))))))))))))))))
    .

    2009-02-15 19:00 . 2009-02-15 19:00      d--------   c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
    2009-02-15 18:55 . 2009-02-15 18:55      d--------   c:\documents and settings\James Stokes\Application Data\Malwarebytes
    2009-02-15 18:53 . 2009-02-15 19:11      d--------   c:\program files\Malwarebytes' Anti-Malware
    2009-02-15 18:53 . 2009-02-15 18:53      d--------   c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-02-15 18:53 . 2009-02-11 10:19   38,496   --a------   c:\windows\system32\drivers\mbamswissarmy.sys
    2009-02-15 18:53 . 2009-02-11 10:19   15,504   --a------   c:\windows\system32\drivers\mbam.sys
    2009-02-15 13:45 . 2009-02-15 17:07      d--------   C:\rsit
    2009-02-15 13:18 . 2009-02-15 19:40      d--------   c:\program files\SUPERAntiSpyware
    2009-02-15 13:18 . 2009-02-15 13:18      d--------   c:\documents and settings\James Stokes\Application Data\SUPERAntiSpyware.com
    2009-02-15 11:55 . 2009-02-15 11:55      d--------   c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
    2009-02-15 04:24 . 2009-02-15 15:55      d--h-----   C:\$AVG8.VAULT$
    2009-02-15 04:20 . 2009-02-15 19:29      d--------   c:\documents and settings\All Users\Application Data\avg8
    2009-02-14 17:11 . 2009-02-14 17:11   302,592   --a------   c:\windows\system32\byXpnmKD.dll.vir
    2009-02-14 15:18 . 2009-02-14 15:18   302,592   --a------   c:\windows\system32\yayvSiGW.dll.vir
    2009-02-12 03:02 . 2009-02-12 03:02      d--------   c:\windows\$SQLUninstallSQL2000-KB960082-v8.00.2055-x86-ENU$
    2009-02-06 14:18 . 2009-02-06 14:38      d--------   c:\program files\PowerStrip
    2009-02-06 13:54 . 2009-02-06 13:54      d--------   c:\program files\MonInfo
    2009-02-06 13:00 . 2009-02-06 13:00      d--------   c:\program files\TightVNC
    2009-02-06 12:30 . 2009-02-06 12:30      d--------   c:\documents and settings\jhs\Application Data\Logitech
    2009-02-06 12:30 . 2009-02-06 12:30      d--------   c:\documents and settings\jhs\Application Data\GTek
    2009-02-06 12:29 . 2009-02-15 04:20      d--------   c:\documents and settings\jhs
    2009-02-06 11:11 . 2009-02-06 11:16      d--------   c:\program files\AirPort

    .
    ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-02-16 01:47   ---------   d-----w   c:\documents and settings\James Stokes\Application Data\nView_Wallpaper
    2009-02-15 19:45   ---------   d-----w   c:\documents and settings\All Users\Application Data\Google Updater
    2009-02-15 18:18   ---------   d-----w   c:\program files\Common Files\Wise Installation Wizard
    2009-02-15 00:31   ---------   d-----w   c:\documents and settings\James Stokes\Application Data\EndNote
    2009-02-14 21:09   ---------   d--h--w   c:\documents and settings\James Stokes\Application Data\Move Networks
    2009-02-14 20:25   ---------   d-----w   c:\program files\McAfee
    2009-02-12 08:44   ---------   d-----w   c:\program files\DivX
    2009-02-12 08:14   ---------   d-----w   c:\documents and settings\James Stokes\Application Data\Azureus
    2009-01-06 08:15   ---------   d-----w   c:\documents and settings\All Users\Application Data\nView_Profiles
    2009-01-06 03:14   ---------   d-----w   c:\program files\Common Files\AOL
    2009-01-06 03:14   ---------   d-----w   c:\program files\AIM
    2009-01-06 03:14   ---------   d-----w   c:\documents and settings\James Stokes\Application Data\Aim
    2009-01-06 03:13   ---------   d-----w   c:\documents and settings\All Users\Application Data\AOL
    2008-12-29 08:14   ---------   d-----w   c:\program files\Java
    2008-12-29 08:10   ---------   d-----w   c:\program files\Google
    2008-12-25 18:09   ---------   d-----w   c:\program files\SystemRequirementsLab
    2008-12-18 23:50   ---------   d-----w   c:\program files\Intelligen
    2008-02-28 02:35   44,360   ----a-w   c:\program files\mozilla firefox\plugins\atgpcdec.dll
    2008-02-28 02:35   107,928   ----a-w   c:\program files\mozilla firefox\plugins\atgpcext.dll
    2008-04-24 14:58   122,880   ----a-w   c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
    2008-11-12 03:07   88   --sha-r   c:\windows\system32\BA8C5A2E66.sys
    2008-11-12 03:07   3,350   --sha-w   c:\windows\system32\KGyGaAvL.sys
    2008-07-01 22:06   32,768   --sha-w   c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008070120080702\index.dat
    .

    (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
    "Steam"="c:\program files\valve\steam\steam.exe" [2008-10-08 1410296]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-19 68856]
    "DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
    "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
    "Google Update"="c:\documents and settings\James Stokes\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-02 133104]
    "AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2008-11-12 2356088]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]
    "DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-11-01 94208]
    "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
    "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
    "DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
    "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-24 29744]
    "HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-10-23 233472]
    "HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2003-06-25 49152]
    "HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2005-07-22 176128]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
    "VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2006-07-13 122880]
    "AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 49152]
    "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
    "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
    "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
    "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
    "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
    "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
    "AirPort Base Station Agent"="c:\program files\AirPort\APAgent.exe" [2008-05-20 737280]
    "SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 c:\windows\stsystra.exe]
    "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-07-22 c:\windows\KHALMNPR.Exe]
    "CTHelper"="CTHELPER.EXE" [2006-08-17 c:\windows\CTHELPER.EXE]
    "CTxfiHlp"="CTXFIHLP.EXE" [2006-08-17 c:\windows\system32\CTXFIHLP.EXE]
    "nwiz"="nwiz.exe" [2008-10-07 c:\windows\system32\nwiz.exe]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "RealUpgradeHelper"="c:\program files\Common Files\Real\Update_OB\upgrdhlp.exe" [2008-10-12 136768]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-06-05 24576]
    Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2006-06-07 528384]
    Run Google Web Accelerator.lnk - c:\program files\Google\Web Accelerator\GoogleWebAccWarden.exe [2007-07-09 1134592]
    Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-05-03 81920]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "vidc.wmv3"= c:\progra~1\COMBIN~1\Filters\wmv9vcm.dll
    "msacm.avis"= ff_acm.acm
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
    "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\AirPort\\APAgent.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "5353:UDP"= 5353:UDP:Bonjour
    "3389:TCP"= 3389:TCP:xpsp2res.dll,-22009

    R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-01-15 8944]
    R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-01-15 55024]
    R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2008-09-25 206096]
    R2 PStrip;PSTRIP;c:\windows\system32\drivers\pstrip.sys [2007-07-14 27992]
    S3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2006-06-05 29744]
    S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-01-15 7408]
    S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2008-04-29 356920]
    S3 se32;EnTech softEngine;c:\windows\system32\drivers\se32.sys [2007-05-03 12112]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{33220075-2790-11dc-b8cb-00038a000015}]
    \Shell\AutoRun\command - F:\LaunchU3.exe -a
    .
    Contents of the 'Scheduled Tasks' folder

    2009-02-14 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

    2009-02-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-914741439-1241626394-3683679332-1006.job
    - c:\documents and settings\James Stokes\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-02 14:54]

    2009-01-15 c:\windows\Tasks\McDefragTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]

    2009-02-01 c:\windows\Tasks\McQcTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
    .
    - - - - ORPHANS REMOVED - - - -

    HKCU-Run-SUPERAntiSpyware - c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.bat.exe
    HKCU-Run-BeFree4iPhone - c:\program files\E.W.E.-Software\Befree4iPhone\befree4iphone.exe


    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/ig/dell?hl=en&client=dell-inc&channel=us
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?Q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    Trusted Zone: internet
    Trusted Zone: mcafee.com
    DPF: Microsoft XML Parser for Java
    FF - ProfilePath - c:\documents and settings\James Stokes\Application Data\Mozilla\Firefox\Profiles\r1yv8447.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?hl=en
    FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
    FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
    FF - plugin: c:\documents and settings\James Stokes\Application Data\Mozilla\Firefox\Profiles\r1yv8447.default\extensions\[email protected]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
    FF - plugin: c:\documents and settings\James Stokes\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll
    FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
    FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-02-15 20:49:18
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ... 

    scanning hidden autostart entries ...

    scanning hidden files ... 

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(700)
    c:\program files\SUPERAntiSpyware\SASWINLO.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\windows\system32\CTSVCCDA.EXE
    c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
    c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\progra~1\McAfee\MSC\mcmscsvc.exe
    c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
    c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
    c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
    c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    c:\windows\system32\CTXFISPI.EXE
    c:\program files\McAfee\MPF\MpfSrv.exe
    c:\program files\McAfee\MSK\msksrver.exe
    c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
    c:\windows\system32\rundll32.exe
    c:\windows\system32\rundll32.exe
    c:\windows\system32\nvsvc32.exe
    c:\windows\system32\HPZipm12.exe
    c:\program files\Dell Support Center\bin\sprtsvc.exe
    c:\program files\Common Files\Logitech\KHAL\KHALMNPR.EXE
    c:\program files\iPod\bin\iPodService.exe
    c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
    c:\program files\Google\Web Accelerator\GoogleWebAccClient.exe
    c:\progra~1\McAfee\MSC\mcuimgr.exe
    .
    **************************************************************************
    .
    Completion time: 2009-02-15 20:59:25 - machine was rebooted
    ComboFix-quarantined-files.txt  2009-02-16 01:59:21

    Pre-Run: 146,709,557,248 bytes free
    Post-Run: 146,866,094,080 bytes free

    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

    258   --- E O F ---   2009-02-12 08:06:36

    Delete these files/folders, as follows:

    1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
    It must be Notepad, not Wordpad.
    2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

    Code: [Select]KillAll::

    File::
    c:\windows\system32\byXpnmKD.dll.vir
    c:\windows\system32\yayvSiGW.dll.vir

    DirLook::
    c:\documents and settings\jhs

    3. Go to the Notepad window and click Edit > Paste
    4. Then click File > Save
    5. Name the file CFScript.txt - Save the file to your Desktop
    6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



    ComboFix will begin to execute, just follow the prompts.
    After reboot (in case it asks to reboot), it will produce a log for you.
    Post that log (Combofix.txt) in your next reply.

    Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeAttached is the Combofix log. 

    I want to go ahead and thank you for all your help, evilfantasy.   

    [attachment deleted by admin]That looks OK. how is the computer running now?Its running great.  Its probably running better than it did before the virus infected it. 

    Thanks again.  Sounds good.

    Cleanup steps.

    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.
    .
    .
    The above procedure will:
    • Delete:
      • ComboFix and its associated files and folders.
      • VundoFix backups, if present
      • The C:\Deckard folder, if present
      • The C:_OtMoveIt folder, if present
      • Reset the clock settings.
      • Hide file extensions, if required.
      • Hide System/Hidden files, if required.
      • Set a new, clean Restore Point.
      .
      ----------

      Use the Secunia Software Inspector to check for out of date software.
      • Click Start Now
      • Check the box next to Enable thorough system inspection.
      • Click Start
      • Allow the scan to finish and scroll down to see if any updates are needed.
      • Update anything listed.
      .
      ----------

      Go to Microsoft Windows Update and get all critical updates.

      ----------

      Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

      Concerned about Browser Security? Consider using Mozilla Firefox. With more than 15,000 improvements, Firefox 3 is faster, safer and smarter than ever before.

      For Internet Explorer 7 users there is IE7Pro. IE7Pro is a must have add-on for Internet Explorer, which includes a lot of features and tweaks to make your IE friendlier, more useful, more secure and customizable.

      To prevent unknown applications from being installed on your computer install WinPatrol 2008
      * Using Winpatrol to protect your computer from malicious software

      I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

      SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
      * Using SpywareBlaster to protect your computer from Spyware and Malware
      * If you don't know what ActiveX controls are, see here

      Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

      Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running SMOOTH.
      953.

      Solve : spyware or malware help??

      Answer»

      O22 - SharedTaskScheduler: causes - {0fe36c74-667b-454b-828e-75e4e72cbef8} - (no file) thats from hijack this log.


      Apple software Update         (size  2.16 MB)
      AVS4YOU software Navigator       (1.2 MB)
      DOA                        (no size)
      Microsoft .NET Framework 1.1         (no size)
      Microsoft .NET Framework 1.1 Hotfix [KB928366]      (no size)
      Microsoft .NET Framework 2.0                 (59.28 MB)
      MSXML 1.0 SP2[KB954430]      (2.67MB)
      Security Task Manager 1.7g         (1.99MB)
      Security Update for Windiows media encoder [KB954156]       (10.84MB)
      Windows Search 4.0    (no size)

      these programs i don't know what they are.    This is step 1

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 9:53:44 AM, on 2/25/2009
      Platform: Windows XP SP3, v.5657 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16791)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program FILES\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
      C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Ahead\InCD\InCDsrv.exe
      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      C:\WINDOWS\system32\PnkBstrA.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
      C:\Program Files\SUPERMICRO\SDIII\NTService.exe
      C:\WINDOWS\system32\SD3Service.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\WINDOWS\system32\WinVNC.exe
      C:\WINDOWS\system32\SearchIndexer.exe
      C:\Program Files\Microsoft IntelliType Pro\type32.exe
      C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
      C:\Program Files\Ahead\InCD\InCD.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
      C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
      C:\Program Files\ATI Multimedia\main\launchpd.exe
      C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\SUPERMICRO\SDIII\Xitami\xiwinnt.exe
      C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
      C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
      C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
      C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\WINDOWS\system32\SearchProtocolHost.exe

      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
      O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
      O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
      O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
      O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
      O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
      O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
      O4 - HKLM\..\Run: [OneTouch Monitor] C:\Program Files\Visioneer OneTouch\OneTouchMon.exe
      O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
      O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
      O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
      O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe"
      O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
      O4 - Global Startup: Supero Doctor III Client.lnk = C:\Program Files\SUPERMICRO\SDIII\SuperoDoctor.exe
      O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
      O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
      O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
      O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (MSN Games – Texas Holdem Poker) - http://zone.msn.com/bingame/zpagames/zpa_txhe.cab79352.cab
      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
      O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
      O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
      O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\
      O22 - SharedTaskScheduler: causes - {0fe36c74-667b-454b-828e-75e4e72cbef8} - (no file)
      O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. http://www.bitdefender.com - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
      O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
      O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
      O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
      O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
      O23 - Service: SuperMicro Health Assistant - Unknown owner - C:\Program Files\SUPERMICRO\SDIII\NTService.exe
      O23 - Service: Supero SD3Service Daemon - Unknown owner - C:\WINDOWS\system32\SD3Service.exe
      O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
      O23 - Service: TridiaVNC Server (winvnc) - Tridia Corporation - C:\WINDOWS\system32\WinVNC.exe
      O23 - Service: Xitami Web Server (Xitami) - Unknown owner - C:\Program Files\SUPERMICRO\SDIII\Xitami\xiwinnt.exe

      --
      End of file - 9923 bytes


      go to the top of this page ( evilfantsy 1 st post ) and post all the logs and an expert will look at themOpen HijackThis and select Do a system scan only.

      Place a check mark next to the following entries: (if there)

      - R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      - R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
      - O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
      - O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\
      - O22 - SharedTaskScheduler: causes - {0fe36c74-667b-454b-828e-75e4e72cbef8} - (no file)


      Important: Close all windows except for HijackThis and then click FIX checked.

      Exit HijackThis.

      ----------

      Download Malwarebytes' Anti-Malware (MBAM)

      • Double-click mbam-setup.exe and follow the prompts to install the program.
      • At the end, be sure a checkmark is placed next to the following:
        • Update Malwarebytes' Anti-Malware
        • Launch Malwarebytes' Anti-Malware
        • Then click Finish.
        • If an update is found, it will download and install the latest version.
        • Once the program has loaded, select Perform quick scan, then click Scan.
        • When the scan is complete, click OK, then Show Results to view the results.
        • Be sure that everything is checked, and click Remove Selected.
        • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
        • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
        • Copy and Paste the entire report in your next reply.
        .
        Extra Note: If MBAM encounters a file that is difficult to remove, you will be PRESENTED with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.


        Scan done and  the report.


        Malwarebytes' Anti-Malware 1.34
        Database version: 1812
        Windows 5.1.2600 Service Pack 3, v.5657

        2/27/2009 10:01:21 PM
        mbam-log-2009-02-27 (22-01-21).txt

        Scan type: Quick Scan
        Objects scanned: 75461
        Time elapsed: 5 minute(s), 25 second(s)

        Memory Processes Infected: 0
        Memory Modules Infected: 0
        Registry Keys Infected: 4
        Registry Values Infected: 0
        Registry Data Items Infected: 0
        Folders Infected: 1
        Files Infected: 0

        Memory Processes Infected:
        (No malicious items detected)

        Memory Modules Infected:
        (No malicious items detected)

        Registry Keys Infected:
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\ASpyC (Rogue.AntiSpyCheck) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\spywarning.warningbho (Rogue.AntiSpyCheck) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\spywarning.warningbho.1 (Rogue.AntiSpyCheck) -> Quarantined and deleted successfully.

        Registry Values Infected:
        (No malicious items detected)

        Registry Data Items Infected:
        (No malicious items detected)

        Folders Infected:
        C:\Program Files\ASpyC (Rogue.AntiSpyCheck) -> Quarantined and deleted successfully.

        Files Infected:
        (No malicious items detected)

        Thank  You evilfantasy for all your help. Thank you so much. Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

        Link #1
        Link #2

        **Note:  It is important that it is saved directly to your Desktop

        Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

        Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
         
        Double click combofix.exe & follow the prompts.
        When finished ComboFix will produce a log for you.
        Post the ComboFix log in your next reply.

        Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

        Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

        If you have problems with ComboFix usage, see How to use ComboFixthe link you gave me to disable my anit-virus s not workin i have bitdefender total security 2009. the steps they gave to temporarily disable them is not workin.  i dont see virus shield on my program. help Try running ComboFix anyway. Just allow it to run if BitDefender tries to stop it.is this a anti-virus program

        Bitdefender Total Security 2009
        there you go.


        ComboFix 09-02-27.02 - Administrator 2009-02-27 22:42:30.1 - NTFSx86
        Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.1023.636 [GMT -5:00]
        Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
        AV: BitDefender Antivirus *On-access scanning disabled* (Updated)
        FW: BitDefender Firewall *disabled*
         * Created a new restore point

        WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
        .

        (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
        .

        c:\documents and settings\All Users\Application Data\vlc-0.9.4-win32.exe
        c:\documents and settings\All Users\Application Data\vlc-0.9.6-win32.exe
        c:\windows\system32\winio.dll

        .
        (((((((((((((((((((((((((   Files Created from 2009-01-28 to 2009-02-28  )))))))))))))))))))))))))))))))
        .

        2009-02-27 22:41 . 2009-02-27 22:41   731   --a--c---   c:\windows\system32\BDUpdateV1.xml
        2009-02-27 21:54 . 2009-02-27 21:54      d----c---   c:\program files\Malwarebytes' Anti-Malware
        2009-02-27 21:54 . 2009-02-27 21:54      d----c---   c:\documents and settings\All Users\Application Data\Malwarebytes
        2009-02-27 21:54 . 2009-02-27 21:54      d----c---   c:\documents and settings\Administrator\Application Data\Malwarebytes
        2009-02-27 21:54 . 2009-02-11 10:19   38,496   --a--c---   c:\windows\system32\drivers\mbamswissarmy.sys
        2009-02-27 21:54 . 2009-02-11 10:19   15,504   --a--c---   c:\windows\system32\drivers\mbam.sys
        2009-02-25 09:53 . 2009-02-25 09:53      d----c---   c:\program files\Trend Micro
        2009-02-24 23:57 . 2009-02-24 23:57      d----c---   c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
        2009-02-19 09:58 . 2009-02-19 10:01      d----c---   c:\program files\RegCure
        2009-02-19 09:39 . 2009-02-22 19:02      d----c---   c:\program files\Security Task Manager
        2009-02-19 09:39 . 2009-02-19 09:49      d----c---   c:\documents and settings\All Users\Application Data\SecTaskMan
        2009-02-16 00:14 . 2009-02-16 00:17      d----c---   c:\documents and settings\Administrator\Application Data\ErrorFix
        2009-02-16 00:06 . 2009-02-16 00:06   23,392   --a--c---   c:\windows\system32\nscompat.tlb
        2009-02-16 00:06 . 2009-02-16 00:06   16,832   --a--c---   c:\windows\system32\amcompat.tlb
        2009-02-14 19:16 . 2009-02-14 19:16      d----c---   c:\documents and settings\Administrator\Application Data\Xilisoft Corporation
        2009-02-14 19:15 . 2009-02-14 19:15      d----c---   c:\program files\Xilisoft
        2009-02-14 17:52 . 2009-02-14 17:52      d----c---   c:\documents and settings\Guest\Application Data\Windows Desktop Search
        2009-02-14 17:52 . 2009-02-14 17:52      d----c---   c:\documents and settings\Guest\Application Data\BitDefender
        2009-02-12 13:50 . 2006-10-26 19:56   32,592   --a--c---   c:\windows\system32\msonpmon.dll
        2009-02-12 13:47 . 2009-02-12 13:47      d----c---   c:\program files\Microsoft Works
        2009-02-12 13:46 . 2009-02-12 13:46      d----c---   c:\program files\MSBuild
        2009-02-12 13:43 . 2009-02-12 13:43      d----c---   c:\program files\Microsoft.NET
        2009-02-12 13:40 . 2009-02-12 13:40      d----c---   c:\program files\Microsoft Visual Studio 8
        2009-02-12 13:39 . 2009-02-12 13:45      d----c---   c:\windows\SHELLNEW
        2009-02-12 13:38 . 2009-02-12 13:51      d----c---   c:\documents and settings\All Users\Application Data\Microsoft Help
        2009-02-12 13:37 . 2009-02-12 13:37      dr-h-c---   C:\MSOCache
        2009-02-12 13:25 . 2009-02-12 13:25      d----c---   C:\ConverterOutput
        2009-02-12 13:24 . 2009-02-12 13:24      d----c---   c:\program files\Cucusoft
        2009-02-12 13:24 . 2007-03-25 00:51   3,049,984   --a--c---   c:\windows\system32\libavcodec.dll
        2009-02-12 13:24 . 2007-03-25 21:40   2,174,976   --a--c---   c:\windows\system32\ffdshow.ax
        2009-02-12 13:24 . 2007-03-25 00:51   404,480   --a--c---   c:\windows\system32\libmplayer.dll
        2009-02-12 13:24 . 2007-01-01 05:30   200,704   --a--c---   c:\windows\system32\TomsMoComp_ff.dll
        2009-02-12 13:24 . 2006-07-08 04:07   114,688   --a--c---   c:\windows\system32\PropListCtrl.ocx
        2009-02-12 13:24 . 2007-03-25 00:51   114,688   --a--c---   c:\windows\system32\libmpeg2_ff.dll
        2009-02-12 13:24 . 2004-09-10 13:50   34,820   --a--c---   c:\windows\system32\ffdshow.reg
        2009-02-12 09:43 . 2009-02-24 15:19      d----c---   c:\program files\PeerGuardian2
        2009-02-11 16:38 . 2009-02-27 22:42   121   --a--c---   c:\windows\bdagent.INI
        2009-02-11 16:37 . 2009-02-11 16:37      d----c---   c:\documents and settings\Administrator\Application Data\Windows Search
        2009-02-11 16:34 . 2009-02-11 16:34      d----c---   c:\windows\system32\GroupPolicy
        2009-02-11 16:34 . 2009-02-11 16:34      d----c---   c:\program files\Windows Desktop Search
        2009-02-11 16:34 . 2009-02-11 16:34      d----c---   c:\documents and settings\Administrator\Application Data\Windows Desktop Search
        2009-02-11 16:32 . 2009-02-16 00:04      d----c---   c:\program files\Windows Media Connect 2
        2009-02-11 16:30 . 2009-02-11 16:31      d----c---   c:\windows\system32\drivers\UMDF
        2009-02-11 16:15 . 2009-02-11 16:15   850   --a--c---   c:\windows\system32\ProductTweaks.xml
        2009-02-11 16:15 . 2009-02-11 16:15   385   --a--c---   c:\windows\system32\user_gensett.xml
        2009-02-11 16:04 . 2009-02-27 22:41   81,984   --a--c---   c:\windows\system32\bdod.bin
        2009-02-11 15:59 . 2009-02-11 15:59      d----c---   c:\windows\system32\logs
        2009-02-11 15:59 . 2009-02-11 15:59      d----c---   c:\program files\BitDefender
        2009-02-11 15:59 . 2009-02-11 16:02      d----c---   c:\documents and settings\All Users\Application Data\BitDefender
        2009-02-11 15:59 . 2009-02-11 15:59      d----c---   c:\documents and settings\Administrator\Application Data\BitDefender
        2009-02-11 15:59 . 2009-02-11 15:59      d----c---   C:\Binaries
        2009-02-11 15:57 . 2009-02-11 15:57      d----c---   c:\windows\system32\URTTemp
        2009-02-11 15:50 . 2009-02-11 15:59      d----c---   c:\program files\Common Files\BitDefender

        .
        ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2009-02-28 02:40   ---------   dc----w   c:\program files\lg_fwupdate
        2009-02-27 19:28   ---------   dc----w   c:\documents and settings\Administrator\Application Data\uTorrent
        2009-02-25 05:11   ---------   dc----w   c:\program files\LimeWire
        2009-02-14 23:52   ---------   dc----w   c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
        2009-02-13 04:10   ---------   dc----w   c:\program files\7-Zip
        2009-02-12 14:33   ---------   dc----w   c:\documents and settings\All Users\Application Data\WinZip
        2009-02-11 21:04   104,328   -c--a-w   c:\windows\system32\drivers\bdfndisf.sys
        2009-01-25 20:56   ---------   dc----w   c:\documents and settings\Administrator\Application Data\Apple Computer
        2009-01-23 21:30   ---------   dc----w   c:\program files\Apple Software Update
        2009-01-23 21:30   ---------   dc----w   c:\documents and settings\All Users\Application Data\Apple
        2009-01-20 16:13   ---------   dc----w   c:\program files\DivX
        2009-01-14 19:42   ---------   dc----w   c:\program files\CDisplay
        2009-01-07 19:48   ---------   dc----w   c:\documents and settings\All Users\Application Data\ATI MMC
        2009-01-07 06:44   ---------   dc----w   c:\documents and settings\Administrator\Application Data\vlc
        2008-12-20 23:15   826,368   -c--a-w   c:\windows\system32\wininet.dll
        2008-12-18 16:48   410,984   -c--a-w   c:\windows\system32\deploytk.dll
        2008-12-11 00:33   86,016   -c--a-w   c:\windows\system32\dpl100.dll
        2008-12-11 00:33   200,704   -c--a-w   c:\windows\system32\dtu100.dll
        2008-12-09 02:28   593,920   -c--a-w   c:\windows\system32\dpuGUI11.dll
        2008-12-09 02:28   57,344   -c--a-w   c:\windows\system32\dpv11.dll
        2008-12-09 02:28   344,064   -c--a-w   c:\windows\system32\dpus11.dll
        2008-12-09 02:28   294,912   -c--a-w   c:\windows\system32\dpu11.dll
        2008-10-05 19:53   22,328   -c--a-w   c:\documents and settings\Administrator\Application Data\PnkBstrK.sys
        2004-10-01 19:00   40,960   -c--a-w   c:\program files\Uninstall_CDS.exe
        2002-05-28 12:19   61,440   -c--a-w   c:\windows\inf\i386\onetUSD.dll
        2002-05-20 12:22   36,864   -c--a-w   c:\windows\inf\i386\Vizmicro.dll
        2002-05-20 12:20   172,032   -c--a-w   c:\windows\inf\i386\viceo.dll
        2002-05-20 12:02   225,280   -c--a-w   c:\windows\inf\i386\rtscan.dll
        2001-08-03 22:29   13,824   -c--a-w   c:\windows\inf\i386\Usbscan.sys
        2008-12-16 22:52   61,440   -c--a-w   c:\program files\mozilla firefox\components\FFComm.dll
        .

        (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        *Note* empty entries & legit default entries are not shown
        REGEDIT4

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "ATI Launchpad"="c:\program files\ATI Multimedia\main\launchpd.exe" [2004-06-15 106571]
        "ATI Remote Control"="c:\program files\ATI Multimedia\RemCtrl\ATIRW.exe" [2004-04-16 196608]
        "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2007-12-01 15360]
        "Google Update"="c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-02-04 133104]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-01-23 155648]
        "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-23 126976]
        "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-07-10 339968]
        "ATI DeviceDetect"="c:\program files\ATI Multimedia\main\ATIDtct.EXE" [2004-06-15 69705]
        "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-18 136600]
        "type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2004-06-03 172032]
        "RemoteControl"="c:\program files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
        "InCD"="c:\program files\Ahead\InCD\InCD.exe" [2005-07-08 1397760]
        "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
        "LGODDFU"="c:\program files\lg_fwupdate\fwupdate.exe" [2008-12-29 548864]
        "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-07-28 185896]
        "OneTouch Monitor"="c:\program files\Visioneer OneTouch\OneTouchMon.exe" [2002-05-28 86016]
        "BDAgent"="c:\program files\BitDefender\BitDefender 2009\bdagent.exe" [2009-01-09 741376]
        "BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2009\IEShow.exe" [2008-10-17 69632]
        "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
        "SoundMan"="SOUNDMAN.EXE" [2005-04-15 c:\windows\SOUNDMAN.EXE]

        c:\documents and settings\All Users\Start Menu\Programs\Startup\
        Supero Doctor III Client.lnk - c:\program files\SUPERMICRO\SDIII\SuperoDoctor.exe [2008-07-23 397312]
        Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]

        [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
        "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
        "vidc.ffds"= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
        SecurityProviders   msapsspc.dll, schannel.dll, digest.dll, credssp.dll, msnsspc.dll

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
        "EnableFirewall"= 0 (0x0)
        "DisableUnicastResponsesToMulticastBroad cast"= 0 (0x0)

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
        "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
        "%windir%\\system32\\sessmgr.exe"=
        "c:\\Program Files\\LimeWire\\LimeWire.exe"=
        "c:\\Program Files\\uTorrent\\uTorrent.exe"=
        "c:\\WINDOWS\\system32\\PnkBstrA.exe"=
        "c:\\WINDOWS\\system32\\PnkBstrB.exe"=
        "c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
        "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
        "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
        "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=

        R1 ISAIONT;ISAIONT;c:\windows\system32\drivers\IsaIoNt.sys [2008-07-23 3853]
        R1 MemMapNt;MemMapNt;c:\windows\system32\drivers\memmapnt.sys [2008-07-23 3908]
        R1 SMBus;SMBus;c:\windows\system32\drivers\smbus.sys [2008-07-23 10112]
        R1 superbmc;superbmc;c:\windows\system32\drivers\SUPERBMC.SYS [2008-07-23 14169]
        R2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2009\BDVEDISK.sys [2008-10-06 82696]
        R2 SuperMicro Health Assistant;SuperMicro Health Assistant;c:\program files\SUPERMICRO\SDIII\NTService.exe [2008-07-23 131072]
        R2 Supero SD3Service Daemon;Supero SD3Service Daemon;c:\windows\system32\SD3Service.exe [2008-07-23 40960]
        R2 Xitami;Xitami Web Server;c:\program files\SUPERMICRO\SDIII\xitami\xiwinnt.exe [2008-07-23 552960]
        R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [2008-09-18 111112]
        R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [2008-10-17 104328]
        S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [2008-07-17 118784]
        S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-09-18 33752]

        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
        bdx   REG_MULTI_SZ      scan
        .
        Contents of the 'Scheduled Tasks' folder

        2009-01-23 c:\windows\Tasks\AppleSoftwareUpdate.job
        - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

        2009-02-27 c:\windows\Tasks\ErrorFix Scan.job
        - c:\program files\ErrorFix\ErrorFix.exe []

        2009-02-27 c:\windows\Tasks\ErrorFix Scan.job
        - c:\program files\ErrorFix []

        2009-02-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-606747145-790525478-1417001333-500.job
        - c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-04 00:32]

        2009-02-28 c:\windows\Tasks\RegCure Program Check.job
        - c:\program files\RegCure\RegCure.exe [2009-02-13 23:20]

        2009-02-26 c:\windows\Tasks\RegCure.job
        - c:\program files\RegCure\RegCure.exe [2009-02-13 23:20]
        .
        .
        ------- Supplementary Scan -------
        .
        uStart Page = hxxp://www.google.com/
        uInternet Connection Wizard,ShellNext = iexplore
        IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
        FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ig28otl2.default\
        FF - prefs.js: browser.startup.homepage - ww.google.com
        FF - component: c:\program files\Mozilla Firefox\components\FFComm.dll
        FF - plugin: c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll
        FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
        FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
        .

        **************************************************************************

        catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2009-02-27 22:44:53
        Windows 5.1.2600 Service Pack 3, v.5657 NTFS

        scanning hidden processes ... 

        scanning hidden autostart entries ...

        scanning hidden files ... 

        scan completed successfully
        hidden files: 0

        **************************************************************************
        .
        --------------------- LOCKED REGISTRY KEYS ---------------------

        [HKEY_USERS\Administrator\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
        "??"=hex:8e,2e,5c,88,69,c3,a3,16,8f,2c,e2,70,9e,01,5e,ac,72,c1,33,82,c8,53,62,
           df,5f,bc,e7,90,01,a3,5c,79,9e,f3,19,4a,c6,b7,2e,18,4b,6d,fd,df,a4,3c,c4,2c,\
        "??"=hex:0f,48,1a,76,ce,fe,3d,eb,b8,9e,e1,3e,48,7b,fe,fd
        .
        --------------------- DLLs Loaded Under Running Processes ---------------------

        - - - - - - - > 'winlogon.exe'(1008)
        c:\windows\system32\Ati2evxx.dll
        .
        Completion time: 2009-02-27 22:46:56
        ComboFix-quarantined-files.txt  2009-02-28 03:46:42

        Pre-Run: 105,960,312,832 bytes free
        Post-Run: 106,018,836,480 bytes free

        220   --- E O F ---   2009-02-27 05:01:06

          • Click START then RUN
          • Now type Combofix /u in the runbox
          • Make sure there's a space between Combofix and /u
          • Then hit Enter.
          • The above procedure will:
          • Delete the following:
          • ComboFix and its associated files and folders.
          • Reset the clock settings.
          • Hide file extensions, if required.
          • Hide System/Hidden files, if required.
          • Set a new, clean Restore Point.
          .
          How is the computer running now?
        i did it in the run box. it told to disable antivirus and i did it. a blank blue screen box pop up and after a couple of seconds it said combo fix is uninstalled. that was it.

        my firefox is still slow loadin up when i click on it. i dont feel anything different still the same. dont know what you mean.
        i do another hijack this and post the log up again.

        dude thanks for all your help. i will recommend you to others.  Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 11:05:47 PM, on 2/27/2009
        Platform: Windows XP SP3, v.5657 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16791)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Ahead\InCD\InCDsrv.exe
        C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\Program Files\Microsoft IntelliType Pro\type32.exe
        C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
        C:\Program Files\Ahead\InCD\InCD.exe
        C:\Program Files\Common Files\LightScribe\LSSrvc.exe
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
        C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
        C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
        C:\WINDOWS\system32\PnkBstrA.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\SUPERMICRO\SDIII\NTService.exe
        C:\WINDOWS\system32\SD3Service.exe
        C:\WINDOWS\system32\WinVNC.exe
        C:\WINDOWS\system32\SearchIndexer.exe
        C:\Program Files\SUPERMICRO\SDIII\Xitami\xiwinnt.exe
        C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
        C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
        C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
        C:\WINDOWS\explorer.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
        O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
        O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
        O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
        O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
        O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
        O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
        O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
        O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
        O4 - HKLM\..\Run: [OneTouch Monitor] C:\Program Files\Visioneer OneTouch\OneTouchMon.exe
        O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
        O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
        O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
        O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe"
        O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
        O4 - Global Startup: Supero Doctor III Client.lnk = C:\Program Files\SUPERMICRO\SDIII\SuperoDoctor.exe
        O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
        O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
        O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
        O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
        O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
        O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (MSN Games – Texas Holdem Poker) - http://zone.msn.com/bingame/zpagames/zpa_txhe.cab79352.cab
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
        O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
        O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
        O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. http://www.bitdefender.com - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
        O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
        O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
        O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
        O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
        O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
        O23 - Service: SuperMicro Health Assistant - Unknown owner - C:\Program Files\SUPERMICRO\SDIII\NTService.exe
        O23 - Service: Supero SD3Service Daemon - Unknown owner - C:\WINDOWS\system32\SD3Service.exe
        O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
        O23 - Service: TridiaVNC Server (winvnc) - Tridia Corporation - C:\WINDOWS\system32\WinVNC.exe
        O23 - Service: Xitami Web Server (Xitami) - Unknown owner - C:\Program Files\SUPERMICRO\SDIII\Xitami\xiwinnt.exe

        --
        End of file - 9216 bytes
        i found a way to disable the anitvirus and firewall. once you the icon on right top corner it will say switch to advanced view. another window pop up and left side of screen you will see a list and anti-virus and firewall is on the list. once you click on them you will see disable and your done.

        you can reword and put in link you gave for people who has latest bitdefender.  Have HijackThis fix this entry:

        O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)

        Close all browsers before clicking Fix checked.

        --

        Do you mean when you first start Firefox? If so then that's how it is. Mine takes a while to open when it first starts also.
        954.

        Solve : okay, so I've used the combofix...?

        Answer»

        So I USED the combfix to get rid of the crap that got on my computer.
        I have no idea what I have to delete from the other notepad document.
        Here's the log.

        Thanks

        [ATTACHMENT DELETED by ADMIN]

        955.

        Solve : Can't uninstall all of program?

        Answer»

        I tried updating my antivirus program and wasn't able to CONNECT to the internet. After several attempts to find the cause, I decided to UNINSTALL and reinstall the program. After re-installing The same thing happened. I uninstalled again, but could not uninstall the firewall portion of the program. The anti virus program is CA Internet Security Suite 2007, which is provided by the cable company I have as a server. When trying to uninstall, I get an error message (Error E9011), with a message stating: You do not have sufficient privileges to install or uninstall CA Personal Fiewall. Unable to update registry key: HKEY_LOCAL_MACHINE\SOFTWARE\classes\.efw.
        It also says Try logging on as Administrator. I am already logged on as the Administrator.
        My OS is Windows Vista.
        Does anyone have any SUGGESTIONS as to how I can uninstall the remainder of this program?

        956.

        Solve : Vista Firewall?

        Answer»

        Does anyone have any experience with this firewall for Vista?I don't have any experience with it but it gets GOOD reviews.

        Quote

        http://www.mywot.com/en/scorecard/sphinx-soft.com
        I have downloaded the firewall control from this site and it has MADE a ONE way not so good firewall into a excellent two way firewall.Good to use and easy to set up
        THANKS, Evil. I installed it on laptop and also on my daughter's laptop and appears to work well. I had ZoneAlarm but apparently, it doesn't get along well with Vista.
        957.

        Solve : further help following your mwsoemon instructions?

        Answer»

        That looks a lot better!

        Go to Add or Remove Programs and uninstall: Viewpoint Media Player

        Go to START > Run and type NOTEPAD.exe then click OK.

        Copy and paste the following text WITHIN the code BOX into the new Notepad file.

        Code: [Select]ECHO OFF
        sc stop "AOLService"
        sc delete "AOLService"
        exit
        In Notepad select File and Save as
        Choose the Save to location to be the Desktop and for the File name: type in fixme.bat making sure that the Save as type field says All files.

        Next double click fixservice.bat to run it.
        A black box should open and close after a short time, this is normal.
        Do not continue until the black box has closed
        Delete fixservice.bat from the Desktop.

        ----------

        How is the computer running now?

        .Thanks for you time & help evilfantasy.  I put new hijack log in the VA9 tool and all ok.

        Can I also ask if it ok to post hijack log for my daughters LAPTOP who also had the same mwsoemon malware for you to check?   Yes but start a new topic for a different computer.

        958.

        Solve : newbie can't restore OS because of virus(es)?

        Answer»

        Hey all!<
        My computer is self destructing, I did not renew my subscription to RegCure and everything has been going south since. I am no longer even able to log in without gettign a blue screen. I know I am loaded with viruses. I was in the middle of a VirusScan re-install with McAfee when I lost internet access. Now it's to the point that I can no longer log on. When I try to do an OS repair/ restore using manufacture's disk I get error messages that certain files do not pass the windows logo test, i say to copy anyway but then install does not finalize. I don't know where to start, I don't necessarily WANT to reformat the whole drive. Can anyone guide me in what STEPS to take using dos commands? I do not have anti virus software installed and do not have internet access. all I have is a DOS prompt
        I am running XP home.
        (this is not the infected computer)
        Thanks,
        RayThanks for all your help, I did the recommended reinstall  but w/out formatting, reinstalled McAfee virus scan plus, and have been updating and rescanning for 2 days straight and FINALLY have a "Clean" scan log! yea!!!  , I was able to boot in safe MODE and change ownership of all my old password protected folders too! Thanks for all your help!!!
        Ray

        959.

        Solve : IE Script Error - opens as a pop-up for many programs?

        Answer»

        Thank GOODNESS!! I was starting to get SORT of stumped.

        Now to finish.

        Disable/Enable the System Restore Utility to flush old corrupted restore points

        1) Right click the My Computer icon on the Desktop and click on Properties.
        2) Click on the System Restore tab.
        3) Put a check mark next to Turn off System Restore on All Drives
        4) Click the OK button.
        5) You will be prompted to restart the computer. Click the Yes button.

        Now re-enable System Restore

        To re-enable the System Restore Utility, follow steps one to five and on step three remove the check mark next to 'Turn off System Restore on All Drives'.

        1) Right click the My Computer icon on the Desktop and click on Properties.
        2) Click on the System Restore tab.
        3) Remove the check mark next to Turn off System Restore on All Drives
        4) Click the OK button.

        ----------

        Here are some great FREE tools to help you keep you safe. These tools use little or no resources so won't slow down your PC.

        To prevent unknown applications from being installed on your computer install WinPatrol 2008
        * Using Winpatrol to protect your computer from malicious software

        I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's EASY and it's free.

        SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
        * Using SpywareBlaster to protect your computer from Spyware and Malware
        * If you don't know what ActiveX controls are, SEE here

        Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

        Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

        960.

        Solve : Avira Anti-Virus?

        Answer»

        Hello all,

        I just have a quick question.  I am currently using AVG, and was thinking about trying Avira.  Does the free Avira program offer email protection?  Yes.

        http://www.free-av.com/en/products/1/avira_antivir_personal__free_antivirus.html

        AntiPhishing
        AntiSpyware
        AntiRootkit
        Email protection
        Award winning malware protection
        Thanks evilfantasy, however; according to the specs. the free avira does NOT offer the email protection.  Perhaps AVG may be my better optionoops, I didn't see that.

        Actually though email protection is a bit confusing. As long as an antivirus is running you have email protection. Products ADVERTISE it but it's there anyway.So I should not be worried about my email not being protected with Avira?No you don't need to worry. Opening an attachment in an email is just like when you download software. The antivirus is protecting you either way. It won't scan them before you open them but that rarely does much good anyway.

        There is also Avast you could look at. It does everything that AVG and Avira do and more, for free.Evilfantasy,

        Thanks you very much for your input   I can now at LEAST have some peace of mind knowing my email is protected.

        I appreciate the input on the Avast program.  I will check it out.

        Thanks again!Email safety is pretty basic, with or without an antivirus. If it contains a virus many times it will install before your antivirus can stop it. Some even have the ability to turn off your AV long enough to install themselves. Or they will lie dormant until you start or shut down your PC. Then nothing is running that can stop them from invading.

        Safe Email Practices

        #  Attachments

        Attachments require special attention. They could contain viruses - even if it's coming from the computer of a friend. Therefore:

        1. Don't open attachments if you don't know who they're from
        2. Even if you do know who it's from, if the subject line sounds SUSPICIOUS, contact your friend before opening. Viruses often "spoof" the from address (masquerade as SOMEONE else - usually getting the name from an infected computer's address book - the infected computer could be a friend's which is why all email - even from friends should be held suspect.) Viruses also often try to come up with a compelling  subject line to GET you to open them.

        961.

        Solve : After deleting virus still get error message.?

        Answer»

        This all HAPPENED when I download VISTA Transformation Pack 9 which was rumored to have Trojans.
        I first got the error and went in to System 32 and found the file and deleted it, then went to CCLEANER and got rid of it's trace.
        Then also AVG found it and deleted it. Since then I have not found the virus but I still KEEP getting this message every time I boot up my computer.

        View Image to view it larger.

        Then I click Ok and get this

        After that everything is okay..

        So how can I get rid of this?

        962.

        Solve : So many problems I'm having, and don't know and having problems understanding?

        Answer»

        I'll try and explain things as best as I can.
        I have been having so many problems over the years with my computer. Seems to be getting worse especially over the past few months or so.
        It is a DELL Computer Dimension 8200
        Have hired several repairmen over the years, and they seem to cause new problems all the time.
        Problems started when I had to download AIM for an online computer class I had just registered for. Something called an MBKWBar Tool bar came through with it and installed itself in Internet Explorer and kept FLOODING me with pop up ads and of course would crash with all the pop ups. So, that is the first time we heard of SPYWARE, ad ware, all that stuff. We had heard of viruses, but not the other stuff. Had Norton Anti virus when I got infected with the tool bar.
        Oh dear, now while on my mom's computer something is
        COMING up and now my mom is mad at me. Thinks I've got her computer hacked. It says Spyware Protect 2009 alert.
        Infiltration Alert-
        Your computer is being attacked by an internet virus. It COULD be a password stealing attack, a trojan- dropper or similar.
        Details:
        Attack from: 153.74.175.9, port 22223
        Attacked Port: 57897
        Threat: BankerFox.A
        Do You want to block this attack? yes or no
        We don't know whether to put yes or no because the repairmen warned us that when hitting yes or no can cause more stuff to come through too.

        I also keep getting parsing errors, and now learning that may have something to do with CSS, and I have no idea anything or how to fix this type of stuff. Getting the same problems on both mine and mom's computer.
        Oh dear, it's happening again on my mom's computer.
        Spyware Protect 2009 alert.
        Saying it again and says
        Details
        Attack from: 148.3.173.122, port 49786
        Attacked port: 32816
        Threat: Win32/Nuquel.E
        Do you want to block this attack?

        If I click yes, it takes me somewhere and then asks for a credit card number. What do I do?

        963.

        Solve : Can a camera memory card catch a viruse??

        Answer»

        My girl friend took the memory card out of her camera, PUT it in a card reader, and uploaded pictures to a computer. Come to find out the computer had a viruse, can her memory card catch that viruse by just uploading the pictures.  Yes. Memory cards are like flash drives and can become infected. Below is a tool to cleanup flash drives, memory cards, cell phones etc.

        Flash Drive Cleanup

        Download Flash Disinfector by sUBs and save it to your Desktop.
         

        • Double-click Flash_Disinfector.exe to run it.
        • Your desktop and icons may disappear. This is normal.
        • It will do a cleanup of removable storage devices, and write a protected Autorun.inf file to help prevent re-infection.
        • Follow any prompts that may appear.
        • The utility may ask you to insert your flash drive and/or other removable drives INCLUDING your mobile phone. Please do so and allow the utility to clean up those drives as well.
        • WAIT until it has FINISHED scanning and then exit the program.
        • There will be no GUI INTERFACE or log file produced.
        • Reboot your computer when done.
        Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder...it will help protect your drives from future infection.
        964.

        Solve : Re: removing a virus?

        Answer» HI,

        You can use SYMANTEC ANTIVIRUS it automatically remove virus.


        Tech Tiger1Come again?Sorry, I split this from ANOTHER POST and forgot to lock it.
        965.

        Solve : Desktop Icons Flashing On and Off as well as Taskbar?

        Answer»

        My desktop icons are flashing on and off as well as my taskbar.  After reading some of the topics already I have already ran the hijackthis and the results are to follow.  Any help is grately appreciated.

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 7:06:40 AM, on 2/14/2009
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16791)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\WLTRYSVC.EXE
        C:\WINDOWS\System32\bcmwltry.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
        C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\WINDOWS\eHome\ehRecvr.exe
        C:\WINDOWS\eHome\ehSched.exe
        C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
        C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Trend Micro\BM\TMBMSRV.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\WINDOWS\system32\dllhost.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\ehome\ehtray.exe
        C:\Program Files\Common Files\AOL\1200796598\ee\AOLSoftware.exe
        C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
        C:\WINDOWS\system32\WLTRAY.exe
        C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
        C:\WINDOWS\stsystra.exe
        C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
        C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
        C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
        C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
        C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
        C:\WINDOWS\eHome\ehmsas.exe
        C:\Program Files\QuickTime\QTTask.exe
        c:\program files\common files\aol\1200796598\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
        C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
        C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        c:\program files\common files\aol\1200796598\ee\aolsoftware.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\Program Files\Microsoft ActiveSync\wcescomm.exe
        C:\PROGRA~1\MI3AA1~1\rapimgr.exe
        C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
        C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
        C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
        C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
        C:\WINDOWS\system32\taskmgr.exe
        C:\WINDOWS\system32\wuauclt.exe
        F:\HiJackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
        O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
        O3 - Toolbar: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll
        O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
        O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1200796598\ee\AOLSoftware.exe
        O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
        O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
        O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
        O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
        O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
        O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
        O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
        O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
        O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
        O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
        O4 - HKLM\..\Run: [HPHUPD08] C:\Program Files\Hewlett-Packard\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKCU\..\Run: [Power2GoExpress] NA
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
        O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
        O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
        O4 - Global Startup: HP Image Zone FAST Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
        O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
        O4 - Global Startup: officejet 6100.lnk = ?
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
        O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
        O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
        O9 - Extra button: CREATE Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
        O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
        O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
        O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
        O16 - DPF: {CAFECAFE-0013-0001-0028-ABCDEFABCDEF} (JInitiator 1.3.1.28) - https://esis.ncwise.org/forms/jinitiator/jinit13128.exe
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
        O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
        O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
        O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
        O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: avast! iAVS4 CONTROL Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
        O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
        O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
        O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
        O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
        O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

        --
        End of file - 11847 bytes
        Welcome to CH.

        Download CCleaner Slim and save it to your Desktop.
        When the file has been saved, go to your Desktop and double-click on ccsetupxxx_slim.exe
        Follow the prompts to install the program.
        Complete the installation then:

        • Double-click the CCleaner shortcut on the desktop to start the program.
        • Click on the Options block on the left, then choose Cookies.
          • Under Cookies to Delete, highlight any cookies you would like to retain permanently
          • Click the right arrow > to move them to the Cookies to Keep window.
        • Go into Options > Advanced uncheck Only delete files in Windows Temp folders older than 48 hours
        • Click Cleaner on the left then Run Cleaner on the right to run the program.
        • Important: Make sure that ALL browser windows are closed before selecting Run Cleaner
        • Caution: It is not recommended that you use the 'Registry' feature unless you are very familiar with the registry.
        • Exit CCleaner after it has completed its process.
        .
        ----------

        Download Malwarebytes' Anti-Malware (MBAM)

        • Double-click mbam-setup.exe and follow the prompts to install the program.
        • At the end, be sure a checkmark is placed next to the following:
          • Update Malwarebytes' Anti-Malware
          • Launch Malwarebytes' Anti-Malware
          • Then click Finish.
          • If an update is found, it will download and install the latest version.
          • Once the program has loaded, select Perform quick scan, then click Scan.
          • When the scan is complete, click OK, then Show Results to view the results.
          • Be sure that everything is checked, and click Remove Selected.
          • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
          • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
          • Copy and Paste the entire report in your next reply.
          Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.
          966.

          Solve : Trojan, no idea what kind, please help, have scan logs?

          Answer»

          i have an hp computer with windows xp and i was told by norton that it has detected a Trojan last night. my computer shut down unexpectedly a couple of times this morning but now it seems to be staying on, the only other symptoms i have so far is every time i right click on any file or try to drag it SOMEWHERE Data Execution Prevention program shows up and shuts windows explorer down. i can still open the programs its just i can't move them or delete them. i've been running scans with Norton but it doesn't detect anything anymore. i know it can't get rid of it so i was hoping someone might know what i should do. please help.

          i have the scan logs below...

          SUPERANTISPYWARE Scan Log
          http://www.superantispyware.com

          Generated 02/13/2009 at 08:23 PM

          Application Version : 4.25.1012

          Core RULES Database Version : 3754
          Trace Rules Database Version: 1718

          Scan type       : Complete Scan
          Total Scan Time : 01:23:38

          Memory items scanned      : 554
          Memory threats detected   : 0
          Registry items scanned    : 6504
          Registry threats detected : 0
          File items scanned        : 176177
          File threats detected     : 0




          Malwarebytes' Anti-Malware 1.34
          Database version: 1736
          Windows 5.1.2600 Service Pack 3

          2/13/2009 8:57:26 PM
          mbam-log-2009-02-13 (20-57-26).txt

          Scan type: Quick Scan
          Objects scanned: 71938
          Time elapsed: 4 minute(s), 3 second(s)

          Memory Processes Infected: 0
          Memory Modules Infected: 0
          Registry Keys Infected: 0
          Registry Values Infected: 0
          Registry Data Items Infected: 0
          Folders Infected: 0
          Files Infected: 0

          Memory Processes Infected:
          (No malicious items detected)

          Memory Modules Infected:
          (No malicious items detected)

          Registry Keys Infected:
          (No malicious items detected)

          Registry Values Infected:
          (No malicious items detected)

          Registry Data Items Infected:
          (No malicious items detected)

          Folders Infected:
          (No malicious items detected)

          Files Infected:
          (No malicious items detected)






          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 9:05:17 PM, on 2/13/2009
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\WINDOWS\eHome\ehRecvr.exe
          C:\WINDOWS\eHome\ehSched.exe
          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
          C:\WINDOWS\system32\nvsvc32.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\Tablet.exe
          C:\WINDOWS\system32\WTablet\TabUserW.exe
          C:\WINDOWS\system32\Tablet.exe
          C:\WINDOWS\ehome\ehtray.exe
          C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
          C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
          C:\Program Files\Common Files\Symantec Shared\ccApp.exe
          C:\WINDOWS\eHome\ehmsas.exe
          C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
          C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
          C:\WINDOWS\system32\dllhost.exe
          C:\Program Files\QuickTime\QTTask.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
          C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
          C:\HP\KBD\KBD.EXE
          C:\WINDOWS\ALCXMNTR.EXE
          c:\windows\system\hpsysdrv.exe
          C:\Program Files\Java\jre1.5.0\bin\jusched.exe
          C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
          C:\Program Files\Symantec\LiveUpdate\AUPDATE.EXE
          C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
          C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
          C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
          C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
          C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
          C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
          C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
          C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
          R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
          O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\UIBHO.dll
          O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
          O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
          O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
          O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
          O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
          O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
          O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
          O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
          O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [WildTangent CDA] "C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll"
          O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
          O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
          O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\HP_Administrator\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
          O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
          O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
          O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
          O8 - Extra context menu item: CACHED Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
          O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
          O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
          O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
          O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
          O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
          O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
          O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
          O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
          O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
          O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
          O24 - Desktop Component 0: (no name) - http://l.yimg.com/a/i/ww/thm/1/whood.png

          --
          End of file - 12958 bytes






          thats it i think....one more question, whats probably the best thing to use instead of Norton. i don't care if its free or not.

          thankyouNORTON IS NOT GREAT SECURITY AN EXPERT WILL GIVE YOU BETTER

          967.

          Solve : viruses in yahoo messenger?

          Answer»

          hi GUYS am DYING please i went online to chat with friends but discovered that ma pc is just sending stupid messages to my friends in a certain language can that be viruses or spyware help please this is the message "open dis natatawata"Download random's system INFORMATION tool (RSIT) by random/random from and save it to your Desktop.

          • Double click on RSIT.exe to run.
          • Click Continue at the disclaimer screen.
          • Once it has finished, TWO LOGS will open.
          • log.txt <will be maximized and info.txt <will be minimized
          • Please post the contents of both logs in the next reply.
          968.

          Solve : hijack this file DELETING AUTORUN.ini?

          Answer»

          i have a virus in my USB that my antivi CNT find
          i tryd NOD32,AVG but still.............
          my files are gone but its there when im scanning but
          when i OPEN itits empty.......
          can any one help me plsssss thnks
          Flash Drive Cleanup

          Download Flash Disinfector by sUBs and save it to your Desktop.
           

          • Double-click Flash_Disinfector.exe to RUN it.
          • Your desktop and icons may disappear. This is normal.
          • It will do a cleanup of removable storage devices, and write a protected Autorun.inf file to help prevent re-infection.
          • Follow any prompts that may appear.
          • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
          • Wait until it has finished scanning and then exit the program.
          • There will be no GUI interface or log file produced.
          • Reboot your computer when done.
          Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder...it will help protect your drives from future infection.

          ----------

          Now POST a new HijackThis log please.
          969.

          Solve : Windows cannot find F:\Windows\eksplorasi.pif?

          Answer»

          Hello

          I am getting the following error:

          Windows cannot find F:\Windows\eksplorasi.pif (Win XP Pro is on the F drive).

          I ran AVG, but it picked up nothing. But then I did a CC Cleaner test and it produced what is in the attachment. Likewise with Malwarebytes' Anti-Malware.

          The Malwarebytes' Anti-Malware appears to have detected a couple of problems in the Registry.

          I haven't downloaded HiJack yet.

          Thanks for any help.

          Steve



          [attachment deleted by admin]That SPECIFIC file is most likely part of a worm. Clean the registry with a registry cleaner. If that doesn't work, I have something to ask. Does it happen on startup?Do not advise anyone to run a registry cleaner in this forum please.

          When a computer is running bad and having errors a reg cleaner is the LAST thing you WANT to run.Whoops. Sorry, didn't know about that. Will keep it in mind.Hello

          Thanks for your contributions so far.

          Yes, the error message only appears at startu. I have used Avast, AVG, CC Cleaner and one or two other programmes, but the error still appears. I have also tried HiJack this and I would appreciate it if someone could look at the log:

          Logfile of Trend Micro HijackThis v2.0.2
          Scan SAVED at 12:17:21, on 08/02/2009
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.5730.0013)
          Boot mode: Normal

          Running processes:
          F:\WINDOWS\System32\smss.exe
          F:\WINDOWS\system32\winlogon.exe
          F:\WINDOWS\system32\services.exe
          F:\WINDOWS\system32\lsass.exe
          F:\WINDOWS\system32\svchost.exe
          F:\WINDOWS\System32\svchost.exe
          F:\WINDOWS\system32\spoolsv.exe
          F:\WINDOWS\Explorer.exe
          F:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
          F:\Program Files\Java\jre6\bin\jqs.exe
          F:\WINDOWS\system32\slserv.exe
          F:\Program Files\Multi-Direction Opitcal Mouse\Multi-Direction Opitcal Mouse\2.0\ACQTMAPP.exe
          F:\WINDOWS\system32\VTTimer.exe
          F:\Program Files\Java\jre6\bin\jusched.exe
          F:\PROGRA~1\AVG\AVG8\avgtray.exe
          F:\WINDOWS\system32\ctfmon.exe
          F:\Program Files\Messenger\msmsgs.exe
          F:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
          F:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
          F:\PROGRA~1\AVG\AVG8\avgrsx.exe
          F:\WINDOWS\system32\wscntfy.exe
          F:\WINDOWS\system32\wuauclt.exe
          F:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
          F2 - REG:system.ini: Shell=Explorer.exe "F:\WINDOWS\eksplorasi.pif"
          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - F:\Program Files\AVG\AVG8\avgssie.dll
          O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre6\bin\ssv.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - F:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - F:\Program Files\Java\jre6\lib\deploy\jqs\IE\jqs_plugin.dll
          O4 - HKLM\..\Run: [ACQTMOUSE] "F:\Program Files\Multi-Direction Opitcal Mouse\Multi-Direction Opitcal Mouse\2.0\ACQTMAPP.exe"
          O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\Program Files\Java\jre6\bin\jusched.exe"
          O4 - HKLM\..\Run: [Bron-Spizaetus] "F:\WINDOWS\ShellNew\bronstab.exe"
          O4 - HKLM\..\Run: [AVG8_TRAY] F:\PROGRA~1\AVG\AVG8\avgtray.exe
          O4 - HKCU\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [MSMSGS] "F:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKCU\..\Run: [Tok-Cirrhatus] "F:\Documents and Settings\Steve Higham\Local Settings\Application Data\smss.exe"
          O4 - HKCU\..\Run: [SUPERAntiSpyware] F:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Global Startup: Adobe Gamma Loader.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
          O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
          O4 - Global Startup: Adobe Reader Synchronizer.lnk = F:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
          O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
          O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - F:\Program Files\AVG\AVG8\avgpp.dll
          O20 - AppInit_DLLs: avgrsstx.dll
          O20 - Winlogon Notify: !SASWinLogon - F:\Program Files\SUPERAntiSpyware\SASWINLO.dll
          O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - F:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - F:\Program Files\Java\jre6\bin\jqs.exe
          O23 - Service: Macromedia Licensing Service - Unknown owner - F:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
          O23 - Service: SmartLinkService (SLService) - Smart Link - F:\WINDOWS\SYSTEM32\slserv.exe

          --
          End of file - 4968 bytes

          Thanks again.

          SteveOpen HijackThis and select Do a system scan only.

          Place a check mark next to:

          - F2 - REG:system.ini: Shell=Explorer.exe \"F:\WINDOWS\eksplorasi.pif\"
          - O4 - HKLM\..\Run: [Bron-Spizaetus] \"F:\WINDOWS\ShellNew\bronstab.exe\"
          - O4 - HKCU\..\Run: [Tok-Cirrhatus] \"F:\Documents and Settings\Steve Higham\Local Settings\Application Data\smss.exe\"

          Now close ALL windows except for HijackThis and click Fix checked.

          ----------

          Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

          Go to Start > Run and type notepad.exe then click OK

          Copy and paste the below into Notepad and save as fixme.reg to Your Desktop

          Code: [Select]REGEDIT4

          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
          "Bron-Spizaetus"=-
          "Tok-Cirrhatus"=-
          Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry.

          Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it did not work.

          Delete the fixme.reg from the Desktop.

          ----------

          Flash Drive Cleanup

          You have an autorun worm that will infect any flash drive you have used on this computer and any other they have been used on. Please have any flash drives ready as Flash Disinfector will ask for them.

          Download Flash Disinfector by sUBs and save it to your Desktop.
           

          • Double-click Flash_Disinfector.exe to run it.
          • Your desktop and icons may disappear. This is normal.
          • It will do a cleanup of removable storage devices, and write a protected Autorun.inf file to help prevent re-infection.
          • Follow any prompts that may appear.
          • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
          • Wait until it has finished scanning and then exit the program.
          • There will be no GUI interface or log file produced.
          • Reboot your computer when done.
          .
          Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder...it will help protect your drives from future infection.

          ----------

          Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

          Link #1
          Link #2

          **Note:  It is important that it is saved directly to your Desktop

          Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

          Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
           
          Double click combofix.exe & follow the prompts.
          When finished ComboFix will produce a log for you.
          Post the ComboFix log in your next reply.

          Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

          Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

          If you have problems with ComboFix usage, see How to use ComboFixHello evilfantasy

          Many thanks for all your work. I'll try it and post back. I couldn't download the Flash disinfector from your post, but I've downloaded it from elsewhere.

          Cheers again.

          SteveHello evilfantasy

          The .pif error message has now gone and I have run the Flash Disinfector. Many thanks for your advice.

          I also downloaded ComboFix, saving it to my desktop and disabling my AVG plus other antivirus software, but I get a permission error (Windows cannot find the path).

          I am not able, therefore, to post the ComboFix log.

          Many thanks, anyway, for removing the .pif error I was getting!

          SteveBefore you begin the SDFix instructions you should copy these instructions in a Notepad file and save them to your desktop or print them for easy reference. Much of SDFix will be done in Safe mode and you will be unable to access this web page after booting into Safe mode.

          Download SDFix by AndyManchesta and save it to your desktop.

          When using this tool, you must use the Administrator's account or an account with Administrative rights


          * Now, double-click on the SDFix icon that should now be residing on your desktop. If a Open File - Security Warning box opens, click on the Run button.
          * A window will now open showing SDFix being extracted into the C:\SDFix folder.     
          * Once the installation program has finished extracting SDFix, it will open a Notepad with further instructions.
          * DO NOT use it just yet.

          Reboot your computer in Safe Mode using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

          When your computer has started in safe mode, and you see the desktop, close all open Windows.

          * Click on the Start button, click on the Run menu option, and type the following text from the Code Box into the Open: field then click the OK  button.

          Code: [Select]C:\SDFix\RunThis.bat
          * SDFix window will open containing some brief info and a disclaimer on the use of the tool.
          * Type Y on your keyboard and then press Enter to begin the cleanup process.
          * It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.
          * Press any Key and it will restart the PC.
          * When the PC restarts, the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
          * Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
          * Copy and paste the contents of the results file Report.txt.
          Hello evil fantasy

          Thanks again for your help.

          This is the log:


          SDFix: Version 1.240
          Run by Steve Higham on 11/02/2009 at 18:42

          Microsoft Windows XP [Version 5.1.2600]
          Running From: F:\SDFix

          Checking Services :


          Restoring Default Security Values
          Restoring Default Hosts File

          Rebooting


          Checking Files :

          No Trojan Files Found






          Removing Temp Files

          ADS Check :
           


                                           Final Check :

          catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2009-02-11 18:46:02
          Windows 5.1.2600 Service Pack 2 NTFS

          scanning hidden processes ...

          scanning hidden services & system hive ...

          scanning hidden registry entries ...

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
          "AppInit_DLLs"="avgrsstx.dll"
          "DeviceNotSelectedTimeout"="15"
          "GDIProcessHandleQuota"=dword:00002710
          "Spooler"="yes"
          "swapdisk"=""
          "TransmissionRetryTimeout"="90"
          "USERProcessHandleQuota"=dword:00002710
          "LoadAppInit_DLLs"=dword:00000001

          scanning hidden files ...

          scan completed successfully
          hidden processes: 0
          hidden services: 0
          hidden files: 0


          Remaining Services :




          Authorized Application Key Export:

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
          "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:xpsp2res.dll,-22019"
          "F:\\Program Files\\Java\\jdk1.6.0_11\\jre\\bin\\java.exe"="F:\\Program Files\\Java\\jdk1.6.0_11\\jre\\bin\\java.exe:*:Enabled:Java(TM) Platform SE binary"
          "F:\\Program Files\\AVG\\AVG8\\avgupd.exe"="F:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
          "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:xpsp2res.dll,-22019"

          Remaining Files :



          Files with Hidden Attributes :

          Tue 30 Oct 2007       607,744 A..H. --- "F:\Documents and Settings\Steve Higham\Desktop\Windows\~WRL0037.tmp"
          Sun 20 Apr 2008        20,992 A..H. --- "F:\Documents and Settings\Steve Higham\Desktop\Windows\Systems Administrator\~WRL2174.tmp"

          Finished!

          I'm not getting the Window cannot find the 'pif' file any longer and that 'sluggish' feel you get from a computer when it is contaimnated has gone.

          It looks as if it's all clean now, doesn't it?

          Cheers

          SteveYes looks good now.

          Download OTCleanIt.exe and save it to your Desktop.
          • Double-click OTCleanIt.exe.
          • Click the CleanUp! button.
          • Select Yes when the "Begin cleanup Process?" prompt appears.
          • If you are prompted to Reboot during the cleanup, select Yes.
          • The tool will delete itself once it finishes, if not delete it yourself.
          .
          ----------


          Set a New Restore Point to prevent possible reinfection from an old one
          Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
          • Go to Start > Programs > Accessories > System Tools and click System Restore
          • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
          • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
          • Next go to Start > Run and type Cleanmgr
          • Click OK
          • Click the More Options Tab.
          • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
          You can find instructions on how to enable and re-enable system restore here:

          Windows XP System Restore Guide or Windows Vista System Restore Guide
          .
          ----------

          Use the Secunia Software Inspector to check for out of date software.
          • Click Start Now
          • Check the box next to Enable thorough system inspection.
          • Click Start
          • Allow the scan to finish and scroll down to see if any updates are needed.
          • Update anything listed.
          .
          ----------

          Go to Microsoft Windows Update and get all critical updates.

          ----------

          Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

          Concerned about Browser Security? Consider using Mozilla Firefox. With more than 15,000 improvements, Firefox 3 is faster, safer and smarter than ever before.

          For Internet Explorer 7 users there is IE7Pro. IE7Pro is a must have add-on for Internet Explorer, which includes a lot of features and tweaks to make your IE friendlier, more useful, more secure and customizable.

          To prevent unknown applications from being installed on your computer install WinPatrol 2008
          * Using Winpatrol to protect your computer from malicious software

          I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

          SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
          * Using SpywareBlaster to protect your computer from Spyware and Malware
          * If you don't know what ActiveX controls are, see here

          Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

          Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
          970.

          Solve : Computer problem help plz?

          Answer»

          Hello there,

          I just returned back from a long trip abroad and now I am trying to figure out my computer.

          Just before I left for my trip my computer was pretty messed up to the point where I could start it and as soon as the main desktop page would load up, it would freeze. It would do this everytime and I would have to restart it and try again.
          Sometimes it would freeze during the windows loadup screen and I would have to restart from there.

          But for some reason, when I got home after my trip, the computer loaded up fine. I am worried though as I have done absolutely nothing and it started with no problems on my first time today.

          One thing that is worrying me is that I was reading your instructions about what programs to install, so I downloaded AVG but for some reason, it fails to install everytime. It says that it has something to do with my registry.

          Can you please tell me what to do as I have alot of progams on this computer and I would hate to have to re-install windows and start from scratch if this bug continues.

          Thanks, RyanHere are both the mbam report and hijack this REPORTS...

          PS I was able to install AVG and did a scan.

          My computer still freezes and still pauses on the windows screen during startup. I have to restart at that point again and hope that the next time it will not pause.

          Please help!

          [attachment DELETED by admin]The real-time protection of two antivirus programs may conflict with each other and cause the following:

          1) False Alarms: When the anti virus software tells you that your PC has a virus when it actually doesn't.
          2) Conflicts: Your system may lock up due to both products attempting to access the same file at the same time.
          3) Performance: More that one antivirus will cause your PC to become slow and it may even crash or blue screen.

          Please completely uninstall either AVG or McAfee and then post a new HijsckThis log.Here is my log with the AVG removed..


          [attachment deleted by admin]Scan Suspicious File(s)

          Please go to VirusTotal.com
          (If more than one file needs scanned they must be done separately and logs posted for each one)

          1. Copy the file path in the below Code box:
          Code: [Select]C:\WINDOWS\Downloaded Program Files\gbieh.dll2. At the upload site, click once inside the window next to Browse.
          3. Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
          4. Next click Send File
          Your file will possibly be entered into a queue which normally takes less than a minute to clear.
          This will perform a scan across multiple different virus scanning engines.
          Important: Wait for all of the scanning engines to complete.
          5. Copy and then Paste the link to the results in the next reply.


          https://www.virustotal.com/analisis/c8fcab60a5d59782ada61ec06862a84cDownload ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

          Link #1
          Link #2

          **Note:  It is important that it is saved directly to your Desktop

          Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

          Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
           
          Double click combofix.exe & follow the prompts.
          When finished ComboFix will produce a log for you.
          Post the ComboFix log in your next reply.

          Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

          Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

          If you have problems with ComboFix usage, see How to use ComboFix
          Here is the Combofix log

          [attachment deleted by admin]Why did you run ComboFix 6 times?

          If your going to do things on your own then my help isn't needed.

          • Click START then RUN
          • Now type Combofix /u in the runbox
          • Make sure there's a space between Combofix and /u
          • Then hit Enter.
          .
          .
          The above procedure will:
          • Delete:
            • ComboFix and its associated files and folders.
            • VundoFix backups, if present
            • The C:\Deckard folder, if present
            • The C:_OtMoveIt folder, if present
            • Reset the CLOCK settings.
            • Hide file extensions, if required.
            • Hide System/Hidden files, if required.
            • Set a new, clean Restore Point.
            .
            ----------

            Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

            Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Hello,

            I had run it 6 times as previously my computer was constantly crashing.

            Just this week, my computer is now acting worse and it does not allow my Mcafee to run. Does not allow my Firefox to run and I have no internet connection.

            After I do these instructions

            What do I do?  Use the ESET Online Antivirus Scanner

            This scanner requires Internet Explorer

            1. Check the box next to YES, I accept the Terms of Use.
            2. Click Start
            3. When asked, allow the activex control to install
            4. Click Start
            5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked.
            6. Click Scan
            7. Wait for the scan to finish
            8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
            9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.my computer seems to be restarting itself before it gets a chance to finish the scan.

            What to do?

            Also, I think the virus is messing with my programs so that I cannot open them. I had to reinstall internet explorer so that I could use it again. I Think the same thing would go for firefox.Note: This tool will self uninstall when you close it so please save the log before closing it.

            Download the latest version of the Kaspersky AVP Tool to your desktop.

            * Reboot your computer into Safe Mode

            You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
             Use your up arrow key to highlight SafeMode then hit enter

            * Double click the setup file to run it.
            * Click Next to continue.
            * It will by default install it to your desktop folder.Click Next.
            * Click OK at the prompt for scanning in Safe Mode.
            * It will then open a box There will be a tab that says Automatic scan.
            * Under Automatic scan make sure these are checked.

            # System Memory
            # Startup OBJECTS
            # Disk Boot Sectors.
            # My Computer.
            # Also any other drives (Removable that you may have)

            * Then click on Scan at the to right hand Corner.
            * It will automatically Neutralize any objects found.
            * If some objects are left unneutralized then click the button that says Neutralize all
            * If it says it cannot be Neutralized then choose The delete option when prompted.
            * After that is done click on the reports button at the bottom and save it to file name it Kas.
            * Save it somewhere convenient like your desktop and just post only the DETECTED Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

            Note: This tool will self uninstall when you close it so please save the log before closing it.
            971.

            Solve : what is tr/crypt.xpack.gen?

            Answer»

            Is it dangerous? Avira found it and (apparently) removed it. The Avira website tells me it is a low THREAT virus capable of minimum damage while this website &LT;Link Removed> tells me it is an extremely dangerous virus.That's a rouge web SITE so I removed the link. See here http://www.mywot.com/en/scorecard/scanforfree.com

            They use scare tactics to try and lure in the unsuspecting and buy their BAD software.

            Most trojans, while they are a pain to have are easily removed with a good antivirus. Avira's description is a good one. http://www.avira.com/en/threats/section/fulldetails/id_vir/3488/tr_crypt.xpack.gen.html

            More info:
            http://www.sophos.com/security/analyses/viruses-and-spyware/maltinydlo.html
            http://www.virustotal.com/analisis/258fbdfb7eb6ecfedbf236533b03c945


            972.

            Solve : Cannot open programmes from Desktop Icons?

            Answer»

            If I have posted in the wrong location, I apologise.

            Running Windows XP Home edition.

            As far as I know, my computer was running ok LAST NIGHT. This morning if I double click on a Desktop Icon, or an Icon in a folder, all I get is a box telling me that it is a short cut. I cannot access the Internet.  No programmes or downloads have been added to this computer in over a week. I have transferred some photographs via my NETWORK Connection.
            I have tried to do a restore and cannot.
            ALSO, if I do any work in a programme, say Photoshop, I cannot save the work.
            I have also found that if I right click on an Icon and Explore I can run a programme but it will not let me save any changes.
            Using the right click method, I have managed to run Malwarebytes SuperAntiSpyware and CCleaner - nothing found.
            Any help appreciated.
            Thank you,
            George.Try performing a System Restore to a few days before this started.As I put in my original post, I am unable to do a Restore.Oh, sorry about that.
            When you try it, what happens?I highlight Restore my computer to an earlier time then click on Next.  The button operates but nothing happens.  It will operate every time that I click on it but it never changes to the CALENDAR - even if I wait.Try doing it in Safe Mode

            973.

            Solve : Help! (beginner here and unexperieced): redirect virus?

            Answer»

            here is the maximized log:

            Logfile of random's system information tool 1.05 (written by random/random)
            Run by Administrator at 2009-01-13 16:53:06
            Microsoft Windows XP Professional Service Pack 2
            System drive C: has 70 GB (92%) free of 76 GB
            Total RAM: 1022 MB (56% free)

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 4:53:11 PM, on 1/13/2009
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
            C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
            C:\WINDOWS\system32\rundll32.exe
            C:\WINDOWS\system32\RUNDLL32.EXE
            C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
            C:\Program Files\Java\jre6\bin\jqs.exe
            C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
            C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
            C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
            C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
            C:\WINDOWS\system32\nvsvc32.exe
            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
            C:\Program Files\AIM6\aim6.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Viewpoint\Common\ViewpointService.exe
            C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
            C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
            C:\Program Files\AIM6\aolsoftware.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\Documents and Settings\Administrator\Desktop\RSIT.exe
            C:\Program Files\Trend Micro\HijackThis\Administrator.exe

            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
            O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
            O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
            O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
            O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
            O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
            O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
            O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
            O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
            O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
            O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel CORPORATION - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
            O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
            O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
            O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
            O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
            O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

            --
            End of file - 6325 bytes

            ======Registry dump======

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
            Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
            Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2009-01-12 320920]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
            Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-01-12 34816]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
            JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-01-12 73728]

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
            "SigmatelSysTrayApp"=C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe [2007-05-10 405504]
            "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-11-17 8495104]
            "nwiz"=nwiz.exe /installquiet []
            "NVHotkey"=C:\WINDOWS\system32\nvHotkey.dll [2007-11-17 86016]
            "NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2007-11-17 81920]
            "IntelZeroConfig"=C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe [2007-10-08 995328]
            "IntelWireless"=C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe [2007-10-08 1101824]
            "PDVDDXSrv"=C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe [2006-10-20 118784]
            "AdaptecDirectCD"=C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe [2002-12-17 684032]
            "GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
            "avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2008-11-26 81000]
            "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-01-12 136600]

            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
            "Aim6"=C:\Program Files\AIM6\aim6.exe [2008-10-21 50472]
            "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
            "Advanced SystemCare 3"=C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe [2009-01-07 2262352]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
            "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
            "dontdisplaylastusername"=0
            "legalnoticecaption"=
            "legalnoticetext"=
            "shutdownwithoutlogon"=1
            "undockwithoutlogon"=1

            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
            "NoDriveTypeAutoRun"=323
            "NoDriveAutoRun"=67108863
            "NoDrives"=0

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
            "NoDriveAutoRun"=
            "NoDriveTypeAutoRun"=
            "NoDrives"=

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
            "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:xpsp2res.dll,-22019"
            "C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
            "C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
            "C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
            "C:\Program Files\AIM6\aim6.exe"="C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM"

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
            "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:xpsp2res.dll,-22019"

            ======List of files/folders created in the last 3 months======

            2009-01-13 16:53:06 ----D---- C:\rsit
            2009-01-12 16:39:28 ----D---- C:\Program Files\Panda Security
            2009-01-12 11:37:48 ----D---- C:\WINDOWS\Sun
            2009-01-12 11:36:07 ----A---- C:\WINDOWS\system32\javaws.exe
            2009-01-12 11:36:07 ----A---- C:\WINDOWS\system32\javaw.exe
            2009-01-12 11:36:07 ----A---- C:\WINDOWS\system32\java.exe
            2009-01-12 11:36:07 ----A---- C:\WINDOWS\system32\deploytk.dll
            2009-01-12 11:35:53 ----D---- C:\Program Files\Java
            2009-01-12 11:34:57 ----D---- C:\Documents and Settings\Administrator\Application Data\Sun
            2009-01-12 11:22:29 ----SHD---- C:\RECYCLER
            2009-01-12 01:14:45 ----A---- C:\WINDOWS\system32\aswBoot.exe
            2009-01-12 01:14:42 ----D---- C:\Program Files\Alwil Software
            2009-01-12 01:02:53 ----D---- C:\WINDOWS\temp
            2009-01-12 01:00:34 ----D---- C:\WINDOWS\ERDNT
            2009-01-11 23:26:11 ----A---- C:\WINDOWS\system32\tmp.txt
            2009-01-11 15:08:24 ----D---- C:\Program Files\Trend Micro
            2009-01-11 02:32:09 ----D---- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
            2009-01-11 02:32:05 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
            2009-01-11 02:32:05 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
            2009-01-11 02:11:22 ----D---- C:\Program Files\IObit
            2009-01-11 02:11:22 ----D---- C:\Documents and Settings\Administrator\Application Data\IObit
            2009-01-11 02:11:19 ----D---- C:\Documents and Settings\All Users\Application Data\Avg8
            2009-01-07 21:39:29 ----D---- C:\Documents and Settings\Administrator\Application Data\Google
            2009-01-07 21:39:05 ----D---- C:\Documents and Settings\All Users\Application Data\Google
            2009-01-07 21:33:03 ----D---- C:\Program Files\AVG
            2009-01-07 21:07:44 ----D---- C:\Program Files\Google
            2008-12-31 12:36:24 ----D---- C:\Documents and Settings\Administrator\Application Data\Roxio
            2008-12-26 00:16:36 ----D---- C:\Documents and Settings\Administrator\Application Data\Macromedia
            2008-12-26 00:16:36 ----D---- C:\Documents and Settings\Administrator\Application Data\Adobe
            2008-12-25 22:06:40 ----D---- C:\Documents and Settings\Administrator\Application Data\acccore
            2008-12-25 22:06:22 ----D---- C:\Documents and Settings\All Users\Application Data\Viewpoint
            2008-12-25 22:06:21 ----D---- C:\Program Files\Viewpoint
            2008-12-25 22:06:21 ----D---- C:\Documents and Settings\All Users\Application Data\acccore
            2008-12-25 22:06:17 ----D---- C:\Documents and Settings\All Users\Application Data\AOL OCP
            2008-12-25 22:06:17 ----D---- C:\Documents and Settings\All Users\Application Data\AOL
            2008-12-25 22:06:05 ----D---- C:\Program Files\Common Files\AOL
            2008-12-25 22:05:48 ----D---- C:\Program Files\AIM6
            2008-12-25 21:59:14 ----D---- C:\Documents and Settings\Administrator\Application Data\Mozilla
            2008-12-25 21:59:09 ----D---- C:\Program Files\Mozilla Firefox
            2008-12-25 11:36:28 ----D---- C:\Documents and Settings\All Users\Application Data\nView_Profiles
            2008-12-05 23:27:09 ----D---- C:\WINDOWS\system32\LogFiles
            2008-12-05 11:40:26 ----A---- C:\WINDOWS\system32\msonpmon.dll
            2008-12-05 11:39:25 ----D---- C:\Program Files\Microsoft Works
            2008-12-05 11:39:15 ----D---- C:\Program Files\MSBuild
            2008-12-05 11:38:53 ----D---- C:\Program Files\Microsoft Visual Studio
            2008-12-05 11:38:53 ----D---- C:\Program Files\Common Files\DESIGNER
            2008-12-05 11:34:48 ----D---- C:\WINDOWS\SHELLNEW
            2008-12-05 11:34:29 ----D---- C:\Program Files\Microsoft Office
            2008-12-05 11:34:28 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
            2008-12-05 11:34:07 ----RHD---- C:\MSOCache
            2008-10-24 15:51:04 ----A---- C:\WINDOWS\uneng.exe
            2008-10-24 15:50:38 ----D---- C:\Program Files\Roxio
            2008-10-24 15:50:17 ----D---- C:\Program Files\Common Files\Adaptec Shared
            2008-10-24 15:49:19 ----D---- C:\Documents and Settings\All Users\Application Data\Dell
            2008-10-24 15:49:09 ----A---- C:\WINDOWS\system32\msxml4r.dll
            2008-10-24 15:49:09 ----A---- C:\WINDOWS\system32\msxml4a.dll
            2008-10-24 15:49:09 ----A---- C:\WINDOWS\system32\msxml4.dll
            2008-10-24 15:48:46 ----D---- C:\Program Files\CyberLink
            2008-10-24 15:48:46 ----A---- C:\WINDOWS\system32\msvcr71.dll
            2008-10-24 15:48:46 ----A---- C:\WINDOWS\system32\msvcp71.dll
            2008-10-24 15:48:46 ----A---- C:\WINDOWS\system32\MFC71u.dll
            2008-10-24 15:48:46 ----A---- C:\WINDOWS\system32\MFC71.dll
            2008-10-24 15:48:46 ----A---- C:\WINDOWS\system32\atl71.dll
            2008-10-24 02:54:59 ----D---- C:\Documents and Settings\Administrator\Application Data\Intel
            2008-10-24 02:54:58 ----A---- C:\WINDOWS\system32\RESULTS.txt
            2008-10-24 02:54:53 ----A---- C:\WINDOWS\system32\AegisI5Installer.exe
            2008-10-24 02:54:32 ----D---- C:\Documents and Settings\All Users\Application Data\Intel
            2008-10-24 02:53:56 ----A---- C:\WINDOWS\system32\NETw4r32.dll
            2008-10-24 02:53:56 ----A---- C:\WINDOWS\system32\NETw4c32.dll
            2008-10-24 01:56:46 ----D---- C:\WINDOWS\nview
            2008-10-24 01:56:46 ----A---- C:\WINDOWS\system32\nvudisp.exe
            2008-10-24 01:53:59 ----A---- C:\WINDOWS\system32\NVUNINST.EXE
            2008-10-24 01:53:46 ----A---- C:\WINDOWS\system32\nwiz.exe
            2008-10-24 01:53:46 ----A---- C:\WINDOWS\system32\nvwssr.dll
            2008-10-24 01:53:46 ----A---- C:\WINDOWS\system32\nvwss.dll
            2008-10-24 01:53:46 ----A---- C:\WINDOWS\system32\nvwrszht.dll
            2008-10-24 01:53:46 ----A---- C:\WINDOWS\system32\nvwrszhc.dll
            2008-10-24 01:53:46 ----A---- C:\WINDOWS\system32\nvwrsru.dll
            2008-10-24 01:53:46 ----A---- C:\WINDOWS\system32\nvwrsptb.dll
            2008-10-24 01:53:46 ----A---- C:\WINDOWS\system32\nvwrspl.dll
            2008-10-24 01:53:46 ----A---- C:\WINDOWS\system32\nvwrsko.dll
            2008-10-24 01:53:46 ----A---- C:\WINDOWS\system32\nvwrsja.dll
            2008-10-24 01:53:46 ----A---- C:\WINDOWS\system32\nvwrsit.dll
            2008-10-24 01:53:46 ----A---- C:\WINDOWS\system32\nvwrsfr.dll
            2008-10-24 01:53:46 ----A---- C:\WINDOWS\system32\nvwrsesm.dll
            2008-10-24 01:53:46 ----A---- C:\WINDOWS\system32\nvwrses.dll
            2008-10-24 01:53:46 ----A---- C:\WINDOWS\system32\nvwrsde.dll
            2008-10-24 01:53:46 ----A---- C:\WINDOWS\system32\nvwimg.dll
            2008-10-24 01:53:46 ----A---- C:\WINDOWS\system32\nvwdmcpl.dll
            2008-10-24 01:53:46 ----A---- C:\WINDOWS\system32\nvwddi.dll
            2008-10-24 01:53:45 ----A---- C:\WINDOWS\system32\nvvitvsr.dll
            2008-10-24 01:53:45 ----A---- C:\WINDOWS\system32\nvvitvs.dll
            2008-10-24 01:53:45 ----A---- C:\WINDOWS\system32\nvsvc32.exe
            2008-10-24 01:53:45 ----A---- C:\WINDOWS\system32\nvshell.dll
            2008-10-24 01:53:45 ----A---- C:\WINDOWS\system32\nvrszht.dll
            2008-10-24 01:53:45 ----A---- C:\WINDOWS\system32\nvrszhc.dll
            2008-10-24 01:53:45 ----A---- C:\WINDOWS\system32\nvrsru.dll
            2008-10-24 01:53:45 ----A---- C:\WINDOWS\system32\nvrsptb.dll
            2008-10-24 01:53:45 ----A---- C:\WINDOWS\system32\nvrspl.dll
            2008-10-24 01:53:45 ----A---- C:\WINDOWS\system32\nvrsko.dll
            2008-10-24 01:53:45 ----A---- C:\WINDOWS\system32\nvrsja.dll
            2008-10-24 01:53:45 ----A---- C:\WINDOWS\system32\nvrsit.dll
            2008-10-24 01:53:45 ----A---- C:\WINDOWS\system32\nvrsfr.dll
            2008-10-24 01:53:45 ----A---- C:\WINDOWS\system32\nvrsesm.dll
            2008-10-24 01:53:45 ----A---- C:\WINDOWS\system32\nvrses.dll
            2008-10-24 01:53:45 ----A---- C:\WINDOWS\system32\nvrsde.dll
            2008-10-24 01:53:45 ----A---- C:\WINDOWS\system32\nvoglnt.dll
            2008-10-24 01:53:45 ----A---- C:\WINDOWS\system32\nvmoblsr.dll
            2008-10-24 01:53:45 ----A---- C:\WINDOWS\system32\nvmobls.dll
            2008-10-24 01:53:45 ----A---- C:\WINDOWS\system32\nvmctray.dll
            2008-10-24 01:53:45 ----A---- C:\WINDOWS\system32\nvmccssr.dll
            2008-10-24 01:53:45 ----A---- C:\WINDOWS\system32\nvmccss.dll
            2008-10-24 01:53:45 ----A---- C:\WINDOWS\system32\nvmccsrs.dll
            2008-10-24 01:53:45 ----A---- C:\WINDOWS\system32\nvmccs.dll
            2008-10-24 01:53:44 ----A---- C:\WINDOWS\system32\nview.dll
            2008-10-24 01:53:44 ----A---- C:\WINDOWS\system32\nvhotkey.dll
            2008-10-24 01:53:44 ----A---- C:\WINDOWS\system32\nvgamesr.dll
            2008-10-24 01:53:44 ----A---- C:\WINDOWS\system32\nvgames.dll
            2008-10-24 01:53:44 ----A---- C:\WINDOWS\system32\nvexpbar.dll
            2008-10-24 01:53:44 ----A---- C:\WINDOWS\system32\nvdspsch.exe
            2008-10-24 01:53:43 ----A---- C:\WINDOWS\system32\nvdispsr.dll
            2008-10-24 01:53:42 ----A---- C:\WINDOWS\system32\nvdisps.dll
            2008-10-24 01:53:41 ----A---- C:\WINDOWS\system32\nvcpluir.dll
            2008-10-24 01:53:41 ----A---- C:\WINDOWS\system32\nvcplui.exe
            2008-10-24 01:53:41 ----A---- C:\WINDOWS\system32\nvcpl.dll
            2008-10-24 01:53:41 ----A---- C:\WINDOWS\system32\nvcodins.dll
            2008-10-24 01:53:41 ----A---- C:\WINDOWS\system32\nvcod.dll
            2008-10-24 01:53:41 ----A---- C:\WINDOWS\system32\nvappbar.exe
            2008-10-24 01:53:41 ----A---- C:\WINDOWS\system32\nvapi.dll
            2008-10-24 01:53:40 ----A---- C:\WINDOWS\system32\nv4_disp.dll
            2008-10-24 01:53:40 ----A---- C:\WINDOWS\system32\keystone.exe
            2008-10-24 01:48:36 ----DC---- C:\WINDOWS\system32\DRVSTORE
            2008-10-24 01:47:34 ----D---- C:\Program Files\O2Micro OZ776 SCR Driver
            2008-10-23 19:39:04 ----A---- C:\WINDOWS\system32\stlang.dll
            2008-10-23 19:39:04 ----A---- C:\WINDOWS\stsystra.exe
            2008-10-23 19:39:03 ----A---- C:\WINDOWS\system32\ksuser.dll
            2008-10-23 19:38:56 ----D---- C:\Program Files\SigmaTel
            2008-10-23 19:38:56 ----A---- C:\WINDOWS\system32\stacapi.dll
            2008-10-23 19:38:56 ----A---- C:\WINDOWS\system32\st325602.dll
            2008-10-23 19:38:55 ----HD---- C:\Program Files\InstallShield Installation Information
            2008-10-23 19:38:51 ----D---- C:\Program Files\Common Files\InstallShield
            2008-10-23 19:38:38 ----D---- C:\Intel
            2008-10-23 19:38:16 ----D---- C:\Program Files\Broadcom
            2008-10-23 19:35:59 ----D---- C:\Program Files\CONEXANT
            2008-10-23 19:34:40 ----A---- C:\WINDOWS\system32\spupdsvc.exe
            2008-10-23 19:34:39 ----HDC---- C:\WINDOWS\$NtUninstallKB888111WXPSP2$
            2008-10-23 19:34:15 ----A---- C:\WINDOWS\system32\Uci32103.dll
            2008-10-23 19:34:15 ----A---- C:\WINDOWS\system32\mdmxsdk.dll
            2008-10-23 19:30:44 ----D---- C:\WINDOWS\system32\ReinstallBackups
            2008-10-23 19:30:43 ----D---- C:\Program Files\Intel
            2008-10-23 19:26:53 ----D---- C:\Documents and Settings\Administrator\Application Data\Identities
            2008-10-23 19:26:52 ----HD---- C:\Program Files\Uninstall Information
            2008-10-23 19:26:46 ----ASH---- C:\Documents and Settings\Administrator\Application Data\desktop.ini
            2008-10-23 19:26:45 ----SD---- C:\Documents and Settings\Administrator\Application Data\Microsoft
            2008-10-23 19:26:40 ----D---- C:\WINDOWS\SoftwareDistribution
            2008-10-23 19:26:39 ----D---- C:\WINDOWS\Prefetch
            2008-10-23 19:26:38 ----SD---- C:\WINDOWS\system32\Microsoft
            2008-10-23 19:26:38 ----A---- C:\WINDOWS\SchedLgU.Txt
            2008-10-23 19:23:14 ----D---- C:\WINDOWS\system32\xircom
            2008-10-23 19:23:14 ----D---- C:\Program Files\xerox
            2008-10-23 19:23:14 ----D---- C:\Program Files\microsoft frontpage
            2008-10-23 19:23:02 ----D---- C:\DELL
            2008-10-23 19:22:52 ----HD---- C:\WINDOWS\$hf_mig$
            2008-10-23 19:22:50 ----N---- C:\WINDOWS\system32\xpsp3res.dll
            2008-10-23 19:22:34 ----A---- C:\WINDOWS\control.ini
            2008-10-23 19:22:34 ----A---- C:\AUTOEXEC.BAT
            2008-10-23 19:22:24 ----A---- C:\WINDOWS\OEWABLog.txt
            2008-10-23 19:22:21 ----A---- C:\WINDOWS\system32\mapi32.dll
            2008-10-23 19:21:33 ----RD---- C:\WINDOWS\Offline Web Pages
            2008-10-23 19:21:32 ----SD---- C:\WINDOWS\Downloaded Program Files
            2008-10-23 19:21:32 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
            2008-10-23 19:21:27 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
            2008-10-23 19:21:23 ----HD---- C:\Program Files\WindowsUpdate
            2008-10-23 19:21:03 ----D---- C:\WINDOWS\system32\DirectX
            2008-10-23 19:20:41 ----A---- C:\WINDOWS\system32\atrace.dll
            2008-10-23 19:20:38 ----A---- C:\WINDOWS\system32\desktop.ini
            2008-10-23 19:20:37 ----A---- C:\WINDOWS\desktop.ini
            2008-10-23 19:20:30 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
            2008-10-23 19:20:29 ----A---- C:\WINDOWS\system32\acctres.dll
            2008-10-23 19:20:28 ----D---- C:\Program Files\Common Files\Services
            2008-10-23 19:20:25 ----SD---- C:\WINDOWS\Tasks
            2008-10-23 19:20:25 ----A---- C:\WINDOWS\system32\icfgnt5.dll
            2008-10-23 19:20:24 ----D---- C:\Program Files\Common Files\MSSoap
            2008-10-23 19:20:19 ----D---- C:\WINDOWS\srchasst
            2008-10-23 19:20:18 ----D---- C:\WINDOWS\system32\Macromed
            2008-10-23 19:20:15 ----A---- C:\WINDOWS\system32\wuweb.dll
            2008-10-23 19:20:15 ----A---- C:\WINDOWS\system32\wucltui.dll
            2008-10-23 19:20:15 ----A---- C:\WINDOWS\system32\wuauserv.dll
            2008-10-23 19:20:15 ----A---- C:\WINDOWS\system32\wuaueng1.dll
            2008-10-23 19:20:14 ----A---- C:\WINDOWS\system32\wups.dll
            2008-10-23 19:20:14 ----A---- C:\WINDOWS\system32\wuaueng.dll
            2008-10-23 19:20:14 ----A---- C:\WINDOWS\system32\wuauclt1.exe
            2008-10-23 19:20:14 ----A---- C:\WINDOWS\system32\wuauclt.exe
            2008-10-23 19:20:14 ----A---- C:\WINDOWS\system32\wuapi.dll
            2008-10-23 19:20:14 ----A---- C:\WINDOWS\system32\bitsprx3.dll
            2008-10-23 19:20:14 ----A---- C:\WINDOWS\system32\bitsprx2.dll
            2008-10-23 19:20:13 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
            2008-10-23 19:20:13 ----A---- C:\WINDOWS\system32\qmgr.dll
            2008-10-23 19:20:08 ----D---- C:\Program Files\Movie Maker
            2008-10-23 19:20:04 ----A---- C:\WINDOWS\system32\safrslv.dll
            2008-10-23 19:20:04 ----A---- C:\WINDOWS\system32\safrdm.dll
            2008-10-23 19:20:04 ----A---- C:\WINDOWS\system32\safrcdlg.dll
            2008-10-23 19:20:04 ----A---- C:\WINDOWS\system32\racpldlg.dll
            2008-10-23 19:19:59 ----A---- C:\WINDOWS\system32\fltMc.exe
            2008-10-23 19:19:59 ----A---- C:\WINDOWS\system32\fltlib.dll
            2008-10-23 19:19:58 ----D---- C:\WINDOWS\system32\Restore
            2008-10-23 19:19:58 ----A---- C:\WINDOWS\system32\srsvc.dll
            2008-10-23 19:19:58 ----A---- C:\WINDOWS\system32\srrstr.dll
            2008-10-23 19:19:58 ----A---- C:\WINDOWS\system32\srclient.dll
            2008-10-23 19:19:57 ----A---- C:\WINDOWS\system32\nmmkcert.dll
            2008-10-23 19:19:57 ----A---- C:\WINDOWS\system32\mnmdd.dll
            2008-10-23 19:19:57 ----A---- C:\WINDOWS\system32\isrdbg32.dll
            2008-10-23 19:19:57 ----A---- C:\WINDOWS\system32\ils.dll
            2008-10-23 19:19:56 ----A---- C:\WINDOWS\system32\msconf.dll
            2008-10-23 19:19:56 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
            2008-10-23 19:19:53 ----D---- C:\Program Files\NetMeeting
            2008-10-23 19:19:53 ----A---- C:\WINDOWS\system32\msoert2.dll
            2008-10-23 19:19:53 ----A---- C:\WINDOWS\system32\msoeacct.dll
            2008-10-23 19:19:52 ----A---- C:\WINDOWS\system32\inetres.dll
            2008-10-23 19:19:51 ----A---- C:\WINDOWS\system32\inetcomm.dll
            2008-10-23 19:19:49 ----D---- C:\Program Files\Outlook Express
            2008-10-23 19:19:49 ----A---- C:\WINDOWS\system32\schedsvc.dll
            2008-10-23 19:19:49 ----A---- C:\WINDOWS\system32\mstinit.exe
            2008-10-23 19:19:49 ----A---- C:\WINDOWS\system32\mstask.dll
            2008-10-23 19:19:48 ----A---- C:\WINDOWS\system32\isign32.dll
            2008-10-23 19:19:48 ----A---- C:\WINDOWS\system32\inetcfg.dll
            2008-10-23 19:19:48 ----A---- C:\WINDOWS\system32\icwphbk.dll
            2008-10-23 19:19:48 ----A---- C:\WINDOWS\system32\icwdial.dll


            2008-10-23 19:19:42 ----D---- C:\Program Files\Common Files\System
            2008-10-23 19:19:36 ----D---- C:\Program Files\Internet Explorer
            2008-10-23 19:19:07 ----D---- C:\Program Files\ComPlus Applications
            2008-10-23 19:19:05 ----A---- C:\WINDOWS\vbaddin.ini
            2008-10-23 19:19:05 ----A---- C:\WINDOWS\vb.ini
            2008-10-23 19:19:01 ----D---- C:\WINDOWS\Registration
            2008-10-23 19:18:54 ----D---- C:\Program Files\Windows Media Player
            2008-10-23 19:18:54 ----D---- C:\Program Files\Online Services
            2008-10-23 19:18:49 ----D---- C:\Program Files\Messenger
            2008-10-23 19:18:44 ----D---- C:\Program Files\MSN Gaming Zone
            2008-10-23 19:18:44 ----A---- C:\WINDOWS\system32\write.exe
            2008-10-23 19:18:36 ----A---- C:\WINDOWS\system32\sndvol32.exe
            2008-10-23 19:18:35 ----A---- C:\WINDOWS\system32\hticons.dll
            2008-10-23 19:18:35 ----A---- C:\WINDOWS\system32\avwav.dll
            2008-10-23 19:18:35 ----A---- C:\WINDOWS\system32\avtapi.dll
            2008-10-23 19:18:35 ----A---- C:\WINDOWS\system32\avmeter.dll
            2008-10-23 19:18:34 ----A---- C:\WINDOWS\system32\winchat.exe
            2008-10-23 19:18:28 ----A---- C:\WINDOWS\system32\getuname.dll
            2008-10-23 19:18:28 ----A---- C:\WINDOWS\system32\charmap.exe
            2008-10-23 19:18:28 ----A---- C:\WINDOWS\system32\calc.exe
            2008-10-23 19:18:27 ----A---- C:\WINDOWS\system32\winmine.exe
            2008-10-23 19:18:27 ----A---- C:\WINDOWS\system32\sol.exe
            2008-10-23 19:18:27 ----A---- C:\WINDOWS\system32\mshearts.exe
            2008-10-23 19:18:26 ----A---- C:\WINDOWS\system32\usrlogon.cmd
            2008-10-23 19:18:26 ----A---- C:\WINDOWS\system32\tsshutdn.exe
            2008-10-23 19:18:26 ----A---- C:\WINDOWS\system32\tslabels.ini
            2008-10-23 19:18:26 ----A---- C:\WINDOWS\system32\tskill.exe
            2008-10-23 19:18:26 ----A---- C:\WINDOWS\system32\tsdiscon.exe
            2008-10-23 19:18:26 ----A---- C:\WINDOWS\system32\tscon.exe
            2008-10-23 19:18:26 ----A---- C:\WINDOWS\system32\shadow.exe
            2008-10-23 19:18:26 ----A---- C:\WINDOWS\system32\rwinsta.exe
            2008-10-23 19:18:26 ----A---- C:\WINDOWS\system32\reset.exe
            2008-10-23 19:18:26 ----A---- C:\WINDOWS\system32\freecell.exe
            2008-10-23 19:18:25 ----A---- C:\WINDOWS\system32\regini.exe
            2008-10-23 19:18:25 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
            2008-10-23 19:18:25 ----A---- C:\WINDOWS\system32\qwinsta.exe
            2008-10-23 19:18:25 ----A---- C:\WINDOWS\system32\qappsrv.exe
            2008-10-23 19:18:25 ----A---- C:\WINDOWS\system32\msg.exe
            2008-10-23 19:18:25 ----A---- C:\WINDOWS\system32\msdtcprf.ini
            2008-10-23 19:18:25 ----A---- C:\WINDOWS\system32\logoff.exe
            2008-10-23 19:18:25 ----A---- C:\WINDOWS\system32\cdmodem.dll
            2008-10-23 19:18:24 ----A---- C:\WINDOWS\system32\mtxlegih.dll
            2008-10-23 19:18:24 ----A---- C:\WINDOWS\system32\mtxex.dll
            2008-10-23 19:18:24 ----A---- C:\WINDOWS\system32\mtxdm.dll
            2008-10-23 19:18:24 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
            2008-10-23 19:18:24 ----A---- C:\WINDOWS\system32\comrepl.dll
            2008-10-23 19:18:24 ----A---- C:\WINDOWS\system32\comaddin.dll
            2008-10-23 19:18:23 ----A---- C:\WINDOWS\system32\stclient.dll
            2008-10-23 19:18:23 ----A---- C:\WINDOWS\system32\comsnap.dll
            2008-10-23 19:18:18 ----A---- C:\WINDOWS\system32\wmimgmt.msc
            2008-10-23 19:17:59 ----D---- C:\Program Files\MSN
            2008-10-23 19:17:58 ----A---- C:\WINDOWS\system32\sndrec32.exe
            2008-10-23 19:17:58 ----A---- C:\WINDOWS\system32\mplay32.exe
            2008-10-23 19:17:58 ----A---- C:\WINDOWS\system32\accwiz.exe
            2008-10-23 19:17:57 ----D---- C:\Program Files\Windows NT
            2008-10-23 19:17:57 ----A---- C:\WINDOWS\system32\mspaint.exe
            2008-10-23 19:17:57 ----A---- C:\WINDOWS\system32\hypertrm.dll
            2008-10-23 19:17:57 ----A---- C:\WINDOWS\system32\clipbrd.exe
            2008-10-23 19:17:56 ----A---- C:\WINDOWS\system32\spider.exe
            2008-10-23 19:17:55 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
            2008-10-23 19:17:55 ----A---- C:\WINDOWS\system32\remotepg.dll
            2008-10-23 19:17:55 ----A---- C:\WINDOWS\system32\rdshost.exe
            2008-10-23 19:17:55 ----A---- C:\WINDOWS\system32\rdsaddin.exe
            2008-10-23 19:17:55 ----A---- C:\WINDOWS\system32\mstscax.dll
            2008-10-23 19:17:55 ----A---- C:\WINDOWS\system32\mstsc.exe
            2008-10-23 19:17:54 ----A---- C:\WINDOWS\system32\tscupgrd.exe
            2008-10-23 19:17:54 ----A---- C:\WINDOWS\system32\termsrv.dll
            2008-10-23 19:17:54 ----A---- C:\WINDOWS\system32\sessmgr.exe
            2008-10-23 19:17:54 ----A---- C:\WINDOWS\system32\rdpwsx.dll
            2008-10-23 19:17:54 ----A---- C:\WINDOWS\system32\rdpsnd.dll
            2008-10-23 19:17:54 ----A---- C:\WINDOWS\system32\rdpclip.exe
            2008-10-23 19:17:54 ----A---- C:\WINDOWS\system32\rdchost.dll
            2008-10-23 19:17:54 ----A---- C:\WINDOWS\system32\qprocess.exe
            2008-10-23 19:17:53 ----D---- C:\WINDOWS\system32\MsDtc
            2008-10-23 19:17:53 ----A---- C:\WINDOWS\system32\mtxoci.dll
            2008-10-23 19:17:53 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
            2008-10-23 19:17:53 ----A---- C:\WINDOWS\system32\msdtcprx.dll
            2008-10-23 19:17:53 ----A---- C:\WINDOWS\system32\icaapi.dll
            2008-10-23 19:17:53 ----A---- C:\WINDOWS\system32\cfgbkend.dll
            2008-10-23 19:17:52 ----A---- C:\WINDOWS\system32\xolehlp.dll
            2008-10-23 19:17:52 ----A---- C:\WINDOWS\system32\msdtctm.dll
            2008-10-23 19:17:52 ----A---- C:\WINDOWS\system32\msdtclog.dll
            2008-10-23 19:17:52 ----A---- C:\WINDOWS\system32\msdtc.exe
            2008-10-23 19:17:51 ----D---- C:\WINDOWS\system32\Com
            2008-10-23 19:17:51 ----A---- C:\WINDOWS\system32\colbact.dll
            2008-10-23 19:17:51 ----A---- C:\WINDOWS\system32\clbcatex.dll
            2008-10-23 19:17:51 ----A---- C:\WINDOWS\system32\catsrvps.dll
            2008-10-23 19:17:50 ----A---- C:\WINDOWS\system32\comsvcs.dll
            2008-10-23 19:17:50 ----A---- C:\WINDOWS\system32\catsrvut.dll
            2008-10-23 19:17:50 ----A---- C:\WINDOWS\system32\catsrv.dll
            2008-10-23 19:17:49 ----A---- C:\WINDOWS\system32\comuid.dll
            2008-10-23 19:17:49 ----A---- C:\WINDOWS\system32\clbcatq.dll
            2008-10-23 19:17:42 ----A---- C:\WINDOWS\system32\servdeps.dll
            2008-10-23 19:17:42 ----A---- C:\WINDOWS\system32\mmfutil.dll
            2008-10-23 19:17:41 ----A---- C:\WINDOWS\system32\licwmi.dll
            2008-10-23 19:17:41 ----A---- C:\WINDOWS\system32\cmprops.dll
            2008-10-23 12:13:16 ----A---- C:\WINDOWS\system32\h323log.txt
            2008-10-23 11:57:29 ----A---- C:\WINDOWS\system32\usbui.dll
            2008-10-23 11:56:28 ----A---- C:\WINDOWS\imsins.BAK
            2008-10-23 11:56:26 ----SHD---- C:\WINDOWS\Installer
            2008-10-23 11:56:26 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
            2008-10-23 11:56:25 ----D---- C:\Program Files\Common Files\ODBC
            2008-10-23 11:56:25 ----A---- C:\WINDOWS\ODBCINST.INI
            2008-10-23 11:56:21 ----RD---- C:\Program Files
            2008-10-23 11:56:21 ----D---- C:\Program Files\Common Files\SpeechEngines
            2008-10-23 11:56:21 ----D---- C:\Program Files\Common Files\Microsoft Shared
            2008-10-23 11:56:21 ----D---- C:\Program Files\Common Files
            2008-10-23 11:56:18 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
            2008-10-23 11:56:18 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
            2008-10-23 11:56:18 ----RA---- C:\WINDOWS\system32\kbdazel.dll
            2008-10-23 11:56:16 ----RA---- C:\WINDOWS\system32\kbdycc.dll
            2008-10-23 11:56:16 ----RA---- C:\WINDOWS\system32\kbduzb.dll
            2008-10-23 11:56:16 ----RA---- C:\WINDOWS\system32\kbdur.dll
            2008-10-23 11:56:16 ----RA---- C:\WINDOWS\system32\kbdtat.dll
            2008-10-23 11:56:16 ----RA---- C:\WINDOWS\system32\kbdru1.dll
            2008-10-23 11:56:16 ----RA---- C:\WINDOWS\system32\kbdru.dll
            2008-10-23 11:56:16 ----RA---- C:\WINDOWS\system32\kbdmon.dll
            2008-10-23 11:56:16 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
            2008-10-23 11:56:16 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
            2008-10-23 11:56:16 ----RA---- C:\WINDOWS\system32\kbdbu.dll
            2008-10-23 11:56:16 ----RA---- C:\WINDOWS\system32\kbdblr.dll
            2008-10-23 11:56:16 ----RA---- C:\WINDOWS\system32\kbdaze.dll
            2008-10-23 11:56:14 ----RA---- C:\WINDOWS\system32\kbdhept.dll
            2008-10-23 11:56:14 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
            2008-10-23 11:56:14 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
            2008-10-23 11:56:14 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
            2008-10-23 11:56:14 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
            2008-10-23 11:56:14 ----RA---- C:\WINDOWS\system32\kbdhe.dll
            2008-10-23 11:56:14 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
            2008-10-23 11:56:13 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
            2008-10-23 11:56:13 ----RA---- C:\WINDOWS\system32\kbdlv.dll
            2008-10-23 11:56:13 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
            2008-10-23 11:56:13 ----RA---- C:\WINDOWS\system32\kbdlt.dll
            2008-10-23 11:56:13 ----RA---- C:\WINDOWS\system32\kbdest.dll
            2008-10-23 11:56:11 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
            2008-10-23 11:56:11 ----RA---- C:\WINDOWS\system32\kbdsl.dll
            2008-10-23 11:56:11 ----RA---- C:\WINDOWS\system32\kbdro.dll
            2008-10-23 11:56:11 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
            2008-10-23 11:56:11 ----RA---- C:\WINDOWS\system32\kbdpl.dll
            2008-10-23 11:56:11 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
            2008-10-23 11:56:11 ----RA---- C:\WINDOWS\system32\kbdhu.dll
            2008-10-23 11:56:10 ----RA---- C:\WINDOWS\system32\kbdycl.dll
            2008-10-23 11:56:10 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
            2008-10-23 11:56:10 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
            2008-10-23 11:56:10 ----RA---- C:\WINDOWS\system32\kbdcz.dll
            2008-10-23 11:56:10 ----RA---- C:\WINDOWS\system32\kbdcr.dll
            2008-10-23 11:56:10 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
            2008-10-23 11:56:08 ----A---- C:\WINDOWS\system32\spxcoins.dll
            2008-10-23 11:56:08 ----A---- C:\WINDOWS\system32\irclass.dll
            2008-10-23 11:56:08 ----A---- C:\WINDOWS\system32\EqnClass.Dll
            2008-10-23 11:56:08 ----A---- C:\WINDOWS\system32\dgsetup.dll
            2008-10-23 11:56:08 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
            2008-10-23 11:56:05 ----N---- C:\WINDOWS\system32\CONFIG.TMP
            2008-10-23 11:56:05 ----A---- C:\WINDOWS\TASKMAN.EXE
            2008-10-23 11:56:05 ----A---- C:\WINDOWS\system32\batt.dll
            2008-10-23 11:56:04 ----A---- C:\WINDOWS\NOTEPAD.EXE
            2008-10-23 11:56:03 ----A---- C:\WINDOWS\system32\storprop.dll
            2008-10-23 11:55:57 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
            2008-10-23 11:55:56 ----RA---- C:\WINDOWS\SET2A.tmp
            2008-10-23 11:55:56 ----RA---- C:\WINDOWS\SET29.tmp
            2008-10-23 11:55:53 ----RA---- C:\WINDOWS\SET8.tmp
            2008-10-23 11:55:50 ----RA---- C:\WINDOWS\SET4.tmp
            2008-10-23 11:55:49 ----RA---- C:\WINDOWS\SET3.tmp
            2008-10-23 11:55:44 ----D---- C:\WINDOWS\system32\CatRoot2
            2008-10-23 11:55:44 ----D---- C:\WINDOWS\system32\CatRoot
            2008-10-23 11:55:38 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
            2008-10-23 11:55:15 ----A---- C:\WINDOWS\setuplog.txt
            2008-10-23 11:55:13 ----D---- C:\Documents and Settings
            2008-10-23 11:55:12 ----SHD---- C:\System Volume Information
            2008-10-23 11:54:07 ----SH---- C:\boot.ini
            2008-10-23 11:45:56 ----RSHDC---- C:\WINDOWS\system32\dllcache
            2008-10-23 11:45:56 ----RSD---- C:\WINDOWS\Fonts
            2008-10-23 11:45:56 ----RD---- C:\WINDOWS\Web
            2008-10-23 11:45:56 ----HD---- C:\WINDOWS\inf
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\WinSxS
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\twain_32
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\wins
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\wbem
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\usmt
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\spool
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\ShellExt
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\Setup
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\ras
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\oobe
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\npp
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\mui
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\inetsrv
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\IME
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\icsxml
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\ias
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\export
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\drivers
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\dhcp
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\config
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\3com_dmi
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\3076
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\2052
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\1054
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\1042
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\1041
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\1037
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\1033
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\1031
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\1028
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32\1025
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system32
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\system
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\security
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\Resources
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\repair
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\Provisioning
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\PeerNet
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\pchealth
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\mui
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\msapps
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\msagent
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\Media
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\java
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\ime
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\Help
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\ehome
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\Driver Cache
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\dell
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\Debug
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\Cursors
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\Connection Wizard
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\Config
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\AppPatch
            2008-10-23 11:45:56 ----D---- C:\WINDOWS\addins
            2008-10-23 11:45:56 ----D---- C:\WINDOWS

            ======List of files/folders modified in the last 3 months======

            2009-01-12 01:02:15 ----A---- C:\WINDOWS\system.ini
            2008-12-05 11:34:58 ----A---- C:\WINDOWS\win.ini

            ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

            R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2008-11-26 26944]
            R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2008-11-26 111184]
            R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2008-11-26 50864]
            R1 Cdr4_xp;Cdr4_xp; C:\WINDOWS\system32\drivers\Cdr4_xp.sys [2002-12-17 61424]
            R1 Cdralw2k;Cdralw2k; C:\WINDOWS\system32\drivers\Cdralw2k.sys [2002-12-17 23436]
            R1 cdudf_xp;cdudf_xp; C:\WINDOWS\system32\drivers\cdudf_xp.sys [2002-12-17 241152]
            R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-04 36096]
            R1 pwd_2k;pwd_2k; C:\WINDOWS\system32\drivers\pwd_2k.sys [2008-10-24 143834]
            R1 UdfReadr_xp;UdfReadr_xp; C:\WINDOWS\system32\drivers\UdfReadr_xp.sys [2008-10-24 206464]
            R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2004-08-03 8832]
            R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.7.5.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2008-10-24 21361]
            R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-11-26 20560]
            R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2008-11-26 94032]
            R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2005-10-05 12544]
            R2 s24trans;WLAN Transport; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2007-08-27 12288]
            R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-04 60800]
            R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2008-11-26 23152]
            R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2005-10-26 142720]
            R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2004-08-03 14080]
            R3 dvd_2K;dvd_2K; C:\WINDOWS\system32\drivers\dvd_2K.sys [2008-10-24 25898]
            R3 guardian2;guardian2; C:\WINDOWS\System32\Drivers\oz776.sys [2007-12-23 68696]
            R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
            R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
            R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSX_DPV.sys [2005-12-01 936960]
            R3 HSXHWAZL;HSXHWAZL; C:\WINDOWS\system32\DRIVERS\HSXHWAZL.sys [2005-12-01 192512]
            R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
            R3 NETw4x32;Intel(R) Wireless WiFi Link Adapter Driver for Windows XP 32 Bit; C:\WINDOWS\system32\DRIVERS\NETw4x32.sys [2007-09-26 2236032]
            R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-04 61824]
            R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-11-17 6864064]
            R3 STHDA;SigmaTel High Definition Audio CODEC; C:\WINDOWS\system32\drivers\sthda.sys [2007-05-10 1222840]
            R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-04 26624]
            R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-04 57600]
            R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-04 20480]
            R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSX_CNXT.sys [2005-12-01 669696]
            S3 mmc_2K;mmc_2K; C:\WINDOWS\system32\drivers\mmc_2K.sys [2008-10-24 30630]
            S3 UIUSys;Conexant Setup API; C:\WINDOWS\system32\DRIVERS\UIUSYS.SYS []
            S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
            S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

            ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

            R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2008-11-26 18752]
            R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2008-11-26 155160]
            R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2007-10-08 794624]
            R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-01-12 152984]
            R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2007-11-17 155716]
            R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2007-10-08 483328]
            R2 S24EventMonitor;Intel(R) PROSet/Wireless Service; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [2007-10-08 1183744]
            R2 Viewpoint Manager Service;Viewpoint Manager Service; C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
            R2 WLANKEEPER;Intel(R) PROSet/Wireless SSO Service; C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe [2007-10-08 356352]
            R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2008-11-26 254040]
            R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2008-11-26 352920]
            S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
            S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
            S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

            -----------------EOF-----------------
            here is the minimized log:

            info.txt logfile of random's system information tool 1.05 2009-01-13 16:53:13

            ======Uninstall list======

            -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
            Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
            Advanced SystemCare 3-->"C:\Program Files\IObit\Advanced SystemCare 3\unins000.exe"
            AIM 6-->C:\Program Files\AIM6\uninst.exe
            avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
            Broadcom Gigabit Integrated Controller-->MsiExec.exe /X{B7F54262-AB66-44B3-88BF-9FC69941B643}
            Conexant HDA D110 MDC V.92 Modem-->C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3\HXFSETUP.EXE -U -Idel1028p.inf
            Easy CD Creator 5 Basic-->MsiExec.exe /I{609F7AC8-C510-11D4-A788-009027ABA5D0}
            Google SketchUp 7-->MsiExec.exe /I{BEF106F8-2689-4530-925A-E1117836E8CD}
            High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
            HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
            Intel(R) PROSet/Wireless Software-->C:\WINDOWS\Installer\iProInst.exe
            Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
            Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
            mCore-->MsiExec.exe /I{E81667C6-2856-46D6-ABEA-6A2F42166779}
            mDriver-->MsiExec.exe /I{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}
            mDrWiFi-->MsiExec.exe /I{F6090A17-0967-4A8A-B3C3-422A1B514D49}
            mHlpDell-->MsiExec.exe /I{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}
            Microsoft Office Access MUI (English) 2007-->MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
            Microsoft Office Access Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
            Microsoft Office Enterprise 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
            Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
            Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
            Microsoft Office Groove MUI (English) 2007-->MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE}
            Microsoft Office Groove Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE}
            Microsoft Office InfoPath MUI (English) 2007-->MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}
            Microsoft Office OneNote MUI (English) 2007-->MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
            Microsoft Office Outlook MUI (English) 2007-->MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
            Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
            Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
            Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
            Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
            Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
            Microsoft Office Publisher MUI (English) 2007-->MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
            Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
            Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
            Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
            Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
            mIWA-->MsiExec.exe /I{3E9D596A-61D4-4239-BD19-2DB984D2A16F}
            mLogView-->MsiExec.exe /I{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}
            mMHouse-->MsiExec.exe /I{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}
            Mozilla Firefox (3.0.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
            mPfMgr-->MsiExec.exe /I{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}
            mPfWiz-->MsiExec.exe /I{90B0D222-8C21-4B35-9262-53B042F18AF9}
            mProSafe-->MsiExec.exe /I{23FB368F-1399-4EAC-817C-4B83ECBE3D83}
            mSCfg-->MsiExec.exe /I{829CD169-E692-48E8-9BDE-A3E8D8B65538}
            mSSO-->MsiExec.exe /I{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}
            MSXML 6.0 Parser-->MsiExec.exe /I{AEB9948B-4FF2-47C9-990E-47014492A0FE}
            mWlsSafe-->MsiExec.exe /I{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}
            mWMI-->MsiExec.exe /I{63DB9CCD-2B56-4217-9A3D-507AC78320CA}
            mZConfig-->MsiExec.exe /I{94658027-9F16-4509-BBD7-A59FE57C3023}
            NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
            OZ776 SCR Driver V1.1.4.202-->"C:\Program Files\InstallShield Installation Information\{EDC2B89F-3F72-48EA-B63E-985BC51622E4}\setup.exe" -runfromtemp -l0x0409 -removeonly
            OZ776 SCR Driver V1.1.4.202-->MsiExec.exe /X{EDC2B89F-3F72-48EA-B63E-985BC51622E4}
            Panda ActiveScan 2.0-->C:\Program Files\Panda Security\ActiveScan 2.0\as2uninst.exe
            PowerDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{281ECE39-F043-492B-8337-F2E546B5604A}\Setup.exe" -l0x9  -cluninstall
            SigmaTel Audio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}\setup.exe" -l0x9 -remove -removeonly
            Viewpoint Media Player-->C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u

            =====HijackThis Backups=====

            O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)

            ======Security center information======

            AV: avast! antivirus 4.8.1296 [VPS 090113-1]

            System event log

            Computer Name: D820-8A3EA4B82E
            Event Code: 3260
            Message: This computer has been successfully joined to workgroup 'WORKGROUP'.

            Record Number: 5
            Source Name: Workstation
            Time Written: 20081023201734.000000-240
            Event Type: information
            User:

            Computer Name: D820-8A3EA4B82E
            Event Code: 6011
            Message: The NetBIOS name and DNS host name of this machine have been changed from MACHINENAME to D820-8A3EA4B82E.

            Record Number: 4
            Source Name: EventLog
            Time Written: 20081023201323.000000-240
            Event Type: information
            User:

            Computer Name: MACHINENAME
            Event Code: 2
            Message: While validating that \Device\Serial0 was really a serial port, a fifo was detected. The fifo will be used.

            Record Number: 3
            Source Name: Serial
            Time Written: 20081023125537.000000-240
            Event Type: information
            User:

            Computer Name: MACHINENAME
            Event Code: 6005
            Message: The Event log service was started.

            Record Number: 2
            Source Name: EventLog
            Time Written: 20081023125519.000000-240
            Event Type: information
            User:

            Computer Name: MACHINENAME
            Event Code: 6009
            Message: Microsoft (R) Windows (R) 5.01. 2600 Service Pack 2 Multiprocessor Free.

            Record Number: 1
            Source Name: EventLog
            Time Written: 20081023125519.000000-240
            Event Type: information
            User:

            ======Environment variables======

            "ComSpec"=%SystemRoot%\system32\cmd.exe
            "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\Common Files\Adaptec Shared\System
            "windir"=%SystemRoot%
            "FP_NO_HOST_CHECK"=NO
            "OS"=Windows_NT
            "PROCESSOR_ARCHITECTURE"=x86
            "PROCESSOR_LEVEL"=6
            "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 14 Stepping 8, GenuineIntel
            "PROCESSOR_REVISION"=0e08
            "NUMBER_OF_PROCESSORS"=2
            "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
            "TEMP"=%SystemRoot%\TEMP
            "TMP"=%SystemRoot%\TEMP

            -----------------EOF-----------------
            Save space and scrolling, please, make it an attachment... Quote from: BatchRocks on January 13, 2009, 03:01:50 PM

            Save space and scrolling, please, make it an attachment...

            Only attach if specifically requested please Quote from: evilfantasy on January 13, 2009, 03:04:26 PM
            Quote from: BatchRocks on January 13, 2009, 03:01:50 PM
            Save space and scrolling, please, make it an attachment...

            Only attach if specifically requested please

            Requested? I thought they always were. Sorry!They were at one time. Now I prefer them inline. Makes Googling EASIER...

            Download ViewpointKiller.zip
            • Unzip the program and all of the contents of ViewpointKiller.zip to a location such as your desktop.
            • Double click the ViewpointKiller icon to run ViewpointKiller.exe.
            • Select the File menu, and select Check to see if you have Viewpoint installed.
            • If ViewpointKiller indicates that any of the Viewpoint variants are installed, select the proper Kill option in the File menu.
            • Follow the prompts and instructions very carefully, answering Yes or No depending on which option you are most comfortable with.
            • The MsConfig instructions are very important, so be sure to read them carefully.
            • Note: When DONE with ViewpointKiller right click and delete all files that were unzipped.
            .
            ----------

            Download the OTMoveIt3 by OldTimer

            Note: If you are running on Vista, right-click on OTMoveIt3.exe and choose Run As Administrator.

            * Save it to your Desktop.
            * Double-click OTMoveIt3.exe to run it.
            * Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy)

            Code: [Select]:Processes
            explorer.exe

            :services

            :reg

            :files
            C:\WINDOWS\SET2A.tmp
            C:\WINDOWS\SET29.tmp
            C:\WINDOWS\SET8.tmp
            C:\WINDOWS\SET4.tmp
            C:\WINDOWS\SET3.tmp

            :Commands
            [purity]
            [emptytemp]
            [start explorer]
            [Reboot]

            * Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
            * Click the red Moveit! button.
            * Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
            Close OTMoveIt3

            Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes. If not, reboot anyway.

            ----------

            How is the computer running now?not any better. i went to yahoo and it still does the redirect thing... here is the moveit log from the last reboot:

            ========== PROCESSES ==========
            Process explorer.exe killed successfully.
            ========== SERVICES/DRIVERS ==========
            ========== REGISTRY ==========
            ========== FILES ==========
            C:\WINDOWS\SET2A.tmp moved successfully.
            C:\WINDOWS\SET29.tmp moved successfully.
            C:\WINDOWS\SET8.tmp moved successfully.
            C:\WINDOWS\SET4.tmp moved successfully.
            C:\WINDOWS\SET3.tmp moved successfully.
            ========== COMMANDS ==========
            File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\etilqs_UqdM3Z2tpw55gZy5h1xE scheduled to be deleted on reboot.
            User's Temp folder emptied.
            User's Temporary Internet Files folder emptied.
            User's Internet Explorer cache folder emptied.
            Local Service Temp folder emptied.
            File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
            Local Service Temporary Internet Files folder emptied.
            File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_5f8.dat scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_6d8.dat scheduled to be deleted on reboot.
            Windows Temp folder emptied.
            Java cache emptied.
            File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\rdfw7xfg.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
            File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\rdfw7xfg.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
            File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\rdfw7xfg.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
            File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\rdfw7xfg.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
            File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\rdfw7xfg.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
            File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\rdfw7xfg.default\XUL.mfl scheduled to be deleted on reboot.
            FireFox cache emptied.
            Temp folders emptied.
            Explorer started successfully
             
            OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01132009_180725

            Files moved on Reboot...
            File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\etilqs_UqdM3Z2tpw55gZy5h1xE not found!
            File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
            File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
            File C:\WINDOWS\temp\Perflib_Perfdata_5f8.dat not found!
            C:\WINDOWS\temp\Perflib_Perfdata_6d8.dat moved successfully.
            C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\rdfw7xfg.default\Cache\_CACHE_001_ moved successfully.
            C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\rdfw7xfg.default\Cache\_CACHE_002_ moved successfully.
            C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\rdfw7xfg.default\Cache\_CACHE_003_ moved successfully.
            C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\rdfw7xfg.default\Cache\_CACHE_MAP_ moved successfully.
            C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\rdfw7xfg.default\urlclassifier3.sqlite moved successfully.
            C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\rdfw7xfg.default\XUL.mfl moved successfully.
            This scanner requires Internet Explorer

            Scan with the BitDefender Online Scanner
            Click I Agree to the license and then install the ActiveX control.
            Please DO NOT change the Scanning Options.
            That will make your logs huge and we don't need to see clean files.

            Select Start Scan to begin.
            This scan can take a while so please be patient and let it complete.

            Once Bitdefender completes the scan:
            Click-on the Detected Problems tab.
            Then select Click here to export the scan report



            This will save a file named bdscan.html I would suggest saving it to the Desktop so you can easily find it. (take notice of where you save it so you can find it later)
             
            You will have to upload the file online. The forums will not accept HTML.

            Upload the file to Savefile.com
            There is no need to Register
            Select Browse and locate the file.
            Fill in the Title, Description and security code then click Upload
            Copy the link next to Your link to the file: and post the link back here.Just a question that I think might actually be important. What site did yahoo redirect to. Please give a complete url(not just the domain name).when i go to bitdefender, it fails when i click on start scan. i was using IE when doing this.Try another scanner please.

            Run this online scan.

            This scanner requires Internet Explorer

            Use the ESET Nod32 Online Scanner

            1. Check the box next to YES, I accept the Terms of Use.
            2. Click Start
            3. When asked, allow the activex control to install
            4. Click Start
            5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked.
            6. Click Scan
            7. Wait for the scan to finish
            8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
            9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.
            974.

            Solve : advanced systemcare ( advice please )?

            Answer»

            i have had this for a good while and find the UPDATE very good and easy to use

            has any-one went into utilities and used all that is in " tune up , security , ADMIN tools " or are there any in there that you WOULD not use

            i have used most of them

            thanks for your help , harry

            975.

            Solve : Help, desktop died...?

            Answer»

            Here's what happened. We use Avaist. The other day, a window came up and said that Avaist was expired and we needed to ENTER a new REGISTRATION code, but Avaist was last installed in Nov., and should have expired yet. Well, sometime between it expired and we reinstalled it, something must have gotten in, because when we rebooted, the boot scan came up and just about every file that it scanned was put in the chest and then it said the chest was full, so we ESCAPED out and rebooted. Now it loads up to the user name/password LOGIN box, you hit ok, and it says loading personal settings, and then immediately LOGS back off to the login box. Does the same thing when trying to load in safe mode and from last good known configuration.

            Please help.

            Thanks.

            976.

            Solve : antivirus 360?

            Answer»

            Help..... Was interupted in the middle of something, and downloaded this 'thing' in error. Now I cnt get rid of it. it WONT let me do anything... and keeps TELLING me i got VIRUS's and things.


            It doesn't show in add and remove programmes, and it wont let me delete from'my computer' I get the message "cannot delete av360 exe. access denied." and pop-ups appear all over the place. Any web site i got to (including microsoft's own) is blocked so I have to 'back' up to previous page to continue. I tried re-setting to a previous date and that doesn't work either.

            Help...Please  Need...more...info...gasp 

            Operating SYSTEM / antivirus & antispyware PROTECTION / service packs installed / tried booting into safe mode (F8 when starting computer) and running scans?

            Alan <><

            977.

            Solve : help everytime i open .bat files my pc shut downs!!?

            Answer»

            help everytime i open .BAT FILES my pc shut downs!!do you think its a virus and if i scan it ..it will REMOVE RIGHT?

            978.

            Solve : NORTON . allow inbound and outbound connections to?

            Answer»

            hello there

            Would anyone out there advise me on how to do this,  with the norton version
            10.2.0.30



            Quote

            ALLOW inbound and outbound connections to:

            <http://*egalacoral.com>
            and
            <https://*.egalacoral.com>

            Allow outbound connections to:

            tcpport414
            and
            62.189.69.39

            This should RECTIFY the PROBLEM.

            979.

            Solve : Norton 2009 unblock virus??

            Answer»

            I GOT a problem whit norton 2009, im TRYING to get a file but norton class it as a virus, well it is a virus but a virus i need to do a thing.
            and i have try to do all things i can THINK of but still it just wont leave it alone...

            i have looked in nortons home page, and more forums but dident find any thing

            so do some one KNOW how to fix this?
            In my experience, Norton isn't easy to turn off.

            What is this file, what are you trying to do may I ask?its a trojan who can hide drivers, program and so on like it can hide your games, so no one know your playing it. like you have Xfire it will SENS if you are playing a game but whit this "virus" it hide the game so Xfire wont see that you are playing it.

            It might seam like I'm crazy but it is quite nice program which you can have much fun whit... It sounds like something we can't do here too....well guess i have to live whit out it... well thx anyway

            980.

            Solve : Continue to have problems?

            Answer»

            I was here a few weeks ago, and got assistance with my computer and what I believe was spyware and such. However, now just a few weeks later, it is all starting over again. My computer, while on internet, is extremely slow, I have a DSL connection. And it's starting again where I click on certain buttons and it does nothing, just sits there. I've run the SuperAntiSpyware program, and removed the files it said, etc...but it's still so slow. Can someone tell me if I'm going to have to go through this continually now, or what the problem might be? Thanks!Hard to say. Have a friend come to you house with his laptop and see if it is the DSL connection. I've had my isp check that, it's not the connection. It's doing almost exactly what it was before, which is running extremely slow, not navigating to pages when I click on things, even the spyware, malware and virus programs I got here are all messed up, they don't run the scans the same way. One of the things that I thought was really WEIRD is when I am typing, about every 15 characters or so, it'll "miss" the stroke, I GUESS is the only way to put it. I'll be typing and one letter or character will not come through. I don't know how to explain that PART, it's just another one of the weird things happening. Anyone have any ideas here? This is causing major frustration, as I work on my computer from home, and it really slows things down for me. could you run through the malware guides and post the logs; our experts can then look over the logs for you

            I'll try, but that's another one of the issues I am now having. None of them are doing what they used to do. I ran all the programs I have in the last 24 hours, I will attach them here, but I'm not sure if they will be useful, since so MUCH seems to be happening. I also want to be sure to include that last night this computer completely went NUTS for a few hours. It would either let me get to the point where you click on your username, right at the start of windows, then my mouse would freeze. If I got past that page, one of two things happened: I would either get my usual desktop but when I clicked on any of my icons, got nothing OR I would get the picture of my girls I have on my desktop, but none of my icons or the tool bar at the bottom. If I got that, I had to disconnect my computer from the power in order to start over. I did this for a couple of hours at least, until I finally was able to do a system restore in safe mode. Not sure if that means anything or not, but it was really weird and very frustrating. Thanks for the quick replies, I'll get the logs now! I'm attaching the logs I have so far, thanks! The 2nd attachment is ComboFix

            [attachment deleted by admin]

            981.

            Solve : Online XP Scanner: DANGER! Virus upgraded and back on the prowl!?

            Answer»

            This is a message to everyone, to watch out for page redirects on google...I was searching for some info on a local air cadet squadron, I clicked a link hoping it had valuable information (hxxp://chavrie.com/include/page.php?p=1126980&f=56 WARNING: EXTREMELY DANGEROUS SITE! GO AT OWN RISK!) and it brought me to, yet another Online XP scanner website...

            I am telling you this as an ex-victim of this site's viruses. It will lagg your computer to the point of crashing. Less than every 10 minutes, it brings errors saying that you've been infected, clicking the alert at all (even clicking the X button) will bring you to their website, to SLOW down your computer even farther, and pester you into buying the full version of a fake XP scanner, for $50 USD. (I never had the free version in the first place)


            Be aware, if you are going to click the link above, make sure to add it to your restricted section, and enable every security feature on your firewall for protection. This virus is like head lice in the middle ages, comes in quickly, spreads fast and is horrible to remove. It manages to embed itself within system restore and explorer.exe, so no matter how many times you remove it with your anti-virus system, it keeps coming back.

            This is not to be trifled with. More and more seemingly legitimate sites are popping up, implanting viruses on your computer, urging you to buy the upgraded version of some "anti-virus" software to "remove" the viruses, just to get another virus, and more messages telling you to get the "Ultimate" virus removal tool...

            I speak of this from past experience.

            Link Disabled - EFI went there and nothing happened.

            I've gotten them a few times; only took a few minutes writing down process names and then a drop to recovery console to fix it.

            But I remember my first experience with "SpywareAxe" or something. ahh, I was new to XP, so none of my win98 experience at removing malware was valid. didn't KNOW about RC, and couldn't get into "DOS" mode.

            I did get rid of it though.


            Are you using Internet Explorer, Perchance? Quote from: BC_Programmer on January 13, 2009, 06:23:59 PM

            I went there and nothing happened.

            I've gotten them a few times; only took a few minutes writing down process names and then a drop to recovery console to fix it.

            But I remember my first experience with "SpywareAxe" or something. ahh, I was new to XP, so none of my win98 experience at removing malware was valid. didn't know about RC, and couldn't get into "DOS" mode.

            I did get rid of it though.


            Are you using Internet Explorer, Perchance?
            Currently no. After I heard that there is a major security FLAW, I went to FireFox. I did when I got the virus, although I'm not sure about SpywareAxe, I got Trojan.Vundoo or something like that...IMO the "major security flaw" is that MS didn't surround the execution of ActiveX controls in tight security measures and some form of sandboxing.

            ActiveX is great for applications, but for web programs/browsers it's a completely stupid application of the technology.For some reason not all hijacked sites "attack" every visitor. We were investigating one and it only launched (antivirus 2009) on 2 of us. Me being one, but I was smart ENOUGH to open the link while Sandboxed.
            982.

            Solve : I Have Virus(es) on my computer, please assist!?

            Answer»

            Okay, then try this: right-click on the FILE and go to Send To > COMPRESSED (zipped) Folder.  That should create a .zip file.  You can then attach it to your next post or try uploading it to SaveFile.http://www.savefile.com/files/1961368
             Thank you for getting the file uploaded.  I have scanned it with several different programs and none of them FOUND anything, so it looks like the file should be LEGIT.  I guess you're in the clear!  Are things running okay?Yes! everything is running great!Great, I'm glad to hear it.Thanks a million!

            983.

            Solve : trojan and new problem that wont come off ); im gonna cry?

            Answer»

            hi i kno that im new here but dont even kno if this is right section for me but am REQUIRING some help on y my computer is acting funny obvoiusly from a virus or trojan but ive delt with this same trogan a aday ago and seems as if it is back i have using many things trying to remove it COMBOFIX avg spybot search destroy and spybot had found it but couldnt remove it becuase it was runing in memory or something but i need help now becuase now i cant deal with this on my own im not sure if the 2 are related thow here is the website it was trying to acess
            http://70.38.98.32/red.php?lid=acr [...] z&xp=1&p=1

            http://sagipsul.com/go/?cmp=vm_mg_ [...] profiling4

            and many others related to taht i have no clue what it is but the website cant be shown when it is accessed

            here is a hijackthis log

            ~~~~~~~~~~~
            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 7:48:37 PM, on 1/3/2009
            Platform: Windows XP SP3 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16762)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Common Files\APPLE\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
            C:\Program Files\Bonjour\mDNSResponder.exe
            C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
            C:\Program Files\Java\jre6\bin\jqs.exe
            C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
            C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
            C:\WINDOWS\system32\nvsvc32.exe
            C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
            C:\PROGRA~1\AVG\AVG8\avgrsx.exe
            C:\Games\EA Games\Need for Speed Undercover\PB\PnkBstrA.exe
            C:\Program Files\Viewpoint\Common\ViewpointService.exe
            c:\WINDOWS\system32\ZuneBusEnum.exe
            C:\PROGRA~1\AVG\AVG8\avgemc.exe
            C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
            C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
            C:\WINDOWS\system32\SearchIndexer.exe
            C:\WINDOWS\system32\rundll32.exe
            C:\WINDOWS\Explorer.EXE
            C:\PROGRA~1\AVG\AVG8\avgtray.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\Program Files\Zune\ZuneLauncher.exe
            C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
            C:\WINDOWS\system32\RUNDLL32.EXE
            C:\Program Files\Analog Devices\Core\smax4pnp.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
            C:\Program Files\Ventrilo\Ventrilo.exe
            C:\Program Files\Xfire\xfire.exe
            C:\Program Files\Teamspeak2_RC2\TeamSpeak.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\Games\Silkroad\sro_client.exe
            C:\WINDOWS\system32\rundll32.exe
            C:\WINDOWS\system32\wscntfy.exe
            C:\WINDOWS\system32\rundll32.exe
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\Games\Silkroad\sro_client.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\WINDOWS\system32\SearchProtocolHost.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
            O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
            O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
            O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
            O4 - HKLM\..\Run: [SoundMax] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
            O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.22\RivaTuner.exe" /S
            O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
            O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
            O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
            O9 - EXTRA button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/Driv [...] eqlab3.cab
            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wi [...] 0140548374
            O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
            O20 - AppInit_DLLs: avgrsstx.dll iiickz.dll fzwtze.dll
            O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
            O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
            O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
            O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
            O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
            O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
            O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
            O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
            O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
            O23 - Service: PunkBuster (PnkBstrA) - Unknown owner - C:\Games\EA Games\Need for Speed Undercover\PB\PnkBstrA.exe
            O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

            --
            End of file - 7455 bytes

            dont kno if that helps but thanks for replys nvm i fixed I have the same winlogun problem.  How did you fix this?
            It's also made it impossible to change my folder options (Show hidden folders, etc) and creates a ridiculous amount of popups on various browsers.

            984.

            Solve : Computer...****** completely?

            Answer»

            To be honest, I'm not really seeing much.  I only noticed one file that looked suspicious, but I don't even know if it's still on your computer.  For the heck of it, CREATE a new CFScript using the text below:
            Code: [Select]KillAll::

            File::
            C:\WINDOWS\system32\ieiwebmscgfwieuet.exe

            Then just follow the CFScript instructions I gave before.  Other than that, I can't find anything that looks like it would be causing all of your problems.  You may want to try Sophos Anti-Rootkit, but at this point, there's a chance that you're not infected anymore.  It seems to me that either your problem is related to something other than a virus, or the infections did some real damage on your computer.Hi again. Sorry been around the last few days trying to see what anyone can do with this computer physically but had no RESULTS so far. Ive tried your second ComboFix text and got the results on the attachment. I take it that a solution is now looking...well...dismally bleak?

            [attachment deleted by admin]Tried that Sophos Root-Kit...well attempted to. Can't run a scan whatsoever in Safe Mode. And well, thats all that my laptop can pretty much do at the moment. Any other suggestions would be very helpful. But if you THINK the laptops hit the fan then, well, nothing more can be done I suppose. do you have a windows CD? You could try a format/Install. (after backing up any important stuff.)Unfortunately, BC's suggestion MIGHT be your best bet.  I can't really find much of anything malicious anymore, which suggests that it is not a virus issue.  There may be something you can do, but with all of the things on my plate right now, I'm not quite sure where to begin with the troubleshooting PROCESS.  If you have the CD, you can try a reformat or fresh install of Windows.  Or you can see if anyone over at the Windows or Software sections of the forum might have any better suggestions.

            985.

            Solve : csrssc.exe virus and random black windows popping up with errors?

            Answer»

            Hi,
            I was recently watching a show on Fox.com and an antispyware program popped up on my screen and started scanning my computer, so I immediately stopped the scan and DELETED the program. Or so I thought. Now, every time I log on to my account (the only account on the computer) I KEEP getting these little black windows that pop up and tell me that there has been some sort of error.

            I first went to the post that said to do this stuff before I POSTED and I did and this is the report for the SUPERAntiSpyware scan:

            SUPERAntiSpyware Scan Log
            http://www.superantispyware.com

            Generated 01/29/2009 at 05:59 PM

            Application Version : 4.25.1012

            Core Rules Database Version : 3743
            Trace Rules Database Version: 1711

            Scan type       : Complete Scan
            Total Scan Time : 01:04:33

            Memory items scanned      : 556
            Memory threats detected   : 4
            Registry items scanned    : 6361
            Registry threats detected : 211
            File items scanned        : 79273
            File threats detected     : 32

            Trojan.Smitfraud Variant-Gen/Bensorty
               C:\WINDOWS\SYSTEM32\GSDRGFDRRGND.DLL
               C:\WINDOWS\SYSTEM32\GSDRGFDRRGND.DLL
               HKLM\Software\Classes\CLSID\{D5BF4552-94F1-42BD-F434-3604812C807D}
               HKCR\CLSID\{D5BF4552-94F1-42BD-F434-3604812C807D}
               HKCR\CLSID\{D5BF4552-94F1-42BD-F434-3604812C807D}
               HKCR\CLSID\{D5BF4552-94F1-42BD-F434-3604812C807D}#ThreadingModel
               HKCR\CLSID\{D5BF4552-94F1-42BD-F434-3604812C807D}\InProcServer32
               HKCR\CLSID\{D5BF4552-94F1-42BD-F434-3604812C807D}\InProcServer32#ThreadingModel
               HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d5bf4552-94f1-42bd-f434-3604812c807d}
               HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler#{D5BF4552-94F1-42BD-F434-3604812C807D}
               HKU\s-1-5-21-2831675395-3779781758-680594672-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D5BF4552-94F1-42BD-F434-3604812C807D}

            Trojan.Dropper/Gen-NV
               C:\DOCUME~1\PHIXIUS\LOCALS~1\TEMP\WINLOGNN.EXE
               C:\DOCUME~1\PHIXIUS\LOCALS~1\TEMP\WINLOGNN.EXE
               [lrijh8s73jhbfgfd] C:\DOCUME~1\PHIXIUS\LOCALS~1\TEMP\WINLOGNN.EXE
               [lrijh8s73jhbfgfd] C:\DOCUME~1\PHIXIUS\LOCALS~1\TEMP\WINLOGNN.EXE
               C:\DOCUMENTS AND SETTINGS\PHIXIUS\LOCAL SETTINGS\TEMP\WINLOGNN.EXE
               C:\WINDOWS\Prefetch\WINLOGNN.EXE-1008CFA5.pf

            Trojan.Downloader-Gen/A
               C:\DOCUME~1\PHIXIUS\LOCALS~1\TEMP\A.EXE
               C:\DOCUME~1\PHIXIUS\LOCALS~1\TEMP\A.EXE
               C:\WINDOWS\Prefetch\A.EXE-2C1E3FDA.pf

            Trojan.Csrssc/Systemc-B
               C:\DOCUME~1\PHIXIUS\LOCALS~1\TEMP\CSRSSC.EXE
               C:\DOCUME~1\PHIXIUS\LOCALS~1\TEMP\CSRSSC.EXE
               [tezrtsjhfr84iusjfo84f] C:\DOCUME~1\PHIXIUS\LOCALS~1\TEMP\CSRSSC.EXE
               C:\DOCUMENTS AND SETTINGS\PHIXIUS\LOCAL SETTINGS\TEMP\CSRSSC.EXE
               C:\WINDOWS\Prefetch\CSRSSC.EXE-326D7AD2.pf

            Trojan.FakeAlert-GenA
               [MSFox] C:\DOCUME~1\PHIXIUS\LOCALS~1\TEMP\A.EXE
               C:\DOCUMENTS AND SETTINGS\PHIXIUS\LOCAL SETTINGS\TEMP\A.EXE

            Malware.Safety Bar
               HKLM\Software\Classes\CLSID\{052b12f7-86fa-4921-8482-26c42316b522}
               HKCR\CLSID\{052B12F7-86FA-4921-8482-26C42316B522}
               HKCR\CLSID\{052B12F7-86FA-4921-8482-26C42316B522}
               HKCR\CLSID\{052B12F7-86FA-4921-8482-26C42316B522}\Implemented Categories
               HKCR\CLSID\{052B12F7-86FA-4921-8482-26C42316B522}\Implemented Categories\{00021493-0000-0000-C000-000000000046}
               HKCR\CLSID\{052B12F7-86FA-4921-8482-26C42316B522}\InprocServer32
               HKCR\CLSID\{052B12F7-86FA-4921-8482-26C42316B522}\InprocServer32#ThreadingModel
               C:\PROGRAM FILES\SAFETY BAR\SAFETYBAR.DLL
               HKU\s-1-5-21-2831675395-3779781758-680594672-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{052B12F7-86FA-4921-8482-26C42316B522}
               HKU\s-1-5-21-2831675395-3779781758-680594672-1007\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser#{052B12F7-86FA-4921-8482-26C42316B522}
               HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SafetyBar
               HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SafetyBar#DisplayName
               HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SafetyBar#UninstallString

            Trojan.Unclassified/MSXML71
               HKLM\Software\Classes\CLSID\{500BCA15-57A7-4eaf-8143-8C619470B13D}
               HKCR\CLSID\{500BCA15-57A7-4EAF-8143-8C619470B13D}
               HKCR\CLSID\{500BCA15-57A7-4EAF-8143-8C619470B13D}
               HKCR\CLSID\{500BCA15-57A7-4EAF-8143-8C619470B13D}#Install
               HKCR\CLSID\{500BCA15-57A7-4EAF-8143-8C619470B13D}\InprocServer32
               HKCR\CLSID\{500BCA15-57A7-4EAF-8143-8C619470B13D}\InprocServer32#ThreadingModel
               HKCR\CLSID\{500BCA15-57A7-4EAF-8143-8C619470B13D}\ProgID
               HKCR\CLSID\{500BCA15-57A7-4EAF-8143-8C619470B13D}\Programmable
               HKCR\CLSID\{500BCA15-57A7-4EAF-8143-8C619470B13D}\TypeLib
               HKCR\CLSID\{500BCA15-57A7-4EAF-8143-8C619470B13D}\VersionIndependentProgID
               HKCR\XML.XML.1
               HKCR\XML.XML.1\CLSID
               HKCR\XML.XML
               HKCR\XML.XML\CLSID
               HKCR\XML.XML\CurVer
               HKCR\TypeLib\{48DE7E85-178E-CA61-5325-23647F3D90CC}
               HKCR\TypeLib\{48DE7E85-178E-CA61-5325-23647F3D90CC}\.0
               C:\WINDOWS\SYSTEM32\MSXML71.DLL
               HKU\s-1-5-21-2831675395-3779781758-680594672-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{500bca15-57a7-4eaf-8143-8c619470b13d}

            Adware.MyWebSearch
               HKU\s-1-5-21-2831675395-3779781758-680594672-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D}
               HKU\s-1-5-21-2831675395-3779781758-680594672-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
               HKU\s-1-5-21-2831675395-3779781758-680594672-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA}

            Browser Hijacker.BestSafetyGuide
               HKU\s-1-5-21-2831675395-3779781758-680594672-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A43385F0-7113-496D-96D7-B9B550E3FCCA}

            Trojan.Unknown Origin
               HKLM\SOFTWARE\Microsoft\MSSMGR
               HKLM\SOFTWARE\Microsoft\MSSMGR#Data
               HKLM\SOFTWARE\Microsoft\MSSMGR#LSTV
               HKLM\SOFTWARE\Microsoft\MSSMGR#Brnd
               HKLM\SOFTWARE\Microsoft\MSSMGR#MSLIST
               HKLM\SOFTWARE\Microsoft\MSSMGR#PID
               HKLM\SOFTWARE\Microsoft\MSSMGR#Rid
               HKLM\SOFTWARE\Microsoft\MSSMGR#LID
               HKLM\SOFTWARE\Microsoft\MSSMGR#SCLIST
               HKLM\SOFTWARE\Microsoft\MSSMGR#SSLIST
               HKLM\SOFTWARE\Microsoft\MSSMGR#BSTV
               HKLM\SOFTWARE\Microsoft\MSSMGR#BPTV
               HKLM\SOFTWARE\Microsoft\MSSMGR#PSTV
               HKLM\SOFTWARE\Microsoft\MSSMGR#SSTV
               HKLM\SOFTWARE\Microsoft\MSSMGR#OCCUR
               C:\WINDOWS\SYSTEM32\OT.ICO
               C:\WINDOWS\SYSTEM32\TS.ICO

            Adware.MyWebSearch/FunWebProducts
               HKU\s-1-5-21-2831675395-3779781758-680594672-1007\SOFTWARE\Fun Web Products
               HKLM\SOFTWARE\Fun Web Products
               HKLM\SOFTWARE\Fun Web Products#JpegConversionLib
               HKLM\SOFTWARE\Fun Web Products#CacheDir
               HKLM\SOFTWARE\Fun Web Products\ScreenSaver
               HKLM\SOFTWARE\Fun Web Products\ScreenSaver#ImagesDir
               HKLM\SOFTWARE\Fun Web Products\ScreenSaver#PM
               HKLM\SOFTWARE\Fun Web Products\Settings
               HKLM\SOFTWARE\Fun Web Products\Settings\AvatarSmallBtn
               HKLM\SOFTWARE\Fun Web Products\Settings\AvatarSmallBtn#LastHTMLMenuURL
               HKLM\SOFTWARE\Fun Web Products\Settings\AvatarSmallBtn#HTMLMenuRevision
               HKLM\SOFTWARE\Fun Web Products\Settings\AvatarSmallBtn#ETag
               HKLM\SOFTWARE\Fun Web Products\Settings\CursorManiaBtn
               HKLM\SOFTWARE\Fun Web Products\Settings\CursorManiaBtn#LastHTMLMenuURL
               HKLM\SOFTWARE\Fun Web Products\Settings\CursorManiaBtn#HTMLMenuRevision
               HKLM\SOFTWARE\Fun Web Products\Settings\CursorManiaBtn#ETag
               HKLM\SOFTWARE\Fun Web Products\Settings\MailStampBtn
               HKLM\SOFTWARE\Fun Web Products\Settings\MailStampBtn#LastHTMLMenuURL
               HKLM\SOFTWARE\Fun Web Products\Settings\MailStampBtn#HTMLMenuRevision
               HKLM\SOFTWARE\Fun Web Products\Settings\MailStampBtn#ETag
               HKLM\SOFTWARE\Fun Web Products\Settings\MyFunCardsIMBtn
               HKLM\SOFTWARE\Fun Web Products\Settings\MyFunCardsIMBtn#LastHTMLMenuURL
               HKLM\SOFTWARE\Fun Web Products\Settings\MyFunCardsIMBtn#HTMLMenuRevision
               HKLM\SOFTWARE\Fun Web Products\Settings\MyFunCardsIMBtn#ETag
               HKLM\SOFTWARE\Fun Web Products\Settings\Promos
               HKLM\SOFTWARE\Fun Web Products\Settings\Promos#BuddyTextNone.numActive
               HKLM\SOFTWARE\Fun Web Products\Settings\Promos#BuddyTextNone.0
               HKLM\SOFTWARE\Fun Web Products\Settings\Promos#BuddyFreqNone
               HKLM\SOFTWARE\Fun Web Products\Settings\Promos#BuddyTextUninstalled.numActive
               HKLM\SOFTWARE\Fun Web Products\Settings\Promos#BuddyTextUninstalled.0
               HKLM\SOFTWARE\Fun Web Products\Settings\Promos#BuddyFreqUninstalled
               HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.numActive
               HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.numActive2
               HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.1
               HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.2
               HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.3
               HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.4
               HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.5
               HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.6
               HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.7
               HKLM\SOFTWARE\Fun Web Products\Settings\SmileyCentralBtn
               HKLM\SOFTWARE\Fun Web Products\Settings\SmileyCentralBtn#HTMLMenuPosDeleted
               HKLM\SOFTWARE\Fun Web Products\Settings\SmileyCentralBtn#LastHTMLMenuURL
               HKLM\SOFTWARE\Fun Web Products\Settings\SmileyCentralBtn#HTMLMenuRevision
               HKLM\SOFTWARE\Fun Web Products\Settings\SmileyCentralBtn#ETag
               HKLM\SOFTWARE\Fun Web Products\Settings\SmileyCentralBtn#iexplore.exe.pos
               HKLM\SOFTWARE\Fun Web Products\Settings\SmileyCentralBtn#firefox.exe.pos
               HKU\s-1-5-21-2831675395-3779781758-680594672-1007\SOFTWARE\FunWebProducts
               HKLM\SOFTWARE\FunWebProducts
               HKLM\SOFTWARE\FunWebProducts\Installer
               HKLM\SOFTWARE\FunWebProducts\Installer#Dir
               HKLM\SOFTWARE\FunWebProducts\Installer#CurInstall
               HKLM\SOFTWARE\FunWebProducts\Installer#sr
               HKLM\SOFTWARE\FunWebProducts\Installer#pl
               HKLM\SOFTWARE\FunWebProducts\Installer#CheckForConnection
               HKLM\SOFTWARE\FunWebProducts\Installer#CacheDir
               HKLM\SOFTWARE\FunWebProducts\Installer\downloaded
               HKU\s-1-5-21-2831675395-3779781758-680594672-1007\SOFTWARE\MyWebSearch
               HKLM\SOFTWARE\MyWebSearch
               HKLM\SOFTWARE\MyWebSearch\bar
               HKLM\SOFTWARE\MyWebSearch\bar#pid
               HKLM\SOFTWARE\MyWebSearch\bar#Dir
               HKLM\SOFTWARE\MyWebSearch\bar#CurInstall
               HKLM\SOFTWARE\MyWebSearch\bar#SettingsDir
               HKLM\SOFTWARE\MyWebSearch\bar#sr
               HKLM\SOFTWARE\MyWebSearch\bar#pl
               HKLM\SOFTWARE\MyWebSearch\bar#Id
               HKLM\SOFTWARE\MyWebSearch\bar#CacheDir
               HKLM\SOFTWARE\MyWebSearch\bar#HTMLMenuRevision
               HKLM\SOFTWARE\MyWebSearch\bar#sscLabel
               HKLM\SOFTWARE\MyWebSearch\bar#sscURL
               HKLM\SOFTWARE\MyWebSearch\bar#Flags
               HKLM\SOFTWARE\MyWebSearch\bar#HistoryDir
               HKLM\SOFTWARE\MyWebSearch\bar#DSSEnabled
               HKLM\SOFTWARE\MyWebSearch\bar#tiec
               HKLM\SOFTWARE\MyWebSearch\bar#SearchProvider
               HKLM\SOFTWARE\MyWebSearch\SearchAssistant
               HKLM\SOFTWARE\MyWebSearch\SearchAssistant#pid
               HKLM\SOFTWARE\MyWebSearch\SearchAssistant#Dir
               HKLM\SOFTWARE\MyWebSearch\SearchAssistant#esh
               HKLM\SOFTWARE\MyWebSearch\SearchAssistant#lsp
               HKLM\SOFTWARE\MyWebSearch\SearchAssistant#CurInstall
               HKLM\SOFTWARE\MyWebSearch\SearchAssistant#sr
               HKLM\SOFTWARE\MyWebSearch\SearchAssistant#pl
               HKLM\SOFTWARE\MyWebSearch\SearchAssistant#Id
               HKLM\SOFTWARE\MyWebSearch\SearchAssistant#ABS
               HKLM\SOFTWARE\MyWebSearch\SearchAssistant#DES
               HKLM\SOFTWARE\MyWebSearch\SearchAssistant#eintl
               HKLM\SOFTWARE\MyWebSearch\SearchAssistant#fs
               HKLM\SOFTWARE\MyWebSearch\SearchAssistant#sscEnabled
               HKLM\SOFTWARE\MyWebSearch\SearchAssistant#ConfigDateStamp
               HKLM\SOFTWARE\MyWebSearch\SkinTools
               HKLM\SOFTWARE\MyWebSearch\SkinTools#PlayerPath
               HKCR\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}
               HKCR\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}\TreatAs
               HKCR\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179}
               HKCR\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179}\TreatAs
               HKCR\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3}
               HKCR\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3}\TreatAs
               HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
               HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid
               HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid32
               HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib
               HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib#Version
               HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}
               HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ProxyStubClsid
               HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ProxyStubClsid32
               HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\TypeLib
               HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\TypeLib#Version
               HKLM\Software\FocusInteractive
               HKLM\Software\FocusInteractive\bar
               HKLM\Software\FocusInteractive\bar\Switches
               HKLM\Software\FocusInteractive\bar\Switches#incmail.exe
               HKLM\Software\FocusInteractive\bar\Switches#msimn.exe
               HKLM\Software\FocusInteractive\bar\Switches#msn.exe
               HKLM\Software\FocusInteractive\bar\Switches#outlook.exe
               HKLM\Software\FocusInteractive\bar\Switches#waol.exe
               HKLM\Software\FocusInteractive\bar\Switches#aim.exe
               HKLM\Software\FocusInteractive\bar\Switches#icq.exe
               HKLM\Software\FocusInteractive\bar\Switches#icqlite.exe
               HKLM\Software\FocusInteractive\bar\Switches#msmsgs.exe
               HKLM\Software\FocusInteractive\bar\Switches#msnmsgr.exe
               HKLM\Software\FocusInteractive\bar\Switches#ypager.exe
               HKLM\Software\FocusInteractive\bar\Switches#mwsSrcAs.dll
               HKLM\Software\FocusInteractive\bar\Switches#au
               HKLM\Software\FocusInteractive\bar\Switches#ok
               HKLM\Software\FocusInteractive\bar\Switches#od
               HKLM\Software\FocusInteractive\bar\Switches#nk
               HKLM\Software\FocusInteractive\bar\Switches#nd
               HKLM\Software\FocusInteractive\Email-IM
               HKLM\Software\FocusInteractive\Email-IM\0
               HKLM\Software\FocusInteractive\Email-IM\0#Toolbar
               HKLM\Software\FocusInteractive\Email-IM\0#AppName
               HKLM\Software\FocusInteractive\Outlook
               C:\Program Files\MyWebSearch\bar\History\search2
               C:\Program Files\MyWebSearch\bar\History
               C:\Program Files\MyWebSearch\bar\Settings\setting2.htm
               C:\Program Files\MyWebSearch\bar\Settings\settings.dat
               C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
               C:\Program Files\MyWebSearch\bar\Settings
               C:\Program Files\MyWebSearch\bar
               C:\Program Files\MyWebSearch
               C:\Program Files\FunWebProducts\ScreenSaver\Images\0021736A.urr
               C:\Program Files\FunWebProducts\ScreenSaver\Images
               C:\Program Files\FunWebProducts\ScreenSaver
               C:\Program Files\FunWebProducts\Shared
               C:\Program Files\FunWebProducts

            Trojan.Security Toolbar
               C:\Documents and Settings\Phixius\Favorites\Antivirus Test Online.url

            Trojan.Incestuously
               HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler#incestuously [ {03413bf7-e34c-445b-bfc0-a2b127255871} ]

            Trojan.Unclassified/MSFox
               HKU\s-1-5-21-2831675395-3779781758-680594672-1007\Software\Microsoft\Windows\CurrentVersion\Run#MSFox [ C:\DOCUME~1\Phixius\LOCALS~1\Temp\a.exe ]
               HKLM\SOFTWARE\Mozilla\MSFox
               HKLM\SOFTWARE\Mozilla\MSFox#Str5
               HKLM\SOFTWARE\Mozilla\MSFox#Str9
               HKLM\SOFTWARE\Mozilla\MSFox#Str6
               HKLM\SOFTWARE\Mozilla\MSFox#Str7
               HKLM\SOFTWARE\Mozilla\MSFox#Str8
               HKLM\SOFTWARE\Mozilla\MSFox#Str4
               HKLM\SOFTWARE\Mozilla\MSFox#Str10
               HKLM\SOFTWARE\Mozilla\MSFox#Str1
               HKLM\SOFTWARE\Mozilla\MSFox#Str0
               HKLM\SOFTWARE\Mozilla\MSFox#Int2
               HKLM\SOFTWARE\Mozilla\MSFox#Int3

            Trojan.Unclassified/Cognac
               HKU\s-1-5-21-2831675395-3779781758-680594672-1007\Software\Microsoft\Windows\CurrentVersion\Run#Cognac [ C:\DOCUME~1\Phixius\LOCALS~1\Temp\~tmpe.exe ]

            Rogue.MSAntiSpyware2009
               C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009
               C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd

            Adware.MyWebSearch-Installer
               C:\DOCUMENTS AND SETTINGS\PHIXIUS\DESKTOP\UNUSED DESKTOP SHORTCUTS\ZWINKYSETUP2.2.50.1-3.ZJFOX000.EXE

            Adware.ClickSpring/Yazzle
               C:\WINDOWS\PREFETCH\YAZZLE1162OINUNINSTALLER.EXE-1ED8E2D1.PF


            I am now running the Malwarebytes Anti-Malware program.Ok, and here are my Malwarebytes' Anti-Malware log and HijackThis log.

            Now that I have ran all of these programs my computer no longer seems to be bringing up the little black windows with errors anymore.

            Also, in case you need to know, my computer information is:

            MS Windows XP Professional SP3, INTEL Pentium 4 CPU, 2.80GHz, 512MB RAM, Intel 82845G/GL/GE/PE/GU Graphics Controls

            That's about all I know about it. I really hope that this will fix everything on my computer. I use this computer for school so I have a ton of school work SAVED on here.

            [attachment deleted by admin]

            986.

            Solve : I Got What I Believe is a Trojan and I Need HELP Removing It?

            Answer»

            Below is the SUPERAntiSpyware Scan Log. Also Note, at the end of the scan after I pressed next to continue to allow the program to try and fix or quarantine the selected ITEMS, and immediatly my computer went into a blue screen and displyed the following:
            Quote

            TOP: C000021 a {Fatal System Error}
            The windows logon process terminated unexpectedly with a status o
            0x00000000 (0x00000000 0x00000000)
            The system has been shut down
            Quote
            SUPERAntiSpyware Scan Log
            http://www.superantispyware.com

            Generated 09/22/2008 at 08:56 PM

            Application Version : 4.21.1004

            Core Rules Database Version : 3577
            Trace Rules Database Version: 1565

            Scan type       : Complete Scan
            Total Scan Time : 01:52:23

            Memory items scanned      : 693
            Memory threats detected   : 4
            Registry items scanned    : 7597
            Registry threats detected : 38
            File items scanned        : 170147
            File threats detected     : 12

            Trojan.Dropper/WinCtrl32
               C:\WINDOWS\SYSTEM32\WINCQT32.DLL
               C:\WINDOWS\SYSTEM32\WINCQT32.DLL
               Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\wincqt32

            Adware.Vundo Variant/OE
               C:\WINDOWS\SYSTEM32\OPNMJBRS.DLL
               C:\WINDOWS\SYSTEM32\OPNMJBRS.DLL
               C:\WINDOWS\SYSTEM32\EFCAQGXQ.DLL
               C:\WINDOWS\SYSTEM32\EFCAQGXQ.DLL
               HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A1272A-D84B-4F25-B822-8A4C965FC77A}
               HKCR\CLSID\{35A1272A-D84B-4F25-B822-8A4C965FC77A}
               HKCR\CLSID\{35A1272A-D84B-4F25-B822-8A4C965FC77A}\InprocServer32
               HKCR\CLSID\{35A1272A-D84B-4F25-B822-8A4C965FC77A}\InprocServer32#ThreadingModel
               HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DA2E0515-F0D5-4773-8191-400CCD50783B}
               HKCR\CLSID\{DA2E0515-F0D5-4773-8191-400CCD50783B}
               HKCR\CLSID\{DA2E0515-F0D5-4773-8191-400CCD50783B}\InprocServer32
               HKCR\CLSID\{DA2E0515-F0D5-4773-8191-400CCD50783B}\InprocServer32#ThreadingModel
               HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{DA2E0515-F0D5-4773-8191-400CCD50783B}
               Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\opnmJBrs
               C:\WINDOWS\SYSTEM32\CQLBEPXF.DLL
               C:\WINDOWS\SYSTEM32\PKRQPRBC.DLL
               C:\WINDOWS\SYSTEM32\QOMCCCRQ.DLL

            Trojan.Csrssc/Systemc-B
               C:\DOCUME~1\GILBER~1\LOCALS~1\TEMP\CSRSSC.EXE
               C:\DOCUME~1\GILBER~1\LOCALS~1\TEMP\CSRSSC.EXE
               [Jnskdfmf9eldfd] C:\DOCUME~1\GILBER~1\LOCALS~1\TEMP\CSRSSC.EXE
               C:\DOCUMENTS AND SETTINGS\GILBERT MONTEVERDE\LOCAL SETTINGS\TEMP\CSRSSC.EXE

            Adware.Vundo Variant
               HKLM\Software\Classes\CLSID\{C5BF49A2-94F3-42BD-F434-3604812C897D}
               HKCR\CLSID\{C5BF49A2-94F3-42BD-F434-3604812C897D}
               HKCR\CLSID\{C5BF49A2-94F3-42BD-F434-3604812C897D}
               HKCR\CLSID\{C5BF49A2-94F3-42BD-F434-3604812C897D}#ThreadingModel
               HKCR\CLSID\{C5BF49A2-94F3-42BD-F434-3604812C897D}\InProcServer32
               HKCR\CLSID\{C5BF49A2-94F3-42BD-F434-3604812C897D}\InProcServer32#ThreadingModel
               C:\WINDOWS\SYSTEM32\GKS834T.DLL
               HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C5BF49A2-94F3-42BD-F434-3604812C897D}
               HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler#{C5BF49A2-94F3-42BD-F434-3604812C897D}

            Adware.Tracking Cookie
               C:\Documents and Settings\Gilbert Monteverde\Cookies\[email protected][3].txt
               C:\Documents and Settings\Gilbert Monteverde\Cookies\[email protected][2].txt

            Trojan.Unknown Origin
               HKLM\SOFTWARE\Microsoft\MSSMGR
               HKLM\SOFTWARE\Microsoft\MSSMGR#Data
               HKLM\SOFTWARE\Microsoft\MSSMGR#LSTV
               HKLM\SOFTWARE\Microsoft\MSSMGR#Brnd
               HKLM\SOFTWARE\Microsoft\MSSMGR#MSLIST
               HKLM\SOFTWARE\Microsoft\MSSMGR#PID
               HKLM\SOFTWARE\Microsoft\MSSMGR#Rid
               HKLM\SOFTWARE\Microsoft\MSSMGR#BSTV
               HKLM\SOFTWARE\Microsoft\MSSMGR#SSTV
               HKLM\SOFTWARE\Microsoft\MSSMGR#SCLIST
               HKLM\SOFTWARE\Microsoft\MSSMGR#SSLIST
               HKLM\SOFTWARE\Microsoft\MSSMGR#BPTV
               HKLM\SOFTWARE\Microsoft\MSSMGR#PSTV

            Adware.Vundo Variant/Rel
               HKLM\SOFTWARE\Microsoft\aoprndtws
               HKLM\SOFTWARE\Microsoft\FCOVM
               HKLM\SOFTWARE\Microsoft\RemoveRP
               HKU\S-1-5-21-440832953-1699228844-671890266-1006\Software\Microsoft\rdfa
               C:\WINDOWS\SYSTEM32\MCRH.TMP

            Trojan.Unclassified/K-Series
               HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON#SYSTEM
            Below is the Malwarebytes' Anti-Malware log. Afterthis scan and the removal/quarantine of infected items I was told I need to restart my computer. I restarted my computer and as it began to turn off I once again went into a blue screen that displayed the following message again.
            Quote
            TOP: C000021 a {Fatal System Error}
            The windows logon process terminated unexpectedly with a status o
            0x00000000 (0x00000000 0x00000000)
            The system has been shut down
            Quote
            Malwarebytes' Anti-Malware 1.28
            Database version: 1196
            Windows 5.1.2600 Service Pack 3

            9/22/2008 9:39:10 PM
            mbam-log-2008-09-22 (21-39-10).txt

            Scan type: Quick Scan
            Objects scanned: 68935
            Time elapsed: 6 minute(s), 44 second(s)

            Memory Processes Infected: 1
            Memory Modules Infected: 6
            Registry Keys Infected: 34
            Registry Values Infected: 8
            Registry Data Items Infected: 4
            Folders Infected: 0
            Files Infected: 25

            Memory Processes Infected:
            C:\WINDOWS\system32\rs32net.exe (Trojan.Dropper) -> Unloaded process successfully.

            Memory Modules Infected:
            C:\WINDOWS\system32\efcAQGXq.dll (Trojan.Vundo.H) -> Delete on reboot.
            C:\WINDOWS\system32\jwoafgsk.dll (Trojan.Vundo.H) -> Delete on reboot.
            C:\WINDOWS\system32\gks834t.dll (Trojan.BHO) -> Delete on reboot.
            C:\WINDOWS\system32\opnmJBrs.dll (Trojan.Vundo) -> Delete on reboot.
            C:\WINDOWS\system32\zdzljn.dll (Trojan.Vundo) -> Delete on reboot.
            C:\WINDOWS\system32\wincqt32.dll (Trojan.Downloader) -> Delete on reboot.

            Registry Keys Infected:
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a5ef5221-033d-4dcb-8dab-71613ae2a233} (Trojan.Vundo.H) -> Delete on reboot.
            HKEY_CLASSES_ROOT\CLSID\{a5ef5221-033d-4dcb-8dab-71613ae2a233} (Trojan.Vundo.H) -> Delete on reboot.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{da2e0515-f0d5-4773-8191-400ccd50783b} (Trojan.Vundo.H) -> Delete on reboot.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\opnmjbrs (Trojan.Vundo.H) -> Delete on reboot.
            HKEY_CLASSES_ROOT\CLSID\{da2e0515-f0d5-4773-8191-400ccd50783b} (Trojan.Vundo.H) -> Delete on reboot.
            HKEY_CLASSES_ROOT\cpbrkpie.coupon6ctrl.1 (Adware.Coupons) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\c:/windows/cpbrkpie.ocx (Adware.Coupons) -> Quarantined and deleted successfully.
            HKEY_CLASSES_ROOT\TypeLib\{87255c51-cd7d-4506-b9ad-97606daf53f3} (Adware.Coupons) -> Quarantined and deleted successfully.
            HKEY_CLASSES_ROOT\Interface\{6e780f0b-bcd6-40cb-b2db-7af47ab4d4a4} (Adware.Coupons) -> Quarantined and deleted successfully.
            HKEY_CLASSES_ROOT\Interface\{a138be8b-f051-4802-9a3f-a750a6d862d4} (Adware.Coupons) -> Quarantined and deleted successfully.
            HKEY_CLASSES_ROOT\CLSID\{9522b3fb-7a2b-4646-8af6-36e7f593073c} (Adware.Coupons) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{9522b3fb-7a2b-4646-8af6-36e7f593073c} (Adware.Coupons) -> Quarantined and deleted successfully.
            HKEY_CLASSES_ROOT\CLSID\{a85a5e6a-de2c-4f4e-99dc-f469df5a0eec} (Adware.Coupons) -> Quarantined and deleted successfully.
            HKEY_CLASSES_ROOT\CLSID\{87255c51-cd7d-4506-b9ad-97606daf53f3} (Adware.Coupons) -> Quarantined and deleted successfully.
            HKEY_CLASSES_ROOT\CLSID\{70004d5d-3bf6-4d51-43b2-02fc0002cdb5} (Rogue.Errorsafe) -> Quarantined and deleted successfully.
            HKEY_CLASSES_ROOT\CLSID\{c5bf49a2-94f3-42bd-f434-3604812c897d} (Trojan.BHO) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c5bf49a2-94f3-42bd-f434-3604812c897d} (Trojan.BHO) -> Quarantined and deleted successfully.
            HKEY_CLASSES_ROOT\AppID\{8d71eeb8-a1a7-4733-8fa2-1cac015c967d} (Adware.BHO) -> Quarantined and deleted successfully.
            HKEY_CLASSES_ROOT\CLSID\{1333c33e-965c-4dc6-886a-4dba7621274a} (Trojan.Vundo) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Error Nuker (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wincqt32 (Dialer) -> Quarantined and deleted successfully.
            HKEY_CLASSES_ROOT\AppID\Sidebar.DLL (Adware.BHO) -> Quarantined and deleted successfully.
            HKEY_CURRENT_USER\SOFTWARE\Microsoft\AdvRemoteDbg (Adware.Agent) -> Quarantined and deleted successfully.
            HKEY_CURRENT_USER\SOFTWARE\MediaHoldings (Adware.PlayMP3Z) -> Quarantined and deleted successfully.
            HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
            HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSMGR (Trojan.Downloader) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully.

            Registry Values Infected:
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\2887fbbd (Trojan.Vundo.H) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rs32net (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\cpbrkpie.ocx (Adware.Coupons) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{c5bf49a2-94f3-42bd-f434-3604812c897d} (Trojan.BHO) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{da2e0515-f0d5-4773-8191-400ccd50783b} (Trojan.Vundo) -> Delete on reboot.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Error Nuker (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bm2bb4c821 (Trojan.Agent) -> Delete on reboot.
            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Jnskdfmf9eldfd (Trojan.Downloader) -> Quarantined and deleted successfully.

            Registry Data Items Infected:
            HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\efcaqgxq -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\System (Rootkit.DNSChanger.H) -> Data: kdzqt.exe -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\efcaqgxq  -> Delete on reboot.
            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

            Folders Infected:
            (No malicious items detected)

            Files Infected:
            C:\WINDOWS\system32\efcAQGXq.dll (Trojan.Vundo.H) -> Delete on reboot.
            C:\WINDOWS\system32\qXGQAcfe.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
            C:\WINDOWS\system32\qXGQAcfe.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
            C:\WINDOWS\system32\opnmJBrs.dll (Trojan.Vundo.H) -> Delete on reboot.
            C:\WINDOWS\system32\jwoafgsk.dll (Trojan.Vundo.H) -> Delete on reboot.
            C:\WINDOWS\system32\ksgfaowj.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
            C:\WINDOWS\system32\kdzqt.exe (Rootkit.DNSChanger.H) -> Quarantined and deleted successfully.
            C:\WINDOWS\system32\rs32net.exe (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
            C:\WINDOWS\cpbrkpie.ocx (Adware.Coupons) -> Quarantined and deleted successfully.
            C:\WINDOWS\system32\gks834t.dll (Trojan.BHO) -> Delete on reboot.
            C:\WINDOWS\system32\nntfxe.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
            C:\WINDOWS\system32\qoMccCrQ.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
            C:\WINDOWS\system32\WhoisCL.exe (Adware.BHO) -> Quarantined and deleted successfully.
            C:\WINDOWS\system32\cqlbepxf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
            C:\WINDOWS\system32\pkrqprbc.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
            C:\WINDOWS\system32\zdzljn.dll (Trojan.Vundo) -> Delete on reboot.
            C:\WINDOWS\system32\wincqt32.dll (Dialer) -> Delete on reboot.
            C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
            C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
            C:\ybwnngu.exe (Trojan.Agent) -> Quarantined and deleted successfully.
            C:\WINDOWS\system32\ynuvssnp.dll (Trojan.Agent) -> Delete on reboot.
            C:\Documents and Settings\Gilbert Monteverde\Local Settings\Temp\csrssc.exe (Trojan.Downloader) -> Delete on reboot.
            C:\WINDOWS\pskt.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
            C:\WINDOWS\BM2bb4c821.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
            C:\WINDOWS\BM2bb4c821.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
            What about the other log from HJT?Here is the log from HijackThis Quote
            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 10:28:27 PM, on 9/22/2008
            Platform: Windows XP SP3 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16705)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\PRISMSVR.EXE
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
            C:\WINDOWS\system32\bgsvcgen.exe
            C:\WINDOWS\ehome\ehtray.exe
            C:\Program Files\Bonjour\mDNSResponder.exe
            C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
            C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            C:\WINDOWS\eHome\ehRecvr.exe
            C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
            C:\WINDOWS\System32\DLA\DLACTRLW.EXE
            C:\Program Files\Dell\Media Experience\DMXLauncher.exe
            C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
            C:\PROGRA~1\Yahoo!\YOP\yop.exe
            C:\Program Files\Common Files\Symantec Shared\ccApp.exe
            C:\WINDOWS\eHome\ehSched.exe
            C:\PROGRA~1\Yahoo!\browser\ycommon.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
            C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
            C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
            C:\WINDOWS\stsystra.exe
            C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
            C:\Program Files\QuickTime\QTTask.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
            C:\Program Files\Windows Media Player\WMPNSCFG.exe
            C:\Program Files\Digital Line Detect\DLG.exe
            C:\WINDOWS\system32\PRISMSVC.EXE
            C:\WINDOWS\ehome\RMSysTry.exe
            C:\WINDOWS\ehome\RMSvc.exe
            C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
            C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Dell Wireless\PRISMCFG.exe
            C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
            C:\Program Files\Yahoo!\browser\ybrowser.exe
            C:\WINDOWS\system32\dlcccoms.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\WINDOWS\system32\dllhost.exe
            C:\PROGRA~1\Yahoo!\YOP\SSDK02.exe
            C:\WINDOWS\eHome\ehmsas.exe
            C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
            R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
            R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
            O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
            O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
            O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
            O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
            O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
            O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
            O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
            O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
            O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
            O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
            O4 - HKLM\..\Run: [osCheck] "C:\PROGRA~1\Symantec\osCheck.exe"
            O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
            O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
            O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
            O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
            O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,[email protected]
            O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
            O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
            O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart
            O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
            O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
            O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
            O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe
            O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
            O4 - Global Startup: WG111v2 Smart Wizard Wireless Setting.lnk = ?
            O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk = ?
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
            O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
            O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
            O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
            O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O15 - TRUSTED Zone: http://www.bungie.net
            O15 - Trusted Zone: www.halo3forum.com
            O16 - DPF: {15589FA1-C456-11CE-BF01-000000000000} - http://www.errornuker.com/products/errn2004/installers/default/ErrorNukerInstaller.exe
            O16 - DPF: {22E5D91F-89E6-4405-AD9C-0AF27BA6F06B} (HidInputMonitorX Control) - file://D:\components\hidinputmonitorx.ocx
            O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
            O16 - DPF: {4F63D44B-6274-4D60-8AB1-CAA7116B8AF3} (A9Helper.A9) - file://D:\components\A9.ocx
            O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1179881876116
            O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
            O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1219717321296
            O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
            O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://spdarkkiller.spaces.live.com/PhotoUpload/MsnPUpld.cab
            O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
            O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
            O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://games.myspace.com/Gameshell/GameHost/1.0/OberonGameHost.cab
            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
            O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.dellfix.com/rel/41/install/gtdownde.cab
            O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
            O20 - AppInit_DLLs: zdzljn.dll
            O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
            O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
            O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
            O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
            O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
            O23 - Service: dlcc_device -   - C:\WINDOWS\system32\dlcccoms.exe
            O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
            O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
            O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
            O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\PROGRA~1\Symantec\isPwdSvc.exe
            O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
            O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
            O23 - Service: PRISMSVC - Conexant Systems, Inc. - C:\WINDOWS\system32\PRISMSVC.EXE
            O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
            O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
            O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
            O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

            --
            End of file - 14733 bytes
            Looks fine but we should do an online scan just to be SURE. That was a large amount of malware and some could still be hiding.

            Run this online scan. Requires Internet Explorer

            Use the ESET Nod32 Online Scanner

            1. Check the box next to YES, I accept the Terms of Use.
            2. Click Start
            3. When asked, allow the activex control to install
            4. Click Start
            5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked.
            6. Click Scan
            7. Wait for the scan to finish
            8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
            9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.Here is the log of the Scan Quote
            # version=4
            # OnlineScanner.ocx=1.0.0.635
            # OnlineScannerDLLA.dll=1, 0, 0, 79
            # OnlineScannerDLLW.dll=1, 0, 0, 78
            # OnlineScannerUninstaller.exe=1, 0, 0, 49
            # vers_standard_module=3462 (20080923)
            # vers_arch_module=1.064 (20080214)
            # vers_adv_heur_module=1.066 (20070917)
            # EOSSerial=193d12a3ecf8d5439bc45486b6d70e0d
            # end=finished
            # remove_checked=true
            # unwanted_checked=true
            # utc_time=2008-09-23 08:11:20
            # local_time=2008-09-23 01:11:20 (-0800, Pacific Daylight Time)
            # country="United States"
            # osver=5.1.2600 NT Service Pack 3
            # scanned=557063
            # found=2
            # scan_time=8302
            C:\Documents and Settings\Gilbert Monteverde\Shared\i wanna riot capdown.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan (unable to clean - deleted)   00000000000000000000000000000000
            C:\WINDOWS\Downloaded Program Files\gsda.dll   Win32/TrojanDownloader.SpyGame.A trojan (unable to clean - deleted)   00000000000000000000000000000000
            Next: Set a New Restore Point to prevent possible reinfection from an old one.

            Please go to: Start -> All Programs -> Accessories -> System Tools -> System Restore -> System Restore Settings
            Click to add a check mark beside Turn off System Restore and click Apply
            When you are warned that all existing Restore Points will be deleted, click Yes to continue and wait a few moments to let System Restore clear.
            Uncheck "Turn off System Restore"
            Click "Apply," and then click "OK".

            ----------

            Use the Secunia Software Inspector to check for out of date software.
            Click Start Now
            Check the box next to Enable thorough system inspection.
            Click Start
            Allow the scan to finish and scroll down to see if any updates are needed.
            Update anything listed.

            ----------

            SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running MOZILLA based browsers like Firefox.
            * Using SpywareBlaster to protect your computer from Spyware and Malware

            To prevent unknown applications from being installed on your computer install WinPatrol 2008
            * Using Winpatrol to protect your computer from malicious software

            I would suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and Spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

            Learn more about how to protect yourself while on the Internet from the following link. So how did I get infected in the first place? by Tony Klien. When i start my computer it acts like its going to load and then this fatel systen error comes up that says!!!!  STOP: c000021a The session manager Initialization system process Terminated unexpectedly with a status of 0xooooo3a...{0xoooooooo-0xoooooooo}. THE SYSTEM HAS BEEN SHUT DOWN. but also right before that message pops up a screen apears that says {auto check program not found. Skip auto check. then it goes to the fatel system error. If you could help me in any way it would be greatly appriciated. thank you so much laura
            Laura,

            you might want to start you own postLesson learn, its better to equipped myself with good anti virus for better protection against malicious program. Any recommendations? I'm using Kasperzky right now
            Quote from: irvine25 on February 05, 2009, 04:51:00 AM
            Lesson learn, its better to equipped myself with good anti virus for better protection against malicious program. Any recommendations? I'm using Kasperzky right now

            This user has Nortan.

            - Free antivirus software. Remember to install only ONE!
            • Avast! Antivirus - Resident (Realtime) Protection, Instant Messaging, P2P shield, Internet Mail, and more.
            • Avira Antivirus - Protects your computer against dangerous viruses, worms, trojans and costly dialers.
            • AVG Antivirus - Basic antivirus and antispyware protection for Windows.
            987.

            Solve : I keep getting sysxd.exe error?

            Answer»

            So this only pops up periodically and I have been waiting for like half an hour but it won't COME back up so I can reproduce it but I have seen others on the forum with it.

            I tried some of the steps from the other posts and I have logs. Can someone please let me know if there is some crazy infection going on? I am having trouble using the internet so I am running the steps on my laptop in safe mode and saving the files/logs to my flash drive and posting here. I also have to save any installations to the flash drive and OPEN them on the laptop and copy them to the desktop there.

            I have Windows XP SP2

            Thanks

            Cris

            [attachment deleted by admin]I figured i should add all of this INFORMATION:

            What operating system are you using? Windows XP SP2

            If you're getting an error what is the error message?
            Basic details on your computer, MANUFACTURER: IBM Thinkpad T60 2GB Ram


            When did the issue start occurring? Did you recently install a program, new hardware device, or visit a web page? the issue started occuring about 2 weeks ago. I was getting an error about a rafki.b (or something like that) but found out it was a fake error. I followed the instructions Here http://deathwaltz.blogspot.com/2009/01/fake-security-center-alert-win32zafib.html and that FIXED the initial errors but I am still a little cautious about how my laptop is performing.

            Please help. Thanks

            988.

            Solve : Malware infected. Need help?

            Answer»

            Hi experts,

            I need help to get rid of a malware infection.  It affected my MOTHER's notebook, and once she noticed something was wrong and handled the computer to me, the infection was ALREADY pretty bad. I attached logs from SuperAntiSpyware, Mbam and Hijackthis.

            It has AVG 8 installed, and it's updated. It reports threats every boot and during computer use. I disabled the anti-virus while running SuperAntiSpyware, mbam and hijackthis. SuperAntiSpyware could report lots of infections, but crashed while cleaning the computer (the computer restarted without any prompt).

            At the "Add or Remove programs" screen there some softwares that she claimed she did not install. They are ESPNMotion (0.27mb), Mah Jong Quest (13.17mb), Otto (no size available), Penguins (36mb), POLAR Bowler (13.73mb), Polar Golfer (14.12MB), Scrabble (14.78mb), SD Secure MODULE (0.05mb).

            At the DEVICE Manager, under non-plug and play drivers, there's a driver called catchme, that I found at a site that could be a malware.

            [attachment deleted by admin]download , malwarebytes anti-malware and add the log

            and let an expert look at them

            989.

            Solve : Panda Active Scan Reads Adware, Hacktools and Trojan?

            Answer»

            Have you tried uninstalling HomeKey?  If so, what happened?  If you have trouble, you can take a look at this page:
            http://www.spywaredb.com/remove-home-key-logger

            See if you can uninstall it and then try the following steps...
            Download ComboFix by sUBs from one of the below links.  Be sure to save it to the Desktop.

            http://download.bleepingcomputer.com/sUBs/ComboFix.exe
            http://subs.geekstogo.com/ComboFix.exe

            Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix.

            Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

            Double-click combofix.exe and follow the prompts.
            When finished, ComboFix will produce a log for you.
            Post the ComboFix log and a new HijackThis log in your next reply.

            NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

            Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.Combofix is attached...to big to post.

            Hijack this:
            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 1:49:29 AM, on 1/25/2009
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v8.00 (8.00.6001.18241)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Atomic Alarm Clock\AtomicAlarmClock.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
            C:\Program Files\Java\jre6\bin\jqs.exe
            C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\Pen_Tablet.exe
            C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
            C:\WINDOWS\system32\Pen_Tablet.exe
            C:\PROGRA~1\AVG\AVG8\avgrsx.exe
            C:\PROGRA~1\AVG\AVG8\avgemc.exe
            C:\Documents and Settings\Sylverkitti\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
            C:\Program Files\HomeKey\KeyLogger.exe
            C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
            C:\WINDOWS\system32\lxcgcoms.exe
            C:\Program Files\Common Files\Real\Update_OB\realsched.exe
            C:\Program Files\PicPick\picpick.exe
            C:\WINDOWS\system32\notepad.exe
            C:\WINDOWS\explorer.exe
            C:\Program Files\AVG\AVG8\avgtray.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Program Files\Trend Micro\sniper.exe\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.ocwencustomers.com/home.cfm
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
            N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_2/home.html"); (C:\Documents and Settings\SYLVERKITTI\Application Data\Mozilla\Profiles\default\n77ayi80.slt\prefs.js)
            N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\SYLVERKITTI\Application Data\Mozilla\Profiles\default\n77ayi80.slt\prefs.js)
            O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
            O2 - BHO: Adobe PDF READER Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
            O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
            O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
            O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
            O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
            O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,[email protected]
            O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [SkinClock] C:\Program Files\Atomic Alarm Clock\AtomicAlarmClock.exe
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.dell.com/systemprofiler/SysPro.CAB
            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
            O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
            O17 - HKLM\System\CCS\Services\Tcpip\..\{F1AC1131-1A94-4922-82BE-EC2D80A6CCA7}: NameServer = 205.171.3.65,205.171.2.65
            O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
            O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
            O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
            O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
            O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
            O23 - Service: FLEXnet LICENSING Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
            O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
            O23 - Service: Jesuk Service (JesukSrv) - Unknown owner - C:\WINDOWS\system32\jesuk.exe (file missing)
            O23 - Service: lxcg_device -   - C:\WINDOWS\system32\lxcgcoms.exe
            O23 - Service: Mocugyk Service (MocugykSrv) - Unknown owner - C:\WINDOWS\system32\mocugyk.exe (file missing)
            O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
            O23 - Service: SupportSoft RemoteAssist - Unknown owner - C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe (file missing)
            O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\WINDOWS\system32\Pen_Tablet.exe

            --
            End of file - 8276 bytes


            [attachment deleted by admin]Open up HijackThis and run another scan without saving a log file.  When your results are displayed, place checkmarks next to these entries...

            O23 - Service: Jesuk Service (JesukSrv) - Unknown owner - C:\WINDOWS\system32\jesuk.exe (file missing)

            O23 - Service: Mocugyk Service (MocugykSrv) - Unknown owner - C:\WINDOWS\system32\mocugyk.exe (file missing)


            Close all other windows and click on Fix Checked.  Close HijackThis.

            How is your computer running now?  Are you still experiencing any of the same issues as before?It seems ok...when I click links that lead to emailing someone it still is odd, before it wouldn't take me at all to the email...now it does but it has mailto: in front of it for some reason...like it forgets to just put in the email and puts everything in....other than that so far so GOOD.
            That could be an issue with certain sites or with the e-mail client you're using.  What do you use for e-mail?  Perhaps there's a setting that can be changed.I use Yahell...I mean yahoo for everything...I am pretty sure I didn't change anything, I don't think i would know how to change something like that, but it may have been an accident? Do they even have those kind of options?To be honest, I don't really know.  I haven't used Yahoo in years, so I have no idea how much things have changed with them.  It may be worthwhile to get ahold of their Customer Care...
            http://help.yahoo.com/l/us/yahoo/mail/original/forms_index.html

            Or you could perhaps try the Other or Browser section of our forum.  Unfortunately, I don't e-mail much, so I'm not as well-versed in the subject.  My knowledge here is pretty much limited to Microsoft Office Outlook and AOL.Its ok...its something I can live with.  I really appreciate all the help you have offered me...without you guys where would we all be?? I'm sure I'll be back with another problem in the future...thanks!!I'm GLAD I've been able to help somewhat.  I'd hate for you to have more problems, but if you do, we'll be here.  I just wish I could give you more help with the e-mail issue.  Just for the heck of it, you might want to try testing a different e-mail client such as Hotmail to see if the same thing happens with them.

            990.

            Solve : My computer turns completely off if idle for maybe 20 minutes?

            Answer»

            This never happened before.  What would cause this to happen?Make? Model? OS?  Hi Eg0Death,

            It's a Compaq Presario with Windows XPWhat are your power settings?

            Start -> CONTROL Panel -> Power Options

            A setting may have been CHANGED to power down the system after 20 minutes of inactivity. These are the settings:

            System standby:  After 20 mins

            System HIBERNATES:  After 25 mins

            I've never changed these settings and I've had the computer for hours and it never shut off.  Would one of these settings completely shut down the computer?Hibernate saves the contents of RAM to a file on the HARD drive (hiberfil.sys, I think) and shuts down the computer.  I'm not SURE why it wasn't working before.   Thanks for your help.  I'll change the settings.

            991.

            Solve : is ther any thing wrong with my system??

            Answer»

            hi, good day... 

            is there any thing in  my system?




            [Saving space - attachment deleted by ADMIN]You had a couple of minor infections, but it looks like the scans took care of them.  I'd say everything looks clean.  You need a firewall, however.  You're vulnerable without a firewall, so you should look into getting either ZoneAlarm, Kerio PERSONAL Firewall, or Comodo.  They're all good free firewalls.  Just be sure you only have one installed at a time!  DOWNLOAD the firewall of your CHOICE, disconnect from the internet, disable Windows Firewall, and install your new firewall.


            Also, I see that you don't have Java installed.  You'll want to correct this quickly, as it will help provide further protection for you.  To do so, go here and click on Free Java Download.  You will be given instructions on what to do next.thaks a lot for those things....
             You're welcome.  Come back anytime.

            992.

            Solve : avast!?

            Answer»

            Hey, everyone I have a question. I'm running Windows XP, and I have use avast! 4.7 for my antivirus software. I haven't had any problems with VIRUSES since I switched from MCAFEE. I was just wondering, how GOOD is avast! at keeping viruses out and detecting them in scans? And how is the spyware protection, if there is any at all?Avast! is very reliable for protection.

            It has no real time spyware protection.

            For real time spyware protection check out:

            WinPatrel 2007

            Comodo BOClean

            SpywareBlaster
            You have to manually update SpywareBlaster. Usually check weekly.

            Although they have PAID for versions, the FREE ones work just as well.



            993.

            Solve : Spyware & Viruses, Trying to clean out, Can you help please. :-)?

            Answer»

            My apology for not providing all of the scan results that I should have included with my first post as requested by your forum. This is what has been going on with this computer....
            I have some folders in the startup menu that I can not rid of. One is ad rundll32.exe"C\Win Hklm\Software\Microsoft\Windows\Current Ver and the other is NvCpl RUNDLL32.exe"C\Win Hklm\Software\Microsoft\Windows\Current Ver and keep getting the small Dll pop up windows here and there with the top of the window saying RUNDLL with an option to click ok. I never click on the ok but will end it with the task mananger. I have already run Malwarebytes and downloaded a 30 day trial of Kaspersky. Ran a new scan with Malwarebytes yesterday with no findings as well as Kaspersky. Allot has been cleaned out so far with both programs but these files still remain causing the rundll pop ups. Here are the results from my Hijack log, super anti spyware as well as a new Hijack log. Your help would be greatly appreciated. I already do see these two items in the Hijack Report (04 section) but am not sure if there is anything else within this log that needs to be fixed. Your help would be soooo appreciated. I need to get this computer back to the owner. (Helping a friend is all)

             SUPERAntiSpyware Scan Log
            http://www.superantispyware.com

            Generated 10/26/2008 at 05:28 PM

            Application Version : 4.21.1004

            Core Rules Database Version : 3609
            Trace Rules Database Version: 1595

            Scan type       : Complete Scan
            Total Scan Time : 01:21:40

            Memory items scanned      : 402
            Memory threats detected   : 0
            Registry items scanned    : 5539
            Registry threats detected : 4
            File items scanned        : 114235
            File threats detected     : 111

            Adware.Tracking Cookie
               C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][3].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][2].txt
               C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\[email protected][1].txt

            Unclassified.Unknown Origin
               HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run#userinit [ C:\WINDOWS\system32\ntos.exe ]
               HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run#userinit [ C:\WINDOWS\system32\ntos.exe ]

            Rootkit.Unclassified/SysDamp-Traces
               HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Reserved
               HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\System Reserved

            Adware.ClickSpring/Yazzle
               C:\WINDOWS\PREFETCH\YAZZLE1552OINADMIN.EXE-01D813FF.PF

            Trojan.Fake-Drop/Gen
               C:\WINDOWS\TEMP\SALM.EXE


            Malwarebytes' Anti-Malware 1.30
            Database version: 1324
            Windows 5.1.2600 Service Pack 2

            10/26/2008 3:17:53 PM
            mbam-log-2008-10-26 (15-17-53).txt

            Scan type: Full Scan (C:\|D:\|)
            Objects scanned: 156431
            Time elapsed: 1 hour(s), 33 minute(s), 44 second(s)

            Memory Processes Infected: 0
            Memory Modules Infected: 0
            Registry Keys Infected: 0
            Registry Values Infected: 0
            Registry Data Items Infected: 0
            Folders Infected: 0
            Files Infected: 0

            Memory Processes Infected:
            (No malicious items detected)

            Memory Modules Infected:
            (No malicious items detected)

            Registry Keys Infected:
            (No malicious items detected)

            Registry Values Infected:
            (No malicious items detected)

            Registry Data Items Infected:
            (No malicious items detected)

            Folders Infected:
            (No malicious items detected)

            Files Infected:
            (No malicious items detected)


            Hijack log to follow in next post.... If included in this post it exceeds 20000 charaters.

            Thank you in ADVANCE.   

            Hijack Log....

            Logfile of Trend Micro HijackThis v2.0.2
            Scan SAVED at 10:07:05 AM, on 10/27/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16735)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
            C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
            C:\Program Files\Java\jre6\bin\jqs.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Maxtor\Sync\SyncServices.exe
            C:\WINDOWS\system32\nvsvc32.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
            C:\WINDOWS\system32\rundll32.exe
            C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\WINDOWS\system32\notepad.exe
            C:\WINDOWS\system32\NOTEPAD.EXE
            C:\WINDOWS\system32\NOTEPAD.EXE
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PRESARIO&pf=desktop
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=63&bd=PRESARIO&pf=desktop
            R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=63&bd=PRESARIO&pf=desktop
            R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
            R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
            O2 - BHO: (no name) - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - (no file)
            O2 - BHO: (no name) - {33B78DC8-D66F-D1D4-BA4E-C7D46429A466} - (no file)
            O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
            O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
            O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
            O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
            O4 - HKLM\..\Run: [cdcb6378] rundll32.exe "C:\WINDOWS\ad.dll",e
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKUS\S-1-5-18\..\Run: [[system]]  (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [[system]]  (User 'Default user')
            O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
            O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
            O8 - Extra context menu item: ADD to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
            O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
            O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
            O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - http://h30155.www3.hp.com/ediags/dd/install/guidedsolutions.cab
            O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
            O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
            O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
            O20 - Winlogon Notify: dddaebdedeeaa - C:\WINDOWS\system32\dddaebdedeeaa.dll (file missing)
            O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
            O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
            O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
            O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

            --
            End of file - 7401 bytesOnce we start, you won't have access to this post anymore, so I recommend that you print out this post or save it to a Notepad file.  Open HijackThis and scan again.  Check the following entries, but don't do anything to them yet...

            R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
            O2 - BHO: (no name) - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - (no file)
            O2 - BHO: (no name) - {33B78DC8-D66F-D1D4-BA4E-C7D46429A466} - (no file)

            O4 - HKUS\S-1-5-18\..\Run: [[system]] (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [[system]] (User 'Default user')

            O20 - Winlogon Notify: dddaebdedeeaa - C:\WINDOWS\system32\dddaebdedeeaa.dll (file missing)


            Now, close all windows (including this one) besides HijackThis, then click Fix Checked.  Close HijackThis.

            Go to Start > Settings > Control Panel > Add/REMOVE Programs and remove the following (if present)...

            AskBar or Ask.com Toolbar

            Please note any other programs that you dont recognize in that list in your next response.

            Download ComboFix and save it to your desktop.  Run the program and read its disclaimer (it's fairly short) and make sure you really pay attention to what it says.  Follow the prompts and when finished, it will produce a log at C:\ComboFix.txt.  Go ahead and post that here along with a new HijackThis logNote: Don't click on the window while it's running; this may cause stalls.

            994.

            Solve : Help with system32 in a way?

            Answer»

            Hello. Me and my friend are tying to see which one of us can get each OTHERS pw's first lol ik it is probably a stupid and childish thing to do but here is how it goes. We each get an hour a day on each others strictly limited guest ACCOUNT we are not allowed to USE the admin account on the comp. the point is to get the pw not mess with each others files.

            so far i have ESTABLISHED that i can make .bat files
            cmd.exe is blocked but command.com is not
             the "at" command is blocked

            My question is this
            I have copied my friends system32 to my flash drive. Is there a way to get his pw through the files i have obtained on my computer at my house? If so what programs would i need to use and is it possible to run such programs on his restricted account so i can do it on his comp? {btw i cant install or run certain software EX.  U3smart from my other flash drive)

            All help and advice is greatly appreciatedSorry.

            Even if this is a "fun" project and it's a challenge for you and your friend the info won't be found here.

            Didn't the hint after you wanted to hack a server make sense to you ? ?

            It's not what we do.

            Another TOPIC Closed.

            995.

            Solve : My HJT file as requested by evil fantasy?

            Answer»

            Here it is.  Thanks

            [getting disk space - attachment deleted by admin]Go to Start > Control Panel > Add/Remove Programs and remove the following (if they exist):
            VSAdd-in
            Viewpoint
            Viewpoint Manager
            Viewpoint Media Player

            =====

            If you do not use Windows MESSENGER, look for it in Add/Remove programs also and uninstall it.

            **This is not MSN Messenger

            If you do not see it in Add/Remove programs:
            1 SELECT "Start"
            2 Choose "Control Panel"
            3 Choose "Administrative Tools"
            ** note in Windows XP Home edition, Admistrative Tools is in Performance and Maintence
            4 Choose "SERVICES"
            5 Right-click on "Messenger"
            6 Select "Stop"
            To permanently disable Messenger:<---Preferred Method
            7 Right click "Messenger"
            8 Select "Properties"
            9 Change "Startup Type" to "Disabled" and click "OK"

            =====

            Open HijackThis and select "Do a system scan only"
            Place a check mark next to these entries:
            O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
            O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
            O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe<---If present
            O4 - HKLM\..\Run: [QuickTime TASK] "C:\Program Files\QuickTime\qttask.exe" -atboottime<---Unnecessary
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<---Unnecessary
            O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<---If present


            Close all windows except HijackThis and click "Fix checked"

            =====

            Next post:

            Tell me how everything went

            Post a new HijackThis log

            Tell me how things are now.

            996.

            Solve : pls check my laptop?

            Answer»

            here are the 3 logs,





            [Saving space - ATTACHMENT deleted by admin]Download ComboFix by sUBs to your Desktop.

            **Note:  It is important that ComboFix is saved directly to your Desktop

            Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

            Close any open Web browsers. (Firefox, INTERNET Explorer, etc) before starting ComboFix.

            Double click on ComboFix.exe & follow the prompts.

            As part of its process, ComboFix will check to see if the Microsoft Windows Recovery CONSOLE is installed. It is strongly recommended to have this pre-installed on your machine before doing any malware removal should your computer have a problem during the procedure.

            ** If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's NORMAL malware removal procedures and you will not see the Recovery Console Query.

            Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console. When prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.



            Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



            Click on Yes to continue scanning for malware.

            When finished ComboFix will produce a log for you in C:\combofix.txt
            Post the ComboFix log and a NEW HijackThis log in your next reply.

            Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

            Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

            997.

            Solve : Please help!Computer won't start in normal mode after Trojan's cleaned in Safe?

            Answer»

            Hi All,

            Desperate for help...

            I have a Thinkpad T60. Yesterday it's infected by Trojan. I followed Norton's advice. I disabled system recovery and went into safe mode to do a full scan using Kaspersky. Some file were deleted. But after that, the computer won't start in normal mode but safe mode only (without network).. In the blue screen, it asks to uninstall latest software or hardware.

            I removed the Kaspersky folder since I can't uninstall it in safe mode. But it STILL doesn't work..

            I followed the above topic and tried SDFix. It finished its job successfully and FOUND more infected FILES. But now I still can't start the computer in normal mode...

            Would you PLEASE help me out? I really don't want to reinstall the whole system...

            Thanks a million!Can you GET HijackThis on there so you can run a scan in Safe Mode?  Download it on another computer and transfer it via CD or flashdrive.  It's not much, but it may help give us a bit of insight.

            998.

            Solve : heres my HJT log as requested broni?

            Answer»

            Logfile of Trend MICRO HijackThis v2.0.2
            Scan SAVED at 10:15:05 AM, on 14/11/2007
            Platform: Windows Vista  (WinNT 6.00.1904)
            MSIE: Internet Explorer v7.00 (7.00.6000.16546)
            Boot mode: Normal

            Running processes:
            C:\Windows\system32\Dwm.exe
            C:\Windows\Explorer.EXE
            C:\Windows\RtHDVCpl.exe
            C:\Acer\Empowering Technology\SysMonitor.exe
            C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
            C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
            C:\Program Files\Common Files\Symantec Shared\ccApp.exe
            C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe
            C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe
            C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
            C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
            C:\Program Files\Lexmark 3400 Series\lxcymon.exe
            C:\Program Files\Lexmark 3400 Series\ezprint.exe
            C:\Windows\System32\hkcmd.exe
            C:\Windows\System32\igfxpers.exe
            C:\Windows\ehome\ehtray.exe
            C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
            C:\Windows\System32\mobsync.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\ehome\ehmsas.exe
            C:\Program Files\Intel\IntelDH\CCU\CCU_Engine.exe
            C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
            C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
            C:\Program Files\Internet Explorer\IEUser.exe
            C:\Program Files\Windows Media Player\wmplayer.exe
            C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Windows Mail\WinMail.exe
            C:\Windows\system32\igfxsrvc.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Program Files\MICROSOFT Office\Office12\WINWORD.EXE
            C:\Users\Radio Rentals\Desktop\HiJackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://portal.shafston.edu/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.us.acer.yahoo.com
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
            O1 - Hosts: ::1 localhost
            O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
            O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
            O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
            O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
            O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
            O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
            O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
            O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
            O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
            O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
            O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
            O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
            O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton Internet Security\osCheck.exe"
            O4 - HKLM\..\Run: [CCUTRAYICON] C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe
            O4 - HKLM\..\Run: [NMSSupport] "C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" /STARTUP
            O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
            O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
            O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
            O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
            O4 - HKLM\..\Run: [lxcymon.exe] "C:\Program Files\Lexmark 3400 Series\lxcymon.exe"
            O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 3400 Series\ezprint.exe"
            O4 - HKLM\..\Run: [LXCYCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\LXCYtime.dll,[email protected]
            O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
            O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
            O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
            O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
            O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_0
            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
            O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
            O4 - HKUS\S-1-5-18\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe (User 'Default user')
            O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
            O4 - Global Startup: Empowering Technology Launcher.lnk = ?
            O4 - Global Startup: PCM Media Sharing.lnk = C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
            O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
            O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
            O13 - Gopher Prefix:
            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
            O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
            O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
            O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
            O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
            O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
            O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
            O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
            O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
            O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
            O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
            O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
            O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
            O23 - Service: lxcy_device -   - C:\Windows\system32\lxcycoms.exe
            O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
            O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
            O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
            O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
            O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
            O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

            --
            End of file - 11993 bytes
            Let me take a look...Your HJT log is clean
            You may fix just one entry (cosmetic move):
            - O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

            Happy computing your a legend!!!! Please.....LOL

            999.

            Solve : What are spr.exe files? Is that a virus or worm??

            Answer»

            I have found several spr.exe FILES in my local settings, temp folder.  My computer performance is slower than it used to be, and I found these files in an ATTEMPT to clean up the C drive.

            I have Windows XP Home, it's a SONY VAIO computer. I have Norton Security.

            One of the SPR files is listed in a blue font, which I am assuming indicates it's a system file.

            Two of the SPR files show as file type application. One shows as a temp file.

            SPR.18F3.EXE  (BLUE FONT)

            SPR.196A.EXE  (BLACK FONT)

            SPR.196A.TEMP (BLACK FONT)

            How can I find out if these are bad files or what application they belong to?spr.exe are associated with plenty of malware/worms. It is hard to say for sure without some scans though.

            We can take a closer look.

            Download HijackThis  to your desktop.
            Double-click on the file you just downloaded.
            Click on the "Install" button to install.
            It will by default install to the directory - C:\Program Files\Trend Micro\HijackThis
            Please do not change the default install location.
            Upon install, HijackThis should open for you.

            Next click on the "Do a system scan and save a log file" button.
            HijackThis will scan and then a log will open in notepad.
            In the top left of the notepad window click "File" > "Save As" name it hijackthis and then save it to the Desktop.
            Please save the log as a text (.txt) file.
            In your post, add the log as an Attachment.

            * Don't have Hijackthis fix anything yet. Most of what it FINDS will be harmless or even required.
            ** Don't use the Analyse This button. It's findings are dangerous if misinterpreted.

            1000.

            Solve : firewall help!!!!?

            Answer»

            comodo is using a whole core! what should i do?? am i being hacked???it appears to be normal now must be the program i was installingUmm....What? never mind dont worry about itHeh, ok. Quote

            it appears to be normal now must be the program i was installing

            Why would you think you're being hacked?   CAUSE  it was using all of one coreSo?  Why ELSE is the processor there?i dont no The two cores are there to relieve stress. One core can focus on installing the program and the other core will manage everything else (background processes and PROGRAMS)Nicely stated, Carbon!

            This is what I was trying to GET you to realize, cr   ya but it was using the WHOLE core and inever saw it doing that before so i was just woried that mabye it needed more cpu to keep out a hacker or soemthing LIKE that or maybe your just paranoid?most likley