Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

3851.

Solve : VBS:Obfuscated-gen trj problem?

Answer»

Hello,

Today I opened my OPERA browser -which is my main browser-, and all of a sudden avast! said that this trojan (the Obfuscated-gen one) was trying to connect with my computer, and alerted me via a window, asking me if I wanted to stop the connection with the trojan. I ran Malwarebytes and it eliminated two entries from the registry called: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security CENTER\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.

Then I closed and tried opening Opera again, and again avast! alerted me of the trojan problem. Since I didn't know how to get rid of it, I looked for solutions on the Internet and I found this website. I went through all the steps, and after running CCleaner I can open Opera without problems. Nevertheless, I went through all the steps indicated just in case. Here I have the SuperAntispyware, Malwarebytes and HJT logs. I would like to know if my computer has eliminated the nuisance, and if there are no other trojans nor malware on it?

Thank you very much in advance.

[attachment deleted by admin]Download the Norton Removal Tool (SymNRT) to your desktop.

Once downloaded please close ALL open browsers, also save any work because this may require a restart.

* Go to your desktop and double click on the 'Norton_Removal_Tool' and then click Setup.
* Once open Click Next
* Accept the license agreement and click Next
* Type in the letters/numbers that you see into the text box then click Next.
* Then click Next and the tool will start running.
* Once finished restart the PC.
* Delete the 'Norton_Removal_Tool' from your desktop.[/list]

----------

Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop.

Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

* XP users Double click on dds to run it.
* If your antivirus or firewall try to block DDS then please allow it to run.
* When finished DDS will open two (2) logs.

1) DDS.txt
2) Attach.txt

* Save both logs to your desktop.
* Please copy and paste the entire contents of both logs in your next reply.

Note: DDS will instruct you to post the Attach.txt log as an attachment.
Please just post it as you would any other log by copy and pasting it into the reply.Thank you very much for your speedy answer, here are the two logs created by DDS. By the way, on a sidenote, my DVD drive in the CPU opened by itself some time after posting my problem. Might it be related to the trojan issue, or is it an isolated problem?

Here is the DDS log:


DDS (Ver_09-06-26.01) - NTFSx86
Run by HP_Administrateur at 22:55:14,93 on 05/07/2009
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_14
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.2046.1336 [GMT 2:00]

AV: avast! antivirus 4.8.1335 [VPS 090705-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\a-squared Free\a2service.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Wireless 802.11g Monitor\WLService.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\ehome\RMSvc.exe
C:\Program Files\Wireless 802.11g Monitor\WLanCfgG.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAEE.EXE
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Transcode360\Transcode360Tray.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\HP Wireless Keyboard\KMaestro.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
c:\windows\system\hpsysdrv.exe
C:\WINDOWS\ehome\RMSysTry.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\HP_Administrateur.NOM-FB9B15D2723\Bureau\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
mDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
mSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
mSearchAssistant = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Programme d'aide de l'Assistant de connexion Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\fichiers communs\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar2.dll
BHO: FDMIECookiesBHO Class: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - c:\program files\free download manager\iefdm2.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll
TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\Iaanotif.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
mRun: [DMAScheduler] "c:\program files\hp digitalmedia archive\DMAScheduler.exe"
mRun: [PCDrProfiler]
mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run
mRun: [EPSON Stylus DX4200 Series] c:\windows\system32\spool\drivers\w32x86\3\E_FATIAEE.EXE /P26 "EPSON Stylus DX4200 Series" /O6 "USB001" /M "Stylus DX4200"
mRun: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] c:\program files\google\gmail notifier\gnotify.exe
mRun: [transcode360] c:\program files\transcode360\Transcode360Tray.exe
mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [KBD] c:\hp\kbd\KBD.EXE
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
mRun: [BtcMaestro] "c:\program files\hp wireless keyboard\KMaestro.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\hp_adm~1.nom\menudm~1\progra~1\dmarra~1\openof~1.lnk - c:\program files\openoffice.org 2.4\program\quickstart.exe
StartupFolder: c:\docume~1\alluse~1\menudé~1\progra~1\démarr~1\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\docume~1\alluse~1\menudé~1\progra~1\démarr~1\monite~1.lnk - c:\windows\ehome\RMSysTry.exe
StartupFolder: c:\docume~1\alluse~1\menudé~1\progra~1\démarr~1\autoru~1\maximemo.lnk - c:\program files\maximemo\MaxiMemo.exe
IE: E&xportar a Microsoft Excel - c:\progra~1\micros~3\office10\EXCEL.EXE/3000
IE: Tout télécharger avec Free Download Manager - file://c:\program files\free download manager\dlall.htm
IE: Télécharger avec Free Download Manager - file://c:\program files\free download manager\dllink.htm
IE: Télécharger la sélection avec Free Download Manager - file://c:\program files\free download manager\dlselected.htm
IE: Télécharger la vidéo avec Free Download Manager - file://c:\program files\free download manager\dlfvideo.htm
IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\hp_adm~1.nom\applic~1\mozilla\firefox\profiles\5axz8c0l.default\
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\opera\program\plugins\npdivx32.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-1-24 64160]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-9-22 114768]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-6-23 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-6-23 72944]
R2 a2free;a-squared Free Service;c:\program files\a-squared free\a2service.exe [2008-9-22 380536]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-9-22 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2008-9-22 138680]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 1029456]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\McrdSvc.exe [2005-10-29 98304]
R2 R54G Wireless Service;R54G Wireless Service;c:\program files\wireless 802.11g monitor\WLService.exe [2009-1-15 49152]
R3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [2006-1-2 2829696]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2008-9-22 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2008-9-22 352920]
R3 rt2571;Wireless 802.11g USB Adapter Driver;c:\windows\system32\drivers\rt2571.sys [2007-2-28 79616]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-6-23 7408]
S3 WN5301;LIteon Wireless PCI Network Adapter Service;c:\windows\system32\drivers\wn5301.sys [2006-1-2 468768]

=============== Created Last 30 ================

2009-07-05 22:41--d-----c:\docume~1\alluse~1\applic~1\NortonInstaller
2009-07-05 18:25--d-----c:\program files\Trend Micro
2009-07-05 18:1273,728a-------c:\windows\system32\javacpl.cpl
2009-07-05 18:10410,984a-------c:\windows\system32\deploytk.dll
2009-07-05 16:13--d-----c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-07-05 16:13--d-----c:\program files\SUPERAntiSpyware
2009-07-05 16:13--d-----c:\docume~1\hp_adm~1.nom\applic~1\SUPERAntiSpyware.com
2009-07-05 16:12--d-----c:\program files\fichiers communs\Wise Installation Wizard
2009-07-05 15:58--d-----c:\program files\CCleaner
2009-07-03 13:18244a---h---C:\sqmnoopt07.sqm
2009-07-03 13:18232a---h---C:\sqmdata07.sqm
2009-06-10 00:15--d-----c:\program files\fichiers communs\DivX Shared

==================== Find3M ====================

2009-06-17 11:2738,160a-------c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 11:2719,096a-------c:\windows\system32\drivers\mbam.sys
2009-06-08 15:0715,688a-------c:\windows\system32\lsdelete.exe
2009-05-07 17:33348,672a-------c:\windows\system32\localspl.dll
2009-05-07 17:33348,672--------c:\windows\system32\dllcache\localspl.dll
2009-04-29 06:343,089,920--------c:\windows\system32\dllcache\mshtml.dll
2009-04-29 06:34670,720a-------c:\windows\system32\wininet.dll
2009-04-29 06:34670,720--------c:\windows\system32\dllcache\wininet.dll
2009-04-29 06:34621,056--------c:\windows\system32\dllcache\urlmon.dll
2009-04-29 06:3481,920a-------c:\windows\system32\ieencode.dll
2009-04-29 06:341,499,648--------c:\windows\system32\dllcache\shdocvw.dll
2009-04-29 06:3481,920--------c:\windows\system32\dllcache\ieencode.dll
2009-04-19 21:501,847,296a-------c:\windows\system32\win32k.sys
2009-04-19 21:501,847,296--------c:\windows\system32\dllcache\win32k.sys
2009-04-18 12:56446,984a-------c:\windows\system32\perfh00C.dat
2009-04-18 12:5664,724a-------c:\windows\system32\perfc00C.dat
2009-04-15 16:53585,216a-------c:\windows\system32\rpcrt4.dll
2009-04-15 16:53585,216--------c:\windows\system32\dllcache\rpcrt4.dll
2009-01-13 14:144,610a-------c:\docume~1\hp_adm~1.nom\applic~1\wklnhst.dat
2009-01-12 13:2786,016a-------c:\documents and settings\hp_administrateur.nom-fb9b15d2723\IDHWTSS1.dll
2008-09-02 20:1236,868a-------c:\documents and settings\hp_administrateur.nom-fb9b15d2723\PrtDLL.dll
2008-07-30 18:00155,280a-------c:\docume~1\hp_adm~1.nom\applic~1\GDIPFONTCACHEV1.DAT
2006-11-04 12:09251a-------c:\program files\wt3d.ini

============= FINISH: 22:56:28,10 ===============


Here is the Attach log:


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-06-26.01)

Microsoft Windows XP Professionnel
Boot Device: \Device\HarddiskVolume1
Install Date: 24/07/2008 19:26:21
System Uptime: 07/05/2009 22:44:13 (1416 hours ago)

Motherboard: ASUSTek Computer INC. | | Basswood
Processor: Intel(R) Core(TM)2 CPU 6400 @ 2.13GHz | Socket 775 | 2133/266mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 179 GiB total, 85,031 GiB free.
D: is FIXED (NTFS) - 186 GiB total, 152,933 GiB free.
E: is FIXED (FAT32) - 7 GiB total, 0,805 GiB free.
F: is CDROM ()
G: is Removable
H: is Removable
I: is Removable
J: is Removable

==== Disabled Device Manager Items =============

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Wireless LAN PCI 802.11 b/g adapter WN5301A
Device ID: PCI\VEN_168C&DEV_001B&SUBSYS_500111AD&REV_01\4&11B6166B&0&20F0
Manufacturer: Liteon
Name: Wireless LAN PCI 802.11 b/g adapter WN5301A
PNP Device ID: PCI\VEN_168C&DEV_001B&SUBSYS_500111AD&REV_01\4&11B6166B&0&20F0
Service: WN5301

==== System Restore Points ===================

RP315: 07/04/2009 08:20:46 - Point de vérification système
RP316: 08/04/2009 12:40:16 - Point de vérification système
RP317: 09/04/2009 03:00:16 - Software Distribution Service 3.0
RP318: 10/04/2009 15:23:28 - Point de vérification système
RP319: 11/04/2009 03:00:16 - Software Distribution Service 3.0
RP320: 12/04/2009 04:40:01 - Point de vérification système
RP321: 13/04/2009 06:50:27 - Point de vérification système
RP322: 14/04/2009 07:20:58 - Point de vérification système
RP323: 16/04/2009 00:02:45 - Point de vérification système
RP324: 17/04/2009 18:40:44 - Software Distribution Service 3.0
RP325: 18/04/2009 19:19:47 - Point de vérification système
RP326: 19/04/2009 03:00:17 - Software Distribution Service 3.0
RP327: 20/04/2009 07:42:56 - Point de vérification système
RP328: 21/04/2009 09:01:33 - Point de vérification système
RP329: 22/04/2009 09:47:02 - Point de vérification système
RP330: 23/04/2009 21:08:55 - Point de vérification système
RP331: 25/04/2009 03:00:16 - Software Distribution Service 3.0
RP332: 26/04/2009 03:00:18 - Software Distribution Service 3.0
RP333: 27/04/2009 03:00:16 - Software Distribution Service 3.0
RP334: 28/04/2009 03:00:15 - Software Distribution Service 3.0
RP335: 29/04/2009 06:46:50 - Point de vérification système
RP336: 30/04/2009 06:59:15 - Point de vérification système
RP337: 01/05/2009 03:00:14 - Software Distribution Service 3.0
RP338: 02/05/2009 05:03:25 - Point de vérification système
RP339: 03/05/2009 06:02:39 - Point de vérification système
RP340: 04/05/2009 06:45:18 - Point de vérification système
RP341: 05/05/2009 07:45:18 - Point de vérification système
RP342: 06/05/2009 08:45:18 - Point de vérification système
RP343: 07/05/2009 21:34:57 - Point de vérification système
RP344: 08/05/2009 03:00:14 - Software Distribution Service 3.0
RP345: 09/05/2009 04:12:23 - Point de vérification système
RP346: 10/05/2009 06:53:10 - Point de vérification système
RP347: 11/05/2009 07:28:56 - Point de vérification système
RP348: 12/05/2009 19:08:31 - Point de vérification système
RP349: 13/05/2009 03:00:29 - Software Distribution Service 3.0
RP350: 14/05/2009 05:02:06 - Point de vérification système
RP351: 15/05/2009 06:53:19 - Point de vérification système
RP352: 16/05/2009 07:16:20 - Point de vérification système
RP353: 17/05/2009 07:30:48 - Point de vérification système
RP354: 18/05/2009 08:18:39 - Point de vérification système
RP355: 19/05/2009 08:21:42 - Point de vérification système
RP356: 20/05/2009 03:00:13 - Software Distribution Service 3.0
RP357: 21/05/2009 16:07:28 - Point de vérification système
RP358: 22/05/2009 03:00:34 - Software Distribution Service 3.0
RP359: 23/05/2009 07:21:25 - Point de vérification système
RP360: 24/05/2009 07:39:56 - Point de vérification système
RP361: 26/05/2009 00:21:32 - Point de vérification système
RP362: 27/05/2009 03:33:35 - Point de vérification système
RP363: 28/05/2009 03:00:18 - Software Distribution Service 3.0
RP364: 29/05/2009 08:39:39 - Point de vérification système
RP365: 29/05/2009 20:31:02 - Software Distribution Service 3.0
RP366: 01/06/2009 03:00:19 - Software Distribution Service 3.0
RP367: 03/06/2009 03:01:02 - Software Distribution Service 3.0
RP368: 04/06/2009 16:38:39 - Point de vérification système
RP369: 04/06/2009 18:53:25 - Installé QuickTime
RP370: 05/06/2009 16:14:59 - Software Distribution Service 3.0
RP371: 07/06/2009 03:00:18 - Software Distribution Service 3.0
RP372: 10/06/2009 00:23:57 - Supprimé QuickTime
RP373: 10/06/2009 03:00:15 - Software Distribution Service 3.0
RP374: 11/06/2009 03:00:30 - Software Distribution Service 3.0
RP375: 12/06/2009 03:00:24 - Software Distribution Service 3.0
RP376: 20/06/2009 03:00:28 - Software Distribution Service 3.0
RP377: 22/06/2009 03:00:15 - Software Distribution Service 3.0
RP378: 24/06/2009 03:00:18 - Software Distribution Service 3.0
RP379: 25/06/2009 01:10:44 - Software Distribution Service 3.0
RP380: 26/06/2009 03:00:19 - Software Distribution Service 3.0
RP381: 27/06/2009 03:01:19 - Software Distribution Service 3.0
RP382: 28/06/2009 03:00:21 - Software Distribution Service 3.0
RP383: 29/06/2009 16:21:56 - Software Distribution Service 3.0
RP384: 30/06/2009 01:51:37 - Software Distribution Service 3.0
RP385: 01/07/2009 02:17:02 - Software Distribution Service 3.0
RP386: 01/07/2009 16:22:52 - Software Distribution Service 3.0
RP387: 02/07/2009 03:00:14 - Software Distribution Service 3.0
RP388: 02/07/2009 15:07:59 - Software Distribution Service 3.0
RP389: 03/07/2009 03:02:26 - Software Distribution Service 3.0
RP390: 05/07/2009 03:00:16 - Software Distribution Service 3.0
RP391: 05/07/2009 16:13:45 - Installed SUPERAntiSpyware Free Edition
RP392: 05/07/2009 18:10:07 - Installé Java(TM) 6 Update 14
RP393: 05/07/2009 18:11:31 - Supprimé Java(TM) 6 Update 14
RP394: 05/07/2009 18:12:22 - Installé Java(TM) 6 Update 14

==== Installed Programs ======================

a-squared Free 3.5
Ad-Aware
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Reader 7.1.0 - Français
Adobe Shockwave Player 11
Amélioration de nos services
Apple Software Update
Archiveur WinRAR
Ares Ultra 4.0.0
Assistant de connexion Windows Live
AutoUpdate
avast! Antivirus
BufferChm
CCleaner (remove only)
Compatibility Pack for the 2007 Office system
Connexion Facile à Internet
Correctif n°2 pour Windows XP Édition Media Center 2005
Correctif pour Lecteur Windows Media 10 (KB910393)
Correctif pour Lecteur Windows Media 11 (KB939683)
Correctif pour Windows XP (KB952287)
CP_AtenaShokunin1Config
CP_CalendarTemplates1
cp_LightScribeConfig
cp_OnlineProjectsConfig
CP_Package_Basic1
CP_Package_Variety1
CP_Package_Variety2
CP_Package_Variety3
CP_Panorama1Config
cp_PosterPrintConfig
cp_UpdateProjectsConfig
CueTour
Destinations
DeviceManagementQFolder
DivX Codec
DivX Converter
DivX Player
DivX Web Player
DVD X Player 4.1 Professional
Enhanced Multimedia Keyboard Solution
EPSON Attach To Email
EPSON Copy Utility 3
EPSON Easy Photo Print
EPSON File Manager
EPSON Image Clip Palette
EPSON Logiciel imprimante
EPSON Scan
EPSON Scan Assistant
EPSON Web-To-Page
ESDX4800_4200 Guide util.
ffdshow [rev 1723] [2007-12-24]
Foxit Reader
Free Download Manager 2.5
FullDPAppQFolder
Galerie de photos Windows Live
GameSpy Comrade
GemMaster Mystic
Google Earth
Google Gmail Notifier
Google Toolbar for Internet Explorer
Half-Life
High Definition Audio - KB888111
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 10 (KB903157)
HP Boot Optimizer
HP DigitalMedia Archive
HP DVD Play 2.1
HP Imaging Device Functions 7.0
HP Photosmart for Media Center PC
HP Photosmart Premier Software 6.5
HP Update
HP Wireless Keyboard Driver V1.8 (2.0.W-127AU MUL)
HPPhotoSmartExpress
HpSdpAppCoreApp
InstantShareDevices
Intel(R) Matrix Storage Manager
Intel(R) PRO Network Connections Drivers
Intel(R) Quick Resume Technology Drivers
J2SE Runtime Environment 5.0 Update 6
Java(TM) 6 Update 14
Last.fm 1.5.4.24567
Le logiciel Intel® Viiv™
Lecteur Windows Media11
LightScribe 1.4.105.1
Macromedia Flash Player 8
MainConcept for Software Encoder
Malwarebytes' Anti-Malware
Media Center Extender
Messenger Plus! Live
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 French Language Pack
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Bootvis
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office XP Professional
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Works
mIRC
Mise à jour critique pour Lecteur Windows Media 11 (KB959772)
Mise à jour de sécurité pour Lecteur Windows Media (KB952069)
Mise à jour de sécurité pour Lecteur Windows Media 10 (KB911565)
Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)
Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)
Mise à jour de sécurité pour Step by Step Interactive TRAINING (KB923723)
Mise à jour de sécurité pour Windows XP (KB923561)
Mise à jour de sécurité pour Windows XP (KB923689)
Mise à jour de sécurité pour Windows XP (KB938464)
Mise à jour de sécurité pour Windows XP (KB941569)
Mise à jour de sécurité pour Windows XP (KB946648)
Mise à jour de sécurité pour Windows XP (KB950759)
Mise à jour de sécurité pour Windows XP (KB950760)
Mise à jour de sécurité pour Windows XP (KB950762)
Mise à jour de sécurité pour Windows XP (KB950974)
Mise à jour de sécurité pour Windows XP (KB951066)
Mise à jour de sécurité pour Windows XP (KB951376-v2)
Mise à jour de sécurité pour Windows XP (KB951698)
Mise à jour de sécurité pour Windows XP (KB951748)
Mise à jour de sécurité pour Windows XP (KB952004)
Mise à jour de sécurité pour Windows XP (KB952954)
Mise à jour de sécurité pour Windows XP (KB953838)
Mise à jour de sécurité pour Windows XP (KB953839)
Mise à jour de sécurité pour Windows XP (KB954211)
Mise à jour de sécurité pour Windows XP (KB954459)
Mise à jour de sécurité pour Windows XP (KB954600)
Mise à jour de sécurité pour Windows XP (KB955069)
Mise à jour de sécurité pour Windows XP (KB956390)
Mise à jour de sécurité pour Windows XP (KB956391)
Mise à jour de sécurité pour Windows XP (KB956572)
Mise à jour de sécurité pour Windows XP (KB956802)
Mise à jour de sécurité pour Windows XP (KB956803)
Mise à jour de sécurité pour Windows XP (KB956841)
Mise à jour de sécurité pour Windows XP (KB957095)
Mise à jour de sécurité pour Windows XP (KB957097)
Mise à jour de sécurité pour Windows XP (KB958215)
Mise à jour de sécurité pour Windows XP (KB958644)
Mise à jour de sécurité pour Windows XP (KB958687)
Mise à jour de sécurité pour Windows XP (KB958690)
Mise à jour de sécurité pour Windows XP (KB959426)
Mise à jour de sécurité pour Windows XP (KB960225)
Mise à jour de sécurité pour Windows XP (KB960714)
Mise à jour de sécurité pour Windows XP (KB960715)
Mise à jour de sécurité pour Windows XP (KB960803)
Mise à jour de sécurité pour Windows XP (KB961373)
Mise à jour de sécurité pour Windows XP (KB961501)
Mise à jour de sécurité pour Windows XP (KB963027)
Mise à jour de sécurité pour Windows XP (KB968537)
Mise à jour de sécurité pour Windows XP (KB969897)
Mise à jour de sécurité pour Windows XP (KB969898)
Mise à jour de sécurité pour Windows XP (KB970238)
Mise à jour pour Windows XP (KB898461)
Mise à jour pour Windows XP (KB942763)
Mise à jour pour Windows XP (KB951072-v2)
Mise à jour pour Windows XP (KB951978)
Mise à jour pour Windows XP (KB955839)
Mise à jour pour Windows XP (KB967715)
Mozilla Firefox (3.0.11)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
muvee autoProducer 5.0
muvee autoProducer unPlugged 2.0
NVIDIA Drivers
Opera 9.64
OptionalContentQFolder
Otto
PC-Doctor 5 pour Windows
PhotoGallery
PIF DESIGNER
Python 2.2 pywin32 extensions (build 203)
Python 2.2.3
RandMap
RAR Password Cracker 4.12
RealPlayer
Realtek High Definition Audio Driver
Rome - Total War(TM)
Security Update for CAPICOM (KB931906)
Services Internet
Sid Meier's Civilization 4
Sid Meier's Civilization 4 - Beyond the Sword
Sid Meier's Civilization 4 - Warlords
SkinsHP1
SlideShow
SlideShowMusic
Sonic Express Labeler
Sonic MyDVD Plus
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
Sonic_PrimoSDK
Starcraft
SUPERAntiSpyware Free Edition
Transcode 360 for Windows Media Center Edition 2005
TVersity Codec Pack 1.2
Unload
Unlocker 1.8.7
User Profile Hive Cleanup Service
VC80CRTRedist - 8.0.50727.762
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
VobSub v2.23 (Remove Only)
WebFldrs XP
Winamp
Windows Imaging Component
Windows Live installer
Windows Live Messenger
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player Firefox Plugin
Windows XP Media Center Edition 2005 KB905589
Windows XP Media Center Edition 2005 KB925766
Windows XP Service Pack3
Wireless 802.11g USB Adapter
Xfire (remove only)

==== End Of File ===========================
Download the MBR Rootkit Detector to your desktop.

* DOUBLECLICK mbr.exe and follow prompts.
* A black DOS window will quickly appear then disappear.
* When mbr.exe is finished it will create a log on your desktop.
* Copy and paste contents of that log file to your next reply.Here is the requested log:

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.6 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK You have too many antispyware applications running.

  • a-squared
  • Ad-Aware
  • PC-Doctor 5
.
I suggest uninstalling a-squared and PC-Doctor 5. Use Malwarebytes and SUPERAntiSpyware for on-demand scanning. a-squared is known for false positives and PC-Doctor 5 is not very reliable in my opinion.

Also uninstall J2SE Runtime Environment 5.0 Update 6

----------

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

DO NOT run it yet!

Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

DDS::
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

Folder::
c:\docume~1\alluse~1\applic~1\NortonInstaller

3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze
I'm sorry I've got a question. This step requires me to install ComboFix, isn't it? I must look for it online? Since it doesn't seem to be present in my desktop.Sorry I copied the wrong speech. I edited the above instructions.Here is the log. Was my computer severely contaminated?

ComboFix 09-07-05.01 - HP_Administrateur 06/07/2009 3:02.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.2046.1447 [GMT 2:00]
Lancé depuis: c:\documents and settings\HP_Administrateur.NOM-FB9B15D2723\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\HP_Administrateur.NOM-FB9B15D2723\Bureau\CFScript.txt
AV: avast! antivirus 4.8.1335 [VPS 090705-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\alluse~1\applic~1\NortonInstaller
c:\docume~1\alluse~1\applic~1\NortonInstaller\Logs\07-05-2009-22h41m25s\SymNRT-07-05-2009-22h41m25s.log
c:\docume~1\alluse~1\applic~1\NortonInstaller\Logs\07-05-2009-22h41m25s\SymNRT.1.mft.7z
c:\docume~1\alluse~1\applic~1\NortonInstaller\Settings\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}.7z
c:\docume~1\HP_ADM~1.NOM\LOCALS~1\Temp\tmp1.tmp
c:\docume~1\HP_ADM~1.NOM\LOCALS~1\Temp\tmp2.tmp
C:\Documents
c:\program files\messenger\msmsgs.exe
c:\recycler\NPROTECT
c:\recycler\S-1-5-21-25602794-1062246565-3331014846-1007
c:\recycler\S-1-5-21-2631055522-4284232903-2707980172-1007
c:\recycler\S-1-5-21-2631055522-4284232903-2707980172-500
c:\recycler\S-1-5-21-3208901557-1489751670-1171760114-1007
c:\recycler\S-1-5-21-4147084904-3235195045-2169894318-1007
c:\windows\desktop
c:\windows\desktop\IRcap.lnk
c:\windows\Installer\101420.msi
c:\windows\Installer\122fe5.msi
c:\windows\Installer\122fe9.msi
c:\windows\Installer\122ff0.msi
c:\windows\Installer\1291ec4.msi
c:\windows\Installer\1345b1e.msp
c:\windows\Installer\1345b23.msi
c:\windows\Installer\14174e0.msp
c:\windows\Installer\14f79ca.msi
c:\windows\Installer\1752119.msi
c:\windows\Installer\17ec23d.msi
c:\windows\Installer\180998d.msp
c:\windows\Installer\1c14a14.msi
c:\windows\Installer\1f712d.msi
c:\windows\Installer\1f8515e.msi
c:\windows\Installer\207722e.msp
c:\windows\Installer\20a41e.msi
c:\windows\Installer\23c2e86.msi
c:\windows\Installer\2a05f8.msi
c:\windows\Installer\2a05ff.msi
c:\windows\Installer\2a0628.msi
c:\windows\Installer\2a0634.msi
c:\windows\Installer\2bd3ee9.msi
c:\windows\Installer\2cbdc55.msi
c:\windows\Installer\2d751ee.msi
c:\windows\Installer\2e1d7f7.msi
c:\windows\Installer\2e24c2c.msi
c:\windows\Installer\2f6d251.msi
c:\windows\Installer\2f6d253.msi
c:\windows\Installer\3037834.msp
c:\windows\Installer\343cf.msi
c:\windows\Installer\378191e.msi
c:\windows\Installer\378195e.msi
c:\windows\Installer\3781978.msp
c:\windows\Installer\378197f.msi
c:\windows\Installer\378198a.msp
c:\windows\Installer\3b768cc.msi
c:\windows\Installer\3ddbb2b.msi
c:\windows\Installer\3ebcb1.msi
c:\windows\Installer\434684.msi
c:\windows\Installer\472fd7.msi
c:\windows\Installer\4ad34da.msi
c:\windows\Installer\4ad34db.msp
c:\windows\Installer\4ad34dc.msp
c:\windows\Installer\4ad34dd.msp
c:\windows\Installer\4ad34de.msp
c:\windows\Installer\4ad34df.msp
c:\windows\Installer\4ad34e0.msp
c:\windows\Installer\4ad34e1.msp
c:\windows\Installer\4ad34e2.msp
c:\windows\Installer\4ad34e3.msp
c:\windows\Installer\571a62e.msi
c:\windows\Installer\6696d.msi
c:\windows\Installer\6697a.msi
c:\windows\Installer\683998a.msi
c:\windows\Installer\69b5f9b.msi
c:\windows\Installer\6d641a.msi
c:\windows\Installer\7378d2d.msi
c:\windows\Installer\783269.msi
c:\windows\Installer\798d75e.msp
c:\windows\Installer\7e837.msi
c:\windows\Installer\800b1.msp
c:\windows\Installer\864935.msi
c:\windows\Installer\8a950.msi
c:\windows\Installer\8a955.msi
c:\windows\Installer\911a0e1.msi
c:\windows\Installer\911a0e9.msi
c:\windows\Installer\93bd6d.msi
c:\windows\Installer\9ff10.msi
c:\windows\Installer\a73455.msi
c:\windows\Installer\c69b55.msi
c:\windows\Installer\d333d3.msi
c:\windows\Installer\e13c5.msi
c:\windows\Installer\e795b7b.msp
c:\windows\Installer\f1698c.msi
c:\windows\Installer\f2b19a.msi
c:\windows\Installer\fc34f.msi
c:\windows\Installer\fc35f.msi
c:\windows\Installer\fc374.msi
c:\windows\Installer\fc37c.msi
c:\windows\Installer\fc38d.msi
c:\windows\kb913800.exe
E:\Autorun.inf

.
((((((((((((((((((((((((((((( Fichiers créés du 2009-06-06 au 2009-07-06 ))))))))))))))))))))))))))))))))))))
.

2009-07-05 16:25 . 2009-07-05 16:28--------d-----w-c:\program files\Trend Micro
2009-07-05 16:10 . 2009-07-05 16:12410984----a-w-c:\windows\system32\deploytk.dll
2009-07-05 14:14 . 2009-07-05 15:52117760----a-w-c:\documents and settings\HP_Administrateur.NOM-FB9B15D2723\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-07-05 14:13 . 2009-07-05 14:13--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-07-05 14:13 . 2009-07-05 14:13--------d-----w-c:\program files\SUPERAntiSpyware
2009-07-05 14:13 . 2009-07-05 14:13--------d-----w-c:\documents and settings\HP_Administrateur.NOM-FB9B15D2723\Application Data\SUPERAntiSpyware.com
2009-07-05 14:12 . 2009-07-05 14:12--------d-----w-c:\program files\Fichiers communs\Wise Installation Wizard
2009-07-05 13:58 . 2009-07-05 13:58--------d-----w-c:\program files\CCleaner
2009-07-05 12:27 . 2009-07-05 12:273561743----a-w-c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-22 20:48 . 2009-06-22 20:48--------d-----w-c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-06-22 13:19 . 2009-07-02 23:30314712----a-w-c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\threatwork.exe
2009-06-22 13:19 . 2009-07-02 23:3025440----a-w-c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\savapibridge.dll
2009-06-22 13:19 . 2009-07-02 23:30169312----a-w-c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\lavamessage.dll
2009-06-22 13:18 . 2009-07-02 23:30348496----a-w-c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\lavalicense.dll
2009-06-22 13:18 . 2009-07-02 23:30298336----a-w-c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\UpdateManager.dll
2009-06-22 13:18 . 2009-07-02 23:301630560----a-w-c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Resources.dll
2009-06-22 13:17 . 2009-07-02 23:3085352----a-w-c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Drivers\32\AAWDriverTool.exe
2009-06-22 13:17 . 2009-07-02 23:30664424----a-w-c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\CEAPI.dll
2009-06-22 13:17 . 2009-07-02 23:30563064----a-w-c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Ad-AwareCommand.exe
2009-06-22 13:16 . 2009-07-02 23:30566632----a-w-c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Ad-AwareAdmin.exe
2009-06-22 13:16 . 2009-06-29 14:112352968----a-w-c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Ad-Aware.exe
2009-06-22 13:14 . 2009-06-29 14:10629072----a-w-c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\AAWWSC.exe
2009-06-22 13:14 . 2009-07-02 23:30520024----a-w-c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\AAWTray.exe
2009-06-22 13:14 . 2009-07-02 23:301029456----a-w-c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\AAWService.exe
2009-06-09 22:15 . 2009-06-09 22:15--------d-----w-c:\program files\Fichiers communs\DivX Shared
2009-06-09 22:15 . 2009-06-09 22:15--------d-----w-c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-06-08 13:07 . 2009-06-08 13:0715688----a-w-c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\lsdelete.exe
2009-06-08 13:07 . 2009-07-02 23:3084832----a-w-c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\ShellExt.dll

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-06 01:21 . 2008-07-24 19:42--------d-----w-c:\documents and settings\HP_Administrateur.NOM-FB9B15D2723\Application Data\OpenOffice.org2
2009-07-06 01:18 . 2008-07-27 23:59--------d-----w-c:\program files\Transcode360
2009-07-06 00:38 . 2006-01-02 20:13--------d-----w-c:\program files\Java
2009-07-05 20:42 . 2006-01-02 20:57--------d-----w-c:\program files\Fichiers communs\Symantec Shared
2009-07-05 14:03 . 2008-07-24 22:50--------d-----w-c:\documents and settings\HP_Administrateur.NOM-FB9B15D2723\Application Data\Azureus
2009-07-05 12:28 . 2008-12-30 02:14--------d-----w-c:\program files\Malwarebytes' Anti-Malware
2009-07-02 23:30 . 2009-06-01 13:24246128----a-w-c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\RPAPI.dll
2009-07-02 23:30 . 2009-06-01 13:2440288----a-w-c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\PrivacyClean.dll
2009-06-17 09:27 . 2008-12-30 02:1438160----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 09:27 . 2008-12-30 02:1419096----a-w-c:\windows\system32\drivers\mbam.sys
2009-06-11 15:37 . 2008-07-26 21:33--------d-----w-c:\documents and settings\HP_Administrateur.NOM-FB9B15D2723\Application Data\Free Download Manager
2009-06-09 22:24 . 2006-09-08 21:18--------d-----w-c:\documents and settings\All Users\Application Data\Apple Computer
2009-06-09 22:17 . 2006-01-02 20:41--------d-----w-c:\program files\DivX
2009-06-09 22:16 . 2006-01-02 20:52--------d-----w-c:\program files\Google
2009-06-08 13:07 . 2009-01-24 19:1315688----a-w-c:\windows\system32\lsdelete.exe
2009-06-04 16:53 . 2009-06-04 16:53--------d-----w-c:\program files\Apple Software Update
2009-06-04 16:53 . 2009-06-04 16:53--------d-----w-c:\documents and settings\All Users\Application Data\Apple
2009-06-02 12:16 . 2009-06-02 12:16--------d-----w-c:\program files\HP Wireless Keyboard
2009-05-31 23:04 . 2008-08-04 18:23--------d-----w-c:\program files\Azureus Games
2009-05-31 15:28 . 2009-05-31 15:28--------d-----w-c:\program files\Western Digital
2009-05-26 18:29 . 2008-10-28 11:59265----a-w-c:\windows\system32\qwavecache.dat
2009-05-07 15:33 . 2004-08-10 11:00348672----a-w-c:\windows\system32\localspl.dll
2009-04-29 04:34 . 2004-08-10 11:00670720----a-w-c:\windows\system32\wininet.dll
2009-04-29 04:34 . 2004-08-10 11:0081920----a-w-c:\windows\system32\ieencode.dll
2009-04-25 17:05 . 2009-04-25 17:0564160----a-w-c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Drivers\32\lbd.sys
2009-04-25 17:05 . 2009-01-24 18:0564160----a-w-c:\windows\system32\drivers\Lbd.sys
2009-04-19 19:50 . 2004-08-10 11:001847296----a-w-c:\windows\system32\win32k.sys
2009-04-18 10:56 . 2005-10-10 11:3964724----a-w-c:\windows\system32\perfc00C.dat
2009-04-18 10:56 . 2005-10-10 11:39446984----a-w-c:\windows\system32\perfh00C.dat
2009-04-15 14:53 . 2004-08-10 11:00585216----a-w-c:\windows\system32\rpcrt4.dll
2006-11-04 10:09 . 2006-11-04 10:09251----a-w-c:\program files\wt3d.ini
2009-05-01 21:02 . 2009-05-01 21:021044480----a-w-c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02200704----a-w-c:\program files\mozilla firefox\plugins\ssldivx.dll
2009-05-01 21:02 . 2009-05-01 21:021044480----a-w-c:\program files\opera\program\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02200704----a-w-c:\program files\opera\program\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-07-06 151552]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-04-28 7573504]
"DMAScheduler"="c:\program files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 90112]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 249856]
"EPSON Stylus DX4200 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAEE.EXE" [2005-03-08 98304]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"Transcode360"="c:\program files\Transcode360\Transcode360Tray.exe" [2006-05-02 192512]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-22 237568]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-07-02 520024]
"BtcMaestro"="c:\program files\HP Wireless Keyboard\KMaestro.exe" [2005-06-13 278528]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-05 148888]
"ftutil2"="ftutil2.dll" - c:\windows\system32\ftutil2.dll [2004-06-07 106496]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2006-06-14 16239616]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-04-28 1519616]

c:\documents and settings\Default User\Menu D‚marrer\Programmes\D‚marrage\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-1-2 27136]
PinMcLnk.lnk - c:\hp\bin\cloaker.exe [2006-1-2 27136]

c:\documents and settings\MCX1\Menu D‚marrer\Programmes\D‚marrage\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-1-2 27136]
PinMcLnk.lnk - c:\hp\bin\cloaker.exe [2006-1-2 27136]

c:\documents and settings\MCX2\Menu D‚marrer\Programmes\D‚marrage\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-1-2 27136]
PinMcLnk.lnk - c:\hp\bin\cloaker.exe [2006-1-2 27136]

c:\documents and settings\Default User\Menu D‚marrer\Programmes\D‚marrage\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-1-2 27136]
PinMcLnk.lnk - c:\hp\bin\cloaker.exe [2006-1-2 27136]

c:\documents and settings\HP_Administrateur.NOM-FB9B15D2723\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-1-21 393216]

c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Moniteur de ressources Extender.lnk - c:\windows\ehome\RMSysTry.exe [2005-10-20 18432]

c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\AutorunsDisabled
MaxiMemo.lnk - c:\program files\MaxiMemo\MaxiMemo.exe [2008-1-19 828928]

c:\documents and settings\Default User\Menu D‚marrer\Programmes\D‚marrage\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-1-2 27136]
PinMcLnk.lnk - c:\hp\bin\cloaker.exe [2006-1-2 27136]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 10:05356352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.sys

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
backup=c:\windows\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords_PitBoss.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
"c:\\mIRC\\mirc.exe"=
"c:\\Program Files\\Transcode360\\Transcode360Tray.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Ares Ultra\\Ares Ultra.exe"=
"c:\\Program Files\\Valve\\Half-Life\\hl.exe"=
"d:\\Games\\Unreal Tournament\\System\\UnrealTournament.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3776:UDP"= 3776:UDP:Service de Media Center Extender
"3390:TCP"= 3390:TCP:Services Media Center à distance

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [24/01/2009 20:05 64160]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [22/09/2008 17:22 114768]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [23/06/2009 11:01 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [23/06/2009 11:01 72944]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [22/09/2008 17:22 20560]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [18/01/2009 23:34 1029456]
R2 R54G Wireless Service;R54G Wireless Service;c:\program files\Wireless 802.11g Monitor\WLService.exe [15/01/2009 12:21 49152]
R3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [02/01/2006 22:28 2829696]
R3 rt2571;Wireless 802.11g USB Adapter Driver;c:\windows\system32\drivers\rt2571.sys [28/02/2007 22:41 79616]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [23/06/2009 11:01 7408]
S3 WN5301;LIteon Wireless PCI Network Adapter Service;c:\windows\system32\drivers\wn5301.sys [02/01/2006 22:28 468768]

--- Autres Services/Pilotes en mémoire ---

*NewlyCreated* - GTNDIS5
*Deregistered* - uphcleanhlp

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVEREG_MULTI_SZ QWAVE
.
Contenu du dossier 'Tâches planifiées'

2009-06-29 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 23:30]

2009-06-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2009-07-05 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 17:20]
.
- - - - ORPHELINS SUPPRIMES - - - -

HKLM-Run-PCDrProfiler - (no file)


.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
IE: E&xportar a Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
IE: Tout télécharger avec Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
IE: Télécharger avec Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
IE: Télécharger la sélection avec Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
IE: Télécharger la vidéo avec Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
FF - ProfilePath - c:\documents and settings\HP_Administrateur.NOM-FB9B15D2723\Application Data\Mozilla\Firefox\Profiles\5axz8c0l.default\
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Opera\program\plugins\npdivx32.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-06 03:15
Windows 5.1.2600 Service Pack 3 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------

- - - - - - - > 'winlogon.exe'(992)
c:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'explorer.exe'(3328)
c:\windows\system32\nview.dll
c:\windows\system32\NVWRSFR.DLL
c:\program files\HP Wireless Keyboard\HidKeybd.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\nvwddi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Fichiers communs\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\windows\ehome\RMSvc.exe
c:\program files\Wireless 802.11g Monitor\WLanCfgG.exe
c:\program files\UPHClean\uphclean.exe
c:\windows\ehome\McrdSvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\ELService.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\rundll32.exe
c:\windows\system\hpsysdrv.exe
c:\program files\OpenOffice.org 2.4\program\soffice.exe
c:\program files\OpenOffice.org 2.4\program\soffice.bin
.
**************************************************************************
.
Heure de fin: 2009-07-06 3:33 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-07-06 01:33

Avant-CF: 91259133952 octets libres
Après-CF: 95215472640 octets libres

359--- E O F ---2009-07-06 01:00
Quote from: TMNT on July 05, 2009, 07:36:23 PM
Was my computer severely contaminated?

Yes and I'm not sure it's all gone yet.

Go to Start > Run and type notepad.exe then click OK

Copy and paste the below into Notepad and save as fixme.reg to Your Desktop

Code: [Select]REGEDIT4

[-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

[-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry.

Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it did not work.

Delete the fixme.reg from the Desktop.

----------

* Click START then RUN
* Now type Combofix /u in the runbox
* Make sure there's a space between Combofix and /u
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the CLOCK settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

----------

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

----------

Use the Kaspersky Lab Online Scanner

In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.

  • Click on SCAN NOW
  • Click Accept.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded locate the Scan Settings and have it scan My Computer.
  • The scan will take a while, so be patient and let it finish.
When the scan is done, in the Scan is complete window, any infection is displayed.
There is no option to clean/disinfect, however, we need to analyze the information on the report.

To obtain the report:
Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop.
  • In the File name area use KScan, or something similar.
  • In Save as type: click the drop arrow and select: Text file [*.txt]
  • Then, click: Save


Copy and paste the Kaspersky Online Scanner Report in your next reply.

Note for Internet Explorer 7 and 8 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.

If needed, this animation will guide you through the process.Does this mean I should change important passwords just in case? fixme.reg was succesfully added to the registry. Here is the requested log:

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0 REPORT
Monday, July 6, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Monday, July 06, 2009 03:33:55
Records in database: 2430652
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\

Scan statistics:
Files scanned: 166837
Threat name: 1
Infected objects: 2
Suspicious objects: 0
Duration of the scan: 02:25:17


File name / Threat name / Threats count
C:\mIRC\mirc.exeInfected: not-a-virus:Client-IRC.Win32.mIRC.6031
C:\Program Files\mIRC\mirc.exeInfected: not-a-virus:Client-IRC.Win32.mIRC.6031

The selected area was scanned.
Quote
Does this mean I should change important passwords just in case?

It's always a good idea to do that now and then.

You use mIRC so those are false positives.

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

Thank you very much evilfantasy for your valuable help!
3852.

Solve : What do the experts on CH suggest about this??

Answer» http://www.microsoft.com/technet/security/advisory/972890.mspx My question is how does one know if they should take any action (corrective or preventative) and if action is taken apart from the removal of the threat what other impact will it have on computer programs? truenorthQuote
What do the experts on CH suggest about this?

Use Firefox...ActiveX has always been a security mess. BIG part of the reason I originally moved away from IE.
If you for some reason need to use IE, apply the WORKAROUND Microsoft have come up with.
http://support.microsoft.com/kb/972890For Internet Explorer you can also use SpywareBlaster to block known bad ActiveX.

How to use SpywareBlaster to protect your computer from Spyware, Hijackers, and MalwareActiveX is great on the client but the extension to the net was a bit ill-thought out by MS.
3853.

Solve : UIPOPUPHIDDEN?

Answer» FOR INFORMATION : This forum search did not identify subject so I think it useful for ANYONE else searching.

When turning off my PC, Windows XP SP3 with Virgin Media PC Guard Total AV Suite, I got a popup box titled 'Uipopuphidden' stating that I would loose all unsaved data if I closed it. This box only appeared when I replaced my AVG 8.0 with PC guard 6 weeks AGO. Also since Saturday 30th May, my optical mouse pointer has been jerking around the screen/freezing.

SOLUTION:

I telephoned VM this morning and they confirmed that Uipopuphidden is SPYWARE, instructed me to uninstall PC Guard and reinstall it to Fix the problem. I have done so, and now when I turn off the PC everything appears to be OK. My mouse pointer is behaving normally.

I have posted here in addition to other PC forums where the problem was STILL unresolved within their postings.
Thanks for sharing. I will remember this.Thanks for the warning, if I ever get anything LIKE I will go straight the the malware section Quote from: John A Taylor on June 01, 2009, 06:35:25 AM
.........Also since Saturday 30th May, my optical mouse pointer has been jerking around the screen/freezing.


Mouse gave up last night, following a restart I got the message " mouse not detected" etc. Took it to local PC repair shop and told it was 'banjacked'. Got a new mouse, working perfectly so unlikely the Uipopuphidden problem had any affect on mouse pointer.

The PC shop advisor also said he did not think Uipopuphidden was spy or malware but was a small 'user interface' piece of software which was created by PC Guard. The 'fix' now prevents it showing on PC shutdown.

Sorry if I misled anyone but I took the VM Indian call-centre operative's word for it.Ya, it seems to be a problem with the Bell Sympatico Security Manager software as well. I spent most of today on the phone with them. They seemed to be either unaware of it, or in denial. Blaming conflicting programs on my computer or saying I needed a system CLEAN for my problems.
3854.

Solve : My search engines get rerouted. Posted my HJT log?

Answer»

Everytime I do a search from google it reroutes me to random sites. Also, when I go to yahoo, it redirects me to m.yahoo.com.

Please help.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:38:54 PM, on 7/7/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\mpktnpah.exe
C:\Program Files\APOINT\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\LMI7.tmp\lmi_rescue.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rpcnet.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\LMI7.tmp\lmi_rescue.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Trend Micro\HijackThis\sniper.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=5061017
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=5061017
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O1 - Hosts: 105.1.11.5 seahq_exchange
O1 - Hosts: 105.1.11.6 seahq_exchange2
O1 - Hosts: 105.1.11.7 seahq_exchange3
O1 - Hosts: 105.1.11.12 SEUSA seusa.net
O1 - Hosts: 105.1.11.19 pilot pilot.sdsosc.co.kr #acube communication server
O1 - Hosts: 105.1.11.24 sds.samsung.com sds
O1 - Hosts: 105.1.11.229 foxhound
O1 - Hosts: 105.1.11.233 hawker
O1 - Hosts: 105.1.15.80 edcmon
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autoclose
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\RunOnce: [*LogMeInRescue_2581696517] "C:\WINDOWS\LMI7.tmp\lmi_rescue.exe" -runonce reboot
O4 - HKLM\..\Policies\Explorer\Run: [SpywareGuard] "C:\mpktnpah.exe"
O4 - Global Startup: SAMSUNG NETWORKS VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O15 - Trusted Zone: http://*.samsung.net
O15 - Trusted Zone: *.samsungportal.com
O15 - Trusted IP RANGE: http://70.2.140.140
O15 - Trusted IP range: http://70.20.10.140
O16 - DPF: {08BCD971-A13B-4D6E-A2A5-E9B2324FC00D} (ClientEXE Class) - http://service.samsungportal.com/EP/web/common/cabfiles/CM_ClientEXE.cab
O16 - DPF: {2DAAD547-FA98-498C-8FB7-63A7FCBDC0AF} (MenuCtrl Class) - http://70.20.10.140:8011/sdscc/cabs/pdss40.cab
O16 - DPF: {2FF8F8B7-1B3F-4E5F-93B1-FEF1D703C0F4} (LocalTree.LocalXMLTree) - http://w2.samsung.net/cabs/LocalFolder2004/Cab/mySingleLocal_U.cab
O16 - DPF: {34B5A473-9696-4F9A-9BA1-41B8185A9798} (EpFTP3 CONTROL) - http://w2.samsung.net/cabs/EpFTP3/EpFTP3_U.cab
O16 - DPF: {37DEC207-782F-40F5-803C-18ACEDA1ABA6} (PersonalCache Control) - http://203.254.195.140/portalWeb/cabs/mySinglePersonalCache.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1200941689187
O16 - DPF: {714E667D-360C-4BFB-8C1A-E4812B608CC1} (ACUBETrustChecker Control) - http://70.20.10.140:8000/EP/web/common/cabfiles/ACUBETrustChecker.cab
O16 - DPF: {859A7EB3-35E6-434B-A82B-08B4F8DDE1B6} (NamoWeCtl 6.0 for samsung_mysingle) - http://w2.samsung.net/cabs/Namo/NamoWec.cab
O16 - DPF: {88DDFD7D-14F7-4E89-8F85-737B90B1A0D0} (mySingleTrust.ClsMain) - http://203.254.195.140/cabs/LocalFolder2004/Cab/mySingle_Trust.CAB
O16 - DPF: {9D67EBF0-AF1A-4BCE-BAC9-C84A9383E0B3} (SSOCheck Class) - https://service.samsungportal.com//EP/web/common/cabfiles/UniSSOCheck.cab
O16 - DPF: {C4D88B8E-352B-11D6-BF77-0080C740A177} (Setup Class) - http://service.samsungportal.com/EP/web/common/cabfiles/ActiveXSetup.cab
O16 - DPF: {C63E3330-049F-4C31-B47E-425C84A5A725} (EpAdm2 Control) - http://203.254.195.140/cabs/Tray/EpAdm2.cab
O16 - DPF: {DE6ABA6A-095B-43E3-BEBB-879868DC5C8A} (SSLinks Control) - http://203.254.195.140/cabs/messenger/SSLinks.cab
O16 - DPF: {E1D1DACA-5BA2-4376-89AD-3A213B916779} (IBLeaders IBSheet For UNICODE Control) - http://70.20.1.100:7081/ghr/common/sheet/IBSheet4Unicode.CAB
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupControlXP Class) - https://206.67.236.179/dana-cached/setup/JuniperSetupSP1.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = sea.samsung.com
O17 - HKLM\Software\..\Telephony: DomainName = sea.samsung.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{7BD95933-CE86-4F62-9DF3-3F5AC5ADF1D6}: NameServer = 105.1.11.4,105.1.11.5,206.67.236.3,206.67.236.20
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = sea.samsung.com
O17 - HKLM\System\CS1\Services\Tcpip\..\{7BD95933-CE86-4F62-9DF3-3F5AC5ADF1D6}: NameServer = 105.1.11.4,105.1.11.5,206.67.236.3,206.67.236.20
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Remote Procedure Call (RPC) Net (Rpcnet) - Absolute Software Corp. - C:\WINDOWS\system32\rpcnet.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Well please don't forget you need your MBAM and SUPERantispyware logs. we can see just little of what is wrong with your computer right now, but it sounds like you have malware.

Also, many replies on google are stating that MBAM and SUPERantispyware has fixed the same problem you have.

3855.

Solve : CPU running at 100% with no applications open?

Answer»

When I start up my Laptop I see the power indicator light flashing, but it doesn't stay lit.
Once I actually login to my user account, it jumps to 100% and stays there.
I also get a notification upon login that I have no Firewall running...I've gone in and turned Windows Firewall on, and rebooted, but still get the same notification upon my next login.

If I boot from (not sure if it's HDD, or IDD) and then start Windows in Safe Mode, I do not get this problem, which leads me to believe it is a Virus.

I have:
Gateway 7330GZ, Pentium 4
Windows XP Home Edition, Version 2002, Service Pack 3, 3.06GHz, 3.06GHz, 480 MB of Ram (taken from my "System" screen)

My AVG hasn't caught anything, and I have it set to run every night and usually try my best to keep my CPU clean...I've ran HJT numerous times in the past, and am familiar with the results - here's the recent HJT log, nothing seems to be new...I haven't made any changes to my system...last thing I recall doing before this problem came up was just running Windows Clean Up! followed by a Defrag of my C & D Drives.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:09:50 PM, on 6/25/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\ssstars.scr
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\system32\taskmgr.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sportingnews.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://secure.webroot.com/keycodes/alreadyregistered.asp?kc=SSDCRETLAAAANSLHUPPQ&lang=en
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,C:\WINDOWS\system32\twext.exe,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30FEDFBF-391B-45F7-8AFF-796E8A532869} (PCRHTML3.HTML1) - http://www.pcrecruiter.net/pcrimg/PCRHTML.CAB
O16 - DPF: {4F1F4A2E-F7D0-402E-BBFB-04AC32A6755F} (PCRMANF.FILEM) - http://www.pcrecruiter.net/pcrimg/pcrfilem.cab
O16 - DPF: {8FAC20B4-0B1D-4BAC-BCE0-59DA519DEE67} (PCRALM.ALARM1) - http://www.pcrecruiter.net/pcrimg/PCRALM.CAB
O16 - DPF: {F8E159B1-2433-478A-B82E-9CCC87A7FAFB} (PCRRTF4.RTF4) - http://www.pcrecruiter.net/pcrimg/MS.CAB
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
O24 - Desktop Component 0: (no name) - (no file)

--
End of file - 6440 bytes



Thank you in advance for any assistance. If there's anything missing let me know and I can get it and post it TONIGHT; I'm at work now and my Laptop is at home.

Josh




*Also, if I posted this in the wrong thread, I apologize and please let me know where to move it to.
go to task manager , proccess , and take a photo of everything thats there so an expert can see it


http://www.screencapturer.com/


go to above download and this will take a photo ( maybe 2 ) , save to docs and post here , use the 3rd RIGHT

at the top it will take what you want , harryQuote

go to task manager , proccess , and take a photo of everything thats there so an expert can see it


Make sure that you get all of the processes, if you can't fit them all in one image scroll down and take a second. Also make sure that you enable 'Show Processes For All Users'.


quantos , when you open task manager it opens at processes , where do you enable " show processes for all "


Also make sure that you enable 'Show Processes For All Users'Thanks, Quantos and harry 48; hectic weekend so I didn't get a chance to jump online and work on this...
I'll take the screen shot(s) tonight when I get home from work and will post.
I've attached the two shots taken with Screencapture.
As indicated, I took these shots with 'Show Processes For All Users' enabled.
(harry, at the bottom right of the task manager processes screen, you can check a box to 'Show Processes For All Users')

I'm not sure if this will be helpful also, but in case it is, I have also attached the last HJT Log I'd saved before this problem started - I haven't compared the two HJT Logs yet as this thought just occurred to me.

Thank you in advance for the assistance.




[attachment deleted by admin]Hi Dues12,

Have you tired SAS and MBAM?Quote from: randysilverio on July 02, 2009, 09:55:25 PM
Hi Dues12,

Have you tired SAS and MBAM?

Randy,
I am not familiar with either program, but can look into downloading and running them today.
I'm also starting to move the few files I do have on my hard drive to an external hard drive so I'm ready to do a destructive system restore if need be to fix my problem...but first let me try the PROGRAMS you'd mentioned.
Thank you.


Forgive my ignorance here, but I'm assuming I cannot run all the virus/etc scans when my computer is started in safe mode, and instead I need to run the virus/etc scans in normal mode (which will take FOREVER...) - is this correct?





*Also,
I just compared the two HJT Logs I have, I noticed a few inconsistencies, some which can be explained...others though...here are all the inconsistencies found:

Processes that were running on 6/25, but not on 6/5:

C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ssstars.scr
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE


Reg Entries not found on 6/25, but found on 6/5:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page =
http://go.microsoft.com/fwlink/?LinkId=54843
(This was an old entry I had removed)

O4 - HKLM\..\Run: [StartupDelayer] "C:\Program Files\r2
Studios\Startup Delayer\Startup Launcher GUI.exe"
(I'd decided since I wasn't starting up more than a couple of programs now, I no longer needed to run SUD)

O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
(Didn't look like I needed this - I don't use excel much - so I removed it)
If you already have Malwarebytes be sure to update it before running the scan!

Download Malwarebytes' Anti-Malware (MBAM)

Alternate MBAM download link

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to the following:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
    • Then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select Perform quick scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy and Paste the entire report in your next reply.
    Extra Note: If MBAM encounters a file that is DIFFICULT to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

    ----------

    Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop.

    Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

    * XP users Double click on dds to run it.
    * If your antivirus or firewall try to block DDS then please allow it to run.
    * When finished DDS will open two (2) logs.

    1) DDS.txt
    2) Attach.txt

    * Save both logs to your desktop.
    * Please copy and paste the entire contents of both logs in your next reply.

    Note: DDS will instruct you to post the Attach.txt log as an attachment.
    Please just post it as you would any other log by copy and pasting it into the reply.Thank you to everyone for your comments and help.
    I'm pleased to announce my issue has been resolved.
    After installing, updating, and running a couple Anti-Spyware programs I was able to remove 8 traces of a Trojan Horse - progdav or something like that - and my cpu is now back to running as it should.
    Thank you!!!!

    Josh
    Lack of symptoms doesn't always mean all of the malware is gone. Without posting the logs we can't know if everything was actually removed or not.Quote from: evilfantasy on July 06, 2009, 02:03:53 PM
    Lack of symptoms doesn't always mean all of the malware is gone. Without posting the logs we can't know if everything was actually removed or not.

    Good point; thank you, evilfantasy.
    What logs in specific should I post?
    I'm pretty sure it was Spysweeper out of the 3 I ran that located the traces and removed them...

    Let me know and I should be able to post any needed logs tonight after work.

    Thank you,
    Josh
    If you already have Malwarebytes be sure to update it before running the scan!

    Download Malwarebytes' Anti-Malware (MBAM)

    Alternate MBAM download link

    • Double-click mbam-setup.exe and follow the prompts to install the program.
    • At the end, be sure a checkmark is placed next to the following:
      • Update Malwarebytes' Anti-Malware
      • Launch Malwarebytes' Anti-Malware
      • Then click Finish.
      • If an update is found, it will download and install the latest version.
      • Once the program has loaded, select Perform quick scan, then click Scan.
      • When the scan is complete, click OK, then Show Results to view the results.
      • Be sure that everything is checked, and click Remove Selected.
      • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
      • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
      • Copy and Paste the entire report in your next reply.
      Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

      ----------

      Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop.

      Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

      * XP users Double click on dds to run it.
      * If your antivirus or firewall try to block DDS then please allow it to run.
      * When finished DDS will open two (2) logs.

      1) DDS.txt
      2) Attach.txt

      * Save both logs to your desktop.
      * Please copy and paste the entire contents of both logs in your next reply.

      Note: DDS will instruct you to post the Attach.txt log as an attachment.
      Please just post it as you would any other log by copy and pasting it into the reply.
      3856.

      Solve : Virus has disabled all my protection programs?

      Answer»

      Click START then RUN

      • Now type Combo-Fix in the runbox
      • Make sure there's a space between Combo-Fix and /u
      • Then hit Enter.
        .
        That should uninstall ComboFix.

        Now restart the computer and install it again. Be sure to rename it during the install using the instructions from HERE.

        If that does or doesn't work try running Malwarebytes also.
      Malwarebytes' Anti-Malware 1.38
      Database version: 2384
      Windows 5.1.2600 Service PACK 2

      07/07/2009 12:13:56 AM
      mbam-log-2009-07-07 (00-13-56).txt

      Scan type: Full Scan (C:\|F:\|L:\|Z:\|)
      Objects scanned: 248359
      Time elapsed: 1 hour(s), 27 minute(s), 23 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 0
      Registry Values Infected: 0
      Registry Data Items Infected: 0
      Folders Infected: 0
      Files Infected: 0

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      (No malicious items detected)

      Registry Values Infected:
      (No malicious items detected)

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      (No malicious items detected)

      Files Infected:
      (No malicious items detected)


      -----
      Windows can't find "Combo-Fix". Another way to uninstall?Go to C:\Combo-Fix and delet ethe entire folder. Also delete the Qoobox folder.

      Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop.

      Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

      * XP users Double click on dds to run it.
      * If your antivirus or firewall try to block DDS then please allow it to run.
      * When finished DDS will open two (2) logs.

      1) DDS.txt
      2) Attach.txt

      * Save both logs to your desktop.
      * Please copy and paste the entire contents of both logs in your next reply.

      Note: DDS will instruct you to post the Attach.txt log as an attachment.
      Please just post it as you would any other log by copy and pasting it into the reply.

      -------
      DDS (Ver_09-06-26.01) - NTFSx86
      Run by justin at 16:52:04.15 on 07/07/2009
      Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_13
      Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.991.311 [GMT -7:00]


      ============== Running Processes ===============

      C:\WINDOWS\system32\svchost -k DcomLaunch
      svchost.exe
      C:\WINDOWS\System32\svchost.exe -k netsvcs
      C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
      svchost.exe
      svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      svchost.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Common Files\Mediafour\iPod\M4iPodWPDService.exe
      C:\Program Files\Network Associates\VirusScan\Mcshield.exe
      C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
      C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
      C:\WINDOWS\system32\IoctlSvc.exe
      C:\Program Files\Sprint\Sierra Wireless\Sprint PCS CONNECTION Manager\SPCSUtilityService.exe
      C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
      C:\WINDOWS\System32\svchost.exe -k imgsvc
      C:\Program Files\Airlink101\AWLH4030\WLService.exe
      C:\Program Files\Airlink101\AWLH4030\WLanCfgAG.exe
      C:\Program Files\Viewpoint\Common\ViewpointService.exe
      C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
      C:\Program Files\VIA\RAID\raid_tool.exe
      C:\WINDOWS\system32\VTTimer.exe
      C:\WINDOWS\system32\VTtrayp.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\WINDOWS\Logi_MwX.Exe
      C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
      C:\WINDOWS\system32\hphmon04.exe
      C:\Program Files\Mediafour\XPlay 3\XPlay.exe
      C:\Program Files\Unlocker\UnlockerAssistant.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
      C:\Program Files\Hewlett-Packard\AiO\hp officejet g series\Bin\hpoavn07.exe
      C:\Program Files\Launchy\Launchy.exe
      C:\Program Files\Logitech\SetPoint\SetPoint.exe
      C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
      C:\Program Files\VirtuaWin\VirtuaWin.exe
      C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
      C:\WINDOWS\system32\hpoipm07.exe
      C:\Program Files\VirtuaWin\modules\WinList.exe
      C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
      C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Sprint\Sierra Wireless\Sprint PCS Connection Manager\SPCSCM.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Documents and Settings\justin\Desktop\dds.com

      ============== Pseudo HJT Report ===============

      uStart Page = hxxp://my.yahoo.com/index.html
      BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
      BHO: Mediafour XPlay Explorer notifications: {4907c0ad-874d-44d9-b13e-7b0a4d8b9d3e} - c:\program files\mediafour\xplay 3\XPBHO.DLL
      BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
      BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
      BHO: Google Gears Helper: {e0fefe40-fbf9-42ae-ba58-794ca7e3fb53} - c:\program files\google\google gears\internet explorer\0.5.23.0\gears.dll
      BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
      uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
      uRun: [Google Update] "c:\documents and settings\justin\local settings\application data\google\update\GoogleUpdate.exe" /c
      mRun: [ShStatEXE] "c:\program files\network associates\virusscan\SHSTAT.EXE" /STANDALONE
      mRun: [McAfeeUpdaterUI] "c:\program files\network associates\common framework\UpdaterUI.exe" /StartedFromRunKey
      mRun: [RaidTool] c:\program files\via\raid\raid_tool.exe
      mRun: [VTTimer] VTTimer.exe
      mRun: [VTTrayp] VTtrayp.exe
      mRun: [SoundMan] SOUNDMAN.EXE
      mRun: [Logitech Utility] Logi_MwX.Exe
      mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
      mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
      mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe
      mRun: [HPHmon04] c:\windows\system32\hphmon04.exe
      mRun: [{914C5BF8-EEDD-4F3A-A8BE-34EE71CF1B29}] "c:\program files\mediafour\xplay 3\XPlay.exe"
      mRun: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
      mRun: [NeroFilterCheck] c:\program files\common files\nero\lib\NeroCheck.exe
      mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
      mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
      mRun: [UnlockerAssistant] "c:\program files\unlocker\UnlockerAssistant.exe"
      mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
      mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
      mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
      StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpaiod~1.lnk - c:\program files\hewlett-packard\aio\hp officejet g series\bin\hpoavn07.exe
      StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\launchy.lnk - c:\program files\launchy\Launchy.exe
      StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
      StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\virtua~1.lnk - c:\program files\virtuawin\VirtuaWin.exe
      IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
      IE: {F4430FE8-2638-42e5-B849-800749B94EED} - c:\program files\partygaming.net\partypokernet\RunPF.exe
      IE: {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - {0B4350D1-055F-47A3-B112-5F2F2B0D6F08} - c:\program files\google\google gears\internet explorer\0.5.23.0\gears.dll
      IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
      IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
      Trusted Zone: turbotax.com
      DPF: {00000055-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/fhg.CAB
      DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
      DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
      DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
      DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
      DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
      DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
      TCP: {A315D4DD-5828-447F-BB9F-2F1F4CFD6E9C} = 68.28.50.91 68.28.58.92
      Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
      Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
      Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
      SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
      SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
      SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL

      ================= FIREFOX ===================

      FF - ProfilePath - c:\docume~1\justin\applic~1\mozilla\firefox\profiles\2iky4cir.default\
      FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/|https://mail.google.com/mail/?nsr=0&zx=1x6pno7em8jhx&shva=1#inbox/11d75484357f61b2
      FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=chrff-brandt_off&type=000123X001US&p=
      FF - component: c:\documents and settings\justin\application data\mozilla\firefox\profiles\2iky4cir.default\extensions\{62760fd6-b943-48c9-ab09-f99c6fe96088}\platform\winnt\components\EbayAccessService.dll
      FF - component: c:\documents and settings\justin\application data\mozilla\firefox\profiles\2iky4cir.default\extensions\{62760fd6-b943-48c9-ab09-f99c6fe96088}\platform\winnt\components\EbayFormSubmitObserver.dll
      FF - component: c:\program files\google\google gears\firefox\components\gears.dll
      FF - plugin: c:\documents and settings\justin\application data\mozilla\plugins\npgoogletalk.dll
      FF - plugin: c:\documents and settings\justin\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll
      FF - plugin: c:\program files\google\update\1.2.145.5\npGoogleOneClick8.dll
      FF - plugin: c:\program files\google\update\1.2.183.7\npGoogleOneClick8.dll
      FF - plugin: c:\program files\mozilla firefox\plugins\npmusicn.dll
      FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
      FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
      FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
      FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
      FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
      FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
      FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

      ---- FIREFOX POLICIES ----
      FF - user.js: network.http.max-persistent-connections-per-server - 4
      FF - user.js: content.max.tokenizing.time - 200000
      FF - user.js: content.notify.interval - 100000
      FF - user.js: content.switch.threshold - 650000
      FF - user.js: nglayout.initialpaint.delay - 300
      FF - user.js: browser.tabs.tabMinWidth - 125

      ============= SERVICES / DRIVERS ===============

      R0 MDFSYSNT;MacDrive file system driver;c:\windows\system32\drivers\MDFSYSNT.SYS [2008-10-24 293632]
      R1 CbFs;CbFs;c:\windows\system32\drivers\cbfs.sys [2009-2-22 136744]
      R1 NaiAvTdi1;NaiAvTdi1;c:\windows\system32\drivers\mvstdi5x.sys [2006-1-25 58048]
      R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2006-10-10 5632]
      R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2007-2-27 32256]
      R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2009-1-7 10384]
      R2 M4iPodWPDService;M4iPodWPDService;c:\program files\common files\mediafour\ipod\M4iPodWPDService.exe [2008-10-6 211456]
      R2 McShield;Network Associates McShield;c:\program files\network associates\virusscan\Mcshield.exe [2004-9-22 221191]
      R2 McTaskManager;Network Associates Task Manager;c:\program files\network associates\virusscan\VsTskMgr.exe [2004-9-22 28672]
      R2 Super G Wireless Cardbus Service;Super G Wireless Cardbus Adapter Service;c:\program files\airlink101\awlh4030\WLService.exe [2006-2-19 49152]
      R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-1-25 24652]
      R3 NaiAvFilter1;NaiAvFilter1;c:\windows\system32\drivers\naiavf5x.sys [2006-1-25 108256]
      R3 USBNET;Instant Wireless USB Network Adapter ver.2.6 Driver;c:\windows\system32\drivers\vnetusbl.sys [2006-3-11 107648]
      S2 gupdate1c9e5f3fd5fd1fe;Google Update Service (gupdate1c9e5f3fd5fd1fe);c:\program files\google\update\GoogleUpdate.exe [2009-6-5 133104]
      S2 McAfeeFramework;McAfee Framework Service;c:\program files\network associates\common framework\FrameworkService.exe [2006-1-25 102463]
      S3 PsSdk30;PsSdk30;\??\c:\windows\system32\drivers\pssdk30.drv --> c:\windows\system32\drivers\PsSdk30.drv [?]
      S3 PTDUBus;PANTECH UM175 Composite Device Driver ;c:\windows\system32\drivers\PTDUBus.sys [2009-2-1 29824]
      S3 PTDUMdm;PANTECH UM175 Drivers;c:\windows\system32\drivers\PTDUMdm.sys [2009-2-1 41344]
      S3 PTDUVsp;PANTECH UM175 Diagnostic Port;c:\windows\system32\drivers\PTDUVsp.sys [2009-2-1 39936]
      S3 PTDUWWAN;PANTECH UM175 WWAN Driver;c:\windows\system32\drivers\PTDUWWAN.sys [2009-2-1 59776]
      S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2006-2-16 4096]

      =============== Created Last 30 ================

      2009-07-06 17:37--d-----C:\32788R22FWJFW.0.tmp
      2009-07-06 16:12388,608a-------c:\windows\system32\cmd.execf
      2009-07-06 14:43a-dshr--C:\cmdcons
      2009-07-06 14:42161,792a-------c:\windows\SWREG.exe
      2009-07-06 14:42155,136a-------c:\windows\PEV.exe
      2009-07-06 14:4298,816a-------c:\windows\sed.exe
      2009-07-06 14:41388,608a-------c:\windows\system32\CF21703.exe
      2009-07-05 15:42--d-----c:\program files\CCleaner
      2009-07-01 16:53--d-----c:\program files\Trend Micro
      2009-06-26 15:31--d-----c:\docume~1\justin\applic~1\VirtuaWin
      2009-06-26 15:31--d-----c:\program files\VirtuaWin
      2009-06-25 22:00--d-----c:\docume~1\justin\applic~1\Launchy
      2009-06-25 22:00--d-----c:\program files\Launchy
      2009-06-24 14:26--d-----c:\program files\DVD-Cloner Platinum
      2009-06-20 00:37--d-----c:\program files\Pod to PC
      2009-06-18 22:04--d-----c:\program files\DVDFab 6
      2009-06-17 12:11--d-----c:\docume~1\justin\applic~1\GrabIt
      2009-06-12 22:20--d-----c:\program files\Western Digital Technologies
      2009-06-12 00:24--d-----c:\program files\WBFS
      2009-06-09 21:02--d-----c:\program files\AMT
      2009-06-09 09:30--d-----c:\program files\iTunes

      ==================== Find3M ====================

      2009-06-25 21:5447,360a-------c:\docume~1\justin\applic~1\pcouffin.sys
      2009-06-17 11:2738,160a-------c:\windows\system32\drivers\mbamswissarmy.sys
      2009-06-17 11:2719,096a-------c:\windows\system32\drivers\mbam.sys
      2009-06-05 11:422,060,288a-------c:\windows\system32\usbaaplrc.dll
      2009-06-05 11:4239,424a-------c:\windows\system32\drivers\usbaapl.sys
      2009-06-01 01:31359,808a-------c:\windows\system32\drivers\TCPIP.SYS
      2009-05-28 22:0347,360a-------c:\windows\system32\drivers\pcouffin.sys
      2009-05-21 15:12359,808a-------c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL
      2007-07-30 16:3332,968ac------c:\docume~1\justin\applic~1\GDIPFONTCACHEV1.DAT
      2006-05-03 22:20454a-------c:\program files\Shortcut to games.lnk
      2006-02-19 17:371,117,491ac------c:\program files\DVD_Shrink_v3[1].2_Install.exe

      ============= FINISH: 16:53:11.75 ===============




      UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
      IF REQUESTED, ZIP IT UP & ATTACH IT

      DDS (Ver_09-06-26.01)

      Microsoft Windows XP Professional
      Boot Device: \Device\HarddiskVolume1
      Install DATE: 10/19/2005 4:44:32 AM
      System Uptime: 07/07/2009 4:38:31 PM (0 hours ago)

      Motherboard: ECS | | P4M800-M7
      Processor: Intel(R) Pentium(R) 4 CPU 2.66GHz | CPU 1 | 2659/133mhz

      ==== Disk Partitions =========================


      ==== Installed Programs ======================

      µTorrent
      Adobe AIR
      Adobe Anchor Service CS3
      Adobe Asset Services CS3
      Adobe Bridge CS3
      Adobe Bridge Start Meeting
      Adobe Camera Raw 4.0
      Adobe CMaps
      Adobe Color - Photoshop Specific
      Adobe Color Common Settings
      Adobe Color EU Extra Settings
      Adobe Color JA Extra Settings
      Adobe Color NA Recommended Settings
      Adobe Default Language CS3
      Adobe Device Central CS3
      Adobe ExtendScript Toolkit 2
      Adobe Flash Player 10 Plugin
      Adobe Fonts All
      Adobe Help Viewer CS3
      Adobe Linguistics CS3
      Adobe PDF Library Files
      Adobe Photoshop CS3
      Adobe Reader 8.1.1
      Adobe Reader 9.1
      Adobe Setup
      Adobe Shockwave Player
      Adobe Stock Photos CS3
      Adobe Type Support
      Adobe Update Manager CS3
      Adobe Version Cue CS3 Client
      Adobe WinSoft Linguistics Plugin
      Adobe XMP Panels CS3
      Airlink101 SuperG Wireless Adapter
      AnswerWorks 4.0 Runtime - English
      Apple Mobile Device Support
      Apple Software Update
      Audacity 1.2.6
      Bonjour
      C-Media WDM Audio Driver
      CCleaner (remove only)
      CDDRV_Installer
      CloneDVD2
      DVD Decrypter (Remove Only)
      DVD Shrink 3.2
      DVDFab 6.0.1.0 (May 15, 2009)
      Google Gears
      Google Talk Plugin
      Google Update Helper
      HandBrake 0.9.3
      HijackThis 2.0.2
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
      Hotfix for Windows XP (KB926239)
      hp officejet g series
      ImagXpress
      Instant Wireless USB Adapter
      iTunes
      Java Adapter for Mobile
      Java(TM) 6 Update 13
      Java(TM) 6 Update 5
      Java(TM) 6 Update 7
      KhalInstallWrapper
      Launchy 2.1.2
      LG PC Suite II
      LG USB Modem driver
      Logitech iTouch Software
      Logitech MouseWare 9.79
      Logitech Resource Center
      Logitech SetPoint
      Machinist2DLL
      Macromedia Flash Player 8
      Malwarebytes' Anti-Malware
      McAfee VirusScan Enterprise
      Merriam-Webster
      Metafile Companion
      Microsoft .NET Framework 2.0 Service Pack 2
      Microsoft .NET Framework 3.0 Service Pack 2
      Microsoft .NET Framework 3.5 SP1
      Microsoft Compression Client Pack 1.0 for Windows XP
      Microsoft Office Access MUI (English) 2007
      Microsoft Office Access Setup Metadata MUI (English) 2007
      Microsoft Office Enterprise 2007
      Microsoft Office Excel MUI (English) 2007
      Microsoft Office Groove MUI (English) 2007
      Microsoft Office Groove Setup Metadata MUI (English) 2007
      Microsoft Office InfoPath MUI (English) 2007
      Microsoft Office OneNote MUI (English) 2007
      Microsoft Office Outlook MUI (English) 2007
      Microsoft Office PowerPoint MUI (English) 2007
      Microsoft Office Proof (English) 2007
      Microsoft Office Proof (French) 2007
      Microsoft Office Proof (Spanish) 2007
      Microsoft Office Proofing (English) 2007
      Microsoft Office Publisher MUI (English) 2007
      Microsoft Office Shared MUI (English) 2007
      Microsoft Office Shared Setup Metadata MUI (English) 2007
      Microsoft Office Word MUI (English) 2007
      Microsoft Silverlight
      Microsoft Software Update for Web Folders (English) 12
      Microsoft User-Mode Driver Framework Feature Pack 1.7
      Microsoft Visual C++ 2005 Redistributable
      Microsoft XML Parser
      Mozilla Firefox (3.0.11)
      MSXML 4.0 SP2 (KB936181)
      MSXML 6.0 Parser (KB933579)
      MSXML4 Parser
      Musicnotes Player V1.23.0
      Nero 8 Ultra Edition HD
      neroxml
      overland
      PAC7302
      PANTECH UM175 Driver
      PartitionMagic
      PartyPokerNet
      PDF Settings
      Photosmart 130,230,7150,7345,7350,7550 (Remove only)
      Platform
      Pod to PC 2.6
      PowerDVD
      PowerISO
      PowerQuest PartitionMagic 8.0
      QuickTime
      Real Alternative 1.9.0
      Realtek AC'97 Audio
      Revo Uninstaller 1.80
      Rosetta Stone 2.1.5.1A
      Security Update for Windows Media Player (KB911564)
      Security Update for Windows Media Player 6.4 (KB925398)
      Security Update for Windows Media Player 9 (KB911565)
      Security Update for Windows Media Player 9 (KB917734)
      Security Update for Windows Media Player 9 (KB936782)
      Security Update for Windows XP (KB890046)
      Security Update for Windows XP (KB893066)
      Security Update for Windows XP (KB893756)
      Security Update for Windows XP (KB896358)
      Security Update for Windows XP (KB896422)
      Security Update for Windows XP (KB896423)
      Security Update for Windows XP (KB896424)
      Security Update for Windows XP (KB896428)
      Security Update for Windows XP (KB899587)
      Security Update for Windows XP (KB899589)
      Security Update for Windows XP (KB899591)
      Security Update for Windows XP (KB900725)
      Security Update for Windows XP (KB901017)
      Security Update for Windows XP (KB901214)
      Security Update for Windows XP (KB902400)
      Security Update for Windows XP (KB904706)
      Security Update for Windows XP (KB905414)
      Security Update for Windows XP (KB905749)
      Security Update for Windows XP (KB905915)
      Security Update for Windows XP (KB908519)
      Security Update for Windows XP (KB908531)
      Security Update for Windows XP (KB911280)
      Security Update for Windows XP (KB911562)
      Security Update for Windows XP (KB911567)
      Security Update for Windows XP (KB911927)
      Security Update for Windows XP (KB912812)
      Security Update for Windows XP (KB912919)
      Security Update for Windows XP (KB913446)
      Security Update for Windows XP (KB913580)
      Security Update for Windows XP (KB914388)
      Security Update for Windows XP (KB914389)
      Security Update for Windows XP (KB916281)
      Security Update for Windows XP (KB917159)
      Security Update for Windows XP (KB917344)
      Security Update for Windows XP (KB917422)
      Security Update for Windows XP (KB917953)
      Security Update for Windows XP (KB918118)
      Security Update for Windows XP (KB918439)
      Security Update for Windows XP (KB918899)
      Security Update for Windows XP (KB919007)
      Security Update for Windows XP (KB920213)
      Security Update for Windows XP (KB920214)
      Security Update for Windows XP (KB920670)
      Security Update for Windows XP (KB920683)
      Security Update for Windows XP (KB920685)
      Security Update for Windows XP (KB921398)
      Security Update for Windows XP (KB921503)
      Security Update for Windows XP (KB921883)
      Security Update for Windows XP (KB922616)
      Security Update for Windows XP (KB922819)
      Security Update for Windows XP (KB923191)
      Security Update for Windows XP (KB923414)
      Security Update for Windows XP (KB923689)
      Security Update for Windows XP (KB923980)
      Security Update for Windows XP (KB924270)
      Security Update for Windows XP (KB924496)
      Security Update for Windows XP (KB924667)
      Security Update for Windows XP (KB925902)
      Security Update for Windows XP (KB926255)
      Security Update for Windows XP (KB926436)
      Security Update for Windows XP (KB927779)
      Security Update for Windows XP (KB927802)
      Security Update for Windows XP (KB928255)
      Security Update for Windows XP (KB928843)
      Security Update for Windows XP (KB929123)
      Security Update for Windows XP (KB930178)
      Security Update for Windows XP (KB931261)
      Security Update for Windows XP (KB931784)
      Security Update for Windows XP (KB932168)
      Security Update for Windows XP (KB935839)
      Security Update for Windows XP (KB935840)
      Security Update for Windows XP (KB936021)
      Security Update for Windows XP (KB937143)
      Security Update for Windows XP (KB938127)
      Security Update for Windows XP (KB938829)
      Sibelius Scorch (Firefox, Opera, Netscape only)
      Sprint Mobile Broadband (Sierra)
      Spybot - Search & Destroy
      SUPERAntiSpyware Free Edition
      Sure Cuts A Lot 1.016
      TI Connect 1.6
      Total Video Converter 3.10
      TotalAudioConverter
      TuneUp Utilities 2008
      Ultra Video Converter 4.4.0329
      Universal Media Player
      Unlocker 1.8.7
      Update for Windows XP (KB894391)
      Update for Windows XP (KB898461)
      Update for Windows XP (KB900485)
      Update for Windows XP (KB910437)
      Update for Windows XP (KB916595)
      Update for Windows XP (KB920872)
      Update for Windows XP (KB922582)
      Update for Windows XP (KB927891)
      Update for Windows XP (KB930916)
      Update for Windows XP (KB931836)
      Update for Windows XP (KB936357)
      Update for Windows XP (KB938828)
      VCRedistSetup
      VIA Platform Device Manager
      VIA Rhine-Family Fast Ethernet Adapter
      VIA/S3G Display Driver
      Viewpoint Manager (Remove Only)
      Viewpoint Media Player
      VirtuaWin v4.0.1
      VZAccess Manager
      WBFS Manager 3.0
      WD Diagnostics
      WebFldrs XP
      Windows Genuine Advantage v1.3.0254.0
      Windows Imaging Component
      Windows Installer 3.1 (KB893803)
      Windows Media Format 11 runtime
      Windows Media Player 11
      Windows Media Player Firefox Plugin
      Windows Rights Management Client Backwards Compatibility SP2
      Windows Rights Management Client with Service Pack 2
      Windows XP Hotfix - KB873339
      Windows XP Hotfix - KB885250
      Windows XP Hotfix - KB885835
      Windows XP Hotfix - KB885836
      Windows XP Hotfix - KB885884
      Windows XP Hotfix - KB886185
      Windows XP Hotfix - KB887472
      Windows XP Hotfix - KB887742
      Windows XP Hotfix - KB888113
      Windows XP Hotfix - KB888302
      Windows XP Hotfix - KB890859
      Windows XP Hotfix - KB891781
      Windows XP Service Pack 2
      WinRAR archiver
      XML Paper Specification Shared Components Pack 1.0
      XPlay 3

      ==== End Of File ===========================

      Go to Add or Remove Programs and uninstall:

      • Viewpoint Manager (Remove Only)
      • Viewpoint Media Player
      .
      ----------

      Download OTM by OldTimer to your desktop.

      Note: If you are running on Vista, right-click on OTM.exe and choose Run As Administrator.

      * Save it to your Desktop.
      * Double-click OTM.exe to run it.
      * Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy)

      Code: [Select]:Processes
      explorer.exe

      :services
      Viewpoint Manager Service

      :reg

      :files
      C:\Program Files\Viewpoint
      C:\32788R22FWJFW.0.tmp
      c:\windows\system32\cmd.execf
      C:\cmdcons
      c:\windows\SWREG.exe
      c:\windows\PEV.exe
      c:\windows\sed.exe
      c:\windows\system32\CF21703.exe

      :Commands
      [purity]
      [emptytemp]
      [start explorer]
      [Reboot]

      * Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
      * Click the red Moveit! button.
      * Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
      Close OTM

      Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes. If not, reboot anyway.

      ----------

      Use the ESET Online Antivirus Scanner

      This scanner requires Internet Explorer

      1. Check the box next to YES, I accept the Terms of Use.
      2. Click Start
      3. When asked, allow the activex control to install
      4. Click Start
      5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked.
      6. Click Scan
      7. Wait for the scan to finish
      8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
      9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.All processes killed
      ========== PROCESSES ==========
      No active process named explorer.exe was found!
      ========== SERVICES/DRIVERS ==========
      Service\Driver Viewpoint Manager Service not found.
      Service\Driver Viewpoint Manager Service not found.
      ========== REGISTRY ==========
      ========== FILES ==========
      C:\Program Files\Viewpoint\Viewpoint Media Player\NewComponents moved successfully.
      C:\Program Files\Viewpoint\Viewpoint Media Player\DownloadedComponents\VMgr_Win moved successfully.
      C:\Program Files\Viewpoint\Viewpoint Media Player\DownloadedComponents\AxMetaStream_Win moved successfully.
      C:\Program Files\Viewpoint\Viewpoint Media Player\DownloadedComponents moved successfully.
      C:\Program Files\Viewpoint\Viewpoint Media Player\Components moved successfully.
      C:\Program Files\Viewpoint\Viewpoint Media Player moved successfully.
      C:\Program Files\Viewpoint moved successfully.
      C:\32788R22FWJFW.0.tmp moved successfully.
      c:\windows\system32\cmd.execf moved successfully.
      Folder move failed. C:\cmdcons\SYSTEM32 scheduled to be moved on reboot.
      Folder move failed. C:\cmdcons scheduled to be moved on reboot.
      c:\windows\SWREG.exe moved successfully.
      c:\windows\PEV.exe moved successfully.
      c:\windows\sed.exe moved successfully.
      c:\windows\system32\CF21703.exe moved successfully.
      ========== COMMANDS ==========

      [EMPTYTEMP]

      User: Administrator
      ->TEMP folder emptied: 0 bytes
      ->Temporary Internet Files folder emptied: 67 bytes

      User: All Users

      User: Application Data

      User: Default User
      ->Temp folder emptied: 0 bytes
      ->Temporary Internet Files folder emptied: 67 bytes

      User: Guest
      ->Temp folder emptied: 0 bytes
      ->Temporary Internet Files folder emptied: 67 bytes
      ->Java cache emptied: 39940 bytes

      User: justin
      ->Temp folder emptied: 64185532 bytes
      ->Temporary Internet Files folder emptied: 2420411 bytes
      ->Java cache emptied: 5035 bytes
      ->FireFox cache emptied: 617298332 bytes

      User: LocalService
      ->Temp folder emptied: 0 bytes
      File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
      ->Temporary Internet Files folder emptied: 49286 bytes

      User: NetworkService
      ->Temp folder emptied: 0 bytes
      ->Temporary Internet Files folder emptied: 482310 bytes

      %systemdrive% .tmp files removed: 0 bytes
      %systemroot% .tmp files removed: 0 bytes
      %systemroot%\System32 .tmp files removed: 2775569 bytes
      File delete failed. C:\WINDOWS\temp\WFV3.tmp scheduled to be deleted on reboot.
      Windows Temp folder emptied: 52650027 bytes
      RecycleBin emptied: 25711730 bytes

      Total Files Cleaned = 730.15 mb


      OTM by OldTimer - Version 3.0.0.4 log created on 07072009_174324

      Files moved on Reboot...
      C:\cmdcons\SYSTEM32 moved successfully.
      Folder move failed. C:\cmdcons scheduled to be moved on reboot.
      File C:\WINDOWS\temp\WFV3.tmp not found!

      Registry entries deleted on Reboot...


      [emailprotected] as CAB hook log:
      OnlineScanner.ocx - registred OK
      # version=6
      # iexplore.exe=6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
      # OnlineScanner.ocx=1.0.0.5886
      # api_version=3.0.2
      # EOSSerial=095d76691df05a4498bd7a723464f1fc
      # end=finished
      # remove_checked=true
      # archives_checked=true
      # unwanted_checked=true
      # unsafe_checked=true
      # antistealth_checked=true
      # utc_time=2009-07-08 08:56:23
      # local_time=2009-07-08 01:56:23 (-0700, US Mountain Standard Time)
      # country="United States"
      # lang=1033
      # osver=5.1.2600 NT Service Pack 2
      # scanned=141587
      # found=6
      # cleaned=6
      # scan_time=26750
      C:\Documents and Settings\justin\Application Data\Symantec\Layouts\Norton AntiVirus\15.0\SymAllLanguages\NAVCD_RETAIL\20070826\CDStart.exea variant of Win32/Injector.FN trojan (deleted - quarantined)00000000000000000000000000000000C
      C:\Documents and Settings\justin\Application Data\Symantec\Layouts\Norton AntiVirus\15.0\SymAllLanguages\NAVCD_RETAIL\20070826\Setup.exea variant of Win32/Injector.FN trojan (deleted - quarantined)00000000000000000000000000000000C
      C:\Documents and Settings\justin\Desktop\16gb\Nero 8.3.2.1 Ultra Edition HD -Eng-\Nero-8.3.2.1_eng.exeWin32/Toolbar.AskSBar application (deleted - quarantined)00000000000000000000000000000000C
      C:\Program Files\BitLord\Downloads\FruityLoops Studio.rarprobably a variant of Win32/Delf trojan (deleted - quarantined)00000000000000000000000000000000C
      C:\Program Files\BitLord\Downloads\Nero 8.3.2.1 Ultra Edition HD -Eng-\Nero-8.3.2.1_eng.exeWin32/Toolbar.AskSBar application (deleted - quarantined)00000000000000000000000000000000C
      C:\Program Files\BitLord\Downloads\Rosetta\Rosetta Application.isoWin32/HackTool.Patcher.A application (deleted - quarantined)00000000000000000000000000000000C

      1. Double click OTM to launch it.
      Vista users right click and choose Run As Administrator
      2. Click on the CleanUp! button.
      3. OTM will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
      4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
      5. When finished exit out of OTM.

      ----------

      How is the computer running now?My computer is free from all known symptoms! Thank you, thank you, a million times thank you. Ironically, your name doesn't suit the good that you have done and are doing, nevertheless please continue to help those of us who need it.

      Any recommendations to keep my computer protected and up to par?Use the Secunia Software Inspector to check for out of date software.
      • Click Start Now
      • Check the box next to Enable thorough system inspection.
      • Click Start
      • Allow the scan to finish and scroll down to see if any updates are needed.
      • Update anything listed.
      .
      ----------

      Go to Microsoft Windows Update and get all critical updates.

      ----------

      I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

      SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also STOP certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
      * Using SpywareBlaster to protect your computer from Spyware and Malware
      * If you don't know what ActiveX controls are, see here

      Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

      Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
      3857.

      Solve : Problem with USB sticks after infection?

      Answer»

      Hello,

      My friend has asked me to look at 2 USB sticks that are misbehaving after having an infected file on them. Apparently her virus checker detected the file when the stick was inserted into the desktop & "dealt with it". (I'm not sure exactly what the infection was, other than it was some form of trojan and attached to file f://xlk9.com. I'm also not sure whether the virus checker deleted, cleaned or renamed the file).

      The problem is that when you now double click on the sticks in either windows explorer or my computer, one asks you to choose the program to open the file and the other says "access denied". However if you RIGHT click and choose "explore", the files on the sticks are displayed no problem. I would really appreciate some advice please on the best way of proceeding. Thanks 1. Download Flash Disinfector and save it ot your Desktop.
      2. After downloading, double-click on Flash_Disinfector to run it.
      3. Just follow the prompts and CONTINUE until it begin scanning.
      4. If asked to insert your flash drive or any removable device including USB Pen Drive and Memory Stick, please do so.
      5. It will scan removable drives, WAIT for the scan to finish. Done.Thanks mate I'll give that a go shortly and report back. Thanks for your help. Both sticks are WORKING fine now. Great. Good luck.

      3858.

      Solve : Still infected??

      Answer»

      So I ran Kaspersky and deleted some trojans that came up. Then ran the other steps in order including Super Anti-spyware and Malwarebytes and Hijack this. Internet Explorer is still infected or hijacked or whatever because google search results pull up BS sites and not what I am looking for. Also many of my programs all of a sudden can't find the liscence installed or won't open up at all. I am wondering if a virus or trojan has done irreversable damage to my computer? Anyways here are the specs and logs:

      XP Pro SP3
      Intel Core 2 Duo E8400 @ 3.0 Ghz, 3.01 GHz
      4 GB of RAM
      Nvidia 9800 GTX+ 512MB of RAM
      162 GB remaining on C:



      SUPERAntiSpyware Scan Log
      http://www.superantispyware.com

      Generated 07/05/2009 at 04:06 AM

      Application Version : 4.26.1004

      Core Rules Database Version : 3972
      Trace Rules Database Version: 1912

      Scan type : Complete Scan
      Total Scan Time : 00:25:59

      Memory items scanned : 522
      Memory threats detected : 0
      Registry items scanned : 5567
      Registry threats detected : 0
      File items scanned : 25110
      File threats detected : 19

      Adware.Tracking Cookie
      C:\Documents and Settings\Bingo\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bingo\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bingo\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bingo\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bingo\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bingo\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bingo\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bingo\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bingo\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bingo\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Bingo\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bingo\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bingo\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bingo\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bingo\Cookies\[emailprotected][2].txt

      Trojan.Agent/Gen
      C:\WINDOWS\system32\lowsec\local.ds
      C:\WINDOWS\system32\lowsec\user.ds
      C:\WINDOWS\system32\lowsec\user.ds.lll
      C:\WINDOWS\system32\lowsec



      Malwarebytes' Anti-Malware 1.36
      Database version: 2029
      Windows 5.1.2600 Service Pack 3

      7/5/2009 5:08:02 AM
      mbam-log-2009-07-05 (05-08-02).txt

      Scan type: Full Scan (C:\|E:\|)
      Objects scanned: 258467
      Time elapsed: 50 minute(s), 13 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 0
      Registry Values Infected: 0
      Registry Data Items Infected: 0
      Folders Infected: 0
      Files Infected: 0

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      (No malicious items detected)

      Registry Values Infected:
      (No malicious items detected)

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      (No malicious items detected)

      Files Infected:
      (No malicious items detected)




      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 3:20:54 AM, on 7/5/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
      C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
      C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE
      C:\Program Files\Microsoft IntelliPoint\ipoint.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\uTorrent\uTorrent.exe
      C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrobat_sl.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\Wacom_Tablet.exe
      C:\WINDOWS\system32\WTablet\Wacom_TabletUser.exe
      C:\WINDOWS\system32\Wacom_Tablet.exe
      C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\WINDOWS\System32\alg.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Documents and Settings\Bingo\Desktop\ZBrush3.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/accounts/ServiceLogin?service=mail&passive=true&rm=false&continue=http%3A%2F%2Fmail.google.com%2Fmail%2F%3Fui%3Dhtml%26zy%3Dl&bsv=zpwhtygjntrz&scc=1&ltmpl=default&ltmplcache=2
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe" //mailurl:mailto:bubblegi @ net-member.com
      F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
      O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
      O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
      O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
      O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
      O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
      O4 - HKLM\..\Run: [EPSON Stylus CX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P26 "EPSON Stylus CX3800 Series" /O6 "USB001" /M "Stylus CX3800"
      O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
      O4 - HKLM\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" /OM
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe"
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
      O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
      O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
      O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
      O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
      O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
      O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
      O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1240467475984
      O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
      O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
      O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
      O23 - Service: TabletServiceWacom - Wacom Technology, Corp. - C:\WINDOWS\system32\Wacom_Tablet.exe

      --
      End of file - 11034 bytes

      Thanks a lot.



      So I just ran superantispyware again today and I have NEW infections that require a reboot to remove, yet they never seem to fully go away. Kaspersky is sitting there twittling its thumbs. I am seriously thinking I got Virut from p2p............sigh

      Karma is a b$tch I guess; shouldn't have been on those sites.....

      Before I try backing up some files I cannot lose (to DVD mind you and I will scan them on a clean computer) and reinstall windows can anyone confirm from my logs that I indeed have Virut or is there another solution?

      Thanks in advance. Post the new SUPERAntiSpyware log.

      Also post these DDS logs.

      Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop.

      Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

      * XP users Double click on dds to run it.
      * If your antivirus or firewall try to block DDS then please allow it to run.
      * When finished DDS will open two (2) logs.

      1) DDS.txt
      2) Attach.txt

      * Save both logs to your desktop.
      * Please copy and paste the entire contents of both logs in your next reply.

      Note: DDS will instruct you to post the Attach.txt log as an attachment.
      Please just post it as you would any other log by copy and pasting it into the reply.I did not save the log from this can unfortunately, so I hope this helps. I just did a re-scan and nothing else pops up other than tracking cookies. These were the quarantined items from the scan that produced trojans:

      Trojan.Agent/Gen

      C:\WINDOWS\system32\lowsec
      C:\WINDOWS\system32\lowsec\local.ds
      C:\WINDOWS\system32\lowsec\user.ds

      Trojan.Agent/Gen-SDRA

      C:\WINDOWS\SYSTEM32\SDRA64.EXE

      Trojan.FakeAlert-GenA

      C:\DOCUMENTS AND SETTINGS\BINGO\LOCAL SETTINGS\TEMP\C.EXE




      UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
      IF REQUESTED, ZIP IT UP & ATTACH IT

      DDS (Ver_09-06-26.01)

      Microsoft Windows XP Professional
      Boot Device: \Device\HarddiskVolume1
      Install Date: 4/11/2009 12:45:00 PM
      System Uptime: 7/6/2009 3:32:59 PM (1 hours ago)

      Motherboard: ASUSTeK Computer INC. | | P5KPL-CM
      Processor: Intel Pentium III Xeon processor | Socket 775 | 3010/333mhz

      ==== DISK Partitions =========================

      C: is FIXED (NTFS) - 466 GiB total, 163.3 GiB free.
      D: is CDROM ()
      E: is FIXED (NTFS) - 233 GiB total, 94.257 GiB free.

      ==== Disabled Device Manager Items =============

      Class GUID: {4D36E96F-E325-11CE-BFC1-08002BE10318}
      Description: Microsoft PS/2 Port Mouse (IntelliPoint)
      Device ID: ACPI\PNP0F03\4&2C575ACB&0
      Manufacturer: Microsoft
      Name: Microsoft PS/2 Port Mouse (IntelliPoint)
      PNP Device ID: ACPI\PNP0F03\4&2C575ACB&0
      Service: i8042prt

      ==== System Restore Points ===================

      RP1: 4/11/2009 12:47:12 PM - System Checkpoint
      RP2: 4/11/2009 2:07:19 PM - Installed Platform
      RP3: 4/11/2009 2:09:13 PM - Installed Atheros Communications Inc.(R) AR8121/AR8113/AR8114 Gi
      RP4: 4/11/2009 2:17:50 PM - Configured Platform
      RP5: 4/11/2009 2:44:31 PM - Installed Windows NLSDownlevelMapping.
      RP6: 4/11/2009 2:44:45 PM - Installed Windows IDNMitigationAPIs.
      RP7: 4/11/2009 2:45:41 PM - Installed Windows Internet Explorer 7.
      RP8: 4/11/2009 2:56:35 PM - Installed Windows Media Format 9 Series Runtime Setup
      RP9: 4/12/2009 1:37:01 AM - Software Distribution Service 3.0
      RP10: 4/12/2009 1:42:25 AM - Installed Kaspersky Anti-Virus 2009.
      RP11: 4/12/2009 2:11:30 AM - Software Distribution Service 3.0
      RP12: 4/12/2009 12:34:31 PM - Installed DirectX
      RP13: 4/12/2009 12:35:32 PM - Installed Maya 2008
      RP14: 4/13/2009 1:42:46 AM - Installed iTunes
      RP15: 4/14/2009 1:29:11 PM - System Checkpoint
      RP16: 4/15/2009 12:51:58 AM - Printer Driver Adobe PDF Converter Installed
      RP17: 4/16/2009 12:21:39 AM - Software Distribution Service 3.0
      RP18: 4/16/2009 7:37:33 PM - Software Distribution Service 3.0
      RP19: 4/16/2009 10:19:54 PM - Removed Microsoft IntelliPoint 6.3
      RP20: 4/17/2009 11:44:43 AM - Software Distribution Service 3.0
      RP21: 4/18/2009 1:37:58 PM - System Checkpoint
      RP22: 4/19/2009 3:35:05 PM - System Checkpoint
      RP23: 4/20/2009 4:41:31 PM - Installed EPSON EasyPrintModule
      RP24: 4/20/2009 4:42:03 PM - Installed PhotoImpression
      RP25: 4/22/2009 1:36:06 PM - System Checkpoint
      RP26: 4/22/2009 4:12:27 PM - Installed SUPERAntiSpyware Free Edition
      RP27: 4/22/2009 4:15:29 PM - Installed Java(TM) 6 Update 13
      RP28: 4/22/2009 11:10:25 PM - Installed Microsoft Office Standard Edition 2003
      RP29: 4/23/2009 11:32:00 AM - Software Distribution Service 3.0
      RP30: 4/24/2009 12:08:09 PM - System Checkpoint
      RP31: 4/24/2009 12:38:12 PM - Software Distribution Service 3.0
      RP32: 4/24/2009 2:44:09 PM - Installed ZBrush3.
      RP33: 4/24/2009 2:44:34 PM - Installed Microsoft Visual C++ 2005 Redistributable
      RP34: 4/25/2009 12:57:37 PM - Installed DirectX
      RP35: 4/25/2009 12:58:23 PM - Installed Maya 2009
      RP36: 4/25/2009 1:01:58 PM - Installed Maya 2009 Documentation (en_US)
      RP37: 4/25/2009 2:49:54 PM - Removed Microsoft IntelliPoint 6.3
      RP38: 4/27/2009 1:48:35 PM - System Checkpoint
      RP39: 4/28/2009 2:19:51 PM - System Checkpoint
      RP40: 4/29/2009 1:10:42 PM - Software Distribution Service 3.0
      RP41: 4/30/2009 5:30:28 PM - Installed Uniblue DriverScanner v1.0
      RP42: 4/30/2009 5:53:41 PM - Installed IEEE 802.11g Wireless Cardbus/PCI Adapter
      RP43: 4/30/2009 6:04:59 PM - Configured IEEE 802.11g Wireless Cardbus/PCI Adapter
      RP44: 5/2/2009 12:48:42 PM - System Checkpoint
      RP45: 5/4/2009 1:28:04 PM - Installed ZAppLink.
      RP46: 5/7/2009 2:44:06 AM - System Checkpoint
      RP47: 5/8/2009 10:11:36 PM - System Checkpoint
      RP48: 5/10/2009 11:59:54 AM - System Checkpoint
      RP49: 5/12/2009 2:01:19 PM - Installed Windows Media Format 9 Series Runtime Setup
      RP50: 5/12/2009 10:52:28 PM - Installed REALTEK RTL8185 Wireless LAN Driver and Utility
      RP51: 5/13/2009 6:47:19 AM - Software Distribution Service 3.0
      RP52: 5/14/2009 1:35:39 AM - Installed REALTEK RTL8185 Wireless LAN Driver and Utility
      RP53: 5/15/2009 10:43:51 AM - System Checkpoint
      RP54: 5/16/2009 2:34:11 PM - System Checkpoint
      RP55: 5/17/2009 3:31:21 PM - System Checkpoint
      RP56: 5/19/2009 7:47:06 PM - System Checkpoint
      RP57: 5/20/2009 8:33:20 PM - System Checkpoint
      RP58: 5/22/2009 2:30:18 PM - System Checkpoint
      RP59: 5/24/2009 12:55:31 PM - System Checkpoint
      RP60: 5/25/2009 5:10:14 PM - System Checkpoint
      RP61: 5/26/2009 5:23:07 PM - System Checkpoint
      RP62: 5/27/2009 10:33:15 PM - System Checkpoint
      RP63: 5/30/2009 2:47:07 AM - System Checkpoint
      RP64: 5/31/2009 3:34:58 AM - System Checkpoint
      RP65: 6/1/2009 1:12:36 PM - System Checkpoint
      RP66: 6/2/2009 4:23:15 PM - System Checkpoint
      RP67: 6/3/2009 5:00:31 PM - System Checkpoint
      RP68: 6/4/2009 11:23:01 AM - Software Distribution Service 3.0
      RP69: 6/5/2009 11:49:23 AM - System Checkpoint
      RP70: 6/6/2009 2:11:55 PM - System Checkpoint
      RP71: 6/8/2009 3:56:46 AM - System Checkpoint
      RP72: 6/8/2009 11:16:44 PM - Installed DirectX
      RP73: 6/8/2009 11:17:16 PM - Removed Microsoft Visual C++ 2005 Redistributable
      RP74: 6/8/2009 11:17:29 PM - Installed Microsoft Visual C++ 2005 Redistributable
      RP75: 6/9/2009 4:05:15 PM - Installed Java(TM) 6 Update 14
      RP76: 6/11/2009 3:33:41 AM - Software Distribution Service 3.0
      RP77: 6/12/2009 2:06:54 PM - System Checkpoint
      RP78: 6/14/2009 2:48:58 AM - System Checkpoint
      RP79: 6/14/2009 1:41:24 PM - Installed Adobe After Effects 7.0
      RP80: 6/15/2009 10:39:57 PM - System Checkpoint
      RP81: 6/17/2009 2:30:19 AM - System Checkpoint
      RP82: 6/17/2009 3:42:01 PM - Installed Unreal Tournament 3
      RP83: 6/17/2009 9:50:22 PM - Installed Unreal Tournament 3
      RP84: 6/18/2009 10:01:02 PM - System Checkpoint
      RP85: 6/19/2009 10:50:42 PM - System Checkpoint
      RP86: 6/20/2009 1:08:38 PM - Installed TRENDnet TEW-421PC/TEW-423PI 802.11g Wireless Cardbus/
      RP87: 6/25/2009 5:55:32 PM - System Checkpoint
      RP88: 6/26/2009 12:36:39 PM - Configured TRENDnet TEW-421PC/TEW-423PI 802.11g Wireless Cardbus
      RP89: 6/27/2009 7:33:46 PM - System Checkpoint
      RP90: 6/28/2009 3:53:06 AM - Installed YouSendIt Express
      RP91: 6/30/2009 4:36:49 PM - System Checkpoint
      RP92: 7/3/2009 6:27:45 AM - System Checkpoint
      RP93: 7/3/2009 12:50:37 PM - Software Distribution Service 3.0
      RP94: 7/4/2009 1:25:18 PM - System Checkpoint

      ==== Installed Programs ======================

      7-Zip 4.65
      Add or Remove Adobe Creative Suite 3 Design Premium
      Adobe Acrobat 8 Professional
      Adobe After Effects 7.0
      Adobe Anchor Service CS3
      Adobe Asset Services CS3
      Adobe Bridge CS3
      Adobe Bridge Start Meeting
      Adobe BridgeTalk Plugin CS3
      Adobe Camera Raw 4.0
      Adobe CMaps
      Adobe Color - Photoshop Specific
      Adobe Color Common Settings
      Adobe Color EU Extra Settings
      Adobe Color JA Extra Settings
      Adobe Color NA Recommended Settings
      Adobe Creative Suite 3 Design Premium
      Adobe Default Language CS3
      Adobe Device Central CS3
      Adobe Dreamweaver CS3
      Adobe ExtendScript Toolkit 2
      Adobe Extension Manager CS3
      Adobe Flash CS3
      Adobe Flash Player 10 ActiveX
      Adobe Flash Player 10 Plugin
      Adobe Flash Player 9 ActiveX
      Adobe Flash Video Encoder
      Adobe Fonts All
      Adobe Help Viewer CS3
      Adobe Illustrator CS3
      Adobe InDesign CS3
      Adobe InDesign CS3 Icon Handler
      Adobe Linguistics CS3
      Adobe MotionPicture Color Files
      Adobe PDF Library Files
      Adobe Photoshop CS3
      Adobe Setup
      Adobe SING CS3
      Adobe Stock Photos CS3
      Adobe Type Support
      Adobe Update Manager CS3
      Adobe Version Cue CS3 Client
      Adobe Version Cue CS3 Server
      Adobe WAS CS3
      Adobe WinSoft Linguistics Plugin
      Adobe XMP Panels CS3
      AHV content for Acrobat and Flash
      AoA Audio Extractor 1.0
      Apple Mobile Device Support
      Apple Software Update
      ArcSoft PhotoImpression 5
      Atheros Communications Inc.(R) AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver
      Audacity 1.2.6
      Autodesk DirectConnect 2.0
      Autodesk DirectConnect 2009
      AviSynth 2.5
      Bonjour
      CCleaner (remove only)
      DVD Decrypter (Remove Only)
      DVD Wizard Pro
      DVD Wizard Pro Bonus
      EPSON CX 3800 Guide
      EPSON Printer Software
      EPSON Scan
      Google Toolbar for Internet Explorer
      HijackThis 2.0.2
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
      Hotfix for Windows XP (KB952287)
      Hotfix for Windows XP (KB954550-v5)
      Hotfix for Windows XP (KB961118)
      iTunes
      Java(TM) 6 Update 14
      Jpeg Enhancer 1.8
      Kaspersky Anti-Virus 2009
      Malwarebytes' Anti-Malware
      Mass Effect
      Maya 2008
      Maya 2009
      Maya 2009 Documentation (en_US)
      Microsoft .NET Framework 2.0 Service Pack 2
      Microsoft .NET Framework 3.0 Service Pack 2
      Microsoft .NET Framework 3.5 SP1
      Microsoft Application Error Reporting
      Microsoft IntelliPoint 6.3
      Microsoft Internationalized DOMAIN Names Mitigation APIs
      Microsoft National Language Support Downlevel APIs
      Microsoft Office Standard Edition 2003
      Microsoft Silverlight
      Microsoft Visual C++ 2005 Redistributable
      Mozilla Firefox (3.0.11)
      mp4UI
      MSXML 4.0 SP2 (KB954430)
      MSXML 4.0 SP2 Parser and SDK
      Nero Digital
      Nero OEM
      NVIDIA Drivers
      NVIDIA PhysX
      OLYMPUS Master 2
      PDF Settings
      Platform
      PowerDVD
      PS3 Video 9 4.07
      QuickTime
      Replay AV 8
      Replay Converter 3
      Replay Media Catcher 3.02
      Replay Media Splitter 1.6.906
      Replay Music
      Replay Video Capture
      Security Update for Windows Internet Explorer 7 (KB938127-v2)
      Security Update for Windows Internet Explorer 7 (KB961260)
      Security Update for Windows Internet Explorer 7 (KB963027)
      Security Update for Windows Internet Explorer 8 (KB969897)
      Security Update for Windows Media Player (KB952069)
      Security Update for Windows XP (KB923561)
      Security Update for Windows XP (KB938464-v2)
      Security Update for Windows XP (KB946648)
      Security Update for Windows XP (KB950760)
      Security Update for Windows XP (KB950762)
      Security Update for Windows XP (KB950974)
      Security Update for Windows XP (KB951066)
      Security Update for Windows XP (KB951376-v2)
      Security Update for Windows XP (KB951698)
      Security Update for Windows XP (KB951748)
      Security Update for Windows XP (KB952004)
      Security Update for Windows XP (KB952954)
      Security Update for Windows XP (KB954459)
      Security Update for Windows XP (KB954600)
      Security Update for Windows XP (KB955069)
      Security Update for Windows XP (KB956572)
      Security Update for Windows XP (KB956802)
      Security Update for Windows XP (KB956803)
      Security Update for Windows XP (KB956841)
      Security Update for Windows XP (KB957097)
      Security Update for Windows XP (KB958644)
      Security Update for Windows XP (KB958687)
      Security Update for Windows XP (KB958690)
      Security Update for Windows XP (KB959426)
      Security Update for Windows XP (KB960225)
      Security Update for Windows XP (KB960715)
      Security Update for Windows XP (KB960803)
      Security Update for Windows XP (KB961373)
      Security Update for Windows XP (KB961501)
      Security Update for Windows XP (KB968537)
      Security Update for Windows XP (KB969898)
      Security Update for Windows XP (KB970238)
      Sentinel System Driver
      SpeedFan (remove only)
      SUPERAntiSpyware Free Edition
      System Requirements Lab
      Uniblue DriverScanner 2009
      Unreal Tournament 3
      Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
      Update for Windows Internet Explorer 8 (KB971180)
      Update for Windows XP (KB898461)
      Update for Windows XP (KB951978)
      Update for Windows XP (KB955839)
      Update for Windows XP (KB967715)
      VIA Platform Device Manager
      VLC media player 0.9.9
      Wacom Tablet
      WebFldrs XP
      Windows Genuine Advantage Notifications (KB905474)
      Windows Internet Explorer 7
      Windows Internet Explorer 8
      WinPcap 4.0
      YouSendIt Express
      ZAppLink
      ZBrush3

      ==== Event Viewer Messages From Past Week ========

      7/5/2009 4:09:05 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000243' while processing the file 'local.ds' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
      7/2/2009 12:58:14 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Beep Fips intelppm IPSec kl1 klbg KLIF MRxSmb NetBIOS NetBT RasAcd Rdbss SASDIFSV SASKUTIL Tcpip
      7/2/2009 12:58:14 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
      7/2/2009 12:58:14 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
      7/2/2009 12:58:14 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
      7/2/2009 12:58:14 PM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
      7/2/2009 12:58:14 PM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
      7/2/2009 12:57:57 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
      7/2/2009 12:57:47 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
      7/2/2009 12:50:18 PM, error: Service Control Manager [7031] - The Kaspersky Anti-Virus service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.
      7/2/2009 12:45:19 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Beep
      7/2/2009 12:45:16 PM, error: Service Control Manager [7000] - The Realtek EAPPkt Protocol service failed to start due to the following error: The system cannot find the file specified.
      7/2/2009 12:45:16 PM, error: Service Control Manager [7000] - The DS1410D service failed to start due to the following error: The system cannot find the file specified.
      7/2/2009 1:47:56 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
      7/2/2009 1:39:59 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
      7/2/2009 1:07:02 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
      7/1/2009 9:16:32 PM, warning: Windows File Protection [64008] - The protected system file c:\windows\system32\drivers\beep.sys could not be verified as valid because Windows File Protection is terminating. Use the SFC utility to verify the integrity of the file at a later time.

      ==== End Of File ===========================



      DDS (Ver_09-06-26.01) - NTFSx86
      Run by Bingo at 16:19:44.60 on Mon 07/06/2009
      Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_14
      Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3583.2840 [GMT -7:00]

      AV: Kaspersky Anti-Virus *On-access scanning enabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
      FW: Kaspersky Anti-Virus *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}

      ============== Running Processes ===============

      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\svchost -k DcomLaunch
      svchost.exe
      C:\WINDOWS\System32\svchost.exe -k netsvcs
      svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
      C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
      C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE
      C:\Program Files\Microsoft IntelliPoint\ipoint.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      svchost.exe
      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\WINDOWS\system32\svchost.exe -k imgsvc
      C:\WINDOWS\system32\Wacom_Tablet.exe
      C:\WINDOWS\system32\WTablet\Wacom_TabletUser.exe
      C:\WINDOWS\system32\Wacom_Tablet.exe
      C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      C:\Program Files\iPod\bin\iPodService.exe
      svchost
      C:\WINDOWS\System32\svchost.exe -k HTTPFilter
      C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Documents and Settings\Bingo\Local Settings\Temporary Internet Files\Content.IE5\DLAC1WI0\dds[1].com

      ============== Pseudo HJT Report ===============

      uStart Page = https://www.google.com/accounts/ServiceLogin?service=mail&passive=true&rm=false&continue=http%3A%2F%2Fmail.google.com%2Fmail%2F%3Fui%3Dhtml%26zy%3Dl&bsv=zpwhtygjntrz&scc=1&ltmpl=default&ltmplcache=2
      uInternet Connection Wizard,ShellNext = "c:\program files\outlook express\msimn.exe" //mailurl:mailto:[emailprotected]
      mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\sdra64.exe,
      BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
      BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky anti-virus 2009\ievkbd.dll
      BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
      BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
      BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
      BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
      BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
      BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
      TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
      EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
      uRun: [OM2_Monitor] "c:\program files\olympus\olympus master 2\MMonitor.exe"
      uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
      uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
      mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
      mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun
      mRun: [AVP] "c:\program files\kaspersky lab\kaspersky anti-virus 2009\avp.exe"
      mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe"
      mRun: []
      mRun: [Adobe_ID0EYTHM] c:\progra~1\common~1\adobe\adobev~1\server\bin\VERSIO~2.EXE
      mRun: [EPSON Stylus CX3800 Series] c:\windows\system32\spool\drivers\w32x86\3\E_FATIACA.EXE /P26 "EPSON Stylus CX3800 Series" /O6 "USB001" /M "Stylus CX3800"
      mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
      mRun: [OM2_Monitor] "c:\program files\olympus\olympus master 2\FirstStart.exe" /OM
      mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
      mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
      mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
      mRun: [nwiz] nwiz.exe /install
      mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
      mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
      StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-0000-7760-000000000003}\_SC_Acrobat.exe
      StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~2.lnk - c:\program files\adobe\acrobat 8.0\acrobat\AdobeCollabSync.exe
      uPolicies-system: EnableProfileQuota = 1 (0x1)
      IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
      IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
      IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
      IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
      IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
      IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
      IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
      IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
      IE: {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - {85E0B171-04FA-11D1-B7DA-00A0C90348D6} - c:\program files\kaspersky lab\kaspersky anti-virus 2009\SCIEPlgn.dll
      IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
      DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://support.microsoft.com/OAS/ActiveX/MSDcode.cab
      DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
      DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
      DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
      DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1240467475984
      DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
      DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
      DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
      DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
      Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
      Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
      Notify: klogon - c:\windows\system32\klogon.dll
      AppInit_DLLs: c:\progra~1\kasper~1\kasper~1\mzvkbd.dll,c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll
      SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

      ================= FIREFOX ===================

      FF - ProfilePath - c:\docume~1\bingo\applic~1\mozilla\firefox\profiles\xuba6wew.default\
      FF - component: c:\documents and settings\bingo\application data\mozilla\firefox\profiles\xuba6wew.default\extensions\{fcab6fdd-5585-425b-95c1-5ed856f3fd08}\components\nsCatcher.dll
      FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
      FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
      FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

      ============= SERVICES / DRIVERS ===============

      R0 kl1;Kl1;c:\windows\system32\drivers\kl1.sys [2008-7-21 121872]
      R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-1-29 33808]
      R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2009-4-12 213520]
      R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-3-23 9968]
      R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-3-23 72944]
      R2 AVP;Kaspersky Anti-Virus;c:\program files\kaspersky lab\kaspersky anti-virus 2009\avp.exe [2008-7-29 206088]
      R2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [2009-4-23 1373480]
      R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-4-30 24592]
      R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1e51x86.sys [2009-4-11 36864]
      R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-3-23 7408]
      R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-4-11 222976]
      S2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\eappkt.sys --> c:\windows\system32\drivers\EAPPkt.sys [?]
      S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-1-25 42000]

      =============== Created Last 30 ================

      2009-07-04 14:09--d-----c:\program files\Trend Micro
      2009-07-02 13:23--d-----c:\docume~1\bingo\applic~1\Malwarebytes
      2009-07-02 13:06664a-------c:\windows\system32\d3d9caps.dat
      2009-07-01 21:1378,336a-------c:\documents and settings\bingo\nah_thfe.exe
      2009-06-30 01:53--d-----c:\docume~1\bingo\applic~1\SUPERAntiSpyware.com
      2009-06-29 19:2338a-------c:\windows\AviSplitter.INI
      2009-06-29 04:4557,398ac------c:\windows\system32\dllcache\imjpdadm.exe
      2009-06-28 03:54--d-----c:\program files\Replay Media Splitter
      2009-06-28 03:53--d-----c:\program files\YouSendIt
      2009-06-28 03:52--d-----c:\program files\WinPcap
      2009-06-28 03:51--d-----c:\windows\Replay Converter 3
      2009-06-28 03:51--d-----c:\program files\Replay Converter 3
      2009-06-28 03:51737,280a-------c:\windows\iun6002.exe
      2009-06-28 03:50--d-----c:\program files\Replay AV 8
      2009-06-28 03:49--d-----c:\windows\Replay Music
      2009-06-28 03:49--d-----c:\program files\Replay Music 3
      2009-06-28 03:48--d-----c:\windows\Replay Video Capture
      2009-06-28 03:48--d-----c:\program files\Replay Video Capture
      2009-06-28 03:22--d-----c:\program files\mp4UI
      2009-06-28 01:25237,568a-------c:\windows\system32\rmc_rtspdl.dll
      2009-06-28 01:25156,672a-------c:\windows\system32\rmc_fixasf.exe
      2009-06-28 01:24323,584a-------c:\windows\system32\AUDIOGENIE2.DLL
      2009-06-28 01:24--d-----c:\windows\Replay Media Catcher
      2009-06-28 01:24--d-----c:\program files\Replay Media Catcher
      2009-06-27 22:46--d-----c:\docume~1\bingo\applic~1\Red Kawa
      2009-06-27 15:42--dsh---c:\documents and settings\bingo\IECompatCache
      2009-06-26 15:04--d-----c:\docume~1\bingo\applic~1\uTorrent
      2009-06-26 14:45--dsh---c:\documents and settings\bingo\PrivacIE
      2009-06-26 14:33--d-----c:\docume~1\bingo\applic~1\WTablet
      2009-06-26 14:33--dsh---c:\documents and settings\bingo\IETldCache
      2009-06-26 14:33--d-----c:\documents and settings\Bingo
      2009-06-26 12:35610,816a----r--c:\windows\system32\drivers\BCMWL5.SYS
      2009-06-20 13:1641a-------C:\WLANCUGINA.TEXT
      2009-06-20 13:1020a-------C:\GINA.TEXT
      2009-06-20 13:07--d-----c:\program files\TRENDnet
      2009-06-17 21:50--d-----c:\program files\Unreal Tournament 3
      2009-06-17 21:501,358,192a-------c:\windows\system32\D3DCompiler_35.dll
      2009-06-17 21:50444,776a-------c:\windows\system32\d3dx10_35.dll
      2009-06-17 21:503,727,720a-------c:\windows\system32\d3dx9_35.dll
      2009-06-17 21:501,124,720a-------c:\windows\system32\D3DCompiler_34.dll
      2009-06-17 21:50443,752a-------c:\windows\system32\d3dx10_34.dll
      2009-06-17 21:501,123,696a-------c:\windows\system32\D3DCompiler_33.dll
      2009-06-17 21:50443,752a-------c:\windows\system32\d3dx10_33.dll
      2009-06-17 21:503,495,784a-------c:\windows\system32\d3dx9_33.dll
      2009-06-17 21:50--d-----c:\windows\45235788142C44BE8A4DDDE9A84492E5.TMP
      2009-06-14 13:41--d-----c:\program files\common files\Adobe Systems Shared
      2009-06-14 13:41282,176a-------c:\windows\system32\ae700main.dat
      2009-06-10 20:00246,272-c------c:\windows\system32\dllcache\ieproxy.dll
      2009-06-10 20:0012,800-c------c:\windows\system32\dllcache\xpshims.dll
      2009-06-09 00:45107,888a-------c:\windows\system32\CmdLineExt.dll
      2009-06-09 00:37--d-----c:\windows\1C4551A64743409391E41477CD655043.TMP
      2009-06-08 23:172,414,360a-------c:\windows\system32\d3dx9_31.dll
      2009-06-08 23:17237,848a-------c:\windows\system32\xactengine2_4.dll
      2009-06-08 23:17236,824a-------c:\windows\system32\xactengine2_3.dll
      2009-06-08 23:1781,768a-------c:\windows\system32\xinput1_3.dll
      2009-06-08 23:1762,744a-------c:\windows\system32\xinput1_2.dll
      2009-06-08 23:1715,128a-------c:\windows\system32\x3daudio1_1.dll
      2009-06-08 23:162,297,552a-------c:\windows\system32\d3dx9_26.dll
      2009-06-08 23:16--d-----c:\program files\common files\BioWare
      2009-06-08 23:02--d-----c:\program files\Mass Effect

      ==================== Find3M ====================

      2009-07-06 15:3215,081,504a--sh---c:\windows\system32\drivers\fidbox.dat
      2009-07-06 15:32876,576a--sh---c:\windows\system32\drivers\fidbox2.dat
      2009-07-06 15:32121,000a--sh---c:\windows\system32\drivers\fidbox.idx
      2009-07-06 15:325,124a--sh---c:\windows\system32\drivers\fidbox2.idx
      2009-05-21 11:33410,984a-------c:\windows\system32\deploytk.dll
      2009-05-20 12:56105,395a-------c:\windows\system32\drivers\klin.dat
      2009-05-20 12:5694,643a-------c:\windows\system32\drivers\klick.dat
      2009-05-12 22:15915,456a-------c:\windows\system32\wininet.dll
      2009-05-07 08:32345,600a-------c:\windows\system32\localspl.dll
      2009-05-01 00:311,657,376a-------c:\windows\system32\nwiz.exe
      2009-05-01 00:31449,056a-------c:\windows\system32\nvappbar.exe
      2009-05-01 00:31436,768a-------c:\windows\system32\keystone.exe
      2009-05-01 00:311,724,416a-------c:\windows\system32\nvwdmcpl.dll
      2009-05-01 00:311,507,328a-------c:\windows\system32\nview.dll
      2009-05-01 00:311,101,824a-------c:\windows\system32\nvwimg.dll
      2009-05-01 00:31466,944a-------c:\windows\system32\nvshell.dll
      2009-04-30 22:029,994,240a-------c:\windows\system32\nvoglnt.dll
      2009-04-30 22:025,896,320a-------c:\windows\system32\nv4_disp.dll
      2009-04-30 22:021,720,320a-------c:\windows\system32\nvcuda.dll
      2009-04-30 22:021,579,630a-------c:\windows\system32\nvdata.bin
      2009-04-30 22:021,314,816a-------c:\windows\system32\nvcuvenc.dll
      2009-04-30 22:02806,912a-------c:\windows\system32\nvapi.dll
      2009-04-30 22:02663,552a-------c:\windows\system32\nvcuvid.dll
      2009-04-30 22:02457,248a-------c:\windows\system32\nvudisp.exe
      2009-04-30 22:02143,360a-------c:\windows\system32\nvcodins.dll
      2009-04-30 22:02143,360a-------c:\windows\system32\nvcod.dll
      2009-04-27 00:42457,248a-------c:\windows\system32\NVUNINST.EXE
      2009-04-17 05:261,847,168a-------c:\windows\system32\win32k.sys
      2009-04-15 07:51585,216a-------c:\windows\system32\rpcrt4.dll
      2009-04-11 13:0286,327a-------c:\windows\pchealth\helpctr\offlinecache\index.dat
      2009-04-11 12:4021,640a-------c:\windows\system32\emptyregdb.dat

      ============= FINISH: 16:20:08.57 ===============
      Quote

      Trojan.Agent/Gen

      C:\WINDOWS\system32\lowsec
      C:\WINDOWS\system32\lowsec\local.ds
      C:\WINDOWS\system32\lowsec\user.ds

      This is from Koobface, better known as the Faceboof trojan. Be careful what you click on from facebook.

      ---

      Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

      Link #1
      Link #2

      **Note: It is important that it is saved directly to your Desktop

      DO NOT run it yet!

      Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

      Delete these files/folders, as follows:

      1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
      It must be Notepad, not Wordpad.
      2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

      Code: [Select]KillAll::

      DDS::
      mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\sdra64.exe,
      mRun: [<NO NAME>]
      IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

      3. Go to the Notepad window and click Edit > Paste
      4. Then click File > Save
      5. Name the file CFScript.txt - Save the file to your Desktop
      6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



      ComboFix will begin to execute, just follow the prompts.
      After reboot (in case it asks to reboot), it will produce a log for you.
      Post that log (Combofix.txt) in your next reply.

      Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze
      By the way thank you so much for doing this!!! People like you give me hope for our species.

      ComboFix 09-07-07.A2 - Bingo 07/07/2009 21:08.1 - NTFSx86
      Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3583.3100 [GMT -7:00]
      Running from: c:\documents and settings\Bingo\Desktop\ComboFix.exe
      Command switches used :: c:\documents and settings\Bingo\Desktop\CFScript.txt
      AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
      FW: Kaspersky Anti-Virus *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
      * Created a new restore point
      .

      ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      c:\documents and settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\SUPERAntiSpyware Free Edition.lnk
      c:\documents and settings\Bingo\Application Data\Microsoft\Internet Explorer\Quick Launch\SUPERAntiSpyware Free Edition.lnk
      c:\documents and settings\Bingo\Application Data\wiaserva.log
      c:\documents and settings\Bingo\nah_thfe.exe
      c:\program files\messenger\msmsgs.exe
      c:\recycler\S-1-5-21-1844237615-527237240-1801674531-1003
      c:\windows\system32\wbem\proquota.exe

      c:\windows\system32\proquota.exe was missing
      Restored copy from - c:\system volume information\_restore{9E1D7E7C-893B-4E75-AF62-DF487307B03E}\RP91\A0019641.exe

      .
      ((((((((((((((((((((((((( Files Created from 2009-06-08 to 2009-07-08 )))))))))))))))))))))))))))))))
      .

      2009-07-04 21:09 . 2009-07-04 21:09--------d-----w-c:\program files\Trend Micro
      2009-07-02 20:23 . 2009-07-02 20:23--------d-----w-c:\documents and settings\Bingo\Application Data\Malwarebytes
      2009-07-02 20:06 . 2009-07-02 20:06664----a-w-c:\windows\system32\d3d9caps.dat
      2009-06-30 08:53 . 2009-07-08 02:26117760----a-w-c:\documents and settings\Bingo\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
      2009-06-30 08:53 . 2009-06-30 08:53--------d-----w-c:\documents and settings\Bingo\Application Data\SUPERAntiSpyware.com
      2009-06-29 11:45 . 2008-04-14 12:0057398-c--a-w-c:\windows\system32\dllcache\imjpdadm.exe
      2009-06-29 10:20 . 2009-06-23 20:5257344----a-w-c:\documents and settings\Bingo\Application Data\Mozilla\Firefox\Profiles\xuba6wew.default\extensions\{FCAB6FDD-5585-425b-95C1-5ED856F3FD08}\components\nsCatcher.dll
      2009-06-28 10:54 . 2009-06-28 10:54--------d-----w-c:\program files\Replay Media Splitter
      2009-06-28 10:53 . 2009-06-28 10:53--------d-----w-c:\program files\YouSendIt
      2009-06-28 10:52 . 2009-06-28 10:52--------d-----w-c:\program files\WinPcap
      2009-06-28 10:51 . 2009-06-28 10:51--------d-----w-c:\windows\Replay Converter 3
      2009-06-28 10:51 . 2009-06-28 10:53--------d-----w-c:\program files\Replay Converter 3
      2009-06-28 10:51 . 2009-06-28 10:54737280----a-w-c:\windows\iun6002.exe
      2009-06-28 10:50 . 2009-06-28 10:51--------d-----w-c:\program files\Replay AV 8
      2009-06-28 10:49 . 2009-06-28 10:49--------d-----w-c:\program files\Replay Music 3
      2009-06-28 10:49 . 2009-06-28 10:49--------d-----w-c:\windows\Replay Music
      2009-06-28 10:48 . 2009-07-03 21:24--------d-----w-c:\program files\Replay Video Capture
      2009-06-28 10:48 . 2009-06-28 10:48--------d-----w-c:\windows\Replay Video Capture
      2009-06-28 10:22 . 2009-06-28 10:22--------d-----w-c:\program files\mp4UI
      2009-06-28 10:09 . 2009-06-28 10:09--------d-----w-c:\documents and settings\Bingo\Application Data\Ahead
      2009-06-28 08:25 . 2009-06-28 10:48237568----a-w-c:\windows\system32\rmc_rtspdl.dll
      2009-06-28 08:25 . 2009-06-28 10:48156672----a-w-c:\windows\system32\rmc_fixasf.exe
      2009-06-28 08:24 . 2009-06-28 10:47323584----a-w-c:\windows\system32\AUDIOGENIE2.DLL
      2009-06-28 08:24 . 2009-06-28 10:48--------d-----w-c:\program files\Replay Media Catcher
      2009-06-28 08:24 . 2009-06-28 08:24--------d-----w-c:\windows\Replay Media Catcher
      2009-06-28 05:46 . 2009-06-28 05:46--------d-----w-c:\documents and settings\Bingo\Application Data\Red Kawa
      2009-06-27 22:42 . 2009-06-27 22:42--------d-sh--w-c:\documents and settings\Bingo\IECompatCache
      2009-06-27 06:43 . 2009-07-01 19:31--------d-----w-c:\documents and settings\Bingo\Application Data\Apple Computer
      2009-06-27 05:51 . 2009-06-29 12:2729208----a-w-c:\documents and settings\Bingo\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
      2009-06-26 22:04 . 2009-07-06 23:12--------d-----w-c:\documents and settings\Bingo\Application Data\uTorrent
      2009-06-26 22:01 . 2009-06-26 22:01--------d-----w-c:\documents and settings\Bingo\Application Data\vlc
      2009-06-26 21:46 . 2009-06-26 21:46--------d-----w-c:\documents and settings\Bingo\Local Settings\Application Data\Mozilla
      2009-06-26 21:45 . 2009-06-26 21:45--------d-sh--w-c:\documents and settings\Bingo\PrivacIE
      2009-06-26 19:35 . 2006-11-30 08:54610816----a-r-c:\windows\system32\drivers\BCMWL5.SYS
      2009-06-26 17:00 . 2009-06-23 20:5257344----a-w-c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\c3zi4u2k.default\extensions\{FCAB6FDD-5585-425b-95C1-5ED856F3FD08}\components\nsCatcher.dll
      2009-06-20 20:16 . 2009-06-20 20:16--------d-sh--w-c:\windows\system32\config\systemprofile\IETldCache
      2009-06-20 20:07 . 2009-06-20 20:07--------d-----w-c:\program files\TRENDnet
      2009-06-20 10:34 . 2009-06-26 19:38--------d-----w-c:\documents and settings\Administrator\Application Data\uTorrent
      2009-06-18 05:01 . 2009-06-18 05:01--------d-----w-c:\documents and settings\Administrator\Application Data\InstallShield Installation Information
      2009-06-18 05:01 . 2009-06-18 04:50331776----a-w-c:\documents and settings\Administrator\Application Data\InstallShield Installation Information\{BFA90209-7AFF-4DB6-8E4B-E57305751AD7}\SetupUT3.exe
      2009-06-18 05:01 . 2007-10-24 11:474147031----a-w-c:\documents and settings\Administrator\Application Data\InstallShield Installation Information\{BFA90209-7AFF-4DB6-8E4B-E57305751AD7}\ISSetup.dll
      2009-06-18 04:50 . 2009-06-18 04:50--------d-----w-c:\program files\Unreal Tournament 3
      2009-06-18 04:50 . 2007-07-20 01:14444776----a-w-c:\windows\system32\d3dx10_35.dll
      2009-06-18 04:50 . 2007-07-20 01:141358192----a-w-c:\windows\system32\D3DCompiler_35.dll
      2009-06-18 04:50 . 2007-07-20 01:143727720----a-w-c:\windows\system32\d3dx9_35.dll
      2009-06-18 04:50 . 2007-05-16 23:45443752----a-w-c:\windows\system32\d3dx10_34.dll
      2009-06-18 04:50 . 2007-05-16 23:451124720----a-w-c:\windows\system32\D3DCompiler_34.dll
      2009-06-18 04:50 . 2007-03-15 23:57443752----a-w-c:\windows\system32\d3dx10_33.dll
      2009-06-18 04:50 . 2007-03-12 23:421123696----a-w-c:\windows\system32\D3DCompiler_33.dll
      2009-06-18 04:50 . 2007-03-12 23:423495784----a-w-c:\windows\system32\d3dx9_33.dll
      2009-06-18 04:50 . 2009-06-18 04:50--------d-----w-c:\windows\45235788142C44BE8A4DDDE9A84492E5.TMP
      2009-06-15 23:16 . 2009-06-15 23:16--------d-sh--w-c:\documents and settings\LocalService\IETldCache
      2009-06-14 20:42 . 2009-06-14 20:42--------d-----w-c:\documents and settings\All Users\Application Data\Adobe Systems
      2009-06-14 20:41 . 2009-06-14 20:41--------d-----w-c:\program files\Common Files\Adobe Systems Shared
      2009-06-14 20:41 . 2009-06-14 20:41282176----a-w-c:\windows\system32\ae700main.dat
      2009-06-11 03:00 . 2009-04-30 21:2212800-c----w-c:\windows\system32\dllcache\xpshims.dll
      2009-06-11 03:00 . 2009-04-30 21:22246272-c----w-c:\windows\system32\dllcache\ieproxy.dll
      2009-06-09 23:04 . 2009-06-09 23:04152576----a-w-c:\documents and settings\Administrator\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
      2009-06-09 07:45 . 2009-06-09 07:45--------d--h--r-c:\documents and settings\Administrator\Application Data\SecuROM
      2009-06-09 07:45 . 2009-06-09 07:45107888----a-w-c:\windows\system32\CmdLineExt.dll
      2009-06-09 07:37 . 2009-06-09 07:37--------d-----w-c:\windows\1C4551A64743409391E41477CD655043.TMP
      2009-06-09 06:17 . 2007-04-05 01:5381768----a-w-c:\windows\system32\xinput1_3.dll
      2009-06-09 06:17 . 2006-09-28 23:05237848----a-w-c:\windows\system32\xactengine2_4.dll
      2009-06-09 06:17 . 2006-09-28 23:052414360----a-w-c:\windows\system32\d3dx9_31.dll
      2009-06-09 06:17 . 2006-09-28 23:0315128----a-w-c:\windows\system32\x3daudio1_1.dll
      2009-06-09 06:17 . 2006-07-28 16:30236824----a-w-c:\windows\system32\xactengine2_3.dll
      2009-06-09 06:17 . 2006-07-28 16:3062744----a-w-c:\windows\system32\xinput1_2.dll

      .
      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2009-07-08 04:12 . 2009-04-12 08:42884768--sha-w-c:\windows\system32\drivers\fidbox2.dat
      2009-07-08 04:12 . 2009-04-12 08:425152--sha-w-c:\windows\system32\drivers\fidbox2.idx
      2009-07-08 04:12 . 2009-04-12 08:42--------d-----w-c:\documents and settings\All Users\Application Data\Kaspersky Lab
      2009-07-08 04:10 . 2009-04-12 08:4215081504--sha-w-c:\windows\system32\drivers\fidbox.dat
      2009-07-08 04:10 . 2009-04-12 08:42121000--sha-w-c:\windows\system32\drivers\fidbox.idx
      2009-06-26 21:33 . 2009-06-26 21:33--------d-----w-c:\documents and settings\Bingo\Application Data\WTablet
      2009-06-26 21:33 . 2009-05-13 13:02--------d-----w-c:\documents and settings\LocalService\Application Data\WTablet
      2009-06-26 19:38 . 2009-04-23 09:37--------d-----w-c:\documents and settings\Administrator\Application Data\WTablet
      2009-06-26 19:35 . 2009-04-22 23:14117760----a-w-c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
      2009-06-21 08:27 . 2009-04-22 23:12--------d-----w-c:\program files\SUPERAntiSpyware
      2009-06-20 20:14 . 2009-05-13 05:52--------d-----w-c:\program files\REALTEK
      2009-06-20 20:10 . 2009-04-11 21:08--------d--h--w-c:\program files\InstallShield Installation Information
      2009-06-18 04:50 . 2009-04-11 21:38--------d-----w-c:\program files\Common Files\Wise Installation Wizard
      2009-06-15 12:32 . 2009-04-15 08:08--------d-----w-c:\documents and settings\All Users\Application Data\FLEXnet
      2009-06-14 20:41 . 2009-04-15 07:22--------d-----w-c:\program files\Common Files\Adobe
      2009-06-09 23:05 . 2009-04-22 23:15--------d-----w-c:\program files\Java
      2009-06-09 08:02 . 2009-06-09 06:16--------d-----w-c:\program files\Common Files\BioWare
      2009-06-09 07:30 . 2009-04-17 00:33--------d-----w-c:\program files\SystemRequirementsLab
      2009-06-09 06:17 . 2009-06-09 06:02--------d-----w-c:\program files\Mass Effect
      2009-06-05 20:19 . 2009-06-05 20:19--------d-----w-c:\program files\iTunes
      2009-06-05 20:19 . 2009-06-05 20:19--------d-----w-c:\program files\iPod
      2009-06-05 20:19 . 2009-04-13 08:41--------d-----w-c:\program files\Common Files\Apple
      2009-06-05 20:18 . 2009-04-13 08:42--------d-----w-c:\program files\QuickTime
      2009-06-05 20:17 . 2009-04-13 08:42--------d-----w-c:\documents and settings\All Users\Application Data\Apple Computer
      2009-06-05 20:14 . 2009-06-05 20:1475048----a-w-c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
      2009-06-05 10:54 . 2009-06-05 08:03--------d---a-w-c:\documents and settings\All Users\Application Data\TEMP
      2009-06-05 08:11 . 2009-06-05 08:03--------d-----w-c:\program files\AoA Audio Extractor
      2009-06-05 07:38 . 2009-06-05 07:38--------d-----w-c:\program files\Audacity
      2009-06-03 22:33 . 2009-06-03 22:33--------d-----w-c:\program files\DVD Decrypter
      2009-06-03 22:30 . 2009-06-03 22:30--------d-----w-c:\program files\DVD Wizard Pro
      2009-05-28 21:37 . 2009-05-28 21:37--------d-----w-c:\program files\Microsoft Silverlight
      2009-05-21 18:33 . 2009-04-22 23:15410984----a-w-c:\windows\system32\deploytk.dll
      2009-05-20 19:56 . 2009-04-12 08:4394643----a-w-c:\windows\system32\drivers\klick.dat
      2009-05-20 19:56 . 2009-04-12 08:43105395----a-w-c:\windows\system32\drivers\klin.dat
      2009-05-13 07:43 . 2009-04-11 21:4821856----a-w-c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
      2009-05-13 05:52 . 2009-05-13 05:52--------d-----w-c:\documents and settings\Administrator\Application Data\InstallShield
      2009-05-13 05:15 . 2008-04-14 12:00915456----a-w-c:\windows\system32\wininet.dll
      2009-05-12 21:00 . 2009-05-12 21:00--------d-----w-c:\program files\OLYMPUS
      2009-05-12 21:00 . 2009-05-12 21:00--------d-----w-c:\program files\MSXML 4.0
      2009-05-07 15:32 . 2008-04-14 12:00345600----a-w-c:\windows\system32\localspl.dll
      2009-05-01 07:31 . 2009-05-01 07:311657376----a-w-c:\windows\system32\nwiz.exe
      2009-05-01 07:31 . 2009-05-01 07:31449056----a-w-c:\windows\system32\nvappbar.exe
      2009-05-01 07:31 . 2009-05-01 07:31436768----a-w-c:\windows\system32\keystone.exe
      2009-05-01 07:31 . 2009-05-01 07:31466944----a-w-c:\windows\system32\nvshell.dll
      2009-05-01 07:31 . 2009-05-01 07:311724416----a-w-c:\windows\system32\nvwdmcpl.dll
      2009-05-01 07:31 . 2009-05-01 07:311507328----a-w-c:\windows\system32\nview.dll
      2009-05-01 07:31 . 2009-05-01 07:311101824----a-w-c:\windows\system32\nvwimg.dll
      2009-05-01 05:02 . 2009-05-01 05:021579630----a-w-c:\windows\system32\nvdata.bin
      2009-05-01 05:02 . 2009-05-01 05:021314816----a-w-c:\windows\system32\nvcuvenc.dll
      2009-05-01 05:02 . 2009-04-11 21:37457248----a-w-c:\windows\system32\nvudisp.exe
      2009-05-01 05:02 . 2009-03-27 17:03663552----a-w-c:\windows\system32\nvcuvid.dll
      2009-05-01 05:02 . 2008-11-12 06:549994240----a-w-c:\windows\system32\nvoglnt.dll
      2009-05-01 05:02 . 2008-11-12 06:54806912----a-w-c:\windows\system32\nvapi.dll
      2009-05-01 05:02 . 2008-11-12 06:548055584----a-w-c:\windows\system32\drivers\nv4_mini.sys
      2009-05-01 05:02 . 2008-11-12 06:545896320----a-w-c:\windows\system32\nv4_disp.dll
      2009-05-01 05:02 . 2008-11-12 06:541720320----a-w-c:\windows\system32\nvcuda.dll
      2009-05-01 05:02 . 2008-11-12 06:54143360----a-w-c:\windows\system32\nvcodins.dll
      2009-05-01 05:02 . 2008-11-12 06:54143360----a-w-c:\windows\system32\nvcod.dll
      2009-05-01 00:53 . 2009-05-01 00:5362865----a-w-c:\windows\system32\drivers\odysseyIM3.sys
      2009-04-27 07:42 . 2009-04-11 21:37457248----a-w-c:\windows\system32\NVUNINST.EXE
      2009-04-24 21:45 . 2009-04-24 21:458854----a-r-c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{6084D038-3401-4C9D-A216-86E6EEA25AFB}\UNINST_Uninstall_Z_9FB06B5081B842C4B398D85CD33F7F86.exe
      2009-04-24 21:45 . 2009-04-24 21:4469632----a-r-c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{6084D038-3401-4C9D-A216-86E6EEA25AFB}\ZBrush3.exe1_6084D03834014C9DA21686E6EEA25AFB.exe
      2009-04-24 21:45 . 2009-04-24 21:4469632----a-r-c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{6084D038-3401-4C9D-A216-86E6EEA25AFB}\ZBrush3.exe_6084D03834014C9DA21686E6EEA25AFB.exe
      2009-04-24 21:45 . 2009-04-24 21:4410134----a-r-c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{6084D038-3401-4C9D-A216-86E6EEA25AFB}\ARPPRODUCTICON.exe
      2009-04-24 21:44 . 2009-04-24 21:448854----a-r-c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{6084D038-3401-4C9D-A216-86E6EEA25AFB}\UNINST_Uninstall_Z_6084D03834014C9DA21686E6EEA25AFB.exe
      2009-04-22 23:15 . 2009-04-22 23:15152576----a-w-c:\documents and settings\Administrator\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
      2009-04-21 10:40 . 2009-05-01 00:312653088-c--a-w-c:\documents and settings\All Users\Application Data\{66E2F539-12B6-4870-A500-7689CDE75C5E}\DriverScanner_Setup.exe
      2009-04-17 12:26 . 2008-04-14 12:001847168----a-w-c:\windows\system32\win32k.sys
      2009-04-15 14:51 . 2008-04-14 12:00585216----a-w-c:\windows\system32\rpcrt4.dll
      2009-04-12 09:21 . 2009-04-12 09:210----a-w-c:\windows\nsreg.dat
      2009-04-12 09:04 . 2008-01-30 01:2933808----a-w-c:\windows\system32\drivers\klbg.sys
      2009-04-12 09:04 . 2009-04-12 09:0444808----a-w-c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\fssync.dll
      2009-04-12 09:03 . 2009-04-12 09:03206088----a-w-c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\avp.exe
      2009-04-12 09:03 . 2009-04-12 09:0333808----a-w-c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\klbg.sys
      2009-04-12 09:03 . 2009-04-12 09:03213520----a-w-c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\XP\klif.sys
      2009-04-12 09:01 . 2009-04-12 09:018----a-w-c:\windows\system32\nvModes.dat
      2009-04-11 20:02 . 2009-04-11 19:4286327----a-w-c:\windows\pchealth\helpctr\OfflineCache\index.dat
      2009-04-11 19:40 . 2009-04-11 19:4021640----a-w-c:\windows\system32\emptyregdb.dat
      .

      ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* empty ENTRIES & legit default entries are not shown
      REGEDIT4

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2007-09-04 95536]
      "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
      "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-12 39408]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
      "Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-04-12 68592]
      "AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-04-12 206088]
      "Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-23 620152]
      "EPSON Stylus CX3800 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE" [2005-02-07 98304]
      "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2008-06-10 1406024]
      "OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" [2007-09-04 54576]
      "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-27 413696]
      "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-05-30 292136]
      "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-05-01 13750272]
      "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-05-01 86016]
      "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
      "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-05-01 1657376]

      c:\documents and settings\All Users\Start Menu\Programs\Startup\
      Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat.exe [2009-4-15 295606]
      Adobe Acrobat Synchronizer.lnk - c:\program files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-23 734872]

      [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
      "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
      2008-12-22 19:05356352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
      "DisableMonitoring"=dword:00000001

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "%windir%\\system32\\sessmgr.exe"=
      "c:\\Program Files\\Autodesk\\Maya2008\\bin\\maya.exe"=
      "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
      "c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
      "c:\\Program Files\\Autodesk\\Maya2009\\bin\\maya.exe"=
      "c:\\Program Files\\Mass Effect\\Binaries\\MassEffect.exe"=
      "c:\\Program Files\\Mass Effect\\MassEffectLauncher.exe"=
      "c:\\Program Files\\Unreal Tournament 3\\Binaries\\UT3.exe"=
      "c:\\Program Files\\iTunes\\iTunes.exe"=

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
      "3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
      "3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
      "50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
      "50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server

      R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [1/29/2008 6:29 PM 33808]
      R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [3/23/2009 2:07 PM 9968]
      R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [3/23/2009 2:07 PM 72944]
      R2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [4/23/2009 2:36 AM 1373480]
      R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [4/30/2008 6:06 PM 24592]
      R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1e51x86.sys [4/11/2009 2:09 PM 36864]
      R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [4/11/2009 2:07 PM 222976]
      S2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\DRIVERS\EAPPkt.sys --> c:\windows\system32\DRIVERS\EAPPkt.sys [?]
      S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [1/25/2007 10:31 AM 42000]
      S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [3/23/2009 2:07 PM 7408]

      [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
      "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
      .
      Contents of the 'Scheduled Tasks' folder

      2009-07-03 c:\windows\Tasks\AppleSoftwareUpdate.job
      - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
      .
      .
      ------- Supplementary Scan -------
      .
      uStart Page = https://www.google.com/accounts/ServiceLogin?service=mail&passive=true&rm=false&continue=http%3A%2F%2Fmail.google.com%2Fmail%2F%3Fui%3Dhtml%26zy%3Dl&bsv=zpwhtygjntrz&scc=1&ltmpl=default&ltmplcache=2
      uInternet Connection Wizard,ShellNext = "c:\program files\Outlook Express\msimn.exe" //mailurl:mailto:[emailprotected]
      IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
      IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
      IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
      DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
      FF - ProfilePath - c:\documents and settings\Bingo\Application Data\Mozilla\Firefox\Profiles\xuba6wew.default\
      FF - component: c:\documents and settings\Bingo\Application Data\Mozilla\Firefox\Profiles\xuba6wew.default\extensions\{FCAB6FDD-5585-425b-95C1-5ED856F3FD08}\components\nsCatcher.dll
      FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
      FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
      .

      **************************************************************************

      catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2009-07-07 21:12
      Windows 5.1.2600 Service Pack 3 NTFS

      scanning hidden processes ...

      scanning hidden autostart entries ...

      scanning hidden files ...

      scan completed successfully
      hidden files: 0

      **************************************************************************
      .
      --------------------- DLLs Loaded Under Running Processes ---------------------

      - - - - - - - > 'winlogon.exe'(568)
      c:\program files\SUPERAntiSpyware\SASWINLO.dll
      c:\windows\system32\WININET.dll

      - - - - - - - > 'explorer.exe'(1096)
      c:\windows\system32\WININET.dll
      c:\program files\Google\Quick Search Box\bin\1.2.1137.3514\qsb.dll
      c:\windows\system32\ieframe.dll
      c:\windows\system32\webcheck.dll
      .
      ------------------------ Other Running Processes ------------------------
      .
      c:\windows\system32\nvsvc32.exe
      c:\windows\system32\rundll32.exe
      c:\program files\Adobe\Acrobat 8.0\Acrobat\acrobat_sl.exe
      c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      c:\program files\Bonjour\mDNSResponder.exe
      c:\program files\Java\jre6\bin\jqs.exe
      c:\windows\system32\WTablet\Wacom_TabletUser.exe
      c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      c:\program files\iPod\bin\iPodService.exe
      .
      **************************************************************************
      .
      Completion time: 2009-07-08 21:15 - machine was rebooted
      ComboFix-quarantined-files.txt 2009-07-08 04:15

      Pre-Run: 176,964,202,496 bytes free
      Post-Run: 183,685,054,464 bytes free

      WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
      [boot loader]
      timeout=2
      default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
      [operating systems]
      c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
      multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

      302--- E O F ---2009-06-11 10:36
      Quote from: deebingo on July 07, 2009, 10:17:50 PM
      By the way thank you so much for doing this!!! People like you give me hope for our species.

      Your welcome.

      It looks like everything is gone now. How is the computer running now?

      * Click START then RUN
      * Now type Combofix /u in the runbox
      * Make sure there's a space between Combofix and /u
      * Then hit Enter

      * The above procedure will:
      * Delete the following:
      * ComboFix and its associated files and folders.
      * Reset the clock settings.
      * Hide file extensions, if required.
      * Hide System/Hidden files, if required.
      * Set a new, clean Restore Point.

      ----------

      Clean out your temporary internet files and temp files.

      Download TFC by OldTimer to your desktop.

      Double-click TFC.exe to run it.

      Note: If you are running on Vista, right-click on the file and choose Run As Administrator

      TFC will close all programs when run, so make sure you have saved all your work before you begin.

      * Click the Start button to begin the cleaning process.
      * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
      * Please let TFC run uninterrupted until it is finished.

      Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.Everything seems to be ok now! Thank you so much! Going to get an internet security suite today to help prevent this from happening again. Sounds good.

      Use the Secunia Software Inspector to check for out of date software.
      • Click Start Now
      • Check the box next to Enable thorough system inspection.
      • Click Start
      • Allow the scan to finish and scroll down to see if any updates are needed.
      • Update anything listed.
      .
      ----------

      Go to Microsoft Windows Update and get all critical updates.

      ----------

      I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

      SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
      * Using SpywareBlaster to protect your computer from Spyware and Malware
      * If you don't know what ActiveX controls are, see here

      Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

      Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
      3859.

      Solve : eBay "Phishing Scam" ... anyone seen this??

      Answer»

      Quote from: evilfantasy on July 10, 2009, 10:58:52 AM

      I would also recommend that you Defrag the computer.

      You can use the built in Windows Defrag by clicking Start > Run and then type in dfrg.msc then click OK. Or use a faster FREE program. Defraggler is very effective and easy to use.

      Note: Be sure to clean out temp files and restart the computer just before beginning a defrag.

      Actually, I would recommend using IObit's Smart Defrag. Just install, ANALYSE your drive, select Deep Optimize and then start the defrag.

      http://www.iobit.com/iobitsmartdefrag.htmlIObit is more RAM intensive than Defraggler. The computer is already slow. No need adding to the burden with a "heavier" process.Ran the disc defragmenter .... tried eBay, still asking me for my information. Also, still no sound either. Sounds like this thing is f***d

      What's funny is that its a SINGLE program somwhere, I tried eBay and Paypal and get the EXACT message and window when I log on, even if I enter the wrong username and/or password it directs me to that screen that says:

      "We have noticed an increasing fraudulent activity recently. In order to provide your security and protect you from FRAUDSTERS we have introduced a new system of identification that will help us to avoid any kind of fraud or unauthorised access.

      Please enter as more information as possible to provide your complete identification and to activate all the features of the new system"



      Any other suggestions?Download GMER and save it to your desktop
      • Unzip (extract) it to your desktop.
      • Disconnect from Internet and close all running programs.
      • There is a small chance this application may crash your computer so save any work you have open.
      • Double-click gmer.exe to run it.
      • Let the gmer.sys DRIVER to load if asked.
      • If it gives you a warning at program start about rootkit activity and asks if you want to run a scan... click NO
      • Click the Rootkit tab.
      • Make sure all the boxes on the right of the screen are checked, EXCEPT for "Show All".
      • Then click the Scan button. Wait for the scan to finish.
      • Once done, click the Copy button.
      • This will copy the results to the clipboard. Open Notepad and press CTRL + V to paste the log, and save it to your desktop.
      • Add this log to your next reply.
      Here's the RookIt Log:

      GMER 1.0.15.14972 - http://www.gmer.net
      Rootkit scan 2009-07-12 12:40:43
      Windows 5.1.2600 Service Pack 3


      ---- System - GMER 1.0.15 ----

      SSDT kl1.sys (Kaspersky Unified Driver/Kaspersky Lab) ZwOpenFile [0xBAAE3080]

      ---- User code sections - GMER 1.0.15 ----

      .text C:\Program Files\iPod\bin\iPodService.exe[476] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00BA2B80
      .text C:\Program Files\iPod\bin\iPodService.exe[476] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00BA2B3D
      .text C:\Program Files\iPod\bin\iPodService.exe[476] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00BA2B01
      .text C:\Program Files\iPod\bin\iPodService.exe[476] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00BA2AE6
      .text C:\Program Files\iPod\bin\iPodService.exe[476] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00BA2972
      .text C:\Program Files\iPod\bin\iPodService.exe[476] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00BA2A64
      .text C:\Program Files\iPod\bin\iPodService.exe[476] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00BA29AA
      .text C:\Program Files\iPod\bin\iPodService.exe[476] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00BA29E2
      .text C:\WINDOWS\system32\wuauclt.exe[1240] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00EC2B80
      .text C:\WINDOWS\system32\wuauclt.exe[1240] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00EC2B3D
      .text C:\WINDOWS\system32\wuauclt.exe[1240] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00EC2B01
      .text C:\WINDOWS\system32\wuauclt.exe[1240] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00EC2AE6
      .text C:\WINDOWS\system32\wuauclt.exe[1240] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00EC2972
      .text C:\WINDOWS\system32\wuauclt.exe[1240] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00EC2A64
      .text C:\WINDOWS\system32\wuauclt.exe[1240] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00EC29AA
      .text C:\WINDOWS\system32\wuauclt.exe[1240] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00EC29E2
      .text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe[1336] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 012E2B80
      .text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe[1336] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 012E2B3D
      .text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe[1336] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 012E2B01
      .text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe[1336] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 012E2AE6
      .text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe[1336] WS2_32.dll!send 71AB4C27 5 Bytes JMP 012E2972
      .text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe[1336] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 012E2A64
      .text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe[1336] WS2_32.dll!recv 71AB676F 5 Bytes JMP 012E29AA
      .text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe[1336] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 012E29E2
      .text C:\WINDOWS\System32\alg.exe[1628] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00AE2B80
      .text C:\WINDOWS\System32\alg.exe[1628] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00AE2B3D
      .text C:\WINDOWS\System32\alg.exe[1628] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00AE2B01
      .text C:\WINDOWS\System32\alg.exe[1628] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00AE2AE6
      .text C:\WINDOWS\System32\alg.exe[1628] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00AE2972
      .text C:\WINDOWS\System32\alg.exe[1628] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00AE2A64
      .text C:\WINDOWS\System32\alg.exe[1628] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00AE29AA
      .text C:\WINDOWS\System32\alg.exe[1628] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00AE29E2
      .text C:\Program Files\Azureus\Azureus.exe[1668] ADVAPI32.DLL!CryptDestroyKey 77DE9EBC 7 Bytes JMP 03C02B80
      .text C:\Program Files\Azureus\Azureus.exe[1668] ADVAPI32.DLL!CryptDecrypt 77DEA129 7 Bytes JMP 03C02B3D
      .text C:\Program Files\Azureus\Azureus.exe[1668] ADVAPI32.DLL!CryptEncrypt 77DEE360 7 Bytes JMP 03C02B01
      .text C:\Program Files\Azureus\Azureus.exe[1668] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 03C02AE6
      .text C:\Program Files\Azureus\Azureus.exe[1668] WS2_32.dll!send 71AB4C27 5 Bytes JMP 03C02972
      .text C:\Program Files\Azureus\Azureus.exe[1668] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 03C02A64
      .text C:\Program Files\Azureus\Azureus.exe[1668] WS2_32.dll!recv 71AB676F 5 Bytes JMP 03C029AA
      .text C:\Program Files\Azureus\Azureus.exe[1668] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 03C029E2
      .text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1820] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00702AE6
      .text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1820] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00702972
      .text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1820] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00702A64
      .text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1820] WS2_32.dll!recv 71AB676F 5 Bytes JMP 007029AA
      .text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1820] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 007029E2
      .text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1820] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00702B80
      .text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1820] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00702B3D
      .text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1820] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00702B01
      .text C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe[1884] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 01B42B80
      .text C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe[1884] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 01B42B3D
      .text C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe[1884] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 01B42B01
      .text C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe[1884] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01B42AE6
      .text C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe[1884] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01B42972
      .text C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe[1884] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01B42A64
      .text C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe[1884] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01B429AA
      .text C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe[1884] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 01B429E2
      .text C:\Program Files\Common Files\Motive\McciCMService.exe[2028] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00E02B80
      .text C:\Program Files\Common Files\Motive\McciCMService.exe[2028] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00E02B3D
      .text C:\Program Files\Common Files\Motive\McciCMService.exe[2028] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00E02B01
      .text C:\Program Files\Common Files\Motive\McciCMService.exe[2028] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00E02AE6
      .text C:\Program Files\Common Files\Motive\McciCMService.exe[2028] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00E02972
      .text C:\Program Files\Common Files\Motive\McciCMService.exe[2028] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00E02A64
      .text C:\Program Files\Common Files\Motive\McciCMService.exe[2028] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00E029AA
      .text C:\Program Files\Common Files\Motive\McciCMService.exe[2028] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00E029E2
      .text C:\Program Files\Logitech\SetPoint\LU\LogitechUpdate.exe[2364] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 014B2B80
      .text C:\Program Files\Logitech\SetPoint\LU\LogitechUpdate.exe[2364] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 014B2B3D
      .text C:\Program Files\Logitech\SetPoint\LU\LogitechUpdate.exe[2364] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 014B2B01
      .text C:\Program Files\Logitech\SetPoint\LU\LogitechUpdate.exe[2364] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 014B2AE6
      .text C:\Program Files\Logitech\SetPoint\LU\LogitechUpdate.exe[2364] WS2_32.dll!send 71AB4C27 5 Bytes JMP 014B2972
      .text C:\Program Files\Logitech\SetPoint\LU\LogitechUpdate.exe[2364] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 014B2A64
      .text C:\Program Files\Logitech\SetPoint\LU\LogitechUpdate.exe[2364] WS2_32.dll!recv 71AB676F 5 Bytes JMP 014B29AA
      .text C:\Program Files\Logitech\SetPoint\LU\LogitechUpdate.exe[2364] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 014B29E2
      .text C:\Program Files\Internet Explorer\iexplore.exe[2488] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 02302B80
      .text C:\Program Files\Internet Explorer\iexplore.exe[2488] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 02302B3D
      .text C:\Program Files\Internet Explorer\iexplore.exe[2488] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 02302B01
      .text C:\Program Files\Internet Explorer\iexplore.exe[2488] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2151D5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[2488] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9261 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[2488] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DC8A9 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[2488] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2ED2C4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[2488] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254254 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[2488] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E40B6CB C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[2488] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E40B5FD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[2488] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E40B668 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[2488] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E40B4CE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[2488] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E40B530 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[2488] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E40B72E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[2488] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E40B592 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[2488] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 3E2ED320 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[2488] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 02303088
      .text C:\Program Files\Internet Explorer\iexplore.exe[2488] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 023030DD
      .text C:\Program Files\Internet Explorer\iexplore.exe[2488] WININET.dll!HttpOpenRequestA 3D94D5E8 5 Bytes JMP 02302DD5
      .text C:\Program Files\Internet Explorer\iexplore.exe[2488] WININET.dll!InternetConnectA 3D94DF8E 5 Bytes JMP 02302B9B
      .text C:\Program Files\Internet Explorer\iexplore.exe[2488] WININET.dll!HttpSendRequestW 3D94FB9E 5 Bytes JMP 02303A57
      .text C:\Program Files\Internet Explorer\iexplore.exe[2488] WININET.dll!HttpSendRequestA 3D95EEB9 5 Bytes JMP 02302F41
      .text C:\Program Files\Internet Explorer\iexplore.exe[2488] CRYPT32.dll!CertGetCertificateChain 77A92F67 5 Bytes JMP 023035D4
      .text C:\Program Files\Internet Explorer\iexplore.exe[2488] CRYPT32.dll!CertVerifyCertificateChainPolicy 77A9B76F 5 Bytes JMP 023035DD
      .text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2676] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00F82B80
      .text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2676] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00F82B3D
      .text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2676] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00F82B01
      .text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2676] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00F82AE6
      .text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2676] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00F82972
      .text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2676] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00F82A64
      .text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2676] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00F829AA
      .text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2676] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00F829E2
      .text C:\WINDOWS\Explorer.EXE[3160] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00E42B80
      .text C:\WINDOWS\Explorer.EXE[3160] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00E42B3D
      .text C:\WINDOWS\Explorer.EXE[3160] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00E42B01
      .text C:\WINDOWS\Explorer.EXE[3160] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00E42AE6
      .text C:\WINDOWS\Explorer.EXE[3160] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00E42972
      .text C:\WINDOWS\Explorer.EXE[3160] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00E42A64
      .text C:\WINDOWS\Explorer.EXE[3160] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00E429AA
      .text C:\WINDOWS\Explorer.EXE[3160] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00E429E2
      .text C:\Program Files\iTunes\iTunesHelper.exe[3620] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00BD2B80
      .text C:\Program Files\iTunes\iTunesHelper.exe[3620] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00BD2B3D
      .text C:\Program Files\iTunes\iTunesHelper.exe[3620] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00BD2B01
      .text C:\Program Files\iTunes\iTunesHelper.exe[3620] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00BD2AE6
      .text C:\Program Files\iTunes\iTunesHelper.exe[3620] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00BD2972
      .text C:\Program Files\iTunes\iTunesHelper.exe[3620] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00BD2A64
      .text C:\Program Files\iTunes\iTunesHelper.exe[3620] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00BD29AA
      .text C:\Program Files\iTunes\iTunesHelper.exe[3620] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00BD29E2
      .text C:\Program Files\Java\jre6\bin\jusched.exe[3632] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00C42B80
      .text C:\Program Files\Java\jre6\bin\jusched.exe[3632] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00C42B3D
      .text C:\Program Files\Java\jre6\bin\jusched.exe[3632] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00C42B01
      .text C:\Program Files\Java\jre6\bin\jusched.exe[3632] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00C42AE6
      .text C:\Program Files\Java\jre6\bin\jusched.exe[3632] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00C42972
      .text C:\Program Files\Java\jre6\bin\jusched.exe[3632] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00C42A64
      .text C:\Program Files\Java\jre6\bin\jusched.exe[3632] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00C429AA
      .text C:\Program Files\Java\jre6\bin\jusched.exe[3632] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00C429E2
      .text C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe[3704] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 01042B80
      .text C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe[3704] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 01042B3D
      .text C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe[3704] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 01042B01
      .text C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe[3704] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01042AE6
      .text C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe[3704] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01042972
      .text C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe[3704] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01042A64
      .text C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe[3704] WS2_32.dll!recv 71AB676F 5 Bytes JMP 010429AA
      .text C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe[3704] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 010429E2
      .text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe[3784] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 01D02B80
      .text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe[3784] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 01D02B3D
      .text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe[3784] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 01D02B01
      .text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe[3784] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01D02AE6
      .text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe[3784] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01D02972
      .text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe[3784] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01D02A64
      .text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe[3784] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01D029AA
      .text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe[3784] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 01D029E2
      .text C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe[3804] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00E02B80
      .text C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe[3804] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00E02B3D
      .text C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe[3804] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00E02B01
      .text C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe[3804] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00E02AE6
      .text C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe[3804] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00E02972
      .text C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe[3804] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00E02A64
      .text C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe[3804] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00E029AA
      .text C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe[3804] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00E029E2
      .text C:\Program Files\Internet Explorer\iexplore.exe[5416] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 02682B80
      .text C:\Program Files\Internet Explorer\iexplore.exe[5416] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 02682B3D
      .text C:\Program Files\Internet Explorer\iexplore.exe[5416] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 02682B01
      .text C:\Program Files\Internet Explorer\iexplore.exe[5416] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2151D5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[5416] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9261 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[5416] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DC8A9 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[5416] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2ED2C4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[5416] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254254 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[5416] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E40B6CB C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[5416] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E40B5FD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[5416] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E40B668 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[5416] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E40B4CE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[5416] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E40B530 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[5416] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E40B72E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[5416] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E40B592 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[5416] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 3E2ED320 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[5416] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 02683088
      .text C:\Program Files\Internet Explorer\iexplore.exe[5416] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 026830DD
      .text C:\Program Files\Internet Explorer\iexplore.exe[5416] WININET.dll!HttpOpenRequestA 3D94D5E8 5 Bytes JMP 02682DD5
      .text C:\Program Files\Internet Explorer\iexplore.exe[5416] WININET.dll!InternetConnectA 3D94DF8E 5 Bytes JMP 02682B9B
      .text C:\Program Files\Internet Explorer\iexplore.exe[5416] WININET.dll!HttpSendRequestW 3D94FB9E 5 Bytes JMP 02683A57
      .text C:\Program Files\Internet Explorer\iexplore.exe[5416] WININET.dll!HttpSendRequestA 3D95EEB9 5 Bytes JMP 02682F41
      .text C:\Program Files\Internet Explorer\iexplore.exe[5416] CRYPT32.dll!CertGetCertificateChain 77A92F67 5 Bytes JMP 026835D4
      .text C:\Program Files\Internet Explorer\iexplore.exe[5416] CRYPT32.dll!CertVerifyCertificateChainPolicy 77A9B76F 5 Bytes JMP 026835DD
      .text C:\Program Files\Internet Explorer\iexplore.exe[5752] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 02A32B80
      .text C:\Program Files\Internet Explorer\iexplore.exe[5752] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 02A32B3D
      .text C:\Program Files\Internet Explorer\iexplore.exe[5752] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 02A32B01
      .text C:\Program Files\Internet Explorer\iexplore.exe[5752] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2151D5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[5752] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2ED2C4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[5752] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E40B6CB C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[5752] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E40B5FD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[5752] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E40B668 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[5752] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E40B4CE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[5752] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E40B530 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[5752] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E40B72E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[5752] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E40B592 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
      .text C:\Program Files\Internet Explorer\iexplore.exe[5752] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 02A33088
      .text C:\Program Files\Internet Explorer\iexplore.exe[5752] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 02A330DD
      .text C:\Program Files\Internet Explorer\iexplore.exe[5752] WININET.dll!HttpOpenRequestA 3D94D5E8 5 Bytes JMP 02A32DD5
      .text &nbI'm not seeing anything.

      Download Lop S&D by Eric_71 and save it to your Desktop. Lop S&D will only run on Windows XP and Windows Vista

      Disable your antivirus and antimalware programs so they do not INTERFERE with the running of Lop S&D. If needed see: How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs

      Double click LopSD.exe - If you are using Windows Vista, right-click on the LopSD icon and select Run as administrator to perform this scan.

      • Choose the language by typing of the corresponding letter and press Enter
      • Click OK at the informative window
      • Type 1, to choose Option 1 (Search) then press Enter
      • Wait until the end of the scan
      • A report will be generated, post the contents of it in your next reply.
      .
      A copy of the report can be found at this location: %systemdrive%\lopR.txt, in most cases C:\lopR.txt

      ----------

      Download GooredFix from one of the locations below and save it to your Desktop.

      Link #1
      Link #2

      * Double-click GooredFix.exe to run it.
      * Select 1. Find Goored (no fix) by typing 1 and pressing Enter.
      * A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called GooredLog.txt).

      Note: Do not run Option #2 yet.

      3860.

      Solve : My computer was in a battle and i shutdown its shield?

      Answer» NEVER MIND I fixed with malwarebytes, then i installed avg. Not there are no more traces or anything

      So me, being very idiotic, wanted to speed up my computer and all, so i figure since theres no viruses or anything from scans, i could uninstall with no worry. So i did....now i regret it, after i restarted my computer, it ran very....lagging-ly so i check my task MANAGER, i find: a.exe b.exe and a Few others.

      This is now starting to get serious, because its saying explorer.exe needs to close etc etc


      So without going any further:
      i am running Windows xp Pro with SP2(i have read that sp3 isn't ready for hp's)
      448 mb of physical ram with 2056 mb of virtual ram.
      Currently i have no antiviruses Besides the ones needed to post logs.

      This is not an epidemic but last time i messed with infections, i ended up buying a completely new harddrive.

      SuperAntiSpyware:
      I need to do this in the morning...

      Malwarebyte's Anti Malware:

      Code: [Select]Malwarebytes' Anti-Malware 1.37
      Database version: 2182
      Windows 5.1.2600 Service Pack 2

      7/8/2009 12:40:29 AM
      mbam-log-2009-07-08 (00-40-29).txt

      Scan type: Quick Scan
      Objects scanned: 100528
      Time elapsed: 56 minute(s), 20 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 23
      Registry Values Infected: 2
      Registry Data Items Infected: 0
      Folders Infected: 4
      Files Infected: 65

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      HKEY_CURRENT_USER\SOFTWARE\Cognac (Rogue.Multiple) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\MRSoft (Trojan.Agent) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorertoolbar (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\mwc (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\ColdWare (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ef99d588-3d5f-4194-828a-e03870a57a77} (Trojan.BHO) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{ef99d588-3d5f-4194-828a-e03870a57a77} (Trojan.BHO) -> Quarantined and deleted successfully.

      Registry Values Infected:
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Cognac (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\11 (Security.Hijack) -> Quarantined and deleted successfully.

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      C:\WINDOWS\system32smp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\Program Files\POL (Keylogger.Ardamax) -> Quarantined and deleted successfully.
      C:\Program Files\Seekapp (Adware.Seekapp) -> Quarantined and deleted successfully.
      c:\documents and settings\All Users\Application Data\Seekapp (Adware.Seekapp) -> Quarantined and deleted successfully.

      Files Infected:
      c:\WINDOWS\setup_akl.exe (Keylogger.Ardamax) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32smp\msrc.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      c:\program files\POL\akv.cfg (Keylogger.Ardamax) -> Quarantined and deleted successfully.
      c:\program files\POL\key.bin (Keylogger.Ardamax) -> Quarantined and deleted successfully.
      c:\program files\POL\POL.001 (Keylogger.Ardamax) -> Quarantined and deleted successfully.
      c:\program files\POL\POL.002 (Keylogger.Ardamax) -> Quarantined and deleted successfully.
      c:\program files\POL\POL.005 (Keylogger.Ardamax) -> Quarantined and deleted successfully.
      c:\program files\POL\POL.009 (Keylogger.Ardamax) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
      C:\WINDOWS\msa.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\bb1.dat (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\ps1.dat (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\rc.dat (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32akttzn.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32anticipator.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32awtoolb.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32bdn.com (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32bsva-egihsg52.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32dpcproxy.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32emesx.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\[emailprotected]k.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32hoproxy.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32hxiwlgpm.dat (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32hxiwlgpm.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32medup012.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32medup020.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32msgp.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32msnbho.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32mssecu.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32msvchost.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32mtr2.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32mwin32.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32netode.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32newsd32.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32psof1.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32psoft1.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32regc64.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32regm64.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32Rundl1.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32sncntr.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32ssurf022.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32ssvchost.com (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32ssvchost.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32sysreq.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32taack.dat (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32taack.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32thun.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32thun32.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32VBIEWER.OCX (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32vbsys2.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32vcatchpi.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32winlogonpc.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32winsystem.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\System32WINWGPX.EXE (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      c:\documents and settings\Owner\RESULTS.TXT (Malware.Trace) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\cs.dat (Malware.Trace) -> Quarantined and deleted successfully.
      c:\WINDOWS\pskt.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
      c:\WINDOWS\BM53356244.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
      c:\WINDOWS\BM53356244.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
      c:\WINDOWS\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32ps1.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Owner\Local Settings\Temp\b.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\alog.txt (Stolen.Data) -> Quarantined and deleted successfully.
      C:\WINDOWS\Tasks\{783AF354-B514-42d6-970E-3E8BF0A5279C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.


      Hijackthis Log:

      Code: [Select]Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 11:41:53 PM, on 7/7/2009
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Common Files\Apple\Mobile DEVICE Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
      C:\Program Files\TeamViewer\Version4\TeamViewer.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
      C:\Program Files\NETGEAR\WPN111\WPN111.exe
      C:\WINDOWS\Explorer.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Prevx\prevx.exe
      C:\Program Files\Prevx\prevx.exe
      C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
      C:\Documents and Settings\Owner\My Documents\Downloads\SUPERAntiSpyware.exe
      C:\WINDOWS\system32\MSIEXEC.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\WINDOWS\system32\msiexec.exe
      C:\WINDOWS\system32\MsiExec.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(DEFAULT) = http://www.speedapps.com/search.htm
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {2AA0726C-95B7-4216-AA43-B5BDD524892F} - (no file)
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
      O2 - BHO: (no name) - {67775CC4-6A06-465A-8FC9-F1482343E6DD} - (no file)
      O2 - BHO: (no name) - {AD2C8443-63DD-4953-B2BF-6A0E9891CF2F} - (no file)
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.23.0\gears.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O2 - BHO: Rmn plugin - {EF99D588-3D5F-4194-828A-E03870A57A77} - gcomd32.dll (file missing)
      O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - (no file)
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
      O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
      O4 - Startup: Lock.lnk = C:\Documents and Settings\Owner\Desktop\Lock.exe
      O4 - Startup: WPN111.lnk = C:\Program Files\NETGEAR\WPN111\WPN111.exe
      O4 - Global Startup: TeamViewer 4.lnk = C:\Program Files\TeamViewer\Version4\TeamViewer.exe
      O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
      O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
      O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
      O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.23.0\gears.dll
      O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.23.0\gears.dll
      O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\Office12\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O10 - UNKNOWN file in WINSOCK LSP: c:\windows\system32\nwprovau.dll
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1192053397896
      O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
      O20 - Winlogon Notify: mlJDsRki - mlJDsRki.dll (file missing)
      O20 - Winlogon Notify: pMdDuUKC - pMdDuUKC.dll (file missing)
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: CSIScanner - Prevx - C:\Program Files\Prevx\prevx.exe
      O23 - Service: Google Update Service (gupdate1c94846d59c454e) (gupdate1c94846d59c454e) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe

      --
      End of file - 7393 byteshttp://www.free-av.com/


      go to above download the anti-virus and run , harry
      3861.

      Solve : Log-in Information/Cookies get deleted after every startup?

      Answer»

      Sent to this board by BRONI. Posting here in the threat that I have an INFECTION:

      Program I found suspicious/don't know WHAT they are:
      KBD

      And there seems to be a Java(TM) 6 Update 14 and a Java(TM) 6 Update 7 in the list as well. UH...?

      [attachment deleted by ADMIN]

      3862.

      Solve : Cant access many things including some sites and the control panel?

      Answer»

      I don't know if it is a virus but it's something bad i cant access any ANTI virus sites or microsoft.com. Also i cant access the CONTROL panel or anything associated within it. Most of this started happening once my norton ANTIVIRUS subscription ended a COUPLE weeks ago and i can't renew it because i can't access the norton site. Also i can access these sites in the cached version under google search. Please Help...http://www.free-av.com/


      go to above , download and run you NEED an anti-virus , harry

      3863.

      Solve : hijacked DNS server..please help?

      Answer»

      I have the the scan from SUPERantispyware..I will post the results here..

      Adware.Tracking Cookie
      C:\Documents and Settings\Mr. and Mrs. Brown\Cookies\mr. and mrs. [emailprotected][1].txt
      C:\Documents and Settings\Mr. and Mrs. Brown\Cookies\mr. and mrs. [emailprotected][1].txt
      C:\Documents and Settings\Mr. and Mrs. Brown\Cookies\mr. and mrs. [emailprotected][1].txt
      C:\Documents and Settings\Mr. and Mrs. Brown\Cookies\mr. and mrs. [emailprotected][1].txt
      C:\Documents and Settings\Mr. and Mrs. Brown\Cookies\mr. and mrs. [emailprotected][1].txt
      C:\Documents and Settings\Mr. and Mrs. Brown\Cookies\mr. and mrs. [emailprotected][1].txt
      C:\Documents and Settings\Mr. and Mrs. Brown\Cookies\mr. and mrs. [emailprotected][1].txt

      Trojan.DNS-Changer (Hi-Jacked DNS)
      HKLM\SYSTEM\CONTROLSET002\SERVICES\TCPIP\PARAMETERS\INTERFACES\{01B9EC96-33F3-4402-9356-CD8F26129333} (NAMESERVER - 85.255.112.85,85.225.112.180)
      HKLM\SYSTEM\CONTROLSET002\SERVICES\TCPIP\PARAMETERS\INTERFACES\{6AA2E2ED-535D-46E2-8FC3-734E236E4254
      } (NAMESERVER - 85.255.112.85,85.225.112.180)
      HKLM\SYSTEM\CONTROLSET003\SERVICES\TCPIP\PARAMETERS\INTERFACES\{01B9EC96-33F3-4402-9356-CD8F26129333} (NAMESERVER - 85.255.112.85,85.225.112.180)
      HKLM\SYSTEM\CONTROLSET003\SERVICES\TCPIP\PARAMETERS\INTERFACES\{6AA2E2ED-535D-46E2-8FC3-734E236E4254
      } (NAMESERVER - 85.255.112.85,85.225.112.180)


      I quarantined these items, and now I have the option to remove them from my computer. I think I should, but need to make sure, thank you.

      Also, here is a hijackthis log I made :

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 11:53:16 AM, on 7/2/2009
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\WLTRYSVC.EXE
      C:\WINDOWS\System32\bcmwltry.exe
      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Maxtor\Sync\SyncServices.exe
      C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
      C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Viewpoint\Common\ViewpointService.exe
      C:\WINDOWS\system32\mdmcls32.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\explorer.exe
      C:\Program Files\Microsoft IntelliPoint\ipoint.exe
      C:\WINDOWS\system32\WLTRAY.exe
      C:\PROGRA~1\AVG\AVG8\avgtray.exe
      C:\WINDOWS\system32\RunDLL32.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\SUPERAntiSpyware\b238f0d7-906d-4d14-acd0-35598b5dd481.exe
      C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe
      C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe

      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3071221
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R3 - URLSearchHook: AIM Toolbar Search Class - {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (file missing)
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
      O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll (file missing)
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll (file missing)
      O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
      O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
      O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O8 - Extra context menu item: &AIM Toolbar Search - C:\Documents and Settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
      O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll (file missing)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.85,85.255.112.180
      O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.112.85,85.255.112.180
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.85,85.255.112.180
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
      O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
      O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: DellAMBrokerService - Unknown owner - C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe
      O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
      O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
      O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
      O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
      O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
      O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
      O23 - Service: WinSock Extention Manager - Unknown owner - C:\WINDOWS\system32\mdmcls32.exe
      O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

      --
      End of file - 8041 bytes



      Also, i forgot to add an important issue that I have been having. Every time I boot up my computer, the Data Execution Prevention box comes up saying..

      To help protect your computer, Windows has closed this program.

      Name: Userinit Logon Application

      Publisher: Microsoft Corporation

      So I click Close Message.. and then it tells me that Userinit Logon Application has encountered a problem and needs to close.

      I don't even know what 'Userinit Logon Application' is.
      Please Help!Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop.

      Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

      * XP users Double click on dds to run it.
      * If your antivirus or firewall try to block DDS then please allow it to run.
      * When finished DDS will open two (2) logs.

      1) DDS.txt
      2) Attach.txt

      * Save both logs to your desktop.
      * Please copy and paste the entire contents of both logs in your next reply.

      Note: DDS will instruct you to post the Attach.txt log as an attachment.
      Please just post it as you would any other log by copy and pasting it into the reply.Here is the DDS file:


      DDS (Ver_09-06-26.01) - NTFSx86 MINIMAL
      Run by T Brown at 11:18:05.92 on Wed 07/08/2009
      Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13
      Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.772 [GMT -4:00]

      AV: AVG Anti-Virus Free *On-access scanning enabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

      ============== Running Processes ===============

      C:\WINDOWS\system32\svchost -k DcomLaunch
      svchost.exe
      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      C:\WINDOWS\system32\svchost.exe -k netsvcs
      C:\WINDOWS\Explorer.EXE
      F:\dds.pif

      ============== PSEUDO HJT Report ===============

      uStart Page = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3071221
      uInternet Connection Wizard,ShellNext = iexplore
      uInternet Settings,ProxyOverride = *.local
      uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
      uURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} -
      mURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} -
      BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
      BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
      BHO: AIM Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - AIM Toolbar Loader
      BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
      BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      TB: AIM Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} -
      uRun: [Aim6]
      uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
      mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
      mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
      mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
      mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
      mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
      mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
      mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
      mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
      mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
      mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
      mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
      mRun: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
      IE: &AIM Toolbar Search - c:\documents and settings\all users\application data\aim toolbar\ietoolbar\resources\en-us\local\search.html
      IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
      IE: {0b83c99c-1efa-4259-858f-bcb33e007a5b} - {61539ecd-cc67-4437-a03c-9aaccbd14326}
      LSP: winsflt.dll
      DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
      DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
      DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
      Handler: ic32pp - {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} - c:\windows\wc98pp.dll
      Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
      Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
      Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
      Notify: avgrsstarter - avgrsstx.dll
      SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
      SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

      ================= FIREFOX ===================

      FF - ProfilePath - c:\docume~1\tbrown~1\applic~1\mozilla\firefox\profiles\ih8nvsnl.default\
      FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
      FF - prefs.js: browser.search.selectedEngine - Yoog Search
      FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
      FF - prefs.js: keyword.URL - hxxp://www10.yoog.com/search.php?q=
      FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
      FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
      FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
      FF - plugin: c:\program files\scenecaster\version 3.11.16\NPSceneCaster.dll
      FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
      FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
      FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
      FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

      ---- FIREFOX POLICIES ----
      FF - user.js: browser.search.selectedEngine - Yoog Search
      FF - user.js: keyword.URL - hxxp://www10.yoog.com/search.php?q=
      FF - user.js: keyword.enabled - true

      ============= SERVICES / DRIVERS ===============

      R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-7-7 611664]
      S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-12-30 325896]
      S1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2007-12-27 27784]
      S1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2008-12-22 8944]
      S1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2008-12-22 55024]
      S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-12-30 298776]
      S2 datunidr;DellAutomatedPCTuneUp UniDriver;c:\windows\system32\drivers\datunidr.sys [2007-8-23 5376]
      S2 Maxtor Sync Service;Maxtor Service;c:\program files\maxtor\sync\SyncServices.exe [2007-7-13 156976]
      S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-12-28 24652]
      S2 WinSock Extention Manager;WinSock Extention Manager;c:\windows\system32\mdmcls32.exe [2009-1-6 1032192]
      S3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\system32\drivers\OEM02Dev.sys [2007-12-20 235520]
      S3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\system32\drivers\OEM02Vfx.sys [2007-12-20 7424]
      S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2008-12-22 7408]
      UnknownUnknown RTLWUSB;RTLWUSB;



      =============== Created Last 30 ================

      2009-07-08 10:27--d-----c:\program files\Registry Winner
      2009-07-05 20:5842,496a-------c:\windows\ld12.exe
      2009-07-05 20:58154a-------c:\windows\567788.bat
      2009-07-02 12:56-cd-----c:\docume~1\alluse~1\applic~1\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
      2009-06-30 14:11--dsh---c:\documents and settings\t brown\IECompatCache
      2009-06-30 10:230a-------c:\windows\system32\19.tmp
      2009-06-30 10:23360,320a-------c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL
      2009-06-22 13:47--d-----c:\program files\BitLord
      2009-06-18 23:38--d-----c:\program files\iPod
      2009-06-18 23:38--d-----c:\program files\iTunes
      2009-06-10 23:07--dsh---C:\Diskeeper
      2009-06-10 21:28--d-----c:\program files\common files\Diskeeper Corporation
      2009-06-10 21:28--d-----c:\docume~1\alluse~1\applic~1\Diskeeper Corporation
      2009-06-10 21:27--d-----c:\program files\Diskeeper Corporation
      2009-06-10 19:151,985,024--------c:\windows\system32\dllcache\iertutil.dll
      2009-06-10 19:15246,272--------c:\windows\system32\dllcache\ieproxy.dll
      2009-06-10 19:1512,800--------c:\windows\system32\dllcache\xpshims.dll
      2009-06-10 19:1511,064,832--------c:\windows\system32\dllcache\ieframe.dll
      2009-06-10 10:46--d-----c:\windows\Logs
      2009-06-10 10:073,426,072a-------c:\windows\system32\d3dx9_32.dll
      2009-06-10 10:07251,672a-------c:\windows\system32\xactengine2_5.dll
      2009-06-10 10:07237,848a-------c:\windows\system32\xactengine2_4.dll
      2009-06-10 10:0715,128a-------c:\windows\system32\x3daudio1_1.dll
      2009-06-10 10:072,414,360a-------c:\windows\system32\d3dx9_31.dll
      2009-06-10 10:07236,824a-------c:\windows\system32\xactengine2_3.dll
      2009-06-10 10:0762,744a-------c:\windows\system32\xinput1_2.dll
      2009-06-10 10:062,297,552a-------c:\windows\system32\d3dx9_26.dll

      ==================== Find3M ====================

      2009-07-05 20:58360,320a-------c:\windows\system32\drivers\TCPIP.SYS
      2009-07-05 20:58360,320a-------c:\windows\system32\dllcache\TCPIP.SYS
      2009-06-30 13:4167,190a-------c:\windows\system32\nvModes.dat
      2009-06-05 11:422,060,288a-------c:\windows\system32\usbaaplrc.dll
      2009-06-05 11:4239,424a-------c:\windows\system32\drivers\usbaapl.sys
      2009-05-25 09:5751,712a-------c:\windows\wc98pp.dll
      2009-05-13 01:155,936,128a-------c:\windows\system32\dllcache\mshtml.dll
      2009-05-13 01:15915,456a-------c:\windows\system32\wininet.dll
      2009-05-13 01:15915,456a-------c:\windows\system32\dllcache\wininet.dll
      2009-05-12 01:11102,912--------c:\windows\system32\dllcache\iecompat.dll
      2009-05-11 19:3011,952a-------c:\windows\system32\avgrsstx.dll
      2009-05-11 19:30325,896a-------c:\windows\system32\drivers\avgldx86.sys
      2009-05-07 11:44344,064a-------c:\windows\system32\localspl.dll
      2009-05-07 11:44344,064--------c:\windows\system32\dllcache\localspl.dll
      2009-04-30 17:221,207,808a-------c:\windows\system32\dllcache\urlmon.dll
      2009-04-30 17:2225,600a-------c:\windows\system32\dllcache\jsproxy.dll
      2009-04-30 17:22385,536--------c:\windows\system32\dllcache\iedkcs32.dll
      2009-04-30 07:21173,056--------c:\windows\system32\dllcache\ie4uinit.exe
      2009-04-17 05:581,846,656a-------c:\windows\system32\win32k.sys
      2009-04-17 05:581,846,656--------c:\windows\system32\dllcache\win32k.sys
      2009-04-15 11:11584,192a-------c:\windows\system32\rpcrt4.dll
      2009-04-15 11:11584,192--------c:\windows\system32\dllcache\rpcrt4.dll
      2009-02-20 13:30208ac------c:\docume~1\tbrown~1\applic~1\wklnhst.dat
      2008-12-31 13:4247,360ac------c:\docume~1\tbrown~1\applic~1\pcouffin.sys
      1997-05-16 08:5232,528ac------c:\documents and settings\t brown\OLEPRO32.DLL
      1997-05-16 08:52271,632ac------c:\documents and settings\t brown\MSVCRT.DLL
      1997-05-16 08:52939,792a-------c:\documents and settings\t brown\MFC42U.DLL
      1997-05-16 08:52941,840a-------c:\documents and settings\t brown\MFC42.DLL
      1997-05-16 08:52352,016a-------c:\documents and settings\t brown\MSPAINT.EXE
      2007-12-20 22:3476-c-shr--c:\windows\CT4CET.bin
      2008-01-02 23:1410,240ac-sh---c:\windows\rnapxs\rnapxs.dat

      ============= FINISH: 11:19:48.50 ===============


      and here is the attachment:


      DDS (Ver_09-06-26.01)

      Microsoft Windows XP Home Edition
      Boot Device: \Device\HarddiskVolume2
      Install Date: 12/27/2007 11:33:22 AM
      System Uptime: 7/8/2009 10:19:56 AM (1 hours ago)

      Motherboard: Dell Inc. | |
      Processor: Intel(R) Core(TM)2 Duo CPU T5270 @ 1.40GHz | Microprocessor | 1396/200mhz
      Processor: Intel(R) Core(TM)2 Duo CPU T5270 @ 1.40GHz | Microprocessor | 1396/200mhz

      ==== Disk Partitions =========================

      C: is FIXED (NTFS) - 146 GiB total, 75.36 GiB free.
      D: is CDROM ()
      E: is CDROM ()
      F: is Removable

      ==== Disabled Device Manager Items =============

      ==== System Restore Points ===================

      RP382: 6/30/2009 10:22:59 AM - Installed Java(TM) 6 Update 13
      RP383: 6/30/2009 10:23:03 AM - System Checkpoint
      RP384: 6/30/2009 10:23:10 AM - System Checkpoint
      RP385: 6/30/2009 10:23:14 AM - System Checkpoint
      RP386: 6/30/2009 10:23:17 AM - System Checkpoint
      RP387: 6/30/2009 10:23:20 AM - System Checkpoint
      RP388: 6/30/2009 10:23:25 AM - System Checkpoint
      RP389: 6/30/2009 10:23:27 AM - System Checkpoint
      RP390: 6/30/2009 10:23:28 AM - System Checkpoint
      RP391: 6/30/2009 10:23:28 AM - System Checkpoint
      RP392: 6/30/2009 10:23:30 AM - System Checkpoint
      RP393: 6/30/2009 10:23:34 AM - System Checkpoint
      RP394: 6/30/2009 10:23:34 AM - System Checkpoint
      RP395: 6/30/2009 10:23:35 AM - Software Distribution Service 3.0
      RP396: 6/30/2009 10:23:35 AM - Avg8 Update
      RP397: 6/30/2009 10:23:36 AM - System Checkpoint
      RP398: 6/30/2009 10:23:37 AM - System Checkpoint
      RP399: 6/30/2009 10:23:37 AM - System Checkpoint
      RP400: 4/20/2009 11:59:49 PM - System Checkpoint
      RP401: 4/22/2009 12:52:09 AM - System Checkpoint
      RP402: 4/23/2009 1:43:40 AM - System Checkpoint
      RP403: 4/24/2009 2:26:31 AM - System Checkpoint
      RP404: 4/25/2009 2:36:05 AM - System Checkpoint
      RP405: 4/26/2009 10:49:42 AM - System Checkpoint
      RP406: 4/27/2009 5:25:29 PM - System Checkpoint
      RP407: 4/28/2009 7:40:59 PM - System Checkpoint
      RP408: 4/29/2009 9:42:56 PM - System Checkpoint
      RP409: 4/30/2009 11:08:56 PM - System Checkpoint
      RP410: 5/1/2009 11:21:36 PM - System Checkpoint
      RP411: 5/2/2009 11:33:57 PM - System Checkpoint
      RP412: 5/3/2009 11:47:16 PM - System Checkpoint
      RP413: 5/5/2009 12:32:42 AM - System Checkpoint
      RP414: 5/6/2009 1:32:58 AM - System Checkpoint
      RP415: 5/7/2009 2:13:03 AM - System Checkpoint
      RP416: 5/8/2009 2:41:42 AM - System Checkpoint
      RP417: 5/9/2009 3:39:53 AM - System Checkpoint
      RP418: 5/10/2009 6:21:40 PM - System Checkpoint
      RP419: 5/11/2009 7:29:17 PM - Avg8 Update
      RP420: 5/11/2009 7:31:07 PM - Avg8 Update
      RP421: 5/12/2009 11:05:52 PM - System Checkpoint
      RP422: 5/13/2009 7:01:13 AM - Software Distribution Service 3.0
      RP423: 5/14/2009 7:27:47 AM - System Checkpoint
      RP424: 5/15/2009 5:26:26 PM - Avg8 Update
      RP425: 5/17/2009 3:17:09 PM - System Checkpoint
      RP426: 5/18/2009 5:10:12 PM - Avg8 Update
      RP427: 5/18/2009 5:12:09 PM - Avg8 Update
      RP428: 5/20/2009 12:01:34 AM - System Checkpoint
      RP429: 5/21/2009 12:14:34 AM - System Checkpoint
      RP430: 5/21/2009 9:49:14 AM - Installed Windows Media Format Runtime
      RP431: 5/22/2009 11:15:01 AM - Software Distribution Service 3.0
      RP432: 5/23/2009 11:15:34 AM - System Checkpoint
      RP433: 5/24/2009 11:40:20 AM - System Checkpoint
      RP434: 5/26/2009 7:59:08 PM - Removed LightScribe System Software 1.10.19.1.
      RP435: 5/26/2009 8:00:32 PM - Removed LightScribe System Software 1.10.19.1.
      RP436: 5/27/2009 8:44:58 PM - System Checkpoint
      RP437: 5/28/2009 10:07:23 PM - Software Distribution Service 3.0
      RP438: 5/29/2009 10:54:25 PM - System Checkpoint
      RP439: 5/31/2009 9:51:52 PM - System Checkpoint
      RP440: 6/2/2009 12:30:03 AM - System Checkpoint
      RP441: 6/3/2009 12:42:22 AM - System Checkpoint
      RP442: 6/4/2009 1:33:18 AM - System Checkpoint
      RP443: 6/5/2009 2:38:38 AM - System Checkpoint
      RP444: 6/6/2009 3:19:02 AM - System Checkpoint
      RP445: 6/6/2009 9:21:52 AM - Installed Audiosurf.
      RP446: 6/7/2009 11:41:16 PM - System Checkpoint
      RP447: 6/8/2009 11:46:32 PM - System Checkpoint
      RP448: 6/9/2009 11:48:30 PM - System Checkpoint
      RP449: 6/10/2009 10:06:43 AM - Installed DirectX
      RP450: 6/10/2009 9:27:52 PM - Installed Diskeeper 2009 Pro Premier.
      RP451: 6/10/2009 9:43:15 PM - Software Distribution Service 3.0
      RP452: 6/12/2009 1:13:36 AM - System Checkpoint
      RP453: 6/13/2009 1:22:58 AM - System Checkpoint
      RP454: 6/14/2009 2:23:10 AM - System Checkpoint
      RP455: 6/15/2009 2:57:18 PM - System Checkpoint
      RP456: 6/16/2009 3:21:45 PM - System Checkpoint
      RP457: 6/17/2009 3:58:22 PM - System Checkpoint
      RP458: 6/19/2009 1:12:16 AM - System Checkpoint
      RP459: 6/21/2009 4:34:39 PM - System Checkpoint
      RP460: 6/22/2009 5:33:43 PM - System Checkpoint
      RP461: 6/23/2009 9:45:40 AM - Avg8 Update
      RP462: 6/24/2009 9:51:06 AM - System Checkpoint
      RP463: 6/25/2009 11:57:53 AM - System Checkpoint
      RP464: 6/26/2009 12:18:36 PM - System Checkpoint

      ==== Installed Programs ======================

      µTorrent
      AC3Filter (remove only)
      Ad-Aware
      Adobe Anchor Service CS3
      Adobe Asset Services CS3
      Adobe Bridge CS3
      Adobe Bridge Start Meeting
      Adobe Camera Raw 4.0
      Adobe CMaps
      Adobe Color - Photoshop Specific
      Adobe Color Common Settings
      Adobe Color EU Extra Settings
      Adobe Color JA Extra Settings
      Adobe Color NA Recommended Settings
      Adobe Default Language CS3
      Adobe Device Central CS3
      Adobe ExtendScript Toolkit 2
      Adobe Flash Player 10 ActiveX
      Adobe Flash Player 10 Plugin
      Adobe Fonts All
      Adobe Help Viewer CS3
      Adobe LINGUISTICS CS3
      Adobe PDF Library Files
      Adobe Photoshop CS3
      Adobe Reader 8.1.5
      Adobe Setup
      Adobe Shockwave Player
      Adobe Stock Photos CS3
      Adobe Type Support
      Adobe Update Manager CS3
      Adobe Version Cue CS3 Client
      Adobe WinSoft Linguistics Plugin
      Adobe XMP Panels CS3
      Advanced Audio FX Engine
      Advanced Video FX Engine
      AIM 6
      AltoMP3 Gold 5.20
      Apple Mobile Device Support
      Apple Software Update
      Audiosurf
      AVG Free 8.5
      AVS DVD Copy version 1.3
      Bonjour
      Broadcom Management Programs
      Browser Address Error Redirector
      CCleaner (remove only)
      Conexant HDA D330 MDC V.92 Modem
      ConvertXtoDVD 2.2.3.258
      COWON Media Center - jetAudio Basic
      Critical Update for Windows Media Player 11 (KB959772)
      Dell Automated PC TuneUp
      Dell Touchpad
      Dell Webcam Center
      Dell Webcam Manager
      Dell Wireless WLAN Card Utility
      Digital Line Detect
      Diskeeper 2009 Pro Premier
      Download Updater (AOL LLC)
      eMusic Download Manager 3.0
      GOM Player
      Guitar Hero III
      High Definition Audio Driver Package - KB835221
      HijackThis 2.0.2
      Hotfix for Windows Media Format 11 SDK (KB929399)
      Hotfix for Windows Media Player 11 (KB939683)
      Hotfix for Windows XP (KB926239)
      Hotfix for Windows XP (KB952287)
      IntelliSonic Speech Enhancement
      InterVideo Disc Master 2.5
      InterVideo DVDCopy 2
      InterVideo PhotoAlbum
      InterVideo WinDVD
      InterVideo WinDVD Creator 2
      IrfanView (remove only)
      iTunes
      Java(TM) 6 Update 13
      Laptop Integrated Webcam Driver (1.03.02.0719)
      LimeWire 5.1.2
      Live! Cam Avatar Creator
      Live! Cam Avatar v1.0
      Magic Video Converter Trial Version (English) 8.0.2.18
      Malwarebytes' Anti-Malware
      Maxtor Manager
      MediaMonkey 3.0
      Memeo AutoSync
      Microsoft .NET Framework 1.1
      Microsoft .NET Framework 1.1 Hotfix (KB928366)
      Microsoft .NET Framework 2.0
      Microsoft Compression Client Pack 1.0 for Windows XP
      Microsoft IntelliPoint 5.5
      Microsoft Office 97, Professional Edition
      Microsoft SQL Server Desktop Engine (SONY_MEDIAMGR)
      Microsoft User-Mode Driver Framework Feature Pack 1.0
      Microsoft Visual C++ 2005 Redistributable
      Microsoft Works
      Microsoft XML Parser
      MobileMe Control Panel
      Mozilla Firefox (3.0.11)
      MSXML 4.0 SP2 (KB936181)
      MSXML 4.0 SP2 (KB954430)
      MSXML 6 Service Pack 2 (KB954459)
      NavNet
      Nero 8 Essentials
      neroxml
      NVIDIA Drivers
      PCFriendly
      PDF Settings
      PeerGuardian 2.0
      PowerISO
      PureSight PC
      QuickSet
      QuickTime
      Registry Winner 5.2
      Roxio Creator Audio
      Roxio Creator BDAV Plugin
      Roxio Creator Copy
      Roxio Creator Data
      Roxio Creator DE
      Roxio Creator Tools
      Roxio Drag-to-Disc
      Roxio Express Labeler
      Roxio MyDVD DE
      Roxio Update Manager
      Safari
      SceneCaster
      SearchAssist
      Security Update for Step By Step Interactive Training (KB923723)
      Security Update for Windows Internet Explorer 8 (KB969897)
      Security Update for Windows Media Player (KB952069)
      Security Update for Windows Media Player 11 (KB936782)
      Security Update for Windows Media Player 11 (KB954154)
      Security Update for Windows XP (KB893756)
      Security Update for Windows XP (KB896428)
      Security Update for Windows XP (KB899587)
      Security Update for Windows XP (KB900725)
      Security Update for Windows XP (KB901017)
      Security Update for Windows XP (KB902400)
      Security Update for Windows XP (KB905414)
      Security Update for Windows XP (KB905749)
      Security Update for Windows XP (KB911927)
      Security Update for Windows XP (KB913580)
      Security Update for Windows XP (KB914389)
      Security Update for Windows XP (KB917953)
      Security Update for Windows XP (KB922819)
      Security Update for Windows XP (KB923980)
      Security Update for Windows XP (KB927779)
      Security Update for Windows XP (KB931784)
      Security Update for Windows XP (KB933729)
      Security Update for Windows XP (KB938464)
      Security Update for Windows XP (KB939653)
      Security Update for Windows XP (KB941202)
      Security Update for Windows XP (KB941568)
      Security Update for Windows XP (KB941569)
      Security Update for Windows XP (KB941644)
      Security Update for Windows XP (KB941693)
      Security Update for Windows XP (KB942615)
      Security Update for Windows XP (KB943055)
      Security Update for Windows XP (KB943460)
      Security Update for Windows XP (KB943485)
      Security Update for Windows XP (KB944338)
      Security Update for Windows XP (KB944533)
      Security Update for Windows XP (KB944653)
      Security Update for Windows XP (KB945553)
      Security Update for Windows XP (KB946026)
      Security Update for Windows XP (KB946648)
      Security Update for Windows XP (KB947864)
      Security Update for Windows XP (KB948590)
      Security Update for Windows XP (KB948881)
      Security Update for Windows XP (KB950749)
      Security Update for Windows XP (KB950759)
      Security Update for Windows XP (KB950760)
      Security Update for Windows XP (KB950762)
      Security Update for Windows XP (KB950974)
      Security Update for Windows XP (KB951066)
      Security Update for Windows XP (KB951376-v2)
      Security Update for Windows XP (KB951376)
      Security Update for Windows XP (KB951698)
      Security Update for Windows XP (KB951748)
      Security Update for Windows XP (KB952004)
      Security Update for Windows XP (KB952954)
      Security Update for Windows XP (KB953838)
      Security Update for Windows XP (KB953839)
      Security Update for Windows XP (KB954211)
      Security Update for Windows XP (KB954600)
      Security Update for Windows XP (KB955069)
      Security Update for Windows XP (KB956390)
      Security Update for Windows XP (KB956391)
      Security Update for Windows XP (KB956572)
      Security Update for Windows XP (KB956802)
      Security Update for Windows XP (KB956803)
      Security Update for Windows XP (KB956841)
      Security Update for Windows XP (KB957095)
      Security Update for Windows XP (KB957097)
      Security Update for Windows XP (KB958215)
      Security Update for Windows XP (KB958644)
      Security Update for Windows XP (KB958687)
      Security Update for Windows XP (KB958690)
      Security Update for Windows XP (KB959426)
      Security Update for Windows XP (KB960225)
      Security Update for Windows XP (KB960714)
      Security Update for Windows XP (KB960715)
      Security Update for Windows XP (KB960803)
      Security Update for Windows XP (KB961373)
      Security Update for Windows XP (KB961501)
      Security Update for Windows XP (KB963027)
      Security Update for Windows XP (KB968537)
      Security Update for Windows XP (KB969898)
      Security Update for Windows XP (KB970238)
      Skype™ 4.0
      Sonic Activation Module
      Sony ACID Music Studio 7.0
      SUPERAntiSpyware Free Edition
      Uniblue DriverScanner 2009
      Update for Windows Internet Explorer 8 (KB971180)
      Update for Windows XP (KB894391)
      Update for Windows XP (KB898461)
      Update for Windows XP (KB900485)
      Update for Windows XP (KB910437)
      Update for Windows XP (KB911280)
      Update for Windows XP (KB916595)
      Update for Windows XP (KB920872)
      Update for Windows XP (KB922582)
      Update for Windows XP (KB927891)
      Update for Windows XP (KB930916)
      Update for Windows XP (KB932823-v3)
      Update for Windows XP (KB936357)
      Update for Windows XP (KB942763)
      Update for Windows XP (KB942840)
      Update for Windows XP (KB946627)
      Update for Windows XP (KB951072-v2)
      Update for Windows XP (KB955839)
      Update for Windows XP (KB967715)
      VCRedistSetup
      Viewpoint Media Player
      WD Diagnostics
      WebFldrs XP
      Windows Internet Explorer 8
      Windows Media Format 11 runtime
      Windows Media Player 11
      Windows XP Hotfix - KB885836
      Windows XP Hotfix - KB886185
      Windows XP Hotfix - KB888302
      Windows XP Hotfix - KB890859
      WinRAR archiver
      Xbox 360 Controller for Windows
      Xvid 1.2.1 final uninstall

      ==== Event Viewer Messages From Past Week ========

      7/8/2009 9:55:59 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the NVSvc service.
      7/5/2009 8:28:17 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
      7/5/2009 7:46:51 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 240 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
      7/5/2009 4:46:51 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 60 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
      7/5/2009 4:16:51 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 30 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
      7/5/2009 4:01:51 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
      7/5/2009 2:26:40 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 120 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
      7/5/2009 12:32:17 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
      7/5/2009 12:29:44 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
      7/5/2009 12:27:00 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
      7/5/2009 12:02:37 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD APPDRV AvgLdx86 AvgMfx86 Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss SASDIFSV SASKUTIL SCDEmu Tcpip Tcpip6 WS2IFSL
      7/5/2009 12:02:37 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
      7/5/2009 12:02:37 PM, error: Service Control Manager [7001] - The IPv6 Helper Service service depends on the Microsoft IPv6 Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
      7/5/2009 12:02:37 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
      7/5/2009 12:02:37 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
      7/5/2009 12:02:37 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
      7/5/2009 12:02:37 PM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
      7/5/2009 12:02:37 PM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
      7/2/2009 6:08:21 PM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.
      7/2/2009 6:08:10 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}
      7/2/2009 6:06:51 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
      7/2/2009 5:37:06 PM, error: NetBT [4307] - Initialization failed because the transport refused to open initial Addresses.
      7/2/2009 1:04:29 PM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
      7/2/2009 1:03:56 PM, error: Service Control Manager [7023] - The IPSEC Services service terminated with the following error: The requested service provider could not be loaded or initialized.

      ==== End Of File ===========================


      thank you!

      Go to Add or Remove Programs and uninstall:

      - Browser Address Error Redirector
      - Registry Winner 5.2 <- See here
      - SearchAssist
      - Viewpoint Media Player

      ----------

      • Please download LSPFix
      • Run the LSPFix.exe that you have just finished downloading.
      • Check the I know what I'm doing box.
      • In the Keep box you should see one or more instances of winsflt.dll
      • Select every instance of winsflt.dll and move each one to the Remove box by clicking the &GT;> button.
      • If the winsflt.dll file only appears on the right side then just click fix checked and close the program.
      • When you are done click Finish>>
      .
      Important! Restart the computer.

      ----------

      Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

      Link #1
      Link #2

      **Note: It is important that it is saved directly to your Desktop

      DO NOT run it yet!

      Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

      Delete these files/folders, as follows:

      1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
      It MUST be Notepad, not Wordpad.
      2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

      Code: [Select]KillAll::

      Driver::
      Viewpoint Manager Service

      Folder::
      c:\program files\viewpoint
      c:\program files\Registry Winner

      File::
      c:\windows\system32\19.tmp

      DDS::
      uInternet Settings,ProxyOverride = *.local
      mRun: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u

      Firefox::
      FF - ProfilePath - c:\docume~1\tbrown~1\applic~1\mozilla\firefox\profiles\ih8nvsnl.default\
      FF - prefs.js: browser.search.selectedEngine - Yoog Search
      FF - prefs.js: keyword.URL - hxxp://www10.yoog.com/search.php?q=
      FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
      FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
      FF - user.js: browser.search.selectedEngine - Yoog Search
      FF - user.js: keyword.URL - hxxp://www10.yoog.com/search.php?q=

      3. Go to the Notepad window and click Edit > Paste
      4. Then click File > Save
      5. Name the file CFScript.txt - Save the file to your Desktop
      6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



      ComboFix will begin to execute, just follow the prompts.
      After reboot (in case it asks to reboot), it will produce a log for you.
      Post that log (Combofix.txt) in your next reply.

      Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze
      Due to only being able to access my computer in safe mode, only three of the four programs I was told to uninstall were able to be uninstalled.

      The 'Browser Address Error Redirector' was unable to be uninstalled.

      Regrettably, I was also unable to run ComboFix due to the safe mode option.

      Any other advice would be greatly appreciated, thank you.Do you have a flash drive and another computer to transfer over the programs?

      What about Safe Mode With Networking?
      3864.

      Solve : I get an error message every time i start my computer..??

      Answer»

      every time WINDOWS loads a pop up BOX SHOWS up and says
      "ERROR loading c:\windows\system32\ebylcois.dll"
      all i can click is OK..

      [attachment deleted by admin]

      3865.

      Solve : help! my internet connection got blocked after got infected by dirsystem autorun?

      Answer»

      My connection got lost when I plugged a flashdisk with autorun.inf and dirsystem VIRUS, I already cleaned both and no more autoplay when I dbl click my drive

      But I lost my connection, when my modem is about to CONNECT, it suddenly shuts off and blinking it's lamp like never before (It USUALLY shows normal IDLE lights showing normal internet traffic) does a virus can damage my modem?THIS IS A DOUBLE POST

      3866.

      Solve : Re: Virus has disabled all my protection programs?

      Answer»

      evilfantasy, hopefully you're still around.

      I'm having the same problem. Though I don't have Viewpoint.

      Any ideas? Thanks in advance, here are the logs...


      DDS (Ver_09-06-26.01) - NTFSx86
      Run by Mike at 15:29:15.31 on Wed 07/08/2009
      Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_11
      Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3572.2264 [GMT -4:00]

      AV: CA Anti-Virus *On-access scanning disabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
      FW: CA Personal Firewall *enabled* {14CB4B80-8E52-45EA-905E-67C1267B4160}

      ============== Running Processes ===============

      c:\Program Files\Fingerprint Sensor\AtService.exe
      C:\WINDOWS\system32\svchost -k DcomLaunch
      svchost.exe
      C:\WINDOWS\System32\svchost.exe -k netsvcs
      C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
      C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
      svchost.exe
      svchost.exe
      C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
      C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
      C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
      C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
      c:\drivers\audio\r190031\stacsv.exe
      C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
      C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
      svchost.exe
      C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe
      C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
      C:\Program Files\Intel\ASF Agent\ASFAgent.exe
      C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe
      C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
      C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe
      C:\Program Files\Intel\WiFi\bin\EvtEng.exe
      C:\WINDOWS\system32\svchost.exe -k HPService
      C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
      C:\WINDOWS\system32\inetsrv\inetinfo.exe
      C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
      C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
      C:\Program Files\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe
      C:\WINDOWS\System32\svchost.exe -k HPZ12
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\System32\svchost.exe -k HPZ12
      C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
      C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
      C:\WINDOWS\system32\svchost.exe -k imgsvc
      C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
      C:\Program Files\Intel\WiFi\bin\WLKeeper.exe
      C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe
      C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
      C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\Wave Systems Corp\SecureUpgrade.exe
      C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe
      C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\WINDOWS\system32\rundll32.exe
      C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe
      C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
      C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe
      C:\Program Files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe
      C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe
      C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
      C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
      C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
      C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
      C:\WINDOWS\system32\wbem\unsecapp.exe
      C:\Program Files\DellTPad\Apoint.exe
      C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
      C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
      C:\Program Files\DAEMON Tools Lite\daemon.exe
      C:\Program Files\DellTPad\ApMsgFwd.exe
      C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
      C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe
      C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
      C:\Program Files\DellTPad\HidFind.exe
      C:\Program Files\DellTPad\Apntex.exe
      C:\Program Files\Dell\Dell WUSB\WQ_Tray2.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\WINDOWS\System32\svchost.exe -k HTTPFilter
      C:\Program Files\Java\jre6\bin\java.exe
      C:\Program Files\Java\jre6\bin\jucheck.exe
      C:\WINDOWS\system32\dllhost.exe
      c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
      C:\Program Files\Trend Micro\HijackThis\HJ-This.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\Documents and Settings\Mike\Desktop\dds.com

      ============== Pseudo HJT Report ===============

      uStart Page = hxxp://www.google.com/ig?hl=en&source=iglk
      uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/
      BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
      BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
      BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
      BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
      BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
      BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      BHO: CA Toolbar Helper: {fbf2401b-7447-4727-be5d-c19b2075ca84} - c:\program files\ca\ca internet security suite\ca website inspector\toolbar\CallingIDIE.dll
      BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
      TB: CA Toolbar: {10134636-e7af-4ac5-a1dc-c7c44bb97d81} - c:\program files\ca\ca internet security suite\ca website inspector\toolbar\CallingIDIE.dll
      TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
      uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
      uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
      uRun: [igndlm.exe] c:\program files\download manager\DLM.exe /windowsstart /startifwork
      uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun
      mRun: [WavXMgr] c:\program files\wave systems corp\services manager\docmgr\bin\WavXDocMgr.exe
      mRun: [VetStart] "c:\program files\ca\ca internet security suite\ca anti-virus\vetmsg.exe" -r
      mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
      mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
      mRun: [SecureUpgrade] "c:\program files\wave systems corp\SecureUpgrade.exe"
      mRun: [QOELOADER] "c:\program files\ca\ca internet security suite\ca anti-spam\qsp-6.0.1.33\QOELoader.exe"
      mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
      mRun: [nwiz] nwiz.exe /installquiet
      mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
      mRun: [NVHotkey] rundll32.exe nvHotkey.dll,Start
      mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
      mRun: [IntelZeroConfig] "c:\program files\intel\wifi\bin\ZCfgSvc.exe"
      mRun: [IntelWireless] "c:\program files\common files\intel\wirelesscommon\iFrmewrk.exe" /tf Intel Wireless Tray
      mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
      mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
      mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
      mRun: [EmbassySecurityCheck] "c:\program files\wave systems corp\embassy security setup\EMBASSYSecurityCheck.exe"
      mRun: [DellControlPoint] "c:\program files\dell\dell controlpoint\Dell.ControlPoint.exe"
      mRun: [DellConnectionManager] "c:\program files\dell\dell controlpoint\connection manager\Dell.UCM.exe"
      mRun: [Dell Webcam Central] "c:\program files\dell webcam\dell webcam central\WebcamDell.exe" /mode2
      mRun: [DCPstrApp] c:\program files\dell\dell controlpoint\security manager\SecurityDeviceInfoSetRegistryString.exe
      mRun: [cctray] "c:\program files\ca\ca internet security suite\cctray\cctray.exe"
      mRun: [CAVRID] "c:\program files\ca\ca internet security suite\ca anti-virus\CAVRID.exe"
      mRun: [capfupgrade] c:\program files\ca\ca internet security suite\ca personal firewall\capfupgrade.exe
      mRun: [capfasem] c:\program files\ca\ca internet security suite\ca personal firewall\capfasem.exe
      mRun: [cafw] c:\program files\ca\ca internet security suite\ca personal firewall\cafw.exe -cl
      mRun: [Apoint] c:\program files\delltpad\Apoint.exe
      mRun: [AESTFltr] %SystemRoot%\system32\AESTFltr.exe /NoDlg
      mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
      mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
      mRun: [XboxStat] "c:\program files\microsoft xbox 360 accessories\XboxStat.exe" silentrun
      dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
      StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
      StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\dellco~1.lnk - c:\program files\dell\dell controlpoint\system manager\DCPSysMgr.exe
      StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
      StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wirele~1.lnk - c:\program files\dell\dell wusb\WQ_Tray2.exe
      mPolicies-explorer: EnableShellExecuteHooks = 1 (0x1)
      IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
      IE: Send to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
      IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
      IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
      IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
      IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
      IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
      IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
      LSP: c:\windows\system32\VetRedir.dll
      DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.7.109.cab
      DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
      DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
      DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
      DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
      TCP: NameServer = 85.255.112.79,85.255.112.213
      TCP: {866C1E47-FF68-455E-AD71-3AE69957E117} = 85.255.112.79,85.255.112.213
      TCP: {DCA54876-7E5A-4779-9A54-9DCE2C423748} = 85.255.112.79,85.255.112.213
      Notify: PFW - UmxWnp.Dll
      SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
      SEH: ShellHook Class: {1869181a-9f50-4fcf-8bff-1b8588ecb85c} - c:\program files\ca\ca internet security suite\ca website inspector\linkadvisor\CIDLinkAdvisor.dll
      LSA: Authentication Packages = msv1_0 wvauth

      ================= FIREFOX ===================

      FF - ProfilePath - c:\docume~1\mike\applic~1\mozilla\firefox\profiles\netkdg3u.default\
      FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?hl=en&source=iglk
      FF - plugin: c:\documents and settings\mike\application data\mozilla\firefox\profiles\netkdg3u.default\extensions\[emailprotected]\plugins\npGameTapWebUpdater.dll
      FF - plugin: c:\documents and settings\mike\application data\mozilla\firefox\profiles\netkdg3u.default\extensions\[emailprotected]\platform\winnt_x86-msvc\plugins\npmnqmp071303000006.dll
      FF - plugin: c:\program files\download manager\npfpdlm.dll
      FF - plugin: c:\program files\gametap web player\bin\release\npGameTapWebPlayer.dll
      FF - HiddenExtension: Microsoft .NET Framework ASSISTANT: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
      FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}

      ============= SERVICES / DRIVERS ===============

      R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [2008-3-19 93712]
      R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-16 64160]
      R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [2008-3-21 63504]
      R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [2008-3-21 45584]
      R1 VET-FILT;VET File System Filter;c:\windows\system32\drivers\vet-filt.sys [2009-1-17 26352]
      R1 VET-REC;VET File System Recognizer;c:\windows\system32\drivers\vet-rec.sys [2009-1-17 21104]
      R1 VETEFILE;VET File Scan Engine;c:\windows\system32\drivers\vetefile.sys [2009-1-17 880560]
      R1 VETFDDNT;VET Floppy Boot Sector Monitor;c:\windows\system32\drivers\vetfddnt.sys [2009-1-17 21488]
      R1 VETMONNT;VET File Monitor;c:\windows\system32\drivers\vetmonnt.sys [2009-1-17 161008]
      R2 ASFAgent;ASF Agent;c:\program files\intel\asf agent\ASFAgent.exe [2007-4-19 133968]
      R2 ATService;AuthenTec Fingerprint Service;c:\program files\fingerprint sensor\AtService.exe [2008-6-12 1164536]
      R2 buttonsvc32;Dell ControlPoint Button Service;c:\program files\dell\dell controlpoint\DCPButtonSvc.exe [2008-6-3 386328]
      R2 CAISafe;CAISafe;c:\program files\ca\ca internet security suite\ca anti-virus\isafe.exe [2009-1-17 144696]
      R2 Credential Vault Host Control Service;Credential Vault Host Control Service;c:\program files\broadcom corporation\broadcom ush host components\cv\bin\HostControlService.exe [2008-11-11 808296]
      R2 Credential Vault Host Storage;Credential Vault Host Storage;c:\program files\broadcom corporation\broadcom ush host components\cv\bin\HostStorageService.exe [2008-11-11 20840]
      R2 dcpsysmgrsvc;Dell ControlPoint System Manager;c:\program files\dell\dell controlpoint\system manager\DCPSysMgrSvc.exe [2008-8-2 455960]
      R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [2008-3-21 66576]
      R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1029456]
      R2 MsDtsServer;SQL Server Integration Services;c:\program files\microsoft sql server\90\dts\binn\MsDtsSrvr.exe [2007-3-3 202096]
      R2 SMManager;Smith Micro Connection Manager Service;c:\program files\dell\dell controlpoint\connection manager\SMManager.exe [2008-9-9 69632]
      R2 UmxAgent;HIPS Event Manager;c:\program files\ca\sharedcomponents\hipsengine\UmxAgent.exe [2007-10-18 1010192]
      R2 UmxCfg;HIPS Configuration Interpreter;c:\program files\ca\sharedcomponents\hipsengine\UmxCfg.exe [2007-10-18 801296]
      R2 UmxPol;HIPS Policy Manager;c:\program files\ca\sharedcomponents\hipsengine\UmxPol.exe [2008-4-15 281104]
      R2 VETMSGNT;VET Message Service;c:\program files\ca\ca internet security suite\ca anti-virus\vetmsg.exe [2009-1-17 255216]
      R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [2008-12-16 108160]
      R3 CCIDFILTER;Broadcom Smart Card Reader Filter Driver;c:\windows\system32\drivers\ccidflt.sys [2009-1-20 12840]
      R3 cvusbdrv;Broadcom USH CV;c:\windows\system32\drivers\cvusbdrv.sys [2009-1-20 32808]
      R3 e1yexpress;Intel(R) Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [2008-12-16 244368]
      R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [2008-5-30 88816]
      R3 OA001Afx;Provides a software interface to control audio effects of OA001 camera.;c:\windows\system32\drivers\OA001Afx.sys [2008-12-16 148056]
      R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;c:\windows\system32\drivers\OA001Ufd.sys [2008-12-16 144672]
      R3 OA001Vid;Creative Camera OA001 Function Driver;c:\windows\system32\drivers\OA001Vid.sys [2008-12-16 277440]
      R3 PPCtlPriv;PPCtlPriv;c:\program files\ca\ca internet security suite\ca anti-spyware\PPCtlPriv.exe [2009-1-17 185584]
      R3 VETEBOOT;VET Boot Scan Engine;c:\windows\system32\drivers\veteboot.sys [2009-1-17 108368]
      R3 WQ_USBHWA;WiQuest Host Wire Adapter driver;c:\windows\system32\drivers\WQ_hwa.sys [2009-1-21 164664]
      R3 WQ_USBRCI;WiQuest UltraWideBand driver;c:\windows\system32\drivers\WQ_rci.sys [2009-1-21 77880]
      S3 AsfAlrt;AsfAlrt Service;c:\windows\system32\drivers\Asfalrt.sys [2007-4-19 42832]
      S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2009-5-11 33176]
      S3 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [2008-6-4 134648]
      S3 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [2008-3-19 115216]
      S3 VSPerfDrv;Performance Tools Driver;c:\program files\microsoft visual studio 8\team tools\performance tools\VSPerfDrv.sys [2006-12-2 48128]
      S3 WQ_USBLOAD;WiQuest WUSB Loader driver;c:\windows\system32\drivers\WQ_ldr.sys [2009-1-21 33592]
      S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\microsoft visual studio 8\common7\ide\remote debugger\x86\msvsmon.exe [2006-12-2 2805000]

      =============== Created Last 30 ================

      2009-07-08 12:20--d-----c:\program files\Trend Micro
      2009-07-08 12:1838,160a-------c:\windows\system32\drivers\mbamswissarmy.sys
      2009-07-08 12:1819,096a-------c:\windows\system32\drivers\mbam.sys
      2009-07-08 12:18--d-----c:\docume~1\alluse~1\applic~1\Malwarebytes
      2009-07-08 12:18--d-----c:\program files\Malwarebytes' Anti-Malware
      2009-07-08 12:00--d-----c:\program files\CCleaner
      2009-07-06 22:390a---h---c:\windows\system32\drivers\Msft_Kernel_xusb21_01001.Wdf
      2009-07-06 21:55--d-----c:\program files\GameTap Web Player
      2009-07-06 21:55--d-----c:\docume~1\alluse~1\applic~1\GameTap Web Player
      2009-07-06 21:361,421,216a-------c:\windows\system32\WdfCoInstaller01001.dll
      2009-07-06 21:3661,984a-------c:\windows\system32\drivers\xusb21.sys
      2009-07-06 21:36--d-----c:\program files\Microsoft Xbox 360 Accessories
      2009-07-06 21:3668,888a-------c:\windows\system32\xinput1_3.dll
      2009-06-25 05:14--d-----c:\program files\common files\DivX Shared
      2009-06-25 05:14--d-----c:\program files\DivX
      2009-06-19 02:12--d-----c:\program files\common files\HP
      2009-06-19 02:11271,704a----r--c:\windows\system32\hpzids01.dll
      2009-06-19 02:10309,760a----r--c:\windows\system32\difxapi.dll
      2009-06-19 02:10970,752a----r--c:\windows\system32\hpwtiop3.dll
      2009-06-19 02:10729,088a----r--c:\windows\system32\hpwwiax3.dll
      2009-06-19 02:10364,544a----r--c:\windows\system32\hppldcoi.dll
      2009-06-19 02:10294,912a----r--c:\windows\system32\hpovst11.dll
      2009-06-19 02:061,108a----r--c:\windows\hpwmdl14.dat
      2009-06-19 02:06179,579a-------c:\windows\hpwins14.dat
      2009-06-19 00:56--d-----c:\windows\pss
      2009-06-17 13:561,089,593--------c:\windows\system32\dllcache\ntprint.cat
      2009-06-16 20:38--dsh---c:\documents and settings\mike\PrivacIE
      2009-06-16 20:33--dsh---c:\documents and settings\mike\IETldCache
      2009-06-16 20:09--d-----c:\windows\system32\XPSViewer
      2009-06-16 20:09597,504--------c:\windows\system32\dllcache\printfilterpipelinesvc.exe
      2009-06-16 20:09575,488--------c:\windows\system32\xpsshhdr.dll
      2009-06-16 20:09575,488--------c:\windows\system32\dllcache\xpsshhdr.dll
      2009-06-16 20:09117,760--------c:\windows\system32\prntvpt.dll
      2009-06-16 20:0989,088--------c:\windows\system32\dllcache\filterpipelineprintproc.dll
      2009-06-16 20:09--d-----C:\d92bfe9cccee40cb2aa3
      2009-06-16 20:091,676,288--------c:\windows\system32\xpssvcs.dll
      2009-06-16 20:091,676,288--------c:\windows\system32\dllcache\xpssvcs.dll
      2009-06-16 20:09--d-----c:\windows\SxsCaPendDel
      2009-06-16 19:58246,272--------c:\windows\system32\dllcache\ieproxy.dll
      2009-06-16 19:5812,800--------c:\windows\system32\dllcache\xpshims.dll
      2009-06-16 19:57--d-----c:\windows\ie8updates
      2009-06-16 19:57102,912--------c:\windows\system32\dllcache\iecompat.dll
      2009-06-16 19:57-cd-h---c:\windows\ie8
      2009-06-16 19:17--d-----c:\windows\system32\scripting
      2009-06-16 19:17--d-----c:\windows\system32\en
      2009-06-16 19:17--d-----c:\windows\system32\bits
      2009-06-16 19:17--d-----c:\windows\l2schemas
      2009-06-16 19:15--d-----c:\windows\ServicePackFiles
      2009-06-16 05:2015,688a-------c:\windows\system32\lsdelete.exe
      2009-06-16 05:0864,160a-------c:\windows\system32\drivers\Lbd.sys
      2009-06-16 05:04-cd-h---c:\docume~1\alluse~1\applic~1\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
      2009-06-16 05:03--d-----c:\program files\Lavasoft
      2009-06-16 05:01102,664a-------c:\windows\system32\drivers\tmcomm.sys
      2009-06-16 05:00--d-----c:\documents and settings\mike\.housecall6.6
      2009-06-09 19:38268,288--------c:\windows\system32\dllcache\httpext.dll

      ==================== Find3M ====================

      2009-07-08 12:41319,162a-------c:\windows\system32\drivers\kmxcfg.u2k0
      2009-07-08 12:4164a-------c:\windows\system32\drivers\kmxcfg.u2k7
      2009-07-08 12:4164a-------c:\windows\system32\drivers\kmxcfg.u2k6
      2009-07-08 12:4164a-------c:\windows\system32\drivers\kmxcfg.u2k5
      2009-07-08 12:4164a-------c:\windows\system32\drivers\kmxcfg.u2k4
      2009-07-08 12:4164a-------c:\windows\system32\drivers\kmxcfg.u2k3
      2009-07-08 12:4164a-------c:\windows\system32\drivers\kmxcfg.u2k2
      2009-07-08 12:4164a-------c:\windows\system32\drivers\kmxcfg.u2k1
      2009-07-07 00:4442,464a-------c:\windows\system32\nvModes.dat
      2009-06-16 19:1988,375a-------c:\windows\pchealth\helpctr\offlinecache\index.dat
      2009-05-23 03:07161,008a-------c:\windows\system32\drivers\vetmonnt.sys
      2009-05-23 03:0726,352a-------c:\windows\system32\drivers\vet-filt.sys
      2009-05-23 03:0721,488a-------c:\windows\system32\drivers\vetfddnt.sys
      2009-05-23 03:0721,104a-------c:\windows\system32\drivers\vet-rec.sys
      2009-05-13 17:5490,112a-------c:\windows\system32\dpl100.dll
      2009-05-13 17:54823,296a-------c:\windows\system32\divx_xx0c.dll
      2009-05-13 17:54823,296a-------c:\windows\system32\divx_xx07.dll
      2009-05-13 17:54815,104a-------c:\windows\system32\divx_xx0a.dll
      2009-05-13 17:54811,008a-------c:\windows\system32\divx_xx16.dll
      2009-05-13 17:54802,816a-------c:\windows\system32\divx_xx11.dll
      2009-05-13 17:54685,056a-------c:\windows\system32\DivX.dll
      2009-05-13 01:15915,456a-------c:\windows\system32\wininet.dll
      2009-05-13 01:155,936,128--------c:\windows\system32\dllcache\mshtml.dll
      2009-05-13 01:15915,456--------c:\windows\system32\dllcache\wininet.dll
      2009-05-07 11:32345,600a-------c:\windows\system32\localspl.dll
      2009-05-07 11:32345,600--------c:\windows\system32\dllcache\localspl.dll
      2009-04-30 17:221,985,024--------c:\windows\system32\dllcache\iertutil.dll
      2009-04-30 17:2211,064,832--------c:\windows\system32\dllcache\ieframe.dll
      2009-04-30 17:221,207,808--------c:\windows\system32\dllcache\urlmon.dll
      2009-04-30 17:2225,600--------c:\windows\system32\dllcache\jsproxy.dll
      2009-04-30 17:22385,536--------c:\windows\system32\dllcache\iedkcs32.dll
      2009-04-30 07:21173,056--------c:\windows\system32\dllcache\ie4uinit.exe
      2009-04-29 00:55133,120--------c:\windows\system32\dllcache\extmgr.dll
      2009-04-28 05:0513,824--------c:\windows\system32\dllcache\ieudinit.exe
      2009-04-17 06:501,847,808a-------c:\windows\system32\win32k.sys
      2009-04-17 06:501,847,808--------c:\windows\system32\dllcache\win32k.sys
      2009-04-15 10:51585,216a-------c:\windows\system32\rpcrt4.dll
      2009-04-15 10:51585,216--------c:\windows\system32\dllcache\rpcrt4.dll
      2009-01-17 14:1261,224a-------c:\documents and settings\mike\GoToAssistDownloadHelper.exe

      ============= FINISH: 15:30:10.95 ===============



      UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
      IF REQUESTED, ZIP IT UP & ATTACH IT

      DDS (Ver_09-06-26.01)

      Microsoft Windows XP Professional
      Boot Device: \Device\HarddiskVolume2
      Install Date: 1/15/2009 7:11:59 PM
      System Uptime: 7/8/2009 2:21:53 PM (1 hours AGO)

      Motherboard: Dell Inc. | | 0NY980
      Processor: Intel(R) Core(TM)2 Duo CPU T9400 @ 2.53GHz | Microprocessor | 783/266mhz

      ==== Disk Partitions =========================

      C: is FIXED (NTFS) - 233 GiB total, 171.233 GiB free.
      D: is CDROM (CDFS)
      F: is CDROM ()

      ==== Disabled Device Manager Items =============

      Class GUID: {4D36E97D-E325-11CE-BFC1-08002BE10318}
      Description: Broadcom TPM Device
      Device ID: ACPI\BCM0102\4&DCE5D5B&0
      Manufacturer: Broadcom
      Name: Broadcom TPM
      PNP Device ID: ACPI\BCM0102\4&DCE5D5B&0
      Service: BCMTPM

      Class GUID: {4D36E971-E325-11CE-BFC1-08002BE10318}
      Description: Officejet J6400 series
      Device ID: ROOT\MULTIFUNCTION\0000
      Manufacturer: HP
      Name: Officejet J6400 series
      PNP Device ID: ROOT\MULTIFUNCTION\0000
      Service:

      Class GUID: {4D36E979-E325-11CE-BFC1-08002BE10318}
      Description: Officejet J6400 series
      Device ID: ROOT\PRINTER\0000
      Manufacturer: HP
      Name: Officejet J6400 series
      PNP Device ID: ROOT\PRINTER\0000
      Service:

      Class GUID: {53D29EF7-377C-4D14-864B-EB3A85769359}
      Description: TouchChip Fingerprint Reader
      Device ID: ROOT\UNKNOWN\0000
      Manufacturer: UPEK
      Name: TouchChip Fingerprint Reader
      PNP Device ID: ROOT\UNKNOWN\0000
      Service: TcUsb

      ==== System Restore Points ===================

      RP92: 4/10/2009 4:41:54 AM - System Checkpoint
      RP93: 4/11/2009 4:57:56 AM - System Checkpoint
      RP94: 4/12/2009 1:06:30 PM - System Checkpoint
      RP95: 4/13/2009 7:38:37 PM - System Checkpoint
      RP96: 4/15/2009 12:03:00 AM - System Checkpoint
      RP97: 4/16/2009 2:15:47 AM - System Checkpoint
      RP98: 4/16/2009 3:00:24 AM - Software Distribution Service 3.0
      RP99: 4/17/2009 4:52:30 AM - System Checkpoint
      RP100: 4/18/2009 1:05:17 PM - System Checkpoint
      RP101: 4/19/2009 1:20:05 PM - System Checkpoint
      RP102: 4/20/2009 9:29:27 PM - System Checkpoint
      RP103: 4/22/2009 8:58:07 AM - System Checkpoint
      RP104: 4/23/2009 9:53:04 AM - System Checkpoint
      RP105: 4/26/2009 6:28:07 PM - System Checkpoint
      RP106: 4/30/2009 1:31:48 AM - System Checkpoint
      RP107: 4/30/2009 3:00:16 AM - Software Distribution Service 3.0
      RP108: 5/1/2009 3:00:16 AM - Software Distribution Service 3.0
      RP109: 5/2/2009 4:35:44 PM - Software Distribution Service 3.0
      RP110: 5/3/2009 3:00:16 AM - Software Distribution Service 3.0
      RP111: 5/4/2009 8:49:20 PM - Software Distribution Service 3.0
      RP112: 5/5/2009 7:06:55 PM - Software Distribution Service 3.0
      RP113: 5/6/2009 7:04:51 PM - Software Distribution Service 3.0
      RP114: 5/7/2009 10:12:08 PM - Software Distribution Service 3.0
      RP115: 5/8/2009 3:00:16 AM - Software Distribution Service 3.0
      RP116: 5/9/2009 12:11:56 PM - Software Distribution Service 3.0
      RP117: 5/10/2009 7:56:00 AM - Software Distribution Service 3.0
      RP118: 5/10/2009 7:50:50 PM - Software Distribution Service 3.0
      RP119: 5/11/2009 1:51:43 AM - Removed Adobe Reader 9.
      RP120: 5/11/2009 1:51:59 AM - Installed Adobe Reader 9.1.
      RP121: 5/12/2009 10:38:02 PM - Software Distribution Service 3.0
      RP122: 5/13/2009 11:08:02 PM - Software Distribution Service 3.0
      RP123: 5/15/2009 7:35:50 PM - System Checkpoint
      RP124: 5/18/2009 12:21:38 AM - System Checkpoint
      RP125: 5/19/2009 8:51:27 PM - System Checkpoint
      RP126: 5/20/2009 9:07:30 PM - System Checkpoint
      RP127: 5/21/2009 11:24:46 PM - System Checkpoint
      RP128: 5/22/2009 11:41:58 PM - System Checkpoint
      RP129: 5/23/2009 3:01:24 AM - Software Distribution Service 3.0
      RP130: 5/24/2009 4:10:53 AM - Software Distribution Service 3.0
      RP131: 5/26/2009 1:05:01 AM - System Checkpoint
      RP132: 5/29/2009 1:25:38 PM - System Checkpoint
      RP133: 5/31/2009 4:41:56 PM - System Checkpoint
      RP134: 6/2/2009 12:13:26 PM - System Checkpoint
      RP135: 6/3/2009 10:58:41 PM - System Checkpoint
      RP136: 6/5/2009 6:35:37 PM - System Checkpoint
      RP137: 6/7/2009 11:33:57 PM - System Checkpoint
      RP138: 6/9/2009 8:46:51 PM - System Checkpoint
      RP139: 6/10/2009 8:31:14 AM - Software Distribution Service 3.0
      RP140: 6/11/2009 8:58:33 PM - System Checkpoint
      RP141: 6/13/2009 7:37:34 PM - System Checkpoint
      RP142: 6/15/2009 3:00:15 AM - Software Distribution Service 3.0
      RP143: 6/16/2009 7:09:41 PM - Software Distribution Service 3.0
      RP144: 6/16/2009 7:54:45 PM - Software Distribution Service 3.0
      RP145: 6/16/2009 8:35:08 PM - Printer Driver Microsoft XPS Document Writer Installed
      RP146: 6/17/2009 10:37:36 PM - System Checkpoint
      RP147: 6/18/2009 3:00:14 AM - Software Distribution Service 3.0
      RP148: 6/19/2009 1:05:56 AM - Printer Driver HP Officejet J6400 series fax Installed
      RP149: 6/20/2009 6:47:52 PM - System Checkpoint
      RP150: 6/21/2009 6:55:07 PM - System Checkpoint
      RP151: 6/22/2009 7:00:41 AM - Configured Microsoft Office Professional 2007
      RP152: 6/24/2009 2:36:24 AM - System Checkpoint
      RP153: 6/25/2009 2:36:55 AM - System Checkpoint
      RP154: 6/26/2009 2:45:00 AM - System Checkpoint
      RP155: 6/27/2009 11:55:55 AM - System Checkpoint
      RP156: 6/28/2009 4:20:21 PM - System Checkpoint
      RP157: 6/29/2009 5:34:23 PM - System Checkpoint
      RP158: 6/30/2009 6:19:43 PM - System Checkpoint
      RP159: 7/1/2009 8:33:20 AM - Software Distribution Service 3.0
      RP160: 7/2/2009 9:22:12 AM - System Checkpoint
      RP161: 7/3/2009 5:53:54 PM - System Checkpoint
      RP162: 7/4/2009 8:23:56 PM - System Checkpoint
      RP163: 7/5/2009 8:45:14 PM - System Checkpoint
      RP164: 7/6/2009 9:36:13 PM - Installed DirectX

      ==== Installed Programs ======================

      32 Bit HP CIO Components Installer
      6400_Help
      AAC Decoder
      Acrobat.com
      Ad-Aware
      Adobe AIR
      Adobe Flash Player 10 ActiveX
      Adobe Flash Player 10 Plugin
      Adobe Reader 9.1
      All Day Battery Life Configuration
      AuthenTec Fingerprint Sensor
      AuthenTec Fingerprint System
      AutoUpdate
      BioAPI Framework
      biolsp patch
      bpd_scan
      BPDSoftware
      BPDSoftware_Ini
      Broadcom USH Host Components
      CA Anti-Spam
      CA Anti-Spyware
      CA Anti-Virus
      CA Desktop DNA Migrator
      CA Internet Security Suite
      CA Personal Firewall
      CA Pest Patrol Realtime Protection
      CA Website Inspector
      CCleaner (remove only)
      Command & Conquer™ Red Alert™ 3
      Critical Update for Windows Media Player 11 (KB959772)
      Dell Control Point
      Dell ControlPoint Connection Manager
      Dell ControlPoint Security Manager
      Dell ControlPoint System Manager
      Dell Embassy Trust Suite by Wave Systems
      Dell Resource CD
      Dell Security Device Driver Pack
      Dell Touchpad
      Dell Webcam Central
      Dell WUSB
      DivX Codec
      DivX Converter
      DivX Player
      DivX Plus DirectShow Filters
      DivX Version Checker
      DivX Web Player
      Document Manager Lite
      Download Manager 2.3.7
      EditPlus 3
      EMBASSY Security Center
      EMBASSY Security Setup
      ESC Home Page Plugin
      Fax
      GameTap Web Player
      GDR 1406 for SQL Server Analysis Services 2005 ENU (KB932557)
      GDR 1406 for SQL Server Database Services 2005 ENU (KB932557)
      GDR 1406 for SQL Server Integration Services 2005 ENU (KB932557)
      GDR 1406 for SQL Server Notification Services 2005 ENU (KB932557)
      Gemalto
      GlassFish V2 UR2
      GlassFish v3 Prelude
      H.264 Decoder
      High Definition Audio Driver Package - KB835221
      HijackThis 2.0.2
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
      Hotfix for Windows Media Format 11 SDK (KB929399)
      Hotfix for Windows Media Player 11 (KB939683)
      Hotfix for Windows XP (KB945436)
      Hotfix for Windows XP (KB949764)
      Hotfix for Windows XP (KB952287)
      Hotfix for Windows XP (KB953955)
      Hotfix for Windows XP (KB954550-v5)
      Hotfix for Windows XP (KB959252)
      Hotfix for Windows XP (KB961118)
      HP Officejet J6400 Series
      HP Smart Web Printing
      HP Update
      HPSSupply
      Integrated Webcam Driver (1.03.02.0919)
      Intel PROSet Wireless
      Intel(R) Network Connections 13.0.42.0
      Intel(R) PRO Alerting Agent
      Intel(R) PROSet/Wireless WiFi Software
      Intel® Matrix Storage Manager
      J6400
      Java DB 10.4.1.3
      Java(TM) 6 Update 11
      Java(TM) 6 Update 5
      Java(TM) SE Development Kit 6 Update 11
      Malwarebytes' Anti-Malware
      Microsoft .NET Compact Framework 1.0 SP3 Developer
      Microsoft .NET Compact Framework 2.0
      Microsoft .NET Framework 1.1
      Microsoft .NET Framework 1.1 Hotfix (KB928366)
      Microsoft .NET Framework 2.0 Service Pack 2
      Microsoft .NET Framework 3.0 Service Pack 2
      Microsoft .NET Framework 3.5 SP1
      Microsoft Compression Client Pack 1.0 for Windows XP
      Microsoft Device Emulator version 1.0 - ENU
      Microsoft Document Explorer 2005
      Microsoft FrontPage Client - English
      Microsoft Internationalized Domain Names Mitigation APIs
      Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
      Microsoft National Language Support Downlevel APIs
      Microsoft Office 2003 Web Components
      Microsoft Office 2007 Service Pack 2 (SP2)
      Microsoft Office Access MUI (English) 2007
      Microsoft Office Access Setup Metadata MUI (English) 2007
      Microsoft Office Excel MUI (English) 2007
      Microsoft Office Outlook MUI (English) 2007
      Microsoft Office PowerPoint MUI (English) 2007
      Microsoft Office Professional 2007
      Microsoft Office Proof (English) 2007
      Microsoft Office Proof (French) 2007
      Microsoft Office Proof (Spanish) 2007
      Microsoft Office Proofing (English) 2007
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
      Microsoft Office Publisher MUI (English) 2007
      Microsoft Office Shared MUI (English) 2007
      Microsoft Office Shared Setup Metadata MUI (English) 2007
      Microsoft Office Word MUI (English) 2007
      Microsoft Silverlight
      Microsoft Software Update for Web Folders (English) 12
      Microsoft SQL Server 2005
      Microsoft SQL Server 2005 Analysis Services
      Microsoft SQL Server 2005 Backward compatibility
      Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
      Microsoft SQL Server 2005 Integration Services
      Microsoft SQL Server 2005 Mobile [ENU] Developer Tools
      Microsoft SQL Server 2005 Notification Services
      Microsoft SQL Server 2005 Tools Express Edition
      Microsoft SQL Server Native Client
      Microsoft SQL Server Setup Support Files (English)
      Microsoft SQL Server VSS Writer
      Microsoft User-Mode Driver Framework Feature Pack 1.0
      Microsoft Visual C++ 2005 Redistributable
      Microsoft Visual J# .NET Redistributable Package 1.1
      Microsoft Visual J# 2.0 Redistributable Package
      Microsoft Visual Studio .NET Enterprise Architect 2003 - English
      Microsoft Visual Studio 2005 Team Edition for Software Developers - ENU
      Microsoft Visual Studio 2005 Team Edition for Software Developers - ENU Service Pack 1 (KB926601)
      Microsoft Visual Studio 2005 Tools for Office Runtime
      Microsoft Xbox 360 Accessories 1.1
      MKV Splitter
      Mozilla Firefox (3.0.11)
      MSXML 4.0 SP2 (KB954430)
      MSXML 6 Service Pack 2 (KB954459)
      NetBeans IDE 6.5
      NetDeviceManager
      NTRU TCG Software Stack
      NVIDIA Drivers
      PowerDVD
      Preboot Manager
      Private Information Manager
      ProductContext
      Roxio Activation Module
      Roxio Creator Audio
      Roxio Creator BDAV Plugin
      Roxio Creator Copy
      Roxio Creator Data
      Roxio Creator DE
      Roxio Creator Tools
      Roxio Drag-to-Disc
      Roxio Express Labeler 3
      Roxio Update Manager
      Scan
      Secure Update
      Security Update for 2007 Microsoft Office System (KB969559)
      Security Update for 2007 Microsoft Office System (KB969679)
      Security Update for CAPICOM (KB931906)
      Security Update for Microsoft Office Excel 2007 (KB969682)
      Security Update for Microsoft Office PowerPoint 2007 (KB957789)
      Security Update for Microsoft Office system 2007 (KB969613)
      Security Update for Microsoft Office Word 2007 (KB969604)
      Security Update for Microsoft Visual Studio 2005 Team Edition for Software Developers - ENU (KB937061)
      Security Update for Microsoft Visual Studio 2005 Team Edition for Software Developers - ENU (KB947738)
      Security Update for Step By Step Interactive Training (KB923723)
      Security Update for Windows Internet Explorer 7 (KB938127-v2)
      Security Update for Windows Internet Explorer 7 (KB956390)
      Security Update for Windows Internet Explorer 7 (KB958215)
      Security Update for Windows Internet Explorer 7 (KB961260)
      Security Update for Windows Internet Explorer 7 (KB963027)
      Security Update for Windows Internet Explorer 7 (KB969897)
      Security Update for Windows Internet Explorer 8 (KB969897)
      Security Update for Windows Media Player (KB911564)
      Security Update for Windows Media Player (KB952069)
      Security Update for Windows Media Player 11 (KB936782)
      Security Update for Windows Media Player 11 (KB954154)
      Security Update for Windows Media Player 6.4 (KB925398)
      Security Update for Windows Media Player 9 (KB936782)
      Security Update for Windows XP (KB923561)
      Security Update for Windows XP (KB923689)
      Security Update for Windows XP (KB938464-v2)
      Security Update for Windows XP (KB938464)
      Security Update for Windows XP (KB941569)
      Security Update for Windows XP (KB946648)
      Security Update for Windows XP (KB950762)
      Security Update for Windows XP (KB950974)
      Security Update for Windows XP (KB951066)
      Security Update for Windows XP (KB951376-v2)
      Security Update for Windows XP (KB951698)
      Security Update for Windows XP (KB951748)
      Security Update for Windows XP (KB952004)
      Security Update for Windows XP (KB952954)
      Security Update for Windows XP (KB953155)
      Security Update for Windows XP (KB954211)
      Security Update for Windows XP (KB954600)
      Security Update for Windows XP (KB955069)
      Security Update for Windows XP (KB956390)
      Security Update for Windows XP (KB956391)
      Security Update for Windows XP (KB956572)
      Security Update for Windows XP (KB956802)
      Security Update for Windows XP (KB956803)
      Security Update for Windows XP (KB956841)
      Security Update for Windows XP (KB957097)
      Security Update for Windows XP (KB958215)
      Security Update for Windows XP (KB958644)
      Security Update for Windows XP (KB958687)
      Security Update for Windows XP (KB958690)
      Security Update for Windows XP (KB959426)
      Security Update for Windows XP (KB960225)
      Security Update for Windows XP (KB960714)
      Security Update for Windows XP (KB960715)
      Security Update for Windows XP (KB960803)
      Security Update for Windows XP (KB961373)
      Security Update for Windows XP (KB961501)
      Security Update for Windows XP (KB968537)
      Security Update for Windows XP (KB969898)
      Security Update for Windows XP (KB970238)
      Security Update for Windows XP (KB970483)
      Security Wizards
      Shop for HP Supplies
      SmartWebPrintingOC
      Sonic CinePlayer Decoder Pack
      SQLXML4
      Toolbox
      TouchChip USB Driver 2.14
      TouchChip USB Driver 2.6
      Trillian
      Trusted Drive Manager
      tsp patch
      UnloadSupport
      Update for 2007 Microsoft Office System (KB967642)
      Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
      Update for Microsoft Office Outlook 2007 (KB969907)
      Update for Outlook 2007 Junk Email Filter (kb970012)
      Update for Windows Internet Explorer 8 (KB971180)
      Update for Windows XP (KB951978)
      Update for Windows XP (KB955839)
      Update for Windows XP (KB967715)
      VC80CRTRedist - 8.0.50727.762
      Visual C++ 2008 x86 Runtime - (v9.0.30729)
      Visual C++ 2008 x86 Runtime - v9.0.30729.01
      Visual Studio .NET Enterprise Architect 2003 - English
      Visual Studio.NET Baseline - English
      Wave Infrastructure Installer
      Wave Support Software
      WebFldrs XP
      WebReg
      WIDCOMM Bluetooth Software
      Windows Driver Package - Dell Inc. PBADRV System (01/07/2008 1.0.1.5)
      Windows Genuine Advantage Notifications (KB905474)
      Windows Genuine Advantage Validation Tool (KB892130)
      Windows Installer 3.1 (KB893803)
      Windows Internet Explorer 7
      Windows Internet Explorer 8
      Windows Media Format 11 runtime
      Windows Media Player 11
      Windows XP Service Pack 3
      WinRAR ARCHIVER

      ==== Event Viewer Messages From Past Week ========

      7/7/2009 11:56:21 PM, error: NETw5x32 [43] -
      7/7/2009 11:56:20 PM, error: PSched [14103] - QoS [Adapter {866C1E47-FF68-455E-AD71-3AE69957E117}]: The netcard driver failed the query for OID_GEN_LINK_SPEED.
      7/7/2009 11:15:51 PM, error: DCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool.
      7/4/2009 4:22:25 PM, error: Service Control Manager [7034] - The HP Network Devices Support service terminated unexpectedly. It has done this 1 time(s).
      7/2/2009 5:07:47 PM, error: Service Control Manager [7034] - The Dell ControlPoint System Manager service terminated unexpectedly. It has done this 1 time(s).
      7/2/2009 5:07:47 PM, error: Service Control Manager [7034] - The Dell ControlPoint Button Service service terminated unexpectedly. It has done this 1 time(s).
      7/2/2009 5:05:55 PM, error: Service Control Manager [7034] - The Intel® PROSet/Wireless WiFi Service service terminated unexpectedly. It has done this 1 time(s).
      7/2/2009 5:05:49 PM, error: Service Control Manager [7034] - The Intel(R) PROSet/Wireless SSO Service service terminated unexpectedly. It has done this 1 time(s).
      7/2/2009 5:05:44 PM, error: Service Control Manager [7034] - The Intel® PROSet/Wireless Event Log service terminated unexpectedly. It has done this 1 time(s).
      7/2/2009 5:05:34 PM, error: Service Control Manager [7034] - The TdmService service terminated unexpectedly. It has done this 1 time(s).
      7/2/2009 5:05:23 PM, error: Service Control Manager [7034] - The SQL Server Integration Services service terminated unexpectedly. It has done this 1 time(s).
      7/2/2009 5:05:09 PM, error: Service Control Manager [7034] - The SQL Server Analysis Services (MSSQLSERVER) service terminated unexpectedly. It has done this 1 time(s).
      7/2/2009 5:02:15 PM, error: Service Control Manager [7034] - The CA Pest Patrol Realtime Protection Service service terminated unexpectedly. It has done this 1 time(s).
      7/2/2009 5:02:09 PM, error: Service Control Manager [7034] - The SQL Server (SQLEXPRESS) service terminated unexpectedly. It has done this 1 time(s).
      7/2/2009 5:01:51 PM, error: Service Control Manager [7034] - The SQL Server (MSSQLSERVER) service terminated unexpectedly. It has done this 1 time(s).

      ==== End Of File ===========================
      Check your PM inbox.

      3867.

      Solve : I think I conquored the beast myself. Can ya check my logs plz??

      Answer»

      So it figures that I get sick yesterday, which sucks, but I was kind of happy to have an excuse to just veg out in front of the comp all day and guess what happens? My computer gets sick too. I don't know where this one came from. I was not doing ANYTHING suspect at all. No nudey sites or illegal activity. So if you have any suggestions as to how this might have happened so i may avoid this in the future it would be appreciated.

      So all of a sudden one of these false alarm viruses started that first SHUT down Avira Antivirus and then a fake explorer window that started popping up saying I have viruses. At this point Malware Bytes was still functioning so I RAN a search and rebooted and it was better but firefox was still hijacked and I could not run any executables. I ran Malware Bytes again and it came up with 2 trojans, one of which it was saying it was locked out of. Rebooted again and the same TWO trojans came up.

      So I had some experience with this before and these forums, particularly Evil Fantasy, saved my arse. Thank you bro!! I came back here and read through some similar threads again and remembered using Combo-Fix the first time. This worked like magic. Gotta love that combo-fix. I think I am gonna donate some dough to them. Then I ran SuperAntiSpyware, rebooted, ran Hijack This, then ran Malware Bytes again. I have posted all the logs here.

      Would you all mind just checking them out to see if it is dead for sure?

      And also, what good is an AntiVirus program if they can be so easily compromised. That virus just shut Avira down easily. Seems to me Avira should of been the one to say, "No, no, no, my friend. You are not allowed to shut me down or get access to this computer."

      Thanks a lot, friends.

      [attachment deleted by admin]

      3868.

      Solve : Regedit & task manager disabled?

      Answer»

      Hi

      I installed a supposedly Pacman game that my kids downloaded only to be hijacked. I had a "NET meeting" pron window popup and several www.101 something IE popups.

      I've managed to clean the regedit "windows cannot find..." error with Malware Bytes - it found a register key and deleted it. The task manager problem is that it doesn't run. I ctrl-alt-del, pick task manager and nothing happens.

      Malwarebytes, NIS 2009, Super anti spyware find nothing. My HJT log is below

      Thanks in advance

      Ian

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 09:01:42, on 10/07/2009
      Platform: Windows Vista SP1 (WinNT 6.00.1905)
      MSIE: Internet Explorer v7.00 (7.00.6001.18248)
      Boot mode: Normal

      Running processes:
      C:\Program Files\Norton Internet Security\ENGINE\16.5.0.135\ccSvcHst.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\Explorer.EXE
      C:\Windows\System32\CtHelper.exe
      C:\Program Files\Raxco\PerfectDisk10\PDAgentS1.exe
      C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
      C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
      C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
      C:\Program Files\Razer\Habu\razerhid.exe
      C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
      C:\Program Files\Razer\Lycosa\razerhid.exe
      C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      C:\Program Files\Razer\Lycosa\razertra.exe
      C:\Program Files\Razer\Habu\razertra.exe
      C:\Program Files\Razer\Habu\razerofa.exe
      C:\Windows\explorer.exe
      C:\Program Files\Internet Explorer\ieuser.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Trend Micro\HijackThis\sniper.exe
      C:\Windows\system32\SearchFilterHost.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - URLSearchHook: DeviceVM Url Search Hook - {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\Windows\System32\dvmurl.dll
      O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dll
      O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe CONTRIBUTE CS3/contributeieplugin.dll
      O2 - BHO: IE to GetRight Helper - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
      O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
      O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\IPSBHO.DLL
      O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
      O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
      O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
      O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
      O4 - HKLM\..\Run: [trueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
      O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
      O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
      O4 - HKLM\..\Run: [Habu] C:\Program Files\Razer\Habu\razerhid.exe
      O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
      O4 - HKLM\..\Run: [Lycosa] "C:\Program Files\Razer\Lycosa\razerhid.exe"
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
      O4 - HKUS\S-1-5-18\..\Run: [DevconDefaultDB] C:\Windows\system32\READREG /SILENT /FAIL=1 (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [DevconDefaultDB] C:\Windows\system32\READREG /SILENT /FAIL=1 (User 'Default user')
      O4 - Startup: Creative Element Power Tools Startup.lnk = C:\Program Files\Creative Element Power Tools\Startup.exe
      O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
      O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
      O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
      O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
      O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
      O8 - Extra context menu item: Download with GetRight Pro - C:\Program Files\GetRight\GRdownload.htm
      O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: Open with GetRight Pro Browser - C:\Program Files\GetRight\GRbrowse.htm
      O9 - Extra button: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
      O9 - Extra 'Tools' menuitem: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
      O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
      O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
      O13 - GOPHER Prefix:
      O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager/plugin/IEGetPlugin.cab
      O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
      O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
      O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
      O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Norton Internet Security\AddOns\Norton AddOn Pack\Engine\3.5.0.24\ccProxy.exe
      O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
      O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
      O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
      O23 - Service: getPlus(R) Installer - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
      O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
      O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
      O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
      O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe
      O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe
      O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
      O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Windows\System32\nvSCPAPISvr.exe
      O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
      O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe
      O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.1.33\bin\mysqld.exe

      --
      End of file - 10553 bytes


      [ATTACHMENT deleted by admin]

      3869.

      Solve : Help me! Internet Explorer windows open and sounds?

      Answer»

      Hello friends!

      OK, so here's what happened. I downloaded a keygen and when I opened it, nothing happened and it simply dissapeared. I didn't pay much attention to it then, but know I'm getting a little desperate because very frequently IE windows OPEN with different pages (about hotels, games, etc), even though Internet Explorer is not even my default browser.

      And this get better! all of a sudden, I started hearing segments of a radio STATION, MAINLY hip-hop, but it keeps going even thou I have absolutely no application open, every minute or so another segment starts, maybe a song, or an ad or something. They fade-in and fade-out and eventually they repeat themselves. Help me out! I'm going a little crazy!

      I own a Dell Insipron with Windows Vista SERVICE Pack, 4GB Ram, Intel CORE 2 Duo, and Symantec Antivirus. I ran an active scan in the Symantec Endpoint Protection and nothing was detected, but its obvious there's something wrong.

      Thanks a lot!yes! the same thing happened to me just lots of weird storys about killing cats and stuff.
      name is...

      •Bulldozer!Trojan - named by Computer Associates.
      • destructive program - named by F-Prot.
      • QZap126 - named by McAfee.
      • Tr_Sound.82 - named by Panda.
      • Trojan.Sound - named by Kaspersky.

      i cant access my computer at moment due to virus :/ but seriously do a little scanning with antivirus programs such as avg or spyware doctor. and kill.

      3870.

      Solve : help!!! vista contracted a trojan and will not start up.?

      Answer»

      im using windows vista home premium.

      I contracted a few Trojans recently, i was away for a week and came back to find my laptop will not start up.

      it comes to a screen with the heading "Windows Boot MANAGER" and go's on about how i should put in the installation disc to repair the system.
      then has a few little informative things that i cant make sense of.

      FILE: \BOOT\BCD
      STATUS: 0xc000000f
      INFO: An error occurred while attempting to read the boot configuration data.

      First of all i'd LIKE to get back to being able to use my laptop, and SECONDLY as i bought the laptop with vista already installed i never got the install disc.

      so...HELP!!! what do i do.dunno if this is spam (and sorry if it is) but HELP!!!Can you BORROW a Windows Vista Home Premium disk from someone?would it work using someone elses disk to repair your pc? to my understanding there is only 1 disk per computer. and something BOUT copyright if its someone elses.

      -thanksAs long as you use your license key then you can use any disk that is the same as what is installed on your computer.

      3871.

      Solve : How to remove Antivirus System Pro?

      Answer»

      Please help. How do I beat this thing and GET rid of it?http://www.spyware-assistance.org/dangerous-trojans/a/Antivirus-System-PRO/Remove-Antivirus-System-PRO.php?gclid=CI2v4JWVzJsCFVUA4wodOVegKQ


      go to above and READ , HARRY

      3872.

      Solve : WMA/TrojanDownloader.GetCodec.C.trojan?

      Answer»

      OK that got the biggest issue now you should run a full virus scan to make sure nothing else is hiding. Better safe than sorry...

      * Click START then RUN
      * Now type Combofix /u in the runbox
      * Make sure there's a space between Combofix and /u
      * Then hit Enter

      * The above procedure will:
      * Delete the following:
      * ComboFix and its associated FILES and folders.
      * Reset the clock settings.
      * Hide file extensions, if required.
      * Hide System/Hidden files, if required.
      * Set a new, clean Restore Point.

      ----------

      Clean out your temporary internet files and temp files.

      Download TFC by OldTimer to your DESKTOP.

      Double-click TFC.exe to run it.

      Note: If you are running on Vista, right-click on the file and choose Run As Administrator

      TFC will close all programs when run, so make sure you have saved all your work before you begin.

      * Click the Start button to begin the cleaning process.
      * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a MINUTE or TWO.
      * Please let TFC run uninterrupted until it is finished.

      Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

      ----------

      Use the Kaspersky Lab Online Scanner

      In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.

      • Click on SCAN NOW
      • Click Accept.
      • The program will then begin downloading the latest definition files.
      • Once the files have been downloaded locate the Scan Settings and have it scan My Computer.
      • The scan will take a while, so be patient and let it finish.
      When the scan is done, in the Scan is complete window, any infection is displayed.
      There is no option to clean/disinfect, however, we need to analyze the information on the report.

      To obtain the report:
      Click on: Save Report As
      • Next, in the Save as prompt, Save in area, select: Desktop.
      • In the File name area use KScan, or something similar.
      • In Save as type: click the drop arrow and select: Text file [*.txt]
      • Then, click: Save


      Copy and paste the Kaspersky Online Scanner Report in your next reply.

      Note for Internet Explorer 7 and 8 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.

      If needed, this animation will guide you through the process.


      3873.

      Solve : Help ||| Windows XP automatically booting || Critical DATA.?

      Answer»

      I have a windows XP based P||| 128 MB RAM system. It is a standalone machine not conectd to the internet & mainly used for accounting purpose (critical data).

      For some important task I connected it to the internet however after 4 to 5 hours it crashed giving the following error
      "This system is shutting down. Please save all work in progress and log off. Any unsaved changes will be lost. This shutdown was initiated by NT Authority\system.Windows must now restart because Remote Procedure Call (RPC) Service terminated unexpectedly."

      The system then shuts down after 60 sec. I did not understand the problem however the next day my WinXP crashed and giving me a message that
      "Windows cannot load your profile because it may be corrupted. You may be logged in using a temporary User Profile. "

      Windows was not able to load my actual profile but instead loaded the default TEMP profile which will not save your work once u reboot. However all my data in My DOCUMENT of original profile were DELETED when I tried to search for my original profile while logged in with the TEMP (default) profile. The original user profile folder appears as squares or other unusual characters in the folder name. All the other folders inside this folder also had unusual character names as well as the files contained in those folders. In My Document folder (somehow guessed the name) most of the files were deleted.

      I installed a new WinXP on my third PARTITION (E:), installed Avira Antivirus, scanned and found the following:
      1."isass.exe" virus in my systems folder.
      2. "winzip_tmp.exe"
      3. "Temp.Htt" virus on all my drives (C,D,E).

      I quarantined all of their instances. WinXP is now installed on E: drive. Thinking my system is safe and sound once again. I began work and again connected it to the internet.

      ::)But now it rebooted automatically ( no error this time, no blue screen etc) so I had to disconnect it from the internet.

      However the system keeps rebooting automatically in a matter of 5 or 10 MINUTES. Sometime the system failed to recognize the hard drive and gives message "system disk error" message. If I power off completely then it recognizes the hard disk and again boots up but wont recognise E: drive but instead recognizes C: drive (remember I installed another winXP on E:, did not format C:).

      So i proceeded to install another fresh copy of XP on C: by formatting it with FAT32, installed F-Secure anti-virus and scanned the whole system but it did not find any virus or anything however the rebooting problem still remains.

      The system does not recognize WinXP installed on E: but directly boots to C:

      The system would reboot unexpectedly within a space of 5 - 30 mins automatically with no error msg. The reason I have detailed my problem is because I have all my accounting data on D: drive.

      Are there any viruses, spyware still on the system. Is there a problem with the registry which automatically reboots the system.

      Please help me resolve the issue as soon as possible as all my work is held up due to continous rebooting of the system.

      Thanks very much for your help.
      Romesh


      the problem is that you keep attaching an unpatched and unprotected XP system to the internet.THOUGH I AGREE the system being unpatched, however I NEVER used to connect it to the internet until that wretched minute. Surely someone could give me a more creative response than that.

      3874.

      Solve : search hijacked?

      Answer»

      both YAHOO and GOOGLE are sending me to wild search PAGES.. i see US.maxfiles.com pop up repeatedly

      any thoughts

      thanksYou need to provide us with more information. See this THREAD for details.

      3875.

      Solve : Can you check this for me??

      Answer»

      This is from my family's PC, running XP X64 edition SP2, fully updated.
      I only just read the guideline post, so I don't have as many logs as asked for, I can get some more if necessary tomorrow, or maybe Monday.
      The issue was that my sister called me through to see a popup that had appeared, from xpantivirus.com (anyone reading - do not go to that site!). She was on myspace.com at the time.
      I recognized it as a malware site straight away, and ran AVG and Spybot scans. Neither found anything, and the FILES associated with the xpantivirus malware are nowhere to be seen.
      The HJT log is attached, and I can't see anything at a glance which seems out of place. I don't have time to CHECK it all out right now, so don't scold me if I've missed something.
      Please tell me it's clean, a malware infection is something I don't need right now.

      Thanks in advance.
      Calum.

      [file cleanup - saving space - attachment deleted by admin]Log looks OK, you can have Hijackthis fix this one "dead" entry though. O4 - Startup: RMClock.lnk = ?

      There is a tool you can run that specifically looks for XP Antivirus. It only takes about two seconds to run, but trust me it does it's job well. It is free and a great addition to any malware prevention arsenal. RogueRemover Detection List

      Please download RogueRemover and save to you Desktop. (compatible with Windows 2000, NT, XP, Vista)

      • Double-click on rr-free-setup.exe to install in C:\Program Files\RogueRemover and follow the prompts.
      • During installation an icon will automatically be created on your Desktop.
      • If the program does not open after installation, double-click on the RogueRemover icon to launch.
      • Select Check for Updates and click Download if any are found.
      • Wait for the updates to finish downloading, then Close the update window.
      • Select Scan and follow the onscreen directions to remove anything found.
      • Vista users be sure to Run As Administrator.
      • If nothing is found, exit RogueRemover.
      • If RogueRemover finds something, it will present a list of detected items.
      • Click on Save log, then Ok at the prompt.
      • Click Remove selected, then Yes at the prompt.
      • Wait for the removal to complete and then close RogueRemover.
      • A file will be created and saved at C:\Program Files\RogueRemover\RRLog******.txt
      • Post the contents of the RRLog file in your next reply.


      .
      I would suggest running SuperAntispyware when you get a chance to ensure nothing else is hiding.RogueRemover found nothing.
      SuperAntispyware ALSO found nothing.
      And the "dead entry" isn't dead, it's used to start RMClock at startup.
      Thanks for the help, looks like it's clean then.Quote from: Calum on March 02, 2008, 12:43:12 PM
      And the "dead entry" isn't dead, it's used to start RMClock at startup.

      Thanks, I will stash that away in the notes....

      Yes I think you are in the clear. If the COMPUTER doesn't already have it I would suggest using SpywareBlaster. It is an awesome tool and uses zero resources. You just have to open it and manually check for updates from time to time with the free version. http://www.javacoolsoftware.com/spywareblaster.htmlQuote
      Thanks, I will stash that away in the notes....
      RMClock can be started via a Registry key or the startup folder, in this case it was using the startup folder. Strange that it had a ? next to it, but maybe it's just a peculiarity of XP X64, I know some entries are not detected and files are shown missing using HJT and that OS.
      Quote
      Yes I think you are in the clear.
      Great, thanks.
      Quote
      If the computer doesn't already have it I would suggest using SpywareBlaster.
      What do you take me for?
      This may not be my PC, but I didn't abandon it to my family without at least basic security in place.
      AVG, Spybot and Spyware Blaster have been installed from day 1, updated at least once a week.
      Spyware Blaster has been part of my arsenal for years now, as have most of the tools I use.Yea the = ? is what had me thinking it was an empty startup entry.

      Have you upgraded SpywareBlaster to the 4.0 version which was released a few days ago? It got a new GUI along with some bug FIXES, seems to load faster when opened also.

      New in this version:
      -Full Vista support
      -Protection for Netscape
      -Protection for Seamonkey
      -Protection for Flock
      -A brand-new user interface
      -Various feature and protection enhancements
      -Further optimizations to every part of the program
      -And lots of other bug fixes and requested tweaks Of course, everything is always updated by either my family or me whenever I use their PC.
      I don't particularly like the new UI of Spyware Blaster though.
      3876.

      Solve : Need Information on any good Windows XP Registry Cleaners Software?

      Answer»

      I know I have some errors on my Windows XP Registry, What are or are there any good Windows Registry Cleaners Software that WOULD take care of the errors and make my PC run smooth again?Registry Myths...

      But if after reading up on it you still want to do some housekeeping most here recommend CCleaner.Is CCleaner free and doesn't cost anything after you find errors on your Windows Registry?regSeeker, RegCleaner or Ccleaner. All are free and all are good enough for average GENERAL purpose user.

      It helps to do a LITTLE computer cleaning and if you know what you're doing and that's all good.

      It helps though if you're having some freezing or BSOD type problems (don't know if they call it BSOD anymore) or some other problems like computer seeming to run slower and all the like.Just make sure, you know what you're doing...

      3877.

      Solve : MSN Photo Album Virus.... Pls Help?

      Answer»

      The log is clean. Any other issues?
      If not, happy computing YAY!!!!

      thanks so much for your help.....

      you have been great!!!

      Hi Broni, this is the lastest scan i got fromhttp://www.eset.com/onlinescan/.

      Pls help

      # version=4
      # OnlineScanner.ocx=1.0.0.635
      # OnlineScannerDLLA.dll=1, 0, 0, 79
      # OnlineScannerDLLW.dll=1, 0, 0, 78
      # OnlineScannerUninstaller.exe=1, 0, 0, 49
      # vers_standard_module=2923 (20080305)
      # vers_arch_module=1.032 (20050726)
      # vers_adv_heur_module=1.064 (20070717)
      # EOSSerial=c4ff678f52c8af489a6312fecbcabe1d
      # end=finished
      # remove_checked=false
      # unwanted_checked=true
      # utc_time=2008-03-05 06:05:54
      # local_time=2008-03-06 02:05:54 (+0800, Malay Peninsula Standard Time)
      # COUNTRY="United States"
      # osver=5.1.2600 NT Service PACK 2
      # scanned=244777
      # found=6
      # scan_time=1531
      C:\Documents and Settings\User\Local Settings\Temp\photo_22.zipWin32/IRCBot.NAF trojanCB246C6F30C75E9F4A257B12BBC10B29
      C:\Documents and Settings\User\Local Settings\Temp\photo_24.zipWin32/IRCBot.AAI trojan55D19E5E1A23A5B388F85B5E84582E02
      C:\Documents and Settings\User\Local Settings\Temp\removalfile.batWin32/Adware.Virtumonde application9A7EF09167A6F4433681B94351509043
      C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\NPR47J4C\wr10[1].exea variant of Win32/TrojanDownloader.Small.IAW trojanA8144B9743728919E2AFD974545D9F22
      C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\SCA8BPSB\p10[1].exeWin32/IRCBot.AAI trojan8D954E3B652A064470E99960405A24DD
      C:\WINDOWS\system32\dpcsvc.exeWin32/IRCBot.NAF trojanD9323DB3041FBEF133035E23721C496B
      Pauljrt
      Normally, you should start your own topic, but since you posted logs already, I asked one of MODS to move your posts to a new topic.Is your Windows firewall ON?

      Download RapidBlaster KILLER: http://www.castlecops.com/downloads-file-333-details-RapidBlaster_Killer.html
      Unzip the file, and run rbkiller.exe
      RapidBlaster Killer will create a log file named scanlog.txt
      Post the above scan log in your NEXT reply.

      Post new HJT log.

      3878.

      Solve : Free Anti Rootkill??

      Answer»

      I tried to update my AVG free Anti Rootkill program, but see that they no longer update the free version. Is there another free anti rootkill that you would recommend?
      I have seen the Sophos one free to DOWNLOAD?

      Thanks for the list. Is there one of them you think best, or is it just a case of any of them being better than none?I don't have a lot of experience with rootkit removal tools so I'm not sure which one is best. You need to be careful with them because the findings can be misunderstood.

      A safer alternative is to use SuperAntispyware Free which has rootkit detection included. Or the F-Secure ONLINE Virus SCANNER which has an even better rootkit detection/removal rate.

      There is also the F-Secure standalone rootkit scan. It has a guide that can be found hereThanks again EVILFANTASY, I will go for the Super Antispyware free. I did not REALIZE that it included an anti rootkill scan.
      3879.

      Solve : Java Runtime Environment (JRE) 6 Update 5?

      Answer» Download page

      4th ONE down the list - JAVA Runtime Environment (JRE) 6 Update 5

      http://java.sun.com/javase/downloads/index.jsp

      Update Release Notes

      http://java.sun.com/javase/6/webnotes/ReleaseNotes.html#160_05

      Update also available through Java control panel. Be sure to UNINSTALL the old VERSION after installing the new.Got it. Thanks.
      3880.

      Solve : Blue screen STOP error when booting?

      Answer»

      Hi, my son was downloading music the other day on our computer, he had installed a USB cord for his mp3 player to record it and after he finished, shut it down. Yesterday, i tried to start it when i got home, and when it gets to the windows boot screen, in changes to a blue screen and says, STOP ERROR...you cannot access, you may have a virus.." it then gives me a LITTLE instruction to fix, but each time i try to boot, even in safe mode, it keeps reverting to this blue screen before i can get to any antivirus applications or cursor..windows will not load for me to do anything even in safe...what can i do to restore my computer? It's running Windows 2000, Pentium 3, 1999 model from DELL, deskpro. ....thanksPost the exact STOP error CODE you're getting and any files mentioned on the blue screen.It would be good to go to this post and scroll down to the HJT instructions and post that log also so someone on the malware team can have a LOOK.

      3881.

      Solve : HELP WITH TROJAN VIRUS!!!!!!?

      Answer»

      my computer is always popping up a message saying system error and that i have a dangerous trojan file and i can lose key files then it tells me to download this antimalware but i looked up antimalware got 2 free ones ran those got results and i deleted all of the bad files then i checked with mcafee cause thats what we have but its doesnt say anything and that message wont go awayPrint these instructions out.

      1. Download SUPERAntiSpyware Free for HOME Users:
      http://www.superantispyware.com/

      * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
      * An icon will be created on your desktop. Double-click that icon to launch the program.
      * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
      * Close SUPERAntiSpyware.

      Restart computer in Safe Mode.
      To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

      * Open SUPERAntiSpyware.
      * Under "Configuration and Preferences", click the Preferences button.
      * Click the Scanning Control tab.
      * Under Scanner Options make sure the following are checked (leave all OTHERS unchecked):
      o Close BROWSERS before scanning.
      o Scan for tracking cookies.
      o Terminate MEMORY threats before QUARANTINING.
      * Click the "Close" button to leave the control center screen.
      * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
      * On the left, make sure you check C:\Fixed Drive.
      * On the right, under "Complete Scan", choose Perform Complete Scan.
      * Click "Next" to start the scan. Please be patient while it scans your computer.
      * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
      * Make sure everything has a checkmark next to it and click "Next".
      * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
      * If asked if you want to reboot, click "Yes".
      * To retrieve the removal information after reboot, launch SUPERAntispyware again.
      o Click Preferences, then click the Statistics/Logs tab.
      o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
      o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
      o Please copy and paste the Scan Log results in your next reply.
      * Click Close to exit the program.
      Post SUPERAntiSpyware log.

      RESTART COMPUTER!

      2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

      * Double-click mbam-setup.exe and follow the prompts to install the program.
      * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
      * If an update is found, it will download and install the latest version.
      * Once the program has loaded, select Perform full scan, then click Scan.
      * When the scan is complete, click OK, then Show Results to view the results.
      * Be sure that everything is checked, and click Remove Selected.
      * When completed, a log will open in Notepad.
      * Post the log back here.

      The log can also be found here:
      C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
      Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

      RESTART COMPUTER!

      3. Download HijackThis:
      http://www.snapfiles.com/get/hijackthis.html
      Post HijackThis log.

      3882.

      Solve : Best virus protection??

      Answer»

      I posted here before about my computer not STARTING and as it turns out, I had a huge virus and had to get a new computer.
      To prevent this from happening again, I would like to know which virus protection is the best and can be downloaded for free.

      Thank you! Others may chime in with ideas but this is my current package and has served me well for years with no issues...
      Keep in mind if not updated and run regularly there is no protection.

      AVG Free
      AdAware
      Spybot Search and Destroy
      AVG Anti-Spyware (different than AVG Free)
      Win Patrol
      CCleaner.

      All of the above are FREE and considered to be some of the best at what they do.
      No ONE program does it all which is why a layered approach is best.

      Good Luck to you.

      P.S. CCleaner and WinPatrol do accept Donations however this is purely VOLUNTARY but very good Karma....If your anti virus doesn't have a firewall then I think Comodo is really really good protection.
      You should read my problem threads on Computer Viruses and Spyware before i installed comodo (scary ), It doesn't suit some people but it's my favourite .
      I'm not suggesting you install it or something , i just couldn't help but say that its good.

      I'm hope you know that two firewalls shall never be used at the same time(including windows firewall).

      Quote

      I had a huge virus and had to get a new computer
      It was pretty drastic solution....SUPERAntiSpyware is NOT an antivirus program.What does EVERYONE think about Spyware Terminator?Spyware Terminator is good for spyware but isn't to be confused with antivirus.

      There are some advanced features in Spyware Terminator that can be confusing so I rarely recommend it. But it is good.Yea make SURE to understand the difference between spyware and viruses. Those are two completely different things.Kaspersky

      Go to Google and type 'top 10 antiviruses'I use Dogpile instead of Google but that's just me.Independent tests.

      http://www.av-comparatives.org/
      3883.

      Solve : I'm not sure, but I need help?

      Answer»

      I'm almost COMPLETELY computer ILLITERATE, so I'm not sure where to ask for help with this.

      I've been having a strange problem with my computer that STARTED when I downloaded a game from the internet. For no apparent reason I suddenly start hearing some type of program, sounds like a radio or TV broadcast, playing over my speakers, and then it stops only to start up again at random intervals. I also don't see anything, it's just a sound. I recently got a DSL internet connection, and I think it is using that to make the program work, but I don't know how to stop it. I tried deleting the game, but I keep hearing the program, even when I close my internet window. Any advice would be most appreciated. Thanks in advance.Try restarting the computer?
      What antivirus do you have and run a full scan.
      Does the problem still happen when you disconnect from the internet (and then restarting)I've restarted the computer 5 times.

      I use AVG free and I scanned 3 times today, it comes up clean.
      I also use AVG free Anti-spyware, but it hasn't helped.

      How can you disconnect from a DSL internet connection? I have tried removing my ethernet cable from my modem, but again it doesn't help. I just close my internet explorer windows.Download HijackThis:
      http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
      Click on Download HijackThis Installer
      Post HijackTHis log.Hope I did it right...
      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 10:21:15 PM, on 4/9/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16640)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
      C:\Program Files\AT&T\Internet Security Wizard\ISW.exe
      C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
      C:\Program Files\Ahead\InCD\InCDsrv.exe
      C:\Program Files\Common Files\Motive\McciCMService.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\Nexon\Mabinogi\npkcmsvc.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\tcpsvcs.exe
      C:\WINDOWS\System32\snmp.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Raxco\PerfectDisk\PDSched.exe
      C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.att.net/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R3 - URLSearchHook: (no name) - {F0102993-9826-C387-512F-ED1BB0071695} - C:\WINDOWS\system32\jvm.dll (file missing)
      O2 - BHO: (no name) - {031E8EF1-3514-34E9-382C-1DE4BFB0E8C8} - C:\WINDOWS\system32\lmjm.dll (file missing)
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {29ACA570-40C9-1B3B-E8E1-31A60B5B909E} - C:\WINDOWS\system32\krng.dll (file missing)
      O2 - BHO: (no name) - {2BFAF773-4ACE-4968-E8E1-31A60B5B969A} - C:\WINDOWS\system32\xql.dll (file missing)
      O2 - BHO: (no name) - {31E55F30-E9A5-E102-82FB-C46936AE8FC3} - C:\WINDOWS\system32\amyr.dll (file missing)
      O2 - BHO: (no name) - {32FFD737-75C5-656C-FEFE-178A3B6ACDF9} - C:\WINDOWS\system32\rlruxgz.dll (file missing)
      O2 - BHO: (no name) - {50FD43F8-AB19-A0E2-678C-87AD0B7BE3C3} - C:\WINDOWS\system32\jbdkaskb.dll (file missing)
      O2 - BHO: (no name) - {741AC613-62E3-744C-859B-516E855288A7} - C:\WINDOWS\system32\pjqff.dll (file missing)
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O2 - BHO: (no name) - {89DDFA84-1738-43CB-4A3B-3CC62D4966C5} - C:\WINDOWS\system32\doaazse.dll (file missing)
      O2 - BHO: (no name) - {8DF6F6DF-062A-4380-14DD-65AD390978F7} - C:\WINDOWS\system32\rhunfh.dll (file missing)
      O2 - BHO: (no name) - {8F8BF5D6-1169-439C-4E3B-3CC62D493297} - C:\WINDOWS\system32\fvscoa.dll (file missing)
      O2 - BHO: MYPOINTS - {A057A204-BACC-4D26-CEC4-75A487FD6484} - C:\PROGRA~1\mypoints\mypoints.dll
      O2 - BHO: (no name) - {A41CE5D2-5D32-0F9D-13DB-72F2BE5040CF} - C:\WINDOWS\system32\jguehat.dll (file missing)
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: (no name) - {B88FC2AC-2E4A-7FB9-62E4-5180783A00C1} - C:\WINDOWS\system32\sun.dll (file missing)
      O2 - BHO: (no name) - {B8B737C8-C33E-8BC5-5534-FBA4286D45F8} - C:\WINDOWS\system32\uftczc.dll (file missing)
      O2 - BHO: (no name) - {C0A5C7B6-7D06-2EA6-23F8-0045057A229B} - C:\WINDOWS\system32\mkcpuuw.dll (file missing)
      O2 - BHO: (no name) - {F0102993-9826-C387-512F-ED1BB0071695} - C:\WINDOWS\system32\jvm.dll (file missing)
      O3 - Toolbar: MYPOINTS - {A057A204-BACC-4D26-CEC4-75A487FD6484} - C:\PROGRA~1\mypoints\mypoints.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
      O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
      O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe 1
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [ISW.exe] "C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" /AUTORUN
      O4 - HKLM\..\Run: [HelpCenter4.1] C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe /P HelpCenter4.1
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
      O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
      O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZUxdm265NYUS
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
      O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
      O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/MyFunCardsFWBInitialSetup1.0.0.15-3.cab
      O16 - DPF: {26098EA2-C95D-48EA-89B4-63C5A63BD42F} - http://www.pacimedia.com/install/pcs_0031.exe
      O16 - DPF: {5E92F538-B50B-46C5-9C5F-C6EECED3F6C6} - http://www.infospace.com/mypoints.main/tbar/mypointsSetup.exe
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1100886880636
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1168574706123
      O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.verizon.net/checkmypc/includes/MotivePreQual.cab
      O21 - SSODL: UnknownVolume - {84997789-71bf-44ad-826b-0b27d63e432f} - C:\WINDOWS\Resources\UnknownVolume.dll
      O23 - Service: a-squared Free Service (a2free) - Unknown owner - G:\Apps\Antispyware\a-squared Free\a2service.exe (file missing)
      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
      O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
      O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
      O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
      O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
      O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDSched.exe

      --
      End of file - 10182 bytesYou have quiet a few infections...

      Print these instructions out.

      1. Download SUPERAntiSpyware Free for Home Users:
      http://www.superantispyware.com/

      * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
      * An icon will be created on your desktop. Double-click that icon to launch the program.
      * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
      * Close SUPERAntiSpyware.

      Restart computer in Safe Mode.
      To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

      * Open SUPERAntiSpyware.
      * Under "Configuration and Preferences", click the Preferences button.
      * Click the Scanning Control tab.
      * Under Scanner Options make sure the following are checked (leave all others unchecked):
      o Close browsers before scanning.
      o Scan for tracking cookies.
      o Terminate memory threats before quarantining.
      * Click the "Close" button to leave the control center screen.
      * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
      * On the left, make sure you check C:\Fixed Drive.
      * On the right, under "Complete Scan", choose Perform Complete Scan.
      * Click "Next" to start the scan. Please be patient while it scans your computer.
      * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
      * Make sure everything has a checkmark next to it and click "Next".
      * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
      * If asked if you want to reboot, click "Yes".
      * To retrieve the removal information after reboot, launch SUPERAntispyware again.
      o Click Preferences, then click the Statistics/Logs tab.
      o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
      o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
      o Please copy and paste the Scan Log results in your next reply.
      * Click Close to exit the program.
      Post SUPERAntiSpyware log.

      RESTART COMPUTER!

      2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

      * Double-click mbam-setup.exe and follow the prompts to install the program.
      * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
      * If an update is found, it will download and install the latest version.
      * Once the program has loaded, select Perform full scan, then click Scan.
      * When the scan is complete, click OK, then Show Results to view the results.
      * Be sure that everything is checked, and click Remove Selected.
      * When completed, a log will open in Notepad.
      * Post the log back here.

      The log can also be found here:
      C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
      Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

      RESTART COMPUTER!

      3. Post new HijackThis log.SUPERAntiSpyware Scan Log
      http://www.superantispyware.com

      Generated 04/10/2008 at 01:17 AM

      Application Version : 4.0.1154

      Core Rules Database Version : 3435
      Trace Rules Database Version: 1427

      Scan type : Complete Scan
      Total Scan Time : 01:46:16

      Memory items scanned : 171
      Memory threats detected : 0
      Registry items scanned : 5717
      Registry threats detected : 3
      File items scanned : 64719
      File threats detected : 63

      Adware.Tracking Cookie
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt

      Trojan.Net-MU/Gen
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebVideo
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebVideo#uninstallString
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebVideo#DisplayName

      Adware.ClickSpring
      C:\WINDOWS\system32\RGSVR3~1.EXE
      Malwarebytes' Anti-Malware 1.11
      Database version: 606

      Scan type: Full Scan (C:\|F:\|)
      Objects scanned: 94479
      Time elapsed: 28 minute(s), 24 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 1
      Registry Keys Infected: 18
      Registry Values Infected: 1
      Registry Data Items Infected: 0
      Folders Infected: 8
      Files Infected: 20

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      C:\WINDOWS\Resources\UnknownVolume.dll (Trojan.Clicker) -> Unloaded module successfully.

      Registry Keys Infected:
      HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{84997789-71bf-44ad-826b-0b27d63e432f} (Trojan.Clicker) -> Delete on reboot.
      HKEY_CURRENT_USER\Software\mwc (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Software\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Software\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VideoPlugin (Trojan.Fakealert) -> Quarantined and deleted successfully.

      Registry Values Infected:
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\UnknownVolume (Trojan.Clicker) -> Delete on reboot.

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      C:\Program Files\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      C:\Program Files\MyWebSearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      C:\Program Files\MyWebSearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      C:\Program Files\MyWebSearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      C:\Program Files\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      C:\Program Files\FunWebProducts\ScreenSaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      C:\Program Files\FunWebProducts\Shared (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      C:\Program Files\FunWebProducts\ScreenSaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully.

      Files Infected:
      C:\System Volume Information\_restore{148BB4EB-497F-42F0-8136-73653F3B9ECC}\RP1020\A0189041.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      C:\System Volume Information\_restore{148BB4EB-497F-42F0-8136-73653F3B9ECC}\RP1020\A0189043.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      C:\System Volume Information\_restore{148BB4EB-497F-42F0-8136-73653F3B9ECC}\RP1022\A0190061.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      C:\System Volume Information\_restore{148BB4EB-497F-42F0-8136-73653F3B9ECC}\RP1022\A0190062.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      C:\System Volume Information\_restore{148BB4EB-497F-42F0-8136-73653F3B9ECC}\RP1022\A0190063.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      C:\System Volume Information\_restore{148BB4EB-497F-42F0-8136-73653F3B9ECC}\RP1022\A0190064.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      C:\System Volume Information\_restore{148BB4EB-497F-42F0-8136-73653F3B9ECC}\RP1022\A0190065.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      C:\System Volume Information\_restore{148BB4EB-497F-42F0-8136-73653F3B9ECC}\RP1022\A0190066.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      C:\System Volume Information\_restore{148BB4EB-497F-42F0-8136-73653F3B9ECC}\RP1026\A0190139.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      C:\System Volume Information\_restore{148BB4EB-497F-42F0-8136-73653F3B9ECC}\RP1033\A0194218.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      C:\Program Files\MyWebSearch\bar\History\search2 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      C:\Program Files\MyWebSearch\bar\Settings\setting2.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      C:\Program Files\MyWebSearch\bar\Settings\settings.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      C:\Program Files\FunWebProducts\ScreenSaver\Images\10578DCE.urr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      C:\WINDOWS\Resources\UnknownVolume.dll (Trojan.Clicker) -> Delete on reboot.
      C:\WINDOWS\system32\ClickToFindandFixErrors_4.ico (Malware.Trace) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\ClickToFindandFixErrors_Intl.ico (Malware.Trace) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\ClickToFindandFixErrors_RON.ico (Malware.Trace) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\ClickToFindandFixErrors_US.ico (Malware.Trace) -> Quarantined and deleted successfully.
      I've noticed when I restart, an internet window opens up and asks me for my podcast login information. I don't have that, and I don't even know what a podcast is, so I've been closing the window and ignoring it. But I was wondering if that could be the cause of the weird sounds I keep hearing.


      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 9:32:24 AM, on 4/10/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16640)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
      C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
      C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
      C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe
      C:\Program Files\AT&T\Internet Security Wizard\ISW.exe
      C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
      C:\Program Files\Ahead\InCD\InCDsrv.exe
      C:\Program Files\Common Files\Motive\McciCMService.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\Nexon\Mabinogi\npkcmsvc.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
      C:\WINDOWS\system32\tcpsvcs.exe
      C:\WINDOWS\System32\snmp.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Raxco\PerfectDisk\PDSched.exe
      C:\WINDOWS\system32\WgaTray.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.att.net/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R3 - URLSearchHook: (no name) - {F0102993-9826-C387-512F-ED1BB0071695} - C:\WINDOWS\system32\jvm.dll (file missing)
      O2 - BHO: (no name) - {031E8EF1-3514-34E9-382C-1DE4BFB0E8C8} - C:\WINDOWS\system32\lmjm.dll (file missing)
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {29ACA570-40C9-1B3B-E8E1-31A60B5B909E} - C:\WINDOWS\system32\krng.dll (file missing)
      O2 - BHO: (no name) - {2BFAF773-4ACE-4968-E8E1-31A60B5B969A} - C:\WINDOWS\system32\xql.dll (file missing)
      O2 - BHO: (no name) - {31E55F30-E9A5-E102-82FB-C46936AE8FC3} - C:\WINDOWS\system32\amyr.dll (file missing)
      O2 - BHO: (no name) - {32FFD737-75C5-656C-FEFE-178A3B6ACDF9} - C:\WINDOWS\system32\rlruxgz.dll (file missing)
      O2 - BHO: (no name) - {50FD43F8-AB19-A0E2-678C-87AD0B7BE3C3} - C:\WINDOWS\system32\jbdkaskb.dll (file missing)
      O2 - BHO: (no name) - {741AC613-62E3-744C-859B-516E855288A7} - C:\WINDOWS\system32\pjqff.dll (file missing)
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O2 - BHO: (no name) - {89DDFA84-1738-43CB-4A3B-3CC62D4966C5} - C:\WINDOWS\system32\doaazse.dll (file missing)
      O2 - BHO: (no name) - {8DF6F6DF-062A-4380-14DD-65AD390978F7} - C:\WINDOWS\system32\rhunfh.dll (file missing)
      O2 - BHO: (no name) - {8F8BF5D6-1169-439C-4E3B-3CC62D493297} - C:\WINDOWS\system32\fvscoa.dll (file missing)
      O2 - BHO: MYPOINTS - {A057A204-BACC-4D26-CEC4-75A487FD6484} - C:\PROGRA~1\mypoints\mypoints.dll
      O2 - BHO: (no name) - {A41CE5D2-5D32-0F9D-13DB-72F2BE5040CF} - C:\WINDOWS\system32\jguehat.dll (file missing)
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: (no name) - {B88FC2AC-2E4A-7FB9-62E4-5180783A00C1} - C:\WINDOWS\system32\sun.dll (file missing)
      O2 - BHO: (no name) - {B8B737C8-C33E-8BC5-5534-FBA4286D45F8} - C:\WINDOWS\system32\uftczc.dll (file missing)
      O2 - BHO: (no name) - {C0A5C7B6-7D06-2EA6-23F8-0045057A229B} - C:\WINDOWS\system32\mkcpuuw.dll (file missing)
      O2 - BHO: (no name) - {F0102993-9826-C387-512F-ED1BB0071695} - C:\WINDOWS\system32\jvm.dll (file missing)
      O3 - Toolbar: MYPOINTS - {A057A204-BACC-4D26-CEC4-75A487FD6484} - C:\PROGRA~1\mypoints\mypoints.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
      O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
      O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe 1
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [ISW.exe] "C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" /AUTORUN
      O4 - HKLM\..\Run: [HelpCenter4.1] C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe /P HelpCenter4.1
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
      O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
      O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZUxdm265NYUS
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
      O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
      O16 - DPF: {26098EA2-C95D-48EA-89B4-63C5A63BD42F} - http://www.pacimedia.com/install/pcs_0031.exe
      O16 - DPF: {5E92F538-B50B-46C5-9C5F-C6EECED3F6C6} - http://www.infospace.com/mypoints.main/tbar/mypointsSetup.exe
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1100886880636
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1168574706123
      O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.verizon.net/checkmypc/includes/MotivePreQual.cab
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
      O23 - Service: a-squared Free Service (a2free) - Unknown owner - G:\Apps\Antispyware\a-squared Free\a2service.exe (file missing)
      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
      O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
      O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
      O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
      O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
      O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDSched.exe

      --
      End of file - 10117 bytes
      Let me check HJT, first...*** Is Windows firewall ON?

      *** Uninstall AT&T Internet Security Wizard. Instructions here: http://securityhelp.bellsouth.net/index.php?ToDo=view&Frame=1&questId=368&catId=61

      1. Print this post out, since you won't have an access to it, at some point.

      2. Close all windows, except for HijackThis.

      3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actual program will be removed):

      - R3 - URLSearchHook: (no name) - {F0102993-9826-C387-512F-ED1BB0071695} - C:\WINDOWS\system32\jvm.dll (file missing)
      - O2 - BHO: (no name) - {031E8EF1-3514-34E9-382C-1DE4BFB0E8C8} - C:\WINDOWS\system32\lmjm.dll (file missing)
      - O2 - BHO: (no name) - {29ACA570-40C9-1B3B-E8E1-31A60B5B909E} - C:\WINDOWS\system32\krng.dll (file missing)
      - O2 - BHO: (no name) - {2BFAF773-4ACE-4968-E8E1-31A60B5B969A} - C:\WINDOWS\system32\xql.dll (file missing)
      - O2 - BHO: (no name) - {31E55F30-E9A5-E102-82FB-C46936AE8FC3} - C:\WINDOWS\system32\amyr.dll (file missing)
      - O2 - BHO: (no name) - {32FFD737-75C5-656C-FEFE-178A3B6ACDF9} - C:\WINDOWS\system32\rlruxgz.dll (file missing)
      - O2 - BHO: (no name) - {50FD43F8-AB19-A0E2-678C-87AD0B7BE3C3} - C:\WINDOWS\system32\jbdkaskb.dll (file missing)
      - O2 - BHO: (no name) - {741AC613-62E3-744C-859B-516E855288A7} - C:\WINDOWS\system32\pjqff.dll (file missing)
      - O2 - BHO: (no name) - {89DDFA84-1738-43CB-4A3B-3CC62D4966C5} - C:\WINDOWS\system32\doaazse.dll (file missing)
      - O2 - BHO: (no name) - {8DF6F6DF-062A-4380-14DD-65AD390978F7} - C:\WINDOWS\system32\rhunfh.dll (file missing)
      - O2 - BHO: (no name) - {8F8BF5D6-1169-439C-4E3B-3CC62D493297} - C:\WINDOWS\system32\fvscoa.dll (file missing)
      - O2 - BHO: (no name) - {A41CE5D2-5D32-0F9D-13DB-72F2BE5040CF} - C:\WINDOWS\system32\jguehat.dll (file missing)
      - O2 - BHO: (no name) - {B88FC2AC-2E4A-7FB9-62E4-5180783A00C1} - C:\WINDOWS\system32\sun.dll (file missing)
      - O2 - BHO: (no name) - {B8B737C8-C33E-8BC5-5534-FBA4286D45F8} - C:\WINDOWS\system32\uftczc.dll (file missing)
      - O2 - BHO: (no name) - {C0A5C7B6-7D06-2EA6-23F8-0045057A229B} - C:\WINDOWS\system32\mkcpuuw.dll (file missing)
      - O2 - BHO: (no name) - {F0102993-9826-C387-512F-ED1BB0071695} - C:\WINDOWS\system32\jvm.dll (file missing)
      - O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZUxdm265NYUS
      - O16 - DPF: {26098EA2-C95D-48EA-89B4-63C5A63BD42F} - http://www.pacimedia.com/install/pcs_0031.exe
      - O16 - DPF: {5E92F538-B50B-46C5-9C5F-C6EECED3F6C6} - http://www.infospace.com/mypoints.main/tbar/mypointsSetup.exe


      4. Click on Fix checked button.

      5. Restart computer.

      9. Post new HijackThis log.I think my Windows firewall is on, as I never turned it off, but I don't even know how to tell...


      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 8:40:58 PM, on 4/10/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16640)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
      C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
      C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
      C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe
      C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
      C:\Program Files\Ahead\InCD\InCDsrv.exe
      C:\Program Files\Common Files\Motive\McciCMService.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\Nexon\Mabinogi\npkcmsvc.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
      C:\WINDOWS\system32\tcpsvcs.exe
      C:\WINDOWS\System32\snmp.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Raxco\PerfectDisk\PDSched.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.att.net/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O2 - BHO: MYPOINTS - {A057A204-BACC-4D26-CEC4-75A487FD6484} - C:\PROGRA~1\mypoints\mypoints.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: MYPOINTS - {A057A204-BACC-4D26-CEC4-75A487FD6484} - C:\PROGRA~1\mypoints\mypoints.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
      O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
      O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe 1
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [HelpCenter4.1] C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe /P HelpCenter4.1
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
      O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
      O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1100886880636
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1168574706123
      O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.verizon.net/checkmypc/includes/MotivePreQual.cab
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
      O23 - Service: a-squared Free Service (a2free) - Unknown owner - G:\Apps\Antispyware\a-squared Free\a2service.exe (file missing)
      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
      O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
      O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
      O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
      O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
      O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDSched.exe

      --
      End of file - 7847 bytes
      Very well

      HJT log is clean.

      1. Turn off System Restore:

      - Windows XP:
      1. Click Start.
      2. Right-click the My Computer icon, and then click Properties.
      3. Click the System Restore tab.
      4. Check "Turn off System Restore".
      5. Click Apply.
      6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
      7. Click OK.
      - Windows Vista:
      1. Click Start.
      2. Right-click the Computer icon, and then click Properties.
      3. Click on System Protection under the Tasks column on the left side
      4. Click on Continue on the "User Account Control" window that POPS up
      5. Under the System Protection tab, find Available Disks
      6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
      7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
      8. Click OK

      2. Restart computer.

      3. Turn System Restore on. Create new Restore Point.

      4. Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
      Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html, and run CCleaner

      6. Download, and install free ThreatFire: http://www.threatfire.com/, which will give you real-time protection against malwares.
      It won't interfere with your antivirus, nor firewall.

      7. Let me know, how your computer is doing.
      Thank you so much! The noise has stopped, and my computer is running a lot better as well. Thank you again.Good news

      3884.

      Solve : Warning! Potential spyware operation?

      Answer»

      Help! I know this has been here before so I did all the requirements I think and below is the notepad from Hijack this. Very frustrating. Thank you in advance.

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 11:47:00 AM, on 4/10/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16640)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\INTEL\Wireless\Bin\EvtEng.exe
      C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
      C:\WINDOWS\system32\DVDRAMSV.exe
      C:\WINDOWS\eHome\ehRecvr.exe
      C:\WINDOWS\eHome\ehSched.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
      C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
      C:\WINDOWS\system32\svchost.exe
      c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
      C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\dllhost.exe
      C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
      C:\WINDOWS\system32\TDispVol.exe
      C:\WINDOWS\ehome\ehtray.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
      C:\WINDOWS\eHome\ehmsas.exe
      C:\WINDOWS\system32\TPSMain.exe
      C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
      C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\WINDOWS\system32\TPSBattM.exe
      C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
      C:\WINDOWS\system32\RAMASST.exe
      C:\Program Files\STOPzilla!\STOPzilla.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.toshiba.com/search
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
      O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll
      O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
      O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll
      O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
      O4 - HKLM\..\Run: [tdispVol] TDispVol.exe
      O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
      O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /STARTUP
      O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
      O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
      O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
      O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
      O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
      O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
      O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
      O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\DLACTRLW.exe
      O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
      O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
      O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
      O4 - HKLM\..\Run: [MSDisp32] rundll32.exe C:\WINDOWS\system32\drvdav.dll,startup
      O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
      O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
      O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
      O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
      O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
      O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
      O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
      O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
      O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
      O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
      O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
      O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/citrix/wficat-no-eula.cab
      O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1147458700296
      O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1207845332265
      O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - https://beyer.redirectme.net/Remote/msrdp.cab
      O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
      O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
      O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
      O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
      O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
      O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
      O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
      O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
      O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe

      --
      End of file - 9579 bytes
      Print these instructions out.

      1. Download SUPERAntiSpyware Free for Home Users:
      http://www.superantispyware.com/

      * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
      * An icon will be created on your desktop. Double-click that icon to launch the program.
      * If asked to update the program definitions, click "YES". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
      * Close SUPERAntiSpyware.

      Restart computer in Safe Mode.
      To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

      * Open SUPERAntiSpyware.
      * Under "Configuration and Preferences", click the Preferences button.
      * Click the Scanning Control tab.
      * Under Scanner Options make sure the following are checked (leave all others unchecked):
      o Close browsers before scanning.
      o Scan for tracking cookies.
      o Terminate memory threats before quarantining.
      * Click the "Close" button to leave the control center screen.
      * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
      * On the left, make sure you check C:\Fixed Drive.
      * On the right, under "Complete Scan", choose Perform Complete Scan.
      * Click "Next" to start the scan. Please be patient while it scans your computer.
      * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
      * Make sure everything has a checkmark next to it and click "Next".
      * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
      * If asked if you want to reboot, click "Yes".
      * To retrieve the removal information after reboot, launch SUPERAntispyware again.
      o Click Preferences, then click the Statistics/Logs tab.
      o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
      o If there are several logs, click the current dated log and PRESS View log. A text file will open in your default text editor.
      o Please copy and paste the Scan Log results in your next reply.
      * Click Close to exit the program.
      Post SUPERAntiSpyware log.

      RESTART COMPUTER!

      2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

      * Double-click mbam-setup.exe and follow the prompts to install the program.
      * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
      * If an update is found, it will download and install the latest version.
      * Once the program has loaded, select Perform full scan, then click Scan.
      * When the scan is complete, click OK, then Show Results to view the results.
      * Be sure that everything is checked, and click Remove Selected.
      * When completed, a log will open in Notepad.
      * Post the log back here.

      The log can also be found here:
      C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
      Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

      RESTART COMPUTER!

      3. Post new HijackThis log.Thank you Broni. By simply running the Superanti spyware you suggested the problem is gone. I appreciate the help.No, it doesn't work that way. You need to follow ALL my instructions.

      3885.

      Solve : Different Computer Running Very Slow?

      Answer»

      I have another computer that has been quite bothersome.
      It runs extremely slow despite being not all that old.

      My specifics:
      -Dell Dimension DV051
      -Windows XP

      -Total Space 107 GB
      -Free Space 84.6 GB
      -Pentium 4 CPU 4GHz
      -.99 GB RAM

      -McAfee Anti-Virus
      -Super Anti-Spyware
      -CCleaner


      My steps:
      -McAfee run....no virus
      -Super Anti-Spyware......no problems
      -CCleaner...............all emptied


      1) Do you have any idea what the problem could be and how to resolve?HiJack This Log


      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 7:48:04 PM, on 3/18/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16608)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      C:\WINDOWS\system32\LEXBCES.EXE
      C:\WINDOWS\system32\LEXPPS.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Common Files\Command SOFTWARE\dvpapi.exe
      C:\WINDOWS\eHome\ehRecvr.exe
      C:\WINDOWS\eHome\ehSched.exe
      C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
      C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
      c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
      C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
      C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
      c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
      c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
      C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
      C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
      C:\Program Files\McAfee\MPF\MPFSrv.exe
      C:\PROGRA~1\McAfee\MPS\mps.exe
      C:\Program Files\McAfee\MSK\MskSrver.exe
      C:\Program Files\SiteAdvisor\6253\SAService.exe
      C:\Program Files\Dell Support Center\bin\sprtsvc.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Viewpoint\Common\ViewpointService.exe
      C:\WINDOWS\system32\dllhost.exe
      C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
      C:\WINDOWS\Explorer.EXE
      c:\PROGRA~1\mcafee.com\agent\mcagent.exe
      C:\PROGRA~1\Yahoo!\YOP\yop.exe
      C:\Program Files\Yahoo!\Yahoo! Music Engine\YahooMusicEngine.exe
      C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
      C:\Program Files\QuickTime\QTTask.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\WINDOWS\system32\igfxpers.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\Program Files\Common Files\AOL\1151195914\ee\AOLSoftware.exe
      C:\WINDOWS\ehome\ehtray.exe
      C:\PROGRA~1\Yahoo!\browser\ycommon.exe
      C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
      C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
      C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
      C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
      C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
      C:\WINDOWS\eHome\ehmsas.exe
      C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
      C:\Program Files\McAfee\MSK\MskAgent.exe
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
      C:\Program Files\McAfee\MPS\mpsevh.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      C:\Program Files\DellSupport\DSAgnt.exe
      C:\Program Files\Dell Support Center\bin\sprtcmd.exe
      C:\Program Files\AOL 9.0\waol.exe
      C:\Program Files\Common Files\Verizon Online\ConnMgr\cmisrv.exe
      C:\Program Files\Yahoo!\Yahoo! Music Engine\ymetray.exe
      C:\Program Files\Dell Support Center\gs_agent\dsc.exe
      C:\Program Files\Common Files\AOL\1151195914\ee\aolsoftware.exe
      C:\Program Files\Common Files\Verizon Online\AppMgr\vzOpenUIServer.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://verizon.yahoo.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/verizon/*http://www.yahoo.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/verizon/*http://www.yahoo.com/search/ie.html
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/verizon/*http://www.yahoo.com
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://verizon.yahoo.com
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
      O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
      O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
      O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
      O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.8.0\ViewBarBHO.dll
      O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
      O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\IEViewBar.dll
      O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
      O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
      O4 - HKLM\..\Run: [YPC] C:\PROGRA~1\Yahoo!\PARENT~1\ypc.exe
      O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
      O4 - HKLM\..\Run: [ymetray] "C:\Program Files\Yahoo!\Yahoo! Music Engine\YahooMusicEngine.exe" -preload
      O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
      O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1151195914\ee\AOLSoftware.exe
      O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
      O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
      O4 - HKLM\..\Run: [A Verizon App] C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
      O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe"
      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
      O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup



      (Continued)



      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
      O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
      O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
      O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
      O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
      O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0\AOL.EXE" -b
      O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
      O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
      O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Engine\ymetray.exe
      O8 - Extra context menu item: &AOL Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
      O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
      O9 - Extra button: Verizon Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
      O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O15 - Trusted Zone: http://*.mcafee.com
      O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://remote.segalco.com/wficat81.cab
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
      O16 - DPF: {48DF87EE-F2DE-11D8-BE7F-302050C10801} (FlyLoader Class) - http://www.flyword.com/loaderword_win.cab
      O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://www.pcpitstop.com/mhLbl.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
      O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
      O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
      O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
      O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
      O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
      O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
      O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
      O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
      O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
      O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
      O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
      O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
      O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
      O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
      O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
      O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
      O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
      O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6253\SAService.exe
      O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
      O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
      O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

      --
      End of file - 14753 bytes
      I don't see any malware but there is something that needs fixed.

      You have Viewpoint installed.

      Viewpoint Media Player/Manager/Toolbar is considered as foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad". See Viewpoint to Plunge Into Adware

      It is suggested to remove the program now.
      Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present.

      • Viewpoint
      • Viewpoint Manager
      • Viewpoint Media Player
      • Viewpoint Toolbar
      • Viewpoint Experience Technology
      If you have trouble removing Viewpoint, I suggest that you use ViewpointKiller

      Once you have downloaded ViewpointKiller, unzip it to a convenient location such as your desktop.
      Run ViewpointKiller, and select File > Do All Killings
      Follow the prompts, selecting Yes or No, depending on which selection you are most comfortable with.
      A logfile will be created in the folder you unzipped ViewpointKiller to, please paste the contents here.

      Your Java is out of date. Go to this THREAD and scroll down to the Updating Java instructions.


      Have you tried running a disk defrag?

      How attached are you to the McAfee security suite?Alright...thanks.
      I followed the guide to getting started AND your suggestions.
      I have some additional questions.

      1) My anti-virus is McAfee...which was the paid edition. Is this sufficient or should I remove and get a different brand?

      2) Speaking of anti-virus....I downloaded the dr.web.
      A. Does this mean I now have TWO anti-virus programs...and wouldn't this conflict?
      B. It found a trojan....how come McAfee which is paid for DID NOT?

      3) I removed ViewPoint...it no longer is on the add/remove programs. However is there a way to confirm?

      4) This CPU has been defragged a few weeks ago.

      5) Overall...the CPU is running faster. However....it still is noticably slow upon starting.
      A. I believe one of the causes is when the CPU is started...too many programs are running. Is there anyway I can find out what programs run and which are unnecessary/disable?

      6) The windows taskbar...for example...is LOADED with programs I do not want running I unless I specify. These include...
      -Verizon Yahoo Messenger
      -Verizon YahooJukeBox
      -Adobe PhotoDownloader
      -Quicktime
      A. How can I make it so these do not start automatically on the CPU or taskbar?

      7) Speaking of programs....I do not want Verizon Yahoo messenger or Verizon Yahoo Jukebox....how can I delete these without impacting Verizon internet?

      Thanks!Alright...thanks.
      I followed the guide to getting started AND your suggestions.
      I have some additional questions.

      1) My anti-virus is McAfee...which was the paid edition. Is this sufficient or should I remove and get a different brand?

      What version is it?

      2) Speaking of anti-virus....I downloaded the dr.web.
      A. Does this mean I now have TWO anti-virus programs...and wouldn't this conflict?
      B. It found a trojan....how come McAfee which is paid for DID NOT?

      A. Dr Web is an on-demand scanner, it has no real time protection so there will be no conflicts.

      B.Is your McAfee up to date? Different vendors have different databases. This is pert of the reason why we use other products for removal instead of what is already installed.

      3) I removed ViewPoint...it no longer is on the add/remove programs. However is there a way to confirm?

      Need the logs to see for sure.

      4) This CPU has been defragged a few weeks ago.

      5) Overall...the CPU is running faster. However....it still is noticably slow upon starting.
      A. I believe one of the causes is when the CPU is started...too many programs are running. Is there anyway I can find out what programs run and which are unnecessary/disable?

      6) The windows taskbar...for example...is loaded with programs I do not want running I unless I specify. These include...
      -Verizon Yahoo Messenger
      -Verizon YahooJukeBox
      -Adobe PhotoDownloader
      -Quicktime
      A. How can I make it so these do not start automatically on the CPU or taskbar?

      7) Speaking of programs....I do not want Verizon Yahoo messenger or Verizon Yahoo Jukebox....how can I delete these without impacting Verizon internet?

      Thanks!

      Lets clear the malware first to make sure it doesn't interfere with anything then work on the startups.

      I need the logs.
      1) McAfee is up to date.

      2) CPU is still slow.
      -Configuered and ran CCleaner
      -Ran SAS, no viruses came up.
      -Ran Dr.Web, posted log
      -Turned off, and then on system restore
      -Downloaded threatfire
      -Cleaned the DISC drive
      -Java is up to date
      -Ran HiJack this, posted log

      3) What else can I do to make the CPU run normal?
      -What is the problem?

      4) The taskbar when the CPU starts has WAAY too many things going on....how can I MINIMIZE the activity?

      Thanks.




      Dr. Web Log








      inst.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\AIMSUD338;Probably BACKDOOR.Trojan;Deleted.;
      setup.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\AOL_OpenRide_1.22.61.1;Probably BACKDOOR.Trojan;Incurable.Deleted.;
      inst.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\ssc_suite_installer_1.205.7.1_suite;Probably BACKDOOR.Trojan;Incurable.Deleted.;
      inst.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\ssc_suite_installer_1.210.2.4_suite;Probably BACKDOOR.Trojan;Incurable.Deleted.;
      inst.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\SUD4028;Probably BACKDOOR.Trojan;Incurable.Deleted.;
      setup.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\SUD4131;Probably BACKDOOR.Trojan;Incurable.Deleted.;
      inst.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_suite_install_2.2.71.1;Probably BACKDOOR.Trojan;Incurable.Deleted.;
      inst.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_suite_install_2.2.78.1;Probably BACKDOOR.Trojan;Incurable.Deleted.;
      inst.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_suite_install_6.0.28.3;Probably BACKDOOR.Trojan;Incurable.Deleted.;
      inst.exe;C:\Program Files\AOL\Installers\AOL Safety & Security Center 1.0;Probably BACKDOOR.Trojan;Incurable.Deleted.;
      inst.exe;C:\Program Files\AOL\Installers\AOL Safety & Security Center 1.02;Probably BACKDOOR.Trojan;Incurable.Deleted.;
      setup.exe;C:\Program Files\AOL\Installers\ASP 2.0;Probably BACKDOOR.Trojan;Incurable.Deleted.;
      setup.exe;C:\Program Files\AOL\Internet Access Controls\Installer;Probably BACKDOOR.Trojan;Incurable.Deleted.;
      ppctl.dll;C:\Program Files\Common Files\AOL\1151195914\ee\services\antiSpyware\ver2_4_9_1\resources;Probably DLOADER.Trojan;Incurable.Deleted.;
      ppctl.dll;C:\Program Files\Common Files\PestPatrol;Probably DLOADER.Trojan;Incurable.Deleted.;
      ppctl.dll;C:\Program Files\Common Files\Scanner;Probably DLOADER.Trojan;Incurable.Deleted.;



      Notice how most are AOL...since I have DSL...should I just use the mozilla and NOT the AOL browser?HiJack this Log








      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 6:00:04 PM, on 4/12/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16640)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      C:\WINDOWS\system32\LEXBCES.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\LEXPPS.EXE
      C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Common Files\Command Software\dvpapi.exe
      C:\WINDOWS\eHome\ehRecvr.exe
      C:\WINDOWS\eHome\ehSched.exe
      C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
      C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
      c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
      C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
      C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
      c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
      c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
      C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
      C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
      C:\Program Files\McAfee\MPF\MPFSrv.exe
      C:\PROGRA~1\McAfee\MPS\mps.exe
      C:\Program Files\McAfee\MSK\MskSrver.exe
      C:\Program Files\SiteAdvisor\6253\SAService.exe
      C:\Program Files\Dell Support Center\bin\sprtsvc.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\ThreatFire\TFService.exe
      C:\WINDOWS\ehome\mcrdsvc.exe
      C:\WINDOWS\system32\dllhost.exe
      C:\WINDOWS\System32\alg.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe
      C:\WINDOWS\Explorer.EXE
      c:\PROGRA~1\mcafee.com\agent\mcagent.exe
      C:\PROGRA~1\Yahoo!\YOP\yop.exe
      C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
      C:\Program Files\QuickTime\QTTask.exe
      C:\WINDOWS\system32\igfxpers.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\Program Files\Common Files\AOL\1151195914\ee\AOLSoftware.exe
      C:\Program Files\McAfee\MPS\mpsevh.exe
      C:\WINDOWS\ehome\ehtray.exe
      C:\PROGRA~1\Yahoo!\browser\ycommon.exe
      C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
      C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
      C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
      C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
      C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
      C:\Program Files\McAfee\MSK\MskAgent.exe
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
      C:\WINDOWS\eHome\ehmsas.exe
      C:\Program Files\ThreatFire\TFTray.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Common Files\Verizon Online\ConnMgr\cmisrv.exe
      C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      C:\Program Files\DellSupport\DSAgnt.exe
      C:\Program Files\Dell Support Center\bin\sprtcmd.exe
      C:\Program Files\Yahoo!\Yahoo! Music Engine\ymetray.exe
      C:\Program Files\Common Files\Verizon Online\AppMgr\vzOpenUIServer.exe
      C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
      C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32Info.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exeContinued



      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://verizon.yahoo.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/verizon/*http://www.yahoo.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/verizon/*http://www.yahoo.com/search/ie.html
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/verizon/*http://www.yahoo.com
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://verizon.yahoo.com
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
      O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
      O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
      O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
      O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
      O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
      O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
      O4 - HKLM\..\Run: [YPC] C:\PROGRA~1\Yahoo!\PARENT~1\ypc.exe
      O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
      O4 - HKLM\..\Run: [ymetray] "C:\Program Files\Yahoo!\Yahoo! Music Engine\YahooMusicEngine.exe" -preload
      O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
      O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1151195914\ee\AOLSoftware.exe
      O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
      O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
      O4 - HKLM\..\Run: [A Verizon App] C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
      O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe"
      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
      O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
      O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
      O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
      O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
      O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
      O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
      O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
      O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
      O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Engine\ymetray.exe
      O8 - Extra context menu item: &AOL Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
      O9 - Extra button: Verizon Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
      O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O15 - Trusted Zone: http://*.mcafee.com
      O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://remote.segalco.com/wficat81.cab
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
      O16 - DPF: {48DF87EE-F2DE-11D8-BE7F-302050C10801} (FlyLoader Class) - http://www.flyword.com/loaderword_win.cab
      O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://www.pcpitstop.com/mhLbl.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
      O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
      O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
      O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
      O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
      O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
      O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
      O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
      O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
      O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
      O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
      O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
      O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
      O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
      O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
      O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
      O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
      O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
      O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
      O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6253\SAService.exe
      O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
      O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
      O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

      --
      End of file - 14114 bytes
      VerizonServicepoint.exe < What is this for? It is a known memory hog.

      Download and run Folder Size. See if you find what is taking up space.

      Download and run StartUpLite. Get rid of unnecessary startups.

      The reason I mentioned McAfee is because security suites will slow most computers down. A mix of free solutions can drastically improve performance, not always but more often than not.

      3886.

      Solve : HiJackThisLog , Take a look please.?

      Answer»

      Ok , im pretty sure i have a bad infection on my computer , IVE scanned with avg 8.0 and im very new to the new 8.0 version . it was warning the addware rather than wipeing it from my computer :S . Im pretty sure i have a bad vundo infection as well , as 8.0 was picking up vundo . Ive tried vundofix but it didnt pick anything up . Im getting a loads and loads of system hang on start up and on general use of the computer .
      Im going to do a scan in safe mode in a bit . See what you think guys cheers.

      Formatting isnt a option as i have world of warcraft installed on here , and it would take a day to re-patch and install . pplus around 20 other games.

      cheers for looking.













      Logfile of Trend Micro HIJACKTHIS v2.0.2
      Scan saved at 10:38:09, on 13/04/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\PnkBstrA.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\PROGRA~1\AVG\AVG8\avgam.exe
      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
      C:\PROGRA~1\AVG\AVG8\avgnsx.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\WINDOWS\system32\ctfmon.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\Program Files\Xfire\xfire.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\Program Files\AVG\AVG8\avgtray.exe
      C:\PROGRA~1\Mozilla Firefox\firefox.exe
      C:\Documents and Settings\Tony\Desktop\HiJackThis.exe

      R0 - HKCU\Software\MICROSOFT\Internet Explorer\Main,Start Page = http://www.tiscali.co.uk/broadband
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Startup Manager] "C:\Program Files\Advanced System Optimizer\startUp manager.exe"
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O17 - HKLM\System\CCS\Services\Tcpip\..\{89C5B8C2-A212-4C82-B6EF-2A17E38C1088}: NameServer = 212.139.132.9 212.139.132.8
      O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
      O20 - AppInit_DLLs: avgrsstx.dll
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
      O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

      --
      End of file - 5194 bytes
      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 14:57:22, on 13/04/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Safe mode

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
      C:\Documents and Settings\Tony\Desktop\hijackthis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - Default URLSearchHook is missing
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
      O4 - HKCU\..\RunOnce: [NeroHomeFirstStart] "C:\Program Files\Common Files\Nero\Lib\NMFirstStart.exe"
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
      O20 - AppInit_DLLs: avgrsstx.dll
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
      O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
      O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

      --
      End of file - 4669 bytes



      SAFE MODE LOG ABOVEFollow These Steps
      I mean look at this .... everytime i scan it comes up with what it has healed , and what is has deleted and what it has warned :S.



      All that right there , it just wouldnt clear it ...... That's why, you need to follow with other steps from patio's link.DR web seems to be working .

      Follow ALL the steps...

      3887.

      Solve : PLEASE HELP trojandownloader.xs and god knows what else?

      Answer»

      I have run ccleaner, and super anti spyware attached is a copy of text from super anti spyware:
      SUPERAntiSpyware Scan Log
      http://www.superantispyware.com

      Generated 04/13/2008 at 02:32 PM

      Application Version : 4.0.1154

      Core Rules Database Version : 3437
      Trace Rules Database Version: 1429

      Scan type : CUSTOM Scan
      Total Scan Time : 00:45:05

      Memory ITEMS SCANNED : 461
      Memory threats detected : 5
      Registry items scanned : 5597
      Registry threats detected : 54
      File items scanned : 57860
      File threats detected : 125

      Trojan.Vundo-Variant/F
      C:\WINDOWS\SYSTEM32\EFCBQNNO.DLL
      C:\WINDOWS\SYSTEM32\EFCBQNNO.DLL
      Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\efcBqnnO

      Trojan.Net-MGS/NMC
      C:\WINDOWS\MGSVFLKW.DLL
      C:\WINDOWS\MGSVFLKW.DLL
      HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad#mgsvflkw [ {874F94C3-AA99-4591-B60A-59A429FBAC5A} ]

      Trojan.Net-QDN/NMC
      C:\WINDOWS\QDNKEWFA.DLL
      C:\WINDOWS\QDNKEWFA.DLL
      HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad#qdnkewfa [ {755E45D1-A211-4938-A0A9-F6475DF9F95A} ]

      Trojan.Unclassified/Multi-Dropper (Packed)
      C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\DGNUTWPG\DMROVONI.EXE
      [oitSrSpcjn] C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\DGNUTWPG\DMROVONI.EXE
      C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\DGNUTWPG\DMROVONI.EXE
      C:\DOCUMENTS AND SETTINGS\DELA FAMILY\LOCAL SETTINGS\TEMP\EXPLOR~1.EXE.BAK

      Trojan.Unclassified/Multi-Dropper
      C:\WINDOWS\SYSTEM32\LWJGBIZU.EXE
      C:\WINDOWS\SYSTEM32\LWJGBIZU.EXE
      [gmphffdh] C:\WINDOWS\SYSTEM32\LWJGBIZU.EXE

      Adware.Vundo Variant
      HKLM\Software\Classes\CLSID\{B82F29E4-8368-4B14-9C00-5138C0D94034}
      HKCR\CLSID\{B82F29E4-8368-4B14-9C00-5138C0D94034}
      HKCR\CLSID\{B82F29E4-8368-4B14-9C00-5138C0D94034}\InprocServer32
      HKCR\CLSID\{B82F29E4-8368-4B14-9C00-5138C0D94034}\InprocServer32#ThreadingModel
      HKLM\Software\Classes\CLSID\{D212F823-17B0-470A-832F-86D3B30EE0D1}
      HKCR\CLSID\{D212F823-17B0-470A-832F-86D3B30EE0D1}
      HKCR\CLSID\{D212F823-17B0-470A-832F-86D3B30EE0D1}
      HKCR\CLSID\{D212F823-17B0-470A-832F-86D3B30EE0D1}\InprocServer32
      HKCR\CLSID\{D212F823-17B0-470A-832F-86D3B30EE0D1}\InprocServer32#ThreadingModel
      HKCR\CLSID\{D212F823-17B0-470A-832F-86D3B30EE0D1}\ProgID
      HKCR\CLSID\{D212F823-17B0-470A-832F-86D3B30EE0D1}\Programmable
      HKCR\CLSID\{D212F823-17B0-470A-832F-86D3B30EE0D1}\TypeLib
      HKCR\CLSID\{D212F823-17B0-470A-832F-86D3B30EE0D1}\VersionIndependentProgID
      C:\WINDOWS\VNBPTXLF.DLL
      HKLM\Software\Classes\CLSID\{DF69FC15-5D77-4679-9C27-FCD90846460F}
      HKCR\CLSID\{DF69FC15-5D77-4679-9C27-FCD90846460F}
      HKCR\CLSID\{DF69FC15-5D77-4679-9C27-FCD90846460F}
      HKCR\CLSID\{DF69FC15-5D77-4679-9C27-FCD90846460F}\InprocServer32
      HKCR\CLSID\{DF69FC15-5D77-4679-9C27-FCD90846460F}\InprocServer32#ThreadingModel
      HKCR\CLSID\{DF69FC15-5D77-4679-9C27-FCD90846460F}\ProgID
      HKCR\CLSID\{DF69FC15-5D77-4679-9C27-FCD90846460F}\Programmable
      HKCR\CLSID\{DF69FC15-5D77-4679-9C27-FCD90846460F}\TypeLib
      HKCR\CLSID\{DF69FC15-5D77-4679-9C27-FCD90846460F}\VersionIndependentProgID
      C:\WINDOWS\TEMLXOPQQWM.DLL
      HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B82F29E4-8368-4B14-9C00-5138C0D94034}
      HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DF69FC15-5D77-4679-9C27-FCD90846460F}
      HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{B82F29E4-8368-4B14-9C00-5138C0D94034}
      HKLM\Software\Microsoft\Internet Explorer\Toolbar#{D212F823-17B0-470A-832F-86D3B30EE0D1}
      HKCR\vnbptxlf.1
      HKCR\vnbptxlf
      HKCR\TypeLib\{E209E7D8-8D9C-4C25-9EF2-BF7B2CC48A03}
      HKCR\TypeLib\{E209E7D8-8D9C-4C25-9EF2-BF7B2CC48A03}\1.0
      HKCR\TypeLib\{E209E7D8-8D9C-4C25-9EF2-BF7B2CC48A03}\1.0\0
      HKCR\TypeLib\{E209E7D8-8D9C-4C25-9EF2-BF7B2CC48A03}\1.0\0\win32
      HKCR\TypeLib\{E209E7D8-8D9C-4C25-9EF2-BF7B2CC48A03}\1.0\FLAGS
      HKCR\TypeLib\{E209E7D8-8D9C-4C25-9EF2-BF7B2CC48A03}\1.0\HELPDIR
      HKCR\CLSID\{B82F29E4-8368-4B14-9C00-5138C0D94034}

      Unclassified.Unknown Origin
      HKLM\Software\Classes\CLSID\{CCB3638E-35AB-45B3-A96F-8D45295CA9E2}
      HKCR\CLSID\{CCB3638E-35AB-45B3-A96F-8D45295CA9E2}
      HKCR\CLSID\{CCB3638E-35AB-45B3-A96F-8D45295CA9E2}
      HKCR\CLSID\{CCB3638E-35AB-45B3-A96F-8D45295CA9E2}#AppID
      HKCR\CLSID\{CCB3638E-35AB-45B3-A96F-8D45295CA9E2}\InprocServer32
      HKCR\CLSID\{CCB3638E-35AB-45B3-A96F-8D45295CA9E2}\InprocServer32#ThreadingModel
      HKCR\CLSID\{CCB3638E-35AB-45B3-A96F-8D45295CA9E2}\ProgID
      HKCR\CLSID\{CCB3638E-35AB-45B3-A96F-8D45295CA9E2}\Programmable
      HKCR\CLSID\{CCB3638E-35AB-45B3-A96F-8D45295CA9E2}\TypeLib
      HKCR\CLSID\{CCB3638E-35AB-45B3-A96F-8D45295CA9E2}\VersionIndependentProgID
      C:\PROGRAM FILES\HOOPAA\CHOOZTRACK.DLL
      HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CCB3638E-35AB-45B3-A96F-8D45295CA9E2}

      Adware.Tracking Cookie
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\dela_family[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][5].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][4].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected]amateurporn[2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][4].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][11].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][6].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][9].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][5].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][8].txt
      C:\Documents and Settings\Dela Family\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt

      Trojan.Net-MSV/VPS
      HKCR\MSVPS.MSVPSApp
      HKCR\MSVPS.MSVPSApp\CLSID
      HKCR\MSVPS.MSVPSApp\CurVer

      Desktop Hijacker.AboutYourPrivacy
      C:\Documents and Settings\Dela Family\Favorites\Error Cleaner.url
      C:\Documents and Settings\Dela Family\Favorites\Privacy Protector.url
      C:\Documents and Settings\Dela Family\Favorites\Spyware&Malware Protection.url

      BearShare File Sharing Client
      C:\PROGRAM FILES\BEARSHARE APPLICATIONS\BEARSHARE\BEARSHARE.EXE
      C:\SYSTEM VOLUME INFORMATION\_RESTORE{1E89B178-81A0-4E8A-893A-5F93B20F80EE}\RP456\A0265805.LNK

      Malware.VirusBurster-Install
      C:\SYSTEM VOLUME INFORMATION\_RESTORE{1E89B178-81A0-4E8A-893A-5F93B20F80EE}\RP433\A0231723.EXE

      Adware.Vundo-Variant/Small-A
      C:\SYSTEM VOLUME INFORMATION\_RESTORE{1E89B178-81A0-4E8A-893A-5F93B20F80EE}\RP509\A0330449.DLL

      Adware.Vundo-Variant
      C:\SYSTEM VOLUME INFORMATION\_RESTORE{1E89B178-81A0-4E8A-893A-5F93B20F80EE}\RP509\A0330457.DLL

      Adware.Vundo Variant/Rel
      C:\WINDOWS\SYSTEM32\MCRH.TMP
      1, Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

      * Double-click mbam-setup.exe and follow the prompts to install the program.
      * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
      * If an update is found, it will download and install the latest version.
      * Once the program has loaded, select Perform FULL scan, then click Scan.
      * When the scan is complete, click OK, then Show Results to view the results.
      * Be sure that everything is checked, and click Remove Selected.
      * When completed, a log will open in Notepad.
      * Post the log back here.

      The log can also be found here:
      C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
      Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

      RESTART COMPUTER!

      2. Download HijackThis:
      http://www.snapfiles.com/get/hijackthis.html
      Post HijackThis log.

      3888.

      Solve : Why Anti-Hacking Software Is A Growing Need Of Todays Bussiness World??

      Answer»

      Do you all know that orginally "hacker" means a very talented programmer,who is gifted to access various systems.This word has a positive aspect if we look real meaning of the word but now-a -days it has negative implicatons.Why this has happened?A word with positive meaning is now counted in the list of negative words.Why so?

      Answer to these question is the NEED and HUMAN BRAIN.The need and craze of becoming RICH and FAMOUS is the root cause of diverting such talented programmers towards such evil paths to earn fast money.These hackers are indeed a very talented brains if used in correct way can help world to solve various queries of nature.For example,We could have STOPPED the loss done by Tsunami.These Hackers have given Insomnias to various Banking Systems and Big Bussiness personalities.Normal thieves work and enter from outside.They can be caught and sighted by physical
      means but Hackers are the person who sitting in one corner of the world can bankrupt an account of a person having an account in the bank at the other end of the world without actually visiting the place.No security guys can stop them.

      Yes these are the modern trends of thieves which is emerging now-a-days.This much stuff must be known to many readers but How to protect our bussiness at the basic level from hacking must be a issue for many?I have shared a small piece of information in this post have a look at it.
      Mainly hackers first target the points like-

      *Low or poorly configured Web Servers
      *Old and poorly maintained softwares
      *Use of poor or default passwords
      These are the parts where we never give much heed but these things leads an open doors for Hackers.Now A Days Cell phones and ATMs and Credit Cards too are hacked.

      These all THREATS has increased the need of Anti Hacking Softwares for various systems in banking sectors as well as bussiness worlds.

      Tips:

      *ALWAYS while giving passwords use Un-Guessable Words and never use dictionary words.
      *Always try for alpha-numeric passwords.
      *Scan your system for spyware and adware with some excellent spyware programmes available now a days in markets.
      *Check for worms which can be SENT through EMAILS and IRC (Internet Relay Chat)
      *There are some programmes like keyword trackers which do not destroy data but keeps track of each and every new keyword use and send it back to owner of programme.Trojan is one such programme and are counted in viruses so check for viruses before loading any stuff send to you through attached files via Emails.

      3889.

      Solve : Administrator has disabled Task Manager...I'm the Administrator!!?

      Answer»

      You're very WELCOME, and YES, fix WHATEVER SAS FOUND.

      3890.

      Solve : Adware/Spyware Virus Help?

      Answer»

      Hi all,
      Today i was infect with one of these viruses and not sure where to start to fix it.
      It has taken away my desk top screen picture and it has a message STATING i have been infected.
      It also has a message to click to scan for the virus, but then it starts to look scary, so i just
      shut down the computer.
      What to do now, go to the store and TRY to install something to fix it, or try to back up files to a cd from
      another computer?

      By the way i have a xternal backup drive, has it been infected also? how would i know?

      PLESE help
      Thank YouGo through the steps here and post the required logs. One of our malware experts will be able to help you then.Never mine,
      this is a terrible forum.LOL!
      I guess he didn't actually want to do any work himself in order to get rid of his infection.Maybe it's better, he's gone...LOL

      3891.

      Solve : help me clear this up.?

      Answer»

      im cleaning my sisters computer for her and ive ran SuperAntiSpyware and Malwarebytes Anti-Malware and got rid of some adware and trojans but i'm not a genius so thats where you come in.
      alot of stuff opens at startup and theres probably more viruses.
      basically im just trying to get the performance up so she can take some online courses with no trouble so please help.

      anything i can do please let me know.

      thanks =]please?
      =/Go to Run --> type msconfig; go to startup tab and uncheck all tabs (or just the ones you don't want, make sure not to disable windows programs).Print these INSTRUCTIONS out.

      1. Download SUPERAntiSpyware Free for Home Users:
      http://www.superantispyware.com/

      * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
      * An icon will be created on your desktop. Double-click that icon to launch the program.
      * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
      * Close SUPERAntiSpyware.

      Restart computer in Safe Mode.
      To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

      * Open SUPERAntiSpyware.
      * Under "Configuration and Preferences", click the Preferences button.
      * Click the Scanning Control tab.
      * Under Scanner Options make sure the following are checked (leave all others unchecked):
      o Close browsers before scanning.
      o Scan for tracking cookies.
      o Terminate MEMORY threats before quarantining.
      * Click the "Close" button to leave the control center screen.
      * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
      * On the left, make sure you check C:\FIXED Drive.
      * On the right, under "Complete Scan", choose Perform Complete Scan.
      * Click "Next" to start the scan. Please be patient while it scans your computer.
      * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
      * Make sure everything has a checkmark next to it and click "Next".
      * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
      * If asked if you want to reboot, click "Yes".
      * To retrieve the removal information after reboot, launch SUPERAntispyware again.
      o Click Preferences, then click the Statistics/Logs tab.
      o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
      o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
      o Please copy and paste the Scan Log results in your next reply.
      * Click Close to exit the program.
      Post SUPERAntiSpyware log.

      RESTART COMPUTER!

      2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

      * Double-click mbam-setup.exe and follow the prompts to install the program.
      * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
      * If an update is found, it will download and install the latest VERSION.
      * Once the program has loaded, select Perform full scan, then click Scan.
      * When the scan is complete, click OK, then Show Results to view the results.
      * Be sure that everything is checked, and click Remove Selected.
      * When completed, a log will open in Notepad.
      * Post the log back here.

      The log can ALSO be found here:
      C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
      Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

      RESTART COMPUTER!

      3. Download HijackThis:
      http://www.snapfiles.com/get/hijackthis.html
      Post HijackThis log.Quote

      Go to Run --> type msconfig; go to startup tab and uncheck all tabs (or just the ones you don't want, make sure not to disable windows programs).
      Disregard.
      3892.

      Solve : i don't know what to do..?

      Answer»

      please HELP me about my problem. the problem is that every time i start my laptap, there is an error. the error is : error loading C:\\windows\system32\rtaicxxe.dll and the specified module could not be found.. i have search the net on how to resolve this problem but it never shows how to fix.. can ANYONE help me? thnxx....Quote from: ran6 on April 16, 2008, 03:15:18 PM

      my laptap



      Does it dispense tummy custard?

      When did you last run a virus check?

      Neither do I. Need more information. See here for guidance.

      Specifically interested in:
      o Make and model number of computer (if brand name)
      o Operating system (and service pack level)
      o Does the error prevent you from loading and using the operating system?
      o What changes were made (hardware or SOFTWARE) before error occurred, if any?
      o What anti-virus software and is it up to date?
      o What other security software and do you keep it up to date.
      3893.

      Solve : annoying virus?

      Answer»

      i have a a virus i have never heard of before it created a file on my in my comps c drive called "1" and filled it with thousands upon thousands of 1 kb files and a few 2 gig files well more or less it took up all my remaining disk space i have successfully solved the space problem by deleting the files inside it but i cant delete the folder as something else is using it and i cant locate an exe that might be doing it nvm i followed steps in the waht to do before asking for help and the programs fixed it apparently i was able to delete the file completely
      thanks for helpPrint these instructions out.

      1. Download SUPERAntiSpyware Free for Home Users:
      http://www.superantispyware.com/

      * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
      * An icon will be created on your desktop. Double-click that icon to launch the program.
      * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
      * Close SUPERAntiSpyware.

      Restart computer in Safe Mode.
      To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

      * Open SUPERAntiSpyware.
      * Under "Configuration and Preferences", click the Preferences button.
      * Click the Scanning Control tab.
      * Under Scanner Options make sure the following are checked (leave all others unchecked):
      o Close browsers before scanning.
      o Scan for tracking cookies.
      o Terminate memory threats before quarantining.
      * Click the "Close" button to leave the control center screen.
      * Back on the main screen, under "Scan for Harmful SOFTWARE" click Scan your computer.
      * On the left, make sure you check C:\Fixed Drive.
      * On the right, under "Complete Scan", choose PERFORM Complete Scan.
      * Click "Next" to start the scan. Please be patient while it scans your computer.
      * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
      * Make sure everything has a checkmark next to it and click "Next".
      * A NOTIFICATION will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
      * If asked if you want to reboot, click "Yes".
      * To retrieve the removal information after reboot, launch SUPERAntispyware again.
      o Click Preferences, then click the Statistics/Logs tab.
      o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
      o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
      o Please copy and paste the Scan Log results in your next reply.
      * Click Close to exit the program.
      POST SUPERAntiSpyware log.

      RESTART COMPUTER!

      2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

      * Double-click mbam-setup.exe and follow the prompts to install the program.
      * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
      * If an update is found, it will download and install the latest version.
      * Once the program has loaded, select Perform full scan, then click Scan.
      * When the scan is complete, click OK, then SHOW Results to view the results.
      * Be sure that everything is checked, and click Remove Selected.
      * When completed, a log will open in Notepad.
      * Post the log back here.

      The log can also be found here:
      C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
      Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

      RESTART COMPUTER!

      3. Download HijackThis:
      http://www.snapfiles.com/get/hijackthis.html
      Post HijackThis log.

      3894.

      Solve : Just ran Dr.Web and got this?

      Answer»

      Just ran Dr.Web and got this message below. I have the option to move it and not cure it. What should i do.

      C:\System Volume Information\_restore{52667C67-2164-4AFC-856E-1D2B2741FC9F}\RP602\A0261978.dll

      infected with Trojan.Inject.origin and cannot be cured.Print these instructions out.

      1. Download SUPERAntiSpyware Free for Home Users:
      http://www.superantispyware.com/

      * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
      * An ICON will be created on your desktop. Double-click that icon to launch the program.
      * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for UPDATES". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
      * Close SUPERAntiSpyware.

      Restart computer in Safe Mode.
      To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

      * OPEN SUPERAntiSpyware.
      * Under "Configuration and Preferences", click the Preferences BUTTON.
      * Click the Scanning Control tab.
      * Under Scanner Options make sure the following are checked (leave all others unchecked):
      o Close browsers before scanning.
      o Scan for tracking cookies.
      o Terminate memory threats before quarantining.
      * Click the "Close" button to leave the control center screen.
      * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
      * On the left, make sure you check C:\Fixed Drive.
      * On the right, under "Complete Scan", choose Perform Complete Scan.
      * Click "Next" to start the scan. Please be patient while it scans your computer.
      * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
      * Make sure everything has a checkmark next to it and click "Next".
      * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
      * If asked if you want to reboot, click "Yes".
      * To retrieve the removal information after reboot, launch SUPERAntispyware again.
      o Click Preferences, then click the Statistics/Logs tab.
      o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
      o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
      o Please copy and paste the Scan Log results in your next reply.
      * Click Close to exit the program.
      Post SUPERAntiSpyware log.

      RESTART COMPUTER!

      2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

      * Double-click mbam-setup.exe and follow the prompts to install the program.
      * At the END, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
      * If an update is found, it will download and install the latest version.
      * Once the program has loaded, select Perform full scan, then click Scan.
      * When the scan is complete, click OK, then Show Results to view the results.
      * Be sure that everything is checked, and click Remove Selected.
      * When completed, a log will open in Notepad.
      * Post the log back here.

      The log can also be found here:
      C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
      Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

      RESTART COMPUTER!

      3. Download HijackThis:
      http://www.snapfiles.com/get/hijackthis.html
      Post HijackThis log.

      3895.

      Solve : Trogan horse?

      Answer»

      Hi
      My computer has just come up with you have a trojan horse!
      C:/WINDOWS/SYSTEMS32/DRIVERS/KMXAGENT.SYS
      Is this what is affecting my computer?
      I hope somebody can help me! this is really doing my head in.
      THANKS.could be try to remove with avg free anti spywearHere's the superanti spyware log
      SUPERAntiSpyware Scan Log
      http://www.superantispyware.com

      Generated 04/15/2008 at 11:05 PM

      Application Version : 4.0.1154

      Core Rules Database Version : 3438
      Trace Rules Database Version: 1430

      Scan type : Complete Scan
      Total Scan Time : 01:02:44

      Memory items SCANNED : 600
      Memory threats detected : 0
      Registry items scanned : 7330
      Registry threats detected : 0
      File items scanned : 92063
      File threats detected : 21

      Adware.Tracking Cookie
      C:\Documents and Settings\steven westwood\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\steven westwood\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\steven westwood\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\steven westwood\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\steven westwood\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\steven westwood\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\steven westwood\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\steven westwood\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\steven westwood\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\steven westwood\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\steven westwood\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\steven westwood\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\steven westwood\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\steven westwood\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\steven westwood\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\steven westwood\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\steven westwood\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\steven westwood\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\steven westwood\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\steven westwood\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\steven westwood\Cookies\[emailprotected][1].txt
      Do you use CA?

      The signature of this file is verified by windows
      This means that the publisher CA of this software signed the file kmxagent.sys with a CERTIFICATE from a TRUSTED windows source.Yes! i use CA.you MIGHT want to get the a-squared free program and double check your SYSTEM. It's fee and it is updated every day (you have to update manually though)

      3896.

      Solve : Trojan Horses and Spyware!?

      Answer»

      Hey, so I have trojan HORSES, spyware and hijackers taking over my computer. Now I downloaded Spysweeper to it and it really didn't do jack.

      So right now, the only way I can do anything on it is if I work in Safe Mode.
      Will all of these directions you all are giving work on a pc in safe mode?

      Also can someone tell me in SIMPLE terms what to do to get rid of these things? And can the virus still infect your pc if the power is off?

      Please HELP! And thanks so much!!!

      What happens when you try to boot into Normal Mode?When I try to boot in normal mode the computer just restarts. It KEEP restarting. You think you can explain to me in simple terms how to fix this. Thanks so much for RESPONDING. Download HijackThis:
      http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
      Click on Download HijackThis Installer
      Post HijackTHis log.

      3897.

      Solve : Help used Avast! now everything gone!!?

      Answer»

      Please help someone. So I downloaded Avast to get rid of the viruses now when I reboot, I get nothing on my MAIN screen. What should I do? Please help. This should all be KEPT in one thread...you now have 3 going.
      See the replies in your other one.
      Topic CLOSED.

      3898.

      Solve : Virus or trojan or spartan or something?

      Answer»

      Hi,

      I've been away so I wasn't able to try your suggestion 'till just now.

      I ran the Vundofix then added the file C:\WINDOWS\system32\hmxmnqlq.exe. Vundofix rebooted the MACHINE then I ran Hijackthis again.

      The current Hijackthis log file still shows that file.

      Crap.

      David

      Lets try this. DOWNLOAD Autoruns and search for the related entry and then delete it.

      • Create a new folder on your hard drive called AutoRuns (C:\AutoRuns) and extract (unzip) the file there. (click HERE if your not sure how to do this.)
      • Open the folder and double-click on autoruns.exe to launch it.
      • Please be patient as it scans and populates the entries.
      • When done scanning, it will say Ready at the bottom.
      • Scroll through the list and look for the startup entry related to the file hmxmnqlq.exe
      • Right click on the entry and choose delete
      • Reboot your computer and see if it returns.
      I ran Autoruns as you described then rebooted and hmxmnqlq.exe was gone!

      I also rebooted and logged on for each of my separate user accounts, checking for the existence of hmxmnqlq.exe in each one. It's not there in any of them.

      I've attached a new log from Hijackthis for you to verify.

      Is my computer now clean?

      David

      [recovering space - attachment deleted by admin]evilfantasy,

      I GOT your message and realized that I sent you the wrong Hijackthis log.

      The log attached to this message is the one that I created after running Autoruns and rebooting, etc. This one does not have evidence of hmxmnqlq.exe (I think).

      David

      [recovering space - attachment deleted by admin]Hello. Sorry it has taken so long to get back to you. Looks like it is gone indeed.

      Let's clear out the programs we've been using to clean up your computer, they are not suitable for
      general malware removal and could cause damage if launched accidentally and will help secure the work you have done.
      .
      • Click START then RUN
      • Now type Combofix /u in the runbox
      • Make sure there's a space between Combofix and /u
      • Then hit Enter.
      .
      .
      The above procedure will:
      • Delete:
        • ComboFix and its associated files and folders.
        • VundoFix backups, if present
        • The C:\Deckard folder, if present
        • The C:_OtMoveIt folder, if present
        • Reset the clock settings.
        • Hide file extensions, if required.
        • Hide System/Hidden files, if required.
        • Set a new, clean Restore Point.
        .
        Download OTMoveIt2 by OldTimer OTMoveIt2.exe and place it on your desktop. (unless you already have it installed)

        1. Double click OTMoveIt2.exe to launch it.
        Vista users right click and choose Run As Administrator
        2. Click on the CleanUp! button.
        3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
        4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
        5. Once complete exit out of OTMoveIt2

        Set a New Restore Point to prevent possible reinfection from an old one
        Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
        • Go to Start > Programs > Accessories > System Tools and click System Restore
        • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
        • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
        • Next go to Start > Run and type Cleanmgr
        • Click OK
        • Click the More OPTIONS Tab.
        • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
        .
        Use the Secunia Software Inspector to check for out of date software.
        • Click Start Now
        • Check the box next to Enable thorough system inspection.
        • Click Start
        • Allow the scan to finish and scroll down to see if any updates are needed.
        • Update anything listed.
        .
        Here are some great tools to help you keep from getting infected again.

        To prevent unknown applications from being installed on your computer install WinPatrol 2007

        Another THING I would suggest installing SiteAdvisor. SiteAdvisor rates sites on business practices and spam.

        Spybot Search & Destroy - A safe and effective spyware scanner.
        * Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

        AVG Anti-Spyware Free Edition - Very reliable with a high detection rate.
        * AVG Anti-Spyware User Manual

        SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
        * Using SpywareBlaster to protect your computer from Spyware and Malware

        Comodo BOClean - Stops trojans and many more malicious attacks.

        Use a Firewall - It can not be stressed enough how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over.
        * Click here for a list of free firewalls.
        * Why would I consider a third party firewall?
        * Understanding and Using Firewalls

        UPDATE!!! UPDATE!!! UPDATE!!! - If you do not have automatic updates enabled then visit http://www.windowsupdate.com[/b]]http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer.
        * Help with Windows updates

        Learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place?

        Let us know if anything else comes up.
        3899.

        Solve : Is there a fake Mcafee icon??

        Answer»

        I started my computer today and now there is an icon next to the time, it will not let me left or right click it but when i point the mouse on it, it says mcafee personal firewall. I do not use mcafee, never have, and did not download this. I went to start-control panel-add/remove programs and there is no mcafee anything there. Can this be a fake icon or some virus?

        Sorry I do not know much about computers. This is my personal computer. It has Windows XP, internet explorer, etc. I have not downloaded anything new, do not download music/videos, etc.

        Any help. THANK you.Print these instructions out.

        1. Download SUPERAntiSpyware Free for Home Users:
        http://www.superantispyware.com/

        * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
        * An icon will be created on your desktop. Double-click that icon to launch the program.
        * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
        * Close SUPERAntiSpyware.

        Restart computer in Safe MODE.
        To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

        * Open SUPERAntiSpyware.
        * Under "Configuration and Preferences", click the Preferences button.
        * Click the Scanning Control tab.
        * Under Scanner Options make sure the following are checked (leave all others unchecked):
        o Close browsers before scanning.
        o Scan for tracking cookies.
        o Terminate memory threats before quarantining.
        * Click the "Close" button to leave the control center screen.
        * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
        * On the left, make sure you check C:\Fixed Drive.
        * On the right, under "Complete Scan", choose Perform Complete Scan.
        * Click "Next" to start the scan. Please be patient while it scans your computer.
        * After the scan is complete, a Scan SUMMARY box will appear with potentially harmful items that were detected. Click "OK".
        * Make sure everything has a checkmark next to it and click "Next".
        * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
        * If asked if you want to reboot, click "Yes".
        * To retrieve the removal information after reboot, launch SUPERAntispyware again.
        o Click Preferences, then click the Statistics/Logs tab.
        o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
        o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
        o Please copy and paste the Scan Log results in your next reply.
        * Click Close to exit the program.
        Post SUPERAntiSpyware log.

        RESTART COMPUTER!

        2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

        * Double-click mbam-setup.exe and follow the prompts to install the program.
        * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
        * If an update is found, it will download and install the latest VERSION.
        * Once the program has loaded, select Perform full scan, then click Scan.
        * When the scan is complete, click OK, then Show Results to view the results.
        * Be sure that everything is checked, and click Remove Selected.
        * When completed, a log will open in NOTEPAD.
        * Post the log back here.

        The log can also be found here:
        C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
        Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

        RESTART COMPUTER!

        3. Download HijackThis:
        http://www.snapfiles.com/get/hijackthis.html
        Post HijackThis log.

        3900.

        Solve : Want to Uninstall Norton AV 2007?

        Answer»
        After using Norton AV for sometime, now, I have decided to remove it and install Avast. What is the proper method to uninstall this so no future problems will arise. Thanks. Quote
        I have decided to remove it
        Congratulations!!

        The best way to get rid of it, is to use this tool: http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2005033108162039The Longer but Fail-Safe Approach.Thanks Broni and Patio. Uh, wait, Broni's post has me confused: What's so bad about Norton?

        Edit in reply to bottom post: Heh, enough said.What's good about Norton?I prefer to refer to it as Symantec... Peter Norton was an old time hero in my mind.
        I believe if he had to do it all over again he still may have sold out but not put his name on it.

        The above is merely opinion and in no way constitutes a statement of fact as interpreted in a legal sense.only thing good with Norton is it's name?

        AVG or AVAST beats norton since you can get free version of their programs with the automatic scanning and UPDATING (As you probably already knew)

        Commodo firewall, AVG or AVAST, Microsoft Windows Defender and EITHER spybot or A-squared free or Ad-Aware on hand ---> that is my ARSENAL of computer protection. Enough?
        My reason to uninstall NortonAV 2007, probably is simplistic.

        1. Impossible to contact anyone at Symantec for HELP. Seeking help thru
        their troubleshooting programs is futile.

        2. My problem is: I cannot run their Updates in "Live Updates" When I
        run the Updates, now for "2 months" I get nothing but Errors, No. 1812
        and 1806.

        3. Following Norton's procedure: HOT FIX, i GET nothing, only message I
        get is "USE LIVE UPDATES AGAIN IN TWO WEEKS" @%$#&

        4. This is what I pay for! Anyone have anything on this?No. We don't use it