<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>DAL Computer Help - Spyware, Adware, Viruses and HijackThis Logs</title>
		<link>http://www.d-a-l.com/help/</link>
		<description />
		<language>en</language>
		<lastBuildDate>Fri, 20 Nov 2009 21:53:28 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://www.d-a-l.com/help/images/styles/dal/misc/rss.jpg</url>
			<title>DAL Computer Help - Spyware, Adware, Viruses and HijackThis Logs</title>
			<link>http://www.d-a-l.com/help/</link>
		</image>
		<item>
			<title>Upset and confused</title>
			<link>http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67181-upset-confused.html</link>
			<pubDate>Fri, 20 Nov 2009 18:08:50 GMT</pubDate>
			<description>Hello over the last day I have been contacted by so many people as I had told them about an iphone that I had brought!! And I feel that someone out there has hacked into my computer. I am on windowsxp and have norton as well. I am not very techincal at all and just simply dont know what to do for...</description>
			<content:encoded><![CDATA[<div> Hello over the last day I have been contacted by so many people as I had told them about an iphone that I had brought!! And I feel that someone out there has hacked into my computer. I am on windowsxp and have norton as well. I am not very techincal at all and just simply dont know what to do for the best at times. I feel like throwing this whole computer and works out the door as I feel so small and upset. how dare these people get away with it and norton are saying its not them but me and my fault. Please help Thank you</div>

]]></content:encoded>
			<category domain="http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/">Spyware, Adware, Viruses and HijackThis Logs</category>
			<dc:creator>amandah</dc:creator>
			<guid isPermaLink="true">http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67181-upset-confused.html</guid>
		</item>
		<item>
			<title>eliminate a virus</title>
			<link>http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67167-eliminate-virus.html</link>
			<pubDate>Thu, 19 Nov 2009 05:38:33 GMT</pubDate>
			<description>how do I remove the following virus from windows XP 
 
Win32/Spy.Ursnif.Avirus</description>
			<content:encoded><![CDATA[<div>how do I remove the following virus from windows XP<br />
<br />
Win32/Spy.Ursnif.Avirus</div>

]]></content:encoded>
			<category domain="http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/">Spyware, Adware, Viruses and HijackThis Logs</category>
			<dc:creator>royalavid</dc:creator>
			<guid isPermaLink="true">http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67167-eliminate-virus.html</guid>
		</item>
		<item>
			<title><![CDATA[[Active] friend let someone who cold called him log onto his PC]]></title>
			<link>http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67163-active-friend-let-someone-who.html</link>
			<pubDate>Wed, 18 Nov 2009 16:21:51 GMT</pubDate>
			<description><![CDATA[Hi, I have a freind, really it wasn't me, who let someone from Online PC Support | Fix all PC problems without hassle (http://www.supportonclick.com) who cold called him convince him they were authorised by Microsoft to help people who were having PC problems. they basically convinced him by making...]]></description>
			<content:encoded><![CDATA[<div>Hi, I have a freind, really it wasn't me, who let someone from <a href="http://www.supportonclick.com" target="_blank">Online PC Support | Fix all PC problems without hassle</a> who cold called him convince him they were authorised by Microsoft to help people who were having PC problems. they basically convinced him by making him look at the event logs that there were problems with his PC, so the daft fool paid them £139 and let them log onto his machine. I don't know what they did or what they installed, but I've restored his PC to a point prior to him letting them on and ran the spybot and an AG scan. The results of the HJS scan are below, can you see anything that might be dodgy. The machine is running OK at the moment, but I wanted to check.<br />
<br />
cheers<br />
Mark<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 16:14:19, on 18/11/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\SOUNDMAN.EXE<br />
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC  2.EXE<br />
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe<br />
C:\WINDOWS\system32\CTHELPER.EXE<br />
C:\Program Files\QuickTime\qttask.exe<br />
C:\Program Files\Microsoft IntelliType Pro\type32.exe<br />
C:\Program Files\Microsoft IntelliPoint\point32.exe<br />
C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe<br />
C:\Program Files\Trust\MI-2550XP OPTICAL MINI MOUSE\Mouse32a.exe<br />
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F  2.EXE<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
C:\Program Files\Jasc Software Inc\After Shot\IXApplet.exe<br />
C:\Program Files\Ulead Systems\Ulead Photo Express 3.0 SE\CalCheck.exe<br />
C:\Program Files\WinZip\WZQKPICK.EXE<br />
C:\WINDOWS\system32\ntvdm.exe<br />
C:\OPLIMIT\ocrawr32.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://g.msn.co.uk/0SEENGB/SAOS01" target="_blank">Bing</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.google.co.uk/" target="_blank">Google</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">Hotmail, News, Sport, Music, Movies, Money, Cars, Shopping, Windows Live from MSN UK</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">Hotmail, News, Sport, Music, Movies, Money, Cars, Shopping, Windows Live from MSN UK</a><br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &quot;C:\Program Files\Outlook Express\msimn.exe&quot;<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1517.0\en-gb\msntb.dll<br />
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br />
O4 - HKLM\..\Run: [CProgramFile0] C:\Program Files\ViaVoice\bin\prtStart.exe 12 01 6 28 2003 &quot;C:\Program Files\ViaVoice\bin\PRT0771432.exe&quot; /splashDelay=3<br />
O4 - HKLM\..\Run: [EPSON Stylus C62 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC  2.EXE /P23 &quot;EPSON Stylus C62 Series&quot; /O6 &quot;USB001&quot; /M &quot;Stylus C62&quot;<br />
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe<br />
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE<br />
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE<br />
O4 - HKLM\..\Run: [Jet Detection] &quot;C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [type32] &quot;C:\Program Files\Microsoft IntelliType Pro\type32.exe&quot;<br />
O4 - HKLM\..\Run: [IntelliPoint] &quot;C:\Program Files\Microsoft IntelliPoint\point32.exe&quot;<br />
O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe<br />
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Trust\MI-2550XP OPTICAL MINI MOUSE\Mouse32a.exe<br />
O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F  2.EXE /P30 &quot;EPSON Stylus Photo R300 Series&quot; /O6 &quot;USB002&quot; /M &quot;Stylus Photo R300&quot;<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKCU\..\Run: [Spamihilator] &quot;C:\Program Files\Spamihilator\spamihilator.exe&quot;<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - Startup: OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE<br />
O4 - Global Startup: Camio Viewer.lnk = C:\Program Files\Jasc Software Inc\After Shot\IXApplet.exe<br />
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br />
O4 - Global Startup: Ulead Photo Express 3.0 SE Calendar Checker.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 3.0 SE\CalCheck.exe<br />
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll<br />
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - <a href="http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-12.cab" target="_blank">http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-12.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1168458565037" target="_blank">http://update.microsoft.com/microsof...?1168458565037</a><br />
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - <a href="http://games-dl.real.com/gameconsole/Bundler/CAB/RealArcadeRdxIE.cab" target="_blank">http://games-dl.real.com/gameconsole...rcadeRdxIE.cab</a><br />
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - <a href="https://www-secure.symantec.com/techsupp/activedata/SymAData.dll" target="_blank">https://www-secure.symantec.com/tech...a/SymAData.dll</a><br />
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - <a href="http://www.adobe.com/products/acrobat/nos/gp.cab" target="_blank">Adobe - Adobe Acrobat: Create PDF file, edit PDF file, convert PDF to word, convert PDF to doc</a><br />
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - <a href="https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab" target="_blank">https://www-secure.symantec.com/tech...ActiveData.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe<br />
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe<br />
<br />
--<br />
End of file - 7922 bytes<br />
<br />
uninstall log<br />
<br />
Acrobat.com<br />
Adobe Acrobat 4.0, 5.0<br />
Adobe AIR<br />
Adobe AIR<br />
Adobe Flash Player 10 ActiveX<br />
Adobe Reader 9.2<br />
AND Route 2004 UK &amp; Ireland<br />
ArcSoft PhotoBase 3<br />
ArcSoft PhotoStudio 5<br />
AudioWriter<br />
Avance AC'97 Audio<br />
AVG Free 9.0<br />
Canon CanoCraft CS-P 3.7<br />
Canon ScanGear Toolbox CS<br />
Digital Camera Driver<br />
DiscJuggler<br />
Dual Mode USB Camera Plus<br />
EPSON CardMonitor<br />
EPSON PhotoQuicker3.2<br />
EPSON PhotoStarter3.1<br />
EPSON Print CD<br />
EPSON PRINT Image Framer Tool2.1<br />
EPSON Printer Software<br />
ESPR300 Reference Guide<br />
ESPR300 Software Guide<br />
ESPR300 Standalone Guide<br />
Family Tree Maker 2005<br />
getPlus(R)_ocx<br />
Gloop!<br />
greenstreet Draw 3.0<br />
greenstreet PhotoFX<br />
greenstreet PowerText3D 2.0<br />
greenstreet Publisher  3.13<br />
greenstreet Utilities<br />
Heat<br />
HijackThis 2.0.2<br />
Hotfix for Windows XP (KB952287)<br />
Hotfix for Windows XP (KB970653-v3)<br />
ImageMixer VCD for FinePix<br />
ImgBurn (Remove Only)<br />
Jasc After Shot<br />
LiveReg (Symantec Corporation)<br />
LiveUpdate 2.5 (Symantec Corporation)<br />
LP Recorder<br />
MAGIX audio cleaning 3.0 deLuxe<br />
Microsoft Internationalized Domain Names Mitigation APIs<br />
Microsoft National Language Support Downlevel APIs<br />
Microsoft Office XP Professional with FrontPage<br />
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053<br />
Microsoft Visual C++ 2005 Redistributable<br />
Microsoft Windows Script Host<br />
MicroStaff WINASPI<br />
MSI MSIDVD<br />
MSN Toolbar<br />
NetShow Tools 3.0<br />
Norton WMI Update<br />
OmniPage SE<br />
Paint Shop Pro 7 Anniversary Edition<br />
PIF DESIGNER2.1<br />
Professor Franklin<br />
QuickTime<br />
Quicktime Browser Plug-In<br />
ScanToWeb<br />
Security Update for CAPICOM (KB931906)<br />
Security Update for CAPICOM (KB931906)<br />
Security Update for Windows Internet Explorer 7 (KB938127)<br />
Security Update for Windows Internet Explorer 7 (KB960714)<br />
Security Update for Windows Internet Explorer 7 (KB961260)<br />
Security Update for Windows Internet Explorer 7 (KB963027)<br />
Security Update for Windows Internet Explorer 7 (KB969897)<br />
Security Update for Windows Internet Explorer 8 (KB969897)<br />
Security Update for Windows Internet Explorer 8 (KB971961)<br />
Security Update for Windows Internet Explorer 8 (KB972260)<br />
Security Update for Windows Internet Explorer 8 (KB974455)<br />
Security Update for Windows Media Player (KB952069)<br />
Security Update for Windows Media Player (KB954155)<br />
Security Update for Windows Media Player (KB968816)<br />
Security Update for Windows Media Player (KB973540)<br />
Security Update for Windows Media Player 9 (KB917734)<br />
Security Update for Windows XP (KB923561)<br />
Security Update for Windows XP (KB938464)<br />
Security Update for Windows XP (KB938464-v2)<br />
Security Update for Windows XP (KB941569)<br />
Security Update for Windows XP (KB946648)<br />
Security Update for Windows XP (KB950760)<br />
Security Update for Windows XP (KB950762)<br />
Security Update for Windows XP (KB950974)<br />
Security Update for Windows XP (KB951066)<br />
Security Update for Windows XP (KB951376)<br />
Security Update for Windows XP (KB951376-v2)<br />
Security Update for Windows XP (KB951698)<br />
Security Update for Windows XP (KB951748)<br />
Security Update for Windows XP (KB952004)<br />
Security Update for Windows XP (KB952954)<br />
Security Update for Windows XP (KB953839)<br />
Security Update for Windows XP (KB954211)<br />
Security Update for Windows XP (KB954459)<br />
Security Update for Windows XP (KB954600)<br />
Security Update for Windows XP (KB955069)<br />
Security Update for Windows XP (KB956391)<br />
Security Update for Windows XP (KB956572)<br />
Security Update for Windows XP (KB956744)<br />
Security Update for Windows XP (KB956802)<br />
Security Update for Windows XP (KB956803)<br />
Security Update for Windows XP (KB956841)<br />
Security Update for Windows XP (KB956844)<br />
Security Update for Windows XP (KB957095)<br />
Security Update for Windows XP (KB957097)<br />
Security Update for Windows XP (KB958644)<br />
Security Update for Windows XP (KB958687)<br />
Security Update for Windows XP (KB958690)<br />
Security Update for Windows XP (KB958869)<br />
Security Update for Windows XP (KB959426)<br />
Security Update for Windows XP (KB960225)<br />
Security Update for Windows XP (KB960715)<br />
Security Update for Windows XP (KB960803)<br />
Security Update for Windows XP (KB960859)<br />
Security Update for Windows XP (KB961371)<br />
Security Update for Windows XP (KB961373)<br />
Security Update for Windows XP (KB961501)<br />
Security Update for Windows XP (KB968537)<br />
Security Update for Windows XP (KB969059)<br />
Security Update for Windows XP (KB969898)<br />
Security Update for Windows XP (KB969947)<br />
Security Update for Windows XP (KB970238)<br />
Security Update for Windows XP (KB971486)<br />
Security Update for Windows XP (KB971557)<br />
Security Update for Windows XP (KB971633)<br />
Security Update for Windows XP (KB971657)<br />
Security Update for Windows XP (KB973346)<br />
Security Update for Windows XP (KB973354)<br />
Security Update for Windows XP (KB973507)<br />
Security Update for Windows XP (KB973525)<br />
Security Update for Windows XP (KB973869)<br />
Security Update for Windows XP (KB974112)<br />
Security Update for Windows XP (KB974571)<br />
Security Update for Windows XP (KB975025)<br />
Security Update for Windows XP (KB975467)<br />
SkyMap Pro 6<br />
Sound Blaster Live!<br />
Spybot - Search &amp; Destroy<br />
Starry Night Backyard 3.1<br />
TRUST MI-2550XP OPTICAL MINI MOUSE<br />
Ulead Photo Explorer 6.0<br />
Ulead Photo Explorer 8.0 SE Basic<br />
Ulead Photo Express 3.0 SE<br />
Ulead VideoStudio version 4.0 SE Basic<br />
Update for Windows Internet Explorer 8 (KB971930)<br />
Update for Windows Internet Explorer 8 (KB976749)<br />
Update for Windows XP (KB951072-v2)<br />
Update for Windows XP (KB951978)<br />
Update for Windows XP (KB955839)<br />
Update for Windows XP (KB967715)<br />
Update for Windows XP (KB968389)<br />
Update for Windows XP (KB973815)<br />
<acronym title="vBulletin">VB</acronym> Runtime<br />
VIA Rhine-Family Fast Ethernet Adapter<br />
Windows Internet Explorer 8<br />
Windows XP Service Pack 3<br />
WinZip<br />
XElemental<br />
Xtras 2</div>

]]></content:encoded>
			<category domain="http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/">Spyware, Adware, Viruses and HijackThis Logs</category>
			<dc:creator>mrh74</dc:creator>
			<guid isPermaLink="true">http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67163-active-friend-let-someone-who.html</guid>
		</item>
		<item>
			<title><![CDATA[[Resolved] Serious problem - please help!!!]]></title>
			<link>http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67146-resolved-serious-problem-please-help.html</link>
			<pubDate>Tue, 17 Nov 2009 01:24:48 GMT</pubDate>
			<description>Just today, something has taken over my system and I cannot even get to your site without rebooting in Safe Mode.  Here is my Hijackthis log.  Please help!!!! 
 
 
AC3File 0.6b 
Adobe AIR 
Adobe AIR 
Adobe Flash Player 10 ActiveX 
Adobe Flash Player 10 Plugin 
Adobe Reader 8.1.2 
Adobe Shockwave...</description>
			<content:encoded><![CDATA[<div>Just today, something has taken over my system and I cannot even get to your site without rebooting in Safe Mode.  Here is my Hijackthis log.  Please help!!!!<br />
<br />
<br />
AC3File 0.6b<br />
Adobe AIR<br />
Adobe AIR<br />
Adobe Flash Player 10 ActiveX<br />
Adobe Flash Player 10 Plugin<br />
Adobe Reader 8.1.2<br />
Adobe Shockwave Player 11<br />
Adobe SVG Viewer 3.0<br />
AMDAway INF<br />
BlackBerry Desktop Software 4.3<br />
BlackBerry Desktop Software 4.3<br />
BlackBerry Media Sync<br />
BlackBerry® Media Sync<br />
Bonjour<br />
Browser Address Error Redirector<br />
Canon G.726 WMP-Decoder<br />
Canon MovieEdit Task for ZoomBrowser EX<br />
Canon RAW Image Task for ZoomBrowser EX<br />
Canon Utilities CameraWindow<br />
Canon Utilities CameraWindow DC<br />
Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX<br />
Canon Utilities MyCamera<br />
Canon Utilities MyCamera DC<br />
Canon Utilities PhotoStitch<br />
Canon Utilities RemoteCapture Task for ZoomBrowser EX<br />
Canon Utilities ZoomBrowser EX<br />
Canon ZoomBrowser EX Memory Card Utility<br />
CCScore<br />
Cheetah DVD Burner<br />
Conexant D850 PCI V.92 Modem<br />
Creative MediaSource<br />
Creative MuVo N200 Media Explorer<br />
Dassault Systemes Software Prerequisites x86<br />
Dell DataSafe Online<br />
Dell Getting Started Guide<br />
Dell Support Center (Support Software)<br />
Digital Line Detect<br />
Dirt Alert<br />
DivX Codec<br />
DivX Converter<br />
DivX Player<br />
DivX Plus DirectShow Filters<br />
DivX Web Player<br />
EPSON Print CD<br />
EPSON Printer Software<br />
EPSON R280 User's Guide<br />
EPSON Web-To-Page<br />
ESSBrwr<br />
ESSCDBK<br />
ESScore<br />
ESSgui<br />
ESSini<br />
ESSPCD<br />
ESSPDock<br />
ESSTOOLS<br />
essvatgt<br />
Free Window Registry Repair<br />
Google Desktop<br />
Google Earth<br />
Google Toolbar for Internet Explorer<br />
Google Toolbar for Internet Explorer<br />
GoToAssist 8.0.0.480<br />
HijackThis 2.0.2<br />
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)<br />
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)<br />
ImageMixer3<br />
Internet Service Offers Launcher<br />
iTunes<br />
Java(TM) 6 Update 10<br />
Java(TM) SE Runtime Environment 6<br />
Kodak EasyShare software<br />
LEGO Digital Designer<br />
McAfee SecurityCenter<br />
Microsoft .NET Framework 3.5 SP1<br />
Microsoft .NET Framework 3.5 SP1<br />
Microsoft Office 2007 Service Pack 2 (SP2)<br />
Microsoft Office 2007 Service Pack 2 (SP2)<br />
Microsoft Office 2007 Service Pack 2 (SP2)<br />
Microsoft Office 2007 Service Pack 2 (SP2)<br />
Microsoft Office 2007 Service Pack 2 (SP2)<br />
Microsoft Office 2007 Service Pack 2 (SP2)<br />
Microsoft Office 2007 Service Pack 2 (SP2)<br />
Microsoft Office 2007 Service Pack 2 (SP2)<br />
Microsoft Office 2007 Service Pack 2 (SP2)<br />
Microsoft Office 2007 Service Pack 2 (SP2)<br />
Microsoft Office 2007 Service Pack 2 (SP2)<br />
Microsoft Office 2007 Service Pack 2 (SP2)<br />
Microsoft Office 2007 Service Pack 2 (SP2)<br />
Microsoft Office 2007 Service Pack 2 (SP2)<br />
Microsoft Office Access MUI (English) 2007<br />
Microsoft Office Access Setup Metadata MUI (English) 2007<br />
Microsoft Office Enterprise 2007<br />
Microsoft Office Enterprise 2007<br />
Microsoft Office Excel MUI (English) 2007<br />
Microsoft Office Groove MUI (English) 2007<br />
Microsoft Office Groove Setup Metadata MUI (English) 2007<br />
Microsoft Office InfoPath MUI (English) 2007<br />
Microsoft Office OneNote MUI (English) 2007<br />
Microsoft Office Outlook MUI (English) 2007<br />
Microsoft Office PowerPoint MUI (English) 2007<br />
Microsoft Office Proof (English) 2007<br />
Microsoft Office Proof (French) 2007<br />
Microsoft Office Proof (Spanish) 2007<br />
Microsoft Office Proofing (English) 2007<br />
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)<br />
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)<br />
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)<br />
Microsoft Office Publisher MUI (English) 2007<br />
Microsoft Office Shared MUI (English) 2007<br />
Microsoft Office Shared Setup Metadata MUI (English) 2007<br />
Microsoft Office Word MUI (English) 2007<br />
Microsoft Silverlight<br />
Microsoft Works<br />
Modem Diagnostic Tool<br />
Mouse Suite for Desktop Computers<br />
Mozilla Firefox (3.5.5)<br />
MSXML 4.0 SP2 (KB936181)<br />
MSXML 4.0 SP2 (KB941833)<br />
MSXML 4.0 SP2 (KB954430)<br />
Music, Photos &amp; Videos Launcher<br />
MuVo Driver<br />
netbrdg<br />
NetWaiting<br />
NVIDIA Drivers<br />
NVIDIA Stereoscopic 3D Driver<br />
NVIDIANetworkDiagnostic<br />
OfotoXMI<br />
OGA Notifier 2.0.0048.0<br />
PCsync<br />
Photosynth 2.0.1403.5<br />
Picasa 3<br />
Product Documentation Launcher<br />
QuickTime<br />
Realtek High Definition Audio Driver<br />
Rhapsody Player Engine<br />
RocketDock 1.3.5<br />
Roxio Creator Audio<br />
Roxio Creator BDAV Plugin<br />
Roxio Creator Copy<br />
Roxio Creator Data<br />
Roxio Creator DE<br />
Roxio Creator Tools<br />
Roxio Express Labeler<br />
Roxio Update Manager<br />
Security Update for 2007 Microsoft Office System (KB969559)<br />
Security Update for 2007 Microsoft Office System (KB973704)<br />
Security Update for Microsoft Office Excel 2007 (KB973593)<br />
Security Update for Microsoft Office Outlook 2007 (KB972363)<br />
Security Update for Microsoft Office PowerPoint 2007 (KB957789)<br />
Security Update for Microsoft Office Publisher 2007 (KB969693)<br />
Security Update for Microsoft Office system 2007 (972581)<br />
Security Update for Microsoft Office system 2007 (KB969613)<br />
Security Update for Microsoft Office system 2007 (KB974234)<br />
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)<br />
SFR<br />
SHASTA<br />
skin0001<br />
SKINXSDK<br />
Sonic Activation Module<br />
Spybot - Search &amp; Destroy<br />
staticcr<br />
Super DX-Ball v1.1<br />
System Requirements Lab<br />
Update for 2007 Microsoft Office System (KB967642)<br />
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)<br />
Update for Microsoft Office 2007 Help for Common Features (KB963673)<br />
Update for Microsoft Office Access 2007 Help (KB963663)<br />
Update for Microsoft Office Excel 2007 Help (KB963678)<br />
Update for Microsoft Office Infopath 2007 Help (KB963662)<br />
Update for Microsoft Office OneNote 2007 Help (KB963670)<br />
Update for Microsoft Office Outlook 2007 Help (KB963677)<br />
Update for Microsoft Office Powerpoint 2007 Help (KB963669)<br />
Update for Microsoft Office Publisher 2007 Help (KB963667)<br />
Update for Microsoft Office Script Editor Help (KB963671)<br />
Update for Microsoft Office Word 2007 (KB974561)<br />
Update for Microsoft Office Word 2007 Help (KB963665)<br />
Update for Outlook 2007 Junk Email Filter (kb975960)<br />
User's Guides<br />
VC80CRTRedist - 8.0.50727.4053<br />
VPRINTOL<br />
VZAccess Manager for RIM<br />
Windows Media Player Firefox Plugin<br />
WinRAR archiver<br />
WIRELESS<br />
<br />
<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 8:22:10 PM, on 11/16/2009<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18828)<br />
Boot mode: Safe mode with network support<br />
<br />
Running processes:<br />
C:\Windows\Explorer.EXE<br />
c:\PROGRA~1\mcafee.com\agent\mcagent.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Windows\system32\config\systemprofile\AppData\L  ocal\Temp\lsass.exe<br />
C:\Windows\system32\config\systemprofile\AppData\L  ocal\Temp\system.exe<br />
C:\Windows\system32\config\systemprofile\AppData\L  ocal\Temp\services.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">Hotmail, News, Sport, Music, Movies, Money, Cars, Shopping, Windows Live from MSN UK</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int  ernet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
R3 - Default URLSearchHook is missing<br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: C:\Windows\system32\t3hqv.dll - {B45A4B16-23F2-41AD-F4E4-00AAC39C0004} - C:\Windows\system32\t3hqv.dll<br />
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll<br />
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe<br />
O4 - HKLM\..\Run: [ISUSScheduler] &quot;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&quot; -start<br />
O4 - HKLM\..\Run: [dscactivate] &quot;C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe&quot;<br />
O4 - HKLM\..\Run: [GrooveMonitor] &quot;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&quot;<br />
O4 - HKLM\..\Run: [DellSupportCenter] &quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&quot; /P DellSupportCenter<br />
O4 - HKLM\..\Run: [mcagent_exe] &quot;C:\Program Files\McAfee.com\Agent\mcagent.exe&quot; /runkey<br />
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br />
O4 - HKLM\..\Run: [calc] rundll32.exe C:\Windows\system32\calc.dll,_IWMPEvents@0<br />
O4 - HKCU\..\Run: [asg984jgkfmgasi8ug98jgkfgfb] C:\Windows\system32\config\systemprofile\AppData\L  ocal\Temp\services.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-18\..\Run: [asg984jgkfmgasi8ug98jgkfgfb] C:\Windows\system32\config\systemprofile\AppData\L  ocal\Temp\services.exe (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [asg984jgkfmgasi8ug98jgkfgfb] C:\Windows\system32\config\systemprofile\AppData\L  ocal\Temp\services.exe (User 'Default user')<br />
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe<br />
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Pol  icies\System, DisableRegedit=1<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - <a href="http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab" target="_blank">http://www.nvidia.com/content/Driver...reqlab_nvd.cab</a><br />
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - <a href="http://www.linkedin.com/cab/LinkedInContactFinderControl.cab" target="_blank">http://www.linkedin.com/cab/LinkedIn...derControl.cab</a><br />
O16 - DPF: {BAC761D3-DFFD-4DB4-A01D-173346E090A7} (CPlayFirstzenerchiControl Object) - <a href="http://chill.comcast.net/AspNet2.0/App/games/channel--110341560/lc--en/room--dd4908ed-13cf-40ca-8cec-824e8df57e3f/online/zenerchi/en/ZenerchiWeb.1.0.0.10.cab" target="_blank">Play Games Online | Online Games | Web Games | Comcast.net</a><br />
O16 - DPF: {C7DEDA04-2FFF-4B81-AE66-0A0E0EF4AD2F} (Image Uploader Control) - <a href="http://www.ritzpix.com/net/Uploader/LPUploader57.cab" target="_blank">http://www.ritzpix.com/net/Uploader/LPUploader57.cab</a><br />
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - <a href="http://chill.comcast.net/Gameshell/GameHost/1.0/OberonGameHost.cab" target="_blank">Play Games Online | Online Games | Web Games | Comcast.net</a><br />
O16 - DPF: {DAF7E6E7-D53A-439A-B28D-12271406B8A9} (AxLoaderPassword Class) - <a href="http://mobileapps.blackberry.com/devicesoftware/AxLoader.cab" target="_blank">http://mobileapps.blackberry.com/dev...e/AxLoader.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll<br />
O20 - Winlogon Notify: GoToAssist - C:\Windows\<br />
O20 - Winlogon Notify: __c003BDF6 - C:\Windows\system32\__c003BDF6.dat<br />
O22 - SharedTaskScheduler: jkshf8a3rudbfa873fudfhbdugf87whjdb - {B45A4B16-23F2-41AD-F4E4-00AAC39C0004} - C:\Windows\system32\t3hqv.dll<br />
O23 - Service: ArcSoft Connect Daemon (ACDaemon) -  - (no file)<br />
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br />
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br />
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe<br />
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe<br />
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br />
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe<br />
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe<br />
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe<br />
<br />
--<br />
End of file - 8359 bytes</div>

]]></content:encoded>
			<category domain="http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/">Spyware, Adware, Viruses and HijackThis Logs</category>
			<dc:creator>bobomonkey</dc:creator>
			<guid isPermaLink="true">http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67146-resolved-serious-problem-please-help.html</guid>
		</item>
		<item>
			<title><![CDATA[[Active] lost - mounting number of websites can't access including https]]></title>
			<link>http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67144-active-lost-mounting-number-websites.html</link>
			<pubDate>Mon, 16 Nov 2009 23:32:30 GMT</pubDate>
			<description><![CDATA[totally lost, running KASPERSKY no prob, when suddenly couldn't access bank accounts, phone account etc on line.  Added to white lists and trusted sites, no joy.  Updated Kaspersky -no difference.  System restore - Kaspersky not working can't uninstall even. AOL re-built adaptor no probs there but...]]></description>
			<content:encoded><![CDATA[<div>totally lost, running KASPERSKY no prob, when suddenly couldn't access bank accounts, phone account etc on line.  Added to white lists and trusted sites, no joy.  Updated Kaspersky -no difference.  System restore - Kaspersky not working can't uninstall even. AOL re-built adaptor no probs there but losing even more access - even Windows Update now.  Re-set IE to default levels. cleared caches now completey lost. 2/10 computer literate (was 3/10 before creating all this mess!)<br />
<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 23:13:35, on 16/11/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\WINDOWS\eHome\ehRecvr.exe<br />
C:\WINDOWS\eHome\ehSched.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\ehome\ehtray.exe<br />
C:\WINDOWS\stsystra.exe<br />
C:\Program Files\Common Files\AOL\1151915566\ee\AOLSoftware.exe<br />
C:\Program Files\Lexmark 4300 Series\lxcemon.exe<br />
C:\Program Files\Dell Support Center\bin\sprtcmd.exe<br />
C:\WINDOWS\eHome\ehmsas.exe<br />
C:\WINDOWS\system32\lxcecoms.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
C:\Program Files\NETGEAR\WG111v2\WG111v2.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\AOL 9.0 VRa\waol.exe<br />
C:\Program Files\AOL 9.0 VRa\shellmon.exe<br />
C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe<br />
C:\WINDOWS\system32\NOTEPAD.EXE<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">Hotmail, News, Sport, Music, Movies, Money, Cars, Shopping, Windows Live from MSN UK</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">Hotmail, News, Sport, Music, Movies, Money, Cars, Shopping, Windows Live from MSN UK</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about<b></b>:blank<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = <a href="http://www.google.co.uk/ig/dell?hl=en&amp;client=dell-inc&amp;channel=uk" target="_blank">Dell Start Page</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = <a href="http://search.aol.co.uk/web?isinit=true&amp;query=%s" target="_blank">AOL Search</a><br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = <a href="http://127.0.0.1:4664/&amp;s=3DJ_CCOlusjI65kuB7E40WkjQSQ" target="_blank">http://127.0.0.1:4664/&amp;s=3DJ_CCOlusjI65kuB7E40WkjQSQ</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int  ernet Settings,ProxyOverride = *.local<br />
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe<br />
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)<br />
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll<br />
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe<br />
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe<br />
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1151915566\ee\AOLSoftware.exe<br />
O4 - HKLM\..\Run: [LXCECATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCEtim  e.dll,_RunDLLEntry@16<br />
O4 - HKLM\..\Run: [lxcemon.exe] &quot;C:\Program Files\Lexmark 4300 Series\lxcemon.exe&quot;<br />
O4 - HKLM\..\Run: [dscactivate] &quot;C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe&quot;<br />
O4 - HKLM\..\Run: [DellSupportCenter] &quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&quot; /P DellSupportCenter<br />
O4 - HKLM\..\Run: [ATIPTA] &quot;C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [ISUSPM Startup] &quot;C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe&quot; -startup<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] &quot;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&quot; /background (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')<br />
O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = ?<br />
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - <a href="http://www.pcpitstop.com/betapit/PCPitStop.CAB" target="_blank">http://www.pcpitstop.com/betapit/PCPitStop.CAB</a><br />
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - <a href="http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-5/myWebFaceInitialSetup1.0.1.3.cab" target="_blank">http://ak.exe.imgfarm.com/images/noc...tup1.0.1.3.cab</a><br />
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - <a href="http://download.eset.com/special/eos/OnlineScanner.cab" target="_blank">http://download.eset.com/special/eos/OnlineScanner.cab</a><br />
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll<br />
O18 - Protocol: schmap-help - (no CLSID) - (no file)<br />
O20 - AppInit_DLLs: ??????P,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll<br />
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe<br />
O23 - Service: Kaspersky Internet Security (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe (file missing)<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe<br />
O23 - Service: lxce_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcecoms.exe<br />
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe<br />
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br />
<br />
--<br />
End of file - 7548 bytes</div>

]]></content:encoded>
			<category domain="http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/">Spyware, Adware, Viruses and HijackThis Logs</category>
			<dc:creator>LeighSarah</dc:creator>
			<guid isPermaLink="true">http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67144-active-lost-mounting-number-websites.html</guid>
		</item>
		<item>
			<title>Hijackthis log</title>
			<link>http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67142-hijackthis-log.html</link>
			<pubDate>Mon, 16 Nov 2009 19:56:01 GMT</pubDate>
			<description>Hi guys this is from a fresh install with only a few installs. im having problems connecting and getting updates to microsoft hoping this will solve the problem. thanks in advance. 
 
 
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 2:55:05 AM, on 11/16/2009 
Platform: Windows XP SP1...</description>
			<content:encoded><![CDATA[<div>Hi guys this is from a fresh install with only a few installs. im having problems connecting and getting updates to microsoft hoping this will solve the problem. thanks in advance.<br />
<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 2:55:05 AM, on 11/16/2009<br />
Platform: Windows XP SP1 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\msdrv32.exe<br />
C:\WINDOWS\System32\lssas.exe<br />
C:\WINDOWS\System32\Cilevb.com<br />
C:\WINDOWS\System32\firewall.exe<br />
C:\WINDOWS\System32\ssms.exe<br />
C:\WINDOWS\explorer.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
O3 - Toolbar: &amp;Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx<br />
O4 - HKLM\..\Run: [Local Security Authority Service] C:\WINDOWS\System32\lssas.exe<br />
O4 - HKLM\..\Run: [netmon] C:\WINDOWS\system\netmon.exe<br />
O4 - HKLM\..\Run: [Copic Tilevb] Cilevb.com<br />
O4 - HKLM\..\Run: [CTRegRun] C:\WINDOWS\CTRegRun.EXE<br />
O4 - HKLM\..\Run: [Microsoft Driver Setup] C:\WINDOWS\msdrv32.exe<br />
O4 - HKLM\..\Run: [Windows Network Firewall] C:\WINDOWS\System32\firewall.exe<br />
O4 - HKLM\..\Run: [Windows Update] ssms.exe<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe<br />
O4 - HKLM\..\RunServices: [Copic Tilevb] Cilevb.com<br />
O4 - HKLM\..\RunServices: [Windows Update] ssms.exe<br />
O4 - HKCU\..\Run: [Tjmm71] C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1455\mmdg.exe<br />
O4 - HKCU\..\Run: [12CFG515-K641-55SF-N66P] C:\RECYCLER\S-1-5-21-0243636035-3055115376-381863306-1556\pqlmq.exe<br />
O4 - HKLM\..\Policies\Explorer\Run: [Microsoft Driver Setup] C:\WINDOWS\msdrv32.exe<br />
O4 - HKUS\S-1-5-18\..\Run: [Tjmm71] C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1455\mmdg.exe (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [Tjmm71] C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1455\mmdg.exe (User 'Default user')<br />
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm<br />
O9 - Extra 'Tools' menuitem: Show &amp;Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm<br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1258349844906" target="_blank">http://update.microsoft.com/microsof...?1258349844906</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1258349884140" target="_blank">http://www.update.microsoft.com/micr...?1258349884140</a></div>

]]></content:encoded>
			<category domain="http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/">Spyware, Adware, Viruses and HijackThis Logs</category>
			<dc:creator>arisner</dc:creator>
			<guid isPermaLink="true">http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67142-hijackthis-log.html</guid>
		</item>
		<item>
			<title>threat..</title>
			<link>http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67138-threat.html</link>
			<pubDate>Mon, 16 Nov 2009 11:20:49 GMT</pubDate>
			<description><![CDATA[hello i was wondering if i could have some knowledge on a potentially dangerous threat called 'adware generic4 RRA' . thanks]]></description>
			<content:encoded><![CDATA[<div>hello i was wondering if i could have some knowledge on a potentially dangerous threat called 'adware generic4 RRA' . thanks</div>

]]></content:encoded>
			<category domain="http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/">Spyware, Adware, Viruses and HijackThis Logs</category>
			<dc:creator>shannonroberts1</dc:creator>
			<guid isPermaLink="true">http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67138-threat.html</guid>
		</item>
		<item>
			<title><![CDATA[[Active] dl.exe]]></title>
			<link>http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67116-active-dl-exe.html</link>
			<pubDate>Fri, 13 Nov 2009 23:59:23 GMT</pubDate>
			<description>All the usual problems that everyone else has had with this little nasty one, no connection after an error box, originally just did a system restore and it was fine, for a couple of days, then the box came back and i lost internet conn and the ability to run windows in normal mode.. I however can...</description>
			<content:encoded><![CDATA[<div>All the usual problems that everyone else has had with this little nasty one, no connection after an error box, originally just did a system restore and it was fine, for a couple of days, then the box came back and i lost internet conn and the ability to run windows in normal mode.. I however can run in safe mode with networking and access the internet. Been searching for fixes, found none.. I cant run windows in normal mode at all so i dont know what im gonna be able to do exactly, but here is the HJT log in safe mode, although i don't know if it is useful. I guess i could do a system resore to get back to normal mode and run it again, let me know if this is something i should do.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 7:03:27 PM, on 11/13/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Safe mode with network support<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\HiJackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=Q106&amp;bd=pavilion&amp;pf=desktop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...ion&amp;pf=desktop</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iesearch&amp;locale=EN_US&amp;c=Q106&amp;bd=pavilion&amp;pf=desktop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...ion&amp;pf=desktop</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iesearch&amp;locale=EN_US&amp;c=Q106&amp;bd=pavilion&amp;pf=desktop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...ion&amp;pf=desktop</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iesearch&amp;locale=EN_US&amp;c=Q106&amp;bd=pavilion&amp;pf=desktop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...ion&amp;pf=desktop</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iesearch&amp;locale=EN_US&amp;c=Q106&amp;bd=pavilion&amp;pf=desktop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...ion&amp;pf=desktop</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iesearch&amp;locale=EN_US&amp;c=Q106&amp;bd=pavilion&amp;pf=desktop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...ion&amp;pf=desktop</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = <a href="http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com" target="_blank">http://red.clientapps.yahoo.com/cust.../www.yahoo.com</a><br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=Q106&amp;bd=pavilion&amp;pf=desktop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...ion&amp;pf=desktop</a><br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\s  wg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe<br />
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe<br />
O4 - HKLM\..\Run: [DISCover] C:\Program Files\DISC\DISCover.exe<br />
O4 - HKLM\..\Run: [DiscUpdateManager] C:\Program Files\DISC\DiscUpdateMgr.exe<br />
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE<br />
O4 - HKLM\..\Run: [HPBootOp] &quot;C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe&quot; /run<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE<br />
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br />
O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;  -osboot<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [ISUSScheduler] &quot;c:\program files\common files\installshield\updateservice\issch.exe&quot; -start<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [MSMSGS] &quot;C:\Program Files\Messenger\msmsgs.exe&quot; /background<br />
O4 - HKCU\..\Run: [updateMgr] &quot;C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe&quot; AcRdB7_0_8 -reboot 1<br />
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.  exe<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo  tifier.exe&quot;<br />
O4 - HKCU\..\Run: [BitTorrent DNA] &quot;C:\Program Files\DNA\btdna.exe&quot;<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork<br />
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')<br />
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br />
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br />
O4 - Global Startup: APC UPS Status.lnk = ?<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br />
O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm<br />
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O15 - Trusted Zone: <a href="http://*.trymedia.com" target="_blank">http://*.trymedia.com</a> (HKLM)<br />
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - <a href="http://cache.systemrequirementslab.com/htdocs/srl_bin/sysreqlab_srl.cab" target="_blank">http://cache.systemrequirementslab.c...reqlab_srl.cab</a><br />
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - <a href="http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab" target="_blank">http://www.fileplanet.com/fpdlmgr/ca..._2.3.9.113.cab</a><br />
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - <a href="https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab" target="_blank">https://h20436.www2.hp.com/ediags/de...e/HPDEXAXO.cab</a><br />
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Program Files\AutoCAD LT 2000i\AcDcToday.ocx<br />
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (NOXLATE) - file://C:\Program Files\AutoCAD LT 2000i\InstFred.ocx<br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - <a href="http://h30155.www3.hp.com/ediags/hpfix/sj/en/check/xp/qdiagh.cab?326" target="_blank">http://h30155.www3.hp.com/ediags/hpf...qdiagh.cab?326</a><br />
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD LT 2000i\AcPreview.ocx<br />
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe<br />
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - C:\Program Files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe<br />
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM1  2.EXE<br />
<br />
--<br />
End of file - 9825 bytes</div>

]]></content:encoded>
			<category domain="http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/">Spyware, Adware, Viruses and HijackThis Logs</category>
			<dc:creator>kcrisher</dc:creator>
			<guid isPermaLink="true">http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67116-active-dl-exe.html</guid>
		</item>
		<item>
			<title><![CDATA[Malwarebytes bug - it's extremely important to read this]]></title>
			<link>http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67108-malwarebytes-bug-its-extremely-important.html</link>
			<pubDate>Fri, 13 Nov 2009 03:15:14 GMT</pubDate>
			<description><![CDATA[Due to a bug in Malwarebytes, you may see in MBAM's log following entries: 
*HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\atapi (Rootkit) 
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\atapi (Rootkit) 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\atapi (Rootkit)* 
*_DO NOT_* remove...]]></description>
			<content:encoded><![CDATA[<div>Due to a bug in Malwarebytes, you may see in MBAM's log following entries:<br />
<b>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\a  tapi (Rootkit)<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\a  tapi (Rootkit)<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic  es\atapi (Rootkit)</b><br />
<b><u>DO NOT</u></b> remove those entries!<br />
<b>If you do, your computer will become UN-bootable.</b><br />
The issue has been fixed in the latest MBAM update, so, please, make sure, you <b><font color="Red">update MBAM before you run it</font></b>.</div>

]]></content:encoded>
			<category domain="http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/">Spyware, Adware, Viruses and HijackThis Logs</category>
			<dc:creator>broni</dc:creator>
			<guid isPermaLink="true">http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67108-malwarebytes-bug-its-extremely-important.html</guid>
		</item>
		<item>
			<title><![CDATA[[Active] Google links]]></title>
			<link>http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67079-active-google-links.html</link>
			<pubDate>Mon, 09 Nov 2009 18:31:03 GMT</pubDate>
			<description><![CDATA[Hi, new to the forums. 
 
Whenever I'm on Google and clicking on links I'm being redirected to random sites. I'm sure it's something pretty simple, anybody have any ideas? 
 
Thanks 
 
 
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 18:32:32, on 09/11/2009 
Platform: Windows Vista  (WinNT...]]></description>
			<content:encoded><![CDATA[<div>Hi, new to the forums.<br />
<br />
Whenever I'm on Google and clicking on links I'm being redirected to random sites. I'm sure it's something pretty simple, anybody have any ideas?<br />
<br />
Thanks<br />
<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 18:32:32, on 09/11/2009<br />
Platform: Windows Vista  (WinNT 6.00.1904)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18828)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\System32\mobsync.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\Program Files\Opera\opera.exe<br />
C:\Program Files\Browser MOUSE\mouse32a.exe<br />
C:\Program Files\Common Files\AOL\1234746178\ee\aolsoftware.exe<br />
C:\Program Files\Thomson SpeedTouch\SpeedTouch 121g Wireless USB Monitor\PRISMSVR.exe<br />
C:\Program Files\QuickTime\qttask.exe<br />
C:\Program Files\Winamp\winampa.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo  tifier.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Program Files\DAEMON Tools Lite\daemon.exe<br />
C:\Program Files\Steam\steam.exe<br />
C:\Program Files\AOL 9.0\aoltray.exe<br />
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe<br />
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe<br />
C:\Program Files\Thomson SpeedTouch\SpeedTouch 121g Wireless USB Monitor\st121g.exe<br />
C:\Program Files\OpenOffice.org 3\program\soffice.exe<br />
C:\Program Files\OpenOffice.org 3\program\soffice.bin<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Program Files\Winamp\winamp.exe<br />
C:\Program Files\Winamp\elevator.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.google.co.uk/" target="_blank">http://www.google.co.uk/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\s  wg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;  -osboot<br />
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Browser MOUSE\mouse32a.exe<br />
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1234746178\ee\AOLSoftware.exe<br />
O4 - HKLM\..\Run: [PRISMSVR.EXE] &quot;C:\Program Files\Thomson SpeedTouch\SpeedTouch 121g Wireless USB Monitor\PRISMSVR.EXE&quot; /APPLY<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [WinampAgent] &quot;C:\Program Files\Winamp\winampa.exe&quot;<br />
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo  tifier.exe&quot;<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKCU\..\Run: [DAEMON Tools Lite] &quot;C:\Program Files\DAEMON Tools Lite\daemon.exe&quot; -autorun<br />
O4 - HKCU\..\Run: [Steam] &quot;C:\Program Files\Steam\Steam.exe&quot; -silent<br />
O4 - HKCU\..\RunOnce: [DAEMON Tools Pro 4.35.0306.0088 Setup] &quot;C:\Users\Ken\Desktop\DAEMONToolsPro4350306.ex  e&quot;<br />
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil10a.ex  e (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil10a.ex  e (User 'Default user')<br />
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe<br />
O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe<br />
O4 - Global Startup: hp psc 1000 series.lnk = ?<br />
O4 - Global Startup: hpoddt01.exe.lnk = ?<br />
O4 - Global Startup: SpeedTouch 121g Wireless USB Monitor.lnk = C:\Program Files\Thomson SpeedTouch\SpeedTouch 121g Wireless USB Monitor\st121g.exe<br />
O8 - Extra context menu item: &amp;AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - <br />
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - <a href="http://download.divx.com/webplayer/stage6/windows/AutoDLDivXWebPlayerInstaller.cab" target="_blank">http://download.divx.com/webplayer/s...rInstaller.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O20 - AppInit_DLLs: avgrsstx.dll<br />
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe<br />
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search &amp; Destroy\SDWinSec.exe<br />
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe<br />
<br />
--<br />
End of file - 7816 bytes</div>

]]></content:encoded>
			<category domain="http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/">Spyware, Adware, Viruses and HijackThis Logs</category>
			<dc:creator>Silence208</dc:creator>
			<guid isPermaLink="true">http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67079-active-google-links.html</guid>
		</item>
		<item>
			<title><![CDATA[[Resolved] can't open HJT from hard disc]]></title>
			<link>http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67072-resolved-cant-open-hjt-hard.html</link>
			<pubDate>Mon, 09 Nov 2009 08:10:04 GMT</pubDate>
			<description><![CDATA[Hi, 
Just managed to remove a virus which caused "NT Authority \system shutdown" using combofix (log attached) However, HJT, which was blocked when virus was around, and "Prevx v3" will not open. HJT cannot be "deleted" with an "access denied" error. I have managed to get a HJT log by using the...]]></description>
			<content:encoded><![CDATA[<div>Hi,<br />
Just managed to remove a virus which caused &quot;NT Authority \system shutdown&quot; using combofix (log attached) However, HJT, which was blocked when virus was around, and &quot;Prevx v3&quot; will not open. HJT cannot be &quot;deleted&quot; with an &quot;access denied&quot; error. I have managed to get a HJT log by using the program loaded onto a usb stick (Also attached) . The machine appears to be virus free Any ideas? Roger<br />
<br />
ComboFix 09-11-08.03 - RogerD 09/11/2009  0:02.1.2 - NTFSx86<br />
Microsoft Windows XP Professional  5.1.2600.3.1252.44.1033.18.2046.1448 [GMT 0:00]<br />
Running from: c:\documents and settings\RogerD\Desktop\ComboFix.exe<br />
AV: ESET NOD32 Antivirus 3.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}<br />
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}<br />
 * Resident AV is active<br />
<br />
.<br />
<br />
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br />
<br />
c:\documents and settings\RogerD\Application Data\inst.exe<br />
c:\progra~1\COMMON~1\{54A58~1<br />
c:\program files\LPVideoPlugin<br />
c:\program files\LPVideoPlugin\work.log<br />
c:\windows\a3kebook.ini<br />
c:\windows\akebook.ini<br />
c:\windows\ANS2000.INI<br />
c:\windows\kb913800.exe<br />
c:\windows\system32\AutoRun.inf<br />
<br />
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected <br />
Restored copy from - c:\windows\ServicePackFiles\i386\eventlog.dll <br />
<br />
.<br />
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br />
<br />
-------\Legacy_NPF<br />
-------\Service_NPF<br />
-------\Legacy_NPF<br />
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}<br />
<br />
<br />
(((((((((((((((((((((((((   Files Created from 2009-10-09 to 2009-11-09  )))))))))))))))))))))))))))))))<br />
.<br />
<br />
2009-11-08 20:14 . 2009-11-08 20:14	--------	d-----w-	c:\program files\Prevx<br />
2009-11-08 19:54 . 2009-11-08 20:14	53136	----a-w-	c:\windows\system32\PxSecure.dll<br />
2009-11-08 19:54 . 2009-11-08 20:14	30280	----a-w-	c:\windows\system32\drivers\pxscan.sys<br />
2009-11-08 19:54 . 2009-11-08 20:14	46768	----a-w-	c:\windows\system32\drivers\pxrts.sys<br />
2009-11-08 19:54 . 2009-11-08 20:14	24368	----a-w-	c:\windows\system32\drivers\pxkbf.sys<br />
2009-11-08 19:53 . 2009-11-08 21:11	--------	d-----w-	c:\documents and settings\All Users\Application Data\PrevxCSI<br />
2009-11-08 16:59 . 2009-11-08 16:59	--------	d-----w-	c:\program files\HJT<br />
2009-11-08 16:58 . 2009-11-08 16:25	401720	----a-w-	C:\HijackThis.exe<br />
2009-11-07 21:09 . 2009-11-08 22:47	0	----a-r-	c:\windows\win32k.sys<br />
2009-11-07 20:30 . 2009-11-07 20:30	--------	d-----w-	c:\documents and settings\RogerD\Local Settings\Application Data\ESET<br />
2009-11-07 20:30 . 2009-11-07 20:30	--------	d-----w-	c:\documents and settings\LocalService\Local Settings\Application Data\ESET<br />
2009-11-07 20:22 . 2009-11-07 20:22	--------	d-sh--w-	c:\documents and settings\RogerD\IECompatCache<br />
2009-10-26 20:24 . 2009-10-26 20:24	152576	----a-w-	c:\documents and settings\RogerD\Application Data\Sun\Java\jre1.6.0_15\lzma.dll<br />
<br />
.<br />
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))  ))<br />
.<br />
2009-11-08 16:25 . 2005-02-16 11:06	401720	----a-w-	c:\program files\HijackThis.exe<br />
2009-11-08 15:53 . 2008-07-24 19:34	--------	d-----w-	c:\documents and settings\RogerD\Application Data\Skype<br />
2009-11-08 15:51 . 2008-06-18 15:52	--------	d-----w-	c:\documents and settings\RogerD\Application Data\skypePM<br />
2009-11-07 22:59 . 2006-09-30 18:27	--------	d-----w-	c:\program files\Microsoft IntelliPoint<br />
2009-10-27 22:01 . 2006-03-27 11:31	--------	d-----w-	c:\program files\Common Files\Adobe<br />
2009-10-27 21:30 . 2008-09-08 22:53	--------	d-----w-	c:\program files\TradeGuider<br />
2009-10-26 20:25 . 2006-03-27 11:29	--------	d-----w-	c:\program files\Java<br />
2009-09-11 14:18 . 2006-03-24 08:26	136192	----a-w-	c:\windows\system32\msv1_0.dll<br />
2009-09-04 21:03 . 2006-03-24 08:26	58880	----a-w-	c:\windows\system32\msasn1.dll<br />
2009-08-29 08:08 . 2006-03-24 08:27	916480	----a-w-	c:\windows\system32\wininet.dll<br />
2009-08-26 08:00 . 2006-03-24 08:27	247326	----a-w-	c:\windows\system32\strmdll.dll<br />
2009-08-25 20:31 . 2006-09-27 19:58	76512	----a-w-	c:\documents and settings\RogerD\Local Settings\Application Data\GDIPFONTCACHEV1.DAT<br />
2007-12-02 19:41 . 2007-12-02 19:41	0	----a-w-	c:\program files\error.dat<br />
2006-10-31 22:15 . 2006-10-31 22:15	11572	----a-w-	c:\program files\hijackthis.log<br />
.<br />
<br />
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br />
.<br />
*Note* empty entries &amp; legit default entries are not shown <br />
REGEDIT4<br />
<br />
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre  ntVersion\Run]<br />
&quot;MSMSGS&quot;=&quot;c:\program files\Messenger\msmsgs.exe&quot; [2008-04-14 1695232]<br />
&quot;H/PC Connection Agent&quot;=&quot;c:\program files\Microsoft ActiveSync\wcescomm.exe&quot; [2006-11-13 1289000]<br />
&quot;Google Update&quot;=&quot;c:\documents and settings\RogerD\Local Settings\Application Data\Google\Update\GoogleUpdate.exe&quot; [2009-04-10 133104]<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr  entVersion\Run]<br />
&quot;Apoint&quot;=&quot;c:\program files\Apoint\Apoint.exe&quot; [2004-11-17 118784]<br />
&quot;ehTray&quot;=&quot;c:\windows\ehome\ehtray.exe&quot; [2005-08-05 64512]<br />
&quot;VAIOCameraUtility&quot;=&quot;c:\program files\Sony\VAIO Camera Utility\VCUServe.exe&quot; [2005-12-27 69632]<br />
&quot;ISBMgr.exe&quot;=&quot;c:\program files\Sony\ISB Utility\ISBMgr.exe&quot; [2004-02-20 32768]<br />
&quot;Switcher.exe&quot;=&quot;c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe&quot; [2006-02-14 176128]<br />
&quot;AppMon Utility&quot;=&quot;c:\program files\Sony\AppMonUtil\AppMonUtility.exe&quot; [2006-03-15 40960]<br />
&quot;SonyPowerCfg&quot;=&quot;c:\program files\Sony\VAIO Power Management\SPMgr.exe&quot; [2006-01-26 212992]<br />
&quot;NvMediaCenter&quot;=&quot;c:\windows\system32\NvMcTray.  dll&quot; [2006-04-17 86016]<br />
&quot;NvCplDaemon&quot;=&quot;c:\windows\system32\NvCpl.dll&quot; [2006-04-17 7561216]<br />
&quot;SsAAD.exe&quot;=&quot;c:\progra~1\Sony\SONICS~1\SsAAD.e  xe&quot; [2006-01-07 81920]<br />
&quot;IntelliPoint&quot;=&quot;c:\program files\Microsoft IntelliPoint\ipoint.exe&quot; [2005-12-05 461584]<br />
&quot;egui&quot;=&quot;c:\program files\ESET\ESET NOD32 Antivirus\egui.exe&quot; [2008-10-24 1451264]<br />
&quot;QuickTime Task&quot;=&quot;d:\program files\QTTask.exe&quot; [2009-05-26 413696]<br />
&quot;iTunesHelper&quot;=&quot;c:\program files\iTunes\iTunesHelper.exe&quot; [2009-07-13 292128]<br />
&quot;SunJavaUpdateSched&quot;=&quot;c:\program files\Java\jre6\bin\jusched.exe&quot; [2009-07-25 149280]<br />
&quot;Adobe Reader Speed Launcher&quot;=&quot;c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot; [2009-10-03 35696]<br />
&quot;Adobe ARM&quot;=&quot;c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot; [2009-09-04 935288]<br />
&quot;Mouse Suite 98 Daemon&quot;=&quot;ICO.EXE&quot; - c:\windows\system32\ico.exe [2002-03-14 45056]<br />
<br />
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur  rentVersion\Run]<br />
&quot;CTFMON.EXE&quot;=&quot;c:\windows\system32\CTFMON.EXE&quot; [2008-04-14 15360]<br />
<br />
c:\documents and settings\All Users\Start Menu\Programs\Startup\<br />
ELWAVE UDS.lnk - c:\program files\Common Files\PrognosisUDS\UDS.exe [2009-6-18 630784]<br />
Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2007-2-5 118784]<br />
<br />
[hkey_local_machine\software\microsoft\windows\curr  entversion\explorer\ShellExecuteHooks]<br />
&quot;{56F9679E-7826-4C84-81F3-532071A8BCC5}&quot;= &quot;c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll&quot; [2007-02-05 294400]<br />
<br />
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]<br />
2006-03-09 13:51	73728	----a-w-	c:\windows\system32\VESWinlogon.dll<br />
<br />
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]<br />
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk<br />
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup<br />
<br />
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth Manager.lnk]<br />
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk<br />
backup=c:\windows\pss\Bluetooth Manager.lnkCommon Startup<br />
<br />
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]<br />
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk<br />
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup<br />
<br />
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PrintKey-Pro.lnk]<br />
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\PrintKey-Pro.lnk<br />
backup=c:\windows\pss\PrintKey-Pro.lnkCommon Startup<br />
<br />
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]<br />
&quot;DisableMonitoring&quot;=dword:00000001<br />
<br />
[HKLM\~\services\sharedaccess\parameters\firewallpo  licy\standardprofile]<br />
&quot;EnableFirewall&quot;= 0 (0x0)<br />
<br />
[HKLM\~\services\sharedaccess\parameters\firewallpo  licy\standardprofile\AuthorizedApplications\List]<br />
&quot;%windir%\\system32\\sessmgr.exe&quot;=<br />
&quot;c:\\Program Files\\Adobe\\Photoshop Elements 4.0\\AdobePhotoshopElementsMediaServer.exe&quot;=<br />
&quot;c:\\Program Files\\LimeWire\\LimeWire.exe&quot;=<br />
&quot;c:\\Program Files\\Messenger\\msmsgs.exe&quot;=<br />
&quot;%windir%\\Network Diagnostic\\xpnetdiag.exe&quot;=<br />
&quot;c:\\Program Files\\BitLord\\BitLord.exe&quot;=<br />
&quot;c:\\Program Files\\TVAnts\\Tvants.exe&quot;=<br />
&quot;c:\\Program Files\\TVUPlayer\\TVUPlayer.exe&quot;=<br />
&quot;c:\\Program Files\\MaxGammon\\maxgammon.exe&quot;=<br />
&quot;c:\\Documents and Settings\\RogerD\\Application Data\\SopCast\\adv\\SopAdver.exe&quot;=<br />
&quot;c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE&quot;=<br />
&quot;c:\program files\Microsoft ActiveSync\rapimgr.exe&quot;= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager<br />
&quot;c:\program files\Microsoft ActiveSync\wcescomm.exe&quot;= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager<br />
&quot;c:\program files\Microsoft ActiveSync\WCESMgr.exe&quot;= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application<br />
&quot;c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe&quot;=<br />
&quot;c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe&quot;=<br />
&quot;c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe&quot;=<br />
&quot;c:\\Program Files\\Sony\\VAIO Media 5.0\\Vc.exe&quot;=<br />
&quot;c:\\Program Files\\Bonjour\\mDNSResponder.exe&quot;=<br />
&quot;c:\\Program Files\\iTunes\\iTunes.exe&quot;=<br />
&quot;c:\\Program Files\\Skype\\Phone\\Skype.exe&quot;=<br />
<br />
[HKLM\~\services\sharedaccess\parameters\firewallpo  licy\standardprofile\GloballyOpenPorts\List]<br />
&quot;26675:TCP&quot;= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service<br />
<br />
R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.s  ys [08/11/2009 19:54 30280]<br />
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfw  tdir.sys [24/10/2008 20:53 34824]<br />
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [09/10/2007 12:13 38144]<br />
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [24/10/2008 20:51 468224]<br />
R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB --&gt; c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB [?]<br />
R2 pxrts;pxrts;c:\windows\system32\drivers\pxrts.sys [08/11/2009 19:54 46768]<br />
R3 AVerM115S;AVerM115S service;c:\windows\system32\drivers\AVerM115S.sys [24/03/2006 10:36 745600]<br />
R3 pxkbf;pxkbf;c:\windows\system32\drivers\pxkbf.sys [08/11/2009 19:54 24368]<br />
R3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [24/03/2006 08:27 29184]<br />
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21  sony.sys [24/03/2006 08:27 226304]<br />
S2 CSIScanner;CSIScanner;c:\program files\Prevx\prevx.exe [08/11/2009 20:14 6210488]<br />
S2 ecure;FireDaemon Service: ecure;c:\windows\Temp\FireDaemon.EXE --&gt; c:\windows\Temp\FireDaemon.EXE [?]<br />
S2 svchost1;FireDaemon Service: svchost1;c:\windows\Temp\FireDaemon.EXE --&gt; c:\windows\Temp\FireDaemon.EXE [?]<br />
S3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\drivers\wg111v3.sys [28/12/2007 14:02 287232]<br />
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB --&gt; c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB [?]<br />
<br />
--- Other Services/Drivers In Memory ---<br />
<br />
*NewlyCreated* - MBR<br />
*Deregistered* - mbr<br />
<br />
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]<br />
HPZ12	REG_MULTI_SZ   	Pml Driver HPZ12 Net Driver HPZ12<br />
hpdevmgmt	REG_MULTI_SZ   	hpqcxs08<br />
.<br />
Contents of the 'Scheduled Tasks' folder<br />
<br />
2009-07-30 c:\windows\Tasks\AppleSoftwareUpdate.job<br />
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 12:34]<br />
<br />
2009-11-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3007359059-2519479876-3341910830-1006Core.job<br />
- c:\documents and settings\RogerD\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-10 23:08]<br />
<br />
2009-11-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3007359059-2519479876-3341910830-1006UA.job<br />
- c:\documents and settings\RogerD\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-10 23:08]<br />
<br />
2008-11-22 c:\windows\Tasks\HubTask 0 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0.job<br />
- c:\program files\Common Files\Sonic Shared\Sonic Central\Main\Mediahub.exe [2006-03-30 01:07]<br />
<br />
2009-11-08 c:\windows\Tasks\User_Feed_Synchronization-{FC78BF24-9B7A-4451-B009-38B60BFAE2B5}.job<br />
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]<br />
.<br />
.<br />
------- Supplementary Scan -------<br />
.<br />
uStart Page = hxxp://news.bbc.co.uk/<br />
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&amp;sourceid=ie7&amp;rls=com.micros  oft:en-US&amp;ie=utf8&amp;oe=utf8<br />
uInternet Connection Wizard,ShellNext = iexplore<br />
uInternet Settings,ProxyOverride = *.local<br />
IE: Add RSS Support Site to VAIO Information FLOW - c:\program files\Sony\VAIO Information FLOW\aiesc.html<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000<br />
Trusted Zone: sony-europe.com<br />
Trusted Zone: sonystyle-europe.com<br />
Trusted Zone: vaio-link.com<br />
FF - ProfilePath - c:\documents and settings\RogerD\Application Data\Mozilla\Firefox\Profiles\ewdkopfh.default\<br />
FF - prefs.<acronym title="JavaScript">js</acronym>: browser.startup.homepage - hxxp://news.bbc.co.uk/1/hi/uk/default.stm<br />
FF - plugin: c:\documents and settings\RogerD\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dl  l<br />
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll<br />
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll<br />
FF - plugin: d:\program files\Plugins\npqtplugin.dll<br />
FF - plugin: d:\program files\Plugins\npqtplugin2.dll<br />
FF - plugin: d:\program files\Plugins\npqtplugin3.dll<br />
FF - plugin: d:\program files\Plugins\npqtplugin4.dll<br />
FF - plugin: d:\program files\Plugins\npqtplugin5.dll<br />
FF - plugin: d:\program files\Plugins\npqtplugin6.dll<br />
FF - plugin: d:\program files\Plugins\npqtplugin7.dll<br />
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\<br />
<br />
---- FIREFOX POLICIES ----<br />
c:\program files\Mozilla Firefox\greprefs\security-prefs.<acronym title="JavaScript">js</acronym> - pref(&quot;security.ssl3.rsa_seed_sha&quot;, true);<br />
.<br />
- - - - ORPHANS REMOVED - - - -<br />
<br />
BHO-{F1870D8F-A860-481E-8C74-20DC6C1CF09C} - (no file)<br />
Notify-ddabx - c:\windows\system32\ddabx.dll<br />
Notify-hggdeeb - hggdeeb.dll<br />
Notify-nnnmnmk - nnnmnmk.dll<br />
SafeBoot-AVG Anti-Spyware Driver<br />
SafeBoot-AVG Anti-Spyware Guard<br />
AddRemove-HijackThis - H:\HijackThis.exe<br />
<br />
<br />
<br />
**************************************************  ************************<br />
<br />
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, <a href="http://www.gmer.net" target="_blank">GMER - Rootkit Detector and Remover</a><br />
Rootkit scan 2009-11-09 00:18<br />
Windows 5.1.2600 Service Pack 3 NTFS<br />
<br />
scanning hidden processes ...  <br />
<br />
scanning hidden autostart entries ... <br />
<br />
scanning hidden files ...  <br />
<br />
scan completed successfully<br />
hidden files: 0<br />
<br />
**************************************************  ************************<br />
.<br />
--------------------- LOCKED REGISTRY KEYS ---------------------<br />
<br />
[HKEY_USERS\S-1-5-21-3007359059-2519479876-3341910830-1006\Software\Microsoft\Windows\CurrentVersion\She  ll Extensions\Approved\{DEA9DD8E-69B4-F821-6AA3-4C06FED3ECCE}*]<br />
@Allowed: (Read) (RestrictedCode)<br />
@Allowed: (Read) (RestrictedCode)<br />
&quot;iaianndcgalncjljii&quot;=hex:6b,61,6f,65,68,6f,6b,6f,7  0,61,6a,6c,68,67,69,61,68,6a,<br />
   6b,6d,6d,6e,00,00<br />
&quot;hacblepfbggpajjo&quot;=hex:6b,61,6f,65,68,6f,6b,6f,70,  61,6a,6c,68,67,69,61,68,6a,<br />
   6b,6d,6d,6e,00,00<br />
<br />
[HKEY_USERS\S-1-5-21-3007359059-2519479876-3341910830-1006\Software\Microsoft\Windows\CurrentVersion\She  ll Extensions\Approved\{EF2376D3-C8FF-5A41-3324-EF5DC32C0EBF}*]<br />
@Allowed: (Read) (RestrictedCode)<br />
@Allowed: (Read) (RestrictedCode)<br />
&quot;iaijgbbabdihnfngcf&quot;=hex:6b,61,63,67,63,6f,6d,6c,6  f,61,6c,63,6e,6c,68,63,61,6b,<br />
   65,6f,6a,68,00,00<br />
&quot;haoieephhnnbkanh&quot;=hex:6b,61,63,67,63,6f,6d,6c,6f,  61,6c,63,6e,6c,68,63,61,6b,<br />
   65,6f,6a,68,00,00<br />
<br />
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1A68D66  8-6DF3-702D-2A0852A803C1488D}\{D6F2E9CD-48BA-CDDC-BEA31B576464FCAF}\{421B9E29-5D23-2966-C9D7C1E976BC0884}*]<br />
&quot;{3EE4C831-B7E0-4ed1-B9FC-EDC523C9612F}1&quot;=hex:01,00,01,00,0c,00,00,00,4e,55,  7d,<br />
   a1,27,65,a4,99,71,72,b0,2b,12,1c,4a,b4,92,59,16,04  ,76,d0,c6,51,d5,fb,6f,f6,\<br />
<br />
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4262173  D-BE17-0AF1-BC367E078DE3B172}\{0348FBC8-06E2-B99C-443C2E87108EE036}\{533D0420-D13F-E032-E569EC2F904CC0B3}*]<br />
&quot;VBOGEGOY1DKTBDELSVQBDYRDXB1&quot;=hex:01,00,01,00,00,0  0,00,00,d4,b3,d7,da,ae,5a,86,<br />
   f1,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61<br />
<br />
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4F56E72  7-0A5D-9C93-99600FC5295CA3F5}\{8257E326-E765-C505-3AEB2DA5981E86BA}\{7ADCE296-1D79-0777-094B0CE9C6E4DF1E}*]<br />
&quot;VBOGEGOY1DKTBDELSVQBDYRDXB1&quot;=hex:01,00,01,00,00,0  0,00,00,d4,b3,d7,da,ae,5a,86,<br />
   f1,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61<br />
<br />
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DBE5F6A  6-C8E0-8D37-B1C3ECD994E168FF}\{7F7185F9-7F48-A4B8-D3088315D7013D5E}\{124A519E-6019-9B74-2FA3F0240754901A}*]<br />
&quot;{3EE4C831-B7E0-4ed1-B9FC-EDC523C9612F}1&quot;=hex:01,00,01,00,0c,00,00,00,4e,55,  7d,<br />
   a1,27,65,a4,99,71,72,b0,2b,12,1c,4a,b4,92,59,16,04  ,76,d0,c6,51,d5,fb,6f,f6,\<br />
.<br />
--------------------- DLLs Loaded Under Running Processes ---------------------<br />
<br />
- - - - - - - &gt; 'winlogon.exe'(1272)<br />
c:\windows\system32\VESWinlogon.dll<br />
<br />
- - - - - - - &gt; 'explorer.exe'(5436)<br />
c:\windows\system32\WININET.dll<br />
c:\windows\system32\ieframe.dll<br />
c:\windows\system32\webcheck.dll<br />
c:\windows\system32\WPDShServiceObj.dll<br />
c:\windows\system32\PortableDeviceTypes.dll<br />
c:\windows\system32\PortableDeviceApi.dll<br />
.<br />
------------------------ Other Running Processes ------------------------<br />
.<br />
c:\program files\Intel\Wireless\Bin\EvtEng.exe<br />
c:\program files\Intel\Wireless\Bin\S24EvMon.exe<br />
c:\windows\system32\brss01a.exe<br />
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
c:\windows\SYSTEM32\astsrv.exe<br />
c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br />
c:\program files\Bonjour\mDNSResponder.exe<br />
c:\windows\system32\crypserv.exe<br />
c:\windows\eHome\ehRecvr.exe<br />
c:\windows\eHome\ehSched.exe<br />
c:\program files\Java\jre6\bin\jqs.exe<br />
c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe<br />
c:\windows\system32\nvsvc32.exe<br />
c:\program files\Intel\Wireless\Bin\RegSrvc.exe<br />
c:\program files\SigmaTel\C-Major Audio\WDM\StacSV.exe<br />
c:\program files\Sony\VAIO Event Service\VESMgr.exe<br />
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe<br />
c:\windows\system32\SearchIndexer.exe<br />
c:\windows\ehome\mcrdsvc.exe<br />
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe<br />
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe<br />
c:\windows\eHome\ehmsas.exe<br />
c:\program files\Apoint\Apntex.exe<br />
c:\program files\Apoint\Apvfb.exe<br />
c:\windows\system32\RUNDLL32.EXE<br />
c:\progra~1\MI3AA1~1\rapimgr.exe<br />
c:\program files\ELWAVE 7.6\rlogapp.exe<br />
c:\windows\system32\SearchProtocolHost.exe<br />
c:\windows\system32\wscntfy.exe<br />
c:\program files\Common Files\PrognosisUDS\esignal.ude<br />
c:\program files\Common Files\PrognosisUDS\FXtrek.ude<br />
c:\program files\Common Files\PrognosisUDS\taipanrt.ude<br />
c:\program files\Common Files\PrognosisUDS\tenfore.ude<br />
c:\windows\system32\dllhost.exe<br />
c:\program files\iPod\bin\iPodService.exe<br />
c:\windows\system32\SearchFilterHost.exe<br />
.<br />
**************************************************  ************************<br />
.<br />
Completion time: 2009-11-09  0:20 - machine was rebooted<br />
ComboFix-quarantined-files.txt  2009-11-09 00:18<br />
<br />
Pre-Run: 53,832,441,856 bytes free<br />
Post-Run: 54,020,829,184 bytes free<br />
<br />
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe<br />
[boot loader]<br />
timeout=2<br />
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOW  S<br />
[operating systems]<br />
c:\cmdcons\BOOTSECT.DAT=&quot;Microsoft Windows Recovery Console&quot; /cmdcons<br />
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS=&quot;Windo  ws XP Media Center Edition&quot; /noexecute=optin /fastdetect<br />
<br />
- - End Of File - - 3A6A1F5A9DD80CFD1F97A0058A37E8C6<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 07:54:22, on 09/11/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br />
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br />
C:\WINDOWS\system32\brsvc01a.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\system32\brss01a.exe<br />
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\WINDOWS\SYSTEM32\astsrv.exe<br />
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\WINDOWS\system32\crypserv.exe<br />
C:\WINDOWS\eHome\ehRecvr.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\eHome\ehSched.exe<br />
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br />
C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe<br />
C:\Program Files\Apoint\Apoint.exe<br />
C:\WINDOWS\ehome\ehtray.exe<br />
C:\WINDOWS\system32\ICO.EXE<br />
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe<br />
C:\Program Files\Sony\ISB Utility\ISBMgr.exe<br />
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe<br />
C:\Program Files\Sony\AppMonUtil\AppMonUtility.exe<br />
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe<br />
C:\WINDOWS\eHome\ehmsas.exe<br />
C:\WINDOWS\system32\RUNDLL32.EXE<br />
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe<br />
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe<br />
C:\WINDOWS\system32\SearchIndexer.exe<br />
C:\Program Files\Microsoft IntelliPoint\ipoint.exe<br />
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe<br />
C:\Program Files\Apoint\Apntex.exe<br />
C:\Program Files\Apoint\Apvfb.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe<br />
C:\Program Files\Messenger\msmsgs.exe<br />
C:\Program Files\Microsoft ActiveSync\wcescomm.exe<br />
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe<br />
C:\Program Files\Common Files\PrognosisUDS\UDS.exe<br />
C:\Program Files\Windows Desktop Search\WindowsSearch.exe<br />
C:\Program Files\ELWAVE 7.6\rlogapp.exe<br />
C:\PROGRA~1\MI3AA1~1\rapimgr.exe<br />
C:\Program Files\Common Files\PrognosisUDS\esignal.ude<br />
C:\Program Files\Common Files\PrognosisUDS\FXtrek.ude<br />
C:\Program Files\Common Files\PrognosisUDS\taipanrt.ude<br />
C:\Program Files\Common Files\PrognosisUDS\tenfore.ude<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\SearchProtocolHost.exe<br />
C:\Documents and Settings\RogerD\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\RogerD\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\RogerD\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
H:\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://news.bbc.co.uk/" target="_blank">BBC NEWS | News Front Page</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">Hotmail, News, Sport, Music, Movies, Money, Cars, Shopping, Windows Live from MSN UK</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">Hotmail, News, Sport, Music, Movies, Money, Cars, Shopping, Windows Live from MSN UK</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int  ernet Settings,ProxyOverride = *.local<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe<br />
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe<br />
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE<br />
O4 - HKLM\..\Run: [VAIOCameraUtility] &quot;C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe&quot;<br />
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe<br />
O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe<br />
O4 - HKLM\..\Run: [AppMon Utility] C:\Program Files\Sony\AppMonUtil\AppMonUtility.exe @@@Start<br />
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe<br />
O4 - HKLM\..\Run: [IntelliPoint] &quot;C:\Program Files\Microsoft IntelliPoint\ipoint.exe&quot;<br />
O4 - HKLM\..\Run: [egui] &quot;C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe&quot; /hide /waitservice<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;D:\Program Files\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKCU\..\Run: [MSMSGS] &quot;C:\Program Files\Messenger\msmsgs.exe&quot; /background<br />
O4 - HKCU\..\Run: [H/PC Connection Agent] &quot;C:\Program Files\Microsoft ActiveSync\wcescomm.exe&quot;<br />
O4 - HKCU\..\Run: [Google Update] &quot;C:\Documents and Settings\RogerD\Local Settings\Application Data\Google\Update\GoogleUpdate.exe&quot; /c<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')<br />
O4 - Global Startup: ELWAVE UDS.lnk = C:\Program Files\Common Files\PrognosisUDS\UDS.exe<br />
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe<br />
O8 - Extra context menu item: Add RSS Support Site to VAIO Information FLOW - C:\Program Files\Sony\VAIO Information FLOW\aiesc.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll<br />
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll<br />
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll<br />
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/en/<br />
O15 - Trusted Zone: *.sony-europe.com<br />
O15 - Trusted Zone: *.sonystyle-europe.com<br />
O15 - Trusted Zone: *.vaio-link.com<br />
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - <a href="http://www.adobe.com/products/acrobat/nos/gp.cab" target="_blank">Adobe - Adobe Acrobat: Create PDF file, edit PDF file, convert PDF to word, convert PDF to doc</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...nt/swflash.cab</a><br />
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - <a href="https://secure.logmein.com/activex/ractrl.cab?lmi=100" target="_blank">https://secure.logmein.com/activex/ractrl.cab?lmi=100</a><br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: AST Service (astcc) -  Advanced Software Technologies - C:\WINDOWS\SYSTEM32\astsrv.exe<br />
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe<br />
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe<br />
O23 - Service: CSIScanner - Unknown owner - C:\Program Files\Prevx\prevx.exe<br />
O23 - Service: FireDaemon Service: ecure (ecure) - Unknown owner - C:\WINDOWS\Temp\FireDaemon.EXE (file missing)<br />
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe<br />
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe<br />
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br />
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe<br />
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br />
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br />
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe<br />
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe<br />
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe<br />
O23 - Service: FireDaemon Service: svchost1 (svchost1) - Unknown owner - C:\WINDOWS\Temp\FireDaemon.EXE (file missing)<br />
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardware  ResourceManager.exe<br />
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe<br />
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe<br />
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe<br />
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe<br />
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe<br />
O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe<br />
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe<br />
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe<br />
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe<br />
<br />
--<br />
End of file - 14037 bytes</div>

]]></content:encoded>
			<category domain="http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/">Spyware, Adware, Viruses and HijackThis Logs</category>
			<dc:creator>roger_g_d</dc:creator>
			<guid isPermaLink="true">http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67072-resolved-cant-open-hjt-hard.html</guid>
		</item>
		<item>
			<title><![CDATA[[Resolved] Alpha antivirus]]></title>
			<link>http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67066-resolved-alpha-antivirus.html</link>
			<pubDate>Sun, 08 Nov 2009 17:09:11 GMT</pubDate>
			<description>Is there a step by step instruction on how to remove Alpha antivirus after you boot PC into safe mode? If so would someone post. I have done a search and come up with nothing on the Malware portion of the site.</description>
			<content:encoded><![CDATA[<div>Is there a step by step instruction on how to remove Alpha antivirus after you boot PC into safe mode? If so would someone post. I have done a search and come up with nothing on the Malware portion of the site.</div>

]]></content:encoded>
			<category domain="http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/">Spyware, Adware, Viruses and HijackThis Logs</category>
			<dc:creator>Katman104</dc:creator>
			<guid isPermaLink="true">http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67066-resolved-alpha-antivirus.html</guid>
		</item>
		<item>
			<title><![CDATA[[Active] Ive still got adware ive tried every thing please help :)]]></title>
			<link>http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67054-active-ive-still-got-adware.html</link>
			<pubDate>Sat, 07 Nov 2009 12:34:26 GMT</pubDate>
			<description><![CDATA[Hiya ive got adware if i open a google link it gives me a random ad page so of which are detected by avg as trying to instal malware or it will open tabs at random when im on a website with ad sites or open a new window on firefox with 10 tabs "saying sorry link not found" and other adsites. 
ive...]]></description>
			<content:encoded><![CDATA[<div>Hiya ive got adware if i open a google link it gives me a random ad page so of which are detected by avg as trying to instal malware or it will open tabs at random when im on a website with ad sites or open a new window on firefox with 10 tabs &quot;saying sorry link not found&quot; and other adsites.<br />
ive deleted my temp files ive scaned with avg, malbytes, spybot and adaware and its still happening.<br />
ive got a hijack this log but no idea what it mean and wondering if anyone could help me<br />
ive also tryed reinstaling firefox.<br />
<br />
:Logfile of Trend Micro HijackThis v2.0.2:<br />
Scan saved at 12:14:43, on 07/11/2009<br />
Platform: Unknown Windows (WinNT 6.01.3504)<br />
MSIE: Internet Explorer v8.00 (8.00.7600.16385)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\taskhost.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe<br />
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe<br />
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe<br />
C:\Program Files\HP\QuickPlay\QPService.exe<br />
C:\Program Files\AVG\AVG8\avgtray.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe<br />
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe<br />
C:\Windows\system32\taskhost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_gb&amp;c=91&amp;bd=Presario&amp;pf=cnnb" target="_blank">AOL.co.uk</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_gb&amp;c=91&amp;bd=Presario&amp;pf=cnnb" target="_blank">AOL.co.uk</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_gb&amp;c=91&amp;bd=Presario&amp;pf=cnnb" target="_blank">AOL.co.uk</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_gb&amp;c=91&amp;bd=Presario&amp;pf=cnnb" target="_blank">AOL.co.uk</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int  ernet Settings,ProxyOverride = local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (file missing)<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (file missing)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (file missing)<br />
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (file missing)<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe<br />
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe<br />
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start<br />
O4 - HKLM\..\Run: [QPService] &quot;C:\Program Files\HP\QuickPlay\QPService.exe&quot;<br />
O4 - HKLM\..\Run: [UCam_Menu] &quot;C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.ex  e&quot; &quot;C:\Program Files\CyberLink\YouCam&quot; update &quot;Software\CyberLink\YouCam\2.0&quot;<br />
O4 - HKLM\..\Run: [UpdateLBPShortCut] &quot;C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMen  u.exe&quot; &quot;C:\Program Files\CyberLink\LabelPrint&quot; UpdateWithCreateOnce &quot;Software\CyberLink\LabelPrint\2.5&quot;<br />
O4 - HKLM\..\Run: [UpdateP2GoShortCut] &quot;C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.  exe&quot; &quot;C:\Program Files\CyberLink\Power2Go&quot; UpdateWithCreateOnce &quot;SOFTWARE\CyberLink\Power2Go\6.0&quot;<br />
O4 - HKLM\..\Run: [UpdatePDIRShortCut] &quot;C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStart  Menu.exe&quot; &quot;C:\Program Files\CyberLink\PowerDirector&quot; UpdateWithCreateOnce &quot;SOFTWARE\CyberLink\PowerDirector\7.0&quot;<br />
O4 - HKLM\..\Run: [UpdatePSTShortCut] &quot;C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe&quot; &quot;C:\Program Files\CyberLink\DVD Suite&quot; UpdateWithCreateOnce &quot;Software\CyberLink\PowerStarter&quot;<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [PC Alarm Clock] C:\Program Files\PC Alarm Clock\pcalarmclock.exe<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden<br />
O4 - HKCU\..\Run: [msnmsgr] &quot;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&quot; /background<br />
O4 - HKCU\..\Run: [uTorrent] &quot;C:\Program Files\uTorrent\uTorrent.exe&quot;<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O8 - Extra context menu item: &amp;AOL Toolbar Search - C:\ProgramData\AOL\ieToolbar\resources\en-GB\local\search.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL<br />
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - <a href="http://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab" target="_blank">http://messenger.zone.msn.com/Messen.../GAME_UNO1.cab</a><br />
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - <a href="http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab" target="_blank">http://messenger.zone.msn.com/binary...t.cab56907.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG8\avgemc.exe<br />
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe<br />
O23 - Service: GameConsoleService - Unknown owner - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe (file missing)<br />
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe<br />
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe<br />
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe<br />
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe<br />
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe<br />
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search &amp; Destroy\SDWinSec.exe<br />
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe<br />
<br />
--<br />
End of file - 10619 bytes<br />
<br />
Any help would be so much apreciated but i dont reli wanna use combofix thanks guys.</div>

]]></content:encoded>
			<category domain="http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/">Spyware, Adware, Viruses and HijackThis Logs</category>
			<dc:creator>superbloom</dc:creator>
			<guid isPermaLink="true">http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67054-active-ive-still-got-adware.html</guid>
		</item>
		<item>
			<title><![CDATA[[Active] Google, redirection (Firefox)]]></title>
			<link>http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67053-active-google-redirection-firefox.html</link>
			<pubDate>Fri, 06 Nov 2009 13:57:37 GMT</pubDate>
			<description>Hi, 
I ran Avast 4.8 a few days ago....The scan was telling me that a got a virus in 2 files. I deleted those two files. 
But when I use google (browser: Firefox) for research, I am redirected to other sites. 
Here is my Hijackthis Log.  
 
ogfile of Trend Micro HijackThis v2.0.2 
Scan saved at...</description>
			<content:encoded><![CDATA[<div>Hi,<br />
I ran Avast 4.8 a few days ago....The scan was telling me that a got a virus in 2 files. I deleted those two files.<br />
But when I use google (browser: Firefox) for research, I am redirected to other sites.<br />
Here is my Hijackthis Log. <br />
<br />
ogfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 08:49:58, on 2009-11-06<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18828)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\RtHDVCpl.exe<br />
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe<br />
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe<br />
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe<br />
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe<br />
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe<br />
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe<br />
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe<br />
C:\Program Files\ltmoh\ltmoh.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe<br />
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe<br />
C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe<br />
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Alwil Software\Avast4\ashDisp.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\Protector Suite QL\psqltray.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe<br />
C:\Program Files\Logitech\SetPoint\SetPoint.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Program Files\Synaptics\SynTP\SynToshiba.exe<br />
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.shoptoshiba.ca/welcome" target="_blank">AOL.ca - Canada's Breaking News, Entertainment, Music, Life &amp; Style and Email</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">Hotmail, News, Sport, Music, Movies, Money, Cars, Shopping, Windows Live from MSN UK</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">Hotmail, News, Sport, Music, Movies, Money, Cars, Shopping, Windows Live from MSN UK</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll<br />
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O3 - Toolbar: &amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br />
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe<br />
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe<br />
O4 - HKLM\..\Run: [HWSetup] \HWSetup.exe hwSetUP<br />
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL<br />
O4 - HKLM\..\Run: [Camera Assistant Software] &quot;C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe&quot;<br />
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE<br />
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe<br />
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe<br />
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe<br />
O4 - HKLM\..\Run: [PSQLLauncher] &quot;C:\Program Files\Protector Suite QL\launcher.exe&quot; /startup<br />
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [OneCareUI] &quot;C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe&quot;<br />
O4 - HKLM\..\Run: [GrooveMonitor] &quot;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&quot;<br />
O4 - HKLM\..\Run: [SSBkgdUpdate] &quot;C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe&quot; -Embedding -boot<br />
O4 - HKLM\..\Run: [OpwareSE4] &quot;C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Skytel] Skytel.exe<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe<br />
O4 - HKCU\..\Run: [msnmsgr] &quot;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&quot; /background<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKCU\..\Run: [Gestionnaire Antidote.exe] C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-18\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe (User 'Default user')<br />
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe<br />
O8 - Extra context menu item: &amp;D&amp;ownload &amp;with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm<br />
O8 - Extra context menu item: &amp;D&amp;ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm<br />
O8 - Extra context menu item: &amp;D&amp;ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll/206 (file missing)<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll<br />
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe<br />
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe<br />
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br />
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe<br />
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe<br />
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br />
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search &amp; Destroy\SDWinSec.exe<br />
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe<br />
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe<br />
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe<br />
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe<br />
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe<br />
<br />
--<br />
End of file - 11785 bytes</div>

]]></content:encoded>
			<category domain="http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/">Spyware, Adware, Viruses and HijackThis Logs</category>
			<dc:creator>Libe</dc:creator>
			<guid isPermaLink="true">http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67053-active-google-redirection-firefox.html</guid>
		</item>
		<item>
			<title><![CDATA[[Active] Another System32/Drivers/Files overload...]]></title>
			<link>http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67044-active-another-system32-drivers-files.html</link>
			<pubDate>Thu, 05 Nov 2009 15:39:10 GMT</pubDate>
			<description>A seldom used (but fairly important) computer at my office recently had some virus issues and then the hard drive got plugged up and is now showing 13gb of files in the system32/drivers/files folder and since this is an old machine, is really affecting performance.   
 
Ran Hijackthis and my log is...</description>
			<content:encoded><![CDATA[<div>A seldom used (but fairly important) computer at my office recently had some virus issues and then the hard drive got plugged up and is now showing 13gb of files in the system32/drivers/files folder and since this is an old machine, is really affecting performance.  <br />
<br />
Ran Hijackthis and my log is attached (from other threads I couldn't identify specific malware from my log)<br />
<br />
It seems the process for this issue's resolution is relatively the same, I just need to know where I start - particularly with the malware.  Any help is greatly appreciated.<br />
<br />
Thanks!</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.d-a-l.com/help/images/styles/dal/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.d-a-l.com/help/attachments/spyware-adware-viruses-hijackthis-logs/2221d1257435537-active-another-system32-drivers-files-hijackthis.txt">hijackthis.txt</a> (10.0 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/">Spyware, Adware, Viruses and HijackThis Logs</category>
			<dc:creator>adamnldt</dc:creator>
			<guid isPermaLink="true">http://www.d-a-l.com/help/spyware-adware-viruses-hijackthis-logs/67044-active-another-system32-drivers-files.html</guid>
		</item>
	</channel>
</rss>
