<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Spyware &amp; Virus Removal — Icrontic</title>
        <link>https://icrontic.com/</link>
        <pubDate>Thu, 11 Jun 2026 06:53:56 +0000</pubDate>
        <language>en</language>
            <description>Spyware &amp; Virus Removal — Icrontic</description>
    <atom:link href="https://icrontic.com/categories/spyware-virus-removal-c/p5/feed.rss" rel="self" type="application/rss+xml"/>
    <item>
        <title>System Locked - win.worm32.netsky</title>
        <link>https://icrontic.com/discussion/88030/system-locked-win-worm32-netsky</link>
        <pubDate>Sat, 30 Jan 2010 15:25:35 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator></dc:creator>
        <guid isPermaLink="false">88030@/discussions</guid>
        <description><![CDATA[My 75-year-old mother's computer is hosed and I've been put in charge of fixing it.<br /><br />
It runs Windows XP Home and has 2GB memory<br /><br />
When I got the computer, it had a ton Porn site icon/shortcuts on the desktop, and I can assure you that they got there through some malware -- and not from my mother. Although, she did have some idiot living there for a little while -- and he may have been trolling porn sites.<br /><br />
When I start the computer it comes up with a message saying that the computer is infected with win.worm32.netsky and to run a virus scan. I'm then presented with a window saying that McAffee hasn't been updated in over 7 days -- and asks if I want to check for updates. I indicate no, because I'm not going to hook this computer to my network for Internet access in its current state. I then get a black box with red/white/blue text telling me that the system has been shut down. Nothing short of pressing the power button will do anything at this point. Ctrl/Alt/Del will not work, nor does clicking on anything.<br /><br />
Rebooting in Safe Mode gets me the blue screen of death, and the message:<br /><br />
STOP: 0x0000007E (0x0000005, 0x805331C, 0xF7A2A504, 0xF7A2A200)<br /><br />
I've read a million fixes on the Internet -- but this computer is dead in the water and I'm unable to perform any steps requiring keyboard or mouse interaction.<br /><br />
To further complicate -- I wasn't given the XP Home disk or the password, and actually don't think there even is a admin password as Startup skipped by a login screen and went to a desk top.<br /><br />
I'm thinking that I'm going to need a boot disk of some type that can unhose this puter. I'm at a loss as to what to do from here and need a Major Geek to advise me.]]>
        </description>
    </item>
    <item>
        <title>Nexplore and other popups virus</title>
        <link>https://icrontic.com/discussion/88027/nexplore-and-other-popups-virus</link>
        <pubDate>Sat, 30 Jan 2010 12:15:25 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator></dc:creator>
        <guid isPermaLink="false">88027@/discussions</guid>
        <description><![CDATA[Hi all,<br /><br />
It appears that I've got what I see that many others here have come for.  I use Google Chrome pretty much exclusively and every few minutes I get a popup for any of a variety of different ads.  This includes a NeXplore ad among others.  Here is my HijackThis logfile.  Any help would be appreciated, and thanks.<br /><br />
Logfile of Trend Micro HijackThis v2.0.3 (BETA)<br />
Scan saved at 12:03:22 PM, on 1/30/2010<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18882)<br />
Boot mode: Normal<br /><br />
Running processes:<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
D:\Utilities\Avira\AntiVir Desktop\avgnt.exe<br />
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe<br />
D:\Applications\iTunes\iTunesHelper.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
D:\Utilities\DAEMON Tools Lite\daemon.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe<br />
D:\Applications\Thunderbird\thunderbird.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br />
C:\Windows\system32\conime.exe<br />
C:\Users\Bjorn\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Bjorn\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Bjorn\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Bjorn\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Bjorn\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Bjorn\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Users\Bjorn\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Users\Bjorn\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br /><br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [avgnt] "D:\Utilities\Avira\AntiVir Desktop\avgnt.exe" /min<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"<br />
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br />
O4 - HKLM\..\Run: [pdfFactory Pro Dispatcher v3] "C:\Windows\system32\spool\DRIVERS\W32X86\3\fppdis3a.exe" /source=HKLM<br />
O4 - HKLM\..\Run: [iTunesHelper] "D:\Applications\iTunes\iTunesHelper.exe"<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"<br />
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [lepanutul] Rundll32.exe "c:\windows\system32\gotekonu.dll",a<br />
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [Steam] "d:\applications\steam\steam.exe" -silent<br />
O4 - HKCU\..\Run: [Google Update] "C:\Users\Bjorn\AppData\Local\Google\Update\GoogleUpdate.exe" /c<br />
O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\Utilities\DAEMON Tools Lite\daemon.exe" -autorun<br />
O4 - HKCU\..\RunOnce: [JavaInstallRetry] "C:\Users\Bjorn\AppData\LocalLow\Sun\Java\JRERunOnce.exe" RUNONCE=1 SPONSORS=0<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O13 - Gopher Prefix:<br />
O15 - Trusted Zone: <a href="http://asia.msi.com.tw" rel="nofollow">http://asia.msi.com.tw</a><br />
O15 - Trusted Zone: <a href="http://global.msi.com.tw" rel="nofollow">http://global.msi.com.tw</a><br />
O15 - Trusted Zone: <a href="http://www.msi.com.tw" rel="nofollow">http://www.msi.com.tw</a><br />
O15 - ESC Trusted Zone: <a href="http://*.update.microsoft.com" rel="nofollow">http://*.update.microsoft.com</a><br />
O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - <a href="http://liveupdate.msi.com.tw/autobios/LOnline/install.cab" rel="nofollow">http://liveupdate.msi.com.tw/autobios/LOnline/install.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" rel="nofollow">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O20 - AppInit_DLLs: resiyefu.dll c:\windows\system32\gotekonu.dll<br />
O21 - SSODL: sevayigan - {152cd40d-549b-4159-8eb6-050f97504c08} - c:\windows\system32\gotekonu.dll<br />
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll<br />
O22 - SharedTaskScheduler: mujuzedij - {152cd40d-549b-4159-8eb6-050f97504c08} - c:\windows\system32\gotekonu.dll<br />
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - D:\Utilities\Avira\AntiVir Desktop\sched.exe<br />
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - D:\Utilities\Avira\AntiVir Desktop\avguard.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - d:\applications\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe<br />
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe<br />
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe<br />
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe<br /><br />
--<br />
End of file - 6491 bytes]]>
        </description>
    </item>
    <item>
        <title>Nexplore popups + disabled malwarebytes</title>
        <link>https://icrontic.com/discussion/88022/nexplore-popups-disabled-malwarebytes</link>
        <pubDate>Fri, 29 Jan 2010 22:53:08 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator></dc:creator>
        <guid isPermaLink="false">88022@/discussions</guid>
        <description><![CDATA[Today i began receiving popups on Firefox that displayed what looked like a Nexplore advertisement, when i try to close the window, all of my currently opened windows and tabs close and one window pops up which says that my computer is at risk + other stuff, the only option was to press OK so i opened up the task manager to end firefox.exe. Then i restarted firefox and did a google search for " nexplore popup" and learned that the spyware/malware cause malwarebytes to be disabled. The malwarebytes icon was still in the taskbar, i clicked on it but nothing happened so i tried to open mbam.exe, but a window popped up and said that the file/shortcut was not found. So i googled for a fix to this problem and followed some steps on a tech forum involving combofix and a cfscript.txt, it deleted 3 files, which was really stupid of me since i just learned a few minutes ago that the cfscript is meant only for that certain persons computer- but i still have the logs that combofix made after deleting those files and the cfscript that i used. This didnt fix the disabled malwarebytes, but it might have stopped the popups from "popping" , im not sure because im currently on the administrator account- the user i was on initially was didn't have access to administrator rights. Any help or suggestions would be greatly appreciated, thank you.<br /><br />
edit: update: Apparently the cfscript+combofix that i used disabled the spywares ability to stop malwarebytes from running on startup, malwarebytes is running as usual but i cannot access mbam.exe still because it's missing - i still get popups but they are blank thanx to malwarebytes ip-block feature<br /><br /><br />
Logfile of Trend Micro HijackThis v2.0.3 (BETA)<br />
Scan saved at 7:36:40 PM, on 1/29/2010<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16945)<br />
Boot mode: Normal<br /><br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
D:\Program Files\Alwil Software\Avast5\AvastSvc.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
D:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe<br />
C:\Program Files\Google\Update\1.2.183.13\GoogleCrashHandler.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\WINDOWS\SOUNDMAN.EXE<br />
D:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\WINDOWS\explorer.exe<br />
D:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\WINDOWS\system32\msiexec.exe<br />
D:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe<br /><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.symantec.com/enterprise/security_response/index.jsp" rel="nofollow">http://www.symantec.com/enterprise/security_response/index.jsp</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\Program Files\RealPlayer\rpbrowserrecordplugin.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.33.0\gears.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br />
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "D:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [avast5] D:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui<br />
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - AutorunsDisabled - (no file)<br />
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.33.0\gears.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.33.0\gears.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: <a href="https://icrontic.com/profile/xpsp3res" rel="nofollow">@xpsp3res</a>.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - <a href="http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab" rel="nofollow">http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab</a><br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a href="http://go.microsoft.com/fwlink/?LinkID=39204" rel="nofollow">http://go.microsoft.com/fwlink/?LinkID=39204</a><br />
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - <a href="http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab" rel="nofollow">http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1159074557359" rel="nofollow">http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1159074557359</a><br />
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - <a href="http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab" rel="nofollow">http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab</a><br />
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - <a href="http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab" rel="nofollow">http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab</a><br />
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll<br />
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll<br />
O23 - Service: avast! Antivirus - ALWIL Software - D:\Program Files\Alwil Software\Avast5\AvastSvc.exe<br />
O23 - Service: avast! Mail Scanner - ALWIL Software - D:\Program Files\Alwil Software\Avast5\AvastSvc.exe<br />
O23 - Service: avast! Web Scanner - ALWIL Software - D:\Program Files\Alwil Software\Avast5\AvastSvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Google Update Service (gupdate1c972cbf5adb7a0) (gupdate1c972cbf5adb7a0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: MBAMService - Malwarebytes Corporation - D:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe<br />
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe<br /><br />
--<br />
End of file - 7146 bytes]]>
        </description>
    </item>
    <item>
        <title>Acebot/Dr Watson Freezing My External Hard Drive</title>
        <link>https://icrontic.com/discussion/87589/acebot-dr-watson-freezing-my-external-hard-drive</link>
        <pubDate>Sat, 09 Jan 2010 02:55:07 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator></dc:creator>
        <guid isPermaLink="false">87589@/discussions</guid>
        <description><![CDATA[For the past few days whenever I try to access my external hard drive, after a few seconds I get the 'Windows Explorer has encountered a problem' message. So after I click Don't Send, I soon get the 'DrWatson Postmortem Debugger' error. Once I click Don't Send for this, my external hard drive folder freezes. Sometimes though it freezes after the Windows Explorer error, and the DrWatson thing doesn't show up... Maybe it only happens once for each time I turn on the computer... Once it freezes, all my other programs and windows still work, and I'm able to move the cursor, but I can't click anything. I have to open Windows Task Manager and End Task on the drive to get everything functioning again. I ran a scan using avast! on both the internal and external hard drive, but it didn't turn anything up. Looking it up online, from what I can tell I think this is the Acebot trojan.<br /><br />
I downloaded HijackThis and made a log:<br /><br />
Logfile of Trend Micro HijackThis v2.0.3 (BETA)<br />
Scan saved at 8:26:59 PM, on 1/8/2010<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br /><br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br />
C:\Program Files\Common Files\AOL\1219278719\ee\AOLSoftware.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe<br />
C:\WINDOWS\system32\Rundll32.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
C:\Program Files\MSI\Live Update 3\LMonitor.exe<br />
C:\WINDOWS\system32\RUNDLL32.EXE<br />
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
C:\Program Files\Common Files\RPEX\RPEXUpdate.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe<br />
C:\Program Files\DNA\btdna.exe<br />
C:\Program Files\AIM6\aim6.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\Documents and Settings\Jonathan\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Program Files\OpenOffice.org 3\program\soffice.exe<br />
C:\Program Files\OpenOffice.org 3\program\soffice.bin<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\AIM6\aolsoftware.exe<br />
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\WINDOWS\system32\CTsvcCDA.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe<br />
C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe<br /><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll<br />
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll<br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx<br />
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll<br />
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll<br />
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll<br />
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll<br />
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup<br />
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start<br />
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe<br />
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot<br />
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1219278719\ee\AOLSoftware.exe<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br />
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r<br />
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper<br />
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br />
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"<br />
O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe<br />
O4 - HKLM\..\Run: [RPEX Video Codec Automatic Update] C:\Program Files\Common Files\RPEX\RPEXUpdate.exe /auto<br />
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br />
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden<br />
O4 - HKCU\..\Run: [DLD.EXE] C:\Program Files\Download Direct\DLD.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet<br />
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"<br />
O4 - HKCU\..\Run: [Desktop Software] "C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe"  /ini "uinstaller.ini" /fromrun /starthidden<br />
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp<br />
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h<br />
O4 - HKCU\..\Run: [Vidalia] "C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe"<br />
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background<br />
O4 - HKCU\..\Run: [SansaDispatch] C:\Documents and Settings\Jonathan\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe<br />
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O8 - Extra context menu item: &amp;AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html<br />
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll<br />
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll<br />
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll<br />
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - <a href="http://go.divx.com/plugin/DivXBrowserPlugin.cab" rel="nofollow">http://go.divx.com/plugin/DivXBrowserPlugin.cab</a><br />
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -<br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" rel="nofollow">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll<br />
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll<br />
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br /><br />
--<br />
End of file - 11821 bytes]]>
        </description>
    </item>
    <item>
        <title>Trojan Help!  VirTool:Win32/ursnif.A detected</title>
        <link>https://icrontic.com/discussion/88021/trojan-help-virtool-win32-ursnif-a-detected</link>
        <pubDate>Fri, 29 Jan 2010 21:14:43 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator></dc:creator>
        <guid isPermaLink="false">88021@/discussions</guid>
        <description><![CDATA[My computer was running slow, so I decided to download Windows Defender to protect it and MSE to scan for any malicious software and protect from further infections.  It found this trojan and keeps trying to fix it and it keeps popping up that it needs to "restart" and after I do, it finds it again.  Help Please!  My thanks in advance!  <img src="https://icrontic.com/resources/icrontimoji/grumble.gif" title=":grumble:" alt=":grumble:" />]]>
        </description>
    </item>
    <item>
        <title>ad.reduxmedia.com taken over internet explorer</title>
        <link>https://icrontic.com/discussion/88002/ad-reduxmedia-com-taken-over-internet-explorer</link>
        <pubDate>Fri, 29 Jan 2010 12:21:14 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator></dc:creator>
        <guid isPermaLink="false">88002@/discussions</guid>
        <description><![CDATA[Internet explorer has started opening on its own and ad.reduxmedia.com is the homepage. Firefox is my default browser and the computer hasn't seemed any slower but is very irritating. Any help would be appreciated. Here is my hijackthis log<br /><br />
Logfile of Trend Micro HijackThis v2.0.3 (BETA)<br />
Scan saved at 17:13:20, on 29/01/2010<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18882)<br />
Boot mode: Normal<br /><br />
Running processes:<br />
C:\Windows\system32\taskeng.exe<br />
C:\Program Files\Spyware Doctor\pctsTray.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Users\Dan\AppData\Local\Temp\Opj.exe<br />
C:\Windows\RtHDVCpl.exe<br />
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe<br />
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe<br />
C:\Program Files\AVG\AVG8\avgtray.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Common Files\Java\Java Update\jusched.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe<br />
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE<br />
C:\Program Files\Steam\steam.exe<br />
C:\Users\Dan\Downloads\utorrent(4).exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE<br />
C:\Users\Dan\AppData\Local\Temp\Opk.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Windows\system32\ctfmon.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe<br />
C:\Program Files\Windows Live\Contacts\wlcomm.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\AVG\AVG8\avgui.exe<br />
C:\Program Files\AVG\AVG8\avgscanx.exe<br />
C:\Program Files\AVG\AVG8\avgscanx.exe<br />
C:\Program Files\AVG\AVG8\avgcsrvx.exe<br />
C:\Program Files\AVG\AVG8\avgcsrvx.exe<br />
C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe<br />
C:\Windows\system32\rundll32.exe<br /><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\<a href="www.pcspecialist.co.uk" rel="nofollow">www.pcspecialist.co.uk</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://www.crawler.com/search/dispatcher.aspx?tp=aus&amp;qkw=%s&amp;tbid=61008" rel="nofollow">http://www.crawler.com/search/dispatcher.aspx?tp=aus&amp;qkw=%s&amp;tbid=61008</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://uk.ask.com?o=15153&amp;l=dis" rel="nofollow">http://uk.ask.com?o=15153&amp;l=dis</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\<a href="www.pcspecialist.co.uk" rel="nofollow">www.pcspecialist.co.uk</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =<br />
R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb128\SearchSettings.dll<br />
O2 - BHO: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll<br />
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll<br />
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll<br />
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb128\SearchSettings.dll<br />
O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll<br />
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll<br />
O3 - Toolbar: &amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O3 - Toolbar: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll<br />
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br />
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"<br />
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br />
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe<br />
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br />
O4 - HKLM\..\Run: [Skytel] Skytel.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"<br />
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"<br />
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background<br />
O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"<br />
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Dan\Downloads\utorrent(4).exe"<br />
O4 - HKCU\..\Run: [BMIMZMHMFM] C:\Users\Dan\AppData\Local\Temp\Opk.exe<br />
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE<br />
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll<br />
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O13 - Gopher Prefix:<br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll<br />
O20 - AppInit_DLLs: avgrsstx.dll<br />
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL<br />
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe<br />
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - C:\Program Files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe<br />
O23 - Service: Google Update Service (gupdate1c9d940299c3d4d) (gupdate1c9d940299c3d4d) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe<br />
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe<br />
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe<br />
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe<br />
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe<br />
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe<br /><br />
--<br />
End of file - 11659 bytes]]>
        </description>
    </item>
    <item>
        <title>Lots of popups, computer running very slowly</title>
        <link>https://icrontic.com/discussion/88000/lots-of-popups-computer-running-very-slowly</link>
        <pubDate>Fri, 29 Jan 2010 12:05:33 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator></dc:creator>
        <guid isPermaLink="false">88000@/discussions</guid>
        <description><![CDATA[I have been having a big popup problem lately, full screen popups for nexplore, webfetti, full sail university, surveys for whatever site I am on, etc.  Also, my computer is running much, much slower than usual.  Programs are freezing or not minimizing.  I am not a very computer literate person, so if someone will help, please keep it simple.  I have followed the instructions at the top of the forum for creating a hijackthis log.  I would appreciate any help that comes my way.<br /><br />
Logfile of Trend Micro HijackThis v2.0.3 (BETA)<br />
Scan saved at 10:59:27 AM, on 1/29/2010<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br />
Boot mode: Normal<br /><br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\csrss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\ehome\ehtray.exe<br />
C:\Program Files\Digital Media Reader\shwiconem.exe<br />
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe<br />
C:\WINDOWS\zHotkey.exe<br />
C:\WINDOWS\SOUNDMAN.EXE<br />
C:\WINDOWS\ALCWZRD.EXE<br />
C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe<br />
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe<br />
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\WINDOWS\system32\igfxtray.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\Program Files\Lexmark 3100 Series\lxbrbmon.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\Program Files\Spyware Doctor\pctsTray.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Messenger\msmsgs.exe<br />
C:\WINDOWS\system32\LEXBCES.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\system32\LEXPPS.EXE<br />
C:\Program Files\BigFix\BigFix.exe<br />
C:\Program Files\palmOne\Hotsync.exe<br />
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\a-squared Anti-Malware\a2service.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe<br />
C:\WINDOWS\eHome\ehRecvr.exe<br />
C:\WINDOWS\eHome\ehSched.exe<br />
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe<br />
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS<br />
C:\Program Files\Spyware Doctor\pctsAuxs.exe<br />
C:\Program Files\Spyware Doctor\pctsSvc.exe<br />
C:\Program Files\SolidDocuments\SolidPDFCreator\SPC\SolidPdfService.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe<br />
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe<br />
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe<br />
C:\Program Files\Spyware Doctor\pctsTray.exe<br />
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\WINDOWS\System32\alg.exe<br />
C:\WINDOWS\eHome\ehmsas.exe<br />
C:\Program Files\Java\jre1.5.0_07\bin\jucheck.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\WINDOWS\system32\msiexec.exe<br />
C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe<br />
C:\WINDOWS\system32\wbem\wmiprvse.exe<br /><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="www.google.com" rel="nofollow">www.google.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://www.gatewaybiz.com" rel="nofollow">http://www.gatewaybiz.com</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = <a href="http://search.yahoo.com/search?fr=mcafee&amp;p=%s" rel="nofollow">http://search.yahoo.com/search?fr=mcafee&amp;p=%s</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O1 - Hosts: ::1 localhost<br />
O1 - Hosts: 91.212.65.127 spywareprotector-2009.com<br />
O1 - Hosts: 91.212.65.127 <a href="www.spywareprotector-2009.com" rel="nofollow">www.spywareprotector-2009.com</a><br />
O1 - Hosts: 91.212.65.127 secure.spywareprotector-2009.com<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll<br />
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll<br />
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe<br />
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE<br />
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe<br />
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"<br />
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br />
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe<br />
O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe<br />
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe<br />
O4 - HKLM\..\Run: [Mixersel] C:\Program Files\Realtek\InstallShield\mixersel.exe<br />
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br />
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE<br />
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br />
O4 - HKLM\..\Run: [Lexmark 3100 Series] "C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe"<br />
O4 - HKLM\..\Run: [LXBRKsk] C:\PROGRA~1\LEXMAR~1\LXBRKsk.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe<br />
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br />
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe" /d=60<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br />
O4 - HKLM\..\Run: [hokodumub] Rundll32.exe "c:\windows\system32\kozotifa.dll",a<br />
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes Anti-Malware\mbamgui.exe /install /silent<br />
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br />
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl<br />
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent<br />
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H<br />
O4 - Startup: palmOne Registration.lnk = C:\Program Files\palmOne\register.exe<br />
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe<br />
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe<br />
O4 - Global Startup: Adobe Gamma Loader.lnk = ?<br />
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br />
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe<br />
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe<br />
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O20 - AppInit_DLLs: c:\windows\system32\kozotifa.dll,loguteyu.dll<br />
O21 - SSODL: sanohidim - {c81321cd-a441-42bd-bdfe-1d8df3374aa0} - c:\windows\system32\kozotifa.dll<br />
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll<br />
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll<br />
O22 - SharedTaskScheduler: tokatiluy - {c81321cd-a441-42bd-bdfe-1d8df3374aa0} - c:\windows\system32\kozotifa.dll<br />
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE<br />
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe<br />
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS<br />
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe<br />
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe<br />
O23 - Service: SolidPDFCreatorReadSpool (SdReadSpool) - Solid Documents, LLC - C:\Program Files\SolidDocuments\SolidPDFCreator\SPC\SolidPdfService.exe<br />
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe<br />
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)<br />
O23 - Service: WUSB54GCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe<br /><br />
--<br />
End of file - 11512 bytes<br /><br /><br />
Thanks in advance,<br />
Ryan]]>
        </description>
    </item>
    <item>
        <title>adware popups and possible slowdown</title>
        <link>https://icrontic.com/discussion/87995/adware-popups-and-possible-slowdown</link>
        <pubDate>Fri, 29 Jan 2010 10:34:23 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator></dc:creator>
        <guid isPermaLink="false">87995@/discussions</guid>
        <description><![CDATA[A few days ago I downloaded something from a suspect site and my virus scanner (AVG free) registered it as a threat.  I deleted it right away but a while later I started getting weird popups every time a browser window was open.  My computer also seems to be slowing down with some actions but not all.  I've since scanned the computer again with AVG.  It found upwards of 15 files, mostly .dll's, that were of the type "Vundo.KC","Vundo.KE", or "KillAV.AC".  All attempts to remove these with AVG seem to do nothing.  Here is my HJT log:<br /><br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 10:23:37 AM, on 1/29/2010<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br />
Boot mode: Normal<br /><br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Alias\Maya7.0\docs\wrapper.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\Program Files\Alias\Maya7.0\docs\jre\bin\java.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe<br />
C:\WINDOWS\system32\Wacom_Tablet.exe<br />
C:\WINDOWS\System32\ups.exe<br />
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\AVG\AVG9\avgemc.exe<br />
C:\WINDOWS\system32\WTablet\Wacom_TabletUser.exe<br />
C:\WINDOWS\system32\Wacom_Tablet.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\WINDOWS\System32\nvraidservice.exe<br />
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe<br />
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe<br />
C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe<br />
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe<br />
C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe<br />
C:\Program Files\Trend Micro\Internet Security\TmPfw.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\Program Files\Trend Micro\BM\TMBMSRV.exe<br /><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common<br /><br />
Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program<br /><br />
Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: Trend Micro Toolbar BHO - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend<br /><br />
Micro\TrendSecure\TISProToolbar\TSToolbar.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)<br />
O3 - Toolbar: Trend Micro Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend<br /><br />
Micro\TrendSecure\TISProToolbar\TSToolbar.dll<br />
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\System32\nvraidservice.exe<br />
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"<br />
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [muBlinder] C:\Documents and Settings\Ed\Desktop\etc. and downloads\muBlinder.exe -startup<br />
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win<br />
O4 - HKUS\S-1-5-21-436374069-1343024091-839522115-1003\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM<br /><br />
XP Pro\FreeRAM XP Pro.exe" -win (User '?')<br />
O4 - S-1-5-21-436374069-1343024091-839522115-1003 Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe (User<br /><br />
'?')<br />
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program<br /><br />
Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program<br /><br />
Files\Messenger\msmsgs.exe<br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -<br /><br /><a href="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1158356849130" rel="nofollow">http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1158356849130</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -<br /><br /><a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1158365573874" rel="nofollow">http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1158365573874</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O18 - Protocol: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend<br /><br />
Micro\TrendSecure\TISProToolbar\TSToolbar.dll<br />
O20 - AppInit_DLLs: gademoma.dll c:\windows\system32\jevojosa.dll c:\windows\system32\verazemi.dll<br /><br />
c:\windows\system32\kegawapi.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O21 - SSODL: layilutih - {dcac5dfd-2d31-457c-88b9-7b3ace480ff1} - c:\windows\system32\verazemi.dll (file missing)<br />
O21 - SSODL: mihivonin - {eb2baf21-e501-43cc-9e11-b2853ab608ca} - c:\windows\system32\verazemi.dll (file missing)<br />
O21 - SSODL: wizewuvul - {2534f03b-4504-4526-ad01-acc2359d0cf1} - c:\windows\system32\kegawapi.dll (file missing)<br />
O22 - SharedTaskScheduler: tokatiluy - {dcac5dfd-2d31-457c-88b9-7b3ace480ff1} - c:\windows\system32\verazemi.dll (file<br /><br />
missing)<br />
O22 - SharedTaskScheduler: gahurihor - {eb2baf21-e501-43cc-9e11-b2853ab608ca} - c:\windows\system32\verazemi.dll (file<br /><br />
missing)<br />
O22 - SharedTaskScheduler: gahurihor - {2534f03b-4504-4526-ad01-acc2359d0cf1} - c:\windows\system32\kegawapi.dll (file<br /><br />
missing)<br />
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program<br /><br />
Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision<br /><br />
Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common<br /><br />
Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
O23 - Service: License Management Service ESD - element5 - C:\Program Files\Common Files\element5 Shared\Service\Licence<br /><br />
Manager ESD.exe<br />
O23 - Service: Maya 7.0 Documentation Server (maya70docserver) - Unknown owner - C:\Program<br /><br />
Files\Alias\Maya7.0\docs\wrapper.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet<br /><br />
Security\SfCtlCom.exe<br />
O23 - Service: TabletServiceWacom - Wacom Technology, Corp. - C:\WINDOWS\system32\Wacom_Tablet.exe<br />
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend<br /><br />
Micro\BM\TMBMSRV.exe<br />
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet<br /><br />
Security\TmPfw.exe<br />
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet<br /><br />
Security\TmProxy.exe<br /><br />
--<br />
End of file - 8004 bytes]]>
        </description>
    </item>
    <item>
        <title>Unable to boot PC (no HJT log). Dr Watson/Acebot?</title>
        <link>https://icrontic.com/discussion/87978/unable-to-boot-pc-no-hjt-log-dr-watson-acebot</link>
        <pubDate>Thu, 28 Jan 2010 04:14:58 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator></dc:creator>
        <guid isPermaLink="false">87978@/discussions</guid>
        <description><![CDATA[I should start by apologizing for not providing the HJT log, but the computer will not boot. Also, since I'm not exactly PC savvy thanks in advance for having patience.<br /><br />
The problem started when a downloaded file was opened and a message, saying something to the effect of "Dr Watson postmortem error", popped up. The computer froze, the user got frustrated and then tried to preform a hard reboot to fix it. Now the PC will not boot in any mode. (normal, safe, safe w/net, safe w/command prompt, or last successful config(?)) It gets as far as the Windows logo and then reboots itself back to the mode prompt. I may be missing some details about the way it happened; I was not the user at the time. The user who made this mess has panicked and gone into hiding. The above was all I could get out of her.<br /><br />
I've stopped trying to start it, because I honestly don't know if that will do more harm than good. It's also been disconnected from the internet, because, again, I don't know and figured it couldn't hurt.<br /><br />
I keep coming across Acebot while googling the symptoms I described, but I haven't been able to find a case or solution where the computer doesn't boot at all. For all I know, which is obviously next to nothing, this detail eliminates Acebot as the cause. Any possible diagnosis or even better a solution would be very much appreciated. Thanks in advance!]]>
        </description>
    </item>
    <item>
        <title>Popups everywhere help!?!?</title>
        <link>https://icrontic.com/discussion/87948/popups-everywhere-help</link>
        <pubDate>Tue, 26 Jan 2010 19:26:05 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator></dc:creator>
        <guid isPermaLink="false">87948@/discussions</guid>
        <description><![CDATA[I am very new to this so thank you for you help!  I have  ALOT of popups.  NeXplore seems to be the most frequent, but there are many others, as well as my computer working very slow. AVG doesn't seem to be doing it's job! I have read many of your forums and now that you can help.  Where do I get the Hijackthis tool? and what other steps do I need to take?  PLEASE please HELP!?!?]]>
        </description>
    </item>
    <item>
        <title>trojan.desktopblocker.cd HELP!</title>
        <link>https://icrontic.com/discussion/87964/trojan-desktopblocker-cd-help</link>
        <pubDate>Wed, 27 Jan 2010 14:48:18 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator></dc:creator>
        <guid isPermaLink="false">87964@/discussions</guid>
        <description><![CDATA[i guess i have a virus called trojan.desktopblocker.cd  I have no icons on my desktop at all.  I am "computer stupid" and have NO idea what to do to get rid of this and get everything back to normal.  Please help. Thanks]]>
        </description>
    </item>
    <item>
        <title>Internet Security 2010</title>
        <link>https://icrontic.com/discussion/87952/internet-security-2010</link>
        <pubDate>Wed, 27 Jan 2010 01:40:21 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>Koreish</dc:creator>
        <guid isPermaLink="false">87952@/discussions</guid>
        <description><![CDATA[I'm not entirely sure where I got it from but I know it isn't good.  Does anyone know of a good way to get rid of it?   Several websites have pointed towards Malwarebytes AntiMalware. Is this a safe bet?]]>
        </description>
    </item>
    <item>
        <title>Popups everywhere help!?!?</title>
        <link>https://icrontic.com/discussion/87947/popups-everywhere-help</link>
        <pubDate>Tue, 26 Jan 2010 19:20:22 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator></dc:creator>
        <guid isPermaLink="false">87947@/discussions</guid>
        <description><![CDATA[I have been having ALOT of popups lately, NeXplore being the prominent one amoung many others. My computer is running very sllloowww. AVG is doing what it is supposed to I guess! I have read a lot of your forums and KNOW that you can help.  Please PLEASE help!  Were do I get the Hijackthis tool? and what are the steps for me to take?<br /><br /><br />
THANK YOU]]>
        </description>
    </item>
    <item>
        <title>Nexplore! Help! Logs included.</title>
        <link>https://icrontic.com/discussion/87943/nexplore-help-logs-included</link>
        <pubDate>Tue, 26 Jan 2010 17:12:33 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator></dc:creator>
        <guid isPermaLink="false">87943@/discussions</guid>
        <description><![CDATA[I am having a issue with Nexplore and a couple other popups in Firefox.  Any help would be appreciated.  I have included logs from Combox Fix and Hijack.<br /><br />
ComboFix:<br />
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br /><br />
c:\documents and settings\All Users\Start Menu\Programs\Spyware Cease<br />
c:\documents and settings\All Users\Start Menu\Programs\Spyware Cease\Spyware Cease on the Web.lnk<br />
c:\documents and settings\All Users\Start Menu\Programs\Spyware Cease\Spyware Cease.lnk<br />
c:\documents and settings\All Users\Start Menu\Programs\Spyware Cease\Uninstall Spyware Cease.lnk<br />
c:\documents and settings\pretsam\Application Data\inst.exe<br />
c:\documents and settings\pretsam\My Documents\Regback.reg<br />
c:\program files\Spyware Cease<br />
c:\program files\Spyware Cease\AutoUpdate.exe<br />
c:\program files\Spyware Cease\bmgac<br />
c:\program files\Spyware Cease\dxddd<br />
c:\program files\Spyware Cease\fp.fpl<br />
c:\program files\Spyware Cease\hrdb.hrl<br />
c:\program files\Spyware Cease\idamx<br />
c:\program files\Spyware Cease\iflee<br />
c:\program files\Spyware Cease\LSR.lsr<br />
c:\program files\Spyware Cease\md5.dll<br />
c:\program files\Spyware Cease\mtools.dll<br />
c:\program files\Spyware Cease\networkdll.dll<br />
c:\program files\Spyware Cease\opfile.dll<br />
c:\program files\Spyware Cease\QAreaDLL.dll<br />
c:\program files\Spyware Cease\RkHitApi.dll<br />
c:\program files\Spyware Cease\sctdll.dll<br />
c:\program files\Spyware Cease\spkdll.dll<br />
c:\program files\Spyware Cease\SpywareCease.chm<br />
c:\program files\Spyware Cease\SpywareCease.exe<br />
c:\program files\Spyware Cease\SpywareCease.url<br />
c:\program files\Spyware Cease\tmp5<br />
c:\program files\Spyware Cease\udefend.dll<br />
c:\program files\Spyware Cease\unins000.dat<br />
c:\program files\Spyware Cease\unins000.exe<br />
c:\program files\Spyware Cease\update\Update.ini<br />
c:\program files\Spyware Cease\update\uplist.up<br />
c:\program files\Spyware Cease\ussafe.dll<br />
c:\program files\Spyware Cease\vf<br />
c:\program files\Spyware Cease\vsn.lst<br />
c:\program files\Spyware Cease\wcfile.lst<br />
c:\program files\Spyware Cease\wl.swl<br />
c:\program files\Spyware Cease\xxcum<br />
c:\program files\Spyware Cease\zlib1.dll<br />
c:\windows\mplayerplgn.dll<br />
c:\windows\system32\drivers\RKHit.sys<br />
c:\windows\system32\fupipivo.dll<br />
c:\windows\system32\jinuwayi.dll<br />
c:\windows\system32\SKYNETurubhxep.da_<br />
c:\windows\system32\tezepugi.dll<br />
c:\windows\Tasks\gyrvqlqp.job<br /><br />
.<br />
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br /><hr />
\Legacy_RKHIT
<hr />
\Legacy_SKYNETklvdypyd
<hr />
\Service_RkHit
<hr />
\Service_SKYNETklvdypyd<br /><br /><br />
(((((((((((((((((((((((((   Files Created from 2009-12-26 to 2010-01-26  )))))))))))))))))))))))))))))))<br />
.<br /><br />
2010-01-26 19:58 . 2010-01-26 19:58
<hr />
d
<hr />
w-    c:\windows\Sun<br />
2010-01-26 19:58 . 2010-01-26 19:58    411368    ----a-w-    c:\windows\system32\deploytk.dll<br />
2010-01-26 19:58 . 2010-01-26 19:58
<hr />
d
<hr />
w-    c:\program files\Java<br />
2010-01-26 19:57 . 2010-01-26 19:57    152576    ----a-w-    c:\documents and settings\pretsam\Application Data\Sun\Java\jre1.6.0_17\lzma.dll<br />
2010-01-26 19:56 . 2010-01-26 19:56    79488    ----a-w-    c:\documents and settings\pretsam\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll<br />
2010-01-26 19:56 . 2010-01-26 19:56
<hr />
d-s---w-    c:\documents and settings\pretsam\UserData<br />
2010-01-26 19:25 . 2010-01-26 20:54
<hr />
d
<hr />
w-    c:\program files\trend micro<br />
2010-01-26 19:25 . 2010-01-26 19:25
<hr />
d
<hr />
w-    C:\rsit<br />
2010-01-26 19:17 . 2010-01-26 19:17
<hr />
d
<hr />
w-    c:\documents and settings\Administrator\Application Data\Malwarebytes<br />
2010-01-26 05:44 . 2010-01-26 05:44    8677824    ----a-w-    c:\documents and settings\pretsam\Application Data\Azureus\tmp\AZU9194.tmp\Vuze_4.3.0.6b_win32.exe<br />
2010-01-26 04:47 . 2010-01-26 04:47
<hr />
d
<hr />
w-    c:\temp\mirc<br />
2010-01-25 23:57 . 2010-01-25 23:58
<hr />
d
<hr />
w-    c:\temp\298.PS3.Themes.IPT<br />
2010-01-25 22:58 . 2010-01-26 05:47
<hr />
d
<hr />
w-    c:\temp\The Book of Eli TS X264 720P - IMAGiNE<br />
2010-01-25 04:27 . 2010-01-25 04:27    4141117    ----a-w-    c:\documents and settings\pretsam\Application Data\Azureus\plugins\vuzexcode\mediainfo.exe<br />
2010-01-25 04:27 . 2010-01-25 04:27    6516755    ----a-w-    c:\documents and settings\pretsam\Application Data\Azureus\plugins\vuzexcode\ffmpeg.exe<br />
2010-01-17 18:00 . 2010-01-18 01:33
<hr />
d
<hr />
w-    c:\temp\Couples.Retreat.2009.720p.BluRay.x264.DTS-WiKi<br />
2010-01-16 06:17 . 2010-01-17 17:59
<hr />
d
<hr />
w-    c:\temp\Extract.2009.720p.BluRay.x264.DTS-WiKi<br />
2010-01-09 06:12 . 2010-01-09 06:12
<hr />
d
<hr />
w-    c:\documents and settings\pretsam\Local Settings\Application Data\Move Networks<br />
2010-01-09 06:11 . 2010-01-09 06:11    1795704    ----a-w-    c:\documents and settings\pretsam\Application Data\Move Networks\MoveMediaPlayerWin_071705000014.exe<br /><br />
.<br />
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br />
2010-01-26 20:54 . 2009-03-06 06:02
<hr />
d
<hr />
w-    c:\documents and settings\pretsam\Application Data\.purple<br />
2010-01-26 20:28 . 2009-03-06 06:05
<hr />
d
<hr />
w-    c:\program files\Mozilla Thunderbird<br />
2010-01-26 19:56 . 2009-05-30 02:59
<hr />
d
<hr />
w-    c:\program files\FlashFXP<br />
2010-01-26 19:48 . 2009-03-07 12:11
<hr />
d
<hr />
w-    c:\program files\Bonjour<br />
2010-01-26 19:13 . 2009-03-17 14:00
<hr />
d
<hr />
w-    c:\documents and settings\pretsam\Application Data\Azureus<br />
2010-01-26 04:57 . 2009-10-30 00:57
<hr />
d
<hr />
w-    c:\program files\mIRC<br />
2010-01-26 01:15 . 2009-03-06 07:01
<hr />
d
<hr />
w-    c:\documents and settings\pretsam\Application Data\Vso<br />
2010-01-25 03:47 . 2009-07-07 14:50
<hr />
d
<hr />
w-    c:\documents and settings\pretsam\Application Data\vlc<br />
2010-01-09 06:12 . 2009-06-17 18:02    144160    ----a-w-    c:\documents and settings\pretsam\Application Data\Move Networks\uninstall.exe<br />
2010-01-09 06:12 . 2009-06-17 18:02
<hr />
d
<hr />
w-    c:\documents and settings\pretsam\Application Data\Move Networks<br />
2010-01-09 06:12 . 2009-12-07 01:22    5603776    ----a-w-    c:\documents and settings\pretsam\Application Data\Move Networks\plugins\npqmp071705000014.dll<br />
2010-01-04 04:05 . 2009-03-06 06:12
<hr />
d
<hr />
w-    c:\documents and settings\pretsam\Application Data\gtk-2.0<br />
2009-12-07 01:22 . 2009-12-07 01:22    97216    ----a-w-    c:\documents and settings\pretsam\Application Data\Move Networks\ie_bin\MovePlayerUpgrade.exe<br />
2009-11-21 06:15 . 2009-10-15 00:50    5642688    ----a-w-    c:\documents and settings\pretsam\Application Data\Move Networks\plugins\npqmp071701000002.dll<br />
2009-11-21 06:15 . 2009-11-21 06:14    1794456    ----a-w-    c:\documents and settings\pretsam\Application Data\Move Networks\MoveMediaPlayerWin_071701000002.exe<br />
1601-01-01 00:03 . 1601-01-01 00:03    52224    --sha-w-    c:\windows\system32\duzirasa.dll<br />
1601-01-01 00:03 . 1601-01-01 00:03    39424    --sha-w-    c:\windows\system32\fowanodi.dll<br />
1601-01-01 00:03 . 1601-01-01 00:03    52224    --sha-w-    c:\windows\system32\hefakola.dll<br />
1601-01-01 00:03 . 1601-01-01 00:03    60928    --sha-w-    c:\windows\system32\yagepodo.dll<br />
1601-01-01 00:03 . 1601-01-01 00:03    39424    --sha-w-    c:\windows\system32\yobuwiji.dll<br />
.<br /><br />
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br />
.<br />
*Note* empty entries &amp; legit default entries are not shown<br />
REGEDIT4<br /><br />
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{98fd29ec-b7fc-4acc-96c1-d5788a949196}]<br />
1601-01-01 00:03    52224    --sha-w-    c:\windows\system32\duzirasa.dll<br /><br />
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]<br /><br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]<br />
"D-Link Network USB Utility"="c:\program files\D-Link\Network USB Utility\Network USB Utility.exe" [2008-08-19 1885952]<br />
"NetWorx"="c:\program files\NetWorx\networx.exe" [2009-08-22 1862144]<br />
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-26 149280]<br /><br />
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]<br />
BootExecute    REG_MULTI_SZ       autocheck autochk *\0OODBS<br /><br />
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]<br />
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk<br />
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup<br /><br />
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlackBerryAutoUpdate]<br />
2008-11-04 17:09    615696    ----a-w-    c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe<br /><br />
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]<br />
2008-04-14 12:00    15360
<hr />
w-    c:\windows\system32\ctfmon.exe<br /><br />
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]<br />
2007-08-30 15:50    205480    ----a-w-    c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe<br /><br />
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]<br />
2008-09-19 15:37    236016    ----a-w-    c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe<br /><br />
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]<br />
2005-08-17 10:39    90112
<hr />
r-    c:\windows\soundman.exe<br /><br />
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br />
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=<br />
"%windir%\\system32\\sessmgr.exe"=<br />
"c:\\mirc\\mirc.exe"=<br />
"c:\\Program Files\\EA SPORTS\\Madden NFL 08\\Updater.exe"=<br />
"c:\\Program Files\\iTunes\\iTunes.exe"=<br />
"c:\\Program Files\\EA SPORTS\\Madden NFL 08\\mainapp.exe"=<br />
"c:\\Program Files\\Pidgin\\pidgin.exe"=<br />
"c:\\Program Files\\Vuze\\Azureus.exe"=<br />
"c:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe"=<br />
"c:\\Program Files\\FTPRush\\FTPRush.exe"=<br />
"c:\\Program Files\\FlashFXP\\FlashFXP.exe"=<br />
"c:\\Program Files\\D-Link\\Network USB Utility\\Network USB Utility.exe"=<br />
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=<br />
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=<br />
"c:\\Program Files\\mIRC\\mirc.exe"=<br /><br />
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]<br />
"9303:UDP"= 9303:UDP:Network USB Utility UDP Port<br /><br />
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [3/6/2009 7:14 PM 717296]<br />
R1 PSSDK42;PSSDK42;c:\windows\system32\drivers\pssdk42.sys [8/22/2009 11:00 PM 38976]<br />
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\CyberLink\PowerDVD8\000.fcl [2/1/2008 5:24 PM 41456]<br />
R3 DlinkUDSMBus;UDS Master Bus of Kernel USB Software Bus by TCP;c:\windows\system32\drivers\DlinkUDSMBus.sys [8/18/2008 1:20 PM 73600]<br />
S3 DlinkUDSTcpBus;DlinkUDSTcpBus;c:\windows\system32\drivers\DlinkUDSTcpBus.sys [8/18/2008 1:20 PM 97408]<br />
S3 SliceDisk5;SliceDisk5;\??\c:\docume~1\pretsam\LOCALS~1\Temp\slicedisk.sys --&gt; c:\docume~1\pretsam\LOCALS~1\Temp\slicedisk.sys [?]<br />
.<br />
Contents of the 'Scheduled Tasks' folder<br /><br />
2009-03-19 c:\windows\Tasks\AppleSoftwareUpdate.job<br />
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]<br />
.<br />
.
<hr />
Supplementary Scan
<hr />
.<br />
uInternet Settings,ProxyOverride = *.local<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
FF - ProfilePath - c:\documents and settings\pretsam\Application Data\Mozilla\Firefox\Profiles\9b8zviug.default\<br />
FF - prefs.js: browser.startup.homepage - <a href="www.espn.com" rel="nofollow">www.espn.com</a><br />
FF - plugin: c:\documents and settings\pretsam\Application Data\Move Networks\plugins\npqmp071701000002.dll<br />
FF - plugin: c:\documents and settings\pretsam\Application Data\Move Networks\plugins\npqmp071705000014.dll<br />
.<br />
- - - - ORPHANS REMOVED - - - -<br /><br />
HKLM-Run-SpywareCease.exe - c:\program files\Spyware Cease\SpywareCease.exe<br />
HKLM-Run-puhikuboh - c:\windows\system32\tezepugi.dll<br />
HKLM-Run-pabugekori - jinuwayi.dll<br />
SharedTaskScheduler-{ee5ba5c0-7ac3-435c-80c3-7ebbbd24691c} - c:\windows\system32\tezepugi.dll<br />
SSODL-kobaruped-{ee5ba5c0-7ac3-435c-80c3-7ebbbd24691c} - c:\windows\system32\tezepugi.dll<br />
MSConfigStartUp-puhikuboh - c:\windows\system32\tezepugi.dll<br /><br /><br /><br />
**************************************************************************<br /><br />
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, <a href="http://www.gmer.net" rel="nofollow">http://www.gmer.net</a><br />
Rootkit scan 2010-01-26 16:19<br />
Windows 5.1.2600 Service Pack 3 NTFS<br /><br />
scanning hidden processes ...<br /><br />
scanning hidden autostart entries ...<br /><br />
scanning hidden files ...<br /><br />
scan completed successfully<br />
hidden files: 0<br /><br />
**************************************************************************<br /><br />
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, <a href="http://www.gmer.net" rel="nofollow">http://www.gmer.net</a><br /><br />
device: opened successfully<br />
user: MBR read successfully<br />
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll &gt;&gt;UNKNOWN [0x867D71F8]&lt;&lt;<br />
kernel: MBR read successfully<br />
detected MBR rootkit hooks:<br />
\Driver\Disk -&gt; CLASSPNP.SYS @ 0xf7674f28<br />
\Driver\ACPI -&gt; ACPI.sys @ 0xf73cfcb8<br />
\Driver\atapi -&gt; atapi.sys @ 0xf7364b40<br />
IoDeviceObjectType -&gt; DeleteProcedure -&gt; ntkrnlpa.exe @ 0x805836a8<br />
ParseProcedure -&gt; ntkrnlpa.exe @ 0x805827e8<br />
\Device\Harddisk0\DR0 -&gt; DeleteProcedure -&gt; ntkrnlpa.exe @ 0x805836a8<br />
ParseProcedure -&gt; ntkrnlpa.exe @ 0x805827e8<br />
NDIS: NVIDIA nForce Networking Controller -&gt; SendCompleteHandler -&gt; NDIS.sys @ 0xf7256bb0<br />
PacketIndicateHandler -&gt; NDIS.sys @ 0xf7263a21<br />
SendHandler -&gt; NDIS.sys @ 0xf724187b<br />
user &amp; kernel MBR OK<br /><br />
**************************************************************************<br /><br />
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]<br />
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"<br />
.
<hr />
LOCKED REGISTRY KEYS
<hr /><br />
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]<br />
"OODEFRAG06.00.00.01WORKSTATION"="6C7FCD270AAAC883AA3B90737F69363D78D560AB48F2C52171FC24C2932319127CD671734904641B968DDCC3FEDD23B8F8E9A394C3FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79335D575E7D6A3B9808A2D97226D213B555A6A0AC4980AC79331E418C0094FD9F6520E135F0F3F2910517CF067BDD8A5F9B2065C75490911C81744F14CBB49BCFC56E4A1EF8FE2E0978BE370D23DEAEFA3F1BEC6882BAAB3643086B8FD6C0EE66672BD649BE43E0A74DB8C356EDA9BFE6B3E1D2A530EDA4561B611F84B1A6D26FBF917A74A7AFE283600D77F8BA4F32615A6EC70FCBF7AB068E0EE89C8397D65D1A5D2181AE75C098634B4AB0F720318FE9C0EE59DBECA9AF791A38A283853E8419CD2876E3083CC3D905A75A273318F5ECD9E1DB75A4B7A58A1D728880AA021F2FA9627DE522C8489E4EEDF9E0E07A83BE42AB924638251A442C7164DA82CBC9233993E3EDBF104CDBC1EF37D0C89D041403CC1D8F0874287EE281EC084C7D8691C7F71DC5236D5A147CF55CB5CDF82EF02CB7C02438DAC9E1626301118C283A6AA6BD3C4A5171619B21B9D662943C97AECFD6636EADC5E0EFCDCCA0148C94AE712C847DEE9260329B546ABBBF87C7BBFB048513E71650B1F8CB66F041D63D92BD2FE43EB9F3B4048FC02C4147D5B2F8DA63127DA2DD4FE3A489CC39DE3C53F4BC8B6801C5C898F1499393C109F0C495A08E4278C1BAC8056D3592E8C5D139CB2C248B6940A26D796DFDAFBB278E7CB676A54EFA7FA27704A3833A1063EE8672A0DB42C3EADEC8FD7536FAD35BA80AE85C51E020A5CF4936682CBFE2B7AF87A4821DF07D1D96F1C32D75EBCFEF7F559A21B99AA91644E0D3B26A8DBAD973BA038C5273A6C02E65F736F9E71BC292F5A06C9010F945BF94794EFC8694735F5494CFED1677D4C8D4A78384CAC4482ABA303886C81ABACBEF2759A87E11BE5CBB42AE649B496BCF2444DFDB627E084F2466515241B492B1B042C6B53E7690158C58E12DBA992971EAA66748729F9B4FE7C159B0689A7E03C8915C6E052B4C7A950AF4461B0A4A1EF6070B193323353E6F2746DCA2BFC0116042B52381BD6B40DA6CC7305E621D0BC7050F1F4DA995F1595CE29B493B33F2D0E542275A5FFADE15F70D6E138981B193220CAF61731503F58D4C3427C94184A86E44D2A6E31D13AD0ACD8AC10FF04EC0C5F02503E81F514B4A7470FCCBEA652B375202754507DB46E4E512E2A4F3636D397B5CB614B27D1305211EFC4346F74E7AD692469F817D30AE0513E421A8B569AB41B7F92562EEB916EA90D1597963BB5812E98F33E801756E2E252B7CC14DB830AC1DBB6E574FE2B8419E965A4292545794EE39663132CE133ADD89D68577953B7975DC66CA0D618C65A35935"<br />
.
<hr />
DLLs Loaded Under Running Processes
<hr /><br />
- - - - - - - &gt; 'winlogon.exe'(728)<br />
c:\windows\system32\Ati2evxx.dll<br />
.
<hr />
Other Running Processes
<hr />
.<br />
c:\windows\system32\Ati2evxx.exe<br />
c:\windows\system32\Ati2evxx.exe<br />
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
c:\program files\Java\jre6\bin\jqs.exe<br />
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe<br />
c:\windows\system32\oodag.exe<br />
c:\windows\system32\wdfmgr.exe<br />
c:\windows\system32\imapi.exe<br />
c:\windows\system32\wscntfy.exe<br />
.<br />
**************************************************************************<br />
.<br />
Completion time: 2010-01-26  16:20:30 - machine was rebooted<br />
ComboFix-quarantined-files.txt  2010-01-26 21:20<br /><br />
Pre-Run: 13,176,913,920 bytes free<br />
Post-Run: 13,177,106,432 bytes free<br /><br />
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe<br />
[boot loader]<br />
timeout=2<br />
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS<br />
[operating systems]<br />
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons<br />
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer<br /><br />
- - End Of File - - 561F6186E321AEE1DC73D94A6ACBA8E4<br /><br /><br />
Hijack:<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe<br />
C:\WINDOWS\system32\oodag.exe<br />
C:\Program Files\NetWorx\networx.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\DAEMON Tools Lite\daemon.exe<br />
C:\WINDOWS\explorer.exe<br />
C:\WINDOWS\system32\notepad.exe<br />
C:\Program Files\Pidgin\pidgin.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Documents and Settings\pretsam\My Documents\Downloads\RSIT.exe<br />
C:\Program Files\trend micro\pretsam.exe<br /><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: &amp;NetWorx Desk Band - {FEEA54B4-D80F-41C7-87B9-DC08E6D3255F} - C:\PROGRA~1\NetWorx\deskband.dll<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br />
O4 - HKLM\..\Run: [D-Link Network USB Utility] C:\Program Files\D-Link\Network USB Utility\Network USB Utility.exe -mini<br />
O4 - HKLM\..\Run: [NetWorx] "C:\Program Files\NetWorx\networx.exe" /auto<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br />
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - AutorunsDisabled - (no file)<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: <a href="https://icrontic.com/profile/xpsp3res" rel="nofollow">@xpsp3res</a>.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O16 - DPF: {22E5D91F-89E6-4405-AD9C-0AF27BA6F06B} (HidInputMonitorX Control) - file://H:\components\hidinputmonitorx.ocx<br />
O16 - DPF: {4F63D44B-6274-4D60-8AB1-CAA7116B8AF3} (A9Helper.A9) - file://H:\components\A9.ocx<br />
O16 - DPF: {7030CC6C-1A88-4591-BB5A-651B9F7F0C30} (WMVHDRatingCtrl Class) - file://H:\components\wmvhdrating.ocx<br />
O20 - AppInit_DLLs: fupipivo.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: O&amp;O Defrag - O&amp;O Software GmbH - C:\WINDOWS\system32\oodag.exe<br />
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe<br />
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe<br />
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe<br />
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe<br />
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe<br /><br />
--<br />
End of file - 4545 bytes<br /><br />
======Scheduled tasks folder======<br /><br />
C:\WINDOWS\tasks\AppleSoftwareUpdate.job<br /><br />
======Registry dump======<br /><br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]<br />
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]<br /><br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]<br />
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-01-26 41760]<br /><br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]<br />
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-01-26 73728]<br /><br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]<br />
{FEEA54B4-D80F-41C7-87B9-DC08E6D3255F} - &amp;NetWorx Desk Band - C:\PROGRA~1\NetWorx\deskband.dll [2009-08-21 498176]<br /><br />
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]<br />
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2009-01-05 413696]<br />
"D-Link Network USB Utility"=C:\Program Files\D-Link\Network USB Utility\Network USB Utility.exe [2008-08-19 1885952]<br />
"NetWorx"=C:\Program Files\NetWorx\networx.exe [2009-08-21 1862144]<br />
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2010-01-26 149280]<br /><br />
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-12-29 687560]<br /><br />
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlackBerryAutoUpdate]<br />
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe [2008-11-04 615696]<br /><br />
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]<br />
C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]<br /><br />
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]<br />
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [2007-08-30 205480]<br /><br />
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]<br />
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe [2008-09-19 236016]<br /><br />
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]<br />
C:\WINDOWS\SOUNDMAN.EXE [2005-08-17 90112]<br /><br />
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]<br />
C:\PROGRA~1\Adobe\ACROBA~2.0\Reader\READER~1.EXE [2004-12-14 29696]<br /><br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]<br />
"AppInit_DLLS"="fupipivo.dll"<br /><br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]<br />
C:\WINDOWS\system32\Ati2evxx.dll [2009-02-03 155648]<br /><br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]<br />
"notification packages"=scecli<br />
jinuwayi.dll<br /><br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]<br /><br />
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]<br />
"dontdisplaylastusername"=0<br />
"legalnoticecaption"=<br />
"legalnoticetext"=<br />
"shutdownwithoutlogon"=1<br />
"undockwithoutlogon"=1<br /><br />
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]<br />
"NoDriveTypeAutoRun"=323<br />
"NoDriveAutoRun"=67108863<br />
"NoDrives"=0<br /><br />
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]<br />
"NoDriveAutoRun"=<br />
"NoDriveTypeAutoRun"=<br />
"NoDrives"=<br /><br />
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]<br />
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:<a href="https://icrontic.com/profile/xpsp3res" rel="nofollow">@xpsp3res</a>.dll,-20000"<br />
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:<a href="https://icrontic.com/profile/xpsp2res" rel="nofollow">@xpsp2res</a>.dll,-22019"<br />
"C:\mirc\mirc.exe"="C:\mirc\mirc.exe:*:Enabled:mIRC"<br />
"C:\Program Files\EA SPORTS\Madden NFL 08\Updater.exe"="C:\Program Files\EA SPORTS\Madden NFL 08\Updater.exe:*:Enabled:Updater"<br />
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"<br />
"C:\Program Files\EA SPORTS\Madden NFL 08\mainapp.exe"="C:\Program Files\EA SPORTS\Madden NFL 08\mainapp.exe:*:Enabled:Madden NFL 08"<br />
"C:\Program Files\Pidgin\pidgin.exe"="C:\Program Files\Pidgin\pidgin.exe:*:Enabled:Pidgin"<br />
"C:\Program Files\Vuze\Azureus.exe"="C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus"<br />
"C:\Program Files\Mozilla Thunderbird\thunderbird.exe"="C:\Program Files\Mozilla Thunderbird\thunderbird.exe:*:Enabled:Mozilla Thunderbird"<br />
"C:\Program Files\FTPRush\FTPRush.exe"="C:\Program Files\FTPRush\FTPRush.exe:*:Enabled:FTPRush FTP Client"<br />
"C:\Program Files\FlashFXP\FlashFXP.exe"="C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3"<br />
"C:\Program Files\D-Link\Network USB Utility\Network USB Utility.exe"="C:\Program Files\D-Link\Network USB Utility\Network USB Utility.exe:*:Enabled:Network USB Utility"<br />
"C:\Program Files\VideoLAN\VLC\vlc.exe"="C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"<br />
"C:\Program Files\Ventrilo\Ventrilo.exe"="C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe"<br />
"C:\Program Files\mIRC\mirc.exe"="C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC"<br />
"C:\WINDOWS\explorer.exe"="C:\WINDOWS\explorer.exe:*:Enabled:explorer"<br /><br />
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]<br />
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:<a href="https://icrontic.com/profile/xpsp3res" rel="nofollow">@xpsp3res</a>.dll,-20000"<br />
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:<a href="https://icrontic.com/profile/xpsp2res" rel="nofollow">@xpsp2res</a>.dll,-22019"<br />
"C:\Program Files\FlashFXP\FlashFXP.exe"="C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3"<br /><br />
======List of files/folders created in the last 1 months======<br /><br />
65535-65535-31889 379:31889:443 ----ASH---- C:\WINDOWS\system32\yobuwiji.dll<br />
65535-65535-31889 379:31889:443 ----ASH---- C:\WINDOWS\system32\yagepodo.dll<br />
65535-65535-31889 379:31889:443 ----ASH---- C:\WINDOWS\system32\hefakola.dll<br />
65535-65535-31889 379:31889:443 ----ASH---- C:\WINDOWS\system32\fowanodi.dll<br />
65535-65535-31889 379:31889:443 ----ASH---- C:\WINDOWS\system32\duzirasa.dll<br />
2010-01-26 16:20:31 ----A---- C:\ComboFix.txt<br />
2010-01-26 16:14:42 ----A---- C:\Boot.bak<br />
2010-01-26 16:14:39 ----RASHD---- C:\cmdcons<br />
2010-01-26 16:14:06 ----A---- C:\WINDOWS\PEV.exe<br />
2010-01-26 16:14:06 ----A---- C:\WINDOWS\NIRCMD.exe<br />
2010-01-26 16:14:06 ----A---- C:\WINDOWS\MBR.exe<br />
2010-01-26 16:14:05 ----A---- C:\WINDOWS\zip.exe<br />
2010-01-26 16:14:05 ----A---- C:\WINDOWS\SWXCACLS.exe<br />
2010-01-26 16:14:05 ----A---- C:\WINDOWS\SWSC.exe<br />
2010-01-26 16:14:05 ----A---- C:\WINDOWS\SWREG.exe<br />
2010-01-26 16:14:05 ----A---- C:\WINDOWS\sed.exe<br />
2010-01-26 16:14:05 ----A---- C:\WINDOWS\grep.exe<br />
2010-01-26 16:12:37 ----D---- C:\WINDOWS\ERDNT<br />
2010-01-26 16:10:59 ----D---- C:\Qoobox<br />
2010-01-26 14:58:46 ----D---- C:\WINDOWS\Sun<br />
2010-01-26 14:58:16 ----A---- C:\WINDOWS\system32\javaws.exe<br />
2010-01-26 14:58:16 ----A---- C:\WINDOWS\system32\javaw.exe<br />
2010-01-26 14:58:16 ----A---- C:\WINDOWS\system32\java.exe<br />
2010-01-26 14:58:16 ----A---- C:\WINDOWS\system32\deploytk.dll<br />
2010-01-26 14:58:07 ----D---- C:\Program Files\Java<br />
2010-01-26 14:56:50 ----D---- C:\Documents and Settings\pretsam\Application Data\Sun<br />
2010-01-26 14:25:07 ----D---- C:\Program Files\trend micro<br />
2010-01-26 14:25:06 ----D---- C:\rsit<br /><br />
======List of files/folders modified in the last 1 months======<br /><br />
2010-01-26 16:33:45 ----D---- C:\WINDOWS\Prefetch<br />
2010-01-26 16:31:50 ----D---- C:\Program Files\Mozilla Firefox<br />
2010-01-26 16:31:36 ----D---- C:\Documents and Settings\pretsam\Application Data\.purple<br />
2010-01-26 16:23:46 ----D---- C:\WINDOWS\system32\drivers<br />
2010-01-26 16:22:55 ----RD---- C:\Program Files<br />
2010-01-26 16:20:18 ----D---- C:\WINDOWS\Temp<br />
2010-01-26 16:19:47 ----SD---- C:\WINDOWS\Tasks<br />
2010-01-26 16:19:33 ----D---- C:\WINDOWS\system32\CatRoot2<br />
2010-01-26 16:18:51 ----D---- C:\WINDOWS<br />
2010-01-26 16:18:51 ----A---- C:\WINDOWS\system.ini<br />
2010-01-26 16:17:13 ----D---- C:\WINDOWS\system32\config<br />
2010-01-26 16:16:54 ----D---- C:\WINDOWS\system32<br />
2010-01-26 16:16:09 ----D---- C:\WINDOWS\AppPatch<br />
2010-01-26 16:16:09 ----D---- C:\Program Files\Common Files<br />
2010-01-26 16:14:42 ----RASH---- C:\boot.ini<br />
2010-01-26 16:14:10 ----A---- C:\WINDOWS\SchedLgU.Txt<br />
2010-01-26 16:07:59 ----A---- C:\WINDOWS\win.ini<br />
2010-01-26 15:28:05 ----D---- C:\Program Files\Mozilla Thunderbird<br />
2010-01-26 14:58:19 ----SHD---- C:\WINDOWS\Installer<br />
2010-01-26 14:56:06 ----D---- C:\Program Files\FlashFXP<br />
2010-01-26 14:48:17 ----D---- C:\Program Files\Bonjour<br />
2010-01-26 14:16:39 ----D---- C:\Documents and Settings<br />
2010-01-26 14:13:32 ----D---- C:\Documents and Settings\pretsam\Application Data\Azureus<br />
2010-01-26 00:56:47 ----D---- C:\Temp<br />
2010-01-26 00:42:21 ----D---- C:\mirc<br />
2010-01-26 00:39:57 ----A---- C:\WINDOWS\system32\BASSMOD.dll<br />
2010-01-26 00:37:23 ----D---- C:\WINDOWS\pss<br />
2010-01-26 00:08:13 ----A---- C:\WINDOWS\oodcnt.INI<br />
2010-01-25 23:57:21 ----D---- C:\Program Files\mIRC<br />
2010-01-25 20:15:11 ----D---- C:\Documents and Settings\pretsam\Application Data\Vso<br />
2010-01-25 19:53:20 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI<br />
2010-01-25 19:48:27 ----A---- C:\WINDOWS\winamp.ini<br />
2010-01-24 22:47:29 ----D---- C:\Documents and Settings\pretsam\Application Data\vlc<br />
2010-01-09 01:12:01 ----D---- C:\Documents and Settings\pretsam\Application Data\Move Networks<br />
2010-01-03 23:05:50 ----D---- C:\Documents and Settings\pretsam\Application Data\gtk-2.0<br /><br />
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======<br /><br />
R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 36352]<br />
R1 AvgArCln;Avg Anti-Rootkit Clean Driver; C:\WINDOWS\System32\DRIVERS\AvgArCln.sys [2007-01-18 3968]<br />
R1 PQNTDrv;PQNTDrv; C:\WINDOWS\system32\drivers\PQNTDrv.sys [2004-05-05 4228]<br />
R1 PSSDK42;PSSDK42; \??\C:\WINDOWS\system32\Drivers\pssdk42.sys []<br />
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}; \??\C:\Program Files\CyberLink\PowerDVD8\000.fcl []<br />
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-08-19 3644800]<br />
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2009-02-04 3488768]<br />
R3 catchme;catchme; \??\C:\ComboFix\catchme.sys []<br />
R3 DlinkUDSMBus;UDS Master Bus of Kernel USB Software Bus by TCP; C:\WINDOWS\System32\Drivers\DlinkUDSMBus.sys [2008-08-18 73600]<br />
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2008-04-17 15464]<br />
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]<br />
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-04-05 33536]<br />
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-04-05 12928]<br />
R3 RimVSerPort;RIM Virtual Serial Port v2; C:\WINDOWS\system32\DRIVERS\RimSerial.sys [2007-01-18 26496]<br />
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2008-04-14 5888]<br />
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]<br />
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]<br />
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-14 17152]<br />
R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]<br />
S3 a4we5kq9;a4we5kq9; C:\WINDOWS\system32\drivers\a4we5kq9.sys []<br />
S3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]<br />
S3 DlinkUDSTcpBus;DlinkUDSTcpBus; C:\WINDOWS\System32\Drivers\DlinkUDSTcpBus.sys [2008-08-18 97408]<br />
S3 mbr;mbr; \??\C:\DOCUME~1\pretsam\LOCALS~1\Temp\mbr.sys []<br />
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]<br />
S3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2009-03-06 47360]<br />
S3 RimUsb;BlackBerry Smartphone; C:\WINDOWS\System32\Drivers\RimUsb.sys [2008-05-20 22784]<br />
S3 SliceDisk5;SliceDisk5; \??\C:\DOCUME~1\pretsam\LOCALS~1\Temp\slicedisk.sys []<br />
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]<br />
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []<br /><br />
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======<br /><br />
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-11-07 132424]<br />
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2009-02-03 602112]<br />
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-01-26 153376]<br />
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]<br />
R2 O&amp;O Defrag;O&amp;O Defrag; C:\WINDOWS\system32\oodag.exe [2003-10-31 214528]<br />
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]<br />
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2009-02-03 593920]<br />
S2 Roxio Upnp Server 9;Roxio Upnp Server 9; C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe [2007-12-06 362992]<br />
S2 RoxLiveShare9;LiveShare P2P Server 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe [2008-09-19 313840]<br />
S2 RoxWatch9;Roxio Hard Drive Watcher 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe [2008-09-19 170480]<br />
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]<br />
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]<br />
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]<br />
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-01-06 536872]<br />
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]<br />
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]<br />
S3 Roxio UPnP Renderer 9;Roxio UPnP Renderer 9; C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe [2007-12-06 88560]<br />
S3 RoxMediaDB9;RoxMediaDB9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [2008-09-19 1108464]<br />
S4 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe []<br /><hr />
EOF
<hr />]]>
        </description>
    </item>
    <item>
        <title>HELP! Pop ups have taken over, esp. Nexplore</title>
        <link>https://icrontic.com/discussion/87937/help-pop-ups-have-taken-over-esp-nexplore</link>
        <pubDate>Tue, 26 Jan 2010 14:26:59 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator></dc:creator>
        <guid isPermaLink="false">87937@/discussions</guid>
        <description><![CDATA[I don't know where it came from, but suddenly I am getting pop-ups from NeXplore, but also lots of randon ads blockbuster, publisher's clearinghouse, Fullsail University, Sony, etc.<br />
The pop up about one every 3-4 minutes...one at a time.  I am generally able to close them, but sometimes when doing so, they freeze the computer and I have to shut down my browser through the task manager.  When I do that, task manager when open 20+ times and it takes forever to close everything.<br />
I ran Registry Booster and have AVG as my anti-virus, etc.  I also ran adaware free home edition.  Nothing worked.<br />
I use Mozilla Firefox as my browser.<br /><br />
Can anyone help...please?]]>
        </description>
    </item>
    <item>
        <title>Random pop ups from Nexplore, registry defender, etc.</title>
        <link>https://icrontic.com/discussion/87933/random-pop-ups-from-nexplore-registry-defender-etc</link>
        <pubDate>Tue, 26 Jan 2010 12:35:22 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator></dc:creator>
        <guid isPermaLink="false">87933@/discussions</guid>
        <description><![CDATA[<i>Hi everybody,<br /><br />
Recently my computer has been experiencing random popups when I open my browser (Firefox). I ran HiJackThis and hoping somebody can help me through this process.</i><i><br /><br />
Thanks!</i><br /><br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 12:31:26 PM, on 1/26/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br /><br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Canon\CAL\CALMAIN.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\RUNDLL32.EXE<br />
C:\Program Files\QuickTime\qttask.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br /><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html" rel="nofollow">http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www.yahoo.com" rel="nofollow">http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www.yahoo.com</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.yahoo.com/" rel="nofollow">http://www.yahoo.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html" rel="nofollow">http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = <a href="http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com" rel="nofollow">http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com</a><br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search &amp; Destroy\SDHelper.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: 180search Toolbar - {93CECBB2-6B1B-448D-91B9-72604EF70105} - C:\Program Files\180search Assistant Programs\180search Toolbar\180ST.dll (file missing)<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br />
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br />
O4 - HKLM\..\Run: [kelelojas] Rundll32.exe "c:\windows\system32\wefakupa.dll",a<br />
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min<br />
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search &amp; Destroy\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp;&amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search &amp; Destroy\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: <a href="https://icrontic.com/profile/xpsp3res" rel="nofollow">@xpsp3res</a>.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll<br />
O16 - DPF: {26FCCDF9-A7E1-452A-A73D-7BF7B4D0BA6C} (AOL Pictures Uploader Class) - <a href="http://o.aolcdn.com/pictures/ap/Resources/2.0.8.98/cab/aolpPlugins.10.6.0.6.cab" rel="nofollow">http://o.aolcdn.com/pictures/ap/Resources/2.0.8.98/cab/aolpPlugins.10.6.0.6.cab</a><br />
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - <a href="http://lads.myspace.com/upload/MySpaceUploader1005.cab" rel="nofollow">http://lads.myspace.com/upload/MySpaceUploader1005.cab</a><br />
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - <a href="http://web1.shutterfly.com/downloads/Uploader.cab" rel="nofollow">http://web1.shutterfly.com/downloads/Uploader.cab</a><br />
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - <a href="https://home01.mail.nypl.org/dwa7W.cab" rel="nofollow">https://home01.mail.nypl.org/dwa7W.cab</a><br />
O20 - AppInit_DLLs: c:\windows\system32\wefakupa.dll,tinajepu.dll<br />
O21 - SSODL: vokojuwek - {5825f28c-42b9-41ca-97b1-63be1bc19cd5} - c:\windows\system32\wefakupa.dll<br />
O22 - SharedTaskScheduler: jugezatag - {5825f28c-42b9-41ca-97b1-63be1bc19cd5} - c:\windows\system32\wefakupa.dll<br />
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br /><br />
--<br />
End of file - 6522 bytes]]>
        </description>
    </item>
    <item>
        <title>Slow computer, firewall unable to be turned on</title>
        <link>https://icrontic.com/discussion/87930/slow-computer-firewall-unable-to-be-turned-on</link>
        <pubDate>Tue, 26 Jan 2010 10:53:37 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>Miss_Alef</dc:creator>
        <guid isPermaLink="false">87930@/discussions</guid>
        <description><![CDATA[The computer is very slow to startup.  Sometimes programs have trouble starting.  Windows update can't ever seem to finish searching for possible updates. I tried to open the install/uninstall programs list, but the list never populates itself. Internet Explorer and Firefox sometimes take an eternity to start.  Even opening a new tab in either one freezes the computer for around 10 seconds before anything can be done.  Windows is telling me that the firewall is off, but if I try to go to firewall settings, it says, "Due to an unidentified problem, Windows cannot display Windows Firewall settings."<br /><br />
I scanned with spybot search and destroy, and ad-aware. Here is my HijackThis log:<br /><br />
Logfile of HijackThis v1.99.1<br />
Scan saved at 9:52:03 AM, on 1/26/2010<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br /><br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br />
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Symantec AntiVirus\DefWatch.exe<br />
C:\WINDOWS\eHome\ehRecvr.exe<br />
C:\WINDOWS\eHome\ehSched.exe<br />
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe<br />
C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br />
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe<br />
C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe<br />
C:\WINDOWS\system32\java.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\WINDOWS\ehome\ehtray.exe<br />
C:\WINDOWS\stsystra.exe<br />
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe<br />
C:\Program Files\Dell\Media Experience\DMXLauncher.exe<br />
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br />
C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br />
C:\WINDOWS\eHome\ehmsas.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br />
C:\PROGRA~1\SYMANT~1\VPTray.exe<br />
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe<br />
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe<br />
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe<br />
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe<br />
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe<br />
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe<br />
C:\Program Files\DellSupport\DSAgnt.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Skype\Phone\Skype.exe<br />
C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe<br />
C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe<br />
C:\Program Files\Digital Line Detect\DLG.exe<br />
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe<br />
C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Skype\Plugin Manager\skypePM.exe<br />
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br />
C:\Program Files\Symantec AntiVirus\vpc32.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Documents and Settings\Katheryn\Desktop\hijackthis_199\HijackThis.exe<br /><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = <a href="www.google.com/ig/dell?hl=en&amp;client=dell-usuk&amp;channel=us" rel="nofollow">www.google.com/ig/dell?hl=en&amp;client=dell-usuk&amp;channel=us</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll<br />
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll<br />
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe<br />
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe<br />
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe<br />
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"<br />
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe<br />
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup<br />
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start<br />
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br />
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br />
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br />
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br />
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br />
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot<br />
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"<br />
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"<br />
O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini"<br />
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN<br />
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun<br />
O4 - HKLM\..\Run: [LELA] "C:\Program Files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe" /minimized<br />
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"<br />
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br />
O4 - HKLM\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" /OM<br />
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe<br />
O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF<br />
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=2 /w /h<br />
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe<br />
O4 - HKCU\..\Run: [ares ultra] "C:\Program Files\Ares Ultra\Ares Ultra.exe" -h<br />
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"<br />
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized<br />
O4 - HKCU\..\Run: [Desktop Software] "C:\Program Files\Common Files\SupportSoft\bin\bcont.exe"  /ini "C:\Program Files\ComcastUI\Desktop Software\uinstaller.ini" /fromrun /starthidden<br />
O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe"<br />
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br />
O4 - Global Startup: Clean Access Agent.lnk = C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe<br />
O4 - Global Startup: Digital Line Detect.lnk = ?<br />
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?<br />
O4 - Global Startup: McAfee Security Scan.lnk = ?<br />
O8 - Extra context menu item: &amp;Search - ?p=GRman000<br />
O8 - Extra context menu item: &amp;Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html<br />
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?f1a3acb69ec844969d2f5fb9e0dd1ff6<br />
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?f1a3acb69ec844969d2f5fb9e0dd1ff6<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll<br />
O11 - Options group: [INTERNATIONAL] International<br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - <a href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" rel="nofollow">http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab</a><br />
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - <a href="http://photos.walmart.com/WalmartActivia.cab" rel="nofollow">http://photos.walmart.com/WalmartActivia.cab</a><br />
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - <a href="http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab" rel="nofollow">http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab</a><br />
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - <a href="http://upload.facebook.com/controls/FacebookPhotoUploader3.cab" rel="nofollow">http://upload.facebook.com/controls/FacebookPhotoUploader3.cab</a><br />
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - <a href="http://upload.facebook.com/controls/FacebookPhotoUploader.cab" rel="nofollow">http://upload.facebook.com/controls/FacebookPhotoUploader.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1264449007218" rel="nofollow">http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1264449007218</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1264448986875" rel="nofollow">http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1264448986875</a><br />
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - <a href="http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab" rel="nofollow">http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab</a><br />
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -<br />
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - <a href="http://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab" rel="nofollow">http://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab</a><br />
O18 - Protocol: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp3.dll<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll<br />
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll<br />
O21 - SSODL: hksrv.dll - {45084BF1-55CB-4A8D-B0BB-BAD6DF96566D} - hksrv.dll (file missing)<br />
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe<br />
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br />
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe<br />
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe<br />
O23 - Service: IntelÂ® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
O23 - Service: Linksys Updater (LinksysUpdater) - Unknown owner - C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe" -s "C:\Program Files\Linksys\Linksys Updater\conf\wrapper.conf (file missing)<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br />
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe<br />
O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe<br />
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe<br />
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br />
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br />
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br /><br />
Thanks for any help you can give.]]>
        </description>
    </item>
    <item>
        <title>Think I got a problem here!</title>
        <link>https://icrontic.com/discussion/87776/think-i-got-a-problem-here</link>
        <pubDate>Mon, 18 Jan 2010 22:32:03 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>The-Lovable-Mr--Hater</dc:creator>
        <guid isPermaLink="false">87776@/discussions</guid>
        <description><![CDATA[hey guys. long time since i've been in here. well, all has been well and i hope everyone had a great new year.<br />
onto my problem now.<br /><br />
i recently noticed my pc being a little sluggish, so i ran malwarebytes to check for any situations. no probs. then i went to msconfig to turn off some of the processes that i know i dont need at start up (zune, webcam, etc.). well, i went to run, and did a chkdsk /f to make sure there were no errors, and when i turned the system back on, now all i get is a black screen that says lsass.exe - unable to locate component. i looked up online and this could be a virus or trojan. since i cant get into anything to check, how do i fix this. i tried running safe mode and nothing. please help!!<br /><br />
you guys rock in advance! <img src="https://icrontic.com/resources/icrontimoji/respect.gif" title=":respect:" alt=":respect:" />]]>
        </description>
    </item>
    <item>
        <title>Please help me remove</title>
        <link>https://icrontic.com/discussion/87910/please-help-me-remove</link>
        <pubDate>Mon, 25 Jan 2010 09:17:06 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator></dc:creator>
        <guid isPermaLink="false">87910@/discussions</guid>
        <description><![CDATA[I have found what I think is a virus on my computer. I keep having web sites on my history and none of us have visited those sites. I believe the culpert to be " ad.reduxmedia.com ". Has anyone ever heard of this? It keeps popping up with the pop up blocker on. I also havelem maybe caused by this visrus. I keep getting the message " internet explore has stopped working... it comes on everytime I visit a website. Please help if you can.]]>
        </description>
    </item>
    <item>
        <title>Computer will only boot up in Safe Mode</title>
        <link>https://icrontic.com/discussion/87889/computer-will-only-boot-up-in-safe-mode</link>
        <pubDate>Fri, 22 Jan 2010 23:43:16 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>Nutty110</dc:creator>
        <guid isPermaLink="false">87889@/discussions</guid>
        <description><![CDATA[Computer will only boot up in Safe Mode<br />
All attempts to boot normally my screen locks up when the icons start<br />
loading up.
<hr />
here is a highjackthis log..........<br /><br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 11:42:25 PM, on 01/22/2010<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Safe mode with network support<br /><br />
Running processes:<br />
G:\Windows\System32\smss.exe<br />
G:\Windows\system32\winlogon.exe<br />
G:\Windows\system32\services.exe<br />
G:\Windows\system32\lsass.exe<br />
G:\Windows\system32\svchost.exe<br />
G:\Windows\system32\svchost.exe<br />
G:\Windows\Explorer.EXE<br />
G:\Program Files\Internet Explorer\iexplore.exe<br />
G:\Windows\system32\ctfmon.exe<br />
G:\Program Files\Internet Explorer\iexplore.exe<br />
G:\Utilities\Hijackthis\HijackThis.exe<br /><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.google.ca/" rel="nofollow">http://www.google.ca/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
O2 - BHO: (no name) - {02478d38-c3f9-4efb-9b51-7695eca05670} - (no file)<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - G:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - G:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - G:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - (no file)<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - G:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - G:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - G:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: &amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - G:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - G:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [PSDrvCheck] G:\WINDOWS\system32\PSDrvCheck.exe<br />
O4 - HKLM\..\Run: [ATICCC] "G:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "G:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br />
O4 - HKLM\..\Run: [TkBellExe] "G:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "G:\Program Files\Java\jre6\bin\jusched.exe"<br />
O4 - HKLM\..\Run: [Google Quick Search Box] "G:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe"  /autorun<br />
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Comodo AntiVirus\Comodo\COMODO Internet Security\cfp.exe" -h<br />
O4 - HKLM\..\Run: [Adobe ARM] "G:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"<br />
O4 - HKCU\..\Run: [NBJ] "G:\Program Files\Ahead\Nero BackItUp\NBJ.exe"<br />
O4 - HKCU\..\Run: [ctfmon.exe] G:\Windows\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [swg] "G:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://G:\UTILIT~1\MICROS~1\Office10\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Google Sidewiki... - res://G:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html<br />
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - G:\Windows\bdoscandel.exe<br />
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - G:\Windows\bdoscandel.exe<br />
O9 - Extra button: UB - {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} - G:\Windows\System32\shdocvw.dll (HKCU)<br />
O9 - Extra 'Tools' menuitem: UB - {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} - G:\Windows\System32\shdocvw.dll (HKCU)<br />
O16 - DPF: Garmin Communicator Plug-In - <a href="https://my.garmin.com/mygarmin/m/GarminAxControl.CAB" rel="nofollow">https://my.garmin.com/mygarmin/m/GarminAxControl.CAB</a><br />
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - <a href="http://www.creative.com/su/ocx/15015/CTSUEng.cab" rel="nofollow">http://www.creative.com/su/ocx/15015/CTSUEng.cab</a><br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a href="http://go.microsoft.com/fwlink/?linkid=39204" rel="nofollow">http://go.microsoft.com/fwlink/?linkid=39204</a><br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - G:\Program Files\Yahoo!\Common\yinsthelper.dll<br />
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - <a href="http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-24-0.cab" rel="nofollow">http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-24-0.cab</a><br />
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - <a href="http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab" rel="nofollow">http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab</a><br />
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - <a href="http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase4009.cab" rel="nofollow">http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase4009.cab</a><br />
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - <a href="http://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.info.apple.com/mickey/us/win/QuickTimeInstaller.exe" rel="nofollow">http://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.info.apple.com/mickey/us/win/QuickTimeInstaller.exe</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1136916728625" rel="nofollow">http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1136916728625</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1160562902890" rel="nofollow">http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1160562902890</a><br />
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - <a href="http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab" rel="nofollow">http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab</a><br />
O16 - DPF: {7530bfb8-7293-4d34-9923-61a11451afc5} (OnlineScanner Control) - <a href="http://download.eset.com/special/eos/OnlineScanner.cab" rel="nofollow">http://download.eset.com/special/eos/OnlineScanner.cab</a><br />
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} - <a href="http://www.bitdefender.com/scan/Msie/bitdefender.cab" rel="nofollow">http://www.bitdefender.com/scan/Msie/bitdefender.cab</a><br />
O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} (DDRevision Class) - <a href="http://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab" rel="nofollow">http://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab</a><br />
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - <a href="http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab" rel="nofollow">http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" rel="nofollow">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - <a href="http://www.creative.com/su/ocx/15021/CTPID.cab" rel="nofollow">http://www.creative.com/su/ocx/15021/CTPID.cab</a><br />
O16 - DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} (Flash Casino Helper Control) - <a href="https://plugins.valueactive.eu/flashax/iefax.cab" rel="nofollow">https://plugins.valueactive.eu/flashax/iefax.cab</a><br />
O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} (H2hPool Control) - <a href="http://mirror.worldwinner.com//games/v47/h2hpool/h2hpool.cab" rel="nofollow">http://mirror.worldwinner.com//games/v47/h2hpool/h2hpool.cab</a><br />
O20 - AppInit_DLLs:  G:\WINDOWS\system32\guard32.dll G:\Windows\system32\guard32.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - G:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - G:\Windows\system32\Ati2evxx.exe<br />
O23 - Service: ATI Smart - Unknown owner - G:\WINDOWS\system32\ati2sgag.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - G:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Comodo AntiVirus\Comodo\COMODO Internet Security\cmdagent.exe<br />
O23 - Service: GEARSecurity - GEAR Software - G:\Windows\System32\GEARSec.exe<br />
O23 - Service: Google Desktop Manager 5.5.709.30344 (GoogleDesktopManager-093007-112848) - Google - G:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - G:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: iPod Service - Apple Inc. - G:\Utilities\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - G:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Microsoft .NET Framework v1.1.4322 Update (NetFxUpdate_v1.1.4322) - Unknown owner - G:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe (file missing)<br />
O23 - Service: Pml Driver HPZ12 - HP - G:\WINDOWS\System32\HPZipm12.exe<br />
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - G:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe<br /><br />
--<br />
End of file - 9009 bytes]]>
        </description>
    </item>
    <item>
        <title>Google redirect</title>
        <link>https://icrontic.com/discussion/87896/google-redirect</link>
        <pubDate>Sat, 23 Jan 2010 17:49:29 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>ammexico</dc:creator>
        <guid isPermaLink="false">87896@/discussions</guid>
        <description><![CDATA[Hello,<br />
I was helping my uncle fix a virus (Windows defender 2010 or something like that). After running spybot and combofix I was able to get some control back, however it seems that not all has been fixed. Google redirects to searchclick8.com and I cant get rid of a toolbar "Mirar". Also I cant get windows automatic updates working and when trying to install malwarebytes the .exe is deleted. I used gooredfix and it fixes it for about 2 mins. Any help would be greatly appreciated. Attached are the latest combofix and hjt logs.]]>
        </description>
    </item>
    <item>
        <title>Nasty Malware is taking over my computer</title>
        <link>https://icrontic.com/discussion/87893/nasty-malware-is-taking-over-my-computer</link>
        <pubDate>Sat, 23 Jan 2010 15:37:42 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator></dc:creator>
        <guid isPermaLink="false">87893@/discussions</guid>
        <description><![CDATA[This virus is changing my background to make it say that i have a virus and i have run a few scans from Kaspersky and it tells me that there is something in the system memory but I can not get it to get rid of it.  It also blocked some webpages.<br /><br />
Here is the highjack this log:<br /><br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 3:33:00 PM, on 1/23/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)<br />
Boot mode: Normal<br /><br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe<br />
C:\WINDOWS\system32\HPZipm12.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\PowerISO\PWRISOVM.EXE<br />
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe<br />
C:\WINDOWS\system32\RUNDLL32.EXE<br />
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\WINDOWS\system32\smss32.exe<br />
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\HOTALBUMMyBOX\MediaChecker.exe<br />
C:\WINDOWS\system32\devldr32.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtblfs.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br /><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\winlogon32.exe<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)<br />
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll<br />
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br />
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll<br />
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE<br />
O4 - HKLM\..\Run: [MBBalloon] C:\Program Files\HOTALBUMMyBOX\MBBalloon.exe<br />
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br />
O4 - HKLM\..\Run: [smss32.exe] C:\WINDOWS\system32\smss32.exe<br />
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKUS\S-1-5-18\..\Run: [Internet Security 2010] C:\Program Files\InternetSecurity2010\IS2010.exe (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [Internet Security 2010] C:\Program Files\InternetSecurity2010\IS2010.exe (User 'Default user')<br />
O4 - Global Startup: MediaChecker.lnk = C:\Program Files\HOTALBUMMyBOX\MediaChecker.exe<br />
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: &amp;Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe<br />
O9 - Extra button: URLs c&amp;heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: <a href="https://icrontic.com/profile/xpsp3res" rel="nofollow">@xpsp3res</a>.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\helper32.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\helper32.dll<br />
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} - <a href="https://config.skillcheck.com/onlinetesting/icaclients/win32/10.0/onlinetesting.cab" rel="nofollow">https://config.skillcheck.com/onlinetesting/icaclients/win32/10.0/onlinetesting.cab</a><br />
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - <a href="http://asp.mathxl.com/wizmodules/testgen/installers/TestGenXInstall.cab" rel="nofollow">http://asp.mathxl.com/wizmodules/testgen/installers/TestGenXInstall.cab</a><br />
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - <a href="http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab" rel="nofollow">http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab</a><br />
O16 - DPF: {EEC9DBCC-04AD-4A1B-BEA7-C6DAD9515D5A} (Pearson MyEconLab Player Control) - <a href="http://asp.mathxl.com/books/_Players/EconPlayer.cab" rel="nofollow">http://asp.mathxl.com/books/_Players/EconPlayer.cab</a><br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: LiveShare P2P Server 10 (RoxLiveShare10) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe (file missing)<br />
O23 - Service: SessionLauncher - Unknown owner - C:\DOCUME~1\KYLES~1\LOCALS~1\Temp\DX9\SessionLauncher.exe (file missing)<br /><br />
--<br />
End of file - 8223 bytes]]>
        </description>
    </item>
    <item>
        <title>Help! In virus hell!</title>
        <link>https://icrontic.com/discussion/87875/help-in-virus-hell</link>
        <pubDate>Fri, 22 Jan 2010 07:38:31 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator></dc:creator>
        <guid isPermaLink="false">87875@/discussions</guid>
        <description><![CDATA[I have downloaded every malware program and avirus protection I could find but nothing helps. I have no idea if it is coincidence or not but I updated to IE8, had a lot of problems, and the went back to IE7. Had nothing but problems since. The new anti-virus program I installed (avira) has been popping up constantly with trojan warnings. If anyone can help I sure would appreciate it.<br />
Thank you, Patty<br />
(hijack log)<br /><br />
Logfile of Trend Micro HijackThis v2.0.3 (BETA)<br />
Scan saved at 6:30:42 AM, on 1/22/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16981)<br />
Boot mode: Normal<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\csrss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe<br />
C:\windows\system\hpsysdrv.exe<br />
C:\WINDOWS\system32\hphmon06.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
C:\Program Files\LSI SoftModem\agrsmsvc.exe<br />
C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe<br />
C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\hp\patches\51WW1VIA\src\VTTimer.exe<br />
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\iWin Games\iWinTrusted.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
c:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\WINDOWS\ALCWZRD.EXE<br />
C:\WINDOWS\ALCMTR.EXE<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br />
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe<br />
C:\Program Files\ThreatFire\TFTray.exe<br />
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\ThreatFire\TFService.exe<br />
C:\WINDOWS\system32\SearchIndexer.exe<br />
C:\Program Files\Windows Media Player\WMPNetwk.exe<br />
C:\WINDOWS\system32\wbem\unsecapp.exe<br />
C:\WINDOWS\system32\wbem\wmiprvse.exe<br />
C:\WINDOWS\System32\alg.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=Q105&amp;bd=pavilion&amp;pf=desktop" rel="nofollow">http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=Q105&amp;bd=pavilion&amp;pf=desktop</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iesearch&amp;locale=EN_US&amp;c=Q105&amp;bd=pavilion&amp;pf=desktop" rel="nofollow">http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iesearch&amp;locale=EN_US&amp;c=Q105&amp;bd=pavilion&amp;pf=desktop</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://att.my.yahoo.com/" rel="nofollow">http://att.my.yahoo.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iesearch&amp;locale=EN_US&amp;c=Q105&amp;bd=pavilion&amp;pf=desktop" rel="nofollow">http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iesearch&amp;locale=EN_US&amp;c=Q105&amp;bd=pavilion&amp;pf=desktop</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=Q105&amp;bd=pavilion&amp;pf=desktop" rel="nofollow">http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=Q105&amp;bd=pavilion&amp;pf=desktop</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local<br />
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)<br />
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: (no name) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - (no file)<br />
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search &amp; Destroy\SDHelper.dll<br />
O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)<br />
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll<br />
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll<br />
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe<br />
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe<br />
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe<br />
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKLM\..\Run: [WrtMon.exe] C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe<br />
O4 - HKLM\..\Run: [VTTimer] C:\hp\patches\51WW1VIA\src\VTTimer.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br />
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE<br />
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE<br />
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE<br />
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br />
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br />
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe<br />
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE<br />
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"<br />
O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe<br />
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br />
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1103471 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"<a href="http://www.gamevial.com/bbgames/teamtanks.html" rel="nofollow">http://www.gamevial.com/bbgames/teamtanks.html</a>"<br />
O8 - Extra context menu item: &amp;eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html<br />
O8 - Extra context menu item: &amp;ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM<br />
O8 - Extra context menu item: &amp;Search - ?p=ZCxdm594YYUS<br />
O8 - Extra context menu item: Check &amp;Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html<br />
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html<br />
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html<br />
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html<br />
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html<br />
O8 - Extra context menu item: Lookup on Merriam Webster - [URL]file://C:\Program[/URL] Files\ieSpell\Merriam Webster.HTM<br />
O8 - Extra context menu item: Lookup on Wikipedia - [URL]file://C:\Program[/URL] Files\ieSpell\wikipedia.HTM<br />
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll<br />
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll<br />
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll<br />
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search &amp; Destroy\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp;&amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search &amp; Destroy\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: <a href="https://icrontic.com/profile/xpsp3res" rel="nofollow">@xpsp3res</a>.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll<br />
O16 - DPF: Ali Baba Slots TM by pogo - <a href="http://game1.pogo.com/applet-6.9.0.43/slots/alibaba-en_US.cab" rel="nofollow">http://game1.pogo.com/applet-6.9.0.43/slots/alibaba-en_US.cab</a><br />
O16 - DPF: Animal Ark by pogo - <a href="http://www.pogo.com/applet-6.3.1.33/animal/animal-ob-assets.cab" rel="nofollow">http://www.pogo.com/applet-6.3.1.33/animal/animal-ob-assets.cab</a><br />
O16 - DPF: Bingo Luau by pogo - <a href="http://game3.pogo.com/v/9.0.1.7/applet/freebingo/freebingo-en_US.cab" rel="nofollow">http://game3.pogo.com/v/9.0.1.7/applet/freebingo/freebingo-en_US.cab</a><br />
O16 - DPF: First Class Solitaire by pogo - <a href="http://game3.pogo.com/v/8.1.9.1/applet/firstclass2/firstclass2-en_US.cab" rel="nofollow">http://game3.pogo.com/v/8.1.9.1/applet/firstclass2/firstclass2-en_US.cab</a><br />
O16 - DPF: Fortune Bingo by pogo - <a href="http://game1.pogo.com/v/8.1.9.1/applet/superbingo/superbingo-en_US.cab" rel="nofollow">http://game1.pogo.com/v/8.1.9.1/applet/superbingo/superbingo-en_US.cab</a><br />
O16 - DPF: High Stakes Poker by pogo - <a href="http://game3.pogo.com/v/8.1.9.1/applet/drawpoker/drawpoker-en_US.cab" rel="nofollow">http://game3.pogo.com/v/8.1.9.1/applet/drawpoker/drawpoker-en_US.cab</a><br />
O16 - DPF: High Stakes Pool by pogo - <a href="http://game1.pogo.com/applet-6.3.1.33/pool2/pool-ob-assets.cab" rel="nofollow">http://game1.pogo.com/applet-6.3.1.33/pool2/pool-ob-assets.cab</a><br />
O16 - DPF: Hog Heaven Slots by pogo - <a href="http://game1.pogo.com/applet-6.9.0.43/fancy/fancy-en_US.cab" rel="nofollow">http://game1.pogo.com/applet-6.9.0.43/fancy/fancy-en_US.cab</a><br />
O16 - DPF: Jungle Gin by pogo - <a href="http://game3.pogo.com/v/9.2.0.14/applet/gin2/gin2-en_US.cab" rel="nofollow">http://game3.pogo.com/v/9.2.0.14/applet/gin2/gin2-en_US.cab</a><br />
O16 - DPF: Mah Jong Garden by pogo - <a href="http://game3.pogo.com/v/9.2.4.13/applet/mahjong2/mahjong2-en_US.cab" rel="nofollow">http://game3.pogo.com/v/9.2.4.13/applet/mahjong2/mahjong2-en_US.cab</a><br />
O16 - DPF: NASCAR Web Racing by pogo - <a href="http://game1.pogo.com/applet-6.3.0.53/nascar/nascar-ob-assets.cab" rel="nofollow">http://game1.pogo.com/applet-6.3.0.53/nascar/nascar-ob-assets.cab</a><br />
O16 - DPF: Penguin Blocks by pogo - <a href="http://game1.pogo.com/applet-6.5.2.33/penguins/penguins-en_US.cab" rel="nofollow">http://game1.pogo.com/applet-6.5.2.33/penguins/penguins-en_US.cab</a><br />
O16 - DPF: Pirate's Gold by pogo - <a href="http://game1.pogo.com/applet-6.3.1.33/piratesgold/piratesgold-ob-assets.cab" rel="nofollow">http://game1.pogo.com/applet-6.3.1.33/piratesgold/piratesgold-ob-assets.cab</a><br />
O16 - DPF: Pop Fu by pogo - <a href="http://game1.pogo.com/applet-6.4.4.34/popfu/popfu-ob-assets.cab" rel="nofollow">http://game1.pogo.com/applet-6.4.4.34/popfu/popfu-ob-assets.cab</a><br />
O16 - DPF: PoppaZoppa by pogo - <a href="http://game1.pogo.com/applet-6.8.2.23/poppazoppa/poppazoppa-en_US.cab" rel="nofollow">http://game1.pogo.com/applet-6.8.2.23/poppazoppa/poppazoppa-en_US.cab</a><br />
O16 - DPF: Poppit by pogo - <a href="http://game3.pogo.com/v/8.1.9.11/applet/poppit2/poppit2-en_US.cab" rel="nofollow">http://game3.pogo.com/v/8.1.9.11/applet/poppit2/poppit2-en_US.cab</a><br />
O16 - DPF: QWERTY by pogo - <a href="http://game3.pogo.com/v/9.2.4.18/applet/squares/squares-en_US.cab" rel="nofollow">http://game3.pogo.com/v/9.2.4.18/applet/squares/squares-en_US.cab</a><br />
O16 - DPF: SciFi Slots by pogo - <a href="http://game1.pogo.com/applet-6.9.0.43/slots/scifi-en_US.cab" rel="nofollow">http://game1.pogo.com/applet-6.9.0.43/slots/scifi-en_US.cab</a><br />
O16 - DPF: Stellar Sweeper by pogo - <a href="http://game1.pogo.com/applet-6.4.4.34/sweeper/sweeper-ob-assets.cab" rel="nofollow">http://game1.pogo.com/applet-6.4.4.34/sweeper/sweeper-ob-assets.cab</a><br />
O16 - DPF: Sweet Tooth TM by pogo - <a href="http://game1.pogo.com/applet-6.9.0.43/sweettooth/sweettooth-en_US.cab" rel="nofollow">http://game1.pogo.com/applet-6.9.0.43/sweettooth/sweettooth-en_US.cab</a><br />
O16 - DPF: Tank Hunter by pogo - <a href="http://www.pogo.com/applet-6.3.1.33/tank/tank-ob-assets.cab" rel="nofollow">http://www.pogo.com/applet-6.3.1.33/tank/tank-ob-assets.cab</a><br />
O16 - DPF: The Sims Pinball by pogo - <a href="http://game1.pogo.com/applet-6.3.1.33/simball/simball-ob-assets.cab" rel="nofollow">http://game1.pogo.com/applet-6.3.1.33/simball/simball-ob-assets.cab</a><br />
O16 - DPF: Tri-Peaks by pogo - <a href="http://game3.pogo.com/v/9.2.4.6/applet/peaks/peaks-en_US.cab" rel="nofollow">http://game3.pogo.com/v/9.2.4.6/applet/peaks/peaks-en_US.cab</a><br />
O16 - DPF: Tumble Bees by pogo - <a href="http://game3.pogo.com/v/9.2.0.14/applet/tumbee2/tumbee2-en_US.cab" rel="nofollow">http://game3.pogo.com/v/9.2.0.14/applet/tumbee2/tumbee2-en_US.cab</a><br />
O16 - DPF: Wonderland Memories by pogo - <a href="http://game1.pogo.com/applet-6.5.2.33/memories/memories-en_US.cab" rel="nofollow">http://game1.pogo.com/applet-6.5.2.33/memories/memories-en_US.cab</a><br />
O16 - DPF: Word Craft by pogo - <a href="http://game3.pogo.com/v/9.1.7.20/applet/babble/babble-en_US.cab" rel="nofollow">http://game3.pogo.com/v/9.1.7.20/applet/babble/babble-en_US.cab</a><br />
O16 - DPF: Word Search Daily by pogo - <a href="http://game3.pogo.com/v/9.2.2.4/applet/wordsearch/wordsearch-en_US.cab" rel="nofollow">http://game3.pogo.com/v/9.2.2.4/applet/wordsearch/wordsearch-en_US.cab</a><br />
O16 - DPF: Word Whomp by pogo - <a href="http://game1.pogo.com/v/8.1.7.44/applet/wordwhomp2/whomp2-en_US.cab" rel="nofollow">http://game1.pogo.com/v/8.1.7.44/applet/wordwhomp2/whomp2-en_US.cab</a><br />
O16 - DPF: Word Whomp Whackdown by pogo - <a href="http://game3.pogo.com/v/9.2.4.6/applet/whackdown/whackdown-en_US.cab" rel="nofollow">http://game3.pogo.com/v/9.2.4.6/applet/whackdown/whackdown-en_US.cab</a><br />
O16 - DPF: WordJong by pogo - <a href="http://game3.pogo.com/v/9.0.1.7/applet/wordjong/wordjong-en_US.cab" rel="nofollow">http://game3.pogo.com/v/9.0.1.7/applet/wordjong/wordjong-en_US.cab</a><br />
O16 - DPF: Yahoo! Chinese Checkers - <a href="http://download.games.yahoo.com/games/clients/y/cct0_x.cab" rel="nofollow">http://download.games.yahoo.com/games/clients/y/cct0_x.cab</a><br />
O16 - DPF: Yahoo! Word Racer - <a href="http://download2.games.yahoo.com/games/clients/y/wt1_x.cab" rel="nofollow">http://download2.games.yahoo.com/games/clients/y/wt1_x.cab</a><br />
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - <a href="http://housecall60.trendmicro.com/housecall/xscan60.cab" rel="nofollow">http://housecall60.trendmicro.com/housecall/xscan60.cab</a><br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll<br />
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} (PogoWebLauncher Control) - <a href="http://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB" rel="nofollow">http://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB</a><br />
O16 - DPF: {4FAE30E1-EE9C-477D-8D06-BF8D3429B60F} -<br />
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - <a href="http://fb.familylink.com/we_are_related/stream/core/lib/AurigmaImageUploader/ImageUploader5.cab" rel="nofollow">http://fb.familylink.com/we_are_related/stream/core/lib/AurigmaImageUploader/ImageUploader5.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120282568328" rel="nofollow">http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120282568328</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1133966564729" rel="nofollow">http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1133966564729</a><br />
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - <a href="http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab" rel="nofollow">http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab</a><br />
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - <a href="http://offers.e-centives.com/cif/download/bin/actxcab.cab" rel="nofollow">http://offers.e-centives.com/cif/download/bin/actxcab.cab</a><br />
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - <a href="http://www.linksysfix.com/netcheck/53/install/gtdownls.cab" rel="nofollow">http://www.linksysfix.com/netcheck/53/install/gtdownls.cab</a><br />
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - <a href="http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab" rel="nofollow">http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab</a><br />
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} (Java Plug-in 1.5.0_04) -<br />
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.5.0_06) -<br />
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} (Java Plug-in 1.5.0_09) -<br />
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} (Java Plug-in 1.6.0_05) -<br />
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} (Java Plug-in 1.6.0_07) -<br />
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} (Java Plug-in 1.6.0_13) -<br />
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -<br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" rel="nofollow">http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab</a><br />
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -<br />
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - <a href="http://clubgames.pogo.com/online2/pogop/insaniquarium/popcaploader_v6.cab" rel="nofollow">http://clubgames.pogo.com/online2/pogop/insaniquarium/popcaploader_v6.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" rel="nofollow">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - <a href="http://www.auctiva.com/hostedimages/activex/xupload/XUpload.ocx" rel="nofollow">http://www.auctiva.com/hostedimages/activex/xupload/XUpload.ocx</a><br />
O16 - DPF: {EF148DBB-5B6D-4130-B2A1-661571E86260} (Playtime Games Launcher) - <a href="http://download-games.pogo.com/online2/pogo/mahjong_escape_ancient/PTGameLauncher.cab" rel="nofollow">http://download-games.pogo.com/online2/pogo/mahjong_escape_ancient/PTGameLauncher.cab</a><br />
O16 - DPF: {FE5B9F54-7764-4C01-89F0-4862601EE954} (DigWebHelper Class) - <a href="http://photos.msn.com/resources/neutral/controls/DigWebX2.cab?10,0,910,0" rel="nofollow">http://photos.msn.com/resources/neutral/controls/DigWebX2.cab?10,0,910,0</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)<br />
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll<br />
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll<br />
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe<br />
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe<br />
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: BufferZone Service (BufferZoneSvc) - Unknown owner - C:\Program Files\BufferZone\ClntSvc.exe (file missing)<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: iWinGamesInstaller - Unknown owner - C:\Program Files\iWin Games\iWinGamesInstaller.exe (file missing)<br />
O23 - Service: iWinTrusted - iWin Inc. - C:\Program Files\iWin Games\iWinTrusted.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br />
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br />
O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe<br />
--<br />
End of file - 20304 bytes]]>
        </description>
    </item>
    <item>
        <title>DEP - Generic Host Process (and PC auto shutting down) after virii</title>
        <link>https://icrontic.com/discussion/87874/dep-generic-host-process-and-pc-auto-shutting-down-after-virii</link>
        <pubDate>Fri, 22 Jan 2010 07:08:16 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>The-Reverend</dc:creator>
        <guid isPermaLink="false">87874@/discussions</guid>
        <description><![CDATA[Hi there and apologies for the length of the post.<br /><br />
Having some major issues with my PC and was referred to here. Any help would be greatly appreciated! Here is what's happened so far:<br /><br />
I had AVG on my PC, the PC was behaving oddly and I installed Microsoft Security Essentials instead.  That picked up some viruses including trojans which I deleted. I was still having issues though and I didn't trust entering passwords etc. into web forms. Google searches in Firefox came up with links that didn't take me to the pages they should have done, I had to copy the shortcut and paste it into the url bar manually, not click through. Obviously still some Malware left on the system.<br /><br />
I installed Malwarebytes Anti-Malware which picked up a load more viruses missed by MSE. These were deleted by the program but one came back after each reboot, sdra64.exe, which I eventually got rid of with the help of a program called Process Explorer. I ran Malwarebytes Anti-Malware again to get rid of the other bits than the main exe left on the system, they deleted successfully. There were no more problems found by Anti-Malware.<br /><br />
Still Firefox was not working properly, it was also coming up with new tabs to the same sort of sites which Google links were redirecting to.  I was also, following removal of sdra64.exe (which showed up as svchost.exe in Tast Manager) getting seemingly random messages that Windows would be shutting down in 60 seconds and to save any work etc. I have got around this with the shutdown.exe -a command, but it keeps happening.<br /><br />
I tried to install Ad-Aware, and discovered Windows Installer was now not working. I found a fix for that, editing the registry then registering it or something similar, can't remember exactly, and installed Ad-Aware. That came up with some matches which I all deleted, although they looked like genuine files, part of online poker rooms to me.<br /><br />
I then also installed SUPERAntiSpyware, ran that, it too came up with matches (not sure if false positives or not) which I deleted.<br /><br />
I was then left with two problems. On bootup, as soon as Windows (XP with Service Pack 3) loads, I get a DEP message - "To help protect your computer, Windows has closed this program."<br /><br />
Name: Generic Host Process for Win32 Services<br />
Publisher: Microsoft Corporation<br /><br />
If I close the message I get the option to report error to Microsoft, if I do or just say no, I get the same DEP message come straight back up again, so I always have this window on when Windows is booted. Annoying but no biggie. I'm more concerned that this is the sdra64.exe virus being stopped running/doing something again (although where on the system it's still hiding I don't know), so I do not want to turn off DEP.<br /><br />
The more serious issue is that the 60 second shutdown warning still keeps popping up. If I'm not at my PC to abort it will reset in the middle of whatever work I've got open.... "Windows must now restart because the DCOM Server Process Launcher service terminated unexpectedly"<br /><br />
All the programs I've listed above now show my PC as clean. As per the FAQ here I downloaded Hijack This. Again the Windows Installer wouldn't work but I reinstalled that from the Microsoft site and Hijack This did install. This is the log:<br /><br />
Logfile of Trend Micro HijackThis v2.0.3 (BETA)<br />
Scan saved at 11:31:33 AM, on 01/22/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br /><br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe<br />
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Microsoft Security Essentials\msseces.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\WINDOWS\system32\dumprep.exe<br />
C:\Program Files\LogMeIn\x86\LMIGuardian.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\runservice.exe<br />
C:\Program Files\Skype\Phone\Skype.exe<br />
C:\Program Files\LogMeIn\x86\RaMaint.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Program Files\LogMeIn\x86\LogMeIn.exe<br />
C:\Program Files\LogMeIn\x86\LMIGuardian.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\system32\PnkBstrA.exe<br />
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\Windows Live\Contacts\wlcomm.exe<br />
C:\Program Files\Skype\Plugin Manager\skypePM.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\WINDOWS\system32\msiexec.exe<br />
C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe<br /><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.thehendonmob.com/" rel="nofollow">http://www.thehendonmob.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"<br />
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br />
O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide<br />
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u<br />
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background<br />
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized<br />
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')<br />
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html<br />
O9 - Extra button: InterCasino Â£Â£Â£ - {03588886-5C50-4645-BD5D-F105F84417DE} - C:\Documents and Settings\Rob\Desktop\InterCasino Â£Â£Â£.lnk (file missing)<br />
O9 - Extra 'Tools' menuitem: InterCasino Â£Â£Â£ - {03588886-5C50-4645-BD5D-F105F84417DE} - C:\Documents and Settings\Rob\Desktop\InterCasino Â£Â£Â£.lnk (file missing)<br />
O9 - Extra button: Coral Eurobet Poker - {050AC5CD-E1E1-41ab-8CE0-61B56EFA7FA1} - C:\Program Files\CoralEurobetPoker\coraleurobetpoker.exe (file missing)<br />
O9 - Extra 'Tools' menuitem: Coral Eurobet Poker - {050AC5CD-E1E1-41ab-8CE0-61B56EFA7FA1} - C:\Program Files\CoralEurobetPoker\coraleurobetpoker.exe (file missing)<br />
O9 - Extra button: Casino-on-Net  - {3015DB92-158E-4b77-9020-85C8E311FBB5} - C:\PROGRA~1\CASINO~1\Casino.exe (file missing)<br />
O9 - Extra button: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - C:\Documents and Settings\Rob\Desktop\WH GBP Casino.lnk (file missing)<br />
O9 - Extra 'Tools' menuitem: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - C:\Documents and Settings\Rob\Desktop\WH GBP Casino.lnk (file missing)<br />
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe<br />
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePokerMaster\EmpirePoker\RunEPoker.exe (file missing)<br />
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePokerMaster\EmpirePoker\RunEPoker.exe (file missing)<br />
O9 - Extra button: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe<br />
O9 - Extra 'Tools' menuitem: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe<br />
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe<br />
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe<br />
O9 - Extra button: Littlewoods Casino - {BAA37C20-5000-11DB-B0DE-0800200C9A66} - C:\Documents and Settings\Rob\Desktop\Littlewoods Casino.lnk (file missing)<br />
O9 - Extra 'Tools' menuitem: Littlewoods Casino - {BAA37C20-5000-11DB-B0DE-0800200C9A66} - C:\Documents and Settings\Rob\Desktop\Littlewoods Casino.lnk (file missing)<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: <a href="https://icrontic.com/profile/xpsp3res" rel="nofollow">@xpsp3res</a>.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra button: InterCasino Â£Â£Â£ - {03588886-5C50-4645-BD5D-F105F84417DE} - C:\Documents and Settings\Rob\Desktop\InterCasino Â£Â£Â£.lnk (file missing) (HKCU)<br />
O9 - Extra 'Tools' menuitem: InterCasino Â£Â£Â£ - {03588886-5C50-4645-BD5D-F105F84417DE} - C:\Documents and Settings\Rob\Desktop\InterCasino Â£Â£Â£.lnk (file missing) (HKCU)<br />
O9 - Extra button: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - <a href="http://www.williamhillcasino.com" rel="nofollow">http://www.williamhillcasino.com</a> (file missing) (HKCU)<br />
O9 - Extra 'Tools' menuitem: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - <a href="http://www.williamhillcasino.com" rel="nofollow">http://www.williamhillcasino.com</a> (file missing) (HKCU)<br />
O9 - Extra button: Littlewoods Casino - {BAA37C20-5000-11DB-B0DE-0800200C9A66} - <a href="http://www.littlewoodscasino.com" rel="nofollow">http://www.littlewoodscasino.com</a> (file missing) (HKCU)<br />
O9 - Extra 'Tools' menuitem: Littlewoods Casino - {BAA37C20-5000-11DB-B0DE-0800200C9A66} - <a href="http://www.littlewoodscasino.com" rel="nofollow">http://www.littlewoodscasino.com</a> (file missing) (HKCU)<br />
O16 - DPF: {0835BC90-6ABC-4F52-A103-4FC3A61F2C33} (A18X Control) - <a href="http://www.albatross18.com/cabs/A18X.ocx" rel="nofollow">http://www.albatross18.com/cabs/A18X.ocx</a><br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a href="http://go.microsoft.com/fwlink/?linkid=39204" rel="nofollow">http://go.microsoft.com/fwlink/?linkid=39204</a><br />
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - <a href="http://www1.snapfish.co.uk/SnapfishUKActivia.cab" rel="nofollow">http://www1.snapfish.co.uk/SnapfishUKActivia.cab</a><br />
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - <a href="http://download.divx.com/webplayer/stage6/windows/DivXBrowserPlugin.cab" rel="nofollow">http://download.divx.com/webplayer/stage6/windows/DivXBrowserPlugin.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1161722446828" rel="nofollow">http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1161722446828</a><br />
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - <a href="http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab" rel="nofollow">http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" rel="nofollow">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - <a href="https://secure.logmein.com/activex/ractrl.cab?lmi=100" rel="nofollow">https://secure.logmein.com/activex/ractrl.cab?lmi=100</a><br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O20 - AppInit_DLLs: C:\WINDOWS\system32\curslib.dll<br />
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll<br />
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll<br />
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll<br />
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe<br />
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe<br />
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: PostgreSQL Database Server 8.0 (pgsql-8.0) - PostgreSQL Global Development Group - C:\Program Files\PostgreSQL\8.0\bin\pg_ctl.exe<br />
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe<br />
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe<br /><br />
--<br />
End of file - 12023 bytes<br /><br />
This may not qualify as a virus/spyware problem any more, I really don't know, so apologies if I have posted in the wrong section. Please let me know if so and I'll post elsewhere.<br /><br />
I am out of ideas myself now. I can't find my XP Home CD and really don't want to do a format/reinstall anyhow. I do have an unused XP Professional CD with key here if that is of any use.<br />
Many thanks for any help you can give me!<br /><br />
Rob]]>
        </description>
    </item>
    <item>
        <title>i need help again..</title>
        <link>https://icrontic.com/discussion/87855/i-need-help-again</link>
        <pubDate>Thu, 21 Jan 2010 15:28:51 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>ushio-chan</dc:creator>
        <guid isPermaLink="false">87855@/discussions</guid>
        <description><![CDATA[i think a problem like this was already posted before but i seem to be having a problem with my avira anti-virus software. i don't know what's wrong but it won't update anymore and when i try to do it manually it takes forever and nothing seems to be happining. please someone help and tell me what should i do to make it start updating again thx you very much.]]>
        </description>
    </item>
    <item>
        <title>Desktop Hijacked</title>
        <link>https://icrontic.com/discussion/87863/desktop-hijacked</link>
        <pubDate>Thu, 21 Jan 2010 17:24:51 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator></dc:creator>
        <guid isPermaLink="false">87863@/discussions</guid>
        <description><![CDATA[My desktop on XP has been hijacked. Start menu flashed on/off. Cannot use taskbar. Cannot start browsers running. MyComputer does not show directories. Cannot type into text fields.<br /><br />
Ran Mcaffee, found no virus, trojans, etc.<br /><br />
Tried restoring default desktop settings, made things worse. Cannot login now with Admin password.<br /><br />
tried downloading Desktop Hijacking fix 1.3.8, did not work either.<br /><br />
Does anyone know anything about this malware?]]>
        </description>
    </item>
    <item>
        <title>Broswer keeps being redirected</title>
        <link>https://icrontic.com/discussion/87828/broswer-keeps-being-redirected</link>
        <pubDate>Wed, 20 Jan 2010 14:08:21 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator></dc:creator>
        <guid isPermaLink="false">87828@/discussions</guid>
        <description><![CDATA[As of yesterday, my computer has been acting funny. While surfing the web, tabs that I have opened are redirected to various sites or new windows pop up with different sites. Usually the windows are redirected to generic search sites and uses keywords that I was previously typing. As I wrote this, I did a google search for "How to catch a crab", clicked on one link and as I let the window idle it was redirected to this<br /><pre spellcheck="false" tabindex="0">http://www.allthebrands.com/search-results.aspx?keywords=crab
</pre>
<br />
I ran startup mechanic to see if I could find any definite changes and found that under the "Harmful" Tab the entry "RunNarrator" with the command of "Narrator.exe" and the description of "QOOLOGIC TROJAN". I know that Startup Mechanic tends to show a lot of false positives, so I'm not really sure whats going on.<br /><br /><br />
Hijack This Log
<pre spellcheck="false" tabindex="0">Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 1:00:25 PM, on 1/20/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Startup Mechanic\StartupMonitor.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Startup Manager Scanner] C:\Program Files\Startup Mechanic\StartupMonitor.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Steam] "c:\program files\steamg\steam.exe" -silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Auto Shutdown.lnk = C:\Program Files\Auto Shutdown\AutoShutdown.exe
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Amy\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1242155351515
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe

--
End of file - 7190 bytes
</pre>
<br />
Your Help is appreciated]]>
        </description>
    </item>
    <item>
        <title>PC...runs...too...slow...ly...HELP!</title>
        <link>https://icrontic.com/discussion/87175/pc-runs-too-slow-ly-help</link>
        <pubDate>Wed, 09 Dec 2009 21:54:51 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>panget</dc:creator>
        <guid isPermaLink="false">87175@/discussions</guid>
        <description><![CDATA[Hello,<br /><br />
Something went wrong with my PC.  Start up takes too much time to download.  Could there be a spyware inside?<br /><br />
Here is my log.  Hope you could respond the soonest.  Thank you.<br /><br />
Logfile of HijackThis v1.99.1<br />
Scan saved at 10:54, on 2009-12-10<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)<br /><br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\ctfmon.exe<br />
E:\hijackthis\HijackThis.exe<br />
C:\Documents and Settings\inkfinity center\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\inkfinity center\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\inkfinity center\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\inkfinity center\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br /><br />
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\PROGRA~1\FlashGet\jccatch.dll<br />
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll<br />
O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\PROGRA~1\FlashGet\getflash.dll<br />
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll<br />
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll<br />
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (file missing)<br />
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min<br />
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br />
O4 - HKLM\..\Run: [Auto EPSON Stylus Photo R230 Series on USER-EB7F5E9936] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIP.EXE /P54 "Auto EPSON Stylus Photo R230 Series on USER-EB7F5E9936" /O27 "\\USER-EB7F5E9936\Printer17" /M "Stylus Photo R230"<br />
O4 - HKLM\..\Run: [USB Antivirus] C:\Program Files\USB Disk Security\USBGuard.exe<br />
O4 - HKLM\..\Run: [EPSON Stylus Photo R230 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIP.EXE /P39 "EPSON Stylus Photo R230 Series (Copy 1)" /O6 "USB019" /M "Stylus Photo R230"<br />
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br />
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start<br />
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC<br />
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName<br />
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32<br />
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon<br />
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br />
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent<br />
O4 - HKLM\..\Run: [EPSON Stylus Photo R310 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P30 "EPSON Stylus Photo R310 Series" /O6 "USB014" /M "Stylus Photo R310"<br />
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"<br />
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h<br />
O4 - HKCU\..\Run: [EPSON Stylus Photo R290 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICKP.EXE /FU "C:\WINDOWS\TEMP\E_SAD.tmp" /EF "HKCU"<br />
O4 - HKCU\..\Run: [EPSON Stylus T10 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEBS.EXE /FU "C:\WINDOWS\TEMP\E_S73.tmp" /EF "HKCU"<br />
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\inkfinity center\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c<br />
O4 - HKCU\..\Run: [EPSON Stylus T10 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEBS.EXE /FU "C:\WINDOWS\TEMP\E_S6.tmp" /EF "HKCU"<br />
O4 - HKCU\..\Run: [EPSON Stylus Photo R230 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIP.EXE /FU "C:\WINDOWS\TEMP\E_S8.tmp" /EF "HKCU"<br />
O4 - HKCU\..\Run: [Videohost] C:\DOCUME~1\INKFIN~1\LOCALS~1\Temp\b.exe<br />
O4 - HKCU\..\Run: [EPSON Stylus T10 Series (Copy 2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEBS.EXE /FU "C:\WINDOWS\TEMP\E_SA.tmp" /EF "HKCU"<br />
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe<br />
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm<br />
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe<br />
O9 - Extra 'Tools' menuitem: &amp;FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)<br />
O9 - Extra 'Tools' menuitem: <a href="https://icrontic.com/profile/xpsp3res" rel="nofollow">@xpsp3res</a>.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - <a href="http://www.lizardtech.com/download/files/win/djvuplugin/en_US/DjVuControl_en_US.cab" rel="nofollow">http://www.lizardtech.com/download/files/win/djvuplugin/en_US/DjVuControl_en_US.cab</a><br />
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL<br />
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe<br />
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)<br />
O23 - Service: SQL Server (INFLOWSQL) (MSSQL$INFLOWSQL) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sINFLOWSQL (file missing)<br />
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe]]>
        </description>
    </item>
    <item>
        <title>Is this infected with &quot;about:blank&quot; virus?</title>
        <link>https://icrontic.com/discussion/87668/is-this-infected-with-about-blank-virus</link>
        <pubDate>Wed, 13 Jan 2010 01:30:34 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>Byron172</dc:creator>
        <guid isPermaLink="false">87668@/discussions</guid>
        <description><![CDATA[My mum's laptop has been slow of late so I have done a cleanup using CCleaner and run Malwarebytes quick scan just to check for any viruses.  I noticed as I was testing her Internet onnection that IE seems to try to goto about:blank before going to her homepage.  I thought that this was nothing to worry about but some research on the net made me a tadconcerned.  If anyone has a spare minute to look over the following HijackThis log file I will be very thankful:<br /><br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 4:27:51 PM, on 13/01/2010<br />
Platform: Windows Vista SP1 (WinNT 6.00.1905)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18865)<br />
Boot mode: Normal<br /><br />
Running processes:<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Program Files\ASUS\ASUS Live Update\ALU.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe<br />
C:\Windows\RtHDVCpl.exe<br />
C:\Program Files\ASUS\ATK Media\DMedia.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\ASUS\EZVCR\Agent.exe<br />
C:\Program Files\McAfee.com\Agent\mcagent.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Program Files\Skype\Phone\Skype.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\ASUS\Asus MultiFrame\MultiFrame.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Windows\System32\mobsync.exe<br />
C:\Program Files\Optus Wireless Broadband\Optus Wireless Broadband.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe<br />
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe<br />
C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br /><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.optuszoo.com.au/" rel="nofollow">http://www.optuszoo.com.au/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = <a href="http://au.search.yahoo.com/search?fr=mcafee&amp;p=%s" rel="nofollow">http://au.search.yahoo.com/search?fr=mcafee&amp;p=%s</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =<br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll<br />
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll<br />
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll<br />
O3 - Toolbar: Yahoo!7 Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe<br />
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br />
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [PowerForPhone] C:\Program Files\PowerForPhone\PowerForPhone.exe<br />
O4 - HKLM\..\Run: [EzAgent] C:\Program Files\ASUS\EZVCR\Agent.exe<br />
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey<br />
O4 - HKLM\..\Run: [NeroCheck] C:\Windows\system32\NeroCheck.exe<br />
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - Global Startup: MultiFrame.lnk = ?<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O13 - Gopher Prefix:<br />
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll<br />
O23 - Service: McAfee Application Installer Cleanup (0009001263356386) (0009001263356386mcinstcleanup) - McAfee, Inc. - C:\Windows\TEMP\000900~1.EXE<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)<br />
O23 - Service: Google Update Service (gupdate1ca08f024560980) (gupdate1ca08f024560980) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe<br />
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br />
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe<br />
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search &amp; Destroy\SDWinSec.exe<br />
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe<br />
O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\Windows\System32\StkCSrv.exe<br /><br />
--<br />
End of file - 9336 bytes]]>
        </description>
    </item>
    <item>
        <title>Just done a combofix scan...what do i do next?</title>
        <link>https://icrontic.com/discussion/87801/just-done-a-combofix-scan-what-do-i-do-next</link>
        <pubDate>Tue, 19 Jan 2010 16:50:06 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>tej125</dc:creator>
        <guid isPermaLink="false">87801@/discussions</guid>
        <description><![CDATA[ComboFix 10-01-19.01 - Tej 19/01/2010  21:34:16.1.4 - x86<br />
MicrosoftÂ® Windows Vistaâ„¢ Home Premium   6.0.6002.2.1252.44.1033.18.3325.2284 [GMT 0:00]<br />
Running from: c:\users\Tej\Desktop\ComboFix.exe<br />
.<br /><br />
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br /><br />
c:\windows\system32\twain_32.dll<br /><br />
.<br />
(((((((((((((((((((((((((   Files Created from 2009-12-19 to 2010-01-19  )))))))))))))))))))))))))))))))<br />
.<br /><br />
2010-01-18 02:43 . 2010-01-18 02:43
<hr />
d
<hr />
w-    c:\users\Tej\AppData\Roaming\Malwarebytes<br />
2010-01-18 02:43 . 2010-01-07 16:07    38224    ----a-w-    c:\windows\system32\drivers\mbamswissarmy.sys<br />
2010-01-18 02:43 . 2010-01-18 02:43
<hr />
d
<hr />
w-    c:\program files\Malwarebytes' Anti-Malware<br />
2010-01-18 02:43 . 2010-01-18 02:43
<hr />
d
<hr />
w-    c:\programdata\Malwarebytes<br />
2010-01-18 02:43 . 2010-01-07 16:07    19160    ----a-w-    c:\windows\system32\drivers\mbam.sys<br />
2010-01-17 19:21 . 2010-01-17 19:46
<hr />
d
<hr />
w-    C:\divx<br />
2010-01-17 16:55 . 2010-01-17 16:55
<hr />
d
<hr />
w-    c:\users\Tej\AppData\Roaming\AnvSoft<br />
2010-01-17 01:22 . 2009-10-19 13:38    156672    ----a-w-    c:\windows\system32\t2embed.dll<br />
2010-01-17 01:22 . 2009-10-19 13:35    72704    ----a-w-    c:\windows\system32\fontsub.dll<br /><br />
.<br />
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br />
2010-01-18 20:50 . 2008-11-01 15:52    0    ----a-w-    c:\users\Tej\AppData\Local\prvlcl.dat<br />
2010-01-17 19:17 . 2008-10-14 20:49
<hr />
d
<hr />
w-    c:\program files\DivX<br />
2010-01-17 19:17 . 2009-12-06 03:37
<hr />
d
<hr />
w-    c:\program files\Common Files\DivX Shared<br />
2010-01-17 14:57 . 2009-07-07 14:35
<hr />
d
<hr />
w-    c:\users\Tej\AppData\Roaming\BitTorrent<br />
2010-01-17 03:03 . 2008-06-17 12:07
<hr />
d
<hr />
w-    c:\programdata\Microsoft Help<br />
2010-01-17 03:03 . 2006-11-02 11:18
<hr />
d
<hr />
w-    c:\program files\Windows Mail<br />
2010-01-17 01:03 . 2009-09-10 23:01    19944    ----a-w-    c:\windows\system32\drivers\atapi.sys<br />
2010-01-17 01:02 . 2009-11-17 16:31
<hr />
d
<hr />
w-    c:\program files\Windows Portable Devices<br />
2010-01-14 11:12 . 2009-10-04 10:21    181120
<hr />
w-    c:\windows\system32\MpSigStub.exe<br />
2009-12-22 12:31 . 2009-12-10 20:10    2066200    ----a-w-    c:\programdata\avg8\update\backup\avgcorex.dll<br />
2009-12-06 19:46 . 2008-09-30 19:33    105408    ----a-w-    c:\users\Tej\AppData\Local\GDIPFONTCACHEV1.DAT<br />
2009-12-05 17:24 . 2009-12-05 17:24
<hr />
d
<hr />
w-    c:\program files\DebugMode<br />
2009-11-21 06:40 . 2009-12-10 20:18    916480    ----a-w-    c:\windows\system32\wininet.dll<br />
2009-11-21 06:34 . 2009-12-10 20:18    71680    ----a-w-    c:\windows\system32\iesetup.dll<br />
2009-11-21 06:34 . 2009-12-10 20:18    109056    ----a-w-    c:\windows\system32\iesysprep.dll<br />
2009-11-21 04:59 . 2009-12-10 20:18    133632    ----a-w-    c:\windows\system32\ieUnatt.exe<br />
2009-11-17 16:31 . 2006-11-02 10:25    665600    ----a-w-    c:\windows\inf\drvindex.dat<br />
2009-11-14 00:47 . 2009-11-14 00:47    90112    ----a-w-    c:\windows\system32\dpl100.dll<br />
2009-11-14 00:47 . 2009-11-14 00:47    856064    ----a-w-    c:\windows\system32\divx_xx0c.dll<br />
2009-11-14 00:47 . 2009-11-14 00:47    856064    ----a-w-    c:\windows\system32\divx_xx07.dll<br />
2009-11-14 00:47 . 2009-11-14 00:47    847872    ----a-w-    c:\windows\system32\divx_xx0a.dll<br />
2009-11-14 00:47 . 2009-11-14 00:47    843776    ----a-w-    c:\windows\system32\divx_xx16.dll<br />
2009-11-14 00:47 . 2009-11-14 00:47    839680    ----a-w-    c:\windows\system32\divx_xx11.dll<br />
2009-11-14 00:47 . 2009-11-14 00:47    696320    ----a-w-    c:\windows\system32\DivX.dll<br />
2009-11-12 17:07 . 2009-11-12 17:07    79144    ----a-w-    c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe<br />
2009-11-09 12:31 . 2009-12-13 19:42    24064    ----a-w-    c:\windows\system32\nshhttp.dll<br />
2009-11-09 12:30 . 2009-12-13 19:42    30720    ----a-w-    c:\windows\system32\httpapi.dll<br />
2009-11-09 10:36 . 2009-12-13 19:42    411648    ----a-w-    c:\windows\system32\drivers\http.sys<br />
2009-10-29 09:17 . 2009-11-25 17:24    2048    ----a-w-    c:\windows\system32\tzres.dll<br />
2009-01-27 23:28 . 2009-01-10 15:08    67688    ----a-w-    c:\program files\mozilla firefox\components\jar50.dll<br />
2009-01-27 23:28 . 2009-01-10 15:08    54368    ----a-w-    c:\program files\mozilla firefox\components\jsd3250.dll<br />
2009-01-27 23:28 . 2009-01-10 15:08    34944    ----a-w-    c:\program files\mozilla firefox\components\myspell.dll<br />
2009-01-27 23:28 . 2009-01-10 15:08    46712    ----a-w-    c:\program files\mozilla firefox\components\spellchk.dll<br />
2009-01-27 23:28 . 2009-01-10 15:08    172136    ----a-w-    c:\program files\mozilla firefox\components\xpinstal.dll<br />
2008-04-21 14:46 . 2008-04-21 14:46    8192    --sha-w-    c:\windows\Users\Default\NTUSER.DAT<br />
.<br /><br />
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br />
.<br />
*Note* empty entries &amp; legit default entries are not shown<br />
REGEDIT4<br /><br />
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]<br />
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2009-08-27 247144]<br />
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]<br /><br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]<br />
"RtHDVCpl"="RtHDVCpl.exe" [2008-05-13 6139904]<br />
"SpareMessaging"="c:\program files\Spare Messaging\MessagingApp.exe" [2007-11-28 42824]<br />
"UpdateP2GShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-01-04 222504]<br />
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]<br />
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]<br />
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]<br />
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-10 2043160]<br />
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]<br />
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13687328]<br />
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 92704]<br />
"Skytel"="Skytel.exe" [2007-11-21 1826816]<br />
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]<br />
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]<br />
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]<br />
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-01-07 1394000]<br /><br />
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]<br />
"EnableUIADesktopToggle"= 0 (0x0)<br /><br />
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]<br />
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll<br /><br />
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]<br />
"mixer1"=wdmaud.drv<br /><br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]<br /><a href="https://icrontic.com/profile/%3D%26quot" rel="nofollow">@=&amp;quot</a>;Service"<br /><br />
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]<br />
"VistaSp2"=hex(b):06,20,4f,bc,97,34,ca,01<br /><br />
R0 AvgRkx86;avgrkx86.sys;c:\windows\System32\drivers\avgrkx86.sys [05/03/2009 00:02 12552]<br />
R1 Avgfwfd;AVG network filter service;c:\windows\System32\drivers\avgfwd6x.sys [29/10/2008 02:35 23832]<br />
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [05/03/2009 00:02 335240]<br />
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [05/03/2009 00:02 108552]<br />
R1 RtlProt;Realtke RtlProt WLAN Utility Protocol Driver;c:\windows\System32\drivers\RtlProt.sys [17/06/2008 11:29 25896]<br />
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [05/03/2009 00:01 297752]<br />
R2 avgfws8;AVG8 Firewall;c:\progra~1\AVG\AVG8\avgfws8.exe [29/04/2009 17:25 1370488]<br />
R2 sprtsvc_O2;SupportSoft Sprocket Service (O2);c:\program files\O2\bin\sprtsvc.exe [07/06/2007 15:19 202280]<br />
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [27/08/2009 15:05 92008]<br />
R3 AVerBDA3x;AVerMedia SAA713x BDA Service;c:\windows\System32\drivers\AVerBDA3x.sys [17/06/2008 11:30 1183744]<br />
R3 RTL85n86;Realtek 8180/8185 Extensible 802.11 Wireless Device Driver;c:\windows\System32\drivers\RTL85n86.sys [17/06/2008 11:13 354816]<br />
S1 RCFOX;SonicWALL IPsec Driver;c:\windows\System32\drivers\RCFOX.SYS [01/06/2009 17:47 91136]<br />
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [21/01/2008 02:23 21504]<br />
S3 PAC207;SoC PC-Camera;c:\windows\System32\drivers\PFC027.SYS [05/12/2006 10:34 507136]<br />
S3 rcvpn;SonicWALL VPN Adapter;c:\windows\System32\drivers\rcvpn.sys [01/06/2009 17:46 23180]<br /><br />
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]<br />
LocalServiceAndNoImpersonation    REG_MULTI_SZ       FontCache<br />
.<br />
.
<hr />
Supplementary Scan
<hr />
.<br />
uStart Page = hxxp://www.google.com/<br />
uInternet Settings,ProxyOverride = *.local<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000<br />
Trusted Zone: o2.co.uk\*.broadband<br />
FF - ProfilePath - c:\users\Tej\AppData\Roaming\Mozilla\Firefox\Profiles\4xkahiwj.default\<br />
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/<br />
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll<br />
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll<br />
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\<br /><br />
---- FIREFOX POLICIES ----<br />
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.allow_platform_file_picker", true);<br />
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel",             1); // 0=low, 1=medium, 2=high, 3=custom<br />
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad",                   false); // Allow client to do proxy autodiscovery<br />
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess");<br />
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");<br />
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom",  "chrome://branding/content/searchconfig.properties");<br />
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("signon.prefillForms",                 true);<br />
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.enabled", false);<br />
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.remoteLookups", false);<br />
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.updateURL", "<a href="http://sb.google.com/safebrowsing/update?client={moz:client}&amp;appver={moz:version}&amp;&quot;)" rel="nofollow">http://sb.google.com/safebrowsing/update?client={moz:client}&amp;appver={moz:version}&amp;")</a>;<br />
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.lookupURL", "<a href="http://sb.google.com/safebrowsing/lookup?sourceid=firefox-antiphish&amp;features=TrustRank&amp;client={moz:client}&amp;appver={moz:version}&amp;&quot;)" rel="nofollow">http://sb.google.com/safebrowsing/lookup?sourceid=firefox-antiphish&amp;features=TrustRank&amp;client={moz:client}&amp;appver={moz:version}&amp;")</a>;<br />
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.reportURL", "<a href="http://sb.google.com/safebrowsing/report?&quot;)" rel="nofollow">http://sb.google.com/safebrowsing/report?")</a>;<br />
.<br />
- - - - ORPHANS REMOVED - - - -<br /><br />
HKLM-Run-c:\program files\Free Video Zilla\FVZilla.exe - (no file)<br />
HKLM-Run-UDC Integration - (no file)<br />
AddRemove-Adobe_acce07fd2c8fe7f9e3f26243e626578 - c:\program files\Common Files\Adobe\Installers\acce07fd2c8fe7f9e3f26243e626578\Setup.exe<br /><br /><br /><br />
**************************************************************************<br /><br />
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, <a href="http://www.gmer.net" rel="nofollow">http://www.gmer.net</a><br />
Rootkit scan 2010-01-19 21:41<br />
Windows 6.0.6002 Service Pack 2 NTFS<br /><br />
scanning hidden processes ...<br /><br />
scanning hidden autostart entries ...<br /><br />
scanning hidden files ...<br /><br />
scan completed successfully<br />
hidden files: 0<br /><br />
**************************************************************************<br /><br />
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, <a href="http://www.gmer.net" rel="nofollow">http://www.gmer.net</a><br /><br />
device: opened successfully<br />
user: MBR read successfully<br />
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll &gt;&gt;UNKNOWN [0x859AA856]&lt;&lt;<br />
kernel: MBR read successfully<br />
detected MBR rootkit hooks:<br />
\Driver\Disk -&gt; CLASSPNP.SYS @ 0x8b3a5d24<br />
\Driver\ACPI -&gt; acpi.sys @ 0x80693d68<br />
\Driver\atapi -&gt; ataport.SYS @ 0x807a2a2c<br />
IoDeviceObjectType -&gt;\Device\Harddisk0\DR0 -&gt;user &amp; kernel MBR OK<br /><br />
**************************************************************************<br />
.<br />
Completion time: 2010-01-19  21:45:09<br />
ComboFix-quarantined-files.txt  2010-01-19 21:45<br /><br />
Pre-Run: 340,265,488,384 bytes free<br />
Post-Run: 341,905,874,944 bytes free<br /><br />
- - End Of File - - 2D5C7E683E5A04086789931C2E6F810F]]>
        </description>
    </item>
   </channel>
</rss>
