<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Spyware &amp; Virus Removal — Icrontic</title>
        <link>https://icrontic.com/</link>
        <pubDate>Fri, 12 Jun 2026 14:39:02 +0000</pubDate>
        <language>en</language>
            <description>Spyware &amp; Virus Removal — Icrontic</description>
    <atom:link href="https://icrontic.com/categories/spyware-virus-removal-c/feed.rss" rel="self" type="application/rss+xml"/>
    <item>
        <title>Something got a hold of my laptop.</title>
        <link>https://icrontic.com/discussion/95723/something-got-a-hold-of-my-laptop</link>
        <pubDate>Mon, 14 May 2012 18:11:43 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>jajenk</dc:creator>
        <guid isPermaLink="false">95723@/discussions</guid>
        <description><![CDATA[I'm looking for some help. I have a dell latitude d610 and recently had some malware that was detected by spybot s and d. It removed the problems and says I'm clean. Malwarebytes and AVG also say I have no problems, but I'm getting glitches all over. Not sure what the problem is. I have a hijack this log, and an wondering if I can get a little help. Thanks in advance for any info. The forum says my message is over 3000 characters too long if I attach the Hijack this log. ]]>
        </description>
    </item>
    <item>
        <title>I believe I have either a few trojans or viruses. HijackThis log. Please help.</title>
        <link>https://icrontic.com/discussion/95457/i-believe-i-have-either-a-few-trojans-or-viruses-hijackthis-log-please-help</link>
        <pubDate>Wed, 28 Mar 2012 22:08:28 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>4Nmissile</dc:creator>
        <guid isPermaLink="false">95457@/discussions</guid>
        <description><![CDATA[I have been getting some popups lately that tend to say things like women's hair care and whatnot. Although, it opens up an entire webpage rather than an official popup. Mainly though, everytime I open up the internet (Internet Explorer) I get a popup that says Windows Firewall has blocked this application from accessing the internet, indicating Internet Explorer. However, if I just close that window I can go anywhere online even though it's still "blocked". I also get an AVG popup that says it has detected a random trojan/virus file and then has me detain/quarantine it. Usually, it's in the C://Windows directory, but it has been in the Temp folder and also I've seen some in other folders according to the AVG alert. I have included my most recent HijackThis log with this post. I have to split it in half as it's too big for one post. The second post shows the rest of the HijackThis log.

Someone please check it out and tell me how  to be rid of these nuisances.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:24:23 PM, on 3/28/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\O2Micro Oz128 Driver\o2flash.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.2.0\ToolbarUpdater.exe
C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Acer\Bio-Protection fingerprint solution\PdtWzd.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Acer\Empowering Technology\ePresentation\ePresentation.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Program Files\Microsoft Office 2007 Trial\Office12\GrooveMonitor.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Acer\Bio-Protection fingerprint solution\FPLaunch.exe
C:\DOCUME~1\BRIANC~1\LOCALS~1\Temp\RtkBtMnt.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Programs\My Programs\PC Doctors\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://en.us.acer.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz2.dll]]>
        </description>
    </item>
    <item>
        <title>My Computer will not run programs</title>
        <link>https://icrontic.com/discussion/87755/my-computer-will-not-run-programs</link>
        <pubDate>Mon, 18 Jan 2010 01:34:03 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>hustler07</dc:creator>
        <guid isPermaLink="false">87755@/discussions</guid>
        <description><![CDATA[Hi guys,<br /><br />
Recently a pdf opened randomly after visiting a website, it was flagged by my anti-virus.  I opted to heal the file.  After that my computer would not run any programs except for my anti-virus.  Whenever I try to run a program it says it is missing netngtu.dll and that I should re-install the program.  None of my anti-virus can detect any problems.  Please help.  Here is my HJT log:<br /><br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 10:24:31 PM, on 1/17/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br /><br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
C:\WINDOWS\eHome\ehRecvr.exe<br />
C:\WINDOWS\eHome\ehSched.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\system32\lxdccoms.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br />
C:\Program Files\Webroot\Enterprise\Spy Sweeper\CommAgent.exe<br />
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Webroot\Enterprise\Spy Sweeper\SpySweeper.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\Documents and Settings\Heather Harvey\Desktop\CPU Protection\HijackThis.exe<br /><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.gmail.com/" rel="nofollow">http://www.gmail.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = <a href="https://register.hp.com/servlet/WebReg.servlets.ProdReg1Servlet?appID=java_wreg_wreg_genpg&amp;modelID=EZ700UA&amp;product_full_name=HP%20Pavilion%20dv8000&amp;PROD_SERIAL_ID=CND6221PRW&amp;PURCH_DT_MONTH=07&amp;PURCH_DT_DAY=21&amp;PURCH_DT_YEAR=2006&amp;gwCountry=US&amp;language=EN&amp;prodOS=012" rel="nofollow">https://register.hp.com/servlet/WebReg.servlets.ProdReg1Servlet?appID=java_wreg_wreg_genpg&amp;modelID=EZ700UA&amp;product_full_name=HP%20Pavilion%20dv8000&amp;PROD_SERIAL_ID=CND6221PRW&amp;PURCH_DT_MONTH=07&amp;PURCH_DT_DAY=21&amp;PURCH_DT_YEAR=2006&amp;gwCountry=US&amp;language=EN&amp;prodOS=012</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll<br />
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br />
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll<br />
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll<br />
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll<br />
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"<br />
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - S-1-5-18 Startup: Vongo Tray.lnk.disabled (User 'SYSTEM')<br />
O4 - .DEFAULT Startup: Vongo Tray.lnk.disabled (User 'Default user')<br />
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')<br />
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: <a href="https://icrontic.com/profile/xpsp3res" rel="nofollow">@xpsp3res</a>.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O14 - IERESET.INF: START_PAGE_URL=<a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=Q306&amp;bd=pavilion&amp;pf=laptop" rel="nofollow">http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=Q306&amp;bd=pavilion&amp;pf=laptop</a><br />
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - <a href="http://www.worldwinner.com/games/v47/shared/FunGamesLoader.cab" rel="nofollow">http://www.worldwinner.com/games/v47/shared/FunGamesLoader.cab</a><br />
O16 - DPF: {1D082E71-DF20-4AAF-863B-596428C49874} (TPIR Control) - <a href="http://www.worldwinner.com/games/v50/tpir/tpir.cab" rel="nofollow">http://www.worldwinner.com/games/v50/tpir/tpir.cab</a><br />
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - <a href="http://upload.facebook.com/controls/FacebookPhotoUploader.cab" rel="nofollow">http://upload.facebook.com/controls/FacebookPhotoUploader.cab</a><br />
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - <a href="http://www.worldwinner.com/games/v51/bejeweled/bejeweled.cab" rel="nofollow">http://www.worldwinner.com/games/v51/bejeweled/bejeweled.cab</a><br />
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - <a href="http://www.worldwinner.com/games/shared/wwlaunch.cab" rel="nofollow">http://www.worldwinner.com/games/shared/wwlaunch.cab</a><br />
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} (FamilyFeud Control) - <a href="http://www.worldwinner.com/games/v47/familyfeud/familyfeud.cab" rel="nofollow">http://www.worldwinner.com/games/v47/familyfeud/familyfeud.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" rel="nofollow">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O20 - AppInit_DLLs: acaptuser32.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: Adobe Version Cue CS4 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe<br />
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: lxcr_device -   - C:\WINDOWS\system32\lxcrcoms.exe<br />
O23 - Service: lxdcCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdcserv.exe<br />
O23 - Service: lxdc_device -   - C:\WINDOWS\system32\lxdccoms.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe<br />
O23 - Service: Webroot CommAgent Service (WebrootCommAgentService) - Webroot Software, Inc. - C:\Program Files\Webroot\Enterprise\Spy Sweeper\CommAgent.exe<br />
O23 - Service: WebrootSpySweeperService - Webroot Software, Inc. - C:\Program Files\Webroot\Enterprise\Spy Sweeper\SpySweeper.exe<br />
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/HEATHE~1/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg<br /><br />
--<br />
End of file - 9695 bytes<br /><br /><br />
Thanks for the help!<br /><br />
-Jon]]>
        </description>
    </item>
    <item>
        <title>AntiVirus Soft Virus..please help</title>
        <link>https://icrontic.com/discussion/90107/antivirus-soft-virus-please-help</link>
        <pubDate>Fri, 25 Jun 2010 14:42:20 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>michgal2k</dc:creator>
        <guid isPermaLink="false">90107@/discussions</guid>
        <description><![CDATA[I am runnign WINDOWS XP Pro SP3 on a desktop.  I cannot post a log of HJT on that PC so I am also using my laptop.  (hope I don't spread the germs)<br />
I have tried to get rid if the virus but believe it's still there...the PC also is running really slow.  Can you help?????<br /><br />
Here is the HJT log:<br />
Logfile of Trend Micro HijackThis v2.0.4<br />
Scan saved at 2:16:06 PM, on 6/25/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.17023)<br />
Boot mode: Normal<br /><br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Dell\EUSW\Support.exe<br />
C:\Program Files\Real\RealPlayer\RealPlay.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\QuickTime\qttask.exe<br />
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe<br />
C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\PROGRA~1\Comcast\COMCAS~1\data\Xtras\mssysmgr.exe<br />
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe<br />
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe<br />
C:\Program Files\CreataCard\Plus\FMRemind.exe<br />
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\WINDOWS\System32\drivers\CDAC11BA.EXE<br />
C:\WINDOWS\System32\CTsvcCDA.exe<br />
C:\WINDOWS\system32\E_S00RP1.EXE<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
C:\Program Files\internet explorer\iexplore.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe<br />
C:\WINDOWS\System32\nvsvc32.exe<br />
C:\ESM2\SAgentNT.exe<br />
C:\WINDOWS\system32\SAgent4.exe<br />
C:\ESM2\EBRR.EXE<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\IntraPort Client\vpn5000service.exe<br />
C:\WINDOWS\wanmpsvc.exe<br />
C:\WINDOWS\System32\MsPMSPSv.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\WINDOWS\system32\msiexec.exe<br />
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe<br /><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.yahoo.com/" rel="nofollow">http://www.yahoo.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = <a href="http://search.yahoo.com/search?fr=mcafee&amp;p=%s" rel="nofollow">http://search.yahoo.com/search?fr=mcafee&amp;p=%s</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555<br />
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O1 - Hosts: ::1 localhost<br />
O1 - Hosts: 91.212.127.227 antiviraprof2009.microsoft.com<br />
O1 - Hosts: 91.212.127.227 antiviraprof2009.com<br />
O1 - Hosts: 91.212.127.227 <a href="www.antiviraprof2009.com" rel="nofollow">www.antiviraprof2009.com</a><br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: CCHelper - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\Program Files\Panicware\Pop-Up Stopper Pro\CCHelper.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll<br />
O3 - Toolbar: Pa&amp;nicware Pop-Up Stopper Pro - {B1E741E7-1E77-40D4-9FD8-51949B9CCBD0} - C:\Program Files\Panicware\Pop-Up Stopper Pro\popuppro.dll<br />
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O4 - HKLM\..\Run: [DwlClient] "C:\Program Files\Common Files\Dell\EUSW\Support.exe"<br />
O4 - HKLM\..\Run: [UpdReg] "C:\WINDOWS\UpdReg.EXE"<br />
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" NvQTwk,NvCplDaemon initialize<br />
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup<br />
O4 - HKLM\..\Run: [RealTray] "C:\Program Files\Real\RealPlayer\RealPlay.exe" SYSTEMBOOTHIDEPLAYER<br />
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br />
O4 - HKLM\..\Run: [MimBoot] "C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe"<br />
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Comcast\COMCAS~1\data\Xtras\mssysmgr.exe<br />
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe<br />
O4 - Global Startup: CreataCard Plus 3 Forget Me Not Reminders Tray Icon.lnk = C:\Program Files\CreataCard\Plus\FMRemind.exe<br />
O4 - Global Startup: Digital Line Detect.lnk = ?<br />
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000<br />
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Documents and Settings\Fran Spraetz\Desktop\AIM95\aim.exe<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: <a href="https://icrontic.com/profile/xpsp3res" rel="nofollow">@xpsp3res</a>.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: JavaConnect - <a href="http://imlab1.collab.ford.com/sametime/javaconnect/JavaConnect.cab" rel="nofollow">http://imlab1.collab.ford.com/sametime/javaconnect/JavaConnect.cab</a><br />
O16 - DPF: symsupportutil - <a href="http://www.symantec.com/techsupp/activedata/symsupportutil.CAB" rel="nofollow">http://www.symantec.com/techsupp/activedata/symsupportutil.CAB</a><br />
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - <a href="http://www.comcastsupport.com/sdccommon/download/tgctlcm.cab" rel="nofollow">http://www.comcastsupport.com/sdccommon/download/tgctlcm.cab</a><br />
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - <a href="http://support.dell.com/systemprofiler/SysPro.CAB" rel="nofollow">http://support.dell.com/systemprofiler/SysPro.CAB</a><br />
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - <a href="http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab" rel="nofollow">http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab</a><br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a href="http://go.microsoft.com/fwlink/?linkid=39204" rel="nofollow">http://go.microsoft.com/fwlink/?linkid=39204</a><br />
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - <a href="http://www.snapfish.com/SnapfishActivia.cab" rel="nofollow">http://www.snapfish.com/SnapfishActivia.cab</a><br />
O16 - DPF: {63CA7AC8-7161-47AB-9357-0A27612031A6} (IPCamera Control) - <a href="http://foclcam.myphotos.cc:32768/classes/absCamV.cab" rel="nofollow">http://foclcam.myphotos.cc:32768/classes/absCamV.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1100350152906" rel="nofollow">http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1100350152906</a><br />
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - <a href="http://us.games2.yimg.com/download.games.yahoo.com/games/play/client/exentctl_0_0_0_1.ocx" rel="nofollow">http://us.games2.yimg.com/download.games.yahoo.com/games/play/client/exentctl_0_0_0_1.ocx</a><br />
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - <a href="http://216.249.24.143/code/PWActiveXImgCtl.CAB" rel="nofollow">http://216.249.24.143/code/PWActiveXImgCtl.CAB</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1195159129596" rel="nofollow">http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1195159129596</a><br />
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - <a href="http://www.ofoto.com/downloads/BUM/BUM_WIN_IE_1/axofupld.cab" rel="nofollow">http://www.ofoto.com/downloads/BUM/BUM_WIN_IE_1/axofupld.cab</a><br />
O16 - DPF: {8D83D301-E841-11D1-B155-00600823BCF9} (WebLine Browser Integration Classes) - <a href="http://live.landsend.com/webline/applets/msie40x.cab" rel="nofollow">http://live.landsend.com/webline/applets/msie40x.cab</a><br />
O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} (CustomerCtrl Class) - <a href="http://cs2b.instantservice.com/jars/customerxsigned41.cab" rel="nofollow">http://cs2b.instantservice.com/jars/customerxsigned41.cab</a><br />
O16 - DPF: {8EC18CE2-D7B4-11D2-88C8-006008A717FD} (NCSView Class) - <a href="http://www.aerialsexpress.com/ecwplugins/ncs.cab" rel="nofollow">http://www.aerialsexpress.com/ecwplugins/ncs.cab</a><br />
O16 - DPF: {90051A81-3018-4826-8B38-DD60B6B53F9C} (Snapfish File Upload ActiveX Control) - <a href="http://www.snapfish.com/SnapfishUpload.cab" rel="nofollow">http://www.snapfish.com/SnapfishUpload.cab</a><br />
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - <a href="http://www.installengine.com/engine/isetup.cab" rel="nofollow">http://www.installengine.com/engine/isetup.cab</a><br />
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - <a href="https://webchat.dell.com/Media/VisitorChat/TLIEFlash.CAB" rel="nofollow">https://webchat.dell.com/Media/VisitorChat/TLIEFlash.CAB</a><br />
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - <a href="http://web1.shutterfly.com/downloads/Uploader.cab" rel="nofollow">http://web1.shutterfly.com/downloads/Uploader.cab</a><br />
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - <a href="http://acs.pandasoftware.com/activescan/as5free/asinst.cab" rel="nofollow">http://acs.pandasoftware.com/activescan/as5free/asinst.cab</a><br />
O16 - DPF: {A25BE7A9-3102-46B4-BAAE-462471B60ACB} (STConnectivityAgent Control) - <a href="https://myvpn.ford.com/sametime/javaconnect/InstallSTConnAgent.cab,DanaInfo=.ainndf6FjwuvlnMt37uRv87,CT=java+" rel="nofollow">https://myvpn.ford.com/sametime/javaconnect/InstallSTConnAgent.cab,DanaInfo=.ainndf6FjwuvlnMt37uRv87,CT=java+</a><br />
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - <a href="http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab" rel="nofollow">http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab</a><br />
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} (Create &amp; Print ActiveX Plug-in) - <a href="http://www.imgag.com/cp/install/AxCtp2.cab" rel="nofollow">http://www.imgag.com/cp/install/AxCtp2.cab</a><br />
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - <a href="http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab" rel="nofollow">http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" rel="nofollow">http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" rel="nofollow">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - <a href="https://myvpn.ford.com/dana-cached/setup/JuniperSetupSP1.cab" rel="nofollow">https://myvpn.ford.com/dana-cached/setup/JuniperSetupSP1.cab</a><br />
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} - <a href="http://www.symantec.com/techsupp/activedata/ActiveData.cab" rel="nofollow">http://www.symantec.com/techsupp/activedata/ActiveData.cab</a><br />
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - <a href="http://www2.incredimail.com/contents/setup/downloader/imloader.cab" rel="nofollow">http://www2.incredimail.com/contents/setup/downloader/imloader.cab</a><br />
O16 - DPF: {FEDA837C-E930-41A4-855B-5E2B90626855} (DARTGrid.BlendedRatesCtl) - <a href="https://myvpn.ford.com/static/cab/DARTGrid.CAB,DanaInfo=.awxyChfx0Hoy2pMq32,CT=java+" rel="nofollow">https://myvpn.ford.com/static/cab/DARTGrid.CAB,DanaInfo=.awxyChfx0Hoy2pMq32,CT=java+</a><br />
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)<br />
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll<br />
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll<br />
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE<br />
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe<br />
O23 - Service: EPSON V3 Service2(03) (EPSON_PM_RPCV2_01) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\E_S00RP1.EXE<br />
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe<br />
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br />
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe<br />
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe<br />
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe<br />
O23 - Service: Epson Printer Status Agent (StatusAgent) - SEIKO EPSON CORPORATION - C:\ESM2\SAgentNT.exe<br />
O23 - Service: Epson Printer Status Agent4 (StatusAgent4) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\SAgent4.exe<br />
O23 - Service: VPN 5000 Service 1.00.00 (VPN5000Service) - Unknown owner - C:\Program Files\IntraPort Client\vpn5000service.exe<br />
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe<br /><br />
--<br />
End of file - 13765 bytes]]>
        </description>
    </item>
    <item>
        <title>Email is not working</title>
        <link>https://icrontic.com/discussion/90184/email-is-not-working</link>
        <pubDate>Sat, 03 Jul 2010 00:49:06 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>panget</dc:creator>
        <guid isPermaLink="false">90184@/discussions</guid>
        <description><![CDATA[Hello,<br /><br />
Please take a look at my system.  I've just installed Kaspersky and a lot of problems began to surface.  I feel that there is a virus that has yet to be removed.  Here's the log:<br /><br />
Logfile of Trend Micro<br /><br />
HijackThis v2.0.2<br />
Scan saved at 10:12:46, on<br /><br />
2008-3-26<br />
Platform: Windows XP SP3<br /><br />
(WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00<br /><br />
(8.00.6001.18702)<br />
Boot mode: Normal<br /><br />
Running processes:<br />
D:\WINDOWS\System32\smss.exe<br />
D:\WINDOWS\system32<br /><br />
\winlogon.exe<br />
D:\WINDOWS\system32<br /><br />
\services.exe<br />
D:\WINDOWS\system32\lsass.exe<br />
D:\WINDOWS\system32<br /><br />
\Ati2evxx.exe<br />
D:\WINDOWS\system32<br /><br />
\svchost.exe<br />
D:\WINDOWS\System32<br /><br />
\svchost.exe<br />
D:\WINDOWS\system32<br /><br />
\Ati2evxx.exe<br />
D:\WINDOWS\system32<br /><br />
\spoolsv.exe<br />
D:\Program Files\Kaspersky<br /><br />
Lab\Kaspersky Anti-Virus<br /><br />
2010\avp.exe<br />
D:\Program<br /><br />
Files\Bonjour\mDNSResponder.e<br /><br />
xe<br />
D:\Program Files\95599<br /><br />
Certificate<br /><br />
Tools\Watertek\c20ukdrwsvr.ex<br /><br />
e<br />
D:\Program Files\Common<br /><br />
Files\EPSON\EBAPI\SAgent2.exe<br />
D:\WINDOWS\system32<br /><br />
\HZ_CommSrv.exe<br />
D:\Program Files\Java\jre6<br /><br />
\bin\jqs.exe<br />
D:\WINDOWS\system32<br /><br />
\svchost.exe<br />
D:\Program Files\Yahoo!<br /><br />
\SoftwareUpdate\YahooAUServic<br /><br />
e.exe<br />
D:\WINDOWS\Explorer.EXE<br />
D:\WINDOWS\System32<br /><br />
\spool\DRIVERS\W32X86\3<br /><br />
\E_FATIAIP.EXE<br />
D:\WINDOWS\System32<br /><br />
\spool\DRIVERS\W32X86\3<br /><br />
\E_FATIAHP.EXE<br />
D:\WINDOWS\system32<br /><br />
\Rundll32.exe<br />
D:\Program Files\Kaspersky<br /><br />
Lab\Kaspersky Anti-Virus<br /><br />
2010\avp.exe<br />
D:\WINDOWS\VM_STI.EXE<br />
D:\WINDOWS\System32<br /><br />
\spool\DRIVERS\W32X86\3<br /><br />
\E_FATI9AP.EXE<br />
D:\WINDOWS\system32<br /><br />
\ctfmon.exe<br />
D:\Documents and<br /><br />
Settings\Owner\Local<br /><br />
Settings\Application<br /><br />
Data\Google\Update\1.2.183.29<br /><br />
\GoogleCrashHandler.exe<br />
D:\Program Files\Mozilla<br /><br />
Firefox\firefox.exe<br />
D:\Program Files\Kaspersky<br /><br />
Lab\Kaspersky Anti-Virus<br /><br />
2010\klwtblfs.exe<br />
D:\Program<br /><br />
Files\kondge_netphone_sipsms\<br /><br />
KONDGE_NetphoneSMS.exe<br />
D:\Program Files\Trend<br /><br />
Micro\HijackThis\HijackThis.e<br /><br />
xe<br /><br />
F2 - REG:system.ini:<br /><br />
UserInit=userinit.exe,passwor<br /><br />
d_viewer.exe<br />
O2 - BHO: &amp;Yahoo! Toolbar<br /><br />
Helper - {02478D38-C3F9-4efb<br /><br />
-9B51-7695ECA05670} -<br /><br />
D:\Program Files\Yahoo!<br /><br />
\Companion\Installs\cpn3<br /><br />
\yt.dll<br />
O2 - BHO: Adobe PDF Reader<br /><br />
Link Helper - {06849E9F-C8D7<br /><br />
-4D59-B87D-784B7D6BE0B3} -<br /><br />
D:\Program Files\Common<br /><br />
Files\Adobe\Acrobat\ActiveX\A<br /><br />
croIEHelper.dll<br />
O2 - BHO: AcroIEHelperStub -<br /><br />
{18DF081C-E8AD-4283-A596-<br /><br />
FA578C2EBDC3} - D:\Program<br /><br />
Files\Common<br /><br />
Files\Adobe\Acrobat\ActiveX\A<br /><br />
croIEHelperShim.dll<br />
O2 - BHO: QQå·¥å…·æ  -<br /><br />
{29CF293A-1E7D-4069-9E11-<br /><br />
E39698D0AF95} - D:\Program<br /><br />
Files\Tencent\QQToolbar\IEBar<br /><br />
.dll<br />
O2 - BHO: IEVkbdBHO -<br /><br />
{59273AB4-E7D3-40F9-A1A8-<br /><br />
6FA9CCA1862C} - D:\Program<br /><br />
Files\Kaspersky Lab\Kaspersky<br /><br />
Anti-Virus 2010\ievkbd.dll<br />
O2 - BHO: ThunderAtOnce Class<br /><br />
- {D13424D4-2159-46EC-A46D-<br /><br />
17BD39FDC3ED} - D:\Program<br /><br />
Files\Internet<br /><br />
Explorer\Connection<br /><br />
Wizard\TDAtOnce_Now.dll<br />
O2 - BHO: Java(tm) Plug-In 2<br /><br />
SSV Helper - {DBC80044-A445-<br /><br />
435b-BC74-9C25C1C588A9} -<br /><br />
D:\Program Files\Java\jre6<br /><br />
\bin\jp2ssv.dll<br />
O2 - BHO: link filter bho -<br /><br />
{E33CF602-D945-461A-83F0-<br /><br />
819F76A199F8} - D:\Program<br /><br />
Files\Kaspersky Lab\Kaspersky<br /><br />
Anti-Virus 2010\klwtbbho.dll<br />
O2 - BHO:<br /><br />
JQSIEStartDetectorImpl -<br /><br />
{E7E6F031-17CE-4C07-BC86-<br /><br />
EABFE594F69C} - D:\Program<br /><br />
Files\Java\jre6<br /><br />
\lib\deploy\jqs\ie\jqs_plugin<br /><br />
.dll<br />
O2 - BHO: EpsonToolBandKicker<br /><br />
Class - {E99421FB-68DD-40F0-<br /><br />
B4AC-B7027CAE2F1A} -<br /><br />
D:\Program Files\EPSON\EPSON<br /><br />
Web-To-Page\EPSON Web-To-<br /><br />
Page.dll<br />
O2 - BHO: SingleInstance<br /><br />
Class - {FDAD4DA1-61A2-4FD8-<br /><br />
9C17-86F7AC245081} -<br /><br />
D:\Program Files\Yahoo!<br /><br />
\Companion\Installs\cpn3<br /><br />
\YTSingleInstance.dll<br />
O3 - Toolbar: EPSON Web-To-<br /><br />
Page - {EE5D279F-081B-4404-<br /><br />
994D-C6B60AAEBA6D} -<br /><br />
D:\Program Files\EPSON\EPSON<br /><br />
Web-To-Page\EPSON Web-To-<br /><br />
Page.dll<br />
O3 - Toolbar: QQå·¥å…·æ  -<br /><br />
{29CF293A-1E7D-4069-9E11-<br /><br />
E39698D0AF95} - D:\Program<br /><br />
Files\Tencent\QQToolbar\IEBar<br /><br />
.dll<br />
O3 - Toolbar: Google Toolbar<br /><br />
- {2318C2B1-4965-11d4-9B18-<br /><br />
009027A5CD4F} - D:\Program<br /><br />
Files\Google\Google<br /><br />
Toolbar\GoogleToolbar_32.dll<br /><br />
(file missing)<br />
O3 - Toolbar: Yahoo! Toolbar<br /><br />
- {EF99BD32-C1FB-11D2-892F-<br /><br />
0090271D4F88} - D:\Program<br /><br />
Files\Yahoo!<br /><br />
\Companion\Installs\cpn3<br /><br />
\yt.dll<br />
O4 - HKLM\..\Run: [EPSON<br /><br />
Stylus Photo R230 Series]<br /><br />
D:\WINDOWS\System32<br /><br />
\spool\DRIVERS\W32X86\3<br /><br />
\E_FATIAIP.EXE /P30 "EPSON<br /><br />
Stylus Photo R230 Series" /O6<br /><br />
"USB001" /M "Stylus Photo<br /><br />
R230"<br />
O4 - HKLM\..\Run: [EPSON<br /><br />
Stylus Photo R230 Series<br /><br />
(Copy 5)]<br /><br />
D:\WINDOWS\System32<br /><br />
\spool\DRIVERS\W32X86\3<br /><br />
\E_FATIAIP.EXE /P39 "EPSON<br /><br />
Stylus Photo R230 Series<br /><br />
(Copy 5)" /O6 "USB050" /M<br /><br />
"Stylus Photo R230"<br />
O4 - HKLM\..\Run: [EPSON<br /><br />
Stylus Photo RX630 Series]<br /><br />
D:\WINDOWS\System32<br /><br />
\spool\DRIVERS\W32X86\3<br /><br />
\E_FATI9HP.EXE /P31 "EPSON<br /><br />
Stylus Photo RX630 Series"<br /><br />
/O6 "USB011" /M "Stylus Photo<br /><br />
RX630"<br />
O4 - HKLM\..\Run: [EPSON<br /><br />
Stylus CX3500 Series (Copy<br /><br />
1)] D:\WINDOWS\System32<br /><br />
\spool\DRIVERS\W32X86\3<br /><br />
\E_FATI9BP.EXE /P35 "EPSON<br /><br />
Stylus CX3500 Series (Copy<br /><br />
1)" /O6 "USB034" /M "Stylus<br /><br />
CX3500"<br />
O4 - HKLM\..\Run: [EPSON<br /><br />
Stylus Photo R230 Series<br /><br />
(Copy 10)]<br /><br />
D:\WINDOWS\System32<br /><br />
\spool\DRIVERS\W32X86\3<br /><br />
\E_FATIAIP.EXE /P40 "EPSON<br /><br />
Stylus Photo R230 Series<br /><br />
(Copy 10)" /O6 "USB053" /M<br /><br />
"Stylus Photo R230"<br />
O4 - HKLM\..\Run: [EPSON<br /><br />
Stylus Photo R300 Series<br /><br />
(Copy 1)]<br /><br />
D:\WINDOWS\System32<br /><br />
\spool\DRIVERS\W32X86\3<br /><br />
\E_S4I2F1.EXE /P39 "EPSON<br /><br />
Stylus Photo R300 Series<br /><br />
(Copy 1)" /O5 "LPT1:" /M<br /><br />
"Stylus Photo R300"<br />
O4 - HKLM\..\Run: [EPSON<br /><br />
Stylus Photo RX630 Series<br /><br />
(Copy 1)]<br /><br />
D:\WINDOWS\System32<br /><br />
\spool\DRIVERS\W32X86\3<br /><br />
\E_FATI9HP.EXE /P40 "EPSON<br /><br />
Stylus Photo RX630 Series<br /><br />
(Copy 1)" /O6 "USB034" /M<br /><br />
"Stylus Photo RX630"<br />
O4 - HKLM\..\Run: [EPSON<br /><br />
Stylus Photo R250 Series]<br /><br />
D:\WINDOWS\System32<br /><br />
\spool\DRIVERS\W32X86\3<br /><br />
\E_FATIAHP.EXE /P30 "EPSON<br /><br />
Stylus Photo R250 Series" /O6<br /><br />
"USB033" /M "Stylus Photo<br /><br />
R250"<br />
O4 - HKLM\..\Run: [EPSON<br /><br />
Stylus Photo R230 Series<br /><br />
(Copy 11)]<br /><br />
D:\WINDOWS\System32<br /><br />
\spool\DRIVERS\W32X86\3<br /><br />
\E_FATIAIP.EXE /P40 "EPSON<br /><br />
Stylus Photo R230 Series<br /><br />
(Copy 11)" /O6 "USB054" /M<br /><br />
"Stylus Photo R230"<br />
O4 - HKLM\..\Run: [EPSON<br /><br />
Stylus Photo R230 Series<br /><br />
(Copy 2)]<br /><br />
D:\WINDOWS\System32<br /><br />
\spool\DRIVERS\W32X86\3<br /><br />
\E_FATIAIP.EXE /P39 "EPSON<br /><br />
Stylus Photo R230 Series<br /><br />
(Copy 2)" /O6 "USB044" /M<br /><br />
"Stylus Photo R230"<br />
O4 - HKLM\..\Run: [EPSON<br /><br />
Stylus Photo R230 Series<br /><br />
(Copy 1)]<br /><br />
D:\WINDOWS\System32<br /><br />
\spool\DRIVERS\W32X86\3<br /><br />
\E_FATIAIP.EXE /P39 "EPSON<br /><br />
Stylus Photo R230 Series<br /><br />
(Copy 1)" /O6 "USB032" /M<br /><br />
"Stylus Photo R230"<br />
O4 - HKLM\..\Run: [EPSON<br /><br />
Stylus Photo R230 Series<br /><br />
(Copy 4)]<br /><br />
D:\WINDOWS\System32<br /><br />
\spool\DRIVERS\W32X86\3<br /><br />
\E_FATIAIP.EXE /P39 "EPSON<br /><br />
Stylus Photo R230 Series<br /><br />
(Copy 4)" /O6 "USB049" /M<br /><br />
"Stylus Photo R230"<br />
O4 - HKLM\..\Run: [DirLocker]<br /><br />
D:\Documents and Settings\All<br /><br />
Users\application<br /><br />
data\Zilch.InfiniSoft\dirlock<br /><br />
.exe<br />
O4 - HKLM\..\Run: [LSAShell]<br /><br />
D:\WINDOWS\lsass.exe<br />
O4 - HKLM\..\Run: [stup.exe]<br /><br />
Rundll32.exe D:\PROGRA~1<br /><br />
\TENCENT\SSPlus\SPlus.dll,Run<br /><br />
dll32 R<br />
O4 - HKLM\..\Run: [AVP]<br /><br />
"D:\Program Files\Kaspersky<br /><br />
Lab\Kaspersky Anti-Virus<br /><br />
2010\avp.exe"<br />
O4 - HKLM\..\Run: [SSC<br /><br />
Service Utility] D:\Program<br /><br />
Files\SSC Service<br /><br />
Utility\ssc_serv.exe /s<br />
O4 - HKLM\..\Run: [EPSON<br /><br />
Stylus Photo R230 Series<br /><br />
(Copy 7)]<br /><br />
D:\WINDOWS\System32<br /><br />
\spool\DRIVERS\W32X86\3<br /><br />
\E_FATIAIP.EXE /P39 "EPSON<br /><br />
Stylus Photo R230 Series<br /><br />
(Copy 7)" /O6 "USB046" /M<br /><br />
"Stylus Photo R230"<br />
O4 - HKLM\..\Run: [NewRecog]<br /><br />
D:\Program<br /><br />
Files\HandWrite\MyNewRecog.ex<br /><br />
e<br />
O4 - HKLM\..\Run:<br /><br />
[BigDogPath]<br /><br />
D:\WINDOWS\VM_STI.EXE ZSMC<br /><br />
USB PC Camera<br />
O4 - HKLM\..\Run: [EPSON<br /><br />
Stylus Photo R230 Series<br /><br />
(Copy 6)]<br /><br />
D:\WINDOWS\System32<br /><br />
\spool\DRIVERS\W32X86\3<br /><br />
\E_FATIAIP.EXE /P39 "EPSON<br /><br />
Stylus Photo R230 Series<br /><br />
(Copy 6)" /O6 "USB045" /M<br /><br />
"Stylus Photo R230"<br />
O4 - HKLM\..\Run: [EPSON<br /><br />
Stylus CX4500 Series]<br /><br />
D:\WINDOWS\System32<br /><br />
\spool\DRIVERS\W32X86\3<br /><br />
\E_FATI9AP.EXE /P26 "EPSON<br /><br />
Stylus CX4500 Series" /O6<br /><br />
"USB040" /M "Stylus CX4500"<br />
O4 - HKLM\..\Run: [EPSON<br /><br />
Stylus C87 Series (Copy 1)]<br /><br />
D:\WINDOWS\System32<br /><br />
\spool\DRIVERS\W32X86\3<br /><br />
\E_FATIABP.EXE /P32 "EPSON<br /><br />
Stylus C87 Series (Copy 1)"<br /><br />
/O6 "USB043" /M "Stylus C87"<br />
O4 - HKLM\..\Run: [EPSON<br /><br />
Stylus Photo R230 Series<br /><br />
(Copy 3)]<br /><br />
D:\WINDOWS\System32<br /><br />
\spool\DRIVERS\W32X86\3<br /><br />
\E_FATIAIP.EXE /P39 "EPSON<br /><br />
Stylus Photo R230 Series<br /><br />
(Copy 3)" /O6 "USB045" /M<br /><br />
"Stylus Photo R230"<br />
O4 - HKCU\..\Run: [WinSys]<br /><br />
D:\WINDOWS\system.exe<br />
O4 - HKCU\..\Run:<br /><br />
[ctfmon.exe]<br /><br />
D:\WINDOWS\system32<br /><br />
\ctfmon.exe<br />
O4 - HKCU\..\Run: [Google<br /><br />
Update] "D:\Documents and<br /><br />
Settings\Owner\Local<br /><br />
Settings\Application<br /><br />
Data\Google\Update\GoogleUpda<br /><br />
te.exe" /c<br />
O4 - HKCU\..\Run: [EPSON<br /><br />
Stylus Photo 1390 Series<br /><br />
(Copy 1)]<br /><br />
D:\WINDOWS\System32<br /><br />
\spool\DRIVERS\W32X86\3<br /><br />
\E_FATIBXP.EXE /FU<br /><br />
"D:\WINDOWS\TEMP\E_S119.tmp"<br /><br />
/EF "HKCU"<br />
O8 - Extra context menu item:<br /><br />
E&amp;xport to Microsoft Excel -<br /><br />
res://D:\PROGRA~1\MICROS~2<br /><br />
\OFFICE11\EXCEL.EXE/3000<br />
O8 - Extra context menu item:<br /><br />
æ·»åŠ åˆ°QQè¡¨æƒ… - D:\Program<br /><br />
Files\Tencent\QQ\Bin\AddEmoti<br /><br />
on.htm<br />
O9 - Extra button: &amp;Virtual<br /><br />
keyboard - {4248FE82-7FCB-<br /><br />
46AC-B270-339F08212110} -<br /><br />
D:\Program Files\Kaspersky<br /><br />
Lab\Kaspersky Anti-Virus<br /><br />
2010\klwtbbho.dll<br />
O9 - Extra button: Research -<br /><br />
{92780B25-18CC-41C8-B9BE-<br /><br />
3C9C571A8263} - D:\PROGRA~1<br /><br />
\MICROS~2\OFFICE11<br /><br />
\REFIEBAR.DLL<br />
O9 - Extra button: URLs<br /><br />
c&amp;heck - {CCF151D8-D089-449F<br /><br />
-A5A4-D9909053F20F} -<br /><br />
D:\Program Files\Kaspersky<br /><br />
Lab\Kaspersky Anti-Virus<br /><br />
2010\klwtbbho.dll<br />
O9 - Extra button: (no name)<br /><br />
- {e2e2dd38-d088-4134-82b7-<br /><br />
f2ba38496583} -<br /><br />
D:\WINDOWS\Network<br /><br />
Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem:<br /><br /><a href="https://icrontic.com/profile/xpsp3res" rel="nofollow">@xpsp3res</a>.dll,-20001 -<br /><br />
{e2e2dd38-d088-4134-82b7-<br /><br />
f2ba38496583} -<br /><br />
D:\WINDOWS\Network<br /><br />
Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger<br /><br />
- {FB5F1910-F110-11d2-BB9E-<br /><br />
00C04F795683} - D:\Program<br /><br />
Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem:<br /><br />
Windows Messenger -<br /><br />
{FB5F1910-F110-11d2-BB9E-<br /><br />
00C04F795683} - D:\Program<br /><br />
Files\Messenger\msmsgs.exe<br />
O11 - Options group: [TBH]<br /><br />
SOSO AddressBar Search<br />
O15 - Trusted Zone:<br /><br /><a href="http://easyabc.95599.cn" rel="nofollow">http://easyabc.95599.cn</a><br />
O15 - Trusted Zone:<br /><br /><a href="http://www.95599.cn" rel="nofollow">http://www.95599.cn</a><br />
O15 - Trusted Zone:<br /><br /><a href="http://www.abchina.com" rel="nofollow">http://www.abchina.com</a><br />
O15 - ESC Trusted Zone:<br /><br /><a href="http://*.update.microsoft.com" rel="nofollow">http://*.update.microsoft.com</a><br />
O16 - DPF: {62B938C4-4190-<br /><br />
4F37-8CF0-A92B0A91CC77}<br /><br />
(InfoSecNetSign Class) -<br /><br /><a href="http://www.95599.cn/update/do" rel="nofollow">http://www.95599.cn/update/do</a><br /><br />
wn/NetSign.cab<br />
O16 - DPF: {9B479D7B-916A-<br /><br />
45B0-B042-D42865A60E21}<br /><br />
(DvrOcx Control) -<br /><br /><a href="http://111.68.34.113/DvrOcx.c" rel="nofollow">http://111.68.34.113/DvrOcx.c</a><br /><br />
ab<br />
O16 - DPF: {D27CDB6E-AE6D-<br /><br />
11CF-96B8-444553540000}<br /><br />
(Shockwave Flash Object) -<br /><br /><a href="http://fpdownload2.macromedia" rel="nofollow">http://fpdownload2.macromedia</a><br /><br />
.com/get/shockwave/cabs/flash<br /><br />
/swflash.cab<br />
O20 - AppInit_DLLs:<br /><br />
D:\PROGRA~1\KASPER~1<br /><br />
\KASPER~1\mzvkbd3.dll<br />
O23 - Service: Adobe LM<br /><br />
Service - Adobe Systems -<br /><br />
D:\Program Files\Common<br /><br />
Files\Adobe Systems<br /><br />
Shared\Service\Adobelmsvc.exe<br />
O23 - Service: Ati HotKey<br /><br />
Poller - ATI Technologies<br /><br />
Inc. - D:\WINDOWS\system32<br /><br />
\Ati2evxx.exe<br />
O23 - Service: ATI Smart -<br /><br />
Unknown owner -<br /><br />
D:\WINDOWS\system32<br /><br />
\ati2sgag.exe<br />
O23 - Service: Kaspersky<br /><br />
Anti-Virus (AVP) - Kaspersky<br /><br />
Lab - D:\Program<br /><br />
Files\Kaspersky Lab\Kaspersky<br /><br />
Anti-Virus 2010\avp.exe<br />
O23 - Service:<br /><br />
##Id_String1.6844F930_1628_42<br /><br />
23_B5CC_5BB94B879762##<br /><br />
(Bonjour Service) - Apple<br /><br />
Computer, Inc. - D:\Program<br /><br />
Files\Bonjour\mDNSResponder.e<br /><br />
xe<br />
O23 - Service: c20ukdrwsvc -<br /><br />
Unknown owner - D:\Program<br /><br />
Files\95599 Certificate<br /><br />
Tools\Watertek\c20ukdrwsvr.ex<br /><br />
e<br />
O23 - Service: EPSON Printer<br /><br />
Status Agent2<br /><br />
(EPSONStatusAgent2) - SEIKO<br /><br />
EPSON CORPORATION -<br /><br />
D:\Program Files\Common<br /><br />
Files\EPSON\EBAPI\SAgent2.exe<br />
O23 - Service: FLEXnet<br /><br />
Licensing Service -<br /><br />
Macrovision Europe Ltd. -<br /><br />
D:\Program Files\Common<br /><br />
Files\Macrovision<br /><br />
Shared\FLEXnet<br /><br />
Publisher\FNPLicensingService<br /><br />
.exe<br />
O23 - Service: Google<br /><br />
Software Updater (gusvc) -<br /><br />
Google - D:\Program<br /><br />
Files\Google\Common\Google<br /><br />
Updater\GoogleUpdaterService.<br /><br />
exe<br />
O23 - Service: HDZB Comm<br /><br />
Service For V2.0 (HZ_CommSrv)<br /><br />
- åŽå¤§æ™ºå®ç”µå­ç³»ç»Ÿæœ‰é™å…¬å¸ -<br /><br />
D:\WINDOWS\system32<br /><br />
\HZ_CommSrv.exe<br />
O23 - Service: Java Quick<br /><br />
Starter<br /><br />
(JavaQuickStarterService) -<br /><br />
Sun Microsystems, Inc. -<br /><br />
D:\Program Files\Java\jre6<br /><br />
\bin\jqs.exe<br />
O23 - Service: Tencent<br /><br />
Software Update Service<br /><br />
(TSUSVC) - Tencent -<br /><br />
D:\Program<br /><br />
Files\Tencent\QQSoftMgr\Tence<br /><br />
ntUpdateSvc.exe<br />
O23 - Service: Yahoo! Updater<br /><br />
(YahooAUService) - Yahoo!<br /><br />
Inc. - D:\Program<br /><br />
Files\Yahoo!<br /><br />
\SoftwareUpdate\YahooAUServic<br /><br />
e.exe<br /><br />
--<br />
End of file - 11419 bytes<br /><br />
***<br /><br />
Thank you.]]>
        </description>
    </item>
    <item>
        <title>Hijackthis log not sure what to do.</title>
        <link>https://icrontic.com/discussion/90054/hijackthis-log-not-sure-what-to-do</link>
        <pubDate>Mon, 21 Jun 2010 18:22:24 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>Delta</dc:creator>
        <guid isPermaLink="false">90054@/discussions</guid>
        <description><![CDATA[My pc has been running slow and boots slow. I ran HJT and Spybot S&amp;D and the entries come back after boot.  In S&amp;D it finds "Right Media" &amp; " win32.PornPopUp" a delete them and after reboot it comes back. HJT find "O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeCtfmon.exe"CoolWebSearch Ctfmon32 parasite variant"<br /><br />
Here is the HJT log<br /><br /><br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 6:11:31 PM, on 6/21/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgemc.exe<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\WINDOWS\system32\igfxsrvc.exe<br />
C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
C:\Program Files\Synaptics\SynTP\SynToshiba.exe<br />
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\Program Files\Windows Live\Contacts\wlcomm.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll<br />
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O3 - Toolbar: &amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"<br />
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br />
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\Computer1\Application Data\mjusbsp\cdloader2.exe" MAGICJACK<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: <a href="https://icrontic.com/profile/xpsp3res" rel="nofollow">@xpsp3res</a>.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {38AB0814-B09B-4378-9940-14A19638C3C2} (Auctiva Image Uploader Control) - <a href="http://www.auctiva.com/Aurigma/ImageUploader57.cab" rel="nofollow">http://www.auctiva.com/Aurigma/ImageUploader57.cab</a><br />
O16 - DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} (SpinTop Games Launcher) - <a href="http://webgames.d.tmsrv.com/c=9cec9bd2f8374347186728bdfe60ea15/aff=t_23vt_wg/p/release/gamehouse/wg_lotteryticket/lotteryticket/SpinTopGamesLauncher.cab" rel="nofollow">http://webgames.d.tmsrv.com/c=9cec9bd2f8374347186728bdfe60ea15/aff=t_23vt_wg/p/release/gamehouse/wg_lotteryticket/lotteryticket/SpinTopGamesLauncher.cab</a><br />
O16 - DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} (PCMaticVer Class) - <a href="http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab" rel="nofollow">http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab</a><br />
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - <a href="http://zone.msn.com/bingame/feed/default/SproutLauncher.cab" rel="nofollow">http://zone.msn.com/bingame/feed/default/SproutLauncher.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" rel="nofollow">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - <a href="http://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab" rel="nofollow">http://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe<br />
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe<br />
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe<br />
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
--<br />
End of file - 8889 bytes<br /><br />
Any help would be appreciated<br /><br />
Thank you!]]>
        </description>
    </item>
    <item>
        <title>Genuine Windows Advanage pop-up?</title>
        <link>https://icrontic.com/discussion/90214/genuine-windows-advanage-pop-up</link>
        <pubDate>Tue, 06 Jul 2010 15:14:44 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>Sunsetlover1013</dc:creator>
        <guid isPermaLink="false">90214@/discussions</guid>
        <description><![CDATA[Hello -- I am running VMFusion Virtual Machine and keep  getting a pop-up from Genuine Windows Advantage... wanting to install something. I used HiJack and my code is below... can anyone tell me if I am in trouble.. I have run malware bytes and AVG - both show me clean - but I can not system restore and I know this is a big clue to problems... HELP!! and thanks!!<br /><br />
Logfile of Trend Micro HijackThis v2.0.4<br />
Scan saved at 6:46:18 PM, on 7/1/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)<br />
Boot mode: Normal<br /><br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\Program Files\VMware\VMware Tools\vmacthlp.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe<br />
C:\Program Files\VMware\VMware Tools\VMwareService.exe<br />
C:\Program Files\VMware\VMware Tools\TPAutoConnSvc.exe<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\VMware\VMware Tools\VMwareTray.exe<br />
C:\Program Files\VMware\VMware Tools\VMwareUser.exe<br />
C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\VMware\VMware Tools\TPAutoConnect.exe<br />
C:\WINDOWS\system32\imapi.exe<br />
C:\WINDOWS\system32\msiexec.exe<br />
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe<br /><br />
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL<br />
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll<br />
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O4 - HKLM\..\Run: [VMware Tools] "C:\Program Files\VMware\VMware Tools\VMwareTray.exe"<br />
O4 - HKLM\..\Run: [VMware User Process] "C:\Program Files\VMware\VMware Tools\VMwareUser.exe"<br />
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe  startup<br />
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe /autorun<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: <a href="https://icrontic.com/profile/xpsp3res" rel="nofollow">@xpsp3res</a>.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware tools\vsock sdk\bin\win32\vsocklib.dll<br />
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware tools\vsock sdk\bin\win32\vsocklib.dll<br />
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - <a href="http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.0.cab" rel="nofollow">http://dlm.tools.akamai.com/dlmanage...ex-2.2.5.0.cab</a><br />
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL<br />
O18 - Protocol: intu-help-qb3 - {C5E479EA-0A65-4B05-8C6C-2FC8CC682EB4} - C:\Program Files\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll<br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)<br />
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)<br />
O20 - Winlogon Notify: TPSvc - TPSvc.dll (file missing)<br />
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll<br />
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll<br />
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe<br />
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe<br />
O23 - Service: QuickBooksDB17 - iAnywhere Solutions, Inc. - C:\PROGRA~1\Intuit\QUICKB~1\QBDBMgrN.exe<br />
O23 - Service: QuickBooksDB20 - Intuit, Inc. - C:\PROGRA~1\Intuit\QUICKB~3\QBDBMgrN.exe<br />
O23 - Service: TP AutoConnect Service (TPAutoConnSvc) - ThinPrint GmbH - C:\Program Files\VMware\VMware Tools\TPAutoConnSvc.exe<br />
O23 - Service: TP VC Gateway Service (TPVCGateway) - ThinPrint GmbH - C:\Program Files\VMware\VMware Tools\TPVCGateway.exe<br />
O23 - Service: VMware Tools Service (VMTools) - VMware, Inc. - C:\Program Files\VMware\VMware Tools\VMwareService.exe<br />
O23 - Service: VMware Physical Disk Helper Service - VMware, Inc. - C:\Program Files\VMware\VMware Tools\vmacthlp.exe<br /><br />
--<br />
End of file - 7858 bytes]]>
        </description>
    </item>
    <item>
        <title>The 72 Hour Bump Thread - No reply in 3 days? Respond here!</title>
        <link>https://icrontic.com/discussion/51612/the-72-hour-bump-thread-no-reply-in-3-days-respond-here</link>
        <pubDate>Wed, 08 Nov 2006 10:46:06 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>Trogan</dc:creator>
        <guid isPermaLink="false">51612@/discussions</guid>
        <description><![CDATA[This thread is for posting links to your unanswered Hijackthis logs that have been posted for over 72 hours and only that.<br /><br />
If you post here and you do not have a topic that is 72 hours old, your post here will be deleted. All help you receive will be in your original topic.<br /><br /><ol><li><b>Do not post your <u>Hijackthis log</u> in this thread</b> as it will be deleted. Instead, reply in THIS THREAD with a link to your topic.<br /><br /></li>
<li><b>If you do not put a link in your post here, then it will be deleted</b>.<br /><br /></li>
<li>Once you have posted a link to your topic, please scan with Hijackthis and post a new log in your <b>original</b> topic. As already stated, any Hijackthis logs that are posted in this thread will be deleted.<br /><br /></li>
<li>All of the helpers are busy as is and don't have time to search the site when a link is asked for.<br /><br /></li>
<li>If you have a question, then you can ask it here, such as how do I post a link or how do I find my topic. Otherwise, put all comments in your original post.</li>
</ol><br />
Once someone has started to help you, they will reply to your original topic and get started with helping you. Your post here, in this thread, will eventually be deleted.<br /><br />
If you haven't read this, go read it now!<br /><a href="http://icrontic.com/forum/showthread.php?t=43902" rel="nofollow">http://icrontic.com/forum/showthread.php?t=43902</a><br /><br />
Thank you!]]>
        </description>
    </item>
    <item>
        <title>Win Firewall Disabled, Redirects, Remote Attacks</title>
        <link>https://icrontic.com/discussion/90123/win-firewall-disabled-redirects-remote-attacks</link>
        <pubDate>Mon, 28 Jun 2010 10:32:41 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>Slider51</dc:creator>
        <guid isPermaLink="false">90123@/discussions</guid>
        <description><![CDATA[A week or so ago while browsing the web my machine was infected with 2 or 3 virus/malware applications. Two types of rogue anti-virus attacks, complete with fake infection alerts and attempted redirects to fake "scanner" sites, and a remote takeover trojan. The rogue AV attack included a persistent attempt at uninstalling AVG9.0 free, which I use as my AV solution. I was able to stop the uninstall both times. A couple of full scans with free MBAM and AVG free each seemingly cleaned everything up. I then registered MBAM and I'm now running the full paid version. My OS is Win XP Pro SP3, with all current updates and patches. My machine accesses the internet through a cable modem and a wired DLink router, which is used only as an internet "splitter" for this machine and another PC of my wife's. The two PC's are not networked or connected in any way other than through the wired router.<br /><br /><b>I'm left with two types of problems...</b><br /><br /><b>(1)</b> My Win firewall is stopped and I cannot restart it...The red "X" Shield for Windows Security Alerts is on in my tray, indicating the Win firewall is disabled. Attempting to turn the firewall back on results in a query window advising that Win Firewall/ICS is not running and asking if I want to start the service. Selecting "yes" results in an error window stating that the Win Firewall/ICS service cannot be started. I get the same result whether trying to start the service thorugh the Security Center or through Control Panel. Checking the system Event Viewer, I find repeated sets of two Information events followed by an error Event, as follows:<br /><br />Service Control Manager Event 7035: <i>"The Windows Firewall/Internet Connection Sharing (ICS) service was successfully sent a start control."</i><br />Service Control Manager Event 7036: <i>"The Windows Firewall/Internet Connection Sharing (ICS) service entered the stopped state."</i>Service Control Manager Event number 7023: <i>"The Windows Firewall/Internet Connection Sharing (ICS) service terminated with the following error: The system cannot find the file specified." </i><br /><br />In addition, I see several occurances of FTDisk Error 49: <i>"Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory."</i> immediately followed by FTDisk Error 45: <i>"The system could not sucessfully load the crash dump driver."</i> <br /><br />I have had several instances of my machine hanging on shutdown or during program launches and having no choice other than a hard shutdown to get out of the hang. I am assuming the "crash dump" is a service to help shut the system down in a hang situation?<br /><br />Also affected was my ability to download Windows updates and install them when notified that they are available by the yellow shield appreaing in my system tray. I have always had the option "Prompt me, but do not download or install updates automatically" selected, but after this attack, the shield would apprear but clicking on it would not start the download. I reset to Automatic downloads to try to re-enable the updates, but I don;t now if either service is working properly now.<br /><br /><b>(2)</b> Since cleaning the system as best as is possible with AVG and MBAM, I get continual remote attacks being noted in the system tray by MBAM, both while not connected to the internet and while connected. The following is a list of the attacker's IP's, and is not necessarily complete:<br /><br />91.212.226.67<br />91.212.226.59<br />91.228.209.200<br />85.12.46.157<br />85.12.46.155<br />85.12.46.158<br /><br />These come in waves, 15-20 minutes apart, and generally go through the entire list above. Meantime, I am getting occasional redirects upon launching IE8, mostly to "get rich quick" scheme websites, although other times to what seem to just be random legit sites.<br />I believe I have been infected on some level for months, my machine often runs incredibly slow, with command latencies up to 10-15 seconds in any number of applications, including extremely slow start-ups and shutdowns of the machine.<br /><br />Additionally, I cannot even post on this forum using my machine, whatever I am infected with immediately sends me to the "IE8 cannot open this page" when I click "Submit new thread" or "preview post". I'm actally using a different machine to post this.<br /><br />Please help! I feel pretty vulnerable without the firewall running and this machine should run much better than it does now...thanks in advance for your expert help.<br /><br />Slider<br /><br />HJT Log:<br /><br />Logfile of Trend Micro HijackThis v2.0.4<br />Scan saved at 8:26:35 PM, on 6/27/2010<br />Platform: Windows XP SP3 (WinNT 5.01.2600)<br />MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />Boot mode: Normal<br />Running processes:<br />C:\WINDOWS\System32\smss.exe<br />C:\WINDOWS\system32\winlogon.exe<br />C:\WINDOWS\system32\services.exe<br />C:\WINDOWS\system32\lsass.exe<br />C:\WINDOWS\system32\svchost.exe<br />C:\WINDOWS\System32\svchost.exe<br />C:\Program Files\AVG\AVG9\avgchsvx.exe<br />C:\Program Files\AVG\AVG9\avgrsx.exe<br />C:\WINDOWS\system32\spoolsv.exe<br />C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe<br />C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />C:\Program Files\Java\jre6\bin\jqs.exe<br />C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe<br />C:\PROGRA~1\PANASO~1\LocalCom\lmsrvnt.exe<br />C:\PROGRA~1\PANASO~1\TRAPMO~1\Trapmnnt.exe<br />C:\WINDOWS\System32\svchost.exe<br />C:\Program Files\AVG\AVG9\avgnsx.exe<br />C:\WINDOWS\system32\svchost.exe<br />C:\WINDOWS\Explorer.EXE<br />C:\WINDOWS\system32\RUNDLL32.EXE<br />C:\Program Files\Panasonic\Device Monitor\dmwakeup.exe<br />C:\Program Files\Panasonic\MFStation\PCCMFSDM.exe<br />C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />C:\WINDOWS\SOUNDMAN.EXE<br />C:\WINDOWS\ALCWZRD.EXE<br />C:\Program Files\Acronis\TrueImageWorkstation\TrueImageMonitor.exe<br />C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe<br />C:\Program Files\Acronis\TrueImageWorkstation\TimounterMonitor.exe<br />C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe<br />C:\WINDOWS\system32\ctfmon.exe<br />C:\WINDOWS\System32\svchost.exe<br />C:\WINDOWS\system32\wscntfy.exe<br />C:\WINDOWS\system32\notepad.exe<br />C:\WINDOWS\system32\wuauclt.exe<br />C:\Documents and Settings\Administrator\Desktop\HijackThis.exe<br />R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.comcast.net/a/" rel="nofollow">http://www.comcast.net/a/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555<br />
N3 - Netscape 7: # Mozilla User Preferences<br />/* Do not edit this file.<br />*<br />* If you make changes to this file while the browser is running,<br />* the changes will be overwritten when the browser exits.<br />*<br />* To make a manual change to preferences, you can visit the URL about:config<br />* For more information, see <a href="http://www.mozilla.org/unix/customizing.html#prefs" rel="nofollow">http://www.mozilla.org/unix/customizing.html#prefs</a><br />
*/<br />user_pref("aim.session.firsttime", false);<br />user_pref("browser.activation.checkedNNFlag", true);<br />user_pref("browser.bookmarks.added_static_root", true);<br />user_pref("browser.cache.disk.parent_directory", "C:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\APPLICATION DATA\\Mozilla\\Profiles\\default\\lxcunvvv.slt");<br />user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src");<br />user_pref("browser.startup.homepage_override.mstone", "rv:1.7.2");<br />user_pref("dom.disable_open_during_load", true);<br />user_pref("intl.charsetmenu.browser.cache", "us-ascii, UTF-8, windows-1252, ISO-8859-1");<br />user_pref("mail<br />O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll<br />O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br />O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll<br />O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll<br />O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll<br />O4 - HKLM\..\Run: [Panasonic Device Monitor Wakeup] C:\Program Files\Panasonic\Device Monitor\dmwakeup.exe<br />O4 - HKLM\..\Run: [Panasonic Device Manager for Multi-Function Station software] C:\Program Files\Panasonic\MFStation\PCCMFSDM.exe<br />O4 - HKLM\..\Run: [Panasonic PCFAX for Multi-Function Station software] C:\Program Files\Panasonic\MFStation\KmPcFax.exe -1<br />O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br />O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE<br />O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageWorkstation\TrueImageMonitor.exe<br />O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageWorkstation\TimounterMonitor.exe<br />O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"<br />O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br />O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray<br />O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll<br />O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />O15 - Trusted Zone: <a href="http://www.comcast.net/" rel="nofollow">http://www.comcast.net</a><br />
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - <a href="http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab" rel="nofollow">http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab</a><br />
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - <a href="http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab" rel="nofollow">http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab</a><br />
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - <a href="http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab" rel="nofollow">http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1096722207781" rel="nofollow">http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1096722207781</a><br />
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - <a href="http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab" rel="nofollow">http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1140016650656" rel="nofollow">http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1140016650656</a><br />
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - <a href="https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx" rel="nofollow">https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx</a><br />
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - <a href="http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?323" rel="nofollow">http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?323</a><br />
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = MANDP.Local<br />
O17 - HKLM\Software\..\Telephony: DomainName = MANDP.Local<br />
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = MANDP.Local<br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)<br />
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll<br />
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll<br />
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe<br />
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: JavaQuickStarterService - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe<br />
O23 - Service: Panasonic Local Printer Service - Panasonic Communications Co., Ltd. - C:\PROGRA~1\PANASO~1\LocalCom\lmsrvnt.exe<br />
O23 - Service: Panasonic Trap Monitor Service - Panasonic - C:\PROGRA~1\PANASO~1\TRAPMO~1\Trapmnnt.exe<br />
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
O23 - Service: Marvell Yukon Service (yksvc) - Unknown owner - RUNDLL32.EXE (file missing)<br />--<br />End of file - 9260 bytes]]>
        </description>
    </item>
    <item>
        <title>Virtual Machine Hijacked?</title>
        <link>https://icrontic.com/discussion/90165/virtual-machine-hijacked</link>
        <pubDate>Thu, 01 Jul 2010 19:02:51 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>Sunsetlover1013</dc:creator>
        <guid isPermaLink="false">90165@/discussions</guid>
        <description><![CDATA[Hello -- I am a mac user running VMFusion software on my mac.  I thought I would use limewire to grab a song... and all of a sudden I am getting a pop-up from Genuine Windows avantage... wanting to install something.  It happened as soon as I used limewire and downloaded a file.  I used HiJack and my code is below... can anyone tell me if I am in trouble.. I have run malware bytes and AVG - both show me clean - but I can not system restore and I know this is a big clue to problems...  HELP!!   and thanks!!<br /><br />
Logfile of Trend Micro HijackThis v2.0.4<br />
Scan saved at 6:46:18 PM, on 7/1/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)<br />
Boot mode: Normal<br /><br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\Program Files\VMware\VMware Tools\vmacthlp.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe<br />
C:\Program Files\VMware\VMware Tools\VMwareService.exe<br />
C:\Program Files\VMware\VMware Tools\TPAutoConnSvc.exe<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\VMware\VMware Tools\VMwareTray.exe<br />
C:\Program Files\VMware\VMware Tools\VMwareUser.exe<br />
C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\VMware\VMware Tools\TPAutoConnect.exe<br />
C:\WINDOWS\system32\imapi.exe<br />
C:\WINDOWS\system32\msiexec.exe<br />
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe<br /><br />
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL<br />
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll<br />
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O4 - HKLM\..\Run: [VMware Tools] "C:\Program Files\VMware\VMware Tools\VMwareTray.exe"<br />
O4 - HKLM\..\Run: [VMware User Process] "C:\Program Files\VMware\VMware Tools\VMwareUser.exe"<br />
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe  startup<br />
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe /autorun<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: <a href="https://icrontic.com/profile/xpsp3res" rel="nofollow">@xpsp3res</a>.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware tools\vsock sdk\bin\win32\vsocklib.dll<br />
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware tools\vsock sdk\bin\win32\vsocklib.dll<br />
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - <a href="http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.0.cab" rel="nofollow">http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.0.cab</a><br />
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL<br />
O18 - Protocol: intu-help-qb3 - {C5E479EA-0A65-4B05-8C6C-2FC8CC682EB4} - C:\Program Files\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll<br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)<br />
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)<br />
O20 - Winlogon Notify: TPSvc - TPSvc.dll (file missing)<br />
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll<br />
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll<br />
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe<br />
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe<br />
O23 - Service: QuickBooksDB17 - iAnywhere Solutions, Inc. - C:\PROGRA~1\Intuit\QUICKB~1\QBDBMgrN.exe<br />
O23 - Service: QuickBooksDB20 - Intuit, Inc. - C:\PROGRA~1\Intuit\QUICKB~3\QBDBMgrN.exe<br />
O23 - Service: TP AutoConnect Service (TPAutoConnSvc) - ThinPrint GmbH - C:\Program Files\VMware\VMware Tools\TPAutoConnSvc.exe<br />
O23 - Service: TP VC Gateway Service (TPVCGateway) - ThinPrint GmbH - C:\Program Files\VMware\VMware Tools\TPVCGateway.exe<br />
O23 - Service: VMware Tools Service (VMTools) - VMware, Inc. - C:\Program Files\VMware\VMware Tools\VMwareService.exe<br />
O23 - Service: VMware Physical Disk Helper Service - VMware, Inc. - C:\Program Files\VMware\VMware Tools\vmacthlp.exe<br /><br />
--<br />
End of file - 7858 bytes]]>
        </description>
    </item>
    <item>
        <title>I Think I Have A Rootkit...HELP?!?!</title>
        <link>https://icrontic.com/discussion/90117/i-think-i-have-a-rootkit-help</link>
        <pubDate>Sun, 27 Jun 2010 19:35:05 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>MrTRiot</dc:creator>
        <guid isPermaLink="false">90117@/discussions</guid>
        <description><![CDATA[My problem started when I tried to DL a dll file for my directX drivers. Needless to say it's one of the WORST things I've done in awhile...<br /><br /><br />
I've run a full virus scan using norton as well as Malwarebytes. Both found problems, fixed them...and then all hell broke loose<br /><br /><br />
When I start windows, it goes to a black screen for about 5 minutes, then cmd.exe starts up and windows loads shortly after that....<br /><br />
IE can connect to the internet. Chrome just won't even attempt to load...Can't burn anything...basically my computer is dead...<br /><br />
Here's my hijackthis log....I'm currently running trendmicro's rootkit buster as a last ditch effort....<br /><br />
HELP PLEZ?!?!?!?! I've NEVER encounted anything like this before. Also did all scans in safemode (which came up clean)<br /><br />
Logfile of Trend Micro HijackThis v2.0.4<br />
Scan saved at 7:34:11 PM, on 27/06/2010<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18928)<br />
Boot mode: Normal<br /><br />
Running processes:<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\Norton Internet Security\Engine\17.0.0.136\ccSvcHst.exe<br />
C:\hp\support\hpsysdrv.exe<br />
C:\Windows\vVX6000.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe<br />
C:\Program Files\Common Files\Java\Java Update\jusched.exe<br />
C:\Program Files\Logitech\SetPointP\SetPoint.exe<br />
C:\Program Files\uTorrent\uTorrent.exe<br />
C:\Program Files\DAEMON Tools Pro\DTAgent.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Program Files\MagicDisc\MagicDisc.exe<br />
C:\Program Files\Norton Internet Security\Engine\17.0.0.136\MCUI32.EXE<br />
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE<br />
C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe<br />
C:\Users\Rob\Desktop\RootkitBuster.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe<br />
C:\Users\Rob\Desktop\HijackThis.exe<br /><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.google.ca/" rel="nofollow">http://www.google.ca/</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =<br />
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\coIEPlg.dll<br />
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\IPSBHO.DLL<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\coIEPlg.dll<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br />
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe<br />
O4 - HKLM\..\Run: [VX6000] C:\Windows\vVX6000.exe<br />
O4 - HKLM\..\Run: [DPService] "C:\Program Files\HP\DVDPlay\DPService.exe"<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [EVGAPrecision] "C:\Program Files\EVGA Precision\EVGAPrecisionWrapper.exe" /s<br />
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"<br />
O4 - HKLM\..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming<br />
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW<br />
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe<br />
O4 - HKCU\..\Run: [Google Update] "C:\Users\Rob\AppData\Local\Google\Update\GoogleUpdate.exe" /c<br />
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork<br />
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"<br />
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTAgent.exe" -autorun<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'NETWORK SERVICE')<br />
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O15 - Trusted Zone: <a href="http://www.cbc.ca" rel="nofollow">http://www.cbc.ca</a><br />
O15 - Trusted Zone: <a href="http://www.simcountry.com" rel="nofollow">http://www.simcountry.com</a><br />
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - <a href="http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab" rel="nofollow">http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab</a><br />
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - <a href="http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab" rel="nofollow">http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab</a><br />
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - <a href="http://cdn.scan.onecare.live.com/resource/download/scanner/en-US/wlscctrl2.cab" rel="nofollow">http://cdn.scan.onecare.live.com/resource/download/scanner/en-US/wlscctrl2.cab</a><br />
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - <a href="http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab" rel="nofollow">http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab</a><br />
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - <a href="http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab" rel="nofollow">http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab</a><br />
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - <a href="http://gfx2.hotmail.com/mail/w2/resources/VistaMSNPUplden-ca.cab" rel="nofollow">http://gfx2.hotmail.com/mail/w2/resources/VistaMSNPUplden-ca.cab</a><br />
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - <a href="http://simcity.ea.com/update/EARTPX.cab" rel="nofollow">http://simcity.ea.com/update/EARTPX.cab</a><br />
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - <a href="http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab" rel="nofollow">http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab</a><br />
O16 - DPF: {6678BE91-1E04-4A4A-9C32-63145EA79C2A} (EAFO3AXLauncher Control) - <a href="http://fifa-online.easports.com/fo3-theme/addons/EAFO3AXLauncher.cab" rel="nofollow">http://fifa-online.easports.com/fo3-theme/addons/EAFO3AXLauncher.cab</a><br />
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} (Battlefield Heroes Updater) - <a href="https://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.53.0.cab" rel="nofollow">https://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.53.0.cab</a><br />
O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - <a href="http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab" rel="nofollow">http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab</a><br />
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - <a href="http://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab" rel="nofollow">http://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" rel="nofollow">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll<br />
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe<br />
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)<br />
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - G:\Games\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: Turbine Message Service - Live (LiveTurbineMessageService) - Turbine, Inc. - C:\Program Files\Turbine\Turbine Download Manager\TurbineMessageService.exe<br />
O23 - Service: Turbine Network Service - Live (LiveTurbineNetworkService) - Turbine, Inc. - C:\Program Files\Turbine\Turbine Download Manager\TurbineNetworkService.exe<br />
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe<br />
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\ccSvcHst.exe<br />
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)<br />
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe<br />
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe<br />
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI.SP1a\Win32\RpcDataSrv.exe<br />
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI.SP1a\RpcSandraSrv.exe<br />
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe<br />
O23 - Service: stllssvr - Unknown owner - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)<br />
O23 - Service: Update Center Service (UpdateCenterService) - NVIDIA - C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe<br />
O23 - Service: <a href="https://icrontic.com/profile/C" rel="nofollow">@C</a>:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100 (WPFFontCache_v0400) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (file missing)<br />
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe<br /><br />
--<br />
End of file - 9438 bytes]]>
        </description>
    </item>
    <item>
        <title>Problem : unknown bkkwhygtsstd.exe running, accessing the internet - Poster Levan</title>
        <link>https://icrontic.com/discussion/90079/problem-unknown-bkkwhygtsstd-exe-running-accessing-the-internet-poster-levan</link>
        <pubDate>Wed, 23 Jun 2010 00:28:56 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>Levan</dc:creator>
        <guid isPermaLink="false">90079@/discussions</guid>
        <description><![CDATA[In folder : C:\Documents and Settings\default\Application Data\ylanukmgh\bkkwhygtssd.exe<br /><br />
Windows says that the folder / file was created last night<br /><br />
Hijack this shows this as a running process - log pasted below<br /><br />
My ESET firewall alerted me to a new program trying to access the internet. I didn't knowingly download this program or anything else which might have contained it. I think I might have gotten it from surfing the web and closing a pop up window. I did a full system scan with ESET and Pest Patrol, neither identified it as a threat, but the exe is still there.<br /><br />
When trying to post on this forum, I'm seeing a rollover ad for Charleston, SC. Mousing away from it, a new window popped up redirecting me to a local search for "betty crocker recipes" in my zip code.<br /><br />
Thanks for reading. Please help!<br /><br /><br /><br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 11:11:56 PM, on 6/22/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\ESET\ESET Smart Security\ekrn.exe<br />
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe<br />
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Matrox Graphics<br />
Inc\PowerDesk\Services\Matrox.PowerDesk.Services.exe<br />
C:\Program Files\Matrox Graphics Inc\PowerDesk<br />
SE\Matrox.Pdesk.ServicesHost.exe<br />
C:\Program Files\Maxtor\Sync\SyncServices.exe<br />
C:\Program Files\Common Files\Motive\McciCMService.exe<br />
C:\WINDOWS\system32\mgabg.exe<br />
C:\SUPERFAX\PROGRAM\PICPMON.EXE<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Matrox Graphics Inc\PowerDesk<br />
SE\Matrox.DesktopManagement.Host.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\pctspk.exe<br />
C:\Program Files\Matrox Graphics Inc\PowerDesk SE\Matrox.PowerDesk SE.exe<br />
C:\WINDOWS\system32\devldr32.exe<br />
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe<br />
C:\Program Files\ESET\ESET Smart Security\egui.exe<br />
C:\Program Files\QuickTime\qttask.exe<br />
C:\Program Files\Common Files\Java\Java Update\jusched.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\OpenOffice.org 3\program\soffice.exe<br />
C:\Program Files\OpenOffice.org 3\program\soffice.bin<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Documents and Settings\default\Application<br />
Data\ylanukmgh\bkkwhygtssd.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\Documents and Settings\default\Desktop\PC Tools\HiJackThis.exe<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =<br /><a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =<br /><a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =<br /><a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =<br /><a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title =<br />
Microsoft Internet Explorer provided by Comcast<br />
R3 - URLSearchHook: Yahoo! Toolbar -<br />
{EF99BD32-C1FB-11D2-892F-0090271D4F88} -<br />
C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\yt.dll<br />
N3 - Netscape 7: # Mozilla User Preferences<br />
// This is a generated<br />
file!<br />
user_pref("Dick Cox.aim.session.autologin", false);<br />
user_pref("Dick Cox.aim.session.connectionname", "AIM");<br />
user_pref("Dick<br />
Cox.aim.session.password", "0");<br />
user_pref("Dick<br />
Cox.aim.session.storepassword", false);<br />
user_pref("aim.away.disablesound", false);<br />
user_pref("aim.internal.buddy.MaxBuddies", 220);<br />
user_pref("aim.internal.intproxyprotocol", 1);<br />
user_pref("aim.session.finishedwizard", true);<br />
user_pref("aim.session.firsttime", false);<br />
user_pref("aim.session.latestaimscreenname", "icehelmets");<br />
user_pref("aim.session.migrateBuddyList", "Dick Cox");<br />
user_pref("aim.session.screenname", "icehelmets");<br />
user_pref("browser.bookmarks.added_static_root", true);<br />
user_pref("browser.download.dir", "C:\\WINDOWS\\Desktop");<br />
user_pref("browser.history.last_page_visited",<br />
"<a href="http://boards.billmaher.com/logout.php?Cat" rel="nofollow">http://boards.billmaher.com/logout.php?Cat</a>=");<br />
user_pref("browser.search.defaultengine",<br />
"engine://C%3A%5CPROGRAM%20FILES%5CNETSCAPE%5CNETSCAPE%206%5Csearchplugin<br />
s%5CSBWeb_01.src<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670}<br />
- C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: Adobe PDF Reader Link Helper -<br />
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common<br />
Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: (no name) - {1FD79A59-37B1-459B-9097-09F9FAB8A523} - (no file)<br />
O2 - BHO: CDNSCacheObj Object - {376892AE-1825-4E5F-9F85-23F9640051CC} -<br />
(no file)<br />
O2 - BHO: Yahoo! IE Services Button -<br />
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program<br />
Files\Yahoo!\Common\yiesrvc.dll<br />
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} -<br />
C:\WINDOWS\system\dla\tfswshx.dll<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -<br />
C:\Program Files\Microsoft\Search Enhancement Pack\Search<br />
Helper\SearchHelper.dll<br />
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -<br />
C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper -<br />
{DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program<br />
Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C}<br />
- C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} -<br />
C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\yt.dll<br />
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} -<br />
C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll<br />
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe<br />
O4 - HKLM\..\Run: [Matrox Powerdesk] C:\WINDOWS\System32\PDesk\PDesk.exe<br />
/Autolaunch<br />
O4 - HKLM\..\Run: [MpsOnn]<br />
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\MpsOnn.exe<br />
O4 - HKLM\..\Run: [Matrox PowerDesk SE] "C:\Program Files\Matrox Graphics<br />
Inc\PowerDesk SE\Matrox.PowerDesk SE.exe"<br />
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program<br />
Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe"<br />
-resume<br />
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch<br />
Status\maxmenumgr.exe"<br />
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart<br />
Security\egui.exe" /hide /waitservice<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program<br />
Files\QuickTime\qttask.exe" -atboottime<br />
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common<br />
Files\Real\Update_OB\realsched.exe" -osboot<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common<br />
Files\Java\Java Update\jusched.exe"<br />
O4 - HKLM\..\Run: [cmdnqgyk] C:\Documents and<br />
Settings\default\Application Data\ylanukmgh\bkkwhygtssd.exe<br />
O4 - HKLM\..\Run: [PPMemCheck] c:\PROGRA~1\PESTPA~1\PPMemCheck.exe<br />
O4 - HKLM\..\Run: [PestPatrol Control Center]<br />
c:\PROGRA~1\PESTPA~1\PPControl.exe<br />
O4 - HKLM\..\RunOnce: [TSC]<br />
"C:\DOCUME~1\default\LOCALS~1\Temp\HouseCall\tsc.exe" /HD<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [cmdnqgyk] C:\Documents and<br />
Settings\default\Application Data\ylanukmgh\bkkwhygtssd.exe<br />
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org<br />
3\program\quickstart.exe<br />
O8 - Extra context menu item: Add to Google Photos Screensa&amp;ver -<br />
res://C:\WINDOWS\system32\GPhotos.scr/200<br />
O9 - Extra button: Yahoo! Services -<br />
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program<br />
Files\Yahoo!\Common\yiesrvc.dll<br />
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} -<br />
C:\Program Files\AIM95\aim.exe<br />
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -<br />
(no file)<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} -<br />
C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: <a href="https://icrontic.com/profile/xpsp3res" rel="nofollow">@xpsp3res</a>.dll,-20001 -<br />
{e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network<br />
Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -<br />
C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger -<br />
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program<br />
Files\Messenger\msmsgs.exe<br />
O9 - Extra button: Support - {1B2897F0-7F93-417D-B240-D720DA9B2339} -<br /><a href="http://www.comcastsupport.com" rel="nofollow">http://www.comcastsupport.com</a> (file missing) (HKCU)<br />
O9 - Extra button: ComcastHSI - {291EA4D8-C8BC-4D70-82FB-15FE40113ACF} -<br /><a href="http://www.comcast.net" rel="nofollow">http://www.comcast.net</a> (file missing) (HKCU)<br />
O9 - Extra button: Help - {E941727A-3ABE-4332-93F2-D20FFF992FC2} -<br /><a href="http://www.comcast.net/memberservices/" rel="nofollow">http://www.comcast.net/memberservices/</a> (file missing) (HKCU)<br />
O9 - Extra button: Dell Home - {EE117DAA-A30B-40FC-945C-38AE1B80C1FA} -<br /><a href="http://www.dellnet.com" rel="nofollow">http://www.dellnet.com</a> (file missing) (HKCU)<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll<br />
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll<br />
O16 - DPF: Win32 Classes -<br />
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -<br /><a href="http://www.pcpitstop.com/betapit/PCPitStop.CAB" rel="nofollow">http://www.pcpitstop.com/betapit/PCPitStop.CAB</a><br />
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} -<br /><a href="http://a1540.g.akamai.net/7/1540/52/20040427/qtinstall.info.apple.com/sab" rel="nofollow">http://a1540.g.akamai.net/7/1540/52/20040427/qtinstall.info.apple.com/sab</a><br />
a/us/win/QuickTimeInstaller.exe<br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -<br /><a href="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/clie" rel="nofollow">http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/clie</a><br />
nt/muweb_site.cab?1259480903199<br />
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control)<br />
- <a href="http://download.eset.com/special/eos/OnlineScanner.cab" rel="nofollow">http://download.eset.com/special/eos/OnlineScanner.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -<br /><a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" rel="nofollow">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O23 - Service: ATI Smart - Unknown owner -<br />
C:\WINDOWS\SYSTEM32\ati2sgag.exe (file missing)<br />
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program<br />
Files\ESET\ESET Smart Security\EHttpSrv.exe<br />
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET<br />
Smart Security\ekrn.exe<br />
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program<br />
Files\Common Files\EPSON\EBAPI\eEBSVC.exe<br />
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO<br />
EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe<br />
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program<br />
Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun<br />
Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Matrox Centering Service - Matrox Graphics Inc. -<br />
C:\Program Files\Matrox Graphics<br />
Inc\PowerDesk\Services\Matrox.PowerDesk.Services.exe<br />
O23 - Service: Matrox.Pdesk.ServicesHost - Matrox Graphics Inc -<br />
C:\Program Files\Matrox Graphics Inc\PowerDesk<br />
SE\Matrox.Pdesk.ServicesHost.exe<br />
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology<br />
LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe<br />
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common<br />
Files\Motive\McciCMService.exe<br />
O23 - Service: MGABGEXE - Matrox Graphics Inc. -<br />
C:\WINDOWS\system32\mgabg.exe<br />
O23 - Service: Pacific Image Comm. Fax Server - Unknown owner -<br />
C:\SUPERFAX\PROGRAM\PICPMON.EXE<br />
O23 - Service: PCTEL Speaker Phone (Pctspk) - Unknown owner -<br />
C:\WINDOWS\system32\pctspk.exe<br />
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC -<br />
C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe<br />
--<br />
End of file - 10627 bytes]]>
        </description>
    </item>
    <item>
        <title>ran panda found 6 virus</title>
        <link>https://icrontic.com/discussion/90101/ran-panda-found-6-virus</link>
        <pubDate>Fri, 25 Jun 2010 02:44:41 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>epistaxis</dc:creator>
        <guid isPermaLink="false">90101@/discussions</guid>
        <description><![CDATA[unfortunatly my wife or kid clsed before i got home from work to see whatthey where. I know vbradcrayicon was one. I also had KGB installed myself, but i uninstalled before i ran this log. here it is<br />
Logfile of Trend Micro HijackThis v2.0.4<br />
Scan saved at 11:38:26 PM, on 6/24/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br /><br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\msiexec.exe<br />
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe<br /><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://search.conduit.com?SearchSource=10&amp;ctid=CT2405280" rel="nofollow">http://search.conduit.com?SearchSource=10&amp;ctid=CT2405280</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =<br />
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe<br />
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll<br />
O15 - Trusted Zone: <a href="http://software.kuaiche.com" rel="nofollow">http://software.kuaiche.com</a><br />
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = skyfalker<br />
O17 - HKLM\Software\..\Telephony: DomainName = skyfalker<br />
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = skyfalker<br />
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = skyfalker<br />
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll<br />
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll<br />
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br /><br />
--<br />
End of file - 2406 bytes]]>
        </description>
    </item>
    <item>
        <title>I need some help</title>
        <link>https://icrontic.com/discussion/90057/i-need-some-help</link>
        <pubDate>Tue, 22 Jun 2010 03:06:42 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>jajenk</dc:creator>
        <guid isPermaLink="false">90057@/discussions</guid>
        <description><![CDATA[Hello, I hope you can help. I got a virus, AV SEcurity Suite, and went through the steps to remove it. Now things are running pretty well, but I cannot go to windows update. Whenever I go to any site fo information, I am taken to some randowm unknown search engine and cannot get any answers. If i go right to windows update, It says IE cannot display the web page. Other things like FB and browsing seem to be alright. Here's my Hijack this Log...Any Help would be appreciated...<br /><br />
Logfile of HijackThis v1.99.1<br />
Scan saved at 2:24:10 AM, on 6/22/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br /><br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\WINDOWS\system32\lxddcoms.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgemc.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\WINDOWS\Dit.exe<br />
C:\WINDOWS\SOUNDMAN.EXE<br />
C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
C:\WINDOWS\DitExp.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe<br />
C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe<br />
C:\WINDOWS\explorer.exe<br />
C:\Documents and Settings\Owner\Desktop\My Programs\HijackThis.exe<br /><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =<br />
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll<br />
O4 - HKLM\..\Run: [Dit] Dit.exe<br />
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler<br />
O4 - Startup: VZAccess Manager.lnk = C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)<br />
O9 - Extra 'Tools' menuitem: <a href="https://icrontic.com/profile/xpsp3res" rel="nofollow">@xpsp3res</a>.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O11 - Options group: [INTERNATIONAL] International<br />
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - <a href="http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab" rel="nofollow">http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" rel="nofollow">http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab</a><br />
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - <a href="http://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab" rel="nofollow">http://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab</a><br />
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - <a href="http://driveragent.com/files/driveragent.cab" rel="nofollow">http://driveragent.com/files/driveragent.cab</a><br />
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - <a href="http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll" rel="nofollow">http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)<br />
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll<br />
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: lxddCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxddserv.exe<br />
O23 - Service: lxdd_device -   - C:\WINDOWS\system32\lxddcoms.exe<br />
O23 - Service: Roxio UPnP Renderer 9 - Unknown owner - C:\Program Files\Common Files\Sonic Shared\RoxioUPnPRenderer9.exe (file missing)<br />
O23 - Service: Roxio Upnp Server 9 - Unknown owner - C:\Program Files\Common Files\Sonic Shared\RoxioUpnpService9.exe (file missing)<br />
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)<br />
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)<br />
O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)<br /><br /><br /><br />
Thanks for any help...]]>
        </description>
    </item>
    <item>
        <title>NASTY hijacking. PLEASE HELP (HJthis log included)</title>
        <link>https://icrontic.com/discussion/89665/nasty-hijacking-please-help-hjthis-log-included</link>
        <pubDate>Wed, 19 May 2010 21:51:54 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>M_ROUSSEAU</dc:creator>
        <guid isPermaLink="false">89665@/discussions</guid>
        <description><![CDATA[this malware won't let me run system restore, and has changed my desktop appearance. System restore is locked due to group policy, and when I try to enter gpedit.msc, It states that access is denied.<br /><br />
Log:<br /><br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 9:22:09 PM, on 5/19/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.17023)<br />
Boot mode: Normal<br /><br />
Running processes:<br />
C:\windows\system32\csrss.exe<br />
C:\windows\system32\winlogon.exe<br />
C:\windows\system32\services.exe<br />
C:\windows\system32\lsass.exe<br />
C:\windows\system32\svchost.exe<br />
C:\windows\system32\svchost.exe<br />
C:\windows\System32\svchost.exe<br />
C:\windows\system32\svchost.exe<br />
C:\windows\system32\svchost.exe<br />
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
C:\windows\system32\spoolsv.exe<br />
C:\windows\system32\svchost.exe<br />
C:\WINDOWS\Psyxoa.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\windows\Explorer.EXE<br />
C:\WINDOWS\eHome\ehRecvr.exe<br />
C:\WINDOWS\eHome\ehSched.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe<br />
C:\Program Files\Spyware Doctor\pctsAuxs.exe<br />
C:\windows\system32\svchost.exe<br />
C:\Documents and Settings\All Users\Application Data\ZwangiSrch\zwangi161.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\windows\System32\alg.exe<br />
C:\Program Files\Spyware Doctor\pctsSvc.exe<br />
C:\Program Files\Spyware Doctor\pctsTray.exe<br />
C:\windows\system32\wuauclt.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\DAEMON Tools Pro\DTPro.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\WINDOWS\system32\wbem\wmiprvse.exe<br /><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =<br />
R3 - Default URLSearchHook is missing<br />
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Documents and Settings\Matthew\Application Data\sdra64.exe,C:\WINDOWS\system32\sdra64.exe,<br />
O2 - BHO: C:\WINDOWS\system32\uuxntd.dll - {C7BA40A1-74F2-52BD-F411-04B15A2C8953} - C:\WINDOWS\system32\uuxntd.dll<br />
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll<br />
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (file missing)<br />
O3 - Toolbar: My.Freeze.com Toolbar - {D0523BB4-21E7-11DD-9AB7-415B56D89593} - C:\Program Files\My.Freeze.com Toolbar\freeze_us.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe<br />
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE<br />
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br />
O4 - HKLM\..\Run: [net] "C:\WINDOWS\system32\net.net"<br />
O4 - HKLM\..\Run: [notepad] rundll32.exe C:\WINDOWS\system32\notepad.dll,_NtLoad@0<br />
O4 - HKLM\..\Run: [igdwwlyv] C:\Documents and Settings\Matthew\Local Settings\Application Data\iumqltmoi\dedeqritssd.exe<br />
O4 - HKLM\..\Run: [M5T8QL3YW3] C:\DOCUME~1\Matthew\LOCALS~1\Temp\Pbh.exe<br />
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"<br />
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent<br />
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br />
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE<br />
O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll<br />
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\Program Files\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll (file missing)<br />
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\Program Files\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll (file missing)<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (file missing)<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (file missing)<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: <a href="https://icrontic.com/profile/xpsp3res" rel="nofollow">@xpsp3res</a>.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O15 - ProtocolDefaults: '<a href="https://icrontic.com/profile/ivt" rel="nofollow">@ivt</a>' protocol is in My Computer Zone, should be Intranet Zone<br />
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone<br />
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone<br />
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone<br />
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone<br />
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -<br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" rel="nofollow">http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab</a><br />
O22 - SharedTaskScheduler: har98fefiesjfs93s8i9sejsdf - {C7BA40A1-74F2-52BD-F411-04B15A2C8953} - C:\WINDOWS\system32\uuxntd.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Browser Defender Update Service - Threat Expert Ltd. - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe<br />
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildGames\Game Console - WildGames\GameConsoleService.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe<br />
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe<br />
O23 - Service: ZwangiSrch Service - Unknown owner - C:\Documents and Settings\All Users\Application Data\ZwangiSrch\zwangi161.exe<br /><br />
--<br />
End of file - 8107 bytes<br /><br />
Thanks for your help!]]>
        </description>
    </item>
    <item>
        <title>Need Help Maleware</title>
        <link>https://icrontic.com/discussion/89978/need-help-maleware</link>
        <pubDate>Wed, 16 Jun 2010 01:13:37 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>Stykie</dc:creator>
        <guid isPermaLink="false">89978@/discussions</guid>
        <description><![CDATA[Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 1:01:20 AM, on 6/16/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br /><br />
Running processes:<br />
C:\windows\System32\smss.exe<br />
C:\windows\system32\winlogon.exe<br />
C:\windows\system32\services.exe<br />
C:\windows\system32\lsass.exe<br />
C:\windows\system32\svchost.exe<br />
C:\windows\System32\svchost.exe<br />
C:\windows\system32\svchost.exe<br />
C:\Program Files\Maxthon2\Modules\MxKWS\KSWebShield.exe<br />
C:\windows\system32\spoolsv.exe<br />
C:\windows\Explorer.EXE<br />
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe<br />
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\windows\system32\svchost.exe<br />
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe<br />
C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
C:\windows\system32\ctfmon.exe<br />
C:\Program Files\AIM6\aim6.exe<br />
C:\windows\system32\rundll32.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\AIM6\aolsoftware.exe<br />
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtblfs.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br /><br />
R3 - URLSearchHook: Device Doctor Toolbar - {bb6d9528-45f5-4c75-91c9-93290710ec4c} - C:\Program Files\Device_Doctor\tbDev1.dll (file missing)<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\ievkbd.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: eSnipBHO - {B530A9A4-1722-4D16-AAD6-AA85E3AD2ADE} - (no file)<br />
O2 - BHO: Device Doctor Toolbar - {bb6d9528-45f5-4c75-91c9-93290710ec4c} - C:\Program Files\Device_Doctor\tbDev1.dll (file missing)<br />
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll<br />
O3 - Toolbar: Device Doctor Toolbar - {bb6d9528-45f5-4c75-91c9-93290710ec4c} - C:\Program Files\Device_Doctor\tbDev1.dll (file missing)<br />
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"<br />
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"<br />
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"<br />
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"<br />
O4 - HKLM\..\Run: [Evikukowomaqu] rundll32.exe "C:\windows\owitaxuhijuciv.dll",Startup<br />
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe"<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (rootkit-scan)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp<br />
O4 - HKCU\..\Run: [Isiwabu] rundll32.exe "C:\windows\mshc32.dll",Startup<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: &amp;Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: URLs c&amp;heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: <a href="https://icrontic.com/profile/xpsp3res" rel="nofollow">@xpsp3res</a>.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O15 - ESC Trusted Zone: <a href="http://*.update.microsoft.com" rel="nofollow">http://*.update.microsoft.com</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1271373856812" rel="nofollow">http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1271373856812</a><br />
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\system32\Ati2evxx.exe<br />
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe<br />
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Kingsoft Antivirus WebShield Service - Kingsoft Corporation - C:\Program Files\Maxthon2\Modules\MxKWS\KSWebShield.exe<br />
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\windows\system32\HPZipm12.exe<br />
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br /><br />
--<br />
End of file - 6829 bytes]]>
        </description>
    </item>
    <item>
        <title>not sure if virus or not....</title>
        <link>https://icrontic.com/discussion/89936/not-sure-if-virus-or-not</link>
        <pubDate>Sun, 13 Jun 2010 20:57:51 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>The-Lovable-Mr--Hater</dc:creator>
        <guid isPermaLink="false">89936@/discussions</guid>
        <description><![CDATA[Hi ya guys. been a long time. everything seems to be going well for me, except my most recent quandry. i hope all is well with everyone here. my question is, what would cause my add/remove programs in my control panel not to work? i have searched and found all kinds of people that say they have the same problem, and i have tried their resolutions without any success. maybe some of the really smart people in here would know what to do.<br /><br />
thanks in advance,<br /><br />
the lovable mr. hater]]>
        </description>
    </item>
    <item>
        <title>Is this system now clean?</title>
        <link>https://icrontic.com/discussion/89897/is-this-system-now-clean</link>
        <pubDate>Fri, 11 Jun 2010 04:41:07 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>SillyViking</dc:creator>
        <guid isPermaLink="false">89897@/discussions</guid>
        <description><![CDATA[Hi,<br />
long time no post <img src="https://icrontic.com/resources/icrontimoji/smile.gif" title=":)" alt=":)" /><br /><br />
My eldest daughter recently managed to make a total mess of her pc - all kinds of things had been installed and/or trashed and, after much messing around to try and fix the problems, I decided it was easier/safer to reinstall from scratch (using the built in, hidden, restore partition).<br /><br />
One odd error still appeared after this process was complete - on system startup AVG would report a worm in autorun.inf which was launching in explorer.exe<br /><br />
I ran MBAM and a few other programs to try and find out what, exactly, was causing this problem and, after everything else tested clear, I came to the conclusion (along with much googling) that it was some kind of weird thing that AVG was doing. I uninstalled AVG and tried various free AV programs - none repeated the same issue. The system is now running Avast!<br /><br />
I am attaching, below, a HJT log and would be very grateful if one of you guru-bods could run your eyes over it (and read above), to check to see if there is anything I am missing.<br /><br />
Thank you<br /><br />
SV <img src="https://icrontic.com/resources/icrontimoji/smile.gif" title=":)" alt=":)" /><br /><br />
Logfile of Trend Micro HijackThis v2.0.4<br />
Scan saved at 09:33:07, on 11/06/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br /><br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\System32\wltrysvc.exe<br />
C:\WINDOWS\System32\bcmwltry.exe<br />
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\ehome\ehtray.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\Program Files\Common Files\Java\Java Update\jusched.exe<br />
C:\WINDOWS\system32\SysMonitor.exe<br />
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe<br />
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe<br />
C:\WINDOWS\system32\RUNDLL32.EXE<br />
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe<br />
C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe<br />
C:\Program Files\Belkin\F5D7001v2000\Belkinwcui.exe<br />
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe<br />
C:\WINDOWS\eHome\ehRecvr.exe<br />
C:\WINDOWS\eHome\ehSched.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
c:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\WINDOWS\eHome\ehmsas.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\WINDOWS\system32\msiexec.exe<br />
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe<br /><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://uk.rd.yahoo.com/customize/ycomp/defaults/sp/*http://uk.yahoo.com" rel="nofollow">http://uk.rd.yahoo.com/customize/ycomp/defaults/sp/*http://uk.yahoo.com</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.google.co.uk/" rel="nofollow">http://www.google.co.uk/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = <a href="http://uk.rd.yahoo.com/customize/ycomp/defaults/su/*http://uk.yahoo.com" rel="nofollow">http://uk.rd.yahoo.com/customize/ycomp/defaults/su/*http://uk.yahoo.com</a><br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = <a href="http://en.uk.acer.yahoo.com/" rel="nofollow">http://en.uk.acer.yahoo.com/</a><br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (file missing)<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll<br />
O3 - Toolbar: &amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)<br />
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe<br />
O4 - HKLM\..\Run: [LaunchApp] Alaunch<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE<br />
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br />
O4 - HKLM\..\Run: [ntiMUI] c:\Program Files\NewTech Infosystems\NTI CD &amp; DVD-Maker 7\ntiMUI.exe<br />
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32<br />
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE<br />
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC<br />
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC<br />
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"<br />
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\WINDOWS\system32\SysMonitor.exe<br />
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe 0<br />
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')<br />
O4 - Global Startup: Acer Empowering Technology.lnk = ?<br />
O4 - Global Startup: Acer WLAN 11g USB Dongle.lnk = C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe<br />
O4 - Global Startup: Belkin Wireless Utility.lnk = ?<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: <a href="https://icrontic.com/profile/xpsp3res" rel="nofollow">@xpsp3res</a>.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1275865202203" rel="nofollow">http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1275865202203</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1275865260578" rel="nofollow">http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1275865260578</a><br />
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll<br />
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll<br />
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe<br />
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe<br />
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe<br />
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe<br /><br />
--<br />
End of file - 8425 bytes]]>
        </description>
    </item>
    <item>
        <title>PC has been hi-jacked</title>
        <link>https://icrontic.com/discussion/89721/pc-has-been-hi-jacked</link>
        <pubDate>Tue, 25 May 2010 13:39:06 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>Surtlab</dc:creator>
        <guid isPermaLink="false">89721@/discussions</guid>
        <description><![CDATA[I do believe my PC has been hi-jacked or something of the sort.  I have ran all of my spyware programs and my Kaspersky and found nothing, however, recently, PC running strange, slow loading pages, then people are receiving emails from me that I havent sent.  Even on FaceBook this is happening.  I just bought Kaspersky and previously been using free version of avast, which I had no problems.  When I log on, I see what flashes as a virus waring, very quickly, as what use to flash if avast found something, but the purchased version of kaspersky has found nothing.<br />
I do realize that Limewire is installed, as has been for years now, however, this problem is new and not related.<br />
I have enclosed a copy of my logs for review:<br /><br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 12:58:57 PM, on 5/25/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br /><br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe<br />
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\WINDOWS\eHome\ehRecvr.exe<br />
C:\WINDOWS\eHome\ehSched.exe<br />
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS<br />
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Blue Coat K9 Web Protection\k9filter.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Digital Media Reader\shwiconem.exe<br />
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe<br />
C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe<br />
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br /><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://foxnews.com/" rel="nofollow">http://foxnews.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\ievkbd.dll<br />
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br />
O2 - BHO: TwcToolbarBhoApp Class - {AA1F9DDB-E605-4ba6-81D4-E427DEE012AD} - C:\WINDOWS\system32\TwcToolbarBho.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll<br />
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll<br />
O3 - Toolbar: The Weather Channel Toolbar - {2E5E800E-6AC0-411E-940A-369530A35E43} - C:\WINDOWS\system32\TwcToolbarIe7.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll<br />
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe<br />
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"<br />
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe  startup<br />
O4 - HKLM\..\Run: [ContentTransferWMDetector.exe] C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"<br />
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"<br />
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe"<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"<br />
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"<br />
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: &amp;Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: URLs c&amp;heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: <a href="https://icrontic.com/profile/xpsp3res" rel="nofollow">@xpsp3res</a>.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - <a href="http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab" rel="nofollow">http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab</a><br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll<br />
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} - <a href="http://www.passalong.com/Music/install/network/install.exe" rel="nofollow">http://www.passalong.com/Music/install/network/install.exe</a><br />
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - <a href="http://acs.pandasoftware.com/activescan/as5free/asinst.cab" rel="nofollow">http://acs.pandasoftware.com/activescan/as5free/asinst.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" rel="nofollow">http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" rel="nofollow">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - <a href="http://by109fd.bay109.hotmail.msn.com/activex/HMAtchmt.ocx" rel="nofollow">http://by109fd.bay109.hotmail.msn.com/activex/HMAtchmt.ocx</a><br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll<br />
O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll<br />
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)<br />
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll<br />
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe<br />
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS<br />
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe<br />
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe<br />
O23 - Service: Blue Coat K9 Web Protection (WebFilter) - Unknown owner - C:\Program Files\Blue Coat K9 Web Protection\k9filter.exe<br /><br />
--<br />
End of file - 10278 bytes]]>
        </description>
    </item>
    <item>
        <title>XP Internet Security Virus (at a minimum)</title>
        <link>https://icrontic.com/discussion/88167/xp-internet-security-virus-at-a-minimum</link>
        <pubDate>Sun, 07 Feb 2010 12:48:05 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator></dc:creator>
        <guid isPermaLink="false">88167@/discussions</guid>
        <description><![CDATA[Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 11:41:16 AM, on 2/7/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe<br />
C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\WINDOWS\eHome\ehRecvr.exe<br />
C:\WINDOWS\eHome\ehSched.exe<br />
C:\Program Files\Flip Video\FlipShare\FlipShareService.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe<br />
C:\WINDOWS\system32\mqsvc.exe<br />
C:\Program Files\Canon\CAL\CALMAIN.exe<br />
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
C:\WINDOWS\system32\mqtgsvc.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\HPZipm12.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\ehome\ehtray.exe<br />
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe<br />
C:\WINDOWS\system32\RUNDLL32.EXE<br />
C:\WINDOWS\eHome\ehmsas.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\HP\QuickPlay\QPService.exe<br />
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe<br />
C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe<br />
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe<br />
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe<br />
C:\Program Files\PIXELA\ImageMixer 3 SE\CameraMonitor.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe<br />
C:\Program Files\Java\jre6\bin\jucheck.exe<br />
C:\WINDOWS\system32\msiexec.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.runescape.com/" rel="nofollow">http://www.runescape.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =<br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=64&amp;bd=pavilion&amp;pf=laptop" rel="nofollow">http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=64&amp;bd=pavilion&amp;pf=laptop</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br />
O1 - Hosts: HP56934E HP00187156934E<br />
O1 - Hosts: 82.98.231.89 url.adtrgt.com<br />
O1 - Hosts: 82.98.231.89 googleads2.gdoubleclick.net<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll<br />
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe<br />
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect<br />
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll<br />
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup<br />
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start<br />
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start<br />
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe<br />
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe<br />
O4 - HKLM\..\Run: [Reminder] C:\Windows\CREATOR\Remind_XP.exe<br />
O4 - HKLM\..\Run: [basicsmssmenu] "C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe"<br />
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br />
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"<br />
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe<br />
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe<br />
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKUS\S-1-5-21-3268937493-411182698-2146996859-1008\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Jake')<br />
O4 - HKUS\S-1-5-21-3268937493-411182698-2146996859-1008\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Jake')<br />
O4 - HKUS\S-1-5-21-3268937493-411182698-2146996859-1008\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" (User 'Jake')<br />
O4 - HKUS\S-1-5-21-3268937493-411182698-2146996859-1008\..\Run: [Monopod] C:\DOCUME~1\Jake\LOCALS~1\Temp\a.exe (User 'Jake')<br />
O4 - HKUS\S-1-5-21-3268937493-411182698-2146996859-1008\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe (User 'Jake')<br />
O4 - HKUS\S-1-5-21-3268937493-411182698-2146996859-1008\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (User 'Jake')<br />
O4 - S-1-5-21-3268937493-411182698-2146996859-1008 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Jake')<br />
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')<br />
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O4 - Global Startup: HP Pavilion Webcam Tray Icon.lnk = C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe<br />
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe<br />
O4 - Global Startup: ImageMixer 3 SE Camera Monitor.lnk = ?<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunApp.exe (file missing)<br />
O9 - Extra 'Tools' menuitem: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunApp.exe (file missing)<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: <a href="https://icrontic.com/profile/xpsp3res" rel="nofollow">@xpsp3res</a>.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O14 - IERESET.INF: START_PAGE_URL=<a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=64&amp;bd=pavilion&amp;pf=laptop" rel="nofollow">http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=64&amp;bd=pavilion&amp;pf=laptop</a><br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - <a href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" rel="nofollow">http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab</a><br />
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - <a href="http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-5/myWebFaceInitialSetup1.0.1.3.cab" rel="nofollow">http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-5/myWebFaceInitialSetup1.0.1.3.cab</a><br />
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - <a href="https://meccslb01.wrberkley.com/iNotes6W.cab" rel="nofollow">https://meccslb01.wrberkley.com/iNotes6W.cab</a><br />
O16 - DPF: {427273CC-764E-11D3-823D-006097F90453} (Pixami Image Editor Control) - <a href="http://www.cmphotocenter.com/is/BPImageEditor.cab" rel="nofollow">http://www.cmphotocenter.com/is/BPImageEditor.cab</a><br />
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - <a href="http://ipgweb.cce.hp.com/rdqnbk2/downloads/sysinfo.cab" rel="nofollow">http://ipgweb.cce.hp.com/rdqnbk2/downloads/sysinfo.cab</a><br />
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - <a href="https://webdl.symantec.com/activex/symdlmgr.cab" rel="nofollow">https://webdl.symantec.com/activex/symdlmgr.cab</a><br />
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - <a href="http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab" rel="nofollow">http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" rel="nofollow">http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab</a><br />
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - <a href="https://cardiometabolic.webex.com/client/T27L/webex/ieatgpc.cab" rel="nofollow">https://cardiometabolic.webex.com/client/T27L/webex/ieatgpc.cab</a><br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe<br />
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe<br />
O23 - Service: Basics Service - Seagate Technology LLC - C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe<br />
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe<br />
O23 - Service: FlipShare Service - Unknown owner - C:\Program Files\Flip Video\FlipShare\FlipShareService.exe<br />
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildTangent\Apps\HP Game Console\GameConsoleService.exe<br />
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE<br />
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE<br />
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE<br />
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe<br />
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe<br />
--<br />
End of file - 16977 bytes<br /><br /><br /><br />
Hi,<br /><br />
We have an XP operating system with 4 accounts, one for each of us in our family.  My sons account has the xp internet security virus, but it does not appear to be annoying the rest of us.  He gets balloons in the bottom right of the screen, he gets pop up boxes that talk of trojans and other bad stuff, and when he launches the explorer, he gets rerouted to pages that say he should not go to the websites because they are threats.<br /><br />
Thanks in advance for your help.  You have been a big help in the past.<br /><br />
Cowboy]]>
        </description>
    </item>
    <item>
        <title>I think I have a ghost on my system</title>
        <link>https://icrontic.com/discussion/89649/i-think-i-have-a-ghost-on-my-system</link>
        <pubDate>Tue, 18 May 2010 22:15:10 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>j24jacobs</dc:creator>
        <guid isPermaLink="false">89649@/discussions</guid>
        <description><![CDATA[Hi there,<br />
I have posted twice in the past because of virus/malware/trojans and the like. Both times I was blown away by the level of help I received and would again like to thank you for all of the help. The first time my computer ran better than new after the bad stuff was removed. The last time the virus (or?) was removed my computer still seemed slow. The virus removal went well but it seems like there are programs running that I don't know about. I have tried what little I know to do but have had no luck. I have updated then ran McAfee, Superantispyware, Spybot, Adaware, Malwarebytes, CCleaner, ATF-cleaner and Hijack This. Nothing has seemed to help. The only added program that I know runs on start up is McAfee. I don't use instant messanger or download music or anything like that so I should have no other progragrams running. I just want my computer to run like I know it can again. Can someone please help me discover and fix whatever is going on? Any help would be greatly appreciated. Thank you in advance for your help. You folks really rock.]]>
        </description>
    </item>
    <item>
        <title>Help analyzing logfile</title>
        <link>https://icrontic.com/discussion/89725/help-analyzing-logfile</link>
        <pubDate>Tue, 25 May 2010 21:17:17 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>dtoffey</dc:creator>
        <guid isPermaLink="false">89725@/discussions</guid>
        <description><![CDATA[Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 8:23:08 PM, on 5/25/2010<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v7.00 (7.00.6002.18005)<br />
Boot mode: Normal<br /><br />
Running processes:<br />
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe<br />
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe<br />
C:\hp\support\hpsysdrv.exe<br />
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe<br />
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe<br />
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe<br />
C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe<br />
C:\Program Files (x86)\Java\jre6\bin\jusched.exe<br />
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe<br />
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe<br />
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe<br />
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe<br />
C:\Program Files (x86)\Hewlett-Packard\KBD\kbd.exe<br />
C:\Program Files (x86)\Internet Explorer\ieuser.exe<br />
J:\HijackThis.exe<br /><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=91&amp;bd=bestbuy&amp;pf=cndt" rel="nofollow">http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=91&amp;bd=bestbuy&amp;pf=cndt</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=91&amp;bd=bestbuy&amp;pf=cndt" rel="nofollow">http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=91&amp;bd=bestbuy&amp;pf=cndt</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=91&amp;bd=bestbuy&amp;pf=cndt" rel="nofollow">http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=91&amp;bd=bestbuy&amp;pf=cndt</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll<br />
F2 - REG:system.ini: UserInit=userinit.exe<br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll<br />
O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe<br />
O4 - HKLM\..\Run: [KBD] C:\Program Files (x86)\Hewlett-Packard\KBD\KbdStub.EXE<br />
O4 - HKLM\..\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun<br />
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe<br />
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "c:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"<br />
O4 - HKLM\..\Run: [UpdatePDIRShortCut] "c:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"<br />
O4 - HKLM\..\Run: [UpdatePSTShortCut] "c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Deluxe" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"<br />
O4 - HKLM\..\Run: [TSMAgent] "c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe"<br />
O4 - HKLM\..\Run: [CLMLServer for HP TouchSmart] "c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe"<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe<br />
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"<br />
O4 - HKLM\..\Run: [DVDAgent] "C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe"<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"<br />
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"<br />
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN<br />
O4 - HKCU\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe<br />
O4 - HKCU\..\Run: [cksbbgvl] C:\Users\Bill Toffey\AppData\Local\rwbhqrpmp\cgwbrcutssd.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-18\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'Default user')<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe<br />
O4 - Global Startup: PictureMover.lnk = C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL<br />
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O13 - Gopher Prefix:<br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll<br />
O23 - Service: <a href="https://icrontic.com/profile/%25SystemRoot%25%5Csystem32%5CAlg" rel="nofollow">@%SystemRoot%\system32\Alg</a>.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)<br />
O23 - Service: AMD RAIDXpert (AMD_RAIDXpert) - AMD - C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe<br />
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)<br />
O23 - Service: <a href="https://icrontic.com/profile/dfsrres" rel="nofollow">@dfsrres</a>.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)<br />
O23 - Service: dlbx_device - Unknown owner - C:\Windows\system32\dlbxcoms.exe (file missing)<br />
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe<br />
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe<br />
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe<br />
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe<br />
O23 - Service: <a href="https://icrontic.com/profile/keyiso" rel="nofollow">@keyiso</a>.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: <a href="https://icrontic.com/profile/comres" rel="nofollow">@comres</a>.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)<br />
O23 - Service: <a href="https://icrontic.com/profile/%25SystemRoot%25%5CSystem32%5Cnetlogon" rel="nofollow">@%SystemRoot%\System32\netlogon</a>.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: Norton Internet Security - Unknown owner - C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe (file missing)<br />
O23 - Service: <a href="https://icrontic.com/profile/%25systemroot%25%5Csystem32%5Cpsbase" rel="nofollow">@%systemroot%\system32\psbase</a>.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: <a href="https://icrontic.com/profile/%25systemroot%25%5Csystem32%5CLocator" rel="nofollow">@%systemroot%\system32\Locator</a>.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)<br />
O23 - Service: <a href="https://icrontic.com/profile/%25SystemRoot%25%5Csystem32%5Csamsrv" rel="nofollow">@%SystemRoot%\system32\samsrv</a>.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe<br />
O23 - Service: <a href="https://icrontic.com/profile/%25SystemRoot%25%5Csystem32%5CSLsvc" rel="nofollow">@%SystemRoot%\system32\SLsvc</a>.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)<br />
O23 - Service: <a href="https://icrontic.com/profile/%25SystemRoot%25%5Csystem32%5Csnmptrap" rel="nofollow">@%SystemRoot%\system32\snmptrap</a>.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)<br />
O23 - Service: <a href="https://icrontic.com/profile/%25systemroot%25%5Csystem32%5Cspoolsv" rel="nofollow">@%systemroot%\system32\spoolsv</a>.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)<br />
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe<br />
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe<br />
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe<br />
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe<br />
O23 - Service: <a href="https://icrontic.com/profile/%25SystemRoot%25%5Csystem32%5Cui0detect" rel="nofollow">@%SystemRoot%\system32\ui0detect</a>.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)<br />
O23 - Service: <a href="https://icrontic.com/profile/%25SystemRoot%25%5Csystem32%5Cvds" rel="nofollow">@%SystemRoot%\system32\vds</a>.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)<br />
O23 - Service: <a href="https://icrontic.com/profile/%25systemroot%25%5Csystem32%5Cvssvc" rel="nofollow">@%systemroot%\system32\vssvc</a>.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)<br />
O23 - Service: <a href="https://icrontic.com/profile/%25Systemroot%25%5Csystem32%5Cwbem%5Cwmiapsrv" rel="nofollow">@%Systemroot%\system32\wbem\wmiapsrv</a>.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)<br />
O23 - Service: <a href="https://icrontic.com/profile/%25ProgramFiles%25%5CWindows" rel="nofollow">@%ProgramFiles%\Windows</a> Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)<br /><br />
--<br />
End of file - 11665 bytes]]>
        </description>
    </item>
    <item>
        <title>Please Help - Windows XP doesn't load</title>
        <link>https://icrontic.com/discussion/89542/please-help-windows-xp-doesnt-load</link>
        <pubDate>Sun, 09 May 2010 19:21:07 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>jwat</dc:creator>
        <guid isPermaLink="false">89542@/discussions</guid>
        <description><![CDATA[Hi everyone,<br /><br />
I'm not sure if this is a virus problem, but my Windows XP Professional wouldn't load and I'm not able to provide the Hijack this log.<br /><br />
When I start my computer, everything loads smoothly until after the Windows XP loading bar completes, then I get a black screen with only my mouse pointer.  I've tried loading through Safe Mode and last known configuration and I get the same result.<br /><br />
The problem started when I closed IE with the task manager when my IE stopped responding.  IE closed but my computer was still lagging, so I wanted to log out.  As it logged out, it gave me a black screen with a mouse pointer and the log-in screen never came out.  Since then, I've been getting the same screen when I try to load Windows.<br /><br />
These are the things I've tried but failed:<br />
1. Safe Mode<br />
2. Last known good configuration<br />
3. <a href="http://tech.icrontic.com/articles/repair_windows_xp/" rel="nofollow">http://tech.icrontic.com/articles/repair_windows_xp/</a><br />
4. <a href="http://www.michaelstevenstech.com/XPrepairinstall.htm" rel="nofollow">http://www.michaelstevenstech.com/XPrepairinstall.htm</a><br /><br />
Help would be much appreciated.  Thanks!<br /><br />
-J]]>
        </description>
    </item>
    <item>
        <title>Nexplore pop up virus - help! Hijackthis log attached.</title>
        <link>https://icrontic.com/discussion/87899/nexplore-pop-up-virus-help-hijackthis-log-attached</link>
        <pubDate>Sun, 24 Jan 2010 12:02:43 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator></dc:creator>
        <guid isPermaLink="false">87899@/discussions</guid>
        <description><![CDATA[I have been getting a lot of pop ups about nexplore and a windows defender registry. Below is the log from hijackthis. Please help!! Thanks <img src="https://icrontic.com/resources/icrontimoji/smile.gif" title=":)" alt=":)" /><br /><br />
Logfile of Trend Micro HijackThis v2.0.3 (BETA)<br />
Scan saved at 11:57:59 AM, on 1/24/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br /><br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\windows\system\hpsysdrv.exe<br />
C:\HP\KBD\KBD.EXE<br />
C:\WINDOWS\system32\VTTimer.exe<br />
C:\WINDOWS\AGRSMMSG.exe<br />
C:\WINDOWS\ALCXMNTR.EXE<br />
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\HP\HP Software Update\HPWuSchd.exe<br />
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\QuickTime\QTTask.exe<br />
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Program Files\Trend Micro\BM\TMBMSRV.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\WINDOWS\system32\HPZipm12.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\HP\hpcoretech\comp\hpdarc.exe<br />
C:\WINDOWS\System32\msiexec.exe<br />
C:\Program Files\Trend Micro\TrendMicro\HiJackThis\HiJackThis.exe<br /><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=Q304&amp;bd=presario&amp;pf=desktop" rel="nofollow">http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=Q304&amp;bd=presario&amp;pf=desktop</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="https://205.232.252.20/exchange/" rel="nofollow">https://205.232.252.20/exchange/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iesearch&amp;locale=EN_US&amp;c=Q304&amp;bd=presario&amp;pf=desktop" rel="nofollow">http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iesearch&amp;locale=EN_US&amp;c=Q304&amp;bd=presario&amp;pf=desktop</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =<br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = <a href="http://java.com/en/download/help/index.xml" rel="nofollow">http://java.com/en/download/help/index.xml</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local<br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)<br />
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe<br />
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE<br />
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe<br />
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe<br />
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE<br />
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br />
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"<br />
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"<br />
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br />
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br />
O4 - HKLM\..\Run: [fazirowak] Rundll32.exe "c:\windows\system32\wirubifa.dll",a<br />
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe<br />
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin\core.hp.main\SendTo.html<br />
O8 - Extra context menu item: Add to Google Photos Screensa&amp;ver - res://C:\WINDOWS\system32\GPhotos.scr/200<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: <a href="https://icrontic.com/profile/xpsp3res" rel="nofollow">@xpsp3res</a>.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1247059506125" rel="nofollow">http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1247059506125</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab" rel="nofollow">http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab</a><br />
O20 - AppInit_DLLs: bopufeto.dll c:\windows\system32\wirubifa.dll<br />
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL<br />
O21 - SSODL: yovijubeg - {589336f9-563f-47c6-8a66-a50472384616} - c:\windows\system32\wirubifa.dll<br />
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll<br />
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll<br />
O22 - SharedTaskScheduler: jugezatag - {589336f9-563f-47c6-8a66-a50472384616} - c:\windows\system32\wirubifa.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe<br />
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe<br />
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe<br /><br />
--<br />
End of file - 7902 bytes]]>
        </description>
    </item>
    <item>
        <title>Malware infection ?</title>
        <link>https://icrontic.com/discussion/89677/malware-infection</link>
        <pubDate>Fri, 21 May 2010 03:02:31 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>-Flames</dc:creator>
        <guid isPermaLink="false">89677@/discussions</guid>
        <description><![CDATA[When i boot my pc up , after the desktop appears it takes a long time for the pc to be actually "active" ( about 20 mins ) and i get a message from avast! scanner saying " a rootkit has been found " with the following details :<br />
C:\WINDOWS\System32\Drivers\bsyxult.sys<br />
hidden services<br />
Win32:Rootkit-gen [Rtk].<br /><br />
My on access antivirus is avast! . and i have scanned with a lot of others like malware bytes , ad aware , spybot .. they find infected files yet they fail to fix the problem .<br />
Anyway heres my HJK log :<br /><br /><br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 10:01:10 Øµ, on 21/05/2010<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16705)<br />
Boot mode: Normal<br /><br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br />
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device<br /><br />
Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\ICQ6Toolbar\ICQ Service.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\Microsoft<br /><br />
Shared\VS7DEBUG\MDM.EXE<br />
C:\WINDOWS\system32\PnkBstrA.exe<br />
C:\WINDOWS\system32\PnkBstrB.exe<br />
C:\Program Files\CyberLink\Shared files\RichVideo.exe<br />
D:\Proshow\ScsiAccess.exe<br />
C:\Program Files\Microsoft\Search Enhancement<br /><br />
Pack\SeaPort\SeaPort.exe<br />
C:\Program Files\Microsoft SQL Server\90<br /><br />
\Shared\sqlwriter.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe<br />
D:\Program Files\Nokia\Nokia PC Suite 6<br /><br />
\LaunchApplication.exe<br />
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
C:\Program Files\WebMoney Agent\wmagent.exe<br />
D:\Program Files\Converter\mon.exe<br />
C:\Program Files\Common<br /><br />
Files\Real\Update_OB\realsched.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\PC Connectivity<br /><br />
Solution\ServiceLayer.exe<br />
D:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\WINDOWS\system32\igfxsrvc.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\WINDOWS\TEMP\714f47fe.tmp<br />
C:\WINDOWS\system32\NOTEPAD.EXE<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br /><br />
R0 - HKCU\Software\Microsoft\Internet<br /><br />
Explorer\Main,Start Page = <a href="http://search.conduit.com?" rel="nofollow">http://search.conduit.com?</a><br /><br />
SearchSource=10&amp;ctid=CT2233703<br />
R1 - HKLM\Software\Microsoft\Internet<br /><br />
Explorer\Main,Default_Page_URL =<br /><br /><a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet<br /><br />
Explorer\Main,Default_Search_URL =<br /><br /><a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet<br /><br />
Explorer\Main,Search Page =<br /><br /><a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet<br /><br />
Explorer\Main,Start Page =<br /><br /><a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 -<br /><br />
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet<br /><br />
Settings,ProxyOverride = local;*.local<br />
R3 - URLSearchHook: AIM Toolbar Search Class -<br /><br />
{03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program<br /><br />
Files\AIM Toolbar\aimtb.dll<br />
R3 - URLSearchHook: (no name) -  - (no file)<br />
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-<br /><br />
8A56-BBB695989046} - C:\Program<br /><br />
Files\ICQ6Toolbar\ICQToolBar.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-<br /><br />
FA578C2EBDC3} - C:\Program Files\Common<br /><br />
Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: RealPlayer Download and Record Plugin for<br /><br />
Internet Explorer - {3049C3E9-B461-4BC5-8870-<br /><br />
4C09146192CA} - C:\Program<br /><br />
Files\Real\RealPlayer\rpbrowserrecordplugin.dll<br />
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-<br /><br />
47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-<br /><br />
WebPrint EX\ewpexbho.dll<br />
O2 - BHO: Windows Live Family Safety Browser Helper -<br /><br />
{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program<br /><br />
Files\Windows Live\Family Safety\fssbho.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-<br /><br />
2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1<br /><br />
\SDHelper.dll<br />
O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-<br /><br />
90988571CECB} - C:\Program Files\Windows<br /><br />
Live\Messenger\wlchtc.dll<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-<br /><br />
B9E3AAC4465B} - C:\Program Files\Microsoft\Search<br /><br />
Enhancement Pack\Search Helper\SearchHelper.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-<br /><br />
4ABF-8ECC-5164760863C6} - C:\Program Files\Common<br /><br />
Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-<br /><br />
4638-B6FA-CE66B5AD205D} - C:\Program<br /><br />
Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll<br />
O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174<br /><br />
-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-<br /><br />
A445-435b-BC74-9C25C1C588A9} - C:\Program<br /><br />
Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-<br /><br />
42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows<br /><br />
Live\Toolbar\wltcore.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-<br /><br />
BC86-EABFE594F69C} - C:\Program Files\Java\jre6<br /><br />
\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-<br /><br />
BBB695989046} - C:\Program<br /><br />
Files\ICQ6Toolbar\ICQToolBar.dll<br />
O3 - Toolbar: &amp;Windows Live Toolbar - {21FA44EF-376D-<br /><br />
4D53-9B0F-8A89D3229068} - C:\Program Files\Windows<br /><br />
Live\Toolbar\wltcore.dll<br />
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-<br /><br />
4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools<br /><br />
Toolbar\DTToolbar.dll<br />
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-<br /><br />
9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll<br />
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-<br /><br />
4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-<br /><br />
WebPrint EX\ewpexhlp.dll<br />
O4 - HKLM\..\Run: [RemoteControl] "C:\Program<br /><br />
Files\CyberLink\PowerDVD\PDVDServ.exe"<br />
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program<br /><br />
Files\CyberLink\PowerDVD\Language\Language.exe"<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32<br /><br />
\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32<br /><br />
\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32<br /><br />
\igfxpers.exe<br />
O4 - HKLM\..\Run: [PCSuiteTrayApplication] D:\Program<br /><br />
Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -<br /><br />
startup<br />
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4<br /><br />
\ashDisp.exe<br />
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common<br /><br />
Files\InstallShield\UpdateService\isuspm.exe" -scheduler<br />
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows<br /><br />
Live\Family Safety\fsui.exe" -autorun<br />
O4 - HKLM\..\Run: [wmagent.exe] "C:\Program<br /><br />
Files\WebMoney Agent\wmagent.exe"<br />
O4 - HKLM\..\Run: [redtubeconverter] D:\Program<br /><br />
Files\Converter\mon.exe<br />
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common<br /><br />
Files\Real\Update_OB\realsched.exe"  -osboot<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program<br /><br />
Files\Java\jre6\bin\jusched.exe<br />
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA<br /><br />
Corporation\nView\nwiz.exe /install<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE<br /><br />
C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE<br /><br />
C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program<br /><br />
Files\QuickTime\QTTask.exe" -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program<br /><br />
Files\iTunes\iTunesHelper.exe"<br />
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program<br /><br />
Files\Canon\MyPrinter\BJMyPrt.exe /logon<br />
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program<br /><br />
Files\Canon\SolutionMenu\CNSLMAIN.exe /logon<br />
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program<br /><br />
Files\Common<br /><br />
Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -<br /><br />
launchedbylogin<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher]<br /><br />
"C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"<br />
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common<br /><br />
Files\Adobe\ARM\1.0\AdobeARM.exe"<br />
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%<br /><br />
\system32\dumprep 0 -u<br />
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32<br /><br />
\ctfmon.exe<br />
O4 - HKCU\..\Run: [cdoosoft] C:\DOCUME~1\user\LOCALS~1<br /><br />
\Temp\herss.exe<br />
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows<br /><br />
Live\Messenger\msnmsgr.exe" /background<br />
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE]<br /><br />
C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE]<br /><br />
C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE]<br /><br />
C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE]<br /><br />
C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')<br />
O8 - Extra context menu item: &amp;Download All using<br /><br />
4shared Desktop - C:\Program Files\4shared<br /><br />
Desktop\down_all.htm<br />
O8 - Extra context menu item: &amp;Search - ?p=ZUfox000<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel<br /><br />
- res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7<br /><br />
-D9FCDDC9D600} - C:\Program Files\Windows<br /><br />
Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live<br /><br />
Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} -<br /><br />
C:\Program Files\Windows<br /><br />
Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-<br /><br />
B7E7-B6E1F053A9E7} - C:\Program<br /><br />
Files\EmpirePokerMaster\EmpirePoker\RunEPoker.exe (file<br /><br />
missing)<br />
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-<br /><br />
4284-41d6-B7E7-B6E1F053A9E7} - C:\Program<br /><br />
Files\EmpirePokerMaster\EmpirePoker\RunEPoker.exe (file<br /><br />
missing)<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-<br /><br />
3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11<br /><br />
\REFIEBAR.DLL<br />
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1<br /><br />
-9C6B-12A255F085E1} - C:\Program<br /><br />
Files\PartyGaming\PartyPoker\RunApp.exe (file missing)<br />
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70<br /><br />
-9AA2-40F1-9C6B-12A255F085E1} - C:\Program<br /><br />
Files\PartyGaming\PartyPoker\RunApp.exe (file missing)<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200<br /><br />
-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy<br /><br />
Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -<br /><br />
C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-<br /><br />
FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe<br />
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851<br /><br />
-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E<br /><br />
-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br /><br />
(file missing)<br />
O9 - Extra 'Tools' menuitem: Windows Messenger -<br /><br />
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program<br /><br />
Files\Messenger\msmsgs.exe (file missing)<br />
O9 - Extra button: 32Red Poker Room - {00000000-0000-<br /><br />
0000-0000-000000000000} -<br /><br />
C:\MicroGaming\Poker\32RedMPP\MPPoker.exe (file missing)<br /><br />
(HKCU)<br />
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c<br /><br />
-91F6-8C13714ED485} - C:\Documents and<br /><br />
Settings\user\Start Menu\Programs\Absolute<br /><br />
Poker\Absolute Poker.lnk (file missing) (HKCU)<br />
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6<br /><br />
-7535-495c-91F6-8C13714ED485} - C:\Documents and<br /><br />
Settings\user\Start Menu\Programs\Absolute<br /><br />
Poker\Absolute Poker.lnk (file missing) (HKCU)<br />
O17 - HKLM\System\CCS\Services\Tcpip\..\{C8C48ED6-C929-<br /><br />
421C-87C7-27D8A99B2733}: NameServer = 196.27.0.35<br /><br />
196.27.0.230<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-<br /><br />
1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O23 - Service: Lavasoft Ad-Aware Service (aawservice) -<br /><br />
Lavasoft - C:\Program Files\Lavasoft\Ad-<br /><br />
Aware\aawservice.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. -<br /><br />
C:\Program Files\Common Files\Apple\Mobile Device<br /><br />
Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) -<br /><br />
ALWIL Software - C:\Program Files\Alwil Software\Avast4<br /><br />
\aswUpdSv.exe<br />
O23 - Service: avast! Antivirus - ALWIL Software -<br /><br />
C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
O23 - Service: avast! Mail Scanner - ALWIL Software -<br /><br />
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
O23 - Service: avast! Web Scanner - ALWIL Software -<br /><br />
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program<br /><br />
Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: FLEXnet Licensing Service - Acresso<br /><br />
Software Inc. - C:\Program Files\Common<br /><br />
Files\Macrovision Shared\FLEXnet<br /><br />
Publisher\FNPLicensingService.exe<br />
O23 - Service: Ø®Ø¯Ù…Ø© ØªØ­Ø¯ÙŠØ« Google (gupdate1ca2d674c9a654e)<br /><br />
(gupdate1ca2d674c9a654e) - Google Inc. - C:\Program<br /><br />
Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google<br /><br />
- C:\Program Files\Google\Common\Google<br /><br />
Updater\GoogleUpdaterService.exe<br />
O23 - Service: ICQ Service - Unknown owner - C:\Program<br /><br />
Files\ICQ6Toolbar\ICQ Service.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) -<br /><br />
Macrovision Corporation - C:\Program Files\Common<br /><br />
Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program<br /><br />
Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter<br /><br />
(JavaQuickStarterService) - Sun Microsystems, Inc. -<br /><br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Macromedia Licensing Service - Unknown<br /><br />
owner - C:\Program Files\Common Files\Macromedia<br /><br />
Shared\Service\Macromedia Licensing.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) -<br /><br />
NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: PnkBstrA - Unknown owner -<br /><br />
C:\WINDOWS\system32\PnkBstrA.exe<br />
O23 - Service: PnkBstrB - Unknown owner -<br /><br />
C:\WINDOWS\system32\PnkBstrB.exe<br />
O23 - Service: Cyberlink RichVideo Service(CRVS)<br /><br />
(RichVideo) - Unknown owner - C:\Program<br /><br />
Files\CyberLink\Shared files\RichVideo.exe<br />
O23 - Service: ScsiAccess - Unknown owner -<br /><br />
D:\Proshow\ScsiAccess.exe<br />
O23 - Service: ServiceLayer - Nokia. - C:\Program<br /><br />
Files\PC Connectivity Solution\ServiceLayer.exe<br /><br />
--<br />
End of file - 13607 bytes]]>
        </description>
    </item>
    <item>
        <title>Possible Spyware/Virus</title>
        <link>https://icrontic.com/discussion/89664/possible-spyware-virus</link>
        <pubDate>Wed, 19 May 2010 18:20:31 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>sap1622</dc:creator>
        <guid isPermaLink="false">89664@/discussions</guid>
        <description><![CDATA[hi I recently accidently opened a website which contained a virus or somthing of that nature. I need some help to get rid of it! thanks!!!]]>
        </description>
    </item>
    <item>
        <title>Windows XP Slow and cant run AdAware</title>
        <link>https://icrontic.com/discussion/89623/windows-xp-slow-and-cant-run-adaware</link>
        <pubDate>Sun, 16 May 2010 14:48:34 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>yossarian084</dc:creator>
        <guid isPermaLink="false">89623@/discussions</guid>
        <description><![CDATA[Log file follows:  See anything strange?<br /><br />
Logfile of HijackThis v1.99.1<br />
Scan saved at 2:46:49 PM, on 5/16/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.17023)<br /><br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Google\Update\1.2.183.23\GoogleCrashHandler.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe<br />
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe<br />
C:\Program Files\DropBox\DropBox\DropBox.exe<br />
C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
C:\Program Files\Fisher-Price\Computer Cool School\FPCCSMiddleware.exe<br />
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe<br />
C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Eraser\eraser.exe<br />
C:\Garmin\ANT Agent\ANT Agent.exe<br />
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Java\jre1.5.0_09\bin\jucheck.exe<br />
C:\Documents and Settings\Home Desktop\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\Home Desktop\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\Home Desktop\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
D:\Program Files\HijackThis.exe<br /><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun<br />
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"<br />
O4 - HKLM\..\Run: [DigidesignMMERefresh] E:\Digidesign\Drivers\MMERefresh.exe<br />
O4 - HKLM\..\Run: [C:\WINDOWS\system32\V0250Cvw.dll] C:\WINDOWS\system32\RegSvr32.exe /s C:\WINDOWS\system32\V0250Cvw.dll<br />
O4 - HKLM\..\Run: [DropBoxUtility] "C:\Program Files\DropBox\DropBox\DropBox.exe" /s<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKLM\..\Run: [FPCCSMiddleware] C:\Program Files\Fisher-Price\Computer Cool School\FPCCSMiddleware.exe<br />
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide<br />
O4 - HKLM\..\Run: [Monitor] "C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe"<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"<br />
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide<br />
O4 - HKCU\..\Run: [ANT Agent] C:\Garmin\ANT Agent\ANT Agent.exe<br />
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Home Desktop\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c<br />
O8 - Extra context menu item: Add to Google Photos Screensa&amp;ver - res://C:\WINDOWS\system32\GPhotos.scr/200<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll<br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" rel="nofollow">http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab</a><br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll<br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL<br />
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)<br />
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Unknown owner - E:\Digidesign\Drivers\MMERefresh.exe (file missing)<br />
O23 - Service: Google Update Service (gupdate1ca0b15c3470c34) (gupdate1ca0b15c3470c34) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe" /svc (file missing)<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)<br />
O23 - Service: LeapFrog Connect Device Service - LeapFrog Enterprises, Inc. - C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe<br />
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe<br /><br />
What can I safely kill?]]>
        </description>
    </item>
    <item>
        <title>Search results being redirected in IE/FF with yahoo &amp; google &amp; bing &amp; ask &amp; others.</title>
        <link>https://icrontic.com/discussion/89626/search-results-being-redirected-in-ie-ff-with-yahoo-google-bing-ask-others</link>
        <pubDate>Sun, 16 May 2010 23:25:02 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>allstar</dc:creator>
        <guid isPermaLink="false">89626@/discussions</guid>
        <description><![CDATA[My search results are being redirected to malware sites.  I have tried a  lot of different virus, malware, etc scanners to fix this issue.   Malwarebytes, Spybot, avast, superantispyware, avira, using boot disk to  run avg in linux, and also running a few anti malware/spyware on the  partion from a live linux cd and the problem is still around.  It has  only started for the last 3 days.  I did not install any software in  that time.  A system restore didn't work it still did it.  I also tried  to clear out the system restore data and then run everything and it  still does it.<br /><br />
Here are the small list of the sites it is  redirecting to and using javascript to load results on  alltheservices.com.<br />
bjfr.com<br />
solarzones.com<br />
synqstartup.com<br />
wattosjunkyard.com<br />
cl1i1lc1ilk.com<br />
alltheservices.com<br /><br />
=======<br /><br />
When I try to post the hijack.log it makes the connection not connect.  I am going to reboot into linux and try to repost it in a bit.  Search results being redirected in IE/FF with yahoo &amp; google &amp; bing &amp; ask &amp; others.  Logfile of Trend Micro HijackThis v2.0.4<br />
Scan saved at 10:07:11 PM, on 5/16/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
C:\Program Files\DU Meter\DUMeterSvc.exe<br />
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe<br />
C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\WINDOWS\system32\lxcgcoms.exe<br />
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\notepad.exe<br />
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe<br />
C:\WINDOWS\system32\msiexec.exe<br />
C:\Documents and Settings\Cyndi\Application Data\CBS Interactive\CNET TechTracker\TechTracker.exe<br /><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.yahoo.com/" rel="nofollow">http://www.yahoo.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"<br />
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent<br />
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe<br />
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')<br />
O4 - Global Startup: Bluetooth.lnk = ?<br />
O8 - Extra context menu item: Send to &amp;Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm<br />
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra button: <a href="https://icrontic.com/profile/btrez" rel="nofollow">@btrez</a>.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra 'Tools' menuitem: <a href="https://icrontic.com/profile/btrez" rel="nofollow">@btrez</a>.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: <a href="https://icrontic.com/profile/xpsp3res" rel="nofollow">@xpsp3res</a>.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: Justin.tv Publisher - <a href="http://www.justin.tv/plugins/justintv_publisher.CAB" rel="nofollow">http://www.justin.tv/plugins/justintv_publisher.CAB</a><br />
O16 - DPF: {3188FB46-456D-4C07-8A11-F5F3BBBA8AF2} (SeeTooControl Class) - <a href="http://www.seetoo.com/downloadAddon.php?platform=Win32&amp;browser=ie&amp;ref=justintv&amp;c=c97a3668363012046&amp;browserVersion=8.0" rel="nofollow">http://www.seetoo.com/downloadAddon.php?platform=Win32&amp;browser=ie&amp;ref=justintv&amp;c=c97a3668363012046&amp;browserVersion=8.0</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1250465939015" rel="nofollow">http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1250465939015</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1250550630390" rel="nofollow">http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1250550630390</a><br />
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - <a href="http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab" rel="nofollow">http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab</a><br />
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} (MySpace Uploader Control) - <a href="http://lads.myspace.com/upload/MySpaceUploader2.cab" rel="nofollow">http://lads.myspace.com/upload/MySpaceUploader2.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" rel="nofollow">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll<br />
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll<br />
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll<br />
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe<br />
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe<br />
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe<br />
O23 - Service: DU Meter Service (DUMeterSvc) - Hagel Technologies Ltd. - C:\Program Files\DU Meter\DUMeterSvc.exe<br />
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: lxcg_device -   - C:\WINDOWS\system32\lxcgcoms.exe<br />
O23 - Service: MediaMall Server - MediaMall Technologies, Inc. - C:\Program Files\MediaMall\MediaMallServer.exe<br /><br />
--<br />
End of file - 7018 bytes]]>
        </description>
    </item>
    <item>
        <title>some major problems</title>
        <link>https://icrontic.com/discussion/89597/some-major-problems</link>
        <pubDate>Thu, 13 May 2010 17:44:32 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>sodabone</dc:creator>
        <guid isPermaLink="false">89597@/discussions</guid>
        <description><![CDATA[hi<br /><br />
my noob friend is having problems with his comp.<br /><br />
The comp in question works fine in safe mode but will not go past the welcome screen in normal mode. I did a scan in safe mode with malware bytes and it found 50 malicous objects which I deleted. I then tried to restart the comp in normal mode but again it wouldnt get past the welcome screen - constantly loading after I put in the login details.<br /><br />
I then did a hijackthis scan in safe mode and then entered the log file into <a href="www.hijackthis.de" rel="nofollow">www.hijackthis.de</a> and deleted the entries it told me to delete - but im still having the same problems.<br /><br />
Did another scan with malwarebytes and there wasnt any malicious items found.<br /><br />
I tried to do a fresh reformat but the comp will not boot windows from a disk, it just freezes?!?<br /><br />
Anyway dds scan files<br /><br /><br /><br /><br />
DDS (Ver_10-03-17.01) - NTFSx86 NETWORK<br />
Run by john does at 23:40:50.37 on 11/05/2010<br />
Internet Explorer: 7.0.6000.17037 BrowserJavaVersion: 1.6.0_19<br />
MicrosoftÂ® Windows Vistaâ„¢ Home Basic 6.0.6000.0.1252.44.1033.18.1013.387 [GMT 1:00]<br /><br />
AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}<br />
SP: Microsoft Security Essentials *disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDE}<br />
SP: AVG Anti-Spyware *disabled* (Outdated) {48F2E28D-ED66-4646-9C11-B3055B0AF604}<br />
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}<br />
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}<br /><br />
============== Running Processes ===============<br /><br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\svchost.exe -k rpcss<br />
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\helppane.exe<br />
C:\Users\john does\AppData\Local\Google\Chrome\Application\chrom e.exe<br />
C:\Users\john does\AppData\Local\Google\Chrome\Application\chrom e.exe<br />
C:\Users\john does\AppData\Local\Google\Chrome\Application\chrom e.exe<br />
C:\Users\john does\AppData\Local\Google\Chrome\Application\chrom e.exe<br />
C:\Users\john does\AppData\Local\Google\Chrome\Application\chrom e.exe<br />
C:\Users\john does\Documents\Downloads\dds.scr<br />
C:\Windows\system32\wbem\wmiprvse.exe<br /><br />
============== Pseudo HJT Report ===============<br /><br />
uWindow Title = Internet Explorer provided by Dell<br />
uStart Page = hxxp://www.google.co.uk/<br />
uDefault_Page_URL = hxxp://www.google.co.uk/ig/dell?hl=en&amp;client=dell-usuk&amp;channel=uk&amp;ibd=4080112<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll<br />
BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\program files\bitcomet\tools\BitCometBHO_1.2.1.2.dll<br />
BHO: Windows Live OneCare Family Safety Browser Helper Class: {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - c:\program files\windows live\family safety\fssbho.dll<br />
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll<br />
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll<br />
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\s wg.dll<br />
BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll<br />
BHO: 1 (0x1) - No File<br />
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll<br />
TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll<br />
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll<br />
TB: SweetIM For Internet Explorer: {bc4ffe41-de9f-46fa-b455-aad49b9f9938} - c:\program files\macrogaming\sweetimbarforie\toolbar.dll<br />
uRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background<br />
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter<br />
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe<br />
uRun: [Steam] "c:\program files\steam\Steam.exe" -silent<br />
uRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start<br />
uRun: [Google Update] "c:\users\john does\appdata\local\google\update\GoogleUpdate.exe" /c<br />
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe<br />
mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe<br />
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe<br />
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe<br />
mRun: [Persistence] c:\windows\system32\igfxpers.exe<br />
mRun: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe<br />
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe<br />
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start<br />
mRun: [&lt;NO NAME&gt;]<br />
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"<br />
mRun: [Unattend0000000001{FD63CC11-BC30-475A-9CC2-BC5D72177EA5}] c:\dell\cfi\RunGo.lnk<br />
mRun: [4oD] "c:\program files\kontiki\KHost.exe" -all<br />
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter<br />
mRun: [MSConfig] "c:\windows\system32\msconfig.exe" /auto<br />
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey<br />
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript<br />
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent<br />
dRun: [PcSync] c:\program files\nokia\nokia pc suite 6\PcSync2.exe /NoDialog<br />
StartupFolder: c:\users\john does\appdata\roaming\micros~1\windows\startm~1\pro grams\startup\sonici~1.lnk - c:\users\john does\appdata\local\temp\vies2f6a\Setup.EXE<br />
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\sta rtup\digita~1.lnk - c:\program files\digital line detect\DLG.exe<br />
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\sta rtup\quickset.lnk - c:\windows\installer\{7f0c4457-8e64-491b-8d7b-991504365d1e}\NewShortcut2_53A01CC614B04512A2E710D 39BF83DC4.exe<br />
IE: &amp;D&amp;ownload &amp;with BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm<br />
IE: &amp;D&amp;ownload all video with BitComet - c:\program files\bitcomet\BitComet.exe/AddVideo.htm<br />
IE: &amp;D&amp;ownload all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm<br />
IE: &amp;Search<br />
IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://c:\program files\bitcomet\tools\BitCometBHO_1.2.1.2.dll/206<br />
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll<br />
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll<br />
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL<br />
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader5.cab<br />
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w2/resources/VistaMSNPUplden-gb.cab<br />
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab<br />
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab<br />
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab<br />
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab<br />
Notify: igfxcui - igfxdev.dll<br />
AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL<br /><br />
================= FIREFOX ===================<br /><br />
FF - ProfilePath - c:\users\john does\appdata\roaming\mozilla\firefox\profiles\15jd 2lcy.default\<br />
FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll<br />
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}<br /><br />
---- FIREFOX POLICIES ----<br />
FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\all.js - pref("ui.allow_platform_file_picker", true);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom<br />
c:\program files\mozilla firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery<br />
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");<br />
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");<br />
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("signon.prefillForms", true);<br />
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.remoteLookups", false);<br />
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.updateURL", "<a href="http://sb.google.com/safebrowsing/update?client={moz:client}&amp;appver={moz:version}&amp;&quot;)" rel="nofollow">http://sb.google.com/safebrowsing/update?client={moz:client}&amp;appver={moz:version}&amp;")</a> ;<br />
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.lookupURL", "<a href="http://sb.google.com/safebrowsing/lookup?sourceid=firefox-antiphish&amp;features=TrustRank&amp;client={moz:client}&amp;a" rel="nofollow">http://sb.google.com/safebrowsing/lookup?sourceid=firefox-antiphish&amp;features=TrustRank&amp;client={moz:client}&amp;a</a> ppver={moz:version}&amp;");<br />
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.reportURL", "<a href="http://sb.google.com/safebrowsing/report?&quot;)" rel="nofollow">http://sb.google.com/safebrowsing/report?")</a>;<br /><br />
============= SERVICES / DRIVERS ===============<br /><br />
S1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-12-2 149040]<br />
S2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2008-1-11 73728]<br />
S2 fssfltr;FssFltr;c:\windows\system32\drivers\fssflt r.sys [2008-1-27 43816]<br />
S2 fsssvc;Windows Live OneCare Family Safety;c:\program files\windows live\family safety\fsssvc.exe [2007-12-17 523816]<br />
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-3-28 135664]<br />
S2 TeamViewer5;TeamViewer 5;c:\program files\teamviewer\version5\TeamViewer_Service.exe [2010-4-16 173352]<br />
S2 VMCService;Vodafone Mobile Connect Service;c:\program files\vodafone\vodafone mobile connect\bin\VMCService.exe [2008-10-9 14336]<br />
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-1-11 30192]<br />
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2009-12-2 42368]<br /><br />
=============== Created Last 30 ================<br /><br />
2010-05-11 20:57:10	0	d
<hr />
w-	c:\program files\Trend Micro<br />
2010-05-11 20:48:48	0	d
<hr />
w-	c:\program files\TeamViewer<br />
2010-05-10 20:31:24	0	d
<hr />
w-	c:\program files\common files\Wise Installation Wizard<br />
2010-05-10 20:09:01	0	d
<hr />
w-	c:\users\john does\appdata\roaming\Malwarebytes<br />
2010-05-10 20:08:56	38224	----a-w-	c:\windows\system32\drivers\mbamswissarmy.sys<br />
2010-05-10 20:08:55	20952	----a-w-	c:\windows\system32\drivers\mbam.sys<br />
2010-05-10 20:08:55	0	d
<hr />
w-	c:\programdata\Malwarebytes<br />
2010-05-10 20:08:55	0	d
<hr />
w-	c:\program files\Malwarebytes' Anti-Malware<br />
2010-05-09 16:51:46	0	d
<hr />
w-	c:\program files\Microsoft Security Essentials<br />
2010-05-09 16:25:23	2	----a-w-	c:\windows\msoffice.ini<br />
2010-05-09 16:02:24	0	d
<hr />
w-	c:\program files\VS Revo Group<br />
2010-04-30 15:37:07	453456	----a-w-	c:\windows\system32\d3dx10_41.dll<br />
2010-04-30 15:37:07	1846632	----a-w-	c:\windows\system32\D3DCompiler_41.dll<br />
2010-04-30 15:37:01	4178264	----a-w-	c:\windows\system32\D3DX9_41.dll<br />
2010-04-30 15:37:00	69448	----a-w-	c:\windows\system32\XAPOFX1_3.dll<br />
2010-04-30 15:37:00	517448	----a-w-	c:\windows\system32\XAudio2_4.dll<br />
2010-04-23 20:28:32	0	d
<hr />
w-	c:\users\john does\Office Genuine Advantage<br />
2010-04-14 11:15:19	3502480	----a-w-	c:\windows\system32\ntkrnlpa.exe<br />
2010-04-14 11:15:19	3468168	----a-w-	c:\windows\system32\ntoskrnl.exe<br />
2010-04-14 11:15:09	58368	----a-w-	c:\windows\system32\drivers\mrxsmb20.sys<br />
2010-04-14 11:15:08	211968	----a-w-	c:\windows\system32\drivers\mrxsmb10.sys<br />
2010-04-14 11:15:08	102400	----a-w-	c:\windows\system32\drivers\mrxsmb.sys<br />
2010-04-14 11:12:23	171520	----a-w-	c:\windows\system32\wintrust.dll<br />
2010-04-14 11:11:35	97792	----a-w-	c:\windows\system32\cabview.dll<br /><br />
==================== Find3M ====================<br /><br />
2010-05-11 21:13:01	335	---ha-w-	c:\windows\system32\drivers\vsconfig.xml<br />
2010-05-06 09:36:38	221568
<hr />
w-	c:\windows\system32\MpSigStub.exe<br />
2010-04-01 16:11:55	411368	----a-w-	c:\windows\system32\deploytk.dll<br />
2010-03-09 16:54:49	832512	----a-w-	c:\windows\system32\wininet.dll<br />
2010-03-09 16:50:34	56320	----a-w-	c:\windows\system32\iesetup.dll<br />
2010-03-09 16:50:25	78336	----a-w-	c:\windows\system32\ieencode.dll<br />
2010-03-09 16:48:34	72704	----a-w-	c:\windows\system32\admparse.dll<br />
2010-03-09 14:17:48	26624	----a-w-	c:\windows\system32\ieUnatt.exe<br />
2010-03-09 12:43:52	48128	----a-w-	c:\windows\system32\mshtmler.dll<br />
2010-03-04 19:24:26	434176	----a-w-	c:\windows\system32\vbscript.dll<br />
2010-02-18 14:19:34	179712	----a-w-	c:\windows\system32\iphlpsvc.dll<br />
2010-02-18 14:01:48	167424	----a-w-	c:\windows\system32\tcpipcfg.dll<br />
2010-02-18 13:56:56	416768	----a-w-	c:\windows\system32\IKEEXT.DLL<br />
2010-02-18 13:56:27	543232	----a-w-	c:\windows\system32\FWPUCLNT.DLL<br />
2010-02-18 13:55:43	317440	----a-w-	c:\windows\system32\BFE.DLL<br />
2010-02-18 11:51:11	22016	----a-w-	c:\windows\system32\netiougc.exe<br />
2010-02-12 10:49:08	293376	----a-w-	c:\windows\system32\browserchoice.exe<br />
2009-07-13 19:33:48	51200	----a-w-	c:\windows\inf\infpub.dat<br />
2009-07-13 19:33:47	86016	----a-w-	c:\windows\inf\infstor.dat<br />
2009-07-13 19:33:46	143360	----a-w-	c:\windows\inf\infstrng.dat<br />
2008-12-10 16:45:40	174	--sha-w-	c:\program files\desktop.ini<br />
2008-06-13 05:58:34	665600	----a-w-	c:\windows\inf\drvindex.dat<br />
2006-11-02 12:39:34	30674	----a-w-	c:\windows\inf\perflib\0409\perfd.dat<br />
2006-11-02 12:39:34	30674	----a-w-	c:\windows\inf\perflib\0409\perfc.dat<br />
2006-11-02 12:39:34	287440	----a-w-	c:\windows\inf\perflib\0409\perfi.dat<br />
2006-11-02 12:39:34	287440	----a-w-	c:\windows\inf\perflib\0409\perfh.dat<br />
2006-11-02 09:20:21	287440	----a-w-	c:\windows\inf\perflib\0000\perfi.dat<br />
2006-11-02 09:20:21	287440	----a-w-	c:\windows\inf\perflib\0000\perfh.dat<br />
2006-11-02 09:20:19	30674	----a-w-	c:\windows\inf\perflib\0000\perfd.dat<br />
2006-11-02 09:20:19	30674	----a-w-	c:\windows\inf\perflib\0000\perfc.dat<br />
2008-01-26 13:16:43	16384	--sha-w-	c:\windows\temp\cookies\index.dat<br />
2008-01-26 13:16:43	16384	--sha-w-	c:\windows\temp\history\history.ie5\index.dat<br />
2008-01-26 13:16:43	32768	--sha-w-	c:\windows\temp\temporary internet files\content.ie5\index.dat<br />
2008-01-12 00:55:53	8192	--sha-w-	c:\windows\users\default\NTUSER.DAT<br /><br />
============= FINISH: 23:42:52.83 ===============<br /><br /><br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 23:56:00, on 11/05/2010<br />
Platform: Windows Vista (WinNT 6.00.1904)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.17037)<br />
Boot mode: Safe mode with network support<br /><br />
Running processes:<br />
C:\Windows\Explorer.EXE<br />
C:\Users\john doe\AppData\Local\Google\Chrome\Application\chrome .exe<br />
C:\Users\john doe\AppData\Local\Google\Chrome\Application\chrome .exe<br />
C:\Users\john doe\AppData\Local\Google\Chrome\Application\chrome .exe<br />
C:\Windows\system32\igfxsrvc.exe<br />
C:\Windows\system32\notepad.exe<br />
C:\Windows\system32\notepad.exe<br />
C:\Users\john doe\AppData\Local\Google\Chrome\Application\chrome .exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br /><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://www.google.co.uk/ig/dell?hl=e...uk&amp;ibd=4080112" rel="nofollow">http://www.google.co.uk/ig/dell?hl=e...uk&amp;ibd=4080112</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.google.co.uk/" rel="nofollow">http://www.google.co.uk/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =<br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll<br />
O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\s wg.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll<br />
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe<br />
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe<br />
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe<br />
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start<br />
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"<br />
O4 - HKLM\..\Run: [Unattend0000000001{FD63CC11-BC30-475A-9CC2-BC5D72177EA5}] c:\dell\cfi\RunGo.lnk<br />
O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all<br />
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter<br />
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto<br />
O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript<br />
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent<br />
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background<br />
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent<br />
O4 - HKCU\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start<br />
O4 - HKCU\..\Run: [Google Update] "C:\Users\john doe\AppData\Local\Google\Update\GoogleUpdate.exe" /c<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-18\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')<br />
O4 - Startup: Sonic INSTALLit! Setup.lnk = C:\Users\john doe\AppData\Local\Temp\VIES2F6A\Setup.EXE<br />
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe<br />
O4 - Global Startup: QuickSet.lnk = ?<br />
O8 - Extra context menu item: &amp;D&amp;ownload &amp;with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm<br />
O8 - Extra context menu item: &amp;D&amp;ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm<br />
O8 - Extra context menu item: &amp;D&amp;ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: <a href="https://icrontic.com/profile/C" rel="nofollow">@C</a>:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll<br />
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll<br />
O9 - Extra 'Tools' menuitem: <a href="https://icrontic.com/profile/C" rel="nofollow">@C</a>:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll/206 (file missing)<br />
O13 - Gopher Prefix:<br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - <a href="http://upload.facebook.com/controls/...oUploader5.cab" rel="nofollow">http://upload.facebook.com/controls/...oUploader5.cab</a><br />
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - <a href="http://gfx1.hotmail.com/mail/w2/reso...PUplden-gb.cab" rel="nofollow">http://gfx1.hotmail.com/mail/w2/reso...PUplden-gb.cab</a><br />
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - <a href="http://upload.facebook.com/controls/...Uploader55.cab" rel="nofollow">http://upload.facebook.com/controls/...Uploader55.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="https://fpdownload.macromedia.com/pu...sh/swflash.cab" rel="nofollow">https://fpdownload.macromedia.com/pu...sh/swflash.cab</a><br />
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL<br />
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br />
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe<br />
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe<br />
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe<br />
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br />
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe<br />
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe<br />
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe<br />
O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe<br />
O23 - Service: Vodafone Mobile Connect Service (VMCService) - Vodafone - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe<br />
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe<br />
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE<br />
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe<br /><br />
--<br />
End of file - 10458 bytes<br />
End of file - 10458 bytes]]>
        </description>
    </item>
    <item>
        <title>Everything is super slow to startup. Please help.</title>
        <link>https://icrontic.com/discussion/89384/everything-is-super-slow-to-startup-please-help</link>
        <pubDate>Tue, 27 Apr 2010 17:44:14 +0000</pubDate>
        <category>Spyware &amp; Virus Removal</category>
        <dc:creator>Miss_Alef</dc:creator>
        <guid isPermaLink="false">89384@/discussions</guid>
        <description><![CDATA[Everything is super slow to startup.  And mozilla regularly crashes trying to load pages.  Opening a new tab will sometimes start quickly, or it will freeze everything and make the browser crash.  I ran spybot and adaware, and things were running a little more smoothly, but now neither of those programs are able to update.  They encounter errors trying to update.  I posted a couple months ago, but never got a response, but here is my hijackthis log:<br /><br />
Logfile of HijackThis v1.99.1<br />
Scan saved at 4:34:41 PM, on 4/27/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br /><br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\ehome\ehtray.exe<br />
C:\WINDOWS\stsystra.exe<br />
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe<br />
C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br />
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe<br />
C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Symantec AntiVirus\DefWatch.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br />
C:\PROGRA~1\SYMANT~1\VPTray.exe<br />
C:\WINDOWS\eHome\ehRecvr.exe<br />
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe<br />
C:\WINDOWS\eHome\ehSched.exe<br />
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe<br />
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe<br />
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe<br />
C:\Program Files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe<br />
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe<br />
C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe<br />
C:\Program Files\Common Files\Java\Java Update\jusched.exe<br />
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe<br />
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe<br />
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe<br />
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
c:\program files\common files\installshield\updateservice\isuspm.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE<br />
C:\Program Files\DellSupport\DSAgnt.exe<br />
C:\WINDOWS\system32\fxssvc.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Skype\Phone\Skype.exe<br />
C:\Program Files\Common Files\SupportSoft\bin\bcont.exe<br />
C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe<br />
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe<br />
C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntispy.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\WINDOWS\system32\java.exe<br />
C:\WINDOWS\eHome\ehmsas.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe<br />
C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe<br />
C:\Program Files\Digital Line Detect\DLG.exe<br />
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe<br />
C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe<br />
C:\Program Files\Windows Desktop Search\WindowsSearch.exe<br />
C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\Program Files\Skype\Plugin Manager\skypePM.exe<br />
C:\Program Files\Common Files\Java\Java Update\jucheck.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\WINDOWS\system32\SearchIndexer.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe<br />
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe<br />
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br />
C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\WINDOWS\Jfysia.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\WINDOWS\system32\SearchProtocolHost.exe<br />
C:\Documents and Settings\Katheryn\Desktop\hijackthis_199\HijackThis.exe<br />
C:\WINDOWS\system32\SearchProtocolHost.exe<br /><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = <a href="www.google.com/ig/dell?hl=en&amp;client=dell-usuk&amp;channel=us" rel="nofollow">www.google.com/ig/dell?hl=en&amp;client=dell-usuk&amp;channel=us</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
F2 - REG:system.ini: Shell=Explorer.exe rundll32.exe hnbc.dro qoobyqc<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll<br />
O2 - BHO: Comcast Toolbar - {79CEEA4E-C231-4614-9E3B-53B2A02F39B7} - C:\Program Files\comcasttb\comcastdx.dll<br />
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Comcast Toolbar - {79CEEA4E-C231-4614-9E3B-53B2A02F39B7} - C:\Program Files\comcasttb\comcastdx.dll<br />
O3 - Toolbar: &amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe<br />
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe<br />
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe<br />
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"<br />
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup<br />
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start<br />
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br />
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall<br />
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br />
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br />
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br />
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot<br />
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"<br />
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"<br />
O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini"<br />
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN<br />
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun<br />
O4 - HKLM\..\Run: [LELA] "C:\Program Files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe" /minimized<br />
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"<br />
O4 - HKLM\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" /OM<br />
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe<br />
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br />
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized<br />
O4 - HKCU\..\Run: [Desktop Software] "C:\Program Files\Common Files\SupportSoft\bin\bcont.exe"  /ini "C:\Program Files\ComcastUI\Desktop Software\uinstaller.ini" /fromrun /starthidden<br />
O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe"<br />
O4 - HKCU\..\Run: [ComcastAntispyClient] "C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntispy.exe" /hide<br />
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background<br />
O4 - HKCU\..\Run: [YVIBBBHA8C] C:\DOCUME~1\Katheryn\LOCALS~1\Temp\Jmg.exe<br />
O4 - HKCU\..\Run: [QZAIB7KITK] C:\WINDOWS\Jfysia.exe<br />
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br />
O4 - Global Startup: Clean Access Agent.lnk = C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe<br />
O4 - Global Startup: Digital Line Detect.lnk = ?<br />
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?<br />
O4 - Global Startup: McAfee Security Scan.lnk = ?<br />
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe<br />
O8 - Extra context menu item: &amp;Search - ?p=GRman000<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html<br />
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?f1a3acb69ec844969d2f5fb9e0dd1ff6<br />
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?f1a3acb69ec844969d2f5fb9e0dd1ff6<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)<br />
O9 - Extra 'Tools' menuitem: <a href="https://icrontic.com/profile/xpsp3res" rel="nofollow">@xpsp3res</a>.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll<br />
O11 - Options group: [INTERNATIONAL] International<br />
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - <a href="http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab" rel="nofollow">http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1264449007218" rel="nofollow">http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1264449007218</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1264448986875" rel="nofollow">http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1264448986875</a><br />
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - <a href="http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab" rel="nofollow">http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab</a><br />
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -<br />
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - <a href="http://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab" rel="nofollow">http://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab</a><br />
O17 - HKLM\System\CCS\Services\Tcpip\..\{670D04FA-093F-43A8-85B6-0593B129F808}: NameServer = 93.188.164.19,93.188.161.158<br />
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 93.188.164.19,93.188.161.158<br />
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 93.188.164.19,93.188.161.158<br />
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.164.19,93.188.161.158<br />
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL<br />
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL<br />
O18 - Protocol: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp3.dll<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)<br />
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll<br />
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll<br />
O21 - SSODL: hksrv.dll - {45084BF1-55CB-4A8D-B0BB-BAD6DF96566D} - hksrv.dll (file missing)<br />
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll<br />
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe<br />
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: Comcast AntiSpyware (AntiSpywareService) - Unknown owner - C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br />
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe<br />
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe<br />
O23 - Service: IntelÂ® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe<br />
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)<br />
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
O23 - Service: Linksys Updater (LinksysUpdater) - Unknown owner - C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe" -s "C:\Program Files\Linksys\Linksys Updater\conf\wrapper.conf (file missing)<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br />
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe<br />
O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe<br />
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe<br />
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br />
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br />
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - Unknown owner - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe" /service /P ddoctorv2 (file missing)<br />
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe]]>
        </description>
    </item>
   </channel>
</rss>
