<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>Tech Support Forum - HijackThis Log Help (Inactive)</title>
		<link>http://www.techsupportforum.com</link>
		<description />
		<language>en</language>
		<lastBuildDate>Fri, 20 Nov 2009 23:27:10 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://www.techsupportforum.com/cwd/images/misc/rss.jpg</url>
			<title>Tech Support Forum - HijackThis Log Help (Inactive)</title>
			<link>http://www.techsupportforum.com</link>
		</image>
		<item>
			<title>Trojan.Win32.32.exe</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/433008-trojan-win32-32-exe.html</link>
			<pubDate>Wed, 18 Nov 2009 16:00:48 GMT</pubDate>
			<description>Hi. 
 
I have a Trojan worm that from time to time pops up from my Kaspersky Security window. 
 
It can be deleted but reappears sporadically even when PC is unattended but connected to the internet. 
 
The file shows: C:\System Volume...</description>
			<content:encoded><![CDATA[<div>Hi.<br />
<br />
I have a Trojan worm that from time to time pops up from my Kaspersky Security window.<br />
<br />
It can be deleted but reappears sporadically even when PC is unattended but connected to the internet.<br />
<br />
The file shows: C:\System Volume Information\_restore{EDC08634-9242-46EC-A8A0-9CA8F7A81F52}\RP205\A0114997.exe<br />
<br />
Any help on removing this would be appreciated.<br />
<br />
I believe it may have come from this.  is this a virus carrying mail? Received: from virus_17.livemail.co.uk (virus-cluster.livemail<br />
<br />
Thanks</div>

]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/">HijackThis Log Help (Inactive)</category>
			<dc:creator>dulcima</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/433008-trojan-win32-32-exe.html</guid>
		</item>
		<item>
			<title>Hacking problem</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/432990-hacking-problem.html</link>
			<pubDate>Wed, 18 Nov 2009 14:25:12 GMT</pubDate>
			<description><![CDATA[A few hours ago, someone changed my email's password. I thought it was an error at first, but when I checked my blog, I couldn't open it too. I knew right away someone hacked my accounts. I managed to recover my accounts and then replaced my passwords...I thought everything was OK until my email...]]></description>
			<content:encoded><![CDATA[<div>A few hours ago, someone changed my email's password. I thought it was an error at first, but when I checked my blog, I couldn't open it too. I knew right away someone hacked my accounts. I managed to recover my accounts and then replaced my passwords...I thought everything was OK until my email got hacked again. <br />
<br />
I changed my passwords again using my desktop, so I;ve realized it's my laptop that's probably being hacked. I don't know how though?<br />
<br />
Can I get some help right away pls! I use my laptop for university too, so it's really a big burden that I can't use it...</div>

]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/">HijackThis Log Help (Inactive)</category>
			<dc:creator>sorakusanagi</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/432990-hacking-problem.html</guid>
		</item>
		<item>
			<title>Browser Hijack</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/432948-browser-hijack.html</link>
			<pubDate>Wed, 18 Nov 2009 09:58:27 GMT</pubDate>
			<description><![CDATA[Recently, to my own shame, after visiting some porn sites my browser keeps reverting to unwanted sites. At first only to random sites that sell stuff but later to obscene sites.  
 
I've ran Spybot numerous times but it didn't work, I also switched from IE to Opera but it's the same story.  
 
I...]]></description>
			<content:encoded><![CDATA[<div>Recently, to my own shame, after visiting some porn sites my browser keeps reverting to unwanted sites. At first only to random sites that sell stuff but later to obscene sites. <br />
<br />
I've ran Spybot numerous times but it didn't work, I also switched from IE to Opera but it's the same story. <br />
<br />
I have Avira Antivir as virus protection.<br />
<br />
How can i stop it?<br />
<br />
Please help!</div>

]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/">HijackThis Log Help (Inactive)</category>
			<dc:creator>LourensMS</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/432948-browser-hijack.html</guid>
		</item>
		<item>
			<title>Virus, maybe spyware problems</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/432914-virus-maybe-spyware-problems.html</link>
			<pubDate>Wed, 18 Nov 2009 05:44:30 GMT</pubDate>
			<description>Ok heres the thing, i believe im infected with a virus or maybe spyware. Im not sure because i dont know a whole lot about computers. but heres whats happened. Some ad like things started popping up a few days ago and i knew that it was spyware or something so i went and bought some anti-Virus...</description>
			<content:encoded><![CDATA[<div>Ok heres the thing, i believe im infected with a virus or maybe spyware. Im not sure because i dont know a whole lot about computers. but heres whats happened. Some ad like things started popping up a few days ago and i knew that it was spyware or something so i went and bought some anti-Virus protection. When i restarted my computer to install it, beforing loading the desktop a fake anti virus type thing popped up syaing i was unprotected and what not. If i try to cancel it out it tells me it isnt allowed, if i press ctrl+alt+delete the task manager button isnt there, and if i press ctrl+shift+esc the task manager wont appear. So i have no desktop and no way to make this program install on my computer. I tried installing it while in safe mode but it fails. What should i do exactly? I would like to try to just get rid of it with the program if possible because i have pictures and such that i would like to keep. Anyone, please let me know what to do. Currently i am accessing the net from Safe mode with Networking support. Please help ASAP. thanks</div>

]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/">HijackThis Log Help (Inactive)</category>
			<dc:creator>saken5676</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/432914-virus-maybe-spyware-problems.html</guid>
		</item>
		<item>
			<title>TROJAN Horse Generic15.AVLU - Infected my XP! HELP to FIX!?!</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/432912-trojan-horse-generic15-avlu-infected-my-xp-help-fix.html</link>
			<pubDate>Wed, 18 Nov 2009 05:33:41 GMT</pubDate>
			<description><![CDATA[Thanks in advance for your help, it is very appreciated.  I accidentally accessed a video file that had a trojan in it.  I've tried combofix and sdfix.exe and neither have worked.  I've tried avg spyware and virus, Malwares, spybot, adaware, and none of them detect or allow me to remove the...]]></description>
			<content:encoded><![CDATA[<div>Thanks in advance for your help, it is very appreciated.  I accidentally accessed a video file that had a trojan in it.  I've tried combofix and sdfix.exe and neither have worked.  I've tried avg spyware and virus, Malwares, spybot, adaware, and none of them detect or allow me to remove the infection.  Please Help!<br />
<br />
I receive a popup every 2 minutes from AVG web shield alert stating &quot;threat detected&quot;<br />
<br />
File Name: 91.212.226.178/1inst.exe<br />
Threat Name: Trojan Horse Generic15.AVLU<br />
<br />
Process Name: C:\Windows\system32\svchost.exe<br />
Process ID: 940<br />
<br />
Hijack Log:<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 10:38 PM, on 11/17/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Sprint\Mobile Broadband\SMBAUtilSvc.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\AskBarDis\bar\bin\AskService.exe<br />
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\WINDOWS\system32\dlcxcoms.exe<br />
C:\PROGRA~1\AVG\AVG8\avgam.exe<br />
C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br />
C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\Program Files\Softex\OmniPass\Omniserv.exe<br />
C:\WINDOWS\system32\HPZipm12.exe<br />
C:\WINDOWS\system32\PnkBstrA.exe<br />
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Webroot\Washer\WasherSvc.exe<br />
C:\Program Files\Softex\OmniPass\OPXPApp.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\windows\system\hpsysdrv.exe<br />
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe<br />
C:\Program Files\Dell Photo AIO Printer 926\memcard.exe<br />
C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
C:\Program Files\VIA\VIAudioi\EnvyADeck\EnMixCPL.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Microsoft ActiveSync\wcescomm.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\PROGRA~1\MICROS~3\rapimgr.exe<br />
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe<br />
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe<br />
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\Updates\advcheck165.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\SpybotSD.exe<br />
C:\DOCUME~1\Owner\LOCALS~1\Temp\is-UB5KS.tmp\advcheck165.tmp<br />
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll (file missing)<br />
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll<br />
O3 - Toolbar: &amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe<br />
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart<br />
O4 - HKLM\..\Run: [GrooveMonitor] &quot;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&quot;<br />
O4 - HKLM\..\Run: [MemoryCardManager] &quot;C:\Program Files\Dell Photo AIO Printer 926\memcard.exe&quot;<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [EnvyHFCPL] C:\Program Files\VIA\VIAudioi\EnvyADeck\EnMixCPL.exe 1<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [!AVG Anti-Spyware] &quot;C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe&quot; /minimized<br />
O4 - HKCU\..\Run: [H/PC Connection Agent] &quot;C:\Program Files\Microsoft ActiveSync\wcescomm.exe&quot;<br />
O4 - HKCU\..\Run: [Google Update] &quot;C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe&quot; /c<br />
O4 - HKCU\..\Run: [updateMgr] &quot;C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe&quot; AcPro7_1_0 -reboot 1<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - Global Startup: Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe<br />
O8 - Extra context menu item: &amp;Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm<br />
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Yahoo! &amp;Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm<br />
O8 - Extra context menu item: Yahoo! &amp;Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm<br />
O8 - Extra context menu item: Yahoo! &amp;SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm<br />
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll (file missing)<br />
O9 - Extra 'Tools' menuitem: &amp;Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll (file missing)<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll<br />
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll<br />
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll<br />
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll<br />
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll<br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - <a href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" target="_blank">http://upload.facebook.com/controls/...oUploader5.cab</a><br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll<br />
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - <a href="http://lads.myspace.com/upload/MySpaceUploader1006.cab" target="_blank">http://lads.myspace.com/upload/MySpaceUploader1006.cab</a><br />
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - <a href="http://upload.facebook.com/controls/FacebookPhotoUploader.cab" target="_blank">http://upload.facebook.com/controls/...toUploader.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1140286330640" target="_blank">http://update.microsoft.com/microsof...?1140286330640</a><br />
O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - <a href="http://bestbuy.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab" target="_blank">http://bestbuy.kodakgallery.com/down...2/axofupld.cab</a><br />
O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - <a href="http://bestbuy.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab" target="_blank">http://bestbuy.kodakgallery.com/down...2/axofupld.cab</a><br />
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - <a href="http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab" target="_blank">http://upload.facebook.com/controls/...Uploader55.cab</a><br />
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - <a href="http://www.vzwpix.com/activex/VerizonWirelessUploadControl.cab" target="_blank">http://www.vzwpix.com/activex/Verizo...oadControl.cab</a><br />
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} (MySpace Uploader Control) - <a href="http://lads.myspace.com/upload/MySpaceUploader2.cab" target="_blank">http://lads.myspace.com/upload/MySpaceUploader2.cab</a><br />
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} - <a href="http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab" target="_blank">http://mvnet.xlontech.net/qm/fox/061...ie06101001.cab</a><br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll<br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: Access Utility Service - SprintNextel - C:\Program Files\Sprint\Mobile Broadband\SMBAUtilSvc.exe<br />
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe<br />
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe<br />
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: dlcx_device -   - C:\WINDOWS\system32\dlcxcoms.exe<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: Google Update Service (gupdate1c93597f679cda2) (gupdate1c93597f679cda2) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: hpdj - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\hpdj.exe (file missing)<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe<br />
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe<br />
<br />
--<br />
End of file - 15151 bytes<br />
<br />
<br />
Any assistance is greatly appreciated.  I have exams coming up online and I can't afford to have a this trojan mess everything up<br />
<br />
James</div>

]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/">HijackThis Log Help (Inactive)</category>
			<dc:creator>JChimlife</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/432912-trojan-horse-generic15-avlu-infected-my-xp-help-fix.html</guid>
		</item>
		<item>
			<title>College student in need of assistance</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/432877-college-student-need-assistance.html</link>
			<pubDate>Wed, 18 Nov 2009 02:53:55 GMT</pubDate>
			<description>Hello, i am a Virtual Technology and Design student, so my laptop is my life and my career. Recently while browsing the internet, the moment a page loaded i get a popup from AVG saying that there is a infected file detected, but offers no solution. I assume this means it is fixed, and continue on...</description>
			<content:encoded><![CDATA[<div>Hello, i am a Virtual Technology and Design student, so my laptop is my life and my career. Recently while browsing the internet, the moment a page loaded i get a popup from AVG saying that there is a infected file detected, but offers no solution. I assume this means it is fixed, and continue on with my day. But my browser started to randomly open up new tabs or redirect me to when i click on a link. It will send me to some no-name search engine for about a second, and then re-redirect me to a completely random site, however on some occasions it has to do with what i was looking at. Ran Malwarebytes, got one item, took it off, and the problem persists. AVG picks nothing up, and i honestly dont feel like using the trial and error method for every AV out there until hopefully one works. When i try to run the GMER program in your tutorial, my laptop instantly resets the moment i click the scan button, so i dont have that information for you sadly. However, in the event viewer, i found this under the system log which i think may have been the event giving me the virus:<br />
<br />
The master browser has received a server announcement from the computer WHITEBABY that believes that it is the master browser for the domain on transport NetBT_Tcpip_{6700717A-220B-4D92-83C2-213E1C58. The master browser is stopping or an election is being forced.<br />
<br />
Any help is greatly appreciated, and i will attach the DDS file if that helps at all. Running Vista 32 bit service pack 1. THANK YOU<br />
<br />
<br />
<br />
DDS (Ver_09-10-26.01) - NTFSx86  <br />
Run by Joe at 18:24:49.82 on Tue 11/17/2009<br />
Internet Explorer: 7.0.6001.18000<br />
Microsoft® Windows Vista™ Home Premium   6.0.6001.1.1252.1.1033.18.1982.1011 [GMT -8:00]<br />
<br />
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)   {17DDD097-36FF-435F-9E1B-52D74245D6BF}<br />
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}<br />
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}<br />
<br />
============== Running Processes ===============<br />
<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\nvvsvc.exe<br />
C:\Windows\system32\svchost.exe -k rpcss<br />
C:\Windows\System32\svchost.exe -k secsvcs<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\system32\SLsvc.exe<br />
C:\Windows\system32\rundll32.exe<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Windows\system32\svchost.exe -k bthsvcs<br />
C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br />
C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe<br />
C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
C:\Program Files\AVG\AVG8\avgtray.exe<br />
C:\Windows\system32\svchost.exe -k imgsvc<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\Program Files\Zune\ZuneLauncher.exe<br />
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe<br />
C:\Windows\System32\svchost.exe -k WerSvcGroup<br />
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Windows\system32\DRIVERS\xaudio.exe<br />
C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
C:\Program Files\AVG\AVG8\avgcsrvx.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Program Files\Windows Live\Contacts\wlcomm.exe<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Program Files\Zune\ZuneNss.exe<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Program Files\DAEMON Tools Pro\DTProShellHlp.exe<br />
C:\Windows\system32\mmc.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Windows\system32\SearchProtocolHost.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Windows\explorer.exe<br />
C:\Users\Joe\Desktop\dds.scr<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
<br />
============== Pseudo HJT Report ===============<br />
<br />
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=73&amp;bd=Pavilion&amp;pf=laptop<br />
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=73&amp;bd=Pavilion&amp;pf=laptop<br />
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=73&amp;bd=Pavilion&amp;pf=laptop<br />
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=73&amp;bd=Pavilion&amp;pf=laptop<br />
uInternet Settings,ProxyOverride = *.local<br />
BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll<br />
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll<br />
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll<br />
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll<br />
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File<br />
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll<br />
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll<br />
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll<br />
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll<br />
uRun: [msnmsgr] &quot;c:\program files\windows live\messenger\msnmsgr.exe&quot; /background<br />
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe<br />
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe<br />
mRun: [TkBellExe] &quot;c:\program files\common files\real\update_ob\realsched.exe&quot;  -osboot<br />
mRun: [Zune Launcher] &quot;c:\program files\zune\ZuneLauncher.exe&quot;<br />
mRun: [GrooveMonitor] &quot;c:\program files\microsoft office\office12\GrooveMonitor.exe&quot;<br />
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe<br />
mRun: [Malwarebytes Anti-Malware (reboot)] &quot;c:\program files\malwarebytes' anti-malware\mbam.exe&quot; /runcleanupscript<br />
mPolicies-system: EnableLUA = 0 (0x0)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000<br />
IE: Send image to &amp;Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm<br />
IE: Send page to &amp;Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm<br />
IE: {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - c:\program files\paltalk messenger\Paltalk.exe<br />
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm<br />
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\ssv.dll<br />
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL<br />
DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab<br />
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab<br />
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll<br />
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll<br />
AppInit_DLLs: avgrsstx.dll<br />
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll<br />
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - &quot;c:\program files\common files\lightscribe\LSRunOnce.exe&quot;<br />
<br />
================= FIREFOX ===================<br />
<br />
FF - ProfilePath - c:\users\joe\appdata\roaming\mozilla\firefox\profiles\9p5ymek4.default\<br />
FF - prefs.js: browser.startup.homepage - <a href="http://www.google.com" target="_blank">www.google.com</a><br />
FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll<br />
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava11.dll<br />
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava12.dll<br />
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava13.dll<br />
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava14.dll<br />
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava32.dll<br />
FF - plugin: c:\program files\java\jre1.6.0\bin\npjpi160.dll<br />
FF - plugin: c:\program files\java\jre1.6.0\bin\npoji610.dll<br />
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll<br />
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\<br />
<br />
---- FIREFOX POLICIES ----<br />
FF - user.js: browser.windows.loadOnNewWindow - 2<br />
FF - user.js: layout.spellcheckDefault - 2<br />
<br />
============= SERVICES / DRIVERS ===============<br />
<br />
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-1-4 335240]<br />
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-2-1 108552]<br />
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-1-4 908056]<br />
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-1-4 297752]<br />
S2 mi-raysat_3dsmax2010_32;mental ray 3.7 Satellite for Autodesk 3ds Max 2010 32-bit 32-bit;c:\program files\autodesk\3ds max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe [2009-3-12 86016]<br />
<br />
=============== Created Last 30 ================<br />
<br />
2009-11-17 23:30:06	0	d-----w-	C:\.jagex_cache_32<br />
2009-11-17 20:24:31	0	d-----w-	c:\users\joe\appdata\roaming\Malwarebytes<br />
2009-11-17 20:24:25	38224	----a-w-	c:\windows\system32\drivers\mbamswissarmy.sys<br />
2009-11-17 20:24:23	19160	----a-w-	c:\windows\system32\drivers\mbam.sys<br />
2009-11-17 20:24:23	0	d-----w-	c:\programdata\Malwarebytes<br />
2009-11-17 20:24:23	0	d-----w-	c:\program files\Malwarebytes' Anti-Malware<br />
2009-11-17 07:23:01	63	----a-w-	c:\users\joe\jagex_runescape_preferences2.dat<br />
2009-11-17 07:22:06	38	----a-w-	c:\users\joe\jagex_runescape_preferences.dat<br />
2009-11-12 01:00:16	351232	----a-w-	c:\windows\system32\WSDApi.dll<br />
2009-11-12 01:00:12	2035712	----a-w-	c:\windows\system32\win32k.sys<br />
2009-11-05 21:33:41	2421760	----a-w-	c:\windows\system32\wucltux.dll<br />
2009-11-05 21:33:13	87552	----a-w-	c:\windows\system32\wudriver.dll<br />
2009-11-05 21:33:01	33792	----a-w-	c:\windows\system32\wuapp.exe<br />
2009-11-05 21:33:01	171608	----a-w-	c:\windows\system32\wuwebv.dll<br />
2009-11-04 01:53:27	0	d-----w-	c:\program files\Pokemon World Online<br />
2009-10-29 06:26:42	132880	----a-w-	c:\windows\system32\MSINET.OCX<br />
2009-10-29 06:26:42	1227264	----a-w-	c:\windows\system32\dx8vb.dll<br />
2009-10-29 06:26:42	108336	----a-w-	c:\windows\system32\MSWINSCK.OCX<br />
<br />
==================== Find3M  ====================<br />
<br />
2009-11-18 00:51:12	113593	----a-w-	c:\programdata\nvModes.dat<br />
2009-11-03 04:42:06	195456	------w-	c:\windows\system32\MpSigStub.exe<br />
2009-10-09 02:47:27	19497	----a-w-	c:\windows\hpqins13.dat<br />
2009-10-09 00:10:24	51200	----a-w-	c:\windows\inf\infpub.dat<br />
2009-10-09 00:10:23	143360	----a-w-	c:\windows\inf\infstrng.dat<br />
2009-10-09 00:10:21	86016	----a-w-	c:\windows\inf\infstor.dat<br />
2009-10-06 23:15:31	57366	----a-w-	c:\windows\system32\mausling_Joe_Midterm.zip<br />
2009-10-05 00:07:15	34745	----a-w-	c:\windows\system32\Mausling_Joe_Ex5.zip<br />
2009-09-29 01:54:46	1606	----a-w-	c:\users\joe\appdata\roaming\wklnhst.dat<br />
2009-09-20 08:47:00	0	---ha-w-	c:\windows\system32\drivers\Msft_User_ZuneDriver_01_09_00.Wdf<br />
2009-09-10 17:30:12	213504	----a-w-	c:\windows\system32\msv1_0.dll<br />
2009-09-04 20:17:00	447216	----a-w-	c:\windows\system32\ZuneWlanCfgSvc.exe<br />
2009-09-04 12:24:34	61440	----a-w-	c:\windows\system32\msasn1.dll<br />
2009-09-02 07:29:12	74240	----a-w-	c:\windows\system32\ZuneUsbTransport.dll<br />
2009-09-02 07:29:10	57344	----a-w-	c:\windows\system32\ZuneRegUtil.dll<br />
2009-09-02 07:29:10	18944	----a-w-	c:\windows\system32\ZuneTcp2Udp.dll<br />
2009-09-02 07:29:10	12800	----a-w-	c:\windows\system32\ZunePTDNS.dll<br />
2009-09-02 07:29:02	310784	----a-w-	c:\windows\system32\ZuneNetProxy.dll<br />
2009-09-02 07:29:00	147456	----a-w-	c:\windows\system32\ZuneMTPZ.dll<br />
2009-08-28 15:47:15	11952	----a-w-	c:\windows\system32\avgrsstx.dll<br />
2009-08-27 13:32:41	833024	----a-w-	c:\windows\system32\wininet.dll<br />
2009-08-27 13:29:25	78336	----a-w-	c:\windows\system32\ieencode.dll<br />
2009-08-27 10:58:58	26624	----a-w-	c:\windows\system32\ieUnatt.exe<br />
2009-05-11 05:02:27	174	--sha-w-	c:\program files\desktop.ini<br />
2009-05-11 04:38:34	665600	----a-w-	c:\windows\inf\drvindex.dat<br />
2006-11-02 12:42:02	30674	----a-w-	c:\windows\inf\perflib\0409\perfd.dat<br />
2006-11-02 12:42:02	30674	----a-w-	c:\windows\inf\perflib\0409\perfc.dat<br />
2006-11-02 12:42:02	287440	----a-w-	c:\windows\inf\perflib\0409\perfi.dat<br />
2006-11-02 12:42:02	287440	----a-w-	c:\windows\inf\perflib\0409\perfh.dat<br />
2006-11-02 09:20:21	287440	----a-w-	c:\windows\inf\perflib\0000\perfi.dat<br />
2006-11-02 09:20:21	287440	----a-w-	c:\windows\inf\perflib\0000\perfh.dat<br />
2006-11-02 09:20:19	30674	----a-w-	c:\windows\inf\perflib\0000\perfd.dat<br />
2006-11-02 09:20:19	30674	----a-w-	c:\windows\inf\perflib\0000\perfc.dat<br />
<br />
============= FINISH: 18:26:42.25 ===============<br />
<br />
eh... BUMP?? I kinda need this fixed soon. New info up to date Malwarebytes finds nothing, but avg has found 30 so far all named Trojan horse Agent_r.PC.<br />
<br />
Only problem is that it is mostly system 32 files, AVG files such as avgscanx.exe, java, microsoft office, zune, hp, and other stuff. Ill update more as scan finishes, but any imput so far would be lovely</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techsupportforum.com/cwd/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techsupportforum.com/attachments/hijackthis-log-help-inactive/60441d1258512812-college-student-need-assistance-dds.txt">DDS.txt</a> (12.2 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/">HijackThis Log Help (Inactive)</category>
			<dc:creator>AKaveman</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/432877-college-student-need-assistance.html</guid>
		</item>
		<item>
			<title>Annoying virus</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/431585-annoying-virus.html</link>
			<pubDate>Sat, 14 Nov 2009 02:36:17 GMT</pubDate>
			<description>Hey, I had posted a thread a while earlier, but due to complications I could not follow through. That is not the case anymore and would greatly appreciate further help. The link to the original topic is: ...</description>
			<content:encoded><![CDATA[<div>Hey, I had posted a thread a while earlier, but due to complications I could not follow through. That is not the case anymore and would greatly appreciate further help. The link to the original topic is: <br />
<a href="!417591!http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/417591-annoying-virus.html" target="_blank">http://www.techsupportforum.com/secu...ing-virus.html</a><br />
<br />
I was instructed to provide a log of combo fix as follows: <br />
<br />
ComboFix 09-11-13.04 - LOUIS 13/11/2009 18:07.2.2 - NTFSx86<br />
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.1014.694 [GMT 11:00]<br />
Running from: c:\documents and settings\LOUIS\My Documents\Downloads\ComboFix.exe<br />
AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}<br />
 * Created a new restore point<br />
.<br />
<br />
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br />
<br />
c:\program files\sFX<br />
c:\program files\sFX\sfX.sYs<br />
c:\windows\010112010146118114.dat<br />
c:\windows\0101120101465752.dat<br />
c:\windows\934fdfg34fgjf23<br />
c:\windows\bf23567.dat<br />
<br />
.<br />
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br />
<br />
-------\Legacy_SFX<br />
-------\Legacy_SFXDRV<br />
-------\Service_sfx<br />
-------\Service_sFxdrv<br />
<br />
<br />
(((((((((((((((((((((((((   Files Created from 2009-10-13 to 2009-11-13  )))))))))))))))))))))))))))))))<br />
.<br />
<br />
2009-11-10 11:41 . 2009-11-11 19:52	79488	----a-w-	c:\documents and settings\LOUIS\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll<br />
2009-11-10 11:41 . 2009-11-10 11:41	--------	d-----w-	c:\program files\Common Files\Skype<br />
2009-11-10 11:31 . 2009-11-10 11:31	--------	d-----w-	c:\windows\system32\wbem\Repository<br />
2009-11-10 11:26 . 2009-11-10 11:26	--------	d-----w-	c:\program files\Common Files\Intel<br />
2009-11-10 11:16 . 2009-11-10 11:16	--------	d-----w-	C:\Intel<br />
<br />
.<br />
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br />
2009-11-13 07:25 . 2009-05-18 01:34	--------	d-----w-	c:\documents and settings\LOUIS\Application Data\skypePM<br />
2009-11-13 07:25 . 2009-05-18 01:29	--------	d-----w-	c:\documents and settings\LOUIS\Application Data\Skype<br />
2009-11-13 07:25 . 2009-06-26 09:25	--------	d-----w-	c:\program files\Steam<br />
2009-11-10 11:42 . 2009-05-18 01:26	--------	d-----r-	c:\program files\Skype<br />
2009-11-10 11:41 . 2009-05-18 01:25	--------	d-----w-	c:\documents and settings\All Users\Application Data\Skype<br />
2009-11-10 11:39 . 2009-04-28 10:25	--------	d-----w-	c:\program files\Messenger Plus! Live<br />
2009-11-10 11:26 . 2009-04-28 06:23	--------	d-----w-	c:\program files\Intel<br />
2009-11-10 11:16 . 2009-04-28 06:22	--------	d--h--w-	c:\program files\InstallShield Installation Information<br />
2009-10-25 12:38 . 2009-06-15 09:51	--------	d-----w-	c:\documents and settings\LOUIS\Application Data\dvdcss<br />
2009-10-25 11:24 . 2009-05-28 07:01	--------	d-----w-	c:\program files\Counter-Strike 1.6<br />
2009-10-15 06:05 . 2009-04-29 10:12	--------	d-----w-	c:\documents and settings\LOUIS\Application Data\Apple Computer<br />
2009-10-14 10:06 . 2009-04-30 04:41	--------	d-----w-	c:\documents and settings\LOUIS\Application Data\Audacity<br />
2009-09-30 09:36 . 2009-09-30 09:33	--------	d-----w-	c:\program files\Optus Wireless Broadband<br />
2009-09-27 23:45 . 2009-09-16 11:32	--------	d-----w-	c:\program files\Microsoft Silverlight<br />
2009-09-25 05:37 . 2004-08-12 13:33	667136	----a-w-	c:\windows\system32\wininet.dll<br />
2009-09-25 05:37 . 2004-08-12 13:19	81920	----a-w-	c:\windows\system32\ieencode.dll<br />
2009-09-16 11:37 . 2009-04-28 10:24	54008	----a-w-	c:\documents and settings\LOUIS\Local Settings\Application Data\GDIPFONTCACHEV1.DAT<br />
2009-09-16 11:32 . 2009-09-16 11:29	--------	d-----w-	c:\program files\Microsoft<br />
2009-09-16 11:31 . 2009-04-28 10:25	--------	d-----w-	c:\program files\Windows Live<br />
2009-09-16 11:29 . 2009-09-16 11:29	--------	d-----w-	c:\program files\Windows Live SkyDrive<br />
2009-09-16 11:25 . 2009-09-16 11:25	--------	d-----w-	c:\program files\Common Files\Windows Live<br />
2009-09-11 14:18 . 2004-08-12 13:23	136192	----a-w-	c:\windows\system32\msv1_0.dll<br />
2009-09-04 21:03 . 2004-08-12 13:22	58880	----a-w-	c:\windows\system32\msasn1.dll<br />
2009-08-26 08:00 . 2004-08-12 13:30	247326	----a-w-	c:\windows\system32\strmdll.dll<br />
2009-02-24 19:34 . 2009-02-24 19:34	1044480	----a-w-	c:\program files\mozilla firefox\plugins\libdivx.dll<br />
2009-02-24 19:34 . 2009-02-24 19:34	200704	----a-w-	c:\program files\mozilla firefox\plugins\ssldivx.dll<br />
.<br />
<br />
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br />
.<br />
*Note* empty entries &amp; legit default entries are not shown <br />
REGEDIT4<br />
<br />
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />
&quot;MsnMsgr&quot;=&quot;c:\program files\Windows Live\Messenger\msnmsgr.exe&quot; [2009-07-26 3883856]<br />
&quot;PC Suite Tray&quot;=&quot;c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe&quot; [2009-05-18 1312256]<br />
&quot;Steam&quot;=&quot;c:\program files\Steam\Steam.exe&quot; [2009-10-30 1217808]<br />
&quot;MSMSGS&quot;=&quot;c:\program files\Messenger\msmsgs.exe&quot; [2008-04-13 1695232]<br />
&quot;Skype&quot;=&quot;c:\program files\Skype\\Phone\Skype.exe&quot; [2009-10-09 25623336]<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />
&quot;igfxtray&quot;=&quot;c:\windows\system32\igfxtray.exe&quot; [2005-12-13 98304]<br />
&quot;igfxhkcmd&quot;=&quot;c:\windows\system32\hkcmd.exe&quot; [2005-12-13 77824]<br />
&quot;igfxpers&quot;=&quot;c:\windows\system32\igfxpers.exe&quot; [2005-12-13 118784]<br />
&quot;IntelZeroConfig&quot;=&quot;c:\program files\Intel\Wireless\bin\ZCfgSvc.exe&quot; [2005-12-28 667718]<br />
&quot;IntelWireless&quot;=&quot;c:\program files\Intel\Wireless\Bin\ifrmewrk.exe&quot; [2005-12-28 602182]<br />
&quot;DVDLauncher&quot;=&quot;c:\program files\CyberLink\PowerDVD\DVDLauncher.exe&quot; [2005-12-09 49152]<br />
&quot;dla&quot;=&quot;c:\windows\system32\dla\tfswctrl.exe&quot; [2005-03-15 127037]<br />
&quot;ShStatEXE&quot;=&quot;c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE&quot; [2007-02-22 112216]<br />
&quot;McAfeeUpdaterUI&quot;=&quot;c:\program files\McAfee\Common Framework\UdaterUI.exe&quot; [2006-12-19 136768]<br />
&quot;QuickTime Task&quot;=&quot;c:\program files\QuickTime\QTTask.exe&quot; [2009-01-05 413696]<br />
&quot;iTunesHelper&quot;=&quot;c:\program files\iTunes\iTunesHelper.exe&quot; [2009-04-02 342312]<br />
&quot;SigmatelSysTrayApp&quot;=&quot;c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe&quot; [2007-05-10 405504]<br />
&quot;WinampAgent&quot;=&quot;c:\program files\Winamp\winampa.exe&quot; [2008-08-03 36352]<br />
&quot;SunJavaUpdateSched&quot;=&quot;c:\program files\Java\jre6\bin\jusched.exe&quot; [2009-05-17 148888]<br />
<br />
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&quot;CTFMON.EXE&quot;=&quot;c:\windows\system32\CTFMON.EXE&quot; [2008-04-13 15360]<br />
<br />
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]<br />
&quot;midi4&quot;=KORGUMDD.DRV<br />
&quot;midi6&quot;=KORGUMDD.DRV<br />
<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]<br />
@=&quot;Driver&quot;<br />
<br />
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]<br />
&quot;EnableFirewall&quot;= 0 (0x0)<br />
<br />
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br />
&quot;%windir%\\system32\\sessmgr.exe&quot;=<br />
&quot;%windir%\\Network Diagnostic\\xpnetdiag.exe&quot;=<br />
&quot;c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe&quot;=<br />
&quot;c:\\Program Files\\Ares\\Ares.exe&quot;=<br />
&quot;c:\\Program Files\\Bonjour\\mDNSResponder.exe&quot;=<br />
&quot;c:\\Program Files\\iTunes\\iTunes.exe&quot;=<br />
&quot;c:\\Program Files\\BitLord\\BitLord.exe&quot;=<br />
&quot;c:\\Program Files\\Counter-Strike 1.6\\hl.exe&quot;=<br />
&quot;c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe&quot;=<br />
&quot;c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe&quot;=<br />
&quot;c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe&quot;=<br />
&quot;c:\\Program Files\\Skype\\Phone\\Skype.exe&quot;=<br />
<br />
S3 KORGUMDS;KORG USB-MIDI Driver for Windows;c:\windows\system32\drivers\KORGUMDS.SYS [27/03/2009 2:11 AM 21720]<br />
<br />
--- Other Services/Drivers In Memory ---<br />
<br />
*NewlyCreated* - MBR<br />
*Deregistered* - mbr<br />
.<br />
Contents of the 'Scheduled Tasks' folder<br />
<br />
2009-10-16 c:\windows\Tasks\AppleSoftwareUpdate.job<br />
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 02:34]<br />
.<br />
.<br />
------- Supplementary Scan -------<br />
.<br />
uInternet Connection Wizard,ShellNext = <a href="https://login.live.com/ppsecure/sha1auth.srf?lc=3081" target="_blank">https://login.live.com/ppsecure/sha1auth.srf?lc=3081</a><br />
uInternet Settings,ProxyOverride = *.local<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
FF - ProfilePath - c:\documents and settings\LOUIS\Application Data\Mozilla\Firefox\Profiles\1ukdzh2z.default\<br />
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig<br />
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll<br />
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\<br />
<br />
---- FIREFOX POLICIES ----<br />
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref(&quot;security.ssl3.rsa_seed_sha&quot;, true);<br />
.<br />
- - - - ORPHANS REMOVED - - - -<br />
<br />
HKLM-Run-ISUSPM Startup - c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe<br />
HKLM-Run-ISUSScheduler - c:\program files\Common Files\InstallShield\UpdateService\issch.exe<br />
<br />
<br />
<br />
**************************************************************************<br />
<br />
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, <a href="http://www.gmer.net" target="_blank">http://www.gmer.net</a><br />
Rootkit scan 2009-11-13 18:23<br />
Windows 5.1.2600 Service Pack 3 NTFS<br />
<br />
scanning hidden processes ...  <br />
<br />
scanning hidden autostart entries ... <br />
<br />
scanning hidden files ...  <br />
<br />
scan completed successfully<br />
hidden files: 0<br />
<br />
**************************************************************************<br />
.<br />
------------------------ Other Running Processes ------------------------<br />
.<br />
c:\program files\Intel\Wireless\Bin\EvtEng.exe<br />
c:\program files\Intel\Wireless\Bin\S24EvMon.exe<br />
c:\program files\Intel\Wireless\Bin\WLKeeper.exe<br />
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
c:\program files\Bonjour\mDNSResponder.exe<br />
c:\program files\Java\jre6\bin\jqs.exe<br />
c:\program files\McAfee\Common Framework\FrameworkService.exe<br />
c:\program files\McAfee\VirusScan Enterprise\Mcshield.exe<br />
c:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exe<br />
c:\program files\Intel\Wireless\Bin\RegSrvc.exe<br />
c:\windows\system32\wdfmgr.exe<br />
c:\program files\McAfee\Common Framework\naPrdMgr.exe<br />
c:\windows\system32\wscntfy.exe<br />
c:\windows\system32\igfxsrvc.exe<br />
c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe<br />
c:\program files\McAfee\Common Framework\McTray.exe<br />
c:\program files\PC Connectivity Solution\ServiceLayer.exe<br />
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe<br />
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe<br />
c:\program files\Windows Live\Contacts\wlcomm.exe<br />
c:\program files\Skype\Phone\Skype.exe<br />
c:\program files\Skype\Plugin Manager\skypePM.exe<br />
c:\program files\Java\jre6\bin\jucheck.exe<br />
.<br />
**************************************************************************<br />
.<br />
Completion time: 2009-11-13 18:29 - machine was rebooted<br />
ComboFix-quarantined-files.txt  2009-11-13 07:29<br />
ComboFix2.txt  2009-05-14 06:24<br />
<br />
Pre-Run: 54,065,717,248 bytes free<br />
Post-Run: 54,118,064,128 bytes free<br />
<br />
- - End Of File - - 56BF462198F0144816CEE008CDF945CD</div>

]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/">HijackThis Log Help (Inactive)</category>
			<dc:creator>sck</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/431585-annoying-virus.html</guid>
		</item>
		<item>
			<title><![CDATA[AVG won't install]]></title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/431111-avg-wont-install.html</link>
			<pubDate>Thu, 12 Nov 2009 18:10:03 GMT</pubDate>
			<description>Ok so I have a PC that is infected when I try to install AVG Antivirus it tells me that it could not find internet connectivity and it cannot install.  the computer can go on the internet.  
 
This is the only PC I have had this problem with. I have downloaded the file why does it need the internet...</description>
			<content:encoded><![CDATA[<div>Ok so I have a PC that is infected when I try to install AVG Antivirus it tells me that it could not find internet connectivity and it cannot install.  the computer can go on the internet. <br />
<br />
This is the only PC I have had this problem with. I have downloaded the file why does it need the internet to install?</div>

]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/">HijackThis Log Help (Inactive)</category>
			<dc:creator>GrTech2009</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/431111-avg-wont-install.html</guid>
		</item>
		<item>
			<title>AntiVirus Pro 2010</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/430988-antivirus-pro-2010-a.html</link>
			<pubDate>Thu, 12 Nov 2009 09:17:50 GMT</pubDate>
			<description>Hi,  
 
 
Antivirus_Pro 2010 Infection 
Sys Information: 
 
HP Compaq dc5100 - 
Pentium 2.80GHz - 
1.49GB Ram -</description>
			<content:encoded><![CDATA[<div>Hi, <br />
<br />
<br />
Antivirus_Pro 2010 Infection<br />
Sys Information:<br />
<br />
HP Compaq dc5100 -<br />
Pentium 2.80GHz -<br />
1.49GB Ram -<br />
<br />
Windows XP Pro SP3<br />
<br />
AVG Free Anti Virus.<br />
<br />
I recently had help removing an infection from my machine.  I belive it may still be infected.. It is still showing in the startup tab of MSCONFIG &amp; whenever I remove it and restart the computer it comes back.<br />
<br />
There are no longer any pop ups or redirects being caused by the virus, but i think some part of it remains.<br />
<br />
Any help is appreciated <br />
<br />
Liam<br />
<br />
This is the listing in &quot;msconfig - start up tab&quot; :-<br />
&quot;c:\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe&quot; /hide&quot;<br />
<br />
(here is a link to the originall thread)<br />
<a href="!424548!http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/resolved-hjt-threads/424548-solved-antivirus_pro-2010-infection.html" target="_blank">http://www.techsupportforum.com/secu...infection.html</a></div>

]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/">HijackThis Log Help (Inactive)</category>
			<dc:creator>LooRoll</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/430988-antivirus-pro-2010-a.html</guid>
		</item>
		<item>
			<title>My Dell XPS M1330 SP2 keeps on freezing</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/430689-my-dell-xps-m1330-sp2-keeps-freezing.html</link>
			<pubDate>Wed, 11 Nov 2009 14:49:01 GMT</pubDate>
			<description>My Dell XPS M1330 SP2 keeps on freezing and the only way to make it run again is to pullout the battery...Im afraid a virus causes this 
It freezes in about 20 mins after startup 
 
In this post i have attach a dds.txt and hijackthis log both were used during Safe Mode 
 
 
I will attach the GMER...</description>
			<content:encoded><![CDATA[<div>My Dell XPS M1330 SP2 keeps on freezing and the only way to make it run again is to pullout the battery...Im afraid a virus causes this<br />
It freezes in about 20 mins after startup<br />
<br />
In this post i have attach a dds.txt and hijackthis log both were used during Safe Mode<br />
<br />
<br />
I will attach the GMER later...in case my laptop freezes again<br />
<br />
This post contains ark.txt<br />
<br />
how do i get the attach.txt?<br />
<br />
<br />
<br />
DDS (Ver_09-10-26.01) - NTFSx86 MINIMAL <br />
Run by Karlo at 22:22:28.38 on Wed 11/11/2009<br />
Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_16<br />
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.3069.2677 [GMT 8:00]<br />
<br />
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}<br />
<br />
============== Running Processes ===============<br />
<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\svchost.exe -k rpcss<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Users\Karlo\Desktop\dds.scr<br />
<br />
============== Pseudo HJT Report ===============<br />
<br />
uStart Page = hxxp://www.ask.com/?o=13920&amp;l=dis<br />
mWinlogon: Userinit=userinit.exe<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll<br />
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll<br />
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll<br />
uRun: [uTorrent] &quot;c:\program files\utorrent\uTorrent.exe&quot;<br />
uRun: [BitTorrent DNA] &quot;c:\program files\dna\btdna.exe&quot;<br />
mRun: [PCMService] &quot;c:\program files\dell\mediadirect\PCMService.exe&quot;<br />
mRun: [OEM02Mon.exe] c:\windows\OEM02Mon.exe<br />
mRun: [NVHotkey] rundll32.exe c:\windows\system32\nvHotkey.dll,Start<br />
mRun: [RivaTunerStartupDaemon] &quot;c:\program files\rivatuner v2.24\RivaTunerWrapper.exe&quot; /S<br />
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe<br />
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe<br />
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe<br />
mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe<br />
mRun: [NvSvc] RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart<br />
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup<br />
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit<br />
mRun: [nwiz] nwiz.exe /install<br />
mRun: [SunJavaUpdateSched] &quot;c:\program files\java\jre6\bin\jusched.exe&quot;<br />
mRun: [COMODO Internet Security] &quot;c:\program files\comodo\comodo internet security\cfp.exe&quot; -h<br />
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe<br />
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe<br />
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)<br />
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)<br />
mPolicies-system: ConsentPromptBehaviorUser = 0 (0x0)<br />
mPolicies-system: EnableLUA = 0 (0x0)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000<br />
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll<br />
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab<br />
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab<br />
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll<br />
AppInit_DLLs: avgrsstx.dll<br />
<br />
================= FIREFOX ===================<br />
<br />
FF - ProfilePath - c:\users\karlo\appdata\roaming\mozilla\firefox\profiles\4d4hyc5j.default\<br />
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\NPMFireLauncher.dll<br />
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}<br />
<br />
---- FIREFOX POLICIES ----<br />
 FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\security-prefs.js - pref(&quot;security.ssl3.rsa_seed_sha&quot;, true);<br />
<br />
============= SERVICES / DRIVERS ===============<br />
<br />
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-11-9 333192]<br />
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-11-9 360584]<br />
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2009-11-9 128888]<br />
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2009-11-9 29520]<br />
S2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2009-5-20 73728]<br />
S2 Apache2.2;Apache2.2;&quot;c:\program files\xampp\apache\bin\apache.exe&quot; -k runservice --&gt; c:\program files\xampp\apache\bin\apache.exe [?]<br />
S2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2009-11-9 906520]<br />
S2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2009-11-9 285392]<br />
S2 hcefbty;fxnuhiw;c:\windows\system32\svchost.exe -k netsvcs [2008-1-21 21504]<br />
S2 typzb;System Update;c:\windows\system32\svchost.exe -k netsvcs [2008-1-21 21504]<br />
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2007-2-26 179712]<br />
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]<br />
S3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\system32\drivers\OEM02Dev.sys [2009-5-20 235648]<br />
S3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\system32\drivers\OEM02Vfx.sys [2009-5-20 7424]<br />
S4 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --&gt; c:\windows\system32\GameMon.des -service [?]<br />
<br />
=============== Created Last 30 ================<br />
<br />
2009-11-11 14:17:44	0	d-----w-	c:\program files\Trend Micro<br />
2009-11-09 23:09:28	0	d-----w-	c:\programdata\WindowsSearch<br />
2009-11-09 12:03:55	0	d--h--w-	C:\$AVG<br />
2009-11-09 12:03:52	12464	----a-w-	c:\windows\system32\avgrsstx.dll<br />
2009-11-09 12:03:48	360584	----a-w-	c:\windows\system32\drivers\avgtdix.sys<br />
2009-11-09 12:03:38	333192	----a-w-	c:\windows\system32\drivers\avgldx86.sys<br />
2009-11-09 12:03:33	0	d-----w-	c:\windows\system32\drivers\Avg<br />
2009-11-09 12:03:25	0	d-----w-	c:\programdata\avg9<br />
2009-11-09 11:26:50	0	d-----w-	c:\programdata\Comodo<br />
2009-11-09 11:26:44	29520	----a-w-	c:\windows\system32\drivers\cmdhlp.sys<br />
2009-11-09 11:26:44	179792	----a-w-	c:\windows\system32\guard32.dll<br />
2009-11-09 11:26:44	128888	----a-w-	c:\windows\system32\drivers\cmdguard.sys<br />
2009-11-08 15:47:30	0	d-----w-	c:\programdata\Media Center Programs<br />
2009-11-08 15:47:28	0	d-----w-	c:\program files\common files\BioWare<br />
2009-11-06 14:34:18	0	d-----w-	c:\programdata\MySQL<br />
2009-11-06 14:34:18	0	d-----w-	c:\program files\MySQL<br />
2009-11-06 13:04:17	862	----a-w-	c:\windows\system32\termcap<br />
2009-11-06 12:36:12	0	d-----w-	C:\MySQL Datafiles<br />
2009-11-06 10:38:15	172	----a-w-	c:\windows\ODBC.INI<br />
2009-11-06 10:36:53	0	d-----w-	c:\program files\Business Objects<br />
2009-11-06 10:29:10	0	d-----w-	c:\program files\Microsoft SQL Server<br />
2009-11-06 10:27:15	0	d-----w-	c:\program files\Microsoft Device Emulator<br />
2009-11-06 10:24:16	0	d-----w-	c:\program files\Windows Mobile 5.0 SDK R2<br />
2009-11-06 10:22:58	0	d-----w-	c:\program files\Microsoft SQL Server Compact Edition<br />
2009-11-06 10:09:52	0	d-----w-	c:\programdata\PreEmptive Solutions<br />
2009-11-06 09:57:47	0	d-----w-	c:\windows\system32\1033<br />
2009-11-06 09:55:16	0	d-----w-	c:\program files\HTML Help Workshop<br />
2009-11-06 09:55:16	0	d-----w-	c:\program files\common files\Merge Modules<br />
2009-11-06 09:55:15	0	d-----w-	c:\program files\CE Remote Tools<br />
2009-11-06 09:51:49	0	d-----w-	c:\program files\Microsoft Web Designer Tools<br />
2009-11-06 05:20:09	0	d-----w-	c:\users\karlo\appdata\roaming\MySQL<br />
2009-11-06 05:18:08	232	----a-w-	c:\windows\ODBCINST.INI<br />
2009-11-06 03:50:48	0	d-----w-	c:\users\karlo\.netbeans<br />
2009-11-06 03:50:46	0	d-----w-	c:\users\karlo\.netbeans-registration<br />
2009-11-06 03:50:01	0	d-----w-	c:\program files\sges-v3-prelude<br />
2009-11-06 03:49:56	120	----a-w-	c:\users\karlo\.asadminpass<br />
2009-11-06 03:49:34	793	----a-w-	c:\users\karlo\.asadmintruststore<br />
2009-11-06 03:46:38	0	d-----w-	C:\Sun<br />
2009-11-06 03:34:08	0	----a-w-	c:\users\karlo\.javafx_eula_accepted<br />
2009-11-06 03:27:16	0	d-----w-	c:\program files\NetBeans 6.7.1<br />
2009-11-06 03:25:24	0	d-----w-	c:\program files\Sun<br />
2009-11-06 03:16:49	0	d-----w-	c:\users\karlo\.nbi<br />
2009-11-03 10:43:09	0	d-----w-	c:\program files\Folder Icon Changer<br />
2009-11-01 12:35:03	0	d-----w-	c:\program files\SystemRequirementsLab<br />
2009-11-01 07:11:16	0	d-----w-	c:\program files\common files\Futuremark Shared<br />
2009-11-01 06:58:05	0	d-----w-	c:\program files\Windows Portable Devices<br />
2009-11-01 06:57:15	0	---ha-w-	c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf<br />
2009-11-01 06:56:34	0	---ha-w-	c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf<br />
2009-11-01 06:19:34	92672	----a-w-	c:\windows\system32\UIAnimation.dll<br />
2009-11-01 06:19:34	3023360	----a-w-	c:\windows\system32\UIRibbon.dll<br />
2009-11-01 06:19:34	1164800	----a-w-	c:\windows\system32\UIRibbonRes.dll<br />
2009-11-01 06:17:42	81920	----a-w-	c:\windows\system32\wpdbusenum.dll<br />
2009-11-01 06:16:16	4096	----a-w-	c:\windows\system32\oleaccrc.dll<br />
2009-11-01 06:16:15	555520	----a-w-	c:\windows\system32\UIAutomationCore.dll<br />
2009-11-01 06:16:15	234496	----a-w-	c:\windows\system32\oleacc.dll<br />
2009-10-31 16:03:49	0	d-----w-	c:\users\karlo\appdata\roaming\uTorrent<br />
2009-10-29 22:33:35	0	d-----w-	c:\windows\system32\eu-ES<br />
2009-10-29 22:33:35	0	d-----w-	c:\windows\system32\ca-ES<br />
2009-10-29 22:33:24	0	d-----w-	c:\windows\system32\vi-VN<br />
2009-10-29 22:23:01	0	d-----w-	c:\windows\system32\SPReview<br />
2009-10-29 22:10:37	928768	----a-w-	c:\windows\system32\scavenge.dll<br />
2009-10-29 22:10:26	57856	----a-w-	c:\windows\system32\compcln.exe<br />
2009-10-29 22:07:57	148480	----a-w-	c:\windows\system32\drivers\nwifi.sys<br />
2009-10-29 22:06:59	1645568	----a-w-	c:\windows\system32\connect.dll<br />
2009-10-29 22:05:38	208896	----a-w-	c:\windows\system32\mfplat.dll<br />
2009-10-29 22:02:38	0	d-----w-	c:\windows\system32\EventProviders<br />
2009-10-29 15:15:49	0	d-----w-	c:\users\karlo\appdata\roaming\Uniblue<br />
2009-10-29 14:48:57	647168	----a-w-	c:\windows\system32\aestecap.dll<br />
2009-10-29 14:48:57	53248	----a-w-	c:\windows\system32\aestaren.dll<br />
2009-10-29 14:48:57	4947968	----a-w-	c:\windows\system32\stacgui.cpl<br />
2009-10-29 14:48:57	1601536	----a-w-	c:\windows\system32\stlang.dll<br />
2009-10-29 14:48:57	131072	----a-w-	c:\windows\system32\aestacap.dll<br />
2009-10-29 14:48:57	102400	----a-w-	c:\windows\system32\stacsv.exe<br />
2009-10-29 14:46:53	595456	----a-w-	c:\windows\system32\stapo.dll<br />
2009-10-29 14:46:53	328704	----a-w-	c:\windows\system32\stcplx.dll<br />
2009-10-29 14:46:53	299520	----a-w-	c:\windows\system32\stapi32.dll<br />
2009-10-29 12:03:43	0	d-----w-	c:\program files\Free Fire Screensaver<br />
2009-10-29 12:03:35	0	d-----w-	c:\users\karlo\appdata\roaming\Laconic Software<br />
2009-10-28 15:43:26	48	----a-w-	c:\windows\iltwain.ini<br />
2009-10-28 15:28:28	0	d-----w-	c:\program files\AveIconifier2<br />
2009-10-28 13:37:18	3600456	----a-w-	c:\windows\system32\ntkrnlpa.exe<br />
2009-10-28 13:37:17	3548216	----a-w-	c:\windows\system32\ntoskrnl.exe<br />
2009-10-28 13:35:21	60928	----a-w-	c:\windows\system32\msasn1.dll<br />
2009-10-28 13:34:54	144896	----a-w-	c:\windows\system32\drivers\srv2.sys<br />
2009-10-28 13:34:35	310784	----a-w-	c:\windows\system32\unregmp2.exe<br />
2009-10-28 13:34:34	8147456	----a-w-	c:\windows\system32\wmploc.DLL<br />
2009-10-28 13:34:25	0	d-----w-	c:\users\karlo\appdata\roaming\OtakuSoftware<br />
2009-10-28 13:34:02	604672	----a-w-	c:\windows\system32\WMSPDMOD.DLL<br />
2009-10-28 12:08:25	0	d-----w-	c:\program files\CodeGazer<br />
2009-10-28 12:04:13	0	d-----w-	c:\program files\DeskSpace<br />
2009-10-21 10:48:22	2421760	----a-w-	c:\windows\system32\wucltux.dll<br />
2009-10-21 10:48:14	87552	----a-w-	c:\windows\system32\wudriver.dll<br />
2009-10-21 10:48:09	33792	----a-w-	c:\windows\system32\wuapp.exe<br />
2009-10-21 10:48:09	171608	----a-w-	c:\windows\system32\wuwebv.dll<br />
2009-10-16 12:42:13	218624	----a-w-	c:\windows\system32\msv1_0.dll<br />
2009-10-16 12:39:52	0	d-----w-	c:\windows\system32\AGEIA<br />
2009-10-16 12:39:28	0	d-----w-	c:\program files\common files\Wise Installation Wizard<br />
2009-10-14 12:54:19	8457	----a-w-	c:\windows\system32\SpoonUninstall-dBpoweramp DSP Effects.dat<br />
2009-10-14 12:54:19	33846	----a-w-	c:\windows\system32\SpoonUninstall-dBpoweramp DSP Effects.bmp<br />
2009-10-14 12:54:13	33846	----a-w-	c:\windows\system32\SpoonUninstall-dBpoweramp Music Converter.bmp<br />
2009-10-14 12:54:13	13281	----a-w-	c:\windows\system32\SpoonUninstall-dBpoweramp Music Converter.dat<br />
2009-10-14 12:54:09	0	d-----w-	c:\program files\Illustrate<br />
2009-10-14 08:50:14	327680	----a-w-	c:\windows\system32\vp6dec.ax<br />
<br />
==================== Find3M  ====================<br />
<br />
2009-11-11 13:20:13	131587	----a-w-	c:\users\karlo\appdata\roaming\nvModes.dat<br />
2009-11-09 11:27:47	51200	----a-w-	c:\windows\inf\infpub.dat<br />
2009-11-09 11:27:47	143360	----a-w-	c:\windows\inf\infstrng.dat<br />
2009-11-09 11:27:45	86016	----a-w-	c:\windows\inf\infstor.dat<br />
2009-11-01 06:57:24	665600	----a-w-	c:\windows\inf\drvindex.dat<br />
2009-10-29 23:02:21	615424	----a-w-	c:\windows\system32\themeui.dll<br />
2009-10-29 22:19:40	37665	----a-w-	c:\windows\fonts\GlobalUserInterface.CompositeFont<br />
2009-10-28 12:10:03	240128	----a-w-	c:\windows\system32\uxtheme.dll<br />
2009-10-08 01:02:10	43520	----a-w-	c:\windows\system32\CmdLineExt03.dll<br />
2009-10-03 01:43:01	28672	----a-w-	c:\windows\system32\death.dll<br />
2009-10-01 01:02:17	2537472	----a-w-	c:\windows\system32\wpdshext.dll<br />
2009-10-01 01:02:05	30208	----a-w-	c:\windows\system32\WPDShextAutoplay.exe<br />
2009-10-01 01:02:04	334848	----a-w-	c:\windows\system32\PortableDeviceApi.dll<br />
2009-10-01 01:02:02	87552	----a-w-	c:\windows\system32\WPDShServiceObj.dll<br />
2009-10-01 01:02:00	31232	----a-w-	c:\windows\system32\BthMtpContextHandler.dll<br />
2009-10-01 01:01:59	546816	----a-w-	c:\windows\system32\wpd_ci.dll<br />
2009-10-01 01:01:59	160256	----a-w-	c:\windows\system32\PortableDeviceTypes.dll<br />
2009-10-01 01:01:56	60928	----a-w-	c:\windows\system32\PortableDeviceConnectApi.dll<br />
2009-10-01 01:01:56	350208	----a-w-	c:\windows\system32\WPDSp.dll<br />
2009-10-01 01:01:56	196608	----a-w-	c:\windows\system32\PortableDeviceWMDRM.dll<br />
2009-10-01 01:01:56	100864	----a-w-	c:\windows\system32\PortableDeviceClassExtension.dll<br />
2009-10-01 01:01:54	40448	----a-w-	c:\windows\system32\drivers\WpdUsb.sys<br />
2009-10-01 01:01:50	226816	----a-w-	c:\windows\system32\WpdMtp.dll<br />
2009-10-01 01:01:49	61952	----a-w-	c:\windows\system32\WpdMtpUS.dll<br />
2009-10-01 01:01:49	33280	----a-w-	c:\windows\system32\WpdConns.dll<br />
2009-09-25 02:10:10	974848	----a-w-	c:\windows\system32\WindowsCodecs.dll<br />
2009-09-25 02:07:08	189440	----a-w-	c:\windows\system32\WindowsCodecsExt.dll<br />
2009-09-25 02:04:32	321024	----a-w-	c:\windows\system32\PhotoMetadataHandler.dll<br />
2009-09-25 01:49:22	1554432	----a-w-	c:\windows\system32\xpsservices.dll<br />
2009-09-25 01:48:08	351232	----a-w-	c:\windows\system32\XpsPrint.dll<br />
2009-09-25 01:38:29	847360	----a-w-	c:\windows\system32\OpcServices.dll<br />
2009-09-25 01:36:13	280064	----a-w-	c:\windows\system32\XpsGdiConverter.dll<br />
2009-09-25 01:35:31	135680	----a-w-	c:\windows\system32\XpsRasterService.dll<br />
2009-09-25 01:33:25	195584	----a-w-	c:\windows\system32\dxdiagn.dll<br />
2009-09-25 01:33:15	829440	----a-w-	c:\windows\system32\d3d10warp.dll<br />
2009-09-25 01:33:01	369664	----a-w-	c:\windows\system32\WMPhoto.dll<br />
2009-09-25 01:32:59	252928	----a-w-	c:\windows\system32\dxdiag.exe<br />
2009-09-25 01:31:53	519680	----a-w-	c:\windows\system32\d3d11.dll<br />
2009-09-25 01:31:26	486912	----a-w-	c:\windows\system32\d3d10level9.dll<br />
2009-09-25 01:31:21	161280	----a-w-	c:\windows\system32\d3d10_1.dll<br />
2009-09-25 01:31:19	218112	----a-w-	c:\windows\system32\d3d10_1core.dll<br />
2009-09-25 01:31:16	1030144	----a-w-	c:\windows\system32\d3d10.dll<br />
2009-09-25 01:31:15	828928	----a-w-	c:\windows\system32\d2d1.dll<br />
2009-09-25 01:30:23	481792	----a-w-	c:\windows\system32\dxgi.dll<br />
2009-09-25 01:30:23	190464	----a-w-	c:\windows\system32\d3d10core.dll<br />
2009-09-25 01:27:25	634880	----a-w-	c:\windows\system32\drivers\dxgkrnl.sys<br />
2009-09-25 01:27:04	793088	----a-w-	c:\windows\system32\FntCache.dll<br />
2009-09-25 01:27:04	37888	----a-w-	c:\windows\system32\cdd.dll<br />
2009-09-25 01:27:04	1064448	----a-w-	c:\windows\system32\DWrite.dll<br />
2009-09-24 22:54:55	258048	----a-w-	c:\windows\system32\winspool.drv<br />
2009-09-24 22:54:53	667648	----a-w-	c:\windows\system32\printfilterpipelinesvc.exe<br />
2009-09-24 22:54:52	26112	----a-w-	c:\windows\system32\printfilterpipelineprxy.dll<br />
2009-09-04 09:44:40	69464	----a-w-	c:\windows\system32\XAPOFX1_3.dll<br />
2009-09-04 09:44:40	515416	----a-w-	c:\windows\system32\XAudio2_5.dll<br />
2009-09-04 09:44:40	238936	----a-w-	c:\windows\system32\xactengine3_5.dll<br />
2009-09-04 09:29:34	453456	----a-w-	c:\windows\system32\d3dx10_42.dll<br />
2009-09-04 09:29:34	235344	----a-w-	c:\windows\system32\d3dx11_42.dll<br />
2009-09-04 09:29:32	5501792	----a-w-	c:\windows\system32\d3dcsx_42.dll<br />
2009-09-04 09:29:32	1974616	----a-w-	c:\windows\system32\D3DCompiler_42.dll<br />
2009-09-04 09:29:30	1892184	----a-w-	c:\windows\system32\D3DX9_42.dll<br />
2009-08-29 09:07:02	444952	----a-w-	c:\windows\system32\wrap_oal.dll<br />
2009-08-29 09:07:02	109080	----a-w-	c:\windows\system32\OpenAL32.dll<br />
2009-08-29 00:27:49	4240384	----a-w-	c:\windows\system32\GameUXLegacyGDFs.dll<br />
2009-08-29 00:14:38	28672	----a-w-	c:\windows\system32\Apphlpdm.dll<br />
2009-08-18 23:10:48	165153	----a-w-	c:\windows\hphins30.dat<br />
2009-08-17 15:33:52	1193832	----a-w-	c:\windows\system32\FM20.DLL<br />
2009-08-14 15:53:34	17920	----a-w-	c:\windows\system32\netevent.dll<br />
2009-08-14 13:49:20	9728	----a-w-	c:\windows\system32\TCPSVCS.EXE<br />
2009-08-14 13:49:18	17920	----a-w-	c:\windows\system32\ROUTE.EXE<br />
2009-08-14 13:49:18	11264	----a-w-	c:\windows\system32\MRINFO.EXE<br />
2009-08-14 13:49:15	27136	----a-w-	c:\windows\system32\NETSTAT.EXE<br />
2009-08-14 13:49:14	8704	----a-w-	c:\windows\system32\HOSTNAME.EXE<br />
2009-08-14 13:49:14	19968	----a-w-	c:\windows\system32\ARP.EXE<br />
2009-08-14 13:49:13	10240	----a-w-	c:\windows\system32\finger.exe<br />
2009-08-14 13:48:02	105984	----a-w-	c:\windows\system32\netiohlp.dll<br />
2009-08-14 05:36:18	70936	----a-w-	c:\windows\system32\PhysXLoader.dll<br />
2008-01-21 02:43:21	174	--sha-w-	c:\program files\desktop.ini<br />
2006-11-02 12:42:02	30674	----a-w-	c:\windows\inf\perflib\0409\perfd.dat<br />
2006-11-02 12:42:02	30674	----a-w-	c:\windows\inf\perflib\0409\perfc.dat<br />
2006-11-02 12:42:02	287440	----a-w-	c:\windows\inf\perflib\0409\perfi.dat<br />
2006-11-02 12:42:02	287440	----a-w-	c:\windows\inf\perflib\0409\perfh.dat<br />
2006-11-02 09:20:21	287440	----a-w-	c:\windows\inf\perflib\0000\perfi.dat<br />
2006-11-02 09:20:21	287440	----a-w-	c:\windows\inf\perflib\0000\perfh.dat<br />
2006-11-02 09:20:19	30674	----a-w-	c:\windows\inf\perflib\0000\perfd.dat<br />
2006-11-02 09:20:19	30674	----a-w-	c:\windows\inf\perflib\0000\perfc.dat<br />
2009-05-20 05:25:53	74	--sh--r-	c:\windows\CT4CET.bin<br />
2009-07-23 10:03:25	30	--sha-r-	c:\windows\pc-off.bat<br />
<br />
============= FINISH: 22:25:16.72 ===============</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techsupportforum.com/cwd/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techsupportforum.com/attachments/hijackthis-log-help-inactive/60054d1257950722-my-dell-xps-m1330-sp2-keeps-freezing-dds.txt">DDS.txt</a> (19.7 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techsupportforum.com/cwd/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techsupportforum.com/attachments/hijackthis-log-help-inactive/60055d1257950997-my-dell-xps-m1330-sp2-keeps-freezing-hijackthis.txt">hijackthis.txt</a> (5.5 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techsupportforum.com/cwd/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techsupportforum.com/attachments/hijackthis-log-help-inactive/60056d1257952344-my-dell-xps-m1330-sp2-keeps-freezing-ark.txt">ark.txt</a> (18.8 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/">HijackThis Log Help (Inactive)</category>
			<dc:creator>Bob_Binky</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/430689-my-dell-xps-m1330-sp2-keeps-freezing.html</guid>
		</item>
		<item>
			<title>Slow as heck computer getting slower.</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/430575-slow-heck-computer-getting-slower.html</link>
			<pubDate>Wed, 11 Nov 2009 04:11:29 GMT</pubDate>
			<description><![CDATA[DDS (Ver_09-10-26.01) - NTFSx86   
Run by Barnes Daphne at 20:50:57.00 on Tue 11/10/2009 
Internet Explorer: 7.0.5730.13 
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.255.28 [GMT -7:00] 
 
FW: McAfee Personal Firewall *enabled*   {94894B63-8C7F-4050-BDA4-813CA00DA3E8} 
...]]></description>
			<content:encoded><![CDATA[<div>DDS (Ver_09-10-26.01) - NTFSx86  <br />
Run by Barnes Daphne at 20:50:57.00 on Tue 11/10/2009<br />
Internet Explorer: 7.0.5730.13<br />
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.255.28 [GMT -7:00]<br />
<br />
FW: McAfee Personal Firewall *enabled*   {94894B63-8C7F-4050-BDA4-813CA00DA3E8}<br />
<br />
============== Running Processes ===============<br />
<br />
C:\WINDOWS\system32\svchost -k DcomLaunch<br />
svchost.exe<br />
C:\WINDOWS\System32\svchost.exe -k netsvcs<br />
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup<br />
svchost.exe<br />
svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
svchost.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe<br />
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe<br />
C:\WINDOWS\System32\svchost.exe -k HTTPFilter<br />
C:\Program Files\CA\eTrust Antivirus\InoRpc.exe<br />
C:\Program Files\CA\eTrust Antivirus\InoRT.exe<br />
C:\Program Files\CA\eTrust Antivirus\InoTask.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br />
C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
C:\WINDOWS\system32\HPZipm12.exe<br />
C:\WINDOWS\System32\svchost.exe -k imgsvc<br />
c:\PROGRA~1\mcafee.com\agent\mcagent.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
c:\SafetyCenter\new.exe<br />
C:\PROGRA~1\CA\ETRUST~1\realmon.exe<br />
C:\Program Files\Linksys\LinksysDiag\LinksysDiag.exe<br />
C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe<br />
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe<br />
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe<br />
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\WINDOWS\explorer.exe<br />
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
C:\WINDOWS\System32\mshta.exe<br />
C:\WINDOWS\system32\taskmgr.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
C:\Documents and Settings\barnes daphne\Desktop\dds.com<br />
<br />
============== Pseudo HJT Report ===============<br />
<br />
uStart Page = <a href="https://remoteaccess.newworldsystems.com/dana-na/auth/url_default/welcome.cgi" target="_blank">https://remoteaccess.newworldsystems...lt/welcome.cgi</a><br />
uSearch Page = hxxp://www.google.com<br />
uSearch Bar = hxxp://www.google.com/ie<br />
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&amp;sourceid=ie7&amp;rls=com.microsoft:en-US&amp;ie=utf8&amp;oe=utf8<br />
uInternet Connection Wizard,ShellNext = iexplore<br />
uSearchAssistant = hxxp://www.google.com/ie<br />
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s<br />
mSearchAssistant = hxxp://www.google.com/ie<br />
BHO: c:\windows\system32\l5j65syo8.dll: {a45a4b15-23f2-42ad-f4e4-00aac39c0004} - c:\windows\system32\l5j65syo8.dll<br />
TB: {BA52B914-B692-46c4-B683-905236F6F655} - No File<br />
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll<br />
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File<br />
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File<br />
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe<br />
uRun: [updateMgr] &quot;c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe&quot; AcRdB7_0_9 -reboot 1<br />
uRun: [MsnMsgr] &quot;c:\program files\windows live\messenger\MsnMsgr.Exe&quot; /background<br />
uRun: [swg] &quot;c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe&quot;<br />
uRun: [calc] rundll32.exe c:\windows\system32\config\system~1\ntuser.dll,_IWMPEvents@0<br />
uRun: [A00FD1BD189.exe] c:\docume~1\barnes~1\locals~1\temp\_A00FD1BD189.exe<br />
uRun: [BackUp Windows 2009] c:\docume~1\barnes~1\locals~1\temp\q7o6ky.exe<br />
uRun: [Yjafosi8kdf98winmdkmnkmfnwe] c:\docume~1\barnes~1\locals~1\temp\csrss.exe<br />
uRun: [fontatmgfx] rundll32.exe &quot;c:\documents and settings\barnes daphne\local settings\application data\fontatmgfx\fontatmgfx.dll&quot;, DllInit<br />
uRun: [AntiVirus Plus] &quot;c:\windows\system32\rundll32.exe&quot; &quot;c:\documents and settings\barnes daphne\application data\antivirus plus\AntiVirus Plus.70367.dll&quot;, start 70367<br />
mRun: [Realtime Monitor] c:\progra~1\ca\etrust~1\realmon.exe -s<br />
mRun: [&lt;NO NAME&gt;] <br />
mRun: [LinksysDiag] c:\program files\linksys\linksysdiag\LinksysDiag /hw<br />
mRun: [VerizonServicepoint.exe] c:\program files\verizon\servicepoint\VerizonServicepoint.exe<br />
mRun: [GrooveMonitor] &quot;c:\program files\microsoft office\office12\GrooveMonitor.exe&quot;<br />
mRun: [mxomssmenu] &quot;c:\program files\maxtor\onetouch status\maxmenumgr.exe&quot;<br />
mRun: [mcagent_exe] &quot;c:\program files\mcafee.com\agent\mcagent.exe&quot; /runkey<br />
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe<br />
mRun: [BlackBerryAutoUpdate] c:\program files\common files\research in motion\auto update\RIMAutoUpdate.exe /background<br />
mRun: [Verizon Custom Uninstall Tracking] c:\docume~1\barnes~1\locals~1\temp\InstallHelper.exe /uninstalltrackingvendor=Verizon<br />
mRun: [calc] rundll32.exe c:\windows\system32\calc.dll,_IWMPEvents@0<br />
mRun: [Tlohukowomaqude] rundll32.exe &quot;c:\windows\orezakoboxa.dll&quot;,Startup<br />
mRun: [bowihaveg] Rundll32.exe &quot;c:\windows\system32\zokumuyi.dll&quot;,a<br />
mRun: [AntiVirus Plus] &quot;c:\windows\system32\rundll32.exe&quot; &quot;c:\documents and settings\barnes daphne\application data\antivirus plus\AntiVirus Plus.70367.dll&quot;, start 70367<br />
mRun: [Adobe Photo Downloader] &quot;c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe&quot;<br />
mRunOnce: [SafetyCenter] c:\safetycenter\start.exe<br />
uPolicies-explorer: NoFolderOptions = 1 (0x1)<br />
uPolicies-system: DisableRegistryTools = 1 (0x1)<br />
mPolicies-system: EnableLUA = 0 (0x0)<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000<br />
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL<br />
Trusted Zone: newworldsystems.com\remoteaccess<br />
Trusted Zone: turbotax.com<br />
DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxps://activatemyfios.verizon.net/sdcCommon/download/FIOS/tgctlcm.cab<br />
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab<br />
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://go.microsoft.com/fwlink/?linkid=58813<br />
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab<br />
DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - hxxp://www.musicnotes.com/download/mnviewer.cab<br />
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab<br />
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204<br />
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab<br />
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc.cab<br />
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos.walmart.com/WalmartActivia.cab<br />
DPF: {49232000-16E4-426C-A231-62846947304B} - hxxp://ipgweb.cce.hp.com/rdqnbk/downloads/sysinfo.cab<br />
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab<br />
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab<br />
DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - hxxp://www.nick.com/common/groove/gx/GrooveAX27.cab<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab<br />
DPF: {A8683C98-5341-421B-B23C-8514C05354F1} - hxxp://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab<br />
DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} - hxxps://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx<br />
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab<br />
DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxp://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab<br />
DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-1_4_2_06-windows-i586.cab<br />
DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab<br />
DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab<br />
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab<br />
DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - hxxp://fdl.msn.com/zone/datafiles/heartbeat.cab<br />
DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} - hxxps://remoteaccess.newworldsystems.com/dana-cached/setup/JuniperSetupSP1.cab<br />
TCP: {4EB3E8F2-627B-496E-9309-9F260945AE48} = 77.74.48.113<br />
TCP: {68F56C44-7E92-43B7-AFCA-9FDD4007C93A} = 77.74.48.113<br />
TCP: {B09D5833-AC6E-4729-98B3-7077E0E5606C} = 77.74.48.113<br />
Filter: text/html - {2ee1b2e9-4530-4982-8345-8466216982b3} - c:\windows\mark_32.dll<br />
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll<br />
Notify: __c00EF6A9 - c:\windows\system32\__c00EF6A9.dat<br />
AppInit_DLLs: bedikupo.dll c:\windows\system32\zokumuyi.dll<br />
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll<br />
SSODL: wuzowubij - {0e6096bd-9bd4-4c81-8d89-168c6a7f5b78} - c:\windows\system32\zokumuyi.dll<br />
STS: c:\windows\system32\l5j65syo8.dll: {a45a4b15-23f2-42ad-f4e4-00aac39c0004} - c:\windows\system32\l5j65syo8.dll<br />
STS: kupuhivus: {0e6096bd-9bd4-4c81-8d89-168c6a7f5b78} - c:\windows\system32\zokumuyi.dll<br />
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll<br />
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll<br />
LSA: Notification Packages = scecli jifusawo.dll mngseli.dll<br />
<br />
============= SERVICES / DRIVERS ===============<br />
<br />
R? BEFCMU10V4XP;Linksys BEFCMU10 ver. 4 Cable Modem<br />
R? hamachi_oem;PlayLinc Adapter<br />
R? NC100;Network Everywhere Fast Ethernet Adapter(NC100 v2)<br />
R? ncvcp;Network Connect Virtual Com Port<br />
R? Radialpoint Security Services;Radialpoint Security Services<br />
R? RTLVLANMP;Linksys Virtual Adapter<br />
R? RTLVLANXP;Linksys VLAN Intermediate Driver<br />
S? Cinemsup;Cinemsup<br />
S? Diag69xp;Diag69xp<br />
S? LANPkt;Linksys LANPkt Protocol Driver<br />
S? Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service<br />
S? Lbd;Lbd<br />
S? Maxtor Sync Service;Maxtor Service<br />
<br />
=============== Created Last 30 ================<br />
<br />
2009-11-10 05:58:49	15688	----a-w-	c:\windows\system32\lsdelete.exe<br />
2009-11-09 07:52:44	64288	----a-w-	c:\windows\system32\drivers\Lbd.sys<br />
2009-11-09 07:50:56	0	dc-h--w-	c:\docume~1\alluse~1\applic~1\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}<br />
2009-11-09 04:02:18	27413	----a-w-	c:\windows\system32\Config.MPF<br />
2009-11-09 02:04:04	0	d-----w-	c:\docume~1\barnes~1\applic~1\AntiVirus Plus<br />
2009-11-09 02:02:04	0	----a-w-	c:\windows\Qsubo.bin<br />
2009-11-09 02:02:03	120	----a-w-	c:\windows\Lgeturu.dat<br />
2009-11-09 02:00:57	2198	----a-w-	C:\aLySy.bat<br />
2009-11-09 02:00:09	0	d-----w-	C:\SafetyCenter<br />
2009-11-09 01:56:59	27648	----a-w-	c:\windows\system32\__c00EF6A9.dat<br />
2009-11-09 01:56:57	15000	----a-w-	c:\windows\system32\l5j65syo8.dll<br />
2009-11-09 01:56:44	37376	----a-w-	C:\oqbkddrr.exe<br />
2009-11-09 01:56:43	52224	----a-w-	C:\ydlcgx.exe<br />
2009-11-09 01:56:41	52736	----a-w-	C:\luobk.exe<br />
2009-11-09 01:55:24	0	--sha-w-	C:\12104718<br />
<br />
==================== Find3M  ====================<br />
<br />
2009-11-06 19:16:04	1632	----a-w-	c:\windows\system32\d3d8caps.dat<br />
2009-11-03 20:08:09	1744	----a-w-	c:\windows\system32\d3d9caps.dat<br />
2009-09-11 14:33:52	133632	----a-w-	c:\windows\system32\msv1_0.dll<br />
2009-09-04 20:45:26	58880	----a-w-	c:\windows\system32\msasn1.dll<br />
2009-08-29 07:36:27	832512	----a-w-	c:\windows\system32\wininet.dll<br />
2009-08-29 07:36:24	78336	----a-w-	c:\windows\system32\ieencode.dll<br />
2009-08-29 07:36:24	17408	------w-	c:\windows\system32\corpol.dll<br />
2009-08-26 08:16:37	247326	----a-w-	c:\windows\system32\strmdll.dll<br />
2009-08-18 05:33:52	1193832	----a-w-	c:\windows\system32\FM20.DLL<br />
2009-08-09 01:56:52	52736	--sha-w-	c:\windows\system32\bedikupo.dll<br />
2009-03-21 14:18:57	24064	--sha-w-	c:\windows\system32\calc.dll<br />
2009-08-09 01:56:52	52736	--sha-w-	c:\windows\system32\hipehuko.dll<br />
2009-08-09 01:56:52	52736	--sha-w-	c:\windows\system32\jifusawo.dll<br />
2009-08-09 02:02:53	107008	--sha-w-	c:\windows\system32\kihebopa.exe<br />
2009-08-09 02:02:53	45056	--sha-w-	c:\windows\system32\kivobimo.dll<br />
2009-08-09 02:02:54	39424	--sha-w-	c:\windows\system32\vozasela.dll<br />
2009-08-09 02:02:53	92672	--sha-w-	c:\windows\system32\zokumuyi.dll<br />
2009-03-21 14:18:57	24064	--sha-w-	c:\windows\system32\config\systemprofile\start menu\programs\startup\scandisk.dll<br />
<br />
============= FINISH: 20:55:01.76 =============== <br />
<br />
We could not get the Attach.zip, it only showed up with 1 log file. The program is called Antivirus Plus that is attacking us. This is a repost from An already slow computer getting slower. Here is the contents. My computer is Windows XP, a few years old. And we have a problem. There is a virus scan, well, virus. It is a fake program called Antivirus Plus. It just pops up with tons of little things saying something is wrong. We can't even access the internet on it. It already was slow, now, it is dying.</div>

]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/">HijackThis Log Help (Inactive)</category>
			<dc:creator>cdabrnes</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/430575-slow-heck-computer-getting-slower.html</guid>
		</item>
		<item>
			<title>Help - issue with trojan/cannot get rid</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/430716-help-issue-trojan-cannot-get-rid.html</link>
			<pubDate>Tue, 10 Nov 2009 19:36:03 GMT</pubDate>
			<description><![CDATA[trojan SC/Win32.Agent.fbx and PUPSC following download of Live Player, only picked up by running Spybot, and not by McAfee, worryingly! 
 
Now runing slow and cannot get on many websites I use daily. 
 
I've tried a system restore to before I downloaded live player and also tried to unistall it,...]]></description>
			<content:encoded><![CDATA[<div>trojan SC/Win32.Agent.fbx and PUPSC following download of Live Player, only picked up by running Spybot, and not by McAfee, worryingly!<br />
<br />
Now runing slow and cannot get on many websites I use daily.<br />
<br />
I've tried a system restore to before I downloaded live player and also tried to unistall it, but it won't let me.<br />
<br />
Please help.<br />
<br />
Many thanks<br />
<br />
Jane Downs<br />
<br />
PS  I've also attached everything you asked for, I think :o)<br />
<br />
<br />
<br />
DDS (Ver_09-10-26.01) - NTFSx86  <br />
Run by Jane at 19:13:26.34 on 10/11/2009<br />
Internet Explorer: 8.0.6001.18828<br />
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.44.1033.18.3034.1572 [GMT 0:00]<br />
<br />
SP: Spybot - Search and Destroy *enabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}<br />
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}<br />
<br />
============== Running Processes ===============<br />
<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\svchost.exe -k rpcss<br />
C:\Windows\System32\svchost.exe -k secsvcs<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\STacSV.exe<br />
C:\Windows\system32\svchost.exe -k GPSvcGroup<br />
C:\Windows\system32\SLsvc.exe<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\System32\WLTRYSVC.EXE<br />
C:\Windows\System32\bcmwltry.exe<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\aestsrv.exe<br />
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe<br />
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
C:\Windows\system32\rundll32.exe<br />
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
C:\Program Files\McAfee\MSK\MskSrver.exe<br />
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe<br />
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe<br />
C:\Windows\system32\svchost.exe -k imgsvc<br />
C:\Windows\System32\svchost.exe -k WerSvcGroup<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Program Files\Webroot\Washer\WasherSvc.exe<br />
C:\Windows\system32\RUNDLL32.EXE<br />
C:\Program Files\Spybot - Search &amp; Destroy\SDWinSec.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe<br />
c:\PROGRA~1\mcafee.com\agent\mcagent.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\DellTPad\Apoint.exe<br />
C:\Windows\System32\WLTRAY.EXE<br />
C:\Program Files\Dell\QuickSet\quickset.exe<br />
C:\Windows\System32\igfxtray.exe<br />
C:\Windows\System32\igfxpers.exe<br />
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br />
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe<br />
C:\Program Files\McAfee\Anti-Theft\McPvTray.exe<br />
C:\Windows\system32\igfxsrvc.exe<br />
C:\Program Files\IDT\WDM\sttray.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Program Files\Webroot\Washer\wwDisp.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Program Files\AIM6\aim6.exe<br />
C:\Program Files\DellTPad\Apntex.exe<br />
C:\Program Files\DellTPad\HidFind.exe<br />
C:\Program Files\AIM6\aolsoftware.exe<br />
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe<br />
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Windows\System32\wsqmcons.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Users\Jane\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Jane\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Jane\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Windows\system32\SearchProtocolHost.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Users\Jane\Documents\Downloads\dds.scr<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Users\Jane\Documents\Downloads\dds.scr<br />
<br />
============== Pseudo HJT Report ===============<br />
<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll<br />
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll<br />
BHO: Spybot-S&amp;D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search &amp; destroy\SDHelper.dll<br />
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File<br />
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll<br />
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll<br />
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll<br />
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll<br />
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun<br />
uRun: [Google Update] &quot;c:\users\jane\appdata\local\google\update\GoogleUpdate.exe&quot; /c<br />
uRun: [Window Washer] c:\program files\webroot\washer\wwDisp.exe<br />
uRun: [msnmsgr] &quot;c:\program files\windows live\messenger\msnmsgr.exe&quot; /background<br />
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search &amp; destroy\TeaTimer.exe<br />
uRun: [Aim6] &quot;c:\program files\aim6\aim6.exe&quot; /d locale=en-GB ee://aol/imApp<br />
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
mRun: [Apoint] c:\program files\delltpad\Apoint.exe<br />
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe<br />
mRun: [QuickSet] c:\program files\dell\quickset\QuickSet.exe<br />
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe<br />
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe<br />
mRun: [Persistence] c:\windows\system32\igfxpers.exe<br />
mRun: [mcagent_exe] &quot;c:\program files\mcafee.com\agent\mcagent.exe&quot; /runkey<br />
mRun: [McENUI] c:\progra~1\mcafee\mhn\McENUI.exe /hide<br />
mRun: [DELL Webcam Manager] &quot;c:\program files\dell\dell webcam manager\DellWMgr.exe&quot; /s<br />
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup<br />
mRun: [ISUSScheduler] &quot;c:\program files\common files\installshield\updateservice\issch.exe&quot; -start<br />
mRun: [&lt;NO NAME&gt;] <br />
mRun: [RoxWatchTray] &quot;c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe&quot;<br />
mRun: [McPvTray] c:\program files\mcafee\anti-theft\McPvTray.exe<br />
mRun: [Adobe Reader Speed Launcher] &quot;c:\program files\adobe\reader 9.0\reader\Reader_sl.exe&quot;<br />
mRun: [Adobe ARM] &quot;c:\program files\common files\adobe\arm\1.0\AdobeARM.exe&quot;<br />
mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe<br />
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search &amp; destroy\SDHelper.dll<br />
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab<br />
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll<br />
Notify: igfxcui - igfxdev.dll<br />
<br />
============= SERVICES / DRIVERS ===============<br />
<br />
R0 McPvDrv;McPvDrv;c:\windows\system32\drivers\McPvDrv.sys [2008-5-28 61688]<br />
R1 RapportKELL;RapportKELL;c:\program files\trusteer\rapport\bin\RapportKELL.sys [2009-10-20 58984]<br />
R1 RapportPG;RapportPG;c:\program files\trusteer\rapport\bin\RapportPG.sys [2009-10-20 334440]<br />
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_ae0b52e0\AEstSrv.exe [2009-10-22 81920]<br />
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-10-22 210216]<br />
R2 RapportMgmtService;Rapport Management Service;c:\program files\trusteer\rapport\bin\RapportMgmtService.exe [2009-10-20 972008]<br />
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search &amp; destroy\SDWinSec.exe [2009-10-22 1153368]<br />
R2 wwEngineSvc;Window Washer Engine;c:\program files\webroot\washer\WasherSvc.exe [2009-10-22 598856]<br />
R2 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx32coinst,serviceStartProc --&gt; RUNDLL32.EXE ykx32coinst,serviceStartProc [?]<br />
R3 OA009Ufd;Creative Camera OA009 Upper Filter Driver;c:\windows\system32\drivers\OA009Ufd.sys [2009-3-6 133632]<br />
R3 OA009Vid;Creative Camera OA009 Function Driver;c:\windows\system32\drivers\OA009Vid.sys [2009-3-19 271552]<br />
<br />
=============== Created Last 30 ================<br />
<br />
2009-11-10 17:37:11	195456	------w-	c:\windows\system32\MpSigStub.exe<br />
2009-11-09 22:12:22	2421760	----a-w-	c:\windows\system32\wucltux.dll<br />
2009-11-09 22:11:49	87552	----a-w-	c:\windows\system32\wudriver.dll<br />
2009-11-09 22:11:25	33792	----a-w-	c:\windows\system32\wuapp.exe<br />
2009-11-09 22:11:25	171608	----a-w-	c:\windows\system32\wuwebv.dll<br />
2009-10-25 13:29:05	0	d-----w-	c:\program files\Live-Player<br />
2009-10-24 19:10:07	9728	----a-w-	c:\users\jane\Letter template.wps<br />
2009-10-24 19:06:13	82	----a-w-	c:\users\jane\appdata\roaming\wklnhst.dat<br />
2009-10-24 09:03:56	0	d-----w-	c:\windows\system32\eu-ES<br />
2009-10-24 09:03:56	0	d-----w-	c:\windows\system32\ca-ES<br />
2009-10-24 09:03:55	0	d-----w-	c:\windows\system32\vi-VN<br />
2009-10-24 08:46:40	0	d-----w-	c:\windows\system32\EventProviders<br />
2009-10-23 18:27:54	0	d-----w-	c:\programdata\Adobe<br />
2009-10-23 12:07:40	0	d-----w-	c:\program files\MSXML 4.0<br />
2009-10-23 12:06:12	12240896	----a-w-	c:\windows\system32\NlsLexicons0007.dll<br />
2009-10-23 12:06:07	3408896	----a-w-	c:\windows\system32\SLsvc.exe<br />
2009-10-23 12:06:07	1081344	----a-w-	c:\windows\system32\SLCExt.dll<br />
2009-10-23 12:06:05	65536	----a-w-	c:\windows\system32\DevicePairingWizard.exe<br />
2009-10-23 12:06:05	2134528	----a-w-	c:\windows\system32\FunctionDiscoveryFolder.dll<br />
2009-10-23 12:06:03	2644480	----a-w-	c:\windows\system32\NlsLexicons0009.dll<br />
2009-10-23 12:06:01	1480704	----a-w-	c:\windows\system32\mssrch.dll<br />
2009-10-23 12:04:59	97792	----a-w-	c:\windows\system32\mprapi.dll<br />
2009-10-23 08:13:49	0	d-----w-	c:\programdata\McAfee Anti-Theft<br />
2009-10-22 23:10:25	0	d-----w-	c:\users\jane\appdata\roaming\Spotify<br />
2009-10-22 23:10:23	0	d-----w-	c:\program files\Spotify<br />
2009-10-22 21:38:17	0	d-----w-	c:\programdata\AOL OCP<br />
2009-10-22 21:38:14	0	d-----w-	c:\programdata\AOL<br />
2009-10-22 21:38:06	0	d-----w-	c:\programdata\Viewpoint<br />
2009-10-22 21:38:05	0	d-----w-	c:\program files\Viewpoint<br />
2009-10-22 21:37:37	0	d-----w-	c:\program files\common files\AOL<br />
2009-10-22 21:37:31	0	d-----w-	c:\program files\AIM6<br />
2009-10-22 21:34:30	0	d-----w-	c:\programdata\AOL Downloads<br />
2009-10-22 21:34:25	989	---ha-w-	C:\IPH.PH<br />
2009-10-22 20:02:36	0	d-----w-	c:\windows\Panther<br />
2009-10-22 20:02:31	8192	--s-a-r-	C:\BOOTSECT.BAK<br />
2009-10-22 20:02:30	333257	--sha-r-	C:\bootmgr<br />
2009-10-22 20:02:30	0	d-sh--w-	C:\Boot<br />
2009-10-22 20:02:11	24	---ha-r-	c:\windows\dell_version<br />
2009-10-22 20:02:11	0	d-----w-	c:\windows\system32\OEM<br />
2009-10-22 17:29:32	0	d-----w-	c:\users\jane\appdata\roaming\Trusteer<br />
2009-10-22 17:29:26	0	d-----w-	c:\program files\Trusteer<br />
2009-10-22 17:28:44	0	d-----w-	c:\programdata\Trusteer<br />
2009-10-22 14:30:08	99176	----a-w-	c:\windows\system32\drivers\DRVMCDB.SYS<br />
2009-10-22 14:30:08	51768	----a-w-	c:\windows\system32\drivers\DRVNDDM.SYS<br />
2009-10-22 14:30:07	92920	----a-w-	c:\windows\DLA.EXE<br />
2009-10-22 14:30:07	56056	----a-w-	c:\windows\system32\DLAAPI_W.DLL<br />
2009-10-22 14:30:07	28120	----a-w-	c:\windows\system32\drivers\DLARTL_M.SYS<br />
2009-10-22 14:30:07	12856	----a-w-	c:\windows\system32\drivers\DLACDBHM.SYS<br />
2009-10-22 14:30:07	120	----a-w-	c:\windows\wininit.ini<br />
2009-10-22 14:30:07	0	d-----w-	c:\windows\system32\DLA<br />
2009-10-22 14:27:07	0	d-----w-	c:\programdata\Roxio<br />
2009-10-22 14:25:24	0	d-----w-	c:\program files\common files\SureThing Shared<br />
2009-10-22 14:22:25	0	d-----w-	c:\programdata\Sonic<br />
2009-10-22 14:22:15	0	d-----w-	c:\program files\common files\Sonic Shared<br />
2009-10-22 14:19:30	0	d-----w-	c:\programdata\InstallShield<br />
2009-10-22 14:18:59	0	d-----w-	c:\program files\Roxio<br />
2009-10-22 13:40:41	0	d-----w-	c:\programdata\Spybot - Search &amp; Destroy<br />
2009-10-22 13:40:41	0	d-----w-	c:\program files\Spybot - Search &amp; Destroy<br />
2009-10-22 13:20:13	0	d-----w-	c:\users\jane\Tracing<br />
2009-10-22 13:18:55	0	d-----w-	c:\program files\Microsoft<br />
2009-10-22 13:18:37	0	d-----w-	c:\program files\Windows Live SkyDrive<br />
2009-10-22 13:18:01	0	d-----w-	c:\windows\PCHEALTH<br />
2009-10-22 13:15:57	0	d-----w-	c:\program files\common files\Windows Live<br />
2009-10-22 12:52:08	2048	----a-w-	c:\windows\system32\tzres.dll<br />
2009-10-22 12:51:30	75	--sh--r-	c:\windows\CT4CET.bin<br />
2009-10-22 12:51:09	0	d-----w-	c:\program files\common files\Reallusion<br />
2009-10-22 12:50:15	5627904	----a-w-	c:\windows\system32\LiveCamVirtual.ocx<br />
2009-10-22 12:49:53	348160	------w-	c:\windows\system32\msvcr71.dll<br />
2009-10-22 12:49:52	499712	------w-	c:\windows\system32\msvcp71.dll<br />
2009-10-22 12:49:52	1060864	------w-	c:\windows\system32\MFC71.DLL<br />
2009-10-22 12:49:47	0	d-----w-	c:\program files\Creative Live! Cam<br />
2009-10-22 12:49:20	0	d-----w-	c:\program files\Creative<br />
2009-10-22 12:45:34	0	d-----w-	c:\users\jane\appdata\roaming\Webroot<br />
2009-10-22 12:45:33	0	d-----w-	c:\programdata\Webroot<br />
2009-10-22 12:45:33	0	d-----w-	c:\program files\Webroot<br />
2009-10-22 12:45:33	0	d-----w-	c:\program files\common files\Webroot Shared<br />
2009-10-22 12:45:22	194888	----a-w-	c:\windows\Unwash6.exe<br />
2009-10-22 12:31:51	18904	----a-w-	c:\windows\system32\StructuredQuerySchemaTrivial.bin<br />
2009-10-22 12:31:46	11967524	----a-w-	c:\windows\system32\korwbrkr.lex<br />
2009-10-22 12:05:30	41984	----a-w-	c:\windows\system32\netfxperf.dll<br />
2009-10-22 12:01:39	2034688	----a-w-	c:\windows\system32\win32k.sys<br />
2009-10-22 11:58:20	6656	----a-w-	c:\windows\system32\kbd106n.dll<br />
2009-10-22 11:56:19	499712	----a-w-	c:\windows\system32\kerberos.dll<br />
2009-10-22 11:56:19	175104	----a-w-	c:\windows\system32\wdigest.dll<br />
2009-10-22 11:56:19	1259008	----a-w-	c:\windows\system32\lsasrv.dll<br />
2009-10-22 11:56:18	9728	----a-w-	c:\windows\system32\lsass.exe<br />
2009-10-22 11:56:18	72704	----a-w-	c:\windows\system32\secur32.dll<br />
2009-10-22 11:56:18	439864	----a-w-	c:\windows\system32\drivers\ksecdd.sys<br />
2009-10-22 11:56:18	270848	----a-w-	c:\windows\system32\schannel.dll<br />
2009-10-22 11:56:01	160256	----a-w-	c:\windows\system32\wkssvc.dll<br />
2009-10-22 11:54:43	2066432	----a-w-	c:\windows\system32\mstscax.dll<br />
2009-10-22 11:54:42	53248	----a-w-	c:\windows\system32\tsgqec.dll<br />
2009-10-22 11:54:42	136192	----a-w-	c:\windows\system32\aaclient.dll<br />
2009-10-22 11:53:52	71680	----a-w-	c:\windows\system32\atl.dll<br />
2009-10-22 11:53:00	218624	----a-w-	c:\windows\system32\msv1_0.dll<br />
2009-10-22 11:51:56	623616	----a-w-	c:\windows\system32\localspl.dll<br />
2009-10-22 11:51:51	784896	----a-w-	c:\windows\system32\rpcrt4.dll<br />
2009-10-22 11:51:38	144896	----a-w-	c:\windows\system32\drivers\srv2.sys<br />
2009-10-22 11:47:36	11887	----a-w-	c:\windows\system32\Config.MPF<br />
2009-10-22 11:47:19	0	d-----w-	c:\programdata\SiteAdvisor<br />
2009-10-22 11:47:09	0	d-----w-	c:\program files\SiteAdvisor<br />
2009-10-22 11:44:39	604672	----a-w-	c:\windows\system32\WMSPDMOD.DLL<br />
2009-10-22 11:44:09	79816	----a-w-	c:\windows\system32\drivers\mfeavfk.sys<br />
2009-10-22 11:44:09	40552	----a-w-	c:\windows\system32\drivers\mfesmfk.sys<br />
2009-10-22 11:44:09	35272	----a-w-	c:\windows\system32\drivers\mfebopk.sys<br />
2009-10-22 11:44:04	130424	----a-w-	c:\windows\system32\drivers\Mpfp.sys<br />
2009-10-22 11:43:40	0	d-----w-	c:\program files\common files\McAfee<br />
2009-10-22 11:43:38	0	d-----w-	c:\program files\McAfee.com<br />
2009-10-22 11:43:36	0	d-----w-	c:\program files\McAfee<br />
2009-10-22 11:42:37	34248	----a-w-	c:\windows\system32\drivers\mferkdk.sys<br />
2009-10-22 11:28:17	0	d-----w-	c:\programdata\McAfee<br />
2009-10-22 11:24:50	16086	----a-w-	c:\windows\system32\results.xml<br />
2009-10-22 11:20:18	0	d-----w-	c:\programdata\Dell<br />
2009-10-22 11:18:56	60416	----a-w-	c:\windows\system32\aestaren.dll<br />
2009-10-22 11:18:29	0	d-----w-	c:\program files\IDT<br />
2009-10-22 11:18:01	0	d-----w-	c:\program files\Marvell<br />
2009-10-22 11:17:34	0	d-----w-	c:\users\jane\appdata\roaming\TMP<br />
2009-10-22 11:17:01	0	d-----w-	c:\program files\Cisco<br />
2009-10-22 11:15:33	772384	----a-w-	c:\windows\system32\oem8.inf<br />
2009-10-22 11:15:09	1044992	----a-w-	c:\windows\system32\BCMLogon.dll<br />
2009-10-22 11:14:24	0	d-----w-	c:\program files\DellTPad<br />
2009-10-22 11:13:39	170032	----a-w-	c:\windows\system32\drivers\Apfiltr.sys<br />
2009-10-22 11:13:39	1419232	----a-w-	c:\windows\system32\WdfCoInstaller01005.dll<br />
2009-10-22 11:13:39	100546	----a-w-	c:\windows\system32\Vxdif.dll<br />
2009-10-22 11:13:32	6416928	----a-w-	c:\windows\system\DriveIcon.dll<br />
2009-10-22 11:13:32	62976	----a-w-	c:\windows\system32\drivers\RTSTOR.sys<br />
2009-10-22 11:13:32	5430	----a-w-	c:\windows\system\MyMulti.ico<br />
2009-10-22 11:11:53	53248	----a-w-	c:\windows\system32\CSVer.dll<br />
2009-10-22 11:11:46	0	d-----w-	C:\Intel<br />
2009-10-22 11:11:43	0	d-----w-	C:\dell<br />
2009-10-22 11:11:14	0	d-----w-	c:\windows\system32\vmm32<br />
2009-10-22 11:11:14	0	d-----w-	c:\program files\Dell<br />
2009-10-22 11:11:02	0	d-sh--w-	c:\windows\Installer<br />
2009-10-22 11:06:34	0	---ha-w-	c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf<br />
<br />
==================== Find3M  ====================<br />
<br />
2009-10-24 09:09:30	86016	----a-w-	c:\windows\inf\infstrng.dat<br />
2009-10-24 09:09:30	86016	----a-w-	c:\windows\inf\infstor.dat<br />
2009-10-24 09:09:30	51200	----a-w-	c:\windows\inf\infpub.dat<br />
2009-10-24 09:03:45	665600	----a-w-	c:\windows\inf\drvindex.dat<br />
2009-10-24 08:55:40	37665	----a-w-	c:\windows\fonts\GlobalUserInterface.CompositeFont<br />
2009-10-22 11:14:32	0	---ha-w-	c:\windows\system32\drivers\Msft_Kernel_Apfiltr_01005.Wdf<br />
2009-09-16 09:22:48	214664	----a-w-	c:\windows\system32\drivers\mfehidk.sys<br />
2009-09-04 11:41:59	60928	----a-w-	c:\windows\system32\msasn1.dll<br />
2009-08-29 00:27:49	4240384	----a-w-	c:\windows\system32\GameUXLegacyGDFs.dll<br />
2009-08-29 00:14:38	28672	----a-w-	c:\windows\system32\Apphlpdm.dll<br />
2009-08-27 05:22:28	916480	----a-w-	c:\windows\system32\wininet.dll<br />
2009-08-27 05:17:43	71680	----a-w-	c:\windows\system32\iesetup.dll<br />
2009-08-27 05:17:43	109056	----a-w-	c:\windows\system32\iesysprep.dll<br />
2009-08-27 03:42:29	133632	----a-w-	c:\windows\system32\ieUnatt.exe<br />
2009-08-14 15:53:34	17920	----a-w-	c:\windows\system32\netevent.dll<br />
2009-08-14 13:49:20	9728	----a-w-	c:\windows\system32\TCPSVCS.EXE<br />
2009-08-14 13:49:18	17920	----a-w-	c:\windows\system32\ROUTE.EXE<br />
2009-08-14 13:49:18	11264	----a-w-	c:\windows\system32\MRINFO.EXE<br />
2009-08-14 13:49:15	27136	----a-w-	c:\windows\system32\NETSTAT.EXE<br />
2009-08-14 13:49:14	8704	----a-w-	c:\windows\system32\HOSTNAME.EXE<br />
2009-08-14 13:49:14	19968	----a-w-	c:\windows\system32\ARP.EXE<br />
2009-08-14 13:49:13	10240	----a-w-	c:\windows\system32\finger.exe<br />
2009-08-14 13:48:02	105984	----a-w-	c:\windows\system32\netiohlp.dll<br />
2008-01-21 02:43:21	174	--sha-w-	c:\program files\desktop.ini<br />
2006-11-02 12:42:02	30674	----a-w-	c:\windows\inf\perflib\0409\perfd.dat<br />
2006-11-02 12:42:02	30674	----a-w-	c:\windows\inf\perflib\0409\perfc.dat<br />
2006-11-02 12:42:02	287440	----a-w-	c:\windows\inf\perflib\0409\perfi.dat<br />
2006-11-02 12:42:02	287440	----a-w-	c:\windows\inf\perflib\0409\perfh.dat<br />
2006-11-02 09:20:21	287440	----a-w-	c:\windows\inf\perflib\0000\perfi.dat<br />
2006-11-02 09:20:21	287440	----a-w-	c:\windows\inf\perflib\0000\perfh.dat<br />
2006-11-02 09:20:19	30674	----a-w-	c:\windows\inf\perflib\0000\perfd.dat<br />
2006-11-02 09:20:19	30674	----a-w-	c:\windows\inf\perflib\0000\perfc.dat<br />
<br />
============= FINISH: 19:13:54.24 ===============<br />
<br />
Sorry - here is the attach file.<br />
<br />
Many thanks.</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techsupportforum.com/cwd/images/attach/zip.gif" alt="File Type: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techsupportforum.com/attachments/hijackthis-log-help-inactive/60066d1257881986-help-issue-trojan-cannot-get-rid-ark.zip">ark.zip</a> (894 Bytes)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techsupportforum.com/cwd/images/attach/zip.gif" alt="File Type: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techsupportforum.com/attachments/hijackthis-log-help-inactive/60067d1257882209-help-issue-trojan-cannot-get-rid-dds.zip">DDS.zip</a> (5.4 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techsupportforum.com/cwd/images/attach/zip.gif" alt="File Type: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techsupportforum.com/attachments/hijackthis-log-help-inactive/60094d1257977745-help-issue-trojan-cannot-get-rid-attach.zip">Attach.zip</a> (1.2 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/">HijackThis Log Help (Inactive)</category>
			<dc:creator>Janeyd</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/430716-help-issue-trojan-cannot-get-rid.html</guid>
		</item>
		<item>
			<title>Web opens new windows and redirects</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/430313-web-opens-new-windows-redirects.html</link>
			<pubDate>Tue, 10 Nov 2009 14:27:23 GMT</pubDate>
			<description>Hi, 
 
A couple of days ago when browsing the web, some additional browser windows started opening up without me requesting them. Random sites, and a lot of broken URLs etc. Also when searching in Google, I would click on a link in the SERPS and I would be taken to somewhere else. Once it was to a...</description>
			<content:encoded><![CDATA[<div>Hi,<br />
<br />
A couple of days ago when browsing the web, some additional browser windows started opening up without me requesting them. Random sites, and a lot of broken URLs etc. Also when searching in Google, I would click on a link in the SERPS and I would be taken to somewhere else. Once it was to a AskJeeves!?!?<br />
<br />
I am running Norton 360 and it has always been kept up to date. I have tried Spyware Doctor, Adaware, S&amp;D, but none of them find anything other than a couple of tracking cookies.<br />
<br />
Here is the log file (hope you can help?), many thanks :pray: ...<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 14:26:00, on 10/11/2009<br />
Platform: Unknown Windows (WinNT 6.01.3504)<br />
MSIE: Internet Explorer v8.00 (8.00.7600.16385)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\taskhost.exe<br />
C:\Windows\System32\CtHelper.exe<br />
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe<br />
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Logitech\GamePanel Software\LGDevAgt.exe<br />
C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe<br />
C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Program Files\Norton 360\Engine\3.5.2.11\ccSvcHst.exe<br />
C:\Users\Gareth\AppData\Local\Google\Update\1.2.183.13\GoogleCrashHandler.exe<br />
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Program Files\Logitech\SetPoint\SetPoint.exe<br />
C:\Program Files\Logitech\GamePanel Software\Applets\LCDClock.exe<br />
C:\Program Files\Logitech\GamePanel Software\Applets\LCDPop3.exe<br />
C:\Program Files\Logitech\GamePanel Software\Applets\LCDRSS.exe<br />
C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe<br />
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br />
C:\Program Files\BBC iPlayer Desktop\BBC iPlayer Desktop.exe<br />
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE<br />
C:\Program Files\Windows Media Player\WMPSideShowGadget.exe<br />
C:\Program Files\Windows Media Player\wmplayer.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\3.5.2.11\coIEPlg.dll<br />
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\3.5.2.11\IPSBHO.DLL<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\3.5.2.11\coIEPlg.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O3 - Toolbar: &amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE<br />
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE<br />
O4 - HKLM\..\Run: [WD Drive Manager] C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [Launch LgDeviceAgent] &quot;C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe&quot;<br />
O4 - HKLM\..\Run: [Launch LCDMon] &quot;C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe&quot;<br />
O4 - HKLM\..\Run: [Launch LGDCore] &quot;C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe&quot; /SHOWHIDE<br />
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] &quot;C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe&quot; -launchedbylogin<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;<br />
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [msnmsgr] &quot;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&quot; /background<br />
O4 - HKCU\..\Run: [Google Update] &quot;C:\Users\Gareth\AppData\Local\Google\Update\GoogleUpdate.exe&quot; /c<br />
O4 - HKCU\..\Run: [TomTomHOME.exe] &quot;C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe&quot;<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-18\..\Run: [DevconDefaultDB] C:\Windows\system32\READREG /SILENT /FAIL=1 (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [DevconDefaultDB] C:\Windows\system32\READREG /SILENT /FAIL=1 (User 'Default user')<br />
O4 - Startup: BBC iPlayer Desktop.lnk = C:\Program Files\BBC iPlayer Desktop\BBC iPlayer Desktop.exe<br />
O4 - Startup: Logitech . Product Registration.lnk = C:\Program Files\Common Files\Logishrd\eReg\SetPoint\eReg.exe<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe<br />
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIF5BA~1\Office12\REFIEBAR.DLL<br />
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - <a href="http://cdn.scan.onecare.live.com/resource/download/scanner/en-us/wlscctrl2.cab" target="_blank">http://cdn.scan.onecare.live.com/res.../wlscctrl2.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton 360\Engine\3.5.2.11\coIEPlg.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe<br />
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\3.5.2.11\ccSvcHst.exe<br />
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe<br />
O23 - Service: WD Drive Manager Service (WDBtnMgrSvc.exe) - WDC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe<br />
<br />
--<br />
End of file - 11075 bytes</div>

]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/">HijackThis Log Help (Inactive)</category>
			<dc:creator>amser666</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/430313-web-opens-new-windows-redirects.html</guid>
		</item>
		<item>
			<title>3 month old computer WITH A NICE NEW VIRUS</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/430156-3-month-old-computer-nice-new-virus.html</link>
			<pubDate>Tue, 10 Nov 2009 01:38:35 GMT</pubDate>
			<description><![CDATA[Hi! 
Description of what is wrong:  
Ocassional blue screen of death "file corrupt" message followed by a restart, ill try to get a picture of it but it autorestarts in about 5 seconds. THis is the most annoying part of the virus.  
Also:  
Desktop becomes hidden by a black window, a fake task...]]></description>
			<content:encoded><![CDATA[<div>Hi!<br />
Description of what is wrong: <br />
Ocassional blue screen of death &quot;file corrupt&quot; message followed by a restart, ill try to get a picture of it but it autorestarts in about 5 seconds. THis is the most annoying part of the virus. <br />
Also: <br />
Desktop becomes hidden by a black window, a fake task manager has been seen at one point, Certain applications suddenly stop working, folder locations seem different for instance sometimes when you double click my computer it opens my documents instead. <br />
<br />
I can still scan with AVG anti virus and Malwarebyes and neither of those programs are any help.<br />
<br />
DDT:<br />
<br />
DDS (Ver_09-10-26.01) - NTFSx86  <br />
Run by Jessica at 20:35:08.18 on Mon 11/09/2009<br />
Internet Explorer: 8.0.6001.18828<br />
Microsoft® Windows Vista™ Home Basic   6.0.6002.2.1252.1.1033.18.3062.1939 [GMT -5:00]<br />
<br />
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}<br />
<br />
============== Running Processes ===============<br />
<br />
C:\Windows\system32\wininit.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\svchost.exe -k rpcss<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\system32\svchost.exe -k GPSvcGroup<br />
C:\Windows\system32\SLsvc.exe<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Windows\system32\taskeng.exe<br />
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe<br />
C:\Windows\system32\AERTSrv.exe<br />
C:\Program Files\AGI\common\win32\PythonService.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Windows\system32\svchost.exe -k hpdevmgmt<br />
C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\Windows\System32\svchost.exe -k HPZ12<br />
C:\Windows\System32\svchost.exe -k HPZ12<br />
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe<br />
C:\Windows\system32\svchost.exe -k imgsvc<br />
C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
C:\Windows\System32\svchost.exe -k WerSvcGroup<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Windows\system32\spool\DRIVERS\W32X86\3\HP1006MC.EXE<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
C:\Windows\system32\SearchProtocolHost.exe<br />
C:\Windows\explorer.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Users\Jessica\Desktop\dds.scr<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
<br />
============== Pseudo HJT Report ===============<br />
<br />
uURLSearchHooks: AGSearchHook Class: {0bc6e3fa-78ef-4886-842c-5a1258c4455a} - c:\program files\agi\common\agcutils.dll<br />
uWinlogon: Shell=explorer.exe,c:\recycler\s-1-5-21-6661766519-1619243805-433085554-7426\rundll32.exe<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll<br />
BHO: {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - No File<br />
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll<br />
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll<br />
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll<br />
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll<br />
BHO: IeMonitorBho Class: {bf00e119-21a3-4fd1-b178-3b8537e75c92} - c:\program files\megaupload\mega manager\MegaIEMn.dll<br />
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll<br />
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll<br />
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll<br />
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File<br />
TB: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File<br />
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\npjpi160_07.dll<br />
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL<br />
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522}<br />
DPF: {588031A3-94BF-4CDD-86D0-939F6F93910F} - hxxps://fixit.support.microsoft.com/ActiveX/FixItClient.CAB<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab<br />
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL<br />
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll<br />
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll<br />
Notify: igfxcui - igfxdev.dll<br />
AppInit_DLLs: avgrsstx.dll<br />
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll<br />
<br />
================= FIREFOX ===================<br />
<br />
FF - ProfilePath - c:\users\jessica\appdata\roaming\mozilla\firefox\profiles\qpqvpzdq.default\<br />
FF - prefs.js: browser.search.selectedEngine - Google<br />
FF - prefs.js: browser.startup.homepage - hxxp://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;_trksid=m37<br />
FF - prefs.js: keyword.URL - hxxp://www.crawler.com/search/dispatcher.aspx?tp=aus&amp;tbid=60342&amp;qkw=<br />
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll<br />
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll<br />
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll<br />
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll<br />
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll<br />
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll<br />
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\nptgeqplugin.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll<br />
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll<br />
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll<br />
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\<br />
<br />
---- FIREFOX POLICIES ----<br />
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref(&quot;security.ssl3.rsa_seed_sha&quot;, true);<br />
<br />
============= SERVICES / DRIVERS ===============<br />
<br />
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-11-3 333192]<br />
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-11-3 360584]<br />
R2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2009-2-6 73728]<br />
R2 AGWinService;AG Windows Service;c:\program files\agi\common\win32\pythonservice.exe [2009-2-10 10240]<br />
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2009-11-3 285392]<br />
R2 RtNdPt60;Realtek NDIS Protocol Driver;c:\windows\system32\drivers\RtNdPt60.sys [2009-2-6 27648]<br />
R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512]<br />
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-6-23 24652]<br />
R3 DLXPDisplayName;DLXPDisplayName;c:\windows\system32\drivers\DLACPI.sys [2009-2-6 14392]<br />
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [2009-2-16 84832]<br />
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-11-3 38224]<br />
<br />
=============== Created Last 30 ================<br />
<br />
2009-11-09 23:48:07	0	d-----w-	c:\windows\pss<br />
2009-11-08 20:28:17	310784	----a-w-	c:\windows\system32\unregmp2.exe<br />
2009-11-08 20:28:14	8147456	----a-w-	c:\windows\system32\wmploc.DLL<br />
2009-11-08 19:55:40	0	d-----w-	c:\programdata\96377638<br />
2009-11-04 09:27:12	1638912	----a-w-	c:\windows\system32\mshtml.tlb<br />
2009-11-03 22:11:05	38224	----a-w-	c:\windows\system32\drivers\mbamswissarmy.sys<br />
2009-11-03 22:11:04	19160	----a-w-	c:\windows\system32\drivers\mbam.sys<br />
2009-11-03 22:11:04	0	d-----w-	c:\program files\Malwarebytes' Anti-Malware<br />
2009-11-03 21:44:26	0	d--h--w-	C:\$AVG<br />
2009-11-03 21:44:22	12464	----a-w-	c:\windows\system32\avgrsstx.dll<br />
2009-11-03 21:44:21	360584	----a-w-	c:\windows\system32\drivers\avgtdix.sys<br />
2009-11-03 21:44:15	333192	----a-w-	c:\windows\system32\drivers\avgldx86.sys<br />
2009-11-03 21:44:13	0	d-----w-	c:\windows\system32\drivers\Avg<br />
2009-11-03 21:44:05	0	d-----w-	c:\programdata\AVG Security Toolbar<br />
2009-11-03 21:43:54	0	d-----w-	c:\programdata\avg9<br />
2009-11-03 21:43:54	0	d-----w-	c:\program files\AVG<br />
2009-11-03 21:37:47	0	d-sh--w-	c:\programdata\e797b15<br />
2009-11-02 02:11:53	0	d-----w-	c:\program files\Easy Video Joiner<br />
2009-11-01 03:29:00	0	d-----w-	c:\programdata\Macrovision<br />
2009-11-01 03:28:53	0	d-----w-	c:\program files\common files\Adobe Systems Shared<br />
2009-10-31 00:36:35	376	----a-w-	c:\windows\ODBC.INI<br />
2009-10-30 19:03:13	0	d-----w-	C:\teamojcms<br />
2009-10-30 18:45:32	0	d-----w-	c:\program files\SmartFTP Client<br />
2009-10-30 18:44:38	0	d-----w-	c:\program files\SmartFTP Client 4.0 Setup Files<br />
2009-10-23 19:16:38	0	d-----w-	C:\EPSONREG<br />
2009-10-23 18:49:26	0	d-----w-	c:\programdata\ArcSoft<br />
2009-10-23 18:48:12	11776	----a-w-	c:\windows\system32\drivers\afc.sys<br />
2009-10-23 18:48:08	258352	----a-w-	c:\windows\system32\unicows.dll<br />
2009-10-23 18:48:07	212480	----a-w-	c:\windows\PCDLIB32.DLL<br />
2009-10-23 18:48:03	126976	----a-w-	c:\windows\system32\PhotoImpression Slideshow.scr<br />
2009-10-23 18:47:32	0	d-----w-	c:\windows\system32\PhotoImpression Slideshow<br />
2009-10-23 18:44:11	0	d-----w-	c:\program files\EPSON Print CD<br />
2009-10-23 18:43:42	0	d-----w-	c:\programdata\EPSON<br />
2009-10-23 18:41:36	0	d-----w-	c:\program files\EPSON<br />
2009-10-23 18:40:58	44	----a-w-	c:\windows\EPSPR280.ini<br />
2009-10-17 22:01:29	0	d-----w-	c:\programdata\NCH Software<br />
2009-10-17 18:45:04	0	d-----w-	c:\program files\Ask.com<br />
2009-10-17 18:44:44	0	d-----w-	c:\program files\Free RAR Extract Frog<br />
2009-10-17 00:47:55	0	d-----w-	c:\program files\MasterSplitter<br />
2009-10-14 18:42:36	604672	----a-w-	c:\windows\system32\WMSPDMOD.DLL<br />
2009-10-14 06:08:30	0	d-----w-	c:\windows\system32\eu-ES<br />
2009-10-14 06:08:30	0	d-----w-	c:\windows\system32\ca-ES<br />
2009-10-14 06:08:29	0	d-----w-	c:\windows\system32\vi-VN<br />
2009-10-14 05:46:43	0	d-----w-	c:\windows\system32\EventProviders<br />
2009-10-13 23:10:02	317651838	----a-w-	c:\windows\MEMORY.DMP<br />
2009-10-11 17:21:49	0	d-----w-	c:\users\jessica\appdata\roaming\W Photo Studio Viewer<br />
<br />
==================== Find3M  ====================<br />
<br />
2009-10-23 18:42:33	86016	----a-w-	c:\windows\inf\infstor.dat<br />
2009-10-23 18:42:33	51200	----a-w-	c:\windows\inf\infpub.dat<br />
2009-10-23 18:42:32	143360	----a-w-	c:\windows\inf\infstrng.dat<br />
2009-10-14 06:08:19	665600	----a-w-	c:\windows\inf\drvindex.dat<br />
2009-10-14 05:54:25	37665	----a-w-	c:\windows\fonts\GlobalUserInterface.CompositeFont<br />
2009-10-01 14:29:14	195440	------w-	c:\windows\system32\MpSigStub.exe<br />
2009-09-25 16:41:26	856064	----a-w-	c:\windows\system32\divx_xx0c.dll<br />
2009-09-25 16:41:26	856064	----a-w-	c:\windows\system32\divx_xx07.dll<br />
2009-09-25 16:41:26	847872	----a-w-	c:\windows\system32\divx_xx0a.dll<br />
2009-09-25 16:41:26	843776	----a-w-	c:\windows\system32\divx_xx16.dll<br />
2009-09-25 16:41:26	839680	----a-w-	c:\windows\system32\divx_xx11.dll<br />
2009-09-25 16:41:26	696320	----a-w-	c:\windows\system32\DivX.dll<br />
2009-09-14 09:29:50	144896	----a-w-	c:\windows\system32\drivers\srv2.sys<br />
2009-09-10 16:48:01	218624	----a-w-	c:\windows\system32\msv1_0.dll<br />
2009-09-04 11:41:59	60928	----a-w-	c:\windows\system32\msasn1.dll<br />
2009-08-29 00:27:49	4240384	----a-w-	c:\windows\system32\GameUXLegacyGDFs.dll<br />
2009-08-29 00:14:38	28672	----a-w-	c:\windows\system32\Apphlpdm.dll<br />
2009-08-27 05:22:28	916480	----a-w-	c:\windows\system32\wininet.dll<br />
2009-08-27 05:17:43	71680	----a-w-	c:\windows\system32\iesetup.dll<br />
2009-08-27 05:17:43	109056	----a-w-	c:\windows\system32\iesysprep.dll<br />
2009-08-27 03:42:29	133632	----a-w-	c:\windows\system32\ieUnatt.exe<br />
2009-08-18 18:06:04	87608	----a-w-	c:\users\jessica\appdata\roaming\inst.exe<br />
2009-08-18 18:06:04	47360	----a-w-	c:\users\jessica\appdata\roaming\pcouffin.sys<br />
2009-08-18 03:33:52	1193832	----a-w-	c:\windows\system32\FM20.DLL<br />
2009-08-18 00:41:07	81920	----a-w-	c:\users\jessica\appdata\roaming\ezpinst.exe<br />
2009-08-14 15:53:34	17920	----a-w-	c:\windows\system32\netevent.dll<br />
2009-08-14 13:49:20	9728	----a-w-	c:\windows\system32\TCPSVCS.EXE<br />
2009-08-14 13:49:18	17920	----a-w-	c:\windows\system32\ROUTE.EXE<br />
2009-08-14 13:49:18	11264	----a-w-	c:\windows\system32\MRINFO.EXE<br />
2009-08-14 13:49:15	27136	----a-w-	c:\windows\system32\NETSTAT.EXE<br />
2009-08-14 13:49:14	8704	----a-w-	c:\windows\system32\HOSTNAME.EXE<br />
2009-08-14 13:49:14	19968	----a-w-	c:\windows\system32\ARP.EXE<br />
2009-08-14 13:49:13	10240	----a-w-	c:\windows\system32\finger.exe<br />
2009-08-14 13:48:02	105984	----a-w-	c:\windows\system32\netiohlp.dll<br />
2008-01-21 02:57:01	174	--sha-w-	c:\program files\desktop.ini<br />
2006-11-02 12:39:34	30674	----a-w-	c:\windows\inf\perflib\0409\perfd.dat<br />
2006-11-02 12:39:34	30674	----a-w-	c:\windows\inf\perflib\0409\perfc.dat<br />
2006-11-02 12:39:34	287440	----a-w-	c:\windows\inf\perflib\0409\perfi.dat<br />
2006-11-02 12:39:34	287440	----a-w-	c:\windows\inf\perflib\0409\perfh.dat<br />
2006-11-02 09:20:21	287440	----a-w-	c:\windows\inf\perflib\0000\perfi.dat<br />
2006-11-02 09:20:21	287440	----a-w-	c:\windows\inf\perflib\0000\perfh.dat<br />
2006-11-02 09:20:19	30674	----a-w-	c:\windows\inf\perflib\0000\perfd.dat<br />
2006-11-02 09:20:19	30674	----a-w-	c:\windows\inf\perflib\0000\perfc.dat<br />
2009-07-05 12:05:58	16384	--sha-w-	c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\history\history.ie5\index.dat<br />
2009-07-05 12:05:58	32768	--sha-w-	c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat<br />
2009-07-05 12:05:58	16384	--sha-w-	c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\cookies\index.dat<br />
2009-07-05 12:05:58	245760	--sha-w-	c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat<br />
2009-02-06 23:21:10	8192	--sha-w-	c:\windows\users\default\NTUSER.DAT<br />
<br />
============= FINISH: 20:36:13.06 ===============<br />
<br />
Here is Attach.txt from DDS<br />
<br />
GMER is not done scanning, the computer seems to blue-screen and crash before the GMER application can finish.<br />
Ill try to get it up asap<br />
<br />
gmer here<br />
<br />
not sure if i did it right, its very short</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techsupportforum.com/cwd/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techsupportforum.com/attachments/hijackthis-log-help-inactive/59952d1257817386-3-month-old-computer-nice-new-virus-attach.txt">Attach.txt</a> (8.1 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techsupportforum.com/cwd/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techsupportforum.com/attachments/hijackthis-log-help-inactive/59956d1257819428-3-month-old-computer-nice-new-virus-gmer.txt">gmer.txt</a> (721 Bytes)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/">HijackThis Log Help (Inactive)</category>
			<dc:creator>tinytink</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/430156-3-month-old-computer-nice-new-virus.html</guid>
		</item>
		<item>
			<title>Windows is getting worse</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/430092-windows-getting-worse.html</link>
			<pubDate>Mon, 09 Nov 2009 21:03:11 GMT</pubDate>
			<description><![CDATA[Thank you in advance for taking the time to review this and offer any help .... 
 
a few of the problems windows has been having include 
* start menu stalling out 
* computer running really slow with every program 
* rtclick-->send to freezing up the system 
* cannot "save as" when downloading a...]]></description>
			<content:encoded><![CDATA[<div>Thank you in advance for taking the time to review this and offer any help ....<br />
<br />
a few of the problems windows has been having include<ul><li>start menu stalling out</li>
<li>computer running really slow with every program</li>
<li>rtclick--&gt;send to freezing up the system</li>
<li>cannot &quot;save as&quot; when downloading a file with mozilla</li>
<li>along with svchost.exe pop ups from McAfee</li>
</ul><br />
<br />
DDS (Ver_09-10-26.01) - NTFSx86  <br />
Run by cbellson at 12:05:45.25 on Mon 11/09/2009<br />
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_07<br />
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.2046.838 [GMT -6:00]<br />
<br />
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)   {17DDD097-36FF-435F-9E1B-52D74245D6BF}<br />
AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated)   {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}<br />
<br />
============== Running Processes ===============<br />
<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost -k DcomLaunch<br />
svchost.exe<br />
C:\WINDOWS\System32\svchost.exe -k netsvcs<br />
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup<br />
svchost.exe<br />
svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br />
C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br />
C:\WINDOWS\SYSTEM32\DWRCS.EXE<br />
C:\Program Files\McAfee\Common Framework\FrameworkService.exe<br />
C:\Program Files\Google\Update\1.2.183.13\GoogleCrashHandler.exe<br />
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\notes\ntmulti.exe<br />
C:\WINDOWS\system32\svchost.exe -k imgsvc<br />
C:\WINDOWS\TIREMOTE\wuser32.exe<br />
C:\WINDOWS\TIREMOTE\TIRemoteService.exe<br />
C:\Program Files\RealVNC\WinVNC\WinVNC.exe<br />
C:\WINDOWS\SYSTEM32\DWRCST.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\CheckPoint\SecureAgent\uatc.exe<br />
C:\WINDOWS\system32\ntvdm.exe<br />
C:\Program Files\Analog Devices\Core\smax4pnp.exe<br />
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe<br />
C:\Program Files\McAfee\Common Framework\UdaterUI.exe<br />
C:\Program Files\McAfee\Common Framework\McTray.exe<br />
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe<br />
C:\Program Files\RightFax\Client\FaxCtrl.exe<br />
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe<br />
C:\Program Files\PowerISO\PWRISOVM.EXE<br />
C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
C:\Program Files\RocketDock\RocketDock.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe<br />
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
C:\Program Files\Logitech\SetPoint\SetPoint.exe<br />
C:\Program Files\TechSmith\Snagit 9\Snagit32.exe<br />
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE<br />
C:\Documents and Settings\cbellson\Application Data\Dropbox\bin\Dropbox.exe<br />
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
C:\Program Files\TechSmith\Snagit 9\TSCHelp.exe<br />
C:\Program Files\TechSmith\Snagit 9\SnagPriv.exe<br />
C:\Program Files\TechSmith\Snagit 9\snagiteditor.exe<br />
C:\Program Files\Adobe\Adobe Dreamweaver CS3\Dreamweaver.exe<br />
C:\Program Files\AVG\AVG8\avgui.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe<br />
C:\Program Files\AVG\AVG8\avgscanx.exe<br />
C:\Program Files\AVG\AVG8\avgcsrvx.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\DOCUME~1\cbellson\LOCALS~1\Temp\Rar$EX00.875\gmer.exe<br />
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe<br />
C:\Documents and Settings\cbellson\Desktop\dds.scr<br />
<br />
============== Pseudo HJT Report ===============<br />
<br />
uStart Page = hxxp://www.health-fitnesscenters.com/Lindenhurst/employee.html<br />
uInternet Settings,ProxyOverride = *.local<br />
BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 9\SnagitBHO.dll<br />
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll<br />
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll<br />
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll<br />
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan enterprise\scriptcl.dll<br />
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll<br />
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll<br />
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll<br />
TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 9\SnagitIEAddin.dll<br />
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File<br />
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll<br />
uRun: [UATC] &quot;c:\program files\checkpoint\secureagent\uatc.exe&quot; /debug <br />
uRun: [RocketDock] &quot;c:\program files\rocketdock\RocketDock.exe&quot;<br />
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe<br />
uRun: [FreeRAM XP] &quot;c:\program files\yourware solutions\freeram xp pro\FreeRAM XP Pro.exe&quot; -win<br />
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe<br />
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe<br />
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe<br />
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe<br />
mRun: [Persistence] c:\windows\system32\igfxpers.exe<br />
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe<br />
mRun: [WinVNC] &quot;c:\program files\realvnc\winvnc\WinVNC.exe&quot; -servicehelper<br />
mRun: [Acronis Scheduler2 Service] &quot;c:\program files\common files\acronis\schedule2\schedhlp.exe&quot;<br />
mRun: [ShStatEXE] &quot;c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE&quot; /STANDALONE<br />
mRun: [McAfeeUpdaterUI] &quot;c:\program files\mcafee\common framework\UdaterUI.exe&quot; /StartedFromRunKey<br />
mRun: [SunJavaUpdateSched] &quot;c:\program files\java\jre1.6.0_07\bin\jusched.exe&quot;<br />
mRun: [RightFAX Print-to-Fax Driver] c:\program files\rightfax\client\FaxCtrl.exe<br />
mRun: [Acrobat Assistant 8.0] &quot;c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe&quot;<br />
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE<br />
mRun: [QuickTime Task] &quot;c:\program files\quicktime\qttask.exe&quot; -atboottime<br />
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe<br />
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE<br />
StartupFolder: c:\docume~1\cbellson\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe<br />
StartupFolder: c:\docume~1\cbellson\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\cbellson\application data\dropbox\bin\Dropbox.exe<br />
StartupFolder: c:\documents and settings\cbellson\start menu\programs\startup\Fireworks.exe<br />
StartupFolder: c:\documents and settings\cbellson\start menu\programs\startup\Lindenhurst Health &amp; Fitness Center.url<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\snagit~1.lnk - c:\program files\techsmith\snagit 9\Snagit32.exe<br />
IE: &amp;Search<br />
IE: Add to Google Photos Screensa&amp;ver - c:\windows\system32\GPhotos.scr/200<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000<br />
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe<br />
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe<br />
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL<br />
Trusted Zone: smsrsm.com\gldl0fpp1.rsodm20<br />
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab<br />
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab<br />
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab<br />
DPF: {2DEF4530-8CE6-41C9-84B6-A54536C90213} - hxxp://208.254.39.208/viewer9/activeXViewer/activexviewer.cab<br />
DPF: {42F3E909-9DC2-4D58-BCAE-1B4FCF27363B} - hxxp://www.bookingplus.com/ishield/Downloads/setup.cab<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab<br />
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab<br />
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll<br />
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll<br />
Notify: AtiExtEvent - Ati2evxx.dll<br />
Notify: avgrsstarter - avgrsstx.dll<br />
Notify: igfxcui - igfxdev.dll<br />
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll<br />
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL<br />
LSA: Authentication Packages = msv1_0 relog_ap<br />
<br />
================= FIREFOX ===================<br />
<br />
FF - ProfilePath - c:\docume~1\cbellson\applic~1\mozilla\firefox\profiles\lr7zg93g.default\<br />
FF - prefs.js: browser.startup.homepage - hxxp://www.worldofinspiration.com/<br />
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll<br />
FF - plugin: c:\google\picasa3\npPicasa3.dll<br />
FF - plugin: c:\program files\google\google updater\2.4.1636.7222\npCIDetect13.dll<br />
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\npatgpc.dll<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}<br />
<br />
============= SERVICES / DRIVERS ===============<br />
<br />
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-10-14 335240]<br />
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-10-14 108552]<br />
R1 dwvkbd;DameWare Virtual Keyboard 32 bit Driver;c:\windows\system32\drivers\dwvkbd.sys [2007-2-15 26624]<br />
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-10-12 9968]<br />
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-10-12 74480]<br />
R2 AcronisAgent;Acronis Remote Agent;c:\program files\common files\acronis\agent\agent.exe [2006-7-21 319488]<br />
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-10-14 297752]<br />
R2 TIRmtCtl;Track-It! Remote Control;c:\windows\tiremote\wuser32.exe [2007-7-25 311374]<br />
R2 TIRmtSvc;Track-It! Workstation Manager;c:\windows\tiremote\TIRemoteService.exe [2007-7-25 613888]<br />
R3 DwMirror;DwMirror;c:\windows\system32\drivers\DamewareMini.sys [2007-2-7 2944]<br />
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-5-13 38496]<br />
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-10-12 7408]<br />
S2 gupdate1ca00f5c80401b6;Google Update Service (gupdate1ca00f5c80401b6);c:\program files\google\update\GoogleUpdate.exe [2009-7-9 133104]<br />
S2 KeenfinderSrch Service;KeenfinderSrch Service;&quot;c:\documents and settings\all users\application data\keenfindersrch\keenfinder145.exe&quot; &quot;c:\program files\keenfindersrch\keenfinder.dll&quot; service --&gt; c:\documents and settings\all users\application data\keenfindersrch\keenfinder145.exe [?]<br />
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2008-10-2 33752]<br />
<br />
=============== Created Last 30 ================<br />
<br />
2009-11-05 18:20:56	3247	----a-w-	c:\windows\system32\wbem\Outlook_01ca5e44b7c4f5f6.mof<br />
2009-11-05 18:08:44	0	d-----w-	c:\program files\common files\L&amp;H<br />
2009-11-05 18:08:18	0	d-----w-	c:\program files\Microsoft ActiveSync<br />
2009-11-05 18:06:07	0	d-----w-	c:\windows\SHELLNEW<br />
2009-11-02 20:33:18	0	d-----w-	c:\docume~1\alluse~1\applic~1\ALM<br />
2009-10-21 21:03:38	0	d-----w-	c:\windows\system32\IOSUBSYS<br />
2009-10-21 21:03:25	0	d-----w-	C:\Google<br />
2009-10-20 16:56:55	0	d-----w-	c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com<br />
2009-10-20 16:56:15	0	d-----w-	c:\program files\SUPERAntiSpyware<br />
2009-10-20 16:56:15	0	d-----w-	c:\docume~1\cbellson\applic~1\SUPERAntiSpyware.com<br />
2009-10-20 15:46:17	0	d-----w-	c:\docume~1\alluse~1\applic~1\Kaspersky Lab Setup Files<br />
2009-10-14 22:01:59	0	d--h--w-	C:\$AVG8.VAULT$<br />
2009-10-14 21:45:16	11952	----a-w-	c:\windows\system32\avgrsstx.dll<br />
2009-10-14 21:45:15	108552	----a-w-	c:\windows\system32\drivers\avgtdix.sys<br />
2009-10-14 21:45:14	335240	----a-w-	c:\windows\system32\drivers\avgldx86.sys<br />
2009-10-14 21:45:02	0	d-----w-	c:\windows\system32\drivers\Avg<br />
2009-10-14 21:44:17	0	d-----w-	c:\program files\AVG<br />
2009-10-14 21:44:08	0	d-----w-	c:\docume~1\alluse~1\applic~1\avg8<br />
2009-10-14 20:27:34	0	d-----w-	c:\docume~1\cbellson\applic~1\AVG8<br />
<br />
==================== Find3M  ====================<br />
<br />
2009-10-29 15:15:24	249856	------w-	c:\windows\Setup1.exe<br />
2009-10-29 15:15:22	73216	----a-w-	c:\windows\ST6UNST.EXE<br />
2009-09-18 21:30:48	0	---ha-w-	c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf<br />
2009-08-23 21:00:38	922112	------w-	c:\windows\system32\imapi2fs.dll<br />
2009-08-23 21:00:38	426496	------w-	c:\windows\system32\imapi2.dll<br />
2009-08-23 21:00:38	23856	----a-w-	c:\windows\system32\spupdsvc.exe<br />
2009-08-18 19:38:23	60744	----a-w-	c:\documents and settings\cbellson\g2mdlhlpx.exe<br />
<br />
============= FINISH: 12:07:14.46 ===============</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techsupportforum.com/cwd/images/attach/zip.gif" alt="File Type: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techsupportforum.com/attachments/hijackthis-log-help-inactive/59936d1257800646-windows-getting-worse-attach.zip">Attach.zip</a> (4.2 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techsupportforum.com/cwd/images/attach/zip.gif" alt="File Type: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techsupportforum.com/attachments/hijackthis-log-help-inactive/59937d1257800658-windows-getting-worse-ark.zip">ARK.zip</a> (1,005 Bytes)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/">HijackThis Log Help (Inactive)</category>
			<dc:creator>cbell3186</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/430092-windows-getting-worse.html</guid>
		</item>
	</channel>
</rss>
