<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>Tech Support Forum - Virus/Trojan/Spyware Help</title>
		<link>http://www.techsupportforum.com</link>
		<description><![CDATA[Get Rid Of Malware With Help From Our Analysts.   Follow the "First Steps" link at the top right of each page before posting for help.]]></description>
		<language>en</language>
		<lastBuildDate>Fri, 20 Nov 2009 23:54:47 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://www.techsupportforum.com/cwd/images/misc/rss.jpg</url>
			<title>Tech Support Forum - Virus/Trojan/Spyware Help</title>
			<link>http://www.techsupportforum.com</link>
		</image>
		<item>
			<title>Computer extremely slow!!!</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433736-computer-extremely-slow.html</link>
			<pubDate>Fri, 20 Nov 2009 22:42:02 GMT</pubDate>
			<description>My computer is extremely slow. Also, when using the google toolbar I sometime get spanish google for some reason. In addition, different software on my computer often get stuck. 
 
Here is the content of the DDS.txt file: 
 
 
DDS (Ver_09-10-26.01) - NTFSx86   
Run by IBM at 19:21:45.71 on Fri...</description>
			<content:encoded><![CDATA[<div>My computer is extremely slow. Also, when using the google toolbar I sometime get spanish google for some reason. In addition, different software on my computer often get stuck.<br />
<br />
Here is the content of the DDS.txt file:<br />
<br />
<br />
DDS (Ver_09-10-26.01) - NTFSx86  <br />
Run by IBM at 19:21:45.71 on Fri 11/20/2009<br />
Internet Explorer: 7.0.5730.13<br />
Microsoft Windows XP Professional  5.1.2600.2.1255.1.1033.18.1022.402 [GMT 2:00]<br />
<br />
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated)   {FB06448E-52B8-493A-90F3-E43226D3305C}<br />
<br />
============== Running Processes ===============<br />
<br />
C:\Program Files\Common Files\Virtual Token\vtserver.exe<br />
C:\WINDOWS\system32\ibmpmsvc.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost -k DcomLaunch<br />
svchost.exe<br />
C:\WINDOWS\System32\svchost.exe -k netsvcs<br />
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br />
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br />
svchost.exe<br />
svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
svchost.exe<br />
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe<br />
C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe<br />
C:\WINDOWS\system32\cusrvc.exe<br />
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe<br />
C:\Program Files\Symantec AntiVirus\DefWatch.exe<br />
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe<br />
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe<br />
C:\Program Files\Novell\ZENworks\nalntsrv.exe<br />
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br />
C:\Program Files\Novell\ZENworks\RemoteManagement\RMAgent\ZenRem32.exe<br />
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe<br />
C:\WINDOWS\system32\svchost.exe -k imgsvc<br />
C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br />
C:\WINDOWS\System32\TPHDEXLG.EXE<br />
C:\WINDOWS\system32\TpKmpSVC.exe<br />
C:\Program Files\Novell\ZENworks\wm.exe<br />
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe<br />
C:\WINDOWS\System32\Novell\XTAgent.exe<br />
c:\windows\system32\Ati2evxx.exe<br />
C:\WINDOWS\explorer.exe<br />
C:\Program Files\ThinkPad\ConnectUtilities\AcMurocHlpr.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\WINDOWS\system32\TpShocks.exe<br />
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe<br />
C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe<br />
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe<br />
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe<br />
C:\WINDOWS\System32\svchost.exe -k HTTPFilter<br />
C:\WINDOWS\system32\dla\tfswctrl.exe<br />
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe<br />
C:\IBMTOOLS\UTILS\ibmprc.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe<br />
C:\PROGRA~1\SYMANT~1\VPTray.exe<br />
C:\WINDOWS\system32\dpmw32.exe<br />
C:\WINDOWS\system32\NWTRAY.EXE<br />
C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe<br />
C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe<br />
C:\WINDOWS\system32\TpScrLk.exe<br />
C:\Program Files\Winamp\winampa.exe<br />
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe<br />
C:\Program Files\Logitech\QuickCam\Quickcam.exe<br />
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe<br />
C:\Program Files\Skype\Phone\Skype.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe<br />
C:\Program Files\Digital Line Detect\DLG.exe<br />
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe<br />
C:\PROGRA~1\ThinkPad\BLUETO~1\BTSTAC~1.EXE<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Skype\Plugin Manager\skypePM.exe<br />
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe<br />
C:\Documents and Settings\IBM\Desktop\dds.scr<br />
<br />
============== Pseudo HJT Report ===============<br />
<br />
uSearch Page = hxxp://www.google.com<br />
uSearch Bar = hxxp://www.google.com/ie<br />
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&amp;sourceid=ie7&amp;rls=com.microsoft:en-US&amp;ie=utf8&amp;oe=utf8<br />
uDefault_Search_URL = hxxp://www.google.com/ie<br />
uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch<br />
uInternet Settings,ProxyServer = wwwproxy.weizmann.ac.il:8080<br />
uSearchAssistant = hxxp://www.google.com/ie<br />
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s<br />
mSearchAssistant = hxxp://www.google.com/ie<br />
uURLSearchHooks: BS Player Toolbar: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - c:\program files\bs_player\tbBS_1.dll<br />
uURLSearchHooks: Radio G Toolbar: {f228c6a4-a593-4017-944c-4e7958fb3177} - c:\program files\radio_g\tbRadi.dll<br />
mWinlogon: System=ziswin.exe<br />
mWinlogon: Userinit=c:\windows\system32\userinit.exe<br />
mWinlogon: Taskman=c:\recycler\s-1-5-21-1340723235-4178647855-870972809-0609\windll.exe<br />
uWinlogon: Shell=explorer.exe &quot;c:\documents and settings\ibm\vilfjh.exe&quot;<br />
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 5.0\acrobat\activex\AcroIEHelper.ocx<br />
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File<br />
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll<br />
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll<br />
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll<br />
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll<br />
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.3.4501.1418\swg.dll<br />
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll<br />
BHO: Radio G Toolbar: {f228c6a4-a593-4017-944c-4e7958fb3177} - c:\program files\radio_g\tbRadi.dll<br />
BHO: BS Player Toolbar: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - c:\program files\bs_player\tbBS_1.dll<br />
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll<br />
TB: BS Player Toolbar: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - c:\program files\bs_player\tbBS_1.dll<br />
TB: Radio G Toolbar: {f228c6a4-a593-4017-944c-4e7958fb3177} - c:\program files\radio_g\tbRadi.dll<br />
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe<br />
uRun: [ibmmessages] c:\program files\ibm\messages by ibm\ibmmessages.exe<br />
uRun: [Skype] &quot;c:\program files\skype\phone\Skype.exe&quot; /nosplash /minimized<br />
uRun: [swg] &quot;c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe&quot;<br />
uRun: [Picasa Media Detector] c:\program files\picasa2\PicasaMediaDetector.exe<br />
uRun: [msnmsgr] &quot;c:\program files\windows live\messenger\msnmsgr.exe&quot; /background<br />
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe<br />
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe<br />
mRun: [TPKMAPHELPER] c:\program files\thinkpad\utilities\TpKmapAp.exe -helper<br />
mRun: [TpShocks] TpShocks.exe<br />
mRun: [TPHOTKEY] c:\progra~1\lenovo\pkgmgr\hotkey\TPHKMGR.exe<br />
mRun: [ControlCenter] &quot;c:\program files\ibm fingerprint software\ctlcntr.exe&quot; /startup<br />
mRun: [TP4EX] tp4ex.exe<br />
mRun: [EZEJMNAP] c:\progra~1\thinkpad\utilit~1\EzEjMnAp.Exe<br />
mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe<br />
mRun: [SoundMAX] c:\program files\analog devices\soundmax\Smax4.exe /tray<br />
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe<br />
mRun: [UpdateManager] &quot;c:\program files\common files\sonic\update manager\sgtray.exe&quot; /r<br />
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe<br />
mRun: [&lt;NO NAME&gt;] <br />
mRun: [ibmmessages] c:\program files\ibm\messages by ibm\\ibmmessages.exe<br />
mRun: [IBMPRC] c:\ibmtools\utils\ibmprc.exe<br />
mRun: [PWRMGRTR] rundll32 c:\progra~1\thinkpad\utilit~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor<br />
mRun: [BLOG] rundll32 c:\progra~1\thinkpad\utilit~1\BatLogEx.DLL,StartBattLog<br />
mRun: [SunJavaUpdateSched] &quot;c:\program files\java\jre1.6.0_07\bin\jusched.exe&quot;<br />
mRun: [ccApp] &quot;c:\program files\common files\symantec shared\ccApp.exe&quot;<br />
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe<br />
mRun: [NDPS] c:\windows\system32\dpmw32.exe<br />
mRun: [ZENRC Tray Icon] c:\windows\system32\zentray.exe<br />
mRun: [NWTRAY] NWTRAY.EXE<br />
mRun: [ACTray] c:\program files\thinkpad\connectutilities\ACTray.exe<br />
mRun: [ACWLIcon] c:\program files\thinkpad\connectutilities\ACWLIcon.exe<br />
mRun: [TPKBDLED] c:\windows\system32\TpScrLk.exe<br />
mRun: [WinampAgent] c:\program files\winamp\winampa.exe<br />
mRun: [zzzHPSETUP] D:\Setup.exe<br />
mRun: [Share-to-Web Namespace Daemon] c:\program files\hewlett-packard\hp share-to-web\hpgs2wnd.exe<br />
mRun: [LogitechQuickCamRibbon] &quot;c:\program files\logitech\quickcam\Quickcam.exe&quot; /hide<br />
mRun: [QuickTime Task] &quot;c:\program files\quicktime\qttask.exe&quot; -atboottime<br />
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE<br />
StartupFolder: c:\docume~1\ibm\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\quickcam\eReg.exe<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\acroba~1.lnk - c:\program files\adobe\acrobat 5.0\distillr\AcroTray.exe<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\bttray.lnk - c:\program files\thinkpad\bluetooth software\BTTray.exe<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\groupw~1.lnk - c:\novell\groupwise\notify.exe<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{a7091e1d-36a4-47f1-a739-173cc341414f}\Icon3E5562ED7.ico<br />
mPolicies-system: CompatibleRUPSecurity = 1 (0x1)<br />
IE: &amp;&#1497;&#1510;&#1488; &#1500;- Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000<br />
IE: Send To &amp;Bluetooth - c:\program files\thinkpad\bluetooth software\btsendto_ie_ctx.htm<br />
IE: {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - c:\program files\lenovo\pkgmgr\\PkgMgr.exe<br />
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe<br />
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe<br />
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll<br />
IE: {C1994287-422F-47aa-8E5E-6323E210A125} - {4B5F7606-8666-4D5A-9780-DB92A9D8812B} - c:\program files\novell\zenworks\AxNalServer.dll<br />
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab<br />
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab<br />
DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/1.4.2/jinstall-142-win.cab<br />
DPF: {CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab<br />
DPF: {CAFEEFAC-0014-0002-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab<br />
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab<br />
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab<br />
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll<br />
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL<br />
Handler: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - c:\windows\system32\BTXPPanel.dll<br />
Notify: ACNotify - ACNotify.dll<br />
Notify: AtiExtEvent - Ati2evxx.dll<br />
Notify: NavLogon - c:\windows\system32\NavLogon.dll<br />
Notify: NetIdentity Notification - c:\windows\system32\novell\XtNotify.dll<br />
Notify: psfus - c:\program files\ibm fingerprint software\psfus.dll<br />
Notify: tpfnf2 - notifyf2.dll<br />
Notify: tphotkey - tphklock.dll<br />
SEH: {763370c4-268e-4308-a60c-d8da0342be32} - c:\program files\novell\zenworks\NalShell.dll<br />
LSA: Authentication Packages = msv1_0 nwv1_0<br />
LSA: Notification Packages = scecli pwdmon<br />
<br />
================= FIREFOX ===================<br />
<br />
FF - ProfilePath - c:\docume~1\ibm\startm~1\applic~1\mozilla\firefox\profiles\ympm0s35.default\<br />
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&amp;SearchSource=3&amp;q={searchTerms}<br />
FF - prefs.js: browser.search.selectedEngine - Bing<br />
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157<br />
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&amp;SearchSource=2&amp;q=<br />
FF - component: c:\program files\mozilla firefox\extensions\browserhighlighter@ebay.com\components\Shim.dll<br />
<br />
---- FIREFOX POLICIES ----<br />
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref(&quot;security.ssl3.rsa_seed_sha&quot;, true);<br />
<br />
============= SERVICES / DRIVERS ===============<br />
<br />
R0 Shockprf;Shockprf;c:\windows\system32\drivers\shockprf.sys [2005-12-20 85760]<br />
R0 TPDiskPM;TPDiskPM;c:\windows\system32\drivers\TPDiskPM.sys [2005-12-20 14720]<br />
R0 vclvrwng;vclvrwng;c:\windows\system32\drivers\vclvrwng.sys --&gt; c:\windows\system32\drivers\vclvrwng.sys [?]<br />
R1 ANC;ANC;c:\windows\system32\drivers\ANC.sys [2005-12-20 11520]<br />
R1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.sys [2005-12-20 6016]<br />
R1 nipplpt2;Novell iCapture Lpt Redirector 2;c:\windows\system32\drivers\nipplpt.sys [2006-2-21 18527]<br />
R1 ShockMgr;ShockMgr;c:\windows\system32\drivers\ShockMgr.sys [2005-12-20 4736]<br />
R1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\TPPWRIF.SYS [2005-12-20 4442]<br />
R2 BlankScr;HBDevice;c:\windows\system32\drivers\blankscr.sys [2004-6-4 6899]<br />
R2 ibmfilter;ibmfilter;c:\windows\system32\drivers\ibmfilter.sys [2005-4-27 63616]<br />
R2 Remote Management Agent;Novell ZfD Remote Management;c:\program files\novell\zenworks\remotemanagement\rmagent\ZenRem32.exe [2004-5-20 163840]<br />
R2 SmiHlp;SMI helper driver;c:\program files\ibm fingerprint software\smihlp.sys [2005-4-12 3328]<br />
R3 Darpan;Darpan;c:\windows\system32\drivers\Darpan.sys [2004-5-10 2773]<br />
R3 TPInput;TPInput;c:\windows\system32\drivers\TPInput.sys [2005-12-20 6400]<br />
R3 TPM11;NSC Integrated Trusted Platform Module 1.1;c:\windows\system32\drivers\nsctpm11.sys [1980-1-1 14336]<br />
R3 XTAgent;Novell XTier Agent Services;c:\windows\system32\novell\xtagent.exe [2004-2-26 61440]<br />
S2 msupdate;Microsoft security update service;c:\windows\system32\mssrv32.exe [2009-10-28 31744]<br />
<br />
=============== Created Last 30 ================<br />
<br />
2009-11-20 17:16:11	12800	---ha-w-	c:\documents and settings\ibm\vilfjh.exe<br />
2009-11-20 06:53:11	0	d-----w-	c:\program files\Citrix<br />
2009-11-16 03:32:59	0	d-----w-	c:\program files\Microsoft CAPICOM 2.1.0.2<br />
2009-11-15 05:12:20	215920	----a-w-	c:\windows\system32\muweb.dll<br />
2009-11-15 05:12:19	274288	----a-w-	c:\windows\system32\mucltui.dll<br />
2009-11-15 05:12:19	16736	----a-w-	c:\windows\system32\mucltui.dll.mui<br />
2009-11-15 02:07:43	0	d-----w-	c:\docume~1\alluse~1\applic~1\BigFishGamesCache<br />
2009-11-14 23:46:25	0	d-----w-	c:\documents and settings\ibm\Tracing<br />
2009-11-14 23:43:12	0	d-----w-	c:\program files\Microsoft<br />
2009-11-14 23:42:36	0	d-----w-	c:\program files\Windows Live SkyDrive<br />
2009-11-14 23:37:15	0	d-----w-	c:\program files\common files\Windows Live<br />
2009-11-14 23:20:11	12800	---ha-w-	c:\documents and settings\ibm\yohhwx.exe<br />
2009-11-09 08:23:59	0	d-----w-	c:\windows\Internet Logs<br />
2009-11-09 08:22:30	125328	----a-w-	c:\windows\system32\drivers\dne2000.sys<br />
2009-11-09 08:22:30	106768	----a-w-	c:\windows\system32\dneinobj.dll<br />
2009-11-09 08:21:40	0	d-----w-	c:\program files\common files\Deterministic Networks<br />
2009-11-09 08:21:33	0	d-----w-	c:\program files\Cisco Systems<br />
2009-11-09 08:21:11	1594	----a-w-	c:\windows\VPNInstall.MIF<br />
2009-11-06 16:00:13	0	d-----w-	c:\program files\common files\Logitech<br />
2009-11-04 18:26:14	0	d-----w-	c:\program files\Radio_G<br />
2009-11-03 03:06:04	0	----a-w-	c:\windows\system32\drivers\lvuvc.hs<br />
2009-11-03 03:05:50	494104	----a-r-	c:\windows\system32\LVUI2.dll<br />
2009-11-03 03:05:50	432664	----a-r-	c:\windows\system32\LVUI2RC.dll<br />
2009-11-03 03:05:50	416280	----a-r-	c:\windows\system32\lvcodec2.dll<br />
2009-11-03 03:05:49	6364440	----a-r-	c:\windows\system32\drivers\lvuvc.sys<br />
2009-11-03 03:04:48	81110	----a-r-	c:\windows\system32\lvcoinst.ini<br />
2009-11-03 03:04:48	29562	----a-r-	c:\windows\system32\Repository.reg<br />
2009-11-03 03:04:48	195096	----a-r-	c:\windows\system32\lvci11901262.dll<br />
2009-11-03 03:04:47	768024	----a-r-	c:\windows\system32\drivers\lvrs.sys<br />
2009-11-03 03:04:47	41752	----a-r-	c:\windows\system32\drivers\LVUSBSta.sys<br />
2009-11-03 03:03:35	0	----a-w-	c:\windows\system32\drivers\logiflt.iad<br />
2009-11-03 03:03:30	23832	----a-r-	c:\windows\system32\drivers\lvuvcflt.sys<br />
2009-11-03 02:53:41	0	d-----r-	c:\program files\Skype<br />
2009-11-03 01:57:31	49904	----a-r-	c:\windows\system32\drivers\BVRPMPR5.SYS<br />
2009-11-03 01:56:16	0	d-----w-	C:\Netgear<br />
2009-10-28 03:22:40	31744	----a-w-	c:\windows\system32\mssrv32.exe<br />
<br />
==================== Find3M  ====================<br />
<br />
2009-10-21 04:08:54	3598336	------w-	c:\windows\system32\dllcache\mshtml.dll<br />
2009-10-20 20:11:39	12288	---ha-w-	c:\documents and settings\ibm\dbxvvm.exe<br />
2009-10-11 19:46:45	12288	---ha-w-	c:\documents and settings\ibm\nrliry.exe<br />
2009-10-04 05:10:04	12288	---ha-w-	c:\documents and settings\ibm\ayn.exe<br />
2009-10-01 21:05:51	12288	---ha-w-	c:\documents and settings\ibm\mmbtl.exe<br />
2009-09-30 17:37:50	12288	---ha-w-	c:\documents and settings\ibm\kichj.exe<br />
2009-09-30 17:36:18	33440	----a-w-	c:\windows\system32\drivers\vclvrwng.sys<br />
2009-09-30 17:34:44	42496	---h--w-	c:\documents and settings\ibm\secupdat.dat<br />
2009-09-30 17:34:44	12288	---ha-w-	c:\documents and settings\ibm\hsxq.exe<br />
2009-09-11 14:03:37	136192	----a-w-	c:\windows\system32\msv1_0.dll<br />
2009-09-11 14:03:37	136192	------w-	c:\windows\system32\dllcache\msv1_0.dll<br />
2009-09-04 20:45:26	58880	----a-w-	c:\windows\system32\msasn1.dll<br />
2009-09-04 20:45:26	58880	------w-	c:\windows\system32\dllcache\msasn1.dll<br />
2009-08-28 10:28:59	70656	------w-	c:\windows\system32\dllcache\ie4uinit.exe<br />
2009-08-28 10:28:59	13824	------w-	c:\windows\system32\dllcache\ieudinit.exe<br />
2009-08-27 05:18:44	634648	------w-	c:\windows\system32\dllcache\iexplore.exe<br />
2009-08-27 05:18:41	161792	------w-	c:\windows\system32\dllcache\ieakui.dll<br />
2009-08-26 08:16:37	247326	----a-w-	c:\windows\system32\strmdll.dll<br />
2009-08-26 08:16:37	247326	----a-w-	c:\windows\system32\dllcache\strmdll.dll<br />
<br />
============= FINISH: 19:22:55.21 ===============</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techsupportforum.com/cwd/images/attach/zip.gif" alt="File Type: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techsupportforum.com/attachments/virus-trojan-spyware-help/60584d1258756844-computer-extremely-slow-attach.zip">attach.zip</a> (5.6 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/">Virus/Trojan/Spyware Help</category>
			<dc:creator>shalevi</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433736-computer-extremely-slow.html</guid>
		</item>
		<item>
			<title>Random Sound Effects and Random Pop-Up Ads</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433725-random-sound-effects-random-pop-up-ads.html</link>
			<pubDate>Fri, 20 Nov 2009 22:08:19 GMT</pubDate>
			<description>I am getting random sound effects and random pop-up adds.  I think it is due to the perfs.exe virus I have been reading about, but I cannot seam to shake it.  Below is my HJT summary. 
 
rend Micro HijackThis v2.0.2 
Scan saved at 4:08:07 PM, on 11/20/2009 
Platform: Windows XP SP2 (WinNT...</description>
			<content:encoded><![CDATA[<div>I am getting random sound effects and random pop-up adds.  I think it is due to the perfs.exe virus I have been reading about, but I cannot seam to shake it.  Below is my HJT summary.<br />
<br />
rend Micro HijackThis v2.0.2<br />
Scan saved at 4:08:07 PM, on 11/20/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\System32\WLTRYSVC.EXE<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\System32\bcmwltry.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
c:\program files\idt\xpm09_6047v002\wdm\STacSV.exe<br />
C:\WINDOWS\system32\igfxtray.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\WINDOWS\system32\AESTFltr.exe<br />
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe<br />
C:\WINDOWS\system32\WLTRAY.exe<br />
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
C:\Program Files\IDT\WDM\sttray.exe<br />
C:\Program Files\DellTPad\Apoint.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\WINDOWS\system32\igfxsrvc.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
C:\Program Files\DellTPad\ApMsgFwd.exe<br />
C:\Program Files\DellTPad\HidFind.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Program Files\DellTPad\Apntex.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Skype\Phone\Skype.exe<br />
C:\Program Files\Skype\Plugin Manager\skypePM.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\AutoCAD 2010\acad.exe<br />
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
C:\Program Files\Common Files\Autodesk Shared\WSCommCntr1.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: (no name) - {3339222d-40ef-42b1-9213-3b50b939a003} - wewusigo.dll (file missing)<br />
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [OutpostMonitor] C:\PROGRA~1\Agnitum\OUTPOS~1\op_mon.exe /tray /noservice<br />
O4 - HKLM\..\Run: [OutpostFeedBack] &quot;C:\Program Files\Agnitum\Outpost Firewall\feedback.exe&quot; /dump:os_startup<br />
O4 - HKLM\..\Run: [AESTFltr] %SystemRoot%\system32\AESTFltr.exe /NoDlg<br />
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] &quot;C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe&quot;<br />
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe<br />
O4 - HKLM\..\Run: [HP Software Update] &quot;C:\Program Files\HP\HP Software Update\HPWuSchd2.exe&quot;<br />
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart<br />
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe<br />
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br />
O4 - HKCU\..\Run: [Skype] &quot;C:\Program Files\Skype\Phone\Skype.exe&quot; /nosplash /minimized<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br />
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O20 - AppInit_DLLs: c:\progra~1\agnitum\outpos~1\wl_hook.dll  c:\windows\system32\kiropevu.dll,sosilore.dll<br />
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll<br />
O21 - SSODL: nazakimur - {0f41445e-713d-469d-928d-aebbc87ae1ff} - c:\windows\system32\kiropevu.dll (file missing)<br />
O22 - SharedTaskScheduler: tokatiluy - {0f41445e-713d-469d-928d-aebbc87ae1ff} - c:\windows\system32\kiropevu.dll (file missing)<br />
O23 - Service: Agnitum Client Security Service (acssrv) - Agnitum Ltd. - C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe<br />
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: Google Update Service (gupdate1ca28dbe5d2336c) (gupdate1ca28dbe5d2336c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: Audio Service (STacSV) - IDT, Inc. - c:\program files\idt\xpm09_6047v002\wdm\STacSV.exe<br />
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE<br />
<br />
--<br />
End of file - 8810 bytes</div>

]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/">Virus/Trojan/Spyware Help</category>
			<dc:creator>da_jerke</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433725-random-sound-effects-random-pop-up-ads.html</guid>
		</item>
		<item>
			<title>I think this is a virus... Drops CPU Usage to 0% and Freezes with internet disconnect</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433685-i-think-virus-drops-cpu-usage-0-freezes-internet-disconnect.html</link>
			<pubDate>Fri, 20 Nov 2009 19:52:54 GMT</pubDate>
			<description><![CDATA[Unfortunately the computer crashed on my GMER scan, so I only got the amount of the scan I managed to save. However I managed to fully run the other scanner, and save both logs. 
 
Please help me if you can, I don't know what to do and I'm sick of not being able to do anything on my computer...]]></description>
			<content:encoded><![CDATA[<div>Unfortunately the computer crashed on my GMER scan, so I only got the amount of the scan I managed to save. However I managed to fully run the other scanner, and save both logs.<br />
<br />
Please help me if you can, I don't know what to do and I'm sick of not being able to do anything on my computer without crashing... and losing the internet.<br />
<br />
I don't have the resources to reformat.<br />
<br />
<br />
DDS (Ver_09-10-26.01) - NTFSx86  <br />
Run by Dawnie at 11:07:18.18 on 11/20/2009 Fri<br />
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_07<br />
AV: Kaspersky Internet Security *On-access scanning enabled* (Outdated)   {2C4D4BC6-0793-4956-A9F9-E252435469C0}<br />
FW: Kaspersky Internet Security *enabled*   {2C4D4BC6-0793-4956-A9F9-E252435469C0}<br />
FW:  *disabled*   {82B1150E-9B37-49FC-83EB-D52197D900D0}<br />
<br />
============== Running Processes ===============<br />
<br />
<br />
============== Pseudo HJT Report ===============<br />
<br />
uStart Page = hxxp://www.google.com<br />
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/toolbar/ie7/done.html<br />
uInternet Settings,ProxyOverride = localhost<br />
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File<br />
BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll<br />
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll<br />
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll<br />
TB: &amp;Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll<br />
TB: &amp;RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll<br />
uRun: [LDM] c:\program files\logitech\desktop messenger\8876480\program\BackWeb-8876480.exe<br />
uRun: [MSMSGS] &quot;c:\program files\messenger\msmsgs.exe&quot; /background<br />
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup<br />
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit<br />
mRun: [QuickTime Task] &quot;c:\program files\quicktime\qttask.exe&quot; -atboottime<br />
mRun: [itype] &quot;c:\program files\microsoft intellitype pro\itype.exe&quot;<br />
mRun: [WTClient] WTClient.exe<br />
mRun: [Malwarebytes Anti-Malware (reboot)] &quot;c:\program files\malwarebytes' anti-malware\mbam.exe&quot; /runcleanupscript<br />
mRun: [SunJavaUpdateSched] &quot;c:\program files\java\jre1.6.0_07\bin\jusched.exe&quot;<br />
mRun: [SmartDefrag] &quot;c:\program files\iobit\iobit smartdefrag\IObit SmartDefrag.exe&quot; /StartUp<br />
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe<br />
dRun: [DWQueuedReporting] &quot;c:\progra~1\common~1\micros~1\dw\dwtrig20.exe&quot; -t<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\desktop messenger\8876480\program\LDMConf.exe<br />
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html<br />
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html<br />
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html<br />
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe<br />
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe<br />
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\npjpi160_07.dll<br />
DPF: {00001025-A15C-11D4-97A4-0050BF0FBE67} - hxxp://download.netmarble.net/web/nmstarter/NMStarter25.cab<br />
DPF: {00001026-A15C-11D4-97A4-0050BF0FBE67} - hxxp://download.netmarble.net/web/nmstarter/NMStarter26.cab<br />
DPF: {166B1BCA-3F9C-11CF-8075-444553540000}<br />
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab<br />
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab<br />
DPF: {6414512b-b978-451d-a0d8-fcfdf33e833c} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1235565824480<br />
DPF: {7606693a-c18d-4567-af85-6194ff70761e} - hxxp://app.ipop.co.kr/gom/GomWeb.cab<br />
DPF: {8768d5ea-5412-4810-a032-09ad2a726c69} - hxxp://bgweb.nowcdn.co.kr/Bin/DownStarter2.cab<br />
DPF: {87A638DE-396F-40FD-A2F8-01B56072F553} - hxxp://download.gemfighter.com/launcher/gemx2.cab<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab<br />
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab<br />
DPF: {92E82FBB-DA00-41E0-ABFE-95482E21A4F6} - hxxp://download.netmarble.net/NMChatX/NMTransX.cab<br />
DPF: {A4508A45-F1C4-40F3-99B4-0CA08AC77E3B} - hxxp://download.netmarble.net/kdefence/kdfense8237.cab<br />
DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} - hxxp://download.microsoft.com/download/PowerPoint2002/Install/10.0.2609/WIN98MeXP/EN-US/msorun.cab<br />
DPF: {b8339132-e751-452b-87f5-5f3d4365638b} - hxxp://gf.wemade.com/comsso/weGameLauncher.cab<br />
DPF: {BD68328E-1222-4A62-BA16-E6F42CA49A64} - hxxp://gf.wemade.com/comsso/active/WMInstallMgr.cab<br />
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab<br />
DPF: {CBB45291-871B-4ADA-81D0-40D0C89ABD20} - hxxp://download.netmarble.net/web/NMGameCheck/NetmarbleDownloaderEx3013.cab<br />
DPF: {D912AABC-6CB0-416F-85B6-CABBB86FD558} - hxxps://plugin.inicis.com/wallet60_inilite/INIwallet60.cab<br />
Notify: avgrsstarter - avgrsstx.dll<br />
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll<br />
<br />
================= FIREFOX ===================<br />
<br />
FF - ProfilePath - c:\docume~1\dawnie\applic~1\mozilla\firefox\profiles\rzchs6jz.default\<br />
FF - prefs.js: browser.search.defaulturl - hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&amp;v=4&amp;q=<br />
FF - prefs.js: browser.search.selectedEngine - Fast Browser Search<br />
FF - prefs.js: keyword.URL - hxxp://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&amp;v=4&amp;tid={3C1A2D56-AE1A-1F93-B78B-BAB2FA52F798}&amp;q=<br />
FF - plugin: c:\documents and settings\all users\application data\nexon\ngm\npNxGame.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\npbyond.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\NPGomtvx_nie.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\npOGPPlugin.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\npPandoWebInst.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\NPZoneSB.dll<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}<br />
<br />
============= SERVICES / DRIVERS ===============<br />
<br />
<br />
=============== Created Last 30 ================<br />
<br />
2009-11-20 13:58:52	0	d-sh--w-	C:\found.000<br />
2009-11-20 08:07:20	77312	----a-w-	c:\windows\MBR.exe<br />
2009-11-20 08:07:20	260608	----a-w-	c:\windows\PEV.exe<br />
2009-11-20 07:39:34	1393	----a-w-	c:\windows\imsins.BAK<br />
2009-11-20 07:38:21	0	d-sh--w-	c:\documents and settings\dawnie\IECompatCache<br />
2009-11-20 07:22:14	0	d-sh--w-	c:\documents and settings\dawnie\PrivacIE<br />
2009-11-20 07:20:04	0	d-sh--w-	c:\documents and settings\dawnie\IETldCache<br />
2009-11-20 07:08:20	92160	-c----w-	c:\windows\system32\dllcache\iecompat.dll<br />
2009-11-20 07:08:07	0	d-----w-	c:\windows\ie8updates<br />
2009-11-20 07:08:01	12800	-c----w-	c:\windows\system32\dllcache\xpshims.dll<br />
2009-11-20 07:08:00	246272	-c----w-	c:\windows\system32\dllcache\ieproxy.dll<br />
2009-11-20 07:06:04	0	dc-h--w-	c:\windows\ie8<br />
2009-11-20 06:57:56	771581	-c--a-w-	c:\windows\system32\dllcache\winacisa.sys<br />
2009-11-20 06:56:59	60032	-c--a-w-	c:\windows\system32\dllcache\usbaudio.sys<br />
2009-11-20 06:55:59	41472	-c--a-w-	c:\windows\system32\dllcache\sw_effct.dll<br />
2009-11-20 06:54:59	63547	-c--a-w-	c:\windows\system32\dllcache\sla30nd5.sys<br />
2009-11-20 06:53:56	29696	-c--a-w-	c:\windows\system32\dllcache\rw450ext.dll<br />
2009-11-20 06:52:58	211584	-c--a-w-	c:\windows\system32\dllcache\perm2dll.dll<br />
2009-11-20 06:51:59	132695	-c--a-w-	c:\windows\system32\dllcache\netwlan5.sys<br />
2009-11-20 06:50:58	320384	-c--a-w-	c:\windows\system32\dllcache\mgaum.sys<br />
2009-11-20 06:49:44	26624	-c--a-w-	c:\windows\system32\dllcache\irstusb.sys<br />
2009-11-20 06:48:59	109085	-c--a-w-	c:\windows\system32\dllcache\ibmtrp.sys<br />
2009-11-20 06:47:59	59136	-c--a-w-	c:\windows\system32\dllcache\gckernel.sys<br />
2009-11-20 06:46:58	25159	-c--a-w-	c:\windows\system32\dllcache\elnk3.sys<br />
2009-11-20 06:45:59	25600	-c--a-w-	c:\windows\system32\dllcache\dc210_32.dll<br />
2009-11-20 06:44:59	121856	-c--a-w-	c:\windows\system32\dllcache\camext30.dll<br />
2009-11-20 06:44:59	116736	-c--a-w-	c:\windows\system32\dllcache\camext30.ax<br />
2009-11-20 06:44:58	236032	-c--a-w-	c:\windows\system32\dllcache\camext20.dll<br />
2009-11-20 06:44:57	244224	-c--a-w-	c:\windows\system32\dllcache\camext20.ax<br />
2009-11-20 06:44:56	74240	-c--a-w-	c:\windows\system32\dllcache\camexo20.dll<br />
2009-11-20 06:44:55	73216	-c--a-w-	c:\windows\system32\dllcache\camexo20.ax<br />
2009-11-20 06:44:55	171264	-c--a-w-	c:\windows\system32\dllcache\camdrv30.sys<br />
2009-11-20 06:44:54	223232	-c--a-w-	c:\windows\system32\dllcache\camdrv21.sys<br />
2009-11-20 06:44:53	314752	-c--a-w-	c:\windows\system32\dllcache\camdro21.sys<br />
2009-11-20 06:44:12	4224	-c--a-w-	c:\windows\system32\dllcache\beep.sys<br />
2009-11-20 06:13:24	50968	----a-w-	c:\windows\system32\avgfwdx.dll<br />
2009-11-20 06:13:24	30104	----a-w-	c:\windows\system32\drivers\avgfwdx.sys<br />
2009-11-20 06:13:15	0	d-----w-	c:\docume~1\alluse~1\applic~1\avg9<br />
2009-11-20 05:56:37	0	d-----w-	c:\docume~1\dawnie\applic~1\AVG8<br />
2009-11-20 05:32:28	0	d-----w-	c:\docume~1\dawnie\applic~1\SogouPY<br />
2009-11-20 05:32:27	0	d-----w-	c:\docume~1\dawnie\applic~1\SogouPY.users<br />
2009-11-20 05:19:20	0	d-----w-	c:\docume~1\dawnie\applic~1\Uniblue<br />
2009-11-20 04:49:03	0	d-----w-	c:\docume~1\dawnie\applic~1\IObit<br />
2009-11-20 04:47:53	0	d-----w-	c:\docume~1\dawnie\applic~1\Malwarebytes<br />
2009-11-20 00:59:28	0	d-----w-	c:\windows\system32\wbem\Repository<br />
2009-11-19 23:56:36	0	----a-w-	c:\windows\system.ini<br />
2009-11-19 21:06:44	0	d-----w-	c:\program files\Cacheman<br />
2009-11-19 21:02:52	0	d-----w-	c:\program files\CachemanXP<br />
2009-11-02 21:23:48	332	----a-w-	c:\windows\WpePro_0delay.INI<br />
2009-11-01 10:56:44	0	d-----w-	c:\program files\MSXML 4.0<br />
2009-11-01 06:43:14	0	d-----w-	c:\program files\Chatango<br />
2009-10-25 06:57:34	3022158	----a-w-	c:\windows\system32\GameMon.des<br />
<br />
==================== Find3M  ====================<br />
<br />
2009-10-17 00:37:23	34320	----a-w-	c:\windows\system32\GDIPFONTCACHEV1.DAT<br />
2009-10-09 20:12:08	62688	----a-w-	c:\windows\system32\WMWebLauncherUninst.exe<br />
2009-10-09 20:12:04	255200	----a-w-	c:\windows\system32\SystemObserver.dll<br />
2009-10-09 20:11:54	54496	----a-w-	c:\windows\system32\GetInfoLauncher.exe<br />
2009-09-14 20:42:47	3065	----a-w-	c:\windows\system32\SpoonUninstall-dBpoweramp Ogg Vorbis Codec.dat<br />
2009-09-14 20:42:38	652152	----a-w-	c:\windows\system32\SpoonUninstall.exe<br />
2009-09-14 20:40:44	15341	----a-w-	c:\windows\system32\SpoonUninstall-dBpoweramp Music Converter.dat<br />
2009-09-11 14:18:39	136192	----a-w-	c:\windows\system32\msv1_0.dll<br />
2009-09-09 04:58:58	419040	----a-w-	c:\windows\system32\WMInstallMgrUninst.exe<br />
2009-09-09 04:58:50	423136	----a-w-	c:\windows\system32\WMInstallMgrLauncher.exe<br />
2009-09-04 21:03:36	58880	----a-w-	c:\windows\system32\msasn1.dll<br />
2009-08-29 08:08:21	916480	------w-	c:\windows\system32\wininet.dll<br />
2009-08-26 08:00:21	247326	----a-w-	c:\windows\system32\strmdll.dll<br />
2008-12-10 05:42:42	2	--shatr-	c:\windows\winstart.bat<br />
2008-12-07 03:23:52	32768	--sha-w-	c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008120620081207\index.dat<br />
<br />
============= FINISH: 11:08:18.53 ===============<br />
<br />
Edit: added my.. main log. Forgot this was required.</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techsupportforum.com/cwd/images/attach/rar.gif" alt="File Type: rar" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techsupportforum.com/attachments/virus-trojan-spyware-help/60577d1258746737-i-think-virus-drops-cpu-usage-0-freezes-internet-disconnect-attach.rar">attach.rar</a> (7.8 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/">Virus/Trojan/Spyware Help</category>
			<dc:creator>DawnAP</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433685-i-think-virus-drops-cpu-usage-0-freezes-internet-disconnect.html</guid>
		</item>
		<item>
			<title>Google Hi-jacker - Asked for Scans included</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433676-google-hi-jacker-asked-scans-included.html</link>
			<pubDate>Fri, 20 Nov 2009 19:26:49 GMT</pubDate>
			<description>Recently my fiances computer has been redirecting her google,yahoo, an other seraches to a searchclick8.com or uniquesearch.com website. Ive ran malwarbytes,avg,adaware, an other things like this in regular an safe mode cant find anything that stops it, any help would be appreciated 
 
 
 
 
 
...</description>
			<content:encoded><![CDATA[<div>Recently my fiances computer has been redirecting her google,yahoo, an other seraches to a searchclick8.com or uniquesearch.com website. Ive ran malwarbytes,avg,adaware, an other things like this in regular an safe mode cant find anything that stops it, any help would be appreciated<br />
<br />
<br />
<br />
<br />
<br />
<br />
DDS (Ver_09-10-26.01) - NTFSx86  <br />
Run by Owner at 11:07:47.41 on Fri 11/20/2009<br />
Internet Explorer: 7.0.5730.11<br />
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.2047.350 [GMT -6:00]<br />
<br />
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)   {17DDD097-36FF-435F-9E1B-52D74245D6BF}<br />
<br />
============== Running Processes ===============<br />
<br />
C:\WINDOWS\system32\svchost -k DcomLaunch<br />
svchost.exe<br />
C:\WINDOWS\System32\svchost.exe -k netsvcs<br />
svchost.exe<br />
svchost.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Program Files\Messenger\msmsgs.exe<br />
C:\Program Files\Electronic Arts\EADM\Core.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\system32\svchost.exe -k imgsvc<br />
C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
C:\Program Files\AVG\AVG8\avgcsrvx.exe<br />
C:\WINDOWS\system32\igfxsrvc.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\Program Files\World of Warcraft\BackgroundDownloader.exe<br />
C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\WINDOWS\system32\msiexec.exe<br />
C:\Documents and Settings\Owner\Desktop\dds.scr<br />
<br />
============== Pseudo HJT Report ===============<br />
<br />
uStart Page = hxxp://www.google.com<br />
mStart Page = hxxp://www.google.com<br />
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File<br />
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll<br />
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.3.4501.1418\swg.dll<br />
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll<br />
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll<br />
uRun: [swg] &quot;c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe&quot;<br />
uRun: [Steam] &quot;c:\program files\steam\Steam.exe&quot; -silent<br />
uRun: [NCsoft Launcher] c:\program files\ncsoft\launcher\NCLauncher.exe /Minimized<br />
uRun: [MSMSGS] &quot;c:\program files\messenger\msmsgs.exe&quot; /background<br />
uRun: [EA Core] &quot;c:\program files\electronic arts\eadm\Core.exe&quot; -silent<br />
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe<br />
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup<br />
mRun: [RTHDCPL] RTHDCPL.EXE<br />
mRun: [Persistence] c:\windows\system32\igfxpers.exe<br />
mRun: [nwiz] nwiz.exe /install<br />
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit<br />
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe<br />
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe<br />
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe<br />
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\frostw~1.lnk - c:\program files\frostwire\FrostWire.exe<br />
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe<br />
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe<br />
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe<br />
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab<br />
DPF: {75A6AEA3-F26E-4608-AE9B-8DA78C87576E} - hxxps://secure.footprint.net/kingsisle/static/themes/wizard101A/activex/Wizard101GameLauncher.CAB<br />
DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - hxxp://www.nick.com/common/groove/gx/GrooveAX27.cab<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab<br />
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab<br />
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab<br />
TCP: {E2566E08-70C4-46E8-B2DE-964649B53256} = 77.74.48.113<br />
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll<br />
Notify: avgrsstarter - avgrsstx.dll<br />
Notify: igfxcui - igfxdev.dll<br />
<br />
============= SERVICES / DRIVERS ===============<br />
<br />
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-7-14 335240]<br />
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-7-14 108552]<br />
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2008-7-17 908056]<br />
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-7-17 297752]<br />
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-10-13 24652]<br />
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --&gt; c:\windows\system32\GameMon.des -service [?]<br />
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --&gt; d:\NTGLM7X.sys [?]<br />
<br />
=============== Created Last 30 ================<br />
<br />
2009-11-14 00:02:50	50176	-c--a-w-	c:\windows\system32\dllcache\proquota.exe<br />
2009-11-14 00:02:50	50176	----a-w-	c:\windows\system32\proquota.exe<br />
2009-11-13 23:56:41	0	d-sha-r-	C:\cmdcons<br />
2009-11-13 23:55:42	98816	----a-w-	c:\windows\sed.exe<br />
2009-11-13 23:55:42	77312	----a-w-	c:\windows\MBR.exe<br />
2009-11-13 23:55:42	260608	----a-w-	c:\windows\PEV.exe<br />
2009-11-13 23:55:42	161792	----a-w-	c:\windows\SWREG.exe<br />
2009-11-13 23:49:37	0	d-----w-	c:\program files\Trend Micro<br />
2009-11-10 01:59:28	0	d-----w-	c:\windows\pss<br />
2009-11-09 16:58:22	552	----a-w-	c:\windows\system32\d3d8caps.dat<br />
2009-11-09 15:47:19	0	----a-w-	c:\windows\Fjazuveruqap.bin<br />
2009-11-09 15:47:18	120	----a-w-	c:\windows\Dtaruneseyomebuf.dat<br />
2009-11-09 15:43:59	826	----a-w-	c:\windows\system32\wininit.dll<br />
2009-11-09 15:43:22	0	--sha-w-	C:\-392678739<br />
2009-11-08 21:58:25	0	d-----w-	c:\docume~1\owner\applic~1\FrostWire<br />
2009-11-08 21:58:02	0	d-----w-	c:\program files\FrostWire<br />
<br />
==================== Find3M  ====================<br />
<br />
2009-09-26 13:29:04	335240	----a-w-	c:\windows\system32\drivers\avgldx86.sys<br />
2009-09-26 13:29:04	11952	----a-w-	c:\windows\system32\avgrsstx.dll<br />
2009-07-24 02:10:33	16385	----a-w-	c:\program files\common files\xojabyf.dll<br />
2008-07-14 18:31:44	32768	--sha-w-	c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008071420080715\index.dat<br />
<br />
============= FINISH: 11:08:02.52 ===============</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techsupportforum.com/cwd/images/attach/zip.gif" alt="File Type: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techsupportforum.com/attachments/virus-trojan-spyware-help/60574d1258745162-google-hi-jacker-asked-scans-included-attach.zip">Attach.zip</a> (3.2 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/">Virus/Trojan/Spyware Help</category>
			<dc:creator>Tubs.needs.help</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433676-google-hi-jacker-asked-scans-included.html</guid>
		</item>
		<item>
			<title>RUNDLL ugewome error</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433667-rundll-ugewome-error.html</link>
			<pubDate>Fri, 20 Nov 2009 18:50:05 GMT</pubDate>
			<description><![CDATA[Hey guys, thanks in advance for any help given. I appreciate it as I have no idea what im doing. The error message only comes up once when I turn my PC on. I click 'cancel' and its fine until the next startup. I had the same or a similar problem about 2months ago but it came up every 15 seconds or...]]></description>
			<content:encoded><![CDATA[<div>Hey guys, thanks in advance for any help given. I appreciate it as I have no idea what im doing. The error message only comes up once when I turn my PC on. I click 'cancel' and its fine until the next startup. I had the same or a similar problem about 2months ago but it came up every 15 seconds or so until the AVG scan had finished and then it was gone. Heres my scan info:<br />
<br />
<br />
DDS (Ver_09-10-26.01) - NTFSx86  <br />
Run by Nicola at 18:11:29.81 on Wed 11/18/2009<br />
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_17<br />
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.1015.424 [GMT -5:00]<br />
<br />
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)   {17DDD097-36FF-435F-9E1B-52D74245D6BF}<br />
<br />
============== Running Processes ===============<br />
<br />
C:\WINDOWS\system32\svchost -k DcomLaunch<br />
svchost.exe<br />
C:\WINDOWS\System32\svchost.exe -k netsvcs<br />
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
svchost.exe<br />
svchost.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
svchost.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
C:\WINDOWS\system32\svchost.exe -k imgsvc<br />
C:\Program Files\AVG\AVG9\avgemc.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\WINDOWS\system32\igfxtray.exe<br />
C:\WINDOWS\system32\igfxsrvc.exe<br />
C:\Program Files\Elantech\ETDCtrl.exe<br />
C:\Program Files\Elantech\ETDDect.exe<br />
C:\Program Files\EeePC\ACPI\AsTray.exe<br />
C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe<br />
C:\Program Files\EeePC\ACPI\AsEPCMon.exe<br />
C:\WINDOWS\system32\igfxext.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\Program Files\DAEMON Tools Lite\daemon.exe<br />
C:\Program Files\Steam\Steam.exe<br />
C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe<br />
C:\Documents and Settings\Nicola\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\Nicola\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\Nicola\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\Nicola\My Documents\Downloads\dds.scr<br />
<br />
============== Pseudo HJT Report ===============<br />
<br />
uStart Page = hxxp://eeepc.asus.com/global<br />
uInternet Connection Wizard,ShellNext = hxxp://eeepc.asus.com/global<br />
uInternet Settings,ProxyOverride = *.local<br />
uURLSearchHooks: {e312764e-7706-43f1-8dab-fcdd2b1e416d} - c:\program files\pdfforge toolbar\SearchSettings.dll<br />
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll<br />
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll<br />
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll<br />
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File<br />
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll<br />
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll<br />
BHO: pdfforge Toolbar: {b922d405-6d13-4a2b-ae89-08a030da4402} - c:\program files\pdfforge toolbar\pdfforgeToolbarIE.dll<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll<br />
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll<br />
BHO: {e312764e-7706-43f1-8dab-fcdd2b1e416d} - c:\program files\pdfforge toolbar\SearchSettings.dll<br />
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
TB: &amp;Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll<br />
TB: pdfforge Toolbar: {b922d405-6d13-4a2b-ae89-08a030da4402} - c:\program files\pdfforge toolbar\pdfforgeToolbarIE.dll<br />
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File<br />
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe<br />
uRun: [msnmsgr] &quot;c:\program files\windows live\messenger\msnmsgr.exe&quot; /background<br />
uRun: [DW6] &quot;c:\program files\the weather channel fw\desktop\DesktopWeather.exe&quot;<br />
uRun: [DAEMON Tools Lite] &quot;c:\program files\daemon tools lite\daemon.exe&quot; -autorun<br />
uRun: [Google Update] &quot;c:\documents and settings\nicola\local settings\application data\google\update\GoogleUpdate.exe&quot; /c<br />
uRun: [Steam] &quot;c:\program files\steam\Steam.exe&quot; -silent<br />
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe<br />
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe<br />
mRun: [Persistence] c:\windows\system32\igfxpers.exe<br />
mRun: [ETDWare] c:\program files\elantech\ETDCtrl.exe<br />
mRun: [ETDWareDetect] c:\program files\elantech\ETDDect.exe<br />
mRun: [AsusTray] c:\program files\eeepc\acpi\AsTray.exe<br />
mRun: [AsusACPIServer] c:\program files\eeepc\acpi\AsAcpiSvr.exe<br />
mRun: [AsusEPCMonitor] c:\program files\eeepc\acpi\AsEPCMon.exe<br />
mRun: [IMJPMIG8.1] &quot;c:\windows\ime\imjp8_1\IMJPMIG.EXE&quot; /Spoil /RemAdvDef /Migration32<br />
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC<br />
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC<br />
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName<br />
mRun: [SearchSettings] c:\program files\pdfforge toolbar\SearchSettings.exe<br />
mRun: [Smipil] rundll32.exe &quot;c:\windows\ugemewome.dll&quot;,e<br />
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe<br />
mRun: [SunJavaUpdateSched] &quot;c:\program files\java\jre6\bin\jusched.exe&quot;<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\superh~1.lnk - c:\program files\asus\eeepc\super hybrid engine\SuperHybridEngine.exe<br />
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe<br />
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe<br />
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll<br />
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab<br />
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL<br />
Notify: avgrsstarter - avgrsstx.dll<br />
Notify: igfxcui - igfxdev.dll<br />
Notify: sysfldr - sysfldr.dll<br />
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll<br />
LSA: Notification Packages = scecli mrouot.dll<br />
<br />
================= FIREFOX ===================<br />
<br />
FF - ProfilePath - c:\docume~1\nicola\applic~1\mozilla\firefox\profiles\mb5ff9wr.default\<br />
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll<br />
FF - component: c:\program files\mozilla firefox\extensions\search@searchsettings.com\components\SearchSettingsFF.dll<br />
FF - plugin: c:\documents and settings\nicola\local settings\application data\google\update\1.2.183.13\npGoogleOneClick8.dll<br />
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll<br />
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\<br />
FF - HiddenExtension: XUL Cache: {FEC4F67B-0716-464A-B22E-45D3C82530D0} - c:\documents and settings\nicola\local settings\application data\{FEC4F67B-0716-464A-B22E-45D3C82530D0}<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}<br />
<br />
============= SERVICES / DRIVERS ===============<br />
<br />
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-4-5 333192]<br />
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-4-5 360584]<br />
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2009-11-7 906520]<br />
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2009-11-7 285392]<br />
R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512]<br />
R3 AsusACPI;ASUS ACPI Driver;c:\windows\system32\drivers\ASUSACPI.SYS [2010-11-17 10752]<br />
R3 Ktp;Elantech TouchPad;c:\windows\system32\drivers\ETD.sys [2008-9-11 26112]<br />
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1e51x86.sys [2002-1-2 38400]<br />
S3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [2008-9-11 625024]<br />
<br />
=============== Created Last 30 ================<br />
<br />
2010-11-18 00:56:23	1205	----a-w-	c:\windows\system32\drivers\AsusACPI.inf<br />
2010-11-18 00:56:23	10752	----a-w-	c:\windows\system32\drivers\ASUSACPI.SYS<br />
2010-11-18 00:56:22	0	d-----w-	c:\program files\EeePC<br />
2010-11-18 00:47:48	60032	----a-w-	c:\windows\system32\drivers\USBAUDIO.sys<br />
2009-11-17 09:29:45	0	d-----w-	c:\program files\Elantech<br />
2009-11-17 09:19:16	35793	----a-w-	c:\windows\system32\netathw.cat<br />
2009-11-17 09:19:16	161344	----a-w-	c:\windows\system32\netathw.inf<br />
2009-11-17 09:19:15	1326528	----a-w-	c:\windows\system32\drivers\athw.sys<br />
2009-11-17 09:19:15	1326528	----a-w-	c:\windows\system32\athw.sys<br />
2009-11-17 09:19:15	0	d-----w-	c:\program files\Atheros<br />
2009-11-17 09:19:03	0	d-----w-	c:\docume~1\alluse~1\applic~1\Atheros<br />
2009-11-17 09:15:14	1389056	----a-w-	c:\windows\system32\drivers\Monfilt.sys<br />
2009-11-17 09:15:12	1684736	----a-w-	c:\windows\system32\drivers\Ambfilt.sys<br />
2009-11-17 09:14:05	2145280	-c--a-w-	c:\windows\system32\dllcache\ntkrnlmp.exe<br />
2009-11-17 09:14:04	2189184	-c--a-w-	c:\windows\system32\dllcache\ntoskrnl.exe<br />
2009-11-17 09:14:03	2023936	-c--a-w-	c:\windows\system32\dllcache\ntkrpamp.exe<br />
2009-11-17 09:14:02	2066048	-c--a-w-	c:\windows\system32\dllcache\ntkrnlpa.exe<br />
2009-11-17 08:58:19	0	d-----w-	c:\docume~1\alluse~1\applic~1\Norton<br />
2009-11-17 08:57:40	0	d-----w-	c:\docume~1\alluse~1\applic~1\NortonInstaller<br />
2009-11-17 08:57:33	0	d-----w-	c:\program files\Eee Storage<br />
2009-11-07 19:05:45	0	d--h--w-	C:\$AVG<br />
2009-11-07 19:04:39	0	d-----w-	c:\docume~1\alluse~1\applic~1\avg9<br />
2009-11-04 04:13:05	453456	----a-w-	c:\windows\system32\d3dx10_41.dll<br />
2009-11-04 04:13:05	1846632	----a-w-	c:\windows\system32\D3DCompiler_41.dll<br />
2009-11-04 04:13:04	4178264	----a-w-	c:\windows\system32\D3DX9_41.dll<br />
2009-11-04 04:13:02	69448	----a-w-	c:\windows\system32\XAPOFX1_3.dll<br />
2009-11-04 04:13:02	517448	----a-w-	c:\windows\system32\XAudio2_4.dll<br />
2009-11-04 04:13:01	235352	----a-w-	c:\windows\system32\xactengine3_4.dll<br />
2009-11-04 04:13:01	22360	----a-w-	c:\windows\system32\X3DAudio1_6.dll<br />
2009-11-04 04:11:03	0	d-----w-	c:\windows\Logs<br />
2009-11-04 03:36:59	0	d-----w-	c:\program files\Steam<br />
2009-11-04 03:06:14	0	d-----w-	c:\docume~1\nicola\applic~1\runic games<br />
2009-11-04 02:37:36	0	d-----w-	c:\docume~1\alluse~1\applic~1\WildTangent<br />
<br />
==================== Find3M  ====================<br />
<br />
2009-11-16 23:14:13	3242	----a-w-	c:\docume~1\nicola\applic~1\wklnhst.dat<br />
2009-11-09 16:57:48	360584	----a-w-	c:\windows\system32\drivers\avgtdix.sys<br />
2009-11-07 19:05:11	333192	----a-w-	c:\windows\system32\drivers\avgldx86.sys<br />
2009-11-07 19:05:11	12464	----a-w-	c:\windows\system32\avgrsstx.dll<br />
2009-10-11 09:17:27	411368	----a-w-	c:\windows\system32\deploytk.dll<br />
2009-09-25 05:37:11	667136	----a-w-	c:\windows\system32\wininet.dll<br />
2009-09-25 05:37:09	81920	----a-w-	c:\windows\system32\ieencode.dll<br />
2009-09-11 14:18:39	136192	----a-w-	c:\windows\system32\msv1_0.dll<br />
2009-09-04 21:03:36	58880	----a-w-	c:\windows\system32\msasn1.dll<br />
2009-08-26 08:00:21	247326	----a-w-	c:\windows\system32\strmdll.dll<br />
2008-05-07 08:34:00	15523560	----a-w-	c:\program files\U1 Setup.exe<br />
<br />
============= FINISH: 18:12:38.18 ===============<br />
<br />
<br />
The other ones are attached. Thanks so much!</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techsupportforum.com/cwd/images/attach/zip.gif" alt="File Type: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techsupportforum.com/attachments/virus-trojan-spyware-help/60572d1258742949-rundll-ugewome-error-ark.zip">ARK.zip</a> (5.3 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/">Virus/Trojan/Spyware Help</category>
			<dc:creator>baggytheo</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433667-rundll-ugewome-error.html</guid>
		</item>
		<item>
			<title>I have a keylogger or a spyware stealing my infos</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433648-i-have-keylogger-spyware-stealing-my-infos.html</link>
			<pubDate>Fri, 20 Nov 2009 17:39:45 GMT</pubDate>
			<description>Hello  
i play a game and someone keep stealing my account info and destroying everything inside so i setuped a new operating system and setuped AD-aware Malware bytes and Zone alarm and someone told me i should post a hijackthis file here and u guys will help cuz i think the hacker still have...</description>
			<content:encoded><![CDATA[<div>Hello <br />
i play a game and someone keep stealing my account info and destroying everything inside so i setuped a new operating system and setuped AD-aware Malware bytes and Zone alarm and someone told me i should post a hijackthis file here and u guys will help cuz i think the hacker still have access :<br />
<br />
Hijackthis :<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 7:11:25 PM, on 11/20/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\ZoneLabs\vsmon.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Analog Devices\Core\smax4pnp.exe<br />
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br />
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE<br />
C:\WINDOWS\system32\WgaTray.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\Windows Live\Contacts\wlcomm.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\WINDOWS\system32\SNDVOL32.EXE<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.yahoo.com/" target="_blank">http://www.yahoo.com/</a><br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll<br />
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll<br />
O4 - HKLM\..\Run: [StartCCC] &quot;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&quot;<br />
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe<br />
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray<br />
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe&quot; /starttray<br />
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br />
O4 - HKLM\..\Run: [ZoneAlarm Client] &quot;C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe&quot;<br />
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [uTorrent] &quot;C:\Program Files\uTorrent\uTorrent.exe&quot;<br />
O4 - HKCU\..\Run: [MsnMsgr] &quot;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&quot; /background<br />
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y &quot;%SystemRoot%\System32\syssetub.dll&quot; &quot;%SystemRoot%\System32\syssetup.dll&quot; (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-20\..\RunOnce: [nlsf] cmd.exe /C move /Y &quot;%SystemRoot%\System32\syssetub.dll&quot; &quot;%SystemRoot%\System32\syssetup.dll&quot; (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y &quot;%SystemRoot%\System32\syssetub.dll&quot; &quot;%SystemRoot%\System32\syssetup.dll&quot; (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')<br />
O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y &quot;%SystemRoot%\System32\syssetub.dll&quot; &quot;%SystemRoot%\System32\syssetup.dll&quot; (User 'Default user')<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe<br />
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe<br />
<br />
--<br />
End of file - 4524 bytes<br />
<br />
<br />
Malware bytes :<br />
Malwarebytes' Anti-Malware 1.33<br />
Database version: 1654<br />
Windows 5.1.2600 Service Pack 2<br />
<br />
11/20/2009 7:15:16 PM<br />
mbam-log-2009-11-20 (19-15-16).txt<br />
<br />
Scan type: Quick Scan<br />
Objects scanned: 47530<br />
Time elapsed: 2 minute(s), 39 second(s)<br />
<br />
Memory Processes Infected: 0<br />
Memory Modules Infected: 0<br />
Registry Keys Infected: 0<br />
Registry Values Infected: 0<br />
Registry Data Items Infected: 0<br />
Folders Infected: 0<br />
Files Infected: 0<br />
<br />
Memory Processes Infected:<br />
(No malicious items detected)<br />
<br />
Memory Modules Infected:<br />
(No malicious items detected)<br />
<br />
Registry Keys Infected:<br />
(No malicious items detected)<br />
<br />
Registry Values Infected:<br />
(No malicious items detected)<br />
<br />
Registry Data Items Infected:<br />
(No malicious items detected)<br />
<br />
Folders Infected:<br />
(No malicious items detected)<br />
<br />
Files Infected:<br />
(No malicious items detected)<br />
<br />
<br />
<br />
pls help TY!!</div>

]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/">Virus/Trojan/Spyware Help</category>
			<dc:creator>momonir</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433648-i-have-keylogger-spyware-stealing-my-infos.html</guid>
		</item>
		<item>
			<title>Keylogger/Trojan?</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433646-keylogger-trojan.html</link>
			<pubDate>Fri, 20 Nov 2009 17:27:27 GMT</pubDate>
			<description>My world of warcraft account was recently hijacked. I ran various cleaning programs such as Spybot, Ad-Aware, ATFCleaner and MBMA. Then I was instructed to post my HiJackThis logfile here as I dont understand it at all. 
So, please help me by analysing it :pray: 
 
Logfile of Trend Micro HijackThis...</description>
			<content:encoded><![CDATA[<div>My world of warcraft account was recently hijacked. I ran various cleaning programs such as Spybot, Ad-Aware, ATFCleaner and MBMA. Then I was instructed to post my HiJackThis logfile here as I dont understand it at all.<br />
So, please help me by analysing it :pray:<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 17:53:38, on 20.11.2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\System32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\system32\WgaTray.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\SOUNDMAN.EXE<br />
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe<br />
C:\PROGRA~1\mcafee.com\agent\mcagent.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe<br />
C:\Program Files\Winamp\winampa.exe<br />
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe<br />
C:\Program Files\DAEMON Tools\daemon.exe<br />
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe<br />
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe<br />
C:\Program Files\Logitech\SetPoint\SetPoint.exe<br />
C:\Program Files\VIA\RAID\raid_tool.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
c:\program files\mcafee.com\agent\mcdetect.exe<br />
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe<br />
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE<br />
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe<br />
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe<br />
C:\WINDOWS\system32\PnkBstrA.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Windows Live\Contacts\wlcomm.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br />
C:\PROGRA~1\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = <a href="http://uk.mcafee.com/root/forgotPassword.asp?affid=0-43&amp;langid=40&amp;close=true&amp;RW=1" target="_blank">http://uk.mcafee.com/root/forgotPass...lose=true&amp;RW=1</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O4 - HKLM\..\Run: [IMJPMIG8.1] &quot;C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE&quot; /Spoil /RemAdvDef /Migration32<br />
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC<br />
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName<br />
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode<br />
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br />
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe<br />
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe<br />
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe<br />
O4 - HKLM\..\Run: [StartCCC] &quot;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&quot; MSRun<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br />
O4 - HKLM\..\Run: [WinampAgent] &quot;C:\Program Files\Winamp\winampa.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKCU\..\Run: [MsnMsgr] &quot;C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe&quot; /background<br />
O4 - HKCU\..\Run: [Steam] &quot;c:\progra~1\steam\steam.exe&quot; -silent<br />
O4 - HKCU\..\Run: [DAEMON Tools] &quot;C:\Program Files\DAEMON Tools\daemon.exe&quot; -lang 1033<br />
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve')<br />
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve')<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')<br />
O4 - Global Startup: Adobe Gamma Loader.lnk = ?<br />
O4 - Global Startup: hp psc 1000 series.lnk = ?<br />
O4 - Global Startup: hpoddt01.exe.lnk = ?<br />
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe<br />
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br />
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe<br />
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe<br />
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe<br />
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll<br />
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - <a href="http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab" target="_blank">http://download.mcafee.com/molbin/sh...1/mcinsctl.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1214322584515" target="_blank">http://www.update.microsoft.com/micr...?1214322584515</a><br />
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - <a href="http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab" target="_blank">http://acs.pandasoftware.com/actives.../as2stubie.cab</a><br />
O16 - DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} (Flash Casino Helper Control) - <a href="https://plugins.valueactive.eu/flashax/iefax.cab" target="_blank">https://plugins.valueactive.eu/flashax/iefax.cab</a><br />
O20 - AppInit_DLLs: ,C:\WINDOWS\TEMP\372015sys.dll<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe<br />
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe<br />
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe<br />
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe<br />
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe<br />
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe<br />
<br />
--<br />
End of file - 8065 bytes<br />
<br />
AND HERE IS ALSO MY MBMA LOG FILE<br />
<br />
Malwarebytes' Anti-Malware 1.41<br />
Database version: 3193<br />
Windows 5.1.2600 Service Pack 3<br />
<br />
20.11.2009 19:25:38<br />
mbam-log-2009-11-20 (19-25-38).txt<br />
<br />
Scan type: Full Scan (C:\|D:\|E:\|F:\|H:\|)<br />
Objects scanned: 197938<br />
Time elapsed: 40 minute(s), 22 second(s)<br />
<br />
Memory Processes Infected: 0<br />
Memory Modules Infected: 0<br />
Registry Keys Infected: 0<br />
Registry Values Infected: 0<br />
Registry Data Items Infected: 2<br />
Folders Infected: 0<br />
Files Infected: 0<br />
<br />
Memory Processes Infected:<br />
(No malicious items detected)<br />
<br />
Memory Modules Infected:<br />
(No malicious items detected)<br />
<br />
Registry Keys Infected:<br />
(No malicious items detected)<br />
<br />
Registry Values Infected:<br />
(No malicious items detected)<br />
<br />
Registry Data Items Infected:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -&gt; Bad: (1) Good: (0) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -&gt; Bad: (1) Good: (0) -&gt; Quarantined and deleted successfully.<br />
<br />
Folders Infected:<br />
(No malicious items detected)<br />
<br />
Files Infected:<br />
(No malicious items detected)</div>

]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/">Virus/Trojan/Spyware Help</category>
			<dc:creator>Araknida</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433646-keylogger-trojan.html</guid>
		</item>
		<item>
			<title>My first Trojan</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433641-my-first-trojan.html</link>
			<pubDate>Fri, 20 Nov 2009 17:10:31 GMT</pubDate>
			<description>Hey guys, I just got my first Trojan and its an evil one, It all started when i opend a file on a wallpaper side. Then my virus protection started alerting about a trojan, when i tryed to delete it it standed it have change file name.It keeps changing filename and i can´t get rid of it, I got virus...</description>
			<content:encoded><![CDATA[<div>Hey guys, I just got my first Trojan and its an evil one, It all started when i opend a file on a wallpaper side. Then my virus protection started alerting about a trojan, when i tryed to delete it it standed it have change file name.It keeps changing filename and i can´t get rid of it, I got virus protection program but it keeps going enyways. I dont whana do enything without spoken to you pro guys. Please help me :) The trojan can be a Keylogger or just crash the computor as you know. im running a Windows XP, nothing special about it its almost a year old.<br />
<br />
Best Regards<br />
<br />
//Alex</div>

]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/">Virus/Trojan/Spyware Help</category>
			<dc:creator>Alex95</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433641-my-first-trojan.html</guid>
		</item>
		<item>
			<title>Trojan found, no idea where to start</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433630-trojan-found-no-idea-where-start.html</link>
			<pubDate>Fri, 20 Nov 2009 16:30:36 GMT</pubDate>
			<description><![CDATA[i tried to download a video codec and instead got a trojan, i keep getting warnings that a level one trojan warning, "TrojanDownloader:Win32/Renos.JM" 
turned my computer on today and startup failed, so the system fix button came up, pressed it, managed to boot it up. however, now i cant find any...]]></description>
			<content:encoded><![CDATA[<div>i tried to download a video codec and instead got a trojan, i keep getting warnings that a level one trojan warning, &quot;TrojanDownloader:Win32/Renos.JM&quot;<br />
turned my computer on today and startup failed, so the system fix button came up, pressed it, managed to boot it up. however, now i cant find any wireless networks when i try connect to the internet, only dial up. <br />
<br />
no idea where to start, but heres my logs. <br />
<br />
<br />
DDS (Ver_09-10-26.01) - NTFSx86  <br />
Run by Jenny at 15:13:01.14 on 20/11/2009<br />
Internet Explorer: 7.0.6001.18000<br />
Microsoft® Windows Vista™ Home Basic   6.0.6001.1.1252.44.1033.18.3000.1395 [GMT 0:00]<br />
<br />
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}<br />
<br />
============== Running Processes ===============<br />
<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\svchost.exe -k rpcss<br />
C:\Windows\System32\svchost.exe -k secsvcs<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\system32\SLsvc.exe<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Windows\system32\agrsmsvc.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe<br />
C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe<br />
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe<br />
C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br />
C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br />
C:\Program Files\Acer\Empowering Technology\Service\ETService.exe<br />
C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\Acer\Mobility Center\MobilityService.exe<br />
C:\Windows\system32\rundll32.exe<br />
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\msb.exe<br />
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe<br />
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
C:\Program Files\Cyberlink\Shared files\RichVideo.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\svchost.exe -k imgsvc<br />
C:\Windows\System32\svchost.exe -k WerSvcGroup<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\McAfee.com\Agent\mcagent.exe<br />
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe<br />
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe<br />
C:\Program Files\AVG\AVG8\avgcsrvx.exe<br />
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe<br />
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br />
C:\Windows\System32\igfxtray.exe<br />
C:\Windows\System32\igfxpers.exe<br />
C:\Windows\system32\igfxsrvc.exe<br />
C:\Windows\RtHDVCpl.exe<br />
C:\Program Files\Launch Manager\LManager.exe<br />
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe<br />
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe<br />
C:\Program Files\AVG\AVG8\avgtray.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Users\Jenny\AppData\Local\Temp\RtkBtMnt.exe<br />
C:\Windows\system32\igfxext.exe<br />
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe<br />
C:\Windows\system32\igfxsrvc.exe<br />
C:\Program Files\Electronic Arts\EADM\Core.exe<br />
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Program Files\Skype\Phone\Skype.exe<br />
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe<br />
C:\Program Files\Common Files\Nokia\NoA\nokiaaserver.exe<br />
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe<br />
C:\Program Files\PC Connectivity Solution\Transports\NclIrSrv.exe<br />
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe<br />
C:\Program Files\Skype\Plugin Manager\skypePM.exe<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Windows\system32\sdclt.exe<br />
C:\Windows\system32\svchost.exe -k SDRSVC<br />
C:\Program Files\Acer\Empowering Technology\NotificationCenter\Framework.NotificationCenter.exe<br />
C:\Windows\System32\svchost.exe -k wdisvc<br />
C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Windows\system32\WUDFHost.exe<br />
C:\Windows\System32\mobsync.exe<br />
C:\Program Files\Last.fm\LastFM.exe<br />
C:\Program Files\Nokia\Nokia PC Suite 7\OneTouchAccess.exe<br />
C:\Users\Jenny\AppData\Local\Temp\j.exe<br />
C:\Windows\system32\ctfmon.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Windows\system32\msiexec.exe<br />
C:\Windows\system32\vssvc.exe<br />
C:\Windows\System32\svchost.exe -k swprv<br />
C:\Windows\system32\SearchProtocolHost.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Users\Jenny\Desktop\dds.scr<br />
<br />
============== Pseudo HJT Report ===============<br />
<br />
uStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&amp;l=0809&amp;s=2&amp;o=vb32&amp;d=1009&amp;m=aspire_5735<br />
uDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&amp;l=0809&amp;s=2&amp;o=vb32&amp;d=1009&amp;m=aspire_5735<br />
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&amp;l=0809&amp;s=2&amp;o=vb32&amp;d=1009&amp;m=aspire_5735<br />
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll<br />
uURLSearchHooks: H - No File<br />
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll<br />
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll<br />
BHO: ShowBarObj Class: {83a2f9b1-01a2-4aa5-87d1-45b6b8505e96} - c:\program files\acer\empowering technology\edatasecurity\x86\ActiveToolBand.dll<br />
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll<br />
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll<br />
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.3.4501.1418\swg.dll<br />
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll<br />
TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\program files\acer\empowering technology\edatasecurity\x86\eDStoolbar.dll<br />
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll<br />
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll<br />
uRun: [EA Core] &quot;c:\program files\electronic arts\eadm\Core.exe&quot; -silent<br />
uRun: [&lt;NO NAME&gt;] <br />
uRun: [NokiaOviSuite2] c:\program files\nokia\nokia ovi suite\NokiaOviSuite.exe -tray<br />
uRun: [PC Suite Tray] &quot;c:\program files\nokia\nokia pc suite 7\PCSuite.exe&quot; -onlytray<br />
uRun: [swg] &quot;c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe&quot;<br />
uRun: [Skype] &quot;c:\program files\skype\phone\Skype.exe&quot; /nosplash /minimized<br />
uRun: [SSHNAS] rundll32.exe c:\windows\system32\sshnas.dll,DllWork<br />
uRun: [MailBlocker] c:\users\jenny\appdata\local\temp\j.exe<br />
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe<br />
mRun: [BkupTray] &quot;c:\program files\newtech infosystems\nti backup now 5\BkupTray.exe&quot;<br />
mRun: [ArcadeDeluxeAgent] &quot;c:\program files\acer arcade deluxe\acer arcade deluxe\ArcadeDeluxeAgent.exe&quot;<br />
mRun: [CLMLServer] &quot;c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\clml\CLMLSvc.exe&quot;<br />
mRun: [PlayMovie] &quot;c:\program files\acer arcade deluxe\playmovie\PMVService.exe&quot;<br />
mRun: [Google Desktop Search] &quot;c:\program files\google\google desktop search\GoogleDesktop.exe&quot; /startup<br />
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe<br />
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe<br />
mRun: [Persistence] c:\windows\system32\igfxpers.exe<br />
mRun: [RtHDVCpl] RtHDVCpl.exe<br />
mRun: [Skytel] Skytel.exe<br />
mRun: [LManager] c:\progra~1\launch~1\LManager.exe<br />
mRun: [eDataSecurity Loader] c:\program files\acer\empowering technology\edatasecurity\x86\eDSloader.exe<br />
mRun: [ePower_DMC] c:\program files\acer\empowering technology\epower\ePower_DMC.exe<br />
mRun: [eRecoveryService] <br />
mRun: [ProductReg] &quot;c:\program files\acer\wr_popup\ProductReg.exe&quot;<br />
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe<br />
mRun: [QuickTime Task] &quot;c:\program files\quicktime\QTTask.exe&quot; -atboottime<br />
mRun: [iTunesHelper] &quot;c:\program files\itunes\iTunesHelper.exe&quot;<br />
mRun: [NokiaMServer] c:\program files\common files\nokia\mplatform\NokiaMServer /watchfiles startup<br />
mRun: [Adobe Reader Speed Launcher] &quot;c:\program files\adobe\reader 9.0\reader\Reader_sl.exe&quot;<br />
mRun: [Adobe ARM] &quot;c:\program files\common files\adobe\arm\1.0\AdobeARM.exe&quot;<br />
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\$mcreb~1.lnk - c:\windows\system32\cmd.exe<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000<br />
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL<br />
TCP: {2C285D58-D431-4C80-AF02-BD852E4024B9} = 193.35.132.165 193.35.132.164<br />
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL<br />
Notify: igfxcui - igfxdev.dll<br />
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL,avgrsstx.dll<br />
<br />
================= FIREFOX ===================<br />
<br />
FF - ProfilePath - c:\users\jenny\appdata\roaming\mozilla\firefox\profiles\mcg5hr2k.default\<br />
FF - prefs.js: browser.search.selectedEngine - Google<br />
FF - prefs.js: browser.startup.homepage - <a href="http://www.google.co.uk" target="_blank">www.google.co.uk</a><br />
FF - prefs.js: keyword.URL - hxxp://uk.yhs.search.yahoo.com/avg/search?fr=yhs-avg&amp;type=yahoo_avg_hs2-tb-web_uk&amp;p=<br />
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll<br />
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll<br />
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll<br />
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll<br />
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll<br />
FF - component: c:\program files\nokia\nokia ovi suite\connectors\bookmarks connector\firefoxextension\components\FirefoxExtension.dll<br />
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll<br />
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll<br />
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\<br />
<br />
---- FIREFOX POLICIES ----<br />
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref(&quot;security.ssl3.rsa_seed_sha&quot;, true);<br />
<br />
============= SERVICES / DRIVERS ===============<br />
<br />
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-10-8 335240]<br />
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-10-8 108552]<br />
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\acer arcade deluxe\playmovie\000.fcl [2008-5-15 61424]<br />
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-10-8 908056]<br />
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-10-8 297752]<br />
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\newtech infosystems\nti backup now 5\client\Agentsvc.exe [2008-3-3 16384]<br />
R2 CLHNService;CLHNService;c:\program files\acer arcade deluxe\homemedia\kernel\dmp\CLHNService.exe [2008-5-15 81504]<br />
R2 ETService;Empowering Technology Service;c:\program files\acer\empowering technology\service\ETService.exe [2008-5-15 24576]<br />
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\newtech infosystems\nti backup now 5\BackupSvc.exe [2008-4-7 50424]<br />
R2 NTIPPKernel;NTIPPKernel;c:\program files\acer arcade deluxe\homemedia\kernel\dmp\NTIPPKernel.sys [2008-5-15 122368]<br />
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\newtech infosystems\nti backup now 5\SchedulerSvc.exe [2008-4-4 131072]<br />
RUnknown SASDIFSV;SASDIFSV; [x]<br />
RUnknown SASENUM;SASENUM; [x]<br />
RUnknown SASKUTIL;SASKUTIL; [x]<br />
S2 0309001258729698mcinstcleanup;McAfee Application Installer Cleanup (0309001258729698);c:\users\jenny\appdata\local\temp\030900~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service --&gt; c:\users\jenny\appdata\local\temp\030900~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service [?]<br />
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-10-11 133104]<br />
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2008-1-21 179712]<br />
S3 GoogleDesktopManager-080708-050100;Google Desktop Manager 5.7.808.7150;c:\program files\google\google desktop search\GoogleDesktop.exe [2009-10-8 24064]<br />
<br />
=============== Created Last 30 ================<br />
<br />
2009-11-20 14:18:35	0	d-----w-	c:\programdata\WindowsSearch<br />
2009-11-20 13:55:05	3216	----a-w-	c:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0<br />
2009-11-20 13:55:05	3216	----a-w-	c:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0<br />
2009-11-19 23:07:27	0	d-----w-	c:\programdata\SUPERAntiSpyware.com<br />
2009-11-19 22:56:15	178176	----a-w-	c:\windows\msb.exe<br />
2009-11-19 22:23:47	178176	----a-w-	c:\windows\msa.exe<br />
2009-11-14 17:09:29	56	---ha-w-	c:\programdata\ezsidmv.dat<br />
2009-11-14 17:07:44	0	d-----r-	c:\program files\Skype<br />
2009-11-14 17:07:38	0	d-----w-	c:\programdata\Skype<br />
2009-11-11 14:00:06	2035712	----a-w-	c:\windows\system32\win32k.sys<br />
2009-11-11 14:00:00	351232	----a-w-	c:\windows\system32\WSDApi.dll<br />
2009-11-10 15:51:27	0	d--h--w-	C:\$AVG8.VAULT$<br />
2009-11-04 09:58:56	1383424	----a-w-	c:\windows\system32\mshtml.tlb<br />
2009-11-02 23:40:04	0	d-----w-	c:\programdata\Last.fm<br />
2009-11-02 23:39:27	0	d-----w-	c:\program files\Last.fm<br />
2009-11-02 22:53:44	180224	----a-w-	c:\windows\system32\ac3filter.cpl<br />
2009-11-02 22:53:43	0	d-----w-	c:\program files\AC3Filter<br />
2009-10-28 13:00:42	310784	----a-w-	c:\windows\system32\unregmp2.exe<br />
2009-10-28 13:00:40	8147456	----a-w-	c:\windows\system32\wmploc.DLL<br />
2009-10-27 11:46:37	2421760	----a-w-	c:\windows\system32\wucltux.dll<br />
2009-10-27 11:46:22	87552	----a-w-	c:\windows\system32\wudriver.dll<br />
2009-10-27 11:46:14	33792	----a-w-	c:\windows\system32\wuapp.exe<br />
2009-10-27 11:46:14	171608	----a-w-	c:\windows\system32\wuwebv.dll<br />
2009-10-23 15:25:26	0	d-----w-	c:\users\jenny\Option<br />
2009-10-23 00:53:06	195456	----a-w-	c:\windows\system32\MpSigStub.exe<br />
<br />
==================== Find3M  ====================<br />
<br />
2009-11-20 14:54:52	86016	----a-w-	c:\windows\inf\infstrng.dat<br />
2009-11-20 14:54:52	51200	----a-w-	c:\windows\inf\infpub.dat<br />
2009-11-15 06:17:06	182	----a-w-	c:\users\jenny\appdata\roaming\wklnhst.dat<br />
2009-10-13 15:33:11	0	---ha-w-	c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf<br />
2009-10-13 15:32:03	0	---ha-w-	c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf<br />
2009-10-13 15:31:12	0	---ha-w-	c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf<br />
2009-10-13 15:30:30	86016	----a-w-	c:\windows\inf\infstor.dat<br />
2009-10-09 00:33:36	361984	----a-w-	c:\windows\system32\IPSECSVC.DLL<br />
2009-10-09 00:32:30	738304	----a-w-	c:\windows\system32\inetcomm.dll<br />
2009-10-09 00:32:14	269312	----a-w-	c:\windows\system32\es.dll<br />
2009-10-09 00:30:06	72192	----a-w-	c:\windows\system32\drivers\pacer.sys<br />
2009-10-09 00:30:06	15360	----a-w-	c:\windows\system32\pacerprf.dll<br />
2009-10-09 00:29:50	180224	----a-w-	c:\windows\system32\scrobj.dll<br />
2009-10-09 00:29:50	172032	----a-w-	c:\windows\system32\scrrun.dll<br />
2009-10-09 00:29:50	155648	----a-w-	c:\windows\system32\wscript.exe<br />
2009-10-09 00:29:50	135168	----a-w-	c:\windows\system32\cscript.exe<br />
2009-10-09 00:29:49	90112	----a-w-	c:\windows\system32\wshext.dll<br />
2009-10-09 00:29:49	430080	----a-w-	c:\windows\system32\vbscript.dll<br />
2009-10-09 00:28:50	885248	----a-w-	c:\windows\system32\RacEngn.dll<br />
2009-10-09 00:28:39	1314816	----a-w-	c:\windows\system32\quartz.dll<br />
2009-10-09 00:28:28	665600	----a-w-	c:\windows\inf\drvindex.dat<br />
2009-10-09 00:28:17	113664	----a-w-	c:\windows\system32\drivers\rmcast.sys<br />
2009-10-09 00:26:59	428544	----a-w-	c:\windows\system32\EncDec.dll<br />
2009-10-09 00:26:59	293376	----a-w-	c:\windows\system32\psisdecd.dll<br />
2009-10-09 00:26:45	1695744	----a-w-	c:\windows\system32\gameux.dll<br />
2009-10-09 00:25:01	988216	----a-w-	c:\windows\system32\winload.exe<br />
2009-10-09 00:25:01	927288	----a-w-	c:\windows\system32\winresume.exe<br />
2009-10-09 00:25:01	6656	----a-w-	c:\windows\system32\kbd106n.dll<br />
2009-10-09 00:25:01	615992	----a-w-	c:\windows\system32\ci.dll<br />
2009-10-09 00:25:01	46592	----a-w-	c:\windows\system32\setbcdlocale.dll<br />
2009-10-09 00:25:01	40960	----a-w-	c:\windows\system32\srclient.dll<br />
2009-10-09 00:25:01	378368	----a-w-	c:\windows\system32\srcore.dll<br />
2009-10-09 00:25:01	318464	----a-w-	c:\windows\system32\rstrui.exe<br />
2009-10-09 00:25:01	19000	----a-w-	c:\windows\system32\kd1394.dll<br />
2009-10-09 00:25:01	14848	----a-w-	c:\windows\system32\srdelayed.exe<br />
2009-10-09 00:23:50	28728	----a-w-	c:\windows\system32\drivers\msahci.sys<br />
2009-10-09 00:23:50	21560	----a-w-	c:\windows\system32\drivers\atapi.sys<br />
2009-10-08 23:42:42	0	---ha-w-	c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf<br />
2009-10-08 16:58:28	11952	----a-w-	c:\windows\system32\avgrsstx.dll<br />
2009-10-08 16:58:27	108552	----a-w-	c:\windows\system32\drivers\avgtdix.sys<br />
2009-10-08 16:58:17	335240	----a-w-	c:\windows\system32\drivers\avgldx86.sys<br />
2009-10-08 15:58:35	319456	----a-w-	c:\windows\DIFxAPI.dll<br />
2009-10-08 15:58:28	315392	----a-w-	c:\windows\HideWin.exe<br />
2009-09-25 16:41:26	856064	----a-w-	c:\windows\system32\divx_xx0c.dll<br />
2009-09-25 16:41:26	856064	----a-w-	c:\windows\system32\divx_xx07.dll<br />
2009-09-25 16:41:26	847872	----a-w-	c:\windows\system32\divx_xx0a.dll<br />
2009-09-25 16:41:26	843776	----a-w-	c:\windows\system32\divx_xx16.dll<br />
2009-09-25 16:41:26	839680	----a-w-	c:\windows\system32\divx_xx11.dll<br />
2009-09-25 16:41:26	696320	----a-w-	c:\windows\system32\DivX.dll<br />
2009-09-10 17:30:12	213504	----a-w-	c:\windows\system32\msv1_0.dll<br />
2009-09-04 12:24:34	61440	----a-w-	c:\windows\system32\msasn1.dll<br />
2009-08-28 18:42:52	2065696	----a-w-	c:\windows\system32\usbaaplrc.dll<br />
2009-08-28 12:39:07	28672	----a-w-	c:\windows\system32\Apphlpdm.dll<br />
2009-08-28 10:15:30	4240384	----a-w-	c:\windows\system32\GameUXLegacyGDFs.dll<br />
2009-08-27 13:32:41	833024	----a-w-	c:\windows\system32\wininet.dll<br />
2009-08-27 13:29:25	78336	----a-w-	c:\windows\system32\ieencode.dll<br />
2009-08-27 10:58:58	26624	----a-w-	c:\windows\system32\ieUnatt.exe<br />
2008-01-21 02:57:01	174	--sha-w-	c:\program files\desktop.ini<br />
2006-11-02 12:39:34	30674	----a-w-	c:\windows\inf\perflib\0409\perfd.dat<br />
2006-11-02 12:39:34	30674	----a-w-	c:\windows\inf\perflib\0409\perfc.dat<br />
2006-11-02 12:39:34	287440	----a-w-	c:\windows\inf\perflib\0409\perfi.dat<br />
2006-11-02 12:39:34	287440	----a-w-	c:\windows\inf\perflib\0409\perfh.dat<br />
2006-11-02 09:20:21	287440	----a-w-	c:\windows\inf\perflib\0000\perfi.dat<br />
2006-11-02 09:20:21	287440	----a-w-	c:\windows\inf\perflib\0000\perfh.dat<br />
2006-11-02 09:20:19	30674	----a-w-	c:\windows\inf\perflib\0000\perfd.dat<br />
2006-11-02 09:20:19	30674	----a-w-	c:\windows\inf\perflib\0000\perfc.dat<br />
<br />
============= FINISH: 15:14:30.26 ===============</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techsupportforum.com/cwd/images/attach/zip.gif" alt="File Type: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techsupportforum.com/attachments/virus-trojan-spyware-help/60564d1258734627-trojan-found-no-idea-where-start-attach201109.zip">Attach201109.zip</a> (3.0 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/">Virus/Trojan/Spyware Help</category>
			<dc:creator>Jenjen20</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433630-trojan-found-no-idea-where-start.html</guid>
		</item>
		<item>
			<title>Not sure if infected, but think so...</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433615-not-sure-if-infected-but-think-so.html</link>
			<pubDate>Fri, 20 Nov 2009 15:34:49 GMT</pubDate>
			<description><![CDATA[I ran malwarebytes and it didn't detect anything,but when I try to go to facebook.com it brings me to socialfreebies.com - That's probably a sign something is wrong. 
 
Here is my hijackthis log 
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 10:29:23 AM, on 11/20/2009 
Platform: Windows...]]></description>
			<content:encoded><![CDATA[<div>I ran malwarebytes and it didn't detect anything,but when I try to go to facebook.com it brings me to socialfreebies.com - That's probably a sign something is wrong.<br />
<br />
Here is my hijackthis log<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 10:29:23 AM, on 11/20/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16850)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
C:\PROGRA~1\AVG\AVG8\avgfws8.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\system32\HPZipm12.exe<br />
C:\WINDOWS\system32\STacSV.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
C:\PROGRA~1\AVG\AVG8\avgam.exe<br />
C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br />
C:\Program Files\Windows Home Server\WHSConnector.exe<br />
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
C:\Program Files\Microsoft IntelliType Pro\type32.exe<br />
C:\Program Files\Microsoft IntelliPoint\point32.exe<br />
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe<br />
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe<br />
C:\Program Files\QuickTime\qttask.exe<br />
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe<br />
C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe<br />
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Messenger\msmsgs.exe<br />
C:\Program Files\AIM6\aim6.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Program Files\Skype\Phone\Skype.exe<br />
C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Program Files\Windows Home Server\WHSTrayApp.exe<br />
C:\Documents and Settings\Maryann\Application Data\Dropbox\bin\Dropbox.exe<br />
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe<br />
C:\Program Files\AIM6\aolsoftware.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe<br />
C:\Program Files\Skype\Plugin Manager\skypePM.exe<br />
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe<br />
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\PROGRA~1\MICROS~4\Office12\OUTLOOK.EXE<br />
C:\Program Files\Microsoft Office\Office12\EXCEL.EXE<br />
C:\Program Files\Adobe\Adobe Illustrator CS3\Adobe Illustrator CS3\Support Files\Contents\Windows\Illustrator.exe<br />
C:\Program Files\Macromedia\Dreamweaver 8\Dreamweaver.exe<br />
C:\Program Files\AVG\AVG8\avgscanx.exe<br />
C:\Program Files\AVG\AVG8\avgcsrvx.exe<br />
C:\Program Files\AVG\AVG8\avgui.exe<br />
C:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe<br />
C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br />
C:\Program Files\Mozilla Thunderbird\thunderbird.exe<br />
C:\Program Files\Adobe\Photoshop 7.0\Photoshop.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Documents and Settings\Maryann\Local Settings\Temporary Internet Files\Content.IE5\41I9H00W\HijackThis[1].exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://yahoo.com/" target="_blank">http://yahoo.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll<br />
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br />
O2 - BHO: TTB000000 - {62960D20-6D0D-1AB4-4BF1-95B0B5B8783A} - C:\WINDOWS\COUPON~1.DLL (file missing)<br />
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br />
O2 - BHO: BrowserHelper Class - {9A065C65-4EE7-4DDD-9918-F129089A894A} - C:\Program Files\Windows Home Server\WHSDeskBands.dll<br />
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\YTSingleInstance.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll<br />
O3 - Toolbar: Home Server Banner - {D73E76A3-F902-45BD-8FC8-95AE8E014671} - C:\Program Files\Windows Home Server\WHSDeskBands.dll<br />
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br />
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [type32] &quot;C:\Program Files\Microsoft IntelliType Pro\type32.exe&quot;<br />
O4 - HKLM\..\Run: [IntelliPoint] &quot;C:\Program Files\Microsoft IntelliPoint\point32.exe&quot;<br />
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\OLD_HDD\Program Files\viewsonic\registration.exe /title=&quot;CorelDRAW Graphics Suite 12&quot; /date=012407 serial=DR12WRS-5096179-vpv lang=EN<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [YSearchProtection] &quot;C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe&quot;<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] &quot;C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe&quot; -launchedbylogin<br />
O4 - HKLM\..\Run: [GrooveMonitor] &quot;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&quot;<br />
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] &quot;C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKCU\..\Run: [MSMSGS] &quot;C:\Program Files\Messenger\msmsgs.exe&quot; /background<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe<br />
O4 - HKCU\..\Run: [Aim6] &quot;C:\Program Files\AIM6\aim6.exe&quot; /d locale=en-US ee://aol/imApp<br />
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;<br />
O4 - HKCU\..\Run: [Messenger (Yahoo!)] &quot;C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe&quot; -quiet<br />
O4 - HKCU\..\Run: [Skype] &quot;C:\Program Files\Skype\Phone\Skype.exe&quot; /nosplash /minimized<br />
O4 - HKCU\..\Run: [DriverUpdaterPro] C:\Program Files\iXi Tools\Driver Updater Pro\DriverUpdaterPro.exe -t<br />
O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'Default user')<br />
O4 - Startup: Dropbox.lnk = C:\Documents and Settings\Maryann\Application Data\Dropbox\bin\Dropbox.exe<br />
O4 - Startup: MailWasherPro.lnk = C:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe<br />
O4 - Startup: PowerReg Scheduler.exe<br />
O4 - Startup: TipCam.lnk = C:\Program Files\uTIPu\tipc.exe<br />
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe<br />
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br />
O4 - Global Startup: Google Calendar Sync.lnk = C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe<br />
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br />
O4 - Global Startup: Windows Home Server.lnk = ?<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll<br />
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll<br />
O15 - Trusted Zone: <a href="http://fpdownload.macromedia.com" target="_blank">http://fpdownload.macromedia.com</a><br />
O15 - Trusted Zone: <a href="http://www.macromedia.com" target="_blank">http://www.macromedia.com</a><br />
O15 - Trusted Zone: <a href="http://www.salemdeeds.com" target="_blank">http://www.salemdeeds.com</a><br />
O15 - Trusted Zone: <a href="http://*.salemdeeds.com" target="_blank">http://*.salemdeeds.com</a><br />
O15 - Trusted Zone: <a href="http://sdc.shockwave.com" target="_blank">http://sdc.shockwave.com</a><br />
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - <a href="http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab" target="_blank">http://a1540.g.akamai.net/7/1540/52/...x/qtplugin.cab</a><br />
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - <a href="http://www.alternatiff.com/install-ie/alttiff.cab" target="_blank">http://www.alternatiff.com/install-ie/alttiff.cab</a><br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll<br />
O16 - DPF: {4788DE0A-3552-49EA-AC8C-233DA52523B9} (AxLoaderPassword Class) - <a href="http://www.blackberry.com/devicesoftware/AxLoader.cab" target="_blank">http://www.blackberry.com/devicesoftware/AxLoader.cab</a><br />
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - <a href="http://www.linkedin.com/cab/LinkedInContactFinderControl.cab" target="_blank">http://www.linkedin.com/cab/LinkedIn...derControl.cab</a><br />
O16 - DPF: {549F957E-2F89-11D6-8CFE-00C04F52B225} (CMV5 Class) - <a href="http://coupons.smartsource.com/download/cscmv5X.cab" target="_blank">http://coupons.smartsource.com/download/cscmv5X.cab</a><br />
O16 - DPF: {626FE447-E830-4F76-A024-41A20EEECF1A} (RyzeAddrCtrl Class) - <a href="http://www.ryze.com/RyzeAddr.CAB" target="_blank">http://www.ryze.com/RyzeAddr.CAB</a><br />
O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - <a href="https://big-bull-whs/remote/msrdp.cab" target="_blank">https://big-bull-whs/remote/msrdp.cab</a><br />
O16 - DPF: {87587503-20F0-4FF5-8DA3-0107C4C03FDC} (vmLaunch Class) - <a href="http://downloads.comcast.net/videomail/vmLauncher.cab" target="_blank">http://downloads.comcast.net/videomail/vmLauncher.cab</a><br />
O16 - DPF: {F91AB7B8-EE67-42AF-A5AA-8E232C396A04} (HTMLPRint Control) - <a href="https://reports.clearscreening.com/cabs/htmlprint.cab" target="_blank">https://reports.clearscreening.com/cabs/htmlprint.cab</a><br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL<br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O20 - Winlogon Notify: ielib32 - C:\WINDOWS\SYSTEM32\ielib32.dll<br />
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe<br />
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: Google Update Service (gupdate1c9dfcd8488a52) (gupdate1c9dfcd8488a52) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\STacSV.exe<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
<br />
--<br />
End of file - 16573 bytes</div>

]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/">Virus/Trojan/Spyware Help</category>
			<dc:creator>smitnlit</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433615-not-sure-if-infected-but-think-so.html</guid>
		</item>
		<item>
			<title>suspected trojen,malware,virus +rootkit!!</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433599-suspected-trojen-malware-virus-rootkit.html</link>
			<pubDate>Fri, 20 Nov 2009 14:36:10 GMT</pubDate>
			<description><![CDATA[I entered the web page hxxp://www.ebookvortex.net as before but saw that this web page has been changed.There is only a welcome message ,a girl's picture and a search option at the page.Therefore I wanted to test the page whether it was working properly or not and used the search option at the page...]]></description>
			<content:encoded><![CDATA[<div>I entered the web page hxxp://www.ebookvortex.net as before but saw that this web page has been changed.There is only a welcome message ,a girl's picture and a search option at the page.Therefore I wanted to test the page whether it was working properly or not and used the search option at the page and nothing happened.(But at the status bar it was showing a couple of internet addresses for connecting.These addresses are the same with the report at the page  <a href="http://www.threatexpert.com/report.aspx?md5=411baa2c8cd20c6595022913363d41ad" target="_blank">http://www.threatexpert.com/report.a...022913363d41ad</a> .At this report it is said that similar designed webpages causes PC be affected by some trojens and malwares,steals info from pc.(The design of the altered webpage  is similar to the web page that is reported above.welcome text,girl's picture and a search box.)Therefore I am suspicious of being affected by trojen,malware,virus.<br />
<br />
Would you please tell me if I am affected by any viruses,trojens or malwares?<br />
Thanks in advance..<br />
<br />
dss result is listed as below:(done all these tests at normal mode with the internet connection on)<br />
(<b>In addition to this</b>,at the end of gmer test,it warned me by a message that the system is effected by a <b>rootkit</b>.)<br />
Note:from the given link I downloaded the gmer programme,but it didn't work.<br />
Therefore,I run the gmer that I had downloaded before. <br />
<br />
DDS (Ver_09-10-26.01) - NTFSx86  <br />
Run by LIVE at 15:36:23,63 on 20.11.2009<br />
Internet Explorer: 8.0.7600.16385<br />
Microsoft Windows 7 Ultimate   6.1.7600.0.1254.90.1033.18.3582.2624 [GMT 2:00]<br />
<br />
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}<br />
<br />
============== Running Processes ===============<br />
<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\svchost.exe -k RPCSS<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Program Files\Creative\Shared Files\CTAudSvc.exe<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation<br />
C:\Windows\system32\taskhost.exe<br />
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe<br />
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe<br />
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Program Files\AirTies\ADSL Hizmet Programy\AirTies_util3.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Windows\System32\svchost.exe -k secsvcs<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br />
C:\Windows\system32\taskhost.exe<br />
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtblfs.exe<br />
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Users\LIVE\Desktop\dds.scr<br />
C:\Windows\system32\conhost.exe<br />
<br />
============== Pseudo HJT Report ===============<br />
<br />
uStart Page = hxxp://www.ekolay.net/index.htm<br />
uURLSearchHooks: SearchHook Class: {bc86e1ab-eda5-4059-938f-ce307b0c6f0a} - c:\program files\devicevm\browser configuration utility\AddressBarSearch.dll<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll<br />
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2010\ievkbd.dll<br />
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll<br />
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll<br />
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll<br />
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll<br />
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll<br />
TB: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File<br />
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun<br />
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] &quot;c:\program files\common files\nero\lib\NMBgMonitor.exe&quot;<br />
mRun: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntry<br />
mRun: [BCU] &quot;c:\program files\devicevm\browser configuration utility\BCU.exe&quot;<br />
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe<br />
mRun: [Skytel] c:\program files\realtek\audio\hda\Skytel.exe<br />
mRun: [AVP] &quot;c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe&quot;<br />
mRun: [SunJavaUpdateSched] &quot;c:\program files\java\jre1.6.0_07\bin\jusched.exe&quot;<br />
mRun: [WinampAgent] &quot;c:\program files\winamp\winampa.exe&quot;<br />
mRun: [Adobe Reader Speed Launcher] &quot;c:\program files\adobe\reader 9.0\reader\Reader_sl.exe&quot;<br />
mRun: [Adobe ARM] &quot;c:\program files\common files\adobe\arm\1.0\AdobeARM.exe&quot;<br />
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup<br />
mRun: [nwiz] nwiz.exe /install<br />
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit<br />
mRun: [NBKeyScan] &quot;c:\program files\nero\nero8\nero backitup\NBKeyScan.exe&quot;<br />
mRun: [Adobe Acrobat Speed Launcher] &quot;c:\program files\adobe\acrobat 9.0\acrobat\Acrobat_sl.exe&quot;<br />
mRun: [&lt;NO NAME&gt;] <br />
mRun: [Acrobat Assistant 8.0] &quot;c:\program files\adobe\acrobat 9.0\acrobat\Acrotray.exe&quot;<br />
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\AIRTIE~1.LNK - <br />
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)<br />
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html<br />
IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html<br />
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\progra~1\java\jre16~1.0_0\bin\ssv.dll<br />
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll<br />
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab<br />
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab<br />
Notify: klogon - c:\windows\system32\klogon.dll<br />
AppInit_DLLs: c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll,c:\progra~1\kasper~1\kasper~1\kloehk.dll acaptuser32.dll<br />
<br />
================= FIREFOX ===================<br />
<br />
FF - ProfilePath - c:\users\live\appdata\roaming\mozilla\firefox\profiles\836sec4g.default\<br />
FF - prefs.js: browser.startup.homepage - hxxp://www.ekolay.net/index.htm<br />
FF - component: c:\program files\mozilla firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}<br />
<br />
============= SERVICES / DRIVERS ===============<br />
<br />
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-12-15 33808]<br />
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\drivers\klim6.sys [2009-5-15 21008]<br />
R2 BCUService;Browser Configuration Utility Service;c:\program files\devicevm\browser configuration utility\BCUService.exe [2009-11-3 219360]<br />
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2009-9-27 240232]<br />
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-5-16 19472]<br />
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-11-3 187392]<br />
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]<br />
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2009-11-3 79360]<br />
<br />
=============== Created Last 30 ================<br />
<br />
2009-11-20 09:33:54	0	d-----w-	c:\programdata\Lavasoft<br />
2009-11-20 09:33:54	0	d-----w-	c:\program files\Lavasoft<br />
2009-11-19 16:26:38	0	d-----w-	C:\dsp_sps<br />
2009-11-19 11:48:25	0	d-----w-	c:\program files\URUSoft<br />
2009-11-19 11:24:18	0	d-----w-	c:\programdata\FLEXnet<br />
2009-11-19 11:22:22	0	d-----w-	c:\program files\common files\Macrovision Shared<br />
2009-11-19 11:22:12	22872	----a-r-	c:\windows\system32\AdobePDFUI.dll<br />
2009-11-18 21:14:41	0	d-----w-	c:\program files\MSXML 4.0<br />
2009-11-17 15:27:11	0	d-----w-	c:\program files\DAEMON Tools Toolbar<br />
2009-11-17 15:26:56	691696	----a-w-	c:\windows\system32\drivers\sptd.sys<br />
2009-11-17 15:26:17	0	d-----w-	c:\users\live\appdata\roaming\DAEMON Tools Lite<br />
2009-11-17 15:26:12	0	d-----w-	c:\programdata\DAEMON Tools Lite<br />
2009-11-17 15:24:52	0	d-----w-	c:\program files\QuickSFV<br />
2009-11-17 14:00:35	327168	----a-w-	c:\windows\IsUn040c.exe<br />
2009-11-17 13:57:38	0	d-----w-	c:\program files\common files\YDP<br />
2009-11-17 13:57:35	0	d-----w-	c:\program files\common files\GraphBoard 2.00<br />
2009-11-17 13:57:35	0	d-----w-	c:\program files\Business English<br />
2009-11-17 13:57:25	0	d-----w-	c:\program files\ViaVoice<br />
2009-11-17 13:56:07	38160	----a-w-	c:\windows\system32\LMRTREND.dll<br />
2009-11-17 13:56:07	155408	----a-w-	c:\windows\system32\LMRT.dll<br />
2009-11-17 13:56:07	140800	----a-w-	c:\windows\system32\tm20dec.ax<br />
2009-11-17 13:56:06	182032	----a-w-	c:\windows\system32\dxtmsft3.dll<br />
2009-11-17 13:56:05	63488	----a-w-	c:\windows\system32\unam4ie.exe<br />
2009-11-17 13:56:05	217984	----a-w-	c:\windows\system32\strmdll.dll<br />
2009-11-17 13:56:04	5672	----a-w-	c:\windows\system32\quartz.vxd<br />
2009-11-17 13:56:04	194320	----a-w-	c:\windows\system32\qcut.dll<br />
2009-11-17 13:56:04	11776	----a-w-	c:\windows\system32\mciqtz.drv<br />
2009-11-17 13:56:04	10240	----a-w-	c:\windows\system32\vidx16.dll<br />
2009-11-17 13:56:03	4608	----a-w-	c:\windows\system32\w95inf32.dll<br />
2009-11-17 13:56:03	2272	----a-w-	c:\windows\system32\w95inf16.dll<br />
2009-11-17 13:54:56	306688	----a-w-	c:\windows\IsUninst.exe<br />
2009-11-17 12:09:53	0	d-----w-	c:\program files\Nero<br />
2009-11-17 11:40:08	0	d-----w-	c:\programdata\Nero<br />
2009-11-16 18:55:20	0	d-----w-	c:\users\live\appdata\roaming\BSplayer PRO<br />
2009-11-16 18:55:20	0	d-----w-	c:\program files\Webteh<br />
2009-11-16 18:23:34	0	d-----w-	c:\program files\VideoLAN<br />
2009-11-16 07:50:02	186407	----a-w-	c:\windows\system32\nvapps.xml<br />
2009-11-12 18:05:33	215351	----a-w-	c:\windows\system32\nvapps.nvb<br />
2009-11-07 16:46:05	0	d-----w-	c:\windows\DD1865F0AD7340FBB23E1822E02396FF.TMP<br />
2009-11-07 13:58:12	0	d-----w-	c:\program files\NVIDIA Corporation<br />
2009-11-07 13:57:07	0	d-----w-	C:\NVIDIA<br />
2009-11-07 12:33:38	0	d-----w-	c:\windows\system32\directx<br />
2009-11-07 12:23:30	0	d-----w-	c:\programdata\Adobe<br />
2009-11-07 12:11:05	0	d-----w-	c:\windows\system32\appmgmt<br />
2009-11-07 11:50:56	0	d-----w-	c:\windows\Cache<br />
2009-11-07 10:50:36	0	d-----w-	c:\windows\system32\AGEIA<br />
2009-11-07 10:50:31	0	d-----w-	c:\program files\common files\Wise Installation Wizard<br />
2009-11-07 10:50:19	0	d-----w-	c:\windows\nview<br />
2009-11-06 08:53:01	0	d-----w-	c:\program files\HD Tune Pro<br />
2009-11-05 19:28:52	351484845	----a-w-	c:\windows\MEMORY.DMP<br />
2009-11-05 12:43:01	0	d-----w-	c:\program files\GRETECH<br />
2009-11-05 11:03:37	0	d-----w-	c:\program files\uTorrent<br />
2009-11-05 11:02:00	0	d-----w-	c:\users\live\appdata\roaming\uTorrent<br />
2009-11-05 10:16:05	0	d-----w-	c:\users\live\appdata\roaming\OpenOffice.org<br />
2009-11-05 10:10:52	0	d-----w-	c:\program files\JRE<br />
2009-11-05 10:10:51	0	d-----w-	c:\program files\OpenOffice.org 3<br />
2009-11-05 10:09:14	0	d-----w-	c:\program files\MozBackup<br />
2009-11-04 17:21:19	0	d-----w-	c:\program files\AirTies<br />
2009-11-04 16:33:37	0	d-----w-	c:\programdata\NVIDIA<br />
2009-11-04 16:32:25	609690	----a-w-	c:\windows\system32\perfh01F.dat<br />
2009-11-04 16:32:25	37160	----a-w-	c:\windows\system32\perfd01F.dat<br />
2009-11-04 16:32:25	285034	----a-w-	c:\windows\system32\perfi01F.dat<br />
2009-11-04 16:32:25	118128	----a-w-	c:\windows\system32\perfc01F.dat<br />
2009-11-04 16:31:57	0	d-----w-	c:\windows\tr-TR<br />
2009-11-04 16:31:51	0	d-----w-	c:\windows\system32\XPSViewer<br />
2009-11-04 16:31:50	0	d-----w-	c:\windows\system32\tr<br />
2009-11-04 16:31:50	0	d-----w-	c:\windows\system32\drivers\tr-TR<br />
2009-11-04 16:31:49	0	d-----w-	c:\windows\system32\wbem\tr-TR<br />
2009-11-04 13:39:11	0	---ha-w-	c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf<br />
2009-11-04 13:25:03	129784	------w-	c:\windows\system32\pxafs.dll<br />
2009-11-04 13:16:14	604140	--sha-w-	c:\windows\system32\drivers\ISwift3.dat<br />
2009-11-04 13:15:39	95259	----a-w-	c:\windows\system32\drivers\klick.dat<br />
2009-11-04 13:15:39	108059	----a-w-	c:\windows\system32\drivers\klin.dat<br />
2009-11-04 13:15:18	0	d-----w-	c:\programdata\Kaspersky Lab<br />
2009-11-04 13:15:18	0	d-----w-	c:\program files\Kaspersky Lab<br />
2009-11-04 07:35:49	0	d-----w-	c:\program files\Norton Support<br />
2009-11-04 07:16:17	257024	----a-w-	c:\windows\system32\msv1_0.dll<br />
2009-11-04 06:54:41	34816	----a-w-	c:\windows\system32\msasn1.dll<br />
2009-11-04 06:54:37	728648	----a-w-	c:\windows\system32\drivers\dxgkrnl.sys<br />
2009-11-04 06:54:37	71168	----a-w-	c:\windows\system32\fontsub.dll<br />
2009-11-04 06:54:37	507568	----a-w-	c:\windows\system32\winload.exe<br />
2009-11-04 06:54:37	442920	----a-w-	c:\windows\system32\winresume.exe<br />
2009-11-04 06:54:37	293888	----a-w-	c:\windows\system32\atmfd.dll<br />
2009-11-04 06:54:37	2613248	----a-w-	c:\windows\explorer.exe<br />
2009-11-04 06:54:37	1320960	----a-w-	c:\windows\system32\CertEnroll.dll<br />
2009-11-04 06:54:37	12625408	----a-w-	c:\windows\system32\wmploc.DLL<br />
2009-11-04 06:54:37	108544	----a-w-	c:\windows\system32\t2embed.dll<br />
2009-11-03 23:41:26	0	d-----w-	c:\windows\Panther<br />
2009-11-03 14:32:03	0	d-----w-	c:\programdata\Symantec<br />
2009-11-03 14:31:41	0	d-----w-	c:\programdata\Norton<br />
2009-11-03 14:31:24	0	d-sh--w-	c:\windows\Installer<br />
2009-11-03 14:31:03	0	d-----w-	c:\programdata\NortonInstaller<br />
2009-11-03 14:30:39	94208	----a-w-	c:\windows\system32\RTNUninst32.dll<br />
2009-11-03 14:30:39	73728	----a-w-	c:\windows\system32\RtNicProp32.dll<br />
2009-11-03 14:30:26	187392	----a-w-	c:\windows\system32\drivers\Rt86win7.sys<br />
2009-11-03 14:28:28	0	d-----w-	c:\program files\Realtek<br />
2009-11-03 14:28:27	0	d--h--w-	c:\program files\Temp<br />
2009-11-03 14:26:50	53248	----a-r-	c:\windows\system32\CSVer.dll<br />
2009-11-03 14:26:45	0	d-----w-	C:\Intel<br />
2009-11-03 14:26:29	0	d--h--w-	c:\program files\DeviceVM<br />
2009-11-03 14:26:20	7062	----a-w-	c:\windows\system32\audiopid.vxd<br />
2009-11-03 14:25:53	413696	----a-w-	c:\windows\system32\wrap_oal.dll<br />
2009-11-03 14:25:53	2873820	------w-	c:\windows\system32\Sens_oal.dll<br />
2009-11-03 14:25:53	110592	----a-w-	c:\windows\system32\OpenAL32.dll<br />
2009-11-03 14:25:40	0	d-----w-	c:\program files\common files\Creative Labs Shared<br />
2009-11-03 14:25:33	10	----a-w-	c:\windows\GSetup.ini<br />
2009-11-03 14:25:24	0	d-----w-	c:\program files\Creative<br />
2009-11-03 14:10:33	195456	------w-	c:\windows\system32\MpSigStub.exe<br />
2009-11-03 13:59:09	0	d-----w-	c:\programdata\Creative<br />
2009-11-03 13:59:05	87	---ha-r-	c:\windows\ctfile.rfc<br />
2009-11-03 13:59:05	73728	----a-w-	c:\windows\system32\CmdRtr.DLL<br />
2009-11-03 13:59:05	166912	----a-w-	c:\windows\system32\APOMngr.DLL<br />
2009-11-03 13:55:53	1432496	----a-w-	c:\windows\system32\PerfStringBackup.INI<br />
2009-11-03 13:55:37	0	d-----w-	c:\windows\system32\wbem\Performance<br />
2009-11-03 13:52:49	0	d-sh--w-	C:\Recovery<br />
<br />
==================== Find3M  ====================<br />
<br />
2060-08-18 16:02:22	1496064	------w-	c:\windows\system32\CC3250MT.DLL<br />
2060-08-18 15:40:44	909824	------w-	c:\windows\system32\CP3245MT.DLL<br />
2060-08-18 15:40:44	24064	------w-	c:\windows\system32\BORLNDMM.DLL<br />
2009-11-04 16:31:41	37160	----a-w-	c:\windows\inf\perflib\041f\perfd.dat<br />
2009-11-04 16:31:41	37160	----a-w-	c:\windows\inf\perflib\041f\perfc.dat<br />
2009-11-04 16:31:41	285034	----a-w-	c:\windows\inf\perflib\041f\perfi.dat<br />
2009-11-04 16:31:41	285034	----a-w-	c:\windows\inf\perflib\041f\perfh.dat<br />
2009-10-16 00:11:56	1168896	----a-w-	c:\windows\system32\drivers\P17.sys<br />
2009-09-27 21:12:22	795104	----a-w-	c:\windows\system32\dpinst.exe<br />
2009-09-04 15:44:40	69464	----a-w-	c:\windows\system32\XAPOFX1_3.dll<br />
2009-09-04 15:44:40	515416	----a-w-	c:\windows\system32\XAudio2_5.dll<br />
2009-09-04 15:44:40	238936	----a-w-	c:\windows\system32\xactengine3_5.dll<br />
2009-09-04 15:29:34	453456	----a-w-	c:\windows\system32\d3dx10_42.dll<br />
2009-09-04 15:29:34	235344	----a-w-	c:\windows\system32\d3dx11_42.dll<br />
2009-09-04 15:29:32	5501792	----a-w-	c:\windows\system32\d3dcsx_42.dll<br />
2009-09-04 15:29:32	1974616	----a-w-	c:\windows\system32\D3DCompiler_42.dll<br />
2009-09-04 15:29:30	1892184	----a-w-	c:\windows\system32\D3DX9_42.dll<br />
2009-08-27 07:04:14	207400	----a-r-	c:\windows\GSetup.exe<br />
2009-08-25 00:31:18	613503	----a-w-	c:\windows\system32\APOIM32.exe<br />
2009-07-14 04:56:42	31548	----a-w-	c:\windows\inf\perflib\0409\perfd.dat<br />
2009-07-14 04:56:42	31548	----a-w-	c:\windows\inf\perflib\0409\perfc.dat<br />
2009-07-14 04:56:42	291294	----a-w-	c:\windows\inf\perflib\0409\perfi.dat<br />
2009-07-14 04:56:42	291294	----a-w-	c:\windows\inf\perflib\0409\perfh.dat<br />
2009-07-14 04:41:57	174	--sha-w-	c:\program files\desktop.ini<br />
2009-07-14 00:34:40	291294	----a-w-	c:\windows\inf\perflib\0000\perfi.dat<br />
2009-07-14 00:34:40	291294	----a-w-	c:\windows\inf\perflib\0000\perfh.dat<br />
2009-07-14 00:34:38	31548	----a-w-	c:\windows\inf\perflib\0000\perfd.dat<br />
2009-07-14 00:34:38	31548	----a-w-	c:\windows\inf\perflib\0000\perfc.dat<br />
2009-06-10 21:26:35	9633792	--sha-r-	c:\windows\fonts\StaticCache.dat<br />
2009-07-14 01:14:45	396800	--sha-w-	c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe<br />
<br />
============= FINISH: 15:36:47,45 ===============</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techsupportforum.com/cwd/images/attach/zip.gif" alt="File Type: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techsupportforum.com/attachments/virus-trojan-spyware-help/60557d1258727682-suspected-trojen-malware-virus-rootkit-attach.zip">Attach.zip</a> (3.5 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/">Virus/Trojan/Spyware Help</category>
			<dc:creator>fedor22</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433599-suspected-trojen-malware-virus-rootkit.html</guid>
		</item>
		<item>
			<title>Hidden Virus/Trojan/Worm problem?</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433578-hidden-virus-trojan-worm-problem.html</link>
			<pubDate>Fri, 20 Nov 2009 12:51:21 GMT</pubDate>
			<description><![CDATA[Hello all. I believe that my computer has a Virus or Trojan or Worm but I am not sure what or which. I have done scans with Bitdefender 2010 Internet Security as well as Malwarebytes' Anti-Malware but both shows nothing. However my computer hangs occasionally and sometimes even restarts itself. The...]]></description>
			<content:encoded><![CDATA[<div>Hello all. I believe that my computer has a Virus or Trojan or Worm but I am not sure what or which. I have done scans with Bitdefender 2010 Internet Security as well as Malwarebytes' Anti-Malware but both shows nothing. However my computer hangs occasionally and sometimes even restarts itself. The computer also seems to be busy with some process at times but the task manager shows that it is running at less than 5% cpu usage. <br />
<br />
Sometimes I am also unable to access the task manager through ctrl + alt + del, as well as being able to open start menu.<br />
<br />
Any idea what's wrong? Thanks in advance.</div>

]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/">Virus/Trojan/Spyware Help</category>
			<dc:creator>streamofmight</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433578-hidden-virus-trojan-worm-problem.html</guid>
		</item>
		<item>
			<title>Virus messing with my router ports?</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433572-virus-messing-my-router-ports.html</link>
			<pubDate>Fri, 20 Nov 2009 12:18:55 GMT</pubDate>
			<description>Dear Tech Support, 
 
Myself and two roommates share a DSL connection. I believe that I have a virus which is basically opening a ton of router ports and rendering the internet unusable for all of us sometimes (moreso at night). If i run netstat, 10-20 ports show to be open. THe virus does not seem...</description>
			<content:encoded><![CDATA[<div>Dear Tech Support,<br />
<br />
Myself and two roommates share a DSL connection. I believe that I have a virus which is basically opening a ton of router ports and rendering the internet unusable for all of us sometimes (moreso at night). If i run netstat, 10-20 ports show to be open. THe virus does not seem to be affecting the internal speed of my computer if I am not on the internet, but things are often paralyzingly slow if I am. <br />
<br />
I believe I had this virus on an old computer, and then stupidly used an external harddrive to move files between the two, and think the virus came with it.<br />
<br />
Ive copied and attached all scans per the instructions. Unfortunately, i dont have a copy of windows handy.<br />
<br />
Thank you so much for your help!<br />
Kelly<br />
<br />
-----------------------------------------------------------------------<br />
<br />
<br />
DDS (Ver_09-10-26.01) - NTFSx86  <br />
Run by Duck at 12:22:39.17 on Fri 11/20/2009<br />
Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_17<br />
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.3573.2174 [GMT 1:00]<br />
<br />
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}<br />
<br />
============== Running Processes ===============<br />
<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\svchost.exe -k rpcss<br />
C:\Windows\System32\svchost.exe -k secsvcs<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\system32\SLsvc.exe<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Program Files\Dell\DellDock\DockLogin.exe<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\System32\WLTRYSVC.EXE<br />
C:\Windows\system32\WLANExt.exe<br />
C:\Windows\System32\bcmwltry.exe<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Windows\system32\aestsrv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe<br />
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe<br />
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br />
C:\Windows\system32\STacSV.exe<br />
C:\Windows\system32\svchost.exe -k imgsvc<br />
C:\Windows\System32\svchost.exe -k WerSvcGroup<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Windows\system32\DRIVERS\xaudio.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\Dell\DellDock\DellDock.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\DellTPad\Apoint.exe<br />
C:\Windows\OEM02Mon.exe<br />
C:\Windows\System32\igfxtray.exe<br />
C:\Windows\System32\igfxpers.exe<br />
C:\Windows\system32\conime.exe<br />
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe<br />
C:\Windows\System32\WLTRAY.EXE<br />
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br />
C:\Program Files\Dell\MediaDirect\PCMService.exe<br />
C:\Windows\system32\igfxsrvc.exe<br />
C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe<br />
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe<br />
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Program Files\Digital Line Detect\DLG.exe<br />
C:\Program Files\Dell\QuickSet\quickset.exe<br />
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Program Files\DellTPad\ApMsgFwd.exe<br />
C:\Program Files\DellTPad\Apntex.exe<br />
C:\Program Files\DellTPad\HidFind.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Windows\system32\rundll32.exe<br />
C:\Windows\system32\vssvc.exe<br />
C:\Windows\System32\svchost.exe -k swprv<br />
c:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32Info.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Users\Duck\Downloads\dds.scr<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
<br />
============== Pseudo HJT Report ===============<br />
<br />
uSearch Page = hxxp://www.google.com<br />
uStart Page = hxxp://www.thedailyshow.com/<br />
uWindow Title = Internet Explorer provided by Dell<br />
uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&amp;client=dell-usuk&amp;channel=us&amp;ibd=1081215<br />
uSearch Bar = hxxp://www.google.com/ie<br />
uInternet Settings,ProxyOverride = *.local<br />
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll<br />
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll<br />
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll<br />
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll<br />
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll<br />
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll<br />
uRun: [swg] &quot;c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe&quot;<br />
uRun: [DellSupportCenter] &quot;c:\program files\dell support center\bin\sprtcmd.exe&quot; /P DellSupportCenter<br />
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe<br />
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
mRun: [Apoint] c:\program files\delltpad\Apoint.exe<br />
mRun: [OEM02Mon.exe] c:\windows\OEM02Mon.exe<br />
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe<br />
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe<br />
mRun: [Persistence] c:\windows\system32\igfxpers.exe<br />
mRun: [IAAnotif] &quot;c:\program files\intel\intel matrix storage manager\Iaanotif.exe&quot;<br />
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe<br />
mRun: [Adobe Reader Speed Launcher] &quot;c:\program files\adobe\reader 9.0\reader\Reader_sl.exe&quot;<br />
mRun: [Google Desktop Search] &quot;c:\program files\google\google desktop search\GoogleDesktop.exe&quot; /startup<br />
mRun: [dscactivate] &quot;c:\program files\dell support center\gs_agent\custom\dsca.exe&quot;<br />
mRun: [PCMService] &quot;c:\program files\dell\mediadirect\PCMService.exe&quot;<br />
mRun: [Dell DataSafe Online] &quot;c:\program files\dell datasafe online\DataSafeOnline.exe&quot; /m<br />
mRun: [DellSupportCenter] &quot;c:\program files\dell support center\bin\sprtcmd.exe&quot; /P DellSupportCenter<br />
mRun: [egui] &quot;c:\program files\eset\eset nod32 antivirus\egui.exe&quot; /hide /waitservice<br />
mRun: [TkBellExe] &quot;c:\program files\common files\real\update_ob\realsched.exe&quot;  -osboot<br />
mRun: [QuickTime Task] &quot;c:\program files\quicktime\QTTask.exe&quot; -atboottime<br />
mRun: [iTunesHelper] &quot;c:\program files\itunes\iTunesHelper.exe&quot;<br />
mRun: [Google Quick Search Box] &quot;c:\program files\google\quick search box\GoogleQuickSearchBox.exe&quot;  /autorun<br />
mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe<br />
mRun: [SunJavaUpdateSched] &quot;c:\program files\java\jre6\bin\jusched.exe&quot;<br />
StartupFolder: c:\users\duck\appdata\roaming\micros~1\windows\startm~1\programs\startup\delldo~1.lnk - c:\program files\dell\delldock\DellDock.exe<br />
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe<br />
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\program files\dell\quickset\quickset.exe<br />
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
IE: Add to Google Photos Screensa&amp;ver - c:\windows\system32\GPhotos.scr/200<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000<br />
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL<br />
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll<br />
Notify: igfxcui - igfxdev.dll<br />
AppInit_DLLs: c:\progra~1\google\google~3\GOEC62~1.DLL<br />
<br />
================= FIREFOX ===================<br />
<br />
FF - ProfilePath - c:\users\duck\appdata\roaming\mozilla\firefox\profiles\z4vy01nz.default\<br />
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig|<a href="http://www.npr.org/" target="_blank">http://www.npr.org/</a><br />
FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll<br />
FF - component: c:\users\duck\appdata\roaming\mozilla\firefox\profiles\z4vy01nz.default\extensions\{0b457caa-602d-484a-8fe7-c1d894a011ba}\platform\winnt_x86-msvc\components\SSSLauncher.dll<br />
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll<br />
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}<br />
<br />
---- FIREFOX POLICIES ----<br />
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref(&quot;security.ssl3.rsa_seed_sha&quot;, true);<br />
<br />
============= SERVICES / DRIVERS ===============<br />
<br />
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-5-14 107256]<br />
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2008-12-15 73728]<br />
R2 DockLoginService;Dock Login Service;c:\program files\dell\delldock\DockLogin.exe [2008-9-24 155648]<br />
R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2009-5-14 731840]<br />
R2 epfwwfpr;epfwwfpr;c:\windows\system32\drivers\epfwwfpr.sys [2009-5-14 93312]<br />
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [2008-12-15 111616]<br />
R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\system32\drivers\OEM02Dev.sys [2008-12-15 235648]<br />
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\system32\drivers\OEM02Vfx.sys [2008-12-15 7424]<br />
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]<br />
S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-12-15 30192]<br />
<br />
=============== Created Last 30 ================<br />
<br />
2009-11-10 21:23:35	0	d-----w-	c:\program files\Windows Portable Devices<br />
2009-11-10 21:23:26	0	---ha-w-	c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf<br />
2009-11-10 21:18:09	2036736	----a-w-	c:\windows\system32\win32k.sys<br />
2009-11-10 21:17:59	355328	----a-w-	c:\windows\system32\WSDApi.dll<br />
2009-11-10 21:12:27	92672	----a-w-	c:\windows\system32\UIAnimation.dll<br />
2009-11-10 21:12:26	3023360	----a-w-	c:\windows\system32\UIRibbon.dll<br />
2009-11-10 21:12:26	1164800	----a-w-	c:\windows\system32\UIRibbonRes.dll<br />
2009-11-10 21:09:47	555520	----a-w-	c:\windows\system32\UIAutomationCore.dll<br />
2009-11-10 21:09:47	4096	----a-w-	c:\windows\system32\oleaccrc.dll<br />
2009-11-10 21:09:47	234496	----a-w-	c:\windows\system32\oleacc.dll<br />
2009-10-30 00:29:08	2146304	----a-w-	c:\windows\system32\GPhotos.scr<br />
2009-10-28 08:19:19	310784	----a-w-	c:\windows\system32\unregmp2.exe<br />
2009-10-28 08:19:15	8147456	----a-w-	c:\windows\system32\wmploc.DLL<br />
<br />
==================== Find3M  ====================<br />
<br />
2009-11-10 21:23:31	86016	----a-w-	c:\windows\inf\infstor.dat<br />
2009-11-10 21:23:31	665600	----a-w-	c:\windows\inf\drvindex.dat<br />
2009-11-10 21:23:31	51200	----a-w-	c:\windows\inf\infpub.dat<br />
2009-11-10 21:23:31	143360	----a-w-	c:\windows\inf\infstrng.dat<br />
2009-11-02 19:42:06	195456	------w-	c:\windows\system32\MpSigStub.exe<br />
2009-10-11 03:17:27	411368	----a-w-	c:\windows\system32\deploytk.dll<br />
2009-10-01 01:02:17	2537472	----a-w-	c:\windows\system32\wpdshext.dll<br />
2009-10-01 01:02:05	30208	----a-w-	c:\windows\system32\WPDShextAutoplay.exe<br />
2009-10-01 01:02:04	334848	----a-w-	c:\windows\system32\PortableDeviceApi.dll<br />
2009-10-01 01:02:02	87552	----a-w-	c:\windows\system32\WPDShServiceObj.dll<br />
2009-10-01 01:02:00	31232	----a-w-	c:\windows\system32\BthMtpContextHandler.dll<br />
2009-10-01 01:01:59	546816	----a-w-	c:\windows\system32\wpd_ci.dll<br />
2009-10-01 01:01:59	160256	----a-w-	c:\windows\system32\PortableDeviceTypes.dll<br />
2009-10-01 01:01:56	60928	----a-w-	c:\windows\system32\PortableDeviceConnectApi.dll<br />
2009-10-01 01:01:56	350208	----a-w-	c:\windows\system32\WPDSp.dll<br />
2009-10-01 01:01:56	196608	----a-w-	c:\windows\system32\PortableDeviceWMDRM.dll<br />
2009-10-01 01:01:56	100864	----a-w-	c:\windows\system32\PortableDeviceClassExtension.dll<br />
2009-10-01 01:01:54	81920	----a-w-	c:\windows\system32\wpdbusenum.dll<br />
2009-09-25 02:10:10	974848	----a-w-	c:\windows\system32\WindowsCodecs.dll<br />
2009-09-25 02:07:08	189440	----a-w-	c:\windows\system32\WindowsCodecsExt.dll<br />
2009-09-25 02:04:32	321024	----a-w-	c:\windows\system32\PhotoMetadataHandler.dll<br />
2009-09-25 01:49:22	1554432	----a-w-	c:\windows\system32\xpsservices.dll<br />
2009-09-25 01:48:08	351232	----a-w-	c:\windows\system32\XpsPrint.dll<br />
2009-09-25 01:38:29	847360	----a-w-	c:\windows\system32\OpcServices.dll<br />
2009-09-25 01:36:13	280064	----a-w-	c:\windows\system32\XpsGdiConverter.dll<br />
2009-09-25 01:35:31	135680	----a-w-	c:\windows\system32\XpsRasterService.dll<br />
2009-09-25 01:33:25	195584	----a-w-	c:\windows\system32\dxdiagn.dll<br />
2009-09-25 01:33:15	829440	----a-w-	c:\windows\system32\d3d10warp.dll<br />
2009-09-25 01:33:01	369664	----a-w-	c:\windows\system32\WMPhoto.dll<br />
2009-09-25 01:32:59	252928	----a-w-	c:\windows\system32\dxdiag.exe<br />
2009-09-25 01:31:53	519680	----a-w-	c:\windows\system32\d3d11.dll<br />
2009-09-25 01:31:26	486912	----a-w-	c:\windows\system32\d3d10level9.dll<br />
2009-09-25 01:31:21	161280	----a-w-	c:\windows\system32\d3d10_1.dll<br />
2009-09-25 01:31:19	218112	----a-w-	c:\windows\system32\d3d10_1core.dll<br />
2009-09-25 01:31:16	1030144	----a-w-	c:\windows\system32\d3d10.dll<br />
2009-09-25 01:31:15	828928	----a-w-	c:\windows\system32\d2d1.dll<br />
2009-09-25 01:30:23	481792	----a-w-	c:\windows\system32\dxgi.dll<br />
2009-09-25 01:30:23	190464	----a-w-	c:\windows\system32\d3d10core.dll<br />
2009-09-25 01:27:25	634880	----a-w-	c:\windows\system32\drivers\dxgkrnl.sys<br />
2009-09-25 01:27:04	793088	----a-w-	c:\windows\system32\FntCache.dll<br />
2009-09-25 01:27:04	37888	----a-w-	c:\windows\system32\cdd.dll<br />
2009-09-25 01:27:04	1064448	----a-w-	c:\windows\system32\DWrite.dll<br />
2009-09-24 22:54:55	258048	----a-w-	c:\windows\system32\winspool.drv<br />
2009-09-24 22:54:53	667648	----a-w-	c:\windows\system32\printfilterpipelinesvc.exe<br />
2009-09-24 22:54:52	26112	----a-w-	c:\windows\system32\printfilterpipelineprxy.dll<br />
2009-09-16 00:43:41	37665	----a-w-	c:\windows\fonts\GlobalUserInterface.CompositeFont<br />
2009-09-10 16:48:01	218624	----a-w-	c:\windows\system32\msv1_0.dll<br />
2009-09-04 11:41:59	60928	----a-w-	c:\windows\system32\msasn1.dll<br />
2009-08-29 00:27:49	4240384	----a-w-	c:\windows\system32\GameUXLegacyGDFs.dll<br />
2009-08-29 00:14:38	28672	----a-w-	c:\windows\system32\Apphlpdm.dll<br />
2009-08-27 13:29:25	78336	----a-w-	c:\windows\system32\ieencode.dll<br />
2009-08-27 12:40:58	834048	----a-w-	c:\windows\system32\wininet.dll<br />
2008-01-21 02:43:21	174	--sha-w-	c:\program files\desktop.ini<br />
2006-11-02 12:42:02	30674	----a-w-	c:\windows\inf\perflib\0409\perfd.dat<br />
2006-11-02 12:42:02	30674	----a-w-	c:\windows\inf\perflib\0409\perfc.dat<br />
2006-11-02 12:42:02	287440	----a-w-	c:\windows\inf\perflib\0409\perfi.dat<br />
2006-11-02 12:42:02	287440	----a-w-	c:\windows\inf\perflib\0409\perfh.dat<br />
2006-11-02 09:20:21	287440	----a-w-	c:\windows\inf\perflib\0000\perfi.dat<br />
2006-11-02 09:20:21	287440	----a-w-	c:\windows\inf\perflib\0000\perfh.dat<br />
2006-11-02 09:20:19	30674	----a-w-	c:\windows\inf\perflib\0000\perfd.dat<br />
2006-11-02 09:20:19	30674	----a-w-	c:\windows\inf\perflib\0000\perfc.dat<br />
2008-12-15 08:01:36	8192	--sha-w-	c:\windows\users\default\NTUSER.DAT<br />
<br />
============= FINISH: 12:22:54.63 ===============</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techsupportforum.com/cwd/images/attach/zip.gif" alt="File Type: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techsupportforum.com/attachments/virus-trojan-spyware-help/60556d1258719343-virus-messing-my-router-ports-attach.zip">Attach.zip</a> (2.7 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/">Virus/Trojan/Spyware Help</category>
			<dc:creator>Kellyr81</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433572-virus-messing-my-router-ports.html</guid>
		</item>
		<item>
			<title>unable to connect to anti-virus website</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433552-unable-connect-anti-virus-website.html</link>
			<pubDate>Fri, 20 Nov 2009 09:44:28 GMT</pubDate>
			<description><![CDATA[Hi All, 
 
I believe i'm infected. I not able to connect to any anti virus website. I have done a full scan using symantec endpoint protection but no virus detected. 
Can anyone help please. 
 
thanks]]></description>
			<content:encoded><![CDATA[<div>Hi All,<br />
<br />
I believe i'm infected. I not able to connect to any anti virus website. I have done a full scan using symantec endpoint protection but no virus detected.<br />
Can anyone help please.<br />
<br />
thanks</div>

]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/">Virus/Trojan/Spyware Help</category>
			<dc:creator>ciacia</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433552-unable-connect-anti-virus-website.html</guid>
		</item>
		<item>
			<title>C:\Nar.VBS and others</title>
			<link>http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433542-c-nar-vbs-others.html</link>
			<pubDate>Fri, 20 Nov 2009 09:04:53 GMT</pubDate>
			<description>On my main desktop I am running avast and it keeps coming up with warnings regarding these problems  
 
D:\Autorun.inf       (VBS:Malware-gen) VPS version 091119-2, 11/19/2009  
d:\windows\nar.vbs    (VBS:Malware-gen) VPS version 091119-2, 11/19/2009  
C:\nar.vbs     (VBS:Malware-gen) VPS version...</description>
			<content:encoded><![CDATA[<div>On my main desktop I am running avast and it keeps coming up with warnings regarding these problems <br />
<br />
D:\Autorun.inf       (VBS:Malware-gen) VPS version 091119-2, 11/19/2009 <br />
d:\windows\nar.vbs    (VBS:Malware-gen) VPS version 091119-2, 11/19/2009 <br />
C:\nar.vbs     (VBS:Malware-gen) VPS version 091119-2, 11/19/2009 <br />
<br />
The antivirus can't get rid of them, and I looked up a fix on the forums but the link directing to the fix is an invalid thread, and the downlaod for an automated fix won't work (winrar says it's damaged ). <br />
<br />
I'm running Windows XP 32bit on this computer. <br />
<br />
Can anyone help me with fixing this? <br />
<br />
Thank you.</div>

]]></content:encoded>
			<category domain="http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/">Virus/Trojan/Spyware Help</category>
			<dc:creator>tapatio</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/433542-c-nar-vbs-others.html</guid>
		</item>
	</channel>
</rss>
