<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>Tech Support Forum - Inactive Malware Help Topics</title>
		<link>http://www.techsupportforum.com/forums/</link>
		<description />
		<language>en</language>
		<lastBuildDate>Thu, 17 May 2012 07:33:29 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://cdn.techsupportforum.com/forums/images/sk/misc/rss.jpg</url>
			<title>Tech Support Forum - Inactive Malware Help Topics</title>
			<link>http://www.techsupportforum.com/forums/</link>
		</image>
		<item>
			<title>THIS VIRUS DOES NOT WANT TO LEAVE</title>
			<link>http://www.techsupportforum.com/forums/f284/this-virus-does-not-want-to-leave-644525.html</link>
			<pubDate>Tue, 08 May 2012 22:41:52 GMT</pubDate>
			<description>Hello Everyone, 
                    I was redirected here after I posted for help under the Software part of this forum. My problem is, a popup of (My Computer and My Document) appears on its own immediately I boot my laptop. It is a Gateway LT21 series. I followed the NEW INSTRUCTIONS that led me...</description>
			<content:encoded><![CDATA[<div>Hello Everyone,<br />
                    I was redirected here after I posted for help under the Software part of this forum. My problem is, a popup of (My Computer and My Document) appears on its own immediately I boot my laptop. It is a Gateway LT21 series. I followed the NEW INSTRUCTIONS that led me to re-post my problem here together with some information. I successfully finished the scan. Here is the DDS log below. Please find also the attached file. Thanks.<br />
<br />
<br />
<br />
.<br />
DDS (Ver_2011-08-26.01) - NTFSx86 <br />
Internet Explorer: 9.0.8112.16421<br />
Run by MILDRED at 19:06:54 on 2012-05-08<br />
Microsoft Windows 7 Ultimate   6.1.7600.0.1252.1.1033.18.1013.484 [GMT 1:00]<br />
.<br />
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\svchost.exe -k RPCSS<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\WLANExt.exe<br />
C:\Windows\system32\conhost.exe<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Windows\system32\taskhost.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation<br />
C:\Windows\System32\igfxtray.exe<br />
C:\Windows\System32\hkcmd.exe<br />
C:\Windows\System32\igfxpers.exe<br />
C:\Windows\system32\igfxsrvc.exe<br />
C:\Program Files\USB Disk Security\USBGuard.exe<br />
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Windows\System32\svchost.exe -k secsvcs<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Windows\system32\taskhost.exe<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Windows\system32\WUDFHost.exe<br />
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\system32\conhost.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uStart Page = hxxp://www.google.com/<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll<br />
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GR469A~1.DLL<br />
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll<br />
BHO: Softonic Helper Object: {e87806b5-e908-45fd-af5e-957d83e58e68} - c:\program files\softonic\softonic\1.5.21.0\bh\Softonic.dll<br />
TB: Softonic Toolbar: {5018cfd2-804d-4c99-9f81-25eaea2769de} - c:\program files\softonic\softonic\1.5.21.0\SoftonicTlbr.dll<br />
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll<br />
uRun: [swg] &quot;c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe&quot;<br />
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe<br />
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe<br />
mRun: [Persistence] c:\windows\system32\igfxpers.exe<br />
mRun: [USB Security] c:\program files\usb disk security\USBGuard.exe<br />
mRun: [GrooveMonitor] &quot;c:\program files\microsoft office\office12\GrooveMonitor.exe&quot;<br />
mRun: [Adobe Reader Speed Launcher] &quot;c:\program files\adobe\reader 10.0\reader\Reader_sl.exe&quot;<br />
mRun: [Adobe ARM] &quot;c:\program files\common files\adobe\arm\1.0\AdobeARM.exe&quot;<br />
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)<br />
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000<br />
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html<br />
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL<br />
TCP: DhcpNameServer = 192.168.1.1<br />
TCP: Interfaces\{14DE6D2C-5625-485A-95CB-FB8E29D00A2E} : DhcpNameServer = 192.168.1.1<br />
TCP: Interfaces\{F2B715C5-9C6D-4B30-9901-7D01CE8A34F8} : DhcpNameServer = 192.168.1.1<br />
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GRA32A~1.DLL<br />
Notify: igfxcui - igfxdev.dll<br />
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GR469A~1.DLL<br />
.<br />
================= FIREFOX ===================<br />
.<br />
FF - ProfilePath - c:\users\mildred\appdata\roaming\mozilla\firefox\profiles\08zf2fpy.default\<br />
FF - prefs.js: network.proxy.type - 0<br />
FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll<br />
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_2_202_235.dll<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]<br />
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\drivers\L1C62x86.sys [2009-6-10 50688]<br />
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]<br />
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2012-5-1 136176]<br />
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-5-1 257696]<br />
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]<br />
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2012-5-1 136176]<br />
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2012-5-2 1343400]<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2012-05-08 14:53:40    --------    d-----w-    c:\windows\system32\appmgmt<br />
2012-05-06 22:21:55    56200    ----a-w-    c:\programdata\microsoft\windows defender\definition updates\{fa742164-e51a-4903-aae6-3209569ac0f2}\offreg.dll<br />
2012-05-06 21:05:37    409088    ----a-w-    c:\windows\system32\systemcpl.dll<br />
2012-05-06 20:48:00    2101760    ----a-w-    c:\windows\system32\drivers\athr.sys<br />
2012-05-06 20:47:59    64672    ----a-w-    c:\windows\system32\athihvui.dll<br />
2012-05-06 20:47:59    400544    ----a-w-    c:\windows\system32\athihvs.dll<br />
2012-05-06 20:47:59    --------    d-----w-    c:\windows\system32\nn-NO<br />
2012-05-06 20:16:08    33104    ----a-w-    c:\windows\system32\spool\prtprocs\w32x86\msonpppr.dll<br />
2012-05-06 20:16:08    32592    ----a-w-    c:\windows\system32\msonpmon.dll<br />
2012-05-06 20:11:09    --------    d-----w-    c:\windows\PCHEALTH<br />
2012-05-06 20:10:34    --------    d-----w-    c:\users\mildred\appdata\local\Adobe<br />
2012-05-06 20:08:06    --------    d-----w-    c:\program files\Microsoft Visual Studio 8<br />
2012-05-06 20:06:53    --------    d-----w-    c:\users\mildred\appdata\local\Microsoft Help<br />
2012-05-06 20:04:15    --------    d-----w-    c:\users\mildred\appdata\roaming\Zbshareware Lab<br />
2012-05-06 20:04:15    --------    d-----w-    c:\programdata\Zbshareware Lab<br />
2012-05-06 19:59:07    --------    d-----w-    c:\program files\PowerISO<br />
2012-05-06 19:54:56    --------    d-----w-    c:\program files\USB Disk Security<br />
2012-05-02 07:52:12    --------    d-----w-    c:\windows\system32\Wat<br />
2012-05-02 07:30:29    257024    ----a-w-    c:\windows\system32\msv1_0.dll<br />
2012-05-02 02:30:18    99176    ----a-w-    c:\windows\system32\PresentationHostProxy.dll<br />
2012-05-02 02:30:18    49472    ----a-w-    c:\windows\system32\netfxperf.dll<br />
2012-05-02 02:30:18    297808    ----a-w-    c:\windows\system32\mscoree.dll<br />
2012-05-02 02:30:18    295264    ----a-w-    c:\windows\system32\PresentationHost.exe<br />
2012-05-02 02:30:18    1130824    ----a-w-    c:\windows\system32\dfshim.dll<br />
2012-05-02 02:06:23    5120    ----a-w-    c:\windows\system32\wmi.dll<br />
2012-05-02 02:06:23    19312    ----a-w-    c:\windows\system32\drivers\fs_rec.sys<br />
2012-05-02 02:06:23    172544    ----a-w-    c:\windows\system32\wintrust.dll<br />
2012-05-02 02:06:23    158720    ----a-w-    c:\windows\system32\imagehlp.dll<br />
2012-05-02 02:02:00    190976    ----a-w-    c:\windows\system32\drivers\ks.sys<br />
2012-05-02 02:02:00    146304    ----a-w-    c:\windows\system32\drivers\usbvideo.sys<br />
2012-05-02 02:01:19    3958128    ----a-w-    c:\windows\system32\ntkrnlpa.exe<br />
2012-05-02 02:01:18    3902320    ----a-w-    c:\windows\system32\ntoskrnl.exe<br />
2012-05-02 02:01:04    276992    ----a-w-    c:\windows\system32\wcncsvc.dll<br />
2012-05-01 23:22:41    --------    d-----w-    c:\program files\Softonic<br />
2012-05-01 23:21:37    --------    d-----w-    c:\program files\VideoLAN<br />
2012-05-01 23:14:33    1227776    ----a-w-    c:\windows\system32\athr.sys<br />
2012-05-01 23:14:33    --------    d-----w-    c:\windows\Options<br />
2012-05-01 23:14:33    --------    d-----w-    c:\program files\Atheros<br />
2012-05-01 23:13:51    --------    d-----w-    c:\programdata\Atheros<br />
2012-05-01 23:02:37    1006104    ----a-w-    c:\windows\system32\igxpun.exe<br />
2012-05-01 23:02:37    --------    d-----w-    c:\windows\system32\x64<br />
2012-05-01 22:56:16    --------    d-----w-    c:\programdata\Kaspersky Lab<br />
2012-05-01 22:48:47    442880    ----a-w-    c:\windows\system32\XpsPrint.dll<br />
2012-05-01 22:48:44    292864    ----a-w-    c:\windows\system32\apphelp.dll<br />
2012-05-01 22:48:43    288256    ----a-w-    c:\windows\system32\XpsGdiConverter.dll<br />
2012-05-01 22:47:58    38912    ----a-w-    c:\windows\system32\csrsrv.dll<br />
2012-05-01 22:43:49    28672    ----a-w-    c:\windows\system32\dnscacheugc.exe<br />
2012-05-01 22:42:50    749056    ----a-w-    c:\windows\system32\schedsvc.dll<br />
2012-05-01 22:41:46    191488    ----a-w-    c:\windows\system32\FXSCOVER.exe<br />
2012-05-01 22:40:57    2690560    ----a-w-    c:\windows\system32\mstscax.dll<br />
2012-05-01 22:38:22    204288    ----a-w-    c:\windows\system32\upnp.dll<br />
2012-05-01 22:37:45    1137664    ----a-w-    c:\windows\system32\mfc42.dll<br />
2012-05-01 22:37:44    1164288    ----a-w-    c:\windows\system32\mfc42u.dll<br />
2012-05-01 22:37:20    363520    ----a-w-    c:\windows\system32\StructuredQuery.dll<br />
2012-05-01 22:37:19    69632    ----a-w-    c:\windows\system32\drivers\bowser.sys<br />
2012-05-01 22:37:17    26496    ----a-w-    c:\windows\system32\drivers\Diskdump.sys<br />
2012-05-01 22:07:23    6734704    ----a-w-    c:\programdata\microsoft\windows defender\definition updates\{fa742164-e51a-4903-aae6-3209569ac0f2}\mpengine.dll<br />
2012-05-01 22:07:21    237072    ------w-    c:\windows\system32\MpSigStub.exe<br />
2012-05-01 21:59:03    801792    ----a-w-    c:\windows\system32\FntCache.dll<br />
2012-05-01 21:59:03    3181568    ----a-w-    c:\windows\system32\mf.dll<br />
2012-05-01 21:59:03    196608    ----a-w-    c:\windows\system32\mfreadwrite.dll<br />
2012-05-01 21:59:03    1619456    ----a-w-    c:\windows\system32\WMVDECOD.DLL<br />
2012-05-01 21:59:03    1495040    ----a-w-    c:\windows\system32\ExplorerFrame.dll<br />
2012-05-01 21:59:03    135168    ----a-w-    c:\windows\system32\XpsRasterService.dll<br />
2012-05-01 21:55:21    826368    ----a-w-    c:\windows\system32\rdpcore.dll<br />
2012-05-01 21:55:21    24064    ----a-w-    c:\windows\system32\drivers\tdtcp.sys<br />
2012-05-01 21:55:21    177152    ----a-w-    c:\windows\system32\drivers\rdpwd.sys<br />
2012-05-01 21:55:20    8192    ----a-w-    c:\windows\system32\rdrmemptylst.exe<br />
2012-05-01 21:55:19    57856    ----a-w-    c:\windows\system32\rdpwsx.dll<br />
2012-05-01 21:55:19    129536    ----a-w-    c:\windows\system32\rdpcorekmts.dll<br />
2012-05-01 21:54:29    132608    ----a-w-    c:\windows\system32\cabview.dll<br />
2012-05-01 21:54:02    --------    d-sh--w-    c:\windows\Installer<br />
2012-05-01 21:53:44    --------    d-----w-    c:\users\mildred\appdata\local\Google<br />
2012-05-01 21:53:29    70304    ----a-w-    c:\windows\system32\FlashPlayerCPLApp.cpl<br />
2012-05-01 21:53:29    419488    ----a-w-    c:\windows\system32\FlashPlayerApp.exe<br />
2012-05-01 21:50:06    --------    d-----w-    c:\windows\system32\wbem\Performance<br />
2012-04-28 21:38:14    --------    d-----w-    c:\windows\Panther<br />
2012-04-28 12:47:21    --------    d-sh--w-    C:\Recovery<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2012-05-06 21:05:37    13824    ----a-w-    c:\windows\system32\slwga.dll<br />
2012-02-10 05:41:38    1074176    ----a-w-    c:\windows\system32\DWrite.dll<br />
2012-02-10 05:41:20    218624    ----a-w-    c:\windows\system32\d3d10_1core.dll<br />
2012-02-10 05:41:20    161792    ----a-w-    c:\windows\system32\d3d10_1.dll<br />
2012-02-10 05:41:20    1170944    ----a-w-    c:\windows\system32\d3d10warp.dll<br />
2012-02-10 05:41:19    739840    ----a-w-    c:\windows\system32\d2d1.dll<br />
.<br />
============= FINISH: 19:08:15.42 ===============</div>


	<br />
	<div style="padding:8px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://cdn.techsupportforum.com/forums/images/sk/attach/zip.gif" alt="File Type: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techsupportforum.com/forums/attachment.php?attachmentid=109232&amp;d=1336516803">Attach.zip</a> (2.0 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techsupportforum.com/forums/f284/">Inactive Malware Help Topics</category>
			<dc:creator>skratchet</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/forums/f284/this-virus-does-not-want-to-leave-644525.html</guid>
		</item>
		<item>
			<title>Can no longer connect to internet.</title>
			<link>http://www.techsupportforum.com/forums/f284/can-no-longer-connect-to-internet-644408.html</link>
			<pubDate>Tue, 08 May 2012 11:00:42 GMT</pubDate>
			<description>Yesterday i got a virus. 
 
I was looking up some things on wiki when a flash installer popped up. Im usually quite good at knowing when i have a virus but this looked authentic. I had no random popups or anything weird so i let the installer do its thing. 
 
After it was done it removed everything...</description>
			<content:encoded><![CDATA[<div>Yesterday i got a virus.<br />
<br />
I was looking up some things on wiki when a flash installer popped up. Im usually quite good at knowing when i have a virus but this looked authentic. I had no random popups or anything weird so i let the installer do its thing.<br />
<br />
After it was done it removed everything from my desktop and put me on a page about the metropolitan police, paying money to unlock my pc blah blah.<br />
I knew straight away this was utter crap so i restarted the pc and ran spybot S&amp;D, it found some stuff removed it and asked for a restart.<br />
<br />
Upon restart windows wouldn't launch and asked for revert to last known working instance, i did. It put me to the point where the flash installer kept popping up.<br />
<br />
I got bit defender, it installed and as soon as it was done installing my internet knocked out. it ran a scan and removed a couple trojan viruses.<br />
<br />
after finishing i ran a troubleshoot on my connection problem it popped up saying &quot;windows can't communicate with the device or resource (primary dns)&quot; so i started up my lap top (what im using now) it wouldn't connect to my router.<br />
<br />
I unplugged it and now i can connect.<br />
<br />
After doing some research i reset the dns with cmd and some various other commands, (ipv4 , ipv6) but still my desktop wont connect.<br />
I reset the router to factory settings and still nothing.<br />
<br />
I cant connect to anything at all with my desktop, skype, steam, firefox, ventrilo. Nothing.<br />
<br />
Usually id wipe the HD but i really don't want to lose everything so fixing it my only choice.<br />
Any help will be appreciated.</div>

]]></content:encoded>
			<category domain="http://www.techsupportforum.com/forums/f284/">Inactive Malware Help Topics</category>
			<dc:creator>chudy181</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/forums/f284/can-no-longer-connect-to-internet-644408.html</guid>
		</item>
		<item>
			<title>my pc flooding websites. its virus ?</title>
			<link>http://www.techsupportforum.com/forums/f284/my-pc-flooding-websites-its-virus-644075.html</link>
			<pubDate>Sun, 06 May 2012 12:50:29 GMT</pubDate>
			<description><![CDATA[hi .  Im facing this problem 1 month . 
 
pleease help me  
 
My english is not best i hope u understand . 
 
Am browsing internet with opera 11.62 and opera after 15 min or after 40 min start downloading and uploading lot of data like 1 gb to website where i am [youtube , twiter etc .] and my...]]></description>
			<content:encoded><![CDATA[<div>hi .  Im facing this problem 1 month .<br />
<br />
pleease help me <br />
<br />
My english is not best i hope u understand .<br />
<br />
Am browsing internet with opera 11.62 and opera after 15 min or after 40 min start downloading and uploading lot of data like 1 gb to website where i am [youtube , twiter etc .] and my internet become laggy . Than i go to my firewall comodo and see what happening . My IP downloading and somethimes also uploading to other IP , and that other IP belong to somethimes youtube somethimes twiter or any other website WHICH am currently browsing, so its look like i have VIRUS .<br />
<br />
I have also avira free 2012 . I scan my pc with avira , avira boot rescue , nod , kaspersky , spybot antimalware malwarebites or what ever all this programs find nothing ..  i have no infection ... also combofix sayd no infection <br />
<br />
Its not even opera problem i run opera xfire steam and icq ... after 30 min icq start downloading data or xfire , AM playing teamfortress 2 on steam server and my ping goes from 30 ms to 500 ms , i minimize game and am uploading and downing to valve tf2 server where am currently playing 300 mb .  *** !!!<br />
<br />
I formated not whole hdd only C: full format .  Restore my system image WHICH i create 1 year ago and 1 year ago there was no problem . After 20 min baaam i download 1.3 gig  from pcforum i was just reading new threads and i download 1.3 gig ^^ .<br />
<br />
so i restore my  2 years old XP image but to other free virus HDD . old 20 gb ATA hdd . still have problem ... <br />
<br />
THIS IS UNSOLVABLE PROBLEM . i try everything i scan my pc like15 times . <br />
<br />
its not that someone flooding me , I flood internet . pls help :nonono:</div>

]]></content:encoded>
			<category domain="http://www.techsupportforum.com/forums/f284/">Inactive Malware Help Topics</category>
			<dc:creator>techenko</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/forums/f284/my-pc-flooding-websites-its-virus-644075.html</guid>
		</item>
		<item>
			<title>HDD Errors</title>
			<link>http://www.techsupportforum.com/forums/f284/hdd-errors-643853.html</link>
			<pubDate>Fri, 04 May 2012 19:42:45 GMT</pubDate>
			<description><![CDATA[Lately I have been having errors with my HDD, it keeps saying Failure is Predicted.  After googling my way around for a possible fix I think it could possibly (hopefully!) be fixable.  Anyways, here is the required info for my PC, hope you guys can find something I can't...I am not so computer...]]></description>
			<content:encoded><![CDATA[<div>Lately I have been having errors with my HDD, it keeps saying Failure is Predicted.  After googling my way around for a possible fix I think it could possibly (hopefully!) be fixable.  Anyways, here is the required info for my PC, hope you guys can find something I can't...I am not so computer savvy tbh =(.<br />
<br />
<br />
.<br />
DDS (Ver_2011-08-26.01) - NTFSx86 <br />
Internet Explorer: 8.0.7601.17514<br />
Run by Stevo at 11:25:05 on 2012-05-04<br />
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.3070.1547 [GMT -4:00]<br />
.<br />
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}<br />
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}<br />
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\svchost.exe -k RPCSS<br />
C:\Windows\system32\atiesrxx.exe<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\system32\atieclxx.exe<br />
C:\Program Files\AVAST Software\Avast\AvastSvc.exe<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe<br />
C:\Program Files\Hi-Rez Studios\HiPatchService.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Windows\system32\taskhost.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\taskeng.exe<br />
C:\Program Files\Hard Disk Sentinel\HDSentinel.exe<br />
C:\Program Files\AVAST Software\Avast\AvastUI.exe<br />
C:\Games\Steam\Steam.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe<br />
C:\Users\Stevo\AppData\Local\Google\Update\1.3.21.111\GoogleCrashHandler.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation<br />
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Windows\System32\svchost.exe -k LocalServicePeerNet<br />
C:\Program Files\Common Files\Steam\SteamService.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\System32\svchost.exe -k secsvcs<br />
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe<br />
C:\Windows\system32\ctfmon.exe<br />
C:\Windows\system32\taskhost.exe<br />
C:\Program Files\HJT\Trend Micro\HiJackThis\HiJackThis.exe<br />
C:\Users\Stevo\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Stevo\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Stevo\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Stevo\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Stevo\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Stevo\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Stevo\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Windows\system32\rundll32.exe<br />
C:\Users\Stevo\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Stevo\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Windows\system32\SearchProtocolHost.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\system32\conhost.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll<br />
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll<br />
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll<br />
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll<br />
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll<br />
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll<br />
uRun: [Steam] &quot;c:\games\steam\steam.exe&quot; -silent<br />
uRun: [Google Update] &quot;c:\users\stevo\appdata\local\google\update\GoogleUpdate.exe&quot; /c<br />
mRun: [avast] &quot;c:\program files\avast software\avast\avastUI.exe&quot; /nogui<br />
mRun: [StartCCC] &quot;c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe&quot; MSRun<br />
mRun: [AMD AVT] Cmd.exe /c start &quot;AMD Accelerated Video Transcoding device initialization&quot; /min &quot;c:\program files\amd avt\bin\kdbsync.exe&quot; aml<br />
mRun: [amd_dc_opt] c:\program files\amd\dual-core optimizer\amd_dc_opt.exe<br />
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)<br />
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll<br />
Trusted Zone: clonewarsadventures.com<br />
Trusted Zone: freerealms.com<br />
Trusted Zone: soe.com<br />
Trusted Zone: sony.com<br />
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76 192.168.1.1<br />
TCP: Interfaces\{CB2528B0-3F15-4F3A-986C-AFD4F033C093} : DhcpNameServer = 75.75.75.75 75.75.76.76 192.168.1.1<br />
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL<br />
Hosts: 127.0.0.1	<a href="http://www.techsupportforum.com/forums/external-link/?link=http%3A%2F%2Fwww.spywareinfo.com" target="_blank" rel="nofollow">www.spywareinfo.com</a><br />
.<br />
================= FIREFOX ===================<br />
.<br />
FF - ProfilePath - c:\users\stevo\appdata\roaming\mozilla\firefox\profiles\zsmuanu0.default\<br />
FF - prefs.js: browser.startup.homepage - about<b></b>:home<br />
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z192&amp;form=ZGAADF&amp;install_date=20111205&amp;q=<br />
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll<br />
FF - plugin: c:\program files\microsoft silverlight\4.1.10111.0\npctrlui.dll<br />
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll<br />
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll<br />
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll<br />
FF - plugin: c:\users\stevo\appdata\local\google\update\1.3.21.111\npGoogleUpdate3.dll<br />
FF - plugin: c:\users\stevo\appdata\roaming\mozilla\firefox\profiles\zsmuanu0.default\extensions\devicedetection@logitech.com\plugins\npLogitechDeviceDetection.dll<br />
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_2_202_233.dll<br />
.<br />
---- FIREFOX POLICIES ----<br />
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2012-4-8 612184]<br />
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2012-4-8 337880]<br />
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-1-3 63928]<br />
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-4-5 217600]<br />
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2012-4-8 20696]<br />
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-4-8 57688]<br />
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2012-4-8 44768]<br />
R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [2012-4-8 21992]<br />
R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files\hi-rez studios\HiPatchService.exe [2012-1-8 8704]<br />
R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2012-4-6 9334784]<br />
R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2012-4-5 275968]<br />
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2012-2-23 86544]<br />
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2009-7-13 311296]<br />
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]<br />
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot\SDWinSec.exe [2011-7-27 1153368]<br />
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-2-29 158856]<br />
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-8 253088]<br />
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]<br />
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2009-11-23 19720]<br />
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2009-11-23 14856]<br />
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-3-17 129976]<br />
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --&gt; c:\windows\system32\GameMon.des -service [?]<br />
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-7-30 52224]<br />
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-7-29 1343400]<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2012-05-04 14:46:55	388096	----a-r-	c:\users\stevo\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe<br />
2012-05-04 14:46:55	--------	d-----w-	c:\program files\HJT<br />
2012-05-04 03:41:20	--------	d-----w-	c:\program files\FormatFactory<br />
2012-05-04 02:44:37	34304	----a-w-	c:\windows\system32\drivers\AmdLLD.sys<br />
2012-05-04 02:44:35	--------	d-----w-	c:\program files\AMD<br />
2012-05-04 02:44:33	--------	d-----w-	c:\users\stevo\appdata\local\Downloaded Installations<br />
2012-05-04 02:11:50	6734704	----a-w-	c:\programdata\microsoft\windows defender\definition updates\{3c1575b0-449a-4fc0-8232-9e465a2ac91d}\mpengine.dll<br />
2012-05-03 23:10:53	--------	d-----w-	c:\program files\BitPim<br />
2012-04-25 21:19:47	--------	d-----w-	c:\program files\AMD AVT<br />
2012-04-25 21:19:35	--------	d-----w-	c:\program files\AMD APP<br />
2012-04-22 15:19:22	--------	d-----w-	c:\programdata\Battle.net<br />
2012-04-11 21:40:29	--------	d-----w-	c:\users\stevo\appdata\roaming\Hard Disk Sentinel<br />
2012-04-11 21:40:04	--------	d-----w-	c:\program files\Hard Disk Sentinel<br />
2012-04-11 20:32:01	--------	d-----w-	c:\users\stevo\appdata\local\Google<br />
2012-04-11 07:03:49	5120	----a-w-	c:\windows\system32\wmi.dll<br />
2012-04-11 07:03:49	19824	----a-w-	c:\windows\system32\drivers\fs_rec.sys<br />
2012-04-11 07:03:49	172544	----a-w-	c:\windows\system32\wintrust.dll<br />
2012-04-11 07:03:49	159232	----a-w-	c:\windows\system32\imagehlp.dll<br />
2012-04-11 07:02:52	3968368	----a-w-	c:\windows\system32\ntkrnlpa.exe<br />
2012-04-11 07:02:50	3913072	----a-w-	c:\windows\system32\ntoskrnl.exe<br />
2012-04-09 00:57:45	--------	d-----w-	c:\programdata\UAB<br />
2012-04-09 00:57:43	--------	d-----w-	c:\users\stevo\appdata\local\PC_Drivers_Headquarters<br />
2012-04-09 00:57:31	--------	d-----w-	c:\programdata\Driver Tool<br />
2012-04-09 00:56:05	--------	d-----w-	c:\program files\Driver Tool<br />
2012-04-09 00:49:49	21992	----a-w-	c:\windows\system32\drivers\cpuz135_x32.sys<br />
2012-04-09 00:49:49	--------	d-----w-	c:\program files\CPUID<br />
2012-04-08 20:47:13	44376	----a-w-	c:\windows\system32\drivers\aswRdr2.sys<br />
2012-04-08 20:47:07	612184	----a-w-	c:\windows\system32\drivers\aswSnx.sys<br />
2012-04-08 20:46:38	57688	----a-w-	c:\windows\system32\drivers\aswMonFlt.sys<br />
2012-04-08 20:44:56	41184	----a-w-	c:\windows\avastSS.scr<br />
2012-04-08 20:38:27	--------	d-----w-	c:\program files\HD Tune<br />
2012-04-08 20:15:34	--------	d-----w-	c:\programdata\AVAST Software<br />
2012-04-08 20:15:33	--------	d-----w-	c:\program files\AVAST Software<br />
2012-04-08 20:09:50	--------	d-----w-	c:\program files\CCleaner<br />
2012-04-08 20:09:04	--------	d-----w-	c:\program files\DiskCheckup<br />
2012-04-08 18:59:17	418464	----a-w-	c:\windows\system32\FlashPlayerApp.exe<br />
2012-04-06 05:21:10	9334784	----a-w-	c:\windows\system32\drivers\atikmdag.sys<br />
2012-04-06 02:34:22	159232	----a-w-	c:\windows\system32\clinfo.exe<br />
2012-04-06 02:34:04	64512	----a-w-	c:\windows\system32\OpenVideo.dll<br />
2012-04-06 02:33:52	56320	----a-w-	c:\windows\system32\OVDecode.dll<br />
2012-04-06 02:32:56	13007872	----a-w-	c:\windows\system32\amdocl.dll<br />
2012-04-06 02:22:00	159744	----a-w-	c:\windows\system32\atiapfxx.exe<br />
2012-04-06 02:16:52	442368	----a-w-	c:\windows\system32\ATIDEMGX.dll<br />
2012-04-06 02:16:24	451072	----a-w-	c:\windows\system32\atieclxx.exe<br />
2012-04-06 02:15:50	217600	----a-w-	c:\windows\system32\atiesrxx.exe<br />
2012-04-06 02:14:36	159744	----a-w-	c:\windows\system32\atitmmxx.dll<br />
2012-04-06 02:14:28	20992	----a-w-	c:\windows\system32\atimuixx.dll<br />
2012-04-06 02:14:20	43520	----a-w-	c:\windows\system32\ati2edxx.dll<br />
2012-04-06 01:50:56	19753984	----a-w-	c:\windows\system32\atioglxx.dll<br />
2012-04-06 01:34:50	1831424	----a-w-	c:\windows\system32\atiumdmv.dll<br />
2012-04-06 01:30:14	46080	----a-w-	c:\windows\system32\aticalrt.dll<br />
2012-04-06 01:30:06	44032	----a-w-	c:\windows\system32\aticalcl.dll<br />
2012-04-06 01:25:30	13764096	----a-w-	c:\windows\system32\aticaldd.dll<br />
2012-04-06 01:11:18	360448	----a-w-	c:\windows\system32\atiadlxx.dll<br />
2012-04-06 01:11:04	14848	----a-w-	c:\windows\system32\atiglpxx.dll<br />
2012-04-06 01:10:52	33280	----a-w-	c:\windows\system32\atigktxx.dll<br />
2012-04-06 01:10:22	275968	----a-w-	c:\windows\system32\drivers\atikmpag.sys<br />
2012-04-06 01:09:02	53248	----a-w-	c:\windows\system32\drivers\ati2erec.dll<br />
2012-04-06 01:06:04	53760	----a-w-	c:\windows\system32\atimpc32.dll<br />
2012-04-06 01:06:04	53760	----a-w-	c:\windows\system32\amdpcom32.dll<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2012-04-13 22:34:04	70304	----a-w-	c:\windows\system32\FlashPlayerCPLApp.cpl<br />
2012-04-08 16:17:09	16400	----a-w-	c:\windows\system32\drivers\LNonPnP.sys<br />
2012-04-06 02:21:52	909312	----a-w-	c:\windows\system32\aticfx32.dll<br />
2012-04-06 02:13:42	6800896	----a-w-	c:\windows\system32\atidxx32.dll<br />
2012-04-06 02:00:08	52736	----a-w-	c:\windows\system32\coinst.dll<br />
2012-04-06 01:34:04	6203392	----a-w-	c:\windows\system32\atiumdag.dll<br />
2012-04-06 01:22:54	4795904	----a-w-	c:\windows\system32\atiumdva.dll<br />
2012-04-06 01:09:48	41984	----a-w-	c:\windows\system32\atiuxpag.dll<br />
2012-04-06 01:09:34	32256	----a-w-	c:\windows\system32\atiu9pag.dll<br />
2012-03-09 18:06:14	24576	----a-w-	c:\windows\system32\kdbsdk32.dll<br />
2012-02-28 05:38:52	981504	----a-w-	c:\windows\system32\wininet.dll<br />
2012-02-28 03:52:27	1638912	----a-w-	c:\windows\system32\mshtml.tlb<br />
2012-02-23 14:18:36	237072	------w-	c:\windows\system32\MpSigStub.exe<br />
2012-02-23 12:31:58	86544	----a-w-	c:\windows\system32\drivers\AtihdW73.sys<br />
2012-02-17 05:34:22	826880	----a-w-	c:\windows\system32\rdpcore.dll<br />
2012-02-17 04:14:08	183808	----a-w-	c:\windows\system32\drivers\rdpwd.sys<br />
2012-02-17 04:13:22	24576	----a-w-	c:\windows\system32\drivers\tdtcp.sys<br />
2012-02-15 03:03:38	48128	----a-w-	c:\windows\system32\OpenCL.dll<br />
2012-02-10 05:38:43	1077248	----a-w-	c:\windows\system32\DWrite.dll<br />
.<br />
============= FINISH: 11:26:37.89 ===============<br />
<br />
Also I do have access to my Windows 7 disc.</div>


	<br />
	<div style="padding:8px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://cdn.techsupportforum.com/forums/images/sk/attach/zip.gif" alt="File Type: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techsupportforum.com/forums/attachment.php?attachmentid=109015&amp;d=1336160505">Attach.zip</a> (3.0 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techsupportforum.com/forums/f284/">Inactive Malware Help Topics</category>
			<dc:creator>hobbes322</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/forums/f284/hdd-errors-643853.html</guid>
		</item>
		<item>
			<title>I-play Search engine REMOVAL</title>
			<link>http://www.techsupportforum.com/forums/f284/i-play-search-engine-removal-643590.html</link>
			<pubDate>Thu, 03 May 2012 05:05:20 GMT</pubDate>
			<description><![CDATA[I honestly don't even know how this I-play game thing got on my hp lap-top. I believe i'm running windows. Please help rid of this I-Play]]></description>
			<content:encoded><![CDATA[<div><font face="Comic Sans MS">I honestly don't even know how this I-play game thing got on my hp lap-top. I believe i'm running windows. Please help rid of this I-Play</font></div>

]]></content:encoded>
			<category domain="http://www.techsupportforum.com/forums/f284/">Inactive Malware Help Topics</category>
			<dc:creator>belleluvluv</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/forums/f284/i-play-search-engine-removal-643590.html</guid>
		</item>
		<item>
			<title>Anyone have a clue what these are?</title>
			<link>http://www.techsupportforum.com/forums/f284/anyone-have-a-clue-what-these-are-643526.html</link>
			<pubDate>Wed, 02 May 2012 20:29:53 GMT</pubDate>
			<description>I found these doing a search on processes which start up at boot. 
Many of them are in Kanji... 
Image: http://i47.photobucket.com/albums/f164/grumpops/Whatsthis.jpg</description>
			<content:encoded><![CDATA[<div>I found these doing a search on processes which start up at boot.<br />
Many of them are in Kanji...<br />
<img src="http://i47.photobucket.com/albums/f164/grumpops/Whatsthis.jpg" border="0" alt="" onload="NcodeImageResizer.createOn(this);" /></div>

]]></content:encoded>
			<category domain="http://www.techsupportforum.com/forums/f284/">Inactive Malware Help Topics</category>
			<dc:creator>grumpops</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/forums/f284/anyone-have-a-clue-what-these-are-643526.html</guid>
		</item>
		<item>
			<title>win32/small.ca virus</title>
			<link>http://www.techsupportforum.com/forums/f284/win32-small-ca-virus-643511.html</link>
			<pubDate>Wed, 02 May 2012 18:06:31 GMT</pubDate>
			<description>This morning when I logged onto my computer, i got a message from windows defender saying that my computer was infected with a virus called win32/small.ca.  I am also unable to open many of the programs i have on my computer.  i click on the desktop icon and am sent to  Adobe Lightroom.  I have...</description>
			<content:encoded><![CDATA[<div>This morning when I logged onto my computer, i got a message from windows defender saying that my computer was infected with a virus called win32/small.ca.  I am also unable to open many of the programs i have on my computer.  i click on the desktop icon and am sent to  Adobe Lightroom.  I have tried accessing the programs from program folders but it still get sent to Lightroom.<br />
<br />
Here's the DDS.txt:<br />
<br />
.<br />
DDS (Ver_2011-08-26.01) - NTFSx86 <br />
Internet Explorer: 9.0.8112.16421  BrowserJavaVersion: 1.6.0_31<br />
Run by Ornmadee at 11:18:19 on 2012-05-02<br />
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.2940.1936 [GMT -6:00]<br />
.<br />
AV: Norton 360 *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}<br />
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}<br />
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}<br />
FW: Norton 360 *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\svchost.exe -k RPCSS<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe<br />
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe<br />
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Norton 360\Norton 360\Engine\5.2.1.3\ccSvcHst.exe<br />
C:\Program Files\CyberLink\Shared files\RichVideo.exe<br />
C:\Windows\system32\svchost.exe -k imgsvc<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe<br />
C:\Windows\system32\taskhost.exe<br />
C:\Program Files\Norton 360\Norton 360\Engine\5.2.1.3\ccSvcHst.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\spool\DRIVERS\W32X86\3\HP1006MC.EXE<br />
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Windows\system32\SearchProtocolHost.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Windows\system32\svchost.exe -k SDRSVC<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Windows\system32\WUDFHost.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\system32\conhost.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uSearch Page = hxxp://www.google.com<br />
uStart Page = hxxp://start.funmoods.com/?f=1&amp;a=nv1<br />
uSearch Bar = hxxp://www.google.com/ie<br />
uDefault_Search_URL = hxxp://www.google.com/ie<br />
uInternet Settings,ProxyOverride = *.local<br />
uSearchAssistant = hxxp://www.google.com/ie<br />
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll<br />
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll<br />
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\norton 360\engine\5.2.1.3\coIEPlg.dll<br />
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\norton 360\engine\5.2.1.3\ips\IPSBHO.DLL<br />
BHO: Incredibar.com Helper Object: {6e13dde1-2b6e-46ce-8b66-dc8bf36f6b99} - c:\program files\incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll<br />
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll<br />
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll<br />
BHO: Codecv Class: {81c43c4f-6052-4731-9cbd-06e2de6767b7} - c:\programdata\codecv\bhoclass.dll<br />
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll<br />
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll<br />
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll<br />
BHO: {e78a5c92-6a2b-4369-ab14-0ed3b2b18584} - No File<br />
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\norton 360\engine\5.2.1.3\coIEPlg.dll<br />
TB: Incredibar Toolbar: {f9639e4a-801b-4843-aee3-03d9da199e77} - c:\program files\incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll<br />
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun<br />
uRun: [AdobeBridge] <br />
uRun: [Skype] &quot;c:\program files\skype\phone\Skype.exe&quot; /minimized /regrun<br />
uRun: [ISUSPM] &quot;c:\program files\common files\installshield\updateservice\ISUSPM.exe&quot; -scheduler<br />
uRun: [RESTART_STICKY_NOTES] c:\windows\system32\StikyNot.exe<br />
uRun: [uTorrent] &quot;c:\program files\utorrent\uTorrent.exe&quot;  /MINIMIZED<br />
mRun: [APSDaemon] &quot;c:\program files\common files\apple\apple application support\APSDaemon.exe&quot;<br />
mRun: [TkBellExe] &quot;c:\program files\real\realplayer\update\realsched.exe&quot; -osboot<br />
mRun: [iTunesHelper] &quot;c:\program files\itunes\iTunesHelper.exe&quot;<br />
mRun: [Adobe ARM] &quot;c:\program files\common files\adobe\arm\1.0\AdobeARM.exe&quot;<br />
mRun: [Persistence] c:\windows\system32\igfxpers.exe<br />
mRun: [IntelliPoint] &quot;c:\program files\microsoft intellipoint\ipoint.exe&quot;<br />
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe<br />
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe<br />
mRun: [BlackBerryAutoUpdate] c:\program files\common files\research in motion\auto update\RIMAutoUpdate.exe /background<br />
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\skype.lnk - c:\windows\installer\{9c538746-c2dc-40fc-b1fb-d4ea7966abeb}\SkypeIcon.exe<br />
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)<br />
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
IE: Add to Google Photos Screensa&amp;ver - c:\windows\system32\GPhotos.scr/200<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000<br />
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll<br />
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll<br />
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll<br />
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab<br />
TCP: Interfaces\{9A41B2DC-90C9-4085-85F0-42539711E946} : DhcpNameServer = 10.8.8.238 10.8.8.237<br />
TCP: Interfaces\{9A41B2DC-90C9-4085-85F0-42539711E946}\2656C6B696E6534376 : DhcpNameServer = 69.57.56.2 69.57.57.2<br />
TCP: Interfaces\{9A41B2DC-90C9-4085-85F0-42539711E946}\741697027556E646121212 : DhcpNameServer = 192.168.2.1<br />
TCP: Interfaces\{9A41B2DC-90C9-4085-85F0-42539711E946}\741697027556E64612121212 : DhcpNameServer = 192.168.2.1<br />
TCP: Interfaces\{9A41B2DC-90C9-4085-85F0-42539711E946}\C696E6B6379737 : DhcpNameServer = 75.153.176.1 75.153.176.9<br />
TCP: Interfaces\{A0018A01-D9C9-4549-A949-8DE749E77E44} : DhcpNameServer = 192.168.2.1 192.168.2.1<br />
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll<br />
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL<br />
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll<br />
Notify: igfxcui - igfxdev.dll<br />
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll<br />
.<br />
================= FIREFOX ===================<br />
.<br />
FF - ProfilePath - c:\users\ornmadee\appdata\roaming\mozilla\firefox\profiles\ktp4b492.default\<br />
FF - prefs.js: browser.search.selectedEngine - Search<br />
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/<br />
FF - prefs.js: keyword.URL - hxxp://mystart.incredibar.com/mb139/?loc=IB_DS&amp;a=6OyyoiIoen&amp;&amp;i=26&amp;search=<br />
FF - prefs.js: network.proxy.type - 4<br />
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll<br />
FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll<br />
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll<br />
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll<br />
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll<br />
FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll<br />
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll<br />
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll<br />
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll<br />
FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll<br />
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll<br />
FF - plugin: c:\program files\google\update\1.3.21.99\npGoogleUpdate3.dll<br />
FF - plugin: c:\program files\java\jre6\bin\plugin2\npdeployJava1.dll<br />
FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll<br />
FF - plugin: c:\program files\microsoft silverlight\4.1.10111.0\npctrlui.dll<br />
FF - plugin: c:\program files\research in motion limited\blackberry app world browser plugin\npappworld.dll<br />
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll<br />
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll<br />
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll<br />
FF - plugin: c:\users\ornmadee\appdata\local\facebook\messenger\2.0.4478.0\npFbDesktopPlugin.dll<br />
FF - plugin: c:\users\ornmadee\appdata\local\google\update\1.3.21.111\npGoogleUpdate3.dll<br />
FF - plugin: c:\windows\system32\wat\npWatWeb.dll<br />
.<br />
---- FIREFOX POLICIES ----<br />
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=100888<br />
FF - user.js: extensions.BabylonToolbar_i.babExt - <br />
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss<br />
FF - user.js: extensions.BabylonToolbar_i.id - 8297027a000000000000701a0471f69b<br />
FF - user.js: extensions.BabylonToolbar_i.hardId - 8297027a000000000000701a0471f69b<br />
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15354<br />
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17<br />
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17<br />
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1721:21:27<br />
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon<br />
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar<br />
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst<br />
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none<br />
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base<br />
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst<br />
FF - user.js: extensions.incredibar_i.newTab - false<br />
FF - user.js: extensions.incredibar_i.tlbrSrchUrl - hxxp://mystart.Incredibar.com/?a=6OyyoiIoen&amp;loc=IB_TB&amp;i=26&amp;search=<br />
FF - user.js: extensions.incredibar_i.id - 8297027a000000000000701a0471f69b<br />
FF - user.js: extensions.incredibar_i.instlDay - 15439<br />
FF - user.js: extensions.incredibar_i.vrsn - 1.5.11.14<br />
FF - user.js: extensions.incredibar_i.vrsni - 1.5.11.14<br />
FF - user.js: extensions.incredibar_i.vrsnTs - 1.5.11.1417:51:02<br />
FF - user.js: extensions.incredibar_i.prtnrId - Incredibar<br />
FF - user.js: extensions.incredibar_i.prdct - incredibar<br />
FF - user.js: extensions.incredibar_i.aflt - orgnl<br />
FF - user.js: extensions.incredibar_i.smplGrp - none<br />
FF - user.js: extensions.incredibar_i.tlbrId - base<br />
FF - user.js: extensions.incredibar_i.instlRef - <br />
FF - user.js: extensions.incredibar_i.dfltLng - <br />
FF - user.js: extensions.incredibar_i.excTlbr - false<br />
FF - user.js: extensions.incredibar_i.ms_url_id - <br />
FF - user.js: extensions.incredibar_i.upn2 - 6OyyoiIoen<br />
FF - user.js: extensions.incredibar_i.upn2n - 92261212925188635<br />
FF - user.js: extensions.incredibar_i.productid - 26<br />
FF - user.js: extensions.incredibar_i.installerproductid - 26<br />
FF - user.js: extensions.incredibar_i.did - 10650<br />
FF - user.js: extensions.incredibar_i.ppd - 15%5F2<br />
FF - user.js: extensions.funmoods_i.hmpg - true<br />
FF - user.js: extensions.funmoods_i.hmpgUrl - hxxp://start.funmoods.com/?f=1&amp;a=nv1<br />
FF - user.js: extensions.funmoods_i.dfltSrch - true<br />
FF - user.js: extensions.funmoods_i.srchPrvdr - Search<br />
FF - user.js: extensions.funmoods_i.dnsErr - true<br />
FF - user.js: extensions.funmoods_i.newTab - true<br />
FF - user.js: extensions.funmoods_i.newTabUrl - hxxp://start.funmoods.com/?f=2&amp;a=nv1<br />
FF - user.js: extensions.funmoods_i.tlbrSrchUrl - hxxp://start.funmoods.com/results.php?f=3&amp;a=nv1&amp;q=<br />
FF - user.js: extensions.funmoods_i.id - 8297027a000000000000701a0471f69b<br />
FF - user.js: extensions.funmoods_i.instlDay - 15460<br />
FF - user.js: extensions.funmoods_i.vrsn - 1.5.11.16<br />
FF - user.js: extensions.funmoods_i.vrsni - 1.5.11.16<br />
FF - user.js: extensions.funmoods_i.vrsnTs - 1.5.11.1618:41:06<br />
FF - user.js: extensions.funmoods_i.prtnrId - funmoods<br />
FF - user.js: extensions.funmoods_i.prdct - funmoods<br />
FF - user.js: extensions.funmoods_i.aflt - nv1<br />
FF - user.js: extensions.funmoods_i.smplGrp - none<br />
FF - user.js: extensions.funmoods_i.tlbrId - base<br />
FF - user.js: extensions.funmoods_i.instlRef - <br />
FF - user.js: extensions.funmoods_i.dfltLng - <br />
FF - user.js: extensions.funmoods_i.excTlbr - false<br />
.<br />
FF - user.js: extensions.autoDisableScopes - 14<br />
user_pref('extensions.autoDisableScopes', 0);user_pref('security.csp.enable', false);user_pref('security.OCSP.enabled', 0);<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0502010.003\symds.sys [2012-4-4 340088]<br />
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0502010.003\symefa.sys [2012-4-4 744568]<br />
R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\bashdefs\20120413.001\BHDrvx86.sys [2012-4-19 821880]<br />
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\ipsdefs\20120501.001\IDSvix86.sys [2012-5-1 368248]<br />
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0502010.003\ironx86.sys [2012-4-4 136312]<br />
R1 SymNetS;Symantec Network Security WFP Driver;c:\windows\system32\drivers\n360\0502010.003\symnets.sys [2012-4-4 299640]<br />
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]<br />
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-1-3 63928]<br />
R2 N360;Norton 360;c:\program files\norton 360\norton 360\engine\5.2.1.3\ccsvchst.exe [2012-4-4 130008]<br />
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2012-2-5 106104]<br />
R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2011-2-2 7168]<br />
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [2008-1-14 21632]<br />
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-6-10 139776]<br />
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\drivers\rtl8192se.sys [2010-4-26 1011232]<br />
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-13 14336]<br />
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]<br />
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-1-30 136176]<br />
S2 ScanQuery Service;ScanQuery Service;&quot;c:\programdata\scanquery\scanquery123.exe&quot; &quot;c:\program files\scanquery\scanquery.dll&quot; bawacecob ayanonowon --&gt; c:\programdata\scanquery\scanquery123.exe [?]<br />
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-2-29 158856]<br />
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]<br />
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-1-30 136176]<br />
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-3-11 52224]<br />
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-1-31 1343400]<br />
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2012-05-01 23:48:29	--------	d-----w-	c:\users\ornmadee\appdata\local\{65D398AA-EA51-45A5-A19C-79F589679AF9}<br />
2012-05-01 23:48:18	--------	d-----w-	c:\users\ornmadee\appdata\local\{124123C6-1FBF-4539-8703-B33925EA28FC}<br />
2012-05-01 23:31:21	--------	dc----w-	c:\program files\uTorrent<br />
2012-05-01 23:31:07	--------	d-----w-	c:\users\ornmadee\appdata\roaming\uTorrent<br />
2012-05-01 22:49:43	--------	d-----w-	c:\users\ornmadee\appdata\local\{DAF3A075-BF7C-4729-A554-1FE872ABEEBD}<br />
2012-05-01 22:49:31	--------	d-----w-	c:\users\ornmadee\appdata\local\{D96E2CAD-6085-4796-8BC0-38C1627DC026}<br />
2012-05-01 19:47:03	--------	d-----w-	c:\users\ornmadee\appdata\local\{7900340A-43EB-4FC5-A16A-64F710F4D4FC}<br />
2012-05-01 19:46:43	--------	d-----w-	c:\users\ornmadee\appdata\local\{AA383651-65D0-45AA-AFDE-107244EE992E}<br />
2012-05-01 18:07:12	--------	d-----w-	c:\users\ornmadee\appdata\local\{F7F75538-CD9B-4022-9F97-2C9F21796BF4}<br />
2012-05-01 18:06:52	--------	d-----w-	c:\users\ornmadee\appdata\local\{6BF59304-229D-470A-86B8-FCF857F51F71}<br />
2012-05-01 02:46:53	--------	d-----w-	c:\users\ornmadee\appdata\local\{862698CE-9A6C-4764-8A1C-E029AA940FB4}<br />
2012-05-01 02:46:39	--------	d-----w-	c:\users\ornmadee\appdata\local\{CBA06D55-E634-4E7E-AB7B-ECDCE39589E6}<br />
2012-04-30 22:51:40	--------	d-----w-	c:\users\ornmadee\appdata\local\{DAB6795C-7AC2-43AB-958B-2CDADD3FCEEC}<br />
2012-04-30 22:51:27	--------	d-----w-	c:\users\ornmadee\appdata\local\{AF59BA1D-8C99-4B3C-BE3A-57E2F11ED15F}<br />
2012-04-30 20:56:02	--------	d-----w-	c:\users\ornmadee\appdata\local\{2EDB9019-3ABB-4134-B621-178294DD185F}<br />
2012-04-30 20:55:42	--------	d-----w-	c:\users\ornmadee\appdata\local\{2F8C0548-F58E-4BC7-B676-CD907889CC6E}<br />
2012-04-30 19:58:43	--------	d-----w-	c:\users\ornmadee\appdata\local\{0775D4F5-3F9C-4489-9E2F-F778570AD202}<br />
2012-04-30 19:58:33	--------	d-----w-	c:\users\ornmadee\appdata\local\{D6AADFD1-0FD8-425E-904A-6DDBA2DAE86C}<br />
2012-04-30 17:45:30	--------	d-----w-	c:\users\ornmadee\appdata\local\{91ACCFE7-9D31-470B-AF1D-C1EEE3C95705}<br />
2012-04-30 17:45:08	--------	d-----w-	c:\users\ornmadee\appdata\local\{799EA360-11AB-4E7A-8FBE-3DA308A1A673}<br />
2012-04-30 17:10:15	--------	d-----w-	c:\users\ornmadee\appdata\local\{C4AF8748-3703-4EBE-A2F3-64F827435B08}<br />
2012-04-30 02:13:36	--------	d-----w-	c:\users\ornmadee\appdata\local\{31AE90E0-8111-45C4-9D90-17871CCFBDBA}<br />
2012-04-30 02:13:23	--------	d-----w-	c:\users\ornmadee\appdata\local\{2B9C6A44-8661-4906-A044-054E16CB1EDF}<br />
2012-04-30 00:54:36	--------	d-----w-	c:\users\ornmadee\appdata\roaming\SystemUpdaterApp<br />
2012-04-30 00:48:35	--------	d-----w-	c:\users\ornmadee\appdata\local\qBittorrent<br />
2012-04-30 00:48:34	--------	d-----w-	c:\users\ornmadee\appdata\roaming\qBittorrent<br />
2012-04-30 00:46:25	--------	dc----w-	c:\program files\OApps<br />
2012-04-30 00:45:58	--------	dc----w-	c:\program files\intellidownload<br />
2012-04-30 00:41:40	--------	d-----w-	c:\programdata\Tarma Installer<br />
2012-04-29 21:40:34	--------	d-----w-	c:\users\ornmadee\appdata\local\{41F390A1-4262-42AC-887F-8D31CC98C168}<br />
2012-04-29 21:40:20	--------	d-----w-	c:\users\ornmadee\appdata\local\{8AFCA3D1-F99E-4C76-9FC1-822B5778B42F}<br />
2012-04-29 16:55:26	--------	d-----w-	c:\users\ornmadee\appdata\local\{CAAC1043-3B80-47A7-B076-C843CD33DE98}<br />
2012-04-29 16:55:14	--------	d-----w-	c:\users\ornmadee\appdata\local\{3D2436DB-3F3F-4B7B-9457-C4065B2F1236}<br />
2012-04-29 16:43:11	--------	d-----w-	c:\users\ornmadee\appdata\local\{8CF2CC25-E0D3-469C-ABB0-D1F981B5FB6F}<br />
2012-04-29 16:42:59	--------	d-----w-	c:\users\ornmadee\appdata\local\{60D0EEE5-6A7E-4E53-9938-7A587E9AC1BB}<br />
2012-04-29 16:14:22	--------	d-----w-	c:\users\ornmadee\appdata\local\{1AF9A681-6691-41D3-9EE0-D041A5DCC16F}<br />
2012-04-29 16:14:10	--------	d-----w-	c:\users\ornmadee\appdata\local\{AE9A6722-1E55-4E03-BA8E-8362F353CB05}<br />
2012-04-29 05:19:23	--------	d-----w-	c:\users\ornmadee\appdata\local\{3457EDF7-6B0A-4936-922C-4DA14695116D}<br />
2012-04-29 05:19:08	--------	d-----w-	c:\users\ornmadee\appdata\local\{EBC2DEE6-9902-4380-AF74-43F6CF6F17AA}<br />
2012-04-28 15:37:49	--------	d-----w-	c:\users\ornmadee\appdata\local\{6D3E2AB7-1B16-4EC3-BEF8-9E1E7375BD03}<br />
2012-04-28 15:37:36	--------	d-----w-	c:\users\ornmadee\appdata\local\{B5C7F973-8C17-4FD7-8B47-80613C23BAD3}<br />
2012-04-28 00:39:44	--------	d-----w-	c:\users\ornmadee\appdata\local\{48793938-DBB5-4D9C-8D62-961631341922}<br />
2012-04-28 00:39:31	--------	d-----w-	c:\users\ornmadee\appdata\local\{5C77043E-06A2-4D69-B3DD-AF0B5973BD42}<br />
2012-04-27 19:59:51	--------	d-----w-	c:\users\ornmadee\appdata\local\{A13CB559-CCE6-4B68-8E7B-E72CBE1E82A7}<br />
2012-04-27 19:59:31	--------	d-----w-	c:\users\ornmadee\appdata\local\{EC84E17F-8348-4B07-8671-314DB423B128}<br />
2012-04-27 16:40:58	--------	d-----w-	c:\users\ornmadee\appdata\local\{8FCEAB29-5C41-4AD0-B003-EC8BBCBC2802}<br />
2012-04-27 16:40:37	--------	d-----w-	c:\users\ornmadee\appdata\local\{62C1D96E-268E-4BFF-8538-50C44BB0EB24}<br />
2012-04-27 13:58:56	--------	d-----w-	c:\users\ornmadee\appdata\local\{9E205D2B-385D-44F2-9802-3225892C9E93}<br />
2012-04-27 13:58:44	--------	d-----w-	c:\users\ornmadee\appdata\local\{1C5019F4-44E0-42D3-962D-E49446A6E2A1}<br />
2012-04-26 16:05:42	--------	d-----w-	c:\users\ornmadee\appdata\local\{7EFCECBC-9F92-4AD1-89FD-541E704A1F74}<br />
2012-04-26 16:05:21	--------	d-----w-	c:\users\ornmadee\appdata\local\{1079EF49-2E61-48A1-93BF-9B5D546FE27B}<br />
2012-04-26 15:25:18	--------	d-----w-	c:\users\ornmadee\appdata\local\{1C3AE374-AAFA-476A-8546-D476FD5C6E46}<br />
2012-04-26 15:24:58	--------	d-----w-	c:\users\ornmadee\appdata\local\{A6299306-1DC4-4EEA-AA23-41227D5ECFD9}<br />
2012-04-26 14:04:06	--------	d-----w-	c:\users\ornmadee\appdata\local\{74A793C0-F605-4DD5-8E5D-FA87C7F875B0}<br />
2012-04-26 14:03:51	--------	d-----w-	c:\users\ornmadee\appdata\local\{461679C0-A4AA-427F-877B-7F90A90F06B3}<br />
2012-04-25 21:00:25	--------	d-----w-	c:\users\ornmadee\appdata\local\{59209FDA-1586-41B8-95E1-52A983E9D068}<br />
2012-04-25 21:00:05	--------	d-----w-	c:\users\ornmadee\appdata\local\{1832305E-2F85-4640-B238-6A6A18DCFE55}<br />
2012-04-25 16:40:27	--------	d-----w-	c:\users\ornmadee\appdata\local\{340B5F29-ABF4-4214-A975-171A55D920D2}<br />
2012-04-25 16:40:07	--------	d-----w-	c:\users\ornmadee\appdata\local\{5D6D8620-93B0-41BE-BC7D-CF9140ECD1DE}<br />
2012-04-25 14:22:10	--------	d-----w-	c:\users\ornmadee\appdata\local\{8DEF1737-9BDD-4F9A-8752-C41362E8976E}<br />
2012-04-25 14:22:07	--------	d-----w-	c:\users\ornmadee\appdata\local\{69D3C682-DDD9-4820-B8FB-B7CC15D9AE38}<br />
2012-04-25 02:18:30	--------	d-----w-	c:\users\ornmadee\appdata\local\{D291BAE0-77F6-4A9C-82A0-FA27BC9A0D02}<br />
2012-04-25 02:18:27	--------	d-----w-	c:\users\ornmadee\appdata\local\{A50CA0EC-D8CA-463F-A7D7-F6C8CFD0F6CC}<br />
2012-04-24 22:45:12	--------	d-----w-	c:\users\ornmadee\appdata\local\{9566A63C-2009-45CD-ADED-82A2E45FD3BD}<br />
2012-04-24 22:45:09	--------	d-----w-	c:\users\ornmadee\appdata\local\{8ECA7C9D-7A45-4BC7-8C47-A6BC7609D9F0}<br />
2012-04-24 18:11:52	--------	d-----w-	c:\users\ornmadee\appdata\local\{8B817CBE-B697-472D-A168-5BFC657E9975}<br />
2012-04-24 18:11:48	--------	d-----w-	c:\users\ornmadee\appdata\local\{45812650-6A8C-4DE6-AC7A-C02AC016CF52}<br />
2012-04-24 18:10:11	--------	d-----w-	c:\users\ornmadee\appdata\local\{F8D4E185-B244-450F-A857-6CAF3610A8EF}<br />
2012-04-24 18:10:07	--------	d-----w-	c:\users\ornmadee\appdata\local\{50900FEF-3574-44C1-AC85-603C07E2676A}<br />
2012-04-23 02:28:19	--------	d-----w-	c:\users\ornmadee\appdata\local\{02A7548E-F19D-48B9-AB50-E9A7C4BFA30A}<br />
2012-04-23 02:28:15	--------	d-----w-	c:\users\ornmadee\appdata\local\{5380766E-C888-4D16-B5BF-ED6479277C70}<br />
2012-04-22 15:24:03	--------	d-----w-	c:\users\ornmadee\appdata\local\{24B88CE5-4CC3-4D35-9B69-DA8EC56E402E}<br />
2012-04-22 15:23:58	--------	d-----w-	c:\users\ornmadee\appdata\local\{5CD83617-DCB1-4608-9DF8-3210EE2C5E3C}<br />
2012-04-22 00:46:11	--------	d-----w-	c:\windows\system32\%LOCALAPPDATA%<br />
2012-04-21 21:49:06	--------	d-----w-	c:\users\ornmadee\appdata\local\{78887A4E-13CB-4FDB-AA5A-512C9E8102BF}<br />
2012-04-21 21:48:58	--------	d-----w-	c:\users\ornmadee\appdata\local\{A9540FF5-EDC4-422E-9B77-6866ED6943F8}<br />
2012-04-21 16:59:38	--------	d-----w-	c:\users\ornmadee\appdata\local\{592BE848-C1E8-4959-8D51-A5334F94CCFE}<br />
2012-04-21 16:59:33	--------	d-----w-	c:\users\ornmadee\appdata\local\{39857602-89FF-4295-80CB-7484C6345DC3}<br />
2012-04-20 21:48:40	--------	d-----w-	c:\users\ornmadee\appdata\local\{00713082-B010-42D6-A3A8-C1184F3FE7F0}<br />
2012-04-20 21:48:35	--------	d-----w-	c:\users\ornmadee\appdata\local\{DB4E0EA1-89FB-4C49-9B2E-773BB6378956}<br />
2012-04-20 00:46:20	--------	d-----w-	c:\users\ornmadee\appdata\local\{70C57038-66F5-41B2-81EA-4377E70DD5F8}<br />
2012-04-20 00:46:17	--------	d-----w-	c:\users\ornmadee\appdata\local\{C8B3388E-06BF-40BF-B1FE-EFD52D977B23}<br />
2012-04-19 18:16:47	--------	d-----w-	c:\users\ornmadee\appdata\local\{B4435AE3-F579-4BA9-8507-7558EA6BF201}<br />
2012-04-19 15:34:05	--------	d-----w-	c:\users\ornmadee\appdata\local\{FA4BAC55-2F36-4C22-8BC6-ECE44CF8879A}<br />
2012-04-19 15:33:45	--------	d-----w-	c:\users\ornmadee\appdata\local\{DA5725D9-996C-4248-BB20-D2E7961F8488}<br />
2012-04-19 01:55:49	--------	d-----w-	c:\users\ornmadee\appdata\local\{9BE845C5-251C-44F7-B33E-98AA4AECCA5F}<br />
2012-04-19 01:55:34	--------	d-----w-	c:\users\ornmadee\appdata\local\{B37C8F20-1891-4A4D-8E4F-41895936A15D}<br />
2012-04-19 01:26:49	--------	d-----w-	c:\users\ornmadee\appdata\local\{592E6487-5394-4CFB-BF9D-C2BCFC0770D8}<br />
2012-04-19 01:26:35	--------	d-----w-	c:\users\ornmadee\appdata\local\{8A9DA7D5-1788-4343-BD97-3D34EE9F143B}<br />
2012-04-18 20:41:32	--------	d-----w-	c:\users\ornmadee\appdata\local\{0203D290-37CB-4BDB-BC26-07B66948B218}<br />
2012-04-18 20:41:12	--------	d-----w-	c:\users\ornmadee\appdata\local\{16D20863-1BBC-4EE8-B244-F49F67C7F4FC}<br />
2012-04-18 20:17:15	--------	d-----w-	c:\users\ornmadee\appdata\local\{9571B30E-54D9-4DBC-A251-34112B93361E}<br />
2012-04-18 20:16:55	--------	d-----w-	c:\users\ornmadee\appdata\local\{4AE42883-05A6-40F4-A8DE-E02B27A58CFA}<br />
2012-04-18 18:03:22	--------	d-----w-	c:\users\ornmadee\appdata\local\{2647329C-2CFD-4892-8945-5C46E2EA59DD}<br />
2012-04-18 18:03:01	--------	d-----w-	c:\users\ornmadee\appdata\local\{F1E95033-8F55-4898-9A89-9177DDF6E0BD}<br />
2012-04-18 15:20:23	--------	d-----w-	c:\users\ornmadee\appdata\local\{EC25DD43-5430-4961-A765-293314D77435}<br />
2012-04-18 15:20:04	--------	d-----w-	c:\users\ornmadee\appdata\local\{35FD995A-F5A8-4683-8679-0B3C852C995A}<br />
2012-04-18 13:57:03	--------	d-----w-	c:\users\ornmadee\appdata\local\{166DDDD4-C69B-45F1-8F4F-1716DE6AF0A1}<br />
2012-04-18 13:56:50	--------	d-----w-	c:\users\ornmadee\appdata\local\{DB0D3982-94F0-4092-B72C-2210B1A04677}<br />
2012-04-18 02:42:30	--------	d-----w-	c:\users\ornmadee\appdata\local\{18372F03-BEF5-4038-AAE1-2A100E8E98B7}<br />
2012-04-18 02:42:16	--------	d-----w-	c:\users\ornmadee\appdata\local\{20DCFCAF-CA25-46A6-90E1-76AA3080D25C}<br />
2012-04-18 01:28:13	--------	d-----w-	c:\users\ornmadee\appdata\local\{49C1EE70-C1CC-44DA-A7B3-7A57564F11C5}<br />
2012-04-18 01:28:00	--------	d-----w-	c:\users\ornmadee\appdata\local\{A6FADA53-98B9-4A44-964E-26023E1147EE}<br />
2012-04-17 20:45:30	--------	d-----w-	c:\users\ornmadee\appdata\local\{567D2A6C-4764-4948-B561-37FE5CF9EFE5}<br />
2012-04-17 20:45:18	--------	d-----w-	c:\users\ornmadee\appdata\local\{ED2FC3CE-3E3E-4DF1-8070-E82C81DB4823}<br />
2012-04-17 20:34:12	--------	d-----w-	c:\users\ornmadee\appdata\local\{6BAD204F-1EFF-4BEB-9F81-BCFD66769228}<br />
2012-04-17 20:33:49	--------	d-----w-	c:\users\ornmadee\appdata\local\{D358C2DE-E0FC-4EC1-A7EB-4B50D04C44E1}<br />
2012-04-17 19:11:38	--------	d-----w-	c:\users\ornmadee\appdata\local\{34BEDB59-0173-494D-BEBB-D66821759B78}<br />
2012-04-17 19:11:27	--------	d-----w-	c:\users\ornmadee\appdata\local\{F2446956-E016-4594-86A6-34EE16E89BE4}<br />
2012-04-17 17:04:59	--------	d-----w-	c:\users\ornmadee\appdata\local\{E9D54B88-F5E8-42AE-BC38-2816A7728DDB}<br />
2012-04-17 17:04:39	--------	d-----w-	c:\users\ornmadee\appdata\local\{3D802334-6864-47CE-8EA4-091AA2B6ECF6}<br />
2012-04-17 15:39:13	--------	d-----w-	c:\users\ornmadee\appdata\local\{265F4307-9A76-4A43-A52C-3055F81EFB35}<br />
2012-04-17 15:38:53	--------	d-----w-	c:\users\ornmadee\appdata\local\{2F6D3B68-EF93-4131-AC3C-2766E31FA28F}<br />
2012-04-17 14:01:32	--------	d-----w-	c:\users\ornmadee\appdata\local\{7437E437-3E6C-44D7-9828-4CA74D0B0F52}<br />
2012-04-17 14:01:17	--------	d-----w-	c:\users\ornmadee\appdata\local\{B8D9AC1D-36CC-45E5-9C12-F4A0DB6F0098}<br />
2012-04-16 23:24:06	--------	d-----w-	c:\users\ornmadee\appdata\local\{51924071-BB53-4A5B-BF13-8CBE388C29EA}<br />
2012-04-16 23:23:52	--------	d-----w-	c:\users\ornmadee\appdata\local\{1EC12E65-FF9C-44CC-9B4B-9D052CE5BE6C}<br />
2012-04-16 16:56:24	--------	d-----w-	c:\users\ornmadee\appdata\local\{1A9776BB-8071-40DA-9CE4-34F8566A3187}<br />
2012-04-16 16:56:01	--------	d-----w-	c:\users\ornmadee\appdata\local\{0366C164-A574-4053-9957-D04276818337}<br />
2012-04-15 23:55:47	--------	d-----w-	c:\users\ornmadee\appdata\local\{6108B5FF-BCEC-48B0-82BE-663B017AFE71}<br />
2012-04-15 23:55:35	--------	d-----w-	c:\users\ornmadee\appdata\local\{68E84152-D178-4987-A89A-79D9385DCADC}<br />
2012-04-15 16:26:56	--------	d-----w-	c:\users\ornmadee\appdata\local\{CEBCD626-91CB-4675-9EE9-1FC32DD50EB3}<br />
2012-04-15 16:26:43	--------	d-----w-	c:\users\ornmadee\appdata\local\{8EC6725B-9177-431D-ADD5-F2FB81D0B161}<br />
2012-04-14 21:25:53	--------	d-----w-	c:\users\ornmadee\appdata\local\{3B68E202-3ECA-450D-9F4E-9AB232CF721B}<br />
2012-04-14 21:25:39	--------	d-----w-	c:\users\ornmadee\appdata\local\{D016C0B4-6095-416C-A0F5-C8072536341D}<br />
2012-04-14 15:34:18	19824	----a-w-	c:\windows\system32\drivers\fs_rec.sys<br />
2012-04-14 15:34:17	5120	----a-w-	c:\windows\system32\wmi.dll<br />
2012-04-14 15:34:17	172544	----a-w-	c:\windows\system32\wintrust.dll<br />
2012-04-14 15:34:17	159232	----a-w-	c:\windows\system32\imagehlp.dll<br />
2012-04-14 15:33:28	3968368	----a-w-	c:\windows\system32\ntkrnlpa.exe<br />
2012-04-14 15:33:27	3913072	----a-w-	c:\windows\system32\ntoskrnl.exe<br />
2012-04-14 00:30:32	--------	d-----w-	c:\users\ornmadee\appdata\local\{5DAAA029-F387-4131-8A2A-E04207494748}<br />
2012-04-14 00:30:19	--------	d-----w-	c:\users\ornmadee\appdata\local\{F63A886C-0520-4FB5-8A25-977B479CBFB5}<br />
2012-04-13 22:36:31	--------	d-----w-	c:\users\ornmadee\appdata\local\{E6820C5A-7814-43C8-B5C0-5B906775BBBD}<br />
2012-04-13 22:36:18	--------	d-----w-	c:\users\ornmadee\appdata\local\{4C7ED13E-7ED1-4CA4-B2B1-80C4A5C81694}<br />
2012-04-13 03:43:50	--------	d-----w-	c:\users\ornmadee\appdata\local\{C5B395E8-6AAA-4C81-98A3-7F5A98010FF7}<br />
2012-04-13 03:43:39	--------	d-----w-	c:\users\ornmadee\appdata\local\{9B117643-6D35-4339-8A5E-880001D647D6}<br />
2012-04-13 02:26:34	--------	d-----w-	c:\users\ornmadee\appdata\local\{5319A88A-EC53-4E75-B111-9249632DB486}<br />
2012-04-13 02:26:22	--------	d-----w-	c:\users\ornmadee\appdata\local\{758D57D7-6C85-412F-878A-A85958E9AB9E}<br />
2012-04-13 00:49:25	--------	d-----w-	c:\users\ornmadee\appdata\local\{968937B1-AE21-4D85-B7C0-1390CF9B37E3}<br />
2012-04-13 00:45:28	--------	d-----w-	c:\users\ornmadee\appdata\local\{2CDAB854-9B55-437D-B01F-8FDEA08A0876}<br />
2012-04-12 21:31:04	--------	d-----w-	c:\users\ornmadee\appdata\local\{CC26674F-1854-49BF-AE62-D4C690794FC7}<br />
2012-04-12 21:30:53	--------	d-----w-	c:\users\ornmadee\appdata\local\{57A537BC-B542-4F0B-87EC-5A7386DBC2EC}<br />
2012-04-12 20:31:22	--------	d-----w-	c:\users\ornmadee\appdata\local\{7DB8B044-0911-4911-BDE4-AC522EE7BD20}<br />
2012-04-12 20:31:11	--------	d-----w-	c:\users\ornmadee\appdata\local\{4E0F75DC-33BC-435A-9BE1-09C4C0ECDF35}<br />
2012-04-12 18:22:04	--------	d-----w-	c:\users\ornmadee\appdata\local\{27B32201-789E-4F8F-8019-DEA2D799C405}<br />
2012-04-12 18:21:53	--------	d-----w-	c:\users\ornmadee\appdata\local\{F0F32740-4FBC-4E9A-A05A-8088337B768F}<br />
2012-04-12 16:33:09	--------	d-----w-	c:\users\ornmadee\appdata\local\{82CF3EA1-B1A4-40A3-B1DB-A7577118A3FB}<br />
2012-04-12 16:32:57	--------	d-----w-	c:\users\ornmadee\appdata\local\{BA48DF92-B2A7-4919-9C2E-7A35A24F2194}<br />
2012-04-12 15:28:26	--------	d-----w-	c:\users\ornmadee\appdata\local\{84970998-65B7-4C66-B004-63F3AA621713}<br />
2012-04-12 15:28:15	--------	d-----w-	c:\users\ornmadee\appdata\local\{CF6A80F0-1D4B-4157-AB5D-09B9F17B37E0}<br />
2012-04-12 03:56:45	--------	d-----w-	c:\users\ornmadee\appdata\local\{185DE91E-606B-46E2-9F8D-8AC099ACFC87}<br />
2012-04-12 03:56:29	--------	d-----w-	c:\users\ornmadee\appdata\local\{09EE14FE-4741-4E04-8074-9EEC739408A4}<br />
2012-04-12 00:01:21	--------	d-----w-	c:\users\ornmadee\appdata\local\{970E642A-74F8-4CE6-AF34-8E8D7BC47EE5}<br />
2012-04-12 00:01:04	--------	d-----w-	c:\users\ornmadee\appdata\local\{E4230657-857E-4D9F-98E9-BB9A595BFBD7}<br />
2012-04-11 20:54:18	--------	d-----w-	c:\users\ornmadee\appdata\local\{7C11E12B-9364-4AA6-8D14-390C5A632B58}<br />
2012-04-11 20:54:07	--------	d-----w-	c:\users\ornmadee\appdata\local\{1765087A-B942-47C5-A9FB-4520371FB580}<br />
2012-04-11 19:56:08	--------	d-----w-	c:\users\ornmadee\appdata\local\{B24180CB-D05A-49A4-B0C4-E64A8B67A030}<br />
2012-04-11 19:55:55	--------	d-----w-	c:\users\ornmadee\appdata\local\{0EF40091-41CF-4B1C-9B06-5658BCA81556}<br />
2012-04-11 14:55:12	--------	d-----w-	c:\users\ornmadee\appdata\local\{D27DD14C-11FD-4F5D-BC4C-7F0D61DDFB59}<br />
2012-04-11 14:54:59	--------	d-----w-	c:\users\ornmadee\appdata\local\{F1902F1C-6D2C-4392-92FA-454915348702}<br />
2012-04-11 14:06:17	--------	d-----w-	c:\users\ornmadee\appdata\local\{18BBDA6E-0DB6-4C4D-ACC5-A23668EE3E22}<br />
2012-04-11 14:06:06	--------	d-----w-	c:\users\ornmadee\appdata\local\{D32EBED1-F37A-4F2B-9578-688307D74EB3}<br />
2012-04-11 03:33:53	--------	d-----w-	c:\users\ornmadee\appdata\local\{4E07A0E9-1AFB-4711-8570-D9416EBCF8A9}<br />
2012-04-11 03:33:41	--------	d-----w-	c:\users\ornmadee\appdata\local\{A0FE8197-F632-4942-AC4A-18C91A5BD26D}<br />
2012-04-10 18:33:50	--------	d-----w-	c:\users\ornmadee\appdata\local\{56B55C4B-8394-44A2-907B-3474BDCA0BC3}<br />
2012-04-10 18:33:37	--------	d-----w-	c:\users\ornmadee\appdata\local\{181D38FC-BBD1-47AD-BE79-2D7CD0EEAC16}<br />
2012-04-10 15:00:11	--------	d-----w-	c:\users\ornmadee\appdata\local\{F146342B-A099-4813-A924-3757EC39DB54}<br />
2012-04-10 14:59:59	--------	d-----w-	c:\users\ornmadee\appdata\local\{5507AD84-4031-40D3-9AD5-8CD7244014F7}<br />
2012-04-10 01:38:12	--------	d-----w-	c:\users\ornmadee\appdata\local\{AECE5843-2ACF-41D5-9CEE-BC01FF5DCFCD}<br />
2012-04-10 01:37:58	--------	d-----w-	c:\users\ornmadee\appdata\local\{75EF6264-7F60-4FF5-932F-589538EEE85A}<br />
2012-04-09 23:50:56	--------	dc----w-	c:\program files\Incredibar.com<br />
2012-04-09 23:49:59	--------	d-----w-	c:\programdata\Codecv<br />
2012-04-09 23:49:44	--------	dc----w-	C:\codec-info<br />
2012-04-09 20:06:30	--------	d-----w-	c:\users\ornmadee\appdata\local\{59F67D83-F037-4993-B669-B0AB3E78C94F}<br />
2012-04-09 20:06:17	--------	d-----w-	c:\users\ornmadee\appdata\local\{FA7F04E5-28D2-4F44-A6CC-1BBC6A1E2176}<br />
2012-04-09 14:43:49	--------	d-----w-	c:\users\ornmadee\appdata\local\{0EE02D3A-D4D5-4FE5-B960-073EB811FE39}<br />
2012-04-09 14:43:37	--------	d-----w-	c:\users\ornmadee\appdata\local\{CE19DD92-E120-4A26-BCD1-4B1FD353B5AE}<br />
2012-04-09 14:27:04	--------	d-----w-	c:\users\ornmadee\appdata\local\{20DFC51D-82B2-4E08-A679-5072759FDBC6}<br />
2012-04-09 14:26:52	--------	d-----w-	c:\users\ornmadee\appdata\local\{E3E06822-FCE0-45C5-8FDD-D47F4E15AE61}<br />
2012-04-09 02:17:08	--------	d-----w-	c:\users\ornmadee\appdata\local\{BE141C9C-1FE1-4881-8173-317A500646B9}<br />
2012-04-09 02:16:56	--------	d-----w-	c:\users\ornmadee\appdata\local\{71E952A1-AF48-456F-8B3D-28471715C7EC}<br />
2012-04-09 00:29:58	--------	d-----w-	c:\users\ornmadee\appdata\local\{04C09754-099C-46EE-97E1-C2C464D103E9}<br />
2012-04-09 00:29:43	--------	d-----w-	c:\users\ornmadee\appdata\local\{947B5F85-CBE6-4452-A44E-64E5ACEB5D39}<br />
2012-04-08 22:10:52	--------	d-----w-	c:\users\ornmadee\appdata\local\{679ED41E-5C56-4E6E-8F90-2D285E0D485A}<br />
2012-04-08 22:10:38	--------	d-----w-	c:\users\ornmadee\appdata\local\{016BE9FC-4F0F-4237-9E8B-FE165030FEA7}<br />
2012-04-08 20:34:50	--------	d-----w-	c:\users\ornmadee\appdata\local\{C95D3D9E-B9B3-47F3-8BB3-19932C62F855}<br />
2012-04-08 20:34:37	--------	d-----w-	c:\users\ornmadee\appdata\local\{6404BCF1-1EF9-4E3B-887F-7B4A360C4E2D}<br />
2012-04-08 02:32:05	--------	d-----w-	c:\users\ornmadee\appdata\local\{6DBAE1D6-CF1A-45E5-9253-8C2E19C3C4C0}<br />
2012-04-08 02:31:52	--------	d-----w-	c:\users\ornmadee\appdata\local\{8BE9A12F-7A50-4856-B440-9E6C683DFDB9}<br />
2012-04-08 01:42:09	--------	d-----w-	c:\users\ornmadee\appdata\local\{7F18729A-7BEA-47AB-9139-B40338646E9F}<br />
2012-04-08 01:41:56	--------	d-----w-	c:\users\ornmadee\appdata\local\{6D36F16C-A161-4AB0-8B6B-8F56E37B3118}<br />
2012-04-07 23:10:15	--------	d-----w-	c:\users\ornmadee\appdata\local\{919FB66D-50CF-49B6-B984-3852396E9182}<br />
2012-04-07 23:10:03	--------	d-----w-	c:\users\ornmadee\appdata\local\{FCBA62EB-771E-48EA-947F-C051D0689606}<br />
2012-04-07 21:38:50	--------	d-----w-	c:\users\ornmadee\appdata\local\{80D552AA-7701-4F77-BBA9-E0BD94170BAA}<br />
2012-04-07 21:38:38	--------	d-----w-	c:\users\ornmadee\appdata\local\{6A20D707-28EC-4BCD-A7AC-109621E9CAA2}<br />
2012-04-07 11:13:19	--------	d-----w-	c:\users\ornmadee\appdata\local\{EEE7DC5C-7E3D-4EF5-97A3-7F7581E7F374}<br />
2012-04-07 11:12:56	--------	d-----w-	c:\users\ornmadee\appdata\local\{AB0E73FE-E372-4BE9-9161-69F4170EE904}<br />
2012-04-07 09:27:15	--------	d-----w-	c:\users\ornmadee\appdata\local\{91F5BE16-C958-4903-96E5-4802B3B7B9B8}<br />
2012-04-07 09:27:02	--------	d-----w-	c:\users\ornmadee\appdata\local\{86B06A62-F032-4784-A24D-0AC1215DE7FB}<br />
2012-04-07 09:25:03	--------	d-----w-	c:\users\ornmadee\appdata\local\{94BEDB5C-D381-4EF8-ABD8-F1B73B103CAE}<br />
2012-04-07 09:24:45	--------	d-----w-	c:\users\ornmadee\appdata\local\{0DD79021-A60D-447A-AE45-173AD894D233}<br />
2012-04-07 06:25:36	--------	d-----w-	c:\users\ornmadee\appdata\local\{BC35865A-C170-41A2-B2CB-09196901CD8F}<br />
2012-04-07 06:25:23	--------	d-----w-	c:\users\ornmadee\appdata\local\{C2F439AC-5FBE-4A36-A01C-77C74F064757}<br />
2012-04-07 00:06:15	--------	d-----w-	c:\users\ornmadee\appdata\local\{8AE3E518-E877-4263-9DCD-B5DDC0993073}<br />
2012-04-07 00:06:02	--------	d-----w-	c:\users\ornmadee\appdata\local\{0AD09DC8-5016-4C02-9698-8D25C1A48394}<br />
2012-04-06 01:34:12	--------	d-----w-	c:\users\ornmadee\appdata\local\{210E343C-4736-43EF-B48E-A2BB3D32558C}<br />
2012-04-05 20:57:21	--------	d-----w-	c:\users\ornmadee\appdata\local\{4084EA8A-1023-496D-85B1-736806411088}<br />
2012-04-05 20:22:05	--------	d-----w-	c:\users\ornmadee\appdata\local\{14592758-E952-43D7-9B5E-8EDFFB21C0ED}<br />
2012-04-05 16:33:32	--------	d-----w-	c:\users\ornmadee\appdata\local\{34A0C6BA-3047-4D07-BC02-D7F5D68A61B2}<br />
2012-04-05 15:08:03	--------	d-----w-	c:\users\ornmadee\appdata\local\{E1C94C72-ACBF-47AC-A517-31D4CB753CC9}<br />
2012-04-05 14:18:00	--------	d-----w-	c:\users\ornmadee\appdata\local\{40753BF2-3C09-4D85-ADD6-2110D7503765}<br />
2012-04-05 14:11:25	--------	d-----w-	c:\users\ornmadee\appdata\local\{A76BD751-9EB3-46B0-BD97-86F9C8EA30B7}<br />
2012-04-05 12:55:49	--------	d-----w-	c:\users\ornmadee\appdata\local\{10CDC465-FC10-4E91-9E22-AFC932277F3F}<br />
2012-04-05 04:34:14	--------	d-----w-	c:\users\ornmadee\appdata\local\{8392FF46-9AE9-4F7D-8E02-92C7599B7DF9}<br />
2012-04-05 04:18:02	--------	d-----w-	c:\users\ornmadee\appdata\local\{753C27D9-BBCB-4B5F-852F-49710A76841E}<br />
2012-04-05 03:13:37	--------	d-----w-	c:\users\ornmadee\appdata\local\{56F0D4AC-4BB4-4F80-B909-C91ACA5E2A17}<br />
2012-04-04 22:00:54	--------	d-----w-	c:\users\ornmadee\appdata\local\{769C56A3-0467-47E9-B924-5D4E369F75A7}<br />
2012-04-04 22:00:42	--------	d-----w-	c:\users\ornmadee\appdata\local\{9690F1DF-607A-4907-BE7B-AB2286BA04E6}<br />
2012-04-04 20:54:25	--------	d-----w-	c:\users\ornmadee\appdata\local\{6F2F1336-9FF4-46C0-B78E-F6F517765885}<br />
2012-04-04 20:53:58	--------	d-----w-	c:\users\ornmadee\appdata\local\{B467C60E-CC02-40D0-9014-0639286FAAB1}<br />
2012-04-04 17:56:57	744568	----a-r-	c:\windows\system32\drivers\n360\0502010.003\symefa.sys<br />
2012-04-04 17:56:57	516216	----a-r-	c:\windows\system32\drivers\n360\0502010.003\srtsp.sys<br />
2012-04-04 17:56:57	50168	----a-r-	c:\windows\system32\drivers\n360\0502010.003\srtspx.sys<br />
2012-04-04 17:56:57	340088	----a-r-	c:\windows\system32\drivers\n360\0502010.003\symds.sys<br />
2012-04-04 17:56:57	299640	----a-w-	c:\windows\system32\drivers\n360\0502010.003\symnets.sys<br />
2012-04-04 17:56:56	136312	----a-r-	c:\windows\system32\drivers\n360\0502010.003\ironx86.sys<br />
2012-04-04 17:56:28	--------	d-----w-	c:\windows\system32\drivers\n360\0502010.003<br />
2012-04-04 13:48:02	--------	d-----w-	c:\users\ornmadee\appdata\local\{ACB3803E-3A1E-4098-9413-D4E0DA1F0B0E}<br />
2012-04-04 13:47:50	--------	d-----w-	c:\users\ornmadee\appdata\local\{7532E294-E89F-4977-953E-F4B7D108224B}<br />
2012-04-04 05:53:56	182160	-c--a-w-	c:\program files\internet explorer\plugins\nppdf32.dll<br />
2012-04-04 04:31:03	--------	d-----w-	c:\users\ornmadee\appdata\local\{6897FEBE-46DC-4C28-997F-3FED94B20AFA}<br />
2012-04-04 04:30:50	--------	d-----w-	c:\users\ornmadee\appdata\local\{40AF2BC0-C268-4FD8-862B-5425BE293938}<br />
2012-04-04 04:21:01	--------	d-----w-	c:\users\ornmadee\appdata\local\Graboid Inc<br />
2012-04-04 03:08:10	--------	d-----w-	c:\users\ornmadee\appdata\local\{641D8FCB-181D-4D5E-9B9C-219525433BD8}<br />
2012-04-04 02:45:23	--------	d-----w-	c:\users\ornmadee\appdata\local\{6F9681ED-1908-419D-9BFD-571634FD691F}<br />
2012-04-04 02:43:50	--------	d-----w-	c:\users\ornmadee\appdata\local\{C58AE691-9723-42C1-ACC6-0769BCD31759}<br />
2012-04-03 19:05:41	--------	d-----w-	c:\users\ornmadee\appdata\local\{CF2631C7-F7B5-4833-B7CA-A885F53A46BA}<br />
2012-04-03 19:05:29	--------	d-----w-	c:\users\ornmadee\appdata\local\{FD7CDD20-DF3F-4CF4-A242-F293E7CD2575}<br />
2012-04-03 12:43:27	--------	d-----w-	c:\users\ornmadee\appdata\local\{43C50041-AA24-43B6-9D3F-A4FDF3DE493E}<br />
2012-04-03 12:43:05	--------	d-----w-	c:\users\ornmadee\appdata\local\{516CC0C9-4950-4D99-A8B1-36F11B3B92A8}<br />
2012-04-02 21:02:51	--------	d-----w-	c:\users\ornmadee\appdata\local\{CD2BFACC-8B3C-4252-8AF6-504EE06412A7}<br />
2012-04-02 21:02:38	--------	d-----w-	c:\users\ornmadee\appdata\local\{453996AA-4095-4006-88D8-FF0D2582C5B2}<br />
2012-04-02 18:31:46	--------	dc----w-	c:\program files\iPod<br />
2012-04-02 18:09:29	159744	-c--a-w-	c:\program files\internet explorer\plugins\npqtplugin7.dll<br />
2012-04-02 18:09:29	159744	-c--a-w-	c:\program files\internet explorer\plugins\npqtplugin6.dll<br />
2012-04-02 18:09:29	159744	-c--a-w-	c:\program files\internet explorer\plugins\npqtplugin5.dll<br />
2012-04-02 18:09:29	159744	-c--a-w-	c:\program files\internet explorer\plugins\npqtplugin4.dll<br />
2012-04-02 18:09:29	159744	-c--a-w-	c:\program files\internet explorer\plugins\npqtplugin3.dll<br />
2012-04-02 18:09:29	159744	-c--a-w-	c:\program files\internet explorer\plugins\npqtplugin2.dll<br />
2012-04-02 18:09:29	159744	-c--a-w-	c:\program files\internet explorer\plugins\npqtplugin.dll<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2012-04-02 13:07:39	499712	----a-w-	c:\windows\system32\msvcp71.dll<br />
2012-04-02 13:07:39	348160	----a-w-	c:\windows\system32\msvcr71.dll<br />
2012-03-22 19:12:12	4435968	----a-w-	c:\windows\system32\GPhotos.scr<br />
2012-02-29 04:01:23	472808	----a-w-	c:\windows\system32\deployJava1.dll<br />
2012-02-28 01:18:55	1799168	----a-w-	c:\windows\system32\jscript9.dll<br />
2012-02-28 01:11:21	1427456	----a-w-	c:\windows\system32\inetcpl.cpl<br />
2012-02-28 01:11:07	1127424	----a-w-	c:\windows\system32\wininet.dll<br />
2012-02-28 01:03:16	2382848	----a-w-	c:\windows\system32\mshtml.tlb<br />
2012-02-17 05:34:22	826880	----a-w-	c:\windows\system32\rdpcore.dll<br />
2012-02-17 04:14:08	183808	----a-w-	c:\windows\system32\drivers\rdpwd.sys<br />
2012-02-17 04:13:22	24576	----a-w-	c:\windows\system32\drivers\tdtcp.sys<br />
2012-02-15 17:01:50	4547944	----a-w-	c:\windows\system32\usbaaplrc.dll<br />
2012-02-15 17:01:50	43520	----a-w-	c:\windows\system32\drivers\usbaapl.sys<br />
2012-02-10 05:38:43	1077248	----a-w-	c:\windows\system32\DWrite.dll<br />
2012-02-07 17:02:40	1070352	----a-w-	c:\windows\system32\MSCOMCTL.OCX<br />
2012-02-03 03:54:27	2343424	----a-w-	c:\windows\system32\win32k.sys<br />
.<br />
============= FINISH: 11:20:12.99 ===============<br />
<br />
I tried running the GMER Rootkit Scanner, but i kept getting sent to lightroom</div>


	<br />
	<div style="padding:8px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://cdn.techsupportforum.com/forums/images/sk/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techsupportforum.com/forums/attachment.php?attachmentid=108910&amp;d=1335981141">Attach.txt</a> (8.6 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techsupportforum.com/forums/f284/">Inactive Malware Help Topics</category>
			<dc:creator>BCHS</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/forums/f284/win32-small-ca-virus-643511.html</guid>
		</item>
		<item>
			<title>Need help, what else? :) Laptop went berserk.</title>
			<link>http://www.techsupportforum.com/forums/f284/need-help-what-else-laptop-went-berserk-643434.html</link>
			<pubDate>Wed, 02 May 2012 06:57:09 GMT</pubDate>
			<description><![CDATA[I did see a question similar to mine posted recently, but our circumstances are so different - I'm not sure I can use your suggestions to him in my case. 
 
Need your help, guys. I'll try to make this brief (ish).  
 
My HP Pavilion laptop was getting very slow and then started doing weird things,...]]></description>
			<content:encoded><![CDATA[<div>I did see a question similar to mine posted recently, but our circumstances are so different - I'm not sure I can use your suggestions to him in my case.<br />
<br />
Need your help, guys. I'll try to make this brief (ish). <br />
<br />
My HP Pavilion laptop was getting very slow and then started doing weird things, like: the sound icon in the launch tray vanished, the laptop would start ringing like crazy, upon starting, some keys suddenly being disabled, or letters of one word I would type, scrolling 100 lines apart. It was a gradual process but it got worse and worse. AVG and Adaware found nothing. <br />
<br />
A couple of days ago, I used all utilities I could get my hands on and the computer worked great and fast. Except... the next day got bad again. Downloaded Avast and only on boot scan it found Win32:PUP. It put it in a vault. Everything was working great again. <br />
<br />
This morning - laptop is going crazy, doesn't even boot beyond the HP logo, deafening ringing I can't stop, keys don't respond. I was eventually able to boot through F12, I think, but the keys were still not responding. Pushing everywhere, I somehow managed to open Avast, which said that everything was A-OK. I tried to run another boot scan - everything crashed. CTRL ALT DEL did nothing, the screen was just jumping. Anyway - I had to force the shut-of manually and even that didn't work right away. This, or something similar happened in the past and then I would be able to go on again, but today, knowing about Win32:PUP, i didn't want to do anything until I heard from you. <br />
<br />
I have since read that Win32:PUP can hide and bring itself back to life, so to speak, when the system is off, but I thought that if it was quarantined it would be blocked. <br />
<br />
I found these removal instructions: blog.teesupport.com/permanently-remove-win32pup-gen-manually-delete-win32pup-gen/<br />
but I would need a little bit of hand-holding to do it, especially in the state the laptop is in (I'm a good study), and also I'm not sure whether the suggestion is even kosher. <br />
<br />
What do I do now? Help, please.<br />
<br />
Question about Avast: in a regular scan, it decides itself on a fix or recommends one. In the boot scan, it just gave me options, such as &quot;heal&quot;, &quot;delete&quot;, &quot;put in a vault&quot;, etc. Frankly, I didn't know what to choose so I picked what I see most often. Should I have picked something else?</div>

]]></content:encoded>
			<category domain="http://www.techsupportforum.com/forums/f284/">Inactive Malware Help Topics</category>
			<dc:creator>Sophia L</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/forums/f284/need-help-what-else-laptop-went-berserk-643434.html</guid>
		</item>
		<item>
			<title>about.blank resets my homepage. XP.</title>
			<link>http://www.techsupportforum.com/forums/f284/about-blank-resets-my-homepage-xp-643265.html</link>
			<pubDate>Tue, 01 May 2012 00:29:37 GMT</pubDate>
			<description>Very frustrating, about.blank rests my internet explorer 8 home page from Google to about. blank !!!!! 
 
 
. 
DDS (Ver_2011-08-26.01) - NTFSx86  
Internet Explorer: 8.0.6001.18702 
Run by Lime Green at 16:20:46 on 2012-04-30 
Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1033.18.2047.1553...</description>
			<content:encoded><![CDATA[<div>Very frustrating, about.blank rests my internet explorer 8 home page from Google to about. blank !!!!!<br />
<br />
<br />
.<br />
DDS (Ver_2011-08-26.01) - NTFSx86 <br />
Internet Explorer: 8.0.6001.18702<br />
Run by Lime Green at 16:20:46 on 2012-04-30<br />
Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1033.18.2047.1553 [GMT -8:00]<br />
.<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\WINDOWS\system32\svchost -k DcomLaunch<br />
svchost.exe<br />
C:\WINDOWS\System32\svchost.exe -k netsvcs<br />
svchost.exe<br />
svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Mil Incorporated\Mil Shield\ShieldService.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe<br />
C:\Program Files\Intel\Intel(R) Active Monitor\imonnt.exe<br />
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe<br />
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe<br />
C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe<br />
C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe<br />
C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe<br />
C:\WINDOWS\system32\RUNDLL32.EXE<br />
C:\Program Files\ClamWin\bin\ClamTray.exe<br />
C:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe<br />
C:\Program Files\Mil Incorporated\Mil Shield\ShieldWorker.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Program Files\OpenOffice.org1.1.0\program\soffice.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uStart Page = about<b></b>:blank<br />
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File<br />
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll<br />
BHO: IE to GetRight Helper: {31ff080d-12a3-439a-a2ef-4ba95a3148e8} - c:\program files\getright\xx2gr.dll<br />
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File<br />
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll<br />
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll<br />
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe<br />
mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe<br />
mRun: [SoundMAX] &quot;c:\program files\analog devices\soundmax\Smax4.exe&quot; /tray<br />
mRun: [ADS TVR Agent] c:\program files\ads tech\instant tv pvr\Scheduled.exe<br />
mRun: [SunJavaUpdateSched] &quot;c:\program files\java\jre6\bin\jusched.exe&quot;<br />
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe<br />
mRun: [DiscWizardMonitor.exe] c:\program files\seagate\discwizard\DiscWizardMonitor.exe<br />
mRun: [AcronisTimounterMonitor] c:\program files\seagate\discwizard\TimounterMonitor.exe<br />
mRun: [Acronis Scheduler2 Service] &quot;c:\program files\common files\seagate\schedule2\schedhlp.exe&quot;<br />
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup<br />
mRun: [nwiz] nwiz.exe /install<br />
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit<br />
mRun: [Adobe ARM] &quot;c:\program files\common files\adobe\arm\1.0\AdobeARM.exe&quot;<br />
mRun: [ClamWin] &quot;c:\program files\clamwin\bin\ClamTray.exe&quot; --logon<br />
mRun: [IMONTRAY] c:\program files\intel\intel(r) active monitor\imontray.exe<br />
mRun: [MilShieldSlave] &quot;c:\program files\mil incorporated\mil shield\ShieldWorker.exe&quot; -logon<br />
StartupFolder: c:\docume~1\limegr~1\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org1.1.0\program\quickstart.exe<br />
IE: Download with GetRight - c:\program files\getright\GRdownload.htm<br />
IE: Open with GetRight Browser - c:\program files\getright\GRbrowse.htm<br />
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe<br />
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll<br />
DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} - hxxp://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab<br />
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab<br />
TCP: DhcpNameServer = 148.78.249.200 148.78.249.201<br />
TCP: Interfaces\{67165AC8-AE6B-408D-BA03-6D470844A511} : DhcpNameServer = 192.168.0.1<br />
TCP: Interfaces\{807EB632-57A8-4D44-BF8E-CDFE64ECC988} : DhcpNameServer = 148.78.249.200 148.78.249.201<br />
TCP: Interfaces\{BDE832D9-2DC3-4FBC-9D6C-2C67F1DCD81A} : DhcpNameServer = 148.78.249.200 148.78.249.201<br />
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL<br />
AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL<br />
LSA: Authentication Packages = msv1_0 relog_ap<br />
.<br />
================= FIREFOX ===================<br />
.<br />
FF - ProfilePath - c:\documents and settings\lime green\application data\mozilla\firefox\profiles\b6qaiaxq.default\<br />
FF - prefs.js: browser.startup.homepage - about<b></b>:blank<br />
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll<br />
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll<br />
FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll<br />
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll<br />
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}<br />
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}<br />
FF - Ext: Java Quick Starter: <a href="mailto:jqs@sun.com">jqs@sun.com</a> - c:\program files\java\jre6\lib\deploy\jqs\ff<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R3 AR9271;Wireless Network Adapter Service;c:\windows\system32\drivers\athuw.sys [2012-4-2 1756384]<br />
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2012-3-30 116648]<br />
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-2-29 158856]<br />
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-3-29 253088]<br />
S3 Cap713x;Philips Cap713x Video Capture;c:\windows\system32\drivers\Cap713x.sys [2010-12-8 686080]<br />
S3 DM1105SBDA;DM1105 TV Device;c:\windows\system32\drivers\DM1105SBDA.sys [2011-7-26 27392]<br />
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2012-2-23 13192]<br />
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2012-2-23 8456]<br />
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2012-3-30 116648]<br />
S3 m4301a;Linksys Wireless-B USB Network Adapter v4.0 Driver;c:\windows\system32\drivers\m4301A.sys [2011-11-28 83552]<br />
S3 WlanUIG;EDUP 802.11g Wireless LAN USB Adapter Driver;c:\windows\system32\drivers\WlanUIG.sys [2012-3-15 376224]<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2012-04-25 04:36:25	10982	----a-w-	c:\windows\system32\HwInfoD.vxd<br />
2012-04-24 03:55:55	--------	d-----w-	c:\program files\RegClean Pro<br />
2012-04-24 03:48:21	--------	d-----w-	c:\documents and settings\lime green\application data\SpeedyPC Software<br />
2012-04-24 03:48:09	--------	d-----w-	c:\documents and settings\all users\application data\SpeedyPC Software<br />
2012-04-24 03:08:12	--------	d-----w-	c:\documents and settings\lime green\application data\Malwarebytes<br />
2012-04-24 03:05:46	--------	d-----w-	c:\documents and settings\all users\application data\Malwarebytes<br />
2012-04-24 02:31:07	--------	d-----w-	c:\documents and settings\lime green\application data\DriverCure<br />
2012-04-24 02:31:06	--------	d-----w-	c:\documents and settings\lime green\application data\SpeedMaxPc<br />
2012-04-24 02:30:53	--------	d-----w-	c:\documents and settings\all users\application data\SpeedMaxPc<br />
2012-04-23 17:38:10	--------	d-----w-	c:\windows\system32\wbem\repository\FS<br />
2012-04-23 17:38:10	--------	d-----w-	c:\windows\system32\wbem\Repository<br />
2012-04-23 17:35:44	--------	d-----w-	c:\documents and settings\lime green\application data\Systweak<br />
2012-04-23 17:35:38	--------	d-----w-	c:\documents and settings\lime green\local settings\application data\Mil Incorporated<br />
2012-04-20 18:39:40	--------	d-----w-	c:\windows\ShellNew<br />
2012-04-19 00:51:00	--------	d-----w-	c:\program files\nLite<br />
2012-04-18 22:11:32	--------	d-----w-	c:\program files\ToniArts<br />
2012-04-18 22:11:19	729088	----a-w-	c:\program files\common files\installshield\professional\runtime\09\01\intel32\iKernel.dll<br />
2012-04-18 22:11:19	69715	----a-w-	c:\program files\common files\installshield\professional\runtime\09\01\intel32\ctor.dll<br />
2012-04-18 22:11:19	5632	----a-w-	c:\program files\common files\installshield\professional\runtime\09\01\intel32\DotNetInstaller.exe<br />
2012-04-18 22:11:19	266240	----a-w-	c:\program files\common files\installshield\professional\runtime\09\01\intel32\iscript.dll<br />
2012-04-18 22:11:19	192512	----a-w-	c:\program files\common files\installshield\professional\runtime\09\01\intel32\iuser.dll<br />
2012-04-18 22:11:18	311428	----a-w-	c:\program files\common files\installshield\professional\runtime\09\01\intel32\setup.dll<br />
2012-04-18 22:11:18	188548	----a-w-	c:\program files\common files\installshield\professional\runtime\09\01\intel32\iGdi.dll<br />
2012-04-18 22:01:38	2416	----a-w-	c:\windows\system32\ASOROSet.bin<br />
2012-04-18 21:57:59	17280	----a-w-	c:\windows\system32\roboot.exe<br />
2012-04-18 21:51:13	--------	d-----w-	c:\program files\Mil Incorporated<br />
2012-04-16 06:21:39	52736	----a-w-	c:\windows\system32\SPIN32.OCX<br />
2012-04-16 06:21:39	26896	----a-w-	c:\windows\system32\HH.EXE<br />
2012-04-16 06:21:39	204296	----a-w-	c:\windows\system32\Richtx32.ocx<br />
2012-04-16 06:21:39	122880	----a-w-	c:\windows\system32\SensorDLL.dll<br />
2012-04-16 06:21:39	118784	----a-w-	c:\windows\system32\MSSTDFMT.DLL<br />
2012-04-16 06:21:39	1044480	----a-w-	c:\windows\system32\ROBOEX32.DLL<br />
2012-04-16 06:21:39	101888	----a-w-	c:\windows\system32\VB6STKIT.DLL<br />
2012-04-16 06:21:37	21963	----a-w-	c:\windows\system32\drivers\smb.sys<br />
2012-04-16 06:21:23	36484	----a-w-	c:\windows\system32\drivers\SMBios.sys<br />
2012-04-16 06:21:22	7424	----a-w-	c:\windows\system32\drivers\SIODRV.SYS<br />
2012-04-16 06:21:21	212992	----a-w-	c:\program files\common files\installshield\engine\6\intel 32\ILog.dll<br />
2012-04-13 16:47:44	--------	d-----w-	c:\windows\Intuit<br />
2012-04-13 02:16:30	4194304	----a-w-	c:\windows\system32\cdintf400.dll<br />
2012-04-13 01:28:33	135680	----a-w-	c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll<br />
2012-04-04 05:53:56	182160	----a-w-	c:\program files\mozilla firefox\plugins\nppdf32.dll<br />
2012-04-04 05:53:56	182160	----a-w-	c:\program files\internet explorer\plugins\nppdf32.dll<br />
2012-04-03 04:08:15	1756384	----a-r-	c:\windows\system32\drivers\athuw.sys<br />
2012-04-03 01:06:50	--------	d--h--r-	c:\documents and settings\all users\application data\Atheros<br />
2012-04-03 01:05:17	--------	d-----w-	c:\documents and settings\all users\application data\TP-LINK<br />
2012-04-02 23:24:07	--------	d-----w-	C:\New Folder<br />
2012-04-02 23:24:07	--------	d-----w-	c:\documents and settings\lime green\local settings\application data\Help<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2012-04-29 16:51:04	69632	----a-w-	c:\windows\uinst001.exe<br />
2012-04-14 15:34:34	70304	----a-w-	c:\windows\system32\FlashPlayerCPLApp.cpl<br />
2012-04-14 15:34:34	418464	----a-w-	c:\windows\system32\FlashPlayerApp.exe<br />
.<br />
============= FINISH: 16:20:58.95 ===============</div>


	<br />
	<div style="padding:8px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://cdn.techsupportforum.com/forums/images/sk/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techsupportforum.com/forums/attachment.php?attachmentid=108799&amp;d=1335832148">dds.txt</a> (12.0 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://cdn.techsupportforum.com/forums/images/sk/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techsupportforum.com/forums/attachment.php?attachmentid=108800&amp;d=1335832148">attach.txt</a> (7.3 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techsupportforum.com/forums/f284/">Inactive Malware Help Topics</category>
			<dc:creator>zl4gvn</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/forums/f284/about-blank-resets-my-homepage-xp-643265.html</guid>
		</item>
		<item>
			<title>Help with virus</title>
			<link>http://www.techsupportforum.com/forums/f284/help-with-virus-643120.html</link>
			<pubDate>Mon, 30 Apr 2012 07:39:29 GMT</pubDate>
			<description><![CDATA[I am new to these forums and I'm not sure how quickly responses are made, but I will not be able to respond until about noon tomorrow. 
  
I have had some pretty mean viruses is the past. I have had to take 2 computers into a virus removal shop, the others I was able to fix myself. I have never had...]]></description>
			<content:encoded><![CDATA[<div>I am new to these forums and I'm not sure how quickly responses are made, but I will not be able to respond until about noon tomorrow.<br />
 <br />
I have had some pretty mean viruses is the past. I have had to take 2 computers into a virus removal shop, the others I was able to fix myself. I have never had a virus like this one before. Here are my computers symptoms that I have noticed so far:<br />
 <br />
Unable to open several programs<br />
 <br />
Internet explorer opens a blank page at different intervals. Sometimes it happens just once, sometimes it opens one after the other so I can have as many as 70 blank pages open at once.<br />
 <br />
Searches get redirected<br />
 <br />
Websites I type into address bar get redirected<br />
 <br />
Computer is generally slower<br />
 <br />
Virus is not detected on Malwarebytes anti-malware software<br />
 <br />
Thanks in advance to any help!</div>

]]></content:encoded>
			<category domain="http://www.techsupportforum.com/forums/f284/">Inactive Malware Help Topics</category>
			<dc:creator>maxst</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/forums/f284/help-with-virus-643120.html</guid>
		</item>
		<item>
			<title>cant access anti virus sites or microsoft</title>
			<link>http://www.techsupportforum.com/forums/f284/cant-access-anti-virus-sites-or-microsoft-642886.html</link>
			<pubDate>Sat, 28 Apr 2012 18:41:37 GMT</pubDate>
			<description><![CDATA[Ive had this problem for a few a days. I've heard of combofix but not sure how to use it so any help would be appreciated. 
 
Heres My Hijackthis log 
 
 
---Quote--- 
Logfile of Trend Micro HijackThis v2.0.4 
Scan saved at 7:41:10 PM, on 28/04/2012 
Platform: Windows XP SP3 (WinNT 5.01.2600)...]]></description>
			<content:encoded><![CDATA[<div>Ive had this problem for a few a days. I've heard of combofix but not sure how to use it so any help would be appreciated.<br />
<br />
Heres My Hijackthis log<br />
<br />
<div style="margin:20px; margin-top:5px; ">
	<div class="smallfont" style="margin-bottom:2px">Quote:</div>
	<table cellpadding="8" cellspacing="0" border="0" width="100%">
	<tr>
		<td class="alt2">
			<hr />
			
				Logfile of Trend Micro HijackThis v2.0.4<br />
Scan saved at 7:41:10 PM, on 28/04/2012<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\csrss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\LEXBCES.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\system32\LEXPPS.EXE<br />
C:\Program Files\Digital Media Reader\shwiconem.exe<br />
C:\WINDOWS\zHotkey.exe<br />
C:\WINDOWS\SOUNDMAN.EXE<br />
C:\WINDOWS\ALCWZRD.EXE<br />
C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE<br />
C:\WINDOWS\system32\igfxtray.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy 2\SDTray.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\wdfmgr.exe<br />
c:\PROGRA~1\mcafee.com\vso\mcshield.exe<br />
C:\WINDOWS\System32\alg.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy 2\SDFSSvc.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Mozilla Firefox\plugin-container.exe<br />
C:\Program Files\BitTorrent\BitTorrent.exe<br />
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe<br />
C:\WINDOWS\system32\wbem\wmiprvse.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.techsupportforum.com/forums/external-link/?link=http%3A%2F%2Fwww.hotmail.com%2F" target="_blank" rel="nofollow">Sign In</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://www.techsupportforum.com/forums/external-link/?link=http%3A%2F%2Fgo.microsoft.com%2Ffwlink%2F%3FLinkId%3D69157" target="_blank" rel="nofollow">MSN.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://www.techsupportforum.com/forums/external-link/?link=http%3A%2F%2Fgo.microsoft.com%2Ffwlink%2F%3FLinkId%3D54896" target="_blank" rel="nofollow">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://www.techsupportforum.com/forums/external-link/?link=http%3A%2F%2Fgo.microsoft.com%2Ffwlink%2F%3FLinkId%3D54896" target="_blank" rel="nofollow">Bing</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.techsupportforum.com/forums/external-link/?link=http%3A%2F%2Fgo.microsoft.com%2Ffwlink%2F%3FLinkId%3D69157" target="_blank" rel="nofollow">MSN.com</a><br />
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,,C:\Documents and Settings\Chriz\Local Settings\Application Data\jrdqxmro\rxugimbb.exe<br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search &amp; Destroy 2\SDHelper.dll<br />
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: &amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll<br />
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll<br />
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br />
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe<br />
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE<br />
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe<br />
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe<br />
O4 - HKLM\..\Run: [Mixersel] C:\Program Files\Realtek\InstallShield\mixersel.exe<br />
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe<br />
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br />
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE<br />
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br />
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [SDTray] &quot;C:\Program Files\Spybot - Search &amp; Destroy 2\SDTray.exe&quot;<br />
O4 - HKCU\..\Run: [RxuGimbb] C:\Documents and Settings\Chriz\Local Settings\Application Data\jrdqxmro\rxugimbb.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')<br />
O8 - Extra context menu item: &amp;AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search &amp; Destroy 2\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp;&amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search &amp; Destroy 2\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)<br />
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll<br />
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll<br />
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe<br />
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE<br />
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe<br />
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe<br />
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe<br />
O23 - Service: Microsoft security update service (msupdate) - Unknown owner - c:\windows\system32\..\svchost.exe<br />
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS<br />
O23 - Service: Spybot-S&amp;D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search &amp; Destroy 2\SDFSSvc.exe<br />
O23 - Service: Spybot-S&amp;D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search &amp; Destroy 2\SDUpdSvc.exe<br />
<br />
--<br />
End of file - 7779 bytes<br />
			
			<hr />
		</td>
	</tr>
	</table>
</div></div>

]]></content:encoded>
			<category domain="http://www.techsupportforum.com/forums/f284/">Inactive Malware Help Topics</category>
			<dc:creator>jparish1986</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/forums/f284/cant-access-anti-virus-sites-or-microsoft-642886.html</guid>
		</item>
		<item>
			<title>XP Laptop began running slowly</title>
			<link>http://www.techsupportforum.com/forums/f284/xp-laptop-began-running-slowly-642814.html</link>
			<pubDate>Sat, 28 Apr 2012 07:03:40 GMT</pubDate>
			<description><![CDATA[So I have a laptop that I use (as a student) daily, which has suddenly started running very slowly. I've been watching resources in task manager, but I can't find anything recognizably suspicious.  
 
My computer specs are as follows: 
 
Dell Vostro 1500 17" Notebook 
XP Professional 2002 SP3 32bit...]]></description>
			<content:encoded><![CDATA[<div>So I have a laptop that I use (as a student) daily, which has suddenly started running very slowly. I've been watching resources in task manager, but I can't find anything recognizably suspicious. <br />
<br />
My computer specs are as follows:<br />
<br />
Dell Vostro 1500 17&quot; Notebook<br />
XP Professional 2002 SP3 32bit<br />
Intel Mobile Core 2 Duo T5270 @ 1.40GHz (temp normal)<br />
2GB Dual Channel DDR2 @ 332MHz (5-5-5-15)<br />
Dell Inc. 0NX907 (Microprocessor, also at normal temp)<br />
Mobile Intel 965 Express Chipset Family<br />
244GB SATA (Western Digital WDC WD2500BEVS-75UST0) (3/4 full)<br />
(More info on request)<br />
<br />
<br />
Computer health details:<br />
I run Microsoft Security Essentials and Malwarebytes Antivirus<br />
Scanned with both yesterday (Packer.ModifiedUPX found, quarantined)<br />
Defragged yesterday, constantly clear temp files with Piriform CCleaner<br />
I use Revo Uninstaller to remove programs, getting rid of unused registry keys and extra files<br />
<br />
I generally use the machine for student purposes, minor coding and minor gaming.<br />
<br />
HJT LOG:<br />
Logfile of Trend Micro HijackThis v2.0.4<br />
Scan saved at 11:32:02 AM, on 4/26/2012<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.17109)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\igfxtray.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\WINDOWS\system32\igfxsrvc.exe<br />
C:\WINDOWS\system32\KADxMain.exe<br />
C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe<br />
C:\Program Files\Microsoft Security Client\msseces.exe<br />
C:\Program Files\Common Files\Java\Java Update\jusched.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\WINDOWS\system32\wbem\wmiapsrv.exe<br />
C:\Documents and Settings\owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Documents and Settings\owner\Desktop\HijackThis.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://www.techsupportforum.com/forums/external-link/?link=http%3A%2F%2Fgo.microsoft.com%2Ffwlink%2F%3FLinkId%3D69157" target="_blank" rel="nofollow">MSN.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://www.techsupportforum.com/forums/external-link/?link=http%3A%2F%2Fgo.microsoft.com%2Ffwlink%2F%3FLinkId%3D54896" target="_blank" rel="nofollow">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://www.techsupportforum.com/forums/external-link/?link=http%3A%2F%2Fgo.microsoft.com%2Ffwlink%2F%3FLinkId%3D54896" target="_blank" rel="nofollow">Bing</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.techsupportforum.com/forums/external-link/?link=http%3A%2F%2Fgo.microsoft.com%2Ffwlink%2F%3FLinkId%3D69157" target="_blank" rel="nofollow">MSN.com</a><br />
F2 - REG:system.ini: UserInit=userinit.exe,<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [KADxMain] C:\WINDOWS\system32\KADxMain.exe<br />
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] &quot;C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe&quot;<br />
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] &quot;C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe&quot; -launchedbylogin<br />
O4 - HKLM\..\Run: [XboxStat] &quot;c:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe&quot; silentrun<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\Run: [MSC] &quot;c:\Program Files\Microsoft Security Client\msseces.exe&quot; -hide -runkey<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Common Files\Java\Java Update\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe&quot; /starttray<br />
O4 - HKLM\..\Run: [APSDaemon] &quot;C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u<br />
O4 - HKCU\..\Run: [MSMSGS] &quot;C:\Program Files\Messenger\msmsgs.exe&quot; /background<br />
O4 - HKCU\..\Run: [binnmax700setup.exe] C:\Documents and Settings\owner\Application Data\8012BD4C0FDC2CF70580B82573D19E65\binnmax700setup.exe<br />
O4 - HKCU\..\Run: [Google Update] &quot;C:\Documents and Settings\owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe&quot; /c<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [DAEMON Tools Lite] &quot;C:\Program Files\DAEMON Tools Lite\DTLite.exe&quot; -autorun<br />
O4 - HKCU\..\Run: [uTorrent] &quot;C:\Program Files\uTorrent\uTorrent.exe&quot;  /MINIMIZED<br />
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] &quot;c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&quot; -t (User 'SYSTEM')<br />
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10e.exe (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] &quot;c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&quot; -t (User 'Default user')<br />
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10e.exe (User 'Default user')<br />
O4 - Startup: Dropbox.lnk = C:\Documents and Settings\owner\Application Data\Dropbox\bin\Dropbox.exe<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a href="http://www.techsupportforum.com/forums/external-link/?link=http%3A%2F%2Fplatformdl.adobe.com%2FNOS%2FgetPlusPlus%2F1.6%2Fgp.cab" target="_blank" rel="nofollow">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll<br />
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe<br />
<br />
--<br />
End of file - 8204 bytes<br />
<br />
<br />
I realize this might be an excess of info, but is there anything else I can provide?</div>

]]></content:encoded>
			<category domain="http://www.techsupportforum.com/forums/f284/">Inactive Malware Help Topics</category>
			<dc:creator>Kryzm</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/forums/f284/xp-laptop-began-running-slowly-642814.html</guid>
		</item>
		<item>
			<title>Happili Redirect Virus</title>
			<link>http://www.techsupportforum.com/forums/f284/happili-redirect-virus-642631.html</link>
			<pubDate>Fri, 27 Apr 2012 01:47:36 GMT</pubDate>
			<description>I use Internet Explorer, I have been getting redirected to Happili.com and other websites while researching on Google.  I downloaded Avast and Anvisoft Antimalware.  Neither can find the virus.  Avast does block the redirects.  Thank you for any help you can provide. 
  
. 
DDS (Ver_2011-08-26.01)...</description>
			<content:encoded><![CDATA[<div>I use Internet Explorer, I have been getting redirected to Happili.com and other websites while researching on Google.  I downloaded Avast and Anvisoft Antimalware.  Neither can find the virus.  Avast does block the redirects.  Thank you for any help you can provide.<br />
 <br />
.<br />
DDS (Ver_2011-08-26.01) - NTFSAMD64 <br />
Internet Explorer: 9.0.8112.16421<br />
Run by DAN at 19:15:18 on 2012-04-26<br />
Microsoft Windows 7 Home Premium   6.1.7600.0.1252.1.1033.18.3885.1199 [GMT -4:00]<br />
.<br />
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}<br />
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}<br />
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\svchost.exe -k RPCSS<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\system32\FBAgent.exe<br />
C:\Windows\system32\WLANExt.exe<br />
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe<br />
C:\Windows\system32\conhost.exe<br />
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe<br />
C:\Program Files\AVAST Software\Avast\AvastSvc.exe<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\ASDSrv.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe<br />
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe<br />
C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe<br />
C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe<br />
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe<br />
C:\Windows\system32\svchost.exe -k imgsvc<br />
C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe<br />
C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe<br />
C:\Program Files\Intel\WiFi\bin\EvtEng.exe<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Windows\system32\taskhost.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe<br />
C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe<br />
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe<br />
C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe<br />
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe<br />
C:\Program Files\P4G\BatteryLife.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\SysWOW64\ACEngSvr.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe<br />
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe<br />
C:\Program Files\Elantech\ETDCtrl.exe<br />
C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe<br />
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe<br />
C:\Windows\System32\igfxtray.exe<br />
C:\Windows\System32\hkcmd.exe<br />
C:\Windows\System32\igfxpers.exe<br />
C:\Program Files\Microsoft IntelliPoint\ipoint.exe<br />
C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE<br />
C:\Windows\System32\rundll32.exe<br />
C:\Windows\SysWOW64\rundll32.exe<br />
C:\Program Files\Elantech\ETDCtrlHelper.exe<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe<br />
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe<br />
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe<br />
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe<br />
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe<br />
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation<br />
C:\Program Files (x86)\iTunes\iTunesHelper.exe<br />
C:\Program Files\AVAST Software\Avast\AvastUI.exe<br />
C:\Program Files (x86)\ASUS\Wireless Console 3\WimaxConsole.exe<br />
C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\ASDTray.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe<br />
C:\Windows\AsScrPro.exe<br />
C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe<br />
C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe<br />
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe<br />
C:\Windows\System32\svchost.exe -k secsvcs<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE<br />
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe<br />
C:\Windows\system32\conhost.exe<br />
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe<br />
C:\Windows\system32\conhost.exe<br />
C:\Windows\splwow64.exe<br />
C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11e_ActiveX.exe<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Windows\system32\taskhost.exe<br />
C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\igfxsrvc.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\SysWOW64\cmd.exe<br />
C:\Windows\system32\conhost.exe<br />
C:\Windows\SysWOW64\cscript.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uStart Page = hxxp://www.google.com/<br />
uSearch Bar = Preserve<br />
mWinlogon: Userinit=userinit.exe<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL<br />
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll<br />
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll<br />
uRun: [Google Update] &quot;C:\Users\DAN\AppData\Local\Google\Update\GoogleUpdate.exe&quot; /c<br />
uRun: [OfficeSyncProcess] &quot;C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE&quot;<br />
uRun: [Netscape] Rundll32.exe C:\Users\DAN\AppData\Local\Netscape\lpzhystn.dll,OsMuxUnlock<br />
mRun: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe<br />
mRun: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe<br />
mRun: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe<br />
mRun: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe<br />
mRun: [APSDaemon] &quot;C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe&quot;<br />
mRun: [SunJavaUpdateSched] &quot;C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe&quot;<br />
mRun: [BCSSync] &quot;C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe&quot; /DelayServices<br />
mRun: [Adobe Reader Speed Launcher] &quot;C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
mRun: [Adobe ARM] &quot;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
mRun: [iTunesHelper] &quot;C:\Program Files (x86)\iTunes\iTunesHelper.exe&quot;<br />
mRun: [avast] &quot;C:\Program Files\AVAST Software\Avast\avastUI.exe&quot; /nogui<br />
mRun: [Anvi Smart Defender] C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\ASDTray.exe<br />
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\FANCYS~1.LNK - C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe<br />
mPolicies-explorer: NoActiveDesktop = 1 (0x1)<br />
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)<br />
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)<br />
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
IE: E&amp;xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000<br />
IE: Se&amp;nd to OneNote - C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105<br />
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll<br />
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll<br />
Trusted Zone: intuit.com\ttlc<br />
Trusted Zone: ted.com\www<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab<br />
TCP: DhcpNameServer = 192.168.1.254<br />
TCP: Interfaces\{04918C16-C940-4274-94B1-BCF35268FA05} : DhcpNameServer = 192.168.1.254<br />
TCP: Interfaces\{04918C16-C940-4274-94B1-BCF35268FA05}\34F6C41626 : DhcpNameServer = 68.87.68.162 68.87.74.162<br />
TCP: Interfaces\{04918C16-C940-4274-94B1-BCF35268FA05}\34F6C61626D2332746 : DhcpNameServer = 68.87.68.162 68.87.74.162<br />
TCP: Interfaces\{04918C16-C940-4274-94B1-BCF35268FA05}\4656679616E647 : DhcpNameServer = 192.168.1.1<br />
TCP: Interfaces\{04918C16-C940-4274-94B1-BCF35268FA05}\64275656458656E456470275966696 : DhcpNameServer = 10.128.128.128<br />
TCP: Interfaces\{04918C16-C940-4274-94B1-BCF35268FA05}\74575637470294E6475627E6564702143636563737E2 : DhcpNameServer = 75.94.255.12 64.13.115.12<br />
TCP: Interfaces\{04918C16-C940-4274-94B1-BCF35268FA05}\86162616E65627F6 : DhcpNameServer = 192.168.1.1<br />
TCP: Interfaces\{04918C16-C940-4274-94B1-BCF35268FA05}\D4363416274786970275966496 : DhcpNameServer = 192.168.1.254<br />
TCP: Interfaces\{901ED026-93D4-4225-A15E-341A2658C3A1} : NameServer = 192.168.50.225<br />
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL<br />
Handler: intu-help-qb5 - {867FCB77-9823-4cd6-8210-D85F968D466F} - C:\Program Files (x86)\Intuit\QuickBooks 2012\HelpAsyncPluggableProtocol.dll<br />
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - C:\Windows\System32\mscoree.dll<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL<br />
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL<br />
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
BHO-X64:     AcroIEHelperStub - No File<br />
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL<br />
BHO-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll<br />
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL<br />
BHO-X64:     URLRedirectionBHO - No File<br />
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
TB-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll<br />
mRun-x64: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe<br />
mRun-x64: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe<br />
mRun-x64: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe<br />
mRun-x64: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe<br />
mRun-x64: [APSDaemon] &quot;C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe&quot;<br />
mRun-x64: [SunJavaUpdateSched] &quot;C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe&quot;<br />
mRun-x64: [BCSSync] &quot;C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe&quot; /DelayServices<br />
mRun-x64: [Adobe Reader Speed Launcher] &quot;C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
mRun-x64: [Adobe ARM] &quot;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
mRun-x64: [iTunesHelper] &quot;C:\Program Files (x86)\iTunes\iTunesHelper.exe&quot;<br />
mRun-x64: [avast] &quot;C:\Program Files\AVAST Software\Avast\avastUI.exe&quot; /nogui<br />
mRun-x64: [Anvi Smart Defender] C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\ASDTray.exe<br />
IE-X64: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL<br />
.<br />
================= FIREFOX ===================<br />
.<br />
FF - ProfilePath - C:\Users\DAN\AppData\Roaming\Mozilla\Firefox\Profiles\0u1vwv9k.default\<br />
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157<br />
FF - prefs.js: network.proxy.type - 0<br />
FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll<br />
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll<br />
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll<br />
FF - plugin: C:\Users\DAN\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll<br />
FF - plugin: C:\Users\DAN\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll<br />
FF - plugin: C:\Users\DAN\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R0 lullaby;lullaby;C:\Windows\system32\DRIVERS\lullaby.sys --&gt; C:\Windows\system32\DRIVERS\lullaby.sys [?]<br />
R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --&gt; C:\Windows\system32\drivers\aswSnx.sys [?]<br />
R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --&gt; C:\Windows\system32\drivers\aswSP.sys [?]<br />
R1 avfsmn;avfsmn;C:\Windows\system32\DRIVERS\avfsmn.sys --&gt; C:\Windows\system32\DRIVERS\avfsmn.sys [?]<br />
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --&gt; C:\Windows\system32\DRIVERS\vwififlt.sys [?]<br />
R2 AFBAgent;AFBAgent;&quot;C:\Windows\system32\FBAgent.exe&quot; --&gt; C:\Windows\system32\FBAgent.exe [?]<br />
R2 asdsrv;Anvi Smart Defender Realtime Guard Service;C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\ASDSrv.exe [2012-2-3 296232]<br />
R2 ASMMAP64;ASMMAP64;C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-7-2 15416]<br />
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --&gt; C:\Windows\system32\drivers\aswFsBlk.sys [?]<br />
R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --&gt; C:\Windows\system32\drivers\aswMonFlt.sys [?]<br />
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-4-20 44768]<br />
R2 avhips;AntiMalware Host-based Intrusion Prevention System;\??\C:\Windows\system32\DRIVERS\avhips.sys --&gt; C:\Windows\system32\DRIVERS\avhips.sys [?]<br />
R2 DMAgent;Intel® PROSet/Wireless WiMAX Red Bend Device Management Service;C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [2009-12-29 404992]<br />
R2 IntuitUpdateServiceV4;Intuit Update Service v4;C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe [2012-2-6 13672]<br />
R2 QBVSS;QBIDPService;C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe [2011-8-19 1248256]<br />
R2 UNS;Intel(R) Management &amp; Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-10-18 2314240]<br />
R2 WiMAXAppSrv;Intel® PROSet/Wireless WiMAX Service;C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe [2009-12-29 911360]<br />
R3 bpenum;bpenum;C:\Windows\system32\DRIVERS\bpenum.sys --&gt; C:\Windows\system32\DRIVERS\bpenum.sys [?]<br />
R3 bpmp;bpmp;C:\Windows\system32\DRIVERS\bpmp.sys --&gt; C:\Windows\system32\DRIVERS\bpmp.sys [?]<br />
R3 bpusb;bpusb;C:\Windows\system32\Drivers\bpusb.sys --&gt; C:\Windows\system32\Drivers\bpusb.sys [?]<br />
R3 ETD;ELAN PS/2 Port Input Device;C:\Windows\system32\DRIVERS\ETD.sys --&gt; C:\Windows\system32\DRIVERS\ETD.sys [?]<br />
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --&gt; C:\Windows\system32\DRIVERS\HECIx64.sys [?]<br />
R3 Impcd;Impcd;C:\Windows\system32\DRIVERS\Impcd.sys --&gt; C:\Windows\system32\DRIVERS\Impcd.sys [?]<br />
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --&gt; C:\Windows\system32\DRIVERS\IntcDAud.sys [?]<br />
R3 JMCR;JMCR;C:\Windows\system32\DRIVERS\jmcr.sys --&gt; C:\Windows\system32\DRIVERS\jmcr.sys [?]<br />
R3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits);C:\Windows\system32\DRIVERS\JME.sys --&gt; C:\Windows\system32\DRIVERS\JME.sys [?]<br />
R3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\system32\DRIVERS\NETw5s64.sys --&gt; C:\Windows\system32\DRIVERS\NETw5s64.sys [?]<br />
R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]<br />
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --&gt; C:\Windows\system32\DRIVERS\vwifimp.sys [?]<br />
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]<br />
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]<br />
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-2-12 136176]<br />
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-2-29 158856]<br />
S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys --&gt; C:\Windows\system32\DRIVERS\btwl2cap.sys [?]<br />
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-2-12 136176]<br />
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-6-12 31125880]<br />
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2010-3-5 340240]<br />
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;C:\Windows\system32\DRIVERS\SiSG664.sys --&gt; C:\Windows\system32\DRIVERS\SiSG664.sys [?]<br />
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --&gt; C:\Windows\system32\Drivers\usbaapl64.sys [?]<br />
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --&gt; C:\Windows\system32\Wat\WatAdminSvc.exe [?]<br />
S3 WSDPrintDevice;WSD Print Support via UMB;C:\Windows\system32\DRIVERS\WSDPrint.sys --&gt; C:\Windows\system32\DRIVERS\WSDPrint.sys [?]<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2012-04-26 20:46:07 8917360 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{EA692BAB-1AD3-4D98-A965-362A93B64FB1}\mpengine.dll<br />
2012-04-22 00:06:45 388096 ----a-r- C:\Users\DAN\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe<br />
2012-04-22 00:06:45 -------- d-----w- C:\Program Files (x86)\Trend Micro<br />
2012-04-21 22:03:05 80896 ----a-w- C:\Windows\System32\imagehlp.dll<br />
2012-04-21 22:03:05 22896 ----a-w- C:\Windows\System32\drivers\fs_rec.sys<br />
2012-04-21 22:03:04 5120 ----a-w- C:\Windows\SysWow64\wmi.dll<br />
2012-04-21 22:03:04 5120 ----a-w- C:\Windows\System32\wmi.dll<br />
2012-04-21 22:03:04 220672 ----a-w- C:\Windows\System32\wintrust.dll<br />
2012-04-21 22:03:04 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll<br />
2012-04-21 22:03:04 158720 ----a-w- C:\Windows\SysWow64\imagehlp.dll<br />
2012-04-20 17:00:40 24360 ----a-w- C:\Windows\System32\drivers\avhips.sys<br />
2012-04-20 17:00:40 20264 ----a-w- C:\Windows\System32\drivers\avfsmn.sys<br />
2012-04-20 17:00:26 -------- d-----w- C:\Program Files (x86)\Anvisoft<br />
2012-04-20 15:48:35 53080 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys<br />
2012-04-20 15:48:30 819032 ----a-w- C:\Windows\System32\drivers\aswSnx.sys<br />
2012-04-20 15:48:22 69976 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys<br />
2012-04-20 15:47:49 41184 ----a-w- C:\Windows\avastSS.scr<br />
2012-04-20 15:47:38 -------- d-----w- C:\ProgramData\AVAST Software<br />
2012-04-20 15:47:38 -------- d-----w- C:\Program Files\AVAST Software<br />
2012-04-18 15:03:26 -------- d-----w- C:\Users\DAN\AppData\Roaming\Malwarebytes<br />
2012-04-18 15:03:18 -------- d-----w- C:\ProgramData\Malwarebytes<br />
2012-04-18 15:03:16 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware<br />
2012-04-17 06:55:04 -------- d-----w- C:\Users\DAN\AppData\Local\Windows Live<br />
2012-04-17 06:54:59 -------- d-----w- C:\Program Files (x86)\Common Files\Windows Live<br />
2012-04-17 06:09:47 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client<br />
2012-04-17 06:09:31 -------- d-----w- C:\Program Files\Microsoft Security Client<br />
2012-04-13 01:30:06 -------- d-----w- C:\Users\DAN\AppData\Local\Netscape<br />
2012-04-06 05:07:33 -------- d-----w- C:\Users\DAN\AppData\Roaming\Intuit<br />
2012-04-06 05:05:18 -------- d-----w- C:\Users\DAN\AppData\Local\IsolatedStorage<br />
2012-04-06 05:04:50 -------- d-----w- C:\Program Files (x86)\TurboTax<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2012-03-06 06:43:21 5504880 ----a-w- C:\Windows\System32\ntoskrnl.exe<br />
2012-03-06 05:59:41 3958128 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe<br />
2012-03-06 05:59:41 3902320 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe<br />
2012-02-28 06:56:48 2311168 ----a-w- C:\Windows\System32\jscript9.dll<br />
2012-02-28 06:49:56 1390080 ----a-w- C:\Windows\System32\wininet.dll<br />
2012-02-28 06:48:57 1493504 ----a-w- C:\Windows\System32\inetcpl.cpl<br />
2012-02-28 06:42:55 2382848 ----a-w- C:\Windows\System32\mshtml.tlb<br />
2012-02-28 01:18:55 1799168 ----a-w- C:\Windows\SysWow64\jscript9.dll<br />
2012-02-28 01:11:21 1427456 ----a-w- C:\Windows\SysWow64\inetcpl.cpl<br />
2012-02-28 01:11:07 1127424 ----a-w- C:\Windows\SysWow64\wininet.dll<br />
2012-02-28 01:03:16 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb<br />
2012-02-23 15:18:36 279656 ------w- C:\Windows\System32\MpSigStub.exe<br />
2012-02-15 16:01:50 52736 ----a-w- C:\Windows\System32\drivers\usbaapl64.sys<br />
2012-02-15 16:01:50 4547944 ----a-w- C:\Windows\System32\usbaaplrc.dll<br />
2012-02-15 06:27:54 1031680 ----a-w- C:\Windows\System32\rdpcore.dll<br />
2012-02-15 05:44:57 826368 ----a-w- C:\Windows\SysWow64\rdpcore.dll<br />
2012-02-15 04:47:21 204800 ----a-w- C:\Windows\System32\drivers\rdpwd.sys<br />
2012-02-15 04:46:59 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys<br />
2012-02-14 17:09:44 1070352 ----a-w- C:\Windows\SysWow64\MSCOMCTL.OCX<br />
2012-02-10 06:18:10 1541120 ----a-w- C:\Windows\System32\DWrite.dll<br />
2012-02-10 06:17:55 1837568 ----a-w- C:\Windows\System32\d3d10warp.dll<br />
2012-02-10 06:17:54 902656 ----a-w- C:\Windows\System32\d2d1.dll<br />
2012-02-10 06:17:54 320512 ----a-w- C:\Windows\System32\d3d10_1core.dll<br />
2012-02-10 06:17:54 197120 ----a-w- C:\Windows\System32\d3d10_1.dll<br />
2012-02-10 05:41:38 1074176 ----a-w- C:\Windows\SysWow64\DWrite.dll<br />
2012-02-10 05:41:20 218624 ----a-w- C:\Windows\SysWow64\d3d10_1core.dll<br />
2012-02-10 05:41:20 161792 ----a-w- C:\Windows\SysWow64\d3d10_1.dll<br />
2012-02-10 05:41:20 1170944 ----a-w- C:\Windows\SysWow64\d3d10warp.dll<br />
2012-02-10 05:41:19 739840 ----a-w- C:\Windows\SysWow64\d2d1.dll<br />
2012-02-03 04:16:03 3143168 ----a-w- C:\Windows\System32\win32k.sys<br />
2009-04-08 17:31:56 106496 ----a-w- C:\Program Files (x86)\Common Files\CPInstallAction.dll<br />
2008-08-12 04:45:20 155648 ----a-w- C:\Program Files (x86)\Common Files\MSIactionall.dll<br />
.<br />
============= FINISH: 19:16:41.57 ===============</div>


	<br />
	<div style="padding:8px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://cdn.techsupportforum.com/forums/images/sk/attach/zip.gif" alt="File Type: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techsupportforum.com/forums/attachment.php?attachmentid=108639&amp;d=1335491225">Attach.zip.zip</a> (4.5 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techsupportforum.com/forums/f284/">Inactive Malware Help Topics</category>
			<dc:creator>HMABJJ</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/forums/f284/happili-redirect-virus-642631.html</guid>
		</item>
		<item>
			<title>m0rpheu$ Virus...Please help!</title>
			<link>http://www.techsupportforum.com/forums/f284/m0rpheu-virus-please-help-642332.html</link>
			<pubDate>Wed, 25 Apr 2012 07:47:50 GMT</pubDate>
			<description>Hi,  
Has anyone dealt with a m0rpheu$ virus before? I am struggling to get this off a machine. 
When i scan with ESET, it find that the virus is called Win32/Clofect.A.  
I have tried to scan with AVAST, MBAM, Super anti Spyware, Windows Essential. but nothing works.  
Does anyone know how to...</description>
			<content:encoded><![CDATA[<div>Hi, <br />
Has anyone dealt with a m0rpheu$ virus before? I am struggling to get this off a machine.<br />
When i scan with ESET, it find that the virus is called Win32/Clofect.A. <br />
I have tried to scan with AVAST, MBAM, Super anti Spyware, Windows Essential. but nothing works. <br />
Does anyone know how to resolve this? <br />
Please find more information of this virus on the link below,<br />
<a href="http://www.techsupportforum.com/forums/external-link/?link=http%3A%2F%2Fwww.eset.eu%2Fencyclopaedia%2Fwin32-clofect-a-vipantispyware%3Flng%3Den" target="_blank" rel="nofollow"><font color="#0066cc">http://www.eset.eu/encyclopaedia/win32-clofect-a-vipantispyware?lng=en</font></a> <br />
Many Thanks, <br />
Gothy.</div>

]]></content:encoded>
			<category domain="http://www.techsupportforum.com/forums/f284/">Inactive Malware Help Topics</category>
			<dc:creator>Gothy</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/forums/f284/m0rpheu-virus-please-help-642332.html</guid>
		</item>
		<item>
			<title>qiwy.exe running at startup</title>
			<link>http://www.techsupportforum.com/forums/f284/qiwy-exe-running-at-startup-642327.html</link>
			<pubDate>Wed, 25 Apr 2012 06:39:21 GMT</pubDate>
			<description>An executable called qiwy.exe runs when the windows startup everytime.  I can see the command in the startup tab of msconfig, however, I cannot disable it manually by unchecking the box. 
 
I have ran reboot scan with Avast free antivirus and it told me qiwy.exe was a malware and it was being...</description>
			<content:encoded><![CDATA[<div>An executable called qiwy.exe runs when the windows startup everytime.  I can see the command in the startup tab of msconfig, however, I cannot disable it manually by unchecking the box.<br />
<br />
I have ran reboot scan with Avast free antivirus and it told me qiwy.exe was a malware and it was being removed, but Avast failed to clean it.  I have also used malwarebyte and Microsoft Security Essential to scan my computer, they picked up a dozen of other malware, but not qiwy.exe.<br />
<br />
Subsequently I purchased Kaspersky Internet Security 2012, but it cannot pick up qiwy.exe.  <br />
<br />
My internet is at half the speed compared to four months ago when I last recorded it.  <br />
<br />
I want to find out whether this program is a malware, and if so how can I get rid of it.<br />
<br />
The exe is located at:<br />
C:\Users\MY ACCOUNT\AppData\Roaming\Ucun\qiwy.exe<br />
<br />
I am running Windows 7 and I have the installation disc.<br />
<br />
Thank you very much.<br />
<br />
<br />
.<br />
DDS (Ver_2011-08-26.01) - NTFSAMD64 <br />
Internet Explorer: 8.0.7601.17514  BrowserJavaVersion: 1.6.0_26<br />
Run by BRYAN at 15:53:51 on 2012-04-25<br />
Microsoft Windows 7 Home Premium   6.1.7601.1.936.86.1033.18.4091.3073 [GMT 10:00]<br />
.<br />
AV: Kaspersky Internet Security *Enabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984}<br />
SP: Kaspersky Internet Security *Enabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339}<br />
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}<br />
FW: Kaspersky Internet Security *Enabled* {1691B380-548E-1A7A-BE85-9A42CE15AEFF}<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\svchost.exe -k RPCSS<br />
C:\Windows\system32\atiesrxx.exe<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\system32\atieclxx.exe<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe<br />
C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation<br />
C:\Windows\SysWOW64\XSrvSetup.exe<br />
C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe<br />
C:\Windows\system32\svchost.exe -k imgsvc<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE<br />
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe<br />
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\wmi64.exe<br />
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
C:\Windows\system32\userinit.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\taskhost.exe<br />
C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe<br />
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe<br />
C:\Windows\system32\WUDFHost.exe<br />
C:\Windows\SysWOW64\cmd.exe<br />
C:\Windows\system32\conhost.exe<br />
C:\Windows\SysWOW64\cscript.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uStart Page = about<b></b>:blank<br />
mStart Page = about<b></b>:blank<br />
uInternet Settings,ProxyOverride = *.local<br />
uURLSearchHooks: SearchHook Class: {bc86e1ab-eda5-4059-938f-ce307b0c6f0a} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll<br />
mWinlogon: Userinit=userinit.exe,<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll<br />
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll<br />
BHO: {889D2FEB-5411-4565-8998-1DD2C5261283} - No File<br />
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll<br />
uRun: [qiwy.exe] C:\Users\BRYAN\AppData\Roaming\Ucun\qiwy.exe<br />
mRun: [BCU] &quot;C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe&quot;<br />
mRun: [AVP] &quot;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe&quot;<br />
mPolicies-explorer: NoActiveDesktop = 1 (0x1)<br />
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)<br />
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)<br />
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)<br />
mPolicies-system: EnableLUA = 0 (0x0)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)<br />
IE: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm<br />
IE: Add to Google Photos Screensa&amp;ver - C:\Windows\system32\GPhotos.scr/200<br />
IE: E&amp;xport to Microsoft Excel - C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000<br />
IE: Se&amp;nd to OneNote - C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105<br />
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll<br />
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll<br />
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll<br />
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL<br />
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab<br />
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab<br />
TCP: DhcpNameServer = 192.168.0.1<br />
TCP: Interfaces\{C5AEE213-1592-43B2-BA68-E77096D96DBC} : DhcpNameServer = 192.168.0.1<br />
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll<br />
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll<br />
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
BHO-X64:     AcroIEHelperStub - No File<br />
BHO-X64: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll<br />
BHO-X64:     IEVkbdBHO - No File<br />
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll<br />
BHO-X64: {889D2FEB-5411-4565-8998-1DD2C5261283} - No File<br />
BHO-X64:     XunleiBHO - No File<br />
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
BHO-X64:     SkypeIEPluginBHO - No File<br />
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL<br />
BHO-X64:     URLRedirectionBHO - No File<br />
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
BHO-X64: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll<br />
BHO-X64:     link filter bho - No File<br />
mRun-x64: [BCU] &quot;C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe&quot;<br />
mRun-x64: [AVP] &quot;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe&quot;<br />
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll<br />
Hosts: 87.229.126.55    <a href="http://www.techsupportforum.com/forums/external-link/?link=http%3A%2F%2Fwww.bing.com" target="_blank" rel="nofollow">Bing</a><br />
.<br />
================= FIREFOX ===================<br />
.<br />
FF - ProfilePath - C:\Users\BRYAN\AppData\Roaming\Mozilla\Firefox\Profiles\oq983rjo.default\<br />
FF - prefs.js: browser.search.selectedEngine - Google US<br />
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig<br />
FF - plugin: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL<br />
FF - plugin: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL<br />
FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll<br />
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll<br />
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll<br />
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll<br />
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrlui.dll<br />
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll<br />
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll<br />
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll<br />
FF - plugin: E:\Program Files (x86)\Google\Picasa3\npPicasa3.dll<br />
FF - plugin: E:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll<br />
.<br />
---- FIREFOX POLICIES ----<br />
FF - user.js: network.cookie.cookieBehavior - 0<br />
FF - user.js: privacy.clearOnShutdown.cookies - false<br />
FF - user.js: security.warn_viewing_mixed - false<br />
FF - user.js: security.warn_viewing_mixed.show_once - false<br />
FF - user.js: security.warn_submit_insecure - false<br />
FF - user.js: security.warn_submit_insecure.show_once - false<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R1 AppleCharger;AppleCharger;C:\Windows\system32\DRIVERS\AppleCharger.sys --&gt; C:\Windows\system32\DRIVERS\AppleCharger.sys [?]<br />
R1 kl2;kl2;C:\Windows\system32\DRIVERS\kl2.sys --&gt; C:\Windows\system32\DRIVERS\kl2.sys [?]<br />
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys --&gt; C:\Windows\system32\DRIVERS\klim6.sys [?]<br />
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --&gt; C:\Windows\system32\atiesrxx.exe [?]<br />
R2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe [2011-4-24 202296]<br />
R2 BCUService;Browser Configuration Utility Service;C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2009-10-15 223464]<br />
R2 DES2 Service;DES2 Service for Energy Saving.;C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe [2010-7-15 68136]<br />
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-7-14 13336]<br />
R2 JMB36X;JMB36X;C:\Windows\SysWOW64\XSrvSetup.exe [2010-7-14 72304]<br />
R2 Smart TimeLock;Smart TimeLock Service;C:\Program Files (x86)\GIGABYTE\smart6\timelock\TimeMgmtDaemon.exe [2010-7-15 114688]<br />
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --&gt; C:\Windows\system32\DRIVERS\atikmdag.sys [?]<br />
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --&gt; C:\Windows\system32\DRIVERS\atikmpag.sys [?]<br />
R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\system32\DRIVERS\klmouflt.sys --&gt; C:\Windows\system32\DRIVERS\klmouflt.sys [?]<br />
R3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;C:\Windows\system32\DRIVERS\nusb3hub.sys --&gt; C:\Windows\system32\DRIVERS\nusb3hub.sys [?]<br />
R3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;C:\Windows\system32\DRIVERS\nusb3xhc.sys --&gt; C:\Windows\system32\DRIVERS\nusb3xhc.sys [?]<br />
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --&gt; C:\Windows\system32\DRIVERS\Rt64win7.sys [?]<br />
R3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --&gt; C:\Windows\system32\Drivers\usbaapl64.sys [?]<br />
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]<br />
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]<br />
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-10-29 136176]<br />
S3 AppleChargerSrv;AppleChargerSrv;system32\AppleChargerSrv.exe --&gt; system32\AppleChargerSrv.exe [?]<br />
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-10-29 136176]<br />
S3 GVTDrv64;GVTDrv64;C:\Windows\GVTDrv64.sys [2010-7-15 30528]<br />
S3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\system32\DRIVERS\netaapl64.sys --&gt; C:\Windows\system32\DRIVERS\netaapl64.sys [?]<br />
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]<br />
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --&gt; C:\Windows\system32\drivers\tsusbflt.sys [?]<br />
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --&gt; C:\Windows\system32\Wat\WatAdminSvc.exe [?]<br />
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\system32\DRIVERS\wdcsam64.sys --&gt; C:\Windows\system32\DRIVERS\wdcsam64.sys [?]<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2012-04-24 08:20:13    8917360    ----a-w-    C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{AD41572F-4138-410C-ADFA-0F5C5B632EC3}\mpengine.dll<br />
2012-04-19 12:21:00    8917360    ----a-w-    C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll<br />
2012-04-18 13:10:58    750488    ----a-w-    C:\Windows\System32\npdeployJava1.dll<br />
2012-04-18 13:10:58    660368    ----a-w-    C:\Windows\System32\deployJava1.dll<br />
2012-04-18 09:58:45    24904    ----a-w-    C:\Windows\System32\drivers\mbam.sys<br />
2012-04-18 09:58:45    --------    d-----w-    C:\ProgramData\Malwarebytes<br />
2012-04-18 07:40:38    --------    d-----w-    C:\ProgramData\Kaspersky Lab<br />
2012-04-18 07:40:38    --------    d-----w-    C:\Program Files (x86)\Kaspersky Lab<br />
2012-04-17 12:03:00    41184    ----a-w-    C:\Windows\avastSS.scr<br />
2012-04-17 08:28:19    --------    d-----w-    C:\ProgramData\AVAST Software<br />
2012-04-17 08:28:19    --------    d-----w-    C:\Program Files\AVAST Software<br />
2012-04-16 11:44:14    --------    d-----w-    C:\Users\BRYAN\AppData\Roaming\Malwarebytes<br />
2012-04-11 17:01:52    5559152    ----a-w-    C:\Windows\System32\ntoskrnl.exe<br />
2012-04-11 17:01:52    3968368    ----a-w-    C:\Windows\SysWow64\ntkrnlpa.exe<br />
2012-04-11 17:01:52    3913072    ----a-w-    C:\Windows\SysWow64\ntoskrnl.exe<br />
2012-04-11 17:00:27    81408    ----a-w-    C:\Windows\System32\imagehlp.dll<br />
2012-04-11 17:00:27    5120    ----a-w-    C:\Windows\SysWow64\wmi.dll<br />
2012-04-11 17:00:27    5120    ----a-w-    C:\Windows\System32\wmi.dll<br />
2012-04-11 17:00:27    23408    ----a-w-    C:\Windows\System32\drivers\fs_rec.sys<br />
2012-04-11 17:00:27    220672    ----a-w-    C:\Windows\System32\wintrust.dll<br />
2012-04-11 17:00:27    172544    ----a-w-    C:\Windows\SysWow64\wintrust.dll<br />
2012-04-11 17:00:27    159232    ----a-w-    C:\Windows\SysWow64\imagehlp.dll<br />
2012-04-10 11:35:40    --------    d-----w-    C:\Program Files\iTunes<br />
2012-04-10 11:35:40    --------    d-----w-    C:\Program Files\iPod<br />
2012-04-04 17:18:45    --------    d-----w-    C:\ProgramData\Battle.net<br />
2012-04-04 13:36:12    --------    d-----w-    C:\Program Files (x86)\Common Files\Blizzard Entertainment<br />
2012-03-26 15:41:34    103864    ----a-w-    C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll<br />
2012-03-26 15:41:34    103864    ----a-w-    C:\Program Files (x86)\Internet Explorer\Plugins\nppdf32.dll<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2012-04-25 05:53:31    25640    ----a-w-    C:\Windows\gdrv.sys<br />
2012-03-22 19:12:12    4435968    ----a-w-    C:\Windows\SysWow64\GPhotos.scr<br />
2012-03-05 07:23:36    414368    ----a-w-    C:\Windows\SysWow64\FlashPlayerCPLApp.cpl<br />
2012-02-28 06:39:37    1188864    ----a-w-    C:\Windows\System32\wininet.dll<br />
2012-02-28 05:38:52    981504    ----a-w-    C:\Windows\SysWow64\wininet.dll<br />
2012-02-28 04:31:38    1638912    ----a-w-    C:\Windows\System32\mshtml.tlb<br />
2012-02-28 03:52:27    1638912    ----a-w-    C:\Windows\SysWow64\mshtml.tlb<br />
2012-02-23 00:18:36    279656    ------w-    C:\Windows\System32\MpSigStub.exe<br />
2012-02-17 06:38:26    1031680    ----a-w-    C:\Windows\System32\rdpcore.dll<br />
2012-02-17 05:34:22    826880    ----a-w-    C:\Windows\SysWow64\rdpcore.dll<br />
2012-02-17 04:58:24    210944    ----a-w-    C:\Windows\System32\drivers\rdpwd.sys<br />
2012-02-17 04:57:32    23552    ----a-w-    C:\Windows\System32\drivers\tdtcp.sys<br />
2012-02-15 00:01:50    52736    ----a-w-    C:\Windows\System32\drivers\usbaapl64.sys<br />
2012-02-15 00:01:50    4547944    ----a-w-    C:\Windows\System32\usbaaplrc.dll<br />
2012-02-14 02:09:44    1070352    ----a-w-    C:\Windows\SysWow64\MSCOMCTL.OCX<br />
2012-02-10 06:36:07    1544192    ----a-w-    C:\Windows\System32\DWrite.dll<br />
2012-02-10 05:38:43    1077248    ----a-w-    C:\Windows\SysWow64\DWrite.dll<br />
2012-02-03 04:34:34    3145728    ----a-w-    C:\Windows\System32\win32k.sys<br />
.<br />
============= FINISH: 15:54:49.16 ===============</div>


	<br />
	<div style="padding:8px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://cdn.techsupportforum.com/forums/images/sk/attach/zip.gif" alt="File Type: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techsupportforum.com/forums/attachment.php?attachmentid=108562&amp;d=1335335947">Attach.zip</a> (4.4 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techsupportforum.com/forums/f284/">Inactive Malware Help Topics</category>
			<dc:creator>BL23</dc:creator>
			<guid isPermaLink="true">http://www.techsupportforum.com/forums/f284/qiwy-exe-running-at-startup-642327.html</guid>
		</item>
	</channel>
</rss>

