<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title><![CDATA[PC Help Forum - [In Progress] HiJackThis! Logs]]></title>
		<link>http://www.pchelpforum.com</link>
		<description>HJT logs that have been moved from the NEW logs forum and are being worked on by a Security Team Member</description>
		<language>en</language>
		<lastBuildDate>Sat, 21 Nov 2009 23:27:22 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>1</ttl>
		<image>
			<url>http://www.pchelpforum.com/images/styles/pchelpforum/misc/rss.jpg</url>
			<title><![CDATA[PC Help Forum - [In Progress] HiJackThis! Logs]]></title>
			<link>http://www.pchelpforum.com</link>
		</image>
		<item>
			<title>svchost.exe error - WinXP media ed.</title>
			<link>http://www.pchelpforum.com/progress-hijackthis-logs/80996-svchost-exe-error-winxp-media-ed.html</link>
			<pubDate>Sat, 21 Nov 2009 01:41:51 GMT</pubDate>
			<description><![CDATA[I've been troubleshooting this for a friend, tried several solutions without success, and I'm over my head at this point.  The svchost.exe file is...]]></description>
			<content:encoded><![CDATA[<div>I've been troubleshooting this for a friend, tried several solutions without success, and I'm over my head at this point.  The svchost.exe file is consuming memory over time, and multiple scvhost.exe run in processes..  The system slows down and crashed blue screen eventually when memory is all used. I've been able to recover and rehabilitate the PC somewhat but haven't solved the problem yet.   Any help would be great!!  Following is the DDS results. Attachment below, and OTL.txt was too large to attach so I made rar. Hope it helps....  Please let me know if more info I can offer, I think I followed the instructions well.  I'm new to the forum but glad to have found it!  Cheers!<br />
<br />
<br />
DDS (Ver_09-10-26.01) - NTFSx86 <br />
Run by sande waters at 16:25:38.60 on Fri 11/20/2009<br />
Internet Explorer: 8.0.6001.18702<br />
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.511.44 [GMT -8:00]<br />
<br />
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)   {17DDD097-36FF-435F-9E1B-52D74245D6BF}<br />
<br />
============== Running Processes ===============<br />
<br />
C:\WINDOWS\system32\svchost -k DcomLaunch<br />
svchost.exe<br />
C:\WINDOWS\System32\svchost.exe -k netsvcs<br />
svchost.exe<br />
svchost.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
svchost.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
C:\WINDOWS\system32\DVDRAMSV.exe<br />
C:\WINDOWS\eHome\ehRecvr.exe<br />
C:\WINDOWS\eHome\ehSched.exe<br />
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt<br />
C:\WINDOWS\System32\svchost.exe -k HPZ12<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\System32\svchost.exe -k HPZ12<br />
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe<br />
svchost.exe<br />
C:\WINDOWS\system32\svchost.exe -k imgsvc<br />
C:\WINDOWS\Explorer.EXE<br />
c:\TOSHIBA\Ivp\Swupdate\swupdtmr.exe<br />
C:\WINDOWS\system32\00THotkey.exe<br />
C:\WINDOWS\AGRSMMSG.exe<br />
C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
C:\WINDOWS\system32\dla\tfswctrl.exe<br />
C:\WINDOWS\ehome\ehtray.exe<br />
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE<br />
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
C:\Program Files\Microsoft IntelliPoint\point32.exe<br />
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe<br />
C:\toshiba\ivp\ism\pinger.exe<br />
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe<br />
C:\WINDOWS\system32\TFNF5.exe<br />
C:\Program Files\TOSHIBA\TOSHIBA Picture Enhancement Utility\TosPEHK.exe<br />
C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe<br />
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe<br />
C:\WINDOWS\system32\TPSMain.exe<br />
C:\Program Files\Toshiba\Tvs\TvsTray.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\WINDOWS\system32\TPSBattM.exe<br />
C:\WINDOWS\wt\updater\wcmdmgr.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe<br />
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe<br />
C:\WINDOWS\system32\RAMASST.exe<br />
C:\WINDOWS\system32\taskmgr.exe<br />
C:\WINDOWS\system32\svchost.exe -k HPService<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\WINDOWS\eHome\ehmsas.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Documents and Settings\sande waters\My Documents\Downloads\dds.scr<br />
<br />
============== Pseudo <acronym title="HijackThis - Malware Removal Tool">HJT</acronym> Report ===============<br />
<br />
uStart Page = hxxp://toshibadirect.com/<br />
uSearch Bar = hxxp://www.toshiba.com/search<br />
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/bin/search?p={searchTerms}<br />
uInternet Settings,ProxyOverride = localhost<br />
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll<br />
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll<br />
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 5.0\reader\activex\AcroIEHelper.ocx<br />
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll<br />
BHO: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search &amp; destroy\SDHelper.dll<br />
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll<br />
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll<br />
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll<br />
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll<br />
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File<br />
TB: {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No File<br />
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll<br />
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe<br />
uRun: [NBJ] &quot;c:\program files\ahead\nero backitup\NBJ.exe&quot;<br />
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search &amp; destroy\TeaTimer.exe<br />
uRun: [TOSCDSPD] c:\program files\toshiba\toscdspd\toscdspd.exe<br />
mRun: [000StTHK] 000StTHK.exe<br />
mRun: [00THotkey] c:\windows\system32\00THotkey.exe<br />
mRun: [AGRSMMSG] AGRSMMSG.exe<br />
mRun: [Apoint] c:\program files\apoint2k\Apoint.exe<br />
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe<br />
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe<br />
mRun: [ehTray] c:\windows\ehome\ehtray.exe<br />
mRun: [EM_EXEC] c:\progra~1\logitech\mousew~1\system\EM_EXEC.EXE<br />
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe<br />
mRun: [IntelliPoint] &quot;c:\program files\microsoft intellipoint\point32.exe&quot;<br />
mRun: [NDSTray.exe] NDSTray.exe<br />
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe<br />
mRun: [Notebook Maximizer] c:\program files\notebook maximizer\maximizer_startup.exe<br />
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup<br />
mRun: [nwiz] nwiz.exe /installquiet<br />
mRun: [PadTouch] c:\program files\toshiba\touch and launch\PadExe.exe<br />
mRun: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run<br />
mRun: [SoundMAX] c:\program files\analog devices\soundmax\Smax4.exe /tray<br />
mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe<br />
mRun: [TFNF5] TFNF5.exe<br />
mRun: [TOSHIBA Picture Enhancement Utility] c:\program files\toshiba\toshiba picture enhancement utility\TosPEHK.exe<br />
mRun: [TosHKCW.exe] &quot;c:\program files\toshiba\wireless hotkey\TosHKCW.exe&quot;<br />
mRun: [TouchED] c:\program files\toshiba\touched\TouchED.Exe<br />
mRun: [TPSMain] TPSMain.exe<br />
mRun: [Tvs] c:\program files\toshiba\tvs\TvsTray.exe<br />
mRun: [wcmdmgr] c:\windows\wt\updater\wcmdmgrl.exe -launch<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\dat  avi~1.lnk - c:\program files\common files\dataviz\DvzIncMsgr.exe<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hot  syn~1.lnk - c:\program files\palm\Hotsync.exe<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\<acronym title="Random Access Memory">ram</acronym>  asst.lnk - c:\windows\system32\RAMASST.exe<br />
IE: &amp;AOL Toolbar search - c:\program files\aol toolbar\toolbar.dll/SEARCH.HTML<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000<br />
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe<br />
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe<br />
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL<br />
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll<br />
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab<br />
DPF: {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab<br />
DPF: {FA13A9FA-CA9B-11D2-9780-00104B242EA3} - file://e:\games\WebDriverFullInstall.exe<br />
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL<br />
Notify: avgrsstarter - avgrsstx.dll<br />
LSA: Authentication Packages = msv1_0 nwprovau<br />
<br />
================= FIREFOX ===================<br />
<br />
FF - ProfilePath - c:\docume~1\sandew~1\applic~1\mozilla\firefox\prof  iles\0plav30z.default\<br />
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search<br />
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&amp;type=yahoo_avg_hs2-tb-web_us&amp;p=<br />
FF - component: c:\documents and settings\sande waters\application data\mozilla\firefox\profiles\0plav30z.default\ext  ensions\support@lastpass.com\platform\winnt_x86-msvc\components\lpxpcom.dll<br />
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll<br />
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\compone  nts\IGeared_tavgp_xputils2.dll<br />
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\compone  nts\IGeared_tavgp_xputils3.dll<br />
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\compone  nts\IGeared_tavgp_xputils35.dll<br />
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\compone  nts\xpavgtbapi.dll<br />
FF - plugin: c:\documents and settings\sande waters\application data\move networks\plugins\npqmp071505000010.dll<br />
FF - plugin: c:\program files\java\j2re1.4.2_05\bin\NPJava11.dll<br />
FF - plugin: c:\program files\java\j2re1.4.2_05\bin\NPJava12.dll<br />
FF - plugin: c:\program files\java\j2re1.4.2_05\bin\NPJava13.dll<br />
FF - plugin: c:\program files\java\j2re1.4.2_05\bin\NPJava14.dll<br />
FF - plugin: c:\program files\java\j2re1.4.2_05\bin\NPJava32.dll<br />
FF - plugin: c:\program files\java\j2re1.4.2_05\bin\NPJPI142_05.dll<br />
FF - plugin: c:\program files\java\j2re1.4.2_05\bin\NPOJI610.dll<br />
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll<br />
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\<br />
<br />
---- FIREFOX POLICIES ----<br />
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref(&quot;security.ssl3.rsa_seed_sha&quot;, true);<br />
<br />
============= SERVICES / DRIVERS ===============<br />
<br />
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-10-29 333192]<br />
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-10-29 360584]<br />
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2009-10-29 285392]<br />
R3 ttv200x;TOSHIBA PCI TV Tuner type W;c:\windows\system32\drivers\ttv200x.sys [2004-7-26 822656]<br />
S2 HPFECP13;HPFECP13;c:\windows\system32\drivers\HPFe  cp13.sys [1998-9-24 52800]<br />
<br />
=============== Created Last 30 ================<br />
<br />
<br />
==================== Find3M  ====================<br />
<br />
2009-11-12 01:14:31    2354    ----a-w-    c:\docume~1\sandew~1\applic~1\wklnhst.dat<br />
2009-10-08 22:57:02    611328    ----a-w-    c:\windows\system32\uiautomationcore.dll<br />
2009-10-08 22:57:00    220160    ----a-w-    c:\windows\system32\oleacc.dll<br />
2009-10-08 22:56:56    20480    ----a-w-    c:\windows\system32\oleaccrc.dll<br />
2009-09-11 14:18:39    136192    ----a-w-    c:\windows\system32\msv1_0.dll<br />
2009-09-04 21:03:36    58880    ----a-w-    c:\windows\system32\msasn1.dll<br />
2009-08-29 08:08:21    916480    ----a-w-    c:\windows\system32\wininet.dll<br />
2009-08-26 08:00:21    247326    ----a-w-    c:\windows\system32\strmdll.dll<br />
<br />
============= FINISH: 16:27:07.87 ===============<br />
<br />
<font size="4"><u><b>CHECKUP.TXT FROM SECURITY CHECK:</b></u></font><br />
 Results of screen317's Security Check version 0.99.0  <br />
 Windows XP Service Pack 3  <br />
<b>`````````````````````````````` <br />
<u>Antivirus/Firewall Check:</u></b> <br />
 Windows Firewall Enabled!  <br />
 AVG Free 9.0    <br />
 Antivirus up to date!  <br />
<b>`````````````````````````````` <br />
<u>Anti-malware/Other Utilities Check:</u></b> <br />
 <font color="red"><b>Out of date Spybot installed!</b></font> <br />
 Spybot - Search &amp; Destroy 1.4 <br />
 HijackThis 2.0.2    <br />
 CCleaner     <br />
 Java 2 Runtime Environment, SE v1.4.2_05 <br />
 Adobe Flash Player 10  <br />
<b>`````````````````````````````` <br />
Process Check:  <br />
<u>objlist.exe by Laurent</u></b> <br />
 AVG avgwdsvc.exe <br />
 AVG avgtray.exe <br />
 AVG avgrsx.exe <br />
 AVG avgnsx.exe <br />
 AVG avgemc.exe <br />
<b>``````````````````````````````<br />
<u>DNS Vulnerability Check:</u></b><br />
 GREAT! (Not vulnerable to DNS cache poisoning) <br />
<br />
<b>`````````End of Log```````````</b></div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/rar.gif" alt="File Type: rar" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/progress-hijackthis-logs/13881d1258766387-svchost-exe-error-winxp-media-ed-attach.rar">Attach.rar</a> (9.3 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/progress-hijackthis-logs/13883d1258766831-svchost-exe-error-winxp-media-ed-extras.txt" target="_blank">Extras.Txt</a> (54.7 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/rar.gif" alt="File Type: rar" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/progress-hijackthis-logs/13884d1258766904-svchost-exe-error-winxp-media-ed-otl.rar">OTL.rar</a> (11.1 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.pchelpforum.com/progress-hijackthis-logs/"><![CDATA[[In Progress] HiJackThis! Logs]]></category>
			<dc:creator>lbarkster</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/progress-hijackthis-logs/80996-svchost-exe-error-winxp-media-ed.html</guid>
		</item>
		<item>
			<title>Vista Slowing Down</title>
			<link>http://www.pchelpforum.com/progress-hijackthis-logs/80982-vista-slowing-down.html</link>
			<pubDate>Fri, 20 Nov 2009 20:00:37 GMT</pubDate>
			<description>Hi there 
I am new to this website and am having problems with something not sure what, my pc is using 100% cpu usage alot of the time and my email...</description>
			<content:encoded><![CDATA[<div>Hi there<br />
I am new to this website and am having problems with something not sure what, my pc is using 100% <acronym title="Central Processing Unit">cpu</acronym> usage alot of the time and my email program (yahoo) when writing will take a long time to display the letter written, it is like a lag time very annoying, pages dont want to respond when I scroll down, I have been thru the tips and tricks and turned off windows features run a defrag scanned for spyware, turned off windows defender and firewall and have avast, also have turned that off as well, but am still getting delayed response from my PC also having problems with internet speed really slow at times, contacted clearwire about problem and went thru troubleshooting, to some avail, but page load time is slow and delayed response in typing can you help??? I have run a HJ log and also a DDS where do I post this to get it analyzed?<br />
running vista basic w/ 80gig 45 free 2gigs <acronym title="Random Access Memory">ram</acronym> also everytime I boot my Bios has to be reset, changed the battery and that did not help???<br />
not sure what or how to delete personal info but if this could be kept priavate would sure appreciate it</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/zip.gif" alt="File Type: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/progress-hijackthis-logs/13872d1258747092-vista-slowing-down-hijackthislog2.zip">hijackthislog2.zip</a> (1.5 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/zip.gif" alt="File Type: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/progress-hijackthis-logs/13873d1258747092-vista-slowing-down-dds.zip">DDS.zip</a> (3.5 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/zip.gif" alt="File Type: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/progress-hijackthis-logs/13874d1258747696-vista-slowing-down-mbam-log-2009-11-20-09-37-55-.zip">mbam-log-2009-11-20 (09-37-55).zip</a> (486 Bytes)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.pchelpforum.com/progress-hijackthis-logs/"><![CDATA[[In Progress] HiJackThis! Logs]]></category>
			<dc:creator>reesemay</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/progress-hijackthis-logs/80982-vista-slowing-down.html</guid>
		</item>
		<item>
			<title>Please help...my computer is so slow</title>
			<link>http://www.pchelpforum.com/progress-hijackthis-logs/80955-please-help-my-computer-so-slow.html</link>
			<pubDate>Fri, 20 Nov 2009 03:21:18 GMT</pubDate>
			<description>My usual fast connection is going at a turtle speed.  My system hangs and crashes constantly.  This is my log...Please help me... I am not sure what...</description>
			<content:encoded><![CDATA[<div>My usual fast connection is going at a turtle speed.  My system hangs and crashes constantly.  This is my log...Please help me... I am not sure what to do..Any help would be appreciated<br />
 <br />
 <br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\WINDOWS\eHome\ehRecvr.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\ehome\ehtray.exe<br />
C:\WINDOWS\eHome\ehmsas.exe<br />
C:\Program Files\Digital Media Reader\readericon45G.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\WINDOWS\system32\RunDll32.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
C:\WINDOWS\system32\wbem\unsecapp.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\WINDOWS\system32\mmc.exe<br />
C:\WINDOWS\eHome\ehSched.exe<br />
C:\Documents and Settings\Owner.YOUR-9FA6C4D414\My Documents\Downloads\HijackThis.exe<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.yahoo.com/" target="_blank">Yahoo!</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <a href="http://www.gateway.com/g/sidepanel.html?Ch=Retail&amp;Br=EM&amp;Loc=ENG_US&amp;Sys=DTP&amp;M=W6409" target="_blank">http://www.gateway.com/g/sidepanel.h...ys=DTP&amp;M=W6409</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int  ernet Settings,ProxyOverride = *.local<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingle  Instance.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe<br />
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br />
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe<br />
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [CmPCIaudio] RunDll32 CMICNFG3.cpl,CMICtrlWnd<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall<br />
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] &quot;C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.ex  e&quot; -launchedbylogin<br />
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe /boot<br />
O4 - HKCU\..\Run: [Power2GoExpress] NA<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [iLike] C:\Program Files\iLike\1.2.16\ilikesidebar.exe /checkforupdate<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKCU\..\Run: [Messenger (Yahoo!)] &quot;C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.e  xe&quot; -quiet<br />
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')<br />
O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE<br />
O8 - Extra context menu item: &amp;Search - <a href="http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJman000" target="_blank">http://edits.mywebsearch.com/toolbar...tml?p=ZJman000</a><br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - <a href="http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.0.cab" target="_blank">http://dlm.tools.akamai.com/dlmanage...ex-2.2.5.0.cab</a><br />
O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - <a href="http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab" target="_blank">http://zone.msn.com/bingame/zpagames...1.cab60096.cab</a><br />
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - <a href="http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab" target="_blank">http://upload.facebook.com/controls/...Uploader55.cab</a><br />
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - <a href="http://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab" target="_blank">http://cdn2.zone.msn.com/binFramewor....cab102118.cab</a><br />
O20 - Winlogon Notify: RelevantKnowledge - c:\program files\relevantknowledge\rlls.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
--<br />
End of file - 7812 bytes</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/progress-hijackthis-logs/"><![CDATA[[In Progress] HiJackThis! Logs]]></category>
			<dc:creator>amberdtc</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/progress-hijackthis-logs/80955-please-help-my-computer-so-slow.html</guid>
		</item>
		<item>
			<title>Kis 2010</title>
			<link>http://www.pchelpforum.com/progress-hijackthis-logs/80952-kis-2010-a.html</link>
			<pubDate>Fri, 20 Nov 2009 02:06:42 GMT</pubDate>
			<description><![CDATA[Hi there, I'm back again with a brand new problem. 
 
I got my KIS2010 installed and AVG8.5 removed yesterday. 
 
I first installed KAV2010, then I...]]></description>
			<content:encoded><![CDATA[<div>Hi there, I'm back again with a brand new problem.<br />
<br />
I got my KIS2010 installed and AVG8.5 removed yesterday.<br />
<br />
I first installed KAV2010, then I found out that KIS2010 is more recommended then I changed to KIS2010.<br />
Everything when fine until I saw the warning I need to restart my computer in the upper part of KIS2010 (red thingy), I click on Fix, and then it asked me whether I wanted to restart the computer or not, I choose Yes.<br />
<br />
After quite a long moment the computer seemed to be not responding and finally I made my mind to press the restart button on the PC.<br />
<br />
Nothing went wrong until this part until the computer started up again, I clicked on the account as usual. But this time it's quite different, I can't see numbers of unread hotmail email (which you see below your account). After I clicked on it, a window appeared saying that the user can't be found, then a small window appeared on the top left of the screen saying something like the Initializing Desktop Themes, Initializing User Profiles (I don't really remember what it is, but it has something to do with Themes and User Profiles), after that it's something like starting up Microsoft Outlook, Windows Media Player, etc.<br />
<br />
After that part is finished, I'm very shocked to find out that my background has changed into the default background /themes. Also there are only 10 apps on the desktop ( no My Computer, My Documents ), when I tried to open My Document I can't find anything at all besides My Pictures and My Music but when I tried to look up at C : Document and Settings : diigikid  : diigikid's Document I can find everything there (in other words the files exist but I have to look it up again).<br />
This is all the problems I had with this.<br />
<br />
Now I tried uninstalling KIS 2010, but nothing good was done to my computer.<br />
I'm now using no antivirus and no internet security at the moment.<br />
<br />
Please Help!<br />
Thanks<br />
Regards,<br />
diigikid<br />
<br />
PS: I tried to look up at google and Kaps Lab and they said it's very common that your user files cannot be found a few times when you start up your computer, I tried to reboot and really it's just the same!<br />
Also the all the applications in the start menu are all missing, and replaced with the default from XP.<br />
Oh yeah, I lost the browser Google Chrome, and all the Bookmarks are gone...</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/progress-hijackthis-logs/13859d1258682234-kis-2010-attach.txt" target="_blank">Attach.txt</a> (5.6 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/progress-hijackthis-logs/13860d1258682234-kis-2010-dds.txt" target="_blank">dds.txt</a> (10.6 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.pchelpforum.com/progress-hijackthis-logs/"><![CDATA[[In Progress] HiJackThis! Logs]]></category>
			<dc:creator>diigikid</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/progress-hijackthis-logs/80952-kis-2010-a.html</guid>
		</item>
		<item>
			<title>My laptop seems to be unstable at times...</title>
			<link>http://www.pchelpforum.com/progress-hijackthis-logs/80930-my-laptop-seems-unstable-times.html</link>
			<pubDate>Thu, 19 Nov 2009 18:08:37 GMT</pubDate>
			<description>I had a trojan the other day that my Trend Micro could not fix so I downloaded spybot. That seem to fix a few things but it still acts a little...</description>
			<content:encoded><![CDATA[<div>I had a trojan the other day that my Trend Micro could not fix so I downloaded spybot. That seem to fix a few things but it still acts a little weird. So programs dont want to open and I just had to reinstalle TM. Also I cant seem to delete some files in my temp folder named- DF2ED8.tmp,DF3384.tmp,DFAE87.tmp,ppcrlui_4688_2,an  d one {EF7E931D-DC84-471B-8DB6-A83358095474. I have full admin right yet Im still blocked.<br />
<br />
Im really not sure what to look for now, and I would like to know if anything looks out of place.<br />
please any help would be nice. <br />
Thank you!<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 9:43:56 AM, on 11/19/2009<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18828)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Program Files (x86)\ASUS\Direct Console\DCHelper.exe<br />
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe<br />
C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe<br />
C:\Program Files (x86)\Skype\Phone\Skype.exe<br />
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe<br />
C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe<br />
C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe<br />
C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe<br />
C:\Program Files (x86)\ASUS\Direct Console\Direct Console.exe<br />
C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe<br />
C:\Program Files (x86)\Java\jre6\bin\jusched.exe<br />
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe<br />
C:\Program Files (x86)\Safari\Safari.exe<br />
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
F2 - REG:system.ini: UserInit=userinit.exe<br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll<br />
O3 - Toolbar: &amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll<br />
O4 - HKLM\..\Run: [CLMLServer] &quot;C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe&quot;<br />
O4 - HKLM\..\Run: [P2Go_Menu] &quot;C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.  exe&quot; &quot;C:\Program Files (x86)\CyberLink\Power2Go&quot; UpdateWithCreateOnce &quot;SOFTWARE\CyberLink\Power2Go\6.0&quot;<br />
O4 - HKLM\..\Run: [LoJackForLaptops] C:\Program Files (x86)\LFLInstall\InstallManager.exe /d60 /dd1 /bd0<br />
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe<br />
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe<br />
O4 - HKLM\..\Run: [ADSMTray] C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe<br />
O4 - HKLM\..\Run: [ATKMEDIA] &quot;C:\Program Files (x86)\ASUS\ATK Media\DMEDIA.EXE&quot;<br />
O4 - HKLM\..\Run: [DirectConsole2] C:\Program Files (x86)\ASUS\Direct Console\Direct Console.exe<br />
O4 - HKLM\..\Run: [MaxMenuMgr] &quot;C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files (x86)\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files (x86)\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [msnmsgr] &quot;C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe&quot; /background<br />
O4 - HKCU\..\Run: [Skype] &quot;C:\Program Files (x86)\Skype\Phone\Skype.exe&quot; /nosplash /minimized<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll<br />
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL<br />
O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe<br />
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)<br />
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe<br />
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspn  et_state.exe (file missing)<br />
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe<br />
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)<br />
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files (x86)\Seagate\SeagateManager\Sync\FreeAgentService  .exe<br />
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)<br />
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)<br />
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe<br />
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)<br />
O23 - Service: Remote Procedure Call (RPC) Net (rpcnet) - Absolute Software Corp. - C:\Windows\SysWOW64\rpcnet.exe<br />
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe<br />
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)<br />
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe<br />
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)<br />
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe<br />
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe<br />
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe<br />
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe<br />
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)<br />
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)<br />
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)<br />
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
<br />
--<br />
End of file - 10816 bytes</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/progress-hijackthis-logs/"><![CDATA[[In Progress] HiJackThis! Logs]]></category>
			<dc:creator>Lee84</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/progress-hijackthis-logs/80930-my-laptop-seems-unstable-times.html</guid>
		</item>
		<item>
			<title>Browser seems to be hijacked</title>
			<link>http://www.pchelpforum.com/progress-hijackthis-logs/80925-browser-seems-hijacked.html</link>
			<pubDate>Thu, 19 Nov 2009 17:32:03 GMT</pubDate>
			<description><![CDATA[I'm getting random tabs in firefox opening as this fake antivirus garbage and everyone in a while when I google something it redirects me to a spam...]]></description>
			<content:encoded><![CDATA[<div>I'm getting random tabs in firefox opening as this fake antivirus garbage and everyone in a while when I google something it redirects me to a spam page. Norton and Spybot do not detect anything either.<br />
<br />
Here is my hijackthis<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 11:23:59 AM, on 11/19/2009<br />
Platform: Windows Vista SP1 (WinNT 6.00.1905)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18828)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Program Files\DellTPad\Apoint.exe<br />
C:\Windows\OEM02Mon.exe<br />
C:\Windows\WindowsMobile\wmdc.exe<br />
C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe<br />
C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe<br />
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe<br />
C:\Program Files\Dell\MediaDirect\PCMService.exe<br />
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe<br />
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Program Files\Fingerprint Reader Suite\psqltray.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\DellSupport\DSAgnt.exe<br />
C:\Program Files\Dell DataSafe Online\Bin\DataSafeOnlineScheduler.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe<br />
C:\Program Files\Dell DataSafe Online\Bin\DataSafeOnlineTrayIcon.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe<br />
C:\Program Files\Dell\QuickSet\quickset.exe<br />
C:\Users\Craig\AppData\Local\Google\Update\1.2.183  .13\GoogleCrashHandler.exe<br />
C:\Program Files\DellTPad\HidFind.exe<br />
C:\Program Files\DellTPad\Apntex.exe<br />
C:\Program Files\Creative Live! Cam\VideoFX\StartFX.exe<br />
C:\Program Files\iTunes\iTunes.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\distnoted.exe<br />
C:\Windows\explorer.exe<br />
C:\Windows\System32\mobsync.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Users\Craig\Downloads\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int  ernet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll<br />
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\17.0.0.136\IPSBHO.DLL<br />
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br />
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\s  wg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe<br />
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe<br />
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe<br />
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe<br />
O4 - HKLM\..\Run: [VolPanel] &quot;C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe&quot; /r<br />
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE<br />
O4 - HKLM\..\Run: [PSQLLauncher] &quot;C:\Program Files\Fingerprint Reader Suite\launcher.exe&quot; /startup<br />
O4 - HKLM\..\Run: [DELL Webcam Manager] &quot;C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe&quot; /s<br />
O4 - HKLM\..\Run: [IAAnotif] &quot;C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe&quot;<br />
O4 - HKLM\..\Run: [ISUSScheduler] &quot;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&quot; -start<br />
O4 - HKLM\..\Run: [PCMService] &quot;C:\Program Files\Dell\MediaDirect\PCMService.exe&quot;<br />
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br />
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe<br />
O4 - HKLM\..\Run: [RoxWatchTray] &quot;C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe&quot;<br />
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe<br />
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKCU\..\Run: [DellSupport] &quot;C:\Program Files\DellSupport\DSAgnt.exe&quot; /startup<br />
O4 - HKCU\..\Run: [Dell DataSafe Scheduler] &quot;C:\Program Files\Dell DataSafe Online\Bin\DataSafeOnlineScheduler.exe&quot;<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [ISUSPM] &quot;C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe&quot; -scheduler<br />
O4 - HKCU\..\Run: [Google Update] &quot;C:\Users\Craig\AppData\Local\Google\Update\Google  Update.exe&quot; /c<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo  tifier.exe&quot;<br />
O4 - HKCU\..\Run: [BeyluxeMessenger] C:\Program Files\Beyluxe Messenger\Beyluxe Messenger.exe<br />
O4 - HKCU\..\Run: [AdobeUpdater6] &quot;C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe&quot;<br />
O4 - Global Startup: Bluetooth.lnk = ?<br />
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe<br />
O8 - Extra context menu item: &amp;Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm<br />
O8 - Extra context menu item: &amp;Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Send image to &amp;Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm<br />
O8 - Extra context menu item: Send page to &amp;Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll<br />
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll<br />
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe<br />
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll<br />
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe<br />
O23 - Service: Anonymizer Management Service (AnonMgmtSvc) - Anonymizer - C:\Program Files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe<br />
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\Windows\system32\CTsvcCDA.exe<br />
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe<br />
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Norton AntiVirus (NAV) - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\17.1.0.19\ccSvcHst.exe<br />
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe<br />
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br />
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe<br />
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe<br />
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe<br />
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe<br />
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe<br />
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe<br />
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe<br />
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe<br />
<br />
--<br />
End of file - 12549 bytes</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/progress-hijackthis-logs/"><![CDATA[[In Progress] HiJackThis! Logs]]></category>
			<dc:creator>azwethinkweizm</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/progress-hijackthis-logs/80925-browser-seems-hijacked.html</guid>
		</item>
		<item>
			<title><![CDATA[My com[puter is so sloooooooooowwww]]></title>
			<link>http://www.pchelpforum.com/progress-hijackthis-logs/80914-my-com-puter-so-sloooooooooowwww.html</link>
			<pubDate>Thu, 19 Nov 2009 13:07:07 GMT</pubDate>
			<description><![CDATA[Just looking to clean up all the junk that's accumulated on my home PC. It's so slow it's almost impossible to use. Can anybody help. Logs from...]]></description>
			<content:encoded><![CDATA[<div>Just looking to clean up all the junk that's accumulated on my home PC. It's so slow it's almost impossible to use. Can anybody help. Logs from Hijack This and Antimalwarebytes attached.<br />
Thanks,<br />
tune</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/progress-hijackthis-logs/13853d1258635996-my-com-puter-so-sloooooooooowwww-mbam-log-2009-11-18-07-58-15-.txt" target="_blank">mbam-log-2009-11-18 (07-58-15).txt</a> (3.1 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/progress-hijackthis-logs/13854d1258635996-my-com-puter-so-sloooooooooowwww-hijackthis.log_10.18.txt" target="_blank">hijackthis.log_10.18.txt</a> (8.9 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.pchelpforum.com/progress-hijackthis-logs/"><![CDATA[[In Progress] HiJackThis! Logs]]></category>
			<dc:creator>tuneguy</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/progress-hijackthis-logs/80914-my-com-puter-so-sloooooooooowwww.html</guid>
		</item>
		<item>
			<title>Machine running slower than a tortoise</title>
			<link>http://www.pchelpforum.com/progress-hijackthis-logs/80909-machine-running-slower-than-tortoise.html</link>
			<pubDate>Thu, 19 Nov 2009 10:34:27 GMT</pubDate>
			<description>I have an old machine that has suddenly started running like a snail.  I have hoovered the inside and generally tried toi smarten it up.  I have...</description>
			<content:encoded><![CDATA[<div>I have an old machine that has suddenly started running like a snail.  I have hoovered the inside and generally tried toi smarten it up.  I have added a 500Gbyte USB hard drive to store data but it really is just soooo slow.<br />
<br />
herewith the logs  I hope I have submitted the right one.  As a real old buffer some of the terminology is a bit beyond me and the kids are out!<br />
<br />
Cheers Old Buffer  #!#<br />
<br />
 Results of screen317's Security Check version 0.99.0  <br />
 Windows XP Service Pack 3  <br />
<b>`````````````````````````````` <br />
<u>Antivirus/Firewall Check:</u></b> <br />
 Windows Firewall Enabled!  <br />
 OneCare Advisor (Windows Live Toolbar)  <br />
 McAfee SecurityCenter     <br />
<b>`````````````````````````````` <br />
<u>Anti-malware/Other Utilities Check:</u></b> <br />
 Windows Defender    <br />
 Windows Defender Signatures   <br />
 CWShredder     <br />
 HijackThis 2.0.2    <br />
 CCleaner (remove only)   <br />
 Java(TM) 6 Update 15  <br />
 Java(TM) 6 Update 7  <br />
 <font color="red"><b>Out of date Java installed!</b></font> <br />
 Adobe Flash Player 10  <br />
Adobe Reader 7.1.0 <br />
<font color="red"><b>Out of date Adobe Reader installed!</b></font> <br />
<b>`````````````````````````````` <br />
Process Check:  <br />
<u>objlist.exe by Laurent</u></b> <br />
 Windows Defender MSMpEng.exe  <br />
<b>``````````````````````````````<br />
<u>DNS Vulnerability Check:</u></b><br />
 GREAT! (Not vulnerable to DNS cache poisoning) <br />
<br />
<br />
DDS (Ver_09-10-26.01) - NTFSx86  <br />
Run by Jane Jeremy at 10:11:23.57 on 19/11/2009<br />
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_15<br />
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.1023.238 [GMT 0:00]<br />
<br />
AV: McAfee VirusScan *On-access scanning enabled* (Updated)   {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}<br />
FW: McAfee Personal Firewall *enabled*   {94894B63-8C7F-4050-BDA4-813CA00DA3E8}<br />
<br />
============== Running Processes ===============<br />
<br />
C:\WINDOWS\system32\svchost -k DcomLaunch<br />
svchost.exe<br />
C:\Program Files\Windows Defender\MsMpEng.exe<br />
C:\WINDOWS\System32\svchost.exe -k netsvcs<br />
svchost.exe<br />
svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\system32\acs.exe<br />
svchost.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
svchost.exe<br />
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService  .exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Google\Update\GoogleUpdate.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Seagate\SeagateManager\Sync\MaxSync.exe<br />
C:\Program Files\Kontiki\KService.exe<br />
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
c:\program files\common files\mcafee\mna\mcnasvc.exe<br />
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
c:\PROGRA~1\mcafee.com\agent\mcagent.exe<br />
C:\Program Files\McAfee\MSK\MskSrver.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\System32\svchost.exe -k imgsvc<br />
C:\Program Files\inKline Global\PC Booster\pcbooster.exe<br />
C:\WINDOWS\system32\fxssvc.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe<br />
C:\WINDOWS\PixArt\PAC7302\Monitor.exe<br />
C:\WINDOWS\tsnp2std.exe<br />
C:\Program Files\Nimcard Software v3.0\BCRAutoDetect.exe<br />
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe<br />
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe<br />
C:\Program Files\TP-LINK\TWCU\TWCU.exe<br />
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe<br />
C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Skype\Phone\Skype.exe<br />
C:\WINDOWS\system32\taskmgr.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
C:\WINDOWS\System32\svchost.exe -k HTTPFilter<br />
C:\Program Files\Skype\Plugin Manager\skypePM.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
G:\Seagate\Data From D Drive\Data\HijackThis.exe<br />
D:\Data\Downloads\dds.scr<br />
<br />
============== Pseudo <acronym title="HijackThis - Malware Removal Tool">HJT</acronym> Report ===============<br />
<br />
uSearch Page = hxxp://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR<br />
uDefault_Page_URL = hxxp://www.sky.com<br />
uSearch Bar = hxxp://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR<br />
uStart Page = hxxp://www.sky.com<br />
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&amp;sourceid=ie7&amp;rls=com.micros  oft:en-US&amp;ie=utf8&amp;oe=utf8<br />
uWindow Title = Internet Explorer Provided By Sky Broadband<br />
uInternet Settings,ProxyOverride = *.local<br />
uSearchURL,(Default) = hxxp://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR<br />
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - <br />
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll<br />
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll<br />
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll<br />
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File<br />
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll<br />
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar2.dll<br />
BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll<br />
BHO: 1 (0x1) - No File<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll<br />
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
TB: &amp;Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll<br />
TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll<br />
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File<br />
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - <br />
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File<br />
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll<br />
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File<br />
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe<br />
uRun: [Skype] &quot;c:\program files\skype\phone\Skype.exe&quot; /nosplash /minimized<br />
uRun: [IDMan] c:\program files\internet download manager\IDMan.exe /onboot<br />
mRun: [UpdateManager] &quot;c:\program files\common files\sonic\update manager\sgtray.exe&quot; /r<br />
mRun: [PC Booster] c:\program files\inkline global\pc booster\pcbooster.exe<br />
mRun: [REGSHAVE] c:\program files\regshave\REGSHAVE.EXE /AUTORUN<br />
mRun: [Windows Defender] &quot;c:\program files\windows defender\MSASCui.exe&quot; -hide<br />
mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe<br />
mRun: [PAC7302_Monitor] c:\windows\pixart\pac7302\Monitor.exe<br />
mRun: [tsnp2std] c:\windows\tsnp2std.exe<br />
mRun: [HotCard Scanner Autodetect] c:\program files\nimcard software v3.0\BCRAutoDetect.exe<br />
mRun: [Adobe Photo Downloader] &quot;c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe&quot;<br />
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe<br />
mRun: [IndexSearch] &quot;c:\program files\scansoft\paperport\IndexSearch.exe&quot;<br />
mRun: [PPort11reminder] &quot;c:\program files\scansoft\paperport\ereg\ereg.exe&quot; -r &quot;c:\documents and settings\all users\application data\scansoft\paperport\11\config\ereg\Ereg.ini<br />
mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN<br />
mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun<br />
mRun: [mcagent_exe] &quot;c:\program files\mcafee.com\agent\mcagent.exe&quot; /runkey<br />
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
mRun: [TWCU] &quot;c:\program files\tp-link\twcu\TWCU.exe&quot; -nogui<br />
mRun: [QuickTime Task] &quot;c:\program files\quicktime\QTTask.exe&quot; -atboottime<br />
mRun: [iTunesHelper] &quot;c:\program files\itunes\iTunesHelper.exe&quot;<br />
mRun: [SunJavaUpdateSched] &quot;c:\program files\java\jre6\bin\jusched.exe&quot;<br />
mRun: [MaxMenuMgr] &quot;c:\program files\seagate\seagatemanager\freeagent status\StxMenuMgr.exe&quot;<br />
mRun: [McAfee Backup] &quot;c:\program files\mcafee\mbk\McAfeeDataBackup.exe&quot;<br />
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE<br />
dRun: [DWQueuedReporting] &quot;c:\progra~1\common~1\micros~1\dw\dwtrig20.exe  &quot; -t<br />
IE: &amp;Google Search - c:\program files\google\GoogleToolbar2.dll/cmsearch.html<br />
IE: &amp;Translate English Word - c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html<br />
IE: &amp;Windows Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm<br />
IE: Add to Windows &amp;Live Favorites - <a href="http://favorites.live.com/quickadd.aspx" target="_blank">Sign In</a><br />
IE: Backward Links - c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html<br />
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar2.dll/cmcache.html<br />
IE: Download All Links with IDM - c:\program files\internet download manager\IEGetAll.htm<br />
IE: Download with IDM - c:\program files\internet download manager\IEExt.htm<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000<br />
IE: Similar Pages - c:\program files\google\GoogleToolbar2.dll/cmsimilar.html<br />
IE: Translate Page into English - c:\program files\google\GoogleToolbar2.dll/cmtrans.html<br />
IE: {08E730A4-FB02-45BD-A900-01E4AD8016F6} - <a href="http://www.sky.com" target="_blank">Sky.com - your home for the latest news, sport and entertainment</a><br />
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe<br />
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL<br />
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll<br />
DPF: {00B71CFB-6864-4346-A978-C0A14556272C} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab28578.cab<br />
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab<br />
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab<br />
DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab<br />
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab<br />
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/3/9/8/398422c0-8d3e-40e1-a617-af65a72a0465/LegitCheckControl.cab<br />
DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab<br />
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc2.cab<br />
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://spaces.msn.com//PhotoUpload/MsnPUpld.cab<br />
DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cab<br />
DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab<br />
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1133602968281<br />
DPF: {79E0C1C0-316D-11D5-A72A-006097BFA1AC} - hxxp://esupport.epson-europe.com/selftest/en/Prg/ESTPTest.cab<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab<br />
DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} - hxxp://messenger.zone.msn.com/binary/MessengerStatsClient.cab28578.cab<br />
DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} - hxxp://support.euro.dell.com/global/apps/systemprofiler/PROFILER.CAB<br />
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://messenger.zone.msn.com/binary/ZIntro.cab32846.cab<br />
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab<br />
DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - hxxps://www-secure.symantec.com/techsupp/activedata/SymAData.dll<br />
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab<br />
DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} - hxxp://messenger.zone.msn.com/binary/Chess.cab31267.cab<br />
DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} - hxxps://www-secure.symantec.com/techsupp/activedata/ActiveData.cab<br />
DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} - hxxp://messenger.zone.msn.com/binary/SolitaireShowdown.cab28578.cab<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL<br />
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll<br />
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll<br />
<br />
================= FIREFOX ===================<br />
<br />
FF - ProfilePath - c:\docume~1\janeje~1\applic~1\mozilla\firefox\prof  iles\b3o3nllb.default\<br />
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&amp;ie=UTF-8&amp;oe=UTF-8&amp;q=<br />
FF - prefs.js: browser.search.selectedEngine - Google<br />
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.d  ll<br />
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}<br />
<br />
---- FIREFOX POLICIES ----<br />
FF - user.js: dom.disable_open_during_load - true // Popupblocker control handled by McAfee Privacy Service<br />
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref(&quot;security.ssl3.rsa_seed_sha&quot;, true);<br />
<br />
============= SERVICES / DRIVERS ===============<br />
<br />
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\seagate\seagatemanager\sync\FreeAgentService  .exe [2009-9-25 189736]<br />
R3 PAC7302;PC VGA Camer@ Plus;c:\windows\system32\drivers\PAC7302.SYS [2007-9-10 457984]<br />
S2 Ca50xav;Digital Blue DMC2 Video Device;c:\windows\system32\drivers\Ca50xav.sys [2005-8-30 583670]<br />
S2 gupdate1c9dd2e2a047e4;Google Update Service (gupdate1c9dd2e2a047e4);c:\program files\google\update\GoogleUpdate.exe [2009-5-25 133104]<br />
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2009-2-9 33752]<br />
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2008-7-14 13352]<br />
S3 jbridgep;jbridgep;\??\c:\docume~1\janeje~1\locals~  1\temp\jbridgep.sys --&gt; c:\docume~1\janeje~1\locals~1\temp\jbridgep.sys [?]<br />
S3 sea1bus;Sony Ericsson Device 0A1 driver (WDM);c:\windows\system32\drivers\sea1bus.sys [2008-1-5 61536]<br />
S3 sea1mdfl;Sony Ericsson Device 0A1 USB WMC Modem Filter;c:\windows\system32\drivers\sea1mdfl.sys [2008-1-5 9360]<br />
S3 sea1mdm;Sony Ericsson Device 0A1 USB WMC Modem Driver;c:\windows\system32\drivers\sea1mdm.sys [2008-1-5 97088]<br />
S3 sea1mgmt;Sony Ericsson Device 0A1 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\sea1mgmt.sys [2008-1-5 88624]<br />
S3 sea1nd5;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (NDIS);c:\windows\system32\drivers\sea1nd5.sys [2008-1-5 18704]<br />
S3 sea1obex;Sony Ericsson Device 0A1 USB WMC OBEX Interface;c:\windows\system32\drivers\sea1obex.sys [2008-1-5 86432]<br />
S3 sea1unic;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (WDM);c:\windows\system32\drivers\sea1unic.sys [2008-1-5 90800]<br />
S3 usb2vcom;USB Data Cable;c:\windows\system32\drivers\usb2vcom.sys [2005-12-30 22760]<br />
S3 USBCamera;Digital Blue DMC2 Still Camera;c:\windows\system32\drivers\Bulk50x.sys [2005-8-1 10986]<br />
S3 VC4CB104;USB PC Camera;c:\windows\system32\drivers\VC4CB104.SYS [2005-12-29 81924]<br />
S4 0001551254044271mcinstcleanup;McAfee Application Installer Cleanup (0001551254044271);c:\windows\temp\000155~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service --&gt; c:\windows\temp\000155~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service [?]<br />
<br />
=============== Created Last 30 ================<br />
<br />
2009-11-15 20:44:34    3249    ----a-w-    c:\windows\system32\wbem\Outlook_01ca66346fe85e74.  mof<br />
2009-10-24 19:19:05    0    d-----w-    c:\docume~1\alluse~1\applic~1\GARMIN<br />
2009-10-24 19:18:54    0    d-----w-    C:\Garmin<br />
2009-10-23 12:24:44    0    d-----w-    c:\program files\Seagate<br />
2009-10-23 12:24:44    0    d-----w-    c:\docume~1\alluse~1\applic~1\Seagate<br />
<br />
==================== Find3M  ====================<br />
<br />
2009-11-02 20:42:06    195456    ------w-    c:\windows\system32\MpSigStub.exe<br />
2009-10-22 09:19:04    5939712    ----a-w-    c:\windows\system32\dllcache\mshtml.dll<br />
2009-09-11 14:18:39    136192    ----a-w-    c:\windows\system32\msv1_0.dll<br />
2009-09-11 14:18:39    136192    ------w-    c:\windows\system32\dllcache\msv1_0.dll<br />
2009-09-04 21:03:36    58880    ----a-w-    c:\windows\system32\msasn1.dll<br />
2009-09-04 21:03:36    58880    ------w-    c:\windows\system32\dllcache\msasn1.dll<br />
2009-08-28 10:35:52    173056    ----a-w-    c:\windows\system32\dllcache\ie4uinit.exe<br />
2009-08-27 18:01:44    921632    ----a-w-    C:\PA7302.DAT<br />
2009-08-26 08:00:21    247326    ----a-w-    c:\windows\system32\strmdll.dll<br />
2009-08-26 08:00:21    247326    ------w-    c:\windows\system32\dllcache\strmdll.dll<br />
2006-07-12 09:51:43    2599840    ----a-w-    c:\program files\Windows-KB890830-V1.18.exe<br />
2003-12-12 22:07:48    24048571    ----a-w-    c:\program files\nero6300.exe<br />
2003-12-12 22:06:20    1092473    ----a-w-    c:\program files\NBR6300sve.exe<br />
2003-12-10 16:59:56    29    -c--a-w-    c:\program files\Serial.txt<br />
2007-03-03 18:58:50    770491    --sha-w-    c:\windows\system32\uttss.bak1<br />
2007-03-10 00:01:42    774355    --sha-w-    c:\windows\system32\uttss.bak2<br />
<br />
============= FINISH: 10:14:07.50 ===============<br />
<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 10:30:38, on 19/11/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Windows Defender\MsMpEng.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\system32\acs.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService  .exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Google\Update\GoogleUpdate.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Seagate\SeagateManager\Sync\MaxSync.exe<br />
C:\Program Files\Kontiki\KService.exe<br />
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
c:\program files\common files\mcafee\mna\mcnasvc.exe<br />
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
c:\PROGRA~1\mcafee.com\agent\mcagent.exe<br />
C:\Program Files\McAfee\MSK\MskSrver.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\inKline Global\PC Booster\pcbooster.exe<br />
C:\WINDOWS\system32\fxssvc.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe<br />
C:\WINDOWS\PixArt\PAC7302\Monitor.exe<br />
C:\WINDOWS\tsnp2std.exe<br />
C:\Program Files\Nimcard Software v3.0\BCRAutoDetect.exe<br />
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe<br />
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe<br />
C:\Program Files\TP-LINK\TWCU\TWCU.exe<br />
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe<br />
C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Skype\Phone\Skype.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Skype\Plugin Manager\skypePM.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\PROGRA~1\MICROS~3\OFFICE11\OUTLOOK.EXE<br />
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE<br />
G:\Seagate\Data From D Drive\Data\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://www.sky.com" target="_blank">Sky.com - your home for the latest news, sport and entertainment</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR" target="_blank">Bing</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR" target="_blank">Bing</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.sky.com" target="_blank">Sky.com - your home for the latest news, sport and entertainment</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = <a href="http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR" target="_blank">Bing</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided By Sky Broadband<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int  ernet Settings,ProxyOverride = *.local<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll<br />
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll<br />
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: &amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll<br />
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll<br />
O4 - HKLM\..\Run: [UpdateManager] &quot;C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe&quot; /r<br />
O4 - HKLM\..\Run: [PC Booster] C:\Program Files\inKline Global\PC Booster\pcbooster.exe<br />
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN<br />
O4 - HKLM\..\Run: [Windows Defender] &quot;C:\Program Files\Windows Defender\MSASCui.exe&quot; -hide<br />
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe<br />
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe<br />
O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe<br />
O4 - HKLM\..\Run: [HotCard Scanner Autodetect] C:\Program Files\Nimcard Software v3.0\BCRAutoDetect.exe<br />
O4 - HKLM\..\Run: [Adobe Photo Downloader] &quot;C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe&quot;<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [IndexSearch] &quot;C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe&quot;<br />
O4 - HKLM\..\Run: [PPort11reminder] &quot;C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe&quot; -r &quot;C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini<br />
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN<br />
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun<br />
O4 - HKLM\..\Run: [mcagent_exe] &quot;C:\Program Files\McAfee.com\Agent\mcagent.exe&quot; /runkey<br />
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
O4 - HKLM\..\Run: [TWCU] &quot;C:\Program Files\TP-LINK\TWCU\TWCU.exe&quot; -nogui<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [MaxMenuMgr] &quot;C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe&quot;<br />
O4 - HKLM\..\Run: [McAfee Backup] &quot;C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe&quot;<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [Skype] &quot;C:\Program Files\Skype\Phone\Skype.exe&quot; /nosplash /minimized<br />
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] &quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe  &quot; -t (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')<br />
O8 - Extra context menu item: &amp;Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html<br />
O8 - Extra context menu item: &amp;Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html<br />
O8 - Extra context menu item: &amp;Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm<br />
O8 - Extra context menu item: Add to Windows &amp;Live Favorites - <a href="http://favorites.live.com/quickadd.aspx" target="_blank">Sign In</a><br />
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html<br />
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html<br />
O8 - Extra context menu item: Download All Links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm<br />
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html<br />
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html<br />
O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - <a href="http://www.sky.com" target="_blank">Sky.com - your home for the latest news, sport and entertainment</a> (file missing)<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - <a href="http://messenger.zone.msn.com/binary/msgrchkr.cab28578.cab" target="_blank">http://messenger.zone.msn.com/binary...r.cab28578.cab</a><br />
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - <a href="http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab" target="_blank">http://messenger.zone.msn.com/binary...t.cab31267.cab</a><br />
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - <a href="http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab" target="_blank">http://messenger.zone.msn.com/binary...r.cab31267.cab</a><br />
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - <a href="http://spaces.msn.com//PhotoUpload/MsnPUpld.cab" target="_blank">http://spaces.msn.com//PhotoUpload/MsnPUpld.cab</a><br />
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - <a href="http://upload.facebook.com/controls/FacebookPhotoUploader.cab" target="_blank">http://upload.facebook.com/controls/...toUploader.cab</a><br />
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - <a href="http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab" target="_blank">http://security.symantec.com/sscv6/S.../bin/cabsa.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1133602968281" target="_blank">http://update.microsoft.com/microsof...?1133602968281</a><br />
O16 - DPF: {79E0C1C0-316D-11D5-A72A-006097BFA1AC} (EPSON Web Printer-SelfTest Control Class) - <a href="http://esupport.epson-europe.com/selftest/en/Prg/ESTPTest.cab" target="_blank">http://esupport.epson-europe.com/sel...g/ESTPTest.cab</a><br />
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - <a href="http://messenger.zone.msn.com/binary/MessengerStatsClient.cab28578.cab" target="_blank">http://messenger.zone.msn.com/binary...t.cab28578.cab</a><br />
O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - <a href="http://support.euro.dell.com/global/apps/systemprofiler/PROFILER.CAB" target="_blank">http://support.euro.dell.com/global/...r/PROFILER.CAB</a><br />
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - <a href="http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab" target="_blank">http://messenger.zone.msn.com/binary...o.cab32846.cab</a><br />
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - <a href="https://www-secure.symantec.com/techsupp/activedata/SymAData.dll" target="_blank">https://www-secure.symantec.com/tech...a/SymAData.dll</a><br />
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - <a href="http://messenger.zone.msn.com/binary/Chess.cab31267.cab" target="_blank">http://messenger.zone.msn.com/binary/Chess.cab31267.cab</a><br />
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - <a href="https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab" target="_blank">https://www-secure.symantec.com/tech...ActiveData.cab</a><br />
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - <a href="http://messenger.zone.msn.com/binary/SolitaireShowdown.cab28578.cab" target="_blank">http://messenger.zone.msn.com/binary...n.cab28578.cab</a><br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O23 - Service: TP-LINK Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Crypkey License - Unknown owner - crypserv.exe (file missing)<br />
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService  .exe<br />
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe<br />
O23 - Service: Google Update Service (gupdate1c9dd2e2a047e4) (gupdate1c9dd2e2a047e4) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe<br />
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe<br />
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe<br />
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe<br />
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe<br />
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe<br />
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
<br />
--<br />
End of file - 14650 bytes<br />
<br />
<br />
<b>`````````End of Log```````````</b></div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/progress-hijackthis-logs/13849d1258626575-machine-running-slower-than-tortoise-attach.txt" target="_blank">Attach.txt</a> (14.0 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.pchelpforum.com/progress-hijackthis-logs/"><![CDATA[[In Progress] HiJackThis! Logs]]></category>
			<dc:creator>Old Buffer</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/progress-hijackthis-logs/80909-machine-running-slower-than-tortoise.html</guid>
		</item>
		<item>
			<title>Does this look infected?</title>
			<link>http://www.pchelpforum.com/progress-hijackthis-logs/80896-does-look-infected.html</link>
			<pubDate>Thu, 19 Nov 2009 01:31:01 GMT</pubDate>
			<description><![CDATA[Hello, 
I've never posted to this or any other forum, ::) , really, I hope I'm doing this right. While my computer is running verry slow lately my...]]></description>
			<content:encoded><![CDATA[<div>Hello,<br />
I've never posted to this or any other forum, ::) , really, I hope I'm doing this right. While my computer is running verry slow lately my hard drive sounds at times like it it is at maximum RPM and making popcorn on the side. I did a free scan with Norton Security Scan and it turned up koobface!gen and mhbupd32.exe. <br />
Here is the pre-work I hope,<br />
Thank you,<br />
<br />
DDS (Ver_09-10-26.01) - NTFSx86  <br />
Run by Owner at 19:45:44.96 on Wed 11/18/2009<br />
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17<br />
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.503.218 [GMT -5:00]<br />
<br />
============== Running Processes ===============<br />
C:\WINDOWS\system32\svchost -k DcomLaunch<br />
svchost.exe<br />
C:\WINDOWS\System32\svchost.exe -k netsvcs<br />
svchost.exe<br />
svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe<br />
C:\Program Files\Digital Media Reader\shwiconem.exe<br />
C:\WINDOWS\SOUNDMAN.EXE<br />
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe<br />
C:\Program Files\Common Files\SolidWorks Installation Manager\Scheduler\sldIMScheduler.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\Program Files\Verizon\McciTrayApp.exe<br />
C:\WINDOWS\ALCWZRD.EXE<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Messenger\msmsgs.exe<br />
svchost.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\WINDOWS\System32\svchost.exe -k HTTPFilter<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\Motive\McciCMService.exe<br />
C:\WINDOWS\system32\HPZipm12.exe<br />
C:\WINDOWS\system32\svchost.exe -k imgsvc<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
C:\Program Files\Logitech\SetPoint\SetPoint.exe<br />
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
svchost<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Documents and Settings\Owner\Desktop\dds2.pif<br />
============== Pseudo <acronym title="HijackThis - Malware Removal Tool">HJT</acronym> Report ===============<br />
uStart Page = hxxp://www.google.com/<br />
uInternet Connection Wizard,ShellNext = hxxp://www.gateway.com/<br />
uInternet Settings,ProxyOverride = *.local<br />
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File<br />
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll<br />
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll<br />
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
TB: AOL Toolbar: {4982d40a-c53b-4615-b15b-b5b5e98d167c} - <br />
TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll<br />
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File<br />
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File<br />
uRun: [MSMSGS] &quot;c:\program files\messenger\msmsgs.exe&quot; /background<br />
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe<br />
uRun: [WAB] c:\documents and settings\owner\application data\macromedia\common\862a004c19.exe<br />
uRun: [rundll32.exe] <br />
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe<br />
mRun: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe<br />
mRun: [RemoteControl] c:\program files\cyberlink\powerdvd\PDVDServ.exe<br />
mRun: [CHotkey] zHotkey.exe<br />
mRun: [ShowWnd] ShowWnd.exe<br />
mRun: [SunKistEM] c:\program files\digital media reader\shwiconem.exe<br />
mRun: [SoundMan] SOUNDMAN.EXE<br />
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe<br />
mRun: [Microsoft Works Update Detection] c:\program files\common files\microsoft shared\works shared\WkUFind.exe<br />
mRun: [SolidWorks_CheckForUpdates] &quot;c:\program files\common files\solidworks installation manager\scheduler\sldIMScheduler.exe&quot; /scheduler<br />
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE<br />
mRun: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE<br />
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe<br />
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe<br />
mRun: [Persistence] c:\windows\system32\igfxpers.exe<br />
mRun: [Verizon_McciTrayApp] &quot;c:\program files\verizon\McciTrayApp.exe&quot;<br />
mRun: [AlcWzrd] ALCWZRD.EXE<br />
mRun: [Alcmtr] ALCMTR.EXE<br />
mRun: [QuickTime Task] &quot;c:\program files\quicktime\qttask.exe&quot; -atboottime<br />
mRun: [iTunesHelper] &quot;c:\program files\itunes\iTunesHelper.exe&quot;<br />
mRun: [Malwarebytes Anti-Malware (reboot)] &quot;c:\program files\malwarebytes' anti-malware\mbam.exe&quot; /runcleanupscript<br />
mRun: [TkBellExe] &quot;c:\program files\common files\real\update_ob\realsched.exe&quot;  -osboot<br />
mRun: [Kxufuqicacepe] rundll32.exe &quot;c:\windows\ihibupic.dll&quot;,Startup<br />
dRun: [DWQueuedReporting] &quot;c:\progra~1\common~1\micros~1\dw\dwtrig20.exe  &quot; -t<br />
StartupFolder: c:\documents and settings\owner\start menu\programs\startup\mhbupd32.exe<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ado  ber~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\log  ite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe<br />
uPolicies-explorer: NoThemesTab = 0 (0x0)<br />
uPolicies-system: EnableProfileQuota = 1 (0x1)<br />
IE: &amp;AOL Toolbar search - c:\program files\aol toolbar\toolbar.dll/SEARCH.HTML<br />
IE: Easy-WebPrint Add To Print List - c:\program files\canon\easy-webprint\Resource.dll/RC_AddToList.html<br />
IE: Easy-WebPrint High Speed Print - c:\program files\canon\easy-webprint\Resource.dll/RC_HSPrint.html<br />
IE: Easy-WebPrint Preview - c:\program files\canon\easy-webprint\Resource.dll/RC_Preview.html<br />
IE: Easy-WebPrint Print - c:\program files\canon\easy-webprint\Resource.dll/RC_Print.html<br />
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}<br />
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe<br />
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe<br />
IE: {4982D40A-C53B-4615-B15B-B5B5E98D167C} - {4982D40A-C53B-4615-B15B-B5B5E98D167C}<br />
DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxps://activatemyfios.verizon.net/sdcCommon/download/FIOS/Verizon%20FiOS%20Installer.cab<br />
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab<br />
DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://download.ewido.net/ewidoOnlineScan.cab<br />
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll<br />
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab<br />
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB<br />
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab<br />
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1229126398437<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab<br />
DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_03-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab<br />
Notify: igfxcui - igfxdev.dll<br />
Notify: LBTWlgn - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll<br />
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll<br />
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll<br />
LSA: Notification Packages = scecli alapdfgw.dll<br />
============= SERVICES / DRIVERS ===============<br />
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-11-5 64288]<br />
R1 cdrblock;cdrblock;c:\windows\system32\drivers\cdrb  lock.sys [2009-11-6 20864]<br />
R1 cdrport;cdrport;c:\windows\system32\drivers\cdrpor  t.sys [2009-11-6 4608]<br />
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-9-24 1179232]<br />
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\solidworks corp\solidworks\swscheduler\DTSCoordinatorService.  exe [2009-7-29 83240]<br />
S3 MLFILEM;MLFILEM;\??\c:\windows\system32\drivers\ml  filem.sys --&gt; c:\windows\system32\drivers\MLFILEM.SYS [?]<br />
S3 PTDUBus;PANTECH UM175 Composite Device Driver ;c:\windows\system32\drivers\PTDUBus.sys [2008-12-5 29824]<br />
S3 PTDUMdm;PANTECH UM175 Drivers;c:\windows\system32\drivers\PTDUMdm.sys [2008-12-5 41344]<br />
S3 PTDUVsp;PANTECH UM175 Diagnostic Port;c:\windows\system32\drivers\PTDUVsp.sys [2008-12-5 39936]<br />
S3 PTDUWWAN;PANTECH UM175 WWAN Driver;c:\windows\system32\drivers\PTDUWWAN.sys [2008-12-5 59776]<br />
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\microsoft visual studio 8\common7\ide\remote debugger\x86\msvsmon.exe [2005-9-23 2799808]<br />
=============== Created Last 30 ================<br />
2009-11-18 02:43:09 0 d-----w- c:\windows\system32\drivers\NSS<br />
2009-11-18 02:43:08 0 d-----w- c:\program files\Norton Security Scan<br />
2009-11-18 02:43:08 0 d-----w- c:\docume~1\alluse~1\applic~1\Norton<br />
2009-11-18 02:43:06 0 d-----w- c:\program files\NortonInstaller<br />
2009-11-18 02:43:06 0 d-----w- c:\docume~1\alluse~1\applic~1\NortonInstaller<br />
2009-11-17 23:42:03 0 d-----w- c:\windows\system32\Adobe<br />
2009-11-17 00:24:05 0 d-----w- c:\docume~1\owner\applic~1\MozillaControl<br />
2009-11-17 00:23:52 0 d-----w- c:\program files\Mozilla ActiveX Control v1.7.12<br />
2009-11-17 00:23:09 0 d-----w- c:\program files\VideoLAN<br />
2009-11-17 00:23:02 0 d-----w- c:\program files\Graboid<br />
2009-11-14 16:55:16 0 d-----w- C:\v2d<br />
2009-11-12 16:45:53 104448 ----a-w- c:\windows\msacm32.drv<br />
2009-11-12 16:45:53 102 ----a-w- c:\windows\wuasirvy.dll<br />
2009-11-11 05:13:30 28 ----a-w- c:\windows\v2d.INI<br />
2009-11-10 23:32:34 0 d-----w- c:\program files\Total Video2Dvd<br />
2009-11-10 23:24:20 103 ----a-w- c:\windows\canopus.ini<br />
2009-11-08 22:56:49 0 d-----w- C:\New Folder<br />
2009-11-08 22:54:45 0 d-----w- c:\docume~1\owner\applic~1\Canopus<br />
2009-11-08 22:52:43 53760 -c--a-w- c:\windows\system32\dllcache\vfwwdm32.dll<br />
2009-11-06 22:21:34 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll<br />
2009-11-06 22:20:32 33 ----a-w- c:\windows\system32\cnpsedufet4b.EXT<br />
2009-11-06 22:20:32 0 d-----w- c:\docume~1\alluse~1\applic~1\Canopus<br />
2009-11-06 22:19:56 0 d-----w- c:\program files\Canopus<br />
2009-11-06 22:19:55 798801 ----a-w- c:\windows\system32\cseuvec.dll<br />
2009-11-06 22:19:55 122880 ----a-w- c:\windows\system32\icmpeg2.dll<br />
2009-11-06 22:19:55 1085520 ----a-w- c:\windows\system32\csedvh.dll<br />
2009-11-06 22:19:55 0 d-----w- c:\program files\common files\Canopus Shared<br />
2009-11-06 22:19:54 0 d-----w- c:\program files\MSXML 4.0<br />
2009-11-06 22:18:58 693760 ----a-w- c:\windows\system32\drivers\hardlock.sys<br />
2009-11-06 22:18:30 65536 ----a-w- c:\windows\system32\MFC71DEU.DLL<br />
2009-11-06 22:18:30 61440 ----a-w- c:\windows\system32\MFC71ITA.DLL<br />
2009-11-06 22:18:30 61440 ----a-w- c:\windows\system32\MFC71FRA.DLL<br />
2009-11-06 22:18:30 57344 ----a-w- c:\windows\system32\MFC71ENU.DLL<br />
2009-11-06 22:18:30 49152 ----a-w- c:\windows\system32\MFC71JPN.DLL<br />
2009-11-06 22:18:30 45056 ----a-w- c:\windows\system32\MFC71CHT.DLL<br />
2009-11-06 22:18:30 40960 ----a-w- c:\windows\system32\MFC71CHS.DLL<br />
2009-11-06 22:16:23 909312 ------w- c:\windows\system32\pavplal.dll<br />
2009-11-06 22:16:23 57344 ----a-w- c:\windows\system32\pavedius4db.dll<br />
2009-11-06 22:16:23 57344 ------w- c:\windows\system32\pavedius.dll<br />
2009-11-06 22:16:23 458752 ------w- c:\windows\system32\pavapi.dll<br />
2009-11-06 22:16:23 4096 ------w- c:\windows\system32\paveno.dll<br />
2009-11-05 21:24:37 15880 ----a-w- c:\windows\system32\lsdelete.exe<br />
2009-11-05 20:29:38 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys<br />
2009-11-05 20:29:22 93360 ----a-w- c:\windows\system32\drivers\SBREDrv.sys<br />
2009-11-05 20:27:42 0 dc-h--w- c:\docume~1\alluse~1\applic~1\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}<br />
2009-11-05 20:07:15 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys<br />
2009-11-05 20:07:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys<br />
2009-11-05 17:40:21 2 ----a-w- c:\windows\msoffice.ini<br />
2009-11-05 17:02:08 36 ----a-w- c:\windows\rasqervy.dll<br />
2009-11-05 17:01:58 8 ----a-w- c:\windows\sdfinacs.dll<br />
2009-11-05 17:00:34 5 ----a-w- c:\windows\sdfixwcs.dll<br />
2009-11-05 02:19:48 120 ----a-w- c:\windows\Apeximudu.dat<br />
2009-11-05 02:19:48 0 ----a-w- c:\windows\Kqesipe.bin<br />
==================== Find3M  ====================<br />
2009-10-11 09:17:27 411368 ----a-w- c:\windows\system32\deploytk.dll<br />
2009-10-02 18:07:23 103720 ----a-w- c:\documents and settings\owner\GoToAssistDownloadHelper.exe<br />
2009-09-11 14:18:39 136192 ----a-w- c:\windows\system32\msv1_0.dll<br />
2009-09-04 21:03:36 58880 ----a-w- c:\windows\system32\msasn1.dll<br />
2009-08-29 08:08:21 916480 ----a-w- c:\windows\system32\wininet.dll<br />
2009-08-26 08:00:21 247326 ----a-w- c:\windows\system32\strmdll.dll<br />
2005-03-29 22:56:11 2417824 ----a-w- c:\program files\winzip90.exe<br />
2008-12-12 23:51:08 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008121220081  213\index.dat<br />
============= FINISH: 19:47:06.23 ===============<br />
 Results of screen317's Security Check version 0.99.0  <br />
 Windows XP Service Pack 3  <br />
<b>`````````````````````````````` <br />
<u>Antivirus/Firewall Check:</u></b> <br />
 <font color="red"><b>Windows Security Center service is not running! This report may not be accurate!</b></font> <br />
 Windows Firewall Disabled!  <br />
<b>`````````````````````````````` <br />
<u>Anti-malware/Other Utilities Check:</u></b> <br />
 Ad-Aware <br />
 Java Web Start   <br />
 Java(TM) 6 Update 17  <br />
 Java 2 Runtime Environment, SE v1.4.2 <br />
 <font color="red"><b>Out of date Java installed!</b></font> <br />
 Adobe Flash Player 10  <br />
Adobe Reader 7.0 <br />
<font color="red"><b>Out of date Adobe Reader installed!</b></font> <br />
<b>`````````````````````````````` <br />
Process Check:  <br />
<u>objlist.exe by Laurent</u></b> <br />
 <font color="red"><b>Ad-Aware AAWService.exe is disabled!</b></font> <br />
 <font color="red"><b>Ad-Aware AAWTray.exe is disabled!</b></font> <br />
<b>``````````````````````````````<br />
<u>DNS Vulnerability Check:</u></b><br />
 GREAT! (Not vulnerable to DNS cache poisoning) <br />
<b>`````````End of Log```````````</b></div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/zip.gif" alt="File Type: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/progress-hijackthis-logs/13848d1258593605-does-look-infected-attach.zip">Attach.zip</a> (4.5 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.pchelpforum.com/progress-hijackthis-logs/"><![CDATA[[In Progress] HiJackThis! Logs]]></category>
			<dc:creator>billyd</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/progress-hijackthis-logs/80896-does-look-infected.html</guid>
		</item>
		<item>
			<title>Computer Recently got slow.</title>
			<link>http://www.pchelpforum.com/progress-hijackthis-logs/80895-computer-recently-got-slow.html</link>
			<pubDate>Thu, 19 Nov 2009 01:11:20 GMT</pubDate>
			<description>Hello, 
I use FreeAVG, Adaware, SpyBot, Lavasoft firewall. 
 
My Machine started taking long to boot, long to open programs and when I open FireFox...</description>
			<content:encoded><![CDATA[<div>Hello,<br />
I use FreeAVG, Adaware, SpyBot, Lavasoft firewall.<br />
<br />
My Machine started taking long to boot, long to open programs and when I open FireFox or IE6, the pages get &quot;hung up&quot; and take forever to load. Can you please review and advise.<br />
<br />
Here is my hijcak log<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 6:06:18 PM, on 11/18/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\WINDOWS\system32\ZoneLabs\vsmon.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe<br />
C:\WINDOWS\system32\DVDRAMSV.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe<br />
C:\WINDOWS\system32\TODDSrv.exe<br />
C:\Program Files\AVG\AVG9\avgemc.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\WINDOWS\AGRSMMSG.exe<br />
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe<br />
C:\Program Files\Synaptics\SynTP\Toshiba.exe<br />
C:\WINDOWS\system32\TPSBattM.exe<br />
C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe<br />
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe<br />
C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\WINDOWS\system32\RAMASST.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br />
C:\Program Files\TOSHIBA\ConfigFree\CFBtSrch.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://www.yahoo.com/search/ie.html" target="_blank">Yahoo! SearchBar Home Page</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://yahoo.com/" target="_blank">Yahoo!</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://www.toshibadirect.com/dpdstart" target="_blank">Personalized Start Page</a><br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = <a href="http://www.toshibadirect.com/dpdstart" target="_blank">Personalized Start Page</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Cox High Speed Internet<br />
R3 - URLSearchHook: (no name) - CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)<br />
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)<br />
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe<br />
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe<br />
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe<br />
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe<br />
O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient<br />
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
O4 - HKLM\..\Run: [ZoneAlarm Client] &quot;C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe&quot;<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart<br />
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - <a href="http://pcpitstop.com/betapit/PCPitStop.CAB" target="_blank">http://pcpitstop.com/betapit/PCPitStop.CAB</a><br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll<br />
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - <a href="http://webmail01.bjservices.com/iNotes6W.cab" target="_blank">http://webmail01.bjservices.com/iNotes6W.cab</a><br />
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - <a href="http://photos.walmart.com/WalmartActivia.cab" target="_blank">http://photos.walmart.com/WalmartActivia.cab</a><br />
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file:///C:/Program%20Files/AutoCAD%20LT%202002/AcDcToday.ocx<br />
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file:///C:/Program%20Files/AutoCAD%20LT%202002/InstBanr.ocx<br />
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file:///C:/Program%20Files/AutoCAD%20LT%202002/InstFred.ocx<br />
O16 - DPF: {CB97291A-6603-466A-AA11-80C2EB74CB10} (CoxSelfInstallAx10 Control) - <a href="https://install.cox.net/CoxSelfInstall/CoxSelfInstallAx10.ocx" target="_blank">https://install.cox.net/CoxSelfInsta...nstallAx10.ocx</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file:///C:/Program%20Files/AutoCAD%20LT%202002/AcPreview.ocx<br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O18 - Filter hijack: text/html - {c5ee6b8d-ce29-4fc8-8948-ef4300a874ce} - C:\WINDOWS\system32\xwreg32.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe<br />
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe<br />
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe<br />
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\WINDOWS\system32\TODDSrv.exe<br />
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe<br />
<br />
--<br />
End of file - 8008 bytes</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/progress-hijackthis-logs/13847d1258593017-computer-recently-got-slow-hijackthis.log">hijackthis.log</a> (7.9 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.pchelpforum.com/progress-hijackthis-logs/"><![CDATA[[In Progress] HiJackThis! Logs]]></category>
			<dc:creator>CajunMan</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/progress-hijackthis-logs/80895-computer-recently-got-slow.html</guid>
		</item>
		<item>
			<title>lag spike in online gameing</title>
			<link>http://www.pchelpforum.com/progress-hijackthis-logs/80887-lag-spike-online-gameing.html</link>
			<pubDate>Wed, 18 Nov 2009 21:21:14 GMT</pubDate>
			<description>i play 2 fps games online, and they both do the same on every server..  randomly spikes every 4-5 sec for a few min. and the it goes away and comes...</description>
			<content:encoded><![CDATA[<div>i play 2 fps games online, and they both do the same on every server..  randomly spikes every 4-5 sec for a few min. and the it goes away and comes back 10-15 min later..  i just did a complete reformat on my c drive and i still couldn't fix this problem.. im wondering if its possible that it might be hardware problem..  ive got the HijackThis program so ill just post what it says.. any help is appreciated...thx<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 3:13:57 PM, on 11/18/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\system32\PnkBstrA.exe<br />
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\WINDOWS\system32\RUNDLL32.EXE<br />
C:\WINDOWS\system32\CTHELPER.EXE<br />
C:\Program Files\Winamp\Winampa.exe<br />
C:\Program Files\Logitech\SetPoint\SetPoint.exe<br />
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE<br />
C:\Program Files\Xfire\Xfire.exe<br />
C:\WINDOWS\system32\PnkBstrB.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\Opera\opera.exe<br />
C:\totalcmd\TOTALCMD.EXE<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE<br />
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE<br />
O4 - HKLM\..\Run: [Jet Detection] &quot;C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe&quot;<br />
O4 - HKLM\..\Run: [WinampAgent] &quot;C:\Program Files\Winamp\Winampa.exe&quot;<br />
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE<br />
O4 - Startup: Logitech . Product Registration.lnk = C:\Program Files\Common Files\Logishrd\eReg\SetPoint\eReg.exe<br />
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe<br />
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe<br />
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe<br />
<br />
--<br />
End of file - 3347 bytes</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/progress-hijackthis-logs/"><![CDATA[[In Progress] HiJackThis! Logs]]></category>
			<dc:creator>sandseed</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/progress-hijackthis-logs/80887-lag-spike-online-gameing.html</guid>
		</item>
		<item>
			<title>Just a check up.  No rush!</title>
			<link>http://www.pchelpforum.com/progress-hijackthis-logs/80861-just-check-up-no-rush.html</link>
			<pubDate>Wed, 18 Nov 2009 14:24:11 GMT</pubDate>
			<description>Just installed Windows 7 about a week and ive been installing games, and other programs and thought i should just do a little check up so here ya go....</description>
			<content:encoded><![CDATA[<div>Just installed Windows 7 about a week and ive been installing games, and other programs and thought i should just do a little check up so here ya go.  <br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 9:22:09 AM, on 11/18/2009<br />
Platform: Unknown Windows (WinNT 6.01.3504)<br />
MSIE: Internet Explorer v8.00 (8.00.7600.16385)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\system32\taskhost.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\AVG\AVG9\avgtray.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Program Files\OpenOffice.org 3\program\soffice.exe<br />
C:\Program Files\OpenOffice.org 3\program\soffice.bin<br />
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe<br />
C:\Windows\system32\conhost.exe<br />
C:\Program Files\Steam\Steam.exe<br />
C:\Windows\system32\taskhost.exe<br />
C:\Users\Mr. Uber\Desktop\Modern Warfare 2\Modern Warfare 2\Globe Converter.exe<br />
C:\Windows\system32\cmd.exe<br />
C:\Windows\system32\conhost.exe<br />
C:\Users\Mr. Uber\Desktop\Modern Warfare 2\Modern Warfare 2\conv.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [WinampAgent] &quot;C:\Program Files\Winamp\winampa.exe&quot;<br />
O4 - HKCU\..\Run: [Steam] &quot;c:\program files\steam\steam.exe&quot; -silent<br />
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [NVIDIA nTune] &quot;C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe&quot; boot &quot;C:\Users\Mr. Uber\AppData\Local\NVIDIA Corporation\nTune\Profiles\osbootpf.nsu&quot;<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')<br />
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe<br />
O13 - Gopher Prefix: <br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O20 - AppInit_DLLs: avgrsstx.dll<br />
O23 - Service: AVG E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe<br />
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgfws9.exe<br />
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe<br />
O23 - Service: Performance Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe<br />
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe<br />
O23 - Service: Update Center Service (UpdateCenterService) - NVIDIA - C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe<br />
<br />
--<br />
End of file - 4464 bytes<br />
<br />
<br />
Again no rush, and thanks for any help!</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/progress-hijackthis-logs/"><![CDATA[[In Progress] HiJackThis! Logs]]></category>
			<dc:creator>donpoppito</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/progress-hijackthis-logs/80861-just-check-up-no-rush.html</guid>
		</item>
		<item>
			<title>All browsers crashing after a few minutes</title>
			<link>http://www.pchelpforum.com/progress-hijackthis-logs/80819-all-browsers-crashing-after-few-minutes.html</link>
			<pubDate>Tue, 17 Nov 2009 13:20:55 GMT</pubDate>
			<description><![CDATA[Hi, 
  
I've got a problem that's driving me mad. 
  
Running XPsp3 with all available updates and all my internet browsers crash after a few minutes...]]></description>
			<content:encoded><![CDATA[<div>Hi,<br />
 <br />
I've got a problem that's driving me mad.<br />
 <br />
Running XPsp3 with all available updates and all my internet browsers crash after a few minutes of use.<br />
 <br />
I am using firefox 3.5.5 mainly but also ie8 and chrome.<br />
(I can't use IE9 as my works intranet only works properly on IE8)<br />
 <br />
the problem seems worse if the site contains flash but all still crash on non-flash sites.<br />
 <br />
I have uninstalled and reinstalled all browers, running CCleaner in between.<br />
 <br />
I have disabled all plug-ins and reinstalled flash, running CC inbetween.<br />
 <br />
I have run malwarebytes and spybot S&amp;D.<br />
 <br />
also run many virus checks with Avira.<br />
 <br />
All browers still crash, very occasionally resulting in bluescreen.<br />
 <br />
I have a laptop on the same network with no issues.<br />
 <br />
Has anybody got any ideas?<br />
 <br />
Thank you,<br />
 <br />
Graeme.</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/progress-hijackthis-logs/"><![CDATA[[In Progress] HiJackThis! Logs]]></category>
			<dc:creator>emearg1</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/progress-hijackthis-logs/80819-all-browsers-crashing-after-few-minutes.html</guid>
		</item>
		<item>
			<title>PC Freezes on startup only usable in safe mde</title>
			<link>http://www.pchelpforum.com/progress-hijackthis-logs/80815-pc-freezes-startup-only-usable-safe-mde.html</link>
			<pubDate>Tue, 17 Nov 2009 09:59:11 GMT</pubDate>
			<description>Hi, trying desperately to help my brother out with his pc problem although I am probably about as useful as he is! Hope someone out there can help. ...</description>
			<content:encoded><![CDATA[<div>Hi, trying desperately to help my brother out with his pc problem although I am probably about as useful as he is! Hope someone out there can help. <br />
<br />
I have hopefully posted/attached all relevant docs. The only thing he can think that may have caused this is his daughter installed some p2p software (which he soon deleted) but fears it may have left something lying around. Hence my thoughts about posting here...<br />
<br />
His PC is freezing on starting up, he is able to move the cursor around but unable to click on the start button or any icon. The only thing he can do is to power it down using the on/off button and restart the pc in safe mode. <br />
<br />
Any ideas? <br />
<br />
Hijack log and Attach are attached. DDS and Checkup are pasted below. Really appreciate any help or advice in advance. Rgds, Jeff<br />
<br />
<br />
DDS (Ver_09-10-26.01) - NTFSx86 NETWORK <br />
Run by Administrator at 19:07:59.25 on 16/11/2009<br />
Internet Explorer: 8.0.6001.18702<br />
Microsoft Windows XP Home Edition  5.1.2600.3.1252.44.1033.18.3070.2404 [GMT 0:00]<br />
<br />
AV: McAfee VirusScan *On-access scanning disabled* (Updated)   {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}<br />
FW: McAfee Personal Firewall *enabled*   {94894B63-8C7F-4050-BDA4-813CA00DA3E8}<br />
<br />
============== Running Processes ===============<br />
<br />
C:\WINDOWS\system32\svchost -k DcomLaunch<br />
C:\WINDOWS\system32\svchost -k rpcss<br />
C:\Program Files\Windows Defender\MsMpEng.exe<br />
C:\WINDOWS\system32\svchost.exe -k netsvcs<br />
C:\WINDOWS\system32\svchost.exe -k NetworkService<br />
C:\WINDOWS\system32\svchost.exe -k LocalService<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
C:\Program Files\Spyware Doctor\pctsAuxs.exe<br />
C:\Program Files\Spyware Doctor\pctsSvc.exe<br />
C:\Program Files\Spyware Doctor\pctsTray.exe<br />
c:\PROGRA~1\mcafee.com\agent\mcagent.exe<br />
C:\WINDOWS\system32\wbem\unsecapp.exe<br />
C:\WINDOWS\system32\wbem\wmiprvse.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br />
C:\Program Files\Java\jre6\bin\javaw.exe<br />
C:\Program Files\Java\jre6\bin\javaw.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe<br />
C:\Documents and Settings\Administrator.DELL5000.000\My Documents\Downloads\dds.scr<br />
C:\WINDOWS\system32\wbem\wmiprvse.exe<br />
<br />
============== Pseudo <acronym title="HijackThis - Malware Removal Tool">HJT</acronym> Report ===============<br />
<br />
mDefault_Search_URL = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*<a href="http://uk.search.yahoo.com/" target="_blank">Yahoo! Search - Web Search</a><br />
mSearch Page = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sp/*<a href="http://uk.search.yahoo.com/" target="_blank">Yahoo! Search - Web Search</a><br />
mSearch Bar = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*<a href="http://uk.docs.yahoo.com/info/bt_side.html" target="_blank">Yahoo! SearchBar Home Page</a><br />
BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 9\SnagitBHO.dll<br />
BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll<br />
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll<br />
BHO: Spybot-S&amp;D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search &amp; destroy\SDHelper.dll<br />
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\progra~1\yahoo!\common\yiesrvc.dll<br />
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File<br />
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll<br />
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll<br />
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll<br />
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.3.4501.1418\s  wg.dll<br />
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll<br />
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_219B3E1547538286.dll<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll<br />
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 9\SnagitIEAddin.dll<br />
TB: &amp;Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll<br />
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll<br />
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll<br />
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe<br />
uRunOnce: [UniblueRegistryBooster] &quot;launcher.exe&quot; delay 20000<br />
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe<br />
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe<br />
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe<br />
mRun: [Windows Defender] &quot;c:\program files\windows defender\MSASCui.exe&quot; -hide<br />
mRun: [SpeedTouch USB Diagnostics] &quot;c:\program files\thomson\speedtouch usb\Dragdiag.exe&quot; /icon<br />
mRun: [DLBUCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\DLBUtim  e.dll,_RunDLLEntry@16<br />
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe<br />
mRun: [TalkTalk] &quot;c:\program files\talktalk\bin\sprtcmd.exe&quot; /P TalkTalk<br />
mRun: [ATICCC] &quot;c:\program files\ati technologies\ati.ace\CLIStart.exe&quot;<br />
mRun: [btbb_McciTrayApp] &quot;c:\program files\bt broadband desktop help\btbb\BTHelpNotifier.exe&quot;<br />
mRun: [SunJavaUpdateSched] &quot;c:\program files\java\jre6\bin\jusched.exe&quot;<br />
mRun: [mcagent_exe] &quot;c:\program files\mcafee.com\agent\mcagent.exe&quot; /runkey<br />
mRun: [QuickTime Task] &quot;c:\program files\quicktime\QTTask.exe&quot; -atboottime<br />
mRun: [iTunesHelper] &quot;c:\program files\itunes\iTunesHelper.exe&quot;<br />
mRun: [ISTray] &quot;c:\program files\spyware doctor\pctsTray.exe&quot;<br />
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE<br />
dRun: [DWQueuedReporting] &quot;c:\progra~1\common~1\micros~1\dw\dwtrig20.exe  &quot; -t<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\sna  git~1.lnk - c:\program files\techsmith\snagit 9\Snagit32.exe<br />
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe<br />
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe<br />
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\progra~1\yahoo!\common\yiesrvc.dll<br />
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL<br />
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search &amp; destroy\SDHelper.dll<br />
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab<br />
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204<br />
DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} - hxxp://musicmix.messenger.msn.com/Medialogic.CAB<br />
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll<br />
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1216120115147<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab<br />
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab<br />
DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - hxxp://www.sibelius.com/download/software/win/ActiveXPlugin.cab<br />
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab<br />
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab<br />
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab<br />
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL<br />
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll<br />
Notify: GoToAssist - c:\program files\citrix\gotoassist\570\G2AWinLogon.dll<br />
Notify: igfxcui - igfxsrvc.dll<br />
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll<br />
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll<br />
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL<br />
<br />
================= FIREFOX ===================<br />
<br />
FF - ProfilePath - c:\docume~1\admini~1.000\applic~1\mozilla\firefox\  profiles\dnyp8u4k.default\<br />
FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll<br />
FF - plugin: c:\program files\common files\motive\npMotive.dll<br />
<br />
---- FIREFOX POLICIES ----<br />
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref(&quot;security.ssl3.rsa_seed_sha&quot;, true);<br />
<br />
============= SERVICES / DRIVERS ===============<br />
<br />
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-11-14 64288]<br />
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-11-14 206256]<br />
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-9-24 1179232]<br />
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-11-14 348752]<br />
S1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2009-1-15 9968]<br />
S1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-1-15 74480]<br />
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-10-25 203280]<br />
S2 sprtsvc_TalkTalk;SupportSoft Sprocket Service (TalkTalk);c:\program files\talktalk\bin\sprtsvc.exe [2007-10-12 202016]<br />
S2 tgsrvc_TalkTalk;SupportSoft Repair Service (TalkTalk);c:\program files\common files\supportsoft\bin\tgsrvc.exe [2007-8-2 148768]<br />
S3 s115bus;Sony Ericsson Device 115 driver (WDM);c:\windows\system32\drivers\s115bus.sys [2007-4-23 83208]<br />
S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;c:\windows\system32\drivers\s115mdfl.sys [2007-4-23 15112]<br />
S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;c:\windows\system32\drivers\s115mdm.sys [2007-4-23 108680]<br />
S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s115mgmt.sys [2007-4-23 100488]<br />
S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;c:\windows\system32\drivers\s115obex.sys [2007-4-23 98568]<br />
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-1-15 7408]<br />
<br />
=============== Created Last 30 ================<br />
<br />
2009-11-16 18:51:50    0    d-----w-    c:\docume~1\admini~1.000\applic~1\Uniblue<br />
2009-11-16 18:51:45    0    d-----w-    c:\program files\Uniblue<br />
2009-11-15 21:52:08    0    d-----w-    c:\program files\Trend Micro<br />
2009-11-15 19:25:39    0    d-----w-    c:\docume~1\admini~1.000\applic~1\Malwarebytes<br />
2009-11-15 09:34:23    0    d-sh--w-    c:\documents and settings\administrator.dell5000.000\IETldCache<br />
2009-11-14 19:29:12    15880    ----a-w-    c:\windows\system32\lsdelete.exe<br />
2009-11-14 17:58:49    64288    ----a-w-    c:\windows\system32\drivers\Lbd.sys<br />
2009-11-14 17:58:36    93360    ----a-w-    c:\windows\system32\drivers\SBREDrv.sys<br />
2009-11-14 17:56:09    0    dc-h--w-    c:\docume~1\alluse~1\applic~1\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}<br />
2009-11-14 17:55:46    0    d-----w-    c:\program files\Lavasoft<br />
2009-11-14 14:41:34    7396    ----a-w-    c:\windows\system32\drivers\pctcore.cat<br />
2009-11-14 14:27:13    159600    ----a-w-    c:\windows\system32\drivers\pctgntdi.sys<br />
2009-11-14 14:27:04    73840    ----a-w-    c:\windows\system32\drivers\PCTAppEvent.sys<br />
2009-11-14 14:27:04    206256    ----a-w-    c:\windows\system32\drivers\PCTCore.sys<br />
2009-11-14 14:26:56    64392    ----a-w-    c:\windows\system32\drivers\pctplsg.sys<br />
2009-11-14 14:26:56    0    d-----w-    c:\program files\common files\PC Tools<br />
2009-11-14 14:26:51    0    d-----w-    c:\program files\Spyware Doctor<br />
2009-11-14 14:26:51    0    d-----w-    c:\docume~1\alluse~1\applic~1\PC Tools<br />
2009-11-14 13:55:33    0    d-----w-    c:\windows\system32\wbem\Repository<br />
2009-11-14 13:54:00    0    d-----w-    c:\program files\iTunes<br />
2009-11-14 13:54:00    0    d-----w-    c:\program files\iPod<br />
2009-11-04 07:41:01    0    d-----w-    c:\program files\iPod(2)<br />
2009-11-04 07:40:55    0    d-----w-    c:\program files\iTunes(2)<br />
2009-10-27 19:01:24    2560    ----a-w-    c:\windows\_MSRSTRT.EXE<br />
2009-10-27 18:58:41    0    d-----w-    c:\program files\PrintKey2000<br />
2009-10-25 06:37:08    18071    ----a-w-    c:\windows\system32\Config.MPF<br />
2009-10-25 06:33:31    40552    ----a-w-    c:\windows\system32\drivers\mfesmfk.sys<br />
2009-10-25 06:33:31    35272    ----a-w-    c:\windows\system32\drivers\mfebopk.sys<br />
2009-10-25 06:33:30    79816    ----a-w-    c:\windows\system32\drivers\mfeavfk.sys<br />
2009-10-25 06:33:24    120136    ----a-w-    c:\windows\system32\drivers\Mpfp.sys<br />
2009-10-25 06:32:29    0    d-----w-    c:\program files\common files\McAfee<br />
2009-10-25 06:32:26    0    d-----w-    c:\program files\McAfee.com<br />
2009-10-25 06:32:15    0    d-----w-    c:\program files\McAfee<br />
2009-10-25 06:27:33    34248    ----a-w-    c:\windows\system32\drivers\mferkdk.sys<br />
2009-10-23 16:31:25    0    d-----w-    c:\program files\Optimizer Tool<br />
2009-10-23 16:20:26    0    d-----w-    c:\program files\Reg Tool<br />
2009-10-23 15:04:32    274288    ----a-w-    c:\windows\system32\mucltui.dll<br />
2009-10-23 15:04:32    215920    ----a-w-    c:\windows\system32\muweb.dll<br />
2009-10-23 15:04:32    16736    ----a-w-    c:\windows\system32\mucltui.dll.mui<br />
2009-10-23 09:09:42    0    d-----w-    c:\program files\Microsoft<br />
2009-10-23 09:09:23    0    d-----w-    c:\program files\Windows Live SkyDrive<br />
2009-10-23 09:06:40    0    d-----w-    c:\program files\common files\Windows Live<br />
2009-10-23 07:03:39    0    d-----w-    c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD}<br />
2009-10-22 20:13:05    0    d-----w-    c:\program files\CFXDemo<br />
2009-10-21 21:54:17    0    d-----w-    c:\program files\common files\Motive<br />
2009-10-21 21:54:14    0    d-----w-    c:\program files\BT Broadband Desktop Help<br />
2009-10-21 21:53:21    195440    ------w-    c:\windows\system32\MpSigStub.exe<br />
2009-10-21 21:52:40    65536    ----a-w-    c:\windows\system32\YCRWin32.dll<br />
2009-10-21 21:52:36    89088    ----a-w-    c:\windows\system32\ATL71.DLL<br />
2009-10-21 21:52:36    344064    ----a-w-    c:\windows\system32\msvcr70.dll<br />
2009-10-21 21:52:35    84992    ----a-w-    c:\windows\system32\ATL70.DLL<br />
2009-10-21 21:52:19    0    d-----w-    c:\program files\Yahoo!<br />
2009-10-21 21:52:00    0    d-----w-    c:\program files\BTHomeHub<br />
2009-10-21 21:51:42    153088    -c----w-    c:\windows\system32\dllcache\triedit.dll<br />
<br />
==================== Find3M  ====================<br />
<br />
2009-11-16 17:33:40    1984    ----a-w-    c:\windows\system32\d3d9caps.dat<br />
2009-11-05 08:23:25    58164    ---ha-w-    c:\windows\system32\mlfcache.dat<br />
2009-09-11 14:18:39    136192    ----a-w-    c:\windows\system32\msv1_0.dll<br />
2009-09-04 21:03:36    58880    ----a-w-    c:\windows\system32\msasn1.dll<br />
2009-08-29 08:08:21    916480    ----a-w-    c:\windows\system32\wininet.dll<br />
2009-08-28 18:42:52    2065696    ----a-w-    c:\windows\system32\usbaaplrc.dll<br />
2009-08-26 08:00:21    247326    ----a-w-    c:\windows\system32\strmdll.dll<br />
<br />
============= FINISH: 19:08:29.29 ===============<br />
<br />
<br />
<br />
 Results of screen317's Security Check version 0.99.0  <br />
 Windows XP Service Pack 3  <br />
<b>`````````````````````````````` <br />
<u>Antivirus/Firewall Check:</u></b> <br />
 <font color="red"><b>Windows Security Center service is not running! This report may not be accurate!</b></font> <br />
 Windows Firewall Disabled!  <br />
 McAfee SecurityCenter     <br />
<b>`````````````````````````````` <br />
<u>Anti-malware/Other Utilities Check:</u></b> <br />
 Ad-Aware <br />
 Spyware Doctor 6.1   <br />
 Spybot - Search &amp; Destroy <br />
 SUPERAntiSpyware Free Edition   <br />
 Windows Defender    <br />
 HijackThis 2.0.2    <br />
 CCleaner (remove only)   <br />
 Java(TM) 6 Update 16  <br />
 Adobe Flash Player 10  <br />
Adobe Reader 9 <br />
<b>`````````````````````````````` <br />
Process Check:  <br />
<u>objlist.exe by Laurent</u></b> <br />
 Windows Defender MSMpEng.exe  <br />
 <font color="red"><b>Ad-Aware AAWService.exe is disabled!</b></font> <br />
 <font color="red"><b>Ad-Aware AAWTray.exe is disabled!</b></font> <br />
<b>``````````````````````````````<br />
<u>DNS Vulnerability Check:</u></b><br />
 GREAT! (Not vulnerable to DNS cache poisoning) <br />
<br />
<b>`````````End of Log```````````</b></div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/progress-hijackthis-logs/13816d1258451829-pc-freezes-startup-only-usable-safe-mde-hijackthis-3-.log">hijackthis(3).log</a> (11.7 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/progress-hijackthis-logs/13817d1258451829-pc-freezes-startup-only-usable-safe-mde-attach.txt" target="_blank">Attach.txt</a> (11.5 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.pchelpforum.com/progress-hijackthis-logs/"><![CDATA[[In Progress] HiJackThis! Logs]]></category>
			<dc:creator>jeffguru</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/progress-hijackthis-logs/80815-pc-freezes-startup-only-usable-safe-mde.html</guid>
		</item>
		<item>
			<title>Problems-argh!!!!!!</title>
			<link>http://www.pchelpforum.com/progress-hijackthis-logs/80781-problems-argh.html</link>
			<pubDate>Mon, 16 Nov 2009 19:41:57 GMT</pubDate>
			<description>Hi there. 
 
i was having problems with my laptop a little while ago (here is the link) 
...</description>
			<content:encoded><![CDATA[<div>Hi there.<br />
<br />
i was having problems with my laptop a little while ago (here is the link)<br />
<br />
<a href="!78596!http://www.pchelpforum.com/progress-hijackthis-logs/78596-laptop-slow-start-up.html" target="_blank">http://www.pchelpforum.com/progress-...-start-up.html</a><br />
<br />
Whilst i done everything that crush had asked on saturday mcafee kicked in to do its scan and picked something up this is word for word from the log that it produced:-<br />
<br />
one or more items were detected on your computer.<br />
<br />
Detection name: Generic.dx!qpc (Trojan), Generic.dx!qpc (Trojan)<br />
<br />
File: C:\WINDOWS\WINSXS\X86_MICROSOFT-WINDOWS-AUTOCHK_31BF3856AD364E35_6.0.6001.18000_NONE_E1F3E  D49C1C122EF\AUTOCHK.EXE<br />
<br />
It is saying that it cannot be removed.<br />
<br />
i am now going to do the prework but i thought i would post this first incase anyone might have an idea on what else i can do   <br />
<br />
Thanks<br />
Stephanie</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/progress-hijackthis-logs/"><![CDATA[[In Progress] HiJackThis! Logs]]></category>
			<dc:creator>stephanie28</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/progress-hijackthis-logs/80781-problems-argh.html</guid>
		</item>
	</channel>
</rss>
