<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title><![CDATA[PC Help Forum - [Fixed] Hijackthis! Logs]]></title>
		<link>http://www.pchelpforum.com</link>
		<description>Here you will find the HJT logs that have been fixed by the team.</description>
		<language>en</language>
		<lastBuildDate>Fri, 20 Nov 2009 22:25:55 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>1</ttl>
		<image>
			<url>http://www.pchelpforum.com/images/styles/pchelpforum/misc/rss.jpg</url>
			<title><![CDATA[PC Help Forum - [Fixed] Hijackthis! Logs]]></title>
			<link>http://www.pchelpforum.com</link>
		</image>
		<item>
			<title>Fixed: Internet running slow after malware removal.</title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/80791-internet-running-slow-after-malware-removal.html</link>
			<pubDate>Mon, 16 Nov 2009 22:58:33 GMT</pubDate>
			<description>Hi I have been trying to fix a friends computer for quite some time now. The computer is a E-machine running win XP home with SP3. The original...</description>
			<content:encoded><![CDATA[<div>Hi I have been trying to fix a friends computer for quite some time now. The computer is a E-machine running win XP home with SP3. The original problem was the computer would lock up just after booting. I ran Malwarebytes and cc cleaner. This seems to have fixed the lock up but shortly after I was stuck in the endless reboot. I was able to reboot and restore to a previous date. Now the computer is fast and states no spy, ad or malware. I used avast to check for viruses and the machine is clean. My issue now is the Internet seems like its in 1995 its so slow. I read the other forums and have downloaded the required programs. Below i will paste in the logs. I thank you for any help you could give me.<br />
<br />
DDS<br />
<br />
<br />
DDS (Ver_09-10-26.01) - NTFSx86  <br />
Run by Owner at 17:30:01.93 on Mon 11/16/2009<br />
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17<br />
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.382.125 [GMT -5:00]<br />
<br />
<br />
============== Running Processes ===============<br />
<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost -k DcomLaunch<br />
svchost.exe<br />
C:\WINDOWS\System32\svchost.exe -k netsvcs<br />
svchost.exe<br />
svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\zHotkey.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
svchost.exe<br />
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\Motive\McciCMService.exe<br />
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS<br />
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe<br />
C:\WINDOWS\system32\svchost.exe -k imgsvc<br />
C:\WINDOWS\wanmpsvc.exe<br />
C:\WINDOWS\system32\lxcecoms.exe<br />
C:\WINDOWS\explorer.exe<br />
C:\Documents and Settings\Owner\Desktop\dds.scr<br />
<br />
============== Pseudo <acronym title="HijackThis - Malware Removal Tool">HJT</acronym> Report ===============<br />
<br />
uStart Page = hxxp://www.xxxxespaonline.com/<br />
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&amp;sourceid=ie7&amp;rls=com.micros  oft:en-US&amp;ie=utf8&amp;oe=utf8<br />
uInternet Connection Wizard,ShellNext = iexplore<br />
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s<br />
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll<br />
BHO: WormRadar.com IESiteBlocker.NavFilter: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - AVG Safe Search<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll<br />
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
TB: AOL Toolbar: {4982d40a-c53b-4615-b15b-b5b5e98d167c} - c:\program files\aol toolbar\toolbar.dll<br />
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File<br />
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File<br />
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - <br />
mRun: [Malwarebytes Anti-Malware (reboot)] &quot;c:\program files\malwarebytes' anti-malware\mbam.exe&quot; /runcleanupscript<br />
mRun: [FaxCenterServer] &quot;c:\program files\lexmark fax solutions\fm3032.exe&quot; /s<br />
mRun: [EzPrint] &quot;c:\program files\lexmark 4300 series\ezprint.exe&quot;<br />
mRun: [CHotkey] zHotkey.exe<br />
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe<br />
mRun: [LXCECATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\LXCEtim  e.dll,_RunDLLEntry@16<br />
IE: &amp;AOL Toolbar search - c:\program files\aol toolbar\toolbar.dll/SEARCH.HTML<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000<br />
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe<br />
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe<br />
IE: {4982D40A-C53B-4615-B15B-B5B5E98D167C} - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - c:\program files\aol toolbar\toolbar.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL<br />
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE}<br />
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab<br />
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab<br />
DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab<br />
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1257360486453<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {95D88B35-A521-472B-A182-BB1A98356421} - hxxp://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab<br />
DPF: {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_08-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab<br />
DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} - hxxp://asp.mathxl.com/books/_Players/MathPlayer.cab<br />
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll<br />
Notify: AtiExtEvent - Ati2evxx.dll<br />
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL<br />
<br />
================= FIREFOX ===================<br />
<br />
FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profile  s\gbact95u.default\<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}<br />
<br />
---- FIREFOX POLICIES ----<br />
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref(&quot;security.ssl3.rsa_seed_sha&quot;, true);<br />
<br />
============= SERVICES / DRIVERS ===============<br />
<br />
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-10-12 9968]<br />
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-10-12 74480]<br />
S2 Viewpoint Manager Service;Viewpoint Manager Service; [x]<br />
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-10-12 7408]<br />
<br />
=============== Created Last 30 ================<br />
<br />
2009-11-16 21:57:04	0	d-----w-	C:\VundoFix Backups<br />
2009-11-16 21:36:31	0	d-sha-r-	C:\cmdcons<br />
2009-11-16 21:33:55	98816	----a-w-	c:\windows\sed.exe<br />
2009-11-16 21:33:55	77312	----a-w-	c:\windows\MBR.exe<br />
2009-11-16 21:33:55	260608	----a-w-	c:\windows\PEV.exe<br />
2009-11-16 21:33:55	161792	----a-w-	c:\windows\SWREG.exe<br />
2009-11-16 20:46:32	54156	---ha-w-	c:\windows\QTFont.qfn<br />
2009-11-16 20:46:32	1409	----a-w-	c:\windows\QTFont.for<br />
2009-11-14 06:38:32	0	d-----w-	c:\windows\system32\wbem\Repository<br />
2009-11-14 00:41:00	0	d-----w-	c:\docume~1\owner\applic~1\IObit<br />
2009-11-14 00:40:59	0	d-----w-	c:\program files\IObit<br />
2009-11-12 17:38:11	0	d-----w-	c:\windows\system32\scripting<br />
2009-11-12 17:38:10	0	d-----w-	c:\windows\system32\en<br />
2009-11-12 17:38:10	0	d-----w-	c:\windows\l2schemas<br />
2009-11-12 17:38:09	0	d-----w-	c:\windows\system32\bits<br />
2009-11-12 17:28:30	0	d-----w-	c:\windows\EHome<br />
2009-11-05 05:08:03	0	d-sh--w-	c:\documents and settings\owner\IECompatCache<br />
2009-11-05 05:05:41	0	d-sh--w-	c:\documents and settings\owner\PrivacIE<br />
2009-11-05 05:03:14	0	d-sh--w-	c:\documents and settings\owner\IETldCache<br />
2009-11-05 05:00:39	92160	-c----w-	c:\windows\system32\dllcache\iecompat.dll<br />
2009-11-05 05:00:13	0	d-----w-	c:\windows\ie8updates<br />
2009-11-05 04:56:42	0	dc-h--w-	c:\windows\ie8<br />
2009-11-05 04:11:21	0	d-----w-	c:\program files\CCleaner<br />
2009-11-04 19:30:09	0	d-----w-	c:\program files\Free Window Registry Repair<br />
2009-11-04 18:44:12	15064	----a-w-	c:\windows\system32\wuapi.dll.mui<br />
2009-11-04 18:21:36	0	d-----w-	C:\a9d51d94a2c072e5f28d<br />
2009-10-28 03:35:38	0	d-----w-	c:\docume~1\owner\applic~1\AVG8<br />
2009-10-27 21:28:50	0	d-----w-	c:\docume~1\owner\applic~1\Malwarebytes<br />
2009-10-27 21:28:46	38224	----a-w-	c:\windows\system32\drivers\mbamswissarmy.sys<br />
2009-10-27 21:28:45	19160	----a-w-	c:\windows\system32\drivers\mbam.sys<br />
2009-10-27 21:28:45	0	d-----w-	c:\program files\Malwarebytes' Anti-Malware<br />
2009-10-27 21:28:45	0	d-----w-	c:\docume~1\alluse~1\applic~1\Malwarebytes<br />
<br />
==================== Find3M  ====================<br />
<br />
2009-11-14 01:12:07	135680	----a-w-	c:\windows\system32\taskmgr.exe<br />
2009-11-04 17:31:41	94208	----a-w-	c:\windows\DUMP349c.tmp<br />
2009-10-21 22:05:47	10720783	----a-w-	C:\ESMWBK.ZIP<br />
2009-10-12 16:51:34	7082	----a-w-	c:\docume~1\owner\applic~1\wklnhst.dat<br />
2009-10-11 09:17:27	411368	----a-w-	c:\windows\system32\deploytk.dll<br />
2009-09-11 14:18:39	136192	----a-w-	c:\windows\system32\msv1_0.dll<br />
2009-09-04 21:03:36	58880	----a-w-	c:\windows\system32\msasn1.dll<br />
2009-08-29 08:08:21	916480	------w-	c:\windows\system32\wininet.dll<br />
2009-08-26 08:00:21	247326	----a-w-	c:\windows\system32\strmdll.dll<br />
<br />
============= FINISH: 17:30:22.43 ===============<br />
<br />
<br />
<br />
<acronym title="HijackThis - Malware Removal Tool">HJT</acronym> log<br />
<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 5:32:00 PM, on 11/16/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\zHotkey.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\Motive\McciCMService.exe<br />
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS<br />
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\wanmpsvc.exe<br />
C:\WINDOWS\system32\lxcecoms.exe<br />
C:\WINDOWS\explorer.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.radiancespaonline.com/" target="_blank">Radiance Salon and Day Spa</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKLM\..\Run: [FaxCenterServer] &quot;C:\Program Files\Lexmark Fax Solutions\fm3032.exe&quot; /s<br />
O4 - HKLM\..\Run: [EzPrint] &quot;C:\Program Files\Lexmark 4300 Series\ezprint.exe&quot;<br />
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe<br />
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br />
O4 - HKLM\..\Run: [LXCECATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCEtim  e.dll,_RunDLLEntry@16<br />
O8 - Extra context menu item: &amp;AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll<br />
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\shdocvw.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - <a href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" target="_blank">http://upload.facebook.com/controls/...oUploader5.cab</a><br />
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - <a href="http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab" target="_blank">http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-48.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1257360486453" target="_blank">http://update.microsoft.com/microsof...?1257360486453</a><br />
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - <a href="http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab" target="_blank">http://asp.mathxl.com/books/_Players...stallAsst2.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - <a href="http://asp.mathxl.com/books/_Players/MathPlayer.cab" target="_blank">http://asp.mathxl.com/books/_Players/MathPlayer.cab</a><br />
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll<br />
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: lxce_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcecoms.exe<br />
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe<br />
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS<br />
O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe<br />
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe<br />
<br />
--<br />
End of file - 6120 bytes<br />
 <br />
<br />
<br />
Security checkup<br />
<br />
<br />
<br />
 Results of screen317's Security Check version 0.99.0  <br />
 Windows XP Service Pack 3  <br />
<b>`````````````````````````````` <br />
<u>Antivirus/Firewall Check:</u></b> <br />
 Windows Firewall Enabled!  <br />
<b>`````````````````````````````` <br />
<u>Anti-malware/Other Utilities Check:</u></b> <br />
 SUPERAntiSpyware Free Edition   <br />
 CCleaner     <br />
 Java(TM) 6 Update 17  <br />
 <font color="red"><b>Out of date Java installed!</b></font> <br />
 Adobe Flash Player 10  <br />
Adobe Reader 7.0.8 <br />
<font color="red"><b>Out of date Adobe Reader installed!</b></font> <br />
<b>`````````````````````````````` <br />
Process Check:  <br />
<u>objlist.exe by Laurent</u></b> <br />
<b>``````````````````````````````<br />
<u>DNS Vulnerability Check:</u></b><br />
 <font color="red"><b>Request Timed Out (Wireless Internet connection/Disconnected Internet/Proxy?)</b></font> <br />
<br />
<b>`````````End of Log```````````</b><br />
<br />
<br />
<br />
<br />
<br />
ComboFix<br />
<br />
<br />
ComboFix 09-11-16.05 - Owner 11/16/2009 17:12..1 - FAT32x86<br />
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.382.120 [GMT -5:00]<br />
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe<br />
.<br />
<br />
(((((((((((((((((((((((((   Files Created from 2009-10-16 to 2009-11-16  )))))))))))))))))))))))))))))))<br />
.<br />
<br />
2009-11-16 21:57 . 2009-11-16 21:57	--------	d-----w-	C:\VundoFix Backups<br />
2009-11-16 20:39 . 2009-11-16 20:39	--------	d-----w-	c:\documents and settings\All Users\Application Data\CyberLink<br />
2009-11-14 06:48 . 2009-11-14 06:48	--------	d-sh--w-	c:\documents and settings\Administrator\IETldCache<br />
2009-11-14 06:38 . 2009-11-14 06:38	--------	d-----w-	c:\windows\system32\wbem\Repository<br />
2009-11-14 00:41 . 2009-11-14 00:45	--------	d-----w-	c:\documents and settings\Owner\Application Data\IObit<br />
2009-11-14 00:40 . 2009-11-14 00:40	--------	d-----w-	c:\program files\IObit<br />
2009-11-12 18:03 . 2009-11-12 18:03	152576	----a-w-	c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_17\lzma.dll<br />
2009-11-12 18:01 . 2009-11-12 18:03	79488	----a-w-	c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll<br />
2009-11-12 17:51 . 2009-11-12 17:51	--------	d-sh--w-	c:\windows\system32\config\systemprofile\IETldCach  e<br />
2009-11-12 17:38 . 2009-11-12 17:38	--------	d-----w-	c:\windows\system32\scripting<br />
2009-11-12 17:38 . 2009-11-12 17:38	--------	d-----w-	c:\windows\l2schemas<br />
2009-11-12 17:38 . 2009-11-12 17:38	--------	d-----w-	c:\windows\system32\en<br />
2009-11-12 17:38 . 2009-11-12 17:38	--------	d-----w-	c:\windows\system32\bits<br />
2009-11-12 17:28 . 2009-11-12 17:28	--------	d-----w-	c:\windows\EHome<br />
2009-11-05 05:08 . 2009-11-05 05:08	--------	d-sh--w-	c:\documents and settings\Owner\IECompatCache<br />
2009-11-05 05:05 . 2009-11-05 05:05	--------	d-sh--w-	c:\documents and settings\Owner\PrivacIE<br />
2009-11-05 05:03 . 2009-11-05 05:03	--------	d-sh--w-	c:\documents and settings\Owner\IETldCache<br />
2009-11-05 05:00 . 2009-10-02 04:44	92160	-c----w-	c:\windows\system32\dllcache\iecompat.dll<br />
2009-11-05 05:00 . 2009-11-12 17:57	--------	d-----w-	c:\windows\ie8updates<br />
2009-11-05 04:58 . 2009-08-29 08:08	12800	-c----w-	c:\windows\system32\dllcache\xpshims.dll<br />
2009-11-05 04:58 . 2009-08-29 08:08	246272	-c----w-	c:\windows\system32\dllcache\ieproxy.dll<br />
2009-11-05 04:56 . 2009-11-05 04:58	--------	dc-h--w-	c:\windows\ie8<br />
2009-11-05 04:11 . 2009-11-05 04:11	--------	d-----w-	c:\program files\CCleaner<br />
2009-11-04 20:41 . 2009-11-04 20:41	--------	d-----w-	c:\program files\Alwil Software<br />
2009-11-04 19:30 . 2009-11-04 19:30	--------	d-----w-	c:\program files\Free Window Registry Repair<br />
2009-11-04 18:21 . 2009-11-04 18:21	--------	d-----w-	C:\a9d51d94a2c072e5f28d<br />
2009-11-04 15:50 . 2009-11-04 15:50	--------	d-----w-	c:\documents and settings\Owner\Local Settings\Application Data\PCHealth<br />
2009-10-28 07:02 . 2009-10-28 07:02	--------	d-----w-	c:\documents and settings\Administrator\Application Data\Malwarebytes<br />
2009-10-28 05:42 . 2009-11-04 18:51	117760	----a-w-	c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\  UIREPAIR.DLL<br />
2009-10-28 05:41 . 2009-10-28 05:41	--------	d-----w-	c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com<br />
2009-10-28 05:19 . 2009-10-28 05:19	--------	d-----w-	c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla<br />
2009-10-28 03:55 . 2009-10-28 03:55	--------	d-----w-	c:\documents and settings\Owner\Local Settings\Application Data\Mozilla<br />
2009-10-28 03:35 . 2009-10-28 03:35	--------	d-----w-	c:\documents and settings\Owner\Application Data\AVG8<br />
2009-10-27 21:28 . 2009-10-27 21:28	--------	d-----w-	c:\documents and settings\Owner\Application Data\Malwarebytes<br />
2009-10-27 21:28 . 2009-09-10 18:54	38224	----a-w-	c:\windows\system32\drivers\mbamswissarmy.sys<br />
2009-10-27 21:28 . 2009-10-27 21:28	--------	d-----w-	c:\program files\Malwarebytes' Anti-Malware<br />
2009-10-27 21:28 . 2009-10-27 21:28	--------	d-----w-	c:\documents and settings\All Users\Application Data\Malwarebytes<br />
2009-10-27 21:28 . 2009-09-10 18:53	19160	----a-w-	c:\windows\system32\drivers\mbam.sys<br />
<br />
.<br />
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))  ))<br />
.<br />
2009-11-16 01:42 . 2006-01-15 16:41	--------	d-----w-	c:\program files\Lx_cats<br />
2009-11-14 01:24 . 2006-01-15 17:44	60200	----a-w-	c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT<br />
2009-11-14 01:12 . 2005-03-23 16:52	135680	----a-w-	c:\windows\system32\taskmgr.exe<br />
2009-11-12 18:04 . 2006-09-03 23:31	--------	d-----w-	c:\program files\Java<br />
2009-11-12 17:40 . 2005-03-23 18:11	76487	----a-w-	c:\windows\pchealth\helpctr\OfflineCache\index.dat<br />
2009-11-04 20:23 . 2007-02-12 21:05	--------	d-----w-	c:\program files\Web Publish<br />
2009-11-04 17:31 . 2005-05-19 23:32	94208	----a-w-	c:\windows\DUMP349c.tmp<br />
2009-10-28 03:30 . 2009-10-15 17:23	117760	----a-w-	c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\  UIREPAIR.DLL<br />
2009-10-21 22:05 . 2009-02-02 18:10	10720783	----a-w-	C:\ESMWBK.ZIP<br />
2009-10-15 18:21 . 2009-10-15 17:22	--------	d-----w-	c:\program files\SUPERAntiSpyware<br />
2009-10-15 17:23 . 2009-10-15 17:23	--------	d-----w-	c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com<br />
2009-10-15 17:22 . 2009-10-15 17:22	--------	d-----w-	c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com<br />
2009-10-15 17:22 . 2009-10-15 17:22	--------	d-----w-	c:\program files\Common Files\Wise Installation Wizard<br />
2009-10-15 17:12 . 2005-05-20 00:00	--------	d-----w-	c:\program files\BigFix<br />
2009-10-12 16:51 . 2006-02-06 22:39	7082	----a-w-	c:\documents and settings\Owner\Application Data\wklnhst.dat<br />
2009-10-11 09:17 . 2009-02-04 00:07	411368	----a-w-	c:\windows\system32\deploytk.dll<br />
2009-10-06 22:32 . 2009-10-06 22:32	59040	----a-w-	c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT<br />
2009-10-06 22:32 . 2009-10-06 22:32	0	----a-w-	c:\documents and settings\Administrator\Application Data\wklnhst.dat<br />
2009-10-06 22:31 . 2005-05-19 23:57	--------	d-----w-	c:\documents and settings\All Users\Application Data\Viewpoint<br />
2009-10-06 22:29 . 2009-05-06 22:43	--------	d-----w-	c:\program files\Coupons<br />
2009-10-06 22:28 . 2005-05-20 00:07	--------	d-----w-	c:\documents and settings\All Users\Application Data\McAfee.com<br />
2009-10-06 22:25 . 2005-05-20 00:00	--------	d-----w-	c:\program files\Google<br />
2009-10-06 17:29 . 2007-09-05 21:13	--------	d-----w-	c:\documents and settings\All Users\Application Data\Grisoft<br />
2009-09-30 19:27 . 2009-02-20 01:54	77824	----a-w-	c:\documents and settings\All Users\Application Data\Kodak\EasyShareSetup\ess\bindbins\BindBins.ex  e<br />
2009-09-30 19:27 . 2009-09-30 19:27	1167360	----a-w-	c:\documents and settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_190001_481db786\E  asyShrx.Dll<br />
2009-09-11 14:18 . 2005-03-23 16:52	136192	----a-w-	c:\windows\system32\msv1_0.dll<br />
2009-09-04 21:03 . 2005-03-23 16:52	58880	----a-w-	c:\windows\system32\msasn1.dll<br />
2009-08-29 08:08 . 2005-03-23 16:53	916480	------w-	c:\windows\system32\wininet.dll<br />
2009-08-26 08:00 . 2005-03-23 16:53	247326	----a-w-	c:\windows\system32\strmdll.dll<br />
.<br />
<br />
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br />
.<br />
*Note* empty entries &amp; legit default entries are not shown <br />
REGEDIT4<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr  entVersion\Run]<br />
&quot;Malwarebytes Anti-Malware (reboot)&quot;=&quot;c:\program files\Malwarebytes' Anti-Malware\mbam.exe&quot; [2009-09-10 1312080]<br />
&quot;FaxCenterServer&quot;=&quot;c:\program files\Lexmark Fax Solutions\fm3032.exe&quot; [2005-03-16 299008]<br />
&quot;EzPrint&quot;=&quot;c:\program files\Lexmark 4300 Series\ezprint.exe&quot; [2005-02-15 61440]<br />
&quot;ATIPTA&quot;=&quot;c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe&quot; [2005-03-18 339968]<br />
&quot;LXCECATS&quot;=&quot;c:\windows\System32\spool\DRIVERS\W32X  86\3\LXCEtime.dll&quot; [2005-03-22 69632]<br />
&quot;CHotkey&quot;=&quot;zHotkey.exe&quot; - c:\windows\zHotkey.exe [2004-05-18 543232]<br />
<br />
c:\documents and settings\Guest\Start Menu\Programs\Startup\<br />
Elite Scheduler.LNK - c:\elitewin\ElmSched.exe [2006-2-6 28672]<br />
<br />
[hkey_local_machine\software\microsoft\windows\curr  entversion\explorer\ShellExecuteHooks]<br />
&quot;{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}&quot;= &quot;c:\program files\SUPERAntiSpyware\SASSEH.DLL&quot; [2008-05-13 77824]<br />
<br />
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]<br />
2009-09-03 19:21	548352	----a-w-	c:\program files\SUPERAntiSpyware\SASWINLO.dll<br />
<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro  l\SafeBoot\Minimal\AVG Anti-Spyware Guard]<br />
@=&quot;Service&quot;<br />
<br />
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]<br />
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup<br />
<br />
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL Companion.lnk]<br />
backup=c:\windows\pss\AOL Companion.lnkCommon Startup<br />
<br />
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]<br />
backup=c:\windows\pss\BigFix.lnkCommon Startup<br />
<br />
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Elite Scheduler.lnk]<br />
backup=c:\windows\pss\Elite Scheduler.lnkCommon Startup<br />
<br />
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]<br />
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup<br />
<br />
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Elite Scheduler.LNK]<br />
backup=c:\windows\pss\Elite Scheduler.LNKStartup<br />
<br />
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]<br />
&quot;mcupdmgr.exe&quot;=3 (0x3)<br />
&quot;McTskshd.exe&quot;=2 (0x2)<br />
&quot;McDetect.exe&quot;=2 (0x2)<br />
&quot;AVG Anti-Spyware Guard&quot;=2 (0x2)<br />
<br />
[HKEY_LOCAL_MACHINE\software\microsoft\security center]<br />
&quot;AntiVirusOverride&quot;=dword:00000001<br />
<br />
[HKLM\~\services\sharedaccess\parameters\firewallpo  licy\standardprofile\AuthorizedApplications\List]<br />
&quot;%windir%\\system32\\sessmgr.exe&quot;=<br />
&quot;c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe&quot;=<br />
&quot;c:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe&quot;=<br />
&quot;c:\\Program Files\\Common Files\\AOL\\1136553444\\ee\\AOLServiceHost.exe&quot;=<br />
&quot;c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe&quot;=<br />
&quot;c:\\Program Files\\Messenger\\msmsgs.exe&quot;=<br />
&quot;c:\\Program Files\\Common Files\\AOL\\1136553444\\ee\\aolsoftware.exe&quot;=<br />
&quot;c:\\Program Files\\Common Files\\AOL\\1136553444\\ee\\aim6.exe&quot;=<br />
&quot;%windir%\\Network Diagnostic\\xpnetdiag.exe&quot;=<br />
&quot;c:\\Program Files\\FrostWire\\FrostWire.exe&quot;=<br />
&quot;c:\\Program Files\\Common Files\\SafeNet Sentinel\\Sentinel Protection Server\\WinNT\\spnsrvnt.exe&quot;=<br />
&quot;c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe&quot;=<br />
<br />
[HKLM\~\services\sharedaccess\parameters\firewallpo  licy\standardprofile\GloballyOpenPorts\List]<br />
&quot;1723:TCP&quot;= 1723:TCP:@xpsp2res.dll,-22015<br />
&quot;1701:UDP&quot;= 1701:UDP:@xpsp2res.dll,-22016<br />
&quot;500:UDP&quot;= 500:UDP:@xpsp2res.dll,-22017<br />
<br />
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [10/12/2009 8:24 PM 9968]<br />
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10/12/2009 8:24 PM 74480]<br />
S2 Viewpoint Manager Service;Viewpoint Manager Service; [x]<br />
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [10/12/2009 8:24 PM 7408]<br />
<br />
--- Other Services/Drivers In Memory ---<br />
<br />
*NewlyCreated* - MBR<br />
*NewlyCreated* - PROCEXP113<br />
*Deregistered* - mbr<br />
*Deregistered* - PROCEXP113<br />
.<br />
Contents of the 'Scheduled Tasks' folder<br />
<br />
2009-11-16 c:\windows\Tasks\User_Feed_Synchronization-{4CF6FEFD-FA0D-4336-A241-5AE5E18CD9A7}.job<br />
- c:\windows\system32\msfeedssync.exe [2006-10-17 09:31]<br />
.<br />
.<br />
------- Supplementary Scan -------<br />
.<br />
uStart Page = hxxp://www.radiancespaonline.com/<br />
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&amp;sourceid=ie7&amp;rls=com.micros  oft:en-US&amp;ie=utf8&amp;oe=utf8<br />
uInternet Connection Wizard,ShellNext = iexplore<br />
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s<br />
IE: &amp;AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\gbact95u.default\<br />
<br />
---- FIREFOX POLICIES ----<br />
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref(&quot;security.ssl3.rsa_seed_sha&quot;, true);<br />
.<br />
<br />
**************************************************  ************************<br />
<br />
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, <a href="http://www.gmer.net" target="_blank">GMER - Rootkit Detector and Remover</a><br />
Rootkit scan 2009-11-16 17:17<br />
Windows 5.1.2600 Service Pack 3 NTFS<br />
<br />
scanning hidden processes ...  <br />
<br />
scanning hidden autostart entries ... <br />
<br />
HKLM\Software\Microsoft\Windows\CurrentVersion\Run<br />
  LXCECATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtim  e.dll,_RunDLLEntry@16?????????????????????????????  ??????????????????????????????????????????????????  ??????????????????????????????????????????????????  ?????????????????????????????????????????????????? <br />
<br />
scanning hidden files ...  <br />
<br />
scan completed successfully<br />
hidden files: 0<br />
<br />
**************************************************  ************************<br />
.<br />
--------------------- LOCKED REGISTRY KEYS ---------------------<br />
<br />
[HKEY_USERS\S-1-5-21-3821449246-365570171-4292477666-1003\Software\Microsoft\SystemCertificates\Address  Book*]<br />
@Allowed: (Read) (RestrictedCode)<br />
@Allowed: (Read) (RestrictedCode)<br />
.<br />
--------------------- DLLs Loaded Under Running Processes ---------------------<br />
<br />
- - - - - - - &gt; 'winlogon.exe'(592)<br />
c:\program files\SUPERAntiSpyware\SASWINLO.dll<br />
c:\windows\system32\WININET.dll<br />
c:\windows\system32\Ati2evxx.dll<br />
<br />
- - - - - - - &gt; 'explorer.exe'(3004)<br />
c:\windows\system32\WININET.dll<br />
c:\windows\system32\ieframe.dll<br />
c:\windows\system32\webcheck.dll<br />
.<br />
Completion time: 2009-11-16 17:21<br />
ComboFix-quarantined-files.txt  2009-11-16 22:21<br />
ComboFix2.txt  2009-11-16 21:46<br />
<br />
Pre-Run: 81,239,265,280 bytes free<br />
Post-Run: 81,217,851,392 bytes free<br />
<br />
- - End Of File - - 8E9235FF0AE258CDD1D2246615C22150</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/fixed-hijackthis-logs/13808d1258411845-internet-running-slow-after-malware-removal-attach.txt" target="_blank">Attach.txt</a> (17.2 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>redeyebo</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/80791-internet-running-slow-after-malware-removal.html</guid>
		</item>
		<item>
			<title>Internet Explorer popups while using Firefox</title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/80743-internet-explorer-popups-while-using-firefox.html</link>
			<pubDate>Sun, 15 Nov 2009 20:15:58 GMT</pubDate>
			<description>Every time I get onto Firefox two things happen... 
 
1) Internet Explorer opens with some ad for spyware software and... 
 
2) If I click a link on...</description>
			<content:encoded><![CDATA[<div>Every time I get onto Firefox two things happen...<br />
<br />
1) Internet Explorer opens with some ad for spyware software and...<br />
<br />
2) If I click a link on google search engine, or I type in a web address, it takes me to some random site about spyware or &quot;bigsearchfinder&quot;.<br />
<br />
I can't figure out how to fix it (norton anti-virus didn't help) so I used HijackThis, and this is my log.  Can anyone tell me what I need to do next?<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 2:04:39 PM, on 11/15/2009<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18828)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Program Files\Norton AntiVirus\Engine\17.1.0.19\ccSvcHst.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\SYSTEM32\WISPTIS.EXE<br />
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Windows\System32\WLTRAY.EXE<br />
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe<br />
C:\Windows\WindowsMobile\wmdSync.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Windows\System32\igfxtray.exe<br />
C:\Windows\System32\hkcmd.exe<br />
C:\Windows\System32\igfxpers.exe<br />
C:\Windows\sttray.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo  tifier.exe<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Users\Jessica\Desktop\HijackThis.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Windows Live\Toolbar\wltuser.exe<br />
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe<br />
C:\Windows\system32\Macromed\Flash\FlashUtil10c.ex  e<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int  ernet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: (no name) - {015E788C-C6CC-4822-9E23-A7A17E28A3A7} - C:\Windows\System32\dot3dlg32.dll<br />
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\17.1.0.19\IPSBHO.DLL<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\s  wg.dll<br />
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll<br />
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll<br />
O3 - Toolbar: &amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe<br />
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] &quot;C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VER  SIO~2.EXE<br />
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe<br />
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [Google Quick Search Box] &quot;C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe&quot;  /autorun<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo  tifier.exe&quot;<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6  097707281E79.dll/cmsidewiki.html<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL<br />
O13 - Gopher Prefix: <br />
O16 - DPF: Web-Based Email Tools - <a href="http://email.secureserver.net/Download.CAB" target="_blank">http://email.secureserver.net/Download.CAB</a><br />
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - <a href="http://lads.myspace.com/upload/MySpaceUploader1005.cab" target="_blank">http://lads.myspace.com/upload/MySpaceUploader1005.cab</a><br />
O16 - DPF: {54EABC7D-40DC-4667-8517-F42D00540342} (DRMActiveXControl Class) - <a href="http://tegrity.sagu.edu/tegrity/_Player/1.0/code/DRMActiveX.CAB" target="_blank">http://tegrity.sagu.edu/tegrity/_Pla...DRMActiveX.CAB</a><br />
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - <a href="http://upload.facebook.com/controls/FacebookPhotoUploader2.cab" target="_blank">http://upload.facebook.com/controls/...oUploader2.cab</a><br />
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - <a href="http://upload.facebook.com/controls/FacebookPhotoUploader.cab" target="_blank">http://upload.facebook.com/controls/...toUploader.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - <a href="http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab" target="_blank">http://dlm.tools.akamai.com/dlmanage...ex-2.2.1.6.cab</a><br />
O20 - AppInit_DLLs: C:\Windows\System32\dmutil32.dll<br />
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe<br />
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe (file missing)<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: HWSuperPowerTablet - Unknown owner - C:\Windows\jwpen.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Norton AntiVirus (NAV) - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\17.1.0.19\ccSvcHst.exe<br />
O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe (file missing)<br />
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe<br />
O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)<br />
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE<br />
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe<br />
<br />
--<br />
End of file - 11608 bytes<br />
<br />
I would really appreciate anything that will help fix my laptop! Thanks so much!</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>supersteve118</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/80743-internet-explorer-popups-while-using-firefox.html</guid>
		</item>
		<item>
			<title>Laptop running slow - hijackthis analysis</title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/80682-laptop-running-slow-hijackthis-analysis.html</link>
			<pubDate>Sat, 14 Nov 2009 13:50:10 GMT</pubDate>
			<description>Hi all,  
my laptop is running very slowly, i did a scan with hijackthis but need help to check it... 
 
Logfile of Trend Micro HijackThis v2.0.2...</description>
			<content:encoded><![CDATA[<div>Hi all, <br />
my laptop is running very slowly, i did a scan with hijackthis but need help to check it...<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 13:35:00, on 14/11/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe<br />
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
C:\WINDOWS\SOUNDMAN.EXE<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\NETGEAR GA511 Adapter\GA511.exe<br />
C:\Program Files\3M\PSNLite\PsnLite.exe<br />
C:\Program Files\Logitech\MouseWare\system\em_exec.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\WINDOWS\system32\CTsvcCDA.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\PROGRA~1\3M\PSNLite\PSNGive.exe<br />
C:\WINDOWS\system32\slmdmsr.exe<br />
C:\WINDOWS\System32\PAStiSvc.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
C:\Program Files\Skype\Phone\Skype.exe<br />
C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe<br />
C:\Program Files\Skype\Plugin Manager\skypePM.exe<br />
C:\Documents and Settings\Propriétaire\Bureau\RootkitBuster.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.google.fr/" target="_blank">Google</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int  ernet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens<br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll<br />
O4 - HKLM\..\Run: [COMODO Internet Security] &quot;C:\Program Files\COMODO\COMODO Internet Security\cfp.exe&quot; -h<br />
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe<br />
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br />
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')<br />
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')<br />
O4 - Global Startup: GA511 Smart Wizard Utility.lnk = ?<br />
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe<br />
O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convertir en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Translate with &amp;Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - <a href="http://www.pcpitstop.com/betapit/PCPitStop.CAB" target="_blank">http://www.pcpitstop.com/betapit/PCPitStop.CAB</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1245798116125" target="_blank">http://update.microsoft.com/windowsu...?1245798116125</a><br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL<br />
O20 - AppInit_DLLs:   C:\WINDOWS\system32\guard32.dll<br />
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe<br />
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe<br />
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe<br />
O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slmdmsr.exe<br />
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe<br />
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe<br />
<br />
--<br />
End of file - 7530 bytes</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>oneyed</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/80682-laptop-running-slow-hijackthis-analysis.html</guid>
		</item>
		<item>
			<title>pc randomly freezes - windows xp</title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/80673-pc-randomly-freezes-windows-xp.html</link>
			<pubDate>Sat, 14 Nov 2009 07:24:20 GMT</pubDate>
			<description><![CDATA[Sorry, I'm a total noob when it comes to this but need help.  Tried to totally rebuild an old Dell I had and now the thing constantly randomly...]]></description>
			<content:encoded><![CDATA[<div>Sorry, I'm a total noob when it comes to this but need help.  Tried to totally rebuild an old Dell I had and now the thing constantly randomly freezes up.  CTRL+ALT+DEL will not help, no errors, just completely frozen.  Happens when surfing the web, copying files, playing games, etc.  This is what I've put in it.  I'm guessing some incompatibility issues???<br />
 <br />
Elitegroup C51GM-M Motherboard<br />
AMD 64 3200+ 2.01 Ghz, 1 GB of <acronym title="Random Access Memory">RAM</acronym><br />
Nvidia Geforce 7600GS<br />
Maxtor 300GB HD<br />
DYNEX DX-UC104 USB 2.0 4-port<br />
DYNEX DX-4P2H USB hub<br />
Logitech wireless mouse<br />
Windows XP Home Edition SP3<br />
I sometimes use my Sony DVD external drive, if that has anything to do with it...<br />
 <br />
I've tried so many things with my limited pc knowledge.  I recently reinstalled windows xp to see if that would help.  Based on other web advice, I tried setting the hardware accelation to &quot;none&quot; and that didn't work.  I tried updating the drivers.  No luck.  It has to be a hardware issue, right?<br />
 <br />
Appreciate any help.  I'm desperate to get gaming again!!!  Thank you in advance.</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>bmvla</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/80673-pc-randomly-freezes-windows-xp.html</guid>
		</item>
		<item>
			<title><![CDATA[Keyboard & Mouse freeze up during gameplay]]></title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/80618-keyboard-mouse-freeze-up-during-gameplay.html</link>
			<pubDate>Fri, 13 Nov 2009 01:45:28 GMT</pubDate>
			<description>Hey, its me again. I have the same issue as i have previously had before. I suspect that it will also be the same cause as before. Here is the link...</description>
			<content:encoded><![CDATA[<div>Hey, its me again. I have the same issue as i have previously had before. I suspect that it will also be the same cause as before. Here is the link to my previously submitted hijackthis &amp; combo fix logs. <a href="!70814!http://www.pchelpforum.com/fixed-hijackthis-logs/70814-keyboard-mouse-freeze-during-gameplay.html" target="_blank">http://www.pchelpforum.com/fixed-hij...-gameplay.html</a>  I am having the same exact issues as before down to the letter. <br />
<br />
Here is my Hijackthis log:<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 5:58:15 PM, on 11/12/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe<br />
C:\WINDOWS\system32\PnkBstrA.exe<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
C:\WINDOWS\system32\PnkBstrB.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\WINDOWS\system32\RUNDLL32.EXE<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Documents and Settings\Suzanne\Desktop\HijackThis.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int  ernet Settings,ProxyOverride = *.local<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: (no name) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - (no file)<br />
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: (no name) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - (no file)<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)<br />
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [Google Update] &quot;C:\Documents and Settings\Suzanne\Local Settings\Application Data\Google\Update\GoogleUpdate.exe&quot; /c<br />
O4 - HKCU\..\Run: [BitTorrent DNA] &quot;C:\Program Files\DNA\btdna.exe&quot;<br />
O4 - HKCU\..\Run: [JumiController] C:\Program Files\Jumi\Jumi.exe<br />
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O15 - Trusted Zone: <a href="http://www.msn.com" target="_blank">MSN.com</a><br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a href="http://go.microsoft.com/fwlink/?linkid=39204" target="_blank">http://go.microsoft.com/fwlink/?linkid=39204</a><br />
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - <a href="http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab" target="_blank">http://www.nvidia.com/content/Driver...sysreqlab3.cab</a><br />
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - <a href="http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab" target="_blank">http://www.fileplanet.com/fpdlmgr/ca..._2.3.9.113.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1217360418556" target="_blank">http://www.update.microsoft.com/wind...?1217360418556</a><br />
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - <a href="http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab" target="_blank">http://www.nvidia.com/content/Driver...aSmartScan.cab</a><br />
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - <a href="http://javadl.sun.com/webapps/download/AutoDL?BundleId=27986" target="_blank">http://javadl.sun.com/webapps/downlo...BundleId=27986</a><br />
O16 - DPF: {99CAAA27-FA0C-4FA4-B88A-4AB1CC7A17FE} (MGLaunch_v1004 Class) - <a href="http://www.netgame.com/mplugin/mglaunch_USAv1004.cab" target="_blank">http://www.netgame.com/mplugin/mglaunch_USAv1004.cab</a><br />
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - <br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe<br />
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe<br />
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe<br />
<br />
--<br />
End of file - 8106 bytes<br />
<br />
<br />
Performing ComboFix log atm. Will post it soon.</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>remorce</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/80618-keyboard-mouse-freeze-up-during-gameplay.html</guid>
		</item>
		<item>
			<title>Hotmail sending e-mails on its own</title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/80616-hotmail-sending-e-mails-its-own.html</link>
			<pubDate>Fri, 13 Nov 2009 01:11:23 GMT</pubDate>
			<description><![CDATA[Hi, my hotmail is sending spam e-mails out to various people on it's own. It started about 2 months ago where it did it to all of my contacts so i...]]></description>
			<content:encoded><![CDATA[<div>Hi, my hotmail is sending spam e-mails out to various people on it's own. It started about 2 months ago where it did it to all of my contacts so i deleted the contacts so &quot;it&quot; didn't have any addresses to send to but it still does it. It's very annoying as i keep getting people ringing me up asking what it is &quot;i&quot; have sent them, it's doing my head in and i'm worried something more than &quot;get free gifts this christmas&quot; might turn up and they will think the worse of me.<br />
 <br />
All of my family use there hotmail accounts on the computer but it seems only my account that is doing it.<br />
 <br />
Anyone have any ideas?<br />
 <br />
Thanks:mrgreen:</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>TomTom</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/80616-hotmail-sending-e-mails-its-own.html</guid>
		</item>
		<item>
			<title>Hijackthis file analysis</title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/80614-hijackthis-file-analysis.html</link>
			<pubDate>Thu, 12 Nov 2009 23:36:32 GMT</pubDate>
			<description>Hello, I am new to the pchf. Would someone please review my file from the hijackthis scan to determine if I have a virus. I believe it may be the...</description>
			<content:encoded><![CDATA[<div>Hello, I am new to the pchf. Would someone please review my file from the hijackthis scan to determine if I have a virus. I believe it may be the pchealth virus.<br />
 <br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 6:03:30 PM, on 11/12/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe<br />
C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
C:\WINDOWS\system32\igfxtray.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe<br />
C:\Program Files\Picasa2\PicasaMediaDetector.exe<br />
C:\Program Files\Winamp\winampa.exe<br />
C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe<br />
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe<br />
C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe<br />
C:\Program Files\Fast Browser SearchP\FastBrowserSearchProtection.exe<br />
C:\Program Files\QuickTime\QTTask.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Messenger\msmsgs.exe<br />
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe<br />
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe<br />
C:\WINDOWS\SCMain.exe<br />
C:\WINDOWS\WCMain.exe<br />
C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\wltrysvc.exe<br />
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe<br />
C:\WINDOWS\System32\bcmwltry.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Logitech\QuickCam10\COCIManager.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://cgi.verizon.net/bookmarks/bmredir.asp?region=all&amp;bw=dsl&amp;cd=5.1.5&amp;bm=ho_search" target="_blank">Verizon Online - Find what you're looking for.</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr6/*http://www.yahoo.com" target="_blank">Yahoo!</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html" target="_blank">Yahoo! SearchBar Home Page</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = <a href="http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com" target="_blank">Yahoo!</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br />
R3 - URLSearchHook: ToolbarURLSearchHook Class - {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files\Fast Browser Search\IE\tbhelper.dll<br />
O1 - Hosts: ::1 localhost<br />
O1 - Hosts: 91.212.127.227 winwarepro.microsoft.com<br />
O1 - Hosts: 91.212.127.227 winwarepro.com<br />
O1 - Hosts: 91.212.127.227 <a href="http://www.winwarepro.com" target="_blank">www.winwarepro.com</a><br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: My Global Search Bar BHO - {37B85A21-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL<br />
O2 - BHO: (no name) - {3EBBD0F6-1F1F-48A0-89DC-C7505D56E92A} - (no file)<br />
O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll (file missing)<br />
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\s  wg.dll<br />
O2 - BHO: BHO - {B6D223F6-C185-49a2-BA7E-A03E84744702} - C:\WINDOWS\system32\iehelper.dll<br />
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll<br />
O3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll (file missing)<br />
O3 - Toolbar: Fast Browser Search - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll<br />
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [UpdateManager] &quot;C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe&quot; /r<br />
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe<br />
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start<br />
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe<br />
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe<br />
O4 - HKLM\..\Run: [LogitechCommunicationsManager] &quot;C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe&quot;<br />
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] &quot;C:\Program Files\Logitech\QuickCam10\QuickCam10.exe&quot; /hide<br />
O4 - HKLM\..\Run: [LVCOMSX] &quot;C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe&quot;<br />
O4 - HKLM\..\Run: [FBSearch] C:\Program Files\Fast Browser SearchP\FastBrowserSearchProtection.exe<br />
O4 - HKLM\..\Run: [Microsoft Default Manager] &quot;C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe&quot; -resume<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [avgnt] &quot;C:\Program Files\Avira\AntiVir Desktop\avgnt.exe&quot; /min<br />
O4 - HKLM\..\Run: [eoteibva] C:\Documents and Settings\User\Local Settings\Application Data\hdwjae\pppisysguard.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [MSMSGS] &quot;C:\Program Files\Messenger\msmsgs.exe&quot; /background<br />
O4 - HKCU\..\Run: [eoteibva] C:\Documents and Settings\User\Local Settings\Application Data\hdwjae\pppisysguard.exe<br />
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe<br />
O4 - Global Startup: Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe<br />
O4 - Global Startup: Stardust Screen Saver Control 2003.lnk = C:\WINDOWS\SCMain.exe<br />
O4 - Global Startup: Stardust Wallpaper Control 2003.lnk = C:\WINDOWS\WCMain.exe<br />
O8 - Extra context menu item: &amp;Yahoo! Search - <a href="file:///C:\Program" target="_blank">file:///C:\Program</a> Files\Yahoo!\Common/ycsrch.htm<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Yahoo! &amp;Dictionary - <a href="file:///C:\Program" target="_blank">file:///C:\Program</a> Files\Yahoo!\Common/ycdict.htm<br />
O8 - Extra context menu item: Yahoo! &amp;Maps - <a href="file:///C:\Program" target="_blank">file:///C:\Program</a> Files\Yahoo!\Common/ycdict.htm<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=Q304&amp;bd=presar  io&amp;pf=laptop<br />
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - <a href="http://photo2.walgreens.com/WalgreensActivia.cab" target="_blank">http://photo2.walgreens.com/WalgreensActivia.cab</a><br />
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - <a href="http://apps.corel.com/nos_dl_manager/plugin/IEGetPlugin.cab" target="_blank">http://apps.corel.com/nos_dl_manager...EGetPlugin.cab</a><br />
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - <a href="http://offers.e-centives.com/cif/download/bin/actxcab.cab" target="_blank">http://offers.e-centives.com/cif/dow...in/actxcab.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: getPlus(R) Installer - Unknown owner - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (file missing)<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe<br />
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe<br />
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe<br />
--<br />
End of file - 11093 bytes</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>sammitch</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/80614-hijackthis-file-analysis.html</guid>
		</item>
		<item>
			<title>Pls check my laptop</title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/80587-pls-check-my-laptop.html</link>
			<pubDate>Thu, 12 Nov 2009 13:17:41 GMT</pubDate>
			<description><![CDATA[hi! my laptop is just new (3 weeks old) and i find it slow.  i dunno if it's normal or it has s/thing to do with virus. pls see below logs: 
 
root...]]></description>
			<content:encoded><![CDATA[<div>hi! my laptop is just new (3 weeks old) and i find it slow.  i dunno if it's normal or it has s/thing to do with virus. pls see below logs:<br />
<br />
root repeal:<br />
ROOTREPEAL (c) AD, 2007-2009<br />
==================================================<br />
Scan Start Time:        2009/11/12 21:02<br />
Program Version:        Version 1.3.5.0<br />
Windows Version:        Windows Vista SP2<br />
==================================================<br />
<br />
Drivers<br />
-------------------<br />
Name: dump_atapi.sys<br />
Image Path: C:\Windows\System32\Drivers\dump_atapi.sys<br />
Address: 0x8B7D6000    Size: 32768    File Visible: No    Signed: -<br />
Status: -<br />
<br />
Name: dump_dumpata.sys<br />
Image Path: C:\Windows\System32\Drivers\dump_dumpata.sys<br />
Address: 0x8B7CB000    Size: 45056    File Visible: No    Signed: -<br />
Status: -<br />
<br />
Name: rootrepeal.sys<br />
Image Path: C:\Windows\system32\drivers\rootrepeal.sys<br />
Address: 0xA47ED000    Size: 49152    File Visible: No    Signed: -<br />
Status: -<br />
<br />
Hidden/Locked Files<br />
-------------------<br />
Path: C:\hiberfil.sys<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{0646f5ec-cd40-11de-98cc-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{135db894-c990-11de-bb96-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{274ecb5d-c096-11de-9ce5-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{274ecb73-c096-11de-9ce5-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{458d794e-c62e-11de-8aa6-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{61ed0b4a-c364-11de-8ffe-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{61ed0b4e-c364-11de-8ffe-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{715e3baf-c0e8-11de-b699-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{715e3bb5-c0e8-11de-b699-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{715e3bbb-c0e8-11de-b699-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{715e3bc2-c0e8-11de-b699-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{7e7b150f-cdfe-11de-8036-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{84f28da4-cf10-11de-99e2-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{88f1aa8a-c22f-11de-a634-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{88f1aaf6-c22f-11de-a634-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{91a81bca-c415-11de-a51a-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{91a81c3a-c415-11de-a51a-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{a5d4aed8-c3d3-11de-8351-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{a92dd519-c082-11de-9dce-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{61ed0b56-c364-11de-8ffe-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{61ed0b5a-c364-11de-8ffe-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{61ed0b5e-c364-11de-8ffe-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{61ed0b62-c364-11de-8ffe-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{61ed0b66-c364-11de-8ffe-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{61ed0b6d-c364-11de-8ffe-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{61ed0b71-c364-11de-8ffe-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{61ed0b52-c364-11de-8ffe-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{715e3ba9-c0e8-11de-b699-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{a92dd77a-c082-11de-9dce-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{c6859769-c883-11de-ac4d-00242ccfd1a5}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{c685976d-c883-11de-ac4d-00242ccfd1a5}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{c6859779-c883-11de-ac4d-00242ccfd1a5}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{df34a64f-c09f-11de-a705-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{f41d07a6-c146-11de-aa1d-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{f848c2ab-c14a-11de-9ec4-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{66429622-cb71-11de-b301-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{715e3b8a-c0e8-11de-b699-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{715e3b90-c0e8-11de-b699-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{715e3b97-c0e8-11de-b699-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{715e3b9d-c0e8-11de-b699-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\System Volume Information\{715e3ba3-c0e8-11de-b699-00238bcd7516}{3808876b-c176-4e48-b7ae-04046e6cc752}<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\System32\GATHER~1.VBS<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\System32\GATHER~1.XSL<br />
Status: Locked to the Windows API!<br />
<br />
Path: c:\windows\temp\mcmsc_bhadcuczcjtrqoi<br />
Status: Allocation size mismatch (API: 4096, Raw: 0)<br />
<br />
Path: c:\windows\temp\sqlite_kxyrgnsfz8g0rgw<br />
Status: Allocation size mismatch (API: 4096, Raw: 0)<br />
<br />
Path: c:\windows\temp\sqlite_ms9jqf3gdj8jjda<br />
Status: Allocation size mismatch (API: 4096, Raw: 0)<br />
<br />
Path: c:\windows\temp\sqlite_nlm7kwcgiernbrd<br />
Status: Allocation size mismatch (API: 4096, Raw: 0)<br />
<br />
Path: c:\windows\temp\sqlite_u6aigjr16xplm2r<br />
Status: Allocation size mismatch (API: 4096, Raw: 0)<br />
<br />
Path: c:\windows\temp\sqlite_y5j3ifcmxu6zjbs<br />
Status: Allocation size mismatch (API: 4096, Raw: 0)<br />
<br />
Path: c:\windows\temp\sqlite_0msx5tojakfi0vo<br />
Status: Allocation size mismatch (API: 4096, Raw: 0)<br />
<br />
Path: c:\windows\temp\sqlite_1e4wverd5rl77ba<br />
Status: Allocation size mismatch (API: 4096, Raw: 0)<br />
<br />
Path: c:\windows\temp\sqlite_4qccplepy8cwu7s<br />
Status: Allocation size mismatch (API: 4096, Raw: 0)<br />
<br />
Path: c:\windows\temp\sqlite_82owf8gs7c9cm5j<br />
Status: Allocation size mismatch (API: 4096, Raw: 0)<br />
<br />
Path: C:\Windows\PLA\Reports\REPORT~1.XML<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\PLA\Rules\RULESS~1.XML<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\PLA\System\WIRELE~1.XML<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Catalogs\amd64_microsoft.vc90.op  enmp_1fc8b3b9a1e18e3b_9.0.30729.1_none_c9dd3cb0e55  5217c.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsof  t.vc90.openmp_1fc8b3b9a1e18e3b_9.0.30729.1_none_9f  63b3c292618dec.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.open  mp_1fc8b3b9a1e18e3b_9.0.30729.1_none_118a7387f9d14  a82.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Catalogs\amd64_policy.9.0.micros  oft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.30729.1_none_  57b67ceb7de564e6.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Manifests\a2492fa83366394b7c17fa  6c9650ce5688b887d0ad0ad79743a3422debf4d997.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Manifests\534cf013667c78b2ecf44e  00183c95e4c2336f1e150a38452cd7e61ec2a73bfc.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Manifests\dd72f7ab2def5f75f58d01  b24643b308750c38685daaed50bcddf61c18460dee.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Manifests\989e628160e12c984a435d  2bb2a335ad043e006646150c7b1f3bb52dccd842cc.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Manifests\d14225a52543aa5a9605b0  0dd7574812bf89c605ebc73a9730e1e386bfc965f8.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Manifests\935df4549e21123a2efb98  6a707f54475380a037519679510e4b4dfc4bdb5767.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Manifests\88b03fe13d2710ad787d5d  96cd0e5cbeda3a61c2a0a2bdc0c0984a48365242e2.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Manifests\b080e112e69d2e9c8e71ac  d39a81f0d469d837625ceb8ed73b5b87da1fd1424c.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Manifests\26340819d2ef86080d9001  c6f2737d70fd6602ddf4b86b6c26b326ef81cc3342.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Manifests\ef483ae0673e2975dd4224  fe26749623c1c702b8b3fded10161417459e1771a7.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Manifests\2d3cb7907b1336ea5889a2  b731d5e97ad40903a4efd2287c1c117bc30f208f46.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Manifests\d5ecf2ab9387e082648bbc  ccd6eceb9d67b096939150833d0ae3066b3a1a676e.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Manifests\bd83dce340498e7c363093  c2fc74dfb58e1ec17770453905172c7471fadd9333.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Manifests\610730c853431925508643  e33960e750427cd10c421d9ddced230f74ec671e4b.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Manifests\b643d2bc101b4fb5e41380  ec953ffef572cd8c97f43c6cff8fa6b4538e188ba0.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Manifests\71503c1b988fb27a41668f  3ba35468d268daf07e8e79cf7b82a1ef64a8d213a1.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Manifests\f7bf65ca621d8ad32ead15  00a08827be239d0f49d83dc20dabf57d2eb17adbd7.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Manifests\91ca50cec42075fff02b36  6323bf3b45d2053b24544bd12b622b65621bd0edd5.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Manifests\b3beb16c28db357e654a6b  132f59cd48cb95cee949d7b97587f8f02f233f3ce1.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Manifests\1154a0dd8ec7062351d700  a2d07b3bb5154c840bfc84077d20f6947d1e08bb6f.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Manifests\3dd5a727f2a1142223c6d9  a7bff73ae7676aac714a4da8192f66123045b11c41.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Manifests\a951d53950c367acc37622  f0dd619a954df5de2c4ec40296e6636605aa33714a.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Manifests\8b414e757cb8b153bff77d  d00a36556aea3adab25ce15f3e8b184ffbf41ba7a2.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\Manifests\ec6ab08cec3c4a5939ec1a  58eda071d547416f00bee0e337715c0e20fbe1e1bf.cat<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_fundisc_31bf3856ad364e35_6.0  .6001.18000_none_7be46ed83ae29055\$$DeleteMe.fundi  sc.dll.01ca56511ad4884b.0039<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-a..dcredentialprovider_31bf3856ad364e35_6.0.6001.1  8000_none_420aa4b9c28d5162\$$DeleteMe.SmartcardCre  dentialProvider.dll.01ca56512ee2fe2b.006a<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.0.6001.18000_non  e_d51103be4cb9d6c3\$$DeleteMe.apphelp.dll.01ca5651  3a2cc36b.0090<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-a..terface-ldapc-layer_31bf3856ad364e35_6.0.6001.18000_none_5f32743  9667d597c\$$DeleteMe.adsldpc.dll.01ca56511a9b674b.  0037<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-advapi32_31bf3856ad364e35_6.0.6001.18000_none_e348  51aa8681b8b0\$$DeleteMe.advapi32.dll.01ca565110897  62b.001c<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6001.18000_none_769  fc426e49fbfda\$$DeleteMe.audiodg.exe.01ca565110cc1  cab.001d<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6001.18000_none_769  fc426e49fbfda\$$DeleteMe.AudioSes.dll.01ca56512d5a  3b4b.0065<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6001.18000_none_769  fc426e49fbfda\$$DeleteMe.audiosrv.dll.01ca565137fd  604b.0089<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-atl_31bf3856ad364e35_6.0.6001.18000_none_ab203fc65  9b26ce7\$$DeleteMe.atl.dll.01ca54a2a843ef20.0012<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-atl_31bf3856ad364e35_6.0.6001.18293_none_aac1f5245  9f8aeb3\$$DeleteMe.atl.dll.01ca56512f71d0ab.006c<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-authentication-authui_31bf3856ad364e35_6.0.6001.18000_none_0bf37d  16f567e1f7\$$DeleteMe.authui.dll.01ca56512aa0c86b.  005f<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-bits-client_31bf3856ad364e35_6.0.6001.18000_none_2390c4  ecf9720b8c\$$DeleteMe.qmgr.dll.01ca56512551974b.00  54<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_ee8c936ce  f65a88f\$$DeleteMe.bcrypt.dll.01ca56511235edab.001  f<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-bits-igdsearcher_31bf3856ad364e35_6.0.6001.18000_none_b  16c3d098f004f58\$$DeleteMe.bitsigd.dll.01ca5651226  aea4b.004d<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-bth-user_31bf3856ad364e35_6.0.6001.18000_none_65193feb  d52e137a\$$DeleteMe.bthprops.cpl.01ca565135fb374b.  0083<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-c..complus-eventsystem_31bf3856ad364e35_6.0.6001.18057_none_0  cbe918751dfdd3f\$$DeleteMe.es.dll.01ca565137b1344b  .0088<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-c..ent-indexing-common_31bf3856ad364e35_6.0.6001.18000_none_06b40d  cad71051f6\$$DeleteMe.Query.dll.01ca56512474376b.0  050<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-c..rformance-xperfcore_31bf3856ad364e35_6.0.6001.18000_none_d71  173946e986845\$$DeleteMe.diagperf.dll.01ca565140bf  af8b.00a1<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-c..tionauthorityclient_31bf3856ad364e35_6.0.6001.1  8000_none_d77db57c3ca78826\$$DeleteMe.certcli.dll.  01ca56511b8bd22b.003b<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-audio-mmecore-base_31bf3856ad364e35_6.0.6001.18000_none_b5dfbc3a  51b01b87\$$DeleteMe.winmm.dll.01ca5651341f244b.007  c<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-cmi_31bf3856ad364e35_6.0.6001.18000_none_a9ce4a485  a8ade99\$$DeleteMe.cmiv2.dll.01ca56514e2cf10b.00b2<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-com-base-qfe-ole32_31bf3856ad364e35_6.0.6001.18000_none_ac1da75  bf2516084\$$DeleteMe.ole32.dll.01ca56511eccf36b.00  46<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.0.6001.18000_none_69cadbf  c3ddffe3c\$$DeleteMe.rpcss.dll.01ca54a2a5b2f3a0.00  08<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.0.6001.18226_none_69bb41a  c3deac876\$$DeleteMe.rpcss.dll.01ca5651372985eb.00  86<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-comdlg32_31bf3856ad364e35_6.0.6001.18000_none_b5b1  11a1a5a793a5\$$DeleteMe.comdlg32.dll.01ca56511bb6a  aeb.003c<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-coreusermodepnp_31bf3856ad364e35_6.0.6001.18000_no  ne_7701ab362cebf905\$$DeleteMe.umpnpmgr.dll.01ca56  513c849deb.0098<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-credui_31bf3856ad364e35_6.0.6001.18000_none_db374c  c18eed7408\$$DeleteMe.credui.dll.01ca5651093a7d6b.  000a<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-crypt32-dll_31bf3856ad364e35_6.0.6001.18000_none_5b6fc1dbd  dd3c6da\$$DeleteMe.crypt32.dll.01ca565130caf80b.00  72<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6001.18000_none_75ff99649  acf4de9\$$DeleteMe.cryptsvc.dll.01ca56511e28b48b.0  042<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-cryptui-dll_31bf3856ad364e35_6.0.6001.18000_none_85ee5b5e9  8235317\$$DeleteMe.cryptui.dll.01ca565128d7c06b.00  5b<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-d..pwindowmanager-core_31bf3856ad364e35_6.0.6001.18000_none_8da39414  bd31fb37\$$DeleteMe.uxsms.dll.01ca56513b45a5ab.009  3<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-dhcp-client-dll_31bf3856ad364e35_6.0.6001.18000_none_d75a29a02  e8fcf7a\$$DeleteMe.dhcpcsvc.dll.01ca56513b94330b.0  095<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-dhcp-client-dll_31bf3856ad364e35_6.0.6001.18000_none_d75a29a02  e8fcf7a\$$DeleteMe.dhcpcsvc6.dll.01ca56510a0733ab.  000d<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.0.6001.18000_none_b1ee595da  0f48e64\$$DeleteMe.samlib.dll.01ca56512420e74b.004  f<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.0.6001.18000_none_b1ee595da  0f48e64\$$DeleteMe.samsrv.dll.01ca56510f4f40ab.001  8<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client-winrnr_31bf3856ad364e35_6.0.6000.16386_none_571790  f3532b2696\$$DeleteMe.winrnr.dll.01ca56514246110b.  00a4<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-e..-protocol-host-peer_31bf3856ad364e35_6.0.6001.18000_none_64138b2c  c36a286b\$$DeleteMe.eappcfg.dll.01ca56510a17dd4b.0  00e<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-e..-protocol-host-peer_31bf3856ad364e35_6.0.6001.18000_none_64138b2c  c36a286b\$$DeleteMe.eapphost.dll.01ca56514048aacb.  00a0<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-e..emorydevicesservice_31bf3856ad364e35_6.0.6001.1  8098_none_9e329f52f6fc276d\$$DeleteMe.emdmgmt.dll.  01ca5651317b1dcb.0074<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-e..estorageengine-isam_31bf3856ad364e35_6.0.6001.18000_none_f1e446e1  2c0bbf09\$$DeleteMe.esent.dll.01ca56512b68bbeb.006  2<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.0.6001.18000_none_e1e27c  dd8259636b\$$DeleteMe.dnsapi.dll.01ca56510dc8df2b.  0015<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.0.6001.18000_none_e1e27c  dd8259636b\$$DeleteMe.dnsrslvr.dll.01ca5651189b9fa  b.0031<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-eventlog-api_31bf3856ad364e35_6.0.6001.18000_none_ac31021c6  54a3267\$$DeleteMe.wevtapi.dll.01ca56510a49da2b.00  0f<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-eventlog_31bf3856ad364e35_6.0.6001.18000_none_dcc4  5c1a12d92f84\$$DeleteMe.wevtsvc.dll.01ca5651100b4d  4b.0019<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-feclient_31bf3856ad364e35_6.0.6001.18000_none_beda  112b5794d4e0\$$DeleteMe.feclient.dll.01ca56513d02c  6cb.009a<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-feedback-service_31bf3856ad364e35_6.0.6001.18145_none_79a5b  70991018b47\$$DeleteMe.wersvc.dll.01ca56512f38afab  .006b<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-grouppolicy-base_31bf3856ad364e35_6.0.6001.18000_none_282361de  e702a605\$$DeleteMe.gpapi.dll.01ca565124f4c1ab.005  3<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-grouppolicy-base_31bf3856ad364e35_6.0.6001.18000_none_282361de  e702a605\$$DeleteMe.gpsvc.dll.01ca56513365790b.007  a<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-gdi32_31bf3856ad364e35_6.0.6001.18159_none_59519ee  04971f856\$$DeleteMe.gdi32.dll.01ca565130ac062b.00  71<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6001.1  8203_none_b4e61c85d6c731a6\$$DeleteMe.urlmon.dll.0  1ca54a2a8c6dac0.0013<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-i..nal-core-locale-nls_31bf3856ad364e35_6.0.6001.18000_none_6ab830d9a  945c1d1\$$DeleteMe.locale.nls.01ca565141d16dab.00a  2<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-i..oexistencemigration_31bf3856ad364e35_6.0.6001.1  8000_none_11e312d27c5a6ba6\$$DeleteMe.iphlpsvc.dll  .01ca5650fb39a6ab.0004<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.1  8203_none_01ebf827a1d05839\$$DeleteMe.wininet.dll.  01ca54a2a98ece40.0016<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-icm-base_31bf3856ad364e35_6.0.6001.18000_none_22c7ea54  89633945\$$DeleteMe.mscms.dll.01ca565124cc4a4b.005  2<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.18203_none  _134617462226c16f\$$DeleteMe.mshtml.dll.01ca54a2a9  0be2a0.0014<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.18203_n  one_47a6af038c817696\$$DeleteMe.iertutil.dll.01ca5  4a2a923b060.0015<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-imm32_31bf3856ad364e35_6.0.6001.18000_none_5c561e1  67a6afd02\$$DeleteMe.imm32.dll.01ca565115b02feb.00  28<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-installer-engine_31bf3856ad364e35_6.0.6001.18000_none_037a7e  2bb384bf01\$$DeleteMe.msi.dll.01ca56510e9cb98b.001  6<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-ldap-client_31bf3856ad364e35_6.0.6001.18000_none_f33c47  97566bb3db\$$DeleteMe.Wldap32.dll.01ca5651249f102b  .0051<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18000_none_a64a8ac25  ccb3836\$$DeleteMe.lsasrv.dll.01ca54a2a41e49e0.000  5<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18000_none_a64a8ac25  ccb3836\$$DeleteMe.secur32.dll.01ca54a2a43617a0.00  06<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-m..ayer-core.resources_31bf3856ad364e35_6.0.6000.16386_en-us_21450129e4b6dad8\$$DeleteMe.wmploc.DLL.mui.01ca  583bfc81d49b.0002<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-mfplat_31bf3856ad364e35_6.0.6001.18000_none_f6aa98  ad53755122\$$DeleteMe.mfplat.dll.01ca56510c2d114b.  0012<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-mmdeviceapi_31bf3856ad364e35_6.0.6001.18000_none_5  5044397b961da8a\$$DeleteMe.MMDevAPI.dll.01ca56513f  1cbd8b.009e<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-mprapi_31bf3856ad364e35_6.0.6001.18000_none_140c84  ec53049b39\$$DeleteMe.mprapi.dll.01ca5651097d23eb.  000c<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-mpr_31bf3856ad364e35_6.0.6001.18000_none_add5c9725  7f151a1\$$DeleteMe.mpr.dll.01ca56511cf5a32b.003f<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6000.16386_none_c52353  cea8765257\$$DeleteMe.msasn1.dll.01ca54a28f3736e0.  0001<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6001.18326_none_c74a7d  60a56c2a8c\$$DeleteMe.msasn1.dll.01ca56512d76cbcb.  0066<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.0.6001.18000_none  _c7427a4e786d74bc\$$DeleteMe.adtschema.dll.01ca565  1302b7beb.006f<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-msvcrt_31bf3856ad364e35_6.0.6001.18000_none_d15536  209ee61dad\$$DeleteMe.msvcrt.dll.01ca56512188c7ab.  004c<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6001.18136_none_8853d  47896e90b40\$$DeleteMe.msxml3.dll.01ca5651376c2c6b  .0087<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-msxml60_31bf3856ad364e35_6.0.6001.18138_none_88559  0b496e78ad1\$$DeleteMe.msxml6.dll.01ca5651436154ab  .00a6<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-n..-domain-clients-svc_31bf3856ad364e35_6.0.6001.18094_none_43b129ade  c4a9f41\$$DeleteMe.IPSECSVC.DLL.01ca5651201a33eb.0  049<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n  one_9d81873e2afd9b5e\$$DeleteMe.NaturalLanguage6.d  ll.01ca56513e1947ab.009d<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-ncrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_5dde5591f  19c0ea3\$$DeleteMe.ncrypt.dll.01ca56512a14574b.005  d<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-netapi32_31bf3856ad364e35_6.0.6001.18157_none_8d05  0f6301b2186f\$$DeleteMe.netapi32.dll.01ca5651357d0  e6b.0080<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-netshell_31bf3856ad364e35_6.0.6001.18000_none_d583  6ad30e0ac92d\$$DeleteMe.netshell.dll.01ca565136e47  e0b.0085<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.18000_none_cd24  6fe92a8ad809\$$DeleteMe.BFE.DLL.01ca5650faa6116b.0  002<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.18000_none_cd24  6fe92a8ad809\$$DeleteMe.FWPUCLNT.DLL.01ca5650fa825  ccb.0001<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.18000_none_cd24  6fe92a8ad809\$$DeleteMe.IKEEXT.DLL.01ca5650fc03fb8  b.0007<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-ntdll_31bf3856ad364e35_6.0.6001.18000_none_58d6de4  1fc2dac16\$$DeleteMe.ntdll.dll.01ca5650fb0085ab.00  03<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-o..inefiles-win32-apis_31bf3856ad364e35_6.0.6001.18000_none_ab6af9d0  f92539f0\$$DeleteMe.cscapi.dll.01ca56513b77a28b.00  94<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-onex_31bf3856ad364e35_6.0.6001.18000_none_a5cb1bed  1d5ba052\$$DeleteMe.onex.dll.01ca56510b05e6cb.0010<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-oleacc_31bf3856ad364e35_6.0.6001.18000_none_6a84bd  ce2263bb83\$$DeleteMe.oleacc.dll.01ca583bfde4817b.  0003<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-p..ooler-core-localspl_31bf3856ad364e35_6.0.6001.18000_none_301b  5dfb92ae18db\$$DeleteMe.localspl.dll.01ca54a2a7407  940.0010<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-p..ooler-core-localspl_31bf3856ad364e35_6.0.6001.18247_none_2ff7  241d92c8344e\$$DeleteMe.localspl.dll.01ca56513a4bb  54b.0091<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-p..pooler-core-spoolss_31bf3856ad364e35_6.0.6001.18000_none_5b399  2df8e604356\$$DeleteMe.spoolss.dll.01ca56512b2876c  b.0061<br />
Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\winsxs\x86_microsoft-windows-p..rnetprinting-client_31bf3856ad364e35_6.0.6001.18000_none_8ad265  adc8633a42\$$DeleteMe.inetpp.dll.Processes<br />
-------------------<br />
Path: System<br />
PID: 4    Status: Locked to the Windows API!<br />
<br />
Path: C:\Windows\System32\audiodg.exe<br />
PID: 1280    Status: Locked to the Windows API!<br />
<br />
==EOF==<br />
<br />
dds:<br />
<br />
DDS (Ver_09-10-26.01) - NTFSx86  <br />
Run by valjesnet at 21:17:02.49 on Thu 11/12/2009<br />
Internet Explorer: 8.0.6001.18828 BrowserJavaVersion: 1.6.0_17<br />
Microsoft® Windows Vista™ Home Basic   6.0.6002.2.1252.63.1033.18.2038.1127 [GMT 8:00]<br />
<br />
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}<br />
<br />
============== Running Processes ===============<br />
<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\svchost.exe -k rpcss<br />
C:\Windows\System32\svchost.exe -k secsvcs<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\system32\svchost.exe -k GPSvcGroup<br />
C:\Windows\system32\SLsvc.exe<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\system32\WLANExt.exe<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\svchost.exe -k bthsvcs<br />
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe<br />
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe<br />
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
C:\Windows\system32\rundll32.exe<br />
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
C:\Program Files\McAfee\MSK\MskSrver.exe<br />
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
C:\Program Files\Acer\Acer VCM\RS_Service.exe<br />
C:\Windows\system32\svchost.exe -k imgsvc<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
c:\PROGRA~1\mcafee.com\agent\mcagent.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\igfxtray.exe<br />
C:\Program Files\Launch Manager\LManager.exe<br />
C:\Windows\system32\IgfxExt.exe<br />
C:\Windows\system32\igfxsrvc.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo  tifier.exe<br />
C:\Windows\system32\PersistenceThread.exe<br />
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe<br />
C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe<br />
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe<br />
C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\Startup Faster\sfAgent.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Program Files\Acer\Acer VCM\AcerVCM.exe<br />
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br />
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe<br />
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe<br />
C:\Program Files\WordWeb\wweb32.exe<br />
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe<br />
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe<br />
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Windows\system32\SearchProtocolHost.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Users\valjesnet\Downloads\dds.scr<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
<br />
============== Pseudo <acronym title="HijackThis - Malware Removal Tool">HJT</acronym> Report ===============<br />
<br />
uStart Page = hxxp://www.yahoo.com<br />
uDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&amp;l=3409&amp;s=2&amp;o=vb32&amp;d=1009&amp;m=ao751h<br />
uSearch Page = <br />
uSearch Bar = <br />
mStart Page = hxxp://www.yahoo.com/<br />
mDefault_Page_URL = hxxp://www.yahoo.com/<br />
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s<br />
mSearchAssistant = <br />
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll<br />
uURLSearchHooks: H - No File<br />
BHO: &amp;Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll<br />
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll<br />
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll<br />
BHO: Partner BHO Class: {83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4} - c:\programdata\partner\partner.dll<br />
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll<br />
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll<br />
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\s  wg.dll<br />
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll<br />
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll<br />
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInsta  nce.dll<br />
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll<br />
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll<br />
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll<br />
TB: {EEE6C35B-6118-11DC-9C72-001320C79847} - No File<br />
uRun: [swg] &quot;c:\program files\google\googletoolbarnotifier\GoogleToolbarNo  tifier.exe&quot;<br />
uRun: [PC Suite Tray] &quot;c:\program files\nokia\nokia pc suite 7\PCSuite.exe&quot; -onlytray<br />
mRun: [StartupFaster] &quot;c:\program files\startup faster\startuploader.exe&quot; -run SFAURUN SFCURUN SFAUSTARTUP SFCUSTARTUP<br />
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\sta  rtup\startu~1\acervc~1.lnk - c:\program files\acer\acer vcm\AcerVCM.exe<br />
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\sta  rtup\startu~1\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe<br />
StartupFolder: c:\programdata\microsoft\windows\start menu\programs\startup\startupfaster\StartupFaster.  ini<br />
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\sta  rtup\startu~1\wordweb.lnk - c:\program files\wordweb\wweb32.exe<br />
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000<br />
IE: Send image to &amp;Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm<br />
IE: Send page to &amp;Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm<br />
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm<br />
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll<br />
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\acer\acer vcm\Skype4COM.dll<br />
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL<br />
<br />
================= FIREFOX ===================<br />
<br />
FF - ProfilePath - c:\users\valjes~1\appdata\roaming\mozilla\firefox\  profiles\o1t0mtg4.default\<br />
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/index.php?lh=735dccbd2a2a599a0dc2ad2ce6d9185e&amp;<br />
FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&amp;q=<br />
FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll<br />
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll<br />
FF - plugin: c:\users\valjesnet\appdata\roaming\mozilla\firefox  \profiles\o1t0mtg4.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll<br />
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}<br />
<br />
---- FIREFOX POLICIES ----<br />
FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\security-prefs.js - pref(&quot;security.ssl3.rsa_seed_sha&quot;, true);<br />
<br />
============= SERVICES / DRIVERS ===============<br />
<br />
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\drivers\btwl2cap.sys [2009-10-24 29472]<br />
<br />
=============== Created Last 30 ================<br />
<br />
2009-11-11 22:35:43    2036736    ----a-w-    c:\windows\system32\win32k.sys<br />
2009-11-11 22:31:49    355328    ----a-w-    c:\windows\system32\WSDApi.dll<br />
2009-11-10 21:16:20    0    d-----w-    c:\users\valjes~1\appdata\roaming\EurekaLog<br />
2009-11-07 08:40:27    195456    ------w-    c:\windows\system32\MpSigStub.exe<br />
2009-11-04 14:53:34    1638912    ----a-w-    c:\windows\system32\mshtml.tlb<br />
2009-11-01 12:04:02    0    d-----w-    c:\programdata\Spybot - Search &amp; Destroy<br />
2009-11-01 12:04:02    0    d-----w-    c:\program files\Spybot - Search &amp; Destroy<br />
2009-11-01 11:23:58    12    ----a-w-    c:\windows\bthservsdp.dat<br />
2009-11-01 11:05:30    1505    ----a-w-    c:\users\valjesnet\.recently-used.xbel<br />
2009-11-01 00:07:10    0    d-----w-    c:\program files\common files\SWF Studio<br />
2009-10-29 14:32:41    0    d-----w-    c:\users\valjes~1\appdata\roaming\URSoft<br />
2009-10-29 14:32:28    0    d-----w-    c:\program files\Startup Faster<br />
2009-10-29 14:26:16    0    d-----w-    c:\users\valjes~1\appdata\roaming\LimeWire<br />
2009-10-29 14:25:35    0    d-----w-    c:\program files\LimeWire<br />
2009-10-29 02:03:36    0    d-----w-    c:\program files\Windows Portable Devices<br />
2009-10-29 02:03:07    0    ---ha-w-    c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_  07_00.Wdf<br />
2009-10-29 02:02:56    0    ---ha-w-    c:\windows\system32\drivers\Msft_User_WpdFs_01_07_  00.Wdf<br />
2009-10-29 02:00:56    92672    ----a-w-    c:\windows\system32\UIAnimation.dll<br />
2009-10-29 02:00:50    1164800    ----a-w-    c:\windows\system32\UIRibbonRes.dll<br />
2009-10-29 02:00:49    3023360    ----a-w-    c:\windows\system32\UIRibbon.dll<br />
2009-10-29 01:59:21    258048    ----a-w-    c:\windows\system32\winspool.drv<br />
2009-10-29 01:59:20    369664    ----a-w-    c:\windows\system32\WMPhoto.dll<br />
2009-10-29 01:59:11    634880    ----a-w-    c:\windows\system32\drivers\dxgkrnl.sys<br />
2009-10-29 01:59:11    37888    ----a-w-    c:\windows\system32\cdd.dll<br />
2009-10-29 01:59:02    829440    ----a-w-    c:\windows\system32\d3d10warp.dll<br />
2009-10-29 01:59:02    26112    ----a-w-    c:\windows\system32\printfilterpipelineprxy.dll<br />
2009-10-29 01:59:00    135680    ----a-w-    c:\windows\system32\XpsRasterService.dll<br />
2009-10-29 01:57:51    31232    ----a-w-    c:\windows\system32\BthMtpContextHandler.dll<br />
2009-10-29 01:54:32    4096    ----a-w-    c:\windows\system32\oleaccrc.dll<br />
2009-10-29 01:54:29    234496    ----a-w-    c:\windows\system32\oleacc.dll<br />
2009-10-29 01:54:28    555520    ----a-w-    c:\windows\system32\UIAutomationCore.dll<br />
2009-10-28 23:10:00    2421760    ----a-w-    c:\windows\system32\wucltux.dll<br />
2009-10-28 23:07:53    87552    ----a-w-    c:\windows\system32\wudriver.dll<br />
2009-10-28 23:07:24    33792    ----a-w-    c:\windows\system32\wuapp.exe<br />
2009-10-28 23:07:24    171608    ----a-w-    c:\windows\system32\wuwebv.dll<br />
2009-10-28 16:33:07    0    d-----w-    c:\users\valjesnet\Tracing<br />
2009-10-28 16:28:03    0    ---ha-w-    c:\windows\system32\drivers\Msft_User_WpdFs_01_00_  00.Wdf<br />
2009-10-28 02:50:00    0    ---ha-w-    c:\windows\system32\drivers\Msft_User_PCCSWpdDrive  r_01_07_00.Wdf<br />
2009-10-28 02:48:46    0    ---ha-w-    c:\windows\system32\drivers\Msft_Kernel_ccdcmb_010  07.Wdf<br />
2009-10-28 02:46:43    0    d-----w-    c:\programdata\PC Suite<br />
2009-10-28 02:32:54    0    d-----w-    c:\program files\common files\PCSuite<br />
2009-10-28 02:32:30    0    d-----w-    c:\program files\common files\Nokia<br />
2009-10-28 02:32:07    18816    ----a-w-    c:\windows\system32\drivers\pccsmcfd.sys<br />
2009-10-28 02:28:18    0    d-----w-    c:\program files\PC Connectivity Solution<br />
2009-10-28 02:17:03    91136    ----a-w-    c:\windows\system32\nmwcdcls.dll<br />
2009-10-28 02:17:00    0    d-----w-    c:\program files\Nokia<br />
2009-10-28 02:15:58    0    d-----w-    c:\programdata\Installations<br />
2009-10-27 22:49:49    310784    ----a-w-    c:\windows\system32\unregmp2.exe<br />
2009-10-27 22:49:40    8147456    ----a-w-    c:\windows\system32\wmploc.DLL<br />
2009-10-26 23:18:05    1024    ----a-w-    c:\programdata\txtpdf2.dll<br />
2009-10-26 16:11:13    1050296    ------w-    c:\windows\system32\wweb32.dll<br />
2009-10-26 16:11:11    0    d-----w-    c:\program files\WordWeb<br />
2009-10-26 16:02:54    65    ----a-w-    c:\windows\wininit.ini<br />
2009-10-26 16:02:19    0    d-----w-    c:\programdata\Yahoo! Companion<br />
2009-10-26 15:59:12    0    d-----w-    c:\programdata\Yahoo!<br />
2009-10-26 15:59:04    0    d-----w-    c:\program files\Yahoo!<br />
2009-10-26 15:28:41    0    d-----w-    c:\windows\system32\eu-ES<br />
2009-10-26 15:28:41    0    d-----w-    c:\windows\system32\ca-ES<br />
2009-10-26 15:28:36    0    d-----w-    c:\windows\system32\vi-VN<br />
2009-10-26 14:53:14    0    d-----w-    c:\windows\system32\EventProviders<br />
2009-10-26 14:49:58    507904    ----a-w-    c:\windows\system32\drivers\bthport.sys<br />
2009-10-26 14:48:59    339968    ----a-w-    c:\windows\system32\msexcl40.dll<br />
2009-10-26 14:47:58    385536    ----a-w-    c:\windows\system32\vds.exe<br />
2009-10-26 14:46:59    19944    ----a-w-    c:\windows\system32\drivers\atapi.sys<br />
2009-10-26 14:45:59    481792    ----a-w-    c:\windows\system32\cmdial32.dll<br />
2009-10-26 14:44:59    76288    ----a-w-    c:\windows\system32\drivers\dxg.sys<br />
2009-10-26 14:43:47    83968    ----a-w-    c:\windows\system32\wbem\wmiutils.dll<br />
2009-10-26 14:43:47    744448    ----a-w-    c:\windows\system32\wbem\wbemcore.dll<br />
2009-10-26 14:43:47    30208    ----a-w-    c:\windows\system32\wbem\wbemprox.dll<br />
2009-10-26 14:43:47    265728    ----a-w-    c:\windows\system32\wbem\esscli.dll<br />
2009-10-26 14:43:47    189440    ----a-w-    c:\windows\system32\wbem\mofd.dll<br />
2009-10-26 14:43:46    614912    ----a-w-    c:\windows\system32\wbem\fastprox.dll<br />
2009-10-26 14:43:46    265728    ----a-w-    c:\windows\system32\wbem\repdrvfs.dll<br />
2009-10-26 14:43:34    705536    ----a-w-    c:\windows\system32\SmiEngine.dll<br />
2009-10-26 14:43:17    218624    ----a-w-    c:\windows\system32\wdscore.dll<br />
2009-10-26 14:43:17    130560    ----a-w-    c:\windows\system32\PkgMgr.exe<br />
2009-10-26 14:42:29    247808    ----a-w-    c:\windows\system32\drvstore.dll<br />
2009-10-26 14:10:31    0    d-----w-    c:\program files\Paint.NET<br />
2009-10-26 14:01:07    0    d-----w-    c:\users\valjesnet\.thumbnails<br />
2009-10-26 13:57:26    0    d-----w-    c:\users\valjesnet\.gimp-2.6<br />
2009-10-26 13:55:34    0    d-----w-    c:\program files\GIMP-2.0<br />
2009-10-25 09:36:55    411368    ----a-w-    c:\windows\system32\deploytk.dll<br />
2009-10-25 09:26:18    0    ---ha-w-    c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_  00_00.Wdf<br />
2009-10-25 09:17:30    0    d-----w-    c:\programdata\CyberLink<br />
2009-10-24 21:54:05    1784352    ----a-w-    c:\windows\system32\WavesLib.dll<br />
2009-10-24 21:54:04    551456    ----a-w-    c:\windows\system32\RTSndMgr.cpl<br />
2009-10-24 21:54:04    326176    ----a-w-    c:\windows\system32\RtkApoApi.dll<br />
2009-10-24 21:54:04    2897440    ----a-w-    c:\windows\system32\RtkAPO.dll<br />
2009-10-24 21:54:04    2357856    ----a-w-    c:\windows\system32\drivers\RTKVHDA.sys<br />
2009-10-24 21:54:04    1157664    ----a-w-    c:\windows\system32\RtkPgExt.dll<br />
2009-10-24 21:54:03    290304    ----a-w-    c:\windows\system32\RP3DHT32.dll<br />
2009-10-24 21:54:03    290304    ----a-w-    c:\windows\system32\RP3DAA32.dll<br />
2009-10-24 21:54:02    142848    ----a-w-    c:\windows\system32\AERTACap.dll<br />
2009-10-24 21:54:02    125952    ----a-w-    c:\windows\system32\AERTARen.dll<br />
2009-10-24 15:32:59    0    d-----w-    c:\users\valjes~1\appdata\roaming\eSobi<br />
2009-10-24 15:24:20    0    d-----w-    c:\program files\CCleaner<br />
2009-10-24 12:28:59    0    d-----w-    c:\programdata\McAfee Security Scan<br />
2009-10-24 12:26:51    0    d-----w-    c:\programdata\NOS<br />
2009-10-24 12:01:47    2048    ----a-w-    c:\windows\system32\tzres.dll<br />
2009-10-24 10:57:35    41984    ----a-w-    c:\windows\system32\netfxperf.dll<br />
2009-10-24 10:53:19    904776    ----a-w-    c:\windows\system32\drivers\tcpip.sys<br />
2009-10-24 10:53:17    105984    ----a-w-    c:\windows\system32\netiohlp.dll<br />
2009-10-24 10:53:16    30720    ----a-w-    c:\windows\system32\drivers\tcpipreg.sys<br />
2009-10-24 10:53:14    27136    ----a-w-    c:\windows\system32\NETSTAT.EXE<br />
2009-10-24 10:53:14    19968    ----a-w-    c:\windows\system32\ARP.EXE<br />
2009-10-24 10:53:12    9728    ----a-w-    c:\windows\system32\TCPSVCS.EXE<br />
2009-10-24 10:53:10    8704    ----a-w-    c:\windows\system32\HOSTNAME.EXE<br />
2009-10-24 10:53:10    10240    ----a-w-    c:\windows\system32\finger.exe<br />
2009-10-24 10:53:08    17920    ----a-w-    c:\windows\system32\ROUTE.EXE<br />
2009-10-24 10:53:08    11264    ----a-w-    c:\windows\system32\MRINFO.EXE<br />
2009-10-24 10:53:04    17920    ----a-w-    c:\windows\system32\netevent.dll<br />
2009-10-24 10:49:46    784896    ----a-w-    c:\windows\system32\rpcrt4.dll<br />
2009-10-24 10:49:02    71680    ----a-w-    c:\windows\system32\atl.dll<br />
2009-10-24 10:48:56    91136    ----a-w-    c:\windows\system32\avifil32.dll<br />
2009-10-24 10:48:48    2868224    ----a-w-    c:\windows\system32\mf.dll<br />
2009-10-24 10:48:47    98816    ----a-w-    c:\windows\system32\mfps.dll<br />
2009-10-24 10:48:47    53248    ----a-w-    c:\windows\system32\rrinstaller.exe<br />
2009-10-24 10:48:47    24576    ----a-w-    c:\windows\system32\mfpmp.exe<br />
2009-10-24 10:48:44    2048    ----a-w-    c:\windows\system32\mferror.dll<br />
2009-10-24 10:46:29    1696768    ----a-w-    c:\windows\system32\gameux.dll<br />
2009-10-24 10:46:28    28672    ----a-w-    c:\windows\system32\Apphlpdm.dll<br />
2009-10-24 10:46:24    4240384    ----a-w-    c:\windows\system32\GameUXLegacyGDFs.dll<br />
2009-10-24 10:45:53    1259008    ----a-w-    c:\windows\system32\lsasrv.dll<br />
2009-10-24 10:45:52    499712    ----a-w-    c:\windows\system32\kerberos.dll<br />
2009-10-24 10:45:51    175104    ----a-w-    c:\windows\system32\wdigest.dll<br />
2009-10-24 10:45:50    270848    ----a-w-    c:\windows\system32\schannel.dll<br />
2009-10-24 10:45:49    439864    ----a-w-    c:\windows\system32\drivers\ksecdd.sys<br />
2009-10-24 10:45:48    72704    ----a-w-    c:\windows\system32\secur32.dll<br />
2009-10-24 10:45:47    9728    ----a-w-    c:\windows\system32\lsass.exe<br />
2009-10-24 10:33:49    160256    ----a-w-    c:\windows\system32\wkssvc.dll<br />
2009-10-24 10:30:24    3600456    ----a-w-    c:\windows\system32\ntkrnlpa.exe<br />
2009-10-24 10:30:22    3548216    ----a-w-    c:\windows\system32\ntoskrnl.exe<br />
2009-10-24 10:26:02    313344    ----a-w-    c:\windows\system32\wmpdxm.dll<br />
2009-10-24 10:25:59    7680    ----a-w-    c:\windows\system32\spwmp.dll<br />
2009-10-24 10:25:58    4096    ----a-w-    c:\windows\system32\msdxm.ocx<br />
2009-10-24 10:25:58    4096    ----a-w-    c:\windows\system32\dxmasf.dll<br />
2009-10-24 10:25:55    43520    ----a-w-    c:\windows\system32\msdxm.tlb<br />
2009-10-24 10:25:54    18432    ----a-w-    c:\windows\system32\amcompat.tlb<br />
2009-10-24 10:25:46    144896    ----a-w-    c:\windows\system32\drivers\srv2.sys<br />
2009-10-24 10:25:38    2066432    ----a-w-    c:\windows\system32\mstscax.dll<br />
2009-10-24 10:25:37    53248    ----a-w-    c:\windows\system32\tsgqec.dll<br />
2009-10-24 10:25:37    136192    ----a-w-    c:\windows\system32\aaclient.dll<br />
2009-10-24 10:25:33    623616    ----a-w-    c:\windows\system32\localspl.dll<br />
2009-10-24 10:25:15    218624    ----a-w-    c:\windows\system32\msv1_0.dll<br />
2009-10-24 10:18:23    60928    ----a-w-    c:\windows\system32\msasn1.dll<br />
2009-10-24 10:11:03    604672    ----a-w-    c:\windows\system32\WMSPDMOD.DLL<br />
2009-10-24 07:26:00    0    d-----w-    c:\program files\common files\CyberLink<br />
2009-10-24 07:24:26    0    d-sh--w-    c:\users\valjes~1\appdata\roaming\.#<br />
2009-10-24 07:21:06    505128    ----a-w-    c:\windows\system32\msvcp71.dll<br />
2009-10-24 07:21:06    353576    ----a-w-    c:\windows\system32\msvcr71.dll<br />
2009-10-24 07:21:06    29480    ----a-w-    c:\windows\system32\msxml3a.dll<br />
2009-10-24 07:20:59    0    d---a-w-    c:\programdata\Temp<br />
2009-10-24 07:14:40    29472    ----a-w-    c:\windows\system32\drivers\btwl2cap.sys<br />
2009-10-24 07:14:40    106784    ----a-w-    c:\windows\system32\drivers\btwavdt.sys<br />
2009-10-24 07:14:39    84256    ----a-w-    c:\windows\system32\drivers\btwaudio.sys<br />
2009-10-24 07:14:39    17056    ----a-w-    c:\windows\system32\drivers\btwrchid.sys<br />
2009-10-24 07:13:58    0    d-----w-    c:\program files\WIDCOMM<br />
2009-10-24 07:11:27    626688    ----a-w-    c:\windows\Image.dll<br />
2009-10-24 07:11:27    4838    ----a-w-    c:\windows\Suyin.reg<br />
2009-10-24 07:11:27    222382    ----a-w-    c:\windows\Acer Crystal Eye webcam.ico<br />
2009-10-24 07:11:26    319488    ----a-w-    c:\windows\Acer Crystal Eye webcam.exe<br />
2009-10-24 07:11:09    0    ---ha-w-    c:\windows\system32\drivers\Msft_Kernel_SynTP_0100  7.Wdf<br />
2009-10-24 07:10:32    0    d-----w-    c:\program files\Synaptics<br />
2009-10-24 07:08:05    403    ----a-w-    c:\windows\Cleanup.cmd<br />
2009-10-24 07:04:46    0    d-----w-    c:\programdata\Partner<br />
2009-10-24 07:04:26    0    d-----w-    c:\programdata\Google<br />
2009-10-24 07:03:20    0    d-----w-    c:\users\valjes~1\appdata\roaming\Acer GameZone Console<br />
<br />
==================== Find3M  ====================<br />
<br />
2009-10-29 02:03:16    86016    ----a-w-    c:\windows\inf\infstor.dat<br />
2009-10-29 02:03:16    665600    ----a-w-    c:\windows\inf\drvindex.dat<br />
2009-10-29 02:03:16    51200    ----a-w-    c:\windows\inf\infpub.dat<br />
2009-10-29 02:03:16    143360    ----a-w-    c:\windows\inf\infstrng.dat<br />
2009-10-26 15:10:24    37665    ----a-w-    c:\windows\fonts\GlobalUserInterface.CompositeFont<br />
2009-10-24 21:54:09    319456    ----a-w-    c:\windows\DIFxAPI.dll<br />
2009-10-01 01:02:17    2537472    ----a-w-    c:\windows\system32\wpdshext.dll<br />
2009-10-01 01:02:05    30208    ----a-w-    c:\windows\system32\WPDShextAutoplay.exe<br />
2009-10-01 01:02:04    334848    ----a-w-    c:\windows\system32\PortableDeviceApi.dll<br />
2009-10-01 01:02:02    87552    ----a-w-    c:\windows\system32\WPDShServiceObj.dll<br />
2009-10-01 01:01:59    546816    ----a-w-    c:\windows\system32\wpd_ci.dll<br />
2009-10-01 01:01:59    160256    ----a-w-    c:\windows\system32\PortableDeviceTypes.dll<br />
2009-10-01 01:01:56    60928    ----a-w-    c:\windows\system32\PortableDeviceConnectApi.dll<br />
2009-10-01 01:01:56    350208    ----a-w-    c:\windows\system32\WPDSp.dll<br />
2009-10-01 01:01:56    196608    ----a-w-    c:\windows\system32\PortableDeviceWMDRM.dll<br />
2009-10-01 01:01:56    100864    ----a-w-    c:\windows\system32\PortableDeviceClassExtension.d  ll<br />
2009-10-01 01:01:54    81920    ----a-w-    c:\windows\system32\wpdbusenum.dll<br />
2009-10-01 01:01:54    40448    ----a-w-    c:\windows\system32\drivers\WpdUsb.sys<br />
2009-10-01 01:01:50    226816    ----a-w-    c:\windows\system32\WpdMtp.dll<br />
2009-10-01 01:01:49    61952    ----a-w-    c:\windows\system32\WpdMtpUS.dll<br />
2009-10-01 01:01:49    33280    ----a-w-    c:\windows\system32\WpdConns.dll<br />
2009-09-25 02:10:10    974848    ----a-w-    c:\windows\system32\WindowsCodecs.dll<br />
2009-09-25 02:07:08    189440    ----a-w-    c:\windows\system32\WindowsCodecsExt.dll<br />
2009-09-25 02:04:32    321024    ----a-w-    c:\windows\system32\PhotoMetadataHandler.dll<br />
2009-09-25 01:49:22    1554432    ----a-w-    c:\windows\system32\xpsservices.dll<br />
2009-09-25 01:48:08    351232    ----a-w-    c:\windows\system32\XpsPrint.dll<br />
2009-09-25 01:38:29    847360    ----a-w-    c:\windows\system32\OpcServices.dll<br />
2009-09-25 01:36:13    280064    ----a-w-    c:\windows\system32\XpsGdiConverter.dll<br />
2009-09-25 01:33:25    195584    ----a-w-    c:\windows\system32\dxdiagn.dll<br />
2009-09-25 01:32:59    252928    ----a-w-    c:\windows\system32\dxdiag.exe<br />
2009-09-25 01:31:53    519680    ----a-w-    c:\windows\system32\d3d11.dll<br />
2009-09-25 01:31:26    486912    ----a-w-    c:\windows\system32\d3d10level9.dll<br />
2009-09-25 01:31:21    161280    ----a-w-    c:\windows\system32\d3d10_1.dll<br />
2009-09-25 01:31:19    218112    ----a-w-    c:\windows\system32\d3d10_1core.dll<br />
2009-09-25 01:31:16    1030144    ----a-w-    c:\windows\system32\d3d10.dll<br />
2009-09-25 01:31:15    828928    ----a-w-    c:\windows\system32\d2d1.dll<br />
2009-09-25 01:30:23    481792    ----a-w-    c:\windows\system32\dxgi.dll<br />
2009-09-25 01:30:23    190464    ----a-w-    c:\windows\system32\d3d10core.dll<br />
2009-09-25 01:27:04    793088    ----a-w-    c:\windows\system32\FntCache.dll<br />
2009-09-25 01:27:04    1064448    ----a-w-    c:\windows\system32\DWrite.dll<br />
2009-09-24 22:54:53    667648    ----a-w-    c:\windows\system32\printfilterpipelinesvc.exe<br />
2009-09-16 02:22:48    79816    ----a-w-    c:\windows\system32\drivers\mfeavfk.sys<br />
2009-09-16 02:22:48    40552    ----a-w-    c:\windows\system32\drivers\mfesmfk.sys<br />
2009-09-16 02:22:48    35272    ----a-w-    c:\windows\system32\drivers\mfebopk.sys<br />
2009-09-16 02:22:48    214664    ----a-w-    c:\windows\system32\drivers\mfehidk.sys<br />
2009-09-16 02:22:14    34248    ----a-w-    c:\windows\system32\drivers\mferkdk.sys<br />
2009-08-27 05:22:28    916480    ----a-w-    c:\windows\system32\wininet.dll<br />
2009-08-27 05:17:43    71680    ----a-w-    c:\windows\system32\iesetup.dll<br />
2009-08-27 05:17:43    109056    ----a-w-    c:\windows\system32\iesysprep.dll<br />
2009-08-27 03:42:29    133632    ----a-w-    c:\windows\system32\ieUnatt.exe<br />
2008-01-21 02:57:01    174    --sha-w-    c:\program files\desktop.ini<br />
2006-11-02 12:39:34    30674    ----a-w-    c:\windows\inf\perflib\0409\perfd.dat<br />
2006-11-02 12:39:34    30674    ----a-w-    c:\windows\inf\perflib\0409\perfc.dat<br />
2006-11-02 12:39:34    287440    ----a-w-    c:\windows\inf\perflib\0409\perfi.dat<br />
2006-11-02 12:39:34    287440    ----a-w-    c:\windows\inf\perflib\0409\perfh.dat<br />
2006-11-02 09:20:21    287440    ----a-w-    c:\windows\inf\perflib\0000\perfi.dat<br />
2006-11-02 09:20:21    287440    ----a-w-    c:\windows\inf\perflib\0000\perfh.dat<br />
2006-11-02 09:20:19    30674    ----a-w-    c:\windows\inf\perflib\0000\perfd.dat<br />
2006-11-02 09:20:19    30674    ----a-w-    c:\windows\inf\perflib\0000\perfc.dat<br />
<br />
============= FINISH: 21:18:37.70 ===============<br />
<br />
security check:<br />
 Results of screen317's Security Check version 0.99.0  <br />
 Windows Vista Service Pack 2 (UAC is enabled) <br />
<b>`````````````````````````````` <br />
<u>Antivirus/Firewall Check:</u></b> <br />
 Windows Firewall Disabled!  <br />
 McAfee SecurityCenter     <br />
 WMIC entry does not exist for antivirus; attempting automatic update. <br />
<b>`````````````````````````````` <br />
<u>Anti-malware/Other Utilities Check:</u></b> <br />
 CCleaner     <br />
 Java(TM) 6 Update 17  <br />
 <font color="red"><b>Out of date Java installed!</b></font> <br />
 Adobe Flash Player 10  <br />
Adobe Reader 9.2 <br />
<b>`````````````````````````````` <br />
Process Check:  <br />
<u>objlist.exe by Laurent</u></b> <br />
 Windows Defender MSASCui.exe  <br />
<b>``````````````````````````````<br />
<u>DNS Vulnerability Check:</u></b><br />
 GREAT! (Not vulnerable to DNS cache poisoning) <br />
<br />
<b>`````````End of Log```````````</b></div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>valjesnet</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/80587-pls-check-my-laptop.html</guid>
		</item>
		<item>
			<title>Virus on my computer....</title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/80552-virus-my-computer.html</link>
			<pubDate>Wed, 11 Nov 2009 20:02:53 GMT</pubDate>
			<description>Hi guys, 
 
Thanks for taking a look at this thread. I have a virus. Many many popups and when i click on links to google it takes me somewhere...</description>
			<content:encoded><![CDATA[<div>Hi guys,<br />
<br />
Thanks for taking a look at this thread. I have a virus. Many many popups and when i click on links to google it takes me somewhere completely different 2/3 times. Tried all major virus scans. <br />
<br />
Thanks for your help</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/fixed-hijackthis-logs/13721d1257969516-virus-my-computer-hijackthis.log">hijackthis.log</a> (14.8 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>davidwilcock</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/80552-virus-my-computer.html</guid>
		</item>
		<item>
			<title>Rootkit?</title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/80529-rootkit.html</link>
			<pubDate>Wed, 11 Nov 2009 03:41:29 GMT</pubDate>
			<description><![CDATA[I ran a Malware Bytes log as I do from time to time and found this: 
 
Malwarebytes' Anti-Malware 1.41 
Database version: 3143 
Windows 5.1.2600...]]></description>
			<content:encoded><![CDATA[<div>I ran a Malware Bytes log as I do from time to time and found this:<br />
<br />
Malwarebytes' Anti-Malware 1.41<br />
Database version: 3143<br />
Windows 5.1.2600 Service Pack 3<br />
<br />
11/10/2009 10:07:32 PM<br />
mbam-log-2009-11-10 (22-07-28).txt<br />
<br />
Scan type: Full Scan (C:\|)<br />
Objects scanned: 84476<br />
Time elapsed: 10 minute(s), 25 second(s)<br />
<br />
Memory Processes Infected: 0<br />
Memory Modules Infected: 0<br />
Registry Keys Infected: 0<br />
Registry Values Infected: 0<br />
Registry Data Items Infected: 0<br />
Folders Infected: 0<br />
Files Infected: 1<br />
<br />
Memory Processes Infected:<br />
(No malicious items detected)<br />
<br />
Memory Modules Infected:<br />
(No malicious items detected)<br />
<br />
Registry Keys Infected:<br />
(No malicious items detected)<br />
<br />
Registry Values Infected:<br />
(No malicious items detected)<br />
<br />
Registry Data Items Infected:<br />
(No malicious items detected)<br />
<br />
Folders Infected:<br />
(No malicious items detected)<br />
<br />
Files Infected:<br />
C:\WINDOWS\$NtServicePackUninstall$\atapi.sys (Rootkit) -&gt; No action taken.<br />
<br />
<br />
<br />
I used MB to remove the threat and did a second MB scan as well. I used my Kaspersky AV to scan and did a Trend Micro house call scan and Bit Defender scan as well.<br />
<br />
None of these scans showed anything. But I am still worried as I hear rootkits can mean big trouble and can be hard to find and fix.<br />
<br />
Here is a HT log:<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 10:38:45 PM, on 11/10/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\System32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\ASUS\AI Gear\GearHelp.exe<br />
C:\WINDOWS\system32\Rundll32.exe<br />
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE<br />
C:\Program Files\Cyberlink\Shared Files\brs.exe<br />
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Desktop Calendar\Desktop Calendar.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\CyberLink\Shared files\RichVideo.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe<br />
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\DOCUME~1\Asato\LOCALS~1\Temp\HouseCall\housecal  l.bin<br />
C:\Documents and Settings\Asato\Desktop\Antivirus Spyware\HijackThis.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int  ernet Settings,ProxyOverride = *.local<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O4 - HKLM\..\Run: [Ai Gear Help] &quot;C:\Program Files\ASUS\AI Gear\GearHelp.exe&quot;<br />
O4 - HKLM\..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.15\AsRunHelp.exe<br />
O4 - HKLM\..\Run: [ATICCC] &quot;C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe&quot;<br />
O4 - HKLM\..\Run: [P17Helper] Rundll32 SPIRun.dll,RunDLLEntry<br />
O4 - HKLM\..\Run: [AVP] &quot;C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe<br />
O4 - HKLM\..\Run: [RemoteControl] &quot;C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe&quot;<br />
O4 - HKLM\..\Run: [LanguageShortcut] &quot;C:\Program Files\CyberLink\PowerDVD\Language\Language.exe&quot;<br />
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKCU\..\Run: [Desktop Calendar] C:\Program Files\Desktop Calendar\Desktop Calendar.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0<br />
O4 - HKUS\S-1-5-18\..\RunOnce: [DefaultP17] resdef.exe (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\RunOnce: [DefaultP17] resdef.exe (User 'Default user')<br />
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll<br />
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe<br />
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - <a href="http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab" target="_blank">http://download.bitdefender.com/reso...an8/oscan8.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1247795200906" target="_blank">http://update.microsoft.com/windowsu...?1247795200906</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - <a href="http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5795/mcfscan.cab" target="_blank">http://download.mcafee.com/molbin/is...95/mcfscan.cab</a><br />
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - <a href="http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15108/CTPID.cab" target="_blank">http://ccfiles.creative.com/Web/soft...5108/CTPID.cab</a><br />
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA  ~1\KASPER~1\KASPER~1\mzvkbd3.dll<br />
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe<br />
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe<br />
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe<br />
<br />
--<br />
End of file - 7722 bytes<br />
<br />
<br />
<br />
Is there anything else I should do? I'm worried.<br />
Thank you for your help.</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>loveandpoison</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/80529-rootkit.html</guid>
		</item>
		<item>
			<title>fun.exe dc.exe - need help!!!</title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/80390-fun-exe-dc-exe-need-help.html</link>
			<pubDate>Sat, 07 Nov 2009 21:48:41 GMT</pubDate>
			<description>Hi, I was searching for help in some virus matters and I run across this website and so here I am asking some questions. Someone already had asked...</description>
			<content:encoded><![CDATA[<div>Hi, I was searching for help in some virus matters and I run across this website and so here I am asking some questions. Someone already had asked the same question but never followed up. <br />
I am wondering if anyone can help me out here. I have done some stuff that was recommended as follows: <br />
<font face="Arial Black">Posted by CHIAZ (security analyst) - <br />
<br />
Hello.<br />
<br />
Please download Malwarebytes' Anti-Malware by clicking the link below:<br />
<a href="http://www.besttechie.net/tools/mbam-setup.exe" target="_blank">Malwarebytes Anti-Malware - Reviews and free Malwarebytes Anti-Malware downloads at Download.com</a><br />
<br />
Double Click mbam-setup.exe to install the application.<br />
<br />
* Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.<br />
* If an update is found, it will download and install the latest version.<br />
* Once the program has loaded, select &quot;Perform Quick Scan&quot;, then click Scan.<br />
* The scan may take some time to finish,so please be patient.<br />
* When the scan is complete, click OK, then Show Results to view the results.<br />
* Make sure that everything is checked, and click Remove Selected.<br />
* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)<br />
* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.<br />
* You'll be required to post the contents of this log later.<br />
<br />
Please Note:<br />
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.<br />
<br />
Next let's have you download <b>ComboFix.exe.</b> Please visit this webpage for downloading and instructions for running the tool: <br />
<br />
</font>         <font face="Arial Black"><font color="Red">Go here ======&gt; </font></font><font face="Arial Black"><font color="red"><a href="http://www.bleepingcomputer.com/combofix/how-to-use-combofix" target="_blank">A guide and tutorial on using ComboFix</a></font></font><font face="Arial Black"><font color="red">&lt;====== Go here</font></font><font face="Arial Black"><br />
<br />
</font>  <font face="Arial Black"><font color="blue">Please ensure you read this guide carefully and install the Recovery Console first.This applies to XP Pro and XP Home users only.If you have SP3 installed you will need to use SP2 </font></font> <font face="Arial Black"><br />
<br />
The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.<br />
<br />
Once installed, you should get a prompt that says:<br />
<br />
<b>The Recovery Console was successfully installed.</b><br />
<br />
Please continue as follows:<br />
<br />
(1) Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. <br />
(2) Click <b>Yes</b> to allow ComboFix to continue scanning for malware.<br />
<br />
When the tool is finished, it will produce a report for you. <br />
<br />
Please include the following reports for further review (copy and paste them, not attach), so that we may continue cleansing the system:<br />
<br />
<b>MBAM log</b><br />
<b>C:\ComboFix.txt<br />
</b><br />
<br />
</font>             <font color="red"><font face="Arial Black">Caution: Never run and remove files with Combofix unless supervised by a qualified security analyst who is experienced in the use of Combofix. Misuse can cause serious computer problems.</font><br />
<br />
<b>-------------------------------------------------------------<br />
</b></font><font size="4"><b>So, I have done whatever is said above and am looking for someone to review the .txt file given out by combofix and help me out with further instruction. PLEASE!!!!!!<br />
<br />
combofix txt file: </b><br />
</font><br />
ComboFix 09-11-07.02 - ABHI 11/07/2009 11:39.1.1 - NTFSx86<br />
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.502.212 [GMT 0:00]<br />
Running from: c:\documents and settings\ABHI\Desktop\ComboFix.exe<br />
.<br />
<br />
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br />
<br />
c:\recycler\S-1-5-21-1482476501-573735546-725345543-1003<br />
c:\recycler\S-1-5-21-1482476501-573735546-725345543-500<br />
c:\windows\system32\Penx.dat<br />
c:\windows\system32\Xpen.dat<br />
<br />
.<br />
(((((((((((((((((((((((((   Files Created from 2009-10-07 to 2009-11-07  )))))))))))))))))))))))))))))))<br />
.<br />
<br />
2009-11-07 11:07 . 2009-11-07 11:07    --------    d-----w-    c:\documents and settings\ABHI\Application Data\Malwarebytes<br />
2009-11-07 11:06 . 2009-09-10 14:54    38224    ----a-w-    c:\windows\system32\drivers\mbamswissarmy.sys<br />
2009-11-07 11:06 . 2009-11-07 11:06    --------    d-----w-    c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes<br />
2009-11-07 11:06 . 2009-09-10 14:53    19160    ----a-w-    c:\windows\system32\drivers\mbam.sys<br />
2009-11-07 11:06 . 2009-11-07 11:06    --------    d-----w-    c:\program files\Malwarebytes' Anti-Malware<br />
2009-10-18 08:27 . 2009-10-18 08:27    578560    ----a-w-    c:\windows\system32\dllcache\user32.dll<br />
2009-10-18 08:26 . 2009-10-18 08:26    --------    d-----w-    c:\windows\ERUNT<br />
2009-10-18 08:19 . 2008-11-06 01:03    --------    d-----w-    C:\SDFix<br />
2009-10-15 20:47 . 2009-10-17 08:51    --------    d-----w-    c:\documents and settings\ABHI\Local Settings\Application Data\Google<br />
2009-10-08 23:03 . 2007-03-19 13:00    80896    ----a-w-    c:\documents and settings\All Users.WINDOWS\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP210 series Printer\LanguageModules\0411\CNMlr8S.dll<br />
2009-10-08 23:03 . 2007-03-19 13:00    76288    ----a-w-    c:\documents and settings\All Users.WINDOWS\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP210 series Printer\LanguageModules\0409\CNMsr8S.dll<br />
2009-10-08 23:03 . 2007-03-19 13:00    43520    ----a-w-    c:\documents and settings\All Users.WINDOWS\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP210 series Printer\LanguageModules\0411\CNMsr8S.dll<br />
2009-10-08 23:03 . 2007-03-19 13:00    361472    ----a-w-    c:\documents and settings\All Users.WINDOWS\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP210 series Printer\LanguageModules\0409\CNMur8S.dll<br />
2009-10-08 23:03 . 2007-03-19 13:00    265728    ----a-w-    c:\documents and settings\All Users.WINDOWS\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP210 series Printer\LanguageModules\0411\CNMur8S.dll<br />
2009-10-08 23:03 . 2007-03-19 13:00    145408    ----a-w-    c:\documents and settings\All Users.WINDOWS\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP210 series Printer\LanguageModules\0409\CNMlr8S.dll<br />
2009-10-08 23:02 . 2009-10-08 23:02    --------    d--h--w-    c:\documents and settings\All Users.WINDOWS\Application Data\CanonBJ<br />
2009-10-08 23:02 . 2007-03-19 13:00    215040    ----a-w-    c:\windows\system32\CNMLM8S.DLL<br />
2009-10-08 13:31 . 2009-10-08 13:33    --------    d-----w-    c:\windows\system32\NtmsData<br />
<br />
.<br />
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))  ))<br />
.<br />
2009-11-07 10:38 . 2008-01-16 05:05    --------    d--h--w-    c:\program files\InstallShield Installation Information<br />
2009-11-07 10:37 . 2009-07-24 14:32    20    ---h--w-    c:\documents and settings\All Users.WINDOWS\Application Data\PKP_DLbx.DAT<br />
2009-10-30 21:50 . 2009-09-12 16:51    --------    d-----w-    c:\documents and settings\ABHI\Application Data\vlc<br />
2009-10-28 19:42 . 2008-02-23 03:36    --------    d-----w-    c:\program files\SopCast<br />
2009-10-26 15:11 . 2009-01-30 10:12    --------    d-----w-    c:\program files\Guitar Scales Method<br />
2009-10-14 15:42 . 2009-09-12 16:51    --------    d-----w-    c:\documents and settings\ABHI\Application Data\dvdcss<br />
2009-10-14 15:15 . 2008-02-02 02:45    --------    d-----w-    c:\program files\Google<br />
2009-10-14 10:28 . 2009-01-29 19:47    --------    d-----w-    c:\documents and settings\ABHI\Application Data\IObit<br />
2009-10-14 10:14 . 2009-01-29 19:47    --------    d-----w-    c:\program files\IObit<br />
2009-10-03 11:12 . 2008-01-17 00:19    --------    d-----w-    c:\program files\Java<br />
2009-10-03 11:12 . 2009-10-03 11:12    152576    ----a-w-    c:\documents and settings\ABHI\Application Data\Sun\Java\jre1.6.0_15\lzma.dll<br />
2009-10-03 11:02 . 2009-09-30 19:41    --------    d-----w-    c:\program files\Microsoft Silverlight<br />
2009-09-30 19:41 . 2009-07-24 14:32    17576    ----a-w-    c:\documents and settings\ABHI\Local Settings\Application Data\GDIPFONTCACHEV1.DAT<br />
2009-09-30 19:40 . 2008-02-18 03:14    --------    d-----w-    c:\program files\Windows Live<br />
2009-09-30 19:39 . 2009-09-30 19:39    --------    d-----w-    c:\program files\Microsoft<br />
2009-09-30 19:39 . 2009-09-30 19:39    --------    d-----w-    c:\program files\Windows Live SkyDrive<br />
2009-09-30 19:35 . 2009-09-30 19:35    --------    d-----w-    c:\program files\Common Files\Windows Live<br />
2009-09-11 14:18 . 2006-10-01 12:00    136192    ----a-w-    c:\windows\system32\msv1_0.dll<br />
2009-09-11 11:02 . 2009-09-11 11:02    152576    ----a-w-    c:\documents and settings\ABHI\Application Data\Sun\Java\jre1.6.0_14\lzma.dll<br />
2009-09-10 23:38 . 2008-03-03 22:30    --------    d-----w-    c:\program files\MSECache<br />
2009-09-04 21:03 . 2006-10-01 12:00    58880    ----a-w-    c:\windows\system32\msasn1.dll<br />
2009-08-29 07:36 . 2006-10-01 12:00    832512    ----a-w-    c:\windows\system32\wininet.dll<br />
2009-08-29 07:36 . 2006-10-01 12:00    78336    ----a-w-    c:\windows\system32\ieencode.dll<br />
2009-08-29 07:36 . 2006-10-01 12:00    17408    ----a-w-    c:\windows\system32\corpol.dll<br />
2009-08-26 08:00 . 2006-10-01 12:00    247326    ----a-w-    c:\windows\system32\strmdll.dll<br />
.<br />
<br />
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br />
.<br />
*Note* empty entries &amp; legit default entries are not shown <br />
REGEDIT4<br />
<br />
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre  ntVersion\Run]<br />
&quot;LxrAutorun&quot;=&quot;c:\documents and settings\ABHI\Local Settings\Application Data\Lexar Media\LxrAutorun.exe&quot; [2007-03-07 24576]<br />
&quot;Advanced SystemCare 3&quot;=&quot;c:\program files\IObit\Advanced SystemCare 3\AWC.exe&quot; [2009-06-30 2329224]<br />
&quot;SmartRAM&quot;=&quot;c:\program files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe&quot; [2009-02-19 202064]<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr  entVersion\Run]<br />
&quot;IgfxTray&quot;=&quot;c:\windows\system32\igfxtray.exe&quot; [2006-08-14 98304]<br />
&quot;HotKeysCmds&quot;=&quot;c:\windows\system32\hkcmd.exe&quot; [2006-08-14 114688]<br />
&quot;Persistence&quot;=&quot;c:\windows\system32\igfxpers.ex  e&quot; [2006-08-14 94208]<br />
&quot;Lexmark 2200 Series&quot;=&quot;c:\program files\Lexmark 2200 Series\lxbvbmgr.exe&quot; [2004-02-13 57344]<br />
&quot;Adobe Reader Speed Launcher&quot;=&quot;c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot; [2009-02-27 35696]<br />
&quot;SmartDefrag&quot;=&quot;c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe&quot; [2009-07-02 2453264]<br />
&quot;SunJavaUpdateSched&quot;=&quot;c:\program files\Java\jre6\bin\jusched.exe&quot; [2009-07-25 149280]<br />
&quot;Malwarebytes Anti-Malware (reboot)&quot;=&quot;c:\program files\Malwarebytes' Anti-Malware\mbam.exe&quot; [2009-09-10 1312080]<br />
<br />
[HKEY_CURRENT_USER\software\microsoft\windows\curre  ntversion\policies\explorer]<br />
&quot;NoResolveTrack&quot;= 1 (0x1)<br />
&quot;NoSMConfigurePrograms&quot;= 1 (0x1)<br />
&quot;NoSMBalloonTip&quot;= 1 (0x1)<br />
<br />
[HKEY_USERS\.default\software\microsoft\windows\cur  rentversion\policies\explorer]<br />
&quot;NoResolveTrack&quot;= 1 (0x1)<br />
&quot;NoSMConfigurePrograms&quot;= 1 (0x1)<br />
&quot;NoSMBalloonTip&quot;= 1 (0x1)<br />
<br />
[HKEY_LOCAL_MACHINE\software\microsoft\security center]<br />
&quot;AntiVirusOverride&quot;=dword:00000001<br />
<br />
[HKLM\~\services\sharedaccess\parameters\firewallpo  licy\standardprofile\AuthorizedApplications\List]<br />
&quot;%windir%\\system32\\sessmgr.exe&quot;=<br />
&quot;c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe&quot;=<br />
&quot;c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe&quot;=<br />
&quot;c:\\WINDOWS\\system32\\LEXPPS.EXE&quot;=<br />
&quot;c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe&quot;=<br />
&quot;c:\\Program Files\\SopCast\\adv\\SopAdver.exe&quot;=<br />
&quot;c:\\Program Files\\SopCast\\SopCast.exe&quot;=<br />
<br />
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssflt  r_tdi.sys [9/30/2009 7:40 PM 54752]<br />
R2 LxrSII1d;Secure II Driver;c:\windows\system32\drivers\LxrSII1d.sys [8/12/2009 7:19 PM 72672]<br />
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [8/5/2009 9:48 PM 704864]<br />
<br />
--- Other Services/Drivers In Memory ---<br />
<br />
*NewlyCreated* - MBR<br />
*NewlyCreated* - PROCEXP113<br />
*Deregistered* - mbr<br />
*Deregistered* - PROCEXP113<br />
.<br />
Contents of the 'Scheduled Tasks' folder<br />
<br />
2009-11-01 c:\windows\Tasks\SmartDefrag.job<br />
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-02-22 08:22]<br />
.<br />
.<br />
------- Supplementary Scan -------<br />
.<br />
uStart Page = hxxp://www.google.ca/<br />
FF - ProfilePath - c:\documents and settings\ABHI\Application Data\Mozilla\Firefox\Profiles\3rdr5kzw.default\<br />
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&amp;rls=org.mozilla:en-US:official<br />
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll<br />
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll<br />
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll<br />
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\<br />
<br />
---- FIREFOX POLICIES ----<br />
FF - user.js: browser.cache.memory.capacity - 16000<br />
FF - user.js: browser.chrome.favicons - fales<br />
FF - user.js: browser.display.show_image_placeholders - true<br />
FF - user.js: browser.turbo.enabled - true<br />
FF - user.js: browser.urlbar.autocomplete.enabled - true<br />
FF - user.js: browser.urlbar.autofill - true<br />
FF - user.js: content.max.tokenizing.time - 3000000<br />
FF - user.js: content.maxtextrun - 4095<br />
FF - user.js: content.notify.backoffcount - 5<br />
FF - user.js: content.notify.interval - 1000000<br />
FF - user.js: content.notify.ontimer - true<br />
FF - user.js: content.switch.threshold - 1000000<br />
FF - user.js: dom.disable_window_status_change - true<br />
FF - user.js: network.http.max-connections - 48<br />
FF - user.js: network.http.max-connections-per-server - 16<br />
FF - user.js: network.http.max-persistent-connections-per-proxy - 16<br />
FF - user.js: network.http.max-persistent-connections-per-server - 8<br />
FF - user.js: network.http.pipelining - true<br />
FF - user.js: network.http.pipelining.firstrequest - true<br />
FF - user.js: network.http.pipelining.maxrequests - 8<br />
FF - user.js: network.http.proxy.pipelining - true<br />
FF - user.js: network.http.request.max-start-delay - 0<br />
FF - user.js: nglayout.initialpaint.delay - 1000<br />
FF - user.js: plugin.expose_full_path - true<br />
FF - user.js: ui.submenuDelay - 0<br />
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref(&quot;security.ssl3.rsa_seed_sha&quot;, true);<br />
.<br />
<br />
**************************************************  ************************<br />
<br />
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, <a href="http://www.gmer.net" target="_blank">GMER - Rootkit Detector and Remover</a><br />
Rootkit scan 2009-11-07 11:43<br />
Windows 5.1.2600 Service Pack 3 NTFS<br />
<br />
scanning hidden processes ...  <br />
<br />
scanning hidden autostart entries ... <br />
<br />
scanning hidden files ...  <br />
<br />
scan completed successfully<br />
hidden files: 0<br />
<br />
**************************************************  ************************<br />
.<br />
Completion time: 2009-11-07 11:44<br />
ComboFix-quarantined-files.txt  2009-11-07 11:44<br />
<br />
Pre-Run: 51,016,482,816 bytes free<br />
Post-Run: 51,150,323,712 bytes free<br />
<br />
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe<br />
[boot loader]<br />
timeout=2<br />
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOW  S<br />
[operating systems]<br />
c:\cmdcons\BOOTSECT.DAT=&quot;Microsoft Windows Recovery Console&quot; /cmdcons<br />
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS=&quot;Micro  soft Windows XP Professional&quot; /noexecute=optin /fastdetect<br />
<br />
- - End Of File - - 58DFF68FE59C6B4F39F957E689075B81</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>abhie007</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/80390-fun-exe-dc-exe-need-help.html</guid>
		</item>
		<item>
			<title>Browser Hangs</title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/80360-browser-hangs.html</link>
			<pubDate>Sat, 07 Nov 2009 08:29:49 GMT</pubDate>
			<description>I have had recent problems with browsers hanging. I generally use Firefox which has had most problems but Opera does it too. I installed Google...</description>
			<content:encoded><![CDATA[<div>I have had recent problems with browsers hanging. I generally use Firefox which has had most problems but Opera does it too. I installed Google Chrome to try that but whilst that was superfast at first, it too has problems. I have AGV and Zonealarm and run Spybot and Adaware. I have also run Malwarebytes and have fixed a few problems on Spybot but nothing else has been detected. I have very few add ons. Any ideas? My Hijack This logfile is this:<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 08:28:40, on 07/11/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\WINDOWS\system32\ZoneLabs\vsmon.exe<br />
C:\Program Files\SafeNet\SoftRemoteLT\IreIKE.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\AskBarDis\bar\bin\AskService.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\WINDOWS\eHome\ehRecvr.exe<br />
C:\WINDOWS\eHome\ehSched.exe<br />
C:\Program Files\Flip Video\FlipShare\FlipShareService.exe<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
C:\Program Files\Google\Update\GoogleUpdate.exe<br />
C:\Program Files\Dell Network Assistant\hnm_svc.exe<br />
C:\Program Files\SafeNet\SoftRemoteLT\IPSecMon.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe<br />
C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br />
C:\Program Files\TalkTalk\bin\sprtsvc.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Common Files\Supportsoft\bin\tgsrvc.exe<br />
C:\WINDOWS\system32\SearchIndexer.exe<br />
C:\Program Files\Canon\CAL\CALMAIN.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br />
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br />
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe<br />
C:\WINDOWS\system32\ICO.EXE<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\Program Files\Dell Support Center\bin\sprtcmd.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br />
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe<br />
C:\WINDOWS\stsystra.exe<br />
C:\WINDOWS\system32\RUNDLL32.EXE<br />
C:\Program Files\TalkTalk\bin\sprtcmd.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo  tifier.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files\Digital Line Detect\DLG.exe<br />
C:\Program Files\Windows Desktop Search\WindowsSearch.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\AVG\AVG9\avgscanx.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\Program Files\Opera\opera.exe<br />
C:\WINDOWS\system32\SearchProtocolHost.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.mytalktalk.co.uk" target="_blank">Welcome to AOL UK in partnership with TalkTalk</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = <a href="http://www.google.co.uk/ig/dell?hl=en&amp;client=dell-usuk&amp;channel=uk&amp;ibd=4061205" target="_blank">Dell Start Page</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int  ernet Settings,ProxyServer = http=http://www-cache.freeserve.com:8080;ftp=http://www-cache.freeserve.com:8080<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int  ernet Settings,ProxyOverride = *.local<br />
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)<br />
R3 - URLSearchHook: (no name) - *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br />
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll<br />
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL<br />
O2 - BHO: EWPBrowseObject Class - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\s  wg.dll<br />
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll<br />
O3 - Toolbar: &amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll<br />
O3 - Toolbar: Orange Toolbar - {E97B5F2E-CA8E-4D34-BDA3-44EEC4ED2B12} - C:\Program Files\Orange Toolbar UK\ToolbarContainer230.dll<br />
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O3 - Toolbar: ZoneAlarm Spy Blocker Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll<br />
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O3 - Toolbar: &amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br />
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br />
O4 - HKLM\..\Run: [ISUSScheduler] &quot;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&quot; -start<br />
O4 - HKLM\..\Run: [SSBkgdUpdate] &quot;C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe&quot; -Embedding -boot<br />
O4 - HKLM\..\Run: [OpwareSE4] &quot;C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe&quot;<br />
O4 - HKLM\..\Run: [PMX Daemon] ICO.EXE<br />
O4 - HKLM\..\Run: [PspUsbCf] pspusbcf.exe<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;  -osboot<br />
O4 - HKLM\..\Run: [dscactivate] &quot;C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe&quot;<br />
O4 - HKLM\..\Run: [DellSupportCenter] &quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&quot; /P DellSupportCenter<br />
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br />
O4 - HKLM\..\Run: [ZoneAlarm Client] &quot;C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe&quot;<br />
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [TalkTalk] &quot;C:\Program Files\TalkTalk\bin\sprtcmd.exe&quot; /P TalkTalk<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo  tifier.exe<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKCU\..\Run: [updateMgr] &quot;C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe&quot; AcRdB7_0_9 -reboot 1<br />
O4 - HKCU\..\Run: [DellSupportCenter] &quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&quot; /P DellSupportCenter<br />
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')<br />
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br />
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe<br />
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe<br />
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present<br />
O8 - Extra context menu item: &amp;Search - ?p=ZCfox000<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk/<br />
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - <a href="http://support.euro.dell.com/systemprofiler/SysPro.CAB" target="_blank">http://support.euro.dell.com/systemprofiler/SysPro.CAB</a><br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll<br />
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - <a href="http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab" target="_blank">http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1224927237171" target="_blank">http://update.microsoft.com/microsof...?1224927237171</a><br />
O16 - DPF: {A1F35586-A5A8-4D37-947A-81875350B11F} (Bonusprint Image Uploader Version 4.5 Control) - <a href="http://webalbum.bonusprint.com/ukipc01/downloads//ImageUploader4.cab" target="_blank">http://webalbum.bonusprint.com/ukipc...eUploader4.cab</a><br />
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - <a href="http://www.crucial.com/controls/cpcScanner.cab" target="_blank">http://www.crucial.com/controls/cpcScanner.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe<br />
O23 - Service: FlipShare Service - Unknown owner - C:\Program Files\Flip Video\FlipShare\FlipShareService.exe<br />
O23 - Service: Google Update Service (gupdate1c9d164d5383e1c) (gupdate1c9d164d5383e1c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: SafeNet Monitor Service (IPSECMON) - SafeNet - C:\Program Files\SafeNet\SoftRemoteLT\IPSecMon.exe<br />
O23 - Service: SafeNet IKE Service (IREIKE) - SafeNet - C:\Program Files\SafeNet\SoftRemoteLT\IreIKE.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br />
O23 - Service: SupportSoft Sprocket Service (TalkTalk) (sprtsvc_TalkTalk) - SupportSoft, Inc. - C:\Program Files\TalkTalk\bin\sprtsvc.exe<br />
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\Supportsoft\bin\ssrc.exe<br />
O23 - Service: SupportSoft Repair Service (TalkTalk) (tgsrvc_TalkTalk) - SupportSoft, Inc. - C:\Program Files\Common Files\Supportsoft\bin\tgsrvc.exe<br />
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe<br />
<br />
--<br />
End of file - 15826 bytes</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>Mike94</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/80360-browser-hangs.html</guid>
		</item>
		<item>
			<title>calc.dll</title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/80234-calc-dll.html</link>
			<pubDate>Wed, 04 Nov 2009 16:42:26 GMT</pubDate>
			<description><![CDATA[Hi all 
  
Got a virus and I think its calc.dll the problem... I see it in the msconfig > startup tab, and there's also 2 entries that only mark ".."...]]></description>
			<content:encoded><![CDATA[<div>Hi all<br />
 <br />
Got a virus and I think its calc.dll the problem... I see it in the msconfig &gt; startup tab, and there's also 2 entries that only mark &quot;..&quot;<br />
I'll post all prework logs in seperate posts</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>ghost31615089</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/80234-calc-dll.html</guid>
		</item>
		<item>
			<title>Infected with Alpha virus</title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/80225-infected-alpha-virus.html</link>
			<pubDate>Wed, 04 Nov 2009 13:41:47 GMT</pubDate>
			<description>I am running windows xp on an hp desktop. I had limewire installed until recently when I came across some info that said it was really bad. I removed...</description>
			<content:encoded><![CDATA[<div>I am running windows xp on an hp desktop. I had limewire installed until recently when I came across some info that said it was really bad. I removed it and just ran malwarebytes to remove the infections per a friend.  I then came across your site.  I am going to include the malwarebytes files (2 of them as 2 scans with separate results) as well as including the prework scans you request.<br />
 <br />
<br />
8:40 AM 11/4/2009~1\alluse~1\startm~1\programs\startup\kodaks~1  .lnk - c:\program files\kodak\kodak software updater\7288971\program\backWeb-7288971.exe<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\log  ite~2.lnk - c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger  .exe<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\log  ite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\upd  ate~1.lnk - c:\program files\updates from hp\309731\program\Updates from HP.exe<br />
IE: &amp;Search<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000<br />
IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm<br />
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe<br />
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab<br />
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll<br />
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll<br />
Notify: LBTWlgn - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll<br />
LSA: Notification Packages =  :\windows\syste<br />
============= SERVICES / DRIVERS ===============<br />
<br />
=============== Created Last 30 ================<br />
2009-11-04 11:56:57 0 d-----w- c:\docume~1\hp_owner\applic~1\Malwarebytes<br />
2009-11-04 11:56:53 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys<br />
2009-11-04 11:56:51 19160 ----a-w- c:\windows\system32\drivers\mbam.sys<br />
2009-11-04 11:56:51 0 d-----w- c:\program files\Malwarebytes' Anti-Malware<br />
2009-11-04 11:56:51 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes<br />
2009-11-04 11:45:36 0 d-----w- c:\program files\CCleaner<br />
2009-11-04 11:31:44 21504 ----a-w- c:\windows\system32\hidserv.dll<br />
2009-11-04 11:31:44 21504 ----a-w- c:\windows\system32\dllcache\hidserv.dll<br />
2009-11-04 11:31:31 14848 ----a-w- c:\windows\system32\drivers\kbdhid.sys<br />
2009-11-04 11:31:31 14848 ----a-w- c:\windows\system32\dllcache\kbdhid.sys<br />
2009-11-04 11:30:21 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys<br />
2009-11-04 11:30:21 12160 ----a-w- c:\windows\system32\dllcache\mouhid.sys<br />
2009-11-01 16:41:25 0 d-----w- c:\windows\system32\CatRoot_bak<br />
==================== Find3M  ====================<br />
2009-10-31 13:26:50 5274 -c--a-w- c:\docume~1\hp_owner\applic~1\wklnhst.dat<br />
2009-09-18 09:56:10 18432 ----a-w- c:\windows\system32\dllcache\iedw.exe<br />
2009-09-16 14:22:48 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys<br />
2009-09-16 14:22:48 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys<br />
2009-09-16 14:22:48 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys<br />
2009-09-16 14:22:48 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys<br />
2009-09-16 14:22:14 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys<br />
2009-09-11 14:33:52 133632 ----a-w- c:\windows\system32\msv1_0.dll<br />
2009-09-11 14:33:52 133632 ----a-w- c:\windows\system32\dllcache\msv1_0.dll<br />
2009-09-04 20:45:26 58880 ----a-w- c:\windows\system32\msasn1.dll<br />
2009-09-04 20:45:26 58880 ----a-w- c:\windows\system32\dllcache\msasn1.dll<br />
2009-08-26 08:16:37 247326 ----a-w- c:\windows\system32\strmdll.dll<br />
2009-08-26 08:16:37 247326 ----a-w- c:\windows\system32\dllcache\strmdll.dll<br />
2009-08-21 09:46:35 450560 ----a-w- c:\windows\system32\dllcache\jscript.dll<br />
============= FINISH:  8:33:28.50 ===============<br />
<br />
 Results of screen317's Security Check version 0.99.0  <br />
 Windows XP Service Pack 2  <br />
 <font color="red"><b>Out of date service pack!!</b></font> <br />
<b>`````````````````````````````` <br />
<u>Antivirus/Firewall Check:</u></b> <br />
 Windows Firewall Disabled!  <br />
 McAfee SecurityCenter     <br />
<b>`````````````````````````````` <br />
<u>Anti-malware/Other Utilities Check:</u></b> <br />
 CCleaner     <br />
 Adobe Flash Player 10  <br />
Adobe Reader 9.1 <br />
<b>`````````````````````````````` <br />
Process Check:  <br />
<u>objlist.exe by Laurent</u></b> <br />
 McAfee VIRUSS~1 mcshield.exe  <br />
<b>``````````````````````````````<br />
<u>DNS Vulnerability Check:</u></b><br />
 GREAT! (Not vulnerable to DNS cache poisoning) <br />
<b>`````````End of Log```````````</b></div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/fixed-hijackthis-logs/13644d1257342024-infected-alpha-virus-ddsattach.txt" target="_blank">ddsAttach.txt</a> (8.1 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/fixed-hijackthis-logs/13645d1257342024-infected-alpha-virus-mbam-log-2009-11-04-07-05-12-.txt" target="_blank">mbam-log-2009-11-04 (07-05-12).txt</a> (2.8 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/fixed-hijackthis-logs/13646d1257342024-infected-alpha-virus-mbam-log-2009-11-04-08-15-04-alpharemove.txt" target="_blank">mbam-log-2009-11-04 (08-15-04)alpharemove.txt</a> (2.5 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/fixed-hijackthis-logs/13647d1257342036-infected-alpha-virus-rootrepeal-report-11-04-09-08-30-40-.txt" target="_blank">RootRepeal report 11-04-09 (08-30-40).txt</a> (2.0 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>isabella138</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/80225-infected-alpha-virus.html</guid>
		</item>
		<item>
			<title>Broken links time and again</title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/80222-broken-links-time-again.html</link>
			<pubDate>Wed, 04 Nov 2009 12:22:56 GMT</pubDate>
			<description>I open any link in the default Internet Explorer browser of Windows Vista Home Premium and the page does not load most of the time and I get this...</description>
			<content:encoded><![CDATA[<div>I open any link in the default Internet Explorer browser of Windows Vista Home Premium and the page does not load most of the time and I get this message (the usual one)<br />
 <br />
Internet Explorer cannot display the webpage,<br />
Most likely causes:<br />
-You are not connected to the Internet<br />
-The website is encountering problems.<br />
-There might be a typing error in the address.<br />
What you can try:<br />
-Diagnose Connection Problem.<br />
&gt;More Information<br />
 <br />
So I open links and sometimes this happens and I refresh it's okay, but for quite many links I can keep refreshing again and again and get the same message. Links that load also show up in disordered arrangements because the image links of the pages cannot properly. (At least I am able to access this forum) And I am very sure my internet is connected because this problem started yesterday and my MSN messenger was on (I could still chat with others and receive replies). My internet is a wireless connection, and other users in my household (other laptops) are able to access the internet fine. So it isn't some cable not connected kind of trvial problem.<br />
 <br />
So I click on Diagnose Connection Problem. Then it shows &quot;Identifying the problem&quot; for a moment then comes is non-helpful:<br />
 <br />
Windows cannot find the host name &quot;insert the broken link here&quot; using DNS.<br />
The Domain Name Server may be down.<br />
-&gt;Windows found a problem that cannot be repaired automatically.<br />
Contact your service probider or network administrator for help or click here for information about things you can try to resolve the problem.<br />
 <br />
I clicked and I found no viable solution. It should not be my service provider's problem since others in my household are able to access the inernet fine. It cannot be because the site is down because it is happening for sites like blogger, facebook and yahoo and occasionally google. For facebook, I can access the main page but when I log in I get the broken link page.<br />
 <br />
Another time, I tried Diagnosing again and I got:<br />
<br />
Windows did not find any problems with this computer's network connection.<br />
-&gt;Send a report to Microsoft.<br />
I click it, and guess what happenes? My Internet Explorer browser freezes.<br />
 <br />
This is hampering my internet use and I have absolutely no idea what is going on because of the peculiar manner of the problem. (Working sometimes and other times not, some links yes some no) I really hope I am even able to press the &quot;Submit New Thread&quot; button.<br />
 <br />
Any help? Thanks.</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>alqx</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/80222-broken-links-time-again.html</guid>
		</item>
	</channel>
</rss>
