<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title><![CDATA[PC Help Forum - [Fixed] Hijackthis! Logs]]></title>
		<link>http://www.pchelpforum.com/</link>
		<description>Here you will find the HJT logs that have been fixed by the team.</description>
		<language>en</language>
		<lastBuildDate>Thu, 09 Sep 2010 07:50:13 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>1</ttl>
		<image>
			<url>http://www.pchelpforum.com/images/styles/pchelpforum/misc/rss.jpg</url>
			<title><![CDATA[PC Help Forum - [Fixed] Hijackthis! Logs]]></title>
			<link>http://www.pchelpforum.com/</link>
		</image>
		<item>
			<title><![CDATA[Solved: "Error loading dll files"]]></title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/95281-error-loading-dll-files.html</link>
			<pubDate>Sat, 04 Sep 2010 05:56:42 GMT</pubDate>
			<description>Every time i boot up my laptop and get to the desktop i get the following errors: 
  
Error loading c:\windows/dukbcsas.dll 
The specified module...</description>
			<content:encoded><![CDATA[<div>Every time i boot up my laptop and get to the desktop i get the following errors:<br />
 <br />
Error loading c:\windows/dukbcsas.dll<br />
The specified module could not be found<br />
 <br />
Error loading c:\windows/oqukokoxero.dll<br />
The specified module could not be found<br />
 <br />
Also, when i go into google and click on a link for the result of the search it sends me to the wrong page.<br />
 <br />
Can anyone help me with this? Thanks in advance!<br />
 <br />
I can't post my otl.txt file. Is it because the file is too long?</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>dfly</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/95281-error-loading-dll-files.html</guid>
		</item>
		<item>
			<title>Solved: I think I have a virus...Please help</title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/95177-i-think-i-have-virus-please-help.html</link>
			<pubDate>Wed, 01 Sep 2010 19:36:05 GMT</pubDate>
			<description><![CDATA[My computer has been running really slow and often freezes and cuts off completely. My mouse has been "acting up as well." At least I think it is my...]]></description>
			<content:encoded><![CDATA[<div>My computer has been running really slow and often freezes and cuts off completely. My mouse has been &quot;acting up as well.&quot; At least I think it is my mouse, could have something to do with a possible virus. I use mozilla firefox and every time I pull up a new page I am unable to click anything on the page, I have to click off the page and the bottom of the screen where the start menu is until I can click on the page again, I have to repeat this process every time!! I used hijack this and this is what the log reads:<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 3:24:20 PM, on 9/1/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Norton AntiVirus\Engine\17.7.0.12\ccSvcHst.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe<br />
C:\Program Files\Canon\CAL\CALMAIN.exe<br />
C:\Program Files\Norton AntiVirus\Engine\17.7.0.12\ccSvcHst.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\WINDOWS\vVX3000.exe<br />
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe<br />
C:\Program Files\QuickTime\QTTask.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo  tifier.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Documents and Settings\All Users\Application Data\U3\U3Launcher\LaunchU3.exe<br />
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe<br />
C:\WINDOWS\system32\HPZipm12.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br />
c:\windows\system\hpsysdrv.exe<br />
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br />
C:\Program Files\Mozilla Firefox\plugin-container.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iesearch&amp;locale=EN_US&amp;c=64&amp;bd=PAVILION&amp;pf=desktop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...ION&amp;pf=desktop</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iesearch&amp;locale=EN_US&amp;c=64&amp;bd=PAVILION&amp;pf=desktop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...ION&amp;pf=desktop</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int  ernet Settings,ProxyOverride = *.local<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br />
O2 - BHO: (no name) - {09C41C90-0EF2-4069-A929-78050490C101} - (no file)<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\17.7.0.12\IPSBHO.DLL<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll<br />
O2 - BHO: hpWebHelper Class - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\s  wg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll<br />
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: &amp;Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll<br />
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE<br />
O4 - HKLM\..\Run: [HPBootOp] &quot;C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe&quot; /run<br />
O4 - HKLM\..\Run: [Reminder] &quot;C:\Windows\Creator\Remind_XP.exe&quot;<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;  -osboot<br />
O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe<br />
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br />
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe<br />
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKCU\..\Run: [RegistryBooster] &quot;C:\Program Files\Uniblue\RegistryBooster\launcher.exe&quot; delay 20000 <br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo  tifier.exe&quot;<br />
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')<br />
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office2007trail\Office12\ONENOTEM.EXE<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O4 - Global Startup: LaunchU3.exe.lnk = ?<br />
O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MI79C6~1\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll<br />
O9 - Extra button: (no name) - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI79C6~1\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (file missing)<br />
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (file missing)<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - <a href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" target="_blank">Page Not Found | Facebook</a><br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a href="http://go.microsoft.com/fwlink/?linkid=39204" target="_blank">http://go.microsoft.com/fwlink/?linkid=39204</a><br />
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - <a href="https://config.skillcheck.com/onlinetesting/icaclients/win32/10.0/onlinetesting.cab" target="_blank">https://config.skillcheck.com/online...inetesting.cab</a><br />
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - <a href="http://photos.walmart.com/WalmartActivia.cab" target="_blank">http://photos.walmart.com/WalmartActivia.cab</a><br />
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - <a href="http://lads.myspace.com/upload/MySpaceUploader1006.cab" target="_blank">http://lads.myspace.com/upload/MySpaceUploader1006.cab</a><br />
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - <a href="http://by120fd.bay120.hotmail.msn.com/resources/MsnPUpld.cab" target="_blank">http://by120fd.bay120.hotmail.msn.co...s/MsnPUpld.cab</a><br />
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - <a href="http://download.divx.com/player/DivXBrowserPlugin.cab" target="_blank">http://download.divx.com/player/DivXBrowserPlugin.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1194570531343" target="_blank">http://www.update.microsoft.com/micr...?1194570531343</a><br />
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - <a href="http://by120fd.bay120.hotmail.msn.com/activex/HMAtchmt.ocx" target="_blank">http://by120fd.bay120.hotmail.msn.co...x/HMAtchmt.ocx</a><br />
O20 - AppInit_DLLs: okzxft.dll<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br />
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe<br />
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe<br />
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe<br />
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br />
O23 - Service: Norton AntiVirus (NAV) - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\17.7.0.12\ccSvcHst.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe<br />
<br />
--<br />
End of file - 11162 bytes<br />
<br />
Any thoughts?? Thank you for you time and help!!</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>llee524</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/95177-i-think-i-have-virus-please-help.html</guid>
		</item>
		<item>
			<title>Solved: Computer Hangs</title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/94861-computer-hangs.html</link>
			<pubDate>Wed, 25 Aug 2010 15:13:30 GMT</pubDate>
			<description><![CDATA[Hello, 
 
My computer is suddenly hanging. The hourglass shows but when I try to close a program, nothing happens. Even control+Alt+delete doesn't...]]></description>
			<content:encoded><![CDATA[<div>Hello,<br />
<br />
My computer is suddenly hanging. The hourglass shows but when I try to close a program, nothing happens. Even control+Alt+delete doesn't bring up the task manager. I had to reboot by holding the power button.<br />
<br />
After the last reboot, my icons in the task bar don't show.<br />
<br />
Do you think this is a virus problem?<br />
<br />
Thanks for any help.</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>mne_21</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/94861-computer-hangs.html</guid>
		</item>
		<item>
			<title>virus</title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/94826-virus.html</link>
			<pubDate>Tue, 24 Aug 2010 21:03:17 GMT</pubDate>
			<description>my sisters pc is so bummed. she didnt have virus protection and now she has a virus. i tried to install malwarebytes cos i know that seems to be the...</description>
			<content:encoded><![CDATA[<div>my sisters pc is so bummed. she didnt have virus protection and now she has a virus. i tried to install malwarebytes cos i know that seems to be the usual course of action, once i installed it i tried to run it and it told me it was a virus. i then tried to start her laptop in safe mode and it freezes as it ties to load up. are there any ideas???</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>fintan101</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/94826-virus.html</guid>
		</item>
		<item>
			<title>Solved: Unable to use google search</title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/94814-unable-use-google-search.html</link>
			<pubDate>Tue, 24 Aug 2010 16:47:12 GMT</pubDate>
			<description><![CDATA[I am unable to use google search. I get the following message. 
 
*Google*  Sorry... 
   *We're sorry...* 
 
 ... but your computer or network may be...]]></description>
			<content:encoded><![CDATA[<div>I am unable to use google search. I get the following message.<br />
<br />
<b><font face="times"><font size="10"><font color="#0039b6">G</font></font></font><font face="times"><font size="10"><font color="#c41200">o</font></font></font><font face="times"><font size="10"><font color="#f3c518">o</font></font></font><font face="times"><font size="10"><font color="#0039b6">g</font></font></font><font face="times"><font size="10"><font color="#30a72f">l</font></font></font><font face="times"><font size="10"><font color="#c41200">e</font></font></font></b>  Sorry...<br />
   <b>We're sorry...</b><br />
<br />
 ... but your computer or network may be sending automated queries. To protect our users, we can't process your request right now. <br />
       <font color="#aa1002"> <b>To continue searching, please type the characters you see below:</b> </font> <br />
<br />
Malware bytes did not show any malicious items. I am posting my Hijackthis log. Can anyone help?</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/fixed-hijackthis-logs/19035d1282668411-unable-use-google-search-hijackthis.log">hijackthis.log</a> (13.0 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>psmith</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/94814-unable-use-google-search.html</guid>
		</item>
		<item>
			<title>Solved: Logs</title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/94778-logs.html</link>
			<pubDate>Tue, 24 Aug 2010 00:56:06 GMT</pubDate>
			<description>Computer seems to be running slower</description>
			<content:encoded><![CDATA[<div>Computer seems to be running slower</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/fixed-hijackthis-logs/19015d1282611348-logs-extras.txt" target="_blank">Extras.Txt</a> (56.6 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/fixed-hijackthis-logs/19016d1282611348-logs-otl.txt" target="_blank">OTL.Txt</a> (94.2 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>skindred</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/94778-logs.html</guid>
		</item>
		<item>
			<title>Solved: Guess its a virus??</title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/94770-guess-its-virus.html</link>
			<pubDate>Mon, 23 Aug 2010 21:40:10 GMT</pubDate>
			<description><![CDATA[Hey guys!  I have posted on here before about a couple of things.  Luckily I haven't had to post in a while because my computer was running quite...]]></description>
			<content:encoded><![CDATA[<div>Hey guys!  I have posted on here before about a couple of things.  Luckily I haven't had to post in a while because my computer was running quite good....up until the other day.  So i decided i would come back here as you guys gave me some very good advise that REALLY worked...So Thank You for that, anyways...<br />
<br />
Here's my problem, My computer is running SOOOO slow for some reason, im guessing a virus or malware.  I still have malwarebytes on my comp from the last time i got help on here, and i will post the log (i just ran it today at about 4:00pm) at the end of this message just to get it out of the way.  But i also tried to run combofix.exe again, and i cant seem to get it to work at all... An error message comes up every time i try to run it that either says &quot;failed to install&quot; or &quot;32788r22fwjfw\n.pif   Not enough quota is available to process this command.&quot;<br />
<br />
So i dont know what the deal with that is...  I just recently got a new anti-virus program, system cleaning program, and internet security program all by COMODO.  So im guessing it has something to do with it, but am not sure.  Please can someone help me out with this?? I just want my computer to function normally again(speed wise)<br />
<br />
heres that log from malwarebytes.....hmm well i guess i dont have it after all, sry bout that.  I can re-run it if need be, but i will go ahead and tell you it found no threats or anything.</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>Boucheman414</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/94770-guess-its-virus.html</guid>
		</item>
		<item>
			<title><![CDATA[Solved: Nephew's Laptop Infected]]></title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/94728-nephews-laptop-infected.html</link>
			<pubDate>Mon, 23 Aug 2010 04:17:08 GMT</pubDate>
			<description><![CDATA[My nephew's laptop is infected. It is very slow and has many anti-virus popups come up...can't do much of anything. 
 
Attached is the otl file...no...]]></description>
			<content:encoded><![CDATA[<div>My nephew's laptop is infected. It is very slow and has many anti-virus popups come up...can't do much of anything.<br />
<br />
Attached is the otl file...no extras.txt created.<br />
<br />
Thanks!!!</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/fixed-hijackthis-logs/18989d1282537019-nephews-laptop-infected-otl.txt" target="_blank">OTL.Txt</a> (135.7 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>valadezm</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/94728-nephews-laptop-infected.html</guid>
		</item>
		<item>
			<title>Solved: javascript:clickRefresh()   hijacklog posted</title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/94701-javascript-clickrefresh-hijacklog-posted.html</link>
			<pubDate>Sun, 22 Aug 2010 18:17:16 GMT</pubDate>
			<description>Hello im need of some help please wonse in a while internet exploer opens up on its own and displays this in the address bar...</description>
			<content:encoded><![CDATA[<div>Hello im need of some help please wonse in a while internet exploer opens up on its own and displays this in the address bar javascript<b></b>:clickRefresh() it opens internet explorer on its own and multipul times i ran a few differnt scanns from micorsoft and no luck im posting a hijack log if some one can see anything wrong in there thanks hope someone can help thanks..<br />
 <br />
Logfile of Trend Micro HijackThis v2.0.4<br />
Scan saved at 2:19:10 PM, on 8/22/2010<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\System32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\system32\drivers\KodakCCS.exe<br />
C:\Program Files\Raxco\PerfectDisk\PDAgent.exe<br />
C:\WINDOWS\System32\PnkBstrA.exe<br />
C:\WINDOWS\system32\PnkBstrB.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\System32\wwSecure.exe<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
C:\Program Files\AVG\AVG9\avgemc.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\Program Files\Raxco\PerfectDisk\PDEngine.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\Skonoa.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\ATI Multimedia\main\ATIDtct.EXE<br />
C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
C:\Program Files\Common Files\Java\Java Update\jusched.exe<br />
C:\Program Files\Logitech\SetPointP\SetPoint.exe<br />
C:\Program Files\Chameleon Clock\ChamClock.exe<br />
C:\Program Files\CursorXP\CursorXP.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Rainlendar\Rainlendar.exe<br />
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Java\jre6\bin\java.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\Program Files\Windows Live\Contacts\wlcomm.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.google.ca/" target="_blank">Google</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll<br />
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll<br />
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll<br />
O3 - Toolbar: Foxit Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll<br />
O4 - HKLM\..\Run: [mySB] &quot;C:\Program Files\mySB\mySB.exe&quot; [auto]<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br />
O4 - HKLM\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE<br />
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Common Files\Java\Java Update\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming<br />
O4 - HKCU\..\Run: [HomeAlarm] C:\Program Files\Chameleon Clock\ChamClock.exe<br />
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [Google Update] &quot;C:\Documents and Settings\Rick1\Local Settings\Application Data\Google\Update\GoogleUpdate.exe&quot; /c<br />
O4 - Startup: Logitech . Product Registration.lnk = C:\Program Files\Common Files\Logishrd\eReg\SetPoint\eReg.exe<br />
O4 - Startup: Rainlendar.lnk = C:\Program Files\Rainlendar\Rainlendar.exe<br />
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html<br />
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html<br />
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html<br />
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: CabBuilder - <a href="http://ak.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab" target="_blank">http://ak.imgag.com/imgag/kiw/toolba...lerControl.cab</a><br />
O16 - DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} (Device Detection) - <a href="http://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab" target="_blank">http://www.logitech.com/devicedetect...etection32.cab</a><br />
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - <a href="http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab" target="_blank">http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab</a><br />
O16 - DPF: {535AC98D-C942-4C87-9275-09C9C43EF2C1} - <br />
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - <a href="http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6770.cab" target="_blank">http://cdn.scan.onecare.live.com/res...scbase6770.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1261329689900" target="_blank">http://update.microsoft.com/microsof...?1261329689900</a><br />
O16 - DPF: {6924091F-CD97-41E1-B1D4-D9079409D413} - <a href="http://vchat.evoicechat.com/talk.cab" target="_blank">http://vchat.evoicechat.com/talk.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1261329679816" target="_blank">http://update.microsoft.com/microsof...?1261329679816</a><br />
O16 - DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} - <a href="http://www.autodesk.com/global/dwfviewer/installer/DwfViewerSetup.cab" target="_blank">http://www.autodesk.com/global/dwfvi...iewerSetup.cab</a><br />
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - <a href="http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.1.66.0.cab" target="_blank">http://content.systemrequirementslab...l_4.1.66.0.cab</a><br />
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - <a href="http://213.196.182.244/activex/AMC.cab" target="_blank">http://213.196.182.244/activex/AMC.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - <a href="http://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab" target="_blank">http://gfx2.hotmail.com/mail/w4/pr01...l/MSNPUpld.cab</a><br />
O17 - HKLM\System\CCS\Services\Tcpip\..\{2CCB11AF-BB48-4937-A977-6E235094DEFC}: NameServer = 93.188.162.125,93.188.161.215<br />
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 93.188.162.125,93.188.161.215<br />
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 93.188.162.125,93.188.161.215<br />
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.162.125,93.188.161.215<br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)<br />
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll<br />
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe<br />
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe<br />
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe<br />
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe<br />
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe<br />
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe<br />
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\System32\PnkBstrA.exe<br />
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe<br />
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Program Files\WinPcap\rpcapd.exe<br />
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe<br />
O23 - Service: Washer AutoComplete (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\System32\wwSecure.exe<br />
--<br />
End of file - 10528 bytes</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>WildChild</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/94701-javascript-clickrefresh-hijacklog-posted.html</guid>
		</item>
		<item>
			<title>Solved: severe slow down, hijacker infections</title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/94683-severe-slow-down-hijacker-infections.html</link>
			<pubDate>Sun, 22 Aug 2010 14:59:53 GMT</pubDate>
			<description>HI, Running Xp sp3. Past couple months have noticed a severe slow down; 20+ mins to boot and more time than that to try and open something. When...</description>
			<content:encoded><![CDATA[<div>HI, Running Xp sp3. Past couple months have noticed a severe slow down; 20+ mins to boot and more time than that to try and open something. When opened IE, would automatically start typing on its own into the address/search boxes and keep coming back to main page. Ran malwarebytes to get rid of what it could. OTL logs per prework are zipped and attached</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/zip.gif" alt="File Type: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/fixed-hijackthis-logs/18959d1282489186-severe-slow-down-hijacker-infections-otl.zip">otl.zip</a> (103.9 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>jerryw1976</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/94683-severe-slow-down-hijacker-infections.html</guid>
		</item>
		<item>
			<title>Solved: Antimalware Doctor and TDSS Rootkit</title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/94670-antimalware-doctor-tdss-rootkit.html</link>
			<pubDate>Sun, 22 Aug 2010 10:25:15 GMT</pubDate>
			<description><![CDATA[Hi... so I've been infected with this horrible virus that is just about impossible to remove from my laptop. I'm just about at my wit's end. I...]]></description>
			<content:encoded><![CDATA[<div>Hi... so I've been infected with this horrible virus that is just about impossible to remove from my laptop. I'm just about at my wit's end. I noticed that you had resolved this problem for someone else and was wondering if you could help me too.<br />
<br />
A little background: All of a sudden pop-ups starting coming up on my computer advertising Antimalware Doctor. I did some research and read a lot of guides on how to rid myself of this malware and thought I had finally gotten it off with the help of rkill and Malwarebytes. That's when Windows Security Suite popped up. Further research suggested that I had a TDSS rootkit on my computer and so I downloaded TDSSKiller which found the virus and removed it. In order to complete this, the program rebooted my computer. However, the viruses must have infected some of my drivers because my computer froze on boot up. Booting into Safe mode worked halfway but then the computer froze after loading isapnp.sys. My brother is very talented with computers and helped walk me through re-installing windows and many of the drivers on the phone. I finally got my laptop running again and hit it with AVG free scan, Spybot S&amp;D, AdAware, and MalwareBytes. Unfortunately, MalwareBytes just found another instance of Antimalware Doctor. This file I believe is something along the lines of newsecureapp0707000.exe or something like that. I'm guessing that TDSS killer couldn't complete the removal once the system wouldn't reboot. Ok so that was a lot of background but I hope it can help you help me. Anyway, I have a desktop I can use right now but whenever you can get around to maybe helping me that would be absolutely fantastic.<br />
<br />
Thanks for reading this far!<br />
Sara</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>Sara_k</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/94670-antimalware-doctor-tdss-rootkit.html</guid>
		</item>
		<item>
			<title>Solved: I suspect virus</title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/94666-i-suspect-virus.html</link>
			<pubDate>Sun, 22 Aug 2010 06:13:00 GMT</pubDate>
			<description><![CDATA[Hi, guys. 
It's just that I recently found out that my C drive's space is getting lesser and lesser. I suspect it's virus again.... 
 
I did the...]]></description>
			<content:encoded><![CDATA[<div>Hi, guys.<br />
It's just that I recently found out that my C drive's space is getting lesser and lesser. I suspect it's virus again....<br />
<br />
I did the prework scan three times, and only come back with only OTL.txt:<br />
so here's the log<br />
<br />
<br />
OTL logfile created on: 8/22/2010 1:53:11 PM - Run 2<br />
OTL by OldTimer - Version 3.2.10.0     Folder = D:\Downloads<br />
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation<br />
Internet Explorer (Version = 6.0.2900.2180)<br />
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy<br />
 <br />
1,023.00 Mb Total Physical Memory | 513.00 Mb Available Physical Memory | 50.00% Memory free<br />
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 71.00% Paging File free<br />
Paging file location(s): C:\pagefile.sys 384 768 [binary data]<br />
 <br />
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files<br />
Drive C: | 14.65 Gb Total Space | 2.85 Gb Free Space | 19.47% Space Free | Partition Type: NTFS<br />
Drive D: | 23.63 Gb Total Space | 2.14 Gb Free Space | 9.06% Space Free | Partition Type: NTFS<br />
Drive E: | 149.05 Gb Total Space | 27.78 Gb Free Space | 18.64% Space Free | Partition Type: NTFS<br />
Drive F: | 488.00 Mb Total Space | 468.91 Mb Free Space | 96.09% Space Free | Partition Type: FAT32<br />
G: Drive not present or media not loaded<br />
H: Drive not present or media not loaded<br />
I: Drive not present or media not loaded<br />
 <br />
Computer Name: VALSHAR-BADD411<br />
Current User Name: *****<br />
Logged in as Administrator.<br />
 <br />
Current Boot Mode: Normal<br />
Scan Mode: Current user<br />
Company Name Whitelist: Off<br />
Skip Microsoft Files: Off<br />
File Age = 30 Days<br />
Output = Standard<br />
 <br />
<font color="#E56717">========== Processes (SafeList) ==========</font><br />
 <br />
PRC - [2010/08/22 13:11:50 | 000,575,488 | ---- | M] (OldTimer Tools) -- D:\Downloads\OTL.exe<br />
PRC - [2010/06/03 08:50:58 | 001,144,104 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe<br />
PRC - [2010/06/01 10:17:48 | 005,252,408 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe<br />
PRC - [2010/04/12 23:47:12 | 000,152,952 | ---- | M] (Tencent) -- C:\Program Files\Tencent\QQ\Bin\TXPlatform.exe<br />
PRC - [2010/03/16 09:28:48 | 000,144,760 | ---- | M] (Tencent) -- C:\Program Files\Tencent\QQ\Bin\QQ.exe<br />
PRC - [2010/02/27 21:00:23 | 000,202,256 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
PRC - [2009/07/21 13:34:33 | 000,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
PRC - [2009/05/13 15:48:22 | 000,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
PRC - [2009/03/02 12:08:47 | 000,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe<br />
PRC - [2008/11/10 04:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
PRC - [2006/11/10 23:12:30 | 000,099,936 | ---- | M] () -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe<br />
PRC - [2004/09/01 08:00:00 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe<br />
PRC - [2003/04/24 16:53:54 | 000,054,784 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE<br />
 <br />
 <br />
<font color="#E56717">========== Modules (SafeList) ==========</font><br />
 <br />
MOD - [2010/08/22 13:11:50 | 000,575,488 | ---- | M] (OldTimer Tools) -- D:\Downloads\OTL.exe<br />
MOD - [2010/04/12 23:48:40 | 001,748,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_65  95b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\GdiPlus.dll<br />
MOD - [2010/02/27 21:38:22 | 000,118,784 | ---- | M] (RealPlayer) -- C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ho  ok\rpchromebrowserrecordhelper.dll<br />
MOD - [2010/02/27 21:02:10 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvcr71.dll<br />
MOD - [2010/02/27 21:02:09 | 000,499,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvcp71.dll<br />
MOD - [2008/11/24 11:02:24 | 000,177,480 | ---- | M] (&#33150;&#35759;) -- C:\Program Files\Tencent\SSPlus\SPlus1.dll<br />
MOD - [2004/09/01 08:00:00 | 001,050,624 | R--- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll<br />
MOD - [2004/09/01 08:00:00 | 000,102,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx<br />
MOD - [2004/09/01 08:00:00 | 000,059,904 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\cabinet.dll<br />
 <br />
 <br />
<font color="#E56717">========== Win32 Services (SafeList) ==========</font><br />
 <br />
SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)<br />
SRV - [2009/07/21 13:34:33 | 000,185,089 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)<br />
SRV - [2009/05/13 15:48:22 | 000,108,289 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)<br />
SRV - [2008/12/09 17:22:00 | 000,116,040 | ---- | M] (Tencent) [Auto | Stopped] -- C:\Program Files\Tencent\QQSoftMgr\1.0.338.203\TencentUpdateS  vc.exe -- (TSUSVC)<br />
SRV - [2008/11/10 04:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)<br />
SRV - [2006/11/10 23:12:30 | 000,099,936 | ---- | M] () [Auto | Running] -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe -- (IJPLMSVC)<br />
 <br />
 <br />
<font color="#E56717">========== Driver Services (SafeList) ==========</font><br />
 <br />
DRV - File not found [Kernel | On_Demand | Stopped] -- E:\DRIVER\Audio\winio.sys -- (WINIO)<br />
DRV - [2010/06/27 14:07:44 | 000,023,456 | ---- | M] (Phoenix Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\DrvAgent32.sys -- (DrvAgent32)<br />
DRV - [2010/02/24 21:27:40 | 000,056,816 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)<br />
DRV - [2009/05/11 09:12:24 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)<br />
DRV - [2009/03/30 09:33:07 | 000,096,104 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)<br />
DRV - [2009/02/13 11:35:05 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)<br />
DRV - [2004/09/01 08:00:00 | 000,012,160 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\fsvga.sys -- (FsVga)<br />
DRV - [2004/08/04 07:08:22 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)<br />
DRV - [2004/08/04 06:29:56 | 001,897,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)<br />
DRV - [2003/04/24 23:48:02 | 000,730,092 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)<br />
DRV - [2002/10/15 00:00:00 | 000,101,431 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\IdeChnDr.sys -- (IdeChnDr) Intel(R)<br />
DRV - [2002/10/15 00:00:00 | 000,013,891 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\IdeBusDr.sys -- (IdeBusDr)<br />
DRV - [2001/08/17 20:11:42 | 000,029,696 | ---- | M] (CNet Technology, Inc.                                                    ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\DM9PCI5.SYS -- (DM9102) DAVICOM 9102(A)<br />
 <br />
 <br />
<font color="#E56717">========== Standard Registry (SafeList) ==========</font><br />
 <br />
 <br />
<font color="#E56717">========== Internet Explorer ==========</font><br />
 <br />
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://www.google.com/ie" target="_blank">Google Toolbar</a><br />
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm<br />
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = <a href="http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com" target="_blank">Yahoo!</a><br />
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = <a href="http://us.rd.yahoo.com/customize/ie/defaults/cs/msgr8/*http://www.yahoo.com/ext/search/search.html" target="_blank">Yahoo! SearchBar Home Page</a><br />
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = <a href="http://www.google.com/ie" target="_blank">Google Toolbar</a><br />
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = <a href="http://www.google.com/ie" target="_blank">Google Toolbar</a><br />
 <br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = <a href="http://www.google.com" target="_blank">Google</a><br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.yahoo.com/" target="_blank">Yahoo!</a><br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = <a href="http://www.google.com/ie" target="_blank">Google Toolbar</a><br />
IE - HKCU\..\URLSearchHook: {DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9} - C:\Program Files\Tencent\SSPlus\SAddr1.dll (&#33150;&#35759;)<br />
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)<br />
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Int  ernet Settings: &quot;ProxyEnable&quot; = 0<br />
 <br />
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892  B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\E  xt [2010/02/27 21:38:48 | 000,000,000 | ---D | M]<br />
FF - HKLM\software\mozilla\Firefox\Extensions\\support@  predictad.com: C:\Program Files\AutocompletePro\support@predictad.com [2010/07/29 20:35:06 | 000,000,000 | ---D | M]<br />
 <br />
 <br />
O1 HOSTS File: ([2004/09/01 08:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts<br />
O1 - Hosts: 127.0.0.1       localhost<br />
O2 - BHO: (&amp;Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)<br />
O2 - BHO: (IE2EMBHO Class) - {0A0DDBD3-6641-40B9-873F-BBDD26D6C14E} - C:\Program Files\easyMule\modules\IE2EM.dll (VeryCD.com)<br />
O2 - BHO: (Tencent Browser Helper) - {0C7C23EF-A848-485B-873C-0ED954731014} - C:\Program Files\Tencent\SSPlus\SAddr1.dll (&#33150;&#35759;)<br />
O2 - BHO: (AC-Pro) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Program Files\AutocompletePro\AutocompletePro.dll (SimplyGen)<br />
O2 - BHO: (Yahooo Search Protection) - {25BC7718-0BFA-40EA-B381-4B2D9732D686} - C:\Program Files\Yahoo!\Search Protection\ysp.dll (Yahoo! Inc.)<br />
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)<br />
O2 - BHO: (QQ&#24037;&#20855;&#26639;) - {29CF293A-1E7D-4069-9E11-E39698D0AF95} - C:\Program Files\Tencent\QQToolbar\IEBar.dll (Tencent)<br />
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrow  serrecordplugin.dll (RealPlayer)<br />
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)<br />
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInsta  nce.dll (Yahoo! Inc)<br />
O3 - HKLM\..\Toolbar: (QQ&#24037;&#20855;&#26639;) - {29CF293A-1E7D-4069-9E11-E39698D0AF95} - C:\Program Files\Tencent\QQToolbar\IEBar.dll (Tencent)<br />
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)<br />
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)<br />
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {65F8A3D2-4C22-4A33-9633-73167EAEEC45} - No CLSID value found.<br />
O3 - HKCU\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)<br />
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)<br />
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)<br />
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()<br />
O4 - HKLM..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE (CANON INC.)<br />
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)<br />
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)<br />
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)<br />
O4 - HKLM..\Run: [Soltek] C:\WINDOWS\system32\Autorun.exe ()<br />
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)<br />
O4 - HKLM..\Run: [stup.exe] C:\Program Files\Tencent\SSPlus\SPlus1.dll (&#33150;&#35759;)<br />
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)<br />
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)<br />
O4 - HKCU..\Run: [QQ2009] C:\Program Files\Tencent\QQ\Bin\QQ.exe (Tencent)<br />
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\pol  icies\Explorer: NoDriveTypeAutoRun = 145<br />
O8 - Extra context menu item: &amp;Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()<br />
O8 - Extra context menu item: Add to Google Photos Screensa&amp;ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)<br />
O8 - Extra context menu item: Download by easyMule - C:\Program Files\easyMule\IE2EM.htm ()<br />
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)<br />
O9 - Extra 'Tools' menuitem : Yahoo! Search Protection - {BBF74FB9-ABCD-4678-880A-2511DAABB5E1} - C:\Program Files\Yahoo!\Search Protection\ysp.dll (Yahoo! Inc.)<br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)<br />
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} <a href="http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab" target="_blank">http://java.sun.com/update/1.6.0/jin...ndows-i586.cab</a> (Java Plug-in 1.6.0_21)<br />
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} <a href="http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab" target="_blank">http://java.sun.com/update/1.6.0/jin...ndows-i586.cab</a> (Java Plug-in 1.6.0_21)<br />
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <a href="http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab" target="_blank">http://java.sun.com/update/1.6.0/jin...ndows-i586.cab</a> (Java Plug-in 1.6.0_21)<br />
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)<br />
O24 - Desktop WallPaper: C:\Documents and Settings\*****\Local Settings\Application Data\Microsoft\Wallpaper1.bmp<br />
O24 - Desktop BackupWallPaper: C:\Documents and Settings\*****\Local Settings\Application Data\Microsoft\Wallpaper1.bmp<br />
O32 - HKLM CDRom: AutoRun - 1<br />
O32 - AutoRun File - [2010/02/23 20:02:15 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]<br />
O32 - AutoRun File - [2008/09/10 22:31:44 | 000,000,090 | ---- | M] () - D:\AUTORUN.INF -- [ NTFS ]<br />
O33 - MountPoints2\{48855466-20ae-11df-8e9f-806d6172696f}\Shell\AutoRun\command - &quot;&quot; = D:\setupSNK.exe -- [2004/08/04 00:56:58 | 000,028,672 | ---- | M] (Microsoft Corporation)<br />
O33 - MountPoints2\{e55fde2f-9946-11df-b420-0008a1848244}\Shell\AutoRun\command - &quot;&quot; = G:\APPInst.exe -- File not found<br />
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found<br />
O35 - HKLM\..comfile [open] -- &quot;%1&quot; %*<br />
O35 - HKLM\..exefile [open] -- &quot;%1&quot; %*<br />
O37 - HKLM\...com [@ = comfile] -- &quot;%1&quot; %*<br />
O37 - HKLM\...exe [@ = exefile] -- &quot;%1&quot; %*<br />
 <br />
<font color="#E56717">========== Files/Folders - Created Within 30 Days ==========</font><br />
 <br />
[2010/08/03 23:08:15 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java<br />
[2010/08/03 23:07:01 | 000,423,656 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll<br />
[2010/08/03 23:07:01 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe<br />
[2010/08/03 23:07:01 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe<br />
[2010/08/03 23:07:01 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe<br />
[2010/07/29 20:35:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\*****\Application Data\All Free Video Joiner<br />
[2010/07/29 20:35:06 | 000,000,000 | ---D | C] -- C:\Program Files\AutocompletePro<br />
[2010/07/29 18:03:56 | 000,000,000 | ---D | C] -- C:\WINDOWS\Sun<br />
[2010/07/28 14:17:11 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump<br />
[2010/07/27 18:14:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\*****\Application Data\BitTorrent<br />
[3 C:\WINDOWS\*.tmp files -&gt; C:\WINDOWS\*.tmp -&gt; ]<br />
[1 C:\WINDOWS\System32\*.tmp files -&gt; C:\WINDOWS\System32\*.tmp -&gt; ]<br />
 <br />
<font color="#E56717">========== Files - Modified Within 30 Days ==========</font><br />
 <br />
[2010/08/22 13:12:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job<br />
[2010/08/22 12:59:35 | 000,000,104 | ---- | M] () -- C:\Documents and Settings\*****\Desktop\Shortcut to Recycle Bin.lnk<br />
[2010/08/22 12:57:06 | 000,109,056 | ---- | M] () -- C:\Documents and Settings\*****\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini<br />
[2010/08/22 12:45:04 | 000,000,017 | ---- | M] () -- C:\WINDOWS\System32\auto.ini<br />
[2010/08/22 12:45:01 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job<br />
[2010/08/22 12:44:51 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT<br />
[2010/08/22 12:44:48 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat<br />
[2010/08/22 12:44:46 | 1073,270,784 | -HS- | M] () -- C:\hiberfil.sys<br />
[2010/08/22 12:09:35 | 005,767,168 | -H-- | M] () -- C:\Documents and Settings\*****\NTUSER.DAT<br />
[2010/08/22 12:09:11 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\*****\ntuser.ini<br />
[2010/08/22 00:14:41 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk<br />
[2010/08/19 16:01:46 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl<br />
[2010/08/19 09:33:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job<br />
[2010/08/11 06:16:37 | 000,262,144 | ---- | M] () -- C:\Documents and Settings\All Users\ntuser.dat<br />
[2010/08/11 06:16:01 | 000,000,818 | ---- | M] () -- C:\Documents and Settings\*****\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk<br />
[2010/08/11 06:16:01 | 000,000,800 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Yahoo! Messenger.lnk<br />
[2010/07/29 20:24:36 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx<br />
[2010/07/28 10:18:46 | 000,001,791 | ---- | M] () -- C:\Documents and Settings\*****\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk<br />
[3 C:\WINDOWS\*.tmp files -&gt; C:\WINDOWS\*.tmp -&gt; ]<br />
[1 C:\WINDOWS\System32\*.tmp files -&gt; C:\WINDOWS\System32\*.tmp -&gt; ]<br />
 <br />
<font color="#E56717">========== Files Created - No Company Name ==========</font><br />
 <br />
[2010/08/22 12:59:34 | 000,000,104 | ---- | C] () -- C:\Documents and Settings\*****\Desktop\Shortcut to Recycle Bin.lnk<br />
[2010/08/11 06:16:37 | 000,262,144 | ---- | C] () -- C:\Documents and Settings\All Users\ntuser.dat<br />
[2010/08/11 06:16:37 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\All Users\ntuser.dat.LOG<br />
[2010/08/11 06:16:01 | 000,000,818 | ---- | C] () -- C:\Documents and Settings\*****\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk<br />
[2010/08/11 06:16:01 | 000,000,800 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Yahoo! Messenger.lnk<br />
[2010/02/26 15:10:24 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\CNMVS6e.DLL<br />
[2010/02/24 18:53:41 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI<br />
[2010/02/23 22:10:05 | 000,109,056 | ---- | C] () -- C:\Documents and Settings\*****\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini<br />
[2010/02/23 21:40:31 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini<br />
[2010/02/23 21:36:24 | 000,035,955 | ---- | C] () -- C:\WINDOWS\System32\En.ini<br />
[2010/02/23 21:36:24 | 000,014,024 | ---- | C] () -- C:\WINDOWS\System32\Autorun.ini<br />
[2010/02/23 21:36:20 | 000,000,017 | ---- | C] () -- C:\WINDOWS\System32\auto.ini<br />
[2004/09/01 08:00:00 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll<br />
[2004/09/01 08:00:00 | 000,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys<br />
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI<br />
 <br />
<font color="#E56717">========== LOP Check ==========</font><br />
 <br />
[2010/04/16 20:45:10 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ<br />
[2010/04/16 20:53:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJPLM<br />
[2010/04/13 00:05:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Tencent<br />
[2010/07/29 20:35:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\*****\Application Data\All Free Video Joiner<br />
[2010/08/22 13:04:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\*****\Application Data\BitTorrent<br />
[2010/04/13 06:10:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\*****\Application Data\Tencent<br />
 <br />
<font color="#E56717">========== Purity Check ==========</font><br />
 <br />
 <br />
 <br />
<font color="#E56717">========== Custom Scans ==========</font><br />
 <br />
 <br />
<font color="#A23BEC">&lt; %systemroot%\*. /mp /s &gt;</font><br />
 <br />
<font color="#A23BEC">&lt; %systemroot%\system32\*.dll /lockedfiles &gt;</font><br />
[2004/09/01 08:00:00 | 000,357,888 | ---- | M] (Microsoft Corporation)<b> Unable to obtain MD5</b> -- C:\WINDOWS\system32\dxtmsft.dll<br />
[2004/09/01 08:00:00 | 000,201,728 | ---- | M] (Microsoft Corporation)<b> Unable to obtain MD5</b> -- C:\WINDOWS\system32\dxtrans.dll<br />
[1 C:\WINDOWS\system32\*.tmp files -&gt; C:\WINDOWS\system32\*.tmp -&gt; ]<br />
 <br />
<font color="#A23BEC">&lt; %systemroot%\system32\*.exe /lockedfiles &gt;</font><br />
[1 C:\WINDOWS\system32\*.tmp files -&gt; C:\WINDOWS\system32\*.tmp -&gt; ]<br />
 <br />
<font color="#A23BEC">&lt; %systemroot%\Tasks\*.job /lockedfiles &gt;</font><br />
 <br />
<font color="#A23BEC">&lt; %systemroot%\system32\drivers\*.sys /lockedfiles &gt;</font><br />
 <br />
<font color="#A23BEC">&lt; %systemroot%\System32\config\*.sav &gt;</font><br />
[2010/02/24 03:19:49 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav<br />
[2010/02/24 03:19:49 | 000,659,456 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav<br />
[2010/02/24 03:19:48 | 000,880,640 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav<br />
 <br />
<font color="#A23BEC">&lt; %systemroot%\system32\*.sys &gt;</font><br />
[2004/09/01 08:00:00 | 000,009,029 | ---- | M] () -- C:\WINDOWS\system32\ansi.sys<br />
[2004/09/01 08:00:00 | 000,027,097 | ---- | M] () -- C:\WINDOWS\system32\country.sys<br />
[2004/09/01 08:00:00 | 000,004,768 | ---- | M] () -- C:\WINDOWS\system32\himem.sys<br />
[2004/09/01 08:00:00 | 000,042,809 | ---- | M] () -- C:\WINDOWS\system32\key01.sys<br />
[2004/09/01 08:00:00 | 000,042,537 | ---- | M] () -- C:\WINDOWS\system32\keyboard.sys<br />
[2004/09/01 08:00:00 | 000,027,866 | ---- | M] () -- C:\WINDOWS\system32\ntdos.sys<br />
[2004/09/01 08:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos404.sys<br />
[2004/09/01 08:00:00 | 000,029,370 | ---- | M] () -- C:\WINDOWS\system32\ntdos411.sys<br />
[2004/09/01 08:00:00 | 000,029,274 | ---- | M] () -- C:\WINDOWS\system32\ntdos412.sys<br />
[2004/09/01 08:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos804.sys<br />
[2004/09/01 08:00:00 | 000,033,840 | ---- | M] () -- C:\WINDOWS\system32\ntio.sys<br />
[2004/09/01 08:00:00 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio404.sys<br />
[2004/09/01 08:00:00 | 000,035,648 | ---- | M] () -- C:\WINDOWS\system32\ntio411.sys<br />
[2004/09/01 08:00:00 | 000,035,424 | ---- | M] () -- C:\WINDOWS\system32\ntio412.sys<br />
[2004/09/01 08:00:00 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio804.sys<br />
[2004/09/01 08:00:00 | 000,017,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\watchdog.sys<br />
[2004/09/01 08:00:00 | 001,835,904 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\win32k.sys<br />
[1 C:\WINDOWS\system32\*.tmp files -&gt; C:\WINDOWS\system32\*.tmp -&gt; ]<br />
 <br />
<font color="#A23BEC">&lt; %systemroot%\system32\drivers\*.dll &gt;</font><br />
 <br />
<font color="#A23BEC">&lt; %systemroot%\system32\drivers\*.ini &gt;</font><br />
 <br />
<font color="#A23BEC">&lt; %systemroot%\system32\drivers\*.exe &gt;</font><br />
 <br />
<font color="#A23BEC">&lt; %systemroot%\system32\Spool\prtprocs\w32x86\*.dll &gt;</font><br />
[2004/04/23 08:00:00 | 000,017,920 | ---- | M] (CANON INC.) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD6e.  DLL<br />
[2006/11/06 13:00:00 | 000,027,136 | ---- | M] (CANON INC.) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD8O.  DLL<br />
[2004/04/23 08:00:00 | 000,054,272 | ---- | M] (CANON INC.) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP6e.  DLL<br />
[2006/11/06 13:00:00 | 000,069,632 | ---- | M] (CANON INC.) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP8O.  DLL<br />
[2003/06/18 17:31:48 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.d  ll<br />
 <br />
<font color="#A23BEC">&lt; %SYSTEMDRIVE%\*.* &gt;</font><br />
[2010/02/23 20:02:15 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT<br />
[2010/02/23 19:36:44 | 000,000,211 | -HS- | M] () -- C:\boot.ini<br />
[2010/02/23 20:02:15 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS<br />
[2010/08/22 12:44:46 | 1073,270,784 | -HS- | M] () -- C:\hiberfil.sys<br />
[2010/02/23 20:02:15 | 000,000,000 | RHS- | M] () -- C:\IO.SYS<br />
[2010/02/23 20:02:15 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS<br />
[2004/09/01 08:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM<br />
[2004/09/01 08:00:00 | 000,250,032 | RHS- | M] () -- C:\ntldr<br />
[2010/08/22 12:44:45 | 402,653,184 | -HS- | M] () -- C:\pagefile.sys<br />
[2010/02/23 22:15:39 | 000,000,146 | ---- | M] () -- C:\YServer.txt<br />
 <br />
<font color="#A23BEC">&lt; %PROGRAMFILES%\*. &gt;</font><br />
[2010/04/19 18:49:49 | 000,000,000 | ---D | M] -- C:\Program Files\7-Zip<br />
[2010/02/26 12:25:37 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe<br />
[2010/02/23 22:18:23 | 000,000,000 | ---D | M] -- C:\Program Files\Apple Software Update<br />
[2010/07/29 20:35:07 | 000,000,000 | ---D | M] -- C:\Program Files\AutocompletePro<br />
[2010/02/23 21:24:03 | 000,000,000 | ---D | M] -- C:\Program Files\Avira<br />
[2010/02/23 21:46:39 | 000,000,000 | ---D | M] -- C:\Program Files\AvRack<br />
[2010/04/16 20:53:12 | 000,000,000 | ---D | M] -- C:\Program Files\Canon<br />
[2010/04/16 20:43:55 | 000,000,000 | -H-D | M] -- C:\Program Files\CanonBJ<br />
[2010/08/03 23:08:15 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files<br />
[2010/02/23 19:57:28 | 000,000,000 | ---D | M] -- C:\Program Files\ComPlus Applications<br />
[2010/07/19 14:15:45 | 000,000,000 | ---D | M] -- C:\Program Files\DivX<br />
[2010/08/22 01:44:02 | 000,000,000 | ---D | M] -- C:\Program Files\easyMule<br />
[2010/08/18 23:09:56 | 000,000,000 | ---D | M] -- C:\Program Files\Google<br />
[2010/02/23 21:40:26 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information<br />
[2010/02/23 21:39:15 | 000,000,000 | ---D | M] -- C:\Program Files\Intel<br />
[2010/02/23 20:00:15 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer<br />
[2010/08/03 23:06:49 | 000,000,000 | ---D | M] -- C:\Program Files\Java<br />
[2010/02/23 19:56:59 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger<br />
[2010/02/24 18:50:57 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft ActiveSync<br />
[2010/02/23 20:02:46 | 000,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage<br />
[2010/02/24 18:50:16 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Office<br />
[2010/02/24 18:51:06 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft.NET<br />
[2010/02/23 19:58:53 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker<br />
[2010/02/23 19:56:22 | 000,000,000 | ---D | M] -- C:\Program Files\MSN<br />
[2010/02/23 19:56:54 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone<br />
[2010/02/23 19:59:06 | 000,000,000 | ---D | M] -- C:\Program Files\NetMeeting<br />
[2010/02/23 19:59:52 | 000,000,000 | ---D | M] -- C:\Program Files\Online Services<br />
[2010/02/23 19:59:02 | 000,000,000 | ---D | M] -- C:\Program Files\Outlook Express<br />
[2010/02/23 21:45:38 | 000,000,000 | ---D | M] -- C:\Program Files\Project1<br />
[2010/02/23 22:19:42 | 000,000,000 | ---D | M] -- C:\Program Files\QuickTime<br />
[2010/02/27 21:33:28 | 000,000,000 | ---D | M] -- C:\Program Files\Real<br />
[2010/02/23 21:40:34 | 000,000,000 | ---D | M] -- C:\Program Files\Realtek Sound Manager<br />
[2010/04/13 00:23:32 | 000,000,000 | ---D | M] -- C:\Program Files\Tencent<br />
[2010/02/23 20:14:57 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information<br />
[2010/07/23 00:35:22 | 000,000,000 | ---D | M] -- C:\Program Files\VideoLAN<br />
[2010/02/23 22:17:49 | 000,000,000 | ---D | M] -- C:\Program Files\Winamp<br />
[2010/02/23 22:16:57 | 000,000,000 | ---D | M] -- C:\Program Files\Winamp Toolbar<br />
[2010/02/23 22:16:52 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player<br />
[2010/02/23 19:56:45 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT<br />
[2010/02/23 19:59:59 | 000,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate<br />
[2010/02/23 20:02:47 | 000,000,000 | ---D | M] -- C:\Program Files\xerox<br />
[2010/08/11 06:16:36 | 000,000,000 | ---D | M] -- C:\Program Files\Yahoo!<br />
 <br />
<font color="#A23BEC">&lt; %appdata%\*.* &gt;</font><br />
[2010/02/24 03:21:24 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\*****\Application Data\desktop.ini<br />
 <br />
 <br />
<font color="#A23BEC">&lt; MD5 for: AGP440.SYS  &gt;</font><br />
[2004/09/01 08:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys<br />
[2004/08/03 23:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\system32\dllcache\agp440.sys<br />
[2004/08/03 23:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\system32\drivers\AGP440.SYS<br />
[2004/08/04 07:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\system32\ReinstallBackups\0008\DriverFi  les\i386\AGP440.SYS<br />
 <br />
<font color="#A23BEC">&lt; MD5 for: ATAPI.SYS  &gt;</font><br />
[2004/09/01 08:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys<br />
[2004/08/03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\dllcache\atapi.sys<br />
[2004/08/03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys<br />
[2004/08/03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0009\DriverFi  les\i386\atapi.sys<br />
 <br />
<font color="#A23BEC">&lt; MD5 for: DISK.SYS  &gt;</font><br />
[2004/09/01 08:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:disk.sys<br />
[2004/09/01 08:00:00 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=00CA44E4534865F8A3B64F7C0984BFF0 -- C:\WINDOWS\system32\drivers\disk.sys<br />
 <br />
<font color="#A23BEC">&lt; MD5 for: EVENTLOG.DLL  &gt;</font><br />
[2004/09/01 08:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\dllcache\eventlog.dll<br />
[2004/09/01 08:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\eventlog.dll<br />
 <br />
<font color="#A23BEC">&lt; MD5 for: IDECHNDR.SYS  &gt;</font><br />
[2002/10/15 00:00:00 | 000,101,431 | ---- | M] (Intel Corporation) MD5=7D2B8BE9E89628663C1FB571F7C34062 -- C:\Program Files\Intel\Intel Application Accelerator\Driver\IdeChnDr.sys<br />
[2002/10/15 00:00:00 | 000,101,431 | ---- | M] (Intel Corporation) MD5=7D2B8BE9E89628663C1FB571F7C34062 -- C:\WINDOWS\system32\drivers\IdeChnDr.sys<br />
 <br />
<font color="#A23BEC">&lt; MD5 for: NETLOGON.DLL  &gt;</font><br />
[2004/09/01 08:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\dllcache\netlogon.dll<br />
[2004/09/01 08:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\netlogon.dll<br />
 <br />
<font color="#A23BEC">&lt; MD5 for: SCECLI.DLL  &gt;</font><br />
[2004/09/01 08:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\system32\dllcache\scecli.dll<br />
[2004/09/01 08:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\system32\scecli.dll<br />
 <br />
<font color="#A23BEC">&lt; MD5 for: USBSTOR.SYS  &gt;</font><br />
[2004/09/01 08:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:usbstor.sys<br />
[2004/08/03 23:08:48 | 000,026,496 | ---- | M] (Microsoft Corporation) MD5=6CD7B22193718F1D17A47A1CD6D37E75 -- C:\WINDOWS\system32\dllcache\usbstor.sys<br />
[2004/08/03 23:08:48 | 000,026,496 | ---- | M] (Microsoft Corporation) MD5=6CD7B22193718F1D17A47A1CD6D37E75 -- C:\WINDOWS\system32\drivers\USBSTOR.SYS<br />
 <br />
<font color="#A23BEC">&lt; HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr  entVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs &gt;</font><br />
&lt; End of report &gt;</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>velink</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/94666-i-suspect-virus.html</guid>
		</item>
		<item>
			<title>Solved: Computer is Very Slow</title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/94620-computer-very-slow.html</link>
			<pubDate>Sat, 21 Aug 2010 03:14:43 GMT</pubDate>
			<description>My Laptop is really slow.  Can someone review my HJT Log please. Thanks in advance.  
  
  
  
  
Logfile of Trend Micro HijackThis v2.0.2 
Scan...</description>
			<content:encoded><![CDATA[<div>My Laptop is really slow.  Can someone review my <acronym title="HijackThis - Malware Removal Tool">HJT</acronym> Log please. Thanks in advance. <br />
 <br />
 <br />
 <br />
 <br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 8:42:01 PM, on 8/20/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Unable to get Internet Explorer version!<br />
Boot mode: Normal<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\system32\acs.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\WINDOWS\system32\drivers\CDAC11BA.EXE<br />
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe<br />
C:\WINDOWS\system32\DVDRAMSV.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe<br />
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Documents and Settings\martin\Desktop\misc\HijackThis.exe<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://my.netzero.net/s/search?r=minisearch" target="_blank">http://my.netzero.net/s/search?r=minisearch</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://my.netzero.net/s/search?r=minisearch" target="_blank">http://my.netzero.net/s/search?r=minisearch</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://my.netzero.net/s/sp" target="_blank">NetZero - MyNetZero Personalized Start Page - Sign in</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://www.toshibadirect.com/dpdstart" target="_blank">Personalized Start Page</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html" target="_blank">Yahoo! SearchBar Home Page</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://my.netzero.net/s/search?r=minisearch" target="_blank">http://my.netzero.net/s/search?r=minisearch</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.yahoo.com/" target="_blank">Yahoo!</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = <a href="http://my.netzero.net/s/search?r=minisearch" target="_blank">http://my.netzero.net/s/search?r=minisearch</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R3 - Default URLSearchHook is missing<br />
O1 - Hosts: 217.20.175.74 <a href="http://www.review.2009softwarereviews.com" target="_blank">www.review.2009softwarereviews.com</a><br />
O1 - Hosts: 217.20.175.74 review.2009softwarereviews.com<br />
O1 - Hosts: 217.20.175.74 a1.review.zdnet.com<br />
O1 - Hosts: 217.20.175.74 <a href="http://www.d1.reviews.cnet.com" target="_blank">www.d1.reviews.cnet.com</a><br />
O1 - Hosts: 217.20.175.74 <a href="http://www.reviews.toptenreviews.com" target="_blank">www.reviews.toptenreviews.com</a><br />
O1 - Hosts: 217.20.175.74 reviews.toptenreviews.com<br />
O1 - Hosts: 217.20.175.74 <a href="http://www.reviews.download.com" target="_blank">www.reviews.download.com</a><br />
O1 - Hosts: 217.20.175.74 reviews.download.com<br />
O1 - Hosts: 217.20.175.74 <a href="http://www.reviews.pcadvisor.c.uk" target="_blank">www.reviews.pcadvisor.c.uk</a><br />
O1 - Hosts: 217.20.175.74 reviews.pcadvisor.co.uk<br />
O1 - Hosts: 217.20.175.74 <a href="http://www.reviews.pcmag.com" target="_blank">www.reviews.pcmag.com</a><br />
O1 - Hosts: 217.20.175.74 reviews.pcmag.com<br />
O1 - Hosts: 217.20.175.74 <a href="http://www.reviews.pcpro.co.uk" target="_blank">www.reviews.pcpro.co.uk</a><br />
O1 - Hosts: 217.20.175.74 reviews.pcpro.co.uk<br />
O1 - Hosts: 217.20.175.74 <a href="http://www.reviews.reevoo.com" target="_blank">www.reviews.reevoo.com</a><br />
O1 - Hosts: 217.20.175.74 reviews.reevoo.com<br />
O1 - Hosts: 217.20.175.74 <a href="http://www.reviews.riverstreams.co.uk" target="_blank">www.reviews.riverstreams.co.uk</a><br />
O1 - Hosts: 217.20.175.74 reviews.riverstreams.co.uk<br />
O1 - Hosts: 217.20.175.74 <a href="http://www.reviews.techradar.com" target="_blank">www.reviews.techradar.com</a><br />
O1 - Hosts: 217.20.175.74 reviews.techradar.com<br />
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL<br />
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)<br />
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\sw  g.dll<br />
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O8 - Extra context menu item: &amp;Search - ?p=ZCxdm565YYUS<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll<br />
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll<br />
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll<br />
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart<br />
O17 - HKLM\System\CCS\Services\Tcpip\..\{048B6625-782A-4F6B-8D8C-75640F03B3FC}: NameServer = 208.67.220.220,208.67.222.222 <br />
O17 - HKLM\System\CCS\Services\Tcpip\..\{BB299220-9734-4DEB-B7E4-D2EEFDF0D913}: NameServer = 208.67.220.220,208.67.222.222 <br />
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 <br />
O17 - HKLM\System\CS1\Services\Tcpip\..\{048B6625-782A-4F6B-8D8C-75640F03B3FC}: NameServer = 208.67.220.220,208.67.222.222 <br />
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 <br />
O17 - HKLM\System\CS2\Services\Tcpip\..\{048B6625-782A-4F6B-8D8C-75640F03B3FC}: NameServer = 208.67.220.220,208.67.222.222 <br />
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 <br />
O17 - HKLM\System\CS3\Services\Tcpip\..\{048B6625-782A-4F6B-8D8C-75640F03B3FC}: NameServer = 208.67.220.220,208.67.222.222 <br />
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 <br />
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe<br />
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE<br />
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe<br />
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe<br />
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe<br />
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe<br />
--<br />
End of file - 8887 bytes</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>eddie57</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/94620-computer-very-slow.html</guid>
		</item>
		<item>
			<title>Documents, Vids, pics all vanished</title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/94528-documents-vids-pics-all-vanished.html</link>
			<pubDate>Thu, 19 Aug 2010 00:54:08 GMT</pubDate>
			<description>Hello and thank you for reading.  I will explain my situation the best I can.  I had a malware running on my computer that was a keylogger.  I try to...</description>
			<content:encoded><![CDATA[<div>Hello and thank you for reading.  I will explain my situation the best I can.  I had a malware running on my computer that was a keylogger.  I try to get rid of it but it keeps reinstalling every couple of days.  It is not much of a problem I can handle it.  I used CC cleaner as well as Ad-aware and AVG that is constantly running and has for years.  <br />
<br />
 I went on a trip for 5 days and my computer was not turned on the entire time.  I come home and turn on my computer and find that not only do I not have documents, videos or pictures (VERY near and dear to me) but the files do not even exist.  Also my desktop is completely bare (sans the recycling bin.)<br />
<br />
  I have been searching forums for over an hour now and every &quot;solution&quot; I have read points to people changing admin or changing the files names which is not true in my case at all.  Also I know it is nothing like that because I did a restore and the files were there but empty!<br />
<br />
  I have some of these files on a backup HD and I went to move them over into the files to replace them and apparently they are already there! (I got asked to copy over the exact files over and over) so they are there! They are just well inviable.  I am sure this is some kind of sick messed up virus that I just can not find nor can I find any info on.  So I turn to your expertise.  Please help me out with anything you can to see these files. (by the way I have never &quot;hidden&quot; these files nor can I find an option to show hidden file)  Thank you in advance for any support you can give.</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>Chaca</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/94528-documents-vids-pics-all-vanished.html</guid>
		</item>
		<item>
			<title>Solved: Antimalware Doctor</title>
			<link>http://www.pchelpforum.com/fixed-hijackthis-logs/94413-antimalware-doctor.html</link>
			<pubDate>Mon, 16 Aug 2010 20:38:04 GMT</pubDate>
			<description><![CDATA[I have a Dell Dimension Table top with window xp . I have Antimalware Doctor pop up on my Pc saying " Antimalware Doctor has deceted 14 infected...]]></description>
			<content:encoded><![CDATA[<div>I have a Dell Dimension Table top with window xp . I have Antimalware Doctor pop up on my Pc saying &quot; Antimalware Doctor has deceted 14 infected objects on your computer during last scan .<br />
I don't know where this program came from and I can't delete it , when I try to delete it i got the following message &quot; Application cannot be executed.the file newsecureapp 70700.exe is infected.do you want to activate your antivirus software now yes no .&quot;</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/fixed-hijackthis-logs/"><![CDATA[[Fixed] Hijackthis! Logs]]></category>
			<dc:creator>George001</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/fixed-hijackthis-logs/94413-antimalware-doctor.html</guid>
		</item>
	</channel>
</rss>
