<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title><![CDATA[PC Help Forum - [Pending] HJT Logs]]></title>
		<link>http://www.pchelpforum.com</link>
		<description><![CDATA[This forum is for security threads that have seen inactivity for a period of at least two weeks after being reviewed. If your post is in here and you'd like to resume it, please start a new thread in the "[New] HiJackThis Logs" forum with the address of your thread in this forum and they will be merged.]]></description>
		<language>en</language>
		<lastBuildDate>Fri, 20 Nov 2009 23:40:52 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>1</ttl>
		<image>
			<url>http://www.pchelpforum.com/images/styles/pchelpforum/misc/rss.jpg</url>
			<title><![CDATA[PC Help Forum - [Pending] HJT Logs]]></title>
			<link>http://www.pchelpforum.com</link>
		</image>
		<item>
			<title>HELP : Hi Jacking program has taken over.</title>
			<link>http://www.pchelpforum.com/pending-hjt-logs/80617-help-hi-jacking-program-has-taken-over.html</link>
			<pubDate>Fri, 13 Nov 2009 01:20:04 GMT</pubDate>
			<description>Hello all, 
I am a newbie to forums and using some of these programs.  I heard about Hi Jack this and installed it a while ago to fix a similar...</description>
			<content:encoded><![CDATA[<div>Hello all,<br />
I am a newbie to forums and using some of these programs.  I heard about Hi Jack this and installed it a while ago to fix a similar program.  This one is calle Antivirus System Pro.  A bogus website that claims all my programs are infected.  It also opens up links to some porno sites and a viagra commercial.  I am hoping you can help me get this removed from our computer.<br />
Best Regards,<br />
Ralph and Rose</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/pending-hjt-logs/13742d1258075153-help-hi-jacking-program-has-taken-over-hijackthis-11-12-09.txt" target="_blank">hijackthis 11-12-09.txt</a> (9.3 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.pchelpforum.com/pending-hjt-logs/"><![CDATA[[Pending] HJT Logs]]></category>
			<dc:creator>Rhoegerm</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/pending-hjt-logs/80617-help-hi-jacking-program-has-taken-over.html</guid>
		</item>
		<item>
			<title><![CDATA[O4 - HKLM\..\Run: [Uyotuhe] rundll32.exe "C:\]]></title>
			<link>http://www.pchelpforum.com/pending-hjt-logs/80607-o4-hklm-run-uyotuhe-rundll32-exe-c.html</link>
			<pubDate>Thu, 12 Nov 2009 20:55:19 GMT</pubDate>
			<description>Something has got my computer, and is strangling.  I run spybot and avg and Fixit and nothing shows up. However, this has shown up in start up and I...</description>
			<content:encoded><![CDATA[<div>Something has got my computer, and is strangling.  I run spybot and avg and Fixit and nothing shows up. However, this has shown up in start up and I cannot get rid of it  O4 - HKLM\..\Run: [Uyotuhe] rundll32.exe &quot;C:\WINDOWS\ukinoyivoqubub.dll&quot;,Startup.  No one seems to know what it is.  Can anyone help.  Here is my HiJack log.<br />
<br />
C:\Program Files\AVG\AVG9\avgemc.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\PROGRA~1\VCOM\Fix-It\mxtask.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\WINDOWS\system32\taskmgr.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\Program Files\AVG\AVG9\avgscanx.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\Program Files\AVG\AVG9\avgcmgr.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\AVG\AVG9\avgupd.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Documents and Settings\LRR INC\Desktop\HiJackThis.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.aalimo.net/" target="_blank">Always Available Limo</a><br />
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search &amp; Destroy\SDHelper.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br />
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\sw  g.dll<br />
O3 - Toolbar: &amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll<br />
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br />
O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;  -osboot<br />
O4 - HKLM\..\Run: [Uyotuhe] rundll32.exe &quot;C:\WINDOWS\ukinoyivoqubub.dll&quot;,Startup<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search &amp; Destroy\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp;&amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search &amp; Destroy\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe<br />
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: AVG E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe<br />
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: Fix-It Task Manager - V Communications, Inc. - C:\PROGRA~1\VCOM\Fix-It\mxtask.exe<br />
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O24 - Desktop Component 0: (no name) - <a href="http://images.imagefap.com/images/full/21/173/1735251735.jpg" target="_blank">http://images.imagefap.com/images/fu...1735251735.jpg</a><br />
<br />
--<br />
End of file - 5275 bytes</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/pending-hjt-logs/"><![CDATA[[Pending] HJT Logs]]></category>
			<dc:creator>aalimoman</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/pending-hjt-logs/80607-o4-hklm-run-uyotuhe-rundll32-exe-c.html</guid>
		</item>
		<item>
			<title>avg wants me to remove ole part 1 of 5....how</title>
			<link>http://www.pchelpforum.com/pending-hjt-logs/80433-avg-wants-me-remove-ole-part-1-5-how.html</link>
			<pubDate>Sun, 08 Nov 2009 19:26:45 GMT</pubDate>
			<description>Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 2:18:36 PM, on 11/8/2009 
Platform: Windows XP SP3 (WinNT 5.01.2600) 
MSIE: Internet Explorer...</description>
			<content:encoded><![CDATA[<div>Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 2:18:36 PM, on 11/8/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
E:\FIXIT9~1\mxtask.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Common Files\Motive\McciCMService.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
E:\FIXIT9~1\mxtask2.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\System32\snmp.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe<br />
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\Program Files\AVG\AVG9\avgtray.exe<br />
C:\Program Files\Windows Defender\MsMpEng.exe<br />
C:\WINDOWS\system32\igfxsrvc.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.yahoo.com/" target="_blank">Yahoo!</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = <a href="http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com" target="_blank">Yahoo!</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int  ernet Settings,ProxyOverride = *.local<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll<br />
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_printenhancer.dll<br />
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_framework.dll<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br />
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\s  wg.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll<br />
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll<br />
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)<br />
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [Windows Defender] &quot;C:\Program Files\Windows Defender\MSASCui.exe&quot; -hide<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] &quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe  &quot; -t (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] &quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe  &quot; -t (User 'Default user')<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe<br />
O8 - Extra context menu item: &amp;Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\system32\shdocvw.dll<br />
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\system32\shdocvw.dll<br />
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll<br />
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll<br />
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - <a href="http://support.dell.com/systemprofiler/SysPro.CAB" target="_blank">http://support.dell.com/systemprofiler/SysPro.CAB</a><br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - <a href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" target="_blank">http://upload.facebook.com/controls/...oUploader5.cab</a><br />
O16 - DPF: {10093E98-C073-4C75-8D0E-FB5CD3A71D33} (ZoneUpwords Object) - <a href="http://messenger.zone.msn.com/binary/Upwords.cab57176.cab" target="_blank">http://messenger.zone.msn.com/binary...s.cab57176.cab</a><br />
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} (Bebo Uploader Control) - <a href="http://www.bebo.com/files/BeboUploader.5.1.4.cab" target="_blank">http://www.bebo.com/files/BeboUploader.5.1.4.cab</a><br />
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - <a href="http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab" target="_blank">http://messenger.zone.msn.com/binary...r.cab56986.cab</a><br />
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll<br />
O16 - DPF: {25FD7375-AB50-4EE1-8D4E-F76ECAC680B2} (CPlayFirstC4CControl Object) - <a href="http://www.playfirst.com/play/game/connectfour/C4C.1.0.0.47.cab" target="_blank">http://www.playfirst.com/play/game/c...C.1.0.0.47.cab</a><br />
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll<br />
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - <a href="http://asp.mathxl.com/wizmodules/testgen/installers/TestGenXInstall.cab" target="_blank">http://asp.mathxl.com/wizmodules/tes...enXInstall.cab</a><br />
O16 - DPF: {38D63471-E630-4492-A986-B8C48B79F2F8} (CVideoEgg_ActiveXCtl Object) - <a href="http://update.videoegg.com/wintel/VideoEggPublisher.exe" target="_blank">http://update.videoegg.com/wintel/VideoEggPublisher.exe</a><br />
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - <a href="http://disney.go.com/pirates/online/testActiveX/built/signed/DisneyOnlineGames.cab" target="_blank">http://disney.go.com/pirates/online/...nlineGames.cab</a><br />
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - <a href="http://lads.myspace.com/upload/MySpaceUploader1006.cab" target="_blank">http://lads.myspace.com/upload/MySpaceUploader1006.cab</a><br />
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - <a href="http://spaces.msn.com//PhotoUpload/MsnPUpld.cab" target="_blank">http://spaces.msn.com//PhotoUpload/MsnPUpld.cab</a><br />
O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - <a href="http://www.gocyberlink.com/winxp/CheckDVD.cab" target="_blank">Oops, our apologies .. page not found.</a><br />
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - <a href="http://messenger.zone.msn.com/EN-US/a-_UNO/GAME_UNO1.cab" target="_blank">http://messenger.zone.msn.com/EN-US/.../GAME_UNO1.cab</a><br />
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - <a href="http://www.playfirst.com/play/game/dinerdash2/dinerdash2.cab" target="_blank">http://www.playfirst.com/play/game/d...dinerdash2.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1114274806623" target="_blank">http://v5.windowsupdate.microsoft.co...?1114274806623</a><br />
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - <a href="http://us.games2.yimg.com/download.games.yahoo.com/games/play/client/exentctl_0_0_0_2.ocx" target="_blank">http://us.games2.yimg.com/download.g...tl_0_0_0_2.ocx</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1161520925975" target="_blank">http://update.microsoft.com/microsof...?1161520925975</a><br />
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - <a href="http://www.nick.com/common/groove/gx/GrooveAX27.cab" target="_blank">http://www.nick.com/common/groove/gx/GrooveAX27.cab</a><br />
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - <a href="http://landk.spaces.live.com/PhotoUpload/MsnPUpld.cab" target="_blank">http://landk.spaces.live.com/PhotoUpload/MsnPUpld.cab</a><br />
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - <a href="http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab" target="_blank">http://messenger.zone.msn.com/binary...t.cab31267.cab</a><br />
O16 - DPF: {93EFDAB8-8800-4896-B428-76F943140E1B} (Setup Class) - <a href="http://www.consumerinput.com.edgesuite.net/panel/maple/dcainst.cab" target="_blank">http://www.consumerinput.com.edgesui...le/dcainst.cab</a><br />
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - <a href="http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab" target="_blank">http://asp.mathxl.com/books/_Players...stallAsst2.cab</a><br />
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - <a href="http://www.crucial.com/controls/cpcScanner.cab" target="_blank">http://www.crucial.com/controls/cpcScanner.cab</a><br />
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - <a href="http://www.linksysfix.com/netcheck/67/install/gtdownls.cab" target="_blank">http://www.linksysfix.com/netcheck/6...l/gtdownls.cab</a><br />
O16 - DPF: {ABB660B6-6694-407B-950A-EDBA5A159722} (DVCDownloadControl) - <a href="http://download.games.yahoo.com/games/web_games/sony/davinci/DVCDownloadControl.cab" target="_blank">http://download.games.yahoo.com/game...oadControl.cab</a><br />
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - <a href="http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab" target="_blank">http://messenger.msn.com/download/Ms...Downloader.cab</a><br />
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - <a href="http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab" target="_blank">http://messenger.zone.msn.com/binary...o.cab56649.cab</a><br />
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - <a href="http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab" target="_blank">http://messenger.zone.msn.com/binary...t.cab57213.cab</a><br />
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - <a href="http://bmm.imgag.com/imgag/cp/install/crusher-us.cab" target="_blank">http://bmm.imgag.com/imgag/cp/install/crusher-us.cab</a><br />
O16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} (BewitchedGameClass Control) - <a href="http://aolsvc.aol.com/onlinegames/sonybewitched/main.cab" target="_blank">http://aolsvc.aol.com/onlinegames/so...tched/main.cab</a><br />
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - <a href="http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab" target="_blank">http://messenger.zone.msn.com/binary...t.cab56907.cab</a><br />
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - <a href="http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab" target="_blank">http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - <a href="http://download.games.yahoo.com/games/web_games/tikgames/cinematycoon/cinematycoon.cab" target="_blank">http://download.games.yahoo.com/game...nematycoon.cab</a><br />
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} - <br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - <a href="http://asp.mathxl.com/books/_Players/MathPlayer.cab" target="_blank">http://asp.mathxl.com/books/_Players/MathPlayer.cab</a><br />
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - <a href="https://secure.gopetslive.com/dev/GoPetsWeb.cab" target="_blank">https://secure.gopetslive.com/dev/GoPetsWeb.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Fix-It Task Manager - Avanquest North America, Inc. - E:\FIXIT9~1\mxtask.exe<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe<br />
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE<br />
--<br />
End of file - 15325 bytes</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/pending-hjt-logs/"><![CDATA[[Pending] HJT Logs]]></category>
			<dc:creator>kjberry</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/pending-hjt-logs/80433-avg-wants-me-remove-ole-part-1-5-how.html</guid>
		</item>
		<item>
			<title>Hijack This log report</title>
			<link>http://www.pchelpforum.com/pending-hjt-logs/80361-hijack-log-report.html</link>
			<pubDate>Sat, 07 Nov 2009 08:48:33 GMT</pubDate>
			<description><![CDATA[Hello everybody, 
  
I don't have experience in dealing with my log report, can anyone help me? robago:'(]]></description>
			<content:encoded><![CDATA[<div>Hello everybody,<br />
 <br />
I don't have experience in dealing with my log report, can anyone help me? robago:'(</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/pending-hjt-logs/13677d1257583532-hijack-log-report-hijack-analysis-report.txt" target="_blank">Hijack Analysis Report.txt</a> (6.1 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.pchelpforum.com/pending-hjt-logs/"><![CDATA[[Pending] HJT Logs]]></category>
			<dc:creator>robago</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/pending-hjt-logs/80361-hijack-log-report.html</guid>
		</item>
		<item>
			<title>Carmy</title>
			<link>http://www.pchelpforum.com/pending-hjt-logs/80333-carmy.html</link>
			<pubDate>Fri, 06 Nov 2009 19:33:13 GMT</pubDate>
			<description>Extremely slow startup and web surfing</description>
			<content:encoded><![CDATA[<div>Extremely slow startup and web surfing</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/pending-hjt-logs/"><![CDATA[[Pending] HJT Logs]]></category>
			<dc:creator>carmy43</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/pending-hjt-logs/80333-carmy.html</guid>
		</item>
		<item>
			<title>update KB975025 won,t stop .</title>
			<link>http://www.pchelpforum.com/pending-hjt-logs/80327-update-kb975025-won-t-stop.html</link>
			<pubDate>Fri, 06 Nov 2009 16:37:50 GMT</pubDate>
			<description>my pc updates with windows automatic update. The KB975025 update just keeps coming back updated about 20 times as soon as its done the yellow shield...</description>
			<content:encoded><![CDATA[<div>my pc updates with windows automatic update. The KB975025 update just keeps coming back updated about 20 times as soon as its done the yellow shield pops up for it to be done again?</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/pending-hjt-logs/"><![CDATA[[Pending] HJT Logs]]></category>
			<dc:creator>nikonmick110</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/pending-hjt-logs/80327-update-kb975025-won-t-stop.html</guid>
		</item>
		<item>
			<title>Resolved: Abr hijack this log</title>
			<link>http://www.pchelpforum.com/pending-hjt-logs/80279-abr-hijack-log.html</link>
			<pubDate>Thu, 05 Nov 2009 10:07:57 GMT</pubDate>
			<description>Hi all, 
  
Not having enough experience to do this myself can somebody please have a look at my hijack logfile and give suggestions what can be...</description>
			<content:encoded><![CDATA[<div>Hi all,<br />
 <br />
Not having enough experience to do this myself can somebody please have a look at my hijack logfile and give suggestions what can be improved in this?<br />
 <br />
Thanks in advance,<br />
Abr</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.pchelpforum.com/images/styles/pchelpforum/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.pchelpforum.com/attachments/pending-hjt-logs/13656d1257415640-abr-hijack-log-hijackthisnow.log">hijackthisnow.log</a> (15.9 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.pchelpforum.com/pending-hjt-logs/"><![CDATA[[Pending] HJT Logs]]></category>
			<dc:creator>Abr</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/pending-hjt-logs/80279-abr-hijack-log.html</guid>
		</item>
		<item>
			<title>Processes</title>
			<link>http://www.pchelpforum.com/pending-hjt-logs/80217-processes.html</link>
			<pubDate>Wed, 04 Nov 2009 06:14:14 GMT</pubDate>
			<description>I asked a simple question on why does my computer run so slow?  And was directed to Hijack This which has directed me in a roundabout way to here, so...</description>
			<content:encoded><![CDATA[<div>I asked a simple question on why does my computer run so slow?  And was directed to Hijack This which has directed me in a roundabout way to here, so here i am.  How do i post this log - thats what i'm supposed to be doing right now - so you can look at it and tell me what i need and what i don't need....  i think?<br />
 <br />
World of computers is so very plicomplicated!</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/pending-hjt-logs/"><![CDATA[[Pending] HJT Logs]]></category>
			<dc:creator>penijeni</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/pending-hjt-logs/80217-processes.html</guid>
		</item>
		<item>
			<title>Desktop Woes :(</title>
			<link>http://www.pchelpforum.com/pending-hjt-logs/79958-desktop-woes.html</link>
			<pubDate>Sat, 31 Oct 2009 12:52:29 GMT</pubDate>
			<description><![CDATA[Sorry i've been inactive off recently. Lost my granma in an accident. 
 
Anyway, my desktop is back to giving me sleepless nights. Its Infected with...]]></description>
			<content:encoded><![CDATA[<div>Sorry i've been inactive off recently. Lost my granma in an accident.<br />
<br />
Anyway, my desktop is back to giving me sleepless nights. Its Infected with a plethora of viruses. Need some help now.<br />
<br />
I'll update the prework logs in my next post. Advise me if i should run the dds and av4 tests too.<br />
<br />
Regards,<br />
Ann</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/pending-hjt-logs/"><![CDATA[[Pending] HJT Logs]]></category>
			<dc:creator>annihilate22</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/pending-hjt-logs/79958-desktop-woes.html</guid>
		</item>
		<item>
			<title>New To The Forum; New HiJack this log</title>
			<link>http://www.pchelpforum.com/pending-hjt-logs/79771-new-forum-new-hijack-log.html</link>
			<pubDate>Tue, 27 Oct 2009 16:15:19 GMT</pubDate>
			<description><![CDATA[Hola from Rhode Island! Here's my Hijack This Log? Any help deciphering it?Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 12:08:31 PM, on...]]></description>
			<content:encoded><![CDATA[<div>Hola from Rhode Island! Here's my Hijack This Log? Any help deciphering it?Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 12:08:31 PM, on 10/27/2009<br />
Platform: Windows Vista SP1 (WinNT 6.00.1905)<br />
MSIE: Internet Explorer v7.00 (7.00.6001.18000)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Program Files\McAfee.com\Agent\mcagent.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo  tifier.exe<br />
C:\Program Files\MozyHome\mozystat.exe<br />
C:\Windows\system32\sdclt.exe<br />
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\Windows\eHome\EHTray.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe<br />
C:\Windows\explorer.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.nasaspaceflight.com/" target="_blank">NASASpaceFlight.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int  ernet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: (no name) - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - (no file)<br />
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - (no file)<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\virusscan\scriptsn.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll<br />
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\siteadvisor\mcieplg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll<br />
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O3 - Toolbar: (no name) - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - (no file)<br />
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\siteadvisor\mcieplg.dll<br />
O3 - Toolbar: (no name) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - (no file)<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll<br />
O4 - HKLM\..\Run: [mcagent_exe] &quot;C:\Program Files\McAfee.com\Agent\mcagent.exe&quot; /runkey<br />
O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;  -osboot<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo  tifier.exe<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - Global Startup: MozyHome Status.lnk = C:\Program Files\MozyHome\mozystat.exe<br />
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present<br />
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present<br />
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O13 - Gopher Prefix: <br />
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\siteadvisor\mcieplg.dll<br />
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll<br />
O20 - Winlogon Notify: 8449d3a8517 - C:\Windows\<br />
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe<br />
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe<br />
O23 - Service: IWin service - Integrated Technology Express, Inc. - (no file)<br />
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\Windows\runservice.exe<br />
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe<br />
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br />
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VirusScan\mcods.exe<br />
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VirusScan\mcshield.exe<br />
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VirusScan\mcsysmon.exe<br />
O23 - Service: MozyHome Backup Service (mozybackup) - Mozy, Inc. - C:\Program Files\MozyHome\mozybackup.exe<br />
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
<br />
--<br />
End of file - 7282 bytes</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/pending-hjt-logs/"><![CDATA[[Pending] HJT Logs]]></category>
			<dc:creator>BigRIJoe</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/pending-hjt-logs/79771-new-forum-new-hijack-log.html</guid>
		</item>
		<item>
			<title><![CDATA[Unable to Perform "SAVE / SAVE AS" function]]></title>
			<link>http://www.pchelpforum.com/pending-hjt-logs/79452-unable-perform-save-save-function.html</link>
			<pubDate>Sat, 24 Oct 2009 07:42:21 GMT</pubDate>
			<description>Hi, 
 
I was unable to save all kinds of file under windows environment except saving file under MS office applications. 
 
Can anyone advise me on...</description>
			<content:encoded><![CDATA[<div>Hi,<br />
<br />
I was unable to save all kinds of file under windows environment except saving file under MS office applications.<br />
<br />
Can anyone advise me on this issue? <br />
**Which one should i remove in order to work, and also speed up my current performance.<br />
<br />
Below is my attached HiJack Log<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 3:36:17 PM, on 10/24/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16915)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\System32\ibmpmsvc.exe<br />
C:\WINDOWS\System32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\S24EvMon.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe<br />
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe<br />
C:\WINDOWS\system32\RunDll32.exe<br />
C:\WINDOWS\AGRSMMSG.exe<br />
C:\WINDOWS\system32\tp4serv.exe<br />
C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\Program Files\Microsoft ActiveSync\wcescomm.exe<br />
C:\Program Files\PPStream\ppsap.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\System32\QCONSVC.EXE<br />
C:\PROGRA~1\MICROS~3\rapimgr.exe<br />
C:\WINDOWS\system32\RegSrvc.exe<br />
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe<br />
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe<br />
C:\WINDOWS\system32\TpKmpSVC.exe<br />
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe<br />
C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\Documents and Settings\Jiansheng\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\Jiansheng\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Documents and Settings\Jiansheng\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\Jiansheng\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\Jiansheng\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\Jiansheng\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Documents and Settings\Jiansheng\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: &amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName<br />
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br />
O4 - HKLM\..\Run: [IMJPMIG8.1] &quot;C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE&quot; /Spoil /RemAdvDef /Migration32<br />
O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe<br />
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC<br />
O4 - HKLM\..\Run: [UC_Start] C:\IBMTools\Updater\ucstartup.exe<br />
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper<br />
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe<br />
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC<br />
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe<br />
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE<br />
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPw  rMonitor<br />
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe<br />
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe<br />
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe<br />
O4 - HKLM\..\Run: [Samsung Common SM] &quot;C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe&quot; /autorun<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [MobileConnect] %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [MsnMsgr] &quot;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&quot; /background<br />
O4 - HKCU\..\Run: [H/PC Connection Agent] &quot;C:\Program Files\Microsoft ActiveSync\wcescomm.exe&quot;<br />
O4 - HKCU\..\Run: [Google Update] &quot;C:\Documents and Settings\Jiansheng\Local Settings\Application Data\Google\Update\GoogleUpdate.exe&quot; /c<br />
O4 - HKCU\..\Run: [PPS Accelerator] C:\Program Files\PPStream\ppsap.exe<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll<br />
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll<br />
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O15 - ESC Trusted Zone: <a href="http://*.update.microsoft.com" target="_blank">http://*.update.microsoft.com</a><br />
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - <a href="http://upload.facebook.com/controls/FacebookPhotoUploader3.cab" target="_blank">http://upload.facebook.com/controls/...oUploader3.cab</a><br />
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - <a href="http://www.can.com.sg/mwf/mgaxctrl.cab" target="_blank">http://www.can.com.sg/mwf/mgaxctrl.cab</a><br />
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - <a href="http://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab" target="_blank">http://upload.facebook.com/controls/...ploader4_5.cab</a><br />
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe<br />
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)<br />
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE<br />
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe<br />
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\WINDOWS\system32\S24EvMon.exe<br />
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe<br />
O23 - Service: Vodafone Mobile Connect Service (VMCService) - Vodafone - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe<br />
<br />
--<br />
End of file - 8281 bytes</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/pending-hjt-logs/"><![CDATA[[Pending] HJT Logs]]></category>
			<dc:creator>kenz0</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/pending-hjt-logs/79452-unable-perform-save-save-function.html</guid>
		</item>
		<item>
			<title>Oh my word...Can anyone handle this?</title>
			<link>http://www.pchelpforum.com/pending-hjt-logs/79425-oh-my-word-can-anyone-handle.html</link>
			<pubDate>Fri, 23 Oct 2009 21:04:10 GMT</pubDate>
			<description><![CDATA[Hey everyone--- I've got a new problem for everyone. 
 
I recently thought I had gotten my dad's spyware problem under control...and he called me and...]]></description>
			<content:encoded><![CDATA[<div>Hey everyone--- I've got a new problem for everyone.<br />
<br />
I recently thought I had gotten my dad's spyware problem under control...and he called me and told me it was worse.<br />
<br />
Anyway, it's really rough right now..  I know he still has viruses, spyware...all of the above.<br />
<br />
I can't load ANY programs anymore.  I can get into safe mode, and I've tried to run Malwarebytes, but to no success....I've attempted to change the filename, too...and nothing.<br />
<br />
Can't even load any programs now...  I get &quot;choose a you want to use to open this file&quot;.... with programs like Regedit, malwarebytes, etc....<br />
<br />
With regedit, I would find the actual .exe file and hit &quot;open&quot;, and I get an error.  Nothing.  Bing, bang, boom.<br />
<br />
Tried running &quot;Combofix&quot;...and got the same problem.  <br />
<br />
Can't seem to get any antivirus or anti malware programs going...  Seems like I'm in trouble.<br />
<br />
Have I been beaten by a virus?  There is no way.</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/pending-hjt-logs/"><![CDATA[[Pending] HJT Logs]]></category>
			<dc:creator>Volman145</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/pending-hjt-logs/79425-oh-my-word-can-anyone-handle.html</guid>
		</item>
		<item>
			<title><![CDATA[Don't know what's going on in here]]></title>
			<link>http://www.pchelpforum.com/pending-hjt-logs/79412-dont-know-whats-going-here.html</link>
			<pubDate>Fri, 23 Oct 2009 16:55:34 GMT</pubDate>
			<description><![CDATA[Hi all, can anybody tell me what's wrong with my PC? Here I post the log file 
 
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 18.41.13, on...]]></description>
			<content:encoded><![CDATA[<div>Hi all, can anybody tell me what's wrong with my PC? Here I post the log file<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 18.41.13, on 23/10/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Programmi\Bonjour\mDNSResponder.exe<br />
C:\WINDOWS\eHome\ehRecvr.exe<br />
C:\WINDOWS\eHome\ehSched.exe<br />
C:\Programmi\Intel\Intel Matrix Storage Manager\Iaantmon.exe<br />
C:\Programmi\File comuni\LightScribe\LSSrvc.exe<br />
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\Programmi\Norton Internet Security\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Programmi\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\Programmi\Norton Internet Security\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\ehome\ehtray.exe<br />
C:\Programmi\Intel\Intel Matrix Storage Manager\Iaanotif.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\WINDOWS\eHome\ehmsas.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Programmi\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe<br />
C:\Programmi\HP\HP Software Update\HPwuSchd2.exe<br />
C:\PROGRA~1\ALICET~1\SMARTB~1\MotiveSB.exe<br />
C:\Programmi\ScanSoft\OmniPageSE4.0\OpwareSE4.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Programmi\iTunes\iTunesHelper.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Programmi\Google\GoogleToolbarNotifier\GoogleTo  olbarNotifier.exe<br />
C:\Programmi\DAEMON Tools Lite\daemon.exe<br />
C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Programmi\iPod\bin\iPodService.exe<br />
C:\HP\KBD\KBD.EXE<br />
c:\windows\system\hpsysdrv.exe<br />
C:\Programmi\Java\jre1.5.0_05\bin\jusched.exe<br />
C:\Programmi\File comuni\InstallShield\UpdateService\issch.exe<br />
C:\Programmi\Windows Live\Messenger\msnmsgr.exe<br />
C:\Programmi\Windows Live\Contacts\wlcomm.exe<br />
C:\Programmi\Mozilla Firefox\firefox.exe<br />
C:\Documents and Settings\HP_Administrator\Documenti\Download\HiJac  kThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about<b></b>:blank<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int  ernet Settings,AutoConfigURL = <a href="http://wpad.polimi.it/wpad.dat" target="_blank">http://wpad.polimi.it/wpad.dat</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int  ernet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Programmi\Norton Internet Security\Norton Internet Security\Engine\16.7.2.11\coIEPlg.dll<br />
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Programmi\Canon\Easy-WebPrint\EWPBrowseLoader.dll<br />
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Programmi\Norton Internet Security\Norton Internet Security\Engine\16.7.2.11\IPSBHO.DLL<br />
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programmi\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\5.3.4501  .1418\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Programmi\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programmi\Canon\Easy-WebPrint\Toolband.dll<br />
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Programmi\Norton Internet Security\Norton Internet Security\Engine\16.7.2.11\coIEPlg.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programmi\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe<br />
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode<br />
O4 - HKLM\..\Run: [IAAnotif] C:\Programmi\Intel\Intel Matrix Storage Manager\Iaanotif.exe<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [HPHUPD08] c:\Programmi\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe<br />
O4 - HKLM\..\Run: [DMAScheduler] c:\Programmi\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe<br />
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE<br />
O4 - HKLM\..\Run: [HPBootOp] &quot;C:\Programmi\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe&quot; /run<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Programmi\HP\HP Software Update\HPwuSchd2.exe<br />
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ALICET~1\SMARTB~1\MotiveSB.exe<br />
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FILECO~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br />
O4 - HKLM\..\Run: [SSBkgdUpdate] &quot;C:\Programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe&quot; -Embedding -boot<br />
O4 - HKLM\..\Run: [OpwareSE4] &quot;C:\Programmi\ScanSoft\OmniPageSE4.0\OpwareSE4.exe  &quot;<br />
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Programmi\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Programmi\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Programmi\Google\GoogleToolbarNotifier\GoogleT  oolbarNotifier.exe&quot;<br />
O4 - HKCU\..\Run: [DAEMON Tools Lite] &quot;C:\Programmi\DAEMON Tools Lite\daemon.exe&quot; -autorun<br />
O4 - HKCU\..\Policies\Explorer\Run: [FIFA10] C:\Programmi\FIFA 10\FIFA 10 support.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')<br />
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')<br />
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')<br />
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')<br />
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')<br />
O4 - Global Startup: Alice ti aiuta.lnk = C:\Programmi\Alice ti aiuta\bin\matcli.exe<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe<br />
O8 - Extra context menu item: Add to Google Photos Screensa&amp;ver - res://C:\WINDOWS\system32\GPhotos.scr/200<br />
O8 - Extra context menu item: Aggiungi all'elenco di stampa Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html<br />
O8 - Extra context menu item: Anteprima Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html<br />
O8 - Extra context menu item: E&amp;sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Stampa ad alta velocità Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html<br />
O8 - Extra context menu item: Stampa Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_05\bin\npjpi150_05.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_05\bin\npjpi150_05.dll<br />
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: Guida alla connessione - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm<br />
O9 - Extra 'Tools' menuitem: Guida alla connessione - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe<br />
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - <a href="https://webdl.symantec.com/activex/symdlmgr.cab" target="_blank">https://webdl.symantec.com/activex/symdlmgr.cab</a><br />
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - <a href="http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab" target="_blank">http://wwwimages.adobe.com/www.adobe...bat/nos/gp.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Programmi\Norton Internet Security\Norton Internet Security\Engine\16.7.2.11\coIEPlg.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Programmi\Bonjour\mDNSResponder.exe<br />
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Programmi\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe<br />
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Programmi\NOS\bin\getPlus_HelperSvc.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Programmi\Intel\Intel Matrix Storage Manager\Iaantmon.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programmi\File comuni\LightScribe\LSSrvc.exe<br />
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Programmi\Norton Internet Security\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: Utilità di pianificazione di LiveUpdate automatico - Unknown owner - C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.e  xe (file missing)<br />
<br />
--<br />
End of file - 11795 bytes<br />
<br />
<br />
<br />
Thanks everybody for help</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/pending-hjt-logs/"><![CDATA[[Pending] HJT Logs]]></category>
			<dc:creator>j_loca</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/pending-hjt-logs/79412-dont-know-whats-going-here.html</guid>
		</item>
		<item>
			<title>random reboot and tons email bounce messages</title>
			<link>http://www.pchelpforum.com/pending-hjt-logs/79407-random-reboot-tons-email-bounce-messages.html</link>
			<pubDate>Fri, 23 Oct 2009 15:20:09 GMT</pubDate>
			<description><![CDATA[I've been receiving email bounce messages for addresses not found for messages i have not sent. Desktop is now rebooting multiples times a day. 
...]]></description>
			<content:encoded><![CDATA[<div>I've been receiving email bounce messages for addresses not found for messages i have not sent. Desktop is now rebooting multiples times a day.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 9:59:04 AM, on 10/23/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Windows Defender\MsMpEng.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\ehome\ehtray.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\WINDOWS\sm56hlpr.exe<br />
C:\WINDOWS\system32\RUNDLL32.EXE<br />
C:\WINDOWS\system32\SysMonitor.exe<br />
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe<br />
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe<br />
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe<br />
C:\Program Files\Microsoft IntelliType Pro\itype.exe<br />
C:\Program Files\Microsoft IntelliPoint\ipoint.exe<br />
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\McAfee.com\Agent\mcagent.exe<br />
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9  TA.EXE<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe<br />
C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe<br />
C:\Program Files\TiVo\Desktop\TiVoNotify.exe<br />
C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe<br />
C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe<br />
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\WINDOWS\eHome\ehRecvr.exe<br />
C:\WINDOWS\eHome\ehSched.exe<br />
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartService.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
c:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe<br />
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br />
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe<br />
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe<br />
C:\WINDOWS\eHome\ehmsas.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com</a><br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = <a href="http://global.acer.com/" target="_blank">Home</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int  ernet Settings,ProxyOverride = *.local<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll<br />
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)<br />
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe<br />
O4 - HKLM\..\Run: [LaunchApp] Alaunch<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE<br />
O4 - HKLM\..\Run: [ntiMUI] c:\Program Files\NewTech Infosystems\NTI CD &amp; DVD-Maker 7\ntiMUI.exe<br />
O4 - HKLM\..\Run: [IMJPMIG8.1] &quot;C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE&quot; /Spoil /RemAdvDef /Migration32<br />
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE<br />
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC<br />
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC<br />
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName<br />
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\WINDOWS\system32\SysMonitor.exe<br />
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe 1<br />
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe<br />
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe<br />
O4 - HKLM\..\Run: [itype] &quot;C:\Program Files\Microsoft IntelliType Pro\itype.exe&quot;<br />
O4 - HKLM\..\Run: [IntelliPoint] &quot;C:\Program Files\Microsoft IntelliPoint\ipoint.exe&quot;<br />
O4 - HKLM\..\Run: [Symantec PIF AlertEng] &quot;C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe&quot; /a /m &quot;C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [mcagent_exe] &quot;C:\Program Files\McAfee.com\Agent\mcagent.exe&quot; /runkey<br />
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe<br />
O4 - HKLM\..\Run: [EPSON PictureMate Deluxe] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9  TA.EXE /P24 &quot;EPSON PictureMate Deluxe&quot; /O6 &quot;USB001&quot; /M &quot;PictureMate Deluxe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKLM\..\Run: [McAfee Backup] &quot;C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe<br />
O4 - HKCU\..\Run: [Google Update] &quot;C:\Documents and Settings\sysadmin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe&quot; /c<br />
O4 - HKCU\..\Run: [TivoTransfer] &quot;C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe&quot; /service /registry /auto:TivoTransfer<br />
O4 - HKCU\..\Run: [TivoNotify] &quot;C:\Program Files\TiVo\Desktop\TiVoNotify.exe&quot; /service /registry /auto:TivoNotify<br />
O4 - HKCU\..\Run: [TivoServer] &quot;C:\Program Files\TiVo\Desktop\TiVoServer.exe&quot; /service /registry /auto:TivoServer<br />
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] &quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe  &quot; -t (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] &quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe  &quot; -t (User 'Default user')<br />
O4 - Global Startup: Acer Empowering Technology.lnk = ?<br />
O4 - Global Startup: Acer WLAN 11g USB Dongle.lnk = C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - <a href="http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab" target="_blank">http://acs.pandasoftware.com/actives.../as2stubie.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br />
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe<br />
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe<br />
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br />
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe<br />
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: TiVo Beacon (TivoBeacon2) - TiVo Inc. - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe<br />
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe<br />
<br />
--<br />
End of file - 11909 bytes<br />
<br />
Malwarebytes' Anti-Malware 1.41<br />
Database version: 2987<br />
Windows 5.1.2600 Service Pack 3<br />
<br />
10/23/2009 10:09:24 AM<br />
mbam-log-2009-10-23 (10-09-24).txt<br />
<br />
Scan type: Quick Scan<br />
Objects scanned: 109510<br />
Time elapsed: 9 minute(s), 51 second(s)<br />
<br />
Memory Processes Infected: 0<br />
Memory Modules Infected: 0<br />
Registry Keys Infected: 0<br />
Registry Values Infected: 0<br />
Registry Data Items Infected: 0<br />
Folders Infected: 0<br />
Files Infected: 0<br />
<br />
Memory Processes Infected:<br />
(No malicious items detected)<br />
<br />
Memory Modules Infected:<br />
(No malicious items detected)<br />
<br />
Registry Keys Infected:<br />
(No malicious items detected)<br />
<br />
Registry Values Infected:<br />
(No malicious items detected)<br />
<br />
Registry Data Items Infected:<br />
(No malicious items detected)<br />
<br />
Folders Infected:<br />
(No malicious items detected)<br />
<br />
Files Infected:<br />
(No malicious items detected)</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/pending-hjt-logs/"><![CDATA[[Pending] HJT Logs]]></category>
			<dc:creator>pusher</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/pending-hjt-logs/79407-random-reboot-tons-email-bounce-messages.html</guid>
		</item>
		<item>
			<title>Think there may be a virus</title>
			<link>http://www.pchelpforum.com/pending-hjt-logs/79404-think-there-may-virus.html</link>
			<pubDate>Fri, 23 Oct 2009 12:26:42 GMT</pubDate>
			<description>Hello guys , friend of mine was having a lot of trouble with his advent T9508 tower pc running vista . I turned it on there to download the prework...</description>
			<content:encoded><![CDATA[<div>Hello guys , friend of mine was having a lot of trouble with his advent T9508 tower pc running vista . I turned it on there to download the prework and it is explorer that seems to be causing the problem . <br />
A pop up comes up saying windows is searching for a solution ,then another pop up says restarting then back to searching for a solution and it keeps repeating one after the other . I can not quit it , cannot use any other application . Where do i go from here guys ?</div>

]]></content:encoded>
			<category domain="http://www.pchelpforum.com/pending-hjt-logs/"><![CDATA[[Pending] HJT Logs]]></category>
			<dc:creator>clancruiser</dc:creator>
			<guid isPermaLink="true">http://www.pchelpforum.com/pending-hjt-logs/79404-think-there-may-virus.html</guid>
		</item>
	</channel>
</rss>
