<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>Windows BBS - Malware and Virus Removal</title>
		<link>http://www.WindowsBBS.com/</link>
		<description>Problems removing malware/viruses? Get help from our Malware removal experts.</description>
		<language>en</language>
		<lastBuildDate>Fri, 20 Nov 2009 21:51:52 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://www.windowsbbs.com/images_pb/misc/rss.jpg</url>
			<title>Windows BBS - Malware and Virus Removal</title>
			<link>http://www.WindowsBBS.com/</link>
		</image>
		<item>
			<title>Search engine redirect jump</title>
			<link>http://www.WindowsBBS.com/malware-virus-removal/88801-search-engine-redirect-jump.html</link>
			<pubDate>Fri, 20 Nov 2009 18:04:51 GMT</pubDate>
			<description>My browser will do a redirect jump anytime i try to go to any search results from a search engine. my security software sweep found something before this calling it malware and supposedly deleted it..but now this. not to savvy about this sort of thing and  need help. thank you for your time.</description>
			<content:encoded><![CDATA[<div>My browser will do a redirect jump anytime i try to go to any search results from a search engine. my security software sweep found something before this calling it malware and supposedly deleted it..but now this. not to savvy about this sort of thing and  need help. thank you for your time.</div>

]]></content:encoded>
			<category domain="http://www.WindowsBBS.com/malware-virus-removal/">Malware and Virus Removal</category>
			<dc:creator>MFapocalypse</dc:creator>
			<guid isPermaLink="true">http://www.WindowsBBS.com/malware-virus-removal/88801-search-engine-redirect-jump.html</guid>
		</item>
		<item>
			<title>Scanning=clean but antivirus warns of viruses</title>
			<link>http://www.WindowsBBS.com/malware-virus-removal/88782-scanning-clean-but-antivirus-warns-viruses.html</link>
			<pubDate>Thu, 19 Nov 2009 20:29:12 GMT</pubDate>
			<description>Dear all, 
 
Avast updated and Avira updated installed on my PC; 
Ran scanner and no viruses found; 
Ran Bitdefender online scan; no viruses found; 
 
But suddenly my Avast and Avira (simultanely) warns about viruses which I delete but keep coming back again with the same warning, same viruses. 
...</description>
			<content:encoded><![CDATA[<div>Dear all,<br />
<br />
Avast updated and Avira updated installed on my PC;<br />
Ran scanner and no viruses found;<br />
Ran Bitdefender online scan; no viruses found;<br />
<br />
But suddenly my Avast and Avira (simultanely) warns about viruses which I delete but keep coming back again with the same warning, same viruses.<br />
<br />
Pls advise.<br />
<br />
Thank you</div>

]]></content:encoded>
			<category domain="http://www.WindowsBBS.com/malware-virus-removal/">Malware and Virus Removal</category>
			<dc:creator>joedotm</dc:creator>
			<guid isPermaLink="true">http://www.WindowsBBS.com/malware-virus-removal/88782-scanning-clean-but-antivirus-warns-viruses.html</guid>
		</item>
		<item>
			<title><![CDATA[[Active] Internet Explorer redirects me to a different website]]></title>
			<link>http://www.WindowsBBS.com/malware-virus-removal/88770-active-internet-explorer-redirects-me-different-website.html</link>
			<pubDate>Thu, 19 Nov 2009 08:18:44 GMT</pubDate>
			<description>Hello, I am Brugutu. Every time I click on a website. Internet Explorer redirects me to a different website. I dont know what to do, so I was hoping someone will help me. I need Helppppp.  
 
I downloaded HijackThis and the logfile is below: 
 
Logfile of HijackThis v1.99.1 
Scan saved at 07:46:39,...</description>
			<content:encoded><![CDATA[<div>Hello, I am Brugutu. Every time I click on a website. Internet Explorer redirects me to a different website. I dont know what to do, so I was hoping someone will help me. I need Helppppp. <br />
<br />
I downloaded HijackThis and the logfile is below:<br />
<br />
Logfile of HijackThis v1.99.1<br />
Scan saved at 07:46:39, on 19/11/2009<br />
Platform: Unknown Windows (WinNT 6.00.1906 <acronym title="Service Pack 2">SP2</acronym>)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18828)<br />
<br />
Running processes:<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe<br />
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe<br />
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe<br />
C:\Program Files\IDT\WDM\sttray.exe<br />
C:\Program Files\HP\QuickPlay\QPService.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Program Files\Skype\Phone\Skype.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE<br />
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Program Files\Skype\Plugin Manager\skypePM.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE<br />
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe<br />
C:\Program Files\Windows Live\Contacts\wlcomm.exe<br />
C:\Windows\explorer.exe<br />
C:\Program Files\Safari\Safari.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Users\Lovaflex\Desktop\KillBox.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Program Files\Hijackthis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://www.forex-finance-trading.com/" target="_blank">http://www.forex-finance-trading.com/</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://www.forex-finance-trading.com/" target="_blank">http://www.forex-finance-trading.com/</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_gb&amp;c=83&amp;bd=Pavilion&amp;pf=cnnb" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...vilion&amp;pf=cnnb</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_gb&amp;c=83&amp;bd=Pavilion&amp;pf=cnnb" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...vilion&amp;pf=cnnb</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
R3 - URLSearchHook: Softonic-Eng7 Toolbar - {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - C:\Program Files\Softonic-Eng7\tbSoft.dll<br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O2 - BHO: Softonic-Eng7 Toolbar - {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - C:\Program Files\Softonic-Eng7\tbSoft.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll<br />
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll<br />
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll<br />
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll<br />
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll<br />
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O3 - Toolbar: Softonic-Eng7 Toolbar - {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - C:\Program Files\Softonic-Eng7\tbSoft.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start<br />
O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe<br />
O4 - HKLM\..\Run: [ccApp] &quot;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&quot;<br />
O4 - HKLM\..\Run: [osCheck] &quot;C:\Program Files\Norton 360\osCheck.exe&quot;<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe<br />
O4 - HKLM\..\Run: [StartCCC] &quot;c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&quot; MSRun<br />
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe<br />
O4 - HKLM\..\Run: [QPService] &quot;C:\Program Files\HP\QuickPlay\QPService.exe&quot;<br />
O4 - HKLM\..\Run: [UCam_Menu] &quot;C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe&quot; &quot;C:\Program Files\CyberLink\YouCam&quot; UpdateWithCreateOnce &quot;Software\CyberLink\YouCam\2.0&quot;<br />
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\<acronym title="Advanced Micro Devices">AMD</acronym>\Dual-Core Optimizer\amd_dc_opt.exe<br />
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [ATICustomerCare] &quot;C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden<br />
O4 - HKCU\..\Run: [msnmsgr] &quot;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&quot; /background<br />
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [Skype] &quot;C:\Program Files\Skype\Phone\Skype.exe&quot; /nosplash /minimized<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present<br />
O8 - Extra context menu item: &amp;AOL Toolbar Search - C:\ProgramData\AOL\ieToolbar\resources\en-GB\local\search.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL<br />
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll<br />
O11 - Options group: [INTERNATIONAL] International<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - <a href="http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab" target="_blank">http://messenger.zone.msn.com/binary...r.cab56986.cab</a><br />
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - <a href="http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab" target="_blank">http://messenger.zone.msn.com/binary...t.cab56907.cab</a><br />
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL<br />
O18 - Protocol: <acronym title="Microsoft">ms</acronym>-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll<br />
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll<br />
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL<br />
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\aestsrv.e  xe<br />
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe<br />
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&quot; /h ccCommon (file missing)<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&quot; /h ccCommon (file missing)<br />
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&quot; /h ccCommon (file missing)<br />
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe<br />
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe<br />
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)<br />
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe<br />
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe<br />
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
O23 - Service: HP Service (hpsrv) - Hewlett-Packard Corporation - C:\Windows\system32\Hpservice.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE<br />
O23 - Service: LiveUpdate Notice - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&quot; /h ccCommon (file missing)<br />
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe<br />
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe<br />
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe<br />
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)<br />
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe<br />
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe<br />
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)<br />
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\STacSV.ex  e<br />
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe<br />
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)</div>

]]></content:encoded>
			<category domain="http://www.WindowsBBS.com/malware-virus-removal/">Malware and Virus Removal</category>
			<dc:creator>Brugutu</dc:creator>
			<guid isPermaLink="true">http://www.WindowsBBS.com/malware-virus-removal/88770-active-internet-explorer-redirects-me-different-website.html</guid>
		</item>
		<item>
			<title><![CDATA[[Active] Explorer 8 Shuts itself down possible Security Problem?]]></title>
			<link>http://www.WindowsBBS.com/malware-virus-removal/88769-active-explorer-8-shuts-itself-down-possible-security-problem.html</link>
			<pubDate>Thu, 19 Nov 2009 05:03:10 GMT</pubDate>
			<description><![CDATA[I was posting in Windows BBS in regards to a problem with my outlook program. In that discussion I mentioned that my Explorer 8 would shut its self down from time to time because of some security error, but I am not able to remember exactly what it said and it hasn't done in the past couple of day....]]></description>
			<content:encoded><![CDATA[<div>I was posting in Windows BBS in regards to a problem with my outlook program. In that discussion I mentioned that my Explorer 8 would shut its self down from time to time because of some security error, but I am not able to remember exactly what it said and it hasn't done in the past couple of day. However, Arie suggested I run a diagnostic and then post the error message in this forum so this is it! I sure hope someone can help.  Next time Explorer 8 does this, I will be sure to write down what it says.  I am using Windows 7 Home Premium. Just upgraded from Vista last week.  However, Explorer was shutting itself down before I upgraded operating systems.  I downloaded Explorer 8 a few months before I upgraded to Windows 7.  Also, before I ran the following DDS file, it said to turn off scripting files, but I don't understand what that means. Hope this is what is needed. I also can't see how to attach a file, so I have just cut and pasted it here. Again Thank you for any help!<br />
Susan<br />
<br />
DDS (Ver_09-10-26.01) - NTFSx86  <br />
Run by SueZee at 22:46:40.62 on Wed 11/18/2009<br />
Internet Explorer: 8.0.7600.16385<br />
Microsoft Windows 7 Home Premium   6.1.7600.0.1252.1.1033.18.3007.1738 [GMT -6:00]<br />
<br />
AV: F-PROT Antivirus for Windows *On-access scanning disabled* (Outdated)   {3F8BAFFE-D251-4DC6-ACF9-81FDF61FB9C9}<br />
<br />
============== Running Processes ===============<br />
<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\svchost.exe -k RPCSS<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation<br />
C:\Program Files\FRISK Software\F-PROT Antivirus for Windows\FPAVServer.exe<br />
C:\Windows\system32\taskhost.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\svchost.exe -k hpdevmgmt<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\Windows\System32\svchost.exe -k HPZ12<br />
C:\Windows\System32\svchost.exe -k HPZ12<br />
C:\Windows\system32\PSIService.exe<br />
C:\Program Files\CyberLink\Shared files\RichVideo.exe<br />
C:\Windows\system32\svchost.exe -k imgsvc<br />
C:\Program Files\FRISK Software\F-PROT Antivirus for Windows\FProtTray.exe<br />
C:\Program Files\GetSmile\getsmile.exe<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Windows\system32\WUDFHost.exe<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Windows\System32\svchost.exe -k LocalServicePeerNet<br />
C:\Windows\System32\svchost.exe -k secsvcs<br />
c:\program files\windows defender\MpCmdRun.exe<br />
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Windows\system32\SearchProtocolHost.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Users\SueZee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HT30EDEE\dds[1].scr<br />
C:\Windows\system32\conhost.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
<br />
============== Pseudo <acronym title="Hijackthis">HJT</acronym> Report ===============<br />
<br />
uSearch Bar = Preserve<br />
uSearch Page = hxxp://www.google.com<br />
uStart Page = hxxp://www.google.ca/<br />
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File<br />
BHO: IEPlugin Class: {11222041-111b-46e3-bd29-efb2449479b1} - c:\progra~1\arcsoft\videod~1\ARCURL~1.DLL<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll<br />
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File<br />
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll<br />
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll<br />
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll<br />
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File<br />
uRun: [GetSmile] c:\program files\getsmile\getsmile.exe<br />
mRun: [F-PROT Antivirus Tray application] c:\program files\frisk software\f-prot antivirus for windows\FProtTray.exe<br />
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)<br />
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll<br />
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL<br />
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll<br />
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab<br />
DPF: {49232000-16E4-426C-A231-62846947304B} - hxxps://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab<br />
DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.geni.com/ImageUploader_5_5.cab<br />
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab<br />
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab<br />
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab<br />
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab<br />
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll<br />
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll<br />
<br />
============= SERVICES / DRIVERS ===============<br />
<br />
R0 FPAV_RTP;FPAV_RTP;c:\windows\system32\drivers\FStopW.sys [2009-8-31 682840]<br />
R2 FPAVServer;F-PROT Antivirus for Windows system;c:\program files\frisk software\f-prot antivirus for windows\FPAVServer.exe [2009-8-27 75424]<br />
R3 VST_DPV;VST_DPV;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-13 980992]<br />
R3 VSTHWBS2;VSTHWBS2;c:\windows\system32\drivers\VSTBS23.SYS [2009-7-13 266752]<br />
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]<br />
S3 nvrd32;nvrd32;c:\windows\system32\drivers\nvrd32.sys [2007-10-26 131616]<br />
<br />
=============== Created Last 30 ================<br />
<br />
2009-11-16 23:45:53	0	d-----w-	c:\program files\HowTo-Outlook<br />
2009-11-14 22:07:13	0	d-----w-	c:\users\suezee\Tracing<br />
2009-11-14 21:50:17	0	d-----w-	c:\program files\Microsoft<br />
2009-11-14 21:49:55	0	d-----w-	c:\program files\Windows Live SkyDrive<br />
2009-11-14 21:43:56	0	d-----w-	c:\program files\common files\Windows Live<br />
2009-11-14 06:02:49	0	d-----w-	C:\Panasonic Camera Software<br />
2009-11-12 23:49:13	0	d-----w-	c:\users\suezee\appdata\roaming\Avery<br />
2009-11-11 02:07:39	257024	----a-w-	c:\windows\system32\msv1_0.dll<br />
2009-11-10 09:05:07	34816	----a-w-	c:\windows\system32\msasn1.dll<br />
2009-11-10 09:05:03	728648	----a-w-	c:\windows\system32\drivers\dxgkrnl.sys<br />
2009-11-10 09:05:03	71168	----a-w-	c:\windows\system32\fontsub.dll<br />
2009-11-10 09:05:03	507568	----a-w-	c:\windows\system32\winload.exe<br />
2009-11-10 09:05:03	442920	----a-w-	c:\windows\system32\winresume.exe<br />
2009-11-10 09:05:03	293888	----a-w-	c:\windows\system32\atmfd.dll<br />
2009-11-10 09:05:03	2613248	----a-w-	c:\windows\explorer.exe<br />
2009-11-10 09:05:03	1320960	----a-w-	c:\windows\system32\CertEnroll.dll<br />
2009-11-10 09:05:03	108544	----a-w-	c:\windows\system32\t2embed.dll<br />
2009-11-10 09:05:02	12625408	----a-w-	c:\windows\system32\wmploc.DLL<br />
2009-11-10 04:27:18	0	d-----w-	c:\windows\Panther<br />
2009-11-10 04:14:06	0	d--h--w-	C:\$WINDOWS.~Q<br />
2009-11-10 04:08:31	0	d--h--w-	C:\$INPLACE.~TR<br />
2009-11-10 03:54:37	20	--sh--w-	c:\users\suezee\ntuser.ini<br />
2009-11-10 03:54:32	0	d-sh--w-	C:\Recovery<br />
2009-11-10 03:25:43	717892	----a-w-	c:\windows\system32\PerfStringBackup.INI<br />
2009-11-10 03:22:50	0	d-----w-	c:\windows\system32\wbem\Performance<br />
2009-11-10 03:02:10	21316	----a-w-	c:\windows\system32\emptyregdb.dat<br />
2009-11-10 02:33:41	0	d-----w-	c:\programdata\HP<br />
2009-11-10 02:32:03	9504	---ha-w-	c:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0<br />
2009-11-10 02:32:03	9504	---ha-w-	c:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0<br />
2009-11-10 02:31:17	0	d-----w-	c:\windows\system32\RTCOM<br />
2009-11-10 02:30:42	0	---ha-w-	c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf<br />
2009-11-10 01:03:20	1890	----a-w-	c:\windows\diagwrn.xml<br />
2009-11-10 01:03:20	1890	----a-w-	c:\windows\diagerr.xml<br />
2009-11-09 15:18:52	0	d-----w-	c:\users\suezee\Email Contacts vcard Nov 2009<br />
<br />
==================== Find3M  ====================<br />
<br />
2009-11-03 02:42:06	195456	------w-	c:\windows\system32\MpSigStub.exe<br />
2009-07-14 04:56:42	31548	----a-w-	c:\windows\inf\perflib\0409\perfd.dat<br />
2009-07-14 04:56:42	31548	----a-w-	c:\windows\inf\perflib\0409\perfc.dat<br />
2009-07-14 04:56:42	291294	----a-w-	c:\windows\inf\perflib\0409\perfi.dat<br />
2009-07-14 04:56:42	291294	----a-w-	c:\windows\inf\perflib\0409\perfh.dat<br />
2009-07-14 04:41:57	174	--sha-w-	c:\program files\desktop.ini<br />
2009-07-14 00:34:40	291294	----a-w-	c:\windows\inf\perflib\0000\perfi.dat<br />
2009-07-14 00:34:40	291294	----a-w-	c:\windows\inf\perflib\0000\perfh.dat<br />
2009-07-14 00:34:38	31548	----a-w-	c:\windows\inf\perflib\0000\perfd.dat<br />
2009-07-14 00:34:38	31548	----a-w-	c:\windows\inf\perflib\0000\perfc.dat<br />
2009-06-10 21:26:35	9633792	--sha-r-	c:\windows\fonts\StaticCache.dat<br />
2009-07-14 01:14:45	396800	--sha-w-	c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe<br />
<br />
============= FINISH: 22:47:11.33 ===============</div>

]]></content:encoded>
			<category domain="http://www.WindowsBBS.com/malware-virus-removal/">Malware and Virus Removal</category>
			<dc:creator>SueZee</dc:creator>
			<guid isPermaLink="true">http://www.WindowsBBS.com/malware-virus-removal/88769-active-explorer-8-shuts-itself-down-possible-security-problem.html</guid>
		</item>
		<item>
			<title><![CDATA[[Active] Possible Malware and/or Virus]]></title>
			<link>http://www.WindowsBBS.com/malware-virus-removal/88750-active-possible-malware-virus.html</link>
			<pubDate>Wed, 18 Nov 2009 18:35:37 GMT</pubDate>
			<description>Something takes control of my mouse sometimes.  :eek: 
 
Any assistance would be greatly appreciated.  :D 
 
Log details are below: :) 
 
Thank You, 
Sheila</description>
			<content:encoded><![CDATA[<div>Something takes control of my mouse sometimes.  :eek:<br />
<br />
Any assistance would be greatly appreciated.  :D<br />
<br />
Log details are below: :)<br />
<br />
Thank You,<br />
Sheila<br />
<br />
<br />
<br />
SUPERAntiSpyware Scan Log<br />
<a href="http://www.superantispyware.com" target="_blank">http://www.superantispyware.com</a><br />
<br />
Generated 11/17/2009 at 06:09 PM<br />
<br />
Application Version : 4.30.1004<br />
<br />
Core Rules Database Version : 4284<br />
Trace Rules Database Version: 2159<br />
<br />
Scan type       : Complete Scan<br />
Total Scan Time : 02:50:40<br />
<br />
Memory items scanned      : 219<br />
Memory threats detected   : 0<br />
Registry items scanned    : 6331<br />
Registry threats detected : 0<br />
File items scanned        : 70129<br />
File threats detected     : 1<br />
<br />
Adware.CouponBar<br />
	C:\WINDOWS\SYSTEM32\CPNPRT2.CID<br />
<br />
<br />
<br />
Malwarebytes' Anti-Malware 1.41<br />
Database version: 3192<br />
Windows 5.1.2600 Service Pack 3<br />
<br />
11/17/2009 9:50:08 PM<br />
mbam-log-2009-11-17 (21-50-08).txt<br />
<br />
Scan type: Full Scan (C:\|D:\|)<br />
Objects scanned: 205057<br />
Time elapsed: 2 hour(s), 39 minute(s), 47 second(s)<br />
<br />
Memory Processes Infected: 0<br />
Memory Modules Infected: 0<br />
Registry Keys Infected: 0<br />
Registry Values Infected: 0<br />
Registry Data Items Infected: 0<br />
Folders Infected: 0<br />
Files Infected: 0<br />
<br />
Memory Processes Infected:<br />
(No malicious items detected)<br />
<br />
Memory Modules Infected:<br />
(No malicious items detected)<br />
<br />
Registry Keys Infected:<br />
(No malicious items detected)<br />
<br />
Registry Values Infected:<br />
(No malicious items detected)<br />
<br />
Registry Data Items Infected:<br />
(No malicious items detected)<br />
<br />
Folders Infected:<br />
(No malicious items detected)<br />
<br />
Files Infected:<br />
(No malicious items detected)<br />
<br />
<br />
<br />
GMER 1.0.15.15227 - <a href="http://www.gmer.net" target="_blank">http://www.gmer.net</a><br />
Rootkit scan 2009-11-18 05:01:04<br />
Windows 5.1.2600 Service Pack 3<br />
Running: op1lslmb.exe; Driver: C:\DOCUME~1\Sheila\LOCALS~1\Temp\pxtdipow.sys<br />
<br />
<br />
---- System - GMER 1.0.15 ----<br />
<br />
SSDT            \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx)  ZwAssignProcessToJobObject [0xB8F2F1CC]<br />
SSDT            \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx)  ZwCreateThread [0xB8F2F206]<br />
SSDT            \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx)  ZwOpenProcess [0xB8F2F51A]<br />
SSDT            \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx)  ZwOpenThread [0xB8F2F3F6]<br />
SSDT            \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx)  ZwProtectVirtualMemory [0xB8F2F292]<br />
SSDT            \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx)  ZwSetContextThread [0xB8F2F18E]<br />
SSDT            \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx)  ZwTerminateProcess [0xB8F2F64E]<br />
SSDT            \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx)  ZwTerminateThread [0xB8F2F316]<br />
SSDT            \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx)  ZwWriteVirtualMemory [0xB8F2F34E]<br />
<br />
---- User code sections - GMER 1.0.15 ----<br />
<br />
.text           C:\WINDOWS\Explorer.EXE[3080] ntdll.dll!NtWriteFile                     7C90DF7E 5 Bytes  JMP 019B5BA0 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)<br />
.text           C:\WINDOWS\Explorer.EXE[3080] kernel32.dll!CreateThread                 7C8106D7 5 Bytes  JMP 019B5250 C:\WINDOWS\system32\PxSecure.dll (Prevx Security Library/Prevx)<br />
<br />
---- Devices - GMER 1.0.15 ----<br />
<br />
AttachedDevice  \Driver\Tcpip \Device\<acronym title="Internet Protocol">Ip</acronym>                                                msfwhlpr.sys (OneCare Firewall Helper Driver/Microsoft Corporation)<br />
<br />
Device          \Driver\ubohci \Device\UBOHCI0                                          UB1394.SYS (FireAPI® 1394 Class Driver (XP)/Unibrain S.A.)<br />
<br />
AttachedDevice  \Driver\Tcpip \Device\<acronym title="Transmission Control Protocol">Tcp</acronym>                                               msfwhlpr.sys (OneCare Firewall Helper Driver/Microsoft Corporation)<br />
<br />
Device          \Driver\ubohci \Device\C1394                                            UB1394.SYS (FireAPI® 1394 Class Driver (XP)/Unibrain S.A.)<br />
<br />
AttachedDevice  \Driver\Tcpip \Device\Udp                                               msfwhlpr.sys (OneCare Firewall Helper Driver/Microsoft Corporation)<br />
AttachedDevice  \Driver\Tcpip \Device\RawIp                                             msfwhlpr.sys (OneCare Firewall Helper Driver/Microsoft Corporation)<br />
<br />
---- EOF - GMER 1.0.15 ----<br />
<br />
<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 5:07:19 AM, on 11/18/2009<br />
Platform: Windows XP <acronym title="Service Pack 3">SP3</acronym> (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\System32\S24EvMon.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\AGI\core\3.1\AGCoreService.exe<br />
C:\WINDOWS\System32\dllhost.exe<br />
C:\Program Files\Prevx\prevx.exe<br />
C:\WINDOWS\system32\dldfcoms.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe<br />
c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe<br />
C:\WINDOWS\system32\PSIService.exe<br />
C:\WINDOWS\System32\RegSrvc.exe<br />
C:\WINDOWS\System32\tcpsvcs.exe<br />
c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe<br />
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\System32\dllhost.exe<br />
C:\WINDOWS\System32\WLTRYSVC.EXE<br />
C:\WINDOWS\System32\bcmwltry.exe<br />
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe<br />
C:\Program Files\Microsoft Windows OneCare Live\winss.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\WINDOWS\system32\ZCfgSvc.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Prevx\prevx.exe<br />
C:\WINDOWS\System32\1XConfig.exe<br />
C:\Program Files\Apoint\Apoint.exe<br />
C:\Program Files\Dell AIO Printer 948\dldfmon.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe<br />
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe<br />
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Apoint\HidFind.exe<br />
C:\Program Files\Apoint\Apntex.exe<br />
C:\Documents and Settings\Sheila\My Documents\Program Files\HijackThis.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R3 - URLSearchHook: agcore.AGUtils - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - mscoree.dll (file missing)<br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: agcore.AGUtils - {0bc6e3fa-78ef-4886-842c-5a1258c4455a} - mscoree.dll (file missing)<br />
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - (no file)<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers Client\YontooIEClient.dll<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll<br />
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - (no file)<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O3 - Toolbar: Webshots Toolbar - {C17590D2-ECB4-4b15-8820-F58798DCC118} - C:\Program Files\Webshots\3.1.5.7613\WSToolbar4IE.dll<br />
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [dldfmon.exe] &quot;C:\Program Files\Dell AIO Printer 948\dldfmon.exe&quot;<br />
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe<br />
O4 - HKLM\..\Run: [OneCareUI] &quot;C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe&quot;<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe&quot; /starttray<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKUS\S-1-5-21-682003330-507921405-854245398-1004\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')<br />
O4 - S-1-5-21-682003330-507921405-854245398-1004 Startup: Webshots.lnk = C:\Program Files\Webshots\3.1.5.7613\Launcher.exe (User '?')<br />
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\3.1.5.7613\Launcher.exe<br />
O8 - Extra context menu item: &amp;Add animation to IncrediMail Style Box - C:\Program Files\IncrediMail\bin\resources\WebMenuImg.htm<br />
O8 - Extra context menu item: &amp;Webshots Photo Search - res://C:\Program Files\Webshots\3.1.5.7613\WSToolbar4IE.dll/MENUSEARCH.HTM<br />
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - <a href="https://support.dell.com/systemprofiler/SysPro.CAB" target="_blank">https://support.dell.com/systemprofiler/SysPro.CAB</a><br />
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - <a href="http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab" target="_blank">http://upload.facebook.com/controls/...Uploader55.cab</a><br />
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - <a href="http://offers.e-centives.com/cif/download/bin/actxcab.cab" target="_blank">http://offers.e-centives.com/cif/dow...in/actxcab.cab</a><br />
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll<br />
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: AG Core Services (AGCoreService) - AG Interactive - C:\Program Files\AGI\core\3.1\AGCoreService.exe<br />
O23 - Service: CSIScanner - Prevx - C:\Program Files\Prevx\prevx.exe<br />
O23 - Service: dldfCATSCustConnectService - Unknown owner - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\dldfserv.exe<br />
O23 - Service: dldf_device -   - C:\WINDOWS\system32\dldfcoms.exe<br />
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe<br />
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe<br />
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe<br />
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\WINDOWS\System32\S24EvMon.exe<br />
O23 - Service: Dell Wireless <acronym title="Wireless Local Area Network">WLAN</acronym> Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE<br />
<br />
--<br />
End of file - 10319 bytes</div>

]]></content:encoded>
			<category domain="http://www.WindowsBBS.com/malware-virus-removal/">Malware and Virus Removal</category>
			<dc:creator>frostie23</dc:creator>
			<guid isPermaLink="true">http://www.WindowsBBS.com/malware-virus-removal/88750-active-possible-malware-virus.html</guid>
		</item>
		<item>
			<title>simple question, system32.exe need to be remove?</title>
			<link>http://www.WindowsBBS.com/malware-virus-removal/88740-simple-question-system32-exe-need-remove.html</link>
			<pubDate>Wed, 18 Nov 2009 08:41:08 GMT</pubDate>
			<description><![CDATA[I know it is a virus and i know how to remove it, but i just don't know will it affect my computer after remove it. Should i remove it? 
 
thanks in advance.]]></description>
			<content:encoded><![CDATA[<div>I know it is a virus and i know how to remove it, but i just don't know will it affect my computer after remove it. Should i remove it?<br />
<br />
thanks in advance.</div>

]]></content:encoded>
			<category domain="http://www.WindowsBBS.com/malware-virus-removal/">Malware and Virus Removal</category>
			<dc:creator>Hei</dc:creator>
			<guid isPermaLink="true">http://www.WindowsBBS.com/malware-virus-removal/88740-simple-question-system32-exe-need-remove.html</guid>
		</item>
		<item>
			<title><![CDATA[[Active] IE8 Re-directing from chosen web site]]></title>
			<link>http://www.WindowsBBS.com/malware-virus-removal/88734-active-ie8-re-directing-chosen-web-site.html</link>
			<pubDate>Wed, 18 Nov 2009 03:31:07 GMT</pubDate>
			<description><![CDATA[:mad: When I use Bing, google, ect to search a query, and then choose a website, I get re-directed to multiple different sites. they're all different, but One comes more than others. They all have a cursive looking 2 in front of the "http" in the address bar first, then it switches to another...]]></description>
			<content:encoded><![CDATA[<div>:mad: When I use Bing, google, ect to search a query, and then choose a website, I get re-directed to multiple different sites. they're all different, but One comes more than others. They all have a cursive looking 2 in front of the &quot;<acronym title="HyperText Transfer Protocol">http</acronym>&quot; in the address bar first, then it switches to another &quot;type&quot; of search site. I have ran Malwarebytes multiple times. I have also ran IObit Security 360 and Windows Saftey Scanner to no avail. I have Microsoft Security Essentials installed and active. I have also tried uninstalling IE8 and reinstalling. This is on a Dell with XP <acronym title="Service Pack 3">SP3</acronym>.</div>

]]></content:encoded>
			<category domain="http://www.WindowsBBS.com/malware-virus-removal/">Malware and Virus Removal</category>
			<dc:creator>steveo65</dc:creator>
			<guid isPermaLink="true">http://www.WindowsBBS.com/malware-virus-removal/88734-active-ie8-re-directing-chosen-web-site.html</guid>
		</item>
		<item>
			<title><![CDATA[[Active] msa.exe / b.exe / riuom.exe Infected Computer]]></title>
			<link>http://www.WindowsBBS.com/malware-virus-removal/88685-active-msa-exe-b-exe-riuom-exe-infected-computer.html</link>
			<pubDate>Sun, 15 Nov 2009 19:54:59 GMT</pubDate>
			<description><![CDATA[First off, I would like to thank the staff for dedicating their time and effort to helping folks with their computer issues. 
 
I have recently gotten my computer infected with msa.exe, b.exe and riuom.exe while attempting to copy an application to a friend's USB thumb drive.  I immediately ran a...]]></description>
			<content:encoded><![CDATA[<div>First off, I would like to thank the staff for dedicating their time and effort to helping folks with their computer issues.<br />
<br />
I have recently gotten my computer infected with msa.exe, b.exe and riuom.exe while attempting to copy an application to a friend's USB thumb drive.  I immediately ran a full scan with my Anti-Virus, which did not identify any positive results.  After a quick Google search, I realized that this was not a friendly infection and could use some assistance getting it cleaned up.<br />
<br />
Per the instructions in the &quot;Do this before posting&quot; thread, here are my DDS logs:<br />
<br />
DDS.txt<br />
-------------------------------------------------------------<br />
DDS (Ver_09-10-26.01) - NTFSx86  <br />
Run by Stephen at  0:09:16.18 on Mon 11/16/2009<br />
Internet Explorer: 7.0.6002.18005<br />
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.3070.1965 [GMT 4.5:30]<br />
<br />
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}<br />
<br />
============== Running Processes ===============<br />
<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\nvvsvc.exe<br />
C:\Windows\system32\svchost.exe -k rpcss<br />
C:\Windows\System32\svchost.exe -k secsvcs<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\system32\SLsvc.exe<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Windows\system32\rundll32.exe<br />
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe<br />
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\msa.exe<br />
C:\Windows\system32\svchost.exe -k imgsvc<br />
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe<br />
C:\Windows\System32\svchost.exe -k WerSvcGroup<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Users\Stephen\AppData\Local\Temp\b.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe<br />
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe<br />
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe<br />
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe<br />
C:\Program Files\PC Tools AntiVirus\PCTAV.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
D:\EVEMon\EVEMon.exe<br />
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Users\Stephen\riuom.exe<br />
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe<br />
C:\Users\Stephen\AppData\Local\Apps\2.0\20P6E2VL.C6G\W0EZGD44.RXW\curs..tio  n_eee711038731a406_0004.0000_10385b9745e33e88\CurseClient.exe<br />
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe<br />
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Windows\servicing\TrustedInstaller.exe<br />
D:\FDM\fdm.exe<br />
C:\Windows\system32\SearchProtocolHost.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Users\Stephen\Desktop\dds.scr<br />
<br />
============== Pseudo <acronym title="Hijackthis">HJT</acronym> Report ===============<br />
<br />
uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*<a href="http://www.yahoo.com" target="_blank">http://www.yahoo.com</a><br />
uStart Page = hxxp://www.yahoo.com/<br />
uDefault_Page_URL = hxxp://www.msi.com.tw<br />
uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*<a href="http://www.yahoo.com/ext/search/search.html" target="_blank">http://www.yahoo.com/ext/search/search.html</a><br />
mDefault_Page_URL = hxxp://www.msi.com.tw<br />
mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*<a href="http://www.yahoo.com" target="_blank">http://www.yahoo.com</a><br />
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*<a href="http://www.yahoo.com" target="_blank">http://www.yahoo.com</a><br />
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*<a href="http://www.yahoo.com/ext/search/search.html" target="_blank">http://www.yahoo.com/ext/search/search.html</a><br />
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*<a href="http://www.yahoo.com" target="_blank">http://www.yahoo.com</a><br />
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File<br />
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll<br />
BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File<br />
BHO: FDMIECookiesBHO Class: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - d:\fdm\iefdm2.dll<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll<br />
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File<br />
uRun: [EVEMon] &quot;d:\evemon\EVEMon.exe&quot; -startMinimized<br />
uRun: [Messenger (Yahoo!)] &quot;c:\program files\yahoo!\messenger\YahooMessenger.exe&quot; -quiet<br />
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe<br />
uRun: [riuom] c:\users\stephen\riuom.exe<br />
uRun: [SSHNAS] rundll32.exe c:\windows\system32\sshnas.dll,DllWork<br />
uRun: [MailBlocker] c:\users\stephen\appdata\local\temp\b.exe<br />
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup<br />
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit<br />
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe<br />
mRun: [SMSERIAL] c:\program files\motorola\smserial\sm56hlpr.exe<br />
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe<br />
mRun: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START<br />
mRun: [Adobe Reader Speed Launcher] &quot;c:\program files\adobe\reader 8.0\reader\Reader_sl.exe&quot;<br />
mRun: [PCTAVApp] &quot;c:\program files\pc tools antivirus\PCTAV.exe&quot; /MONITORSCAN<br />
mRun: [SunJavaUpdateSched] &quot;c:\program files\java\jre6\bin\jusched.exe&quot;<br />
StartupFolder: c:\users\stephen\appdata\roaming\microsoft\windows\start menu\programs\startup\CurseClientStartup.ccip<br />
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\toshiba\bluetooth toshiba stack\TosBtMng.exe<br />
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)<br />
mPolicies-system: EnableLUA = 0 (0x0)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
IE: Download all with Free Download Manager - file://d:\fdm\dlall.htm<br />
IE: Download selected with Free Download Manager - file://d:\fdm\dlselected.htm<br />
IE: Download video with Free Download Manager - file://d:\fdm\dlfvideo.htm<br />
IE: Download with Free Download Manager - file://d:\fdm\dllink.htm<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000<br />
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL<br />
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
<br />
============= SERVICES / DRIVERS ===============<br />
<br />
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-7-29 130936]<br />
R3 enecir;ENE CIR Receiver;c:\windows\system32\drivers\enecir.sys [2008-4-28 54784]<br />
R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2008-5-30 93968]<br />
R3 NETw5v32;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ;c:\windows\system32\drivers\NETw5v32.sys [2008-4-28 3658752]<br />
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-9-24 45600]<br />
R3 ReallusionVirtualAudio;Reallusion Virtual Audio;c:\windows\system32\drivers\RLVrtAuCbl.sys [2009-5-9 31616]<br />
<br />
=============== Created Last 30 ================<br />
<br />
2009-11-15 18:18:39	247296	----a-w-	c:\windows\msa.exe<br />
2009-11-15 18:15:54	180736	----a-w-	c:\windows\system32\sshnas.dll<br />
2009-11-15 18:13:31	49152	--sh--r-	c:\users\stephen\riuom.exe<br />
2009-11-11 16:08:48	324689495	----a-w-	c:\windows\MEMORY.DMP<br />
2009-11-11 08:11:42	2036736	----a-w-	c:\windows\system32\win32k.sys<br />
2009-11-11 08:11:09	355328	----a-w-	c:\windows\system32\WSDApi.dll<br />
2009-11-08 14:10:59	706	----a-w-	c:\windows\client.config.ini<br />
2009-10-30 04:09:28	1239	----a-w-	c:\windows\jmc.ini<br />
2009-10-28 16:19:42	0	d-----w-	C:\Downloads<br />
2009-10-28 16:18:02	0	d-----w-	c:\users\stephen\appdata\roaming\Free Download Manager<br />
2009-10-28 16:18:00	0	d-----w-	c:\programdata\FreeDownloadManager.ORG<br />
2009-10-27 21:54:17	310784	----a-w-	c:\windows\system32\unregmp2.exe<br />
2009-10-27 21:54:16	8147456	----a-w-	c:\windows\system32\wmploc.DLL<br />
2009-10-27 15:59:30	63	----a-w-	c:\users\stephen\jagex_runescape_preferences2.dat<br />
2009-10-27 15:45:59	38	----a-w-	c:\users\stephen\jagex_runescape_preferences.dat<br />
2009-10-27 15:43:53	0	d-----w-	C:\.jagex_cache_32<br />
2009-10-27 15:28:15	411368	----a-w-	c:\windows\system32\deploytk.dll<br />
2009-10-26 06:22:36	0	d-----w-	c:\windows\Alganon<br />
2009-10-20 04:44:13	2421760	----a-w-	c:\windows\system32\wucltux.dll<br />
2009-10-20 04:44:06	87552	----a-w-	c:\windows\system32\wudriver.dll<br />
2009-10-20 04:43:59	33792	----a-w-	c:\windows\system32\wuapp.exe<br />
2009-10-20 04:43:59	171608	----a-w-	c:\windows\system32\wuwebv.dll<br />
2009-10-17 05:48:32	0	d-----w-	c:\program files\VideoLAN<br />
<br />
==================== Find3M  ====================<br />
<br />
2009-11-15 19:34:54	49965	----a-w-	c:\programdata\nvModes.dat<br />
2009-11-02 16:12:06	195456	------w-	c:\windows\system32\MpSigStub.exe<br />
2009-09-15 17:24:45	86016	----a-w-	c:\windows\inf\infstor.dat<br />
2009-09-15 17:24:45	51200	----a-w-	c:\windows\inf\infpub.dat<br />
2009-09-15 17:24:45	143360	----a-w-	c:\windows\inf\infstrng.dat<br />
2009-09-15 17:18:45	665600	----a-w-	c:\windows\inf\drvindex.dat<br />
2009-09-15 17:14:44	37665	----a-w-	c:\windows\fonts\GlobalUserInterface.CompositeFont<br />
2009-09-10 16:48:01	218624	----a-w-	c:\windows\system32\msv1_0.dll<br />
2009-09-04 11:41:59	60928	----a-w-	c:\windows\system32\msasn1.dll<br />
2009-08-29 00:27:49	4240384	----a-w-	c:\windows\system32\GameUXLegacyGDFs.dll<br />
2009-08-29 00:14:38	28672	----a-w-	c:\windows\system32\Apphlpdm.dll<br />
2009-08-27 13:29:25	78336	----a-w-	c:\windows\system32\ieencode.dll<br />
2009-08-27 12:40:58	834048	----a-w-	c:\windows\system32\wininet.dll<br />
2008-01-21 02:43:21	174	--sha-w-	c:\program files\desktop.ini<br />
2006-11-02 12:42:02	30674	----a-w-	c:\windows\inf\perflib\0409\perfd.dat<br />
2006-11-02 12:42:02	30674	----a-w-	c:\windows\inf\perflib\0409\perfc.dat<br />
2006-11-02 12:42:02	287440	----a-w-	c:\windows\inf\perflib\0409\perfi.dat<br />
2006-11-02 12:42:02	287440	----a-w-	c:\windows\inf\perflib\0409\perfh.dat<br />
2006-11-02 09:20:21	287440	----a-w-	c:\windows\inf\perflib\0000\perfi.dat<br />
2006-11-02 09:20:21	287440	----a-w-	c:\windows\inf\perflib\0000\perfh.dat<br />
2006-11-02 09:20:19	30674	----a-w-	c:\windows\inf\perflib\0000\perfd.dat<br />
2006-11-02 09:20:19	30674	----a-w-	c:\windows\inf\perflib\0000\perfc.dat<br />
<br />
============= FINISH:  0:10:31.08 ===============<br />
<br />
Attach.txt<br />
--------------------------------------------------<br />
<br />
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.<br />
IF REQUESTED, ZIP IT UP &amp; ATTACH IT<br />
<br />
DDS (Ver_09-10-26.01)<br />
<br />
Microsoft® Windows Vista™ Home Premium <br />
Boot Device: \Device\HarddiskVolume2<br />
Install Date: 5/10/2009 9:47:35 AM<br />
System Uptime: 11/16/2009 12:03:28 AM (0 hours ago)<br />
<br />
Motherboard: MSI |  | <acronym title="Microsoft">MS</acronym>-1651<br />
Processor: Intel(R) Core(TM)2 Duo <acronym title="Central Processing Unit">CPU</acronym>     P8600  @ 2.40GHz | <acronym title="Central Processing Unit">CPU</acronym> 1 | 2401/267mhz<br />
<br />
==== Disk Partitions =========================<br />
<br />
C: is FIXED (NTFS) - 44 GiB total, 9.361 GiB free.<br />
D: is FIXED (NTFS) - 246 GiB total, 136.781 GiB free.<br />
F: is CDROM (UDF)<br />
<br />
==== Disabled Device Manager Items =============<br />
<br />
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}<br />
Description: Microsoft ISATAP Adapter<br />
Device ID: ROOT\*ISATAP\0003<br />
Manufacturer: Microsoft<br />
Name: Microsoft ISATAP Adapter #3<br />
PNP Device ID: ROOT\*ISATAP\0003<br />
Service: tunnel<br />
<br />
==== System Restore Points ===================<br />
<br />
RP208: 11/11/2009 5:18:36 PM - Windows Update<br />
RP209: 11/13/2009 1:31:45 AM - Windows Update<br />
RP210: 11/15/2009 7:18:26 PM - Scheduled Checkpoint<br />
<br />
==== Installed Programs ======================<br />
<br />
Adobe Flash Player 10 ActiveX<br />
Adobe Flash Player 9 ActiveX<br />
Adobe Reader 8.1.6<br />
Agere Systems HDA Modem<br />
Alganon<br />
Bluetooth Stack for Windows by Toshiba<br />
BurnRecovery<br />
CrazyTalk Cam Suite<br />
Curse Client<br />
Dolby Control Center<br />
EVEMon<br />
EverQuest Trilogy<br />
Free Download Manager 3.0<br />
Hotfix for Microsoft .NET Framework 3.5 <acronym title="Service Pack 1">SP1</acronym> (KB953595)<br />
Hotfix for Microsoft .NET Framework 3.5 <acronym title="Service Pack 1">SP1</acronym> (KB958484)<br />
Hotfix for Microsoft Visual C++ 2008 Express Edition with <acronym title="Service Pack 1">SP1</acronym> - ENU (KB945282)<br />
Hotfix for Microsoft Visual C++ 2008 Express Edition with <acronym title="Service Pack 1">SP1</acronym> - ENU (KB946040)<br />
Hotfix for Microsoft Visual C++ 2008 Express Edition with <acronym title="Service Pack 1">SP1</acronym> - ENU (KB946308)<br />
Hotfix for Microsoft Visual C++ 2008 Express Edition with <acronym title="Service Pack 1">SP1</acronym> - ENU (KB947540)<br />
Hotfix for Microsoft Visual C++ 2008 Express Edition with <acronym title="Service Pack 1">SP1</acronym> - ENU (KB947789)<br />
Hotfix for Microsoft Visual C++ 2008 Express Edition with <acronym title="Service Pack 1">SP1</acronym> - ENU (KB948127)<br />
Intel® Matrix Storage Manager<br />
Java(TM) 6 Update 17<br />
JMicron JMB38X Flash Media Controller<br />
Microsoft .NET Framework 3.5 <acronym title="Service Pack 1">SP1</acronym><br />
Microsoft Office Excel MUI (English) 2007<br />
Microsoft Office Home and Student 2007<br />
Microsoft Office OneNote MUI (English) 2007<br />
Microsoft Office PowerPoint MUI (English) 2007<br />
Microsoft Office Proof (English) 2007<br />
Microsoft Office Proof (French) 2007<br />
Microsoft Office Proof (Spanish) 2007<br />
Microsoft Office Proofing (English) 2007<br />
Microsoft Office Shared MUI (English) 2007<br />
Microsoft Office Shared Setup Metadata MUI (English) 2007<br />
Microsoft Office Suite Activation Assistant<br />
Microsoft Office Word MUI (English) 2007<br />
Microsoft SQL Server 2008 Management Objects<br />
Microsoft Visual C++ 2005 Redistributable<br />
Microsoft Visual C++ 2008 Express Edition with <acronym title="Service Pack 1">SP1</acronym> - ENU<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729<br />
Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries<br />
Microsoft Windows SDK for Visual Studio 2008 <acronym title="Service Pack 1">SP1</acronym> Express Tools for .NET Framework - enu<br />
Microsoft Windows SDK for Visual Studio 2008 <acronym title="Service Pack 1">SP1</acronym> Express Tools for Win32<br />
Microsoft Works<br />
Motorola SM56 Data Fax Modem<br />
MSI Software Install<br />
MSXML 4.0 <acronym title="Service Pack 2">SP2</acronym> (KB954430)<br />
My POS<br />
NVIDIA Drivers<br />
PC Tools AntiVirus 6.0<br />
Realtek 8169 8168 8101E 8102E Ethernet Driver<br />
Realtek High Definition Audio Driver<br />
Runes of Magic<br />
Spelling Dictionaries Support For Adobe Reader 8<br />
SQL Server System CLR Types<br />
Station Launcher<br />
TeamSpeak 2 RC2<br />
Ulead Burn.Now 4.5<br />
Ulead Burn.Now 4.5 SE<br />
Update for Microsoft .NET Framework 3.5 <acronym title="Service Pack 1">SP1</acronym> (KB963707)<br />
Update for Office 2007 (KB934528)<br />
Update for Office System 2007 Setup (KB929722)<br />
Ventrilo Client<br />
VLC media player 0.9.2<br />
Windows Driver Package - ENE (enecir) HIDClass  (04/29/2008 2.5.0.0)<br />
WinRAR archiver<br />
Yahoo! Messenger<br />
<br />
==== Event Viewer Messages From Past Week ========<br />
<br />
11/15/2009 10:40:24 PM, Error: Microsoft-Windows-<acronym title="Dynamic Host Configuration Protocol">Dhcp</acronym>-Client [1002]  - The <acronym title="Internet Protocol">IP</acronym> address lease 172.16.0.24 for the Network Card with network address 00215DEC10B2 has been denied by the <acronym title="Dynamic Host Configuration Protocol">DHCP</acronym> server 172.16.0.6 (The <acronym title="Dynamic Host Configuration Protocol">DHCP</acronym> Server sent a DHCPNACK message).<br />
11/14/2009 9:19:46 PM, Error: Microsoft-Windows-<acronym title="Dynamic Host Configuration Protocol">Dhcp</acronym>-Client [1002]  - The <acronym title="Internet Protocol">IP</acronym> address lease 172.16.0.22 for the Network Card with network address 00215DEC10B2 has been denied by the <acronym title="Dynamic Host Configuration Protocol">DHCP</acronym> server 172.16.0.6 (The <acronym title="Dynamic Host Configuration Protocol">DHCP</acronym> Server sent a DHCPNACK message).<br />
11/14/2009 9:19:43 PM, Error: Tcpip [4199]  - The system detected an address conflict for <acronym title="Internet Protocol">IP</acronym> address 172.16.0.22 with the system having network hardware address 00-21-5C-8B-B6-4F. Network operations on this system may be disrupted as a result.<br />
11/14/2009 8:01:06 AM, Error: netbt [4321]  - The name &quot;SMC1           :0&quot; could not be registered on the interface with <acronym title="Internet Protocol">IP</acronym> address 172.16.0.150. The computer with the <acronym title="Internet Protocol">IP</acronym> address 172.16.1.71 did not allow the name to be claimed by this computer.<br />
11/12/2009 5:26:57 PM, Error: Service Control Manager [7043]  - The Group Policy Client service did not shut down properly after receiving a preshutdown control.<br />
11/11/2009 8:49:11 PM, Error: Microsoft-Windows-<acronym title="Dynamic Host Configuration Protocol">Dhcp</acronym>-Client [1002]  - The <acronym title="Internet Protocol">IP</acronym> address lease 172.16.0.21 for the Network Card with network address 00215DEC10B2 has been denied by the <acronym title="Dynamic Host Configuration Protocol">DHCP</acronym> server 172.16.0.3 (The <acronym title="Dynamic Host Configuration Protocol">DHCP</acronym> Server sent a DHCPNACK message).<br />
11/11/2009 8:39:42 PM, Error: EventLog [6008]  - The previous system shutdown at 8:37:06 PM on 11/11/2009 was unexpected.<br />
11/11/2009 3:25:57 PM, Error: EventLog [6008]  - The previous system shutdown at 3:24:29 PM on 11/11/2009 was unexpected.<br />
11/11/2009 3:11:29 PM, Error: Service Control Manager [7034]  - The PC Tools AntiVirus Engine service terminated unexpectedly.  It has done this 1 time(s).<br />
11/11/2009 10:25:04 PM, Error: Microsoft-Windows-<acronym title="Dynamic Host Configuration Protocol">Dhcp</acronym>-Client [1002]  - The <acronym title="Internet Protocol">IP</acronym> address lease 172.16.0.23 for the Network Card with network address 00215DEC10B2 has been denied by the <acronym title="Dynamic Host Configuration Protocol">DHCP</acronym> server 10.156.132.1 (The <acronym title="Dynamic Host Configuration Protocol">DHCP</acronym> Server sent a DHCPNACK message).<br />
11/11/2009 10:17:59 PM, Error: Microsoft-Windows-<acronym title="Dynamic Host Configuration Protocol">Dhcp</acronym>-Client [1002]  - The <acronym title="Internet Protocol">IP</acronym> address lease 172.16.0.21 for the Network Card with network address 00215DEC10B2 has been denied by the <acronym title="Dynamic Host Configuration Protocol">DHCP</acronym> server 172.16.0.6 (The <acronym title="Dynamic Host Configuration Protocol">DHCP</acronym> Server sent a DHCPNACK message).<br />
11/11/2009 10:16:09 PM, Error: Microsoft-Windows-<acronym title="Dynamic Host Configuration Protocol">Dhcp</acronym>-Client [1002]  - The <acronym title="Internet Protocol">IP</acronym> address lease 172.16.0.115 for the Network Card with network address 00215DEC10B2 has been denied by the <acronym title="Dynamic Host Configuration Protocol">DHCP</acronym> server 172.16.0.6 (The <acronym title="Dynamic Host Configuration Protocol">DHCP</acronym> Server sent a DHCPNACK message).<br />
11/10/2009 11:37:12 PM, Error: Microsoft-Windows-<acronym title="Dynamic Host Configuration Protocol">Dhcp</acronym>-Client [1002]  - The <acronym title="Internet Protocol">IP</acronym> address lease 172.16.0.102 for the Network Card with network address 00215DEC10B2 has been denied by the <acronym title="Dynamic Host Configuration Protocol">DHCP</acronym> server 172.16.0.3 (The <acronym title="Dynamic Host Configuration Protocol">DHCP</acronym> Server sent a DHCPNACK message).<br />
<br />
==== End Of File ===========================<br />
<br />
Again, thank you for your assistance.</div>

]]></content:encoded>
			<category domain="http://www.WindowsBBS.com/malware-virus-removal/">Malware and Virus Removal</category>
			<dc:creator>Warhead42</dc:creator>
			<guid isPermaLink="true">http://www.WindowsBBS.com/malware-virus-removal/88685-active-msa-exe-b-exe-riuom-exe-infected-computer.html</guid>
		</item>
		<item>
			<title><![CDATA[[Active] iexplore.exe - pop ups from explorer problem]]></title>
			<link>http://www.WindowsBBS.com/malware-virus-removal/88667-active-iexplore-exe-pop-ups-explorer-problem.html</link>
			<pubDate>Sat, 14 Nov 2009 21:26:20 GMT</pubDate>
			<description><![CDATA[hey, i was looking around trying to find a solution, but i'm guessing every case is unique? i wasn't able to find an answer to my issue specifically, and i've done some google searches to see if i could fix the problem myself somehow, and google led me here. 
 
i've seem to have gotten an...]]></description>
			<content:encoded><![CDATA[<div>hey, i was looking around trying to find a solution, but i'm guessing every case is unique? i wasn't able to find an answer to my issue specifically, and i've done some google searches to see if i could fix the problem myself somehow, and google led me here.<br />
<br />
i've seem to have gotten an iexplore.exe problem virus, that's causing internet explorer to give me random pop-<acronym title="Un-interruptible Power Supply">ups</acronym> on my computer. i ran a check with avg, which turned up 'clean', and i ran spybot too, and even after fixing any problems with spybot, the pop-<acronym title="Un-interruptible Power Supply">ups</acronym> still appear! in my processes tab, i get 2 iexplore.exe files that shows. i'm running vista on my computer.<br />
<br />
as per someone else's forum post, i too decided to run hijackthis to see what it would give me. here is the log:<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 14:02:35, on 14/11/2009<br />
Platform: Windows Vista <acronym title="Service Pack 2">SP2</acronym> (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v7.00 (7.00.6002.18005)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\SYSTEM32\WISPTIS.EXE<br />
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\WTablet\Pen_TabletUser.exe<br />
C:\WINDOWS\RtHDVCpl.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\Logitech\QuickCam\Quickcam.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\WINDOWS\System32\rundll32.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\AVG\AVG9\avgtray.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\Program Files\Pando Networks\Media Booster\PMB.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Users\Owner\AppData\Roaming\Dropbox\bin\Dropbox.exe<br />
C:\Program Files\Windows Live\Contacts\wlcomm.exe<br />
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe<br />
C:\Program Files\AIM6\aim6.exe<br />
C:\Program Files\AIM6\aolsoftware.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe<br />
C:\Program Files\Windows Media Player\wmplayer.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Windows\system32\Taskmgr.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Program Files\WinRAR\WinRAR.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_ca&amp;c=81&amp;bd=Pavilion&amp;pf=laptop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...lion&amp;pf=laptop</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_ca&amp;c=81&amp;bd=Pavilion&amp;pf=laptop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...lion&amp;pf=laptop</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_ca&amp;c=81&amp;bd=Pavilion&amp;pf=laptop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...lion&amp;pf=laptop</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_ca&amp;c=81&amp;bd=Pavilion&amp;pf=laptop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TY...lion&amp;pf=laptop</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)<br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)<br />
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll (file missing)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: HP Print Clips - {FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7} - c:\Program Files\HP\Smart Web Printing\hpswp_framework.dll<br />
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)<br />
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] &quot;C:\Program Files\Logitech\QuickCam\Quickcam.exe&quot; /hide<br />
O4 - HKLM\..\Run: [WinampAgent] &quot;C:\Program Files\Winamp\winampa.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKCU\..\Run: [msnmsgr] &quot;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&quot; /background<br />
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe<br />
O4 - HKCU\..\Run: [Skype] &quot;C:\Program Files\Skype\Phone\Skype.exe&quot; /nosplash /minimized<br />
O4 - HKCU\..\Run: [PlayPop] &quot;C:\ProgramData\chic sixth sixth.7v4t44&quot;<br />
O4 - HKCU\..\Run: [Amok Mode Dupe Platform] &quot;C:\ProgramData\Glue phone ball.lueyns&quot;<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - Startup: Dropbox.lnk = C:\Users\Owner\AppData\Roaming\Dropbox\bin\Dropbox.exe<br />
O4 - Startup: Logitech . Product Registration.lnk = C:\Program Files\Logitech\QuickCam\eReg.exe<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Send image to &amp;Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm<br />
O8 - Extra context menu item: Send page to &amp;Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL<br />
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
O13 - Gopher Prefix: <br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O20 - AppInit_DLLs: avgrsstx.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe<br />
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe<br />
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe<br />
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe<br />
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe<br />
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe<br />
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe<br />
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe<br />
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search &amp; Destroy\SDWinSec.exe<br />
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\Windows\system32\Pen_Tablet.exe<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
<br />
--<br />
End of file - 10777 bytes<br />
<br />
what exactly am i looking for, and how do i remove this frustrating little imp on my computer?<br />
<br />
<br />
<br />
<br />
//// <br />
<br />
LOGS AFTER RUNNING DDS<br />
<br />
<br />
DDS (Ver_09-10-26.01) - NTFSx86  <br />
Run by Owner at 14:34:55.61 on 14/11/2009<br />
Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_15<br />
Microsoft® Windows Vista&#8482; Home Premium   6.0.6002.2.1252.2.1033.18.3070.1121 [GMT -7:00]<br />
<br />
SP: Spybot - Search and Destroy *enabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}<br />
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}<br />
<br />
============== Running Processes ===============<br />
<br />
C:\Windows\system32\wininit.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\nvvsvc.exe<br />
C:\Windows\system32\svchost.exe -k rpcss<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\system32\SLsvc.exe<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Windows\system32\svchost.exe -k bthsvcs<br />
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe<br />
C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe<br />
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\rundll32.exe<br />
C:\Windows\SYSTEM32\WISPTIS.EXE<br />
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe<br />
C:\Program Files\CyberLink\Shared Files\RichVideo.exe<br />
C:\Windows\system32\svchost.exe -k imgsvc<br />
C:\Windows\system32\Pen_Tablet.exe<br />
C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
C:\Windows\System32\svchost.exe -k WerSvcGroup<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Program Files\AVG\AVG9\avgemc.exe<br />
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\SDWinSec.exe<br />
C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\SYSTEM32\WISPTIS.EXE<br />
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\WTablet\Pen_TabletUser.exe<br />
C:\WINDOWS\RtHDVCpl.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\Logitech\QuickCam\Quickcam.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Windows\system32\Pen_Tablet.exe<br />
C:\WINDOWS\System32\rundll32.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\AVG\AVG9\avgtray.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\Program Files\Pando Networks\Media Booster\PMB.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Users\Owner\AppData\Roaming\Dropbox\bin\Dropbox.exe<br />
C:\Program Files\Windows Live\Contacts\wlcomm.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe<br />
C:\Program Files\AIM6\aim6.exe<br />
C:\Program Files\AIM6\aolsoftware.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe<br />
C:\Program Files\Windows Media Player\wmplayer.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Windows\system32\Taskmgr.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Program Files\WinRAR\WinRAR.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\Windows\system32\NOTEPAD.EXE<br />
C:\WINDOWS\System32\notepad.exe<br />
C:\Program Files\Internet Explorer\IEUser.exe<br />
C:\Windows\system32\conime.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Windows\system32\Macromed\Flash\FlashUtil9d.exe<br />
C:\Windows\system32\vssvc.exe<br />
C:\Windows\System32\svchost.exe -k swprv<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Users\Owner\Desktop\dds.scr<br />
<br />
============== Pseudo <acronym title="Hijackthis">HJT</acronym> Report ===============<br />
<br />
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_ca&amp;c=81&amp;bd=Pavilion&amp;pf=laptop<br />
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_ca&amp;c=81&amp;bd=Pavilion&amp;pf=laptop<br />
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_ca&amp;c=81&amp;bd=Pavilion&amp;pf=laptop<br />
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_ca&amp;c=81&amp;bd=Pavilion&amp;pf=laptop<br />
uInternet Settings,ProxyOverride = *.local<br />
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll<br />
uURLSearchHooks: H - No File<br />
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File<br />
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll<br />
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll<br />
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File<br />
BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File<br />
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\progra~1\common~1\symant~1\ids\IPSBHO.dll<br />
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll<br />
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll<br />
BHO: HP Print Clips: {ffffffff-ff12-44c5-91ec-068e3aa1b2d7} - c:\program files\hp\smart web printing\hpswp_framework.dll<br />
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File<br />
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll<br />
uRun: [msnmsgr] &quot;c:\program files\windows live\messenger\msnmsgr.exe&quot; /background<br />
uRun: [Pando Media Booster] c:\program files\pando networks\media booster\PMB.exe<br />
uRun: [Skype] &quot;c:\program files\skype\phone\Skype.exe&quot; /nosplash /minimized<br />
uRun: [PlayPop] &quot;c:\programdata\chic sixth sixth.7v4t44&quot;<br />
uRun: [Amok Mode Dupe Platform] &quot;c:\programdata\Glue phone ball.lueyns&quot;<br />
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search &amp; destroy\TeaTimer.exe<br />
mRun: [RtHDVCpl] RtHDVCpl.exe<br />
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe<br />
mRun: [LogitechQuickCamRibbon] &quot;c:\program files\logitech\quickcam\Quickcam.exe&quot; /hide<br />
mRun: [WinampAgent] &quot;c:\program files\winamp\winampa.exe&quot;<br />
mRun: [SunJavaUpdateSched] &quot;c:\program files\java\jre6\bin\jusched.exe&quot;<br />
mRun: [QuickTime Task] &quot;c:\program files\quicktime\QTTask.exe&quot; -atboottime<br />
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup<br />
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit<br />
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe<br />
mRun: [iTunesHelper] &quot;c:\program files\itunes\iTunesHelper.exe&quot;<br />
mRun: [Adobe Reader Speed Launcher] &quot;c:\program files\adobe\reader 8.0\reader\Reader_sl.exe&quot;<br />
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe<br />
StartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\d  ropbox.lnk - c:\users\owner\appdata\roaming\dropbox\bin\Dropbox.exe<br />
StartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\l  ogite~1.lnk - c:\program files\logitech\quickcam\eReg.exe<br />
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000<br />
IE: Send image to &amp;Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm<br />
IE: Send page to &amp;Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm<br />
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm<br />
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll<br />
IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab<br />
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL<br />
AppInit_DLLs: avgrsstx.dll<br />
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - &quot;c:\program files\common files\lightscribe\LSRunOnce.exe&quot;<br />
<br />
================= FIREFOX ===================<br />
<br />
FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\tzdl0uau.default\<br />
FF - prefs.<acronym title="JavaScript">js</acronym>: browser.search.defaulturl - hxxp://aim.search.aol.com/search/search?query={searchTerms}&amp;invocationType=tb50-ff-aim-chromesbox-en-us<br />
FF - prefs.<acronym title="JavaScript">js</acronym>: browser.search.selectedEngine - Yahoo! Search<br />
FF - prefs.<acronym title="JavaScript">js</acronym>: browser.startup.homepage - hxxp://www.google.ca/<br />
FF - prefs.<acronym title="JavaScript">js</acronym>: keyword.URL - hxxp://ca.yhs.search.yahoo.com/avg/search?fr=yhs-avg&amp;type=yahoo_avg_hs2-tb-web_ca&amp;p=<br />
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll<br />
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils  2.dll<br />
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils  3.dll<br />
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils  35.dll<br />
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\npPandoWebInst.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll<br />
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll<br />
FF - plugin: c:\programdata\nexonus\ngm\npNxGameUS.dll<br />
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}<br />
<br />
---- FIREFOX POLICIES ----<br />
FF - user.<acronym title="JavaScript">js</acronym>: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, falsec:\program files\mozilla firefox\greprefs\security-prefs.<acronym title="JavaScript">js</acronym> - pref(&quot;security.ssl3.rsa_seed_sha&quot;, true);<br />
<br />
============= SERVICES / DRIVERS ===============<br />
<br />
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-4-3 333192]<br />
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-4-3 360584]<br />
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2009-11-13 906520]<br />
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2009-11-13 285392]<br />
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search &amp; destroy\SDWinSec.exe [2009-11-13 1153368]<br />
R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2009-4-5 1373480]<br />
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-4-3 24652]<br />
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\NETw5v32.sys [2008-11-17 3668480]<br />
<br />
=============== Created Last 30 ================<br />
<br />
2009-11-14 20:56:53	0	d-----w-	c:\program files\Trend Micro<br />
2009-11-14 20:47:30	28552	----a-w-	c:\windows\system32\drivers\pavboot.sys<br />
2009-11-14 20:47:06	0	d-----w-	c:\program files\Panda Security<br />
2009-11-14 20:41:57	0	d-----w-	c:\program files\GiPo@Utilities<br />
2009-11-14 20:41:57	0	d-----w-	c:\program files\common files\Gibinsoft Shared<br />
2009-11-14 20:31:19	0	d-----w-	c:\users\owner\.housecall6.6<br />
2009-11-14 04:56:46	0	d-----w-	c:\programdata\Spybot - Search &amp; Destroy<br />
2009-11-14 04:56:46	0	d-----w-	c:\program files\Spybot - Search &amp; Destroy<br />
2009-11-14 03:46:25	0	d--h--w-	C:\$AVG<br />
2009-11-14 03:45:59	0	d-----w-	c:\programdata\AVG Security Toolbar<br />
2009-11-14 03:45:08	0	d-----w-	c:\programdata\avg9<br />
2009-11-14 03:11:02	0	d-----w-	c:\users\owner\appdata\roaming\Malwarebytes<br />
2009-11-14 03:10:52	38224	----a-w-	c:\windows\system32\drivers\mbamswissarmy.sys<br />
2009-11-14 03:10:51	0	d-----w-	c:\programdata\Malwarebytes<br />
2009-11-14 03:10:50	19160	----a-w-	c:\windows\system32\drivers\mbam.sys<br />
2009-11-14 03:10:50	0	d-----w-	c:\program files\Malwarebytes' Anti-Malware<br />
2009-11-14 02:26:09	0	d---a-w-	c:\programdata\TEMP<br />
2009-11-14 01:23:19	0	d-----w-	c:\programdata\Hold Trust Amok Mode<br />
2009-11-14 01:23:02	0	d-----w-	c:\programdata\Skipdeadcast<br />
2009-11-14 01:22:35	0	d-----w-	c:\program files\Circle Developemen<br />
2009-11-13 11:00:17	0	d-----w-	c:\program files\CDisplay<br />
2009-11-12 04:00:21	2036736	----a-w-	c:\windows\system32\win32k.sys<br />
2009-11-12 03:54:05	355328	----a-w-	c:\windows\system32\WSDApi.dll<br />
2009-10-30 00:20:59	0	d-----w-	c:\program files\iPod<br />
2009-10-27 19:07:28	310784	----a-w-	c:\windows\system32\unregmp2.exe<br />
2009-10-27 19:07:25	8147456	----a-w-	c:\windows\system32\wmploc.DLL<br />
2009-10-21 06:57:03	0	d-----w-	c:\windows\system32\eu-ES<br />
2009-10-21 06:57:03	0	d-----w-	c:\windows\system32\ca-ES<br />
2009-10-21 06:57:01	0	d-----w-	c:\windows\system32\vi-VN<br />
2009-10-21 06:41:44	0	d-----w-	c:\windows\system32\EventProviders<br />
2009-10-21 04:11:48	2421760	----a-w-	c:\windows\system32\wucltux.dll<br />
2009-10-21 04:11:26	87552	----a-w-	c:\windows\system32\wudriver.dll<br />
2009-10-21 04:11:18	33792	----a-w-	c:\windows\system32\wuapp.exe<br />
2009-10-21 04:11:18	171608	----a-w-	c:\windows\system32\wuwebv.dll<br />
2009-10-21 03:34:58	1216000	----a-w-	c:\windows\system32\AuxiliaryDisplayCpl.dll<br />
2009-10-21 03:33:59	87040	----a-w-	c:\windows\system32\mssitlb.dll<br />
2009-10-21 03:32:59	1671680	----a-w-	c:\windows\system32\wlanpref.dll<br />
2009-10-21 03:31:51	83968	----a-w-	c:\windows\system32\wbem\wmiutils.dll<br />
2009-10-21 03:31:51	30208	----a-w-	c:\windows\system32\wbem\wbemprox.dll<br />
2009-10-21 03:31:51	265728	----a-w-	c:\windows\system32\wbem\esscli.dll<br />
2009-10-21 03:31:51	189440	----a-w-	c:\windows\system32\wbem\mofd.dll<br />
2009-10-21 03:31:50	744448	----a-w-	c:\windows\system32\wbem\wbemcore.dll<br />
2009-10-21 03:31:50	614912	----a-w-	c:\windows\system32\wbem\fastprox.dll<br />
2009-10-21 03:31:50	265728	----a-w-	c:\windows\system32\wbem\repdrvfs.dll<br />
2009-10-21 03:31:46	705536	----a-w-	c:\windows\system32\SmiEngine.dll<br />
2009-10-21 03:31:39	218624	----a-w-	c:\windows\system32\wdscore.dll<br />
2009-10-21 03:31:39	130560	----a-w-	c:\windows\system32\PkgMgr.exe<br />
2009-10-21 03:31:22	247808	----a-w-	c:\windows\system32\drvstore.dll<br />
2009-10-18 21:26:59	58792	------w-	c:\windows\system32\wbload.dll<br />
2009-10-18 21:26:58	42672	------w-	c:\windows\system32\wbsys.dll<br />
2009-10-18 21:26:57	0	d-----w-	c:\program files\Stardock<br />
2009-10-17 10:23:30	26600	----a-w-	c:\windows\system32\drivers\GEARAspiWDM.sys<br />
2009-10-17 10:23:30	107368	----a-w-	c:\windows\system32\GEARAspi.dll<br />
2009-10-17 10:22:24	0	d-----w-	c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}<br />
2009-10-17 10:22:24	0	d-----w-	c:\program files\iTunes<br />
<br />
==================== Find3M  ====================<br />
<br />
2009-11-14 19:12:27	27839	----a-w-	c:\programdata\nvModes.dat<br />
2009-11-14 03:46:07	360584	----a-w-	c:\windows\system32\drivers\avgtdix.sys<br />
2009-11-14 03:46:07	333192	----a-w-	c:\windows\system32\drivers\avgldx86.sys<br />
2009-11-14 03:46:00	12464	----a-w-	c:\windows\system32\avgrsstx.dll<br />
2009-11-03 03:42:06	195456	------w-	c:\windows\system32\MpSigStub.exe<br />
2009-10-21 07:03:30	86016	----a-w-	c:\windows\inf\infstor.dat<br />
2009-10-21 07:03:30	51200	----a-w-	c:\windows\inf\infpub.dat<br />
2009-10-21 07:03:30	143360	----a-w-	c:\windows\inf\infstrng.dat<br />
2009-10-21 06:56:55	665600	----a-w-	c:\windows\inf\drvindex.dat<br />
2009-10-21 06:50:53	37665	----a-w-	c:\windows\fonts\GlobalUserInterface.CompositeFont<br />
2009-09-22 07:34:01	25280	----a-w-	c:\windows\system32\drivers\hamachi.sys<br />
2009-09-10 16:48:01	218624	----a-w-	c:\windows\system32\msv1_0.dll<br />
2009-09-09 23:32:30	56	---ha-w-	c:\programdata\ezsidmv.dat<br />
2009-09-04 11:41:59	60928	----a-w-	c:\windows\system32\msasn1.dll<br />
2009-08-29 01:42:52	2065696	----a-w-	c:\windows\system32\usbaaplrc.dll<br />
2009-08-29 00:27:49	4240384	----a-w-	c:\windows\system32\GameUXLegacyGDFs.dll<br />
2009-08-29 00:14:38	28672	----a-w-	c:\windows\system32\Apphlpdm.dll<br />
2009-08-27 13:29:25	78336	----a-w-	c:\windows\system32\ieencode.dll<br />
2009-08-27 12:40:58	834048	----a-w-	c:\windows\system32\wininet.dll<br />
2009-08-18 05:33:52	1193832	----a-w-	c:\windows\system32\FM20.DLL<br />
2008-01-21 02:43:21	174	--sha-w-	c:\program files\desktop.ini<br />
2006-11-02 12:42:02	30674	----a-w-	c:\windows\inf\perflib\0409\perfd.dat<br />
2006-11-02 12:42:02	30674	----a-w-	c:\windows\inf\perflib\0409\perfc.dat<br />
2006-11-02 12:42:02	287440	----a-w-	c:\windows\inf\perflib\0409\perfi.dat<br />
2006-11-02 12:42:02	287440	----a-w-	c:\windows\inf\perflib\0409\perfh.dat<br />
2006-11-02 09:20:21	287440	----a-w-	c:\windows\inf\perflib\0000\perfi.dat<br />
2006-11-02 09:20:21	287440	----a-w-	c:\windows\inf\perflib\0000\perfh.dat<br />
2006-11-02 09:20:19	30674	----a-w-	c:\windows\inf\perflib\0000\perfd.dat<br />
2006-11-02 09:20:19	30674	----a-w-	c:\windows\inf\perflib\0000\perfc.dat<br />
<br />
============= FINISH: 14:35:09.56 ===============</div>

]]></content:encoded>
			<category domain="http://www.WindowsBBS.com/malware-virus-removal/">Malware and Virus Removal</category>
			<dc:creator>mostlyyetlikely</dc:creator>
			<guid isPermaLink="true">http://www.WindowsBBS.com/malware-virus-removal/88667-active-iexplore-exe-pop-ups-explorer-problem.html</guid>
		</item>
		<item>
			<title><![CDATA[[Active] iexplore.exe]]></title>
			<link>http://www.WindowsBBS.com/malware-virus-removal/88658-active-iexplore-exe.html</link>
			<pubDate>Sat, 14 Nov 2009 17:53:39 GMT</pubDate>
			<description><![CDATA[I've been looking around for hours now, and can't seem to find any one solution, but my machine has fallen victim to having iexplore open all the time using alot of memory and when a legit internet explorer is opened, two process come up. Here are my logs: 
 
 
DDS (Ver_09-10-26.01) - NTFSx86  ...]]></description>
			<content:encoded><![CDATA[<div>I've been looking around for hours now, and can't seem to find any one solution, but my machine has fallen victim to having iexplore open all the time using alot of memory and when a legit internet explorer is opened, two process come up. Here are my logs:<br />
<br />
<br />
DDS (Ver_09-10-26.01) - NTFSx86  <br />
Run by Chris at 12:46:48.23 on Sat 11/14/2009<br />
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_11<br />
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.1023.492 [GMT -5:00]<br />
<br />
AV: Eset NOD32 antivirus system 2.51 *On-access scanning enabled* (Outdated)   {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}<br />
<br />
============== Running Processes ===============<br />
<br />
C:\WINDOWS\System32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost -k DcomLaunch<br />
svchost.exe<br />
C:\WINDOWS\System32\svchost.exe -k netsvcs<br />
svchost.exe<br />
svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\WebWatcherV5\atisvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\WINDOWS\System32\svchost.exe -k HTTPFilter<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\Documents and Settings\All Users\Application Data\Seekdns\seekdns121.exe<br />
C:\WINDOWS\System32\svchost.exe -k imgsvc<br />
C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
C:\Program Files\WebWatcherV5\atisvc.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\Explorer.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\WINDOWS\CTHELPER.EXE<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE<br />
C:\Program Files\DAEMON Tools\daemon.exe<br />
C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe<br />
C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
C:\Program Files\NETGEAR\WPNT121\WPNT121.exe<br />
C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe<br />
C:\Program Files\Seekdns\seekdns.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\WebWatcherV5\atisvc.exe<br />
svchost.exe<br />
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Documents and Settings\Chris\Desktop\dds.scr<br />
<br />
============== Pseudo <acronym title="Hijackthis">HJT</acronym> Report ===============<br />
<br />
uInternet Settings,ProxyOverride = *.local<br />
uURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll<br />
mURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll<br />
mWinlogon: Shell=Explorer.exe rundll32.exe nhni.goo mgxaig<br />
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll<br />
BHO: GigagetIEHelper Class: {111caa23-6f4f-42ac-8555-b48c1d87bbab} - c:\windows\system32\gigagetbho_v10.dll<br />
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL<br />
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll<br />
BHO: AIM Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - c:\program files\aim toolbar\aimtb.dll<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll<br />
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
TB: AIM Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll<br />
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File<br />
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe<br />
uRun: [Aim6] &quot;c:\program files\aim6\aim6.exe&quot; /d locale=en-US ee://aol/imApp<br />
uRun: [MsnMsgr] &quot;c:\program files\msn messenger\MsnMsgr.Exe&quot; /background<br />
uRun: [H/PC Connection Agent] &quot;c:\program files\microsoft activesync\wcescomm.exe&quot;<br />
uRun: [Steam] &quot;c:\program files\steam\steam.exe&quot; -silent<br />
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe<br />
mRun: [CTHelper] CTHELPER.EXE<br />
mRun: [CTxfiHlp] CTXFIHLP.EXE<br />
mRun: [SunJavaUpdateSched] &quot;c:\program files\java\jre6\bin\jusched.exe&quot;<br />
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE<br />
mRun: [Camera Detector] c:\progra~1\acdsys~1\devdet~1\DEVDET~1.EXE -autorun<br />
mRun: [DAEMON Tools] &quot;c:\program files\daemon tools\daemon.exe&quot; -lang 1033<br />
mRun: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u<br />
mRun: [XboxStat] &quot;c:\program files\microsoft xbox 360 accessories\XboxStat.exe&quot; silentrun<br />
mRun: [Adobe Reader Speed Launcher] &quot;c:\program files\adobe\reader 8.0\reader\Reader_sl.exe&quot;<br />
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE<br />
mRun: [QuickTime Task] &quot;c:\program files\quicktime\QTTask.exe&quot; -atboottime<br />
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe<br />
mRun: [iTunesHelper] &quot;c:\program files\itunes\iTunesHelper.exe&quot;<br />
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto<br />
StartupFolder: c:\docume~1\chris\startm~1\programs\startup\pictur~1.lnk - c:\program files\sony\sony picture utility\pmbcore\SPUVolumeWatcher.exe<br />
StartupFolder: c:\docume~1\chris\startm~1\programs\startup\xfire.lnk - c:\program files\xfire\xfire.exe<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wpnt121\WPNT121.exe<br />
IE: &amp;AIM Toolbar Search - c:\documents and settings\all users\application data\aim toolbar\ietoolbar\resources\en-us\local\search.html<br />
IE: &amp;Download All by Gigaget - c:\program files\giganology\gigaget\getallurl.htm<br />
IE: &amp;Download by Gigaget - c:\program files\giganology\gigaget\geturl.htm<br />
IE: &amp;Search<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000<br />
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe<br />
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe<br />
IE: {0b83c99c-1efa-4259-858f-bcb33e007a5b} - {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL<br />
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab<br />
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab<br />
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/3/9/8/398422c0-8d3e-40e1-a617-af65a72a0465/LegitCheckControl.cab<br />
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1170886903470<br />
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1170887013642<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab<br />
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab<br />
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab<br />
Notify: AtiExtEvent - Ati2evxx.dll<br />
AppInit_DLLs:  dkjlmo.dll    <br />
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll<br />
<br />
================= FIREFOX ===================<br />
<br />
FF - ProfilePath - c:\docume~1\chris\applic~1\mozilla\firefox\profiles\m8mi9s2r.default\<br />
FF - prefs.<acronym title="JavaScript">js</acronym>: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&amp;invocationType=&amp;query=<br />
FF - prefs.<acronym title="JavaScript">js</acronym>: browser.search.selectedEngine - Google<br />
FF - prefs.<acronym title="JavaScript">js</acronym>: browser.startup.homepage - hxxp://www.google.com/<br />
FF - prefs.<acronym title="JavaScript">js</acronym>: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&amp;invocationType=&amp;query=<br />
FF - component: c:\program files\mozilla firefox\components\1357468.dll<br />
FF - component: c:\program files\mozilla firefox\components\GigagetComponent.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\npclntax_HotbarSA.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll<br />
FF - plugin: c:\program files\unity\webplayer\loader\npUnity3D32.dll<br />
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}<br />
<br />
============= SERVICES / DRIVERS ===============<br />
<br />
R2 atisvc;atisvc;c:\program files\webwatcherv5\atisvc.exe [2009-11-13 454263]<br />
R2 Seekdns Service;Seekdns Service;c:\documents and settings\all users\application data\seekdns\seekdns121.exe [2009-11-5 58720]<br />
R2 srenum;srenum;c:\windows\system32\drivers\srenum.sys [2009-11-7 36480]<br />
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-2-15 24652]<br />
R3 Airgo3U;NETGEAR RangeMax(TM) 240 Wireless USB 2.0 Adapter WPNT121;c:\windows\system32\drivers\TMIMO31U.sys [2006-3-6 722432]<br />
R3 ndisrd;WinpkFilter Service;c:\windows\system32\drivers\ndisrd.sys [2009-11-7 20480]<br />
<br />
=============== Created Last 30 ================<br />
<br />
2009-11-14 17:41:56	0	d-----w-	C:\SDFix<br />
2009-11-14 17:36:11	0	d-----w-	C:\<acronym title="Hijackthis">HJT</acronym><br />
2009-11-14 17:20:29	244	---ha-w-	C:\sqmnoopt16.sqm<br />
2009-11-14 17:20:29	232	---ha-w-	C:\sqmdata16.sqm<br />
2009-11-14 17:07:03	0	d-----w-	c:\program files\Trend Micro<br />
2009-11-14 12:14:42	0	d-----w-	c:\docume~1\chris\applic~1\AVG8<br />
2009-11-14 11:48:30	232	---ha-w-	C:\sqmdata15.sqm<br />
2009-11-14 11:48:29	244	---ha-w-	C:\sqmnoopt15.sqm<br />
2009-11-13 15:14:25	244	---ha-w-	C:\sqmnoopt14.sqm<br />
2009-11-13 15:14:25	232	---ha-w-	C:\sqmdata14.sqm<br />
2009-11-13 15:06:57	13696	----a-w-	c:\windows\system32\drivers\wpsnuio.sys<br />
2009-11-13 15:06:57	0	d-----w-	c:\program files\Skyhook Wireless<br />
2009-11-13 15:06:52	44544	----a-w-	c:\windows\system32\msxml4a.dll<br />
2009-11-13 15:06:52	402	----a-w-	c:\windows\system32\msxml4.inf<br />
2009-11-13 15:06:37	0	d-----w-	c:\program files\WebWatcherV5<br />
2009-11-13 11:27:10	244	---ha-w-	C:\sqmnoopt13.sqm<br />
2009-11-13 11:27:10	232	---ha-w-	C:\sqmdata13.sqm<br />
2009-11-12 21:33:18	244	---ha-w-	C:\sqmnoopt12.sqm<br />
2009-11-12 21:33:18	232	---ha-w-	C:\sqmdata12.sqm<br />
2009-11-12 17:12:52	244	---ha-w-	C:\sqmnoopt11.sqm<br />
2009-11-12 17:12:52	232	---ha-w-	C:\sqmdata11.sqm<br />
2009-11-12 03:51:16	0	d-----w-	c:\docume~1\alluse~1\applic~1\Sony Corporation<br />
2009-11-11 09:26:55	0	d-----w-	c:\program files\MixMeister BPM Analyzer<br />
2009-11-10 01:25:50	56228	---ha-w-	c:\windows\system32\mlfcache.dat<br />
2009-11-07 12:57:48	232	---ha-w-	C:\sqmdata10.sqm<br />
2009-11-07 12:57:47	244	---ha-w-	C:\sqmnoopt10.sqm<br />
2009-11-07 12:55:39	36480	----a-w-	c:\windows\system32\drivers\srenum.sys<br />
2009-11-07 12:54:40	20480	----a-w-	c:\windows\system32\drivers\ndisrd.sys<br />
2009-11-07 12:54:28	27648	----a-w-	c:\windows\system32\nhni.goo<br />
2009-11-06 02:14:42	41872	----a-w-	c:\windows\system32\xfcodec.dll<br />
2009-11-06 01:17:41	232	---ha-w-	C:\sqmdata09.sqm<br />
2009-11-06 01:17:40	244	---ha-w-	C:\sqmnoopt09.sqm<br />
2009-11-03 15:43:10	0	d-----w-	c:\program files\iPod<br />
2009-10-30 20:19:33	0	d-----w-	c:\program files\ASIO4ALL v2<br />
2009-10-30 20:19:15	225280	----a-w-	c:\windows\system32\rewire.dll<br />
2009-10-30 20:18:40	1554944	----a-w-	c:\windows\system32\vorbis.acm<br />
2009-10-30 20:18:16	0	d-----w-	c:\program files\VstPlugins<br />
2009-10-30 20:18:10	0	d-----w-	c:\program files\Outsim<br />
2009-10-30 20:14:05	0	d-----w-	c:\program files\Image-Line<br />
2009-10-28 21:37:07	232	---ha-w-	C:\sqmdata08.sqm<br />
2009-10-28 21:37:06	244	---ha-w-	C:\sqmnoopt08.sqm<br />
2009-10-28 04:11:01	244	---ha-w-	C:\sqmnoopt07.sqm<br />
2009-10-28 04:11:01	232	---ha-w-	C:\sqmdata07.sqm<br />
2009-10-26 03:20:48	0	d-----w-	c:\program files\common files\DivX Shared<br />
2009-10-22 20:35:30	244	---ha-w-	C:\sqmnoopt06.sqm<br />
2009-10-22 20:35:30	232	---ha-w-	C:\sqmdata06.sqm<br />
2009-10-22 14:05:03	0	d-----w-	c:\docume~1\chris\applic~1\Hotbar<br />
2009-10-20 18:41:39	244	---ha-w-	C:\sqmnoopt05.sqm<br />
2009-10-20 18:41:39	232	---ha-w-	C:\sqmdata05.sqm<br />
2009-10-19 21:49:31	0	d-----w-	c:\docume~1\alluse~1\applic~1\Seekdns<br />
2009-10-19 21:49:30	0	d-----w-	c:\program files\Seekdns<br />
2009-10-19 21:49:10	0	d-----w-	c:\docume~1\alluse~1\applic~1\HotbarSA<br />
2009-10-17 18:50:47	244	---ha-w-	C:\sqmnoopt04.sqm<br />
2009-10-17 18:50:47	232	---ha-w-	C:\sqmdata04.sqm<br />
2009-10-17 00:47:07	244	---ha-w-	C:\sqmnoopt03.sqm<br />
2009-10-17 00:47:07	232	---ha-w-	C:\sqmdata03.sqm<br />
<br />
==================== Find3M  ====================<br />
<br />
2009-08-28 23:42:52	2065696	----a-w-	c:\windows\system32\usbaaplrc.dll<br />
2009-08-25 22:30:55	196608	----a-w-	C:\{EE7253A7-0D2C-4563-9F48-A64343459199}.dll<br />
2009-08-25 22:30:55	196608	----a-w-	C:\{DB819BC5-6B6A-4ED2-ABC1-C8BED08FFF08}.dll<br />
2009-08-25 22:30:55	196608	----a-w-	C:\{B17AEC53-5C76-4AAA-A069-CFBC3BBD5186}.dll<br />
2009-08-25 22:30:55	196608	----a-w-	C:\{A9DBD395-0E85-4F25-9ABC-52DC55AB1B38}.dll<br />
2009-08-25 22:30:55	196608	----a-w-	C:\{7FF30AB7-EF5A-4CC6-B367-5BF36028929E}.dll<br />
2009-08-25 22:30:55	196608	----a-w-	C:\{044CB556-4BAE-4FCF-B9AC-B1EC155BE9AA}.dll<br />
2009-08-25 22:30:39	192512	----a-w-	C:\{4D7CA135-CF94-49BF-B149-2A2F4516ED5C}.dll<br />
2009-08-25 22:30:35	118784	----a-w-	C:\{1CBD4EC1-4187-4AAC-B8D5-CAFAB0504257}.dll<br />
2009-08-25 22:30:31	86016	----a-w-	C:\{C2F84D37-734F-416E-BA9A-A842A3E46C07}.dll<br />
2009-08-25 22:30:29	77824	----a-w-	C:\{77F6F136-522D-4967-9613-1CD5D961D873}.dll<br />
2009-04-19 02:56:09	2713	--sh--w-	c:\windows\system32\dakekeja.exe<br />
2009-04-04 02:50:09	2713	--sh--w-	c:\windows\system32\foyomiwe.exe<br />
2009-02-24 16:34:05	129024	--sha-w-	c:\windows\system32\fuzayubi.dll<br />
2009-04-05 14:51:53	2713	--sh--w-	c:\windows\system32\gikoluyi.exe<br />
2009-05-18 14:38:00	2713	--sh--w-	c:\windows\system32\hawinigi.exe<br />
2009-05-20 02:39:05	2713	--sh--w-	c:\windows\system32\hohazami.exe<br />
2009-05-19 08:38:34	2713	--sh--w-	c:\windows\system32\kahitepi.exe<br />
2009-05-21 14:40:16	2713	--sh--w-	c:\windows\system32\nuwijoti.exe<br />
2009-05-23 20:42:06	2713	--sh--w-	c:\windows\system32\papesezi.exe<br />
2009-05-13 08:25:29	2713	--sh--w-	c:\windows\system32\rahebono.exe<br />
2009-05-20 20:39:40	2713	--sh--w-	c:\windows\system32\refajako.exe<br />
2009-05-24 14:42:44	2713	--sh--w-	c:\windows\system32\rukigiwi.exe<br />
2009-05-22 08:40:51	2713	--sh--w-	c:\windows\system32\susejewe.exe<br />
2009-05-26 02:43:57	2713	--sh--w-	c:\windows\system32\tomesitu.exe<br />
2009-05-25 08:43:20	2713	--sh--w-	c:\windows\system32\vukikudi.exe<br />
2009-05-23 02:41:28	2713	--sh--w-	c:\windows\system32\wararezu.exe<br />
2009-04-04 20:51:02	2713	--sh--w-	c:\windows\system32\yayihoge.exe<br />
<br />
============= FINISH: 12:47:04.20 ===============<br />
<br />
<br />
<br />
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.<br />
IF REQUESTED, ZIP IT UP &amp; ATTACH IT<br />
<br />
DDS (Ver_09-10-26.01)<br />
<br />
Microsoft Windows XP Professional<br />
Boot Device: \Device\HarddiskVolume1<br />
Install Date: 2/7/2007 10:20:04 AM<br />
System Uptime: 11/14/2009 12:19:11 PM (0 hours ago)<br />
<br />
Motherboard: MICRO-STAR INC. |  | <acronym title="Microsoft">MS</acronym>-6580<br />
Processor:               Intel(R) Pentium(R) 4 <acronym title="Central Processing Unit">CPU</acronym> 2.66GHz | FC-478 | 2672/133mhz<br />
<br />
==== Disk Partitions =========================<br />
<br />
C: is FIXED (NTFS) - 56 GiB total, 6.035 GiB free.<br />
D: is CDROM ()<br />
E: is CDROM ()<br />
F: is FIXED (NTFS) - 233 GiB total, 119.525 GiB free.<br />
H: is CDROM (CDFS)<br />
<br />
==== Disabled Device Manager Items =============<br />
<br />
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}<br />
Description: Wireless-G <acronym title="Peripheral Component Interconnect">PCI</acronym> Adapter<br />
Device ID: <acronym title="Peripheral Component Interconnect">PCI</acronym>\VEN_14E4&amp;DEV_4320&amp;SUBSYS_00131737&amp;REV_02\4&amp;1A671D0C&amp;0&amp;00F0<br />
Manufacturer: Linksys, A Division of Cisco Systems, Inc.<br />
Name: Wireless-G <acronym title="Peripheral Component Interconnect">PCI</acronym> Adapter<br />
PNP Device ID: <acronym title="Peripheral Component Interconnect">PCI</acronym>\VEN_14E4&amp;DEV_4320&amp;SUBSYS_00131737&amp;REV_02\4&amp;1A671D0C&amp;0&amp;00F0<br />
Service: BCM43XX<br />
<br />
==== System Restore Points ===================<br />
<br />
RP960: 8/14/2009 8:42:59 PM - System Checkpoint<br />
RP961: 8/15/2009 9:42:58 PM - System Checkpoint<br />
RP962: 8/16/2009 10:43:00 PM - System Checkpoint<br />
RP963: 8/17/2009 11:42:59 PM - System Checkpoint<br />
RP964: 8/19/2009 12:43:00 AM - System Checkpoint<br />
RP965: 8/26/2009 7:05:25 PM - System Checkpoint<br />
RP966: 9/1/2009 2:27:44 AM - System Checkpoint<br />
RP967: 9/2/2009 3:22:16 AM - System Checkpoint<br />
RP968: 9/3/2009 4:22:16 AM - System Checkpoint<br />
RP969: 9/4/2009 5:22:16 AM - System Checkpoint<br />
RP970: 9/5/2009 6:22:16 AM - System Checkpoint<br />
RP971: 9/6/2009 7:22:16 AM - System Checkpoint<br />
RP972: 9/7/2009 8:22:16 AM - System Checkpoint<br />
RP973: 9/8/2009 9:22:18 AM - System Checkpoint<br />
RP974: 9/9/2009 10:22:17 AM - System Checkpoint<br />
RP975: 9/10/2009 11:22:17 AM - System Checkpoint<br />
RP976: 9/11/2009 12:22:17 PM - System Checkpoint<br />
RP977: 9/12/2009 1:22:16 PM - System Checkpoint<br />
RP978: 9/13/2009 2:22:16 PM - System Checkpoint<br />
RP979: 9/14/2009 3:22:17 PM - System Checkpoint<br />
RP980: 9/15/2009 4:22:16 PM - System Checkpoint<br />
RP981: 9/16/2009 5:22:17 PM - System Checkpoint<br />
RP982: 9/17/2009 6:22:17 PM - System Checkpoint<br />
RP983: 9/18/2009 7:22:17 PM - System Checkpoint<br />
RP984: 9/19/2009 8:22:17 PM - System Checkpoint<br />
RP985: 9/20/2009 9:22:17 PM - System Checkpoint<br />
RP986: 9/21/2009 10:22:17 PM - System Checkpoint<br />
RP987: 9/22/2009 11:22:18 PM - System Checkpoint<br />
RP988: 9/24/2009 12:22:17 AM - System Checkpoint<br />
RP989: 9/25/2009 1:22:16 AM - System Checkpoint<br />
RP990: 9/26/2009 2:22:21 AM - System Checkpoint<br />
RP991: 9/27/2009 3:22:17 AM - System Checkpoint<br />
RP992: 10/1/2009 6:29:26 PM - System Checkpoint<br />
RP993: 10/2/2009 9:21:45 PM - System Checkpoint<br />
RP994: 10/3/2009 10:10:11 PM - System Checkpoint<br />
RP995: 10/6/2009 5:24:00 PM - Installed iTunes<br />
RP996: 10/7/2009 5:31:23 PM - System Checkpoint<br />
RP997: 10/8/2009 6:31:26 PM - System Checkpoint<br />
RP998: 10/9/2009 7:31:27 PM - System Checkpoint<br />
RP999: 10/9/2009 10:38:39 PM - Unsigned driver install<br />
RP1000: 10/13/2009 8:23:31 PM - System Checkpoint<br />
RP1001: 10/17/2009 12:07:35 PM - System Checkpoint<br />
RP1002: 10/20/2009 11:57:47 AM - System Checkpoint<br />
RP1003: 10/22/2009 10:37:58 AM - System Checkpoint<br />
RP1004: 10/28/2009 12:39:42 PM - System Checkpoint<br />
RP1005: 11/11/2009 10:44:38 PM - Removed Sony Picture Utility<br />
RP1006: 11/11/2009 10:45:04 PM - Removed VideoConversion<br />
RP1007: 11/11/2009 10:45:29 PM - Removed Shared<br />
RP1008: 11/11/2009 10:47:02 PM - Removed PMBCore<br />
RP1009: 11/11/2009 10:49:24 PM - Removed VideoUtility<br />
RP1010: 11/11/2009 10:52:14 PM - Installed Sony Picture Utility<br />
RP1011: 11/11/2009 10:52:45 PM - Installed PMBCore<br />
RP1012: 11/11/2009 10:53:56 PM - Installed VideoUtility<br />
RP1013: 11/11/2009 10:55:17 PM - Installed DirectX<br />
<br />
==== Installed Programs ======================<br />
<br />
ACDSee for PENTAX<br />
Adobe Anchor Service CS3<br />
Adobe Asset Services CS3<br />
Adobe Bridge CS3<br />
Adobe Bridge Start Meeting<br />
Adobe Camera Raw 4.0<br />
Adobe CMaps<br />
Adobe Color - Photoshop Specific<br />
Adobe Color Common Settings<br />
Adobe Color EU Extra Settings<br />
Adobe Color JA Extra Settings<br />
Adobe Color NA Recommended Settings<br />
Adobe Default Language CS3<br />
Adobe Device Central CS3<br />
Adobe ExtendScript Toolkit 2<br />
Adobe Flash Player 10 ActiveX<br />
Adobe Flash Player 10 Plugin<br />
Adobe Fonts All<br />
Adobe Help Viewer CS3<br />
Adobe Linguistics CS3<br />
Adobe PDF Library Files<br />
Adobe Photoshop CS3<br />
Adobe Reader 8.1.2<br />
Adobe Setup<br />
Adobe Shockwave Player<br />
Adobe Stock Photos CS3<br />
Adobe Type Support<br />
Adobe Update Manager CS3<br />
Adobe Version Cue CS3 Client<br />
Adobe WinSoft Linguistics Plugin<br />
Adobe XMP Panels CS3<br />
AIM Toolbar<br />
Apple Application Support<br />
Apple Mobile Device Support<br />
Apple Software Update<br />
ASIO4ALL<br />
ATI Display Driver<br />
Audiosurf Beta<br />
AviSynth 2.5<br />
Azureus<br />
Boilsoft Video Joiner 4.92<br />
Bonjour<br />
Compatibility Pack for the 2007 Office system<br />
Creative Audio Console<br />
DivX Web Player<br />
Download Updater (AOL LLC)<br />
DVD Decrypter (Remove Only)<br />
Express Burn<br />
FL Studio 9<br />
Gigaget<br />
GreedyTorrent v1.01 beta build 170<br />
Half-Life<br />
Half-Life 2: Jaykin' Bacon Source<br />
Hardcore<br />
HijackThis 2.0.2<br />
Hotbar<br />
Hotfix for Windows Internet Explorer 7 (KB947864)<br />
Hotfix for Windows Media Format 11 SDK (KB929399)<br />
Hotfix for Windows Media Player 11 (KB939683)<br />
Hotfix for Windows XP (KB896344)<br />
Hotfix for Windows XP (KB909394)<br />
Hotfix for Windows XP (KB914440)<br />
Hotfix for Windows XP (KB915865)<br />
Hotfix for Windows XP (KB926239)<br />
Hotfix for Windows XP (KB928388)<br />
Hotfix for Windows XP (KB929120)<br />
Hotfix for Windows XP (KB952287)<br />
IL Download Manager<br />
Intel(R) PRO Ethernet Adapter and Software<br />
InterActual Player<br />
iTunes<br />
J2SE Runtime Environment 5.0 Update 11<br />
Java(TM) 6 Update 11<br />
Last.fm 1.5.2.38918<br />
Malwarebytes' Anti-Malware<br />
Microsoft .NET Framework 1.1<br />
Microsoft .NET Framework 1.1 Hotfix (KB928366)<br />
Microsoft .NET Framework 2.0 Service Pack 1<br />
Microsoft .NET Framework 3.0<br />
Microsoft Base Smart Card Cryptographic Service Provider Package<br />
Microsoft Compression Client Pack 1.0 for Windows XP<br />
Microsoft Internationalized Domain Names Mitigation APIs<br />
Microsoft Kernel-Mode Driver Framework Feature Pack 1.1<br />
Microsoft National Language Support Downlevel APIs<br />
Microsoft Office Professional Edition 2003<br />
Microsoft User-Mode Driver Framework Feature Pack 1.0<br />
Microsoft Xbox 360 Accessories 1.1<br />
mIRC<br />
MixMeister BPM Analyzer 1.0<br />
MobileMe Control Panel<br />
Mozilla Firefox (3.0.15)<br />
MSXML 4.0 <acronym title="Service Pack 2">SP2</acronym> (KB936181)<br />
MSXML 4.0 <acronym title="Service Pack 2">SP2</acronym> (KB954430)<br />
MSXML 6 Service Pack 2 (KB954459)<br />
NCH Toolbox Uninstall<br />
NETGEAR RangeMax(TM) 240 Wireless USB 2.0 Adapter WPNT121<br />
PDF Settings<br />
PeerGuardian 2.0<br />
PoiZone<br />
Primo<br />
QuickTime<br />
Real Lives 2007<br />
Safari<br />
Sawer<br />
Security Update for Windows Internet Explorer 7 (KB928090)<br />
Security Update for Windows Internet Explorer 7 (KB929969)<br />
Security Update for Windows Internet Explorer 7 (KB931768)<br />
Security Update for Windows Internet Explorer 7 (KB933566)<br />
Security Update for Windows Internet Explorer 7 (KB937143)<br />
Security Update for Windows Internet Explorer 7 (KB938127)<br />
Security Update for Windows Internet Explorer 7 (KB939653)<br />
Security Update for Windows Internet Explorer 7 (KB942615)<br />
Security Update for Windows Internet Explorer 7 (KB944533)<br />
Security Update for Windows Internet Explorer 7 (KB950759)<br />
Security Update for Windows Internet Explorer 7 (KB953838)<br />
Security Update for Windows Internet Explorer 7 (KB956390)<br />
Security Update for Windows Internet Explorer 7 (KB958215)<br />
Security Update for Windows Internet Explorer 7 (KB960714)<br />
Security Update for Windows Internet Explorer 7 (KB961260)<br />
Security Update for Windows Media Player (KB911564)<br />
Security Update for Windows Media Player (KB952069)<br />
Security Update for Windows Media Player 11 (KB936782)<br />
Security Update for Windows Media Player 11 (KB954154)<br />
Security Update for Windows Media Player 6.4 (KB925398)<br />
Security Update for Windows Media Player 8 (KB917734)<br />
Security Update for Windows Media Player 9 (KB917734)<br />
Security Update for Windows XP (KB890046)<br />
Security Update for Windows XP (KB893756)<br />
Security Update for Windows XP (KB896358)<br />
Security Update for Windows XP (KB896423)<br />
Security Update for Windows XP (KB896424)<br />
Security Update for Windows XP (KB896428)<br />
Security Update for Windows XP (KB899587)<br />
Security Update for Windows XP (KB899589)<br />
Security Update for Windows XP (KB899591)<br />
Security Update for Windows XP (KB900725)<br />
Security Update for Windows XP (KB901017)<br />
Security Update for Windows XP (KB901214)<br />
Security Update for Windows XP (KB902400)<br />
Security Update for Windows XP (KB904706)<br />
Security Update for Windows XP (KB905414)<br />
Security Update for Windows XP (KB905749)<br />
Security Update for Windows XP (KB908519)<br />
Security Update for Windows XP (KB911562)<br />
Security Update for Windows XP (KB911927)<br />
Security Update for Windows XP (KB912919)<br />
Security Update for Windows XP (KB913580)<br />
Security Update for Windows XP (KB914388)<br />
Security Update for Windows XP (KB914389)<br />
Security Update for Windows XP (KB917344)<br />
Security Update for Windows XP (KB917422)<br />
Security Update for Windows XP (KB917953)<br />
Security Update for Windows XP (KB918118)<br />
Security Update for Windows XP (KB919007)<br />
Security Update for Windows XP (KB920213)<br />
Security Update for Windows XP (KB920670)<br />
Security Update for Windows XP (KB920683)<br />
Security Update for Windows XP (KB920685)<br />
Security Update for Windows XP (KB921398)<br />
Security Update for Windows XP (KB921503)<br />
Security Update for Windows XP (KB921883)<br />
Security Update for Windows XP (KB922616)<br />
Security Update for Windows XP (KB922819)<br />
Security Update for Windows XP (KB923191)<br />
Security Update for Windows XP (KB923414)<br />
Security Update for Windows XP (KB923689)<br />
Security Update for Windows XP (KB923694)<br />
Security Update for Windows XP (KB923789)<br />
Security Update for Windows XP (KB923980)<br />
Security Update for Windows XP (KB924191)<br />
Security Update for Windows XP (KB924270)<br />
Security Update for Windows XP (KB924496)<br />
Security Update for Windows XP (KB924667)<br />
Security Update for Windows XP (KB925454)<br />
Security Update for Windows XP (KB925902)<br />
Security Update for Windows XP (KB926255)<br />
Security Update for Windows XP (KB926436)<br />
Security Update for Windows XP (KB927779)<br />
Security Update for Windows XP (KB927802)<br />
Security Update for Windows XP (KB928255)<br />
Security Update for Windows XP (KB928843)<br />
Security Update for Windows XP (KB929123)<br />
Security Update for Windows XP (KB930178)<br />
Security Update for Windows XP (KB931261)<br />
Security Update for Windows XP (KB931784)<br />
Security Update for Windows XP (KB932168)<br />
Security Update for Windows XP (KB933729)<br />
Security Update for Windows XP (KB935839)<br />
Security Update for Windows XP (KB935840)<br />
Security Update for Windows XP (KB936021)<br />
Security Update for Windows XP (KB937894)<br />
Security Update for Windows XP (KB938464)<br />
Security Update for Windows XP (KB938829)<br />
Security Update for Windows XP (KB941202)<br />
Security Update for Windows XP (KB941568)<br />
Security Update for Windows XP (KB941569)<br />
Security Update for Windows XP (KB941644)<br />
Security Update for Windows XP (KB941693)<br />
Security Update for Windows XP (KB943055)<br />
Security Update for Windows XP (KB943460)<br />
Security Update for Windows XP (KB943485)<br />
Security Update for Windows XP (KB944653)<br />
Security Update for Windows XP (KB945553)<br />
Security Update for Windows XP (KB946026)<br />
Security Update for Windows XP (KB946648)<br />
Security Update for Windows XP (KB948590)<br />
Security Update for Windows XP (KB948881)<br />
Security Update for Windows XP (KB950749)<br />
Security Update for Windows XP (KB950760)<br />
Security Update for Windows XP (KB950762)<br />
Security Update for Windows XP (KB950974)<br />
Security Update for Windows XP (KB951066)<br />
Security Update for Windows XP (KB951376-v2)<br />
Security Update for Windows XP (KB951376)<br />
Security Update for Windows XP (KB951698)<br />
Security Update for Windows XP (KB951748)<br />
Security Update for Windows XP (KB952954)<br />
Security Update for Windows XP (KB953839)<br />
Security Update for Windows XP (KB954211)<br />
Security Update for Windows XP (KB954600)<br />
Security Update for Windows XP (KB955069)<br />
Security Update for Windows XP (KB956391)<br />
Security Update for Windows XP (KB956802)<br />
Security Update for Windows XP (KB956803)<br />
Security Update for Windows XP (KB956841)<br />
Security Update for Windows XP (KB957095)<br />
Security Update for Windows XP (KB957097)<br />
Security Update for Windows XP (KB958644)<br />
Security Update for Windows XP (KB958687)<br />
Security Update for Windows XP (KB960715)<br />
Seekdns 1.0 build 121<br />
Sid Meier's Civilization 4<br />
SoftV92 Data Fax Modem<br />
Sonic UDF Reader<br />
Sony Picture Utility<br />
Sony USB Driver<br />
Steam<br />
System Requirements Lab<br />
Team Fortress Classic<br />
The Ship<br />
The Ship Tutorial<br />
The Sims™ 2 Double Deluxe<br />
Toxic Biohazard<br />
Unity Web Player<br />
Update for Windows XP (KB898461)<br />
Update for Windows XP (KB900485)<br />
Update for Windows XP (KB904942)<br />
Update for Windows XP (KB908531)<br />
Update for Windows XP (KB910437)<br />
Update for Windows XP (KB911280)<br />
Update for Windows XP (KB916595)<br />
Update for Windows XP (KB920342)<br />
Update for Windows XP (KB920872)<br />
Update for Windows XP (KB922582)<br />
Update for Windows XP (KB925720)<br />
Update for Windows XP (KB925876)<br />
Update for Windows XP (KB927891)<br />
Update for Windows XP (KB929338)<br />
Update for Windows XP (KB930916)<br />
Update for Windows XP (KB931836)<br />
Update for Windows XP (KB932823-v3)<br />
Update for Windows XP (KB933360)<br />
Update for Windows XP (KB936357)<br />
Update for Windows XP (KB938828)<br />
Update for Windows XP (KB942763)<br />
Update for Windows XP (KB951072-v2)<br />
Update for Windows XP (KB955839)<br />
VC80CRTRedist - 8.0.50727.762<br />
VideoLAN VLC media player 0.8.6h<br />
Videora iPod classic Converter 3.07<br />
Viewpoint Media Player<br />
WebFldrs XP<br />
WebWatcher V5 Demo<br />
Windows Communication Foundation<br />
Windows Genuine Advantage Notifications (KB905474)<br />
Windows Genuine Advantage Validation Tool (KB892130)<br />
Windows Imaging Component<br />
Windows Installer 3.1 (KB893803)<br />
Windows Internet Explorer 7<br />
Windows Media Format 11 runtime<br />
Windows Media Format SDK Hotfix - KB891122<br />
Windows Media Player 11<br />
Windows Presentation Foundation<br />
Windows Workflow Foundation<br />
Windows XP Hotfix - KB873339<br />
Windows XP Hotfix - KB885835<br />
Windows XP Hotfix - KB885836<br />
Windows XP Hotfix - KB886185<br />
Windows XP Hotfix - KB887472<br />
Windows XP Hotfix - KB888302<br />
Windows XP Hotfix - KB890859<br />
Windows XP Hotfix - KB891781<br />
Windows XP Service Pack 2<br />
WinRAR archiver<br />
Xfire (remove only)<br />
XML Paper Specification Shared Components Pack 1.0<br />
Xvid 1.1.3 final uninstall<br />
<br />
==== Event Viewer Messages From Past Week ========<br />
<br />
11/7/2009 8:57:29 AM, error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  SCDEmu<br />
11/14/2009 12:13:29 PM, error: DCOM [10005]  - DCOM got error &quot;%1084&quot; attempting to start the service netman with arguments &quot;&quot; in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}<br />
11/14/2009 12:13:20 PM, error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  AFD Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss SCDEmu Tcpip<br />
11/14/2009 12:13:20 PM, error: Service Control Manager [7001]  - The <acronym title="Transmission Control Protocol">TCP</acronym>/<acronym title="Internet Protocol">IP</acronym> NetBIOS Helper service depends on the AFD Networking Support Environment service which failed to start because of the following error:  A device attached to the system is not functioning.<br />
11/14/2009 12:13:20 PM, error: Service Control Manager [7001]  - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error:  A device attached to the system is not functioning.<br />
11/14/2009 12:13:20 PM, error: Service Control Manager [7001]  - The <acronym title="Domain Name System">DNS</acronym> Client service depends on the <acronym title="Transmission Control Protocol">TCP</acronym>/<acronym title="Internet Protocol">IP</acronym> Protocol Driver service which failed to start because of the following error:  A device attached to the system is not functioning.<br />
11/14/2009 12:13:20 PM, error: Service Control Manager [7001]  - The <acronym title="Dynamic Host Configuration Protocol">DHCP</acronym> Client service depends on the NetBios over Tcpip service which failed to start because of the following error:  A device attached to the system is not functioning.<br />
11/14/2009 12:13:20 PM, error: Service Control Manager [7001]  - The Bonjour Service service depends on the <acronym title="Transmission Control Protocol">TCP</acronym>/<acronym title="Internet Protocol">IP</acronym> Protocol Driver service which failed to start because of the following error:  A device attached to the system is not functioning.<br />
11/14/2009 12:13:20 PM, error: Service Control Manager [7001]  - The Apple Mobile Device service depends on the <acronym title="Transmission Control Protocol">TCP</acronym>/<acronym title="Internet Protocol">IP</acronym> Protocol Driver service which failed to start because of the following error:  A device attached to the system is not functioning.<br />
11/14/2009 12:13:18 PM, error: DCOM [10005]  - DCOM got error &quot;%1084&quot; attempting to start the service EventSystem with arguments &quot;&quot; in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}<br />
11/13/2009 10:10:04 AM, error: Service Control Manager [7034]  - The Ati HotKey Poller service terminated unexpectedly.  It has done this 1 time(s).<br />
11/11/2009 10:28:49 PM, error: DCOM [10005]  - DCOM got error &quot;%1058&quot; attempting to start the service wuauserv with arguments &quot;&quot; in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}<br />
11/10/2009 8:02:23 PM, error: MRxSmb [8003]  - The master browser has received a server announcement from the computer JOYGREENWAY-PC that believes that it is the master browser for the domain on transport NetBT_Tcpip_{504FBA7B-5943. The master browser is stopping or an election is being forced.<br />
<br />
==== End Of File ===========================</div>

]]></content:encoded>
			<category domain="http://www.WindowsBBS.com/malware-virus-removal/">Malware and Virus Removal</category>
			<dc:creator>skvermillion13</dc:creator>
			<guid isPermaLink="true">http://www.WindowsBBS.com/malware-virus-removal/88658-active-iexplore-exe.html</guid>
		</item>
		<item>
			<title><![CDATA[[Active] Antiviruses stop searching or can't clean]]></title>
			<link>http://www.WindowsBBS.com/malware-virus-removal/88653-active-antiviruses-stop-searching-cant-clean.html</link>
			<pubDate>Sat, 14 Nov 2009 15:10:28 GMT</pubDate>
			<description><![CDATA[Hi, 
  I have a virus problem with my pc. Avira stopped scanning at "ezdgjg.sys" file. 
  Spyware Cleaner 2009, MalwareBytes and RootkitRevealer couldn't finish the scan, too. 
  F-Secure found "Trojan.Generic.IS" and "Rootkit: W32/TDSS.gen!C", but couldn't delete them. 
 
Help, please. 
Stefan]]></description>
			<content:encoded><![CDATA[<div>Hi,<br />
  I have a virus problem with my pc. Avira stopped scanning at &quot;ezdgjg.sys&quot; file.<br />
  Spyware Cleaner 2009, MalwareBytes and RootkitRevealer couldn't finish the scan, too.<br />
  F-Secure found &quot;Trojan.Generic.IS&quot; and &quot;Rootkit: W32/TDSS.gen!C&quot;, but couldn't delete them.<br />
<br />
Help, please.<br />
Stefan</div>

]]></content:encoded>
			<category domain="http://www.WindowsBBS.com/malware-virus-removal/">Malware and Virus Removal</category>
			<dc:creator>Stefan B</dc:creator>
			<guid isPermaLink="true">http://www.WindowsBBS.com/malware-virus-removal/88653-active-antiviruses-stop-searching-cant-clean.html</guid>
		</item>
		<item>
			<title><![CDATA[[Active] Browser's being hijacked intermittently]]></title>
			<link>http://www.WindowsBBS.com/malware-virus-removal/88648-active-browsers-being-hijacked-intermittently.html</link>
			<pubDate>Sat, 14 Nov 2009 09:40:09 GMT</pubDate>
			<description>Hello there all of you very very nice people,  
 
Today I contracted some relatively nasty scareware I assume from a site I visited that was less than reputable. I got rid of that program (and all of the other Trojans and nasty things that were associated with it) with Malwarebytes, ran CCleaner,...</description>
			<content:encoded><![CDATA[<div>Hello there all of you very very nice people, <br />
<br />
Today I contracted some relatively nasty scareware I assume from a site I visited that was less than reputable. I got rid of that program (and all of the other Trojans and nasty things that were associated with it) with Malwarebytes, ran CCleaner, Spybot S&amp;D and Avast! and they all gave me a clean bill of health. The problem is I'm still getting randomly redirected to <acronym title="Active Directory">ad</acronym> sites. <br />
It'll randomly happen when I click links, open new tabs, or even just enter a new address. <br />
Some of the sites I'm being redirected to are:<br />
httx://xxx.createyourfirstwebsiteforbeginners.com/<br />
httx://xxx.ourstage.com/<br />
httx://xxx.ppcblinks.com/promo/ (a site advertising &quot;American Satellite&quot; and/or Dish Network)<br />
httx://search0.info.com/searchw?qkw=asj&amp;cmp=4063&amp;affiliate=231_1448635102<br />
<br />
and various other useless search engines that I can only assume would invariably redirect me to the other pages in this malware's cache of adscam websites.<br />
<br />
I have done everything that I can with my limited computer repairing abilities and I am at my wits end. I come to you all now and ask for your help. <br />
<br />
<b>Here are my logs as per the instructions:<br />
<br />
<br />
DDS.txt</b><br />
<br />
DDS (Ver_09-10-26.01) - NTFSx86  <br />
Run by Beck at  3:32:06.41 on Sat 11/14/2009<br />
Internet Explorer: 7.0.6001.18000<br />
Microsoft® Windows Vista™ Home Basic   6.0.6001.1.1252.1.1033.18.1790.823 [GMT -6:00]<br />
<br />
SP: Spybot - Search and Destroy *enabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}<br />
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}<br />
<br />
============== Running Processes ===============<br />
<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\nvvsvc.exe<br />
C:\Windows\system32\svchost.exe -k rpcss<br />
C:\Windows\System32\svchost.exe -k secsvcs<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\system32\SLsvc.exe<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
C:\Windows\system32\WLANExt.exe<br />
C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
C:\Program Files\SMINST\BLService.exe<br />
C:\Program Files\CyberLink\Shared files\RichVideo.exe<br />
C:\Windows\system32\svchost.exe -k imgsvc<br />
C:\Windows\System32\svchost.exe -k WerSvcGroup<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Windows\system32\DRIVERS\xaudio.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\SDWinSec.exe<br />
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
C:\Windows\system32\taskeng.exe<br />
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\HP\QuickPlay\QPService.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe<br />
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Alwil Software\Avast4\ashDisp.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe<br />
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe<br />
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Program Files\uTorrent\uTorrent.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\PokerStars.NET\PokerStars.exe<br />
C:\Windows\explorer.exe<br />
C:\Windows\system32\SearchProtocolHost.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Users\Beck\Downloads\dds.scr<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
<br />
============== Pseudo <acronym title="Hijackthis">HJT</acronym> Report ===============<br />
<br />
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=91&amp;bd=Presario&amp;pf=cnnb<br />
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=91&amp;bd=Presario&amp;pf=cnnb<br />
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=91&amp;bd=Presario&amp;pf=cnnb<br />
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=91&amp;bd=Presario&amp;pf=cnnb<br />
BHO: Octh Class: {000123b4-9b42-4900-b3f7-f4b073efc214} - c:\program files\orbitdownloader\orbitcth.dll<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll<br />
BHO: Spybot-S&amp;D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll<br />
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll<br />
BHO: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.0541.0\msneshellx.dll<br />
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll<br />
TB: Microsoft Live Search Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.0541.0\msneshellx.dll<br />
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll<br />
TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll<br />
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File<br />
uRun: [HPAdvisor] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe autorun=AUTORUN<br />
uRun: [DAEMON Tools Lite] &quot;c:\program files\daemon tools lite\daemon.exe&quot; -autorun<br />
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe<br />
uRun: [Vidalia] &quot;c:\program files\vidalia bundle\vidalia\vidalia.exe&quot;<br />
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search &amp; destroy\TeaTimer.exe<br />
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup<br />
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit<br />
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe<br />
mRun: [QPService] &quot;c:\program files\hp\quickplay\QPService.exe&quot;<br />
mRun: [UpdateLBPShortCut] &quot;c:\program files\cyberlink\labelprint\muitransfer\muistartmenu.exe&quot; &quot;c:\program files\cyberlink\labelprint&quot; updatewithcreateonce &quot;software\cyberlink\labelprint\2.5&quot;<br />
mRun: [UpdatePSTShortCut] &quot;c:\program files\cyberlink\dvd suite\muitransfer\muistartmenu.exe&quot; &quot;c:\program files\cyberlink\dvd suite&quot; updatewithcreateonce &quot;software\cyberlink\PowerStarter&quot;<br />
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start<br />
mRun: [UpdateP2GoShortCut] &quot;c:\program files\cyberlink\power2go\muitransfer\muistartmenu.exe&quot; &quot;c:\program files\cyberlink\power2go&quot; updatewithcreateonce &quot;software\cyberlink\power2go\6.0&quot;<br />
mRun: [UpdatePDIRShortCut] &quot;c:\program files\cyberlink\powerdirector\muitransfer\muistartmenu.exe&quot; &quot;c:\program files\cyberlink\powerdirector&quot; updatewithcreateonce &quot;software\cyberlink\powerdirector\7.0&quot;<br />
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe<br />
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe<br />
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe<br />
mRun: [QuickTime Task] &quot;c:\program files\quicktime\QTTask.exe&quot; -atboottime<br />
mRun: [iTunesHelper] &quot;c:\program files\itunes\iTunesHelper.exe&quot;<br />
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe<br />
mRun: [Malwarebytes Anti-Malware (reboot)] &quot;c:\program files\malwarebytes' anti-malware\mbam.exe&quot; /runcleanupscript<br />
mPolicies-system: EnableLUA = 0 (0x0)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
IE: &amp;Download by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/201<br />
IE: &amp;Grab video by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/204<br />
IE: Do&amp;wnload selected by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/203<br />
IE: Down&amp;load all by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/202<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000<br />
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\progra~1\java\jre16~1.0_0\bin\ssv.dll<br />
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL<br />
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab<br />
<br />
================= FIREFOX ===================<br />
<br />
FF - ProfilePath - c:\users\beck\appdata\roaming\mozilla\firefox\profiles\trwj9tew.default\<br />
FF - component: c:\program files\orbitdownloader\addons\oneclickyoutubedownloader\components\GrabXpcom  .dll<br />
FF - component: c:\users\beck\appdata\roaming\mozilla\firefox\profiles\trwj9tew.default\ext  ensions\dttoolbar@toolbarnet.com\components\DTToolbarFF.dll<br />
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\<br />
<br />
---- FIREFOX POLICIES ----<br />
c:\program files\mozilla firefox\greprefs\security-prefs.<acronym title="JavaScript">js</acronym> - pref(&quot;security.ssl3.rsa_seed_sha&quot;, true);<br />
<br />
============= SERVICES / DRIVERS ===============<br />
<br />
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-11-11 114768]<br />
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-11-11 20560]<br />
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2009-11-11 53328]<br />
R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2008-10-22 193840]<br />
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-5-9 43040]<br />
<br />
=============== Created Last 30 ================<br />
<br />
2009-11-14 09:02:18	0	d-----w-	c:\program files\Trend Micro<br />
2009-11-14 08:53:17	0	d-----w-	c:\program files\CCleaner<br />
2009-11-14 07:37:13	0	d-----w-	c:\program files\PokerStars.NET<br />
2009-11-14 00:22:10	0	d-----w-	c:\users\beck\appdata\roaming\Malwarebytes<br />
2009-11-14 00:22:06	38224	----a-w-	c:\windows\system32\drivers\mbamswissarmy.sys<br />
2009-11-14 00:22:04	19160	----a-w-	c:\windows\system32\drivers\mbam.sys<br />
2009-11-14 00:22:04	0	d-----w-	c:\programdata\Malwarebytes<br />
2009-11-14 00:22:04	0	d-----w-	c:\program files\Malwarebytes' Anti-Malware<br />
2009-11-12 09:40:29	0	d-----w-	c:\program files\JDownloader<br />
2009-11-12 08:13:29	195456	------w-	c:\windows\system32\MpSigStub.exe<br />
2009-11-12 04:16:06	0	d-----w-	c:\programdata\Spybot - Search &amp; Destroy<br />
2009-11-12 04:16:06	0	d-----w-	c:\program files\Spybot - Search &amp; Destroy<br />
2009-11-12 04:04:28	53328	----a-w-	c:\windows\system32\drivers\aswMonFlt.sys<br />
2009-11-12 03:29:13	2035712	----a-w-	c:\windows\system32\win32k.sys<br />
2009-11-12 03:28:51	351232	----a-w-	c:\windows\system32\WSDApi.dll<br />
2009-11-04 11:08:51	1383424	----a-w-	c:\windows\system32\mshtml.tlb<br />
2009-10-30 18:21:05	0	d-----w-	C:\FUSION<br />
2009-10-30 12:26:47	0	d-----w-	c:\programdata\Digsby<br />
2009-10-30 12:21:08	0	d-----w-	c:\users\beck\appdata\roaming\Digsby<br />
2009-10-30 12:03:44	0	d-----w-	c:\program files\Digsby<br />
2009-10-27 20:09:09	310784	----a-w-	c:\windows\system32\unregmp2.exe<br />
2009-10-27 20:09:04	8147456	----a-w-	c:\windows\system32\wmploc.DLL<br />
2009-10-25 23:42:25	822	----a-w-	c:\users\beck\appdata\roaming\wklnhst.dat<br />
2009-10-24 09:00:01	0	d-----w-	c:\users\beck\.jnlp-applet<br />
2009-10-23 06:57:35	0	d-----w-	c:\program files\Firaxis Games<br />
2009-10-23 06:30:10	0	d-----w-	c:\users\beck\appdata\roaming\GrabPro<br />
2009-10-23 06:30:10	0	d-----w-	C:\downloads<br />
2009-10-23 06:29:42	0	d-----w-	c:\program files\Orbitdownloader<br />
2009-10-22 05:55:08	33021	----a-w-	c:\windows\scunin.dat<br />
2009-10-22 05:54:57	967	----a-w-	c:\windows\ScUnin.pif<br />
2009-10-22 05:54:57	94208	----a-w-	c:\windows\ScUnin.exe<br />
2009-10-22 05:54:47	0	d-----w-	c:\program files\Starcraft<br />
2009-10-20 06:08:57	69464	----a-w-	c:\windows\system32\XAPOFX1_3.dll<br />
2009-10-20 06:07:07	0	d--h--w-	c:\windows\msdownld.tmp<br />
2009-10-20 06:07:01	0	d-----w-	c:\windows\system32\directx<br />
2009-10-17 11:23:58	267272	----a-w-	c:\windows\system32\xactengine2_10.dll<br />
2009-10-17 11:22:05	2297552	----a-w-	c:\windows\system32\d3dx9_26.dll<br />
2009-10-17 11:19:21	1420824	----a-w-	c:\windows\system32\D3DCompiler_37.dll<br />
2009-10-17 11:19:20	462864	----a-w-	c:\windows\system32\d3dx10_37.dll<br />
2009-10-17 11:19:19	3786760	----a-w-	c:\windows\system32\D3DX9_37.dll<br />
2009-10-17 11:19:18	81768	----a-w-	c:\windows\system32\xinput1_3.dll<br />
2009-10-17 11:18:22	0	d-----w-	c:\windows\system32\xlive<br />
2009-10-17 11:18:21	0	d-----w-	c:\program files\Microsoft Games for Windows - LIVE<br />
2009-10-17 10:50:51	0	d-----w-	c:\programdata\DAEMON Tools Lite<br />
2009-10-17 10:50:07	0	d-----w-	c:\program files\DAEMON Tools Toolbar<br />
2009-10-17 10:49:38	0	d-----w-	c:\program files\DAEMON Tools Lite<br />
2009-10-17 10:42:22	721904	----a-w-	c:\windows\system32\drivers\sptd.sys<br />
2009-10-17 10:41:54	0	d-----w-	c:\users\beck\appdata\roaming\DAEMON Tools Lite<br />
2009-10-17 03:47:05	107888	----a-w-	c:\windows\system32\CmdLineExt.dll<br />
2009-10-16 09:10:50	3599960	----a-w-	c:\windows\system32\ntkrnlpa.exe<br />
2009-10-16 09:10:48	3547736	----a-w-	c:\windows\system32\ntoskrnl.exe<br />
2009-10-16 08:54:59	213504	----a-w-	c:\windows\system32\msv1_0.dll<br />
2009-10-16 08:33:18	61440	----a-w-	c:\windows\system32\msasn1.dll<br />
2009-10-16 08:33:10	144896	----a-w-	c:\windows\system32\drivers\srv2.sys<br />
2009-10-16 08:33:02	604672	----a-w-	c:\windows\system32\WMSPDMOD.DLL<br />
<br />
==================== Find3M  ====================<br />
<br />
2009-11-14 00:42:15	27744	----a-w-	c:\programdata\nvModes.dat<br />
2009-11-12 03:41:08	86016	----a-w-	c:\windows\inf\infstrng.dat<br />
2009-11-12 03:41:08	86016	----a-w-	c:\windows\inf\infstor.dat<br />
2009-11-12 03:41:08	51200	----a-w-	c:\windows\inf\infpub.dat<br />
2009-09-29 07:43:18	353840	----a-w-	c:\windows\system32\msvcr71.dll<br />
2009-09-29 07:43:17	505392	----a-w-	c:\windows\system32\msvcp71.dll<br />
2009-09-29 07:43:17	1066544	----a-w-	c:\windows\system32\MFC71.dll<br />
2009-09-29 07:43:17	1053232	----a-w-	c:\windows\system32\MFC71u.dll<br />
2009-09-29 07:37:03	0	---ha-w-	c:\windows\system32\drivers\Msft_Kernel_SynTP_01000.Wdf<br />
2009-09-29 07:31:15	0	---ha-w-	c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf<br />
2009-09-29 05:56:20	0	--sha-r-	c:\windows\system32\drivers\103C_HP_cNB_Presario CQ60 Notebook PC_Y5335KV_0U_Q2CE9139BY0_E508164-001_4A_I303C_SWistron_V08.49_F.35_T090217_WV2-1_L409_M1790_J160_7AMD_8F31_92.00_#090929_N168C001C;10DE0760_(ZY226UA#ABA)_  XMOBILE_CN10_Z_2F.35.MRK<br />
2009-09-04 22:44:40	515416	----a-w-	c:\windows\system32\XAudio2_5.dll<br />
2009-09-04 22:44:40	238936	----a-w-	c:\windows\system32\xactengine3_5.dll<br />
2009-09-04 22:29:34	453456	----a-w-	c:\windows\system32\d3dx10_42.dll<br />
2009-09-04 22:29:34	235344	----a-w-	c:\windows\system32\d3dx11_42.dll<br />
2009-09-04 22:29:32	5501792	----a-w-	c:\windows\system32\d3dcsx_42.dll<br />
2009-09-04 22:29:32	1974616	----a-w-	c:\windows\system32\D3DCompiler_42.dll<br />
2009-09-04 22:29:30	1892184	----a-w-	c:\windows\system32\D3DX9_42.dll<br />
2009-08-29 00:42:52	2065696	----a-w-	c:\windows\system32\usbaaplrc.dll<br />
2009-08-28 12:39:07	28672	----a-w-	c:\windows\system32\Apphlpdm.dll<br />
2009-08-28 10:15:30	4240384	----a-w-	c:\windows\system32\GameUXLegacyGDFs.dll<br />
2009-08-27 13:32:41	833024	----a-w-	c:\windows\system32\wininet.dll<br />
2009-08-27 13:29:25	78336	----a-w-	c:\windows\system32\ieencode.dll<br />
2009-08-27 10:58:58	26624	----a-w-	c:\windows\system32\ieUnatt.exe<br />
2008-10-23 06:05:00	665600	----a-w-	c:\windows\inf\drvindex.dat<br />
2008-01-21 02:57:01	174	--sha-w-	c:\program files\desktop.ini<br />
2006-11-02 12:39:34	30674	----a-w-	c:\windows\inf\perflib\0409\perfd.dat<br />
2006-11-02 12:39:34	30674	----a-w-	c:\windows\inf\perflib\0409\perfc.dat<br />
2006-11-02 12:39:34	287440	----a-w-	c:\windows\inf\perflib\0409\perfi.dat<br />
2006-11-02 12:39:34	287440	----a-w-	c:\windows\inf\perflib\0409\perfh.dat<br />
2006-11-02 09:20:21	287440	----a-w-	c:\windows\inf\perflib\0000\perfi.dat<br />
2006-11-02 09:20:21	287440	----a-w-	c:\windows\inf\perflib\0000\perfh.dat<br />
2006-11-02 09:20:19	30674	----a-w-	c:\windows\inf\perflib\0000\perfd.dat<br />
2006-11-02 09:20:19	30674	----a-w-	c:\windows\inf\perflib\0000\perfc.dat<br />
2008-10-23 06:05:00	8192	--sha-w-	c:\windows\users\default\NTUSER.DAT<br />
<br />
============= FINISH:  3:35:05.43 ===============<br />
<br />
<br />
<br />
<b>And the Attach.txt</b><br />
Microsoft® Windows Vista™ Home Basic <br />
Boot Device: \Device\HarddiskVolume1<br />
Install Date: 9/29/2009 2:28:56 AM<br />
System Uptime: 11/13/2009 6:36:03 PM (9 hours ago)<br />
<br />
Motherboard: Wistron |  | 303C<br />
Processor: <acronym title="Advanced Micro Devices">AMD</acronym> Athlon Dual-Core QL-62 | Socket A | 1000/133mhz<br />
<br />
==== Disk Partitions =========================<br />
<br />
C: is FIXED (NTFS) - 139 GiB total, 12.985 GiB free.<br />
D: is FIXED (NTFS) - 10 GiB total, 1.726 GiB free.<br />
E: is CDROM ()<br />
F: is CDROM ()<br />
<br />
==== Disabled Device Manager Items =============<br />
<br />
==== System Restore Points ===================<br />
<br />
<br />
==== Installed Programs ======================<br />
<br />
µTorrent<br />
Acrobat.com<br />
Activation Assistant for the 2007 Microsoft Office suites<br />
ActiveCheck component for HP Active Support Library<br />
Adobe AIR<br />
Adobe Flash Player 10 Plugin<br />
Adobe Flash Player ActiveX<br />
Adobe Reader 9<br />
Adobe Shockwave Player<br />
Age of Empires III<br />
Apple Application Support<br />
Apple Mobile Device Support<br />
Apple Software Update<br />
Ask Toolbar<br />
Atheros Driver Installation Program<br />
avast! Antivirus<br />
Bonjour<br />
CCleaner<br />
Cisco EAP-FAST Module<br />
Cisco LEAP Module<br />
Cisco PEAP Module<br />
Compatibility Pack for the 2007 Office system<br />
Conexant <acronym title="Hard Disk">HD</acronym> Audio<br />
CyberLink DVD Suite<br />
DAEMON Tools Toolbar<br />
Digsby<br />
ESU for Microsoft Vista<br />
HDAUDIO Soft Data Fax Modem with SmartCP<br />
Hotfix for Microsoft .NET Framework 3.5 <acronym title="Service Pack 1">SP1</acronym> (KB953595)<br />
Hotfix for Microsoft .NET Framework 3.5 <acronym title="Service Pack 1">SP1</acronym> (KB958484)<br />
HP Active Support Library<br />
HP Customer Experience Enhancements<br />
HP Doc Viewer<br />
HP DVD Play 3.7<br />
HP Help and Support<br />
HP Quick Launch Buttons 6.40 H2<br />
HP Total Care Advisor<br />
HP Update<br />
HP User Guides 0118<br />
HP Wireless Assistant<br />
HPAsset component for HP Active Support Library<br />
HPNetworkAssistant<br />
HPTCSSetup<br />
iTunes<br />
Java(TM) 6 Update 7<br />
JDownloader<br />
JEOPARDY! Deluxe (remove only)<br />
Juno Preloader<br />
LabelPrint<br />
Magic Video Converter Trial Version (English) 8.0.2.18<br />
Malwarebytes' Anti-Malware<br />
Microsoft .NET Framework 3.5 <acronym title="Service Pack 1">SP1</acronym><br />
Microsoft Games for Windows - LIVE <br />
Microsoft Games for Windows - LIVE Redistributable<br />
Microsoft Live Search Toolbar<br />
Microsoft Office Excel MUI (English) 2007<br />
Microsoft Office Home and Student 2007<br />
Microsoft Office OneNote MUI (English) 2007<br />
Microsoft Office PowerPoint MUI (English) 2007<br />
Microsoft Office PowerPoint Viewer 2007 (English)<br />
Microsoft Office Proof (English) 2007<br />
Microsoft Office Proof (French) 2007<br />
Microsoft Office Proof (Spanish) 2007<br />
Microsoft Office Proofing (English) 2007<br />
Microsoft Office Shared MUI (English) 2007<br />
Microsoft Office Shared Setup Metadata MUI (English) 2007<br />
Microsoft Office Word MUI (English) 2007<br />
Microsoft Silverlight<br />
Microsoft Visual C++ 2005 Redistributable<br />
Microsoft Works<br />
Mozilla Firefox (3.5.5)<br />
MSXML 4.0 <acronym title="Service Pack 2">SP2</acronym> (KB954430)<br />
muvee Reveal<br />
My HP Games<br />
NetWaiting<br />
NetZero Preloader<br />
NVIDIA Drivers<br />
Opera 10.00<br />
Orbit Downloader<br />
PokerStars.net<br />
Power2Go<br />
PowerDirector<br />
Project64 1.6<br />
QuickTime<br />
Realtek USB 2.0 Card Reader<br />
Sid Meier's Civilization 4<br />
Sid Meier's Civilization 4 - Beyond the Sword<br />
Sid Meier's Civilization 4 - Warlords<br />
SPORE Creature Creator Trial Edition<br />
Spybot - Search &amp; Destroy<br />
Starcraft<br />
Synaptics Pointing Device Driver<br />
Update for Microsoft .NET Framework 3.5 <acronym title="Service Pack 1">SP1</acronym> (KB963707)<br />
Update for Office 2007 (KB934528)<br />
VLC media player 1.0.2<br />
WinRAR archiver<br />
<br />
==== End Of File ===========================</div>

]]></content:encoded>
			<category domain="http://www.WindowsBBS.com/malware-virus-removal/">Malware and Virus Removal</category>
			<dc:creator>UpRise</dc:creator>
			<guid isPermaLink="true">http://www.WindowsBBS.com/malware-virus-removal/88648-active-browsers-being-hijacked-intermittently.html</guid>
		</item>
		<item>
			<title><![CDATA[[Active] Malware affecting WAN Miniport]]></title>
			<link>http://www.WindowsBBS.com/malware-virus-removal/88629-active-malware-affecting-wan-miniport.html</link>
			<pubDate>Fri, 13 Nov 2009 15:57:19 GMT</pubDate>
			<description>Hi, 
 
I have a problem my Network connection is gone when y check the device manager all my adapter are with yellow exclamations 
 
Realtek RTL8139/810X Family Fas Ethernet NIC 
Realtek RTL8139/810X Family Fas Ethernet NIC - Minipuerto del administrador de paquetes 
Realtek RTL8139/810X Family Fas...</description>
			<content:encoded><![CDATA[<div>Hi,<br />
<br />
I have a problem my Network connection is gone when y check the device manager all my adapter are with yellow exclamations<br />
<br />
Realtek RTL8139/810X Family Fas Ethernet <acronym title="Network Interface Card">NIC</acronym><br />
Realtek RTL8139/810X Family Fas Ethernet <acronym title="Network Interface Card">NIC</acronym> - Minipuerto del administrador de paquetes<br />
Realtek RTL8139/810X Family Fas Ethernet <acronym title="Network Interface Card">NIC</acronym> - Teefer2 Miniport<br />
Minipuerto <acronym title="Wide area network">WAN</acronym> (<acronym title="Internet Protocol">IP</acronym>)<br />
Minipuerto <acronym title="Wide area network">WAN</acronym> (<acronym title="Internet Protocol">IP</acronym>) - Miniport del administrador de paquetes<br />
Minipuerto <acronym title="Wide area network">WAN</acronym> (L2TP)<br />
Minipuerto <acronym title="Wide area network">WAN</acronym> (PPPOE)<br />
Minipuerto <acronym title="Wide area network">WAN</acronym> (PPTP)<br />
Paralelo directo<br />
<br />
My anti virus detect cutwail.h Trojan and was removed<br />
<br />
I have installed Symantec Endpoint Protection SEP, superantispyware, malware bytes, ROOTrepeal <br />
<br />
any help fixing the network will be greatly appreciated  <br />
<br />
<br />
here are the logs<br />
<br />
<b>superantispyware</b> <br />
<br />
detect nothing<br />
<br />
<b>Malware bytes</b><br />
Malwarebytes' Anti-Malware 1.41<br />
Versión de la Base de Datos: 2775<br />
Windows 5.1.2600 Service Pack 3<br />
<br />
12/11/2009 13:15:54<br />
mbam-log-2009-11-12 (13-15-54).txt<br />
<br />
Tipo de examen : Examen Rápido<br />
Objetos examinados: 126415<br />
Tiempo transcurrido: 13 minute(s), 54 second(s)<br />
<br />
Procesos en Memoria Infectados: 0<br />
Módulos en Memoria Infectados: 0<br />
Claves del Registro Infectadas: 0<br />
Valores del Registro Infectados: 1<br />
Elementos de Datos del Registro Infectados: 1<br />
Carpetas Infectadas: 0<br />
Ficheros Infectados: 0<br />
<br />
Procesos en Memoria Infectados:<br />
(No se han detectado elementos maliciosos)<br />
<br />
Módulos en Memoria Infectados:<br />
(No se han detectado elementos maliciosos)<br />
<br />
Claves del Registro Infectadas:<br />
(No se han detectado elementos maliciosos)<br />
<br />
Valores del Registro Infectados:<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explor  er\ForceClassicControlPanel (Hijack.ControlPanelStyle) -&gt; Quarantined and deleted successfully.<br />
<br />
Elementos de Datos del Registro Infectados:<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explor  er\NoSMHelp (Hijack.Help) -&gt; Bad: (1) Good: (0) -&gt; Quarantined and deleted successfully.<br />
<br />
Carpetas Infectadas:<br />
(No se han detectado elementos maliciosos)<br />
<br />
Ficheros Infectados:<br />
(No se han detectado elementos maliciosos)<br />
<br />
<br />
<b>root repeal</b><br />
<br />
ROOTREPEAL (c) <acronym title="Active Directory">AD</acronym>, 2007-2009<br />
==================================================<br />
Scan Start Time:		2009/01/13 11:16<br />
Program Version:		Version 1.3.5.0<br />
Windows Version:		Windows XP <acronym title="Service Pack 3">SP3</acronym><br />
==================================================<br />
<br />
Drivers<br />
-------------------<br />
Name: PCI_NTPNP1068<br />
Image Path: \Driver\PCI_NTPNP1068<br />
Address: 0x00000000	Size: 0	File Visible: No	Signed: -<br />
Status: -<br />
<br />
Name: rootrepeal.sys<br />
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys<br />
Address: 0xA8B49000	Size: 49152	File Visible: No	Signed: -<br />
Status: -<br />
<br />
SSDT<br />
-------------------<br />
#: 012	Function Name: NtAlertResumeThread<br />
Status: Hooked by &quot;&lt;unknown&gt;&quot; at address 0x8ae38e90<br />
<br />
#: 013	Function Name: NtAlertThread<br />
Status: Hooked by &quot;&lt;unknown&gt;&quot; at address 0x8ae5c748<br />
<br />
#: 017	Function Name: NtAllocateVirtualMemory<br />
Status: Hooked by &quot;&lt;unknown&gt;&quot; at address 0x8ae2d5d8<br />
<br />
#: 041	Function Name: NtCreateKey<br />
Status: Hooked by &quot;sptd.sys&quot; at address 0xba6be0d0<br />
<br />
#: 043	Function Name: NtCreateMutant<br />
Status: Hooked by &quot;&lt;unknown&gt;&quot; at address 0x8af03930<br />
<br />
#: 053	Function Name: NtCreateThread<br />
Status: Hooked by &quot;&lt;unknown&gt;&quot; at address 0x8a9651d0<br />
<br />
#: 071	Function Name: NtEnumerateKey<br />
Status: Hooked by &quot;sptd.sys&quot; at address 0xba6c3fb2<br />
<br />
#: 073	Function Name: NtEnumerateValueKey<br />
Status: Hooked by &quot;sptd.sys&quot; at address 0xba6c4340<br />
<br />
#: 083	Function Name: NtFreeVirtualMemory<br />
Status: Hooked by &quot;&lt;unknown&gt;&quot; at address 0x8ad54da0<br />
<br />
#: 089	Function Name: NtImpersonateAnonymousToken<br />
Status: Hooked by &quot;&lt;unknown&gt;&quot; at address 0x8ad2ba48<br />
<br />
#: 091	Function Name: NtImpersonateThread<br />
Status: Hooked by &quot;&lt;unknown&gt;&quot; at address 0x8addb8d0<br />
<br />
#: 108	Function Name: NtMapViewOfSection<br />
Status: Hooked by &quot;&lt;unknown&gt;&quot; at address 0x8ad43108<br />
<br />
#: 114	Function Name: NtOpenEvent<br />
Status: Hooked by &quot;&lt;unknown&gt;&quot; at address 0x8adb75f0<br />
<br />
#: 119	Function Name: NtOpenKey<br />
Status: Hooked by &quot;sptd.sys&quot; at address 0xba6be0b0<br />
<br />
#: 123	Function Name: NtOpenProcessToken<br />
Status: Hooked by &quot;&lt;unknown&gt;&quot; at address 0x8af04b18<br />
<br />
#: 129	Function Name: NtOpenThreadToken<br />
Status: Hooked by &quot;&lt;unknown&gt;&quot; at address 0x8ad435b8<br />
<br />
#: 160	Function Name: NtQueryKey<br />
Status: Hooked by &quot;sptd.sys&quot; at address 0xba6c4418<br />
<br />
#: 177	Function Name: NtQueryValueKey<br />
Status: Hooked by &quot;sptd.sys&quot; at address 0xba6c4298<br />
<br />
#: 206	Function Name: NtResumeThread<br />
Status: Hooked by &quot;&lt;unknown&gt;&quot; at address 0x8ae632d8<br />
<br />
#: 213	Function Name: NtSetContextThread<br />
Status: Hooked by &quot;&lt;unknown&gt;&quot; at address 0x8ade5d78<br />
<br />
#: 228	Function Name: NtSetInformationProcess<br />
Status: Hooked by &quot;&lt;unknown&gt;&quot; at address 0x8af47330<br />
<br />
#: 229	Function Name: NtSetInformationThread<br />
Status: Hooked by &quot;&lt;unknown&gt;&quot; at address 0x8ad1f058<br />
<br />
#: 247	Function Name: NtSetValueKey<br />
Status: Hooked by &quot;sptd.sys&quot; at address 0xba6c44aa<br />
<br />
#: 253	Function Name: NtSuspendProcess<br />
Status: Hooked by &quot;&lt;unknown&gt;&quot; at address 0x8aecc0d0<br />
<br />
#: 254	Function Name: NtSuspendThread<br />
Status: Hooked by &quot;&lt;unknown&gt;&quot; at address 0x8ae588e0<br />
<br />
#: 257	Function Name: NtTerminateProcess<br />
Status: Hooked by &quot;C:\Archivos de programa\SUPERAntiSpyware\SASKUTIL.sys&quot; at address 0xa94aa0b0<br />
<br />
#: 258	Function Name: NtTerminateThread<br />
Status: Hooked by &quot;&lt;unknown&gt;&quot; at address 0x8ae38650<br />
<br />
#: 267	Function Name: NtUnmapViewOfSection<br />
Status: Hooked by &quot;&lt;unknown&gt;&quot; at address 0x8af05c98<br />
<br />
#: 277	Function Name: NtWriteVirtualMemory<br />
Status: Hooked by &quot;&lt;unknown&gt;&quot; at address 0x8aaaf9f0<br />
<br />
Stealth Objects<br />
-------------------<br />
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]<br />
Process: System	Address: 0x8aff81e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]<br />
Process: System	Address: 0x8aff81e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]<br />
Process: System	Address: 0x8aff81e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]<br />
Process: System	Address: 0x8aff81e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]<br />
Process: System	Address: 0x8aff81e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]<br />
Process: System	Address: 0x8aff81e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]<br />
Process: System	Address: 0x8aff81e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]<br />
Process: System	Address: 0x8aff81e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]<br />
Process: System	Address: 0x8aff81e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]<br />
Process: System	Address: 0x8aff81e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]<br />
Process: System	Address: 0x8aff81e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]<br />
Process: System	Address: 0x8aff81e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]<br />
Process: System	Address: 0x8aff81e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]<br />
Process: System	Address: 0x8aff81e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]<br />
Process: System	Address: 0x8aff81e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]<br />
Process: System	Address: 0x8aff81e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]<br />
Process: System	Address: 0x8aff81e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]<br />
Process: System	Address: 0x8aff81e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]<br />
Process: System	Address: 0x8aff81e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]<br />
Process: System	Address: 0x8aff81e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]<br />
Process: System	Address: 0x8aff81e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]<br />
Process: System	Address: 0x8aff81e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CREATE]<br />
Process: System	Address: 0x8a8661e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLOSE]<br />
Process: System	Address: 0x8a8661e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Fastfat, IRP_MJ_READ]<br />
Process: System	Address: 0x8a8661e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Fastfat, IRP_MJ_WRITE]<br />
Process: System	Address: 0x8a8661e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_INFORMATION]<br />
Process: System	Address: 0x8a8661e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_INFORMATION]<br />
Process: System	Address: 0x8a8661e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_EA]<br />
Process: System	Address: 0x8a8661e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_EA]<br />
Process: System	Address: 0x8a8661e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Fastfat, IRP_MJ_FLUSH_BUFFERS]<br />
Process: System	Address: 0x8a8661e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_VOLUME_INFORMATION]<br />
Process: System	Address: 0x8a8661e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_VOLUME_INFORMATION]<br />
Process: System	Address: 0x8a8661e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Fastfat, IRP_MJ_DIRECTORY_CONTROL]<br />
Process: System	Address: 0x8a8661e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Fastfat, IRP_MJ_FILE_SYSTEM_CONTROL]<br />
Process: System	Address: 0x8a8661e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Fastfat, IRP_MJ_DEVICE_CONTROL]<br />
Process: System	Address: 0x8a8661e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SHUTDOWN]<br />
Process: System	Address: 0x8a8661e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Fastfat, IRP_MJ_LOCK_CONTROL]<br />
Process: System	Address: 0x8a8661e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLEANUP]<br />
Process: System	Address: 0x8a8661e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Fastfat, IRP_MJ_PNP]<br />
Process: System	Address: 0x8a8661e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: CDRom, IRP_MJ_CREATE]<br />
Process: System	Address: 0x8adae1e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: CDRom, IRP_MJ_CLOSE]<br />
Process: System	Address: 0x8adae1e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: CDRom, IRP_MJ_READ]<br />
Process: System	Address: 0x8adae1e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: CDRom, IRP_MJ_WRITE]<br />
Process: System	Address: 0x8adae1e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: CDRom, IRP_MJ_FLUSH_BUFFERS]<br />
Process: System	Address: 0x8adae1e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: CDRom, IRP_MJ_DEVICE_CONTROL]<br />
Process: System	Address: 0x8adae1e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: CDRom, IRP_MJ_INTERNAL_DEVICE_CONTROL]<br />
Process: System	Address: 0x8adae1e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: CDRom, IRP_MJ_SHUTDOWN]<br />
Process: System	Address: 0x8adae1e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: CDRom, IRP_MJ_POWER]<br />
Process: System	Address: 0x8adae1e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: CDRom, IRP_MJ_SYSTEM_CONTROL]<br />
Process: System	Address: 0x8adae1e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: CDRom, IRP_MJ_PNP]<br />
Process: System	Address: 0x8adae1e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: usbstor, IRP_MJ_CREATE]<br />
Process: System	Address: 0x8a9fd790	Size: 121<br />
<br />
Object: Hidden Code [Driver: usbstor, IRP_MJ_CLOSE]<br />
Process: System	Address: 0x8a9fd790	Size: 121<br />
<br />
Object: Hidden Code [Driver: usbstor, IRP_MJ_READ]<br />
Process: System	Address: 0x8a9fd790	Size: 121<br />
<br />
Object: Hidden Code [Driver: usbstor, IRP_MJ_WRITE]<br />
Process: System	Address: 0x8a9fd790	Size: 121<br />
<br />
Object: Hidden Code [Driver: usbstor, IRP_MJ_DEVICE_CONTROL]<br />
Process: System	Address: 0x8a9fd790	Size: 121<br />
<br />
Object: Hidden Code [Driver: usbstor, IRP_MJ_INTERNAL_DEVICE_CONTROL]<br />
Process: System	Address: 0x8a9fd790	Size: 121<br />
<br />
Object: Hidden Code [Driver: usbstor, IRP_MJ_POWER]<br />
Process: System	Address: 0x8a9fd790	Size: 121<br />
<br />
Object: Hidden Code [Driver: usbstor, IRP_MJ_SYSTEM_CONTROL]<br />
Process: System	Address: 0x8a9fd790	Size: 121<br />
<br />
Object: Hidden Code [Driver: usbstor, IRP_MJ_PNP]<br />
Process: System	Address: 0x8a9fd790	Size: 121<br />
<br />
Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE]<br />
Process: System	Address: 0x8af871e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE]<br />
Process: System	Address: 0x8af871e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: dmio, IRP_MJ_READ]<br />
Process: System	Address: 0x8af871e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE]<br />
Process: System	Address: 0x8af871e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS]<br />
Process: System	Address: 0x8af871e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL]<br />
Process: System	Address: 0x8af871e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL]<br />
Process: System	Address: 0x8af871e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN]<br />
Process: System	Address: 0x8af871e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: dmio, IRP_MJ_POWER]<br />
Process: System	Address: 0x8af871e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL]<br />
Process: System	Address: 0x8af871e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: dmio, IRP_MJ_PNP]<br />
Process: System	Address: 0x8af871e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CREATE]<br />
Process: System	Address: 0x8ae28338	Size: 121<br />
<br />
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CLOSE]<br />
Process: System	Address: 0x8ae28338	Size: 121<br />
<br />
Object: Hidden Code [Driver: usbuhci, IRP_MJ_DEVICE_CONTROL]<br />
Process: System	Address: 0x8ae28338	Size: 121<br />
<br />
Object: Hidden Code [Driver: usbuhci, IRP_MJ_INTERNAL_DEVICE_CONTROL]<br />
Process: System	Address: 0x8ae28338	Size: 121<br />
<br />
Object: Hidden Code [Driver: usbuhci, IRP_MJ_POWER]<br />
Process: System	Address: 0x8ae28338	Size: 121<br />
<br />
Object: Hidden Code [Driver: usbuhci, IRP_MJ_SYSTEM_CONTROL]<br />
Process: System	Address: 0x8ae28338	Size: 121<br />
<br />
Object: Hidden Code [Driver: usbuhci, IRP_MJ_PNP]<br />
Process: System	Address: 0x8ae28338	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]<br />
Process: System	Address: 0x8affa1e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]<br />
Process: System	Address: 0x8affa1e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]<br />
Process: System	Address: 0x8affa1e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]<br />
Process: System	Address: 0x8affa1e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]<br />
Process: System	Address: 0x8affa1e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]<br />
Process: System	Address: 0x8affa1e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]<br />
Process: System	Address: 0x8affa1e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]<br />
Process: System	Address: 0x8affa1e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]<br />
Process: System	Address: 0x8affa1e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]<br />
Process: System	Address: 0x8affa1e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]<br />
Process: System	Address: 0x8affa1e8	Size: 121<br />
<br />
Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]<br />
Process: System	Address: 0x8ae22790	Size: 121<br />
<br />
Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]<br />
Process: System	Address: 0x8ae22790	Size: 121<br />
<br />
Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]<br />
Process: System	Address: 0x8ae22790	Size: 121<br />
<br />
Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]<br />
Process: System	Address: 0x8ae22790	Size: 121<br />
<br />
Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]<br />
Process: System	Address: 0x8ae22790	Size: 121<br />
<br />
Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]<br />
Process: System	Address: 0x8ae22790	Size: 121<br />
<br />
Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]<br />
Process: System	Address: 0x8ae22790	Size: 121<br />
<br />
Object: Hidden Code [Driver: MA, IRP_MJ_CREATE]<br />
Process: System	Address: 0x8a833790	Size: 121<br />
<br />
Object: Hidden Code [Driver: MA, IRP_MJ_CLOSE]<br />
Process: System	Address: 0x8a833790	Size: 121<br />
<br />
Object: Hidden Code [Driver: MA, IRP_MJ_READ]<br />
Process: System	Address: 0x8a833790	Size: 121<br />
<br />
Object: Hidden Code [Driver: MA, IRP_MJ_QUERY_INFORMATION]<br />
Process: System	Address: 0x8a833790	Size: 121<br />
<br />
Object: Hidden Code [Driver: MA, IRP_MJ_SET_INFORMATION]<br />
Process: System	Address: 0x8a833790	Size: 121<br />
<br />
Object: Hidden Code [Driver: MA, IRP_MJ_QUERY_VOLUME_INFORMATION]<br />
Process: System	Address: 0x8a833790	Size: 121<br />
<br />
Object: Hidden Code [Driver: MA, IRP_MJ_DIRECTORY_CONTROL]<br />
Process: System	Address: 0x8a833790	Size: 121<br />
<br />
Object: Hidden Code [Driver: MA, IRP_MJ_FILE_SYSTEM_CONTROL]<br />
Process: System	Address: 0x8a833790	Size: 121<br />
<br />
Object: Hidden Code [Driver: MA, IRP_MJ_DEVICE_CONTROL]<br />
Process: System	Address: 0x8a833790	Size: 121<br />
<br />
Object: Hidden Code [Driver: MA, IRP_MJ_SHUTDOWN]<br />
Process: System	Address: 0x8a833790	Size: 121<br />
<br />
Object: Hidden Code [Driver: MA, IRP_MJ_LOCK_CONTROL]<br />
Process: System	Address: 0x8a833790	Size: 121<br />
<br />
Object: Hidden Code [Driver: MA, IRP_MJ_CLEANUP]<br />
Process: System	Address: 0x8a833790	Size: 121<br />
<br />
Object: Hidden Code [Driver: MA, IRP_MJ_PNP]<br />
Process: System	Address: 0x8a833790	Size: 121<br />
<br />
Shadow SSDT<br />
-------------------<br />
#: 383	Function Name: NtUserGetAsyncKeyState<br />
Status: Hooked by &quot;&lt;unknown&gt;&quot; at address 0x8a23fa10<br />
<br />
==EOF==</div>

]]></content:encoded>
			<category domain="http://www.WindowsBBS.com/malware-virus-removal/">Malware and Virus Removal</category>
			<dc:creator>carlosvj</dc:creator>
			<guid isPermaLink="true">http://www.WindowsBBS.com/malware-virus-removal/88629-active-malware-affecting-wan-miniport.html</guid>
		</item>
		<item>
			<title><![CDATA[[Active] Start up Errors, Can not run any malware or antivirus programs.]]></title>
			<link>http://www.WindowsBBS.com/malware-virus-removal/88625-active-start-up-errors-can-not-run-any-malware-antivirus-programs.html</link>
			<pubDate>Fri, 13 Nov 2009 13:43:35 GMT</pubDate>
			<description>Hey guys,  
 
after noticing new processes such as b.exe and deleteing them i cannot run any programs that will scan my drives. My anti virus will not start neither will any online scans, spybot will not install and malwarebytes terminates just before it tries to scan.  
 
ive tried to run DDS a...</description>
			<content:encoded><![CDATA[<div>Hey guys, <br />
<br />
after noticing new processes such as b.exe and deleteing them i cannot run any programs that will scan my drives. My anti virus will not start neither will any online scans, spybot will not install and malwarebytes terminates just before it tries to scan. <br />
<br />
ive tried to run DDS a few times, it either does nothing for 10 minutes, or just comes up with application error.<br />
<br />
Any Suggestions?</div>

]]></content:encoded>
			<category domain="http://www.WindowsBBS.com/malware-virus-removal/">Malware and Virus Removal</category>
			<dc:creator>kiranp</dc:creator>
			<guid isPermaLink="true">http://www.WindowsBBS.com/malware-virus-removal/88625-active-start-up-errors-can-not-run-any-malware-antivirus-programs.html</guid>
		</item>
		<item>
			<title><![CDATA[[Active] renos.ji malware, system severely limited]]></title>
			<link>http://www.WindowsBBS.com/malware-virus-removal/88615-active-renos-ji-malware-system-severely-limited.html</link>
			<pubDate>Fri, 13 Nov 2009 05:25:48 GMT</pubDate>
			<description><![CDATA[I believe I downloaded a trojan a few days ago.  My browser started acted weird - I'd try to go to one site and it would redirect me to another.  Then Windows Defender popped up saying it had found a trojan win/32/renos.ji.  But when I cllicked on remove, I got a message that Defender could not...]]></description>
			<content:encoded><![CDATA[<div>I believe I downloaded a trojan a few days ago.  My browser started acted weird - I'd try to go to one site and it would redirect me to another.  Then Windows Defender popped up saying it had found a trojan win/32/renos.ji.  But when I cllicked on remove, I got a message that Defender could not remove it and then it shut down and wouldn't start again.  The browser began to work only intermittently.  The next day I was able to download Microsoft Safety scanner but after sitting for awhile trying to initialize the scan, it just shut down.  Then while I was trying to update windows, I got a message from my McAfee virus software that an attempt was being made to alter one of the files in documents and settings\...\temp/b.exe.  I blocked it several times but the windows update was stuck on 0% so I let the change take place.  Now, a few days later, Intern Explorer does not work at all so I can't try to download anything to help, the system says I don't have any printers installed so I am unable to print, it doesn't recognize USB devices when I plug them in so I am unable to copy my files off the system, virus software is totally disabled, when I boot up to the desktop I get several program error messages, and I have no system tray or start menu on the desktop so the only way I know how to shut down the system is to hit the power button.  I tried system restore but it wont work even in safe mode.  Virus scanning won't work even in safe mode.<br />
<br />
At this point I'd be happy to be able to copy all my data off the machine and just buy a new computer.  Is there anything that can be done to fix this or am I *******?</div>

]]></content:encoded>
			<category domain="http://www.WindowsBBS.com/malware-virus-removal/">Malware and Virus Removal</category>
			<dc:creator>L99</dc:creator>
			<guid isPermaLink="true">http://www.WindowsBBS.com/malware-virus-removal/88615-active-renos-ji-malware-system-severely-limited.html</guid>
		</item>
	</channel>
</rss>
