<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title><![CDATA[Byte Forums - All Forums]]></title>
		<link>http://byteforums.com/</link>
		<description><![CDATA[Byte Forums - http://byteforums.com]]></description>
		<pubDate>Fri, 12 Mar 2010 07:09:12 +0000</pubDate>
		<generator>MyBB</generator>
		<item>
			<title><![CDATA[Personal security, storageguardsoft, gomyhit]]></title>
			<link>http://byteforums.com/thread-3144.html</link>
			<pubDate>Sat, 06 Mar 2010 18:50:35 +0000</pubDate>
			<guid isPermaLink="false">http://byteforums.com/thread-3144.html</guid>
			<description><![CDATA[I have a Sony Vaio PCG-V505EX running Windows XP Home SP3.  I was having major issues!  I had the Personal Security pop ups going all over.  I ran MBAM, SAS, ESET, and AVG.  Each found it's share of the bugs and removed them.  I ran all of the scans several times, until they all came back with no entries.<br />
<br />
The funny thing that I noticed, though, is that the wireless connection seems to drop.  If I open IE8, I cannot get to a webpage, even though it says I have a very good connection to my wireless router.  I get the "cannot find" message and a "diagnose".  I have a 2nd laptop that is connecting and working fine.  Then, when I open Firefox, I can connect.  After Firefox connects, then IE8 will connect, as well.  The behavior was so strange, that I decided to run HJT.  I am very unsure of anything in this report (that's why I'm here!), but I noticed entries for "gomyhit.com" and "storageguardsoft", and "Apoint.exe".  A couple of google searches, and I decided to post here.<br />
<br />
Log follows, any help is really appreciated!<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 12:46:58 PM, on 3/6/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\System32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\CenturyTel\Home Network Manager\AffinegyService.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\WinPcap\rpcapd.exe<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Apoint\Apoint.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\WINDOWS\system32\ezSP_Px.exe<br />
C:\Program Files\Canon\CAL\CALMAIN.exe<br />
C:\Program Files\QuickTime\qttask.exe<br />
C:\Program Files\Common Files\Java\Java Update\jusched.exe<br />
C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Apoint\Apntex.exe<br />
C:\Program Files\Messenger\msmsgs.exe<br />
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe<br />
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe<br />
C:\Program Files\PowerPanel\Program\PcfMgr.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Java\jre6\bin\java.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.centurytel.net/" target="_blank">http://www.centurytel.net/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by CenturyTel<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O4 - HKLM\..\Run: [Apoint&#93; C:\Program Files\Apoint\Apoint.exe<br />
O4 - HKLM\..\Run: [VAIO Recovery&#93; C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe<br />
O4 - HKLM\..\Run: [iTunesHelper&#93; "C:\Program Files\iTunes\iTunesHelper.exe"<br />
O4 - HKLM\..\Run: [ezShieldProtector for Px&#93; C:\WINDOWS\system32\ezSP_Px.exe<br />
O4 - HKLM\..\Run: [InstaLAN&#93; "C:\Program Files\CenturyTel\Home Network Manager\HomeNetworkManager.exe" startup<br />
O4 - HKLM\..\Run: [QuickTime Task&#93; "C:\Program Files\QuickTime\qttask.exe" -atboottime<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched&#93; "C:\Program Files\Common Files\Java\Java Update\jusched.exe"<br />
O4 - HKLM\..\Run: [AVG9_TRAY&#93; C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher&#93; "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"<br />
O4 - HKLM\..\Run: [Adobe ARM&#93; "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"<br />
O4 - HKCU\..\Run: [ctfmon.exe&#93; C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [MSMSGS&#93; "C:\Program Files\Messenger\msmsgs.exe" /background<br />
O4 - Global Startup: Ad-Aware.lnk = C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe<br />
O4 - Global Startup: hp psc 1000 series.lnk = ?<br />
O4 - Global Startup: hpoddt01.exe.lnk = ?<br />
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br />
O4 - Global Startup: PowerPanel.lnk = ?<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople<br />
O15 - Trusted Zone: *.gomyhit.com<br />
O15 - Trusted Zone: *.imageservr.com<br />
O15 - Trusted Zone: *.imagesrvr.com<br />
O15 - Trusted Zone: *.storageguardsoft.com<br />
O15 - Trusted Zone: *.gomyhit.com (HKLM)<br />
O15 - Trusted Zone: *.imageservr.com (HKLM)<br />
O15 - Trusted Zone: *.imagesrvr.com (HKLM)<br />
O15 - Trusted Zone: *.storageguardsoft.com (HKLM)<br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a href="http://go.microsoft.com/fwlink/?linkid=39204" target="_blank">http://go.microsoft.com/fwlink/?linkid=39204</a><br />
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - <a href="http://lads.myspace.com/upload/MySpaceUploader1006.cab" target="_blank">http://lads.myspace.com/upload/MySpaceUploader1006.cab</a><br />
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - <a href="http://www.eset.eu/buxus/docs/OnlineScanner.cab" target="_blank">http://www.eset.eu/buxus/docs/OnlineScanner.cab</a><br />
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - <a href="http://upload.facebook.com/controls/FacebookPhotoUploader3.cab" target="_blank">http://upload.facebook.com/controls/Face...oader3.cab</a><br />
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - <a href="http://upload.facebook.com/controls/FacebookPhotoUploader.cab" target="_blank">http://upload.facebook.com/controls/Face...loader.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1267856175694" target="_blank">http://www.update.microsoft.com/microsof...7856175694</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: AffinegyService - Affinegy, Inc. - C:\Program Files\CenturyTel\Home Network Manager\AffinegyService.exe<br />
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe<br />
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe<br />
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe<br />
O23 - Service: VAIO Media Music Server (VAIOMediaPlatform-MusicServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Music\SSSvr.exe<br />
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe<br />
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe<br />
O23 - Service: VAIO Media Photo Server (VAIOMediaPlatform-PhotoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Photo\appsrv\PhotoAppSrv.exe<br />
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe<br />
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe<br />
O23 - Service: VAIO Media Video Server (VAIOMediaPlatform-VideoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Video\GPVSvr.exe<br />
O23 - Service: VAIO Media Video Server (HTTP) (VAIOMediaPlatform-VideoServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe<br />
O23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe<br />
<br />
--<br />
End of file - 9400 bytes]]></description>
			<content:encoded><![CDATA[I have a Sony Vaio PCG-V505EX running Windows XP Home SP3.  I was having major issues!  I had the Personal Security pop ups going all over.  I ran MBAM, SAS, ESET, and AVG.  Each found it's share of the bugs and removed them.  I ran all of the scans several times, until they all came back with no entries.<br />
<br />
The funny thing that I noticed, though, is that the wireless connection seems to drop.  If I open IE8, I cannot get to a webpage, even though it says I have a very good connection to my wireless router.  I get the "cannot find" message and a "diagnose".  I have a 2nd laptop that is connecting and working fine.  Then, when I open Firefox, I can connect.  After Firefox connects, then IE8 will connect, as well.  The behavior was so strange, that I decided to run HJT.  I am very unsure of anything in this report (that's why I'm here!), but I noticed entries for "gomyhit.com" and "storageguardsoft", and "Apoint.exe".  A couple of google searches, and I decided to post here.<br />
<br />
Log follows, any help is really appreciated!<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 12:46:58 PM, on 3/6/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\System32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\CenturyTel\Home Network Manager\AffinegyService.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\WinPcap\rpcapd.exe<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Apoint\Apoint.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\WINDOWS\system32\ezSP_Px.exe<br />
C:\Program Files\Canon\CAL\CALMAIN.exe<br />
C:\Program Files\QuickTime\qttask.exe<br />
C:\Program Files\Common Files\Java\Java Update\jusched.exe<br />
C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Apoint\Apntex.exe<br />
C:\Program Files\Messenger\msmsgs.exe<br />
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe<br />
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe<br />
C:\Program Files\PowerPanel\Program\PcfMgr.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Java\jre6\bin\java.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.centurytel.net/" target="_blank">http://www.centurytel.net/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by CenturyTel<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe<br />
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe<br />
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br />
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe<br />
O4 - HKLM\..\Run: [InstaLAN] "C:\Program Files\CenturyTel\Home Network Manager\HomeNetworkManager.exe" startup<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"<br />
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br />
O4 - Global Startup: Ad-Aware.lnk = C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe<br />
O4 - Global Startup: hp psc 1000 series.lnk = ?<br />
O4 - Global Startup: hpoddt01.exe.lnk = ?<br />
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br />
O4 - Global Startup: PowerPanel.lnk = ?<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople<br />
O15 - Trusted Zone: *.gomyhit.com<br />
O15 - Trusted Zone: *.imageservr.com<br />
O15 - Trusted Zone: *.imagesrvr.com<br />
O15 - Trusted Zone: *.storageguardsoft.com<br />
O15 - Trusted Zone: *.gomyhit.com (HKLM)<br />
O15 - Trusted Zone: *.imageservr.com (HKLM)<br />
O15 - Trusted Zone: *.imagesrvr.com (HKLM)<br />
O15 - Trusted Zone: *.storageguardsoft.com (HKLM)<br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a href="http://go.microsoft.com/fwlink/?linkid=39204" target="_blank">http://go.microsoft.com/fwlink/?linkid=39204</a><br />
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - <a href="http://lads.myspace.com/upload/MySpaceUploader1006.cab" target="_blank">http://lads.myspace.com/upload/MySpaceUploader1006.cab</a><br />
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - <a href="http://www.eset.eu/buxus/docs/OnlineScanner.cab" target="_blank">http://www.eset.eu/buxus/docs/OnlineScanner.cab</a><br />
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - <a href="http://upload.facebook.com/controls/FacebookPhotoUploader3.cab" target="_blank">http://upload.facebook.com/controls/Face...oader3.cab</a><br />
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - <a href="http://upload.facebook.com/controls/FacebookPhotoUploader.cab" target="_blank">http://upload.facebook.com/controls/Face...loader.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1267856175694" target="_blank">http://www.update.microsoft.com/microsof...7856175694</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: AffinegyService - Affinegy, Inc. - C:\Program Files\CenturyTel\Home Network Manager\AffinegyService.exe<br />
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe<br />
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe<br />
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe<br />
O23 - Service: VAIO Media Music Server (VAIOMediaPlatform-MusicServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Music\SSSvr.exe<br />
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe<br />
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe<br />
O23 - Service: VAIO Media Photo Server (VAIOMediaPlatform-PhotoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Photo\appsrv\PhotoAppSrv.exe<br />
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe<br />
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe<br />
O23 - Service: VAIO Media Video Server (VAIOMediaPlatform-VideoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Video\GPVSvr.exe<br />
O23 - Service: VAIO Media Video Server (HTTP) (VAIOMediaPlatform-VideoServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe<br />
O23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe<br />
<br />
--<br />
End of file - 9400 bytes]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Lockerz Invites!]]></title>
			<link>http://byteforums.com/thread-3143.html</link>
			<pubDate>Sat, 27 Feb 2010 11:42:30 +0000</pubDate>
			<guid isPermaLink="false">http://byteforums.com/thread-3143.html</guid>
			<description><![CDATA[Hey guys I'm Sam.<br />
<br />
I know alot of you people may of heard of it already, but i know there is alot of people who haven't, so i thought id tell you all about it.<br />
<br />
Lockerz is a website where you basically invite people to the website and you get 2 points for people you get to register on the website, and you can fill in surveys and stuff like that every day which also gets you points.<br />
<br />
Once you have got so many points you can redeem the points as prizes, anything from Modern Warfare 2 to an Apple iMac. <br />
<br />
You may say oh its a scam blah blah, look on youtube at all the people who have got things from Lockerz, and I have also got things from Lockerz (Modern Warfare 2 for the Xbox 360, an iPod Nano and left for dead 2.)<br />
<br />
This site is invitation only, so if you want an invite, email me spamup94@gmail.com and ill add you, its a great site, I hope you enjoy getting things as much as I have (that was worded bad i know)<br />
<br />
Sam <img src="http://byteforums.com/images/smilies/biggrin.gif" style="vertical-align: middle;" border="0" alt="Big Grin" title="Big Grin" />]]></description>
			<content:encoded><![CDATA[Hey guys I'm Sam.<br />
<br />
I know alot of you people may of heard of it already, but i know there is alot of people who haven't, so i thought id tell you all about it.<br />
<br />
Lockerz is a website where you basically invite people to the website and you get 2 points for people you get to register on the website, and you can fill in surveys and stuff like that every day which also gets you points.<br />
<br />
Once you have got so many points you can redeem the points as prizes, anything from Modern Warfare 2 to an Apple iMac. <br />
<br />
You may say oh its a scam blah blah, look on youtube at all the people who have got things from Lockerz, and I have also got things from Lockerz (Modern Warfare 2 for the Xbox 360, an iPod Nano and left for dead 2.)<br />
<br />
This site is invitation only, so if you want an invite, email me spamup94@gmail.com and ill add you, its a great site, I hope you enjoy getting things as much as I have (that was worded bad i know)<br />
<br />
Sam <img src="http://byteforums.com/images/smilies/biggrin.gif" style="vertical-align: middle;" border="0" alt="Big Grin" title="Big Grin" />]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Browser randomly opens]]></title>
			<link>http://byteforums.com/thread-3142.html</link>
			<pubDate>Sun, 21 Feb 2010 05:38:28 +0000</pubDate>
			<guid isPermaLink="false">http://byteforums.com/thread-3142.html</guid>
			<description><![CDATA[Hope this makes sense to somebody. Initially Firefox would not run (re-installed) and Explorer seem to redirect every link. The mouse cursor had serious "screen drift" in random directions and system performance was almost at a standstill.<br />
<br />
Have run MS Defender, spybot S&amp;D, ATF cleaner, Anti-Malware, and F-secure repeatedly. Symptoms have gradually improved but I have the following problems.<br />
<br />
 My Firefox browser keeps spontaneously opening up new windows in the foreground. They seem to be triggered by mouse clicks in the browser - not necessarily on links. The windows mostly open to the Firefox directory listing but some open up to web sites and are mostly caught by K9 as Trojan download sites. Performance also lags sporadically.<br />
<br />
I would greatly appreciate any help diagnosing and correcting the problem.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 8:15:51 PM, on 2/20/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Windows Defender\MsMpEng.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
C:\Program Files\Blue Coat K9 Web Protection\k9filter.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\Common Files\Java\Java Update\jusched.exe<br />
C:\Program Files\QuickTime\qttask.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = <a href="http://go.microsoft.com/fwlink/?LinkId=74005" target="_blank">http://go.microsoft.com/fwlink/?LinkId=74005</a><br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O4 - HKLM\..\Run: [avast!&#93; C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
O4 - HKLM\..\Run: [AIRPLUS&#93; "C:\Program Files\D-Link\AIRPLUS.exe" -nogui<br />
O4 - HKLM\..\Run: [Windows Defender&#93; "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched&#93; "C:\Program Files\Common Files\Java\Java Update\jusched.exe"<br />
O4 - HKLM\..\Run: [QuickTime Task&#93; "C:\Program Files\QuickTime\qttask.exe" -atboottime<br />
O4 - HKCU\..\Run: [ctfmon.exe&#93; C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting&#93; "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting&#93; "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a href="http://go.microsoft.com/fwlink/?linkid=39204" target="_blank">http://go.microsoft.com/fwlink/?linkid=39204</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1094865255653" target="_blank">http://v5.windowsupdate.microsoft.com/v5...4865255653</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/get/sh...wflash.cab</a><br />
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - <a href="http://www.popcap.com/webgames/popcaploader_v10.cab" target="_blank">http://www.popcap.com/webgames/popcaploader_v10.cab</a><br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
O23 - Service: Blue Coat K9 Web Protection (bckwfs) - Blue Coat Systems, Inc. - C:\Program Files\Blue Coat K9 Web Protection\k9filter.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
<br />
--<br />
End of file - 5166 bytes]]></description>
			<content:encoded><![CDATA[Hope this makes sense to somebody. Initially Firefox would not run (re-installed) and Explorer seem to redirect every link. The mouse cursor had serious "screen drift" in random directions and system performance was almost at a standstill.<br />
<br />
Have run MS Defender, spybot S&amp;D, ATF cleaner, Anti-Malware, and F-secure repeatedly. Symptoms have gradually improved but I have the following problems.<br />
<br />
 My Firefox browser keeps spontaneously opening up new windows in the foreground. They seem to be triggered by mouse clicks in the browser - not necessarily on links. The windows mostly open to the Firefox directory listing but some open up to web sites and are mostly caught by K9 as Trojan download sites. Performance also lags sporadically.<br />
<br />
I would greatly appreciate any help diagnosing and correcting the problem.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 8:15:51 PM, on 2/20/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Windows Defender\MsMpEng.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
C:\Program Files\Blue Coat K9 Web Protection\k9filter.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\Common Files\Java\Java Update\jusched.exe<br />
C:\Program Files\QuickTime\qttask.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = <a href="http://go.microsoft.com/fwlink/?LinkId=74005" target="_blank">http://go.microsoft.com/fwlink/?LinkId=74005</a><br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
O4 - HKLM\..\Run: [AIRPLUS] "C:\Program Files\D-Link\AIRPLUS.exe" -nogui<br />
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a href="http://go.microsoft.com/fwlink/?linkid=39204" target="_blank">http://go.microsoft.com/fwlink/?linkid=39204</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1094865255653" target="_blank">http://v5.windowsupdate.microsoft.com/v5...4865255653</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/get/sh...wflash.cab</a><br />
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - <a href="http://www.popcap.com/webgames/popcaploader_v10.cab" target="_blank">http://www.popcap.com/webgames/popcaploader_v10.cab</a><br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
O23 - Service: Blue Coat K9 Web Protection (bckwfs) - Blue Coat Systems, Inc. - C:\Program Files\Blue Coat K9 Web Protection\k9filter.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
<br />
--<br />
End of file - 5166 bytes]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Boonex Dolphin PHP script is SCAM!!!]]></title>
			<link>http://byteforums.com/thread-3141.html</link>
			<pubDate>Fri, 05 Feb 2010 14:33:58 +0000</pubDate>
			<guid isPermaLink="false">http://byteforums.com/thread-3141.html</guid>
			<description><![CDATA[Why Boonex is a scam?<br />
<br />
Boonex problem nr1. No coding standard <br />
<br />
Boonex is writen by several people using different technologies. Its main base (Dolphin) is writen in pure php with its own template engine and forum  (Orca) uses xlst. That has large negative impact to integration of forum in site and site in forum. When coding, please use single technology and template system. <br />
<br />
Whats even worser, different parts of dolphins code itself is writen by completely different people, and very in the hurry. So everyone has its own imagination how to interact with different parts of the code. It is very tricky to modify code that way to suit site needs. <br />
<br />
Boonex problem nr2. Template engine and separation of code/design/database<br />
<br />
This problem in dolphin/boonex needs a point on its own. Boonex uses custom template system ( that should be called layout system). The blocks of generated html code are pased to specific places in the template. That creates a big headache for programers as they need to search through code for the place where some box is generated. It might be generated in template, or in specific function in one of numerous includes. And so on. Even pligg has better templating than this. <br />
<br />
It is very tricky to rip boonex templating apart, as whole coding is based on such poor programming practice. They would be better off using existing template system like smarty or similar one. <br />
<br />
This leads to problem nr3<br />
<br />
Boonex problem nr3. Crapy use of Database<br />
<br />
We saw serveral other competing sites launched on boonex, but we did not care much. Why? Becouse when they reach 500-1000 daily visitors they will break apart. The reason for it is very bad programming and use of database. <br />
<br />
For example, boonex uses profile builder which assigns fields to profiles. So the output of profile uses more than one table and is quite inefficient. <br />
<br />
Also, there is a nice 20-30 query overhead on each page display to fetch all the configuration values from table. Silly, isn’t it ? They would be FAR better of using a file for configuring sofware or caching it in php file like it is done in most of the systems. <br />
<br />
Another simple problem. When boonex wants to display a profile being online it additionally check database for its status. But that data was pulled from database already. So 20 useless queries again. <br />
<br />
Resume<br />
<br />
I would not suggest using boonex if you want to keep your programmers sane. We have have changed the code almost completely for now, and you will need to do that too. Boonex is a scam. Try googling "boonex scam" first.]]></description>
			<content:encoded><![CDATA[Why Boonex is a scam?<br />
<br />
Boonex problem nr1. No coding standard <br />
<br />
Boonex is writen by several people using different technologies. Its main base (Dolphin) is writen in pure php with its own template engine and forum  (Orca) uses xlst. That has large negative impact to integration of forum in site and site in forum. When coding, please use single technology and template system. <br />
<br />
Whats even worser, different parts of dolphins code itself is writen by completely different people, and very in the hurry. So everyone has its own imagination how to interact with different parts of the code. It is very tricky to modify code that way to suit site needs. <br />
<br />
Boonex problem nr2. Template engine and separation of code/design/database<br />
<br />
This problem in dolphin/boonex needs a point on its own. Boonex uses custom template system ( that should be called layout system). The blocks of generated html code are pased to specific places in the template. That creates a big headache for programers as they need to search through code for the place where some box is generated. It might be generated in template, or in specific function in one of numerous includes. And so on. Even pligg has better templating than this. <br />
<br />
It is very tricky to rip boonex templating apart, as whole coding is based on such poor programming practice. They would be better off using existing template system like smarty or similar one. <br />
<br />
This leads to problem nr3<br />
<br />
Boonex problem nr3. Crapy use of Database<br />
<br />
We saw serveral other competing sites launched on boonex, but we did not care much. Why? Becouse when they reach 500-1000 daily visitors they will break apart. The reason for it is very bad programming and use of database. <br />
<br />
For example, boonex uses profile builder which assigns fields to profiles. So the output of profile uses more than one table and is quite inefficient. <br />
<br />
Also, there is a nice 20-30 query overhead on each page display to fetch all the configuration values from table. Silly, isn’t it ? They would be FAR better of using a file for configuring sofware or caching it in php file like it is done in most of the systems. <br />
<br />
Another simple problem. When boonex wants to display a profile being online it additionally check database for its status. But that data was pulled from database already. So 20 useless queries again. <br />
<br />
Resume<br />
<br />
I would not suggest using boonex if you want to keep your programmers sane. We have have changed the code almost completely for now, and you will need to do that too. Boonex is a scam. Try googling "boonex scam" first.]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[My HiJackThis log, need help please]]></title>
			<link>http://byteforums.com/thread-3140.html</link>
			<pubDate>Thu, 04 Feb 2010 00:37:59 +0000</pubDate>
			<guid isPermaLink="false">http://byteforums.com/thread-3140.html</guid>
			<description><![CDATA[Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 7:30:59 PM, on 2/3/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\System32\Ati2evxx.exe<br />
C:\Program Files\Windows Defender\MsMpEng.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Common Files\Command Software\dvpapi.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Microsoft IntelliPoint\point32.exe<br />
C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe<br />
C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br />
C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br />
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE<br />
C:\Program Files\AVG\AVG8\avgcsrvx.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Documents and Settings\John Glennon\Local Settings\Temporary Internet Files\Content.IE5\0DYFLR0P\HijackThisInstaller[1&#93;.exe<br />
C:\Program Files\HijackThis.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <a href="http://start.earthlink.net/AL/Search" target="_blank">http://start.earthlink.net/AL/Search</a><br />
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)<br />
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br />
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O3 - Toolbar: &amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br />
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [IntelliPoint&#93; "C:\Program Files\Microsoft IntelliPoint\point32.exe"<br />
O4 - HKLM\..\Run: [HPDJ Taskbar Utility&#93; C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe<br />
O4 - HKLM\..\Run: [AVG8_TRAY&#93; C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [UserFaultCheck&#93; %systemroot%\system32\dumprep 0 -u<br />
O4 - HKLM\..\Run: [hpqSRMon&#93; C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe<br />
O4 - HKLM\..\Run: [HP Software Update&#93; C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched&#93; "C:\Program Files\Java\jre6\bin\jusched.exe"<br />
O4 - HKLM\..\Run: [QuickTime Task&#93; "C:\Program Files\QuickTime\qttask.exe" -atboottime<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present<br />
O8 - Extra context menu item: Add to Windows &amp;Live Favorites - <a href="http://favorites.live.com/quickadd.aspx" target="_blank">http://favorites.live.com/quickadd.aspx</a><br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll<br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a href="http://go.microsoft.com/fwlink/?linkid=39204" target="_blank">http://go.microsoft.com/fwlink/?linkid=39204</a><br />
O16 - DPF: {22492231-AEF0-49FC-9180-CE8969AB1273} (F-Secure Online Scanner Launcher) - <a href="http://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab" target="_blank">http://download.sp.f-secure.com/ols/f-se...uncher.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1140821536656" target="_blank">http://update.microsoft.com/microsoftupd...0821536656</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe<br />
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe<br />
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
<br />
--<br />
End of file - 9340 bytes]]></description>
			<content:encoded><![CDATA[Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 7:30:59 PM, on 2/3/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\System32\Ati2evxx.exe<br />
C:\Program Files\Windows Defender\MsMpEng.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Common Files\Command Software\dvpapi.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Microsoft IntelliPoint\point32.exe<br />
C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe<br />
C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br />
C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br />
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe<br />
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE<br />
C:\Program Files\AVG\AVG8\avgcsrvx.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Documents and Settings\John Glennon\Local Settings\Temporary Internet Files\Content.IE5\0DYFLR0P\HijackThisInstaller[1].exe<br />
C:\Program Files\HijackThis.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <a href="http://start.earthlink.net/AL/Search" target="_blank">http://start.earthlink.net/AL/Search</a><br />
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)<br />
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br />
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O3 - Toolbar: &amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br />
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"<br />
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u<br />
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br />
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present<br />
O8 - Extra context menu item: Add to Windows &amp;Live Favorites - <a href="http://favorites.live.com/quickadd.aspx" target="_blank">http://favorites.live.com/quickadd.aspx</a><br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll<br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a href="http://go.microsoft.com/fwlink/?linkid=39204" target="_blank">http://go.microsoft.com/fwlink/?linkid=39204</a><br />
O16 - DPF: {22492231-AEF0-49FC-9180-CE8969AB1273} (F-Secure Online Scanner Launcher) - <a href="http://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab" target="_blank">http://download.sp.f-secure.com/ols/f-se...uncher.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1140821536656" target="_blank">http://update.microsoft.com/microsoftupd...0821536656</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe<br />
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe<br />
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
<br />
--<br />
End of file - 9340 bytes]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Browser Redirecting Help Please!]]></title>
			<link>http://byteforums.com/thread-3139.html</link>
			<pubDate>Sun, 31 Jan 2010 18:07:54 +0000</pubDate>
			<guid isPermaLink="false">http://byteforums.com/thread-3139.html</guid>
			<description><![CDATA[Every time i do a web search and try to click on a link my browser is redirected to some unknown site. I also get new window popping up with random sites. <br />
<br />
i have run Malwarebytes, Spybot, IObit Security 360 &amp; AVG and removed everything the find but i am still having the problem. Now the programs find no threats but the problem is not resolved.<br />
<br />
I ran Hijack This and here is the log file. Please HELP.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 10:05:41 AM, on 1/31/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\csrss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
C:\Program Files\IObit\IObit Security 360\IS360tray.exe<br />
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files\AVG\AVG9\avgfws9.exe<br />
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe<br />
C:\Program Files\IObit\IObit Security 360\IS360srv.exe<br />
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\WINDOWS\system32\wdfmgr.exe<br />
C:\Program Files\AVG\AVG9\avgam.exe<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
C:\Program Files\AVG\AVG9\avgemc.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
C:\WINDOWS\system32\wbem\wmiprvse.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe<br />
C:\WINDOWS\System32\alg.exe<br />
C:\Program Files\IObit\IObit Security 360\is360.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll<br />
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O4 - HKLM\..\Run: [AVG9_TRAY&#93; C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKLM\..\Run: [IObit Security 360&#93; "C:\Program Files\IObit\IObit Security 360\IS360tray.exe" /autostart<br />
O4 - HKCU\..\Run: [LightScribe Control Panel&#93; C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden<br />
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}&#93; "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"<br />
O4 - HKCU\..\Run: [Messenger (Yahoo!)&#93; "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet<br />
O4 - HKCU\..\Run: [ctfmon.exe&#93; C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer&#93; C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?<br />
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe<br />
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1258577339265" target="_blank">http://update.microsoft.com/windowsupdat...8577339265</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: AVG E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe<br />
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgfws9.exe<br />
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: IS360service - IObit - C:\Program Files\IObit\IObit Security 360\IS360srv.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
<br />
--<br />
End of file - 10005 bytes]]></description>
			<content:encoded><![CDATA[Every time i do a web search and try to click on a link my browser is redirected to some unknown site. I also get new window popping up with random sites. <br />
<br />
i have run Malwarebytes, Spybot, IObit Security 360 &amp; AVG and removed everything the find but i am still having the problem. Now the programs find no threats but the problem is not resolved.<br />
<br />
I ran Hijack This and here is the log file. Please HELP.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 10:05:41 AM, on 1/31/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\csrss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
C:\Program Files\IObit\IObit Security 360\IS360tray.exe<br />
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files\AVG\AVG9\avgfws9.exe<br />
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe<br />
C:\Program Files\IObit\IObit Security 360\IS360srv.exe<br />
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\WINDOWS\system32\wdfmgr.exe<br />
C:\Program Files\AVG\AVG9\avgam.exe<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
C:\Program Files\AVG\AVG9\avgemc.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
C:\WINDOWS\system32\wbem\wmiprvse.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe<br />
C:\WINDOWS\System32\alg.exe<br />
C:\Program Files\IObit\IObit Security 360\is360.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll<br />
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKLM\..\Run: [IObit Security 360] "C:\Program Files\IObit\IObit Security 360\IS360tray.exe" /autostart<br />
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden<br />
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"<br />
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?<br />
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe<br />
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1258577339265" target="_blank">http://update.microsoft.com/windowsupdat...8577339265</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: AVG E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe<br />
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgfws9.exe<br />
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: IS360service - IObit - C:\Program Files\IObit\IObit Security 360\IS360srv.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
<br />
--<br />
End of file - 10005 bytes]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[noobest noob ever :)]]></title>
			<link>http://byteforums.com/thread-3137.html</link>
			<pubDate>Sun, 24 Jan 2010 18:30:29 +0000</pubDate>
			<guid isPermaLink="false">http://byteforums.com/thread-3137.html</guid>
			<description><![CDATA[Greetings, fellow forumers!<br />
<br />
I came here from Birdie's youtube upload as well, and I would like to get in the mystery of PHP and MySQL...As the title said, I never did anything similar, and I think I need to get started from the deep depths of true beginnerness. <br />
<br />
Before I start to get off with my first post, it would be very kind if you would direct me to the proper topic of my problem. <br />
<br />
One more thing, as english is not my native language, please bear with me <img src="http://byteforums.com/images/smilies/smile.gif" style="vertical-align: middle;" border="0" alt="Smile" title="Smile" /><br />
<br />
Regards, ASE]]></description>
			<content:encoded><![CDATA[Greetings, fellow forumers!<br />
<br />
I came here from Birdie's youtube upload as well, and I would like to get in the mystery of PHP and MySQL...As the title said, I never did anything similar, and I think I need to get started from the deep depths of true beginnerness. <br />
<br />
Before I start to get off with my first post, it would be very kind if you would direct me to the proper topic of my problem. <br />
<br />
One more thing, as english is not my native language, please bear with me <img src="http://byteforums.com/images/smilies/smile.gif" style="vertical-align: middle;" border="0" alt="Smile" title="Smile" /><br />
<br />
Regards, ASE]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Spayware]]></title>
			<link>http://byteforums.com/thread-3136.html</link>
			<pubDate>Sat, 23 Jan 2010 18:35:10 +0000</pubDate>
			<guid isPermaLink="false">http://byteforums.com/thread-3136.html</guid>
			<description><![CDATA[Logfile of Trend Micro HijackThis v2.0.3 (BETA)<br />
Scan saved at 1:19:23 PM, on 1/23/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe<br />
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe<br />
C:\PROGRA~1\MICROS~4\rapimgr.exe<br />
C:\Program Files\honestech\honestech TVR\scheduleTV.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\WINDOWS\system32\dlcccoms.exe<br />
C:\WINDOWS\system32\inetsrv\inetinfo.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\WINDOWS\system32\msiexec.exe<br />
C:\Program Files\Spyware Doctor\pctsAuxs.exe<br />
C:\Program Files\Spyware Doctor\pctsSvc.exe<br />
C:\Program Files\Spyware Doctor\pctsTray.exe<br />
C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe<br />
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://giovanninarvaez.tripod.com/" target="_blank">http://giovanninarvaez.tripod.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll<br />
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll<br />
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [SystemTray&#93; SysTray.Exe<br />
O4 - HKLM\..\Run: [Cpqset&#93; C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe<br />
O4 - HKLM\..\Run: [QlbCtrl.exe&#93; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start<br />
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon&#93; ICO.EXE<br />
O4 - HKLM\..\Run: [IgfxTray&#93; C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds&#93; C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence&#93; C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut&#93; CHDAudPropShortcut.exe<br />
O4 - HKLM\..\Run: [SynTPEnh&#93; C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [DLCCCATS&#93; rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16<br />
O4 - HKLM\..\Run: [Acrobat Assistant 8.0&#93; "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"<br />
O4 - HKLM\..\Run: [Adobe_ID0EYTHM&#93; C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE<br />
O4 - HKLM\..\Run: [HP Software Update&#93; C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [QlbCtrl&#93; %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start<br />
O4 - HKLM\..\Run: [TkBellExe&#93; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched&#93; "C:\Program Files\Java\jre6\bin\jusched.exe"<br />
O4 - HKLM\..\Run: [QuickTime Task&#93; "C:\Program Files\QuickTime\qttask.exe" -atboottime<br />
O4 - HKLM\..\Run: [UserFaultCheck&#93; %systemroot%\system32\dumprep 0 -u<br />
O4 - HKLM\..\Run: [Google Updater&#93; "C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -systray -startup<br />
O4 - HKLM\..\Run: [ISTray&#93; "C:\Program Files\Spyware Doctor\pctsTray.exe"<br />
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware&#93; C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent<br />
O4 - HKCU\..\Run: [ctfmon.exe&#93; C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [H/PC Connection Agent&#93; "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"<br />
O4 - HKCU\..\Run: [swg&#93; C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br />
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?<br />
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe<br />
O4 - Global Startup: ScheduleTV.lnk = C:\Program Files\honestech\honestech TVR\scheduleTV.exe<br />
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000<br />
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll<br />
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll<br />
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll<br />
O16 - DPF: Win32 Classes - <br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a href="http://go.microsoft.com/fwlink/?linkid=39204" target="_blank">http://go.microsoft.com/fwlink/?linkid=39204</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1247967275062" target="_blank">http://update.microsoft.com/windowsupdat...7967275062</a><br />
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - <a href="http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab" target="_blank">http://h20270.www2.hp.com/ediags/gmn2/in...ction2.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/get/sh...wflash.cab</a><br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll<br />
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll<br />
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe<br />
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: dlcc_device -   - C:\WINDOWS\system32\dlcccoms.exe<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
O23 - Service: Sony SPTI Service for DVE (ICDSPTSV) - Sony Corporation - C:\WINDOWS\SYSTEM32\IcdSptSv.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe<br />
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe<br />
<br />
--<br />
End of file - 11773 bytes]]></description>
			<content:encoded><![CDATA[Logfile of Trend Micro HijackThis v2.0.3 (BETA)<br />
Scan saved at 1:19:23 PM, on 1/23/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe<br />
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe<br />
C:\PROGRA~1\MICROS~4\rapimgr.exe<br />
C:\Program Files\honestech\honestech TVR\scheduleTV.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\WINDOWS\system32\dlcccoms.exe<br />
C:\WINDOWS\system32\inetsrv\inetinfo.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\WINDOWS\system32\msiexec.exe<br />
C:\Program Files\Spyware Doctor\pctsAuxs.exe<br />
C:\Program Files\Spyware Doctor\pctsSvc.exe<br />
C:\Program Files\Spyware Doctor\pctsTray.exe<br />
C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe<br />
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://giovanninarvaez.tripod.com/" target="_blank">http://giovanninarvaez.tripod.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll<br />
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll<br />
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe<br />
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe<br />
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start<br />
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16<br />
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"<br />
O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start<br />
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br />
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u<br />
O4 - HKLM\..\Run: [Google Updater] "C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -systray -startup<br />
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"<br />
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"<br />
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br />
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?<br />
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe<br />
O4 - Global Startup: ScheduleTV.lnk = C:\Program Files\honestech\honestech TVR\scheduleTV.exe<br />
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000<br />
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll<br />
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll<br />
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll<br />
O16 - DPF: Win32 Classes - <br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a href="http://go.microsoft.com/fwlink/?linkid=39204" target="_blank">http://go.microsoft.com/fwlink/?linkid=39204</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1247967275062" target="_blank">http://update.microsoft.com/windowsupdat...7967275062</a><br />
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - <a href="http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab" target="_blank">http://h20270.www2.hp.com/ediags/gmn2/in...ction2.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/get/sh...wflash.cab</a><br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll<br />
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll<br />
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe<br />
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: dlcc_device -   - C:\WINDOWS\system32\dlcccoms.exe<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
O23 - Service: Sony SPTI Service for DVE (ICDSPTSV) - Sony Corporation - C:\WINDOWS\SYSTEM32\IcdSptSv.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe<br />
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe<br />
<br />
--<br />
End of file - 11773 bytes]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Problem with being redirected to random sites from search engines i.e. Google.]]></title>
			<link>http://byteforums.com/thread-3135.html</link>
			<pubDate>Fri, 01 Jan 2010 16:00:23 +0000</pubDate>
			<guid isPermaLink="false">http://byteforums.com/thread-3135.html</guid>
			<description><![CDATA[Hi there, <br />
<br />
I'm after some help regarding a problem I have being redirected to random sites when using search engines. I have tried a number of anti virus, spyware and malware programs without any luck so i have used HijackThis so hopefully someone can help me solve the problem. Any help would be much appreciated, thank you.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 15:50:32, on 01/01/2010<br />
Platform: Windows Vista SP1 (WinNT 6.00.1905)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18865)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\AVG\AVG9\avgtray.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Users\Fairlie\Program Files\DNA\btdna.exe<br />
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\hp\kbd\kbd.exe<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Windows\system32\wermgr.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe<br />
C:\Windows\system32\SearchProtocolHost.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://uk.msn.com/" target="_blank">http://uk.msn.com/</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://www.live.com/?searchonly=true" target="_blank">http://www.live.com/?searchonly=true</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.tiscali.co.uk/" target="_blank">http://www.tiscali.co.uk/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_GB&amp;c=73&amp;bd=Pavilion&amp;pf=desktop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TYPE=3...pf=desktop</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_GB&amp;c=73&amp;bd=Pavilion&amp;pf=desktop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TYPE=3...pf=desktop</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)<br />
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll<br />
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O3 - Toolbar: &amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll<br />
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll<br />
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)<br />
O4 - HKLM\..\Run: [KBD&#93; C:\HP\KBD\KbdStub.EXE<br />
O4 - HKLM\..\Run: [AVG9_TRAY&#93; C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKLM\..\Run: [TkBellExe&#93; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br />
O4 - HKLM\..\RunOnce: [Launcher&#93; %WINDIR%\SMINST\launcher.exe<br />
O4 - HKCU\..\Run: [ehTray.exe&#93; C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [BitTorrent DNA&#93; "C:\Users\Fairlie\Program Files\DNA\btdna.exe"<br />
O4 - HKCU\..\Run: [Google Update&#93; "C:\Users\Fairlie\AppData\Local\Google\Update\GoogleUpdate.exe" /c<br />
O4 - HKCU\..\Run: [ISUSPM&#93; "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler<br />
O4 - HKCU\..\Run: [WMPNSCFG&#93; C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar&#93; %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter&#93; rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar&#93; %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync&#93; C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync&#93; C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')<br />
O4 - Startup: AutorunsDisabled<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe<br />
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - <a href="http://a1540.g.akamai.net/7/1540/52/20070711/qtinstall.info.apple.com/qtactivex/qtplugin.cab" target="_blank">http://a1540.g.akamai.net/7/1540/52/2007...plugin.cab</a><br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - <a href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" target="_blank">http://upload.facebook.com/controls/2008...oader5.cab</a><br />
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - <a href="https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab" target="_blank">https://h20436.www2.hp.com/ediags/dex/se...DEXAXO.cab</a><br />
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - <a href="http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab" target="_blank">http://upload.facebook.com/controls/2009...ader55.cab</a><br />
O20 - AppInit_DLLs: avgrsstx.dll<br />
O23 - Service: Intel&reg; Alert Service (AlertService) - Intel&reg; Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe<br />
O23 - Service: Google Update Service (gupdate1c9f197d8a9cc09) (gupdate1c9f197d8a9cc09) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPBPRO.EXE<br />
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPBOID.EXE<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel&reg; Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Intel&reg; Software Services Manager (ISSM) - Intel&reg; Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: Intel&reg; Viiv&#153; Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe<br />
O23 - Service: Intel&reg; Application Tracker (MCLServiceATL) - Intel&reg; Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe<br />
O23 - Service: Intel&reg; Remoting Service (Remote UI Service) - Intel&reg; Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe<br />
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe<br />
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe<br />
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe<br />
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe<br />
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe<br />
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe<br />
<br />
--<br />
End of file - 9151 bytes]]></description>
			<content:encoded><![CDATA[Hi there, <br />
<br />
I'm after some help regarding a problem I have being redirected to random sites when using search engines. I have tried a number of anti virus, spyware and malware programs without any luck so i have used HijackThis so hopefully someone can help me solve the problem. Any help would be much appreciated, thank you.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 15:50:32, on 01/01/2010<br />
Platform: Windows Vista SP1 (WinNT 6.00.1905)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18865)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\AVG\AVG9\avgtray.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Users\Fairlie\Program Files\DNA\btdna.exe<br />
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\hp\kbd\kbd.exe<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Windows\system32\wermgr.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe<br />
C:\Windows\system32\SearchProtocolHost.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://uk.msn.com/" target="_blank">http://uk.msn.com/</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://www.live.com/?searchonly=true" target="_blank">http://www.live.com/?searchonly=true</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.tiscali.co.uk/" target="_blank">http://www.tiscali.co.uk/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_GB&amp;c=73&amp;bd=Pavilion&amp;pf=desktop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TYPE=3...pf=desktop</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_GB&amp;c=73&amp;bd=Pavilion&amp;pf=desktop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TYPE=3...pf=desktop</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)<br />
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll<br />
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O3 - Toolbar: &amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll<br />
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll<br />
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)<br />
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br />
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Fairlie\Program Files\DNA\btdna.exe"<br />
O4 - HKCU\..\Run: [Google Update] "C:\Users\Fairlie\AppData\Local\Google\Update\GoogleUpdate.exe" /c<br />
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')<br />
O4 - Startup: AutorunsDisabled<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe<br />
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - <a href="http://a1540.g.akamai.net/7/1540/52/20070711/qtinstall.info.apple.com/qtactivex/qtplugin.cab" target="_blank">http://a1540.g.akamai.net/7/1540/52/2007...plugin.cab</a><br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - <a href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" target="_blank">http://upload.facebook.com/controls/2008...oader5.cab</a><br />
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - <a href="https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab" target="_blank">https://h20436.www2.hp.com/ediags/dex/se...DEXAXO.cab</a><br />
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - <a href="http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab" target="_blank">http://upload.facebook.com/controls/2009...ader55.cab</a><br />
O20 - AppInit_DLLs: avgrsstx.dll<br />
O23 - Service: Intel&reg; Alert Service (AlertService) - Intel&reg; Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe<br />
O23 - Service: Google Update Service (gupdate1c9f197d8a9cc09) (gupdate1c9f197d8a9cc09) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPBPRO.EXE<br />
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPBOID.EXE<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel&reg; Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Intel&reg; Software Services Manager (ISSM) - Intel&reg; Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: Intel&reg; Viiv&#153; Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe<br />
O23 - Service: Intel&reg; Application Tracker (MCLServiceATL) - Intel&reg; Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe<br />
O23 - Service: Intel&reg; Remoting Service (Remote UI Service) - Intel&reg; Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe<br />
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe<br />
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe<br />
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe<br />
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe<br />
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe<br />
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe<br />
<br />
--<br />
End of file - 9151 bytes]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Posting my hijackthis log..PLEASE HELP!!]]></title>
			<link>http://byteforums.com/thread-3134.html</link>
			<pubDate>Sun, 27 Dec 2009 23:18:53 +0000</pubDate>
			<guid isPermaLink="false">http://byteforums.com/thread-3134.html</guid>
			<description><![CDATA[I ran a scan with malwarebytes anti-malware and nothing was found. But when I ran the f-secure online scan 4 spyware was detected and cleaned. Here's my hijackthis log...I appreciate any help!!!! <br />
<br />
<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 5:55:14 PM, on 12/27/2009<br />
Platform: Windows Vista SP1 (WinNT 6.00.1905)<br />
MSIE: Internet Explorer v7.00 (7.00.6001.18349)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe<br />
C:\Windows\System32\igfxtray.exe<br />
C:\Windows\System32\hkcmd.exe<br />
C:\Windows\System32\igfxpers.exe<br />
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Windows\system32\igfxsrvc.exe<br />
C:\Program Files\Lenovo\Lenovo OneKey Theater\OneKeyTheater.exe<br />
C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe<br />
C:\Program Files\Lenovo\Lenovo Desktop Navigator\DesktopNavigator.exe<br />
C:\Program Files\Lenovo\VeriFace\PManage.exe<br />
C:\Program Files\Lenovo\ReadyComm\ReadyComm.exe<br />
C:\Program Files\Lenovo\Energy Management\utility.exe<br />
C:\Program Files\Lenovo\Energy Management\Energy Management.exe<br />
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Program Files\RocketDock\RocketDock.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\ooVoo\ooVoo.exe<br />
C:\Windows\system32\igfxext.exe<br />
C:\Users\Norvella\AppData\Local\Google\Update\1.2.183.13\GoogleCrashHandler.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Program Files\Java\jre6\bin\jucheck.exe<br />
C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe<br />
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe<br />
C:\Users\Norvella\AppData\Local\Temp\Low\fsonlinescanner.exe<br />
C:\Users\Norvella\AppData\Local\Temp\OnlineScanner\Anti-Virus\fsgk32.exe<br />
C:\Users\Norvella\AppData\Local\Temp\OnlineScanner\Anti-Virus\fssm32.exe<br />
C:\Program Files\Skype\Phone\Skype.exe<br />
C:\Program Files\Skype\Plugin Manager\skypePM.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Program Files\Carbonite\CarbonitePreinstaller.exe<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Users\Norvella\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Norvella\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Norvella\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Norvella\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\Internet Explorer\ieuser.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe<br />
C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe<br />
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\Windows\system32\taskeng.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://lenovo.live.com/" target="_blank">http://lenovo.live.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://www.lenovo.com" target="_blank">http://www.lenovo.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [Windows Defender&#93; %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [IAAnotif&#93; C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe<br />
O4 - HKLM\..\Run: [IgfxTray&#93; C:\Windows\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds&#93; C:\Windows\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence&#93; C:\Windows\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [RtHDVCpl&#93; C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe<br />
O4 - HKLM\..\Run: [SynTPEnh&#93; C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [OneKey Theater&#93; C:\PROGRA~1\Lenovo\LENOVO~1\ONEKEY~1.EXE<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher&#93; "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br />
O4 - HKLM\..\Run: [IdeaNotesUser&#93; C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe<br />
O4 - HKLM\..\Run: [CarboniteSetupLite&#93; "C:\Program Files\Carbonite\CarbonitePreinstaller.exe" /preinstalled /pausefor=600<br />
O4 - HKLM\..\Run: [MDS_Menu&#93; "C:\Program Files\Lenovo\MediaShow\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\MediaShow" UpdateWithCreateOnce "Software\CyberLink\MediaShow\4.1"<br />
O4 - HKLM\..\Run: [Desktop Navigator&#93; %ProgramFiles%\Lenovo\Lenovo Desktop Navigator\DesktopNavigator.exe -sysStartup<br />
O4 - HKLM\..\Run: [VeriFaceManager&#93; C:\Program Files\Lenovo\VeriFace\PManage.exe<br />
O4 - HKLM\..\Run: [UpdateP2GShortCut&#93; "C:\Program Files\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"<br />
O4 - HKLM\..\Run: [Readycomm&#93; C:\Program Files\Lenovo\ReadyComm\ReadyComm.exe -TrayMode<br />
O4 - HKLM\..\Run: [EnergyUtility&#93; C:\Program Files\Lenovo\Energy Management\utility.exe<br />
O4 - HKLM\..\Run: [Energy Management&#93; C:\Program Files\Lenovo\Energy Management\Energy Management.exe<br />
O4 - HKLM\..\Run: [CanonSolutionMenu&#93; C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon<br />
O4 - HKLM\..\Run: [CanonMyPrinter&#93; C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon<br />
O4 - HKLM\..\Run: [QuickTime Task&#93; "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper&#93; "C:\Program Files\iTunes\iTunesHelper.exe"<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched&#93; "C:\Program Files\Java\jre6\bin\jusched.exe"<br />
O4 - HKLM\..\Run: [UfSeAgnt.exe&#93; "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"<br />
O4 - HKLM\..\Run: [TkBellExe&#93; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br />
O4 - HKCU\..\Run: [Sidebar&#93; C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [Google Update&#93; "C:\Users\Norvella\AppData\Local\Google\Update\GoogleUpdate.exe" /c<br />
O4 - HKCU\..\Run: [RocketDock&#93; "C:\Program Files\RocketDock\RocketDock.exe"<br />
O4 - HKCU\..\Run: [WMPNSCFG&#93; C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKCU\..\Run: [ooVoo.exe&#93; C:\Program Files\ooVoo\oovoo.exe /minimized<br />
O4 - HKCU\..\Run: [OE&#93; "C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe"<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar&#93; %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter&#93; rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar&#93; %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O8 - Extra context menu item: &amp;Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html<br />
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {22492231-AEF0-49FC-9180-CE8969AB1273} (F-Secure Online Scanner Launcher) - <a href="http://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab" target="_blank">http://download.sp.f-secure.com/ols/f-se...uncher.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: DDNIMSGService - Digital Delivery Networks, Inc. - C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGService.exe<br />
O23 - Service: DDNIService - Digital Delivery Networks, Inc. - C:\Program Files\DDNI\DIBS\DDNIService.exe<br />
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe<br />
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildGames\Game Console - WildGames\GameConsoleService.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: Intel&reg; Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe<br />
O23 - Service: IGRS - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe<br />
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe<br />
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe<br />
O23 - Service: System Repair Windows Update Monitor (System_Repair_UpdateMonitor) - Lenovo Group Limited - C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe<br />
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe<br />
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe<br />
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe<br />
<br />
--<br />
End of file - 11827 bytes]]></description>
			<content:encoded><![CDATA[I ran a scan with malwarebytes anti-malware and nothing was found. But when I ran the f-secure online scan 4 spyware was detected and cleaned. Here's my hijackthis log...I appreciate any help!!!! <br />
<br />
<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 5:55:14 PM, on 12/27/2009<br />
Platform: Windows Vista SP1 (WinNT 6.00.1905)<br />
MSIE: Internet Explorer v7.00 (7.00.6001.18349)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe<br />
C:\Windows\System32\igfxtray.exe<br />
C:\Windows\System32\hkcmd.exe<br />
C:\Windows\System32\igfxpers.exe<br />
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Windows\system32\igfxsrvc.exe<br />
C:\Program Files\Lenovo\Lenovo OneKey Theater\OneKeyTheater.exe<br />
C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe<br />
C:\Program Files\Lenovo\Lenovo Desktop Navigator\DesktopNavigator.exe<br />
C:\Program Files\Lenovo\VeriFace\PManage.exe<br />
C:\Program Files\Lenovo\ReadyComm\ReadyComm.exe<br />
C:\Program Files\Lenovo\Energy Management\utility.exe<br />
C:\Program Files\Lenovo\Energy Management\Energy Management.exe<br />
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Program Files\RocketDock\RocketDock.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\ooVoo\ooVoo.exe<br />
C:\Windows\system32\igfxext.exe<br />
C:\Users\Norvella\AppData\Local\Google\Update\1.2.183.13\GoogleCrashHandler.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Program Files\Java\jre6\bin\jucheck.exe<br />
C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe<br />
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe<br />
C:\Users\Norvella\AppData\Local\Temp\Low\fsonlinescanner.exe<br />
C:\Users\Norvella\AppData\Local\Temp\OnlineScanner\Anti-Virus\fsgk32.exe<br />
C:\Users\Norvella\AppData\Local\Temp\OnlineScanner\Anti-Virus\fssm32.exe<br />
C:\Program Files\Skype\Phone\Skype.exe<br />
C:\Program Files\Skype\Plugin Manager\skypePM.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Program Files\Carbonite\CarbonitePreinstaller.exe<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Users\Norvella\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Norvella\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Norvella\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Norvella\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\Internet Explorer\ieuser.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe<br />
C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe<br />
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\Windows\system32\taskeng.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://lenovo.live.com/" target="_blank">http://lenovo.live.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://www.lenovo.com" target="_blank">http://www.lenovo.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe<br />
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [OneKey Theater] C:\PROGRA~1\Lenovo\LENOVO~1\ONEKEY~1.EXE<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br />
O4 - HKLM\..\Run: [IdeaNotesUser] C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe<br />
O4 - HKLM\..\Run: [CarboniteSetupLite] "C:\Program Files\Carbonite\CarbonitePreinstaller.exe" /preinstalled /pausefor=600<br />
O4 - HKLM\..\Run: [MDS_Menu] "C:\Program Files\Lenovo\MediaShow\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\MediaShow" UpdateWithCreateOnce "Software\CyberLink\MediaShow\4.1"<br />
O4 - HKLM\..\Run: [Desktop Navigator] %ProgramFiles%\Lenovo\Lenovo Desktop Navigator\DesktopNavigator.exe -sysStartup<br />
O4 - HKLM\..\Run: [VeriFaceManager] C:\Program Files\Lenovo\VeriFace\PManage.exe<br />
O4 - HKLM\..\Run: [UpdateP2GShortCut] "C:\Program Files\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"<br />
O4 - HKLM\..\Run: [Readycomm] C:\Program Files\Lenovo\ReadyComm\ReadyComm.exe -TrayMode<br />
O4 - HKLM\..\Run: [EnergyUtility] C:\Program Files\Lenovo\Energy Management\utility.exe<br />
O4 - HKLM\..\Run: [Energy Management] C:\Program Files\Lenovo\Energy Management\Energy Management.exe<br />
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon<br />
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br />
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"<br />
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br />
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [Google Update] "C:\Users\Norvella\AppData\Local\Google\Update\GoogleUpdate.exe" /c<br />
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKCU\..\Run: [ooVoo.exe] C:\Program Files\ooVoo\oovoo.exe /minimized<br />
O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe"<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O8 - Extra context menu item: &amp;Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html<br />
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {22492231-AEF0-49FC-9180-CE8969AB1273} (F-Secure Online Scanner Launcher) - <a href="http://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab" target="_blank">http://download.sp.f-secure.com/ols/f-se...uncher.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: DDNIMSGService - Digital Delivery Networks, Inc. - C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGService.exe<br />
O23 - Service: DDNIService - Digital Delivery Networks, Inc. - C:\Program Files\DDNI\DIBS\DDNIService.exe<br />
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe<br />
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildGames\Game Console - WildGames\GameConsoleService.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: Intel&reg; Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe<br />
O23 - Service: IGRS - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe<br />
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe<br />
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe<br />
O23 - Service: System Repair Windows Update Monitor (System_Repair_UpdateMonitor) - Lenovo Group Limited - C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe<br />
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe<br />
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe<br />
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe<br />
<br />
--<br />
End of file - 11827 bytes]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Which is your favorite PS3 Games?]]></title>
			<link>http://byteforums.com/thread-3133.html</link>
			<pubDate>Mon, 21 Dec 2009 10:26:49 +0000</pubDate>
			<guid isPermaLink="false">http://byteforums.com/thread-3133.html</guid>
			<description><![CDATA[My favourite PS3 Games are:<br />
<br />
Grand Theft Auto IV<br />
Call of Duty 4: Modern Warfare<br />
The Last Guardian<br />
Gran Turismo 5<br />
God of War III]]></description>
			<content:encoded><![CDATA[My favourite PS3 Games are:<br />
<br />
Grand Theft Auto IV<br />
Call of Duty 4: Modern Warfare<br />
The Last Guardian<br />
Gran Turismo 5<br />
God of War III]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Whats your favourite Movies?]]></title>
			<link>http://byteforums.com/thread-3132.html</link>
			<pubDate>Mon, 21 Dec 2009 10:22:09 +0000</pubDate>
			<guid isPermaLink="false">http://byteforums.com/thread-3132.html</guid>
			<description><![CDATA[Hi,<br />
My favourite movies are,<br />
1) Titanic<br />
2) The world is not enough<br />
3) Paranormal Activity<br />
4) Toy Story<br />
5) Slum dog millionaire]]></description>
			<content:encoded><![CDATA[Hi,<br />
My favourite movies are,<br />
1) Titanic<br />
2) The world is not enough<br />
3) Paranormal Activity<br />
4) Toy Story<br />
5) Slum dog millionaire]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Newbie here]]></title>
			<link>http://byteforums.com/thread-3131.html</link>
			<pubDate>Mon, 21 Dec 2009 10:19:45 +0000</pubDate>
			<guid isPermaLink="false">http://byteforums.com/thread-3131.html</guid>
			<description><![CDATA[Hello Guys..<br />
<br />
How are you guys, i hope you all are fine and enjoying the life..<br />
<br />
I am Kevin Addes and  I am here for getting some information..]]></description>
			<content:encoded><![CDATA[Hello Guys..<br />
<br />
How are you guys, i hope you all are fine and enjoying the life..<br />
<br />
I am Kevin Addes and  I am here for getting some information..]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[i have downloaded 6 anti spyware anti viruses if you can help ill have your babys!!!!]]></title>
			<link>http://byteforums.com/thread-3130.html</link>
			<pubDate>Sun, 20 Dec 2009 09:30:05 +0000</pubDate>
			<guid isPermaLink="false">http://byteforums.com/thread-3130.html</guid>
			<description><![CDATA[i have bought stopzilla.........nothing happens<br />
i downloaded avg ...................nothing<br />
i downloaded browser hijacker retaliator 4.5........................nothing happen<br />
i downloaded bull dog ...............nothing happens<br />
i uped all security setting on my firewall,internet settings to the max...nothing<br />
<br />
so this is my last ditch attempt here is my hijack this log if you guys can fix this i will give you my kidney just pick one if this cant be fixed i swear i record smashing up my 1300£ computer on youtube and then piss on it<br />
<br />
i am studdying computer programming right now and how so much software that i bought and its cost alot so please please help guys<br />
<br />
THE PROBLEM IS WHEN EVERY I CLICK ON ANYTHING (LINK) AFTER SEARCHING IT IN GOOGLE IT DIRECTES ME TO EITHER "YOUR COMPUTER HAS A VIRUS DOWNLOAD THIS NOW " OR ADVERTISMENT CRAP EVERYSINGLE TIME<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 09:18:44, on 20/12/2009<br />
Platform: Windows Vista SP1 (WinNT 6.00.1905)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18865)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\RtHDVCpl.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Zamaan's Software\Browser Hijack Retaliator 4.5\BHR.exe<br />
C:\Program Files\AVG\AVG9\avgtray.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Program Files\Free Download Manager\fdm.exe<br />
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe<br />
C:\Program Files\STOPzilla!\STOPzilla.exe<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Windows\notepad.exe<br />
C:\Program Files\STOPzilla!\SZOptions.exe<br />
C:\Users\Claire\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Claire\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Claire\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Claire\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Claire\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Claire\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Claire\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe<br />
C:\Users\Claire\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Claire\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Claire\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.google.com" target="_blank">http://www.google.com</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\Stopzilla!\Toolbar\SZSG.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll<br />
O3 - Toolbar: &amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)<br />
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\Stopzilla!\Toolbar\SZSG.dll<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher&#93; "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"<br />
O4 - HKLM\..\Run: [RtHDVCpl&#93; RtHDVCpl.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched&#93; "C:\Program Files\Java\jre6\bin\jusched.exe"<br />
O4 - HKLM\..\Run: [BHR&#93; C:\Program Files\Zamaan's Software\Browser Hijack Retaliator 4.5\BHR.exe<br />
O4 - HKLM\..\Run: [QuickTime Task&#93; "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br />
O4 - HKLM\..\Run: [AVG9_TRAY&#93; C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKCU\..\Run: [ehTray.exe&#93; C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [Google Update&#93; "C:\Users\Claire\AppData\Local\Google\Update\GoogleUpdate.exe" /c<br />
O4 - HKCU\..\Run: [WMPNSCFG&#93; C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKCU\..\Run: [Sidebar&#93; C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [Free Download Manager&#93; "C:\Program Files\Free Download Manager\fdm.exe" -autorun<br />
O4 - HKCU\..\Run: [Software Informer&#93; "C:\Program Files\Free Download Manager\softinfo.exe" -autorun<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar&#93; %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter&#93; rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar&#93; %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-18\..\Run: [RegistryMonitor1&#93; "C:\Windows\TEMP\wtrw.tmp\svchost.exe" (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [RegistryMonitor1&#93; "C:\Windows\TEMP\wtrw.tmp\svchost.exe" (User 'Default user')<br />
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe<br />
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm<br />
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm<br />
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm<br />
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O20 - AppInit_DLLs: avgrsstx.dll<br />
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br />
O23 - Service: AVG E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe<br />
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgfws9.exe<br />
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe<br />
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe<br />
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Windows\System32\nvSCPAPISvr.exe<br />
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe<br />
<br />
--<br />
End of file - 7367 bytes]]></description>
			<content:encoded><![CDATA[i have bought stopzilla.........nothing happens<br />
i downloaded avg ...................nothing<br />
i downloaded browser hijacker retaliator 4.5........................nothing happen<br />
i downloaded bull dog ...............nothing happens<br />
i uped all security setting on my firewall,internet settings to the max...nothing<br />
<br />
so this is my last ditch attempt here is my hijack this log if you guys can fix this i will give you my kidney just pick one if this cant be fixed i swear i record smashing up my 1300£ computer on youtube and then piss on it<br />
<br />
i am studdying computer programming right now and how so much software that i bought and its cost alot so please please help guys<br />
<br />
THE PROBLEM IS WHEN EVERY I CLICK ON ANYTHING (LINK) AFTER SEARCHING IT IN GOOGLE IT DIRECTES ME TO EITHER "YOUR COMPUTER HAS A VIRUS DOWNLOAD THIS NOW " OR ADVERTISMENT CRAP EVERYSINGLE TIME<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 09:18:44, on 20/12/2009<br />
Platform: Windows Vista SP1 (WinNT 6.00.1905)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18865)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\RtHDVCpl.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Zamaan's Software\Browser Hijack Retaliator 4.5\BHR.exe<br />
C:\Program Files\AVG\AVG9\avgtray.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Program Files\Free Download Manager\fdm.exe<br />
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe<br />
C:\Program Files\STOPzilla!\STOPzilla.exe<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Windows\notepad.exe<br />
C:\Program Files\STOPzilla!\SZOptions.exe<br />
C:\Users\Claire\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Claire\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Claire\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Claire\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Claire\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Claire\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Claire\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe<br />
C:\Users\Claire\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Claire\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Claire\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.google.com" target="_blank">http://www.google.com</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\Stopzilla!\Toolbar\SZSG.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll<br />
O3 - Toolbar: &amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br />
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)<br />
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\Stopzilla!\Toolbar\SZSG.dll<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"<br />
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br />
O4 - HKLM\..\Run: [BHR] C:\Program Files\Zamaan's Software\Browser Hijack Retaliator 4.5\BHR.exe<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [Google Update] "C:\Users\Claire\AppData\Local\Google\Update\GoogleUpdate.exe" /c<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun<br />
O4 - HKCU\..\Run: [Software Informer] "C:\Program Files\Free Download Manager\softinfo.exe" -autorun<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-18\..\Run: [RegistryMonitor1] "C:\Windows\TEMP\wtrw.tmp\svchost.exe" (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [RegistryMonitor1] "C:\Windows\TEMP\wtrw.tmp\svchost.exe" (User 'Default user')<br />
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe<br />
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm<br />
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm<br />
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm<br />
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm<br />
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O20 - AppInit_DLLs: avgrsstx.dll<br />
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br />
O23 - Service: AVG E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe<br />
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgfws9.exe<br />
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe<br />
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe<br />
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Windows\System32\nvSCPAPISvr.exe<br />
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe<br />
<br />
--<br />
End of file - 7367 bytes]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[My Greetings to All!!]]></title>
			<link>http://byteforums.com/thread-3129.html</link>
			<pubDate>Thu, 17 Dec 2009 05:18:31 +0000</pubDate>
			<guid isPermaLink="false">http://byteforums.com/thread-3129.html</guid>
			<description><![CDATA[Hello Everyone,<br />
My name is Daniel. I checked the site and found a lot of topics to discuss on and also found the members of this site providing an active contribution to the threads. I think that I will have a good time here posting. I hope that I am welcome here. Looking forward for the exchange of some useful information. Have a nice day and keep posting guys!!]]></description>
			<content:encoded><![CDATA[Hello Everyone,<br />
My name is Daniel. I checked the site and found a lot of topics to discuss on and also found the members of this site providing an active contribution to the threads. I think that I will have a good time here posting. I hope that I am welcome here. Looking forward for the exchange of some useful information. Have a nice day and keep posting guys!!]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Whats your favourite book?]]></title>
			<link>http://byteforums.com/thread-3128.html</link>
			<pubDate>Mon, 14 Dec 2009 05:00:30 +0000</pubDate>
			<guid isPermaLink="false">http://byteforums.com/thread-3128.html</guid>
			<description><![CDATA[What's your favourite book or have you read any good ones lately?]]></description>
			<content:encoded><![CDATA[What's your favourite book or have you read any good ones lately?]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Whats your favourite Movies?]]></title>
			<link>http://byteforums.com/thread-3127.html</link>
			<pubDate>Mon, 14 Dec 2009 04:59:08 +0000</pubDate>
			<guid isPermaLink="false">http://byteforums.com/thread-3127.html</guid>
			<description><![CDATA[Hi,<br />
My favourite movies are,<br />
1) Titanic<br />
2) The world is not enough<br />
3) Paranormal Activity<br />
4) Toy Story<br />
5) Slum dog millionaire]]></description>
			<content:encoded><![CDATA[Hi,<br />
My favourite movies are,<br />
1) Titanic<br />
2) The world is not enough<br />
3) Paranormal Activity<br />
4) Toy Story<br />
5) Slum dog millionaire]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Hello Forum Members!]]></title>
			<link>http://byteforums.com/thread-3126.html</link>
			<pubDate>Mon, 14 Dec 2009 04:57:32 +0000</pubDate>
			<guid isPermaLink="false">http://byteforums.com/thread-3126.html</guid>
			<description><![CDATA[Hello,<br />
<br />
I am Roges Jhone.This is my first visit to site.I love forum discussion.It is one of my hobbies.I can share my thoughts to others and can get plenty of information from others.I just love it.Other then that I like to surf different and new sites. I like the way I am getting plenty of new information from the site.I am very pleased to be part of the site and I am eager to do my first post.I'll do my best to answer anything that come up while you learning Java and game.<br />
<br />
Thanks.]]></description>
			<content:encoded><![CDATA[Hello,<br />
<br />
I am Roges Jhone.This is my first visit to site.I love forum discussion.It is one of my hobbies.I can share my thoughts to others and can get plenty of information from others.I just love it.Other then that I like to surf different and new sites. I like the way I am getting plenty of new information from the site.I am very pleased to be part of the site and I am eager to do my first post.I'll do my best to answer anything that come up while you learning Java and game.<br />
<br />
Thanks.]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[WEB BROWSER IS BEING REDIRECTED]]></title>
			<link>http://byteforums.com/thread-3125.html</link>
			<pubDate>Sun, 06 Dec 2009 04:06:42 +0000</pubDate>
			<guid isPermaLink="false">http://byteforums.com/thread-3125.html</guid>
			<description><![CDATA[I found your article and instructions for removing malware and followed them all the way to this point.  I still get redirected to a different web site when I click on a search link, not every time but almost.  Anyway, here is my Hickjackthis log.  Thanks for helping:<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 9:50:38 PM, on 12/5/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\windows\system\hpsysdrv.exe<br />
C:\WINDOWS\system32\hphmon06.exe<br />
C:\HP\KBD\KBD.EXE<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\AGRSMMSG.exe<br />
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br />
C:\Program Files\McAfee.com\Agent\mcagent.exe<br />
C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe<br />
C:\Program Files\Max Spyware Detector\MaxWatchDogService.exe<br />
C:\WINDOWS\ALCXMNTR.EXE<br />
C:\Program Files\QuickTime\QTTask.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\Program Files\Max Spyware Detector\MaxSDTray.exe<br />
C:\Program Files\Max Spyware Detector\MaxActMon.exe<br />
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe<br />
C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe<br />
C:\QUICKENW\QWDLLS.EXE<br />
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe<br />
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br />
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
c:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Max Registry Cleaner\MaxRCSystemTray.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
C:\Program Files\Java\jre6\bin\jucheck.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=Q105&amp;bd=pavilion&amp;pf=desktop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TYPE=3...pf=desktop</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iesearch&amp;locale=EN_US&amp;c=Q105&amp;bd=pavilion&amp;pf=desktop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TYPE=3...pf=desktop</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://m.www.yahoo.com/" target="_blank">http://m.www.yahoo.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iesearch&amp;locale=EN_US&amp;c=Q105&amp;bd=pavilion&amp;pf=desktop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TYPE=3...pf=desktop</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=Q105&amp;bd=pavilion&amp;pf=desktop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TYPE=3...pf=desktop</a><br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: ALOT Toolbar Helper - {14CEEAFF-96DD-4101-AE37-D5ECDC23C3F6} - C:\Program Files\alot\bin\BHO\alotBHO.dll<br />
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\real\realplayer\rpbrowserrecordplugin.dll<br />
O2 - BHO: PCH Search &amp; Win Toolbar - {4E7BD74F-2B8D-469E-C8ED-EA2EFAD2ED61} - C:\PROGRA~1\SEARCH~1\SEARCH~1.DLL<br />
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll<br />
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O3 - Toolbar: PCH Search &amp; Win Toolbar - {4E7BD74F-2B8D-469E-C8ED-EA2EFAD2ED61} - C:\PROGRA~1\SEARCH~1\SEARCH~1.DLL<br />
O3 - Toolbar: (no name) - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - (no file)<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched&#93; "C:\Program Files\Java\jre6\bin\jusched.exe"<br />
O4 - HKLM\..\Run: [hpsysdrv&#93; c:\windows\system\hpsysdrv.exe<br />
O4 - HKLM\..\Run: [IgfxTray&#93; C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HPHUPD06&#93; c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe<br />
O4 - HKLM\..\Run: [HPHmon06&#93; C:\WINDOWS\system32\hphmon06.exe<br />
O4 - HKLM\..\Run: [KBD&#93; C:\HP\KBD\KBD.EXE<br />
O4 - HKLM\..\Run: [UpdateManager&#93; "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r<br />
O4 - HKLM\..\Run: [iTunesHelper&#93; C:\Program Files\iTunes\iTunesHelper.exe<br />
O4 - HKLM\..\Run: [Recguard&#93; C:\WINDOWS\SMINST\RECGUARD.EXE<br />
O4 - HKLM\..\Run: [VTTimer&#93; VTTimer.exe<br />
O4 - HKLM\..\Run: [SiSPower&#93; Rundll32.exe SiSPower.dll,ModeAgent<br />
O4 - HKLM\..\Run: [AGRSMMSG&#93; AGRSMMSG.exe<br />
O4 - HKLM\..\Run: [PS2&#93; C:\WINDOWS\system32\ps2.exe<br />
O4 - HKLM\..\Run: [LSBWatcher&#93; c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe<br />
O4 - HKLM\..\Run: [ISUSPM Startup&#93; C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br />
O4 - HKLM\..\Run: [ISUSScheduler&#93; "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start<br />
O4 - HKLM\..\Run: [mcagent_exe&#93; "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey<br />
O4 - HKLM\..\Run: [McENUI&#93; C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide<br />
O4 - HKLM\..\Run: [StatusClient 2.6&#93; C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto<br />
O4 - HKLM\..\Run: [TomcatStartup 2.5&#93; C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe<br />
O4 - HKLM\..\Run: [AlcxMonitor&#93; ALCXMNTR.EXE<br />
O4 - HKLM\..\Run: [QuickTime Task&#93; "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br />
O4 - HKLM\..\Run: [AutoTBar&#93; c:\Program Files\HP\Digital Imaging\bin\AUTOTBAR.EXE<br />
O4 - HKLM\..\Run: [TkBellExe&#93; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br />
O4 - HKLM\..\Run: [Intuit SyncManager&#93; c:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe  startup<br />
O4 - HKLM\..\Run: [SDActiveMonitor&#93; C:\Program Files\Max Spyware Detector\MaxSDTray.exe "-AUTO"<br />
O4 - HKLM\..\Run: [RCAutoLiveUpdate&#93; C:\Program Files\Max Registry Cleaner\MaxLURC.exe -AUTO<br />
O4 - HKLM\..\Run: [RCSystemTray&#93; C:\Program Files\Max Registry Cleaner\MaxRCSystemTray.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe&#93; C:\WINDOWS\system32\ctfmon.exe<br />
O4 - Global Startup: Billminder.lnk = C:\QUICKENW\BILLMIND.EXE<br />
O4 - Global Startup: McAfee Security Scan.lnk = ?<br />
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br />
O4 - Global Startup: Quicken Startup.lnk = C:\QUICKENW\QWDLLS.EXE<br />
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe<br />
O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {22492231-AEF0-49FC-9180-CE8969AB1273} (F-Secure Online Scanner Launcher) - <a href="http://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab" target="_blank">http://download.sp.f-secure.com/ols/f-se...uncher.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O18 - Protocol: intu-help-qb3 - {C5E479EA-0A65-4B05-8C6C-2FC8CC682EB4} - c:\Program Files\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll<br />
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)<br />
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: MaxWatchDogService - Max Secure Software - C:\Program Files\Max Spyware Detector\MaxWatchDogService.exe<br />
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe<br />
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br />
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe<br />
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: QBCFMonitorService - Intuit - c:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe<br />
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - c:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe<br />
<br />
--<br />
End of file - 10508 bytes]]></description>
			<content:encoded><![CDATA[I found your article and instructions for removing malware and followed them all the way to this point.  I still get redirected to a different web site when I click on a search link, not every time but almost.  Anyway, here is my Hickjackthis log.  Thanks for helping:<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 9:50:38 PM, on 12/5/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\windows\system\hpsysdrv.exe<br />
C:\WINDOWS\system32\hphmon06.exe<br />
C:\HP\KBD\KBD.EXE<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\AGRSMMSG.exe<br />
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br />
C:\Program Files\McAfee.com\Agent\mcagent.exe<br />
C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe<br />
C:\Program Files\Max Spyware Detector\MaxWatchDogService.exe<br />
C:\WINDOWS\ALCXMNTR.EXE<br />
C:\Program Files\QuickTime\QTTask.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\Program Files\Max Spyware Detector\MaxSDTray.exe<br />
C:\Program Files\Max Spyware Detector\MaxActMon.exe<br />
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe<br />
C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe<br />
C:\QUICKENW\QWDLLS.EXE<br />
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe<br />
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br />
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
c:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Max Registry Cleaner\MaxRCSystemTray.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
C:\Program Files\Java\jre6\bin\jucheck.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=Q105&amp;bd=pavilion&amp;pf=desktop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TYPE=3...pf=desktop</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iesearch&amp;locale=EN_US&amp;c=Q105&amp;bd=pavilion&amp;pf=desktop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TYPE=3...pf=desktop</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://m.www.yahoo.com/" target="_blank">http://m.www.yahoo.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iesearch&amp;locale=EN_US&amp;c=Q105&amp;bd=pavilion&amp;pf=desktop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TYPE=3...pf=desktop</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=Q105&amp;bd=pavilion&amp;pf=desktop" target="_blank">http://ie.redirect.hp.com/svs/rdr?TYPE=3...pf=desktop</a><br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: ALOT Toolbar Helper - {14CEEAFF-96DD-4101-AE37-D5ECDC23C3F6} - C:\Program Files\alot\bin\BHO\alotBHO.dll<br />
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\real\realplayer\rpbrowserrecordplugin.dll<br />
O2 - BHO: PCH Search &amp; Win Toolbar - {4E7BD74F-2B8D-469E-C8ED-EA2EFAD2ED61} - C:\PROGRA~1\SEARCH~1\SEARCH~1.DLL<br />
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll<br />
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O3 - Toolbar: PCH Search &amp; Win Toolbar - {4E7BD74F-2B8D-469E-C8ED-EA2EFAD2ED61} - C:\PROGRA~1\SEARCH~1\SEARCH~1.DLL<br />
O3 - Toolbar: (no name) - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - (no file)<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br />
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe<br />
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe<br />
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE<br />
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r<br />
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe<br />
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE<br />
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe<br />
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent<br />
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe<br />
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe<br />
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe<br />
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br />
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start<br />
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey<br />
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide<br />
O4 - HKLM\..\Run: [StatusClient 2.6] C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto<br />
O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe<br />
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br />
O4 - HKLM\..\Run: [AutoTBar] c:\Program Files\HP\Digital Imaging\bin\AUTOTBAR.EXE<br />
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br />
O4 - HKLM\..\Run: [Intuit SyncManager] c:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe  startup<br />
O4 - HKLM\..\Run: [SDActiveMonitor] C:\Program Files\Max Spyware Detector\MaxSDTray.exe "-AUTO"<br />
O4 - HKLM\..\Run: [RCAutoLiveUpdate] C:\Program Files\Max Registry Cleaner\MaxLURC.exe -AUTO<br />
O4 - HKLM\..\Run: [RCSystemTray] C:\Program Files\Max Registry Cleaner\MaxRCSystemTray.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - Global Startup: Billminder.lnk = C:\QUICKENW\BILLMIND.EXE<br />
O4 - Global Startup: McAfee Security Scan.lnk = ?<br />
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br />
O4 - Global Startup: Quicken Startup.lnk = C:\QUICKENW\QWDLLS.EXE<br />
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe<br />
O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {22492231-AEF0-49FC-9180-CE8969AB1273} (F-Secure Online Scanner Launcher) - <a href="http://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab" target="_blank">http://download.sp.f-secure.com/ols/f-se...uncher.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O18 - Protocol: intu-help-qb3 - {C5E479EA-0A65-4B05-8C6C-2FC8CC682EB4} - c:\Program Files\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll<br />
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)<br />
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll<br />
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: MaxWatchDogService - Max Secure Software - C:\Program Files\Max Spyware Detector\MaxWatchDogService.exe<br />
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe<br />
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br />
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe<br />
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: QBCFMonitorService - Intuit - c:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe<br />
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - c:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe<br />
<br />
--<br />
End of file - 10508 bytes]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Help! - Hijackthis log for Sedoparking redirect]]></title>
			<link>http://byteforums.com/thread-3124.html</link>
			<pubDate>Fri, 04 Dec 2009 04:51:01 +0000</pubDate>
			<guid isPermaLink="false">http://byteforums.com/thread-3124.html</guid>
			<description><![CDATA[Hello, I found this forum through Google and followed the instruction on other thread. I've installed Hijackthis and run it, but don't understand which one to delete. At times when I browse, I'm redirected to sedoparking <img src="http://byteforums.com/images/smilies/dodgy.gif" style="vertical-align: middle;" border="0" alt="Dodgy" title="Dodgy" /><br />
<br />
I tried reinstalling windows, tried several antivirus, but they don't work. Hopefully someone will answer my message. So, here's the log.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 11:40:41 AM, on 12/4/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\igfxtray.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\WINDOWS\system32\igfxsrvc.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\WINDOWS\PLFSetL.exe<br />
C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\DAEMON Tools Lite\daemon.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\Program Files\AVG\AVG9\avgfws9.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgam.exe<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.daemon-search.com/startpage" target="_blank">http://www.daemon-search.com/startpage</a><br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O4 - HKLM\..\Run: [IgfxTray&#93; C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds&#93; C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence&#93; C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [SynTPEnh&#93; C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [PLFSetL&#93; C:\WINDOWS\PLFSetL.exe<br />
O4 - HKLM\..\Run: [Malware Defender&#93; c:\program files\malware defender\malwaredefender.exe<br />
O4 - HKLM\..\Run: [AVG9_TRAY&#93; C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKLM\..\Run: [Prefs&#93; C:\PROGRA~1\oDesk\oDeskLaunch.exe<br />
O4 - HKLM\..\Run: [QuickTime Task&#93; "C:\Program Files\K-Lite Codec Pack\QuickTime\QTTask.exe" -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper&#93; "C:\Program Files\iTunes\iTunesHelper.exe"<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher&#93; "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"<br />
O4 - HKCU\..\Run: [DAEMON Tools Lite&#93; "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun<br />
O4 - HKCU\..\Run: [ctfmon.exe&#93; C:\WINDOWS\system32\ctfmon.exe<br />
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll<br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgfws9.exe<br />
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe<br />
O23 - Service: Malware Defender Service (MalwareDefenderService) - TorchSoft - c:\program files\malware defender\mdservice.exe<br />
<br />
--<br />
End of file - 5560 bytes]]></description>
			<content:encoded><![CDATA[Hello, I found this forum through Google and followed the instruction on other thread. I've installed Hijackthis and run it, but don't understand which one to delete. At times when I browse, I'm redirected to sedoparking <img src="http://byteforums.com/images/smilies/dodgy.gif" style="vertical-align: middle;" border="0" alt="Dodgy" title="Dodgy" /><br />
<br />
I tried reinstalling windows, tried several antivirus, but they don't work. Hopefully someone will answer my message. So, here's the log.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 11:40:41 AM, on 12/4/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\igfxtray.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\WINDOWS\system32\igfxsrvc.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\WINDOWS\PLFSetL.exe<br />
C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\DAEMON Tools Lite\daemon.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\Program Files\AVG\AVG9\avgfws9.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgam.exe<br />
C:\Program Files\AVG\AVG9\avgnsx.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.daemon-search.com/startpage" target="_blank">http://www.daemon-search.com/startpage</a><br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll<br />
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [PLFSetL] C:\WINDOWS\PLFSetL.exe<br />
O4 - HKLM\..\Run: [Malware Defender] c:\program files\malware defender\malwaredefender.exe<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKLM\..\Run: [Prefs] C:\PROGRA~1\oDesk\oDeskLaunch.exe<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\K-Lite Codec Pack\QuickTime\QTTask.exe" -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"<br />
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll<br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgfws9.exe<br />
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe<br />
O23 - Service: Malware Defender Service (MalwareDefenderService) - TorchSoft - c:\program files\malware defender\mdservice.exe<br />
<br />
--<br />
End of file - 5560 bytes]]></content:encoded>
		</item>
	</channel>
</rss>