<?xml version="1.0" encoding="ISO-8859-1" ?>
<rss version="2.0">
<channel>
	<title>247fixes</title>
	<description>247fixes</description>
	<link>http://www.247fixes.com/forums/index.php</link>
	<pubDate>Tue, 09 Feb 2010 14:59:10 +0000</pubDate>
	<ttl>5</ttl>
	<item>
		<title>Hijackthis</title>
		<link>http://www.247fixes.com/forums/topic/6281-hijackthis/</link>
		<description><![CDATA[Logfile of HijackThis v1.99.1<br />
Scan saved at 2:24:46 PM, on 2/7/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Unable to get Internet Explorer version!<br />
<br />
Running processes:<br />
C:&#092;WINDOWS&#092;System32&#092;smss.exe<br />
C:&#092;WINDOWS&#092;system32&#092;winlogon.exe<br />
C:&#092;WINDOWS&#092;system32&#092;services.exe<br />
C:&#092;WINDOWS&#092;system32&#092;lsass.exe<br />
C:&#092;WINDOWS&#092;system32&#092;svchost.exe<br />
C:&#092;WINDOWS&#092;System32&#092;svchost.exe<br />
C:&#092;WINDOWS&#092;system32&#092;spoolsv.exe<br />
C:&#092;WINDOWS&#092;system32&#092;WgaTray.exe<br />
C:&#092;WINDOWS&#092;Explorer.EXE<br />
C:&#092;WINDOWS&#092;SOUNDMAN.EXE<br />
C:&#092;WINDOWS&#092;system32&#092;RUNDLL32.EXE<br />
C:&#092;Program Files&#092;SweetIM&#092;Messenger&#092;SweetIM.exe<br />
C:&#092;Program Files&#092;ESET&#092;ESET NOD32 Antivirus&#092;egui.exe<br />
C:&#092;WINDOWS&#092;system32&#092;ctfmon.exe<br />
C:&#092;Program Files&#092;Google&#092;GoogleToolbarNotifier&#092;GoogleToolbarNotifier.exe<br />
C:&#092;Program Files&#092;Application Updater&#092;ApplicationUpdater.exe<br />
C:&#092;Program Files&#092;ESET&#092;ESET NOD32 Antivirus&#092;ekrn.exe<br />
C:&#092;WINDOWS&#092;NCLAUNCH.EXe<br />
C:&#092;Program Files&#092;Windows Live&#092;Messenger&#092;msnmsgr.exe<br />
C:&#092;WINDOWS&#092;system32&#092;nvsvc32.exe<br />
C:&#092;WINDOWS&#092;system32&#092;PnkBstrA.exe<br />
C:&#092;WINDOWS&#092;system32&#092;PnkBstrB.exe<br />
C:&#092;Program Files&#092;Microsoft&#092;Search Enhancement Pack&#092;SeaPort&#092;SeaPort.exe<br />
C:&#092;Program Files&#092;Alcohol Soft&#092;Alcohol 120&#092;StarWind&#092;StarWindServiceAE.exe<br />
C:&#092;WINDOWS&#092;system32&#092;svchost.exe<br />
C:&#092;Program Files&#092;PC Connectivity Solution&#092;ServiceLayer.exe<br />
C:&#092;Program Files&#092;PC Connectivity Solution&#092;Transports&#092;NclUSBSrv.exe<br />
C:&#092;Program Files&#092;PC Connectivity Solution&#092;Transports&#092;NclRSSrv.exe<br />
C:&#092;Program Files&#092;Windows Live&#092;Contacts&#092;wlcomm.exe<br />
C:&#092;Program Files&#092;Mozilla Firefox&#092;firefox.exe<br />
C:&#092;Program Files&#092;HijackThis&#092;HijackThis.exe<br />
C:&#092;Program Files&#092;Skype&#092;Toolbars&#092;Shared&#092;SkypeNames.exe<br />
<br />
R0 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = <a href='http://www.daemon-search.com/startpage' class='bbc_url' title='External link' rel='nofollow'>http://www.daemon-search.com/startpage</a><br />
<br />
R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Window Title = &gt;&gt;&gt; 'Full Speed' Enabled &lt;&lt;&lt;<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:&#092;Program Files&#092;Yahoo!&#092;Companion&#092;Installs&#092;cpn&#092;yt.dll (file missing)<br />
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:&#092;Program Files&#092;SweetIM&#092;Toolbars&#092;Internet Explorer&#092;mgHelper.dll<br />
R3 - URLSearchHook: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:&#092;Program Files&#092;free-downloads.net&#092;tbfre0.dll<br />
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:&#092;Program Files&#092;Dealio Toolbar&#092;SearchSettings.dll<br />
O1 - Hosts: 80.96.239.15 l2authd.lineage2.com<br />
O1 - Hosts: 216.107.250.194 nprotect.lineage2.com<br />
O2 - BHO: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:&#092;Program Files&#092;Dealio Toolbar&#092;IE&#092;4.0.2&#092;dealioToolbarIE.dll<br />
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:&#092;Program Files&#092;Yahoo!&#092;Companion&#092;Installs&#092;cpn&#092;yt.dll (file missing)<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:&#092;Program Files&#092;Common Files&#092;Adobe&#092;Acrobat&#092;ActiveX&#092;AcroIEHelper.dll<br />
O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - (no file)<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:&#092;Program Files&#092;Common Files&#092;Adobe&#092;Acrobat&#092;ActiveX&#092;AcroIEHelperShim.dll<br />
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:&#092;Program Files&#092;AskBarDis&#092;bar&#092;bin&#092;askBar.dll<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:&#092;Program Files&#092;Microsoft&#092;Search Enhancement Pack&#092;Search Helper&#092;SEPsearchhelperie.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:&#092;Program Files&#092;Common Files&#092;Microsoft Shared&#092;Windows Live&#092;WindowsLiveLogin.dll<br />
O2 - BHO: Hotbar - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - (no file)<br />
O2 - BHO: Mario Forever Toolbar Helper - {A20854FD-DDB5-4931-8F76-D11EA2364D94} - (no file)<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:&#092;Program Files&#092;Google&#092;Google Toolbar&#092;GoogleToolbar.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:&#092;Program Files&#092;Google&#092;GoogleToolbarNotifier&#092;5.4.4525.1752&#092;swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:&#092;Program Files&#092;Google&#092;Google Toolbar&#092;Component&#092;fastsearch_A8904FB862BD9564.dll<br />
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:&#092;Program Files&#092;Dealio Toolbar&#092;SearchSettings.dll<br />
O2 - BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:&#092;Program Files&#092;free-downloads.net&#092;tbfre0.dll<br />
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:&#092;Program Files&#092;SweetIM&#092;Toolbars&#092;Internet Explorer&#092;mgToolbarIE.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:&#092;Program Files&#092;Yahoo!&#092;Companion&#092;Installs&#092;cpn&#092;yt.dll (file missing)<br />
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:&#092;Program Files&#092;SweetIM&#092;Toolbars&#092;Internet Explorer&#092;mgToolbarIE.dll<br />
O3 - Toolbar: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:&#092;Program Files&#092;free-downloads.net&#092;tbfre0.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:&#092;Program Files&#092;Google&#092;Google Toolbar&#092;GoogleToolbar.dll<br />
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:&#092;Program Files&#092;AskBarDis&#092;bar&#092;bin&#092;askBar.dll<br />
O3 - Toolbar: Hotbar - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - (no file)<br />
O3 - Toolbar: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:&#092;Program Files&#092;Dealio Toolbar&#092;IE&#092;4.0.2&#092;dealioToolbarIE.dll<br />
O4 - HKLM&#092;..&#092;Run: [DisplayTrayIcon] C:&#092;WINDOWS&#092;system32&#092;TrayIcon.exe<br />
O4 - HKLM&#092;..&#092;Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM&#092;..&#092;Run: [NvCplDaemon] RUNDLL32.EXE C:&#092;WINDOWS&#092;system32&#092;NvCpl.dll,NvStartup<br />
O4 - HKLM&#092;..&#092;Run: [SoundMan] SOUNDMAN.EXE<br />
O4 - HKLM&#092;..&#092;Run: [NvMediaCenter] RUNDLL32.EXE C:&#092;WINDOWS&#092;system32&#092;NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM&#092;..&#092;Run: [SweetIM] C:&#092;Program Files&#092;SweetIM&#092;Messenger&#092;SweetIM.exe<br />
O4 - HKLM&#092;..&#092;Run: [Adobe Reader Speed Launcher] "C:&#092;Program Files&#092;Adobe&#092;Reader 9.0&#092;Reader&#092;Reader_sl.exe"<br />
O4 - HKLM&#092;..&#092;Run: [RivaTunerStartupDaemon] "C:&#092;Program Files&#092;RivaTuner v2.24&#092;RivaTuner.exe" /S<br />
O4 - HKLM&#092;..&#092;Run: [Lescos Warcraft Toolkit] "C:&#092;DOCUME~1&#092;kwstas&#092;LOCALS~1&#092;Temp&#092;Temporary Directory 2 for LWT.zip&#092;LWT.exe" -minimized<br />
O4 - HKLM&#092;..&#092;Run: [NeroCheck] C:&#092;WINDOWS&#092;system32&#092;NeroCheck.exe<br />
O4 - HKLM&#092;..&#092;Run: [SearchSettings] C:&#092;Program Files&#092;Dealio Toolbar&#092;SearchSettings.exe<br />
O4 - HKLM&#092;..&#092;Run: [egui] "C:&#092;Program Files&#092;ESET&#092;ESET NOD32 Antivirus&#092;egui.exe" /hide /waitservice<br />
O4 - HKCU&#092;..&#092;Run: [ctfmon.exe] C:&#092;WINDOWS&#092;system32&#092;ctfmon.exe<br />
O4 - HKCU&#092;..&#092;Run: [swg] "C:&#092;Program Files&#092;Google&#092;GoogleToolbarNotifier&#092;GoogleToolbarNotifier.exe"<br />
O4 - HKCU&#092;..&#092;Run: [AlcoholAutomount] "C:&#092;Program Files&#092;Alcohol Soft&#092;Alcohol 120&#092;axcmd.exe" /automount<br />
O4 - HKCU&#092;..&#092;Run: [NCLaunch] C:&#092;WINDOWS&#092;NCLAUNCH.EXe<br />
O4 - HKCU&#092;..&#092;Run: [MessengerPlus3] "C:&#092;Program Files&#092;MessengerPlus! 3&#092;MsgPlus.exe" /WinStart<br />
O4 - HKCU&#092;..&#092;Run: [WeatherDPA] "C:&#092;Program Files&#092;Hotbar&#092;bin&#092;11.0.78.0&#092;Weather.exe" -auto<br />
O4 - HKCU&#092;..&#092;Run: [Skype] "C:&#092;Program Files&#092;Skype&#092;Phone&#092;Skype.exe" /nosplash /minimized<br />
O4 - HKCU&#092;..&#092;Run: [PC Suite Tray] "C:&#092;Program Files&#092;Nokia&#092;Nokia PC Suite 7&#092;PCSuite.exe" -onlytray<br />
O4 - HKCU&#092;..&#092;Run: [DAEMON Tools Lite] "C:&#092;Program Files&#092;DAEMON Tools Lite&#092;daemon.exe"<br />
O4 - HKCU&#092;..&#092;Run: [msnmsgr] "C:&#092;Program Files&#092;Windows Live&#092;Messenger&#092;msnmsgr.exe" /background<br />
O4 - Startup: PowerReg Scheduler.exe<br />
O4 - Startup: Stardock ObjectDock.lnk = C:&#092;Program Files&#092;Stardock&#092;ObjectDock&#092;ObjectDock.exe<br />
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:&#092;PROGRA~1&#092;MICROS~3&#092;Office12&#092;EXCEL.EXE/3000<br />
O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:&#092;Program Files&#092;ShoppingReport&#092;Bin&#092;2.6.58&#092;ShoppingReport.dll (file missing)<br />
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:&#092;Program Files&#092;ShoppingReport&#092;Bin&#092;2.6.58&#092;ShoppingReport.dll (file missing)<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%&#092;Network Diagnostic&#092;xpnetdiag.exe (file missing)<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%&#092;Network Diagnostic&#092;xpnetdiag.exe (file missing)<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:&#092;Program Files&#092;Messenger&#092;msmsgs.exe (file missing)<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:&#092;Program Files&#092;Messenger&#092;msmsgs.exe (file missing)<br />
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - <a href='http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab' class='bbc_url' title='External link' rel='nofollow'>http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab</a><br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:&#092;Program Files&#092;Yahoo!&#092;Common&#092;yinsthelper.dll<br />
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - <a href='http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab' class='bbc_url' title='External link' rel='nofollow'>http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab</a><br />
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - <a href='http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab' class='bbc_url' title='External link' rel='nofollow'>http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab</a><br />
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:&#092;PROGRA~1&#092;Windows Live&#092;Messenger&#092;msgrapp.14.0.8089.0726.dll<br />
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:&#092;PROGRA~1&#092;Windows Live&#092;Messenger&#092;msgrapp.14.0.8089.0726.dll<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:&#092;PROGRA~1&#092;COMMON~1&#092;Skype&#092;Skype4COM.dll<br />
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:&#092;Program Files&#092;Google&#092;Google Toolbar&#092;Component&#092;fastsearch_A8904FB862BD9564.dll<br />
O20 - Winlogon Notify: dimsntfy - %SystemRoot%&#092;System32&#092;dimsntfy.dll (file missing)<br />
O20 - Winlogon Notify: WgaLogon - C:&#092;WINDOWS&#092;SYSTEM32&#092;WgaLogon.dll<br />
O23 - Service: Application Updater - Spigot, Inc. - C:&#092;Program Files&#092;Application Updater&#092;ApplicationUpdater.exe<br />
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:&#092;Program Files&#092;ESET&#092;ESET NOD32 Antivirus&#092;EHttpSrv.exe<br />
O23 - Service: ESET Service (ekrn) - ESET - C:&#092;Program Files&#092;ESET&#092;ESET NOD32 Antivirus&#092;ekrn.exe<br />
O23 - Service: Google Update Service (gupdate1c98c95d0656df6) (gupdate1c98c95d0656df6) - Unknown owner - C:&#092;Program Files&#092;Google&#092;Update&#092;GoogleUpdate.exe" /svc (file missing)<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:&#092;Program Files&#092;Google&#092;Common&#092;Google Updater&#092;GoogleUpdaterService.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:&#092;WINDOWS&#092;system32&#092;nvsvc32.exe<br />
O23 - Service: PnkBstrA - Unknown owner - C:&#092;WINDOWS&#092;system32&#092;PnkBstrA.exe<br />
O23 - Service: PnkBstrB - Unknown owner - C:&#092;WINDOWS&#092;system32&#092;PnkBstrB.exe<br />
O23 - Service: ServiceLayer - Nokia - C:&#092;Program Files&#092;PC Connectivity Solution&#092;ServiceLayer.exe<br />
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:&#092;Program Files&#092;Alcohol Soft&#092;Alcohol 120&#092;StarWind&#092;StarWindServiceAE.exe]]></description>
		<pubDate>Sun, 07 Feb 2010 12:49:37 +0000</pubDate>
		<guid>http://www.247fixes.com/forums/topic/6281-hijackthis/</guid>
	</item>
	<item>
		<title>Happy Birthday Artellos, Kern</title>
		<link>http://www.247fixes.com/forums/topic/6277-happy-birthday-artellos-kern/</link>
		<description><![CDATA[Hope you have a great day. <img src='http://www.247fixes.com/forums/public/style_emoticons/default/biggrin.gif' class='bbc_emoticon' alt=':D' /> <img src='http://www.247fixes.com/forums/public/style_emoticons/default/biggrin.gif' class='bbc_emoticon' alt=':D' />]]></description>
		<pubDate>Sat, 06 Feb 2010 16:15:16 +0000</pubDate>
		<guid>http://www.247fixes.com/forums/topic/6277-happy-birthday-artellos-kern/</guid>
	</item>
	<item>
		<title>Happy Birthday Robroy, Boopme!</title>
		<link>http://www.247fixes.com/forums/topic/6275-happy-birthday-robroy-boopme/</link>
		<description>Hope you are having a great day.</description>
		<pubDate>Fri, 05 Feb 2010 23:10:33 +0000</pubDate>
		<guid>http://www.247fixes.com/forums/topic/6275-happy-birthday-robroy-boopme/</guid>
	</item>
	<item>
		<title>Computer Stuck In Loop</title>
		<link>http://www.247fixes.com/forums/topic/6274-computer-stuck-in-loop/</link>
		<description><![CDATA[I was working on my friends computer which was highly infected. I used several programs to clean it and it seemed to be doing alright except for a few minor things like a few programs not wanting to uninstall and the internet not connecting. I was trying to fix the internet and physically entered the ip and dns address since it didn't seem like it was doing it automatically (wireless). It said it was connected but when trying either IE or Firefox, it would not load any pages. I decided to try to put the computer into safe mode for the first time w/network access to see if this would work.<br />
<br />
I went into msconfig/boot and told it to boot into safe mode with network access. Computer shuts down and restarts saying it could not start properly and gave me a choice to start normally or in safe mode again. I tried both options and the computer would start to boot then reset back to the startup option screen...<br />
<br />
Mind you the computer had been restarted more than once successfully although there seemed to be a file missing from windows. It would state something like skipping check. The file ended something like system32/chk... something like that. I was going to try to repair this with a windows cd but have yet to find it so I haven't done it yet...<br />
<br />
Is there anything that can be done?<br />
<br />
<br />
Thanks]]></description>
		<pubDate>Fri, 05 Feb 2010 22:15:00 +0000</pubDate>
		<guid>http://www.247fixes.com/forums/topic/6274-computer-stuck-in-loop/</guid>
	</item>
	<item>
		<title>Help With Log</title>
		<link>http://www.247fixes.com/forums/topic/6262-help-with-log/</link>
		<description><![CDATA[I have noticed recently that my HP Pavillion laptop is slow to boot up.  It seems that it doesn't get to normal speed until Trend Micro antivirus software has loaded...often 2-3 minutes after turning the laptop on.  From my limited research, I keep seeing a theme about checking the hijack log.   I have already performed the disk clean up and degrag functions, and have scanned with Trend recently.<br />
<br />
here is my log...not sure if this is what you need:<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 10:13:25 PM, on 2/4/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:&#092;WINDOWS&#092;System32&#092;smss.exe<br />
C:&#092;WINDOWS&#092;system32&#092;winlogon.exe<br />
C:&#092;WINDOWS&#092;system32&#092;services.exe<br />
C:&#092;WINDOWS&#092;system32&#092;lsass.exe<br />
C:&#092;WINDOWS&#092;system32&#092;svchost.exe<br />
C:&#092;WINDOWS&#092;System32&#092;svchost.exe<br />
C:&#092;WINDOWS&#092;system32&#092;spoolsv.exe<br />
C:&#092;WINDOWS&#092;Explorer.EXE<br />
C:&#092;WINDOWS&#092;ehome&#092;ehtray.exe<br />
C:&#092;Program Files&#092;hpq&#092;HP Wireless Assistant&#092;HP Wireless Assistant.exe<br />
C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;jusched.exe<br />
C:&#092;WINDOWS&#092;system32&#092;igfxtray.exe<br />
C:&#092;WINDOWS&#092;system32&#092;hkcmd.exe<br />
C:&#092;WINDOWS&#092;system32&#092;igfxpers.exe<br />
C:&#092;Program Files&#092;Synaptics&#092;SynTP&#092;SynTPEnh.exe<br />
C:&#092;Program Files&#092;HP&#092;QuickPlay&#092;QPService.exe<br />
C:&#092;Program Files&#092;Common Files&#092;InstallShield&#092;UpdateService&#092;issch.exe<br />
C:&#092;Program Files&#092;Hewlett-Packard&#092;HP Quick Launch Buttons&#092;QlbCtrl.exe<br />
C:&#092;Program Files&#092;Ahead&#092;ODD Toolkit&#092;DVDTray.exe<br />
C:&#092;Program Files&#092;Pinnacle&#092;Shared Files&#092;Programs&#092;USBTip&#092;USBTip.exe<br />
C:&#092;Program Files&#092;Trend Micro&#092;Internet Security&#092;UfSeAgnt.exe<br />
C:&#092;Program Files&#092;Hp&#092;HP Software Update&#092;HPWuSchd2.exe<br />
C:&#092;Program Files&#092;iTunes&#092;iTunesHelper.exe<br />
C:&#092;WINDOWS&#092;system32&#092;ctfmon.exe<br />
C:&#092;Program Files&#092;TomTom HOME 2&#092;TomTomHOMERunner.exe<br />
C:&#092;Program Files&#092;Trend Micro&#092;Internet Security&#092;TMAS_OE&#092;TMAS_OEMon.exe<br />
C:&#092;Program Files&#092;Hewlett-Packard&#092;HP Pavilion Webcam&#092;HPWebcam.exe<br />
C:&#092;Program Files&#092;Western Digital&#092;WD SmartWare&#092;WD Drive Manager&#092;WDDMStatus.exe<br />
C:&#092;Program Files&#092;Western Digital&#092;WD SmartWare&#092;Front Parlor&#092;WDSmartWare.exe<br />
C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;bin&#092;hpqimzone.exe<br />
C:&#092;Program Files&#092;Outlook Express&#092;msimn.exe<br />
C:&#092;Program Files&#092;Common Files&#092;Apple&#092;Mobile Device Support&#092;bin&#092;AppleMobileDeviceService.exe<br />
C:&#092;Program Files&#092;Bonjour&#092;mDNSResponder.exe<br />
C:&#092;WINDOWS&#092;eHome&#092;ehRecvr.exe<br />
C:&#092;WINDOWS&#092;eHome&#092;ehSched.exe<br />
C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;jqs.exe<br />
C:&#092;Program Files&#092;Common Files&#092;LightScribe&#092;LSSrvc.exe<br />
C:&#092;Program Files&#092;Pinnacle&#092;MediaServer&#092;Microsoft SQL Server&#092;MSSQL$PINNACLESYS&#092;Binn&#092;sqlservr.exe<br />
C:&#092;WINDOWS&#092;system32&#092;HPZipm12.exe<br />
C:&#092;Program Files&#092;Trend Micro&#092;Internet Security&#092;SfCtlCom.exe<br />
C:&#092;WINDOWS&#092;system32&#092;svchost.exe<br />
C:&#092;Program Files&#092;TomTom HOME 2&#092;TomTomHOMEService.exe<br />
C:&#092;Program Files&#092;Western Digital&#092;WD SmartWare&#092;WD Drive Manager&#092;WDDMService.exe<br />
C:&#092;Program Files&#092;Western Digital&#092;WD SmartWare&#092;Front Parlor&#092;WDSmartWareBackgroundService.exe<br />
C:&#092;Program Files&#092;Xobni&#092;XobniService.exe<br />
C:&#092;Program Files&#092;Hewlett-Packard&#092;Shared&#092;hpqwmiex.exe<br />
C:&#092;WINDOWS&#092;system32&#092;mqsvc.exe<br />
C:&#092;WINDOWS&#092;system32&#092;mqtgsvc.exe<br />
c:&#092;program files&#092;pinnacle&#092;shared files&#092;programs&#092;mediaserver&#092;pmshost.exe<br />
C:&#092;Program Files&#092;iPod&#092;bin&#092;iPodService.exe<br />
C:&#092;WINDOWS&#092;system32&#092;dllhost.exe<br />
C:&#092;WINDOWS&#092;eHome&#092;ehmsas.exe<br />
C:&#092;Program Files&#092;Trend Micro&#092;Internet Security&#092;TMAS_OE&#092;TMAS_OE.exe<br />
C:&#092;WINDOWS&#092;System32&#092;svchost.exe<br />
C:&#092;Program Files&#092;Messenger&#092;msmsgs.exe<br />
C:&#092;Program Files&#092;Internet Explorer&#092;iexplore.exe<br />
C:&#092;Program Files&#092;Internet Explorer&#092;iexplore.exe<br />
C:&#092;Program Files&#092;Trend Micro&#092;Internet Security&#092;TmProxy.exe<br />
C:&#092;Program Files&#092;Trend Micro&#092;Internet Security&#092;TmPfw.exe<br />
C:&#092;Program Files&#092;Trend Micro&#092;BM&#092;TMBMSRV.exe<br />
C:&#092;Program Files&#092;Internet Explorer&#092;iexplore.exe<br />
C:&#092;Program Files&#092;Trend Micro&#092;Internet Security&#092;UfNavi.exe<br />
C:&#092;Documents and Settings&#092;test&#092;Temporary Internet Files&#092;Content.IE5&#092;NIYDZ8CJ&#092;HijackThis[1].exe<br />
<br />
R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Bar = <a href='http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=pavilion&pf=laptop' class='bbc_url' title='External link' rel='nofollow'>http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=pavilion&pf=laptop</a><br />
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Page_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=69157' class='bbc_url' title='External link' rel='nofollow'>http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Search_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='External link' rel='nofollow'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='External link' rel='nofollow'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = <a href='http://go.microsoft.com/fwlink/?LinkId=69157' class='bbc_url' title='External link' rel='nofollow'>http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Connection Wizard,ShellNext = <a href='http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop' class='bbc_url' title='External link' rel='nofollow'>http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop</a><br />
R1 - HKCU&#092;Software&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Internet Settings,ProxyOverride = *.local<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:&#092;Program Files&#092;Adobe&#092;Acrobat 7.0&#092;ActiveX&#092;AcroIEHelper.dll (file missing)<br />
O2 - BHO: Java&#153; Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;ssv.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:&#092;Program Files&#092;Google&#092;GoogleToolbarNotifier&#092;5.1.1309.3572&#092;swg.dll<br />
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:&#092;Program Files&#092;MSN&#092;Toolbar&#092;3.0.0988.2&#092;msneshellx.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:&#092;Program Files&#092;Java&#092;jre6&#092;lib&#092;deploy&#092;jqs&#092;ie&#092;jqs_plugin.dll<br />
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:&#092;Program Files&#092;MSN&#092;Toolbar&#092;3.0.0988.2&#092;msneshellx.dll<br />
O4 - HKLM&#092;..&#092;Run: [ehTray] C:&#092;WINDOWS&#092;ehome&#092;ehtray.exe<br />
O4 - HKLM&#092;..&#092;Run: [hpWirelessAssistant] C:&#092;Program Files&#092;hpq&#092;HP Wireless Assistant&#092;HP Wireless Assistant.exe<br />
O4 - HKLM&#092;..&#092;Run: [SunJavaUpdateSched] "C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;jusched.exe"<br />
O4 - HKLM&#092;..&#092;Run: [igfxtray] C:&#092;WINDOWS&#092;system32&#092;igfxtray.exe<br />
O4 - HKLM&#092;..&#092;Run: [igfxhkcmd] C:&#092;WINDOWS&#092;system32&#092;hkcmd.exe<br />
O4 - HKLM&#092;..&#092;Run: [igfxpers] C:&#092;WINDOWS&#092;system32&#092;igfxpers.exe<br />
O4 - HKLM&#092;..&#092;Run: [MsmqIntCert] regsvr32 /s mqrt.dll<br />
O4 - HKLM&#092;..&#092;Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe<br />
O4 - HKLM&#092;..&#092;Run: [SynTPEnh] C:&#092;Program Files&#092;Synaptics&#092;SynTP&#092;SynTPEnh.exe<br />
O4 - HKLM&#092;..&#092;Run: [QPService] "C:&#092;Program Files&#092;HP&#092;QuickPlay&#092;QPService.exe"<br />
O4 - HKLM&#092;..&#092;Run: [ISUSPM Startup] "C:&#092;Program Files&#092;Common Files&#092;InstallShield&#092;UpdateService&#092;isuspm.exe" -startup<br />
O4 - HKLM&#092;..&#092;Run: [ISUSScheduler] "C:&#092;Program Files&#092;Common Files&#092;InstallShield&#092;UpdateService&#092;issch.exe" -start<br />
O4 - HKLM&#092;..&#092;Run: [QlbCtrl] %ProgramFiles%&#092;Hewlett-Packard&#092;HP Quick Launch Buttons&#092;QlbCtrl.exe /Start<br />
O4 - HKLM&#092;..&#092;Run: [Cpqset] C:&#092;Program Files&#092;Hewlett-Packard&#092;Default Settings&#092;cpqset.exe<br />
O4 - HKLM&#092;..&#092;Run: [RecGuard] C:&#092;Windows&#092;SMINST&#092;RecGuard.exe<br />
O4 - HKLM&#092;..&#092;Run: [Reminder] C:&#092;Windows&#092;CREATOR&#092;Remind_XP.exe<br />
O4 - HKLM&#092;..&#092;Run: [NeroFilterCheck] C:&#092;WINDOWS&#092;system32&#092;NeroCheck.exe<br />
O4 - HKLM&#092;..&#092;Run: [DVDTray] C:&#092;Program Files&#092;Ahead&#092;ODD Toolkit&#092;DVDTray.exe<br />
O4 - HKLM&#092;..&#092;Run: [USB2Check] RUNDLL32.EXE "C:&#092;WINDOWS&#092;system32&#092;PCLECoInst.dll",CheckUSBController<br />
O4 - HKLM&#092;..&#092;Run: [USBToolTip] "C:&#092;Program Files&#092;Pinnacle&#092;Shared Files&#092;&#092;Programs&#092;USBTip&#092;USBTip.exe"<br />
O4 - HKLM&#092;..&#092;Run: [AppleSyncNotifier] C:&#092;Program Files&#092;Common Files&#092;Apple&#092;Mobile Device Support&#092;bin&#092;AppleSyncNotifier.exe<br />
O4 - HKLM&#092;..&#092;Run: [UfSeAgnt.exe] "C:&#092;Program Files&#092;Trend Micro&#092;Internet Security&#092;UfSeAgnt.exe"<br />
O4 - HKLM&#092;..&#092;Run: [HP Software Update] C:&#092;Program Files&#092;Hp&#092;HP Software Update&#092;HPWuSchd2.exe<br />
O4 - HKLM&#092;..&#092;Run: [QuickTime Task] "C:&#092;Program Files&#092;QuickTime&#092;qttask.exe" -atboottime<br />
O4 - HKLM&#092;..&#092;Run: [iTunesHelper] "C:&#092;Program Files&#092;iTunes&#092;iTunesHelper.exe"<br />
O4 - HKCU&#092;..&#092;Run: [ctfmon.exe] C:&#092;WINDOWS&#092;system32&#092;ctfmon.exe<br />
O4 - HKCU&#092;..&#092;Run: [TomTomHOME.exe] "C:&#092;Program Files&#092;TomTom HOME 2&#092;TomTomHOMERunner.exe"<br />
O4 - HKCU&#092;..&#092;Run: [NBJ] "C:&#092;Program Files&#092;Ahead&#092;Nero BackItUp&#092;NBJ.exe"<br />
O4 - HKCU&#092;..&#092;Run: [OE] C:&#092;Program Files&#092;Trend Micro&#092;Internet Security&#092;TMAS_OE&#092;TMAS_OEMon.exe<br />
O4 - HKUS&#092;S-1-5-19&#092;..&#092;Run: [OE] C:&#092;Program Files&#092;Trend Micro&#092;Internet Security&#092;TMAS_OE&#092;TMAS_OEMon.exe (User 'LOCAL SERVICE')<br />
O4 - HKUS&#092;S-1-5-20&#092;..&#092;Run: [OE] C:&#092;Program Files&#092;Trend Micro&#092;Internet Security&#092;TMAS_OE&#092;TMAS_OEMon.exe (User 'NETWORK SERVICE')<br />
O4 - HKUS&#092;S-1-5-18&#092;..&#092;Run: [OE] C:&#092;Program Files&#092;Trend Micro&#092;Internet Security&#092;TMAS_OE&#092;TMAS_OEMon.exe (User 'SYSTEM')<br />
O4 - HKUS&#092;.DEFAULT&#092;..&#092;Run: [OE] C:&#092;Program Files&#092;Trend Micro&#092;Internet Security&#092;TMAS_OE&#092;TMAS_OEMon.exe (User 'Default user')<br />
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:&#092;Program Files&#092;Vongo&#092;Tray.exe (User 'Default user')<br />
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:&#092;Program Files&#092;Adobe&#092;Acrobat 7.0&#092;Reader&#092;reader_sl.exe<br />
O4 - Global Startup: HP Pavilion Webcam Tray Icon.lnk = C:&#092;Program Files&#092;Hewlett-Packard&#092;HP Pavilion Webcam&#092;HPWebcam.exe<br />
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;bin&#092;hpqthb08.exe<br />
O4 - Global Startup: WDDMStatus.lnk = C:&#092;Program Files&#092;Western Digital&#092;WD SmartWare&#092;WD Drive Manager&#092;WDDMStatus.exe<br />
O4 - Global Startup: WDSmartWare.lnk = C:&#092;Program Files&#092;Western Digital&#092;WD SmartWare&#092;Front Parlor&#092;WDSmartWare.exe<br />
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:&#092;PROGRA~1&#092;MICROS~4&#092;OFFICE11&#092;EXCEL.EXE/3000<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:&#092;PROGRA~1&#092;MICROS~4&#092;OFFICE11&#092;REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:&#092;WINDOWS&#092;Network Diagnostic&#092;xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:&#092;WINDOWS&#092;Network Diagnostic&#092;xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:&#092;Program Files&#092;Messenger&#092;msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:&#092;Program Files&#092;Messenger&#092;msmsgs.exe<br />
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop<br />
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - <a href='http://www.comcastsupport.com/OneClickFix/tgctlsr.cab' class='bbc_url' title='External link' rel='nofollow'>http://www.comcastsupport.com/OneClickFix/tgctlsr.cab</a><br />
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - <a href='https://ra.53.com/CitrixSessionInit/ICAWEB/en/ica32/icaweb.cab' class='bbc_url' title='External link' rel='nofollow'>https://ra.53.com/CitrixSessionInit/ICAWEB/en/ica32/icaweb.cab</a><br />
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - <a href='http://www2.snapfish.com/SnapfishActivia.cab' class='bbc_url' title='External link' rel='nofollow'>http://www2.snapfish.com/SnapfishActivia.cab</a><br />
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - <a href='http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.3.cab' class='bbc_url' title='External link' rel='nofollow'>http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.3.cab</a><br />
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - <a href='http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab' class='bbc_url' title='External link' rel='nofollow'>http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href='http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1197830139984' class='bbc_url' title='External link' rel='nofollow'>http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1197830139984</a><br />
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - <a href='https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab' class='bbc_url' title='External link' rel='nofollow'>https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab</a><br />
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - <a href='http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab' class='bbc_url' title='External link' rel='nofollow'>http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href='http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab' class='bbc_url' title='External link' rel='nofollow'>http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab</a><br />
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:&#092;Program Files&#092;Hewlett-Packard&#092;HP Quick Launch Buttons&#092;AddFiltr.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:&#092;Program Files&#092;Common Files&#092;Apple&#092;Mobile Device Support&#092;bin&#092;AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:&#092;Program Files&#092;Bonjour&#092;mDNSResponder.exe<br />
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:&#092;Program Files&#092;Google&#092;Update&#092;GoogleUpdate.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:&#092;Program Files&#092;Google&#092;Common&#092;Google Updater&#092;GoogleUpdaterService.exe<br />
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:&#092;Program Files&#092;Hewlett-Packard&#092;Shared&#092;hpqwmiex.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:&#092;Program Files&#092;Common Files&#092;InstallShield&#092;Driver&#092;11&#092;Intel 32&#092;IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:&#092;Program Files&#092;iPod&#092;bin&#092;iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;jqs.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:&#092;Program Files&#092;Common Files&#092;LightScribe&#092;LSSrvc.exe<br />
O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - c:&#092;program files&#092;pinnacle&#092;shared files&#092;programs&#092;mediaserver&#092;pmshost.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:&#092;WINDOWS&#092;system32&#092;HPZipm12.exe<br />
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:&#092;Program Files&#092;Trend Micro&#092;Internet Security&#092;SfCtlCom.exe<br />
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:&#092;Program Files&#092;Trend Micro&#092;BM&#092;TMBMSRV.exe<br />
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:&#092;Program Files&#092;Trend Micro&#092;Internet Security&#092;TmPfw.exe<br />
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:&#092;Program Files&#092;Trend Micro&#092;Internet Security&#092;TmProxy.exe<br />
O23 - Service: TomTomHOMEService - TomTom - C:&#092;Program Files&#092;TomTom HOME 2&#092;TomTomHOMEService.exe<br />
O23 - Service: WD SmartWare Drive Manager (WDDMService) - WDC - C:&#092;Program Files&#092;Western Digital&#092;WD SmartWare&#092;WD Drive Manager&#092;WDDMService.exe<br />
O23 - Service: WD SmartWare Background Service (WDSmartWareBackgroundService) - Memeo - C:&#092;Program Files&#092;Western Digital&#092;WD SmartWare&#092;Front Parlor&#092;WDSmartWareBackgroundService.exe<br />
O23 - Service: XobniService - Xobni Corporation - C:&#092;Program Files&#092;Xobni&#092;XobniService.exe<br />
<br />
--<br />
End of file - 13641 bytes<br />
<br />
<br />
Thanks!]]></description>
		<pubDate>Fri, 05 Feb 2010 03:44:52 +0000</pubDate>
		<guid>http://www.247fixes.com/forums/topic/6262-help-with-log/</guid>
	</item>
	<item>
		<title>Help Please!</title>
		<link>http://www.247fixes.com/forums/topic/6254-help-please/</link>
		<description><![CDATA[Can anyone check out this Hijackthis log, because my computer has been running at an average of 80-90% CPU usage; even after I shut down all background programs, and I can't figure out what's wrong.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.3 (BETA)<br />
Scan saved at 12:51:58 AM, on 2/4/2010<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18882)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:&#092;Program Files (x86)&#092;Pando Networks&#092;Media Booster&#092;PMB.exe<br />
C:&#092;Program Files (x86)&#092;PCSecurityShield&#092;The Shield Deluxe 2008&#092;avp.exe<br />
C:&#092;Program Files (x86)&#092;iTunes&#092;iTunesHelper.exe<br />
C:&#092;Program Files (x86)&#092;Common Files&#092;Nikon&#092;Monitor&#092;NkMonitor.exe<br />
C:&#092;Program Files (x86)&#092;Java&#092;jre6&#092;bin&#092;jusched.exe<br />
C:&#092;Program Files (x86)&#092;AIM6&#092;aolsoftware.exe<br />
C:&#092;Program Files (x86)&#092;TrendMicro&#092;HiJackThis&#092;HiJackThis.exe<br />
C:&#092;Program Files (x86)&#092;Mozilla Firefox&#092;firefox.exe<br />
<br />
R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='External link' rel='nofollow'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = <a href='http://google.com/' class='bbc_url' title='External link' rel='nofollow'>http://google.com/</a><br />
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Page_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=69157' class='bbc_url' title='External link' rel='nofollow'>http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Search_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='External link' rel='nofollow'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='External link' rel='nofollow'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = <a href='http://go.microsoft.com/fwlink/?LinkId=69157' class='bbc_url' title='External link' rel='nofollow'>http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Search,SearchAssistant = <br />
R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Search,CustomizeSearch = <br />
R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Local Page = C:&#092;Windows&#092;SysWOW64&#092;blank.htm<br />
R0 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Toolbar,LinksFolderName = <br />
R3 - URLSearchHook: AIM Toolbar Search Class - {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:&#092;Program Files (x86)&#092;AIM Toolbar&#092;aimtb.dll<br />
F2 - REG:system.ini: UserInit=userinit.exe<br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:&#092;Program Files (x86)&#092;Common Files&#092;Adobe&#092;Acrobat&#092;ActiveX&#092;AcroIEHelperShim.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:&#092;Program Files (x86)&#092;Google&#092;GoogleToolbarNotifier&#092;5.2.4204.1700&#092;swg.dll<br />
O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:&#092;Program Files (x86)&#092;AIM Toolbar&#092;aimtb.dll<br />
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:&#092;Program Files (x86)&#092;Ask.com&#092;GenericAskToolbar.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:&#092;Program Files (x86)&#092;Java&#092;jre6&#092;bin&#092;jp2ssv.dll<br />
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:&#092;Program Files (x86)&#092;AIM Toolbar&#092;aimtb.dll<br />
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:&#092;Program Files (x86)&#092;Ask.com&#092;GenericAskToolbar.dll<br />
O4 - HKLM&#092;..&#092;Run: [StartCCC] "C:&#092;Program Files (x86)&#092;ATI Technologies&#092;ATI.ACE&#092;Core-Static&#092;CLIStart.exe" MSRun<br />
O4 - HKLM&#092;..&#092;Run: [DelReg] C:&#092;Program Files (x86)&#092;MSI&#092;GreenPowerCenterII&#092;DelReg.exe<br />
O4 - HKLM&#092;..&#092;Run: [JMB36X IDE Setup] C:&#092;Windows&#092;RaidTool&#092;xInsIDE.exe<br />
O4 - HKLM&#092;..&#092;Run: [AVP] "C:&#092;Program Files (x86)&#092;PCSecurityShield&#092;The Shield Deluxe 2008&#092;avp.exe"<br />
O4 - HKLM&#092;..&#092;Run: [Adobe Reader Speed Launcher] "C:&#092;Program Files (x86)&#092;Adobe&#092;Reader 9.0&#092;Reader&#092;Reader_sl.exe"<br />
O4 - HKLM&#092;..&#092;Run: [PWRISOVM.EXE] "C:&#092;Program Files (x86)&#092;PowerISO&#092;PWRISOVM.EXE"<br />
O4 - HKLM&#092;..&#092;Run: [AppleSyncNotifier] C:&#092;Program Files (x86)&#092;Common Files&#092;Apple&#092;Mobile Device Support&#092;bin&#092;AppleSyncNotifier.exe<br />
O4 - HKLM&#092;..&#092;Run: [AdobeCS4ServiceManager] "C:&#092;Program Files (x86)&#092;Common Files&#092;Adobe&#092;CS4ServiceManager&#092;CS4ServiceManager.exe" -launchedbylogin<br />
O4 - HKLM&#092;..&#092;Run: [QuickTime Task] "C:&#092;Program Files (x86)&#092;QuickTime&#092;QTTask.exe" -atboottime<br />
O4 - HKLM&#092;..&#092;Run: [iTunesHelper] "C:&#092;Program Files (x86)&#092;iTunes&#092;iTunesHelper.exe"<br />
O4 - HKLM&#092;..&#092;Run: [Google Updater] "C:&#092;Program Files (x86)&#092;Google&#092;Google Updater&#092;GoogleUpdater.exe" -systray -startup<br />
O4 - HKLM&#092;..&#092;Run: [Google Desktop Search] "C:&#092;Program Files (x86)&#092;Google&#092;Google Desktop Search&#092;GoogleDesktop.exe" /startup<br />
O4 - HKLM&#092;..&#092;Run: [Nikon Transfer Monitor] C:&#092;Program Files (x86)&#092;Common Files&#092;Nikon&#092;Monitor&#092;NkMonitor.exe<br />
O4 - HKLM&#092;..&#092;Run: [amd_dc_opt] C:&#092;Program Files (x86)&#092;AMD&#092;Dual-Core Optimizer&#092;amd_dc_opt.exe<br />
O4 - HKLM&#092;..&#092;Run: [SunJavaUpdateSched] "C:&#092;Program Files (x86)&#092;Java&#092;jre6&#092;bin&#092;jusched.exe"<br />
O4 - HKCU&#092;..&#092;Run: [Sidebar] C:&#092;Program Files&#092;Windows Sidebar&#092;sidebar.exe /autoRun<br />
O4 - HKCU&#092;..&#092;Run: [Pando Media Booster] C:&#092;Program Files (x86)&#092;Pando Networks&#092;Media Booster&#092;PMB.exe<br />
O4 - HKCU&#092;..&#092;Run: [uTorrent] "C:&#092;Program Files (x86)&#092;uTorrent&#092;uTorrent.exe"<br />
O4 - HKCU&#092;..&#092;Run: [AlcoholAutomount] "C:&#092;Program Files (x86)&#092;Alcohol Soft&#092;Alcohol 120&#092;axcmd.exe" /automount<br />
O4 - HKCU&#092;..&#092;Run: [Aim6] "C:&#092;Program Files (x86)&#092;AIM6&#092;aim6.exe" /d locale=en-US ee://aol/imApp<br />
O4 - HKUS&#092;S-1-5-19&#092;..&#092;Run: [Sidebar] %ProgramFiles%&#092;Windows Sidebar&#092;Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS&#092;S-1-5-19&#092;..&#092;Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS&#092;S-1-5-20&#092;..&#092;Run: [Sidebar] %ProgramFiles%&#092;Windows Sidebar&#092;Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - Startup: MagicDisc.lnk = C:&#092;Program Files (x86)&#092;MagicDisc&#092;MagicDisc.exe<br />
O4 - Global Startup: SetPointII.lnk = ?<br />
O8 - Extra context menu item: &AIM Toolbar Search - C:&#092;ProgramData&#092;AIM Toolbar&#092;ieToolbar&#092;resources&#092;en-US&#092;local&#092;search.html<br />
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:&#092;Windows&#092;system32&#092;GPhotos.scr/200<br />
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:&#092;PROGRA~2&#092;MICROS~1&#092;Office12&#092;EXCEL.EXE/3000<br />
O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:&#092;Program Files (x86)&#092;AIM Toolbar&#092;aimtb.dll<br />
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:&#092;Program Files (x86)&#092;PCSecurityShield&#092;The Shield Deluxe 2008&#092;scieplugin.dll<br />
O9 - Extra button: @C:&#092;Windows&#092;WindowsMobile&#092;INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:&#092;Windows&#092;WindowsMobile&#092;INetRepl.dll<br />
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:&#092;Windows&#092;WindowsMobile&#092;INetRepl.dll<br />
O9 - Extra 'Tools' menuitem: @C:&#092;Windows&#092;WindowsMobile&#092;INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:&#092;Windows&#092;WindowsMobile&#092;INetRepl.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:&#092;PROGRA~2&#092;MICROS~1&#092;Office12&#092;REFIEBAR.DLL<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - <a href='http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.0.cab' class='bbc_url' title='External link' rel='nofollow'>http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.0.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href='http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab' class='bbc_url' title='External link' rel='nofollow'>http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab</a><br />
O20 - AppInit_DLLs: C:&#092;PROGRA~2&#092;PCSECU~1&#092;THESHI~1&#092;r3hook.dll C:&#092;PROGRA~2&#092;Google&#092;GOOGLE~3&#092;GOEC62~1.DLL<br />
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:&#092;Windows&#092;system32&#092;browseui.dll<br />
O23 - Service: @%SystemRoot%&#092;system32&#092;Alg.exe,-112 (ALG) - Unknown owner - C:&#092;Windows&#092;System32&#092;alg.exe (file missing)<br />
O23 - Service: AMD External Events Utility - Unknown owner - C:&#092;Windows&#092;system32&#092;atiesrxx.exe (file missing)<br />
O23 - Service: AODService - Unknown owner - C:&#092;Program.exe (file missing)<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:&#092;Program Files (x86)&#092;Common Files&#092;Apple&#092;Mobile Device Support&#092;bin&#092;AppleMobileDeviceService.exe<br />
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:&#092;Windows&#092;Microsoft.NET&#092;Framework&#092;v2.0.50727&#092;aspnet_state.exe (file missing)<br />
O23 - Service: The Shield Deluxe 2008 (AVP) - PCSecurityShield - C:&#092;Program Files (x86)&#092;PCSecurityShield&#092;The Shield Deluxe 2008&#092;avp.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:&#092;Program Files (x86)&#092;Bonjour&#092;mDNSResponder.exe<br />
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - C:&#092;Program Files (x86)&#092;Dragon Age&#092;bin_ship&#092;DAUpdaterSvc.Service.exe<br />
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:&#092;Windows&#092;system32&#092;DFSR.exe (file missing)<br />
O23 - Service: @%systemroot%&#092;system32&#092;fxsresm.dll,-118 (Fax) - Unknown owner - C:&#092;Windows&#092;system32&#092;fxssvc.exe (file missing)<br />
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:&#092;Program Files (x86)&#092;Common Files&#092;Macrovision Shared&#092;FLEXnet Publisher&#092;FNPLicensingService.exe<br />
O23 - Service: Folding@home-CPU-[1] - Unknown owner - C:&#092;Folding@HomeCPU&#092;1&#092;Fah.exe<br />
O23 - Service: Folding@home-CPU-[2] - Unknown owner - C:&#092;Folding@HomeCPU&#092;2&#092;Fah.exe<br />
O23 - Service: Folding@home-CPU-[3] - Unknown owner - C:&#092;Folding@HomeCPU&#092;3&#092;Fah.exe<br />
O23 - Service: Folding@home-CPU-[4] - Unknown owner - C:&#092;Folding@HomeCPU&#092;4&#092;Fah.exe<br />
O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:&#092;Program Files (x86)&#092;Google&#092;Google Desktop Search&#092;GoogleDesktop.exe<br />
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:&#092;Program Files (x86)&#092;Google&#092;Update&#092;GoogleUpdate.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:&#092;Program Files (x86)&#092;Google&#092;Common&#092;Google Updater&#092;GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:&#092;Program Files (x86)&#092;Common Files&#092;InstallShield&#092;Driver&#092;11&#092;Intel 32&#092;IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:&#092;Program Files&#092;iPod&#092;bin&#092;iPodService.exe<br />
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:&#092;Windows&#092;system32&#092;lsass.exe (file missing)<br />
O23 - Service: LaCie Safe Hard Drive Enabler - LaCie - C:&#092;Program Files (x86)&#092;LaCie&#092;SAFE Hard Drive&#092;SafeService.exe<br />
O23 - Service: Mediafour M4LIC service (M4LIC) - Mediafour Corporation - C:&#092;Program Files (x86)&#092;Common Files&#092;Mediafour&#092;M4LIC.EXE<br />
O23 - Service: MacDrive service (MacDriveService) - Mediafour Corporation - C:&#092;Program Files&#092;Mediafour&#092;MacDrive 8&#092;MacDriveService.exe<br />
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:&#092;Windows&#092;System32&#092;msdtc.exe (file missing)<br />
O23 - Service: @%SystemRoot%&#092;System32&#092;netlogon.dll,-102 (Netlogon) - Unknown owner - C:&#092;Windows&#092;system32&#092;lsass.exe (file missing)<br />
O23 - Service: PnkBstrA - Unknown owner - C:&#092;Windows&#092;system32&#092;PnkBstrA.exe<br />
O23 - Service: @%systemroot%&#092;system32&#092;psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:&#092;Windows&#092;system32&#092;lsass.exe (file missing)<br />
O23 - Service: @%systemroot%&#092;system32&#092;Locator.exe,-2 (RpcLocator) - Unknown owner - C:&#092;Windows&#092;system32&#092;locator.exe (file missing)<br />
O23 - Service: @%SystemRoot%&#092;system32&#092;samsrv.dll,-1 (SamSs) - Unknown owner - C:&#092;Windows&#092;system32&#092;lsass.exe (file missing)<br />
O23 - Service: @%SystemRoot%&#092;system32&#092;SLsvc.exe,-101 (slsvc) - Unknown owner - C:&#092;Windows&#092;system32&#092;SLsvc.exe (file missing)<br />
O23 - Service: @%SystemRoot%&#092;system32&#092;snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:&#092;Windows&#092;System32&#092;snmptrap.exe (file missing)<br />
O23 - Service: @%systemroot%&#092;system32&#092;spoolsv.exe,-1 (Spooler) - Unknown owner - C:&#092;Windows&#092;System32&#092;spoolsv.exe (file missing)<br />
O23 - Service: Steam Client Service - Valve Corporation - C:&#092;Program Files (x86)&#092;Common Files&#092;Steam&#092;SteamService.exe<br />
O23 - Service: @%SystemRoot%&#092;system32&#092;ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:&#092;Windows&#092;system32&#092;UI0Detect.exe (file missing)<br />
O23 - Service: @%SystemRoot%&#092;system32&#092;vds.exe,-100 (vds) - Unknown owner - C:&#092;Windows&#092;System32&#092;vds.exe (file missing)<br />
O23 - Service: @%systemroot%&#092;system32&#092;vssvc.exe,-102 (VSS) - Unknown owner - C:&#092;Windows&#092;system32&#092;vssvc.exe (file missing)<br />
O23 - Service: @%systemroot%&#092;system32&#092;wbengine.exe,-104 (wbengine) - Unknown owner - C:&#092;Windows&#092;system32&#092;wbengine.exe (file missing)<br />
O23 - Service: @%Systemroot%&#092;system32&#092;wbem&#092;wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:&#092;Windows&#092;system32&#092;wbem&#092;WmiApSrv.exe (file missing)<br />
O23 - Service: @%ProgramFiles%&#092;Windows Media Player&#092;wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:&#092;Program Files (x86)&#092;Windows Media Player&#092;wmpnetwk.exe (file missing)<br />
<br />
--<br />
End of file - 11933 bytes<br />
<br />
<br />
<br />
THANX!!!]]></description>
		<pubDate>Thu, 04 Feb 2010 06:02:00 +0000</pubDate>
		<guid>http://www.247fixes.com/forums/topic/6254-help-please/</guid>
	</item>
	<item>
		<title><![CDATA[[Inactive]&nbsp;Please Help Me Fix This!]]></title>
		<link>http://www.247fixes.com/forums/topic/6228-please-help-me-fix-this/</link>
		<description><![CDATA[I've never posted on a forum before so I'm sorry if this is the wrong one but I've been having a bunch of problems with my computer for a week and a half or so and I don't know what to do. PLEASE help me fix this!<br />
<br />
I keep getting a message that says “AXWIN Frame Window: schist.exe - Application Error” and it tells me that “The instruction at “0x02aff7a0” referenced memory at “0x02aff7a0”. The memory could not be written”. When I click okay or cancel I usually get a few more of the same message with different numbers and then sometimes a message comes up that says windows is shutting down and gives me a countdown from a minute. If I don’t receive the countdown and windows doesn’t shut down, my computer usually runs fine for a while but eventually freezes up and I have to shut it down. I also get a message called “Data Execution Prevention - Microsoft Windows” and it says “To Help protect your computer, Windows has closed this Program. Name: Generic Host Process for Win32 Services. Publisher: Microsoft Corporation”. When I click close I usually get a few more of the exact same message. I also cannot shut down or restart my computer using the start menu, I have to hold down the power button until my computer shuts down. I’ve tried using Malwarebytes but it keeps finding something called “Rootkit.Agent”. Then after I tell it to restart my computer nothing happens, but if I try to run anything I get a message telling me that the “the application failed to initiate because the Windows station is shutting down“, but it never shuts down.]]></description>
		<pubDate>Tue, 02 Feb 2010 03:53:08 +0000</pubDate>
		<guid>http://www.247fixes.com/forums/topic/6228-please-help-me-fix-this/</guid>
	</item>
	<item>
		<title><![CDATA[[Inactive]&nbsp;Person Security Virus.....]]></title>
		<link>http://www.247fixes.com/forums/topic/6225-person-security-virus/</link>
		<description><![CDATA[Hello, i have some malware on my computer called "personal security". I think i got rid of some of it by doing some google searches and deleting a few of the registry key things..... but i still have it...  Here is my hijackthis log...<br />
<br />
<br />
<br />
Logfile of HijackThis v1.99.1<br />
Scan saved at 10:27:04 AM, on 2/1/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
<br />
Running processes:<br />
C:&#092;WINDOWS&#092;System32&#092;smss.exe<br />
C:&#092;WINDOWS&#092;system32&#092;winlogon.exe<br />
C:&#092;WINDOWS&#092;system32&#092;services.exe<br />
C:&#092;WINDOWS&#092;system32&#092;lsass.exe<br />
C:&#092;WINDOWS&#092;system32&#092;svchost.exe<br />
C:&#092;WINDOWS&#092;System32&#092;svchost.exe<br />
C:&#092;WINDOWS&#092;Explorer.EXE<br />
C:&#092;WINDOWS&#092;system32&#092;spoolsv.exe<br />
C:&#092;windows&#092;system&#092;hpsysdrv.exe<br />
C:&#092;WINDOWS&#092;system32&#092;hkcmd.exe<br />
C:&#092;WINDOWS&#092;system32&#092;igfxtray.exe<br />
C:&#092;Program Files&#092;QuickTime&#092;qttask.exe<br />
C:&#092;Program Files&#092;Common Files&#092;Microsoft Shared&#092;Works Shared&#092;WkUFind.exe<br />
C:&#092;HP&#092;KBD&#092;KBD.EXE<br />
C:&#092;WINDOWS&#092;AGRSMMSG.exe<br />
C:&#092;PROGRA~1&#092;AVG&#092;AVG8&#092;avgtray.exe<br />
C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;jusched.exe<br />
C:&#092;Program Files&#092;HP&#092;HP Software Update&#092;HPWuSchd2.exe<br />
C:&#092;Program Files&#092;Messenger&#092;msmsgs.exe<br />
C:&#092;WINDOWS&#092;system32&#092;ctfmon.exe<br />
C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;bin&#092;hpqtra08.exe<br />
C:&#092;PROGRA~1&#092;AVG&#092;AVG8&#092;avgwdsvc.exe<br />
C:&#092;WINDOWS&#092;system32&#092;svchost.exe<br />
C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;jqs.exe<br />
C:&#092;WINDOWS&#092;System32&#092;svchost.exe<br />
C:&#092;WINDOWS&#092;System32&#092;svchost.exe<br />
C:&#092;PROGRA~1&#092;AVG&#092;AVG8&#092;avgrsx.exe<br />
C:&#092;WINDOWS&#092;System32&#092;svchost.exe<br />
C:&#092;PROGRA~1&#092;AVG&#092;AVG8&#092;avgnsx.exe<br />
C:&#092;PROGRA~1&#092;AVG&#092;AVG8&#092;avgemc.exe<br />
C:&#092;Program Files&#092;AVG&#092;AVG8&#092;avgcsrvx.exe<br />
C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;bin&#092;hpqSTE08.exe<br />
C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;bin&#092;hpqbam08.exe<br />
C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;bin&#092;hpqgpc01.exe<br />
C:&#092;Program Files&#092;Internet Explorer&#092;iexplore.exe<br />
C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;Smart Web Printing&#092;hpswp_clipbook.exe<br />
C:&#092;Program Files&#092;Internet Explorer&#092;iexplore.exe<br />
C:&#092;Program Files&#092;Internet Explorer&#092;iexplore.exe<br />
C:&#092;Program Files&#092;Internet Explorer&#092;iexplore.exe<br />
C:&#092;Documents and Settings&#092;Owner&#092;Desktop&#092;HijackThis.exe<br />
<br />
R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Search_URL = <a href='http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=presario&pf=desktop' class='bbc_url' title='External link' rel='nofollow'>http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=presario&pf=desktop</a><br />
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Page_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=69157' class='bbc_url' title='External link' rel='nofollow'>http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Search_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='External link' rel='nofollow'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Bar = <a href='http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=presario&pf=desktop' class='bbc_url' title='External link' rel='nofollow'>http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=presario&pf=desktop</a><br />
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='External link' rel='nofollow'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = <a href='http://go.microsoft.com/fwlink/?LinkId=69157' class='bbc_url' title='External link' rel='nofollow'>http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU&#092;Software&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Internet Settings,ProxyOverride = localhost<br />
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)<br />
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:&#092;Program Files&#092;AVG&#092;AVG8&#092;Toolbar&#092;IEToolbar.dll<br />
R3 - URLSearchHook: (no name) - *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br />
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:&#092;Program Files&#092;Yahoo!&#092;Companion&#092;Installs&#092;cpn&#092;yt.dll<br />
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;Smart Web Printing&#092;hpswp_printenhancer.dll<br />
O2 - BHO: &Security Update - {16672C32-9E15-4879-B0AD-0DB2A1721BC6} - C:&#092;WINDOWS&#092;system32&#092;win32extension.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:&#092;Program Files&#092;Common Files&#092;Adobe&#092;Acrobat&#092;ActiveX&#092;AcroIEHelperShim.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:&#092;Program Files&#092;AVG&#092;AVG8&#092;avgssie.dll<br />
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:&#092;Program Files&#092;AVG&#092;AVG8&#092;Toolbar&#092;IEToolbar.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:&#092;Program Files&#092;Java&#092;jre6&#092;lib&#092;deploy&#092;jqs&#092;ie&#092;jqs_plugin.dll<br />
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:&#092;Program Files&#092;Yahoo!&#092;Companion&#092;Installs&#092;cpn&#092;YTSingleInstance.dll<br />
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;Smart Web Printing&#092;hpswp_BHO.dll<br />
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:&#092;Program Files&#092;AVG&#092;AVG8&#092;Toolbar&#092;IEToolbar.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:&#092;Program Files&#092;Yahoo!&#092;Companion&#092;Installs&#092;cpn&#092;yt.dll<br />
O4 - HKLM&#092;..&#092;Run: [hpsysdrv] c:&#092;windows&#092;system&#092;hpsysdrv.exe<br />
O4 - HKLM&#092;..&#092;Run: [HotKeysCmds] C:&#092;WINDOWS&#092;system32&#092;hkcmd.exe<br />
O4 - HKLM&#092;..&#092;Run: [Recguard] C:&#092;WINDOWS&#092;SMINST&#092;RECGUARD.EXE<br />
O4 - HKLM&#092;..&#092;Run: [PrinTray] C:&#092;WINDOWS&#092;System32&#092;spool&#092;DRIVERS&#092;W32X86&#092;3&#092;printray.exe<br />
O4 - HKLM&#092;..&#092;Run: [IgfxTray] C:&#092;WINDOWS&#092;system32&#092;igfxtray.exe<br />
O4 - HKLM&#092;..&#092;Run: [QuickTime Task] "C:&#092;Program Files&#092;QuickTime&#092;qttask.exe" -atboottime<br />
O4 - HKLM&#092;..&#092;Run: [TkBellExe] "C:&#092;Program Files&#092;Common Files&#092;Real&#092;Update_OB&#092;realsched.exe" -osboot<br />
O4 - HKLM&#092;..&#092;Run: [Microsoft Works Update Detection] C:&#092;Program Files&#092;Common Files&#092;Microsoft Shared&#092;Works Shared&#092;WkUFind.exe<br />
O4 - HKLM&#092;..&#092;Run: [KBD] C:&#092;HP&#092;KBD&#092;KBD.EXE<br />
O4 - HKLM&#092;..&#092;Run: [AOLDialer] C:&#092;Program Files&#092;Common Files&#092;AOL&#092;ACS&#092;AOLDial.exe<br />
O4 - HKLM&#092;..&#092;Run: [AGRSMMSG] AGRSMMSG.exe<br />
O4 - HKLM&#092;..&#092;Run: [AVG8_TRAY] C:&#092;PROGRA~1&#092;AVG&#092;AVG8&#092;avgtray.exe<br />
O4 - HKLM&#092;..&#092;Run: [UpdateManager] "c:&#092;Program Files&#092;Common Files&#092;Sonic&#092;Update Manager&#092;sgtray.exe" /r<br />
O4 - HKLM&#092;..&#092;Run: [SunJavaUpdateSched] "C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;jusched.exe"<br />
O4 - HKLM&#092;..&#092;Run: [HP Software Update] C:&#092;Program Files&#092;HP&#092;HP Software Update&#092;HPWuSchd2.exe<br />
O4 - HKLM&#092;..&#092;Run: [Adobe Reader Speed Launcher] "C:&#092;Program Files&#092;Adobe&#092;Reader 9.0&#092;Reader&#092;Reader_sl.exe"<br />
O4 - HKLM&#092;..&#092;Run: [Adobe ARM] "C:&#092;Program Files&#092;Common Files&#092;Adobe&#092;ARM&#092;1.0&#092;AdobeARM.exe"<br />
O4 - HKCU&#092;..&#092;Run: [MSMSGS] "C:&#092;Program Files&#092;Messenger&#092;msmsgs.exe" /background<br />
O4 - HKCU&#092;..&#092;Run: [ctfmon.exe] C:&#092;WINDOWS&#092;system32&#092;ctfmon.exe<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;bin&#092;hpqtra08.exe<br />
O8 - Extra context menu item: Add To Compaq Organize... - C:&#092;PROGRA~1&#092;HEWLET~1&#092;COMPAQ~1&#092;bin&#092;core.hp.main&#092;SendTo.html<br />
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:&#092;PROGRA~1&#092;MI1933~1&#092;OFFICE11&#092;EXCEL.EXE/3000<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:&#092;PROGRA~1&#092;MI1933~1&#092;OFFICE11&#092;REFIEBAR.DLL<br />
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;Smart Web Printing&#092;hpswp_BHO.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%&#092;Network Diagnostic&#092;xpnetdiag.exe (file missing)<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%&#092;Network Diagnostic&#092;xpnetdiag.exe (file missing)<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:&#092;Program Files&#092;Messenger&#092;msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:&#092;Program Files&#092;Messenger&#092;msmsgs.exe<br />
O11 - Options group: [INTERNATIONAL] International<br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:&#092;Program Files&#092;AVG&#092;AVG8&#092;avgpp.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:&#092;WINDOWS&#092;SYSTEM32&#092;avgrsstx.dll<br />
O20 - Winlogon Notify: dimsntfy - %SystemRoot%&#092;System32&#092;dimsntfy.dll (file missing)<br />
O20 - Winlogon Notify: igfxcui - C:&#092;WINDOWS&#092;SYSTEM32&#092;igfxsrvc.dll<br />
O20 - Winlogon Notify: WgaLogon - C:&#092;WINDOWS&#092;SYSTEM32&#092;WgaLogon.dll<br />
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:&#092;WINDOWS&#092;system32&#092;WPDShServiceObj.dll<br />
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:&#092;PROGRA~1&#092;AVG&#092;AVG8&#092;avgemc.exe<br />
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:&#092;PROGRA~1&#092;AVG&#092;AVG8&#092;avgwdsvc.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;jqs.exe" -service -config "C:&#092;Program Files&#092;Java&#092;jre6&#092;lib&#092;deploy&#092;jqs&#092;jqs.conf (file missing)<br />
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:&#092;Program Files&#092;Spyware Doctor&#092;pctsAuxs.exe<br />
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:&#092;Program Files&#092;Spyware Doctor&#092;pctsSvc.exe<br />
<br />
/   It seems to be a little better with so,me of the things i deleted but, i still try to go on some websites, and a fake screen comes up and tells me that it is  a harmful website. I would really appreciate some help trying to get rid of this stupid virus... thank you very much.]]></description>
		<pubDate>Mon, 01 Feb 2010 15:32:14 +0000</pubDate>
		<guid>http://www.247fixes.com/forums/topic/6225-person-security-virus/</guid>
	</item>
	<item>
		<title><![CDATA[[Resolved] Rogue Antispyware]]></title>
		<link>http://www.247fixes.com/forums/topic/6219-rogue-antispyware/</link>
		<description><![CDATA[Logfile of HijackThis v1.99.1<br />
Scan saved at 8:57:17 PM, on 1/31/2010<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.5730.0011)<br />
<br />
Running processes:<br />
C:&#092;WINDOWS&#092;System32&#092;smss.exe<br />
C:&#092;WINDOWS&#092;system32&#092;winlogon.exe<br />
C:&#092;WINDOWS&#092;system32&#092;services.exe<br />
C:&#092;WINDOWS&#092;system32&#092;lsass.exe<br />
C:&#092;WINDOWS&#092;system32&#092;svchost.exe<br />
C:&#092;WINDOWS&#092;System32&#092;svchost.exe<br />
C:&#092;WINDOWS&#092;System32&#092;WLTRYSVC.EXE<br />
C:&#092;WINDOWS&#092;System32&#092;bcmwltry.exe<br />
C:&#092;WINDOWS&#092;system32&#092;spoolsv.exe<br />
C:&#092;Program Files&#092;Avira&#092;AntiVir Desktop&#092;sched.exe<br />
C:&#092;Program Files&#092;Avira&#092;AntiVir Desktop&#092;avguard.exe<br />
C:&#092;Program Files&#092;Common Files&#092;AOL&#092;ACS&#092;AOLAcsd.exe<br />
C:&#092;Program Files&#092;Common Files&#092;Apple&#092;Mobile Device Support&#092;bin&#092;AppleMobileDeviceService.exe<br />
C:&#092;Program Files&#092;Bonjour&#092;mDNSResponder.exe<br />
C:&#092;Program Files&#092;Dell Network Assistant&#092;hnm_svc.exe<br />
C:&#092;WINDOWS&#092;system32&#092;svchost.exe<br />
C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;jqs.exe<br />
C:&#092;WINDOWS&#092;System32&#092;svchost.exe<br />
C:&#092;WINDOWS&#092;system32&#092;nvsvc32.exe<br />
C:&#092;WINDOWS&#092;System32&#092;svchost.exe<br />
C:&#092;WINDOWS&#092;system32&#092;svchost.exe<br />
C:&#092;WINDOWS&#092;wanmpsvc.exe<br />
C:&#092;Program Files&#092;Yahoo!&#092;SoftwareUpdate&#092;YahooAUService.exe<br />
C:&#092;Program Files&#092;Canon&#092;CAL&#092;CALMAIN.exe<br />
C:&#092;WINDOWS&#092;Explorer.EXE<br />
C:&#092;Program Files&#092;Synaptics&#092;SynTP&#092;SynTPEnh.exe<br />
C:&#092;WINDOWS&#092;system32&#092;rundll32.exe<br />
C:&#092;WINDOWS&#092;system32&#092;RUNDLL32.EXE<br />
C:&#092;Program Files&#092;Dell&#092;QuickSet&#092;quickset.exe<br />
C:&#092;WINDOWS&#092;system32&#092;WLTRAY.exe<br />
C:&#092;WINDOWS&#092;stsystra.exe<br />
C:&#092;WINDOWS&#092;system32&#092;KADxMain.exe<br />
C:&#092;Program Files&#092;Dell&#092;MediaDirect&#092;PCMService.exe<br />
C:&#092;Program Files&#092;Real&#092;RealPlayer&#092;RealPlay.exe<br />
C:&#092;Program Files&#092;Common Files&#092;AOL&#092;1209522247&#092;ee&#092;AOLSoftware.exe<br />
C:&#092;Program Files&#092;HP&#092;HP Software Update&#092;HPWuSchd2.exe<br />
C:&#092;Program Files&#092;Avira&#092;AntiVir Desktop&#092;avgnt.exe<br />
C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;jusched.exe<br />
C:&#092;Program Files&#092;Yahoo!&#092;Messenger&#092;YahooMessenger.exe<br />
C:&#092;WINDOWS&#092;system32&#092;ctfmon.exe<br />
C:&#092;Program Files&#092;AIM&#092;aim.exe<br />
C:&#092;Program Files&#092;AOL 9.0&#092;waol.exe<br />
C:&#092;Documents and Settings&#092;Smadar&#092;Local Settings&#092;Application Data&#092;Google&#092;Update&#092;1.2.183.13&#092;GoogleCrashHandler.exe<br />
C:&#092;Program Files&#092;Digital Line Detect&#092;DLG.exe<br />
C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;bin&#092;hpqtra08.exe<br />
C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;bin&#092;hpqSTE08.exe<br />
C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;bin&#092;hpqbam08.exe<br />
C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;bin&#092;hpqgpc01.exe<br />
C:&#092;Program Files&#092;AOL 9.0&#092;shellmon.exe<br />
C:&#092;Program Files&#092;Malwarebytes' Anti-Malware4&#092;mbam.exe<br />
C:&#092;Program Files&#092;Internet Explorer&#092;IEXPLORE.EXE<br />
C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;Smart Web Printing&#092;hpswp_clipbook.exe<br />
C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;java.exe<br />
C:&#092;WINDOWS&#092;system32&#092;rundll32.exe<br />
C:&#092;WINDOWS&#092;system32&#092;smss32.exe<br />
C:&#092;WINDOWS&#092;system32&#092;rundll32.exe<br />
C:&#092;Documents and Settings&#092;Smadar&#092;Desktop&#092;HijackThis.exe<br />
<br />
R0 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = <br />
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Page_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=69157' class='bbc_url' title='External link' rel='nofollow'>http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Search_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='External link' rel='nofollow'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='External link' rel='nofollow'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Search,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=6080415<br />
R1 - HKCU&#092;Software&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Internet Settings,ProxyOverride = *.local<br />
F2 - REG:system.ini: UserInit=C:&#092;WINDOWS&#092;system32&#092;winlogon32.exe<br />
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;Smart Web Printing&#092;hpswp_printenhancer.dll<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:&#092;Program Files&#092;Common Files&#092;Adobe&#092;Acrobat&#092;ActiveX&#092;AcroIEHelper.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:&#092;Program Files&#092;Google&#092;Google Toolbar&#092;GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:&#092;Program Files&#092;Google&#092;GoogleToolbarNotifier&#092;5.4.4525.1752&#092;swg.dll<br />
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:&#092;Program Files&#092;Dell&#092;BAE&#092;BAE.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:&#092;Program Files&#092;Java&#092;jre6&#092;lib&#092;deploy&#092;jqs&#092;ie&#092;jqs_plugin.dll<br />
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;Smart Web Printing&#092;hpswp_BHO.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:&#092;Program Files&#092;Google&#092;Google Toolbar&#092;GoogleToolbar_32.dll<br />
O4 - HKLM&#092;..&#092;Run: [SynTPEnh] C:&#092;Program Files&#092;Synaptics&#092;SynTP&#092;SynTPEnh.exe<br />
O4 - HKLM&#092;..&#092;Run: [NvCplDaemon] RUNDLL32.EXE C:&#092;WINDOWS&#092;system32&#092;NvCpl.dll,NvStartup<br />
O4 - HKLM&#092;..&#092;Run: [nwiz] nwiz.exe /installquiet<br />
O4 - HKLM&#092;..&#092;Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start<br />
O4 - HKLM&#092;..&#092;Run: [NvMediaCenter] RUNDLL32.EXE C:&#092;WINDOWS&#092;system32&#092;NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM&#092;..&#092;Run: [Dell QuickSet] C:&#092;Program Files&#092;Dell&#092;QuickSet&#092;quickset.exe<br />
O4 - HKLM&#092;..&#092;Run: [Broadcom Wireless Manager UI] C:&#092;WINDOWS&#092;system32&#092;WLTRAY.exe<br />
O4 - HKLM&#092;..&#092;Run: [SigmatelSysTrayApp] stsystra.exe<br />
O4 - HKLM&#092;..&#092;Run: [KADxMain] C:&#092;WINDOWS&#092;system32&#092;KADxMain.exe<br />
O4 - HKLM&#092;..&#092;Run: [ECenter] C:&#092;Dell&#092;E-Center&#092;EULALauncher.exe<br />
O4 - HKLM&#092;..&#092;Run: [Adobe Reader Speed Launcher] "C:&#092;Program Files&#092;Adobe&#092;Reader 8.0&#092;Reader&#092;Reader_sl.exe"<br />
O4 - HKLM&#092;..&#092;Run: [dscactivate] "C:&#092;Program Files&#092;Dell Support Center&#092;gs_agent&#092;custom&#092;dsca.exe"<br />
O4 - HKLM&#092;..&#092;Run: [PCMService] "C:&#092;Program Files&#092;Dell&#092;MediaDirect&#092;PCMService.exe"<br />
O4 - HKLM&#092;..&#092;Run: [RealTray] C:&#092;Program Files&#092;Real&#092;RealPlayer&#092;RealPlay.exe SYSTEMBOOTHIDEPLAYER<br />
O4 - HKLM&#092;..&#092;Run: [HostManager] C:&#092;Program Files&#092;Common Files&#092;AOL&#092;1209522247&#092;ee&#092;AOLSoftware.exe<br />
O4 - HKLM&#092;..&#092;Run: [HP Software Update] C:&#092;Program Files&#092;HP&#092;HP Software Update&#092;HPWuSchd2.exe<br />
O4 - HKLM&#092;..&#092;Run: [hpqSRMon] C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;bin&#092;hpqSRMon.exe<br />
O4 - HKLM&#092;..&#092;Run: [QuickTime Task] "C:&#092;Program Files&#092;QuickTime&#092;qttask.exe" -atboottime<br />
O4 - HKLM&#092;..&#092;Run: [avgnt] "C:&#092;Program Files&#092;Avira&#092;AntiVir Desktop&#092;avgnt.exe" /min<br />
O4 - HKLM&#092;..&#092;Run: [SunJavaUpdateSched] "C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;jusched.exe"<br />
O4 - HKLM&#092;..&#092;Run: [takupanene] Rundll32.exe "jisekubu.dll",s<br />
O4 - HKLM&#092;..&#092;Run: [kufovoyay] Rundll32.exe "c:&#092;windows&#092;system32&#092;funokafe.dll",a<br />
O4 - HKLM&#092;..&#092;Run: [smss32.exe] C:&#092;WINDOWS&#092;system32&#092;smss32.exe<br />
O4 - HKCU&#092;..&#092;Run: [Google Update] "C:&#092;Documents and Settings&#092;Smadar&#092;Local Settings&#092;Application Data&#092;Google&#092;Update&#092;GoogleUpdate.exe" /c<br />
O4 - HKCU&#092;..&#092;Run: [swg] C:&#092;Program Files&#092;Google&#092;GoogleToolbarNotifier&#092;GoogleToolbarNotifier.exe<br />
O4 - HKCU&#092;..&#092;Run: [Messenger (Yahoo!)] "C:&#092;Program Files&#092;Yahoo!&#092;Messenger&#092;YahooMessenger.exe" -quiet<br />
O4 - HKCU&#092;..&#092;Run: [ctfmon.exe] C:&#092;WINDOWS&#092;system32&#092;ctfmon.exe<br />
O4 - HKCU&#092;..&#092;Run: [AOL Fast Start] "C:&#092;Program Files&#092;AOL 9.0&#092;AOL.EXE" -b<br />
O4 - HKCU&#092;..&#092;Run: [AIM] C:&#092;Program Files&#092;AIM&#092;aim.exe -cnetwait.odl<br />
O4 - HKCU&#092;..&#092;Run: [smss32.exe] C:&#092;WINDOWS&#092;system32&#092;smss32.exe<br />
O4 - Startup: ERUNT AutoBackup.lnk = C:&#092;Program Files&#092;ERUNT&#092;AUTOBACK.EXE<br />
O4 - Global Startup: Dell Network Assistant.lnk = ?<br />
O4 - Global Startup: Digital Line Detect.lnk = C:&#092;Program Files&#092;Digital Line Detect&#092;DLG.exe<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;bin&#092;hpqtra08.exe<br />
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:&#092;WINDOWS&#092;system32&#092;GPhotos.scr/200<br />
O8 - Extra context menu item: Google Sidewiki... - res://C:&#092;Program Files&#092;Google&#092;Google Toolbar&#092;Component&#092;GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html<br />
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:&#092;Program Files&#092;AIM&#092;aim.exe<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:&#092;WINDOWS&#092;system32&#092;Shdocvw.dll<br />
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;Smart Web Printing&#092;hpswp_BHO.dll<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:&#092;Program Files&#092;Messenger&#092;msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:&#092;Program Files&#092;Messenger&#092;msmsgs.exe<br />
O10 - Unknown file in Winsock LSP: c:&#092;program files&#092;bonjour&#092;mdnsnsp.dll<br />
O11 - Options group: [INTERNATIONAL] International*<br />
O15 - Trusted Zone: http://*.buy-internet-security10.com<br />
O15 - Trusted Zone: http://*.is-soft-download.com<br />
O15 - Trusted Zone: http://*.is-software-download.com<br />
O15 - Trusted Zone: http://*.is-software-download25.com<br />
O15 - Trusted Zone: http://*.buy-internet-security10.com (HKLM)<br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - <a href='http://upload.facebook.com/controls/FacebookPhotoUploader5.cab' class='bbc_url' title='External link' rel='nofollow'>http://upload.facebook.com/controls/FacebookPhotoUploader5.cab</a><br />
O16 - DPF: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - <a href='http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab' class='bbc_url' title='External link' rel='nofollow'>http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href='http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1230406510718' class='bbc_url' title='External link' rel='nofollow'>http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1230406510718</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href='http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1230406502890' class='bbc_url' title='External link' rel='nofollow'>http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1230406502890</a><br />
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - <a href='http://download.eset.com/special/eos/OnlineScanner.cab' class='bbc_url' title='External link' rel='nofollow'>http://download.eset.com/special/eos/OnlineScanner.cab</a><br />
O20 - AppInit_DLLs: vuturogi.dll jisekubu.dll c:&#092;windows&#092;system32&#092;funokafe.dll<br />
O21 - SSODL: niwiduwev - {129327ab-a078-4166-bf34-6c03a036ae4d} - c:&#092;windows&#092;system32&#092;funokafe.dll<br />
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:&#092;Program Files&#092;Avira&#092;AntiVir Desktop&#092;sched.exe<br />
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:&#092;Program Files&#092;Avira&#092;AntiVir Desktop&#092;avguard.exe<br />
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:&#092;Program Files&#092;Common Files&#092;AOL&#092;ACS&#092;AOLAcsd.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:&#092;Program Files&#092;Common Files&#092;Apple&#092;Mobile Device Support&#092;bin&#092;AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:&#092;Program Files&#092;Bonjour&#092;mDNSResponder.exe<br />
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:&#092;Program Files&#092;Canon&#092;CAL&#092;CALMAIN.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:&#092;Program Files&#092;Google&#092;Common&#092;Google Updater&#092;GoogleUpdaterService.exe<br />
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:&#092;Program Files&#092;Dell Network Assistant&#092;hnm_svc.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;jqs.exe" -service -config "C:&#092;Program Files&#092;Java&#092;jre6&#092;lib&#092;deploy&#092;jqs&#092;jqs.conf (file missing)<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:&#092;WINDOWS&#092;system32&#092;nvsvc32.exe<br />
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:&#092;WINDOWS&#092;wanmpsvc.exe<br />
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:&#092;WINDOWS&#092;System32&#092;WLTRYSVC.EXE<br />
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:&#092;Program Files&#092;Yahoo!&#092;SoftwareUpdate&#092;YahooAUService.exe]]></description>
		<pubDate>Mon, 01 Feb 2010 02:03:13 +0000</pubDate>
		<guid>http://www.247fixes.com/forums/topic/6219-rogue-antispyware/</guid>
	</item>
	<item>
		<title>Probable Userinit.exe Hijack</title>
		<link>http://www.247fixes.com/forums/topic/6217-probable-userinit-exe-hijack/</link>
		<description><![CDATA[Hello, I am trying to help a friend fix his computer. After looking through the forums a bit it seems that he probably has a userinit.exe hijack going on. I tried to use the recovery console fix described <a href='http://www.247fixes.com/forums/topic/5094-windows-freezes-acts-weird-refuses-to-sign-me-in/' class='bbc_url' title='External link' rel='nofollow'>here</a> but when I typed in the Expand USERINIT.EX_ C:&#092;Windows&#092;system32 command I received an access denied message. There was no admin password set and I removed the system password before I started.<br />
<br />
The computer is running XP home SP3. I used a XP Pro disc as I don't have an XP Home disc. <br />
<br />
Any ideas on how to get past the log in log out problem?]]></description>
		<pubDate>Sun, 31 Jan 2010 21:06:49 +0000</pubDate>
		<guid>http://www.247fixes.com/forums/topic/6217-probable-userinit-exe-hijack/</guid>
	</item>
	<item>
		<title><![CDATA[Post Is 2010, Malware Defense, &#38; Redirect Virus Check]]></title>
		<link>http://www.247fixes.com/forums/topic/6211-post-is-2010-malware-defense-redirect-virus-check/</link>
		<description><![CDATA[Hello,<br />
<br />
I am a new member.  I think I have effectively removed Internet Security 2010, Malware Defense, and a browser redirect of some sort, but I would like to make sure.  I've also notice an h8str (or whatever combination it was) file that keeps popping up in my malware scans.  My hijackthis file is pasted below.  Thanks for any and all help.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 3:36:46 PM, on 1/30/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:&#092;WINDOWS&#092;System32&#092;smss.exe<br />
C:&#092;WINDOWS&#092;system32&#092;winlogon.exe<br />
C:&#092;WINDOWS&#092;system32&#092;services.exe<br />
C:&#092;WINDOWS&#092;system32&#092;lsass.exe<br />
C:&#092;WINDOWS&#092;system32&#092;nvsvc32.exe<br />
C:&#092;WINDOWS&#092;system32&#092;svchost.exe<br />
C:&#092;Program Files&#092;COMODO&#092;COMODO Internet Security&#092;cmdagent.exe<br />
C:&#092;WINDOWS&#092;system32&#092;svchost.exe<br />
C:&#092;Program Files&#092;Microsoft Forefront&#092;Client Security&#092;Client&#092;Antimalware&#092;MsMpEng.exe<br />
C:&#092;WINDOWS&#092;system32&#092;spoolsv.exe<br />
C:&#092;Program Files&#092;Citrix&#092;ICA Client&#092;ssonsvr.exe<br />
C:&#092;WINDOWS&#092;Explorer.EXE<br />
C:&#092;WINDOWS&#092;system32&#092;RUNDLL32.EXE<br />
C:&#092;WINDOWS&#092;RTHDCPL.EXE<br />
C:&#092;Program Files&#092;Microsoft Forefront&#092;Client Security&#092;Client&#092;SSA&#092;FcsSas.exe<br />
C:&#092;Program Files&#092;Microsoft Forefront&#092;Client Security&#092;Client&#092;Antimalware&#092;MSASCui.exe<br />
C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;jqs.exe<br />
C:&#092;Program Files&#092;COMODO&#092;COMODO Internet Security&#092;cfp.exe<br />
C:&#092;Program Files&#092;Common Files&#092;Java&#092;Java Update&#092;jusched.exe<br />
C:&#092;Program Files&#092;U-ABIT&#092;abitEQ&#092;abiteq.exe<br />
C:&#092;Program Files&#092;NVIDIA Corporation&#092;nTune&#092;nTuneService.exe<br />
c:&#092;Program Files&#092;Microsoft SQL Server&#092;90&#092;Shared&#092;sqlwriter.exe<br />
C:&#092;WINDOWS&#092;system32&#092;svchost.exe<br />
C:&#092;Program Files&#092;Spybot - Search & Destroy&#092;TeaTimer.exe<br />
C:&#092;WINDOWS&#092;system32&#092;SearchIndexer.exe<br />
C:&#092;Program Files&#092;RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition&#092;RivaTuner.exe<br />
C:&#092;Program Files&#092;Mozilla Firefox&#092;firefox.exe<br />
C:&#092;WINDOWS&#092;system32&#092;SearchProtocolHost.exe<br />
C:&#092;Program Files&#092;Trend Micro&#092;HijackThis&#092;HijackThis.exe<br />
<br />
R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydial/*http://www.yahoo.com/search/ie.html<br />
R0 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = <a href='http://www.drudgereport.com/' class='bbc_url' title='External link' rel='nofollow'>http://www.drudgereport.com/</a><br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:&#092;Program Files&#092;Common Files&#092;Adobe&#092;Acrobat&#092;ActiveX&#092;AcroIEHelperShim.dll<br />
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:&#092;PROGRA~1&#092;SPYBOT~1&#092;SDHelper.dll<br />
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:&#092;Program Files&#092;Microsoft Office&#092;Office12&#092;GrooveShellExtensions.dll<br />
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:&#092;Program Files&#092;McAfee&#092;VirusScan Enterprise&#092;scriptcl.dll (file missing)<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:&#092;Program Files&#092;Java&#092;jre6&#092;lib&#092;deploy&#092;jqs&#092;ie&#092;jqs_plugin.dll<br />
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)<br />
O4 - HKLM&#092;..&#092;Run: [NvCplDaemon] RUNDLL32.EXE C:&#092;WINDOWS&#092;system32&#092;NvCpl.dll,NvStartup<br />
O4 - HKLM&#092;..&#092;Run: [nwiz] nwiz.exe /installquiet<br />
O4 - HKLM&#092;..&#092;Run: [NvMediaCenter] RUNDLL32.EXE C:&#092;WINDOWS&#092;system32&#092;NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM&#092;..&#092;Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE<br />
O4 - HKLM&#092;..&#092;Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM&#092;..&#092;Run: [Microsoft Forefront Client Security Antimalware Service] "C:&#092;Program Files&#092;Microsoft Forefront&#092;Client Security&#092;Client&#092;Antimalware&#092;MSASCui.exe" -hide<br />
O4 - HKLM&#092;..&#092;Run: [Adobe Reader Speed Launcher] "C:&#092;Program Files&#092;Adobe&#092;Reader 9.0&#092;Reader&#092;Reader_sl.exe"<br />
O4 - HKLM&#092;..&#092;Run: [Adobe ARM] "C:&#092;Program Files&#092;Common Files&#092;Adobe&#092;ARM&#092;1.0&#092;AdobeARM.exe"<br />
O4 - HKLM&#092;..&#092;Run: [COMODO Internet Security] "C:&#092;Program Files&#092;COMODO&#092;COMODO Internet Security&#092;cfp.exe" -h<br />
O4 - HKLM&#092;..&#092;Run: [SunJavaUpdateSched] "C:&#092;Program Files&#092;Common Files&#092;Java&#092;Java Update&#092;jusched.exe"<br />
O4 - HKCU&#092;..&#092;Run: [NVIDIA nTune] "C:&#092;Program Files&#092;NVIDIA Corporation&#092;nTune&#092;nTuneCmd.exe" clear<br />
O4 - HKCU&#092;..&#092;Run: [ABIT uGuruIII] C:&#092;Program Files&#092;U-ABIT&#092;abitEQ&#092;abiteq.exe<br />
O4 - HKCU&#092;..&#092;Run: [SpybotSD TeaTimer] C:&#092;Program Files&#092;Spybot - Search & Destroy&#092;TeaTimer.exe<br />
O4 - HKUS&#092;S-1-5-18&#092;..&#092;Run: [DWQueuedReporting] "C:&#092;PROGRA~1&#092;COMMON~1&#092;MICROS~1&#092;DW&#092;dwtrig20.exe" -t (User 'SYSTEM')<br />
O4 - HKUS&#092;.DEFAULT&#092;..&#092;Run: [DWQueuedReporting] "C:&#092;PROGRA~1&#092;COMMON~1&#092;MICROS~1&#092;DW&#092;dwtrig20.exe" -t (User 'Default user')<br />
O4 - Startup: RivaTuner.lnk = C:&#092;Program Files&#092;RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition&#092;RivaTuner.exe<br />
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:&#092;PROGRA~1&#092;MICROS~2&#092;Office12&#092;EXCEL.EXE/3000<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:&#092;PROGRA~1&#092;MICROS~2&#092;Office12&#092;ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:&#092;PROGRA~1&#092;MICROS~2&#092;Office12&#092;ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:&#092;PROGRA~1&#092;MICROS~2&#092;Office12&#092;REFIEBAR.DLL<br />
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:&#092;Program Files&#092;AIM&#092;aim.exe<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:&#092;PROGRA~1&#092;SPYBOT~1&#092;SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:&#092;PROGRA~1&#092;SPYBOT~1&#092;SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:&#092;WINDOWS&#092;Network Diagnostic&#092;xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:&#092;WINDOWS&#092;Network Diagnostic&#092;xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:&#092;Program Files&#092;Messenger&#092;msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:&#092;Program Files&#092;Messenger&#092;msmsgs.exe<br />
O15 - Trusted Zone: http://*.mcafee.com<br />
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - <a href='http://go.microsoft.com/fwlink/?linkid=67633' class='bbc_url' title='External link' rel='nofollow'>http://go.microsoft.com/fwlink/?linkid=67633</a><br />
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - <a href='http://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/citrix/wficat-no-eula.cab' class='bbc_url' title='External link' rel='nofollow'>http://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/citrix/wficat-no-eula.cab</a><br />
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - <a href='http://apps.corel.com/nos_dl_manager_dev/plugin/IEGetPlugin.ocx' class='bbc_url' title='External link' rel='nofollow'>http://apps.corel.com/nos_dl_manager_dev/plugin/IEGetPlugin.ocx</a><br />
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - <a href='http://go.divx.com/plugin/DivXBrowserPlugin.cab' class='bbc_url' title='External link' rel='nofollow'>http://go.divx.com/plugin/DivXBrowserPlugin.cab</a><br />
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - <a href='http://www.adobe.com/products/acrobat/nos/gp.cab' class='bbc_url' title='External link' rel='nofollow'>http://www.adobe.com/products/acrobat/nos/gp.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a href='http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab' class='bbc_url' title='External link' rel='nofollow'>http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:&#092;Program Files&#092;Microsoft Office&#092;Office12&#092;GrooveSystemServices.dll<br />
O20 - AppInit_DLLs:   C:&#092;WINDOWS&#092;system32&#092;guard32.dll<br />
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:&#092;Program Files&#092;COMODO&#092;COMODO Internet Security&#092;cmdagent.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;jqs.exe<br />
O23 - Service: SQL Server (MSSMLBIZ) (MSSQL$MSSMLBIZ) - Unknown owner - c:&#092;Program Files&#092;Microsoft SQL Server&#092;MSSQL.1&#092;MSSQL&#092;Binn&#092;sqlservr.exe<br />
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:&#092;Program Files&#092;NVIDIA Corporation&#092;nTune&#092;nTuneService.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:&#092;WINDOWS&#092;system32&#092;nvsvc32.exe<br />
<br />
--<br />
End of file - 7339 bytes]]></description>
		<pubDate>Sat, 30 Jan 2010 21:43:13 +0000</pubDate>
		<guid>http://www.247fixes.com/forums/topic/6211-post-is-2010-malware-defense-redirect-virus-check/</guid>
	</item>
	<item>
		<title><![CDATA[[Inactive]&nbsp;Browser Redirect From Google Results]]></title>
		<link>http://www.247fixes.com/forums/topic/6206-browser-redirect-from-google-results/</link>
		<description><![CDATA[Hi there,<br />
<br />
I have what seems like a pretty common problem with no easy answer. <br />
<br />
My browser redirects from google (and other engines) results. IE also crashes when google page is open. From what I have read on this and other forums it seems people are calling this a goored type virus? <br />
<br />
I have run through the "do this first" instructions and have copied the OTL results below (it seems kinda long...have I done it right?) <br />
<br />
BUT -- GMER will not complete the scan. It gets frozen (and freezes the whole machine) while scanning &#46;&#46;/drivers/disk.sys so I have not been able to copy the results of this scan. I have copied the text that appears when GMER opens but I dont think this is what you need is it?<br />
<br />
Is there anything I can do??? I am tearing my hair out with this one. I am not the most computer savvy character so any help would be so appreciated.<br />
<br />
Cheers<br />
Jen  <br />
<br />
OTL logfile created on: 1/29/2010 12:45:10 AM - Run 1<br />
OTL by OldTimer - Version 3.1.27.0     Folder = C:&#092;Documents and Settings&#092;jenni rowe&#092;Desktop<br />
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation<br />
Internet Explorer (Version = 8.0.6001.18702)<br />
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy<br />
 <br />
894.00 Mb Total Physical Memory | 327.00 Mb Available Physical Memory | 37.00% Memory free<br />
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 74.00% Paging File free<br />
Paging file location(s): C:&#092;pagefile.sys 1344 2688 [binary data]<br />
 <br />
%SystemDrive% = C: | %SystemRoot% = C:&#092;WINDOWS | %ProgramFiles% = C:&#092;Program Files<br />
Drive C: | 108.70 Gb Total Space | 68.85 Gb Free Space | 63.34% Space Free | Partition Type: NTFS<br />
Drive D: | 584.81 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF<br />
E: Drive not present or media not loaded<br />
F: Drive not present or media not loaded<br />
G: Drive not present or media not loaded<br />
H: Drive not present or media not loaded<br />
I: Drive not present or media not loaded<br />
 <br />
Computer Name: JENS<br />
Current User Name: jenni rowe<br />
Logged in as Administrator.<br />
 <br />
Current Boot Mode: Normal<br />
Scan Mode: Current user<br />
Company Name Whitelist: Off<br />
Skip Microsoft Files: Off<br />
File Age = 30 Days<br />
Output = Standard<br />
 <br />
<span style='color: #E56717'>========== Processes (SafeList) ==========</span><br />
 <br />
PRC - [2010/01/29 00:43:14 | 00,548,864 | ---- | M] (OldTimer Tools) -- C:&#092;Documents and Settings&#092;jenni rowe&#092;Desktop&#092;OTL.exe<br />
PRC - [2009/11/12 16:33:10 | 00,141,600 | ---- | M] (Apple Inc.) -- C:&#092;Program Files&#092;iTunes&#092;iTunesHelper.exe<br />
PRC - [2009/11/12 16:33:00 | 00,545,568 | ---- | M] (Apple Inc.) -- C:&#092;Program Files&#092;iPod&#092;bin&#092;iPodService.exe<br />
PRC - [2009/10/29 06:54:44 | 01,218,008 | ---- | M] (McAfee, Inc.) -- C:&#092;Program Files&#092;McAfee.com&#092;Agent&#092;mcagent.exe<br />
PRC - [2009/10/27 10:19:46 | 00,895,696 | ---- | M] (McAfee, Inc.) -- C:&#092;Program Files&#092;McAfee&#092;MPF&#092;MpfSrv.exe<br />
PRC - [2009/09/16 10:22:08 | 00,144,704 | ---- | M] (McAfee, Inc.) -- C:&#092;Program Files&#092;McAfee&#092;VirusScan&#092;Mcshield.exe<br />
PRC - [2009/09/16 09:28:38 | 00,606,736 | ---- | M] (McAfee, Inc.) -- C:&#092;Program Files&#092;McAfee&#092;VirusScan&#092;mcsysmon.exe<br />
PRC - [2009/08/28 19:42:54 | 00,144,672 | ---- | M] (Apple Inc.) -- C:&#092;Program Files&#092;Common Files&#092;Apple&#092;Mobile Device Support&#092;bin&#092;AppleMobileDeviceService.exe<br />
PRC - [2009/07/10 00:26:20 | 00,865,832 | ---- | M] (McAfee, Inc.) -- C:&#092;Program Files&#092;McAfee&#092;MSC&#092;mcmscsvc.exe<br />
PRC - [2009/07/08 14:48:48 | 00,026,640 | ---- | M] (McAfee, Inc.) -- C:&#092;Program Files&#092;McAfee&#092;MSK&#092;msksrver.exe<br />
PRC - [2009/07/08 11:54:34 | 00,359,952 | ---- | M] (McAfee, Inc.) -- c:&#092;Program Files&#092;Common Files&#092;McAfee&#092;McProxy&#092;McProxy.exe<br />
PRC - [2009/07/07 19:10:02 | 02,482,848 | ---- | M] (McAfee, Inc.) -- c:&#092;Program Files&#092;Common Files&#092;McAfee&#092;MNA&#092;McNASvc.exe<br />
PRC - [2009/03/26 17:26:16 | 07,308,800 | ---- | M] () -- C:&#092;Program Files&#092;3 Mobile Broadband&#092;UIMain.exe<br />
PRC - [2009/03/08 14:09:26 | 00,638,816 | ---- | M] (Microsoft Corporation) -- C:&#092;Program Files&#092;Internet Explorer&#092;iexplore.exe<br />
PRC - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:&#092;Program Files&#092;Bonjour&#092;mDNSResponder.exe<br />
PRC - [2008/10/08 15:30:12 | 00,091,648 | ---- | M] () -- C:&#092;WINDOWS&#092;system32&#092;SupportAppXL&#092;AutoDect.exe<br />
PRC - [2008/04/14 08:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:&#092;WINDOWS&#092;explorer.exe<br />
PRC - [2008/02/05 14:16:39 | 00,185,896 | ---- | M] (RealNetworks, Inc.) -- C:&#092;Program Files&#092;Common Files&#092;Real&#092;Update_OB&#092;realsched.exe<br />
PRC - [2007/08/17 11:09:24 | 00,068,856 | ---- | M] (Google Inc.) -- C:&#092;Program Files&#092;Google&#092;GoogleToolbarNotifier&#092;GoogleToolbarNotifier.exe<br />
PRC - [2006/11/23 09:45:34 | 00,020,480 | ---- | M] () -- C:&#092;WINDOWS&#092;system32&#092;WLTRYSVC.EXE<br />
PRC - [2006/11/23 09:45:20 | 01,253,376 | ---- | M] (Dell Inc.) -- C:&#092;WINDOWS&#092;system32&#092;BCMWLTRY.EXE<br />
PRC - [2006/11/05 11:15:12 | 00,880,640 | ---- | M] (Sonic Solutions) -- C:&#092;Program Files&#092;Common Files&#092;Roxio Shared&#092;9.0&#092;SharedCOM&#092;RoxMediaDB9.exe<br />
PRC - [2006/11/05 11:13:00 | 00,159,744 | ---- | M] (Sonic Solutions) -- C:&#092;Program Files&#092;Common Files&#092;Roxio Shared&#092;9.0&#092;SharedCOM&#092;RoxWatch9.exe<br />
PRC - [2006/10/11 12:37:24 | 00,430,080 | ---- | M] (ATI Technologies Inc.) -- C:&#092;WINDOWS&#092;system32&#092;ati2evxx.exe<br />
PRC - [2002/05/10 12:50:04 | 00,065,536 | ---- | M] (America Online, Inc.) -- C:&#092;WINDOWS&#092;wanmpsvc.exe<br />
 <br />
 <br />
<span style='color: #E56717'>========== Modules (SafeList) ==========</span><br />
 <br />
MOD - [2010/01/29 00:43:14 | 00,548,864 | ---- | M] (OldTimer Tools) -- C:&#092;Documents and Settings&#092;jenni rowe&#092;Desktop&#092;OTL.exe<br />
MOD - [2008/04/14 08:12:08 | 00,151,040 | ---- | M] () -- C:&#092;WINDOWS&#092;urefobawut.dll<br />
 <br />
 <br />
<span style='color: #E56717'>========== Win32 Services (SafeList) ==========</span><br />
 <br />
SRV - [2010/01/11 07:14:26 | 00,822,048 | ---- | M] (McAfee, Inc.) [Auto | Stopped] -- C:&#092;WINDOWS&#092;Temp&#092;0105981264623685mcinst.exe -- (0105981264623685mcinstcleanup) McAfee Application Installer Cleanup (0105981264623685)<br />
SRV - [2009/11/12 16:33:00 | 00,545,568 | ---- | M] (Apple Inc.) [On_Demand | Running] -- C:&#092;Program Files&#092;iPod&#092;bin&#092;iPodService.exe -- (iPod Service)<br />
SRV - [2009/10/27 10:19:46 | 00,895,696 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:&#092;Program Files&#092;McAfee&#092;MPF&#092;MPFSrv.exe -- (MpfService)<br />
SRV - [2009/09/16 11:23:32 | 00,365,072 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:&#092;Program Files&#092;McAfee&#092;VirusScan&#092;mcods.exe -- (McODS)<br />
SRV - [2009/09/16 10:22:08 | 00,144,704 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:&#092;Program Files&#092;McAfee&#092;VirusScan&#092;Mcshield.exe -- (McShield)<br />
SRV - [2009/09/16 09:28:38 | 00,606,736 | ---- | M] (McAfee, Inc.) [On_Demand | Running] -- C:&#092;Program Files&#092;McAfee&#092;VirusScan&#092;mcsysmon.exe -- (McSysmon)<br />
SRV - [2009/08/28 19:42:54 | 00,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:&#092;Program Files&#092;Common Files&#092;Apple&#092;Mobile Device Support&#092;bin&#092;AppleMobileDeviceService.exe -- (Apple Mobile Device)<br />
SRV - [2009/07/10 00:26:20 | 00,865,832 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:&#092;Program Files&#092;McAfee&#092;MSC&#092;mcmscsvc.exe -- (mcmscsvc)<br />
SRV - [2009/07/08 14:48:48 | 00,026,640 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:&#092;Program Files&#092;McAfee&#092;MSK&#092;MskSrver.exe -- (MSK80Service)<br />
SRV - [2009/07/08 11:54:34 | 00,359,952 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:&#092;Program Files&#092;Common Files&#092;McAfee&#092;McProxy&#092;McProxy.exe -- (McProxy)<br />
SRV - [2009/07/07 19:10:02 | 02,482,848 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:&#092;program files&#092;common files&#092;mcafee&#092;mna&#092;mcnasvc.exe -- (McNASvc)<br />
SRV - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) [Auto | Running] -- C:&#092;Program Files&#092;Bonjour&#092;mDNSResponder.exe -- (Bonjour Service)<br />
SRV - [2007/08/19 17:32:56 | 01,838,592 | ---- | M] (Google) [On_Demand | Stopped] -- C:&#092;Program Files&#092;Google&#092;Google Desktop Search&#092;GoogleDesktop.exe -- (GoogleDesktopManager)<br />
SRV - [2006/11/23 09:45:34 | 00,020,480 | ---- | M] () [Auto | Running] -- C:&#092;WINDOWS&#092;System32&#092;WLTRYSVC.EXE -- (wltrysvc)<br />
SRV - [2006/11/05 11:15:12 | 00,880,640 | ---- | M] (Sonic Solutions) [On_Demand | Running] -- C:&#092;Program Files&#092;Common Files&#092;Roxio Shared&#092;9.0&#092;SharedCOM&#092;RoxMediaDB9.exe -- (RoxMediaDB9)<br />
SRV - [2006/11/05 11:13:00 | 00,159,744 | ---- | M] (Sonic Solutions) [Auto | Running] -- C:&#092;Program Files&#092;Common Files&#092;Roxio Shared&#092;9.0&#092;SharedCOM&#092;RoxWatch9.exe -- (RoxWatch9)<br />
SRV - [2006/10/11 12:37:24 | 00,430,080 | ---- | M] (ATI Technologies Inc.) [Auto | Running] -- C:&#092;WINDOWS&#092;system32&#092;ati2evxx.exe -- (Ati HotKey Poller)<br />
SRV - [2006/09/14 14:54:34 | 00,073,728 | ---- | M] (MicroVision Development, Inc.) [On_Demand | Stopped] -- C:&#092;Program Files&#092;Common Files&#092;SureThing Shared&#092;stllssvr.exe -- (stllssvr)<br />
SRV - [2005/04/04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:&#092;Program Files&#092;Common Files&#092;InstallShield&#092;Driver&#092;11&#092;Intel 32&#092;IDriverT.exe -- (IDriverT)<br />
SRV - [2004/07/15 01:49:26 | 00,032,768 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:&#092;WINDOWS&#092;Microsoft.NET&#092;Framework&#092;v1.1.4322&#092;aspnet_state.exe -- (aspnet_state)<br />
SRV - [2002/05/10 12:50:04 | 00,065,536 | ---- | M] (America Online, Inc.) [Auto | Running] -- C:&#092;WINDOWS&#092;wanmpsvc.exe -- (WANMiniportService) WAN Miniport (ATW)<br />
 <br />
 <br />
<span style='color: #E56717'>========== Driver Services (SafeList) ==========</span><br />
 <br />
DRV - [2009/09/16 10:22:48 | 00,214,664 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;mfehidk.sys -- (mfehidk)<br />
DRV - [2009/09/16 10:22:48 | 00,079,816 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;mfeavfk.sys -- (mfeavfk)<br />
DRV - [2009/09/16 10:22:48 | 00,040,552 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;mfesmfk.sys -- (mfesmfk)<br />
DRV - [2009/09/16 10:22:48 | 00,035,272 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;mfebopk.sys -- (mfebopk)<br />
DRV - [2009/09/16 10:22:14 | 00,034,248 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;mferkdk.sys -- (mferkdk)<br />
DRV - [2009/08/28 19:42:52 | 00,040,448 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;usbaapl.sys -- (USBAAPL)<br />
DRV - [2009/07/16 12:32:26 | 00,120,136 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;Mpfp.sys -- (MPFP)<br />
DRV - [2009/05/18 14:17:00 | 00,026,600 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;GEARAspiWDM.sys -- (GEARAspiWDM)<br />
DRV - [2009/01/05 16:43:38 | 00,007,680 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;massfilter.sys -- (massfilter)<br />
DRV - [2008/11/08 21:02:38 | 00,104,960 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;ZTEusbnmea.sys -- (ZTEusbnmea)<br />
DRV - [2008/11/08 21:02:24 | 00,104,960 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;ZTEusbmdm6k.sys -- (ZTEusbmdm6k)<br />
DRV - [2008/04/14 02:36:39 | 00,043,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;DRIVERS&#092;amdagp.sys -- (amdagp)<br />
DRV - [2008/04/14 02:36:39 | 00,040,960 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;DRIVERS&#092;sisagp.sys -- (sisagp)<br />
DRV - [2008/04/14 00:36:05 | 00,144,384 | ---- | M] (Windows &reg; Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;hdaudbus.sys -- (HDAudBus)<br />
DRV - [2007/11/13 18:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | On_Demand | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;secdrv.sys -- (Secdrv)<br />
DRV - [2006/11/23 09:45:24 | 00,604,928 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;BCMWL5.SYS -- (BCM43XX)<br />
DRV - [2006/10/11 12:43:56 | 01,777,152 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;ati2mtag.sys -- (ati2mtag)<br />
DRV - [2006/09/22 11:47:52 | 00,191,872 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;SynTP.sys -- (SynTP)<br />
DRV - [2006/09/22 11:06:26 | 01,171,464 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;sthda.sys -- (STHDA)<br />
DRV - [2006/08/18 13:18:08 | 00,009,400 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:&#092;WINDOWS&#092;system32&#092;DLA&#092;DLADResM.SYS -- (DLADResM)<br />
DRV - [2006/08/18 13:17:46 | 00,035,096 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:&#092;WINDOWS&#092;system32&#092;DLA&#092;DLABMFSM.SYS -- (DLABMFSM)<br />
DRV - [2006/08/18 13:17:44 | 00,097,848 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:&#092;WINDOWS&#092;system32&#092;DLA&#092;DLAUDF_M.SYS -- (DLAUDF_M)<br />
DRV - [2006/08/18 13:17:44 | 00,094,648 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:&#092;WINDOWS&#092;system32&#092;DLA&#092;DLAUDFAM.SYS -- (DLAUDFAM)<br />
DRV - [2006/08/18 13:17:42 | 00,026,008 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:&#092;WINDOWS&#092;system32&#092;DLA&#092;DLAOPIOM.SYS -- (DLAOPIOM)<br />
DRV - [2006/08/18 13:17:40 | 00,032,472 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:&#092;WINDOWS&#092;system32&#092;DLA&#092;DLABOIOM.SYS -- (DLABOIOM)<br />
DRV - [2006/08/18 13:17:38 | 00,104,472 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:&#092;WINDOWS&#092;system32&#092;DLA&#092;DLAIFS_M.SYS -- (DLAIFS_M)<br />
DRV - [2006/08/18 13:17:38 | 00,014,520 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:&#092;WINDOWS&#092;system32&#092;DLA&#092;DLAPoolM.SYS -- (DLAPoolM)<br />
DRV - [2006/08/17 13:55:16 | 00,044,544 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;bcm4sbxp.sys -- (bcm4sbxp)<br />
DRV - [2006/08/11 11:05:58 | 00,051,768 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;DRVNDDM.SYS -- (DRVNDDM)<br />
DRV - [2006/08/11 10:35:18 | 00,012,920 | ---- | M] (Roxio) [File_System | System | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;DLACDBHM.SYS -- (DLACDBHM)<br />
DRV - [2006/08/11 10:35:16 | 00,028,184 | ---- | M] (Roxio) [File_System | System | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;DLARTL_M.SYS -- (DLARTL_M)<br />
DRV - [2006/07/24 03:00:00 | 00,036,528 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:&#092;WINDOWS&#092;System32&#092;Drivers&#092;PxHelp20.sys -- (PxHelp20)<br />
DRV - [2006/07/21 11:21:26 | 00,099,176 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:&#092;WINDOWS&#092;System32&#092;Drivers&#092;DRVMCDB.SYS -- (DRVMCDB)<br />
DRV - [2006/07/01 22:39:40 | 00,036,864 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;AmdK8.sys -- (AmdK8)<br />
DRV - [2006/01/10 11:07:58 | 00,004,864 | ---- | M] (GTek Technologies Ltd.) [Kernel | On_Demand | Stopped] -- C:&#092;Program Files&#092;Dell Support&#092;GTAction&#092;triggers&#092;DSproct.sys -- (DSproct)<br />
DRV - [2005/12/01 07:40:56 | 00,936,960 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;HSX_DPV.sys -- (HSF_DPV)<br />
DRV - [2005/12/01 07:40:12 | 00,192,512 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;HSXHWAZL.sys -- (HSXHWAZL)<br />
DRV - [2005/12/01 07:40:08 | 00,669,696 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;HSX_CNXT.sys -- (winachsf)<br />
DRV - [2005/10/05 04:57:08 | 00,012,544 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;mdmxsdk.sys -- (mdmxsdk)<br />
DRV - [2005/08/12 16:50:46 | 00,016,128 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:&#092;WINDOWS&#092;SYSTEM32&#092;DRIVERS&#092;APPDRV.SYS -- (APPDRV)<br />
DRV - [2005/07/14 23:58:14 | 00,028,544 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;rimmptsk.sys -- (rimmptsk)<br />
DRV - [2004/08/04 05:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;ptilink.sys -- (Ptilink)<br />
DRV - [2004/08/03 22:29:56 | 01,897,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;nv4_mini.sys -- (nv)<br />
DRV - [2002/02/05 16:30:42 | 00,028,396 | ---- | M] (America Online, Inc.) [Kernel | On_Demand | Running] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;wanatw4.sys -- (wanatw) WAN Miniport (ATW)<br />
DRV - [2001/08/17 14:07:44 | 00,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;DRIVERS&#092;sparrow.sys -- (Sparrow)<br />
DRV - [2001/08/17 14:07:42 | 00,030,688 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;DRIVERS&#092;sym_u3.sys -- (sym_u3)<br />
DRV - [2001/08/17 14:07:40 | 00,028,384 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;DRIVERS&#092;sym_hi.sys -- (sym_hi)<br />
DRV - [2001/08/17 14:07:36 | 00,032,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;DRIVERS&#092;symc8xx.sys -- (symc8xx)<br />
DRV - [2001/08/17 14:07:34 | 00,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;DRIVERS&#092;symc810.sys -- (symc810)<br />
DRV - [2001/08/17 13:52:22 | 00,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;DRIVERS&#092;ultra.sys -- (ultra)<br />
DRV - [2001/08/17 13:52:20 | 00,045,312 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;DRIVERS&#092;ql12160.sys -- (ql12160)<br />
DRV - [2001/08/17 13:52:20 | 00,040,320 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;DRIVERS&#092;ql1080.sys -- (ql1080)<br />
DRV - [2001/08/17 13:52:18 | 00,049,024 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;DRIVERS&#092;ql1280.sys -- (ql1280)<br />
DRV - [2001/08/17 13:52:16 | 00,179,584 | ---- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;DRIVERS&#092;dac2w2k.sys -- (dac2w2k)<br />
DRV - [2001/08/17 13:52:12 | 00,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;DRIVERS&#092;mraid35x.sys -- (mraid35x)<br />
DRV - [2001/08/17 13:52:00 | 00,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;DRIVERS&#092;asc.sys -- (asc)<br />
DRV - [2001/08/17 13:51:58 | 00,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;DRIVERS&#092;asc3550.sys -- (asc3550)<br />
DRV - [2001/08/17 13:51:56 | 00,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;DRIVERS&#092;aliide.sys -- (AliIde)<br />
DRV - [2001/08/17 13:51:54 | 00,006,656 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;DRIVERS&#092;cmdide.sys -- (CmdIde)<br />
DRV - [2001/08/17 12:12:10 | 00,117,760 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;e100b325.sys -- (E100B) Intel&reg;<br />
 <br />
 <br />
<span style='color: #E56717'>========== Standard Registry (SafeList) ==========</span><br />
 <br />
 <br />
<span style='color: #E56717'>========== Internet Explorer ==========</span><br />
 <br />
IE - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Search,Default_Page_URL = www.google.com.au/ig/dell?hl=en&client=dell-row&channel=au&ibd=5070810<br />
IE - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Search,Default_Search_URL = <a href='http://www.google.com/ie' class='bbc_url' title='External link' rel='nofollow'>http://www.google.com/ie</a><br />
IE - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Search,SearchAssistant = <a href='http://www.google.com/ie' class='bbc_url' title='External link' rel='nofollow'>http://www.google.com/ie</a><br />
IE - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Search,Start Page = www.google.com.au/ig/dell?hl=en&client=dell-row&channel=au&ibd=5070810<br />
 <br />
IE - HKCU&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Page_URL = www.google.com.au/ig/dell?hl=en&client=dell-row&channel=au&ibd=5070810<br />
IE - HKCU&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = <a href='http://www.google.com.au/hws/sb/dell-row/en/side.html?channel=au' class='bbc_url' title='External link' rel='nofollow'>http://www.google.com.au/hws/sb/dell-row/en/side.html?channel=au</a><br />
IE - HKCU&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = <a href='http://www.hotmail.com/' class='bbc_url' title='External link' rel='nofollow'>http://www.hotmail.com/</a><br />
IE - HKCU&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Search,SearchAssistant = <a href='http://www.google.com/ie' class='bbc_url' title='External link' rel='nofollow'>http://www.google.com/ie</a><br />
IE - HKCU&#092;Software&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Internet Settings: "ProxyEnable" = 0<br />
 <br />
<span style='color: #E56717'>========== FireFox ==========</span><br />
 <br />
FF - prefs.js..browser.search.defaultenginename: "Google"<br />
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="<br />
FF - prefs.js..browser.search.selectedEngine: "Google"<br />
 <br />
 <br />
FF - HKLM&#092;software&#092;mozilla&#092;Firefox&#092;Extensions&#092;&#092;{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:&#092;Program Files&#092;Real&#092;RealPlayer&#092;browserrecord [2008/02/05 14:17:10 | 00,000,000 | ---D | M]<br />
FF - HKLM&#092;software&#092;mozilla&#092;Firefox&#092;Extensions&#092;&#092;{DC16D17D-C041-41AE-98E5-30513F8FA33B}: C:&#092;Documents and Settings&#092;jenni rowe&#092;Local Settings&#092;Application Data&#092;{DC16D17D-C041-41AE-98E5-30513F8FA33B}<br />
FF - HKLM&#092;software&#092;mozilla&#092;Mozilla Firefox 2.0&#092;extensions&#092;&#092;Components: C:&#092;Program Files&#092;Mozilla Firefox&#092;components [2008/02/05 14:17:59 | 00,000,000 | ---D | M]<br />
FF - HKLM&#092;software&#092;mozilla&#092;Mozilla Firefox 2.0&#092;extensions&#092;&#092;Plugins: C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins [2010/01/06 04:34:16 | 00,000,000 | ---D | M]<br />
 <br />
[2008/02/05 14:17:59 | 00,000,000 | ---D | M] -- C:&#092;Documents and Settings&#092;jenni rowe&#092;Application Data&#092;Mozilla&#092;Firefox&#092;Profiles&#092;6quf75kj.default&#092;extensions<br />
[2008/02/05 14:15:41 | 00,000,000 | ---D | M] -- C:&#092;Program Files&#092;Mozilla Firefox&#092;extensions<br />
[2008/02/05 14:15:42 | 00,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:&#092;Program Files&#092;Mozilla Firefox&#092;extensions&#092;{3112ca9c-de6d-4884-a869-9855de68056c}<br />
[2008/02/05 14:15:25 | 00,000,000 | ---D | M] -- C:&#092;Program Files&#092;Mozilla Firefox&#092;extensions&#092;real-networks@partners.mozilla.com<br />
[2008/02/05 14:15:29 | 00,000,000 | ---D | M] -- C:&#092;Program Files&#092;Mozilla Firefox&#092;extensions&#092;talkback@mozilla.org<br />
[2006/10/11 16:04:58 | 00,061,036 | ---- | M] (Mozilla Foundation) -- C:&#092;Program Files&#092;Mozilla Firefox&#092;components&#092;jar50.dll<br />
[2006/10/11 16:04:59 | 00,048,742 | ---- | M] (Mozilla Foundation) -- C:&#092;Program Files&#092;Mozilla Firefox&#092;components&#092;jsd3250.dll<br />
[2006/10/11 16:05:03 | 00,029,313 | ---- | M] (Mozilla Foundation) -- C:&#092;Program Files&#092;Mozilla Firefox&#092;components&#092;myspell.dll<br />
[2006/10/11 16:05:03 | 00,041,082 | ---- | M] (Mozilla Foundation) -- C:&#092;Program Files&#092;Mozilla Firefox&#092;components&#092;spellchk.dll<br />
[2006/10/11 16:04:58 | 00,166,510 | ---- | M] (Mozilla Foundation) -- C:&#092;Program Files&#092;Mozilla Firefox&#092;components&#092;xpinstal.dll<br />
 <br />
O1 HOSTS File: ([2004/08/04 05:00:00 | 00,000,734 | ---- | M]) - C:&#092;WINDOWS&#092;system32&#092;drivers&#092;etc&#092;hosts<br />
O1 - Hosts: 127.0.0.1       localhost<br />
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:&#092;Program Files&#092;Common Files&#092;Adobe&#092;Acrobat&#092;ActiveX&#092;AcroIEHelperShim.dll (Adobe Systems Incorporated)<br />
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:&#092;Program Files&#092;McAfee&#092;MSK&#092;mskapbho.dll ()<br />
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:&#092;Program Files&#092;Real&#092;RealPlayer&#092;rpbrowserrecordplugin.dll (RealPlayer)<br />
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:&#092;Program Files&#092;Java&#092;jre1.5.0_06&#092;bin&#092;ssv.dll (Sun Microsystems, Inc.)<br />
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:&#092;Program Files&#092;McAfee&#092;VirusScan&#092;scriptsn.dll (McAfee, Inc.)<br />
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:&#092;Program Files&#092;Google&#092;Google Toolbar&#092;GoogleToolbar.dll ()<br />
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:&#092;Program Files&#092;Google&#092;GoogleToolbarNotifier&#092;5.4.4525.1752&#092;swg.dll (Google Inc.)<br />
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:&#092;Program Files&#092;BAE&#092;BAE.dll (Dell Inc.)<br />
O2 - BHO: (PrimoAdsForYou) - {D35DA2A5-1D09-03BB-FE6E-C569BE05CFA0} - C:&#092;Program Files&#092;PrimoAdsForYou&#092;PrimoAdsForYou.dll ()<br />
O3 - HKLM&#092;..&#092;Toolbar: (&Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:&#092;Program Files&#092;Google&#092;Google Toolbar&#092;GoogleToolbar.dll ()<br />
O3 - HKCU&#092;..&#092;Toolbar&#092;ShellBrowser: (&Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:&#092;Program Files&#092;Google&#092;Google Toolbar&#092;GoogleToolbar.dll ()<br />
O3 - HKCU&#092;..&#092;Toolbar&#092;WebBrowser: (&Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:&#092;Program Files&#092;Google&#092;Google Toolbar&#092;GoogleToolbar.dll ()<br />
O4 - HKLM..&#092;Run: [Adobe Reader Speed Launcher] C:&#092;Program Files&#092;Adobe&#092;Reader 9.0&#092;Reader&#092;Reader_sl.exe (Adobe Systems Incorporated)<br />
O4 - HKLM..&#092;Run: [autodetect] C:&#092;WINDOWS&#092;system32&#092;SupportAppXL&#092;AutoDect.exe ()<br />
O4 - HKLM..&#092;Run: [iTunesHelper] C:&#092;Program Files&#092;iTunes&#092;iTunesHelper.exe (Apple Inc.)<br />
O4 - HKLM..&#092;Run: [KernelFaultCheck]  File not found<br />
O4 - HKLM..&#092;Run: [mcagent_exe] C:&#092;Program Files&#092;McAfee.com&#092;Agent&#092;mcagent.exe (McAfee, Inc.)<br />
O4 - HKLM..&#092;Run: [QuickTime Task] C:&#092;Program Files&#092;QuickTime&#092;qttask.exe (Apple Inc.)<br />
O4 - HKLM..&#092;Run: [TkBellExe] C:&#092;Program Files&#092;Common Files&#092;Real&#092;Update_OB&#092;realsched.exe (RealNetworks, Inc.)<br />
O4 - HKLM..&#092;Run: [Tpebiyayidadot] C:&#092;WINDOWS&#092;urefobawut.DLL ()<br />
O4 - HKCU..&#092;Run: [swg] C:&#092;Program Files&#092;Google&#092;GoogleToolbarNotifier&#092;GoogleToolbarNotifier.exe (Google Inc.)<br />
O4 - HKLM..&#092;RunOnceEx: []  File not found<br />
O6 - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;Explorer: HonorAutoRunSetting = 1<br />
O7 - HKCU&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;Explorer: NoDriveTypeAutoRun = 145<br />
O8 - Extra context menu item: E&xport to Microsoft Excel - C:&#092;Program Files&#092;Microsoft Office&#092;Office10&#092;EXCEL.EXE (Microsoft Corporation)<br />
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:&#092;Program Files&#092;Java&#092;jre1.5.0_06&#092;bin&#092;NPJPI150_06.dll (Sun Microsystems, Inc.)<br />
O9 - Extra Button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:&#092;Program Files&#092;Bonjour&#092;ExplorerPlugin.dll File not found<br />
O10 - NameSpace_Catalog5&#092;Catalog_Entries&#092;000000000004 [] - C:&#092;Program Files&#092;Bonjour&#092;mdnsNSP.dll (Apple Inc.)<br />
O15 - HKLM&#092;..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.<br />
O15 - HKCU&#092;..Trusted Domains: internet ([]about in Trusted sites)<br />
O15 - HKCU&#092;..Trusted Domains: mcafee.com ([]http in Trusted sites)<br />
O15 - HKCU&#092;..Trusted Domains: mcafee.com ([]https in Trusted sites)<br />
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} <a href='http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab' class='bbc_url' title='External link' rel='nofollow'>http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab</a> (Java Plug-in 1.5.0_06)<br />
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} <a href='http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab' class='bbc_url' title='External link' rel='nofollow'>http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab</a> (Java Plug-in 1.5.0_06)<br />
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <a href='http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab' class='bbc_url' title='External link' rel='nofollow'>http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab</a> (Java Plug-in 1.5.0_06)<br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} <a href='http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab' class='bbc_url' title='External link' rel='nofollow'>http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab</a> (Shockwave Flash Object)<br />
O20 - AppInit_DLLs: (C:&#092;PROGRA~1&#092;Google&#092;GOOGLE~1&#092;GOEC62~1.DLL) - C:&#092;Program Files&#092;Google&#092;Google Desktop Search&#092;GoogleDesktopNetwork3.dll (Google)<br />
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:&#092;WINDOWS&#092;explorer.exe (Microsoft Corporation)<br />
O20 - Winlogon&#092;Notify&#092;AtiExtEvent: DllName - Ati2evxx.dll - C:&#092;WINDOWS&#092;System32&#092;ati2evxx.dll (ATI Technologies Inc.)<br />
O24 - Desktop WallPaper: C:&#092;Documents and Settings&#092;jenni rowe&#092;Local Settings&#092;Application Data&#092;Microsoft&#092;Wallpaper1.bmp<br />
O24 - Desktop BackupWallPaper: C:&#092;Documents and Settings&#092;jenni rowe&#092;Local Settings&#092;Application Data&#092;Microsoft&#092;Wallpaper1.bmp<br />
O32 - HKLM CDRom: AutoRun - 1<br />
O32 - AutoRun File - [2004/08/10 13:04:08 | 00,000,000 | ---- | M] () - C:&#092;AUTOEXEC.BAT -- [ NTFS ]<br />
O33 - MountPoints2&#092;{8d4fa3e0-45ca-11dd-9cf2-00038a000015}&#092;Shell&#092;AutoRun&#092;command - "" = F:&#092;Autorun.exe -- File not found<br />
O33 - MountPoints2&#092;{8d4fa3e0-45ca-11dd-9cf2-00038a000015}&#092;Shell&#092;Shell00&#092;Command - "" = F:&#092;Autorun.exe -- File not found<br />
O33 - MountPoints2&#092;{8d4fa3e0-45ca-11dd-9cf2-00038a000015}&#092;Shell&#092;Shell01&#092;Command - "" = F:&#092;Autorun.exe -- File not found<br />
O33 - MountPoints2&#092;{8d4fa3e0-45ca-11dd-9cf2-00038a000015}&#092;Shell&#092;Shell02&#092;Command - "" = F:&#092;Autorun.exe -- File not found<br />
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found<br />
O35 - comfile [open] -- "%1" %*<br />
O35 - exefile [open] -- "%1" %*<br />
 <br />
NetSvcs: 6to4 -  File not found<br />
NetSvcs: Ias - C:&#092;WINDOWS&#092;system32&#092;ias [2004/08/10 12:52:56 | 00,000,000 | ---D | M]<br />
NetSvcs: Iprip -  File not found<br />
NetSvcs: Irmon -  File not found<br />
NetSvcs: NWCWorkstation -  File not found<br />
NetSvcs: Nwsapagent -  File not found<br />
NetSvcs: Wmi - C:&#092;WINDOWS&#092;system32&#092;wmi.dll (Microsoft Corporation)<br />
NetSvcs: WmdmPmSp -  File not found<br />
 <br />
MsConfig - StartUpFolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL 7.0 Tray Icon.lnk - C:&#092;Program Files&#092;AOL 7.0&#092;aoltray.exe - (America Online, Inc.)<br />
MsConfig - StartUpFolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk - C:&#092;Program Files&#092;Digital Line Detect&#092;DLG.exe - (BVRP Software)<br />
MsConfig - StartUpFolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk - C:&#092;Program Files&#092;Kodak&#092;Kodak EasyShare software&#092;bin&#092;EasyShare.exe - ()<br />
MsConfig - StartUpFolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk - C:&#092;Program Files&#092;Microsoft Office&#092;Office10&#092;OSA.EXE - (Microsoft Corporation)<br />
MsConfig - StartUpFolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Unwired Launchpad.lnk - C:&#092;Program Files&#092;Unwired&#092;UwSCT.exe - (Unwired Australia Pty Limited)<br />
MsConfig - StartUpReg: <strong class='bbc'>ATICCC</strong> - hkey= - key= - C:&#092;Program Files&#092;ATI Technologies&#092;ATI.ACE&#092;CLIStart.exe ()<br />
MsConfig - StartUpReg: <strong class='bbc'>Broadcom Wireless Manager UI</strong> - hkey= - key= -  File not found<br />
MsConfig - StartUpReg: <strong class='bbc'>CTSVolFE.exe</strong> - hkey= - key= - C:&#092;Program Files&#092;Creative&#092;Mixer&#092;CTSVolFE.exe (Creative Technology Ltd)<br />
MsConfig - StartUpReg: <strong class='bbc'>Dell QuickSet</strong> - hkey= - key= - C:&#092;Program Files&#092;Dell&#092;QuickSet&#092;quickset.exe (Dell Inc)<br />
MsConfig - StartUpReg: <strong class='bbc'>DellSupport</strong> - hkey= - key= - C:&#092;Program Files&#092;Dell Support&#092;DSAgnt.exe (Gteko Ltd.)<br />
MsConfig - StartUpReg: <strong class='bbc'>DVDLauncher</strong> - hkey= - key= - C:&#092;Program Files&#092;CyberLink&#092;PowerDVD&#092;DVDLauncher.exe (CyberLink Corp.)<br />
MsConfig - StartUpReg: <strong class='bbc'>Google Desktop Search</strong> - hkey= - key= - C:&#092;Program Files&#092;Google&#092;Google Desktop Search&#092;GoogleDesktop.exe (Google)<br />
MsConfig - StartUpReg: <strong class='bbc'>IMJPMIG8.1</strong> - hkey= - key= - C:&#092;WINDOWS&#092;IME&#092;imjp8_1&#092;IMJPMIG.EXE (Microsoft Corporation)<br />
MsConfig - StartUpReg: <strong class='bbc'>ISUSPM Startup</strong> - hkey= - key= - C:&#092;Program Files&#092;Common Files&#092;InstallShield&#092;UpdateService&#092;ISUSPM.exe (Macrovision Corporation)<br />
MsConfig - StartUpReg: <strong class='bbc'>ISUSScheduler</strong> - hkey= - key= - C:&#092;Program Files&#092;Common Files&#092;InstallShield&#092;UpdateService&#092;issch.exe (Macrovision Corporation)<br />
MsConfig - StartUpReg: <strong class='bbc'>ModemOnHold</strong> - hkey= - key= - C:&#092;Program Files&#092;NetWaiting&#092;netwaiting.exe ()<br />
MsConfig - StartUpReg: <strong class='bbc'>MskAgentexe</strong> - hkey= - key= - C:&#092;Program Files&#092;McAfee&#092;MSK&#092;MskAgent.exe File not found<br />
MsConfig - StartUpReg: <strong class='bbc'>MSMSGS</strong> - hkey= - key= - C:&#092;Program Files&#092;Messenger&#092;msmsgs.exe (Microsoft Corporation)<br />
MsConfig - StartUpReg: <strong class='bbc'>MSPY2002</strong> - hkey= - key= -  File not found<br />
MsConfig - StartUpReg: <strong class='bbc'>PHIME2002A</strong> - hkey= - key= -  File not found<br />
MsConfig - StartUpReg: <strong class='bbc'>PHIME2002ASync</strong> - hkey= - key= -  File not found<br />
MsConfig - StartUpReg: <strong class='bbc'>QuickTime Task</strong> - hkey= - key= - C:&#092;Program Files&#092;QuickTime&#092;qttask.exe (Apple Inc.)<br />
MsConfig - StartUpReg: <strong class='bbc'>RealTray</strong> - hkey= - key= - C:&#092;Program Files&#092;Real&#092;RealPlayer&#092;RealPlay.exe (RealNetworks, Inc.)<br />
MsConfig - StartUpReg: <strong class='bbc'>RoxioDragToDisc</strong> - hkey= - key= - C:&#092;Program Files&#092;Roxio&#092;Drag-to-Disc&#092;DrgToDsc.exe (Roxio)<br />
MsConfig - StartUpReg: <strong class='bbc'>RoxWatchTray</strong> - hkey= - key= - C:&#092;Program Files&#092;Common Files&#092;Roxio Shared&#092;9.0&#092;SharedCOM&#092;RoxWatchTray9.exe (Sonic Solutions)<br />
MsConfig - StartUpReg: <strong class='bbc'>SigmatelSysTrayApp</strong> - hkey= - key= - C:&#092;WINDOWS&#092;stsystra.exe (SigmaTel, Inc.)<br />
MsConfig - StartUpReg: <strong class='bbc'>SunJavaUpdateSched</strong> - hkey= - key= - C:&#092;Program Files&#092;Java&#092;jre1.5.0_06&#092;bin&#092;jusched.exe (Sun Microsystems, Inc.)<br />
MsConfig - StartUpReg: <strong class='bbc'>swg</strong> - hkey= - key= - C:&#092;Program Files&#092;Google&#092;GoogleToolbarNotifier&#092;GoogleToolbarNotifier.exe (Google Inc.)<br />
MsConfig - StartUpReg: <strong class='bbc'>SynTPEnh</strong> - hkey= - key= - C:&#092;Program Files&#092;Synaptics&#092;SynTP&#092;SynTPEnh.exe (Synaptics, Inc.)<br />
MsConfig - State: "system.ini" - 0<br />
MsConfig - State: "win.ini" - 0<br />
MsConfig - State: "bootini" - 0<br />
MsConfig - State: "services" - 0<br />
MsConfig - State: "startup" - 1<br />
 <br />
SafeBootMin: Base - Driver Group<br />
SafeBootMin: Boot Bus Extender - Driver Group<br />
SafeBootMin: Boot file system - Driver Group<br />
SafeBootMin: File system - Driver Group<br />
SafeBootMin: Filter - Driver Group<br />
SafeBootMin: mcmscsvc - C:&#092;Program Files&#092;McAfee&#092;MSC&#092;mcmscsvc.exe (McAfee, Inc.)<br />
SafeBootMin: MCODS - C:&#092;Program Files&#092;McAfee&#092;VirusScan&#092;mcods.exe (McAfee, Inc.)<br />
SafeBootMin: PCI Configuration - Driver Group<br />
SafeBootMin: PNP Filter - Driver Group<br />
SafeBootMin: Primary disk - Driver Group<br />
SafeBootMin: SCSI Class - Driver Group<br />
SafeBootMin: sermouse.sys - Driver<br />
SafeBootMin: System Bus Extender - Driver Group<br />
SafeBootMin: vds - Service<br />
SafeBootMin: vga.sys - Driver<br />
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers<br />
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive<br />
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive<br />
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller<br />
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc<br />
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard<br />
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse<br />
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters<br />
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter<br />
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System<br />
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive<br />
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy<br />
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume<br />
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices<br />
 <br />
SafeBootNet: Base - Driver Group<br />
SafeBootNet: Boot Bus Extender - Driver Group<br />
SafeBootNet: Boot file system - Driver Group<br />
SafeBootNet: File system - Driver Group<br />
SafeBootNet: Filter - Driver Group<br />
SafeBootNet: mcmscsvc - C:&#092;Program Files&#092;McAfee&#092;MSC&#092;mcmscsvc.exe (McAfee, Inc.)<br />
SafeBootNet: MCODS - C:&#092;Program Files&#092;McAfee&#092;VirusScan&#092;mcods.exe (McAfee, Inc.)<br />
SafeBootNet: MpfService - C:&#092;Program Files&#092;McAfee&#092;MPF&#092;MPFSrv.exe (McAfee, Inc.)<br />
SafeBootNet: NDIS Wrapper - Driver Group<br />
SafeBootNet: NetBIOSGroup - Driver Group<br />
SafeBootNet: NetDDEGroup - Driver Group<br />
SafeBootNet: Network - Driver Group<br />
SafeBootNet: NetworkProvider - Driver Group<br />
SafeBootNet: PCI Configuration - Driver Group<br />
SafeBootNet: PNP Filter - Driver Group<br />
SafeBootNet: PNP_TDI - Driver Group<br />
SafeBootNet: Primary disk - Driver Group<br />
SafeBootNet: SCSI Class - Driver Group<br />
SafeBootNet: sermouse.sys - Driver<br />
SafeBootNet: Streams Drivers - Driver Group<br />
SafeBootNet: System Bus Extender - Driver Group<br />
SafeBootNet: TDI - Driver Group<br />
SafeBootNet: vga.sys - Driver<br />
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers<br />
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive<br />
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive<br />
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller<br />
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc<br />
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard<br />
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse<br />
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net<br />
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient<br />
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService<br />
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans<br />
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters<br />
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter<br />
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System<br />
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive<br />
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume<br />
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices<br />
 <br />
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)<br />
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)<br />
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow<br />
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4<br />
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation<br />
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%&#092;system32&#092;regsvr32.exe /s /n /i:/UserInstall %SystemRoot%&#092;system32&#092;themeui.dll<br />
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java<br />
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack<br />
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe<br />
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)<br />
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring<br />
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%&#092;Outlook Express&#092;setup50.exe" /APP:OE /CALLER:WINNT /user /install<br />
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:&#092;WINDOWS&#092;INF&#092;msnetmtg.inf,NetMtg.Install.PerUser.NT<br />
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow<br />
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx<br />
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help<br />
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes<br />
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6<br />
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:&#092;WINDOWS&#092;INF&#092;msmsgs.inf,BLC.QuietInstall.PerUser<br />
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW<br />
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools<br />
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements<br />
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player<br />
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access<br />
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders<br />
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%&#092;Outlook Express&#092;setup50.exe" /APP:WAB /CALLER:WINNT /user /install<br />
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll<br />
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:&#092;WINDOWS&#092;system32&#092;ie4uinit.exe -BaseSettings<br />
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:&#092;WINDOWS&#092;system32&#092;Rundll32.exe C:&#092;WINDOWS&#092;system32&#092;mscories.dll,Install<br />
ActiveX: {8b15971b-5355-4c82-8c07-7e181ea07608} - rundll32.exe advpack.dll,LaunchINFSection C:&#092;WINDOWS&#092;INF&#092;fxsocm.inf,Fax.Install.PerUser<br />
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding<br />
ActiveX: {94de52c8-2d59-4f1b-883e-79663d2d9a8c} - Fax Provider<br />
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts<br />
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework<br />
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler<br />
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1<br />
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player<br />
ActiveX: {DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D} - Microsoft .NET Framework 1.1 Security Update (KB953297)<br />
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help<br />
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface<br />
ActiveX: &lt;{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:&#092;WINDOWS&#092;system32&#092;ieudinit.exe<br />
ActiveX: &gt;{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:&#092;WINDOWS&#092;inf&#092;unregmp2.exe /ShowWMP<br />
ActiveX: &gt;{26923b43-4d38-484f-9b9e-de460746276c} - C:&#092;WINDOWS&#092;system32&#092;ie4uinit.exe -UserIconConfig<br />
ActiveX: &gt;{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:&#092;WINDOWS&#092;system32&#092;rundll32.exe" "C:&#092;WINDOWS&#092;system32&#092;iedkcs32.dll",BrandIEActiveSetup SIGNUP<br />
ActiveX: &gt;{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP<br />
ActiveX: &gt;{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%&#092;system32&#092;shmgrate.exe OCInstallUserConfigOE<br />
 <br />
Drivers32: msacm.iac2 - C:&#092;WINDOWS&#092;system32&#092;iac25_32.ax (Intel Corporation)<br />
Drivers32: msacm.l3acm - C:&#092;WINDOWS&#092;system32&#092;l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)<br />
Drivers32: msacm.sl_anet - C:&#092;WINDOWS&#092;System32&#092;sl_anet.acm (Sipro Lab Telecom Inc.)<br />
Drivers32: msacm.trspch - C:&#092;WINDOWS&#092;System32&#092;tssoft32.acm (DSP GROUP, INC.)<br />
Drivers32: vidc.cvid - C:&#092;WINDOWS&#092;System32&#092;iccvid.dll (Radius Inc.)<br />
Drivers32: vidc.iv31 - C:&#092;WINDOWS&#092;System32&#092;ir32_32.dll ()<br />
Drivers32: vidc.iv32 - C:&#092;WINDOWS&#092;System32&#092;ir32_32.dll ()<br />
Drivers32: vidc.iv41 - C:&#092;WINDOWS&#092;System32&#092;ir41_32.ax (Intel Corporation)<br />
Drivers32: vidc.iv50 - C:&#092;WINDOWS&#092;System32&#092;ir50_32.dll (Intel Corporation)<br />
 <br />
CREATERESTOREPOINT<br />
Restore point Set: OTL Restore Point (68683287341563904)<br />
 <br />
<span style='color: #E56717'>========== Files/Folders - Created Within 30 Days ==========</span><br />
 <br />
[2010/01/29 00:43:09 | 00,548,864 | ---- | C] (OldTimer Tools) -- C:&#092;Documents and Settings&#092;jenni rowe&#092;Desktop&#092;OTL.exe<br />
[2010/01/29 00:41:24 | 00,000,000 | ---D | C] -- C:&#092;WINDOWS&#092;ERDNT<br />
[2010/01/29 00:40:05 | 00,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;jenni rowe&#092;Desktop&#092;erunt<br />
[2010/01/29 00:35:35 | 00,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;jenni rowe&#092;Desktop&#092;SysRestorePoint_v12<br />
[2010/01/28 22:01:52 | 00,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;jenni rowe&#092;Application Data&#092;AVG8<br />
[2010/01/28 06:39:05 | 00,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;jenni rowe&#092;Application Data&#092;McAfee<br />
[2010/01/27 03:59:59 | 00,000,000 | ---D | C] -- C:&#092;WINDOWS&#092;Minidump<br />
[2010/01/12 21:51:36 | 00,471,552 | ---- | C] (Microsoft Corporation) -- C:&#092;WINDOWS&#092;System32&#092;dllcache&#092;aclayers.dll<br />
[2010/01/11 19:18:02 | 00,000,000 | ---D | M] -- C:&#092;Documents and Settings&#092;NetworkService&#092;Local Settings&#092;Application Data&#092;Apple<br />
[2010/01/06 16:30:27 | 00,107,368 | ---- | C] (GEAR Software Inc.) -- C:&#092;WINDOWS&#092;System32&#092;GEARAspi.dll<br />
[2010/01/06 16:30:27 | 00,026,600 | ---- | C] (GEAR Software Inc.) -- C:&#092;WINDOWS&#092;System32&#092;drivers&#092;GEARAspiWDM.sys<br />
[2010/01/06 16:28:15 | 00,000,000 | ---D | C] -- C:&#092;Program Files&#092;iPod<br />
[2010/01/06 16:28:07 | 00,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;All Users&#092;Application Data&#092;{755AC846-7372-4AC8-8550-C52491DAA8BD}<br />
[2010/01/06 16:27:16 | 02,065,696 | ---- | C] (Apple, Inc.) -- C:&#092;WINDOWS&#092;System32&#092;usbaaplrc.dll<br />
[2010/01/06 16:27:16 | 00,040,448 | ---- | C] (Apple, Inc.) -- C:&#092;WINDOWS&#092;System32&#092;drivers&#092;usbaapl.sys<br />
[2010/01/06 08:21:23 | 93,234,472 | ---- | C] (Apple Inc.) -- C:&#092;Documents and Settings&#092;jenni rowe&#092;Desktop&#092;iTunesSetup.exe<br />
[2010/01/06 04:29:50 | 00,000,000 | ---D | C] -- C:&#092;Program Files&#092;Common Files&#092;Apple<br />
[2010/01/06 04:29:38 | 00,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;jenni rowe&#092;Local Settings&#092;Application Data&#092;Apple<br />
[2010/01/06 04:29:28 | 00,000,000 | ---D | C] -- C:&#092;Program Files&#092;Apple Software Update<br />
[2010/01/06 04:29:28 | 00,000,000 | ---D | C] -- C:&#092;Documents and Settings&#092;All Users&#092;Application Data&#092;Apple<br />
[2009/10/02 14:38:29 | 00,000,000 | ---D | M] -- C:&#092;Documents and Settings&#092;LocalService&#092;Local Settings&#092;Application Data&#092;Microsoft<br />
[2007/10/12 08:44:19 | 00,000,000 | --SD | M] -- C:&#092;Documents and Settings&#092;LocalService&#092;Application Data&#092;Microsoft<br />
[2007/08/10 23:38:12 | 00,000,000 | ---D | M] -- C:&#092;Documents and Settings&#092;LocalService&#092;Application Data&#092;Roxio<br />
[2004/08/10 13:08:14 | 00,000,000 | ---D | M] -- C:&#092;Documents and Settings&#092;NetworkService&#092;Local Settings&#092;Application Data&#092;Microsoft<br />
[2004/08/10 12:57:26 | 00,000,000 | --SD | M] -- C:&#092;Documents and Settings&#092;NetworkService&#092;Application Data&#092;Microsoft<br />
[1 C:&#092;WINDOWS&#092;System32&#092;*.tmp files -&gt; C:&#092;WINDOWS&#092;System32&#092;*.tmp -&gt; ]<br />
[1 C:&#092;WINDOWS&#092;*.tmp files -&gt; C:&#092;WINDOWS&#092;*.tmp -&gt; ]<br />
 <br />
<span style='color: #E56717'>========== Files - Modified Within 30 Days ==========</span><br />
 <br />
[2010/01/29 00:43:14 | 00,548,864 | ---- | M] (OldTimer Tools) -- C:&#092;Documents and Settings&#092;jenni rowe&#092;Desktop&#092;OTL.exe<br />
[2010/01/29 00:39:23 | 00,513,320 | ---- | M] () -- C:&#092;Documents and Settings&#092;jenni rowe&#092;Desktop&#092;erunt.zip<br />
[2010/01/29 00:35:13 | 00,007,180 | ---- | M] () -- C:&#092;Documents and Settings&#092;jenni rowe&#092;Desktop&#092;SysRestorePoint_v12.zip<br />
[2010/01/29 00:08:55 | 05,242,880 | ---- | M] () -- C:&#092;Documents and Settings&#092;jenni rowe&#092;ntuser.dat<br />
[2010/01/28 23:29:53 | 00,000,120 | ---- | M] () -- C:&#092;WINDOWS&#092;Grupimifet.dat<br />
[2010/01/28 18:24:39 | 00,441,626 | ---- | M] () -- C:&#092;WINDOWS&#092;System32&#092;PerfStringBackup.INI<br />
[2010/01/28 18:24:39 | 00,382,260 | ---- | M] () -- C:&#092;WINDOWS&#092;System32&#092;perfh009.dat<br />
[2010/01/28 18:24:39 | 00,053,838 | ---- | M] () -- C:&#092;WINDOWS&#092;System32&#092;perfc009.dat<br />
[2010/01/28 18:21:23 | 00,012,917 | ---- | M] () -- C:&#092;WINDOWS&#092;System32&#092;Config.MPF<br />
[2010/01/28 18:20:06 | 00,000,006 | -H-- | M] () -- C:&#092;WINDOWS&#092;tasks&#092;SA.DAT<br />
[2010/01/28 18:20:01 | 00,002,048 | --S- | M] () -- C:&#092;WINDOWS&#092;bootstat.dat<br />
[2010/01/28 18:19:57 | 93,747,2000 | -HS- | M] () -- C:&#092;hiberfil.sys<br />
[2010/01/28 06:38:48 | 00,001,729 | ---- | M] () -- C:&#092;Documents and Settings&#092;All Users&#092;Desktop&#092;McAfee Virtual Technician.lnk<br />
[2010/01/28 00:28:31 | 00,000,000 | ---- | M] () -- C:&#092;WINDOWS&#092;Rdurew.bin<br />
[2010/01/28 00:13:44 | 00,002,137 | ---- | M] () -- C:&#092;Documents and Settings&#092;All Users&#092;Desktop&#092;iTunes.lnk<br />
[2010/01/27 02:33:46 | 00,008,192 | ---- | M] () -- C:&#092;kkalf.exe<br />
[2010/01/25 19:18:03 | 00,000,284 | ---- | M] () -- C:&#092;WINDOWS&#092;tasks&#092;AppleSoftwareUpdate.job<br />
[2010/01/23 03:37:40 | 00,045,944 | -H-- | M] () -- C:&#092;WINDOWS&#092;System32&#092;mlfcache.dat<br />
[2010/01/23 03:10:20 | 02,957,312 | R--- | M] () -- C:&#092;Documents and Settings&#092;All Users&#092;Documents&#092;ESBK.mbb<br />
[2010/01/23 03:10:20 | 01,460,224 | R--- | M] () -- C:&#092;Documents and Settings&#092;All Users&#092;Documents&#092;ESBK.mb<br />
[2010/01/15 01:00:00 | 00,000,350 | ---- | M] () -- C:&#092;WINDOWS&#092;tasks&#092;McDefragTask.job<br />
[2010/01/13 03:04:44 | 00,001,374 | ---- | M] () -- C:&#092;WINDOWS&#092;imsins.BAK<br />
[2010/01/11 23:37:57 | 00,021,504 | ---- | M] () -- C:&#092;Documents and Settings&#092;jenni rowe&#092;Desktop&#092;Dear Clients.doc<br />
[2010/01/06 16:33:55 | 00,056,376 | ---- | M] () -- C:&#092;Documents and Settings&#092;jenni rowe&#092;Local Settings&#092;Application Data&#092;GDIPFONTCACHEV1.DAT<br />
[2010/01/06 08:22:03 | 93,234,472 | ---- | M] (Apple Inc.) -- C:&#092;Documents and Settings&#092;jenni rowe&#092;Desktop&#092;iTunesSetup.exe<br />
[2010/01/06 04:33:47 | 00,001,604 | ---- | M] () -- C:&#092;Documents and Settings&#092;All Users&#092;Desktop&#092;QuickTime Player.lnk<br />
[2010/01/06 04:31:32 | 00,054,156 | -H-- | M] () -- C:&#092;WINDOWS&#092;QTFont.qfn<br />
[2010/01/06 04:31:32 | 00,001,409 | ---- | M] () -- C:&#092;WINDOWS&#092;QTFont.for<br />
[2010/01/02 19:23:32 | 00,002,206 | ---- | M] () -- C:&#092;WINDOWS&#092;System32&#092;wpa.dbl<br />
[2010/01/01 01:00:00 | 00,000,352 | ---- | M] () -- C:&#092;WINDOWS&#092;tasks&#092;McQcTask.job<br />
[1 C:&#092;WINDOWS&#092;System32&#092;*.tmp files -&gt; C:&#092;WINDOWS&#092;System32&#092;*.tmp -&gt; ]<br />
[1 C:&#092;WINDOWS&#092;*.tmp files -&gt; C:&#092;WINDOWS&#092;*.tmp -&gt; ]<br />
 <br />
<span style='color: #E56717'>========== Files Created - No Company Name ==========</span><br />
 <br />
[2010/01/29 00:39:22 | 00,513,320 | ---- | C] () -- C:&#092;Documents and Settings&#092;jenni rowe&#092;Desktop&#092;erunt.zip<br />
[2010/01/29 00:35:13 | 00,007,180 | ---- | C] () -- C:&#092;Documents and Settings&#092;jenni rowe&#092;Desktop&#092;SysRestorePoint_v12.zip<br />
[2010/01/28 06:38:48 | 00,001,729 | ---- | C] () -- C:&#092;Documents and Settings&#092;All Users&#092;Desktop&#092;McAfee Virtual Technician.lnk<br />
[2010/01/27 06:06:40 | 00,000,000 | ---- | C] () -- C:&#092;WINDOWS&#092;Rdurew.bin<br />
[2010/01/27 06:06:39 | 00,000,120 | ---- | C] () -- C:&#092;WINDOWS&#092;Grupimifet.dat<br />
[2010/01/27 02:32:57 | 00,008,192 | ---- | C] () -- C:&#092;kkalf.exe<br />
[2010/01/23 03:37:40 | 00,045,944 | -H-- | C] () -- C:&#092;WINDOWS&#092;System32&#092;mlfcache.dat<br />
[2010/01/11 23:37:57 | 00,021,504 | ---- | C] () -- C:&#092;Documents and Settings&#092;jenni rowe&#092;Desktop&#092;Dear Clients.doc<br />
[2010/01/06 16:30:37 | 00,002,137 | ---- | C] () -- C:&#092;Documents and Settings&#092;All Users&#092;Desktop&#092;iTunes.lnk<br />
[2010/01/06 04:33:47 | 00,001,604 | ---- | C] () -- C:&#092;Documents and Settings&#092;All Users&#092;Desktop&#092;QuickTime Player.lnk<br />
[2010/01/06 04:31:32 | 00,054,156 | -H-- | C] () -- C:&#092;WINDOWS&#092;QTFont.qfn<br />
[2010/01/06 04:31:32 | 00,001,409 | ---- | C] () -- C:&#092;WINDOWS&#092;QTFont.for<br />
[2010/01/06 04:29:39 | 00,000,284 | ---- | C] () -- C:&#092;WINDOWS&#092;tasks&#092;AppleSoftwareUpdate.job<br />
[2008/06/03 15:40:26 | 00,000,118 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;MRT.INI<br />
[2008/02/05 14:19:00 | 00,000,866 | ---- | C] () -- C:&#092;WINDOWS&#092;cdplayer.ini<br />
[2007/10/04 10:48:17 | 00,001,350 | ---- | C] () -- C:&#092;Documents and Settings&#092;All Users&#092;Application Data&#092;QTSBandwidthCache<br />
[2007/08/19 11:19:27 | 00,013,824 | ---- | C] () -- C:&#092;Documents and Settings&#092;jenni rowe&#092;Local Settings&#092;Application Data&#092;DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini<br />
[2007/08/19 10:19:40 | 00,000,376 | ---- | C] () -- C:&#092;WINDOWS&#092;ODBC.INI<br />
[2007/08/16 07:00:34 | 00,000,000 | ---- | C] () -- C:&#092;Documents and Settings&#092;jenni rowe&#092;Application Data&#092;wklnhst.dat<br />
[2007/08/16 06:33:49 | 00,000,133 | ---- | C] () -- C:&#092;Documents and Settings&#092;jenni rowe&#092;Local Settings&#092;Application Data&#092;fusioncache.dat<br />
[2007/08/10 23:38:54 | 00,000,061 | ---- | C] () -- C:&#092;WINDOWS&#092;smscfg.ini<br />
[2007/08/10 23:28:50 | 00,056,056 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;DLAAPI_W.DLL<br />
[2007/08/10 23:28:50 | 00,000,120 | ---- | C] () -- C:&#092;WINDOWS&#092;wininit.ini<br />
[2007/08/10 23:19:59 | 00,086,016 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;preflib.dll<br />
[2007/08/10 23:19:57 | 00,757,760 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;bcm1xsup.dll<br />
[2007/08/10 22:53:10 | 00,001,164 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;OEMINFO.INI<br />
[2006/11/07 11:25:58 | 00,000,000 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;px.ini<br />
[2006/09/16 23:36:50 | 00,520,192 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;CddbPlaylist2Roxio.dll<br />
[2006/09/16 23:36:50 | 00,204,800 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;CddbFileTaggerRoxio.dll<br />
[2004/08/10 13:12:05 | 00,000,780 | ---- | C] () -- C:&#092;WINDOWS&#092;orun32.ini<br />
[2004/08/10 13:01:18 | 00,001,793 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;fxsperf.ini<br />
[2004/08/10 12:51:27 | 00,151,040 | ---- | C] () -- C:&#092;WINDOWS&#092;urefobawut.dll<br />
[2000/09/08 17:53:50 | 00,073,839 | ---- | C] () -- C:&#092;WINDOWS&#092;System32&#092;KodakOneTouch.dll<br />
 <br />
<span style='color: #E56717'>========== Custom Scans ==========</span><br />
 <br />
 <br />
<span style='color: #A23BEC'>&lt; %SYSTEMDRIVE%&#092;*.* &gt;</span><br />
[2008/11/25 09:12:54 | 35,124,856 | ---- | M] (                                   ) -- C:&#092;AdbeRdr90_en_US.exe<br />
[2004/08/10 13:04:08 | 00,000,000 | ---- | M] () -- C:&#092;AUTOEXEC.BAT<br />
[2007/10/12 12:59:50 | 00,000,223 | RHS- | M] () -- C:&#092;boot.ini<br />
[2004/08/10 13:04:08 | 00,000,000 | ---- | M] () -- C:&#092;CONFIG.SYS<br />
[2007/08/10 22:56:18 | 00,006,274 | RH-- | M] () -- C:&#092;dell.sdr<br />
[2008/10/10 19:10:31 | 00,104,630 | ---- | M] () -- C:&#092;ForensicPsychiatric.pdf<br />
[2010/01/28 18:19:57 | 93,747,2000 | -HS- | M] () -- C:&#092;hiberfil.sys<br />
[2007/08/16 07:36:43 | 00,004,128 | ---- | M] () -- C:&#092;INFCACHE.1<br />
[2004/08/10 13:04:08 | 00,000,000 | -H-- | M] () -- C:&#092;IO.SYS<br />
[2007/08/10 23:33:29 | 00,000,308 | -H-- | M] () -- C:&#092;IPH.PH<br />
[2008/07/13 11:15:29 | 00,005,934 | ---- | M] () -- C:&#092;join.htm<br />
[2010/01/27 02:33:46 | 00,008,192 | ---- | M] () -- C:&#092;kkalf.exe<br />
[2008/07/13 11:58:25 | 04,898,144 | ---- | M] (Lime Wire LLC) -- C:&#092;LimeWireWin.exe<br />
[2008/11/25 08:41:28 | 00,102,030 | ---- | M] () -- C:&#092;menu_web_04-08-08.pdf<br />
[2004/08/10 13:04:08 | 00,000,000 | -H-- | M] () -- C:&#092;MSDOS.SYS<br />
[2004/08/04 05:00:00 | 00,047,564 | RHS- | M] () -- C:&#092;NTDETECT.COM<br />
[2009/09/30 18:44:07 | 00,250,048 | RHS- | M] () -- C:&#092;ntldr<br />
[2010/01/28 18:19:54 | 14,092,86144 | -HS- | M] () -- C:&#092;pagefile.sys<br />
[2008/09/15 11:44:44 | 00,008,274 | ---- | M] () -- C:&#092;signup.htm<br />
 <br />
 <br />
<span style='color: #A23BEC'>&lt; MD5 for: AGP440.SYS  &gt;</span><br />
[2004/08/04 05:00:00 | 18,738,937 | ---- | M] () .cab file -- C:&#092;i386&#092;sp2.cab:AGP440.sys<br />
[2004/08/04 05:00:00 | 18,738,937 | ---- | M] () .cab file -- C:&#092;WINDOWS&#092;Driver Cache&#092;i386&#092;sp2.cab:AGP440.sys<br />
[2009/09/30 18:37:53 | 23,852,652 | ---- | M] () .cab file -- C:&#092;WINDOWS&#092;Driver Cache&#092;i386&#092;sp3.cab:AGP440.sys<br />
[2009/09/30 18:37:53 | 23,852,652 | ---- | M] () .cab file -- C:&#092;WINDOWS&#092;ServicePackFiles&#092;i386&#092;sp3.cab:AGP440.sys<br />
[2008/04/14 02:36:38 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:&#092;WINDOWS&#092;ServicePackFiles&#092;i386&#092;agp440.sys<br />
[2008/04/14 02:36:38 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;agp440.sys<br />
[2004/08/03 23:07:42 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:&#092;i386&#092;AGP440.SYS<br />
[2004/08/03 23:07:42 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:&#092;WINDOWS&#092;$NtServicePackUninstall$&#092;agp440.sys<br />
 <br />
<span style='color: #A23BEC'>&lt; MD5 for: ATAPI.SYS  &gt;</span><br />
[2004/08/04 05:00:00 | 18,738,937 | ---- | M] () .cab file -- C:&#092;i386&#092;sp2.cab:atapi.sys<br />
[2004/08/04 05:00:00 | 18,738,937 | ---- | M] () .cab file -- C:&#092;WINDOWS&#092;Driver Cache&#092;i386&#092;sp2.cab:atapi.sys<br />
[2009/09/30 18:37:53 | 23,852,652 | ---- | M] () .cab file -- C:&#092;WINDOWS&#092;Driver Cache&#092;i386&#092;sp3.cab:atapi.sys<br />
[2009/09/30 18:37:53 | 23,852,652 | ---- | M] () .cab file -- C:&#092;WINDOWS&#092;ServicePackFiles&#092;i386&#092;sp3.cab:atapi.sys<br />
[2008/04/14 02:40:30 | 00,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:&#092;WINDOWS&#092;ServicePackFiles&#092;i386&#092;atapi.sys<br />
[2008/04/14 02:40:30 | 00,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:&#092;WINDOWS&#092;system32&#092;drivers&#092;atapi.sys<br />
[2004/08/03 22:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:&#092;i386&#092;atapi.sys<br />
[2004/08/03 22:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:&#092;WINDOWS&#092;$NtServicePackUninstall$&#092;atapi.sys<br />
 <br />
<span style='color: #A23BEC'>&lt; MD5 for: EVENTLOG.DLL  &gt;</span><br />
[2008/04/14 08:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:&#092;WINDOWS&#092;ServicePackFiles&#092;i386&#092;eventlog.dll<br />
[2008/04/14 08:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:&#092;WINDOWS&#092;system32&#092;eventlog.dll<br />
[2004/08/04 05:00:00 | 00,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:&#092;i386&#092;eventlog.dll<br />
[2004/08/04 05:00:00 | 00,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:&#092;WINDOWS&#092;$NtServicePackUninstall$&#092;eventlog.dll<br />
 <br />
<span style='color: #A23BEC'>&lt; MD5 for: NETLOGON.DLL  &gt;</span><br />
[2008/04/14 08:12:01 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:&#092;WINDOWS&#092;ServicePackFiles&#092;i386&#092;netlogon.dll<br />
[2008/04/14 08:12:01 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:&#092;WINDOWS&#092;system32&#092;netlogon.dll<br />
[2009/02/07 02:46:09 | 00,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:&#092;WINDOWS&#092;$NtServicePackUninstall$&#092;netlogon.dll<br />
[2004/08/04 05:00:00 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:&#092;i386&#092;netlogon.dll<br />
[2004/08/04 05:00:00 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:&#092;WINDOWS&#092;$NtUninstallKB968389_0$&#092;netlogon.dll<br />
 <br />
<span style='color: #A23BEC'>&lt; MD5 for: SCECLI.DLL  &gt;</span><br />
[2004/08/04 05:00:00 | 00,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:&#092;i386&#092;scecli.dll<br />
[2004/08/04 05:00:00 | 00,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:&#092;WINDOWS&#092;$NtServicePackUninstall$&#092;scecli.dll<br />
[2008/04/14 08:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:&#092;WINDOWS&#092;ServicePackFiles&#092;i386&#092;scecli.dll<br />
[2008/04/14 08:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:&#092;WINDOWS&#092;system32&#092;scecli.dll<br />
 <br />
<span style='color: #A23BEC'>&lt; %systemroot%&#092;*. /mp /s &gt;</span><br />
 <br />
<span style='color: #A23BEC'>&lt; %systemroot%&#092;system32&#092;*.dll /lockedfiles &gt;</span><br />
[1 C:&#092;WINDOWS&#092;system32&#092;*.tmp files -&gt; C:&#092;WINDOWS&#092;system32&#092;*.tmp -&gt; ]<br />
 <br />
<span style='color: #A23BEC'>&lt; %systemroot%&#092;Tasks&#092;*.job /lockedfiles &gt;</span><br />
 <br />
<span style='color: #A23BEC'>&lt;  &gt;</span><br />
 <br />
<span style='color: #A23BEC'>&lt;  &gt;</span><br />
 <br />
<span style='color: #E56717'>========== Alternate Data Streams ==========</span><br />
 <br />
@Alternate Data Stream - 76 bytes -&gt; C:&#092;Documents and Settings&#092;jenni rowe&#092;My Documents&#092;writing:Roxio EMC Stream<br />
@Alternate Data Stream - 76 bytes -&gt; C:&#092;Documents and Settings&#092;jenni rowe&#092;My Documents&#092;wedding:Roxio EMC Stream<br />
@Alternate Data Stream - 76 bytes -&gt; C:&#092;Documents and Settings&#092;jenni rowe&#092;My Documents&#092;My Videos:Roxio EMC Stream<br />
@Alternate Data Stream - 76 bytes -&gt; C:&#092;Documents and Settings&#092;jenni rowe&#092;My Documents&#092;LimeWire:Roxio EMC Stream<br />
@Alternate Data Stream - 76 bytes -&gt; C:&#092;Documents and Settings&#092;jenni rowe&#092;My Documents&#092;JOBS:Roxio EMC Stream<br />
@Alternate Data Stream - 76 bytes -&gt; C:&#092;Documents and Settings&#092;jenni rowe&#092;My Documents&#092;Cyberlink:Roxio EMC Stream<br />
@Alternate Data Stream - 76 bytes -&gt; C:&#092;Documents and Settings&#092;jenni rowe&#092;My Documents&#092;Common-Use Signing Interface:Roxio EMC Stream<br />
@Alternate Data Stream - 76 bytes -&gt; C:&#092;Documents and Settings&#092;jenni rowe&#092;Desktop&#092;Tax n Stuff:Roxio EMC Stream<br />
@Alternate Data Stream - 76 bytes -&gt; C:&#092;Documents and Settings&#092;jenni rowe&#092;Desktop&#092;SysRestorePoint_v12:Roxio EMC Stream<br />
@Alternate Data Stream - 76 bytes -&gt; C:&#092;Documents and Settings&#092;jenni rowe&#092;Desktop&#092;my stuff:Roxio EMC Stream<br />
@Alternate Data Stream - 76 bytes -&gt; C:&#092;Documents and Settings&#092;jenni rowe&#092;Desktop&#092;Incomplete:Roxio EMC Stream<br />
@Alternate Data Stream - 76 bytes -&gt; C:&#092;Documents and Settings&#092;jenni rowe&#092;Desktop&#092;erunt:Roxio EMC Stream<br />
&lt; End of report &gt;<br />
<br />
<br />
OTL Extras logfile created on: 1/29/2010 12:45:14 AM - Run 1<br />
OTL by OldTimer - Version 3.1.27.0     Folder = C:&#092;Documents and Settings&#092;jenni rowe&#092;Desktop<br />
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation<br />
Internet Explorer (Version = 8.0.6001.18702)<br />
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy<br />
 <br />
894.00 Mb Total Physical Memory | 327.00 Mb Available Physical Memory | 37.00% Memory free<br />
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 74.00% Paging File free<br />
Paging file location(s): C:&#092;pagefile.sys 1344 2688 [binary data]<br />
 <br />
%SystemDrive% = C: | %SystemRoot% = C:&#092;WINDOWS | %ProgramFiles% = C:&#092;Program Files<br />
Drive C: | 108.70 Gb Total Space | 68.85 Gb Free Space | 63.34% Space Free | Partition Type: NTFS<br />
Drive D: | 584.81 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF<br />
E: Drive not present or media not loaded<br />
F: Drive not present or media not loaded<br />
G: Drive not present or media not loaded<br />
H: Drive not present or media not loaded<br />
I: Drive not present or media not loaded<br />
 <br />
Computer Name: JENS<br />
Current User Name: jenni rowe<br />
Logged in as Administrator.<br />
 <br />
Current Boot Mode: Normal<br />
Scan Mode: Current user<br />
Company Name Whitelist: Off<br />
Skip Microsoft Files: Off<br />
File Age = 30 Days<br />
Output = Standard<br />
 <br />
<span style='color: #E56717'>========== Extra Registry (SafeList) ==========</span><br />
 <br />
 <br />
<span style='color: #E56717'>========== File Associations ==========</span><br />
 <br />
[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Classes&#092;&lt;extension&gt;]<br />
.html [@ = htmlfile] -- C:&#092;Program Files&#092;Internet Explorer&#092;IEXPLORE.EXE (Microsoft Corporation)<br />
 <br />
<span style='color: #E56717'>========== Shell Spawning ==========</span><br />
 <br />
[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Classes&#092;&lt;key&gt;&#092;shell&#092;[command]&#092;command]<br />
batfile [open] -- "%1" %*<br />
cmdfile [open] -- "%1" %*<br />
comfile [open] -- "%1" %*<br />
exefile [open] -- "%1" %*<br />
htmlfile [edit] -- "C:&#092;Program Files&#092;Microsoft Office&#092;Office10&#092;msohtmed.exe" %1 (Microsoft Corporation)<br />
htmlfile [open] -- "C:&#092;Program Files&#092;Internet Explorer&#092;IEXPLORE.EXE" -nohome (Microsoft Corporation)<br />
htmlfile [opennew] -- "C:&#092;Program Files&#092;Internet Explorer&#092;IEXPLORE.EXE" %1 (Microsoft Corporation)<br />
htmlfile [print] -- "C:&#092;Program Files&#092;Microsoft Office&#092;Office10&#092;msohtmed.exe" /p %1 (Microsoft Corporation)<br />
http [open] -- "C:&#092;Program Files&#092;Internet Explorer&#092;IEXPLORE.EXE" -nohome (Microsoft Corporation)<br />
https [open] -- "C:&#092;Program Files&#092;Internet Explorer&#092;IEXPLORE.EXE" -nohome (Microsoft Corporation)<br />
piffile [open] -- "%1" %*<br />
regfile [merge] -- Reg Error: Key error.<br />
scrfile [config] -- "%1"<br />
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)<br />
scrfile [open] -- "%1" /S<br />
txtfile [edit] -- Reg Error: Key error.<br />
Unknown [openas] -- %SystemRoot%&#092;system32&#092;rundll32.exe %SystemRoot%&#092;system32&#092;shell32.dll,OpenAs_RunDLL %1<br />
Directory [find] -- %SystemRoot%&#092;Explorer.exe (Microsoft Corporation)<br />
Folder [open] -- %SystemRoot%&#092;Explorer.exe /idlist,%I,%L (Microsoft Corporation)<br />
Folder [explore] -- %SystemRoot%&#092;Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)<br />
Drive [find] -- %SystemRoot%&#092;Explorer.exe (Microsoft Corporation)<br />
Applications&#092;iexplore.exe [open] -- "C:&#092;Program Files&#092;Internet Explorer&#092;IEXPLORE.EXE" %1 (Microsoft Corporation)<br />
CLSID&#092;{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:&#092;Program Files&#092;Internet Explorer&#092;iexplore.exe" (Microsoft Corporation)<br />
 <br />
<span style='color: #E56717'>========== Security Center Settings ==========</span><br />
 <br />
[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center]<br />
"FirstRunDisabled" = 1<br />
"AntiVirusDisableNotify" = 1<br />
"FirewallDisableNotify" = 1<br />
"UpdatesDisableNotify" = 0<br />
"AntiVirusOverride" = 0<br />
"FirewallOverride" = 0<br />
 <br />
[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring]<br />
 <br />
[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;AhnlabAntiVirus]<br />
 <br />
[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;ComputerAssociatesAntiVirus]<br />
 <br />
[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;KasperskyAntiVirus]<br />
 <br />
[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;McAfeeAntiVirus]<br />
"DisableMonitoring" = 1<br />
 <br />
[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;McAfeeFirewall]<br />
"DisableMonitoring" = 1<br />
 <br />
[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;PandaAntiVirus]<br />
 <br />
[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;PandaFirewall]<br />
 <br />
[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;SophosAntiVirus]<br />
 <br />
[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;SymantecAntiVirus]<br />
 <br />
[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;SymantecFirewall]<br />
 <br />
[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;TinyFirewall]<br />
 <br />
[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;TrendAntiVirus]<br />
 <br />
[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;TrendFirewall]<br />
 <br />
[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;ZoneLabsFirewall]<br />
 <br />
[HKEY_LOCAL_MACHINE&#092;SYSTEM&#092;CurrentControlSet&#092;Services&#092;SharedAccess&#092;Parameters&#092;FirewallPolicy&#092;DomainProfile]<br />
 <br />
[HKEY_LOCAL_MACHINE&#092;SYSTEM&#092;CurrentControlSet&#092;Services&#092;SharedAccess&#092;Parameters&#092;FirewallPolicy&#092;DomainProfile&#092;GloballyOpenPorts&#092;List]<br />
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007<br />
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008<br />
 <br />
[HKEY_LOCAL_MACHINE&#092;SYSTEM&#092;CurrentControlSet&#092;Services&#092;SharedAccess&#092;Parameters&#092;FirewallPolicy&#092;StandardProfile]<br />
"EnableFirewall" = 0<br />
 <br />
[HKEY_LOCAL_MACHINE&#092;SYSTEM&#092;CurrentControlSet&#092;Services&#092;SharedAccess&#092;Parameters&#092;FirewallPolicy&#092;StandardProfile&#092;GloballyOpenPorts&#092;List]<br />
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007<br />
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008<br />
 <br />
<span style='color: #E56717'>========== Authorized Applications List ==========</span><br />
 <br />
[HKEY_LOCAL_MACHINE&#092;SYSTEM&#092;CurrentControlSet&#092;Services&#092;SharedAccess&#092;Parameters&#092;FirewallPolicy&#092;DomainProfile&#092;AuthorizedApplications&#092;List]<br />
 <br />
[HKEY_LOCAL_MACHINE&#092;SYSTEM&#092;CurrentControlSet&#092;Services&#092;SharedAccess&#092;Parameters&#092;FirewallPolicy&#092;StandardProfile&#092;AuthorizedApplications&#092;List]<br />
"C:&#092;Program Files&#092;Kodak&#092;Kodak EasyShare software&#092;bin&#092;EasyShare.exe" = C:&#092;Program Files&#092;Kodak&#092;Kodak EasyShare software&#092;bin&#092;EasyShare.exe:*:Enabled:EasyShare -- ()<br />
"C:&#092;Program Files&#092;LimeWire&#092;LimeWire.exe" = C:&#092;Program Files&#092;LimeWire&#092;LimeWire.exe:*:Enabled:LimeWire -- (Lime Wire, LLC)<br />
"C:&#092;Program Files&#092;Common Files&#092;McAfee&#092;MNA&#092;McNASvc.exe" = C:&#092;Program Files&#092;Common Files&#092;McAfee&#092;MNA&#092;McNASvc.exe:*:Enabled:McAfee Network Agent -- (McAfee, Inc.)<br />
"C:&#092;Program Files&#092;Bonjour&#092;mDNSResponder.exe" = C:&#092;Program Files&#092;Bonjour&#092;mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Inc.)<br />
"C:&#092;Program Files&#092;iTunes&#092;iTunes.exe" = C:&#092;Program Files&#092;iTunes&#092;iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)<br />
 <br />
 <br />
<span style='color: #E56717'>========== HKEY_LOCAL_MACHINE Uninstall List ==========</span><br />
 <br />
[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Uninstall]<br />
"{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}" = Notifier<br />
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR<br />
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools<br />
"{03EDED24-8375-407D-A721-4643D9768BE1}" = kgchlwn<br />
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour<br />
"{073F22CE-9A5B-4A40-A604-C7270AC6BF34}" = ESSSONIC<br />
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data<br />
"{11F3F858-4131-4FFA-A560-3FE282933B6E}" = kgchday<br />
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime<br />
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD<br />
"{154508C0-07C5-4659-A7A0-E49968750D21}" = HLPPDOCK<br />
"{20E12FE5-AF25-42B5-8EEE-3D0FFDEEA32A}" = Unwired<br />
"{22DE1881-9D24-4981-B5CC-EC7E9F2F4D52}" = Rhapsody Player Engine<br />
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer<br />
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt<br />
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc<br />
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager<br />
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6<br />
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP<br />
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module<br />
"{3CA39B0C-BA85-4D42-AC0F-1FF5F60C3353}" = OTtBPSDK<br />
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = URL Assistant<br />
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting<br />
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support<br />
"{42CFD768-94A5-4C0D-A49A-88B536BAC551}" = FileNet Desktop eForms<br />
"{49FA793C-785E-47E9-93DF-BD442B0B45D1}" = McAfee Virtual Technician<br />
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA<br />
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy<br />
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr<br />
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler<br />
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.7<br />
"{693C08A7-9E76-43FF-B11E-9A58175474C4}" = kgckids<br />
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update<br />
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works<br />
"{6DE13770-01B7-4366-8DA6-48237793F445}" = VoiceOver Kit<br />
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore<br />
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com<br />
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper<br />
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio<br />
"{87843A41-7808-4F2E-B13F-25C1E67CF2FD}" = ESShelp<br />
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin<br />
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr<br />
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS<br />
"{8A8664E1-84C8-4936-891C-BC1F07797549}" = kgcvday<br />
"{8E240C1C-25D0-4248-BC6C-ACC3472E35CE}" = SigmaTel MSCN Audio Player<br />
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini<br />
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage<br />
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui<br />
"{93D34EE3-99B3-4DB1-8B0A-0A657466F90D}" = 3 Mobile Broadband<br />
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL<br />
"{9BD54685-1496-46A5-AB62-357CD140ED8B}" = kgcinvt<br />
"{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}" = ESScore<br />
"{A1588373-1D86-4D44-86C9-78ABD190F9CC}" = kgcmove<br />
"{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}" = iTunes<br />
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support<br />
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9<br />
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK<br />
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI<br />
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore<br />
"{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}" = KSU<br />
"{C151CE54-E7EA-4804-854B-F515368B0798}" = AMD Processor Driver<br />
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet<br />
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE<br />
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1<br />
"{CEE2252C-4035-4B27-8EC6-0B085DD3A413}" = Dell Support 3.2.1<br />
"{D1973749-F5E7-40EB-B528-F2B78685B9FF}" = essvcpt<br />
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software<br />
"{D639085F-4B6E-4105-9F37-A0DBB023E2FB}" = Roxio MyDVD DE<br />
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR<br />
"{E18B549C-5D15-45DA-8D8F-8FD2BD946344}" = kgcbaby<br />
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect<br />
"{E6963450-7577-4049-8793-2B66B85237C1}" = ATI Catalyst Control Center<br />
"{F22C222C-3CE2-4A4B-A83F-AF4681371ABE}" = kgcbase<br />
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK<br />
"{F71760CD-0F8B-4DCC-B7B7-6B223CC3843C}" = OTtBP<br />
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS<br />
"{FB3BE405-6BF0-490A-84B3-00611385EA0D}" = Common-Use Signing Interface<br />
"{FB64BF25-3593-4E4E-AA85-84AEF1D1475F}" = Broadcom Management Programs<br />
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock<br />
"{FDF9943A-3D5C-46B3-9679-586BD237DDEE}" = SKIN0001<br />
"Adobe AIR" = Adobe AIR<br />
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX<br />
"America Online au" = AOL Australia<br />
"ATI Display Driver" = ATI Display Driver<br />
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card<br />
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3" = Conexant HDA D110 MDC V.92 Modem<br />
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com<br />
"Common-Use Signing Interface" = Common-Use Signing Interface<br />
"CTMBDemo_Audigy" = Sound Blaster Audigy ADVANCED MB Demo<br />
"e-Record 6" = e-Record 6<br />
"e-Record Tutorial" = e-Record Tutorial<br />
"e-tax 2008" = e-tax 2008<br />
"Google Desktop" = Google Desktop<br />
"ie8" = Windows Internet Explorer 8<br />
"LimeWire" = LimeWire 4.18.3<br />
"Microsoft .NET Framework 1.1  (1033)" = Microsoft .NET Framework 1.1<br />
"MIXERLITE" = Mixer<br />
"Mozilla Firefox (2.0)" = Mozilla Firefox (2.0)<br />
"MSC" = McAfee SecurityCenter<br />
"net" = Advertisement Service<br />
"PlayMP3" = PlayMP3z<br />
"PrimoAdsForYou" = PrimoAdsForYou<br />
"RealPlayer 6.0" = RealPlayer<br />
"Record Keeping Evaluation Tool" = Record Keeping Evaluation Tool<br />
"SearchAssist" = SearchAssist<br />
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX<br />
"SynTPDeinstKey" = Synaptics Pointing Device Driver<br />
"Tax Withheld Calculator" = Tax Withheld Calculator<br />
"ViewpointMediaPlayer" = Viewpoint Media Player (Remove Only)<br />
"Windows Media Format Runtime" = Windows Media Format Runtime<br />
"Windows XP Service Pack" = Windows XP Service Pack 3<br />
 <br />
<span style='color: #E56717'>========== Last 10 Event Log Errors ==========</span><br />
 <br />
[ Application Events ]<br />
Error - 3/1/2009 11:01:24 PM | Computer Name = JENS | Source = Application Hang | ID = 1002<br />
Description = Hanging application IEXPLORE.EXE, version 6.0.2900.2180, hang module<br />
 hungapp, version 0.0.0.0, hang address 0x00000000.<br />
 <br />
[ System Events ]<br />
Error - 1/28/2010 8:52:09 AM | Computer Name = JENS | Source = ati2mtag | ID = 43015<br />
Description = I2c return failed<br />
 <br />
Error - 1/28/2010 8:52:09 AM | Computer Name = JENS | Source = ati2mtag | ID = 43015<br />
Description = I2c return failed<br />
 <br />
Error - 1/28/2010 10:45:25 AM | Computer Name = JENS | Source = ati2mtag | ID = 43015<br />
Description = I2c return failed<br />
 <br />
Error - 1/28/2010 10:45:25 AM | Computer Name = JENS | Source = ati2mtag | ID = 43015<br />
Description = I2c return failed<br />
 <br />
Error - 1/28/2010 11:28:18 AM | Computer Name = JENS | Source = ati2mtag | ID = 43015<br />
Description = I2c return failed<br />
 <br />
Error - 1/28/2010 11:28:18 AM | Computer Name = JENS | Source = ati2mtag | ID = 43015<br />
Description = I2c return failed<br />
 <br />
Error - 1/28/2010 12:01:04 PM | Computer Name = JENS | Source = ati2mtag | ID = 43015<br />
Description = I2c return failed<br />
 <br />
Error - 1/28/2010 12:01:04 PM | Computer Name = JENS | Source = ati2mtag | ID = 43015<br />
Description = I2c return failed<br />
 <br />
Error - 1/28/2010 12:01:08 PM | Computer Name = JENS | Source = ati2mtag | ID = 43015<br />
Description = I2c return failed<br />
 <br />
Error - 1/28/2010 12:01:08 PM | Computer Name = JENS | Source = ati2mtag | ID = 43015<br />
Description = I2c return failed<br />
 <br />
 <br />
&lt; End of report &gt;<br />
<br />
<br />
GMER 1.0.15.15281 - <a href='http://www.gmer.net' class='bbc_url' title='External link' rel='nofollow'>http://www.gmer.net</a><br />
Rootkit quick scan 2010-01-29 01:37:39<br />
Windows 5.1.2600 Service Pack 3<br />
Running: gmer.exe; Driver: C:&#092;DOCUME~1&#092;JENNIR~1&#092;LOCALS~1&#092;Temp&#092;pxtdypoc.sys<br />
<br />
<br />
---- System - GMER 1.0.15 ----<br />
<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwCreateFile [0xB6FB878A]<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwCreateKey [0xB6FB8821]<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwCreateProcess [0xB6FB8738]<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwCreateProcessEx [0xB6FB874C]<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwDeleteKey [0xB6FB8835]<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwDeleteValueKey [0xB6FB8861]<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwEnumerateKey [0xB6FB88CF]<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwEnumerateValueKey [0xB6FB88B9]<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwMapViewOfSection [0xB6FB87CA]<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwNotifyChangeKey [0xB6FB88FB]<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwOpenKey [0xB6FB880D]<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwOpenProcess [0xB6FB8710]<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwOpenThread [0xB6FB8724]<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwProtectVirtualMemory [0xB6FB879E]<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwQueryKey [0xB6FB8937]<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwQueryMultipleValueKey [0xB6FB88A3]<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwQueryValueKey [0xB6FB888D]<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwRenameKey [0xB6FB884B]<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwReplaceKey [0xB6FB8923]<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwRestoreKey [0xB6FB890F]<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwSetContextThread [0xB6FB8776]<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwSetInformationProcess [0xB6FB8762]<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwSetValueKey [0xB6FB8877]<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwTerminateProcess [0xB6FB87F9]<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwUnloadKey [0xB6FB88E5]<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwUnmapViewOfSection [0xB6FB87E0]<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwYieldExecution [0xB6FB87B4]<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  NtCreateFile<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  NtMapViewOfSection<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  NtOpenProcess<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  NtOpenThread<br />
Code            &#092;SystemRoot&#092;system32&#092;drivers&#092;mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  NtSetInformationProcess<br />
<br />
---- Devices - GMER 1.0.15 ----<br />
<br />
AttachedDevice  &#092;FileSystem&#092;Ntfs &#092;Ntfs                                                                        mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)<br />
AttachedDevice  &#092;Driver&#092;Tcpip &#092;Device&#092;Ip                                                                      Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)<br />
AttachedDevice  &#092;Driver&#092;Tcpip &#092;Device&#092;Tcp                                                                     Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)<br />
AttachedDevice  &#092;Driver&#092;Tcpip &#092;Device&#092;Udp                                                                     Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)<br />
AttachedDevice  &#092;Driver&#092;Tcpip &#092;Device&#092;RawIp                                                                   Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)<br />
AttachedDevice  &#092;Driver&#092;Kbdclass &#092;Device&#092;KeyboardClass0                                                       SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)<br />
AttachedDevice  &#092;Driver&#092;Kbdclass &#092;Device&#092;KeyboardClass1                                                       SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)<br />
<br />
Device           -&gt; &#092;Driver&#092;atapi &#092;Device&#092;Harddisk0&#092;DR0                                                       852BC856<br />
<br />
---- Files - GMER 1.0.15 ----<br />
<br />
File            C:&#092;WINDOWS&#092;system32&#092;drivers&#092;atapi.sys                                                         suspicious modification<br />
<br />
---- EOF - GMER 1.0.15 ----]]></description>
		<pubDate>Fri, 29 Jan 2010 10:53:36 +0000</pubDate>
		<guid>http://www.247fixes.com/forums/topic/6206-browser-redirect-from-google-results/</guid>
	</item>
	<item>
		<title>Microsoft Security Bulletin Summary For January 2010</title>
		<link>http://www.247fixes.com/forums/topic/6179-microsoft-security-bulletin-summary-for-january-2010/</link>
		<description><![CDATA[<strong class='bbc'>Microsoft Security Bulletin Summary for January 2010</strong><br />
<br />
Microsoft Security Bulletin Summary for January 2010<br />
<em class='bbc'>Published: January 12, 2010</em><br />
<br />
<a href='http://www.microsoft.com/technet/security/Bulletin/MS10-jan.mspx' class='bbc_url' title='External link' rel='nofollow'>http://www.microsoft.com/technet/security/Bulletin/MS10-jan.mspx</a>]]></description>
		<pubDate>Tue, 26 Jan 2010 23:15:26 +0000</pubDate>
		<guid>http://www.247fixes.com/forums/topic/6179-microsoft-security-bulletin-summary-for-january-2010/</guid>
	</item>
	<item>
		<title><![CDATA[[Resolved] Url Search Redirected To Yahoo]]></title>
		<link>http://www.247fixes.com/forums/topic/6161-url-search-redirected-to-yahoo/</link>
		<description><![CDATA[Anything I search from the URL location bar in Internet Explorer is redirected to Yahoo, when it used to go to Google.  Is this malware or a virus?  <br />
<br />
Any help would be greatly appreciated.<br />
<br />
Thanks in advance!<br />
<br />
Here is my HijackThis log.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 11:41:16 AM, on 1/25/2010<br />
Platform: Unknown Windows (WinNT 6.01.3504)<br />
MSIE: Internet Explorer v8.00 (8.00.7600.16385)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:&#092;Program Files (x86)&#092;PC Tools Firewall Plus&#092;FirewallGUI.exe<br />
C:&#092;Program Files (x86)&#092;AVG&#092;AVG9&#092;avgtray.exe<br />
C:&#092;Program Files (x86)&#092;CyberLink&#092;PowerDVD&#092;PDVDServ.exe<br />
C:&#092;Program Files&#092;Logitech&#092;SetPoint&#092;x86&#092;SetPoint32.exe<br />
C:&#092;Program Files (x86)&#092;lg_fwupdate&#092;fwupdate.exe<br />
C:&#092;Program Files (x86)&#092;DeviceVM&#092;Browser Configuration Utility&#092;BCU.exe<br />
C:&#092;Program Files (x86)&#092;Internet Explorer&#092;iexplore.exe<br />
C:&#092;Program Files (x86)&#092;Internet Explorer&#092;iexplore.exe<br />
C:&#092;Windows&#092;SysWow64&#092;Macromed&#092;Flash&#092;FlashUtil10d.exe<br />
C:&#092;Program Files (x86)&#092;Internet Explorer&#092;iexplore.exe<br />
C:&#092;Program Files (x86)&#092;Trend Micro&#092;HijackThis&#092;HijackThis.exe<br />
<br />
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Page_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=69157' class='bbc_url' title='External link' rel='nofollow'>http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Search_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='External link' rel='nofollow'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='External link' rel='nofollow'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = <a href='http://go.microsoft.com/fwlink/?LinkId=69157' class='bbc_url' title='External link' rel='nofollow'>http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Search,SearchAssistant = <br />
R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Search,CustomizeSearch = <br />
R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Local Page = C:&#092;Windows&#092;SysWOW64&#092;blank.htm<br />
R0 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Toolbar,LinksFolderName = <br />
R3 - URLSearchHook: SearchHook Class - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:&#092;Program Files (x86)&#092;DeviceVM&#092;Browser Configuration Utility&#092;AddressBarSearch.dll<br />
O4 - HKLM&#092;..&#092;Run: [00PCTFW] "C:&#092;Program Files (x86)&#092;PC Tools Firewall Plus&#092;FirewallGUI.exe" -s<br />
O4 - HKLM&#092;..&#092;Run: [AVG9_TRAY] C:&#092;PROGRA~2&#092;AVG&#092;AVG9&#092;avgtray.exe<br />
O4 - HKLM&#092;..&#092;Run: [RemoteControl] "C:&#092;Program Files (x86)&#092;CyberLink&#092;PowerDVD&#092;PDVDServ.exe"<br />
O4 - HKLM&#092;..&#092;Run: [LanguageShortcut] "C:&#092;Program Files (x86)&#092;CyberLink&#092;PowerDVD&#092;Language&#092;Language.exe"<br />
O4 - HKLM&#092;..&#092;Run: [LGODDFU] "C:&#092;Program Files (x86)&#092;lg_fwupdate&#092;fwupdate.exe" blrun<br />
O4 - HKLM&#092;..&#092;Run: [BCU] "C:&#092;Program Files (x86)&#092;DeviceVM&#092;Browser Configuration Utility&#092;BCU.exe"<br />
O4 - HKUS&#092;S-1-5-19&#092;..&#092;Run: [Sidebar] %ProgramFiles%&#092;Windows Sidebar&#092;Sidebar.exe /autoRun (User 'LOCAL SERVICE')<br />
O4 - HKUS&#092;S-1-5-19&#092;..&#092;RunOnce: [mctadmin] C:&#092;Windows&#092;System32&#092;mctadmin.exe (User 'LOCAL SERVICE')<br />
O4 - HKUS&#092;S-1-5-20&#092;..&#092;Run: [Sidebar] %ProgramFiles%&#092;Windows Sidebar&#092;Sidebar.exe /autoRun (User 'NETWORK SERVICE')<br />
O4 - HKUS&#092;S-1-5-20&#092;..&#092;RunOnce: [mctadmin] C:&#092;Windows&#092;System32&#092;mctadmin.exe (User 'NETWORK SERVICE')<br />
O4 - Startup: Logitech . Product Registration.lnk = C:&#092;Program Files (x86)&#092;Common Files&#092;LogiShrd&#092;eReg&#092;Common&#092;eReg.exe<br />
O4 - Global Startup: Logitech SetPoint.lnk = C:&#092;Program Files&#092;Logitech&#092;SetPoint&#092;SetPoint.exe<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - <a href='http://download.eset.com/special/eos/OnlineScanner.cab' class='bbc_url' title='External link' rel='nofollow'>http://download.eset.com/special/eos/OnlineScanner.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href='http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab' class='bbc_url' title='External link' rel='nofollow'>http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab</a><br />
O20 - Winlogon Notify: !SASWinLogon - C:&#092;Program Files (x86)&#092;SUPERAntiSpyware&#092;SASWINLO.dll<br />
O23 - Service: @%SystemRoot%&#092;system32&#092;Alg.exe,-112 (ALG) - Unknown owner - C:&#092;Windows&#092;System32&#092;alg.exe (file missing)<br />
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:&#092;Program Files (x86)&#092;AVG&#092;AVG9&#092;avgemc.exe<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:&#092;Program Files (x86)&#092;AVG&#092;AVG9&#092;avgwdsvc.exe<br />
O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:&#092;Program Files (x86)&#092;DeviceVM&#092;Browser Configuration Utility&#092;BCUService.exe<br />
O23 - Service: @%SystemRoot%&#092;system32&#092;efssvc.dll,-100 (EFS) - Unknown owner - C:&#092;Windows&#092;System32&#092;lsass.exe (file missing)<br />
O23 - Service: ES lite Service for program management. (ES lite Service) - Unknown owner - C:&#092;Program Files (x86)&#092;Gigabyte&#092;EasySaver&#092;ESSVR.EXE<br />
O23 - Service: @%systemroot%&#092;system32&#092;fxsresm.dll,-118 (Fax) - Unknown owner - C:&#092;Windows&#092;system32&#092;fxssvc.exe (file missing)<br />
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:&#092;Windows&#092;system32&#092;lsass.exe (file missing)<br />
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:&#092;Program Files&#092;Common Files&#092;Logishrd&#092;Bluetooth&#092;LBTServ.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:&#092;Program Files (x86)&#092;Common Files&#092;LightScribe&#092;LSSrvc.exe<br />
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:&#092;Windows&#092;System32&#092;msdtc.exe (file missing)<br />
O23 - Service: @%SystemRoot%&#092;System32&#092;netlogon.dll,-102 (Netlogon) - Unknown owner - C:&#092;Windows&#092;system32&#092;lsass.exe (file missing)<br />
O23 - Service: NMIndexingService - Nero AG - C:&#092;Program Files (x86)&#092;Common Files&#092;Ahead&#092;Lib&#092;NMIndexingService.exe<br />
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:&#092;Windows&#092;system32&#092;nvvsvc.exe (file missing)<br />
O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:&#092;Program Files (x86)&#092;PC Tools Firewall Plus&#092;FWService.exe<br />
O23 - Service: @%systemroot%&#092;system32&#092;psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:&#092;Windows&#092;system32&#092;lsass.exe (file missing)<br />
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:&#092;Program Files (x86)&#092;CyberLink&#092;Shared Files&#092;RichVideo.exe<br />
O23 - Service: @%systemroot%&#092;system32&#092;Locator.exe,-2 (RpcLocator) - Unknown owner - C:&#092;Windows&#092;system32&#092;locator.exe (file missing)<br />
O23 - Service: @%SystemRoot%&#092;system32&#092;samsrv.dll,-1 (SamSs) - Unknown owner - C:&#092;Windows&#092;system32&#092;lsass.exe (file missing)<br />
O23 - Service: @%SystemRoot%&#092;system32&#092;snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:&#092;Windows&#092;System32&#092;snmptrap.exe (file missing)<br />
O23 - Service: @%systemroot%&#092;system32&#092;spoolsv.exe,-1 (Spooler) - Unknown owner - C:&#092;Windows&#092;System32&#092;spoolsv.exe (file missing)<br />
O23 - Service: @%SystemRoot%&#092;system32&#092;sppsvc.exe,-101 (sppsvc) - Unknown owner - C:&#092;Windows&#092;system32&#092;sppsvc.exe (file missing)<br />
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:&#092;Program Files (x86)&#092;NVIDIA Corporation&#092;3D Vision&#092;nvSCPAPISvr.exe<br />
O23 - Service: @%SystemRoot%&#092;system32&#092;ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:&#092;Windows&#092;system32&#092;UI0Detect.exe (file missing)<br />
O23 - Service: @%SystemRoot%&#092;system32&#092;vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:&#092;Windows&#092;system32&#092;lsass.exe (file missing)<br />
O23 - Service: @%SystemRoot%&#092;system32&#092;vds.exe,-100 (vds) - Unknown owner - C:&#092;Windows&#092;System32&#092;vds.exe (file missing)<br />
O23 - Service: @%systemroot%&#092;system32&#092;vssvc.exe,-102 (VSS) - Unknown owner - C:&#092;Windows&#092;system32&#092;vssvc.exe (file missing)<br />
O23 - Service: @%systemroot%&#092;system32&#092;wbengine.exe,-104 (wbengine) - Unknown owner - C:&#092;Windows&#092;system32&#092;wbengine.exe (file missing)<br />
O23 - Service: @%Systemroot%&#092;system32&#092;wbem&#092;wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:&#092;Windows&#092;system32&#092;wbem&#092;WmiApSrv.exe (file missing)<br />
O23 - Service: @%PROGRAMFILES%&#092;Windows Media Player&#092;wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:&#092;Program Files (x86)&#092;Windows Media Player&#092;wmpnetwk.exe (file missing)<br />
<br />
--<br />
End of file - 7370 bytes]]></description>
		<pubDate>Mon, 25 Jan 2010 16:48:58 +0000</pubDate>
		<guid>http://www.247fixes.com/forums/topic/6161-url-search-redirected-to-yahoo/</guid>
	</item>
	<item>
		<title>Profiles</title>
		<link>http://www.247fixes.com/forums/topic/6154-profiles/</link>
		<description><![CDATA[I don't know if it is just me. But, the profile seems to be misaligned. I have a 1280x800 resolution, and I can hardly read my profile. Just wanted to bring that to attention.]]></description>
		<pubDate>Sun, 24 Jan 2010 19:09:53 +0000</pubDate>
		<guid>http://www.247fixes.com/forums/topic/6154-profiles/</guid>
	</item>
	<item>
		<title><![CDATA[[Inactive]&nbsp;Internet Security 2010 Removal]]></title>
		<link>http://www.247fixes.com/forums/topic/6151-internet-security-2010-removal/</link>
		<description>One of my desktops has been hijacked by Internet Security 2010. Does anyone know how to remove this?</description>
		<pubDate>Sun, 24 Jan 2010 05:10:05 +0000</pubDate>
		<guid>http://www.247fixes.com/forums/topic/6151-internet-security-2010-removal/</guid>
	</item>
	<item>
		<title><![CDATA[[Resolved] Help With The Worm Virus?]]></title>
		<link>http://www.247fixes.com/forums/topic/6139-help-with-the-worm-virus/</link>
		<description><![CDATA[Hi. Computer infected with a win virus i believe. I am attaching a malwarebyte's log and also my hijack this log. Computer has a problem rebooting. and continuous pop ups of INTERNET SECURITY 2010....? keeps trying to run a virus check on my computer.<br />
<br />
<br />
**UPDATE** Ran Malewarebytes, restarted my comp and everything was deleted and taken care of. I am just posting still to see if everything is cleaned up.....<br />
<br />
<br />
Logfile of HijackThis v1.99.1<br />
Scan saved at 8:40:03 AM, on 1/21/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
<br />
Running processes:<br />
C:&#092;WINDOWS&#092;System32&#092;smss.exe<br />
C:&#092;WINDOWS&#092;system32&#092;winlogon.exe<br />
C:&#092;WINDOWS&#092;system32&#092;services.exe<br />
C:&#092;WINDOWS&#092;system32&#092;lsass.exe<br />
C:&#092;WINDOWS&#092;system32&#092;svchost.exe<br />
C:&#092;WINDOWS&#092;System32&#092;svchost.exe<br />
C:&#092;WINDOWS&#092;system32&#092;svchost.exe<br />
C:&#092;WINDOWS&#092;Explorer.EXE<br />
C:&#092;WINDOWS&#092;system32&#092;spoolsv.exe<br />
C:&#092;WINDOWS&#092;system32&#092;ctfmon.exe<br />
C:&#092;Program Files&#092;Common Files&#092;Apple&#092;Mobile Device Support&#092;bin&#092;AppleMobileDeviceService.exe<br />
C:&#092;Program Files&#092;Bonjour&#092;mDNSResponder.exe<br />
C:&#092;WINDOWS&#092;system32&#092;CSHelper.exe<br />
C:&#092;WINDOWS&#092;ehome&#092;ehtray.exe<br />
C:&#092;WINDOWS&#092;eHome&#092;ehRecvr.exe<br />
C:&#092;WINDOWS&#092;system32&#092;dla&#092;tfswctrl.exe<br />
C:&#092;WINDOWS&#092;system32&#092;hkcmd.exe<br />
C:&#092;WINDOWS&#092;system32&#092;igfxpers.exe<br />
C:&#092;Program Files&#092;iTunes&#092;iTunesHelper.exe<br />
C:&#092;Program Files&#092;Common Files&#092;InstallShield&#092;UpdateService&#092;issch.exe<br />
C:&#092;WINDOWS&#092;eHome&#092;ehSched.exe<br />
C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;jqs.exe<br />
C:&#092;Program Files&#092;Common Files&#092;Microsoft Shared&#092;VS7DEBUG&#092;MDM.EXE<br />
C:&#092;Program Files&#092;Yahoo!&#092;SoftwareUpdate&#092;YahooAUService.exe<br />
C:&#092;WINDOWS&#092;system32&#092;svchost.exe<br />
C:&#092;WINDOWS&#092;eHome&#092;ehmsas.exe<br />
C:&#092;Program Files&#092;iPod&#092;bin&#092;iPodService.exe<br />
C:&#092;WINDOWS&#092;system32&#092;dllhost.exe<br />
C:&#092;Program Files&#092;Mozilla Firefox&#092;firefox.exe<br />
C:&#092;WINDOWS&#092;system32&#092;wuauclt.exe<br />
C:&#092;Program Files&#092;HijackThis&#092;HijackThis.exe<br />
<br />
R0 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = <a href='http://www.yahoo.com' class='bbc_url' title='External link' rel='nofollow'>http://www.yahoo.com</a><br />
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Page_URL = <a href='http://www.yahoo.com' class='bbc_url' title='External link' rel='nofollow'>http://www.yahoo.com</a><br />
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Search_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='External link' rel='nofollow'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='External link' rel='nofollow'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = <a href='http://www.yahoo.com' class='bbc_url' title='External link' rel='nofollow'>http://www.yahoo.com</a><br />
R1 - HKCU&#092;Software&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Internet Settings,ProxyOverride = *.local<br />
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:&#092;PROGRA~1&#092;Yahoo!&#092;Companion&#092;Installs&#092;cpn&#092;yt.dll<br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:&#092;Program Files&#092;Adobe&#092;Acrobat 6.0&#092;Reader&#092;ActiveX&#092;AcroIEHelper.dll<br />
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:&#092;WINDOWS&#092;system32&#092;dla&#092;tfswshx.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:&#092;program files&#092;google&#092;googletoolbar1.dll<br />
O2 - BHO: GoogleAFE - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:&#092;Program Files&#092;GoogleAFE&#092;GoogleAE.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:&#092;Program Files&#092;Java&#092;jre6&#092;lib&#092;deploy&#092;jqs&#092;ie&#092;jqs_plugin.dll<br />
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:&#092;PROGRA~1&#092;Yahoo!&#092;Companion&#092;Installs&#092;cpn&#092;YTSingleInstance.dll<br />
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:&#092;program files&#092;google&#092;googletoolbar1.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:&#092;PROGRA~1&#092;Yahoo!&#092;Companion&#092;Installs&#092;cpn&#092;yt.dll<br />
O4 - HKLM&#092;..&#092;Run: [ehTray] C:&#092;WINDOWS&#092;ehome&#092;ehtray.exe<br />
O4 - HKLM&#092;..&#092;Run: [dla] C:&#092;WINDOWS&#092;system32&#092;dla&#092;tfswctrl.exe<br />
O4 - HKLM&#092;..&#092;Run: [igfxhkcmd] C:&#092;WINDOWS&#092;system32&#092;hkcmd.exe<br />
O4 - HKLM&#092;..&#092;Run: [igfxpers] C:&#092;WINDOWS&#092;system32&#092;igfxpers.exe<br />
O4 - HKLM&#092;..&#092;Run: [IntelMeM] C:&#092;Program Files&#092;Intel&#092;Modem Event Monitor&#092;IntelMEM.exe<br />
O4 - HKLM&#092;..&#092;Run: [Corel Photo Downloader] C:&#092;Program Files&#092;Corel&#092;Corel Photo Album 6&#092;MediaDetect.exe<br />
O4 - HKLM&#092;..&#092;Run: [iTunesHelper] "C:&#092;Program Files&#092;iTunes&#092;iTunesHelper.exe"<br />
O4 - HKLM&#092;..&#092;Run: [ISUSPM Startup] "C:&#092;Program Files&#092;Common Files&#092;InstallShield&#092;UpdateService&#092;isuspm.exe" -startup<br />
O4 - HKLM&#092;..&#092;Run: [ISUSScheduler] "C:&#092;Program Files&#092;Common Files&#092;InstallShield&#092;UpdateService&#092;issch.exe" -start<br />
O4 - HKLM&#092;..&#092;Run: [googletalk] C:&#092;Program Files&#092;Google&#092;Google Talk&#092;googletalk.exe /autostart<br />
O4 - HKCU&#092;..&#092;Run: [Steam] "C:&#092;Program Files&#092;Steam&#092;Steam.exe" -silent<br />
O4 - HKCU&#092;..&#092;Run: [DellSupport] "C:&#092;Program Files&#092;DellSupport&#092;DSAgnt.exe" /startup<br />
O4 - HKCU&#092;..&#092;Run: [HijackThis startup scan] C:&#092;Program Files&#092;Trend Micro&#092;3444&#092;HijackThis.exe /startupscan<br />
O4 - HKCU&#092;..&#092;Run: [ctfmon.exe] C:&#092;WINDOWS&#092;system32&#092;ctfmon.exe<br />
O4 - HKCU&#092;..&#092;Run: [Messenger (Yahoo!)] "C:&#092;PROGRA~1&#092;Yahoo!&#092;Messenger&#092;YahooMessenger.exe" -quiet<br />
O4 - HKCU&#092;..&#092;Run: [Skype] "C:&#092;Program Files&#092;Skype&#092;Phone&#092;Skype.exe" /nosplash /minimized<br />
O4 - Startup: ERUNT AutoBackup.lnk = C:&#092;Program Files&#092;ERUNT&#092;AUTOBACK.EXE<br />
O8 - Extra context menu item: &Google Search - res://C:&#092;Program Files&#092;Google&#092;GoogleToolbar1.dll/cmsearch.html<br />
O8 - Extra context menu item: &Translate English Word - res://C:&#092;Program Files&#092;Google&#092;GoogleToolbar1.dll/cmwordtrans.html<br />
O8 - Extra context menu item: Backward Links - res://C:&#092;Program Files&#092;Google&#092;GoogleToolbar1.dll/cmbacklinks.html<br />
O8 - Extra context menu item: Cached Snapshot of Page - res://C:&#092;Program Files&#092;Google&#092;GoogleToolbar1.dll/cmcache.html<br />
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:&#092;PROGRA~1&#092;MICROS~2&#092;OFFICE11&#092;EXCEL.EXE/3000<br />
O8 - Extra context menu item: Similar Pages - res://C:&#092;Program Files&#092;Google&#092;GoogleToolbar1.dll/cmsimilar.html<br />
O8 - Extra context menu item: Translate Page into English - res://C:&#092;Program Files&#092;Google&#092;GoogleToolbar1.dll/cmtrans.html<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:&#092;PROGRA~1&#092;MICROS~2&#092;OFFICE11&#092;REFIEBAR.DLL<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:&#092;WINDOWS&#092;system32&#092;Shdocvw.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%&#092;Network Diagnostic&#092;xpnetdiag.exe (file missing)<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%&#092;Network Diagnostic&#092;xpnetdiag.exe (file missing)<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:&#092;Program Files&#092;Messenger&#092;msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:&#092;Program Files&#092;Messenger&#092;msmsgs.exe<br />
O10 - Unknown file in Winsock LSP: c:&#092;program files&#092;bonjour&#092;mdnsnsp.dll<br />
O11 - Options group: [INTERNATIONAL] International<br />
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - <a href='http://support.dell.com/systemprofiler/SysPro.CAB' class='bbc_url' title='External link' rel='nofollow'>http://support.dell.com/systemprofiler/SysPro.CAB</a><br />
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - <a href='http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab' class='bbc_url' title='External link' rel='nofollow'>http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab</a><br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:&#092;PROGRA~1&#092;COMMON~1&#092;Skype&#092;SKYPE4~1.DLL<br />
O20 - Winlogon Notify: dimsntfy - %SystemRoot%&#092;System32&#092;dimsntfy.dll (file missing)<br />
O20 - Winlogon Notify: igfxcui - C:&#092;WINDOWS&#092;SYSTEM32&#092;igfxdev.dll<br />
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:&#092;WINDOWS&#092;system32&#092;WPDShServiceObj.dll<br />
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Unknown owner - C:&#092;Program Files&#092;Avira&#092;AntiVir Desktop&#092;sched.exe (file missing)<br />
O23 - Service: Avira AntiVir Guard (AntiVirService) - Unknown owner - C:&#092;Program Files&#092;Avira&#092;AntiVir Desktop&#092;avguard.exe (file missing)<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:&#092;Program Files&#092;Common Files&#092;Apple&#092;Mobile Device Support&#092;bin&#092;AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:&#092;Program Files&#092;Bonjour&#092;mDNSResponder.exe<br />
O23 - Service: CopySafe Helper Service (CSHelper) - Unknown owner - C:&#092;WINDOWS&#092;system32&#092;CSHelper.exe<br />
O23 - Service: DSBrokerService - Unknown owner - C:&#092;Program Files&#092;DellSupport&#092;brkrsvc.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:&#092;Program Files&#092;iPod&#092;bin&#092;iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;jqs.exe" -service -config "C:&#092;Program Files&#092;Java&#092;jre6&#092;lib&#092;deploy&#092;jqs&#092;jqs.conf (file missing)<br />
O23 - Service: Intel NCS NetService (NetSvc) - Intel&reg; Corporation - C:&#092;Program Files&#092;Intel&#092;PROSetWired&#092;NCS&#092;Sync&#092;NetSvc.exe<br />
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:&#092;Program Files&#092;Yahoo!&#092;SoftwareUpdate&#092;YahooAUService.exe<br />
<br />
Malwarebytes' Anti-Malware 1.44<br />
Database version: 3603<br />
Windows 5.1.2600 Service Pack 3<br />
Internet Explorer 8.0.6001.18702<br />
<br />
1/21/2010 8:34:29 AM<br />
mbam-log-2010-01-21 (08-34-29).txt<br />
<br />
Scan type: Full Scan (C:&#092;|)<br />
Objects scanned: 184140<br />
Time elapsed: 41 minute(s), 40 second(s)<br />
<br />
Memory Processes Infected: 2<br />
Memory Modules Infected: 0<br />
Registry Keys Infected: 3<br />
Registry Values Infected: 3<br />
Registry Data Items Infected: 10<br />
Folders Infected: 1<br />
Files Infected: 24<br />
<br />
Memory Processes Infected:<br />
C:&#092;Program Files&#092;InternetSecurity2010&#092;IS2010.exe (Rogue.Installer) -&gt; Unloaded process successfully.<br />
C:&#092;WINDOWS&#092;system32&#092;smss32.exe (Trojan.Fake&#097;lert) -&gt; Unloaded process successfully.<br />
<br />
Memory Modules Infected:<br />
(No malicious items detected)<br />
<br />
Registry Keys Infected:<br />
HKEY_CURRENT_USER&#092;SOFTWARE&#092;IS2010 (Rogue.InternetSecurity2010) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Main&#092;{F9197A7E-CE10-458e-85F8-5B0CE6DF2BBE} (Trojan.Agent) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;H8SRT (Rootkit.TDSS) -&gt; Quarantined and deleted successfully.<br />
<br />
Registry Values Infected:<br />
HKEY_CURRENT_USER&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Run&#092;internet security 2010 (Rogue.Installer) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Run&#092;smss32.exe (Trojan.Fake&#097;lert) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Desktop&#092;General&#092;wallpaper (Hijack.Wallpaper) -&gt; Quarantined and deleted successfully.<br />
<br />
Registry Data Items Infected:<br />
HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Windows NT&#092;CurrentVersion&#092;Winlogon&#092;Userinit (Trojan.Fake&#097;lert) -&gt; Data: c:&#092;windows&#092;system32&#092;winlogon32.exe -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Windows NT&#092;CurrentVersion&#092;Winlogon&#092;Userinit (Trojan.Fake&#097;lert) -&gt; Data: system32&#092;winlogon32.exe -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Windows NT&#092;CurrentVersion&#092;Winlogon&#092;Userinit (Hijack.UserInit) -&gt; Bad: (C:&#092;WINDOWS&#092;system32&#092;winlogon32.exe) Good: (userinit.exe) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Policies&#092;ActiveDesktop&#092;NoChangingWallpaper (Hijack.DisplayProperties) -&gt; Bad: (1) Good: (0) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Policies&#092;Explorer&#092;NoActiveDesktopChanges (Hijack.DisplayProperties) -&gt; Bad: (1) Good: (0) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Policies&#092;Explorer&#092;NoSetActiveDesktop (Hijack.DisplayProperties) -&gt; Bad: (1) Good: (0) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Policies&#092;activedesktop&#092;NoChangingWallpaper (Hijack.DisplayProperties) -&gt; Bad: (1) Good: (0) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Policies&#092;Explorer&#092;NoActiveDesktopChanges (Hijack.DisplayProperties) -&gt; Bad: (1) Good: (0) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Policies&#092;Explorer&#092;NoSetActiveDesktop (Hijack.DisplayProperties) -&gt; Bad: (1) Good: (0) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Policies&#092;System&#092;DisableTaskMgr (Hijack.TaskManager) -&gt; Bad: (1) Good: (0) -&gt; Quarantined and deleted successfully.<br />
<br />
Folders Infected:<br />
C:&#092;Program Files&#092;InternetSecurity2010 (Rogue.InternetSecurity2010) -&gt; Quarantined and deleted successfully.<br />
<br />
Files Infected:<br />
C:&#092;Program Files&#092;InternetSecurity2010&#092;IS2010.exe (Rogue.Installer) -&gt; Quarantined and deleted successfully.<br />
C:&#092;Documents and Settings&#092;Anthony&#092;Local Settings&#092;temp&#092;3C.tmp (Rootkit.TDSS) -&gt; Quarantined and deleted successfully.<br />
C:&#092;Documents and Settings&#092;Anthony&#092;Local Settings&#092;temp&#092;45.tmp (Rootkit.TDSS) -&gt; Quarantined and deleted successfully.<br />
C:&#092;Documents and Settings&#092;Anthony&#092;Local Settings&#092;temp&#092;49.tmp (Rootkit.TDSS) -&gt; Quarantined and deleted successfully.<br />
C:&#092;Documents and Settings&#092;Anthony&#092;Local Settings&#092;temp&#092;H8SRTce82.tmp (Rogue.Installer) -&gt; Quarantined and deleted successfully.<br />
C:&#092;Documents and Settings&#092;Anthony&#092;Local Settings&#092;temp&#092;H8SRTcfaa.tmp (Trojan.Agent) -&gt; Quarantined and deleted successfully.<br />
C:&#092;Documents and Settings&#092;Anthony&#092;Local Settings&#092;Temporary Internet Files&#092;Content.IE5&#092;0Z24MRKG&#092;dfghfghgfj[1].dll (Trojan.BHO) -&gt; Quarantined and deleted successfully.<br />
C:&#092;Documents and Settings&#092;Anthony&#092;Local Settings&#092;Temporary Internet Files&#092;Content.IE5&#092;V97O4C03&#092;z002102318806r0409J0f000601W95308cfdX2aafc0bdY61fa1c57Z03007f350[1] (Trojan.Downloader) -&gt; Quarantined and deleted successfully.<br />
C:&#092;Documents and Settings&#092;Anthony&#092;Local Settings&#092;Temporary Internet Files&#092;Content.IE5&#092;V97O4C03&#092;SetupIS2010[1].exe (Rogue.Installer) -&gt; Quarantined and deleted successfully.<br />
C:&#092;Documents and Settings&#092;Anthony&#092;Local Settings&#092;Temporary Internet Files&#092;Content.IE5&#092;V97O4C03&#092;load[1].php (Rootkit.TDSS) -&gt; Quarantined and deleted successfully.<br />
C:&#092;WINDOWS&#092;system32&#092;helper32.dll (Trojan.BHO) -&gt; Quarantined and deleted successfully.<br />
C:&#092;WINDOWS&#092;system32&#092;smss32.exe (Trojan.Fake&#097;lert) -&gt; Quarantined and deleted successfully.<br />
C:&#092;WINDOWS&#092;system32&#092;Winlogon32.exe (Trojan.Fake&#097;lert) -&gt; Quarantined and deleted successfully.<br />
C:&#092;Documents and Settings&#092;Anthony&#092;Application Data&#092;Microsoft&#092;Internet Explorer&#092;Quick Launch&#092;Internet Security 2010.lnk (Rogue.InternetSecurity2010) -&gt; Quarantined and deleted successfully.<br />
C:&#092;Documents and Settings&#092;Anthony&#092;Start Menu&#092;Internet Security 2010.lnk (Rogue.InternetSecurity2010) -&gt; Quarantined and deleted successfully.<br />
C:&#092;WINDOWS&#092;system32&#092;H8SRTdldiapomoc.dll (Rootkit.TDSS) -&gt; Quarantined and deleted successfully.<br />
C:&#092;WINDOWS&#092;system32&#092;H8SRTgkypijqrki.dll (Rootkit.TDSS) -&gt; Quarantined and deleted successfully.<br />
C:&#092;WINDOWS&#092;system32&#092;h8srtkrl32mainweq.dll (Rootkit.TDSS) -&gt; Quarantined and deleted successfully.<br />
C:&#092;WINDOWS&#092;system32&#092;H8SRTkyfsuqkuly.dll (Rootkit.TDSS) -&gt; Quarantined and deleted successfully.<br />
C:&#092;WINDOWS&#092;system32&#092;H8SRTtkyypewpow.dll (Rootkit.TDSS) -&gt; Quarantined and deleted successfully.<br />
C:&#092;WINDOWS&#092;system32&#092;H8SRTvdjgqnnowe.dat (Rootkit.TDSS) -&gt; Quarantined and deleted successfully.<br />
C:&#092;WINDOWS&#092;system32&#092;drivers&#092;H8SRTcfkeehihwx.sys (Rootkit.TDSS) -&gt; Quarantined and deleted successfully.<br />
C:&#092;WINDOWS&#092;system32&#092;41.exe (Trojan.Fake&#097;lert) -&gt; Quarantined and deleted successfully.<br />
C:&#092;WINDOWS&#092;system32&#092;warning.html (Trojan.Fake&#097;lert) -&gt; Quarantined and deleted successfully.<br />
<br />
<br />
<br />
<br />
THANK YOU/]]></description>
		<pubDate>Thu, 21 Jan 2010 16:40:59 +0000</pubDate>
		<guid>http://www.247fixes.com/forums/topic/6139-help-with-the-worm-virus/</guid>
	</item>
	<item>
		<title><![CDATA[[Resolved] Need Help]]></title>
		<link>http://www.247fixes.com/forums/topic/6125-need-help/</link>
		<description>I am not computer sazy so i really cant tell you exactly what is going on with my computer. One problem is that my computer will randomly start running extremely slow. When it does this it makes clicking and screeching noises.....? I keep getting a notices saying that my antivirus software has been shut off but i am not able to turn it back on (its not expired). I tried to attach a log but i wasnt able to save the log to word pad???? Any help is much appreciated</description>
		<pubDate>Thu, 21 Jan 2010 06:18:10 +0000</pubDate>
		<guid>http://www.247fixes.com/forums/topic/6125-need-help/</guid>
	</item>
	<item>
		<title><![CDATA[[Inactive]&nbsp;Problems With International Keyboard Possibly Due To Malware?]]></title>
		<link>http://www.247fixes.com/forums/topic/6124-problems-with-international-keyboard-possibly-due-to-malware/</link>
		<description><![CDATA[Hi, I have been having problems with my apostrophe and tilde keys, as they are doubling every time I press them. This only occurs when I use the US INternational keyboard though. I must use this setting to do my French homework, and I cannot type accents when the keys are doubling. If you could help me out by checking my logfile and telling me what does not belong, I would greatly appreciate it. Thank you very much for your time.<br />
<br />
<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 6:24:29 PM, on 1/20/2010<br />
Platform: Windows Vista SP1 (WinNT 6.00.1905)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18372)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:&#092;Windows&#092;system32&#092;taskeng.exe<br />
C:&#092;Windows&#092;system32&#092;Dwm.exe<br />
C:&#092;Windows&#092;Explorer.EXE<br />
C:&#092;Program Files&#092;Windows Defender&#092;MSASCui.exe<br />
C:&#092;Program Files&#092;Toshiba&#092;Power Saver&#092;TPwrMain.exe<br />
C:&#092;Program Files&#092;Toshiba&#092;SmoothView&#092;SmoothView.exe<br />
C:&#092;Windows&#092;System32&#092;igfxpers.exe<br />
C:&#092;Program Files&#092;CyberLink&#092;PowerCinema for TOSHIBA&#092;PCMAgent.exe<br />
C:&#092;Program Files&#092;Intel&#092;Intel Matrix Storage Manager&#092;IAAnotif.exe<br />
C:&#092;Windows&#092;System32&#092;hkcmd.exe<br />
C:&#092;Program Files&#092;CyberLink&#092;PowerCinema for TOSHIBA&#092;Kernel&#092;CLML&#092;CLMLSvc.exe<br />
C:&#092;Program Files&#092;iTunes&#092;iTunesHelper.exe<br />
C:&#092;Windows&#092;ehome&#092;ehtray.exe<br />
C:&#092;Program Files&#092;Yahoo!&#092;Search Protection&#092;SearchProtection.exe<br />
C:&#092;Windows&#092;system32&#092;igfxsrvc.exe<br />
C:&#092;Windows&#092;ehome&#092;ehmsas.exe<br />
C:&#092;Program Files&#092;Mozilla Firefox&#092;firefox.exe<br />
C:&#092;Windows&#092;system32&#092;wuauclt.exe<br />
C:&#092;Program Files&#092;Malwarebytes' Anti-Malware&#092;mbam.exe<br />
C:&#092;Windows&#092;System32&#092;dfrgui.exe<br />
C:&#092;Program Files&#092;Trend Micro&#092;HijackThis&#092;HijackThis.exe<br />
C:&#092;Windows&#092;system32&#092;SearchFilterHost.exe<br />
<br />
R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Page_URL = <a href='http://www.toshibadirect.com/dpdstart' class='bbc_url' title='External link' rel='nofollow'>http://www.toshibadirect.com/dpdstart</a><br />
R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='External link' rel='nofollow'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = <a href='http://www.toshibadirect.com/dpdstart' class='bbc_url' title='External link' rel='nofollow'>http://www.toshibadirect.com/dpdstart</a><br />
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Page_URL = <a href='http://www.toshibadirect.com/dpdstart' class='bbc_url' title='External link' rel='nofollow'>http://www.toshibadirect.com/dpdstart</a><br />
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Search_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='External link' rel='nofollow'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='External link' rel='nofollow'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = <a href='http://go.microsoft.com/fwlink/?LinkId=69157' class='bbc_url' title='External link' rel='nofollow'>http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Search,SearchAssistant = <br />
R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Search,CustomizeSearch = <br />
R0 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Toolbar,LinksFolderName = <br />
R3 - URLSearchHook: (no name) - {dd02a4eb-4afd-4d60-99d8-e67f964ca813} - (no file)<br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:&#092;PROGRA~1&#092;Yahoo!&#092;Companion&#092;Installs&#092;cpn&#092;yt.dll<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:&#092;Program Files&#092;Common Files&#092;Adobe&#092;Acrobat&#092;ActiveX&#092;AcroIEHelper.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:&#092;Program Files&#092;Java&#092;jre1.6.0_07&#092;bin&#092;ssv.dll<br />
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:&#092;Program Files&#092;Ask.com&#092;GenericAskToolbar.dll<br />
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:&#092;PROGRA~1&#092;Yahoo!&#092;Companion&#092;Installs&#092;cpn&#092;YTSingleInstance.dll<br />
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:&#092;Program Files&#092;Ask.com&#092;GenericAskToolbar.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:&#092;PROGRA~1&#092;Yahoo!&#092;Companion&#092;Installs&#092;cpn&#092;yt.dll<br />
O4 - HKLM&#092;..&#092;Run: [Windows Defender] "C:&#092;Program Files&#092;Windows Defender&#092;MSASCui.exe" -hide<br />
O4 - HKLM&#092;..&#092;Run: [TPwrMain] "C:&#092;Program Files&#092;TOSHIBA&#092;Power Saver&#092;TPwrMain.EXE"<br />
O4 - HKLM&#092;..&#092;Run: [SmoothView] "C:&#092;Program Files&#092;Toshiba&#092;SmoothView&#092;SmoothView.exe"<br />
O4 - HKLM&#092;..&#092;Run: [Persistence] "C:&#092;Windows&#092;system32&#092;igfxpers.exe"<br />
O4 - HKLM&#092;..&#092;Run: [PCMAgent] "C:&#092;Program Files&#092;CyberLink&#092;PowerCinema for TOSHIBA&#092;PCMAgent.exe"<br />
O4 - HKLM&#092;..&#092;Run: [IgfxTray] "C:&#092;Windows&#092;system32&#092;igfxtray.exe"<br />
O4 - HKLM&#092;..&#092;Run: [IAAnotif] "C:&#092;Program Files&#092;Intel&#092;Intel Matrix Storage Manager&#092;iaanotif.exe"<br />
O4 - HKLM&#092;..&#092;Run: [HotKeysCmds] "C:&#092;Windows&#092;system32&#092;hkcmd.exe"<br />
O4 - HKLM&#092;..&#092;Run: [CLMLServer] "C:&#092;Program Files&#092;CyberLink&#092;PowerCinema for TOSHIBA&#092;Kernel&#092;CLML&#092;CLMLSvc.exe"<br />
O4 - HKLM&#092;..&#092;Run: [Camera Assistant Software] "C:&#092;Program Files&#092;Camera Assistant Software for Toshiba&#092;traybar.exe" /start<br />
O4 - HKLM&#092;..&#092;Run: [AppleSyncNotifier] "C:&#092;Program Files&#092;Common Files&#092;Apple&#092;Mobile Device Support&#092;bin&#092;AppleSyncNotifier.exe"<br />
O4 - HKLM&#092;..&#092;Run: [QuickTime Task] "C:&#092;Program Files&#092;QuickTime&#092;QTTask.exe" -atboottime<br />
O4 - HKLM&#092;..&#092;Run: [iTunesHelper] "C:&#092;Program Files&#092;iTunes&#092;iTunesHelper.exe"<br />
O4 - HKLM&#092;..&#092;Run: [Adobe Reader Speed Launcher] "C:&#092;Program Files&#092;Adobe&#092;Reader 8.0&#092;Reader&#092;Reader_sl.exe"<br />
O4 - HKLM&#092;..&#092;Run: [Malwarebytes Anti-Malware (reboot)] "C:&#092;Program Files&#092;Malwarebytes' Anti-Malware&#092;mbam.exe" /runcleanupscript<br />
O4 - HKLM&#092;..&#092;Run: [YSearchProtection] "C:&#092;Program Files&#092;Yahoo!&#092;Search Protection&#092;SearchProtection.exe"<br />
O4 - HKCU&#092;..&#092;Run: [ehTray.exe] C:&#092;Windows&#092;ehome&#092;ehTray.exe<br />
O4 - HKCU&#092;..&#092;Run: [userinit] C:&#092;Users&#092;user&#092;AppData&#092;Roaming&#092;sdra64.exe<br />
O4 - HKCU&#092;..&#092;Run: [Search Protection] C:&#092;Program Files&#092;Yahoo!&#092;Search Protection&#092;SearchProtection.exe<br />
O4 - HKUS&#092;S-1-5-19&#092;..&#092;Run: [Sidebar] %ProgramFiles%&#092;Windows Sidebar&#092;Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS&#092;S-1-5-19&#092;..&#092;Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS&#092;S-1-5-20&#092;..&#092;Run: [Sidebar] %ProgramFiles%&#092;Windows Sidebar&#092;Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:&#092;PROGRA~1&#092;MICROS~3&#092;OFFICE11&#092;EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:&#092;PROGRA~1&#092;Java&#092;JRE16~2.0_0&#092;bin&#092;ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:&#092;PROGRA~1&#092;Java&#092;JRE16~2.0_0&#092;bin&#092;ssv.dll<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:&#092;PROGRA~1&#092;MICROS~3&#092;Office12&#092;ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:&#092;PROGRA~1&#092;MICROS~3&#092;Office12&#092;ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:&#092;PROGRA~1&#092;MICROS~3&#092;OFFICE11&#092;REFIEBAR.DLL<br />
O13 - Gopher Prefix: <br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:&#092;Program Files&#092;Xobni&#092;Skype4Com.dll<br />
O20 - AppInit_DLLs: c:&#092;progra~1&#092;google&#092;google~1&#092;goec62~1.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:&#092;Program Files&#092;Common Files&#092;Apple&#092;Mobile Device Support&#092;bin&#092;AppleMobileDeviceService.exe<br />
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:&#092;Program Files&#092;TOSHIBA&#092;ConfigFree&#092;CFSvcs.exe<br />
O23 - Service: Intel&reg; PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:&#092;Program Files&#092;Intel&#092;Wireless&#092;Bin&#092;EvtEng.exe<br />
O23 - Service: Google Updater Service (gusvc) - Google - C:&#092;Program Files&#092;Google&#092;Common&#092;Google Updater&#092;GoogleUpdaterService.exe<br />
O23 - Service: Intel&reg; Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:&#092;Program Files&#092;Intel&#092;Intel Matrix Storage Manager&#092;IAANTMon.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:&#092;Program Files&#092;Common Files&#092;InstallShield&#092;Driver&#092;1150&#092;Intel 32&#092;IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:&#092;Program Files&#092;iPod&#092;bin&#092;iPodService.exe<br />
O23 - Service: lxcr_device -   - C:&#092;Windows&#092;system32&#092;lxcrcoms.exe<br />
O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:&#092;Program Files&#092;O2Micro Flash Memory Card Driver&#092;o2flash.exe<br />
O23 - Service: pinger - Unknown owner - C:&#092;TOSHIBA&#092;IVP&#092;ISM&#092;pinger.exe<br />
O23 - Service: Intel&reg; PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:&#092;Program Files&#092;Intel&#092;Wireless&#092;Bin&#092;RegSrvc.exe<br />
O23 - Service: Swupdtmr - Unknown owner - c:&#092;TOSHIBA&#092;IVP&#092;swupdate&#092;swupdtmr.exe<br />
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:&#092;Program Files&#092;Toshiba&#092;TOSHIBA DVD PLAYER&#092;TNaviSrv.exe<br />
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:&#092;Windows&#092;system32&#092;TODDSrv.exe<br />
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:&#092;Program Files&#092;Toshiba&#092;Power Saver&#092;TosCoSrv.exe<br />
O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:&#092;Program Files&#092;TOSHIBA&#092;SMARTLogService&#092;TosIPCSrv.exe<br />
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:&#092;Program Files&#092;Common Files&#092;Ulead Systems&#092;DVD&#092;ULCDRSvr.exe<br />
O23 - Service: XAudioService - Conexant Systems, Inc. - C:&#092;Windows&#092;system32&#092;DRIVERS&#092;xaudio.exe<br />
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:&#092;Program Files&#092;Yahoo!&#092;SoftwareUpdate&#092;YahooAUService.exe<br />
<br />
--<br />
End of file - 8500 bytes<div id='attach_wrap' class='rounded clearfix'>
	<h4></h4>
	<ul>
		
			<li class='clear'>
				<a href="http://www.247fixes.com/forums/index.php?app=core&module=attach&section=attach&attach_id=911" title=""><img src="http://www.247fixes.com/forums/public/" alt="" /></a>
&nbsp;<a href="http://www.247fixes.com/forums/index.php?app=core&module=attach&section=attach&attach_id=911" title="">hijackthis.log</a> <span class='desc'><strong>(8.3K)</strong></span>
<br /><span class="desc info">: 0</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Thu, 21 Jan 2010 01:58:08 +0000</pubDate>
		<guid>http://www.247fixes.com/forums/topic/6124-problems-with-international-keyboard-possibly-due-to-malware/</guid>
	</item>
	<item>
		<title><![CDATA[[Closed] Ignore This]]></title>
		<link>http://www.247fixes.com/forums/topic/6100-ignore-this/</link>
		<description>argh</description>
		<pubDate>Tue, 19 Jan 2010 02:12:25 +0000</pubDate>
		<guid>http://www.247fixes.com/forums/topic/6100-ignore-this/</guid>
	</item>
</channel>
</rss>