<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title><![CDATA[Antisource Security Forums - All Forums]]></title>
		<link>http://www.antisource.com/forums/</link>
		<description><![CDATA[Antisource Security Forums - http://www.antisource.com/forums]]></description>
		<pubDate>Fri, 18 May 2012 08:20:23 +0000</pubDate>
		<generator>MyBB</generator>
		<item>
			<title><![CDATA[Malware that controls task manager...]]></title>
			<link>http://www.antisource.com/forums/showthread.php?tid=4699</link>
			<pubDate>Fri, 18 Feb 2011 18:29:34 +0000</pubDate>
			<guid isPermaLink="false">http://www.antisource.com/forums/showthread.php?tid=4699</guid>
			<description><![CDATA[Her is my hijack this log...The malware flashes an infection messgae in red on my desktop and starts a virus scan and then tries to sell me a product to remove the infections found.  It also closes task manager if I opened it and then disables it all together.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.4<br />
Scan saved at 9:56:51 AM, on 2/18/2011<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\LEXBCES.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\system32\LEXPPS.EXE<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\Program Files\Common Files\Java\Java Update\jusched.exe<br />
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe<br />
C:\Program Files\Dell\Media Experience\PCMService.exe<br />
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe<br />
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe<br />
C:\Program Files\Real\RealPlayer\RealPlay.exe<br />
C:\Program Files\Common Files\Dell\EUSW\Support.exe<br />
C:\Program Files\Common Files\AOL\1146369632\ee\AOLSoftware.exe<br />
C:\Program Files\McAfee.com\Agent\mcagent.exe<br />
C:\PROGRA~1\MYWEBS~1\bar\7.bin\mwsoemon.exe<br />
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe<br />
C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe<br />
C:\Program Files\Dell V310-V510 Series\dleamon.exe<br />
C:\Program Files\Dell V310-V510 Series\ezprint.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe<br />
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe<br />
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\dleaserv.exe<br />
C:\WINDOWS\system32\dleacoms.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br />
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
C:\Program Files\Common Files\AOL\1146369632\EE\anotify.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe<br />
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe<br />
C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe<br />
C:\Documents and Settings\W. Lou Thompson\Desktop\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://www.dell4me.com/myway" target="_blank">http://www.dell4me.com/myway</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.yahoo.com/" target="_blank">http://www.yahoo.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\7.bin\MWSSRCAS.DLL<br />
R3 - URLSearchHook: (no name) - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - (no file)<br />
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\7.bin\MWSSRCAS.DLL<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\7.bin\MWSBAR.DLL<br />
O2 - BHO: Dell Toolbar - {09B71986-2AC5-482d-B6CB-42EA34F4F85B} - C:\Program Files\Dell Toolbar\toolband.dll<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll<br />
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: MSN Toolbar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\7.bin\MWSBAR.DLL<br />
O3 - Toolbar: MSN Toolbar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll<br />
O3 - Toolbar: Dell Toolbar - {09B71986-2AC5-482d-B6CB-42EA34F4F85B} - C:\Program Files\Dell Toolbar\toolband.dll<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"<br />
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe<br />
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"<br />
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe<br />
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe<br />
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br />
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe<br />
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1146369632\ee\AOLSoftware.exe<br />
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe<br />
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br />
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey<br />
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\7.bin\mwsoemon.exe<br />
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2<br />
O4 - HKLM\..\Run: [MSN Toolbar] "C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe"<br />
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume<br />
O4 - HKLM\..\Run: [dleamon.exe] "C:\Program Files\Dell V310-V510 Series\dleamon.exe"<br />
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Dell V310-V510 Series\ezprint.exe"<br />
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\7.bin\m3SrchMn.exe" /m=2 /w /h<br />
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9<br />
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\7.bin\mwsoemon.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br />
O8 - Extra context menu item: &amp;Search - <a href="http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZSYYYYYYTKUS" target="_blank">http://edits.mywebsearch.com/toolbaredit...YYYYYYTKUS</a><br />
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br />
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - <a href="http://wwws.musicmatch.com/mmz/openWebRadio.html" target="_blank">http://wwws.musicmatch.com/mmz/openWebRadio.html</a> (file missing)<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a href="http://go.microsoft.com/fwlink/?linkid=39204" target="_blank">http://go.microsoft.com/fwlink/?linkid=39204</a><br />
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - <a href="http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/SmileyCentralInitialSetup1.0.1.1.cab" target="_blank">http://ak.exe.imgfarm.com/images/nocache....0.1.1.cab</a><br />
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - <a href="http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab" target="_blank">http://download.mcafee.com/molbin/shared...insctl.cab</a><br />
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - <a href="http://fb.familylink.com/we_are_related/stream/core/lib/AurigmaImageUploader/ImageUploader5.cab" target="_blank">http://fb.familylink.com/we_are_related/...oader5.cab</a><br />
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - <a href="http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab" target="_blank">http://download.mcafee.com/molbin/shared...cgdmgr.cab</a><br />
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - <a href="http://ak.imgag.com/imgag/cp/install/Crusher.cab" target="_blank">http://ak.imgag.com/imgag/cp/install/Crusher.cab</a><br />
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll<br />
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll<br />
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll<br />
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe<br />
O23 - Service: dleaCATSCustConnectService - Unknown owner - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\dleaserv.exe<br />
O23 - Service: dlea_device -   - C:\WINDOWS\system32\dleacoms.exe<br />
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE<br />
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe<br />
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br />
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe<br />
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe<br />
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe<br />
<br />
--<br />
End of file - 11403 bytes]]></description>
			<content:encoded><![CDATA[Her is my hijack this log...The malware flashes an infection messgae in red on my desktop and starts a virus scan and then tries to sell me a product to remove the infections found.  It also closes task manager if I opened it and then disables it all together.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.4<br />
Scan saved at 9:56:51 AM, on 2/18/2011<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\LEXBCES.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\system32\LEXPPS.EXE<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\Program Files\Common Files\Java\Java Update\jusched.exe<br />
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe<br />
C:\Program Files\Dell\Media Experience\PCMService.exe<br />
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe<br />
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe<br />
C:\Program Files\Real\RealPlayer\RealPlay.exe<br />
C:\Program Files\Common Files\Dell\EUSW\Support.exe<br />
C:\Program Files\Common Files\AOL\1146369632\ee\AOLSoftware.exe<br />
C:\Program Files\McAfee.com\Agent\mcagent.exe<br />
C:\PROGRA~1\MYWEBS~1\bar\7.bin\mwsoemon.exe<br />
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe<br />
C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe<br />
C:\Program Files\Dell V310-V510 Series\dleamon.exe<br />
C:\Program Files\Dell V310-V510 Series\ezprint.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe<br />
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe<br />
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\dleaserv.exe<br />
C:\WINDOWS\system32\dleacoms.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br />
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
C:\Program Files\Common Files\AOL\1146369632\EE\anotify.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe<br />
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe<br />
C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe<br />
C:\Documents and Settings\W. Lou Thompson\Desktop\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://www.dell4me.com/myway" target="_blank">http://www.dell4me.com/myway</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.yahoo.com/" target="_blank">http://www.yahoo.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\7.bin\MWSSRCAS.DLL<br />
R3 - URLSearchHook: (no name) - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - (no file)<br />
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\7.bin\MWSSRCAS.DLL<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\7.bin\MWSBAR.DLL<br />
O2 - BHO: Dell Toolbar - {09B71986-2AC5-482d-B6CB-42EA34F4F85B} - C:\Program Files\Dell Toolbar\toolband.dll<br />
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll<br />
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: MSN Toolbar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\7.bin\MWSBAR.DLL<br />
O3 - Toolbar: MSN Toolbar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll<br />
O3 - Toolbar: Dell Toolbar - {09B71986-2AC5-482d-B6CB-42EA34F4F85B} - C:\Program Files\Dell Toolbar\toolband.dll<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"<br />
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe<br />
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"<br />
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe<br />
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe<br />
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br />
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe<br />
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1146369632\ee\AOLSoftware.exe<br />
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe<br />
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br />
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey<br />
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\7.bin\mwsoemon.exe<br />
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2<br />
O4 - HKLM\..\Run: [MSN Toolbar] "C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe"<br />
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume<br />
O4 - HKLM\..\Run: [dleamon.exe] "C:\Program Files\Dell V310-V510 Series\dleamon.exe"<br />
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Dell V310-V510 Series\ezprint.exe"<br />
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\7.bin\m3SrchMn.exe" /m=2 /w /h<br />
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9<br />
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\7.bin\mwsoemon.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br />
O8 - Extra context menu item: &amp;Search - <a href="http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZSYYYYYYTKUS" target="_blank">http://edits.mywebsearch.com/toolbaredit...YYYYYYTKUS</a><br />
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br />
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - <a href="http://wwws.musicmatch.com/mmz/openWebRadio.html" target="_blank">http://wwws.musicmatch.com/mmz/openWebRadio.html</a> (file missing)<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a href="http://go.microsoft.com/fwlink/?linkid=39204" target="_blank">http://go.microsoft.com/fwlink/?linkid=39204</a><br />
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - <a href="http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/SmileyCentralInitialSetup1.0.1.1.cab" target="_blank">http://ak.exe.imgfarm.com/images/nocache....0.1.1.cab</a><br />
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - <a href="http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab" target="_blank">http://download.mcafee.com/molbin/shared...insctl.cab</a><br />
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - <a href="http://fb.familylink.com/we_are_related/stream/core/lib/AurigmaImageUploader/ImageUploader5.cab" target="_blank">http://fb.familylink.com/we_are_related/...oader5.cab</a><br />
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - <a href="http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab" target="_blank">http://download.mcafee.com/molbin/shared...cgdmgr.cab</a><br />
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - <a href="http://ak.imgag.com/imgag/cp/install/Crusher.cab" target="_blank">http://ak.imgag.com/imgag/cp/install/Crusher.cab</a><br />
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll<br />
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll<br />
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll<br />
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe<br />
O23 - Service: dleaCATSCustConnectService - Unknown owner - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\dleaserv.exe<br />
O23 - Service: dlea_device -   - C:\WINDOWS\system32\dleacoms.exe<br />
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE<br />
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe<br />
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br />
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe<br />
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe<br />
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe<br />
<br />
--<br />
End of file - 11403 bytes]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Forum slow]]></title>
			<link>http://www.antisource.com/forums/showthread.php?tid=4695</link>
			<pubDate>Wed, 01 Dec 2010 00:10:07 +0000</pubDate>
			<guid isPermaLink="false">http://www.antisource.com/forums/showthread.php?tid=4695</guid>
			<description><![CDATA[Hiya, I have a small query. Does anybody else feel a small lag using this site after they logon? It normally requires around several seconds roughly for me to get the main page.<br />
<br />
Take care<br />
Marisa <br />
======================================<br />
<a href="http://www.antisource.com" target="_blank">http://www.antisource.com</a> rocks! | <a href="http://roulette-reaper-review.weebly.com" target="_blank">Roulette Reaper Review</a>]]></description>
			<content:encoded><![CDATA[Hiya, I have a small query. Does anybody else feel a small lag using this site after they logon? It normally requires around several seconds roughly for me to get the main page.<br />
<br />
Take care<br />
Marisa <br />
======================================<br />
<a href="http://www.antisource.com" target="_blank">http://www.antisource.com</a> rocks! | <a href="http://roulette-reaper-review.weebly.com" target="_blank">Roulette Reaper Review</a>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Detect  SQL Injection Attacks]]></title>
			<link>http://www.antisource.com/forums/showthread.php?tid=4257</link>
			<pubDate>Sat, 06 Feb 2010 06:13:05 +0000</pubDate>
			<guid isPermaLink="false">http://www.antisource.com/forums/showthread.php?tid=4257</guid>
			<description><![CDATA[<span style="font-weight: bold;">What is SQL Injection Attacks</span><br />
<br />
With the growing up of B/S model application development, more and more programmer write program with it. Unfortunately, many programmers did not judge the validity of usersâ input data during encoding, and then, there will be security risk in the application.<br />
<br />
Malicious attackers submit a special section of database query code to the server, the server will disclosure some sensitive information when respond with corresponding result. This is SQL Injection Attacks. The main trend Firewall currently will not alarm when there is SQL attack because of the SQL Injection is via normal point and hidden and difficult to be detected, seemingly normal website visit.<br />
<br />
<span style="font-weight: bold;">The danger of SQL Injection Attacks</span><br />
<br />
According to the statistics of CVE in 2006, there are more than 70% attacks based on web application. The SQL Injection Attacks increase year by year, it arrives at 1078 in 2006. Even though, these data is only for the vulnerability in universal applications currently.<br />
&lt;!-- m --&gt;&lt;a class="postlink" href="http://www.ids-sax2.com/articles/images/CVESQLInjectVulnerabilities.gif"&gt;http://www.ids-sax2.com/articles/images ... lities.gif&lt;/a&gt;&lt;!-- m --&gt;<br />
<span style="font-weight: bold;">The danger of SQL Injection Attacks including:</span><br />
<br />
ï® Change the data in database without authorization.<br />
     Gain the administration authority of a site without authorization.<br />
ï® Maliciously change content of a site without authorization.<br />
ï® XSS attacks.<br />
ï® Gain the control authority of the server without authorization.<br />
ï® Add, delete and change the accounts in the server without authorization.<br />
 <br />
<span style="font-weight: bold;">The process of detect and revert SQL Injection Attacks</span><br />
<br />
Some IDS software will execute effective detection for SQL Injection Attacks, though, firewall can not. Now, we go to the process of detect and revert SQL Injection Attacks with IDS software Ax3soft Sax2.<br />
<br />
<span style="font-weight: bold;">The steps of SQL Injection Attacks are:</span><br />
<br />
a) Determine environment to find the injection point.<br />
b) Determine the type of database.<br />
c) Guess datasheet.<br />
d) Guess the field.<br />
e) Guess the content.<br />
<br />
The steps âGuess datasheetâ, âGuess the fieldâ and âGuess the contentâ are very important fro SQL Injection Attacks during the full process. Letâs analyze these there steps.<br />
<br />
Sax2 will detect and alarm the attacks in network real-time. It will show the in the table Event when there is SQL Injection Attacks, see the figure 1.<br />
&lt;!-- m --&gt;&lt;a class="postlink" href="http://www.ids-sax2.com/articles/images/DetectSQLInjectionAttacks(1"&gt;http://www.ids-sax2.com/articles/images ... nAttacks(1&lt;/a&gt;&lt;!-- m --&gt;).gif<br />
Figure 1 Sax2 alarm the MS_SQL Injection Attacks real-time<br />
<br />
The selected event in the Figure 1 shows the attackerâs IP 192.168.21.103, the victimâs IP 125.65.112.10. And the original message is âselect * from [dirs]â, means enquire whether there is a datasheet named âdirsâ in current database, in the Original Communication view.<br />
The attacker will repeat the operation to gain the expected datasheet. He will try to guess the filed in the datasheet if found the corresponding datasheet in the database.<br />
&lt;!-- m --&gt;&lt;a class="postlink" href="http://www.ids-sax2.com/articles/images/DetectSQLInjectionAttacks(2"&gt;http://www.ids-sax2.com/articles/images ... nAttacks(2&lt;/a&gt;&lt;!-- m --&gt;).gif<br />
Figure 2 Sax2 analysis the attacker is guessing the filed in the admin database<br />
<br />
The code in the red circle in the Figure 2 show the attacker is guessing the âpathsâ filed in the admin database. Also, the attacker will repeat the operation till find the corresponding filed.<br />
<br />
The attacker will determine the length of the filed and guess the content after found the corresponding filed. It will be a SQL Injection Attacks after the attacker guess the content in the filed successfully. Sometimes, the attacker has to decryption the content if it in MD5 encryption.<br />
<br />
Above is the whole process of SQL Injection Attacks and we detect it with Sax2. As we know, Sax2 can effectively detect and alarm the SQL Injection Attacks when it occurs. IDS software Sax2 is a useful tool for SQL Injection Attacks and make your network security combine with firewall software.]]></description>
			<content:encoded><![CDATA[<span style="font-weight: bold;">What is SQL Injection Attacks</span><br />
<br />
With the growing up of B/S model application development, more and more programmer write program with it. Unfortunately, many programmers did not judge the validity of usersâ input data during encoding, and then, there will be security risk in the application.<br />
<br />
Malicious attackers submit a special section of database query code to the server, the server will disclosure some sensitive information when respond with corresponding result. This is SQL Injection Attacks. The main trend Firewall currently will not alarm when there is SQL attack because of the SQL Injection is via normal point and hidden and difficult to be detected, seemingly normal website visit.<br />
<br />
<span style="font-weight: bold;">The danger of SQL Injection Attacks</span><br />
<br />
According to the statistics of CVE in 2006, there are more than 70% attacks based on web application. The SQL Injection Attacks increase year by year, it arrives at 1078 in 2006. Even though, these data is only for the vulnerability in universal applications currently.<br />
&lt;!-- m --&gt;&lt;a class="postlink" href="http://www.ids-sax2.com/articles/images/CVESQLInjectVulnerabilities.gif"&gt;http://www.ids-sax2.com/articles/images ... lities.gif&lt;/a&gt;&lt;!-- m --&gt;<br />
<span style="font-weight: bold;">The danger of SQL Injection Attacks including:</span><br />
<br />
ï® Change the data in database without authorization.<br />
     Gain the administration authority of a site without authorization.<br />
ï® Maliciously change content of a site without authorization.<br />
ï® XSS attacks.<br />
ï® Gain the control authority of the server without authorization.<br />
ï® Add, delete and change the accounts in the server without authorization.<br />
 <br />
<span style="font-weight: bold;">The process of detect and revert SQL Injection Attacks</span><br />
<br />
Some IDS software will execute effective detection for SQL Injection Attacks, though, firewall can not. Now, we go to the process of detect and revert SQL Injection Attacks with IDS software Ax3soft Sax2.<br />
<br />
<span style="font-weight: bold;">The steps of SQL Injection Attacks are:</span><br />
<br />
a) Determine environment to find the injection point.<br />
b) Determine the type of database.<br />
c) Guess datasheet.<br />
d) Guess the field.<br />
e) Guess the content.<br />
<br />
The steps âGuess datasheetâ, âGuess the fieldâ and âGuess the contentâ are very important fro SQL Injection Attacks during the full process. Letâs analyze these there steps.<br />
<br />
Sax2 will detect and alarm the attacks in network real-time. It will show the in the table Event when there is SQL Injection Attacks, see the figure 1.<br />
&lt;!-- m --&gt;&lt;a class="postlink" href="http://www.ids-sax2.com/articles/images/DetectSQLInjectionAttacks(1"&gt;http://www.ids-sax2.com/articles/images ... nAttacks(1&lt;/a&gt;&lt;!-- m --&gt;).gif<br />
Figure 1 Sax2 alarm the MS_SQL Injection Attacks real-time<br />
<br />
The selected event in the Figure 1 shows the attackerâs IP 192.168.21.103, the victimâs IP 125.65.112.10. And the original message is âselect * from [dirs]â, means enquire whether there is a datasheet named âdirsâ in current database, in the Original Communication view.<br />
The attacker will repeat the operation to gain the expected datasheet. He will try to guess the filed in the datasheet if found the corresponding datasheet in the database.<br />
&lt;!-- m --&gt;&lt;a class="postlink" href="http://www.ids-sax2.com/articles/images/DetectSQLInjectionAttacks(2"&gt;http://www.ids-sax2.com/articles/images ... nAttacks(2&lt;/a&gt;&lt;!-- m --&gt;).gif<br />
Figure 2 Sax2 analysis the attacker is guessing the filed in the admin database<br />
<br />
The code in the red circle in the Figure 2 show the attacker is guessing the âpathsâ filed in the admin database. Also, the attacker will repeat the operation till find the corresponding filed.<br />
<br />
The attacker will determine the length of the filed and guess the content after found the corresponding filed. It will be a SQL Injection Attacks after the attacker guess the content in the filed successfully. Sometimes, the attacker has to decryption the content if it in MD5 encryption.<br />
<br />
Above is the whole process of SQL Injection Attacks and we detect it with Sax2. As we know, Sax2 can effectively detect and alarm the SQL Injection Attacks when it occurs. IDS software Sax2 is a useful tool for SQL Injection Attacks and make your network security combine with firewall software.]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Error: Suddenly Life Has A New Meaning...]]></title>
			<link>http://www.antisource.com/forums/showthread.php?tid=4258</link>
			<pubDate>Sat, 11 Jul 2009 23:23:34 +0000</pubDate>
			<guid isPermaLink="false">http://www.antisource.com/forums/showthread.php?tid=4258</guid>
			<description><![CDATA[Hi,<br />
<br />
I seem to have this problem as well, I've searched your forums for advice on this, and found some... but unsure about using some of the software or scripts that you've discussed on these forums.  <br />
<br />
Any help in regards to this would be most appreciated.  <br />
<br />
I've downloaded the necessary files and stuff, and have the files zipped up and ready to send.  <br />
<br />
Regards.]]></description>
			<content:encoded><![CDATA[Hi,<br />
<br />
I seem to have this problem as well, I've searched your forums for advice on this, and found some... but unsure about using some of the software or scripts that you've discussed on these forums.  <br />
<br />
Any help in regards to this would be most appreciated.  <br />
<br />
I've downloaded the necessary files and stuff, and have the files zipped up and ready to send.  <br />
<br />
Regards.]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[how to redirect]]></title>
			<link>http://www.antisource.com/forums/showthread.php?tid=4259</link>
			<pubDate>Wed, 24 Jun 2009 11:48:55 +0000</pubDate>
			<guid isPermaLink="false">http://www.antisource.com/forums/showthread.php?tid=4259</guid>
			<description><![CDATA[dear all,<br />
<br />
i've got server with one network interface (le0), one public IP address (A.B.C.D) and there is remote proxy (W.X.Y.Z) port 3128. How to redirecting www traffict to use remote proxy using pf ? I use this pf rule but still not work.<br />
<br />
rdr on le0 proto tcp from &#36;my_if to any port www -&gt; W.X.Y.Z port 3128<br />
<br />
<br />
thanks<br />
Reply With Quote]]></description>
			<content:encoded><![CDATA[dear all,<br />
<br />
i've got server with one network interface (le0), one public IP address (A.B.C.D) and there is remote proxy (W.X.Y.Z) port 3128. How to redirecting www traffict to use remote proxy using pf ? I use this pf rule but still not work.<br />
<br />
rdr on le0 proto tcp from &#36;my_if to any port www -&gt; W.X.Y.Z port 3128<br />
<br />
<br />
thanks<br />
Reply With Quote]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[I seem to be having problems with malware &#x26; spam]]></title>
			<link>http://www.antisource.com/forums/showthread.php?tid=4260</link>
			<pubDate>Thu, 04 Jun 2009 06:29:25 +0000</pubDate>
			<guid isPermaLink="false">http://www.antisource.com/forums/showthread.php?tid=4260</guid>
			<description><![CDATA[I am not sure what to call it. Windows with different types of ads open up sparodically on my computer. My son also told me something called Yoog kept prompting him to save something. He thinks he deleted it, but I am not sure. I also keep getting ads from trueads opening up when I first log on to the internet.<br />
<br />
Here is my log.<br />
<br />
<br />
Thanks for your Help.<br />
<br />
Rhonda<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 11:22:50 PM, on 6/3/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16827)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br />
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Symantec AntiVirus\DefWatch.exe<br />
C:\WINDOWS\system32\DWRCS.EXE<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\Program Files\Symantec AntiVirus\DWHWIZRD.EXE<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\DWRCST.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br />
C:\PROGRA~1\SYMANT~1\VPTray.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\WINDOWS\system32\igfxsrvc.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE<br />
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE<br />
C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://sympatico.msn.ca/"&gt;http://sympatico.msn.ca/&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;!-- m --&gt;<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;!-- m --&gt;<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: trueads search enhancer - {224B657E-C6FB-8649-7A70-40DB54998B75} - C:\WINDOWS\system32\escbvinayuwmgdj.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O2 - BHO: trueads - {f4c52357-874f-58fc-babd-ad61d06f4ae6} - C:\WINDOWS\system32\nsfD.dll<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br />
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br />
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br />
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br />
O4 - HKLM\..\Run: [DameWare MRC Agent] C:\WINDOWS\system32\DWRCST.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background<br />
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-21-2000478354-1958367476-1417001333-1006\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" (User 'Jordan')<br />
O4 - HKUS\S-1-5-21-2000478354-1958367476-1417001333-1006\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Jordan')<br />
O4 - HKUS\S-1-5-21-2000478354-1958367476-1417001333-1007\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" (User 'Whitney')<br />
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - &lt;!-- m --&gt;&lt;a class="postlink" href="res://C"&gt;res://C&lt;/a&gt;&lt;!-- m --&gt;:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1233830112531"&gt;http://update.microsoft.com/microsoftup ... 3830112531&lt;/a&gt;&lt;!-- m --&gt;<br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1233830105375"&gt;http://update.microsoft.com/microsoftup ... 3830105375&lt;/a&gt;&lt;!-- m --&gt;<br />
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab"&gt;http://messenger.zone.msn.com/binary/Me ... b56907.cab&lt;/a&gt;&lt;!-- m --&gt;<br />
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://driveragent.com/files/driveragent.cab"&gt;http://driveragent.com/files/driveragent.cab&lt;/a&gt;&lt;!-- m --&gt;<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br />
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe<br />
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINDOWS\system32\DWRCS.EXE<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br />
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe<br />
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br />
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br />
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br />
<br />
--<br />
End of file - 9208 bytes]]></description>
			<content:encoded><![CDATA[I am not sure what to call it. Windows with different types of ads open up sparodically on my computer. My son also told me something called Yoog kept prompting him to save something. He thinks he deleted it, but I am not sure. I also keep getting ads from trueads opening up when I first log on to the internet.<br />
<br />
Here is my log.<br />
<br />
<br />
Thanks for your Help.<br />
<br />
Rhonda<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 11:22:50 PM, on 6/3/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16827)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br />
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Symantec AntiVirus\DefWatch.exe<br />
C:\WINDOWS\system32\DWRCS.EXE<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br />
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\Program Files\Symantec AntiVirus\DWHWIZRD.EXE<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\DWRCST.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br />
C:\PROGRA~1\SYMANT~1\VPTray.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\WINDOWS\system32\igfxsrvc.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE<br />
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE<br />
C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://sympatico.msn.ca/"&gt;http://sympatico.msn.ca/&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;!-- m --&gt;<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;!-- m --&gt;<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: trueads search enhancer - {224B657E-C6FB-8649-7A70-40DB54998B75} - C:\WINDOWS\system32\escbvinayuwmgdj.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O2 - BHO: trueads - {f4c52357-874f-58fc-babd-ad61d06f4ae6} - C:\WINDOWS\system32\nsfD.dll<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br />
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br />
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"<br />
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br />
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br />
O4 - HKLM\..\Run: [DameWare MRC Agent] C:\WINDOWS\system32\DWRCST.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background<br />
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-21-2000478354-1958367476-1417001333-1006\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" (User 'Jordan')<br />
O4 - HKUS\S-1-5-21-2000478354-1958367476-1417001333-1006\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Jordan')<br />
O4 - HKUS\S-1-5-21-2000478354-1958367476-1417001333-1007\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" (User 'Whitney')<br />
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - &lt;!-- m --&gt;&lt;a class="postlink" href="res://C"&gt;res://C&lt;/a&gt;&lt;!-- m --&gt;:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1233830112531"&gt;http://update.microsoft.com/microsoftup ... 3830112531&lt;/a&gt;&lt;!-- m --&gt;<br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1233830105375"&gt;http://update.microsoft.com/microsoftup ... 3830105375&lt;/a&gt;&lt;!-- m --&gt;<br />
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab"&gt;http://messenger.zone.msn.com/binary/Me ... b56907.cab&lt;/a&gt;&lt;!-- m --&gt;<br />
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://driveragent.com/files/driveragent.cab"&gt;http://driveragent.com/files/driveragent.cab&lt;/a&gt;&lt;!-- m --&gt;<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br />
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe<br />
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINDOWS\system32\DWRCS.EXE<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br />
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe<br />
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br />
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br />
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br />
<br />
--<br />
End of file - 9208 bytes]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Firefox Button]]></title>
			<link>http://www.antisource.com/forums/showthread.php?tid=4261</link>
			<pubDate>Thu, 28 May 2009 17:41:33 +0000</pubDate>
			<guid isPermaLink="false">http://www.antisource.com/forums/showthread.php?tid=4261</guid>
			<description><![CDATA[Hallo,<br />
<br />
I often use the saved passwords of my Firefox browser to see and sometimes erase the passwords...only everytime I must go to Tools - Options - Safety - saved password.<br />
I was arguing if there is a way to insert a link in the toolbar to simplify and speed up this task.<br />
<br />
Thank you and hallo to everyone.]]></description>
			<content:encoded><![CDATA[Hallo,<br />
<br />
I often use the saved passwords of my Firefox browser to see and sometimes erase the passwords...only everytime I must go to Tools - Options - Safety - saved password.<br />
I was arguing if there is a way to insert a link in the toolbar to simplify and speed up this task.<br />
<br />
Thank you and hallo to everyone.]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[voip]]></title>
			<link>http://www.antisource.com/forums/showthread.php?tid=4262</link>
			<pubDate>Sat, 16 May 2009 10:06:57 +0000</pubDate>
			<guid isPermaLink="false">http://www.antisource.com/forums/showthread.php?tid=4262</guid>
			<description><![CDATA[Is VoIP a service from ISP's or can I just buy VoIP router and make a virtual number from the router using dsl? I live in austrailia and i want me and my family to call each other whenever for free using voip. how can i do this? i don't want to use skype or any other ip telephony program just voip. I was told if i buy the same brand routers here and in lebanon and make virtual numbers then it would work is that true?]]></description>
			<content:encoded><![CDATA[Is VoIP a service from ISP's or can I just buy VoIP router and make a virtual number from the router using dsl? I live in austrailia and i want me and my family to call each other whenever for free using voip. how can i do this? i don't want to use skype or any other ip telephony program just voip. I was told if i buy the same brand routers here and in lebanon and make virtual numbers then it would work is that true?]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[System running very slow...]]></title>
			<link>http://www.antisource.com/forums/showthread.php?tid=4263</link>
			<pubDate>Tue, 24 Mar 2009 12:04:03 +0000</pubDate>
			<guid isPermaLink="false">http://www.antisource.com/forums/showthread.php?tid=4263</guid>
			<description><![CDATA[Ive included the hijackthis log below but I dont think it shows the problem.    In order to<br />
be able to show some evidence of a problem I did run a kaspersky scan as well and it apparently<br />
shows a worm in an email related file.<br />
<br />
 Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 7:55:50 AM, on 3/24/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16791)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br />
C:\WINDOWS\system32\LEXBCES.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br />
C:\WINDOWS\system32\inetsrv\inetinfo.exe<br />
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe<br />
C:\WINDOWS\system32\LEXPPS.EXE<br />
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Apoint\Apoint.exe<br />
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br />
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe<br />
C:\WINDOWS\system32\dla\tfswctrl.exe<br />
C:\Program Files\Apoint\Apntex.exe<br />
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe<br />
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe<br />
C:\Program Files\Messenger\msmsgs.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe<br />
C:\WINDOWS\system32\mmc.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Documents and Settings\greg\Local Settings\Temp\jkos-greg\binaries\ScanningProcess.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll<br />
O3 - Toolbar: &amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll<br />
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe<br />
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br />
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"<br />
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe<br />
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"<br />
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless<br />
O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup<br />
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll<br />
O15 - Trusted Zone: *.amazon.com<br />
O15 - Trusted Zone: *.amperite.com<br />
O15 - Trusted Zone: *.antisource.com<br />
O15 - Trusted Zone: *.asp.net<br />
O15 - Trusted Zone: *.biblechurch.org<br />
O15 - Trusted Zone: *.bitdefender.com<br />
O15 - Trusted Zone: *.bookpool.com<br />
O15 - Trusted Zone: *.cnbc.com<br />
O15 - Trusted Zone: *.consumerreports.org<br />
O15 - Trusted Zone: *.craigslist.com<br />
O15 - Trusted Zone: *.drudgereport.com<br />
O15 - Trusted Zone: *.durham.nc.us<br />
O15 - Trusted Zone: *.durhamnc.gov<br />
O15 - Trusted Zone: *.e-statement.com<br />
O15 - Trusted Zone: *.ebay.com<br />
O15 - Trusted Zone: *.fidelity.com<br />
O15 - Trusted Zone: *.globalspec.com<br />
O15 - Trusted Zone: *.investorvillage.com<br />
O15 - Trusted Zone: *.java.com<br />
O15 - Trusted Zone: *.kaspersky.com<br />
O15 - Trusted Zone: *.nasa.gov<br />
O15 - Trusted Zone: *.ncmail.net<br />
O15 - Trusted Zone: *.oilintel.com<br />
O15 - Trusted Zone: *.paypal.com<br />
O15 - Trusted Zone: *.ripoffreport.com<br />
O15 - Trusted Zone: *.rr.com<br />
O15 - Trusted Zone: *.scottrade.com<br />
O15 - Trusted Zone: *.stockcharts.com<br />
O15 - Trusted Zone: *.sun.com<br />
O15 - Trusted Zone: *.thermastor.com<br />
O15 - Trusted Zone: *.tradethenews.com<br />
O15 - Trusted Zone: *.ustaxdata.com<br />
O15 - Trusted Zone: *.wral.com<br />
O15 - Trusted Zone: *.wraltv.com<br />
O23 - Service: Intel&reg; PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br />
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE<br />
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe<br />
O23 - Service: Intel&reg; PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br />
O23 - Service: Intel&reg; PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br />
O23 - Service: Intel&reg; PROSet/Wireless SSO Service (WLANKEEPER) - Intel&reg; Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe<br />
<br />
--<br />
End of file - 5365 bytes<br />
<br />
<br />
================================================================================&#8203;=======<br />
<br />
KASPERSKY ONLINE SCANNER 7 REPORT  <br />
Tuesday, March 24, 2009<br />
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)<br />
Kaspersky Online Scanner 7 version: 7.0.25.0<br />
Program database last update: Monday, March 23, 2009 23:13:13<br />
Records in database: 1958593<br />
 <br />
 <br />
Scan settings <br />
Scan using the following database extended <br />
Scan archives yes <br />
Scan mail databases yes <br />
 <br />
Scan area My Computer <br />
C:\<br />
D:\  <br />
 <br />
Scan statistics <br />
Files scanned 149144 <br />
Threat name 9 <br />
Infected objects 11 <br />
Suspicious objects 0 <br />
Duration of the scan 04:11:24 <br />
<br />
File name Threat name Threats count <br />
C:\Documents and Settings\greg\Local Settings\Application Data\Microsoft\Outlook\outlook.pst Infected: Worm.Win32.AutoRun.lpp 1  <br />
 <br />
C:\SDFix\backups_old1\backups.zip Infected: Trojan-Downloader.Win32.PurityScan.gb 2  <br />
 <br />
C:\SDFix\backups_old1\backups.zip Infected: not-a-virus:AdWare.Win32.CommAd.a 2  <br />
 <br />
C:\SDFix\backups_old1\backups.zip Infected: not-virus:Hoax.Win32.Renos.daw 1  <br />
 <br />
C:\SDFix\backups_old1\backups.zip Infected: Trojan-Downloader.Win32.Homles.cx 1  <br />
 <br />
C:\SDFix\backups_old1\backups.zip Infected: not-a-virus:Monitor.Win32.NetMon.a 1  <br />
 <br />
C:\SDFix\backups_old1\backups.zip Infected: not-a-virus:AdWare.Win32.PurityScan.gp 1  <br />
 <br />
C:\SDFix\backups_old2\backups.zip Infected: not-a-virus:FraudTool.Win32.XPSecurityCenter.d 1  <br />
 <br />
C:\SDFix\backups_old2\backups.zip Infected: Trojan.Win32.Crypt.cz 1  <br />
 <br />
The selected area was scanned.]]></description>
			<content:encoded><![CDATA[Ive included the hijackthis log below but I dont think it shows the problem.    In order to<br />
be able to show some evidence of a problem I did run a kaspersky scan as well and it apparently<br />
shows a worm in an email related file.<br />
<br />
 Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 7:55:50 AM, on 3/24/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16791)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br />
C:\WINDOWS\system32\LEXBCES.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br />
C:\WINDOWS\system32\inetsrv\inetinfo.exe<br />
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe<br />
C:\WINDOWS\system32\LEXPPS.EXE<br />
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Apoint\Apoint.exe<br />
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br />
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe<br />
C:\WINDOWS\system32\dla\tfswctrl.exe<br />
C:\Program Files\Apoint\Apntex.exe<br />
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe<br />
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe<br />
C:\Program Files\Messenger\msmsgs.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe<br />
C:\WINDOWS\system32\mmc.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Documents and Settings\greg\Local Settings\Temp\jkos-greg\binaries\ScanningProcess.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll<br />
O3 - Toolbar: &amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll<br />
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe<br />
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br />
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"<br />
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe<br />
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"<br />
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless<br />
O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup<br />
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll<br />
O15 - Trusted Zone: *.amazon.com<br />
O15 - Trusted Zone: *.amperite.com<br />
O15 - Trusted Zone: *.antisource.com<br />
O15 - Trusted Zone: *.asp.net<br />
O15 - Trusted Zone: *.biblechurch.org<br />
O15 - Trusted Zone: *.bitdefender.com<br />
O15 - Trusted Zone: *.bookpool.com<br />
O15 - Trusted Zone: *.cnbc.com<br />
O15 - Trusted Zone: *.consumerreports.org<br />
O15 - Trusted Zone: *.craigslist.com<br />
O15 - Trusted Zone: *.drudgereport.com<br />
O15 - Trusted Zone: *.durham.nc.us<br />
O15 - Trusted Zone: *.durhamnc.gov<br />
O15 - Trusted Zone: *.e-statement.com<br />
O15 - Trusted Zone: *.ebay.com<br />
O15 - Trusted Zone: *.fidelity.com<br />
O15 - Trusted Zone: *.globalspec.com<br />
O15 - Trusted Zone: *.investorvillage.com<br />
O15 - Trusted Zone: *.java.com<br />
O15 - Trusted Zone: *.kaspersky.com<br />
O15 - Trusted Zone: *.nasa.gov<br />
O15 - Trusted Zone: *.ncmail.net<br />
O15 - Trusted Zone: *.oilintel.com<br />
O15 - Trusted Zone: *.paypal.com<br />
O15 - Trusted Zone: *.ripoffreport.com<br />
O15 - Trusted Zone: *.rr.com<br />
O15 - Trusted Zone: *.scottrade.com<br />
O15 - Trusted Zone: *.stockcharts.com<br />
O15 - Trusted Zone: *.sun.com<br />
O15 - Trusted Zone: *.thermastor.com<br />
O15 - Trusted Zone: *.tradethenews.com<br />
O15 - Trusted Zone: *.ustaxdata.com<br />
O15 - Trusted Zone: *.wral.com<br />
O15 - Trusted Zone: *.wraltv.com<br />
O23 - Service: Intel&reg; PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br />
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE<br />
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe<br />
O23 - Service: Intel&reg; PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br />
O23 - Service: Intel&reg; PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br />
O23 - Service: Intel&reg; PROSet/Wireless SSO Service (WLANKEEPER) - Intel&reg; Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe<br />
<br />
--<br />
End of file - 5365 bytes<br />
<br />
<br />
================================================================================&#8203;=======<br />
<br />
KASPERSKY ONLINE SCANNER 7 REPORT  <br />
Tuesday, March 24, 2009<br />
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)<br />
Kaspersky Online Scanner 7 version: 7.0.25.0<br />
Program database last update: Monday, March 23, 2009 23:13:13<br />
Records in database: 1958593<br />
 <br />
 <br />
Scan settings <br />
Scan using the following database extended <br />
Scan archives yes <br />
Scan mail databases yes <br />
 <br />
Scan area My Computer <br />
C:\<br />
D:\  <br />
 <br />
Scan statistics <br />
Files scanned 149144 <br />
Threat name 9 <br />
Infected objects 11 <br />
Suspicious objects 0 <br />
Duration of the scan 04:11:24 <br />
<br />
File name Threat name Threats count <br />
C:\Documents and Settings\greg\Local Settings\Application Data\Microsoft\Outlook\outlook.pst Infected: Worm.Win32.AutoRun.lpp 1  <br />
 <br />
C:\SDFix\backups_old1\backups.zip Infected: Trojan-Downloader.Win32.PurityScan.gb 2  <br />
 <br />
C:\SDFix\backups_old1\backups.zip Infected: not-a-virus:AdWare.Win32.CommAd.a 2  <br />
 <br />
C:\SDFix\backups_old1\backups.zip Infected: not-virus:Hoax.Win32.Renos.daw 1  <br />
 <br />
C:\SDFix\backups_old1\backups.zip Infected: Trojan-Downloader.Win32.Homles.cx 1  <br />
 <br />
C:\SDFix\backups_old1\backups.zip Infected: not-a-virus:Monitor.Win32.NetMon.a 1  <br />
 <br />
C:\SDFix\backups_old1\backups.zip Infected: not-a-virus:AdWare.Win32.PurityScan.gp 1  <br />
 <br />
C:\SDFix\backups_old2\backups.zip Infected: not-a-virus:FraudTool.Win32.XPSecurityCenter.d 1  <br />
 <br />
C:\SDFix\backups_old2\backups.zip Infected: Trojan.Win32.Crypt.cz 1  <br />
 <br />
The selected area was scanned.]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[weird win.ini]]></title>
			<link>http://www.antisource.com/forums/showthread.php?tid=4264</link>
			<pubDate>Fri, 06 Mar 2009 02:15:26 +0000</pubDate>
			<guid isPermaLink="false">http://www.antisource.com/forums/showthread.php?tid=4264</guid>
			<description><![CDATA[What version of Windows are you running?]]></description>
			<content:encoded><![CDATA[What version of Windows are you running?]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Virus controlling Web and Admin functions]]></title>
			<link>http://www.antisource.com/forums/showthread.php?tid=4265</link>
			<pubDate>Mon, 02 Mar 2009 05:44:34 +0000</pubDate>
			<guid isPermaLink="false">http://www.antisource.com/forums/showthread.php?tid=4265</guid>
			<description><![CDATA[Hi Thomas or Antisource Team member .  Its JTADH (Jay) again, been a while. The computer has been running well up to a few days ago.  Some Mal ware took control of my Internet access forcing me to a security product called "something or other PRO".  It auto opens some tabs in Mozilla Firefox and wont let us access other sites.  It also disabled Task Manager and Regedit.  Looks like it disallows at least the  graphic part of Spybot S&amp;D also.  It seems to have gotten worse with each login.  At this point, Our normal logins lock up the computer once the desktop appears.  The only access I have is via Safe Mode, and that, only on the default Administrator ID.  I was able to get on in Safe Mode and run some of the tools you asked me to use before.  I am submitting this from a friends computer via a diskette with the listings. I ran Smitfraudfix, and Silent runners.  Here are the Listings...Thanks in advance for your help.<br />
<br />
SmitFraudFix v2.144<br />
<br />
Scan done at 23:37:50.18, Thu 02/26/2009<br />
Run from C:\Documents and Settings\Jay\Desktop\SmitfraudFix\SmitfraudFix<br />
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT<br />
The filesystem type is <br />
Fix run in safe mode<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» hosts<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» C:\<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» C:\WINDOWS<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» C:\WINDOWS\system<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» C:\WINDOWS\Web<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» C:\WINDOWS\system32<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» C:\Documents and Settings\Jay<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» C:\Documents and Settings\Jay\Application Data<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» Start Menu<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» C:\DOCUME~1\Jay\FAVORI~1<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» Desktop<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» C:\Program Files <br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» Corrupted keys<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» Desktop Components<br />
 <br />
 <br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» Sharedtaskscheduler<br />
!!!Attention, following keys are not inevitably infected!!!<br />
<br />
SrchSTS.exe by S!Ri<br />
Search SharedTaskScheduler's .dll<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTask&#8203;Scheduler]<br />
"{C5BF49A2-94F3-42BD-F434-3604812C8955}"="jgzfkj9w38rksndfi7r4"<br />
<br />
[HKEY_CLASSES_ROOT\CLSID\{C5BF49A2-94F3-42BD-F434-3604812C8955}\InProcServer32]<br />
@="C:\WINDOWS\system32\hhs3ijndfd.dll"<br />
<br />
[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{C5BF49A2-94F3-42BD-F434-3604812C8955}\InProcServer32]<br />
@="C:\WINDOWS\system32\hhs3ijndfd.dll"<br />
<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» AppInit_DLLs<br />
!!!Attention, following keys are not inevitably infected!!!<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]<br />
"AppInit_DLLs"="C:\\WINDOWS\\System32\\reshhf.dll"<br />
"LoadAppInit_DLLs"=dword:00000001<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» Winlogon.System<br />
!!!Attention, following keys are not inevitably infected!!!<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]<br />
"System"=""<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» pe386-msguard-lzx32-huy32<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» Scanning wininet.dll infection<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» End<br />
<br />
<br />
"Silent Runners.vbs", revision R50, &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.silentrunners.org/"&gt;http://www.silentrunners.org/&lt;/a&gt;&lt;!-- m --&gt;<br />
Operating System: Windows XP SP2<br />
Output limited to non-default values, except where indicated by "{++}"<br />
<br />
<br />
Startup items buried in registry:<br />
---------------------------------<br />
<br />
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}<br />
"DW6" = ""C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"" [file not found]<br />
"x4uhkp2rvxr06m" = "C:\DOCUME~1\Jay\LOCALS~1\Temp\vlhahkrbl3xm.exe" [file not found]<br />
"dxyc4p3b2t6egdegh6qlwg6vj6ha4rnf1d33gqoho5" = "C:\DOCUME~1\Jay\LOCALS~1\Temp\uqnhhxdj2.exe" [file not found]<br />
"ecyf83ieh1mgx8lak5g" = "C:\DOCUME~1\Jay\LOCALS~1\Temp\qbeywtg4.exe" [file not found]<br />
"fglzf86v3s9gqw48bkqc6ak49s9fb53wklx00jtieuddr8wg7a" = "C:\DOCUME~1\Jay\LOCALS~1\Temp\xm9ic7lv04y.exe" [file not found]<br />
<br />
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}<br />
"S4F" = "C:\Program Files\S4F\Filter7.exe" ["S4F, Inc."]<br />
"TkBellExe" = ""C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot" ["RealNetworks, Inc."]<br />
"Adobe Photo Downloader" = ""C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"" ["Adobe Systems Incorporated"]<br />
"Gamevance" = "C:\Program Files\Gamevance\gamevance32.exe" [null data]<br />
"QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Inc."]<br />
"AppleSyncNotifier" = "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" ["Apple Inc."]<br />
"iTunesHelper" = ""C:\Program Files\iTunes\iTunesHelper.exe"" ["Apple Inc."]<br />
"Ibayig" = "rundll32.exe "C:\WINDOWS\Yyayoga.dll",e" [MS]<br />
"jsf8uiw3jnjgffght" = "C:\DOCUME~1\Monique\LOCALS~1\Temp\winlognn.exe" [null data]<br />
"Framework Windows" = "frmwrk32.exe" [null data]<br />
"Xwejavaqegay" = "rundll32.exe "C:\WINDOWS\efuyuhasajubijam.dll",e" [MS]<br />
"88d2667a" = "rundll32.exe "C:\WINDOWS\system32\dasakebe.dll",b" [MS]<br />
"kumeforozi" = "Rundll32.exe "C:\WINDOWS\system32\wivovego.dll",s" [MS]<br />
<br />
HKLM\Software\Microsoft\Active Setup\Installed Components\<br />
&gt;{26923b43-4d38-484f-9b9e-de460746276c}\(Default) = "Internet Explorer"<br />
                                        \StubPath   = "C:\WINDOWS\system32\shmgrate.exe OCInstallUserConfigIE" [MS]<br />
&gt;{881dd1c5-3dcf-431b-b061-f3f88e8be88a}\(Default) = "Outlook Express"<br />
                                        \StubPath   = "C:\WINDOWS\system32\shmgrate.exe OCInstallUserConfigOE" [MS]<br />
<br />
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\<br />
{C5BF49A2-94F3-42BD-F434-3604812C8955}\(Default) = (no title provided)<br />
  -&gt; {HKLM...CLSID} = "C:\WINDOWS\system32\hhs3ijndfd.dll"<br />
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\hhs3ijndfd.dll" [null data]<br />
{e2b687e8-85c1-4fc1-a30e-24e1c12a6d86}\(Default) = (no title provided)<br />
  -&gt; {HKLM...CLSID} = (no title provided)<br />
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\gijoyeri.dll" [empty string]<br />
<br />
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\<br />
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"<br />
  -&gt; {HKLM...CLSID} = "Display Panning CPL Extension"<br />
                   \InProcServer32\(Default) = "deskpan.dll" [file not found]<br />
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"<br />
  -&gt; {HKLM...CLSID} = "HyperTerminal Icon Ext"<br />
                   \InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]<br />
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"<br />
  -&gt; {HKLM...CLSID} = (no title provided)<br />
                   \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\msohev.dll" [MS]<br />
"{A4DF5659-0801-4A60-9607-1C48695EFDA9}" = "Share-to-Web Upload Folder"<br />
  -&gt; {HKLM...CLSID} = "Share-to-Web Upload Folder"<br />
                   \InProcServer32\(Default) = "C:\Program Files\Hewlett-Packard\HP Share-to-Web\HPGS2WNS.DLL" ["Hewlett-Packard"]<br />
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"<br />
  -&gt; {HKLM...CLSID} = "Outlook File Icon Extension"<br />
                   \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\OLKFSTUB.DLL" [MS]<br />
"{5464D816-CF16-4784-B9F3-75C0DB52B499}" = "Yahoo! Mail"<br />
  -&gt; {HKLM...CLSID} = "YMailShellExt Class"<br />
                   \InProcServer32\(Default) = "C:\WINDOWS\Downloaded Program Files\ymmapi.dll" ["Yahoo! Inc."]<br />
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"<br />
  -&gt; {HKLM...CLSID} = "RealOne Player Context Menu Class"<br />
                   \InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."]<br />
"{5E44E225-A408-11CF-B581-008029601108}" = "Roxio DragToDisc Shell Extension"<br />
  -&gt; {HKLM...CLSID} = "Roxio DragToDisc Shell Extension"<br />
                   \InProcServer32\(Default) = "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\shellex.dll" ["Roxio"]<br />
"{A44D5ACC-3411-40DE-9AD3-214FFB2ED7AC}" = "My Media"<br />
  -&gt; {HKLM...CLSID} = "My Media"<br />
                   \InProcServer32\(Default) = "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\MediaSX.dll" ["Roxio, Inc."]<br />
"{7D5C4BDD-B015-4401-8731-1507B87DE297}" = "QBVersionTool"<br />
  -&gt; {HKLM...CLSID} = "VersionShellExt Class"<br />
                   \InProcServer32\(Default) = "C:\Program Files\Common Files\Intuit\QuickBooks\QBVersionTool.dll" ["Intuit, Inc."]<br />
"{C55C499D-3518-44a1-998E-796AC5FC989D}" = "NetworkMagic"<br />
  -&gt; {HKLM...CLSID} = "Network Magic Folders"<br />
                   \InProcServer32\(Default) = "C:\Program Files\Pure Networks\Network Magic\nmspce.dll" ["Pure Networks, Inc."]<br />
"{33F85093-44BB-4587-B25B-FFD05D5B9916}" = "NetworkMagic"<br />
  -&gt; {HKLM...CLSID} = "Network Magic Folders"<br />
                   \InProcServer32\(Default) = "C:\Program Files\Pure Networks\Network Magic\nmspce.dll" ["Pure Networks, Inc."]<br />
"{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}" = "iTunes"<br />
  -&gt; {HKLM...CLSID} = "iTunes"<br />
                   \InProcServer32\(Default) = "C:\Program Files\iTunes\iTunesMiniPlayer.dll" ["Apple Inc."]<br />
<br />
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\<br />
&lt;&lt;!&gt;&gt; "{C5BF49A2-94F3-42BD-F434-3604812C8955}" = "jgzfkj9w38rksndfi7r4"<br />
  -&gt; {HKLM...CLSID} = "C:\WINDOWS\system32\hhs3ijndfd.dll"<br />
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\hhs3ijndfd.dll" [null data]<br />
<br />
HKLM\System\CurrentControlSet\Control\Session Manager\<br />
&lt;&lt;!&gt;&gt; "BootExecute" = "autocheck autochk *"|"SsiEfr.e" [file not found]<br />
<br />
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\<br />
&lt;&lt;!&gt;&gt; crypt\DLLName = "crypts.dll" [null data]<br />
<br />
HKLM\Software\Classes\Folder\shellex\ColumnHandlers\<br />
{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"<br />
  -&gt; {HKLM...CLSID} = "PDF Shell Extension"<br />
                   \InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]<br />
<br />
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\<br />
Yahoo! Mail\(Default) = "{5464D816-CF16-4784-B9F3-75C0DB52B499}"<br />
  -&gt; {HKLM...CLSID} = "YMailShellExt Class"<br />
                   \InProcServer32\(Default) = "C:\WINDOWS\Downloaded Program Files\ymmapi.dll" ["Yahoo! Inc."]<br />
<br />
<br />
Group Policies {policy setting}:<br />
--------------------------------<br />
<br />
Note: detected settings may not have any effect.<br />
<br />
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\<br />
<br />
"_NoDriveTypeAutoRun" = (REG_DWORD) hex:0x00000091<br />
{unrecognized setting}<br />
<br />
"NoSetActiveDesktop" = (REG_DWORD) hex:0x00000001<br />
{unrecognized setting}<br />
<br />
"NoFolderOptions" = (REG_DWORD) hex:0x00000001<br />
{Removes the Folder Options menu item from the Tools menu}<br />
<br />
"NoActiveDesktopChanges" = (REG_DWORD) hex:0x00000001<br />
{Prohibit changes}<br />
<br />
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\<br />
<br />
"NoCDBurning" = (REG_DWORD) hex:0x00000000<br />
{unrecognized setting}<br />
<br />
"NoSetActiveDesktop" = (REG_DWORD) hex:0x00000001<br />
{unrecognized setting}<br />
<br />
"NoActiveDesktopChanges" = (REG_DWORD) hex:0x00000001<br />
{unrecognized setting}<br />
<br />
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\<br />
<br />
"DisableRegistryTools" = (REG_DWORD) hex:0x00000001<br />
{Prevent access to registry editing tools}<br />
<br />
"DisableTaskMgr" = (REG_DWORD) hex:0x00000001<br />
{Remove Task Manager}<br />
<br />
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\<br />
<br />
"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001<br />
{Shutdown: Allow system to be shut down without having to log on}<br />
<br />
"undockwithoutlogon" = (REG_DWORD) hex:0x00000001<br />
{Devices: Allow undock without having to log on}<br />
<br />
HKLM\Software\Policies\Microsoft\Windows NT\SystemRestore\<br />
<br />
"Disable Config" = (REG_DWORD) hex:0x00000001<br />
{unrecognized setting}<br />
<br />
<br />
Active Desktop and Wallpaper:<br />
-----------------------------<br />
<br />
Active Desktop may be enabled at this entry:<br />
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState<br />
<br />
<br />
Enabled Scheduled Tasks:<br />
------------------------<br />
<br />
"AppleSoftwareUpdate" -&gt; launches: "C:\Program Files\Apple Software Update\SoftwareUpdate.exe -task" ["Apple Inc."]<br />
"Spybot - Search &amp; Destroy -  Scheduled Task" -&gt; launches: "C:\Program Files\Spybot - Search &amp; Destroy\SpybotSD.exe /AUTOCHECK" ["Safer Networking Limited"]<br />
"uldclhlt" -&gt; launches: "C:\WINDOWS\system32\rundll32.exe "C:\WINDOWS\system32\urqPiiFV.dll",AddRefActCtx" [MS]<br />
<br />
<br />
Winsock2 Service Provider DLLs:<br />
-------------------------------<br />
<br />
Namespace Service Providers<br />
<br />
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Ca&#8203;talog_Entries\ {++}<br />
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]<br />
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]<br />
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]<br />
000000000004\LibraryPath = "C:\Program Files\Bonjour\mdnsNSP.dll" ["Apple Inc."]<br />
<br />
Transport Service Providers<br />
<br />
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Cat&#8203;alog_Entries\ {++}<br />
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:<br />
C:\DOCUME~1\Monique\LOCALS~1\Temp\ntdll64.dll [null data], 01, 33<br />
C:\WINDOWS\system\wins4f.dll [null data], 02 - 16, 32<br />
%SystemRoot%\system32\mswsock.dll [MS], 17 - 19, 22 - 31<br />
%SystemRoot%\system32\rsvpsp.dll [MS], 20 - 21<br />
<br />
<br />
Toolbars, Explorer Bars, Extensions:<br />
------------------------------------<br />
<br />
Toolbars<br />
<br />
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\<br />
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"<br />
  -&gt; {HKLM...CLSID} = "Yahoo! Toolbar"<br />
                   \InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll" ["Yahoo! Inc."]<br />
<br />
HKLM\Software\Microsoft\Internet Explorer\Toolbar\<br />
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = (no title provided)<br />
  -&gt; {HKLM...CLSID} = "Yahoo! Toolbar"<br />
                   \InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll" ["Yahoo! Inc."]<br />
<br />
Explorer Bars<br />
<br />
HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\<br />
<br />
HKLM\Software\Classes\CLSID\{D6A116E7-5906-42E4-87F6-E7E15936415E}\(Default) = "MoneySide"<br />
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]<br />
InProcServer32\(Default) = "C:\Program Files\Microsoft Money\System\mnyside.dll" [MS]<br />
<br />
Extensions (Tools menu items, main toolbar menu buttons)<br />
<br />
HKLM\Software\Microsoft\Internet Explorer\Extensions\<br />
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\<br />
"MenuText" = "Sun Java Console"<br />
"CLSIDExtension" = "{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC}"<br />
  -&gt; {HKLM...CLSID} = "Java Plug-in 1.5.0"<br />
                   \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll" ["Sun Microsystems, Inc."]<br />
<br />
{85D1F590-48F4-11D9-9669-0800200C9A66}\<br />
"MenuText" = "Uninstall BitDefender Online Scanner v8"<br />
"Exec" = "%windir%\bdoscandel.exe" [null data]<br />
<br />
{CD67F990-D8E9-11D2-98FE-00C0F0318AFE}\<br />
<br />
{E023F504-0C5A-4750-A1E7-A9046DEA8A21}\<br />
"ButtonText" = "MoneySide"<br />
"CLSIDExtension" = "{DD6687B5-CB43-4211-BFC9-2942CCBDCB3E}"<br />
  -&gt; {HKLM...CLSID} = (no title provided)<br />
                   \InProcServer32\(Default) = "C:\Program Files\Microsoft Money\System\mnyside.dll" [MS]<br />
<br />
{FB5F1910-F110-11D2-BB9E-00C04F795683}\<br />
"ButtonText" = "Messenger"<br />
"MenuText" = "Windows Messenger"<br />
"Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]<br />
<br />
<br />
All Non-Disabled Services (Display Name, Service Name, Path {Service DLL}):<br />
---------------------------------------------------------------------------<br />
<br />
.NET Runtime Optimization Service v2.0.50727_X86, clr_optimization_v2.0.50727_32, "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe" [MS]<br />
Apple Mobile Device, Apple Mobile Device, ""C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe"" ["Apple Inc."]<br />
ASP.NET State Service, aspnet_state, "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe" [MS]<br />
Bonjour Service, Bonjour Service, ""C:\Program Files\Bonjour\mDNSResponder.exe"" ["Apple Inc."]<br />
Google Updater Service, gusvc, ""C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"" ["Google"]<br />
iPod Service, iPod Service, ""C:\Program Files\iPod\bin\iPodService.exe"" ["Apple Inc."]<br />
Logical Disk Manager Administrative Service, dmadmin, "C:\WINDOWS\System32\dmadmin.exe /com" ["Microsoft Corp., Veritas Software"]<br />
MSSQLSERVER, MSSQLSERVER, "C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe -sMSSQLSERVER" [MS]<br />
Network Provisioning Service, xmlprov, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\xmlprov.dll" [MS]}<br />
Portable Media Serial Number Service, WmdmPmSN, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\system32\MsPMSNSv.dll" [MS]}<br />
Pure Networks Net2Go Service, nmraapache, ""C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe" -k runservice" ["Pure Networks, Inc."]<br />
SQL Server (XACTWARE), MSSQL&#36;XACTWARE, ""C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sXACTWARE" [MS]<br />
SQL Server Active Directory Helper, MSSQLServerADHelper, ""C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe"" [MS]<br />
SQL Server VSS Writer, SQLWriter, ""C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"" [MS]<br />
SQLSERVERAGENT, SQLSERVERAGENT, "C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlagent.EXE -i MSSQLSERVER" [MS]<br />
Windows CardSpace, idsvc, ""C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe"" [MS]<br />
Windows Presentation Foundation Font Cache 3.0.0.0, FontCache3.0.0.0, "c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe" [MS]<br />
Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\system32\wdfmgr.exe" [MS]<br />
WMDM PMSP Service, WMDM PMSP Service, "C:\WINDOWS\System32\MsPMSPSv.exe" [MS]<br />
WMI Performance Adapter, WmiApSrv, "C:\WINDOWS\System32\wbem\wmiapsrv.exe" [MS]<br />
<br />
<br />
----------<br />
&lt;&lt;!&gt;&gt;: Suspicious data at a malware launch point.<br />
<br />
+ This report excludes default entries except where indicated.<br />
+ To see *everywhere* the script checks and *everything* it finds,<br />
  launch it from a command prompt or a shortcut with the -all parameter.<br />
+ To search all directories of local fixed drives for DESKTOP.INI<br />
  DLL launch points, use the -supp parameter or answer "No" at the<br />
  first message box and "Yes" at the second message box.<br />
---------- (total run time: 255 seconds, including 19 seconds for message boxes)]]></description>
			<content:encoded><![CDATA[Hi Thomas or Antisource Team member .  Its JTADH (Jay) again, been a while. The computer has been running well up to a few days ago.  Some Mal ware took control of my Internet access forcing me to a security product called "something or other PRO".  It auto opens some tabs in Mozilla Firefox and wont let us access other sites.  It also disabled Task Manager and Regedit.  Looks like it disallows at least the  graphic part of Spybot S&amp;D also.  It seems to have gotten worse with each login.  At this point, Our normal logins lock up the computer once the desktop appears.  The only access I have is via Safe Mode, and that, only on the default Administrator ID.  I was able to get on in Safe Mode and run some of the tools you asked me to use before.  I am submitting this from a friends computer via a diskette with the listings. I ran Smitfraudfix, and Silent runners.  Here are the Listings...Thanks in advance for your help.<br />
<br />
SmitFraudFix v2.144<br />
<br />
Scan done at 23:37:50.18, Thu 02/26/2009<br />
Run from C:\Documents and Settings\Jay\Desktop\SmitfraudFix\SmitfraudFix<br />
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT<br />
The filesystem type is <br />
Fix run in safe mode<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» hosts<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» C:\<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» C:\WINDOWS<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» C:\WINDOWS\system<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» C:\WINDOWS\Web<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» C:\WINDOWS\system32<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» C:\Documents and Settings\Jay<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» C:\Documents and Settings\Jay\Application Data<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» Start Menu<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» C:\DOCUME~1\Jay\FAVORI~1<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» Desktop<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» C:\Program Files <br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» Corrupted keys<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» Desktop Components<br />
 <br />
 <br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» Sharedtaskscheduler<br />
!!!Attention, following keys are not inevitably infected!!!<br />
<br />
SrchSTS.exe by S!Ri<br />
Search SharedTaskScheduler's .dll<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTask&#8203;Scheduler]<br />
"{C5BF49A2-94F3-42BD-F434-3604812C8955}"="jgzfkj9w38rksndfi7r4"<br />
<br />
[HKEY_CLASSES_ROOT\CLSID\{C5BF49A2-94F3-42BD-F434-3604812C8955}\InProcServer32]<br />
@="C:\WINDOWS\system32\hhs3ijndfd.dll"<br />
<br />
[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{C5BF49A2-94F3-42BD-F434-3604812C8955}\InProcServer32]<br />
@="C:\WINDOWS\system32\hhs3ijndfd.dll"<br />
<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» AppInit_DLLs<br />
!!!Attention, following keys are not inevitably infected!!!<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]<br />
"AppInit_DLLs"="C:\\WINDOWS\\System32\\reshhf.dll"<br />
"LoadAppInit_DLLs"=dword:00000001<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» Winlogon.System<br />
!!!Attention, following keys are not inevitably infected!!!<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]<br />
"System"=""<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» pe386-msguard-lzx32-huy32<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» Scanning wininet.dll infection<br />
<br />
<br />
Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â»Â» End<br />
<br />
<br />
"Silent Runners.vbs", revision R50, &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.silentrunners.org/"&gt;http://www.silentrunners.org/&lt;/a&gt;&lt;!-- m --&gt;<br />
Operating System: Windows XP SP2<br />
Output limited to non-default values, except where indicated by "{++}"<br />
<br />
<br />
Startup items buried in registry:<br />
---------------------------------<br />
<br />
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}<br />
"DW6" = ""C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"" [file not found]<br />
"x4uhkp2rvxr06m" = "C:\DOCUME~1\Jay\LOCALS~1\Temp\vlhahkrbl3xm.exe" [file not found]<br />
"dxyc4p3b2t6egdegh6qlwg6vj6ha4rnf1d33gqoho5" = "C:\DOCUME~1\Jay\LOCALS~1\Temp\uqnhhxdj2.exe" [file not found]<br />
"ecyf83ieh1mgx8lak5g" = "C:\DOCUME~1\Jay\LOCALS~1\Temp\qbeywtg4.exe" [file not found]<br />
"fglzf86v3s9gqw48bkqc6ak49s9fb53wklx00jtieuddr8wg7a" = "C:\DOCUME~1\Jay\LOCALS~1\Temp\xm9ic7lv04y.exe" [file not found]<br />
<br />
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}<br />
"S4F" = "C:\Program Files\S4F\Filter7.exe" ["S4F, Inc."]<br />
"TkBellExe" = ""C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot" ["RealNetworks, Inc."]<br />
"Adobe Photo Downloader" = ""C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"" ["Adobe Systems Incorporated"]<br />
"Gamevance" = "C:\Program Files\Gamevance\gamevance32.exe" [null data]<br />
"QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Inc."]<br />
"AppleSyncNotifier" = "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" ["Apple Inc."]<br />
"iTunesHelper" = ""C:\Program Files\iTunes\iTunesHelper.exe"" ["Apple Inc."]<br />
"Ibayig" = "rundll32.exe "C:\WINDOWS\Yyayoga.dll",e" [MS]<br />
"jsf8uiw3jnjgffght" = "C:\DOCUME~1\Monique\LOCALS~1\Temp\winlognn.exe" [null data]<br />
"Framework Windows" = "frmwrk32.exe" [null data]<br />
"Xwejavaqegay" = "rundll32.exe "C:\WINDOWS\efuyuhasajubijam.dll",e" [MS]<br />
"88d2667a" = "rundll32.exe "C:\WINDOWS\system32\dasakebe.dll",b" [MS]<br />
"kumeforozi" = "Rundll32.exe "C:\WINDOWS\system32\wivovego.dll",s" [MS]<br />
<br />
HKLM\Software\Microsoft\Active Setup\Installed Components\<br />
&gt;{26923b43-4d38-484f-9b9e-de460746276c}\(Default) = "Internet Explorer"<br />
                                        \StubPath   = "C:\WINDOWS\system32\shmgrate.exe OCInstallUserConfigIE" [MS]<br />
&gt;{881dd1c5-3dcf-431b-b061-f3f88e8be88a}\(Default) = "Outlook Express"<br />
                                        \StubPath   = "C:\WINDOWS\system32\shmgrate.exe OCInstallUserConfigOE" [MS]<br />
<br />
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\<br />
{C5BF49A2-94F3-42BD-F434-3604812C8955}\(Default) = (no title provided)<br />
  -&gt; {HKLM...CLSID} = "C:\WINDOWS\system32\hhs3ijndfd.dll"<br />
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\hhs3ijndfd.dll" [null data]<br />
{e2b687e8-85c1-4fc1-a30e-24e1c12a6d86}\(Default) = (no title provided)<br />
  -&gt; {HKLM...CLSID} = (no title provided)<br />
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\gijoyeri.dll" [empty string]<br />
<br />
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\<br />
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"<br />
  -&gt; {HKLM...CLSID} = "Display Panning CPL Extension"<br />
                   \InProcServer32\(Default) = "deskpan.dll" [file not found]<br />
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"<br />
  -&gt; {HKLM...CLSID} = "HyperTerminal Icon Ext"<br />
                   \InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]<br />
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"<br />
  -&gt; {HKLM...CLSID} = (no title provided)<br />
                   \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\msohev.dll" [MS]<br />
"{A4DF5659-0801-4A60-9607-1C48695EFDA9}" = "Share-to-Web Upload Folder"<br />
  -&gt; {HKLM...CLSID} = "Share-to-Web Upload Folder"<br />
                   \InProcServer32\(Default) = "C:\Program Files\Hewlett-Packard\HP Share-to-Web\HPGS2WNS.DLL" ["Hewlett-Packard"]<br />
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"<br />
  -&gt; {HKLM...CLSID} = "Outlook File Icon Extension"<br />
                   \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\OLKFSTUB.DLL" [MS]<br />
"{5464D816-CF16-4784-B9F3-75C0DB52B499}" = "Yahoo! Mail"<br />
  -&gt; {HKLM...CLSID} = "YMailShellExt Class"<br />
                   \InProcServer32\(Default) = "C:\WINDOWS\Downloaded Program Files\ymmapi.dll" ["Yahoo! Inc."]<br />
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"<br />
  -&gt; {HKLM...CLSID} = "RealOne Player Context Menu Class"<br />
                   \InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."]<br />
"{5E44E225-A408-11CF-B581-008029601108}" = "Roxio DragToDisc Shell Extension"<br />
  -&gt; {HKLM...CLSID} = "Roxio DragToDisc Shell Extension"<br />
                   \InProcServer32\(Default) = "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\shellex.dll" ["Roxio"]<br />
"{A44D5ACC-3411-40DE-9AD3-214FFB2ED7AC}" = "My Media"<br />
  -&gt; {HKLM...CLSID} = "My Media"<br />
                   \InProcServer32\(Default) = "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\MediaSX.dll" ["Roxio, Inc."]<br />
"{7D5C4BDD-B015-4401-8731-1507B87DE297}" = "QBVersionTool"<br />
  -&gt; {HKLM...CLSID} = "VersionShellExt Class"<br />
                   \InProcServer32\(Default) = "C:\Program Files\Common Files\Intuit\QuickBooks\QBVersionTool.dll" ["Intuit, Inc."]<br />
"{C55C499D-3518-44a1-998E-796AC5FC989D}" = "NetworkMagic"<br />
  -&gt; {HKLM...CLSID} = "Network Magic Folders"<br />
                   \InProcServer32\(Default) = "C:\Program Files\Pure Networks\Network Magic\nmspce.dll" ["Pure Networks, Inc."]<br />
"{33F85093-44BB-4587-B25B-FFD05D5B9916}" = "NetworkMagic"<br />
  -&gt; {HKLM...CLSID} = "Network Magic Folders"<br />
                   \InProcServer32\(Default) = "C:\Program Files\Pure Networks\Network Magic\nmspce.dll" ["Pure Networks, Inc."]<br />
"{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}" = "iTunes"<br />
  -&gt; {HKLM...CLSID} = "iTunes"<br />
                   \InProcServer32\(Default) = "C:\Program Files\iTunes\iTunesMiniPlayer.dll" ["Apple Inc."]<br />
<br />
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\<br />
&lt;&lt;!&gt;&gt; "{C5BF49A2-94F3-42BD-F434-3604812C8955}" = "jgzfkj9w38rksndfi7r4"<br />
  -&gt; {HKLM...CLSID} = "C:\WINDOWS\system32\hhs3ijndfd.dll"<br />
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\hhs3ijndfd.dll" [null data]<br />
<br />
HKLM\System\CurrentControlSet\Control\Session Manager\<br />
&lt;&lt;!&gt;&gt; "BootExecute" = "autocheck autochk *"|"SsiEfr.e" [file not found]<br />
<br />
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\<br />
&lt;&lt;!&gt;&gt; crypt\DLLName = "crypts.dll" [null data]<br />
<br />
HKLM\Software\Classes\Folder\shellex\ColumnHandlers\<br />
{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"<br />
  -&gt; {HKLM...CLSID} = "PDF Shell Extension"<br />
                   \InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]<br />
<br />
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\<br />
Yahoo! Mail\(Default) = "{5464D816-CF16-4784-B9F3-75C0DB52B499}"<br />
  -&gt; {HKLM...CLSID} = "YMailShellExt Class"<br />
                   \InProcServer32\(Default) = "C:\WINDOWS\Downloaded Program Files\ymmapi.dll" ["Yahoo! Inc."]<br />
<br />
<br />
Group Policies {policy setting}:<br />
--------------------------------<br />
<br />
Note: detected settings may not have any effect.<br />
<br />
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\<br />
<br />
"_NoDriveTypeAutoRun" = (REG_DWORD) hex:0x00000091<br />
{unrecognized setting}<br />
<br />
"NoSetActiveDesktop" = (REG_DWORD) hex:0x00000001<br />
{unrecognized setting}<br />
<br />
"NoFolderOptions" = (REG_DWORD) hex:0x00000001<br />
{Removes the Folder Options menu item from the Tools menu}<br />
<br />
"NoActiveDesktopChanges" = (REG_DWORD) hex:0x00000001<br />
{Prohibit changes}<br />
<br />
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\<br />
<br />
"NoCDBurning" = (REG_DWORD) hex:0x00000000<br />
{unrecognized setting}<br />
<br />
"NoSetActiveDesktop" = (REG_DWORD) hex:0x00000001<br />
{unrecognized setting}<br />
<br />
"NoActiveDesktopChanges" = (REG_DWORD) hex:0x00000001<br />
{unrecognized setting}<br />
<br />
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\<br />
<br />
"DisableRegistryTools" = (REG_DWORD) hex:0x00000001<br />
{Prevent access to registry editing tools}<br />
<br />
"DisableTaskMgr" = (REG_DWORD) hex:0x00000001<br />
{Remove Task Manager}<br />
<br />
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\<br />
<br />
"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001<br />
{Shutdown: Allow system to be shut down without having to log on}<br />
<br />
"undockwithoutlogon" = (REG_DWORD) hex:0x00000001<br />
{Devices: Allow undock without having to log on}<br />
<br />
HKLM\Software\Policies\Microsoft\Windows NT\SystemRestore\<br />
<br />
"Disable Config" = (REG_DWORD) hex:0x00000001<br />
{unrecognized setting}<br />
<br />
<br />
Active Desktop and Wallpaper:<br />
-----------------------------<br />
<br />
Active Desktop may be enabled at this entry:<br />
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState<br />
<br />
<br />
Enabled Scheduled Tasks:<br />
------------------------<br />
<br />
"AppleSoftwareUpdate" -&gt; launches: "C:\Program Files\Apple Software Update\SoftwareUpdate.exe -task" ["Apple Inc."]<br />
"Spybot - Search &amp; Destroy -  Scheduled Task" -&gt; launches: "C:\Program Files\Spybot - Search &amp; Destroy\SpybotSD.exe /AUTOCHECK" ["Safer Networking Limited"]<br />
"uldclhlt" -&gt; launches: "C:\WINDOWS\system32\rundll32.exe "C:\WINDOWS\system32\urqPiiFV.dll",AddRefActCtx" [MS]<br />
<br />
<br />
Winsock2 Service Provider DLLs:<br />
-------------------------------<br />
<br />
Namespace Service Providers<br />
<br />
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Ca&#8203;talog_Entries\ {++}<br />
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]<br />
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]<br />
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]<br />
000000000004\LibraryPath = "C:\Program Files\Bonjour\mdnsNSP.dll" ["Apple Inc."]<br />
<br />
Transport Service Providers<br />
<br />
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Cat&#8203;alog_Entries\ {++}<br />
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:<br />
C:\DOCUME~1\Monique\LOCALS~1\Temp\ntdll64.dll [null data], 01, 33<br />
C:\WINDOWS\system\wins4f.dll [null data], 02 - 16, 32<br />
%SystemRoot%\system32\mswsock.dll [MS], 17 - 19, 22 - 31<br />
%SystemRoot%\system32\rsvpsp.dll [MS], 20 - 21<br />
<br />
<br />
Toolbars, Explorer Bars, Extensions:<br />
------------------------------------<br />
<br />
Toolbars<br />
<br />
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\<br />
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"<br />
  -&gt; {HKLM...CLSID} = "Yahoo! Toolbar"<br />
                   \InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll" ["Yahoo! Inc."]<br />
<br />
HKLM\Software\Microsoft\Internet Explorer\Toolbar\<br />
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = (no title provided)<br />
  -&gt; {HKLM...CLSID} = "Yahoo! Toolbar"<br />
                   \InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll" ["Yahoo! Inc."]<br />
<br />
Explorer Bars<br />
<br />
HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\<br />
<br />
HKLM\Software\Classes\CLSID\{D6A116E7-5906-42E4-87F6-E7E15936415E}\(Default) = "MoneySide"<br />
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]<br />
InProcServer32\(Default) = "C:\Program Files\Microsoft Money\System\mnyside.dll" [MS]<br />
<br />
Extensions (Tools menu items, main toolbar menu buttons)<br />
<br />
HKLM\Software\Microsoft\Internet Explorer\Extensions\<br />
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\<br />
"MenuText" = "Sun Java Console"<br />
"CLSIDExtension" = "{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC}"<br />
  -&gt; {HKLM...CLSID} = "Java Plug-in 1.5.0"<br />
                   \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll" ["Sun Microsystems, Inc."]<br />
<br />
{85D1F590-48F4-11D9-9669-0800200C9A66}\<br />
"MenuText" = "Uninstall BitDefender Online Scanner v8"<br />
"Exec" = "%windir%\bdoscandel.exe" [null data]<br />
<br />
{CD67F990-D8E9-11D2-98FE-00C0F0318AFE}\<br />
<br />
{E023F504-0C5A-4750-A1E7-A9046DEA8A21}\<br />
"ButtonText" = "MoneySide"<br />
"CLSIDExtension" = "{DD6687B5-CB43-4211-BFC9-2942CCBDCB3E}"<br />
  -&gt; {HKLM...CLSID} = (no title provided)<br />
                   \InProcServer32\(Default) = "C:\Program Files\Microsoft Money\System\mnyside.dll" [MS]<br />
<br />
{FB5F1910-F110-11D2-BB9E-00C04F795683}\<br />
"ButtonText" = "Messenger"<br />
"MenuText" = "Windows Messenger"<br />
"Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]<br />
<br />
<br />
All Non-Disabled Services (Display Name, Service Name, Path {Service DLL}):<br />
---------------------------------------------------------------------------<br />
<br />
.NET Runtime Optimization Service v2.0.50727_X86, clr_optimization_v2.0.50727_32, "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe" [MS]<br />
Apple Mobile Device, Apple Mobile Device, ""C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe"" ["Apple Inc."]<br />
ASP.NET State Service, aspnet_state, "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe" [MS]<br />
Bonjour Service, Bonjour Service, ""C:\Program Files\Bonjour\mDNSResponder.exe"" ["Apple Inc."]<br />
Google Updater Service, gusvc, ""C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"" ["Google"]<br />
iPod Service, iPod Service, ""C:\Program Files\iPod\bin\iPodService.exe"" ["Apple Inc."]<br />
Logical Disk Manager Administrative Service, dmadmin, "C:\WINDOWS\System32\dmadmin.exe /com" ["Microsoft Corp., Veritas Software"]<br />
MSSQLSERVER, MSSQLSERVER, "C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe -sMSSQLSERVER" [MS]<br />
Network Provisioning Service, xmlprov, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\xmlprov.dll" [MS]}<br />
Portable Media Serial Number Service, WmdmPmSN, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\system32\MsPMSNSv.dll" [MS]}<br />
Pure Networks Net2Go Service, nmraapache, ""C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe" -k runservice" ["Pure Networks, Inc."]<br />
SQL Server (XACTWARE), MSSQL&#36;XACTWARE, ""C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sXACTWARE" [MS]<br />
SQL Server Active Directory Helper, MSSQLServerADHelper, ""C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe"" [MS]<br />
SQL Server VSS Writer, SQLWriter, ""C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"" [MS]<br />
SQLSERVERAGENT, SQLSERVERAGENT, "C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlagent.EXE -i MSSQLSERVER" [MS]<br />
Windows CardSpace, idsvc, ""C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe"" [MS]<br />
Windows Presentation Foundation Font Cache 3.0.0.0, FontCache3.0.0.0, "c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe" [MS]<br />
Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\system32\wdfmgr.exe" [MS]<br />
WMDM PMSP Service, WMDM PMSP Service, "C:\WINDOWS\System32\MsPMSPSv.exe" [MS]<br />
WMI Performance Adapter, WmiApSrv, "C:\WINDOWS\System32\wbem\wmiapsrv.exe" [MS]<br />
<br />
<br />
----------<br />
&lt;&lt;!&gt;&gt;: Suspicious data at a malware launch point.<br />
<br />
+ This report excludes default entries except where indicated.<br />
+ To see *everywhere* the script checks and *everything* it finds,<br />
  launch it from a command prompt or a shortcut with the -all parameter.<br />
+ To search all directories of local fixed drives for DESKTOP.INI<br />
  DLL launch points, use the -supp parameter or answer "No" at the<br />
  first message box and "Yes" at the second message box.<br />
---------- (total run time: 255 seconds, including 19 seconds for message boxes)]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Error suddenly life has new meaning...]]></title>
			<link>http://www.antisource.com/forums/showthread.php?tid=4266</link>
			<pubDate>Thu, 26 Feb 2009 13:28:16 +0000</pubDate>
			<guid isPermaLink="false">http://www.antisource.com/forums/showthread.php?tid=4266</guid>
			<description><![CDATA[Please help!!!<br />
<br />
I used my friend's thumbdrive on my PC and now this msg keeps appearing when i remove anything plugged into the computer. Including my digital cam.<br />
It also appears when the disc ejects]]></description>
			<content:encoded><![CDATA[Please help!!!<br />
<br />
I used my friend's thumbdrive on my PC and now this msg keeps appearing when i remove anything plugged into the computer. Including my digital cam.<br />
It also appears when the disc ejects]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[win.sality.nau please help]]></title>
			<link>http://www.antisource.com/forums/showthread.php?tid=4267</link>
			<pubDate>Wed, 25 Feb 2009 22:28:00 +0000</pubDate>
			<guid isPermaLink="false">http://www.antisource.com/forums/showthread.php?tid=4267</guid>
			<description><![CDATA[I receently got this ... no access to my directories... alll system kinda working but the sh... is inside<br />
<br />
anybody help , PLEASE<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 11:22:48 PM, on 2/25/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16762)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
G:\WINDOWS\System32\smss.exe<br />
G:\WINDOWS\system32\winlogon.exe<br />
G:\WINDOWS\system32\services.exe<br />
G:\WINDOWS\system32\lsass.exe<br />
G:\WINDOWS\system32\svchost.exe<br />
G:\WINDOWS\System32\svchost.exe<br />
G:\WINDOWS\system32\LEXBCES.EXE<br />
G:\WINDOWS\system32\spoolsv.exe<br />
G:\WINDOWS\system32\LEXPPS.EXE<br />
G:\Program Files\Java\jre6\bin\jqs.exe<br />
G:\Program Files\M-Audio\Conectiv\MAUSBCVInst.exe<br />
G:\WINDOWS\system32\nvsvc32.exe<br />
G:\WINDOWS\system32\PnkBstrA.exe<br />
G:\WINDOWS\system32\svchost.exe<br />
G:\WINDOWS\system32\SearchIndexer.exe<br />
G:\WINDOWS\RTHDCPL.EXE<br />
G:\WINDOWS\system32\RUNDLL32.EXE<br />
G:\WINDOWS\System32\M-AudioTaskBarIcon.exe<br />
G:\WINDOWS\system32\ctfmon.exe<br />
G:\Documents and Settings\hilen\Local Settings\Application Data\Google\Update\GoogleUpdate.exe<br />
G:\Program Files\Windows Desktop Search\WindowsSearch.exe<br />
G:\WINDOWS\system32\notepad.exe<br />
G:\WINDOWS\explorer.exe<br />
G:\WINDOWS\system32\SearchProtocolHost.exe<br />
C:\hjt\HijackThis.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;!-- m --&gt;<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &lt;!-- m --&gt;&lt;a class="postlink" href="http://windowsupdate.microsoft.com/"&gt;http://windowsupdate.microsoft.com/&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br />
O2 - BHO: Java&#153; Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - G:\Program Files\Java\jre6\bin\ssv.dll<br />
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - G:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - G:\Program Files\Windows Live Toolbar\msntb.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - G:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - G:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - G:\Program Files\Windows Live Toolbar\msntb.dll<br />
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br />
O4 - HKLM\..\Run: [snpstd] G:\WINDOWS\vsnpstd.exe<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE G:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE G:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [M-Audio Taskbar Icon] G:\WINDOWS\System32\M-AudioTaskBarIcon.exe<br />
O4 - HKLM\..\Run: [JMB36X IDE Setup] G:\WINDOWS\RaidTool\xInsIDE.exe<br />
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE<br />
O4 - HKLM\..\Run: [36X Raid Configurer] G:\WINDOWS\system32\xRaidSetup.exe boot<br />
O4 - HKCU\..\Run: [ctfmon.exe] G:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [Google Update] "G:\Documents and Settings\hilen\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c<br />
O4 - HKCU\..\Run: [Gadu-Gadu] "G:\Program Files\Gadu-Gadu\gg.exe" /tray<br />
O4 - HKCU\..\Run: [DAEMON Tools Lite] "G:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun<br />
O4 - HKCU\..\Run: [ccleaner] "G:\Program Files\CCleaner\CCleaner.exe" /AUTO<br />
O4 - Global Startup: Adobe Gamma Loader.lnk = G:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br />
O4 - Global Startup: Windows Search.lnk = G:\Program Files\Windows Desktop Search\WindowsSearch.exe<br />
O8 - Extra context menu item: &amp;Windows Live Search - &lt;!-- m --&gt;&lt;a class="postlink" href="res://G"&gt;res://G&lt;/a&gt;&lt;!-- m --&gt;:\Program Files\Windows Live Toolbar\msntb.dll/search.htm<br />
O8 - Extra context menu item: Add to Windows &amp;Live Favorites - &lt;!-- m --&gt;&lt;a class="postlink" href="http://favorites.live.com/quickadd.aspx"&gt;http://favorites.live.com/quickadd.aspx&lt;/a&gt;&lt;!-- m --&gt;<br />
O8 - Extra context menu item: E&amp;ksport do programu Microsoft Excel - &lt;!-- m --&gt;&lt;a class="postlink" href="res://E"&gt;res://E&lt;/a&gt;&lt;!-- m --&gt;:\PROGRA~1\msoffice\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\msoffice\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - G:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - G:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe<br />
O15 - Trusted Zone: &lt;!-- m --&gt;&lt;a class="postlink" href="http://mks.com.pl"&gt;http://mks.com.pl&lt;/a&gt;&lt;!-- m --&gt;<br />
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab"&gt;http://www.nvidia.com/content/DriverDow ... eqlab3.cab&lt;/a&gt;&lt;!-- m --&gt;<br />
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.eset.eu/buxus/docs/OnlineScanner.cab"&gt;http://www.eset.eu/buxus/docs/OnlineScanner.cab&lt;/a&gt;&lt;!-- m --&gt;<br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1223584199281"&gt;http://update.microsoft.com/windowsupda ... 3584199281&lt;/a&gt;&lt;!-- m --&gt;<br />
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.mks.com.pl/skaner/SkanerOnline.cab"&gt;http://www.mks.com.pl/skaner/SkanerOnline.cab&lt;/a&gt;&lt;!-- m --&gt;<br />
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab"&gt;http://www.nvidia.com/content/DriverDow ... rtScan.cab&lt;/a&gt;&lt;!-- m --&gt;<br />
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - &lt;!-- m --&gt;&lt;a class="postlink" href="https://sslvpn.action.pl/dana-cached/setup/JuniperSetupSP1.cab"&gt;https://sslvpn.action.pl/dana-cached/se ... tupSP1.cab&lt;/a&gt;&lt;!-- m --&gt;<br />
O23 - Service: Adobe LM Service - Unknown owner - G:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - G:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - G:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - G:\WINDOWS\system32\LEXBCES.EXE<br />
O23 - Service: M-Audio Conectiv Installer (MAudioConectivService) - Avid Technology, Inc. - G:\Program Files\M-Audio\Conectiv\MAUSBCVInst.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - G:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: PnkBstrA - Unknown owner - G:\WINDOWS\system32\PnkBstrA.exe<br />
<br />
--<br />
End of file - 6817 bytes]]></description>
			<content:encoded><![CDATA[I receently got this ... no access to my directories... alll system kinda working but the sh... is inside<br />
<br />
anybody help , PLEASE<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 11:22:48 PM, on 2/25/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16762)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
G:\WINDOWS\System32\smss.exe<br />
G:\WINDOWS\system32\winlogon.exe<br />
G:\WINDOWS\system32\services.exe<br />
G:\WINDOWS\system32\lsass.exe<br />
G:\WINDOWS\system32\svchost.exe<br />
G:\WINDOWS\System32\svchost.exe<br />
G:\WINDOWS\system32\LEXBCES.EXE<br />
G:\WINDOWS\system32\spoolsv.exe<br />
G:\WINDOWS\system32\LEXPPS.EXE<br />
G:\Program Files\Java\jre6\bin\jqs.exe<br />
G:\Program Files\M-Audio\Conectiv\MAUSBCVInst.exe<br />
G:\WINDOWS\system32\nvsvc32.exe<br />
G:\WINDOWS\system32\PnkBstrA.exe<br />
G:\WINDOWS\system32\svchost.exe<br />
G:\WINDOWS\system32\SearchIndexer.exe<br />
G:\WINDOWS\RTHDCPL.EXE<br />
G:\WINDOWS\system32\RUNDLL32.EXE<br />
G:\WINDOWS\System32\M-AudioTaskBarIcon.exe<br />
G:\WINDOWS\system32\ctfmon.exe<br />
G:\Documents and Settings\hilen\Local Settings\Application Data\Google\Update\GoogleUpdate.exe<br />
G:\Program Files\Windows Desktop Search\WindowsSearch.exe<br />
G:\WINDOWS\system32\notepad.exe<br />
G:\WINDOWS\explorer.exe<br />
G:\WINDOWS\system32\SearchProtocolHost.exe<br />
C:\hjt\HijackThis.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;!-- m --&gt;<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &lt;!-- m --&gt;&lt;a class="postlink" href="http://windowsupdate.microsoft.com/"&gt;http://windowsupdate.microsoft.com/&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br />
O2 - BHO: Java&#153; Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - G:\Program Files\Java\jre6\bin\ssv.dll<br />
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - G:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - G:\Program Files\Windows Live Toolbar\msntb.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - G:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - G:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - G:\Program Files\Windows Live Toolbar\msntb.dll<br />
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br />
O4 - HKLM\..\Run: [snpstd] G:\WINDOWS\vsnpstd.exe<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE G:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE G:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [M-Audio Taskbar Icon] G:\WINDOWS\System32\M-AudioTaskBarIcon.exe<br />
O4 - HKLM\..\Run: [JMB36X IDE Setup] G:\WINDOWS\RaidTool\xInsIDE.exe<br />
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE<br />
O4 - HKLM\..\Run: [36X Raid Configurer] G:\WINDOWS\system32\xRaidSetup.exe boot<br />
O4 - HKCU\..\Run: [ctfmon.exe] G:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [Google Update] "G:\Documents and Settings\hilen\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c<br />
O4 - HKCU\..\Run: [Gadu-Gadu] "G:\Program Files\Gadu-Gadu\gg.exe" /tray<br />
O4 - HKCU\..\Run: [DAEMON Tools Lite] "G:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun<br />
O4 - HKCU\..\Run: [ccleaner] "G:\Program Files\CCleaner\CCleaner.exe" /AUTO<br />
O4 - Global Startup: Adobe Gamma Loader.lnk = G:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br />
O4 - Global Startup: Windows Search.lnk = G:\Program Files\Windows Desktop Search\WindowsSearch.exe<br />
O8 - Extra context menu item: &amp;Windows Live Search - &lt;!-- m --&gt;&lt;a class="postlink" href="res://G"&gt;res://G&lt;/a&gt;&lt;!-- m --&gt;:\Program Files\Windows Live Toolbar\msntb.dll/search.htm<br />
O8 - Extra context menu item: Add to Windows &amp;Live Favorites - &lt;!-- m --&gt;&lt;a class="postlink" href="http://favorites.live.com/quickadd.aspx"&gt;http://favorites.live.com/quickadd.aspx&lt;/a&gt;&lt;!-- m --&gt;<br />
O8 - Extra context menu item: E&amp;ksport do programu Microsoft Excel - &lt;!-- m --&gt;&lt;a class="postlink" href="res://E"&gt;res://E&lt;/a&gt;&lt;!-- m --&gt;:\PROGRA~1\msoffice\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\msoffice\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - G:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - G:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe<br />
O15 - Trusted Zone: &lt;!-- m --&gt;&lt;a class="postlink" href="http://mks.com.pl"&gt;http://mks.com.pl&lt;/a&gt;&lt;!-- m --&gt;<br />
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab"&gt;http://www.nvidia.com/content/DriverDow ... eqlab3.cab&lt;/a&gt;&lt;!-- m --&gt;<br />
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.eset.eu/buxus/docs/OnlineScanner.cab"&gt;http://www.eset.eu/buxus/docs/OnlineScanner.cab&lt;/a&gt;&lt;!-- m --&gt;<br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1223584199281"&gt;http://update.microsoft.com/windowsupda ... 3584199281&lt;/a&gt;&lt;!-- m --&gt;<br />
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.mks.com.pl/skaner/SkanerOnline.cab"&gt;http://www.mks.com.pl/skaner/SkanerOnline.cab&lt;/a&gt;&lt;!-- m --&gt;<br />
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab"&gt;http://www.nvidia.com/content/DriverDow ... rtScan.cab&lt;/a&gt;&lt;!-- m --&gt;<br />
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - &lt;!-- m --&gt;&lt;a class="postlink" href="https://sslvpn.action.pl/dana-cached/setup/JuniperSetupSP1.cab"&gt;https://sslvpn.action.pl/dana-cached/se ... tupSP1.cab&lt;/a&gt;&lt;!-- m --&gt;<br />
O23 - Service: Adobe LM Service - Unknown owner - G:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - G:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - G:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - G:\WINDOWS\system32\LEXBCES.EXE<br />
O23 - Service: M-Audio Conectiv Installer (MAudioConectivService) - Avid Technology, Inc. - G:\Program Files\M-Audio\Conectiv\MAUSBCVInst.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - G:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: PnkBstrA - Unknown owner - G:\WINDOWS\system32\PnkBstrA.exe<br />
<br />
--<br />
End of file - 6817 bytes]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[suspicious email zip]]></title>
			<link>http://www.antisource.com/forums/showthread.php?tid=4268</link>
			<pubDate>Wed, 18 Feb 2009 11:12:08 +0000</pubDate>
			<guid isPermaLink="false">http://www.antisource.com/forums/showthread.php?tid=4268</guid>
			<description><![CDATA[received emai that i purportedly changed my password, on my domain, which quite obviously is not the case.<br />
<br />
<span style="color: #FF0000;">this also serves as a warning for others to watch out for such emails.</span><br />
<br />
need help for someone to analyse the attached zip file that comes with the email, the file opens in windows as a pif file, although it is labeled as htm* ( * is a hidden character not visible in window )<br />
<br />
i renamed the file to .txt but it still shows as MSDOS executable, on inspection through command prompt it is actualy .txt.pif<br />
<br />
could some kind soul with more knowledge on msdos advise what the file does please.<br />
<br />
not much info on the email, it came from IP 58.137.55.113.<br />
did not have much luck looking up that IP.<br />
<br />
thanks much.<br />
<br />
<span style="color: #FF0000;">WARNING : do not download unless you know what you are doing</span><br />
<span style="font-weight: bold;">***link removed***</span>]]></description>
			<content:encoded><![CDATA[received emai that i purportedly changed my password, on my domain, which quite obviously is not the case.<br />
<br />
<span style="color: #FF0000;">this also serves as a warning for others to watch out for such emails.</span><br />
<br />
need help for someone to analyse the attached zip file that comes with the email, the file opens in windows as a pif file, although it is labeled as htm* ( * is a hidden character not visible in window )<br />
<br />
i renamed the file to .txt but it still shows as MSDOS executable, on inspection through command prompt it is actualy .txt.pif<br />
<br />
could some kind soul with more knowledge on msdos advise what the file does please.<br />
<br />
not much info on the email, it came from IP 58.137.55.113.<br />
did not have much luck looking up that IP.<br />
<br />
thanks much.<br />
<br />
<span style="color: #FF0000;">WARNING : do not download unless you know what you are doing</span><br />
<span style="font-weight: bold;">***link removed***</span>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Detect ARP poisoning(ARP spoofing) &#x26; ARP flooding]]></title>
			<link>http://www.antisource.com/forums/showthread.php?tid=4269</link>
			<pubDate>Fri, 13 Feb 2009 02:40:17 +0000</pubDate>
			<guid isPermaLink="false">http://www.antisource.com/forums/showthread.php?tid=4269</guid>
			<description><![CDATA[ARP, because of its simpleness, fastness, and effectiveness, is becoming increasingly popular among internet raggers, thus causing severe influence to the internet environment.With Ax3soft Sax2, we can quickly and accurately locate ARP source when ARP attack happens to the network, so as to ensure normal and reliable network operation.<br />
Solution:<br />
<br />
Diagnosis View is the most direct and effective place to locate ARP attack and should be our first choice. Its interface is displayed as picture1.<br />
<br />
  <img src="http://www.ids-sax2.com/articles/images/QuickLocateARPAttackSource.gif" border="0" alt="[Image: QuickLocateARPAttackSource.gif]" />                                                        (picture1)<br />
<br />
Picture 1 definitely points out that there are two kinds of ARP attack event, ARP Scan and ARP MAC address changed, in the network, and the attack source is clearly given at the bottom. Meanwhile, Sax2 NIDS will provide reasons of such ARP attacks and corresponding solutions.<br />
<br />
For more  information, visit &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.ids-sax2.com/articles/QuickLocateARPAttackSource.htm"&gt;http://www.ids-sax2.com/articles/QuickL ... Source.htm&lt;/a&gt;&lt;!-- m --&gt;]]></description>
			<content:encoded><![CDATA[ARP, because of its simpleness, fastness, and effectiveness, is becoming increasingly popular among internet raggers, thus causing severe influence to the internet environment.With Ax3soft Sax2, we can quickly and accurately locate ARP source when ARP attack happens to the network, so as to ensure normal and reliable network operation.<br />
Solution:<br />
<br />
Diagnosis View is the most direct and effective place to locate ARP attack and should be our first choice. Its interface is displayed as picture1.<br />
<br />
  <img src="http://www.ids-sax2.com/articles/images/QuickLocateARPAttackSource.gif" border="0" alt="[Image: QuickLocateARPAttackSource.gif]" />                                                        (picture1)<br />
<br />
Picture 1 definitely points out that there are two kinds of ARP attack event, ARP Scan and ARP MAC address changed, in the network, and the attack source is clearly given at the bottom. Meanwhile, Sax2 NIDS will provide reasons of such ARP attacks and corresponding solutions.<br />
<br />
For more  information, visit &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.ids-sax2.com/articles/QuickLocateARPAttackSource.htm"&gt;http://www.ids-sax2.com/articles/QuickL ... Source.htm&lt;/a&gt;&lt;!-- m --&gt;]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[need virus help]]></title>
			<link>http://www.antisource.com/forums/showthread.php?tid=4270</link>
			<pubDate>Wed, 11 Feb 2009 04:56:51 +0000</pubDate>
			<guid isPermaLink="false">http://www.antisource.com/forums/showthread.php?tid=4270</guid>
			<description><![CDATA[Here is the hijackthis log, let me know if anything else is needed.<br />
Thank you very much for any help. <br />
<br />
Also, as far as the running processes go, I've already ended a lot of the *32.exe processes that were bogging the computer down.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 10:48:24 PM, on 2/10/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16762)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\System32\bcmwltry.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\WINDOWS\eHome\ehRecvr.exe<br />
C:\Program Files\McAfee\Common Framework\FrameworkService.exe<br />
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe<br />
C:\WINDOWS\system32\userinit.exe<br />
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\MSN Messenger\msnmsgr.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.google.com/ig/dell?hl=en&amp;client=dell-usuk-rel&amp;channel=us&amp;ibd=5070124"&gt;http://www.google.com/ig/dell?hl=en&amp;cli ... bd=5070124&lt;/a&gt;&lt;!-- m --&gt;<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.iastate.edu/"&gt;http://www.iastate.edu/&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;!-- m --&gt;<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.comcast.net/"&gt;http://www.comcast.net/&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.google.com/ig/dell?hl=en&amp;client=dell-usuk-rel&amp;channel=us&amp;ibd=5070124"&gt;http://www.google.com/ig/dell?hl=en&amp;cli ... bd=5070124&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0<br />
R3 - URLSearchHook: (no name) - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - (no file)<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: CPV - {15421B84-3488-49A7-AD18-CBF84A3EFAF6} - C:\Program Files\WebShow\WebShow.dll<br />
O2 - BHO: {6d4540f4-1ce4-3328-d3c4-56b46dccf491} - {194fccd6-4b65-4c3d-8233-4ec14f0454d6} - C:\WINDOWS\system32\lotsxv.dll<br />
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search &amp; Destroy\SDHelper.dll<br />
O2 - BHO: worldadmarketplace - {571cc086-fbb7-2cbb-4c88-d91b3fa280e1} - C:\WINDOWS\system32\nsgD.dll<br />
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\vtUkhiFX.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br />
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll<br />
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br />
O2 - BHO: (no name) - {A02E6FB2-D5D4-4D62-9393-7698A18AF8DA} - C:\WINDOWS\system32\yaywvvur.dll<br />
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)<br />
O2 - BHO: (no name) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - (no file)<br />
O2 - BHO: HelloWorldBHO - {D88E1558-7C2D-407A-953A-C044F5607CEA} - C:\Program Files\Mjcore\Mjcore.dll<br />
O2 - BHO: worldadmarketplace browser enhancer - {EEABFA92-0B51-DF8F-BDAB-970AB5D10AD5} - C:\WINDOWS\system32\wkonygvgiueib.dll<br />
O4 - HKLM\..\Run: [VirusRemover2008] C:\Program Files\VirusRemover2008\VRM2008.exe<br />
O4 - HKLM\..\Run: [vbnualcukhrz] C:\WINDOWS\System32\regsvr32.exe /s "C:\WINDOWS\system32\wkonygvgiueib.dll"<br />
O4 - HKLM\..\Run: [prunnet] "C:\WINDOWS\system32\prunnet.exe"<br />
O4 - HKLM\..\Run: [Framework Windows] frmwrk32.exe<br />
O4 - HKLM\..\Run: [c0afcf83] rundll32.exe "C:\WINDOWS\system32\vqrsxgbw.dll",b<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background<br />
O4 - HKCU\..\Run: [cogad] "C:\Documents and Settings\Alyssa\Application Data\cogad\cogad.exe" 61A847B5BBF728173599284503996897C881250221C8670836AC4FA7C8833201749139<br />
O4 - HKCU\..\Run: [Twain] C:\Documents and Settings\Alyssa\Application Data\Twain\Twain.exe<br />
O4 - HKCU\..\Run: [SpeedRunner] C:\Documents and Settings\Alyssa\Application Data\SpeedRunner\SpeedRunner.exe<br />
O4 - HKCU\..\Run: [SfKg6wIP] C:\Documents and Settings\Alyssa\Application Data\Microsoft\Windows\bjssu.exe<br />
O4 - HKCU\..\Run: [VnrPack23] "C:\Program Files\VnrPack\VnrPack23.exe"<br />
O4 - HKCU\..\Run: [prunnet] "C:\WINDOWS\system32\prunnet.exe"<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - &lt;!-- m --&gt;&lt;a class="postlink" href="res://C"&gt;res://C&lt;/a&gt;&lt;!-- m --&gt;:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br />
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O10 - Unknown file in Winsock LSP: c:\windows\temp\ntdll64.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\temp\ntdll64.dll<br />
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://photo.walgreens.com/WalgreensActivia.cab"&gt;http://photo.walgreens.com/WalgreensActivia.cab&lt;/a&gt;&lt;!-- m --&gt;<br />
O20 - AppInit_DLLs: lotsxv.dll<br />
O20 - Winlogon Notify: vtUkhiFX - C:\WINDOWS\SYSTEM32\vtUkhiFX.dll<br />
O22 - SharedTaskScheduler: depreciable - {716002db-288c-4bf0-80cd-a467e78d8b55} - C:\WINDOWS\system32\dxovx.dll (file missing)<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\QWx5c3Nh\command.exe (file missing)<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe<br />
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe<br />
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe<br />
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe<br />
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe<br />
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE<br />
<br />
--<br />
End of file - 7640 bytes]]></description>
			<content:encoded><![CDATA[Here is the hijackthis log, let me know if anything else is needed.<br />
Thank you very much for any help. <br />
<br />
Also, as far as the running processes go, I've already ended a lot of the *32.exe processes that were bogging the computer down.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 10:48:24 PM, on 2/10/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16762)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\System32\bcmwltry.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\WINDOWS\eHome\ehRecvr.exe<br />
C:\Program Files\McAfee\Common Framework\FrameworkService.exe<br />
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe<br />
C:\WINDOWS\system32\userinit.exe<br />
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\MSN Messenger\msnmsgr.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.google.com/ig/dell?hl=en&amp;client=dell-usuk-rel&amp;channel=us&amp;ibd=5070124"&gt;http://www.google.com/ig/dell?hl=en&amp;cli ... bd=5070124&lt;/a&gt;&lt;!-- m --&gt;<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.iastate.edu/"&gt;http://www.iastate.edu/&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;!-- m --&gt;<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.comcast.net/"&gt;http://www.comcast.net/&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.google.com/ig/dell?hl=en&amp;client=dell-usuk-rel&amp;channel=us&amp;ibd=5070124"&gt;http://www.google.com/ig/dell?hl=en&amp;cli ... bd=5070124&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0<br />
R3 - URLSearchHook: (no name) - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - (no file)<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: CPV - {15421B84-3488-49A7-AD18-CBF84A3EFAF6} - C:\Program Files\WebShow\WebShow.dll<br />
O2 - BHO: {6d4540f4-1ce4-3328-d3c4-56b46dccf491} - {194fccd6-4b65-4c3d-8233-4ec14f0454d6} - C:\WINDOWS\system32\lotsxv.dll<br />
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search &amp; Destroy\SDHelper.dll<br />
O2 - BHO: worldadmarketplace - {571cc086-fbb7-2cbb-4c88-d91b3fa280e1} - C:\WINDOWS\system32\nsgD.dll<br />
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\vtUkhiFX.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br />
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll<br />
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br />
O2 - BHO: (no name) - {A02E6FB2-D5D4-4D62-9393-7698A18AF8DA} - C:\WINDOWS\system32\yaywvvur.dll<br />
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)<br />
O2 - BHO: (no name) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - (no file)<br />
O2 - BHO: HelloWorldBHO - {D88E1558-7C2D-407A-953A-C044F5607CEA} - C:\Program Files\Mjcore\Mjcore.dll<br />
O2 - BHO: worldadmarketplace browser enhancer - {EEABFA92-0B51-DF8F-BDAB-970AB5D10AD5} - C:\WINDOWS\system32\wkonygvgiueib.dll<br />
O4 - HKLM\..\Run: [VirusRemover2008] C:\Program Files\VirusRemover2008\VRM2008.exe<br />
O4 - HKLM\..\Run: [vbnualcukhrz] C:\WINDOWS\System32\regsvr32.exe /s "C:\WINDOWS\system32\wkonygvgiueib.dll"<br />
O4 - HKLM\..\Run: [prunnet] "C:\WINDOWS\system32\prunnet.exe"<br />
O4 - HKLM\..\Run: [Framework Windows] frmwrk32.exe<br />
O4 - HKLM\..\Run: [c0afcf83] rundll32.exe "C:\WINDOWS\system32\vqrsxgbw.dll",b<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background<br />
O4 - HKCU\..\Run: [cogad] "C:\Documents and Settings\Alyssa\Application Data\cogad\cogad.exe" 61A847B5BBF728173599284503996897C881250221C8670836AC4FA7C8833201749139<br />
O4 - HKCU\..\Run: [Twain] C:\Documents and Settings\Alyssa\Application Data\Twain\Twain.exe<br />
O4 - HKCU\..\Run: [SpeedRunner] C:\Documents and Settings\Alyssa\Application Data\SpeedRunner\SpeedRunner.exe<br />
O4 - HKCU\..\Run: [SfKg6wIP] C:\Documents and Settings\Alyssa\Application Data\Microsoft\Windows\bjssu.exe<br />
O4 - HKCU\..\Run: [VnrPack23] "C:\Program Files\VnrPack\VnrPack23.exe"<br />
O4 - HKCU\..\Run: [prunnet] "C:\WINDOWS\system32\prunnet.exe"<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - &lt;!-- m --&gt;&lt;a class="postlink" href="res://C"&gt;res://C&lt;/a&gt;&lt;!-- m --&gt;:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br />
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O10 - Unknown file in Winsock LSP: c:\windows\temp\ntdll64.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\temp\ntdll64.dll<br />
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://photo.walgreens.com/WalgreensActivia.cab"&gt;http://photo.walgreens.com/WalgreensActivia.cab&lt;/a&gt;&lt;!-- m --&gt;<br />
O20 - AppInit_DLLs: lotsxv.dll<br />
O20 - Winlogon Notify: vtUkhiFX - C:\WINDOWS\SYSTEM32\vtUkhiFX.dll<br />
O22 - SharedTaskScheduler: depreciable - {716002db-288c-4bf0-80cd-a467e78d8b55} - C:\WINDOWS\system32\dxovx.dll (file missing)<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\QWx5c3Nh\command.exe (file missing)<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe<br />
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe<br />
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe<br />
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe<br />
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe<br />
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE<br />
<br />
--<br />
End of file - 7640 bytes]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[uninstalling Speeditup Free]]></title>
			<link>http://www.antisource.com/forums/showthread.php?tid=4271</link>
			<pubDate>Sun, 01 Feb 2009 16:15:09 +0000</pubDate>
			<guid isPermaLink="false">http://www.antisource.com/forums/showthread.php?tid=4271</guid>
			<description><![CDATA[I installed Speeditup Free a couple of months ago and began to notice lots of errors. <br />
Main problem is that Internet explorer won't load and any other browser except moxilla won't run.  Moxilla also freezes often.<br />
most antispyware and malware programs won't update when I download them.<br />
<br />
I have been trying to find the cause of this for weeks and today upon running Ad Aware it found a Win 32 worm Kelvir on the system. <br />
<br />
I then ran an online scan on Panda Active Scan 2.0 and this found and disinfected the file- trj/Downloader.VFT. <br />
<br />
Have tried uninstalling Speeditup Free and get the following message;<br />
invalid ininstall control file C:\Program File\Speeditup Free\irunin.xml<br />
<br />
Here is the log file from Hijack this:<br />
 <br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 15:58:21, on 01/02/2009<br />
Platform: Windows Vista SP1 (WinNT 6.00.1905)<br />
MSIE: Internet Explorer v7.00 (7.00.6001.18000)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE<br />
C:\Windows\RtHDVCpl.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe<br />
C:\Program Files\AVG\AVG8\avgtray.exe<br />
C:\Windows\WindowsMobile\wmdSync.exe<br />
C:\Program Files\Virgin Broadband\advisor\Broadbandadvisor.exe<br />
C:\Program Files\Launch Manager\QtZgAcer.EXE<br />
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br />
C:\Users\didean\AppData\Local\Temp\RtkBtMnt.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Windows\system32\rundll32.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://en.uk.acer.yahoo.com"&gt;http://en.uk.acer.yahoo.com&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;!-- m --&gt;<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://en.uk.acer.yahoo.com"&gt;http://en.uk.acer.yahoo.com&lt;/a&gt;&lt;!-- m --&gt;<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy1.equinoxsolutions.com:80<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br />
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll<br />
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll<br />
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll<br />
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL<br />
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"<br />
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot<br />
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe<br />
O4 - HKLM\..\Run: [Broadbandadvisor.exe] "C:\Program Files\Virgin Broadband\advisor\Broadbandadvisor.exe" /AUTORUN<br />
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE<br />
O4 - HKLM\..\Run: [iolo Startup] "C:\Program Files\iolo\Common\Lib\ioloLManager.exe"<br />
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup<br />
O4 - HKCU\..\Run: [?????????] ??????????????e<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O13 - Gopher Prefix: <br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O20 - AppInit_DLLs: avgrsstx.dll C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL<br />
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br />
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe<br />
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe<br />
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe<br />
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)<br />
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe<br />
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe<br />
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe<br />
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe<br />
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe<br />
O23 - Service: Google Desktop Manager 5.8.811.4345 (GoogleDesktopManager-110408-113106) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br />
O23 - Service: Google Update Service (gupdate1c97047fbb13c30) (gupdate1c97047fbb13c30) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe<br />
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe<br />
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe<br />
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe<br />
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe<br />
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP2c\RpcAgentSrv.exe<br />
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe<br />
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe<br />
<br />
--<br />
End of file - 7817 bytes<br />
<br />
<br />
Can anyone suggest what I can do to effectively eradicate and destroy the installed program?  I would be most grateful for any help,]]></description>
			<content:encoded><![CDATA[I installed Speeditup Free a couple of months ago and began to notice lots of errors. <br />
Main problem is that Internet explorer won't load and any other browser except moxilla won't run.  Moxilla also freezes often.<br />
most antispyware and malware programs won't update when I download them.<br />
<br />
I have been trying to find the cause of this for weeks and today upon running Ad Aware it found a Win 32 worm Kelvir on the system. <br />
<br />
I then ran an online scan on Panda Active Scan 2.0 and this found and disinfected the file- trj/Downloader.VFT. <br />
<br />
Have tried uninstalling Speeditup Free and get the following message;<br />
invalid ininstall control file C:\Program File\Speeditup Free\irunin.xml<br />
<br />
Here is the log file from Hijack this:<br />
 <br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 15:58:21, on 01/02/2009<br />
Platform: Windows Vista SP1 (WinNT 6.00.1905)<br />
MSIE: Internet Explorer v7.00 (7.00.6001.18000)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE<br />
C:\Windows\RtHDVCpl.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe<br />
C:\Program Files\AVG\AVG8\avgtray.exe<br />
C:\Windows\WindowsMobile\wmdSync.exe<br />
C:\Program Files\Virgin Broadband\advisor\Broadbandadvisor.exe<br />
C:\Program Files\Launch Manager\QtZgAcer.EXE<br />
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br />
C:\Users\didean\AppData\Local\Temp\RtkBtMnt.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Windows\system32\rundll32.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://en.uk.acer.yahoo.com"&gt;http://en.uk.acer.yahoo.com&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;!-- m --&gt;<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://en.uk.acer.yahoo.com"&gt;http://en.uk.acer.yahoo.com&lt;/a&gt;&lt;!-- m --&gt;<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy1.equinoxsolutions.com:80<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br />
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll<br />
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll<br />
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll<br />
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL<br />
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"<br />
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot<br />
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe<br />
O4 - HKLM\..\Run: [Broadbandadvisor.exe] "C:\Program Files\Virgin Broadband\advisor\Broadbandadvisor.exe" /AUTORUN<br />
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE<br />
O4 - HKLM\..\Run: [iolo Startup] "C:\Program Files\iolo\Common\Lib\ioloLManager.exe"<br />
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup<br />
O4 - HKCU\..\Run: [?????????] ??????????????e<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O13 - Gopher Prefix: <br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O20 - AppInit_DLLs: avgrsstx.dll C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL<br />
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br />
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe<br />
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe<br />
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe<br />
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)<br />
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe<br />
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe<br />
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe<br />
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe<br />
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe<br />
O23 - Service: Google Desktop Manager 5.8.811.4345 (GoogleDesktopManager-110408-113106) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br />
O23 - Service: Google Update Service (gupdate1c97047fbb13c30) (gupdate1c97047fbb13c30) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe<br />
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe<br />
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe<br />
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe<br />
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe<br />
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP2c\RpcAgentSrv.exe<br />
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe<br />
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe<br />
<br />
--<br />
End of file - 7817 bytes<br />
<br />
<br />
Can anyone suggest what I can do to effectively eradicate and destroy the installed program?  I would be most grateful for any help,]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[virus help please]]></title>
			<link>http://www.antisource.com/forums/showthread.php?tid=4272</link>
			<pubDate>Thu, 15 Jan 2009 20:31:02 +0000</pubDate>
			<guid isPermaLink="false">http://www.antisource.com/forums/showthread.php?tid=4272</guid>
			<description><![CDATA[Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 12:42:33 PM, on 1/17/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16762)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\system32\PnkBstrA.exe<br />
C:\WINDOWS\system32\PnkBstrB.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\WINDOWS\system32\RUNDLL32.EXE<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\WINDOWS\system32\HPZipm12.exe<br />
C:\WINDOWS\system32\msiexec.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = &lt;!-- m --&gt;&lt;a class="postlink" href="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html"&gt;http://us.rd.yahoo.com/customize/ie/def ... earch.html&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com"&gt;http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com&lt;/a&gt;&lt;!-- m --&gt;<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.yahoo.com/"&gt;http://www.yahoo.com/&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.yahoo.com/"&gt;http://www.yahoo.com/&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com"&gt;http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &lt;!-- m --&gt;&lt;a class="postlink" href="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html"&gt;http://us.rd.yahoo.com/customize/ie/def ... earch.html&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com"&gt;http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com&lt;/a&gt;&lt;!-- m --&gt;<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.yahoo.com/"&gt;http://www.yahoo.com/&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = &lt;!-- m --&gt;&lt;a class="postlink" href="http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com"&gt;http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com&lt;/a&gt;&lt;!-- m --&gt;<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)<br />
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)<br />
O2 - BHO: Java&#153; Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE<br />
O4 - HKLM\..\Run: [cat]  <br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [FLMK08KB] C:\Program Files\Muiltmedia keyboard utility\1.3\MMKEYBD.EXE<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br />
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet<br />
O4 - Startup: PowerReg Scheduler.exe<br />
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - &lt;!-- m --&gt;&lt;a class="postlink" href="res://C"&gt;res://C&lt;/a&gt;&lt;!-- m --&gt;:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe<br />
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll<br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1200561234789"&gt;http://www.update.microsoft.com/windows ... 0561234789&lt;/a&gt;&lt;!-- m --&gt;<br />
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab"&gt;http://www.nvidia.com/content/DriverDow ... eqlab2.cab&lt;/a&gt;&lt;!-- m --&gt;<br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab"&gt;http://fpdownload2.macromedia.com/get/s ... wflash.cab&lt;/a&gt;&lt;!-- m --&gt;<br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe<br />
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
<br />
--<br />
End of file - 7780 bytes]]></description>
			<content:encoded><![CDATA[Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 12:42:33 PM, on 1/17/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16762)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\system32\PnkBstrA.exe<br />
C:\WINDOWS\system32\PnkBstrB.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\WINDOWS\system32\RUNDLL32.EXE<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\WINDOWS\system32\HPZipm12.exe<br />
C:\WINDOWS\system32\msiexec.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = &lt;!-- m --&gt;&lt;a class="postlink" href="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html"&gt;http://us.rd.yahoo.com/customize/ie/def ... earch.html&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com"&gt;http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com&lt;/a&gt;&lt;!-- m --&gt;<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.yahoo.com/"&gt;http://www.yahoo.com/&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.yahoo.com/"&gt;http://www.yahoo.com/&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com"&gt;http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &lt;!-- m --&gt;&lt;a class="postlink" href="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html"&gt;http://us.rd.yahoo.com/customize/ie/def ... earch.html&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com"&gt;http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com&lt;/a&gt;&lt;!-- m --&gt;<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.yahoo.com/"&gt;http://www.yahoo.com/&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = &lt;!-- m --&gt;&lt;a class="postlink" href="http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com"&gt;http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com&lt;/a&gt;&lt;!-- m --&gt;<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)<br />
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)<br />
O2 - BHO: Java&#153; Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br />
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE<br />
O4 - HKLM\..\Run: [cat]  <br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [FLMK08KB] C:\Program Files\Muiltmedia keyboard utility\1.3\MMKEYBD.EXE<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br />
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet<br />
O4 - Startup: PowerReg Scheduler.exe<br />
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - &lt;!-- m --&gt;&lt;a class="postlink" href="res://C"&gt;res://C&lt;/a&gt;&lt;!-- m --&gt;:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe<br />
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll<br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1200561234789"&gt;http://www.update.microsoft.com/windows ... 0561234789&lt;/a&gt;&lt;!-- m --&gt;<br />
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab"&gt;http://www.nvidia.com/content/DriverDow ... eqlab2.cab&lt;/a&gt;&lt;!-- m --&gt;<br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab"&gt;http://fpdownload2.macromedia.com/get/s ... wflash.cab&lt;/a&gt;&lt;!-- m --&gt;<br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe<br />
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
<br />
--<br />
End of file - 7780 bytes]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Some kind of problem with google]]></title>
			<link>http://www.antisource.com/forums/showthread.php?tid=4273</link>
			<pubDate>Sat, 10 Jan 2009 15:37:32 +0000</pubDate>
			<guid isPermaLink="false">http://www.antisource.com/forums/showthread.php?tid=4273</guid>
			<description><![CDATA[Recently, I have been encountering some kind of problems while searching with google. When I search for something, I get all the results. Then, when I click on any of the links, it does not open that site, but opens some other site which has I suspect has malware content. I did a HijachThis scan and here is the scan.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 10:32:01 AM, on 1/10/2009<br />
Platform: Windows Vista SP1 (WinNT 6.00.1905)<br />
MSIE: Internet Explorer v7.00 (7.00.6001.18000)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Vista Softwares\iTunes\iTunesHelper.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Program Files\Skype\Phone\Skype.exe<br />
C:\Program Files\DAEMON Tools Lite\daemon.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\Vista Softwares\Registry Mechanic\RMTray.exe<br />
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe<br />
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe<br />
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe<br />
C:\Program Files\Skype\Plugin Manager\skypePM.exe<br />
C:\Vista Softwares\System Mechanic Professional\Personal Firewall\ioloFW.exe<br />
C:\Vista Softwares\System Mechanic Professional\AntiVirus\ioloAV.exe<br />
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe<br />
C:\Vista Softwares\System Mechanic Professional\AntiVirus\iAVEmailScanner.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Program Files\Windows Live\Mail\wlmail.exe<br />
C:\Program Files\Opera\Opera.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;!-- m --&gt;<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;!-- m --&gt;<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;!-- m --&gt;<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O2 - BHO: (no name) - {64466B8E-20A7-4A4A-AFF4-AAD9CA68B52C} - C:\Program Files\WebMediaViewer\hpmun.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br />
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [iolo Startup] "C:\Program Files\iolo\Common\Lib\ioloLManager.exe"<br />
O4 - HKLM\..\Run: [iTunesHelper] "C:\Vista Softwares\iTunes\iTunesHelper.exe"<br />
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized<br />
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun<br />
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background<br />
O4 - HKCU\..\Run: [RegistryMechanic] C:\Vista Softwares\Registry Mechanic\RMTray.exe /H<br />
O4 - HKCU\..\Run: [Cognac] C:\Users\Anuj\AppData\Local\Temp\~tmpb.exe<br />
O4 - HKCU\..\Run: [MSFox] C:\Users\Anuj\AppData\Local\Temp\yyy17457.exe<br />
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet<br />
O4 - HKLM\..\Policies\Explorer\Run: [QuickTime Task] C:\Program Files\WebMediaViewer\qttask.exe<br />
O4 - HKLM\..\Policies\Explorer\Run: [VMware hptray] C:\Program Files\WebMediaViewer\hpmon.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - Global Startup: Bluetooth.lnk = ?<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - &lt;!-- m --&gt;&lt;a class="postlink" href="res://C"&gt;res://C&lt;/a&gt;&lt;!-- m --&gt;:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Send image to &amp;Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm<br />
O8 - Extra context menu item: Send page to &amp;Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll<br />
O9 - Extra button: (no name) - {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.iexplorsecurity.com/redirect.php"&gt;http://www.iexplorsecurity.com/redirect.php&lt;/a&gt;&lt;!-- m --&gt; (file missing)<br />
O9 - Extra 'Tools' menuitem: Explorer Security - {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.iexplorsecurity.com/redirect.php"&gt;http://www.iexplorsecurity.com/redirect.php&lt;/a&gt;&lt;!-- m --&gt; (file missing)<br />
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll<br />
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll<br />
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll<br />
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll<br />
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab"&gt;http://www.nvidia.com/content/DriverDow ... eqlab3.cab&lt;/a&gt;&lt;!-- m --&gt;<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.vista.exe<br />
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe<br />
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe<br />
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe<br />
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe<br />
<br />
--<br />
End of file - 9294 bytes<br />
<br />
Any help will be appreciated. Thanks.]]></description>
			<content:encoded><![CDATA[Recently, I have been encountering some kind of problems while searching with google. When I search for something, I get all the results. Then, when I click on any of the links, it does not open that site, but opens some other site which has I suspect has malware content. I did a HijachThis scan and here is the scan.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 10:32:01 AM, on 1/10/2009<br />
Platform: Windows Vista SP1 (WinNT 6.00.1905)<br />
MSIE: Internet Explorer v7.00 (7.00.6001.18000)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Vista Softwares\iTunes\iTunesHelper.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Program Files\Skype\Phone\Skype.exe<br />
C:\Program Files\DAEMON Tools Lite\daemon.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\Vista Softwares\Registry Mechanic\RMTray.exe<br />
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe<br />
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe<br />
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe<br />
C:\Program Files\Skype\Plugin Manager\skypePM.exe<br />
C:\Vista Softwares\System Mechanic Professional\Personal Firewall\ioloFW.exe<br />
C:\Vista Softwares\System Mechanic Professional\AntiVirus\ioloAV.exe<br />
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe<br />
C:\Vista Softwares\System Mechanic Professional\AntiVirus\iAVEmailScanner.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Program Files\Windows Live\Mail\wlmail.exe<br />
C:\Program Files\Opera\Opera.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;!-- m --&gt;<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;!-- m --&gt;<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;!-- m --&gt;<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;!-- m --&gt;&lt;a class="postlink" href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;!-- m --&gt;<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O2 - BHO: (no name) - {64466B8E-20A7-4A4A-AFF4-AAD9CA68B52C} - C:\Program Files\WebMediaViewer\hpmun.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br />
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br />
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [iolo Startup] "C:\Program Files\iolo\Common\Lib\ioloLManager.exe"<br />
O4 - HKLM\..\Run: [iTunesHelper] "C:\Vista Softwares\iTunes\iTunesHelper.exe"<br />
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized<br />
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun<br />
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background<br />
O4 - HKCU\..\Run: [RegistryMechanic] C:\Vista Softwares\Registry Mechanic\RMTray.exe /H<br />
O4 - HKCU\..\Run: [Cognac] C:\Users\Anuj\AppData\Local\Temp\~tmpb.exe<br />
O4 - HKCU\..\Run: [MSFox] C:\Users\Anuj\AppData\Local\Temp\yyy17457.exe<br />
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet<br />
O4 - HKLM\..\Policies\Explorer\Run: [QuickTime Task] C:\Program Files\WebMediaViewer\qttask.exe<br />
O4 - HKLM\..\Policies\Explorer\Run: [VMware hptray] C:\Program Files\WebMediaViewer\hpmon.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - Global Startup: Bluetooth.lnk = ?<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - &lt;!-- m --&gt;&lt;a class="postlink" href="res://C"&gt;res://C&lt;/a&gt;&lt;!-- m --&gt;:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Send image to &amp;Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm<br />
O8 - Extra context menu item: Send page to &amp;Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll<br />
O9 - Extra button: (no name) - {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.iexplorsecurity.com/redirect.php"&gt;http://www.iexplorsecurity.com/redirect.php&lt;/a&gt;&lt;!-- m --&gt; (file missing)<br />
O9 - Extra 'Tools' menuitem: Explorer Security - {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.iexplorsecurity.com/redirect.php"&gt;http://www.iexplorsecurity.com/redirect.php&lt;/a&gt;&lt;!-- m --&gt; (file missing)<br />
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll<br />
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll<br />
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll<br />
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll<br />
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - &lt;!-- m --&gt;&lt;a class="postlink" href="http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab"&gt;http://www.nvidia.com/content/DriverDow ... eqlab3.cab&lt;/a&gt;&lt;!-- m --&gt;<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.vista.exe<br />
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe<br />
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe<br />
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe<br />
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe<br />
<br />
--<br />
End of file - 9294 bytes<br />
<br />
Any help will be appreciated. Thanks.]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Adding Users to Groups]]></title>
			<link>http://www.antisource.com/forums/showthread.php?tid=4274</link>
			<pubDate>Fri, 19 Dec 2008 14:42:09 +0000</pubDate>
			<guid isPermaLink="false">http://www.antisource.com/forums/showthread.php?tid=4274</guid>
			<description><![CDATA[I'm new to Symantec Corporate Edition, having taking over from a botched install.  The server is reporting its on version 10.1.6.6000 and when I run the Find Computers, there on version 8.1.0.825<br />
<br />
However, I created a group but this is empty - how do I add the users to group?  Do I need to do this to configure the updates.  I installed the managed edition of the client and pointed it at the server, but I am unable to ge the clients to be displayed in the Symantec System Centre Console, only via the 'Find Computer' utility.  What am I missing?<br />
<br />
Regards,<br />
<br />
Michael]]></description>
			<content:encoded><![CDATA[I'm new to Symantec Corporate Edition, having taking over from a botched install.  The server is reporting its on version 10.1.6.6000 and when I run the Find Computers, there on version 8.1.0.825<br />
<br />
However, I created a group but this is empty - how do I add the users to group?  Do I need to do this to configure the updates.  I installed the managed edition of the client and pointed it at the server, but I am unable to ge the clients to be displayed in the Symantec System Centre Console, only via the 'Find Computer' utility.  What am I missing?<br />
<br />
Regards,<br />
<br />
Michael]]></content:encoded>
		</item>
	</channel>
</rss>
