<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>Safer Networking Forums</title>
		<link>http://forums.spybot.info/</link>
		<description><![CDATA[Support forums for Spybot-S&amp;D and other products by Safer Networking Limited]]></description>
		<language>en</language>
		<lastBuildDate>Sat, 21 Nov 2009 01:30:15 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://forums.spybot.info/images/misc/rss.jpg</url>
			<title>Safer Networking Forums</title>
			<link>http://forums.spybot.info/</link>
		</image>
		<item>
			<title>taskbar disappears/Hijackthis log attached.</title>
			<link>http://forums.spybot.info/showthread.php?t=53583&amp;goto=newpost</link>
			<pubDate>Fri, 20 Nov 2009 22:18:55 GMT</pubDate>
			<description>Ive got some type of bug that causes my task bar to completelu disappear and thatn I cannot shut doen from Task Manager. I have now had to manually...</description>
			<content:encoded><![CDATA[<div>Ive got some type of bug that causes my task bar to completelu disappear and thatn I cannot shut doen from Task Manager. I have now had to manually turn off then turn back on about 5 times. I've run Spybot, Ad-aware, Superantispyware, and Malewarebytes. Then I have run AVG virus check 2-3 times but after about an hour the taskbar is gone and I have to manually reboot again. Went to <a class="glossarylink" href="http://forums.spybot.info/vbglossar.php?do=showentry&amp;item=Trend+Micro" onmouseover="return overlib('Trend Micro creates antivirus software which, according to the ASC\'s definition, might be regarded as spyware or PUPS (defined as &amp;quot;Technologies [...]...');" onmouseout="return nd();">&#84;&#114;&#101;&#110;&#100; &#77;&#105;&#99;&#114;&#111;</a> and just as the new 7.1 virus check program is about to finish, I get an error and it stops installing. I was able to run a <a class="glossarylink" href="http://forums.spybot.info/vbglossar.php?do=showentry&amp;item=trend+micro" onmouseover="return overlib('Trend Micro creates antivirus software which, according to the ASC\'s definition, might be regarded as spyware or PUPS (defined as &amp;quot;Technologies [...]...');" onmouseout="return nd();">&#116;&#114;&#101;&#110;&#100; &#109;&#105;&#99;&#114;&#111;</a> hijackthis log and here it is.<br />
<br />
Logfile of <a class="glossarylink" href="http://forums.spybot.info/vbglossar.php?do=showentry&amp;item=Trend+Micro" onmouseover="return overlib('Trend Micro creates antivirus software which, according to the ASC\'s definition, might be regarded as spyware or PUPS (defined as &amp;quot;Technologies [...]...');" onmouseout="return nd();">&#84;&#114;&#101;&#110;&#100; &#77;&#105;&#99;&#114;&#111;</a> HijackThis v2.0.2<br />
Scan saved at 4:57:17 PM, on 11/20/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Creative\ShareDLL\CtNotify.exe<br />
C:\Program Files\a la mode\Sched\eSched.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe<br />
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe<br />
C:\WINDOWS\system32\RUNDLL32.EXE<br />
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe<br />
C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe<br />
C:\Program Files\Microsoft IntelliType Pro\itype.exe<br />
C:\Program Files\Creative\ShareDLL\MediaDet.Exe<br />
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
C:\Program Files\AJS Open File Manager\FileAccessManager.exe<br />
C:\Program Files\Eazy-Ware\ezSched.exe<br />
C:\Program Files\Brother\ControlCenter2\brctrcen.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe<br />
C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe<br />
C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Program Files\Creative\PlayCenter2\CTNMRun.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe<br />
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
C:\windows\system32\CTsvcCDA.EXE<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br />
C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe<br />
c:\Program Files\Microsoft SQL Server\MSSQL$ALAMODE\Binn\sqlservr.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\SearchIndexer.exe<br />
C:\Program Files\Java\jre6\bin\jucheck.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE<br />
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE<br />
C:\Program Files\AVG\AVG8\avgcsrvx.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\WINDOWS\system32\SearchProtocolHost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll<br />
O3 - Toolbar: &amp;RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKLM\..\Run: [The Assistant] &quot;C:\Program Files\a la mode\Sched\eSched.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [SSBkgdUpdate] &quot;C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe&quot; -Embedding -boot<br />
O4 - HKLM\..\Run: [RemoteControl] &quot;C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe&quot;<br />
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\windows\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [NeroFilterCheck] C:\windows\system32\NeroCheck.exe<br />
O4 - HKLM\..\Run: [mxomssmenu] &quot;C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe&quot;<br />
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe<br />
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
O4 - HKLM\..\Run: [itype] &quot;C:\Program Files\Microsoft IntelliType Pro\itype.exe&quot;<br />
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [File Access Manager] C:\Program Files\AJS Open File Manager\FileAccessManager.exe<br />
O4 - HKLM\..\Run: [EazyScheduler] C:\Program Files\Eazy-Ware\ezSched.exe<br />
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun<br />
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent<br />
O4 - HKLM\..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [AJS Open File Manager] &quot;C:\Program Files\AJS Open File Manager\fileAccessManager.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] &quot;C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe&quot;<br />
O4 - HKCU\..\Run: [Vidalia] &quot;C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe&quot;<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;<br />
O4 - HKCU\..\Run: [NOMAD Detector] &quot;C:\Program Files\Creative\PlayCenter2\CTNMRun.exe&quot;<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - Global Startup: APC UPS Status.lnk = ?<br />
O4 - Global Startup: Desktop Manager.lnk = C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe<br />
O4 - Global Startup: Privoxy.lnk = C:\Program Files\Vidalia Bundle\Privoxy\privoxy.exe<br />
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html<br />
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html<br />
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html<br />
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html<br />
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html<br />
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html<br />
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html<br />
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html<br />
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O15 - Trusted Zone: <a href="http://*.rapmls.com" target="_blank">http://*.rapmls.com</a><br />
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - <a href="http://support.dell.com/systemprofiler/SysPro.CAB" target="_blank">http://support.dell.com/systemprofiler/SysPro.CAB</a><br />
O16 - DPF: {0854D220-A90A-466D-BC02-6683183802B7} (PrintPreview Class) - <a href="http://nei.fnismls.com/Paragon/Codebase/FNISPrintControl.cab" target="_blank">http://nei.fnismls.com/Paragon/Codeb...intControl.cab</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1199571742828" target="_blank">http://www.update.microsoft.com/wind...?1199571742828</a><br />
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - <a href="http://download.divx.com/player/DivXBrowserPlugin.cab" target="_blank">http://download.divx.com/player/DivXBrowserPlugin.cab</a><br />
O16 - DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} (ContactExtractor Class) - <a href="http://www.facebook.com/controls/contactx.dll" target="_blank">http://www.facebook.com/controls/contactx.dll</a><br />
O16 - DPF: {6DE617B8-49C0-40F8-8118-D2C3741F1C28} (SetTrustedSitesControl.clsReg) - <a href="http://medialaxi.rapmls.com/tools/MlsToTrusted/rapmls/SetTrustedSitesControl.dll" target="_blank">http://medialaxi.rapmls.com/tools/Ml...tesControl.dll</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1200011503734" target="_blank">http://www.update.microsoft.com/micr...?1200011503734</a><br />
O16 - DPF: {A7DB6550-3269-11D4-8C30-0001023CA9DC} (Vault Files Downloader) - <a href="https://vault.alamode.com/cab/vfd.cab" target="_blank">https://vault.alamode.com/cab/vfd.cab</a><br />
O16 - DPF: {F5D98C43-DB16-11CF-8ECA-0000C0FD59C7} (ActiveCGM Control) - <a href="http://maps.cityoffortwayne.org/ACGM/acgm.cab" target="_blank">http://maps.cityoffortwayne.org/ACGM/acgm.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br />
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe<br />
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\windows\system32\CTsvcCDA.EXE<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\windows\system32\spool\drivers\w32x86\3\HPBPRO.EXE<br />
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\windows\system32\spool\drivers\w32x86\3\HPBOID.EXE<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: MaxBackServiceInt - Unknown owner - C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
<br />
--<br />
End of file - 14177 bytes<br />
<br />
<br />
You would save my life if you could help. Thanks, Kurt</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=22">Malware Removal</category>
			<dc:creator>kurtman11</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=53583</guid>
		</item>
		<item>
			<title>Keep getting blue screen</title>
			<link>http://forums.spybot.info/showthread.php?t=53582&amp;goto=newpost</link>
			<pubDate>Fri, 20 Nov 2009 21:40:48 GMT</pubDate>
			<description>I keep getting a blue screen about 5 minutes after a reboot. This is why this message is so short.  I do have a laptop that I can read your responce...</description>
			<content:encoded><![CDATA[<div>I keep getting a blue screen about 5 minutes after a reboot. This is why this message is so short.  I do have a laptop that I can read your responce on.<br />
Here is my log.<br />
Please help...<br />
<br />
Logfile of <a class="glossarylink" href="http://forums.spybot.info/vbglossar.php?do=showentry&amp;item=Trend+Micro" onmouseover="return overlib('Trend Micro creates antivirus software which, according to the ASC\'s definition, might be regarded as spyware or PUPS (defined as &amp;quot;Technologies [...]...');" onmouseout="return nd();">&#84;&#114;&#101;&#110;&#100; &#77;&#105;&#99;&#114;&#111;</a> HijackThis v2.0.2<br />
Scan saved at 2:35:17 PM, on 11/20/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\ehome\ehtray.exe<br />
C:\Program Files\Digital Media Reader\readericon45G.exe<br />
C:\WINDOWS\SOUNDMAN.EXE<br />
C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe<br />
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Microsoft ActiveSync\wcescomm.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
C:\WINDOWS\ehome\RMSysTry.exe<br />
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe<br />
C:\Program Files\Squeezebox\SqueezeTray.exe<br />
C:\PROGRA~1\MICROS~3\rapimgr.exe<br />
C:\Program Files\Portrait Displays\Pivot Software\floater.exe<br />
C:\Program Files\Gateway\EzTune\DTSRVC.exe<br />
C:\WINDOWS\eHome\ehRecvr.exe<br />
C:\WINDOWS\eHome\ehSched.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS<br />
C:\WINDOWS\ehome\RMSvc.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\dllhost.exe<br />
C:\WINDOWS\eHome\ehmsas.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://www.gateway.com/g/startpage.html?Ch=Retail&amp;Br=GTW&amp;Loc=ENG_US&amp;Sys=DTP&amp;M=GM5084" target="_blank">http://www.gateway.com/g/startpage.h...s=DTP&amp;M=GM5084</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.gateway.com/g/startpage.html?Ch=Retail&amp;Br=GTW&amp;Loc=ENG_US&amp;Sys=DTP&amp;M=GM5084" target="_blank">http://www.gateway.com/g/startpage.h...s=DTP&amp;M=GM5084</a><br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe<br />
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe<br />
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe<br />
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE<br />
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe<br />
O4 - HKLM\..\Run: [PivotSoftware] &quot;C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe&quot;<br />
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup<br />
O4 - HKLM\..\Run: [OpwareSE4] &quot;C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe&quot;<br />
O4 - HKLM\..\Run: [SSBkgdUpdate] &quot;C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe&quot; -Embedding -boot<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br />
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKCU\..\Run: [H/PC Connection Agent] &quot;C:\Program Files\Microsoft ActiveSync\wcescomm.exe&quot;<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')<br />
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')<br />
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE<br />
O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe<br />
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe<br />
O4 - Global Startup: Squeezebox Server Tray Tool.lnk = C:\Program Files\Squeezebox\SqueezeTray.exe<br />
O8 - Extra context menu item: &amp;eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll<br />
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll<br />
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - <a href="http://go.microsoft.com/fwlink/?linkid=58813" target="_blank">http://go.microsoft.com/fwlink/?linkid=58813</a><br />
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - <a href="http://support.gateway.com/support/profiler/PCPitStop.CAB" target="_blank">http://support.gateway.com/support/p.../PCPitStop.CAB</a><br />
O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KXHCM10 Control) - <a href="http://192.168.1.149/kxhcm10.ocx" target="_blank">http://192.168.1.149/kxhcm10.ocx</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1225560887703" target="_blank">http://update.microsoft.com/microsof...?1225560887703</a><br />
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - <a href="http://198.182.65.154/activex/AxisCamControl.cab" target="_blank">http://198.182.65.154/activex/AxisCamControl.cab</a><br />
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - <a href="http://h30155.www3.hp.com/ediags/dd/install/guidedsolutions.cab" target="_blank">http://h30155.www3.hp.com/ediags/dd/...dsolutions.cab</a><br />
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} (Java Plug-in 1.5.0_02) - <br />
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.5.0_06) - <br />
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} (Java Plug-in 1.5.0_09) - <br />
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} (Java Plug-in 1.5.0_11) - <br />
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.6.0_01) - <br />
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} (Java Plug-in 1.6.0_02) - <br />
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03) - <br />
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - <br />
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Gateway\EzTune\DTSRVC.exe<br />
O23 - Service: Google Update Service (gupdate1c99228a9244f8) (gupdate1c99228a9244f8) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS<br />
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe<br />
O23 - Service: SqueezeMySQL - Unknown owner - C:\PROGRA~1\SQUEEZ~1\server\Bin\MSWIN3~1\mysqld.exe<br />
O24 - Desktop Component 0: (no name) - <a href="http://banners.wunderground.com/weathersticker/default/language/www/US/AZ/Bisbee.gif" target="_blank">http://banners.wunderground.com/weat.../AZ/Bisbee.gif</a><br />
O24 - Desktop Component 2: (no name) - C:\Documents and Settings\Owner.Media-Desktop\My Documents\My Pictures\Weather Station\icon\Signature Email1.html<br />
<br />
--<br />
End of file - 10210 bytes</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=22">Malware Removal</category>
			<dc:creator>bishouse</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=53582</guid>
		</item>
		<item>
			<title>System Restore-leave it on until advised</title>
			<link>http://forums.spybot.info/showthread.php?t=53579&amp;goto=newpost</link>
			<pubDate>Fri, 20 Nov 2009 16:59:19 GMT</pubDate>
			<description>---Quote--- 
Please do *NOT* turn off System Restore trying to remove an infection. Doing so would only serve to destroy a known restore point (not...</description>
			<content:encoded><![CDATA[<div><div style="margin:20px; margin-top:5px; ">
	<div class="smallfont" style="margin-bottom:2px">Quote:</div>
	<table cellpadding="6" cellspacing="0" border="0" width="100%">
	<tr>
		<td class="alt2">
			<hr />
			
				Please do <b>NOT</b> turn off System Restore trying to remove an infection. Doing so would only serve to destroy a known restore point (not good) and won't remove the malware. Let your helper advise you as to when a System Restore flush is called for.
			
			<hr />
		</td>
	</tr>
	</table>
</div><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">  &quot;BEFORE you POST&quot;(READ this Procedure BEFORE Requesting Assistance) </a><br />
<br />
:secret:A 'dirty' restore is better than none.</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=22">Malware Removal</category>
			<dc:creator>tashi</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=53579</guid>
		</item>
		<item>
			<title>Trojans and hijacked domains</title>
			<link>http://forums.spybot.info/showthread.php?t=53578&amp;goto=newpost</link>
			<pubDate>Fri, 20 Nov 2009 16:35:45 GMT</pubDate>
			<description><![CDATA[I'm back.  I think I cross-infected my laptop from my desktop via an external HDD.  I was dumb. 
Re-read the 'Before you Post'I have downloaded and...]]></description>
			<content:encoded><![CDATA[<div>I'm back.  I think I cross-infected my laptop from my desktop via an external HDD.  I was dumb.<br />
Re-read the 'Before you Post'I have downloaded and run ERUNT.  A lot of domains were hijacked (including the <a class="glossarylink" href="http://forums.spybot.info/vbglossar.php?do=showentry&amp;item=Trend+Micro" onmouseover="return overlib('Trend Micro creates antivirus software which, according to the ASC\'s definition, might be regarded as spyware or PUPS (defined as &amp;quot;Technologies [...]...');" onmouseout="return nd();">&#84;&#114;&#101;&#110;&#100; &#77;&#105;&#99;&#114;&#111;</a> site to download HJT).  I got to it via a google cache.  Thank you for your help.<br />
<br />
Here is the HJT file:<br />
Logfile of <a class="glossarylink" href="http://forums.spybot.info/vbglossar.php?do=showentry&amp;item=Trend+Micro" onmouseover="return overlib('Trend Micro creates antivirus software which, according to the ASC\'s definition, might be regarded as spyware or PUPS (defined as &amp;quot;Technologies [...]...');" onmouseout="return nd();">&#84;&#114;&#101;&#110;&#100; &#77;&#105;&#99;&#114;&#111;</a> HijackThis v2.0.2<br />
Scan saved at 11:29:31 AM, on 11/20/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br />
Boot mode: Safe mode with network support<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\csrss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Citrix\ICA Client\ssonsvr.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Mozilla <a class="glossarylink" href="http://forums.spybot.info/vbglossar.php?do=showentry&amp;item=Firefox" onmouseover="return overlib('Firefox is a free open source web browser. Firefox or Opera are often preferred by users concerned for security because Internet Explorer is targeted...');" onmouseout="return nd();">&#70;&#105;&#114;&#101;&#102;&#111;&#120;</a>\firefox.exe<br />
C:\WINDOWS\system32\E.tmp<br />
C:\WINDOWS\System32\reader_s.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\wbem\wmiprvse.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
C:\WINDOWS\system32\wbem\wmiprvse.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://intranet.mdrobotics.ca/" target="_blank">http://intranet.mdrobotics.ca/</a><br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = <a href="https://wms/certsrv" target="_blank">https://wms/certsrv</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
F3 - REG:win.ini: load=C:\WINDOWS\fonts\services.exe<br />
F3 - REG:win.ini: run=C:\WINDOWS\fonts\services.exe<br />
O1 - Hosts: 74.125.45.100 4-open-davinci.com<br />
O1 - Hosts: 74.125.45.100 securitysoftwarepayments.com<br />
O1 - Hosts: 74.125.45.100 privatesecuredpayments.com<br />
O1 - Hosts: 74.125.45.100 secure.privatesecuredpayments.com<br />
O1 - Hosts: 74.125.45.100 getantivirusplusnow.com<br />
O1 - Hosts: 74.125.45.100 secure-plus-payments.com<br />
O1 - Hosts: 74.125.45.100 <a href="http://www.getantivirusplusnow.com" target="_blank">www.getantivirusplusnow.com</a><br />
O1 - Hosts: 74.125.45.100 <a href="http://www.secure-plus-payments.com" target="_blank">www.secure-plus-payments.com</a><br />
O1 - Hosts: 74.125.45.100 <a href="http://www.getavplusnow.com" target="_blank">www.getavplusnow.com</a><br />
O1 - Hosts: 74.125.45.100 safebrowsing-cache.google.com<br />
O1 - Hosts: 74.125.45.100 <a href="http://www.securesoftwarebill.com" target="_blank">www.securesoftwarebill.com</a><br />
O1 - Hosts: 74.125.45.100 secure.paysecuresystem.com<br />
O1 - Hosts: 74.125.45.100 paysoftbillsolution.com<br />
O1 - Hosts: 89.248.168.186 google.ae<br />
O1 - Hosts: 89.248.168.186 google.as<br />
O1 - Hosts: 89.248.168.186 google.at<br />
O1 - Hosts: 89.248.168.186 google.az<br />
O1 - Hosts: 89.248.168.186 google.ba<br />
O1 - Hosts: 89.248.168.186 google.be<br />
O1 - Hosts: 89.248.168.186 google.bg<br />
O1 - Hosts: 89.248.168.186 google.bs<br />
O1 - Hosts: 89.248.168.186 google.ca<br />
O1 - Hosts: 89.248.168.186 google.cd<br />
O1 - Hosts: 89.248.168.186 google.com.gh<br />
O1 - Hosts: 89.248.168.186 google.com.hk<br />
O1 - Hosts: 89.248.168.186 google.com.jm<br />
O1 - Hosts: 89.248.168.186 google.com.mx<br />
O1 - Hosts: 89.248.168.186 google.com.my<br />
O1 - Hosts: 89.248.168.186 google.com.na<br />
O1 - Hosts: 89.248.168.186 google.com.nf<br />
O1 - Hosts: 89.248.168.186 google.com.ng<br />
O1 - Hosts: 89.248.168.186 google.ch<br />
O1 - Hosts: 89.248.168.186 google.com.np<br />
O1 - Hosts: 89.248.168.186 google.com.pr<br />
O1 - Hosts: 89.248.168.186 google.com.qa<br />
O1 - Hosts: 89.248.168.186 google.com.sg<br />
O1 - Hosts: 89.248.168.186 google.com.tj<br />
O1 - Hosts: 89.248.168.186 google.com.tw<br />
O1 - Hosts: 89.248.168.186 google.dj<br />
O1 - Hosts: 89.248.168.186 google.de<br />
O1 - Hosts: 89.248.168.186 google.dk<br />
O1 - Hosts: 89.248.168.186 google.dm<br />
O1 - Hosts: 89.248.168.186 google.ee<br />
O1 - Hosts: 89.248.168.186 google.fi<br />
O1 - Hosts: 89.248.168.186 google.fm<br />
O1 - Hosts: 89.248.168.186 google.fr<br />
O1 - Hosts: 89.248.168.186 google.ge<br />
O1 - Hosts: 89.248.168.186 google.gg<br />
O1 - Hosts: 89.248.168.186 google.gm<br />
O1 - Hosts: 89.248.168.186 google.gr<br />
O1 - Hosts: 89.248.168.186 google.ht<br />
O1 - Hosts: 89.248.168.186 google.ie<br />
O1 - Hosts: 89.248.168.186 google.im<br />
O1 - Hosts: 89.248.168.186 google.in<br />
O1 - Hosts: 89.248.168.186 google.it<br />
O1 - Hosts: 89.248.168.186 google.ki<br />
O1 - Hosts: 89.248.168.186 google.la<br />
O1 - Hosts: 89.248.168.186 google.li<br />
O1 - Hosts: 89.248.168.186 google.lv<br />
O1 - Hosts: 89.248.168.186 google.ma<br />
O1 - Hosts: 89.248.168.186 google.ms<br />
O1 - Hosts: 89.248.168.186 google.mu<br />
O1 - Hosts: 89.248.168.186 google.mw<br />
O1 - Hosts: 89.248.168.186 google.nl<br />
O1 - Hosts: 89.248.168.186 google.no<br />
O1 - Hosts: 89.248.168.186 google.nr<br />
O1 - Hosts: 89.248.168.186 google.nu<br />
O1 - Hosts: 89.248.168.186 google.pl<br />
O1 - Hosts: 89.248.168.186 google.pn<br />
O1 - Hosts: 89.248.168.186 google.pt<br />
O1 - Hosts: 89.248.168.186 google.ro<br />
O1 - Hosts: 89.248.168.186 google.ru<br />
O1 - Hosts: 89.248.168.186 google.rw<br />
O1 - Hosts: 89.248.168.186 google.sc<br />
O1 - Hosts: 89.248.168.186 google.se<br />
O1 - Hosts: 89.248.168.186 google.sh<br />
O1 - Hosts: 89.248.168.186 google.si<br />
O1 - Hosts: 89.248.168.186 google.sm<br />
O1 - Hosts: 89.248.168.186 google.sn<br />
O1 - Hosts: 89.248.168.186 google.st<br />
O1 - Hosts: 89.248.168.186 google.tl<br />
O1 - Hosts: 89.248.168.186 google.tm<br />
O1 - Hosts: 89.248.168.186 google.tt<br />
O1 - Hosts: 89.248.168.186 google.us<br />
O1 - Hosts: 89.248.168.186 google.vu<br />
O1 - Hosts: 89.248.168.186 google.ws<br />
O1 - Hosts: 89.248.168.186 google.co.ck<br />
O1 - Hosts: 89.248.168.186 google.co.id<br />
O1 - Hosts: 89.248.168.186 google.co.il<br />
O1 - Hosts: 89.248.168.186 google.co.in<br />
O1 - Hosts: 89.248.168.186 google.co.jp<br />
O1 - Hosts: 89.248.168.186 google.co.kr<br />
O1 - Hosts: 89.248.168.186 google.co.ls<br />
O1 - Hosts: 89.248.168.186 google.co.ma<br />
O1 - Hosts: 89.248.168.186 google.co.nz<br />
O1 - Hosts: 89.248.168.186 google.co.tz<br />
O1 - Hosts: 89.248.168.186 google.co.ug<br />
O1 - Hosts: 89.248.168.186 google.co.uk<br />
O1 - Hosts: 89.248.168.186 google.co.za<br />
O1 - Hosts: 89.248.168.186 google.co.zm<br />
O1 - Hosts: 89.248.168.186 google.com<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll<br />
O4 - HKLM\..\Run: [16553] C:\WINDOWS\system32\E.tmp.exe<br />
O4 - HKLM\..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe<br />
O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe<br />
O4 - HKLM\..\RunOnce: [SpybotDeletingA3525] command /c del &quot;C:\WINDOWS\ujeciwiq.dll_old&quot;<br />
O4 - HKLM\..\RunOnce: [SpybotDeletingC3239] cmd /c del &quot;C:\WINDOWS\ujeciwiq.dll_old&quot;<br />
O4 - HKCU\..\Run: [photo_id] C:\Documents and Settings\AALLEN\photo_id.exe<br />
O4 - HKCU\..\Run: [cximddl] C:\WINDOWS\system32\ldfrmmd.exe<br />
O4 - HKCU\..\Run: [shccde] C:\WINDOWS\system32\winssled.exe<br />
O4 - HKCU\..\Run: [qaswww] C:\WINDOWS\system32\jdsuml.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [sqlpdro] C:\WINDOWS\system32\providd.exe<br />
O4 - HKCU\..\RunOnce: [SpybotDeletingB3242] command /c del &quot;C:\WINDOWS\ujeciwiq.dll_old&quot;<br />
O4 - HKCU\..\RunOnce: [SpybotDeletingD2525] cmd /c del &quot;C:\WINDOWS\ujeciwiq.dll_old&quot;<br />
O4 - HKLM\..\Policies\Explorer\Run: [exec] C:\WINDOWS\fonts\services.exe<br />
O4 - HKUS\S-1-5-18\..\Run: [reader_s] C:\Documents and Settings\AALLEN\reader_s.exe (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [reader_s] C:\Documents and Settings\AALLEN\reader_s.exe (User 'Default user')<br />
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE<br />
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br />
O4 - Global Startup: Notification Viewer.lnk = Jeeves\Notify\jnv_client.exe<br />
O4 - Global Startup: Notify.lnk = C:\Novell\GroupWise\notify.exe<br />
O4 - Global Startup: Novell iFolder.lnk = C:\Program Files\Novell\iFolder\trayapp.exe<br />
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present<br />
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a href="http://go.microsoft.com/fwlink/?linkid=39204" target="_blank">http://go.microsoft.com/fwlink/?linkid=39204</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1188926245703" target="_blank">http://www.update.microsoft.com/micr...?1188926245703</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1188926235281" target="_blank">http://www.update.microsoft.com/micr...?1188926235281</a><br />
O16 - DPF: {CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.3.1_02) - <a href="http://www.weeklytime.com/WFC/plugins/j2re-1_3_1_02-win.exe" target="_blank">http://www.weeklytime.com/WFC/plugin...3_1_02-win.exe</a><br />
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ds.mda.ca<br />
O17 - HKLM\Software\..\Telephony: DomainName = ds.mda.ca<br />
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ds.mda.ca<br />
O20 - AppInit_DLLs: C:\WINDOWS\system32\rdolib.dll<br />
O20 - Winlogon Notify: LCredMgr - C:\Program Files\Novell\CASA\bin\lcredmgr.dll<br />
O20 - Winlogon Notify: nzrNotifier - C:\WINDOWS\SYSTEM32\nzrNotifier.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: FCI - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: <a class="glossarylink" href="http://forums.spybot.info/vbglossar.php?do=showentry&amp;item=McAfee" onmouseover="return overlib('McAfee creates antivirus software which, according to the ASC\'s definition, might be regarded as spyware or PUPS (defined as &amp;quot;Technologies [...]...');" onmouseout="return nd();">&#77;&#99;&#65;&#102;&#101;&#101;</a> Framework Service (McAfeeFramework) - <a class="glossarylink" href="http://forums.spybot.info/vbglossar.php?do=showentry&amp;item=McAfee" onmouseover="return overlib('McAfee creates antivirus software which, according to the ASC\'s definition, might be regarded as spyware or PUPS (defined as &amp;quot;Technologies [...]...');" onmouseout="return nd();">&#77;&#99;&#65;&#102;&#101;&#101;</a>, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe<br />
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe<br />
O23 - Service: Novell Identity Store - Novell, Inc - C:\Program Files\Novell\CASA\bin\micasad.exe<br />
O23 - Service: Novell ZENworks Agent Service - Novell, Inc. - C:\Program Files\Novell\ZENworks\bin\ZenworksWindowsService.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: Novell ZENworks Remote Management powered by VNC (nzwinvnc) - Novell, Inc. - C:\Program Files\Novell\ZENworks\bin\nzrWinVNC.exe<br />
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe<br />
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe<br />
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe<br />
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe<br />
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe<br />
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe<br />
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe<br />
O23 - Service: Quest Resource Updating Agent (Vmover.exe) - Quest Software - C:\WINDOWS\System32\Vmover.exe<br />
O23 - Service: Novell ZENworks Pre Agent (ZENPreAgent) - Unknown owner - C:\WINDOWS\novell\zenworks\bin\ZENPreAgent.exe<br />
O23 - Service: Novell ZENworks Pre Agent (ZENPreAgent) - Unknown owner - C:\WINDOWS\novell\zenworks\bin\ZENPreAgent.exe<br />
<br />
--<br />
End of file - 13628 bytes</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=22">Malware Removal</category>
			<dc:creator>synchrotron</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=53578</guid>
		</item>
		<item>
			<title>W32.IRCbot.Gen removal problem then cannot reboot my computer normally</title>
			<link>http://forums.spybot.info/showthread.php?t=53576&amp;goto=newpost</link>
			<pubDate>Fri, 20 Nov 2009 15:21:15 GMT</pubDate>
			<description>hey guys, my Symantec Antivirus detected this trojan (W32.IRCbot.Gen) in my WindowsXP\System32.   I followed instructions laid down by Norton: 
1)...</description>
			<content:encoded><![CDATA[<div>hey guys, my Symantec Antivirus detected this trojan (W32.IRCbot.Gen) in my WindowsXP\System32.   I followed instructions laid down by Norton:<br />
1) Turn off Systems Restore<br />
2) Update my NAV<br />
3) Do a full scan<br />
I scanned with NAV/Spybot/ Malwarebytes but was unable to remove the virus.  <br />
Hence, I shut down my computer and tried to go through step 3) via safe mode.  Same problem but this time much worse because now when my computer starts on up, theres these five options on my screen. <br />
<br />
it says -Safe Mode<br />
-Safe Mode with Networking<br />
-Safe Mode with Command Prompt<br />
<br />
-Last known Good Configuration (your most recent settings that worked) <br />
-Start Windows Normally.<br />
<br />
I've clicked on last know good configuration or start windows normall and after several seconds where it looked like it was gonna work, it just goes back to the same screen.    Normal Windows can't open.  However, I was only able to open via safe mode.<br />
<br />
What in the world do I need to do to get my computer up and running normally again? <br />
<br />
Please help me!</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=22">Malware Removal</category>
			<dc:creator>GUMPY</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=53576</guid>
		</item>
		<item>
			<title>malware infected pc</title>
			<link>http://forums.spybot.info/showthread.php?t=53575&amp;goto=newpost</link>
			<pubDate>Fri, 20 Nov 2009 13:23:01 GMT</pubDate>
			<description>Hi there  I think my pc is infected with malwares. please help. please reply. 
 
 
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 6:46:47...</description>
			<content:encoded><![CDATA[<div>Hi there  I think my pc is infected with malwares. please help. please reply.<br />
<br />
<br />
Logfile of <a class="glossarylink" href="http://forums.spybot.info/vbglossar.php?do=showentry&amp;item=Trend+Micro" onmouseover="return overlib('Trend Micro creates antivirus software which, according to the ASC\'s definition, might be regarded as spyware or PUPS (defined as &amp;quot;Technologies [...]...');" onmouseout="return nd();">&#84;&#114;&#101;&#110;&#100; &#77;&#105;&#99;&#114;&#111;</a> HijackThis v2.0.2<br />
Scan saved at 6:46:47 PM, on 11/20/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18372)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\AVG\AVG9\avgchsvx.exe<br />
C:\Program Files\AVG\AVG9\avgrsx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\AVG\AVG9\avgcsrvx.exe<br />
C:\WINDOWS\explorer.exe<br />
C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
C:\WINDOWS\system32\nyviv.exe<br />
C:\Program Files\PowerISO\PWRISOVM.EXE<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\AVerTV\QuickTV.exe<br />
C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
C:\WINDOWS\system32\crypserv.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\Program Files\Mozilla <a class="glossarylink" href="http://forums.spybot.info/vbglossar.php?do=showentry&amp;item=Firefox" onmouseover="return overlib('Firefox is a free open source web browser. Firefox or Opera are often preferred by users concerned for security because Internet Explorer is targeted...');" onmouseout="return nd();">&#70;&#105;&#114;&#101;&#102;&#111;&#120;</a>\firefox.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = search.speedbit.com<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL<br />
O2 - BHO: SBCONVERT - {A1056498-D09A-41E4-864B-505EDD640D9E} - C:\Program Files\SpeedBit Video Downloader\Toolbar\SpeedBitVideoDownloader.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (file missing)<br />
O2 - BHO: GrabberObj Class - {FF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRA~1\SPEEDB~1\Toolbar\grabber.dll<br />
O3 - Toolbar: &amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar.dll<br />
O3 - Toolbar: SpeedBit Video Downloader - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - C:\Program Files\SpeedBit Video Downloader\Toolbar\SpeedBitVideoDownloader.dll<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\Run: [Windows Update] C:\WINDOWS\system32\wuaucIt.exe<br />
O4 - HKLM\..\Run: [lare] C:\WINDOWS\system32\nyviv.exe<br />
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br />
O4 - HKLM\..\Run: [riwa] C:\WINDOWS\system32\gourotyz.exe<br />
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE<br />
O4 - HKLM\..\RunServices: [lare] C:\WINDOWS\system32\nyviv.exe<br />
O4 - HKLM\..\RunServices: [riwa] C:\WINDOWS\system32\gourotyz.exe<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKLM\..\Policies\Explorer\Run: [csrcs] C:\WINDOWS\system32\csrcs.exe<br />
O4 - HKUS\S-1-5-18\..\Run: [lare] C:\Documents and Settings\LocalService\Application Data\Microsoft\nyviv.exe (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [lare] C:\Documents and Settings\LocalService\Application Data\Microsoft\nyviv.exe (User 'Default user')<br />
O4 - Global Startup: QuickTV.lnk = C:\Program Files\AVerTV\QuickTV.exe<br />
O8 - Extra context menu item: &amp;Google Search - res://C:\Program Files\Google\googletoolbar.dll/cmsearch.html<br />
O8 - Extra context menu item: Backward &amp;Links - res://C:\Program Files\Google\googletoolbar.dll/cmbacklinks.html<br />
O8 - Extra context menu item: Cac&amp;hed Snapshot of Page - res://C:\Program Files\Google\googletoolbar.dll/cmcache.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Si&amp;milar Pages - res://C:\Program Files\Google\googletoolbar.dll/cmsimilar.html<br />
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\googletoolbar.dll/cmtrans.html<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - <a href="http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab" target="_blank">http://acs.pandasoftware.com/actives.../as2stubie.cab</a><br />
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - <a href="http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab" target="_blank">http://acs.pandasoftware.com/actives.../as2stubie.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...nt/swflash.cab</a><br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe<br />
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe<br />
<br />
--<br />
End of file - 6834 bytes</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=22">Malware Removal</category>
			<dc:creator>yukukuhi</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=53575</guid>
		</item>
		<item>
			<title>win32.agent.wsg</title>
			<link>http://forums.spybot.info/showthread.php?t=53574&amp;goto=newpost</link>
			<pubDate>Fri, 20 Nov 2009 12:35:28 GMT</pubDate>
			<description><![CDATA[// info: Rootkit removal help file 
// copyright: (c) 2008-2009 Safer-Networking Ltd. All rights reserved. 
 
:: RootAlyzer Results 
File:"Unknown...]]></description>
			<content:encoded><![CDATA[<div>// info: Rootkit removal help file<br />
// copyright: (c) 2008-2009 Safer-Networking Ltd. All rights reserved.<br />
<br />
:: RootAlyzer Results<br />
File:&quot;Unknown ADS&quot;,&quot;C:\Windows\winsxs\x86_microsoft-windows-p..rastructureconsumer_31bf3856ad364e35_6.0.6002.18005_none_b5c807ab2d93d829\System Diagnostics.xml: 0v1ieca3Feahez0jAwxjjk5uRh:$DATA&quot;<br />
File:&quot;Unknown ADS&quot;,&quot;C:\Windows\winsxs\x86_microsoft-windows-p..rastructureconsumer_31bf3856ad364e35_6.0.6001.18000_none_b3dc8e9f30720cdd\System Diagnostics.xml: 0v1ieca3Feahez0jAwxjjk5uRh:$DATA&quot;<br />
File:&quot;Unknown ADS&quot;,&quot;C:\Windows\PLA\System\System Diagnostics.xml: 0v1ieca3Feahez0jAwxjjk5uRh:$DATA&quot;<br />
File:&quot;Unknown ADS&quot;,&quot;C:\Windows\Cursors\arrow_n.cur:NEDTA.DAT:$DATA&quot;<br />
File:&quot;No admin in ACL&quot;,&quot;C:\Users\Anita\AppData\Local\Temp\~DF2B3F.tmp&quot;<br />
File:&quot;No admin in ACL&quot;,&quot;C:\Users\Anita\AppData\Local\Temp\~DF3725.tmp&quot;<br />
File:&quot;No admin in ACL&quot;,&quot;C:\Users\Anita\AppData\Local\Temp\~DF3EC5.tmp&quot;<br />
File:&quot;No admin in ACL&quot;,&quot;C:\Users\Anita\AppData\Local\Temp\~DF454A.tmp&quot;<br />
File:&quot;No admin in ACL&quot;,&quot;C:\Users\Anita\AppData\Local\Temp\~DF7982.tmp&quot;<br />
File:&quot;No admin in ACL&quot;,&quot;C:\Users\Anita\AppData\Local\Temp\~DF798C.tmp&quot;<br />
File:&quot;No admin in ACL&quot;,&quot;C:\Users\Anita\AppData\Local\Temp\~DF79D5.tmp&quot;<br />
File:&quot;No admin in ACL&quot;,&quot;C:\Users\Anita\AppData\Local\Temp\~DF79DA.tmp&quot;<br />
File:&quot;No admin in ACL&quot;,&quot;C:\Users\Anita\AppData\Local\Temp\~DF97F7.tmp&quot;<br />
File:&quot;No admin in ACL&quot;,&quot;C:\Users\All Users\Microsoft\OFFICE\DATA\81599.bpc&quot;<br />
File:&quot;No admin in ACL&quot;,&quot;C:\Users\All Users\Microsoft\OFFICE\DATA\OPA12.BAK&quot;<br />
File:&quot;No admin in ACL&quot;,&quot;C:\Users\All Users\Microsoft\OFFICE\DATA\opa12.dat&quot;<br />
File:&quot;Unknown ADS&quot;,&quot;C:\perflogs\System\Diagnostics\20091116-0002\report.xml: Qgrg2rf1Znaluncm1kfl1xla5h:$DATA&quot;<br />
File:&quot;Unknown ADS&quot;,&quot;C:\perflogs\System\Diagnostics\20091115-0001\report.xml: Qgrg2rf1Znaluncm1kfl1xla5h:$DATA&quot;<br />
Directory:&quot;No admin in ACL&quot;,&quot;C:\Users\All Users\Microsoft\OFFICE\DATA&quot;<br />
Directory:&quot;No admin in ACL&quot;,&quot;C:\ProgramData\Microsoft\OFFICE\DATA&quot;</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=22">Malware Removal</category>
			<dc:creator>Anita-1</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=53574</guid>
		</item>
		<item>
			<title>Cannot remove Win32.FraudLoad.edt</title>
			<link>http://forums.spybot.info/showthread.php?t=53573&amp;goto=newpost</link>
			<pubDate>Fri, 20 Nov 2009 11:51:26 GMT</pubDate>
			<description><![CDATA[Hello! 
 
I am have been having a malware problem on my computer for a few weeks now, and it's getting so impeding I really need to remove it! I...]]></description>
			<content:encoded><![CDATA[<div>Hello!<br />
<br />
I am have been having a malware problem on my computer for a few weeks now, and it's getting so impeding I really need to remove it! I believe it originates from a trojan called Win32.fraudload.edt which my spyware recognizes but cannot eliminate because some files are archived. I have attempted in safe mode but the problem persists.<br />
<br />
Here is the HijackLog I just completed after reading the post *BEFORE you POST...*:<br />
<br />
Logfile of <a class="glossarylink" href="http://forums.spybot.info/vbglossar.php?do=showentry&amp;item=Trend+Micro" onmouseover="return overlib('Trend Micro creates antivirus software which, according to the ASC\'s definition, might be regarded as spyware or PUPS (defined as &amp;quot;Technologies [...]...');" onmouseout="return nd();">&#84;&#114;&#101;&#110;&#100; &#77;&#105;&#99;&#114;&#111;</a> HijackThis v2.0.2<br />
Scan saved at 10:39:43, on 20-11-2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Programas\Alwil Software\Avast4\aswUpdSv.exe<br />
C:\Programas\Alwil Software\Avast4\ashServ.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Programas\Ficheiros comuns\LogiShrd\LVMVFM\LVPrcSrv.exe<br />
C:\Programas\Ficheiros comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Programas\Bonjour\mDNSResponder.exe<br />
C:\Programas\Java\jre6\bin\jqs.exe<br />
C:\Programas\Intel\AMT\LMS.exe<br />
C:\Programas\Ficheiros comuns\LogiShrd\LVCOMSER\LVComSer.exe<br />
C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\WINDOWS\system32\WgaTray.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Programas\CyberLink\Shared files\RichVideo.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Programas\Alwil Software\Avast4\ashMaiSv.exe<br />
C:\Programas\Alwil Software\Avast4\ashWebSv.exe<br />
C:\WINDOWS\system32\wbem\wmiapsrv.exe<br />
C:\Programas\Ficheiros comuns\LogiShrd\LVCOMSER\LVComSer.exe<br />
C:\WINDOWS\system32\igfxtray.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
C:\Programas\CyberLink\PowerDVD\PDVDServ.exe<br />
C:\Programas\iTunes\iTunesHelper.exe<br />
C:\Programas\Google\Google Talk\googletalk.exe<br />
C:\Programas\Java\jre6\bin\jusched.exe<br />
C:\Programas\Ficheiros comuns\LogiShrd\LComMgr\Communications_Helper.exe<br />
C:\Programas\Logitech\QuickCam\Quickcam.exe<br />
C:\Programas\Skype\Phone\Skype.exe<br />
C:\Programas\TK8 StickyNotes\TK8StickyNotes.exe<br />
C:\Programas\Messenger\msmsgs.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Programas\iPod\bin\iPodService.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Programas\Ficheiros comuns\Logishrd\LQCVFX\COCIManager.exe<br />
C:\Programas\Skype\Plugin Manager\skypePM.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Programas\Google\Chrome\Application\chrome.exe<br />
C:\Programas\Google\Chrome\Application\chrome.exe<br />
C:\Programas\Google\Chrome\Application\chrome.exe<br />
C:\Programas\Google\Chrome\Application\chrome.exe<br />
C:\Programas\Google\Chrome\Application\chrome.exe<br />
C:\WINDOWS\system32\dwwin.exe<br />
C:\Programas\Spybot - Search &amp; Destroy\SpybotSD.exe<br />
C:\Programas\Avira\AntiVir Desktop\sched.exe<br />
C:\Programas\Avira\AntiVir Desktop\avguard.exe<br />
C:\Programas\Avira\AntiVir Desktop\avgnt.exe<br />
C:\Documents and Settings\MKK\Os meus documentos\Downloads\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.hi5.com/" target="_blank">http://www.hi5.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://toolbar.ask.com/toolbarv/askRedirect?o=101761&amp;gct=&amp;gc=1&amp;q=" target="_blank">http://toolbar.ask.com/toolbarv/askR...1&amp;gct=&amp;gc=1&amp;q=</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = <a href="http://toolbar.ask.com/toolbarv/askRedirect?o=101761&amp;gct=&amp;gc=1&amp;q=" target="_blank">http://toolbar.ask.com/toolbarv/askR...1&amp;gct=&amp;gc=1&amp;q=</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = <a href="http://toolbar.ask.com/toolbarv/askRedirect?o=101761&amp;gct=&amp;gc=1&amp;q=%s" target="_blank">http://toolbar.ask.com/toolbarv/askR...gct=&amp;gc=1&amp;q=%s</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações<br />
R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Programas\AskSearch\bin\DefaultSearch.dll<br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: (no name) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - (no file)<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programas\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O4 - HKLM\..\Run: [IgfxTray] &quot;C:\WINDOWS\system32\igfxtray.exe&quot;<br />
O4 - HKLM\..\Run: [HotKeysCmds] &quot;C:\WINDOWS\system32\hkcmd.exe&quot;<br />
O4 - HKLM\..\Run: [Persistence] &quot;C:\WINDOWS\system32\igfxpers.exe&quot;<br />
O4 - HKLM\..\Run: [RTHDCPL] &quot;RTHDCPL.EXE&quot;<br />
O4 - HKLM\..\Run: [SkyTel] &quot;SkyTel.EXE&quot;<br />
O4 - HKLM\..\Run: [Alcmtr] &quot;ALCMTR.EXE&quot;<br />
O4 - HKLM\..\Run: [NeroFilterCheck] &quot;C:\Programas\Ficheiros comuns\Ahead\Lib\NeroCheck.exe&quot;<br />
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
O4 - HKLM\..\Run: [RemoteControl] &quot;C:\Programas\CyberLink\PowerDVD\PDVDServ.exe&quot;<br />
O4 - HKLM\..\Run: [LanguageShortcut] &quot;C:\Programas\CyberLink\PowerDVD\Language\Language.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Programas\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Programas\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [googletalk] &quot;C:\Programas\Google\Google Talk\googletalk.exe&quot; /autostart<br />
O4 - HKLM\..\Run: [avgnt] &quot;C:\Programas\Avira\AntiVir Desktop\avgnt.exe&quot; /min<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Programas\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [LogitechCommunicationsManager] &quot;C:\Programas\Ficheiros comuns\LogiShrd\LComMgr\Communications_Helper.exe&quot;<br />
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] &quot;C:\Programas\Logitech\QuickCam\Quickcam.exe&quot; /hide<br />
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
O4 - HKCU\..\Run: [Skype] &quot;C:\Programas\Skype\Phone\Skype.exe&quot; /nosplash /minimized<br />
O4 - HKCU\..\Run: [TK8 StickyNotes] &quot;C:\Programas\TK8 StickyNotes\TK8StickyNotes.exe&quot;<br />
O4 - HKCU\..\Run: [MSMSGS] &quot;C:\Programas\Messenger\msmsgs.exe&quot; /background<br />
O4 - HKCU\..\Run: [cuecuf] C:\Documents and Settings\MKK\cuecuf.exe<br />
O4 - HKCU\..\Run: [PopRock] C:\DOCUME~1\MKK\DEFINI~1\Temp\b.exe<br />
O4 - HKCU\..\Run: [laqig] C:\Documents and Settings\MKK\laqig.exe<br />
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User '?')<br />
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User '?')<br />
O4 - HKUS\S-1-5-21-602162358-57989841-1606980848-1003\..\Run: [Skype] &quot;C:\Programas\Skype\Phone\Skype.exe&quot; /nosplash /minimized (User '?')<br />
O4 - HKUS\S-1-5-21-602162358-57989841-1606980848-1003\..\Run: [cuecuf] C:\Documents and Settings\MKK\cuecuf.exe (User '?')<br />
O4 - HKUS\S-1-5-21-602162358-57989841-1606980848-1003\..\Run: [PopRock] C:\DOCUME~1\MKK\DEFINI~1\Temp\b.exe (User '?')<br />
O4 - HKUS\S-1-5-21-602162358-57989841-1606980848-1003\..\Run: [laqig] C:\Documents and Settings\MKK\laqig.exe (User '?')<br />
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User '?')<br />
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')<br />
O4 - S-1-5-21-602162358-57989841-1606980848-1003 Startup: ERUNT AutoBackup.lnk = C:\Programas\ERUNT\AUTOBACK.EXE (User '?')<br />
O4 - Startup: ERUNT AutoBackup.lnk = C:\Programas\ERUNT\AUTOBACK.EXE<br />
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br />
O8 - Extra context menu item: E&amp;xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe<br />
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll<br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHEI~1\Skype\SKYPE4~1.DLL<br />
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Programas\Avira\AntiVir Desktop\sched.exe<br />
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Programas\Avira\AntiVir Desktop\avguard.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programas\Ficheiros comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programas\Alwil Software\Avast4\aswUpdSv.exe<br />
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashServ.exe<br />
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashMaiSv.exe<br />
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashWebSv.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Programas\Bonjour\mDNSResponder.exe<br />
O23 - Service: Google Update Service (gupdate1ca3d14e7ddb56c) (gupdate1ca3d14e7ddb56c) - Google Inc. - C:\Programas\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Serviço iPod (iPod Service) - Apple Inc. - C:\Programas\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programas\Java\jre6\bin\jqs.exe<br />
O23 - Service: Intel(R) Active Management Technology LMS Service (LMS) - Intel - C:\Programas\Intel\AMT\LMS.exe<br />
O23 - Service: LVCOMSer - Logitech Inc. - C:\Programas\Ficheiros comuns\LogiShrd\LVCOMSER\LVComSer.exe<br />
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Programas\Ficheiros comuns\LogiShrd\LVMVFM\LVPrcSrv.exe<br />
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Programas\Ficheiros comuns\LogiShrd\SrvLnch\SrvLnch.exe<br />
O23 - Service: NBService - Nero AG - C:\Programas\Nero\Nero 7\Nero BackItUp\NBService.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Programas\Ficheiros comuns\Ahead\Lib\NMIndexingService.exe<br />
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Programas\CyberLink\Shared files\RichVideo.exe<br />
<br />
--<br />
End of file - 10447 bytes<br />
<br />
<br />
<br />
If you need any other info, just let me know. Thanks!!!</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=22">Malware Removal</category>
			<dc:creator>ltai85</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=53573</guid>
		</item>
		<item>
			<title>SB 64 Bit tauglich</title>
			<link>http://forums.spybot.info/showthread.php?t=53572&amp;goto=newpost</link>
			<pubDate>Fri, 20 Nov 2009 11:01:15 GMT</pubDate>
			<description>Hi Leute man findet einen Haufen Infos zu dem 32 Bit Win7 aber keinerlei zum dem 64 Bit. 
Ich würde gerne umsteigen daher muß ich jetzt gerade alle...</description>
			<content:encoded><![CDATA[<div>Hi Leute man findet einen Haufen Infos zu dem 32 Bit Win7 aber keinerlei zum dem 64 Bit.<br />
Ich würde gerne umsteigen daher muß ich jetzt gerade alle Software und Treiber einzeln abklappern. :devil:</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=15"><![CDATA[Spybot-S&D in deutsch]]></category>
			<dc:creator>Chrishnx246</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=53572</guid>
		</item>
		<item>
			<title>Taskhost.exe</title>
			<link>http://forums.spybot.info/showthread.php?t=53571&amp;goto=newpost</link>
			<pubDate>Fri, 20 Nov 2009 10:49:09 GMT</pubDate>
			<description><![CDATA[I have just upgraded from XP to Windows 7 Pro using PCMover. After rebooting, Spybot S&D reports that it has terminated a malicious software process,...]]></description>
			<content:encoded><![CDATA[<div>I have just upgraded from XP to Windows 7 Pro using PCMover. After rebooting, Spybot S&amp;D reports that it has terminated a malicious software process, filename: taskhost.exe found in: C:\Windows\system 32\. It is identified as CoolWWWSearch.hjg. As far as I can tell, taskhost.exe is crucial to Windows. Should I allow the process to run?</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=4"><![CDATA[Spybot-S&D]]></category>
			<dc:creator>iggyignatius</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=53571</guid>
		</item>
		<item>
			<title>rbot.skp What do I do next?</title>
			<link>http://forums.spybot.info/showthread.php?t=53570&amp;goto=newpost</link>
			<pubDate>Fri, 20 Nov 2009 05:42:53 GMT</pubDate>
			<description>Hi 
FROM MY SPYBOT LOG: 2009 Nov 20: Encountered and terminated Rbot.skp in C:\Program Files\RoughDraft\roughdraft.exe! 
 
I then uninstalled...</description>
			<content:encoded><![CDATA[<div>Hi<br />
FROM MY SPYBOT LOG: 2009 Nov 20: Encountered and terminated Rbot.skp in C:\Program Files\RoughDraft\roughdraft.exe!<br />
<br />
I then uninstalled RoughDraft.<br />
<br />
NOTE: This version of RoughDraft has been on my PC for years and has never given me any trouble before.<br />
<br />
Am I now free of rbot.skp? Was it a false positive? What do I do now?<br />
<br />
Thanks in advance.<br />
<br />
Logfile of <a class="glossarylink" href="http://forums.spybot.info/vbglossar.php?do=showentry&amp;item=Trend+Micro" onmouseover="return overlib('Trend Micro creates antivirus software which, according to the ASC\'s definition, might be regarded as spyware or PUPS (defined as &amp;quot;Technologies [...]...');" onmouseout="return nd();">&#84;&#114;&#101;&#110;&#100; &#77;&#105;&#99;&#114;&#111;</a> HijackThis v2.0.2<br />
Scan saved at 6:04:35 p.m., on 20/11/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br />
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe<br />
C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe<br />
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\ZONELABS\vsmon.exe<br />
C:\Program Files\Canon\CAL\CALMAIN.exe<br />
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe<br />
C:\WINDOWS\ATK0100\HControl.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\Program Files\ASUS\Wireless Console\wcourier.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\WINDOWS\SOUNDMAN.EXE<br />
C:\WINDOWS\ALCMTR.EXE<br />
C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe<br />
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe<br />
C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe<br />
C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe<br />
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe<br />
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe<br />
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe<br />
C:\Program Files\Messenger\msmsgs.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\WINDOWS\ATK0100\ATKOSD.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.asus.com/" target="_blank">http://www.asus.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll<br />
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe<br />
O4 - HKLM\..\Run: [Wireless Console] C:\Program Files\ASUS\Wireless Console\wcourier.exe<br />
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br />
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE<br />
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br />
O4 - HKLM\..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1<br />
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless<br />
O4 - HKLM\..\Run: [EOUApp] C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br />
O4 - HKLM\..\Run: [RemoteControl] &quot;C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe&quot;<br />
O4 - HKLM\..\Run: [ZoneAlarm Client] &quot;C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe&quot;<br />
O4 - HKLM\..\Run: [BCWipeTM Startup] &quot;C:\Program Files\Jetico\BCWipe\BCWipeTM.exe&quot; startup<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [egui] &quot;C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe&quot; /hide /waitservice<br />
O4 - HKCU\..\Run: [MSMSGS] &quot;C:\Program Files\Messenger\msmsgs.exe&quot; /background<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O14 - IERESET.INF: START_PAGE_URL=http://www.asus.com<br />
O15 - Trusted Zone: <a href="http://onecare.live.com" target="_blank">http://onecare.live.com</a><br />
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br />
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe<br />
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe<br />
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe<br />
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: OwnershipProtocol - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe<br />
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br />
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br />
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe<br />
<br />
--<br />
End of file - 7056 bytes</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=22">Malware Removal</category>
			<dc:creator>harry999</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=53570</guid>
		</item>
		<item>
			<title>Not Sure what I got but dont like it!!!</title>
			<link>http://forums.spybot.info/showthread.php?t=53569&amp;goto=newpost</link>
			<pubDate>Fri, 20 Nov 2009 05:24:38 GMT</pubDate>
			<description>Anti virus will not run and computer is very slow!  
 
Any help would be greatful!!! 
 
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at...</description>
			<content:encoded><![CDATA[<div>Anti virus will not run and computer is very slow! <br />
<br />
Any help would be greatful!!!<br />
<br />
Logfile of <a class="glossarylink" href="http://forums.spybot.info/vbglossar.php?do=showentry&amp;item=Trend+Micro" onmouseover="return overlib('Trend Micro creates antivirus software which, according to the ASC\'s definition, might be regarded as spyware or PUPS (defined as &amp;quot;Technologies [...]...');" onmouseout="return nd();">&#84;&#114;&#101;&#110;&#100; &#77;&#105;&#99;&#114;&#111;</a> HijackThis v2.0.2<br />
Scan saved at 12:21:47 AM, on 11/20/2009<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\WINDOWS\system32\CTsvcCDA.EXE<br />
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\system32\HPZipm12.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe<br />
C:\WINDOWS\system32\CTHELPER.EXE<br />
C:\Program Files\Analog Devices\Core\smax4pnp.exe<br />
C:\WINDOWS\system32\dla\tfswctrl.exe<br />
C:\Program Files\Defender Pro\Defender Pro Internet Security 6.0\avp.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Mozilla <a class="glossarylink" href="http://forums.spybot.info/vbglossar.php?do=showentry&amp;item=Firefox" onmouseover="return overlib('Firefox is a free open source web browser. Firefox or Opera are often preferred by users concerned for security because Internet Explorer is targeted...');" onmouseout="return nd();">&#70;&#105;&#114;&#101;&#102;&#111;&#120;</a>\firefox.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Defender Pro\Defender Pro Internet Security 6.0\avp.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Defender Pro\Defender Pro Internet Security 6.0\avz.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\Program Files\Defender Pro\Defender Pro Internet Security 6.0\avz.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.excite.com/" target="_blank">http://www.excite.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html" target="_blank">http://us.rd.yahoo.com/customize/ie/...ch/search.html</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: (no name) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - (no file)<br />
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - (no file)<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search &amp; Destroy\SDHelper.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll<br />
O3 - Toolbar: (no name) - {102BAD8B-CD05-46ff-94FF-A2C1ABD5F7D5} - (no file)<br />
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll<br />
O3 - Toolbar: (no name) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - (no file)<br />
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe<br />
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br />
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE<br />
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe<br />
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe<br />
O4 - HKLM\..\Run: [AVP] &quot;C:\Program Files\Defender Pro\Defender Pro Internet Security 6.0\avp.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&quot; /runcleanupscript<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Defender Pro\Defender Pro Internet Security 6.0\ie_banner_deny.htm<br />
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra button: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll<br />
O9 - Extra 'Tools' menuitem: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll<br />
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Defender Pro\Defender Pro Internet Security 6.0\scieplugin.dll<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search &amp; Destroy\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp;&amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search &amp; Destroy\SDHelper.dll<br />
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - <a href="http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab" target="_blank">http://www.kaspersky.com/kos/eng/par...an_unicode.cab</a><br />
O16 - DPF: {192F9A01-8030-48CE-9BC6-B03DE3E613C6} (PeoplePC Web Installer) - <a href="http://www.peoplepc.com/ppcos/isp60/download/ppcwebi.cab" target="_blank">http://www.peoplepc.com/ppcos/isp60/...ad/ppcwebi.cab</a><br />
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - <a href="http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab" target="_blank">http://housecall65.trendmicro.com/ho...vex/hcImpl.cab</a><br />
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - <a href="http://lads.myspace.com/upload/MySpaceUploader1006.cab" target="_blank">http://lads.myspace.com/upload/MySpaceUploader1006.cab</a><br />
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - <a href="http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab" target="_blank">http://www.ca.com/us/securityadvisor...fo/webscan.cab</a><br />
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} (Java Plug-in 1.6.0_11) - <br />
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} (Java Plug-in 1.6.0_13) - <br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O20 - AppInit_DLLs: C:\PROGRA~1\DEFEND~2\DEFEND~1.0\adialhk.dll<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe (file missing)<br />
O23 - Service: Defender Pro Internet Security (AVP) - Defender Pro - C:\Program Files\Defender Pro\Defender Pro Internet Security 6.0\avz.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE<br />
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe<br />
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe<br />
O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
<br />
--<br />
End of file - 8880 bytes</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=22">Malware Removal</category>
			<dc:creator>CDaddy_20</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=53569</guid>
		</item>
		<item>
			<title>Please help me remove dmime32.dll and components</title>
			<link>http://forums.spybot.info/showthread.php?t=53568&amp;goto=newpost</link>
			<pubDate>Fri, 20 Nov 2009 04:44:23 GMT</pubDate>
			<description>Hello, 
 
I have narrowed down what seems to be the source of my issues with my pc and need help trying to remove this tricky bugger. 
 
The first...</description>
			<content:encoded><![CDATA[<div>Hello,<br />
<br />
I have narrowed down what seems to be the source of my issues with my pc and need help trying to remove this tricky bugger.<br />
<br />
The first things I noticed going wrong was whenever I would go to google and click on an organic listing, I would be hijacked to another page.  Even when I tried to copy and paste the link, as soon as I clicked the right mouse button, the address would change to the hijacked address...<br />
<br />
I have tried to &quot;shred&quot; the file with s&amp;d with no success.  Also, I &quot;fixed&quot; the two files with hijackthis (sorry) to no avail.<br />
<br />
Please assist... here is my HJT log file.  Please let me know if there is anything else you may need.<br />
<br />
Thanks so much!<br />
<br />
<br />
Logfile of <a class="glossarylink" href="http://forums.spybot.info/vbglossar.php?do=showentry&amp;item=Trend+Micro" onmouseover="return overlib('Trend Micro creates antivirus software which, according to the ASC\'s definition, might be regarded as spyware or PUPS (defined as &amp;quot;Technologies [...]...');" onmouseout="return nd();">&#84;&#114;&#101;&#110;&#100; &#77;&#105;&#99;&#114;&#111;</a> HijackThis v2.0.2<br />
Scan saved at 10:26:10 PM, on 11/19/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Google\Update\1.2.183.13\GoogleCrashHandler.exe<br />
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe<br />
C:\WINDOWS\system32\HPZipm12.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
C:\WINDOWS\system32\SearchIndexer.exe<br />
C:\Program Files\Apoint2K\Apoint.exe<br />
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe<br />
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe<br />
C:\Program Files\Microsoft IntelliPoint\ipoint.exe<br />
C:\WINDOWS\AGRSMMSG.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe<br />
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe<br />
C:\Program Files\Apoint2K\Apntex.exe<br />
C:\Program Files\HPQ\shared\hpqwmi.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Documents and Settings\Me\Local Settings\Application Data\Yahoo!\BrowserPlus\2.4.17\BrowserPlusCore.exe<br />
C:\Documents and Settings\Me\Desktop\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.yahoo.com" target="_blank">http://www.yahoo.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html" target="_blank">http://us.rd.yahoo.com/customize/ie/...ch/search.html</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll<br />
O1 - Hosts: 169.254.139.22 HP000D9D039914<br />
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 9\SnagitBHO.dll<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll<br />
O2 - BHO: CodecPlugin Class - {098716A9-0310-4CBE-BD64-B790A9761158} - (no file)<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll<br />
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.7.2.11\IPSBHO.DLL<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.33.0\gears.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [IMJPMIG8.1] &quot;C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE&quot; /Spoil /RemAdvDef /Migration32<br />
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe<br />
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe<br />
O4 - HKLM\..\Run: [UpdateManager] &quot;C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe&quot; /r<br />
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe<br />
O4 - HKLM\..\Run: [Symantec PIF AlertEng] &quot;C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe&quot; /a /m &quot;C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll&quot;<br />
O4 - HKLM\..\Run: [IntelliPoint] &quot;C:\Program Files\Microsoft IntelliPoint\ipoint.exe&quot;<br />
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe<br />
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;<br />
O4 - Startup: AutorunsDisabled<br />
O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe<br />
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present<br />
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present<br />
O8 - Extra context menu item: &amp;Search - ?p=ZNxmk572YYUS<br />
O8 - Extra context menu item: &amp;Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Yahoo! &amp;Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm<br />
O8 - Extra context menu item: Yahoo! &amp;Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm<br />
O8 - Extra context menu item: Yahoo! &amp;SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm<br />
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.33.0\gears.dll<br />
O9 - Extra 'Tools' menuitem: &amp;Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.33.0\gears.dll<br />
O9 - Extra button: Wild Jack Poker - {17709D14-4A02-42c6-B9FA-18C90A851F51} - C:\Microgaming\Poker\wildjackMPP\MPPoker.exe<br />
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe<br />
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe<br />
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe<br />
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=EN_US&amp;c=Q105&amp;bd=pavilion&amp;pf=laptop<br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll<br />
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - <a href="https://webdl.symantec.com/activex/symdlmgr.cab" target="_blank">https://webdl.symantec.com/activex/symdlmgr.cab</a><br />
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - <a href="http://picture.vzw.com/activex/VerizonWirelessUploadControl.cab" target="_blank">http://picture.vzw.com/activex/Veriz...oadControl.cab</a><br />
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - <a href="http://h30155.www3.hp.com/ediags/dd/install/guidedsolutions.cab" target="_blank">http://h30155.www3.hp.com/ediags/dd/...dsolutions.cab</a><br />
O16 - DPF: {A7196C8E-35A5-4FF0-9E46-E28918B5CAF6} (GameDesire Domino) - <a href="http://67.15.101.3/g_bin/eng/domino_2_0_0_32.cab" target="_blank">http://67.15.101.3/g_bin/eng/domino_2_0_0_32.cab</a><br />
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - <a href="https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx" target="_blank">https://h17000.www1.hp.com/ewfrf-JAV...oadManager.ocx</a><br />
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - <a href="http://www.adobe.com/products/acrobat/nos/gp.cab" target="_blank">http://www.adobe.com/products/acrobat/nos/gp.cab</a><br />
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - <a href="https://signin3.valueactive.com/Register/Branding/olr3313/OCX/v1018/flashax.cab" target="_blank">https://signin3.valueactive.com/Regi...18/flashax.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O20 - AppInit_DLLs: C:\WINDOWS\System32\dmime32.dll<br />
O20 - Winlogon Notify: 38a8ec15697 - C:\WINDOWS\System32\dmime32.dll<br />
O20 - Winlogon Notify: __c00A2CC3 - C:\WINDOWS\system32\__c00A2CC3.dat<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Google Update Service (gupdate1c9d517aa5a5782) (gupdate1c9d517aa5a5782) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\shared\hpqwmi.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe<br />
O23 - Service: Norton AntiVirus - Symantec Corporation - C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe<br />
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br />
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe<br />
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
<br />
--<br />
End of file - 12210 bytes</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=22">Malware Removal</category>
			<dc:creator>ericl</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=53568</guid>
		</item>
		<item>
			<title>errorguard</title>
			<link>http://forums.spybot.info/showthread.php?t=53567&amp;goto=newpost</link>
			<pubDate>Fri, 20 Nov 2009 04:27:29 GMT</pubDate>
			<description>When running a scan of my computer errorguard was found and i can not delete any thing. the only fix i have tried is manually deleting the files and...</description>
			<content:encoded><![CDATA[<div>When running a scan of my computer errorguard was found and i can not delete any thing. the only fix i have tried is manually deleting the files and running spybot s&amp;d. Error guard is located on my computer in HKEY_CLASSES_ROOT\Install.Install.1<br />
HKEY_CLASSES_ROOT\Install.Install.1\CLSID<br />
HKEY_CLASSES_ROOT\Install.Install<br />
HKEY_CLASSES_ROOT\Install.Install\CLSID<br />
HKEY_CLASSES_ROOT\Install.Install\CurVer<br />
<br />
Thank you.<br />
<br />
Logfile of <a class="glossarylink" href="http://forums.spybot.info/vbglossar.php?do=showentry&amp;item=Trend+Micro" onmouseover="return overlib('Trend Micro creates antivirus software which, according to the ASC\'s definition, might be regarded as spyware or PUPS (defined as &amp;quot;Technologies [...]...');" onmouseout="return nd();">&#84;&#114;&#101;&#110;&#100; &#77;&#105;&#99;&#114;&#111;</a> HijackThis v2.0.2<br />
Scan saved at 11:03:29 PM, on 11/19/2009<br />
Platform: Windows Vista SP1 (WinNT 6.00.1905)<br />
MSIE: Internet Explorer v7.00 (7.00.6001.18294)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Windows\RtHDVCpl.exe<br />
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe<br />
C:\Program Files\HP\QuickPlay\QPService.exe<br />
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe<br />
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe<br />
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe<br />
C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe<br />
C:\Program Files\McAfee\Common Framework\UdaterUI.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Program Files\MSN Messenger\msnmsgr.exe<br />
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
C:\Program Files\SafeConnect\scClient.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe<br />
C:\Program Files\McAfee\Common Framework\McTray.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\Program Files\Mozilla <a class="glossarylink" href="http://forums.spybot.info/vbglossar.php?do=showentry&amp;item=Firefox" onmouseover="return overlib('Firefox is a free open source web browser. Firefox or Opera are often preferred by users concerned for security because Internet Explorer is targeted...');" onmouseout="return nd();">&#70;&#105;&#114;&#101;&#102;&#111;&#120;</a>\firefox.exe<br />
C:\Program Files\AIM6\aim6.exe<br />
C:\Program Files\AIM6\aolsoftware.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\SpybotSD.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://www.yahoo.com/" target="_blank">http://www.yahoo.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.yahoo.com/" target="_blank">http://www.yahoo.com/</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll<br />
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br />
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe<br />
O4 - HKLM\..\Run: [QPService] &quot;C:\Program Files\HP\QuickPlay\QPService.exe&quot;<br />
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start<br />
O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe<br />
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe<br />
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe<br />
O4 - HKLM\..\Run: [ShStatEXE] &quot;C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE&quot; /STANDALONE<br />
O4 - HKLM\..\Run: [McAfeeUpdaterUI] &quot;C:\Program Files\McAfee\Common Framework\UdaterUI.exe&quot; /StartedFromRunKey<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br />
O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;  -osboot<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [ddoctorv2] &quot;C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe&quot; /P ddoctorv2<br />
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [Yahoo! Pager] &quot;C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE&quot; -quiet<br />
O4 - HKCU\..\Run: [msnmsgr] &quot;C:\Program Files\MSN Messenger\msnmsgr.exe&quot; /background<br />
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - Global Startup: SafeConnect.lnk = ?<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} (Java Plug-in 1.6.0_12) - <br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br />
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe<br />
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe<br />
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe<br />
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe<br />
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: <a class="glossarylink" href="http://forums.spybot.info/vbglossar.php?do=showentry&amp;item=McAfee" onmouseover="return overlib('McAfee creates antivirus software which, according to the ASC\'s definition, might be regarded as spyware or PUPS (defined as &amp;quot;Technologies [...]...');" onmouseout="return nd();">&#77;&#99;&#65;&#102;&#101;&#101;</a> Framework Service (McAfeeFramework) - <a class="glossarylink" href="http://forums.spybot.info/vbglossar.php?do=showentry&amp;item=McAfee" onmouseover="return overlib('McAfee creates antivirus software which, according to the ASC\'s definition, might be regarded as spyware or PUPS (defined as &amp;quot;Technologies [...]...');" onmouseout="return nd();">&#77;&#99;&#65;&#102;&#101;&#101;</a>, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe<br />
O23 - Service: <a class="glossarylink" href="http://forums.spybot.info/vbglossar.php?do=showentry&amp;item=McAfee" onmouseover="return overlib('McAfee creates antivirus software which, according to the ASC\'s definition, might be regarded as spyware or PUPS (defined as &amp;quot;Technologies [...]...');" onmouseout="return nd();">&#77;&#99;&#65;&#102;&#101;&#101;</a> McShield (McShield) - <a class="glossarylink" href="http://forums.spybot.info/vbglossar.php?do=showentry&amp;item=McAfee" onmouseover="return overlib('McAfee creates antivirus software which, according to the ASC\'s definition, might be regarded as spyware or PUPS (defined as &amp;quot;Technologies [...]...');" onmouseout="return nd();">&#77;&#99;&#65;&#102;&#101;&#101;</a>, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe<br />
O23 - Service: <a class="glossarylink" href="http://forums.spybot.info/vbglossar.php?do=showentry&amp;item=McAfee" onmouseover="return overlib('McAfee creates antivirus software which, according to the ASC\'s definition, might be regarded as spyware or PUPS (defined as &amp;quot;Technologies [...]...');" onmouseout="return nd();">&#77;&#99;&#65;&#102;&#101;&#101;</a> Task Manager (McTaskManager) - <a class="glossarylink" href="http://forums.spybot.info/vbglossar.php?do=showentry&amp;item=McAfee" onmouseover="return overlib('McAfee creates antivirus software which, according to the ASC\'s definition, might be regarded as spyware or PUPS (defined as &amp;quot;Technologies [...]...');" onmouseout="return nd();">&#77;&#99;&#65;&#102;&#101;&#101;</a>, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe<br />
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br />
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe<br />
O23 - Service: SafeConnect Manager (SCManager) - Unknown owner - C:\Program Files\SafeConnect\scManager.sys servicestart (file missing)<br />
O23 - Service: SpybotSnD Distributed Testing (SDisTestService) - Safer Networking Limited - C:\Program Files\SDistTest\SDistTestSvc.exe<br />
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe<br />
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br />
<br />
--<br />
End of file - 10085 bytes</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=22">Malware Removal</category>
			<dc:creator>grapedrink</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=53567</guid>
		</item>
		<item>
			<title>Adware.SmartShopper found by MBAM</title>
			<link>http://forums.spybot.info/showthread.php?t=53566&amp;goto=newpost</link>
			<pubDate>Fri, 20 Nov 2009 03:44:18 GMT</pubDate>
			<description><![CDATA[Here's the HJT log. I don't know if this came from HotSpot Shield, which is a banner ad program. 
 
Logfile of Trend Micro HijackThis v2.0.2 
Scan...]]></description>
			<content:encoded><![CDATA[<div>Here's the HJT log. I don't know if this came from HotSpot Shield, which is a banner ad program.<br />
<br />
Logfile of <a class="glossarylink" href="http://forums.spybot.info/vbglossar.php?do=showentry&amp;item=Trend+Micro" onmouseover="return overlib('Trend Micro creates antivirus software which, according to the ASC\'s definition, might be regarded as spyware or PUPS (defined as &amp;quot;Technologies [...]...');" onmouseout="return nd();">&#84;&#114;&#101;&#110;&#100; &#77;&#105;&#99;&#114;&#111;</a> HijackThis v2.0.2<br />
Scan saved at 10:42:24 PM, on 11/19/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\AVG\avgrsx.exe<br />
C:\WINDOWS\system32\CSHelper.exe<br />
C:\Program Files\HotspotShield\bin\openvpnas.exe<br />
C:\Program Files\HotspotShield\HssWPR\hsssrv.exe<br />
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe<br />
C:\Program Files\LogMeIn\x86\RaMaint.exe<br />
C:\Program Files\LogMeIn\x86\LogMeIn.exe<br />
C:\Program Files\LogMeIn\x86\LMIGuardian.exe<br />
C:\Program Files\Mozy\mozybackup.exe<br />
C:\WINDOWS\system32\IoctlSvc.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Logitech\MouseWare\system\em_exec.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe<br />
C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe<br />
C:\Program Files\JRE\bin\jusched.exe<br />
C:\Program Files\Microsoft\ActiveSync\wcescomm.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\LogMeIn\x86\LMIGuardian.exe<br />
C:\PROGRA~1\MICROS~2\ACTIVE~1\rapimgr.exe<br />
C:\Program Files\Belkin\F5D9050\Belkinwcui.exe<br />
C:\Program Files\Mozy\mozystat.exe<br />
C:\Program Files\RSIGuard\RSIGuard.exe<br />
C:\Program Files\ZoneAlarm\zlclient.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe<br />
C:\Program Files\KeyText\KeyText.exe<br />
C:\Program Files\NoteTab\NoteTab.exe<br />
C:\Program Files\Mozilla\Firefox\firefox.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\HotspotShield\bin\openvpntray.exe<br />
C:\WINDOWS\system32\ZoneLabs\vsmon.exe<br />
C:\Program Files\HotspotShield\bin\openvpn.exe<br />
C:\Program Files\HijackThis\HijackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.facebook.com/reqs.php" target="_blank">http://www.facebook.com/reqs.php</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\OrbitDL\orbitcth.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\JRE\bin\jp2ssv.dll<br />
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\HotspotShield\hssie\HssIE.dll<br />
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe<br />
O4 - HKLM\..\Run: [RTHDCPL] &quot;C:\WINDOWS\RTHDCPL.EXE&quot;<br />
O4 - HKLM\..\Run: [LogMeIn GUI] &quot;C:\Program Files\LogMeIn\x86\LogMeInSystray.exe&quot;<br />
O4 - HKLM\..\Run: [PHIME2002ASync] &quot;C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE&quot; /SYNC<br />
O4 - HKLM\..\Run: [PHIME2002A] &quot;C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE&quot; /IMEName<br />
O4 - HKLM\..\Run: [IMJPMIG8.1] &quot;C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE&quot; /Spoil /RemAdvDef /Migration32<br />
O4 - HKLM\..\Run: [StartCCC] &quot;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&quot; MSRun<br />
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe /autorun<br />
O4 - HKLM\..\Run: [UserFaultCheck] &quot;%systemroot%\system32\dumprep&quot; 0 -u<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\JRE\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &quot;C:\Program Files\Malwarebytes\mbam.exe&quot; /runcleanupscript<br />
O4 - HKCU\..\Run: [H/PC Connection Agent] &quot;C:\Program Files\Microsoft\ActiveSync\wcescomm.exe&quot;<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKUS\S-1-5-18\..\RunOnce: [WUAppSetup] C:\Program Files\Common Files\logishrd\WUApp32.exe -v 0x046d -p 0x0992 -f video -m logitech -d 11.5.0.1145 (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\RunOnce: [WUAppSetup] C:\Program Files\Common Files\logishrd\WUApp32.exe -v 0x046d -p 0x0992 -f video -m logitech -d 11.5.0.1145 (User 'Default user')<br />
O4 - Startup: Explorer.lnk = C:\WINDOWS\explorer.exe<br />
O4 - Startup: KeyText.lnk = C:\Program Files\KeyText\KeyText.exe<br />
O4 - Startup: NotePro.lnk = C:\Program Files\NoteTab\NoteTab.exe<br />
O4 - Global Startup: Belkin.lnk = C:\Program Files\Belkin\F5D9050\Belkinwcui.exe<br />
O4 - Global Startup: HotSpot.lnk = C:\Program Files\HotspotShield\bin\openvpntray.exe<br />
O4 - Global Startup: Mozy.lnk = C:\Program Files\Mozy\mozystat.exe<br />
O4 - Global Startup: RSIGuard.lnk = ?<br />
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\ZoneAlarm\zlclient.exe<br />
O8 - Extra context menu item: &amp;Download by Orbit - res://C:\Program Files\OrbitDL\orbitmxt.dll/201<br />
O8 - Extra context menu item: &amp;Grab video by Orbit - res://C:\Program Files\OrbitDL\orbitmxt.dll/204<br />
O8 - Extra context menu item: Add to Google Photos Screensa&amp;ver - res://C:\WINDOWS\system32\GPhotos.scr/200<br />
O8 - Extra context menu item: Do&amp;wnload selected by Orbit - res://C:\Program Files\OrbitDL\orbitmxt.dll/203<br />
O8 - Extra context menu item: Down&amp;load all by Orbit - res://C:\Program Files\OrbitDL\orbitmxt.dll/202<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\ACTIVE~1\INetRepl.dll<br />
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\ACTIVE~1\INetRepl.dll<br />
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\ACTIVE~1\INetRepl.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - <a href="http://support.dell.com/systemprofiler/SysPro.CAB" target="_blank">http://support.dell.com/systemprofiler/SysPro.CAB</a><br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1214611352327" target="_blank">http://www.update.microsoft.com/wind...?1214611352327</a><br />
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - <a href="https://media.pineconeresearch.com/ActiveX/downloadcontrol.cab" target="_blank">https://media.pineconeresearch.com/A...oadcontrol.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - <a href="https://secure.logmein.com/activex/ractrl.cab?lmi=100" target="_blank">https://secure.logmein.com/activex/ractrl.cab?lmi=100</a><br />
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br />
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll<br />
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br />
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe<br />
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\avgwdsvc.exe<br />
O23 - Service: CopySafe Helper Service (CSHelper) - Unknown owner - C:\WINDOWS\system32\CSHelper.exe<br />
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe<br />
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\HotspotShield\bin\openvpnas.exe<br />
O23 - Service: Hotspot Shield Routing Service (HssSrv) - AnchorFree Inc. - C:\Program Files\HotspotShield\HssWPR\hsssrv.exe<br />
O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files\HotspotShield\bin\HssTrayService.EXE<br />
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe<br />
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe<br />
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe<br />
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe<br />
O23 - Service: MozyHome Backup Service (mozybackup) - Mozy, Inc. - C:\Program Files\Mozy\mozybackup.exe<br />
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe<br />
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe<br />
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe<br />
<br />
--<br />
End of file - 9287 bytes</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=22">Malware Removal</category>
			<dc:creator>clamenza</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=53566</guid>
		</item>
	</channel>
</rss>
