<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>Safer-Networking Forums</title>
		<link>http://forums.spybot.info/</link>
		<description><![CDATA[Support forums for Spybot-S&amp;D and other products by Safer-Networking Limited]]></description>
		<language>en</language>
		<lastBuildDate>Thu, 02 Sep 2010 14:11:11 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://forums.spybot.info/images/misc/rss.jpg</url>
			<title>Safer-Networking Forums</title>
			<link>http://forums.spybot.info/</link>
		</image>
		<item>
			<title><![CDATA[quick easy question regarding "browser"]]></title>
			<link>http://forums.spybot.info/showthread.php?t=59302&amp;goto=newpost</link>
			<pubDate>Thu, 02 Sep 2010 07:58:44 GMT</pubDate>
			<description><![CDATA[When I "check for problems", all my entries are categorized as "browser".  Does this label mean that they came through use of my browser, or that the...]]></description>
			<content:encoded><![CDATA[<div>When I &quot;check for problems&quot;, all my entries are categorized as &quot;browser&quot;.  Does this label mean that they came through use of my browser, or that the browser is what they affect?<br />
<br />
[edit] I should note that I did check the tutorial and searched the forums here, to no avail.</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=4"><![CDATA[Spybot-S&D]]></category>
			<dc:creator>musenji</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=59302</guid>
		</item>
		<item>
			<title>Norton Ghost vs Acronis</title>
			<link>http://forums.spybot.info/showthread.php?t=59301&amp;goto=newpost</link>
			<pubDate>Thu, 02 Sep 2010 07:32:34 GMT</pubDate>
			<description><![CDATA[I've been using Acronis for quite long and it's a good backup software for my system. Just some questions over here: 
 
Is Norton Ghost better as...]]></description>
			<content:encoded><![CDATA[<div>I've been using Acronis for quite long and it's a good backup software for my system. Just some questions over here:<br />
<br />
Is Norton Ghost better as compared to Acronis? (I heard it's cloning technology is good)<br />
<br />
What are the pros and cons of using Norton Ghost if I switch to it?<br />
<br />
<br />
Cheers.</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=19">Tavern</category>
			<dc:creator>chewdz</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=59301</guid>
		</item>
		<item>
			<title>Hijack This</title>
			<link>http://forums.spybot.info/showthread.php?t=59299&amp;goto=newpost</link>
			<pubDate>Thu, 02 Sep 2010 05:33:11 GMT</pubDate>
			<description>Hi!  
Can anyone inform me where I would obtain a Hijack This Report. I have a thread in Malware and have been asked for this report. I sent DDS just...</description>
			<content:encoded><![CDATA[<div>Hi! <br />
Can anyone inform me where I would obtain a Hijack This Report. I have a thread in Malware and have been asked for this report. I sent DDS just in case that was what was meant.:sad:<br />
<br />
<a href="http://forums.spybot.info/showthread.php?t=59144" target="_blank">http://forums.spybot.info/showthread.php?t=59144</a></div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=19">Tavern</category>
			<dc:creator>bill1312</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=59299</guid>
		</item>
		<item>
			<title>removed security tool malware but internet not working,slow pc</title>
			<link>http://forums.spybot.info/showthread.php?t=59298&amp;goto=newpost</link>
			<pubDate>Thu, 02 Sep 2010 04:28:39 GMT</pubDate>
			<description><![CDATA[Hi, ihave been infected by the "Security tool" malware and was able to remove using Mbam and spybot in safemode. After removal i can't update either...]]></description>
			<content:encoded><![CDATA[<div>Hi, ihave been infected by the &quot;Security tool&quot; malware and was able to remove using Mbam and spybot in safemode. After removal i can't update either Mbam or spybot getting Error retrieving update file. <br />
<br />
Also my internet browser is not working anymore now. getting page not found error. Though msn and google talk programs are working fine. When it was working i could only open pages where username and passwords are needed e.g email, bank etc. Checked router settings and all is same for both computers.<br />
<br />
Please help,computer is very slow, my dds.txt is below.   <br />
<br />
<br />
DDS (Ver_10-03-17.01) - NTFSx86  <br />
Run by Brian Y at 22:07:10.65 on 01/09/2010<br />
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_17<br />
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.1151.479 [GMT -6:00]<br />
<br />
AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated)   {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}<br />
FW: Avira FireWall *enabled*   {11638345-E4FC-4BEE-BB73-EC754659C5F6}<br />
<br />
============== Running Processes ===============<br />
<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\svchost -k DcomLaunch<br />
svchost.exe<br />
C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe<br />
C:\WINDOWS\System32\svchost.exe -k netsvcs<br />
svchost.exe<br />
svchost.exe<br />
C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
svchost.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe<br />
C:\Program Files\McAfee\Common Framework\FrameworkService.exe<br />
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe<br />
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe<br />
C:\WINDOWS\system32\tcpsvcs.exe<br />
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe<br />
C:\WINDOWS\system32\svchost.exe -k imgsvc<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Apoint2K\Apoint.exe<br />
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe<br />
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br />
C:\Program Files\Apoint2K\Apntex.exe<br />
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe<br />
C:\Program Files\USBToolbox\Res.EXE<br />
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe<br />
C:\WINDOWS\AGRSMMSG.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\McAfee\Common Framework\UdaterUI.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\Program Files\Google\Google Talk\googletalk.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\McAfee\Common Framework\McTray.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Documents and Settings\Brian Y\Local Settings\Application Data\TheWeatherNetwork\WeatherEye\WeatherEye.exe<br />
C:\Documents and Settings\Brian Y\Desktop\dds.exe<br />
<br />
============== Pseudo HJT Report ===============<br />
<br />
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&amp;sourceid=ie7&amp;rls=com.microsoft:en-US&amp;ie=utf8&amp;oe=utf8<br />
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll<br />
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File<br />
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan enterprise\scriptcl.dll<br />
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll<br />
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.5126.1836\swg.dll<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll<br />
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File<br />
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll<br />
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - <br />
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File<br />
uRun: [msnmsgr] &quot;c:\program files\windows live\messenger\msnmsgr.exe&quot; /background<br />
uRun: [googletalk] &quot;c:\program files\google\google talk\googletalk.exe&quot; /autostart<br />
uRun: [swg] &quot;c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe&quot;<br />
uRun: [Google Update] &quot;c:\documents and settings\brian y\local settings\application data\google\update\GoogleUpdate.exe&quot; /c<br />
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe<br />
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search &amp; destroy\TeaTimer.exe<br />
uRun: [On-Access Scanner service] c:\program files\mcafee\virusscan enterprise\Mcshield.exe<br />
uRun: [WeatherEye] c:\documents and settings\brian y\local settings\application data\theweathernetwork\weathereye\WeatherEye.exe<br />
mRun: [Apoint] c:\program files\apoint2k\Apoint.exe<br />
mRun: [ATIModeChange] Ati2mdxx.exe<br />
mRun: [Cpqset] c:\program files\hpq\default settings\cpqset.exe<br />
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe<br />
mRun: [eabconfg.cpl] c:\program files\hpq\quick launch buttons\EabServr.exe /Start<br />
mRun: [USB Storage Toolbox] c:\program files\usbtoolbox\Res.EXE<br />
mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot<br />
mRun: [AGRSMMSG] AGRSMMSG.exe<br />
mRun: [SunJavaUpdateSched] &quot;c:\program files\java\jre6\bin\jusched.exe&quot;<br />
mRun: [Adobe Reader Speed Launcher] &quot;c:\program files\adobe\reader 9.0\reader\Reader_sl.exe&quot;<br />
mRun: [Adobe ARM] &quot;c:\program files\common files\adobe\arm\1.0\AdobeARM.exe&quot;<br />
mRun: [McAfeeUpdaterUI] &quot;c:\program files\mcafee\common framework\UdaterUI.exe&quot; /StartedFromRunKey<br />
StartupFolder: c:\docume~1\briany~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE<br />
IE: Add to Google Photos Screensa&amp;ver<br />
IE: E&amp;xport to Microsoft Excel<br />
IE: Google Sidewiki...<br />
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe<br />
IE: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - c:\program files\yahoo!\messenger\YahooMessenger.exe<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~1\office11\REFIEBAR.DLL<br />
LSP: c:\windows\system32\jjca.dll<br />
DPF: McAfee Wi-FiScan - hxxp://download.mcafee.com/molbin/iss-loc/mwfs/3.1.0.0/WscWlanScannerCtrl.cab<br />
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab<br />
DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} - hxxp://h20278.www2.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB<br />
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll<br />
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://by104fd.bay104.hotmail.msn.com/resources/MsnPUpld.cab<br />
DPF: {5EC7C511-CD0F-42E6-830C-1BD9882F3458} - hxxp://download.ppstream.com/bin/powerplayer.cab<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab<br />
DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5247/mcfscan.cab<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL<br />
Notify: AtiExtEvent - Ati2evxx.dll<br />
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll<br />
Hosts: 127.0.0.1	<a href="http://www.spywareinfo.com" target="_blank">www.spywareinfo.com</a><br />
<br />
================= FIREFOX ===================<br />
<br />
FF - ProfilePath - c:\docume~1\briany~1\applic~1\mozilla\firefox\profiles\4hi6cmi0.default\<br />
FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/accounts/ServiceLogin?service=mail&amp;passive=true&amp;rm=false&amp;continue=http%3A%2F%2Fgmail.google.com%2Fgmail%3Fui%3Dhtml%26zy%3Dl&amp;hl=en<br />
FF - prefs.js: network.proxy.type - 4<br />
FF - plugin: c:\documents and settings\brian y\application data\mozilla\firefox\profiles\4hi6cmi0.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll<br />
FF - plugin: c:\documents and settings\brian y\application data\mozilla\plugins\npgoogletalk.dll<br />
FF - plugin: c:\documents and settings\brian y\application data\mozilla\plugins\npgtpo3dautoplugin.dll<br />
FF - plugin: c:\documents and settings\brian y\local settings\application data\google\update\1.2.183.29\npGoogleOneClick8.dll<br />
FF - plugin: c:\progra~1\yahoo!\common\npyaxmpb.dll<br />
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll<br />
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll<br />
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll<br />
FF - plugin: c:\program files\google\update\1.2.183.17\npGoogleOneClick8.dll<br />
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\NPinfotl.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll<br />
FF - plugin: c:\program files\real\realarcade\plugins\mozilla\npracplug.dll<br />
FF - plugin: c:\program files\tvuplayer\npTVUAx.dll<br />
FF - plugin: c:\program files\veoh networks\veoh\plugins\noreg\NPVeohVersion.dll<br />
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}<br />
<br />
---- FIREFOX POLICIES ----<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;ui.use_native_colors&quot;, true);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;ui.use_native_popup_windows&quot;, false);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;browser.enable_click_image_resizing&quot;, true);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;accessibility.browsewithcaret_shortcut.enabled&quot;, true);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;javascript.options.mem.high_water_mark&quot;, 32);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;javascript.options.mem.gc_frequency&quot;,   1600);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;network.IDN.whitelist.lu&quot;, true);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;network.IDN.whitelist.nu&quot;, true);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;network.IDN.whitelist.nz&quot;, true);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;network.IDN.whitelist.xn--mgbaam7a8h&quot;, true); <br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;network.IDN.whitelist.xn--mgberp4a5d4ar&quot;, true); <br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;network.IDN.whitelist.xn--p1ai&quot;, true);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;network.IDN.whitelist.xn--mgbayh7gpa&quot;, true);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;network.IDN.whitelist.tel&quot;, true);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;network.auth.force-generic-ntlm&quot;, false);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;network.proxy.type&quot;,                  5);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;network.buffer.cache.count&quot;, 24);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;network.buffer.cache.size&quot;,  4096);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;dom.ipc.plugins.timeoutSecs&quot;, 45);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;svg.smil.enabled&quot;, false);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;ui.trackpoint_hack.enabled&quot;, -1);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;browser.formfill.debug&quot;,            false);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;browser.formfill.agedWeight&quot;,       2);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;browser.formfill.bucketSize&quot;,       1);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;browser.formfill.maxTimeGroupings&quot;, 25);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;browser.formfill.timeGroupingSize&quot;, 604800);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;browser.formfill.boundaryWeight&quot;,   25);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;browser.formfill.prefixWeight&quot;,     5);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;accelerometer.enabled&quot;, true);<br />
c:\program files\mozilla firefox\greprefs\all.js - pref(&quot;html5.enable&quot;, false);<br />
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref(&quot;security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref&quot;, true);<br />
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref(&quot;security.ssl.renego_unrestricted_hosts&quot;, &quot;&quot;);<br />
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref(&quot;security.ssl.treat_unsafe_negotiation_as_broken&quot;, false);<br />
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref(&quot;security.ssl.require_safe_negotiation&quot;,  false);<br />
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref(&quot;security.ssl3.rsa_seed_sha&quot;, true);<br />
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref(&quot;app.update.download.backgroundInterval&quot;, 600);<br />
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref(&quot;app.update.url.manual&quot;, &quot;http://www.firefox.com&quot;);<br />
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref(&quot;browser.search.param.yahoo-fr-ja&quot;, &quot;mozff&quot;);<br />
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref(&quot;extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name&quot;, &quot;chrome://browser/locale/browser.properties&quot;);<br />
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref(&quot;extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description&quot;, &quot;chrome://browser/locale/browser.properties&quot;);<br />
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref(&quot;xpinstall.whitelist.add&quot;, &quot;addons.mozilla.org&quot;);<br />
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref(&quot;xpinstall.whitelist.add.36&quot;, &quot;getpersonas.com&quot;);<br />
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref(&quot;lightweightThemes.update.enabled&quot;, true);<br />
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref(&quot;browser.allTabs.previews&quot;, false);<br />
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref(&quot;plugins.hide_infobar_for_outdated_plugin&quot;, false);<br />
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref(&quot;plugins.update.notifyUser&quot;, false);<br />
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref(&quot;toolbar.customization.usesheet&quot;, false);<br />
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref(&quot;dom.ipc.plugins.enabled.nptest.dll&quot;, true);<br />
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref(&quot;dom.ipc.plugins.enabled.npswf32.dll&quot;, true);<br />
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref(&quot;dom.ipc.plugins.enabled.npctrl.dll&quot;, true);<br />
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref(&quot;dom.ipc.plugins.enabled.npqtplugin.dll&quot;, true);<br />
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref(&quot;dom.ipc.plugins.enabled&quot;, false);<br />
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref(&quot;browser.taskbar.previews.enable&quot;, false);<br />
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref(&quot;browser.taskbar.previews.max&quot;, 20);<br />
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref(&quot;browser.taskbar.previews.cachetime&quot;, 20);<br />
<br />
============= SERVICES / DRIVERS ===============<br />
<br />
R0 atiide;atiide;c:\windows\system32\drivers\atiide.sys [2004-11-18 5632]<br />
R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [2005-4-18 155136]<br />
R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [2005-4-18 5248]<br />
R1 mferkdk;VSCore mferkdk;c:\program files\mcafee\virusscan enterprise\mferkdk.sys [2007-10-16 31784]<br />
R1 RapportKELL;RapportKELL;c:\program files\trusteer\rapport\bin\RapportKELL.sys [2010-7-7 59240]<br />
R1 RapportPG;RapportPG;c:\program files\trusteer\rapport\bin\RapportPG.sys [2010-7-7 166632]<br />
R2 McAfeeFramework;McAfee Framework Service;c:\program files\mcafee\common framework\FrameworkService.exe [2010-6-4 103744]<br />
R2 McShield;McAfee McShield;c:\program files\mcafee\virusscan enterprise\Mcshield.exe [2007-10-16 144704]<br />
R2 McTaskManager;McAfee Task Manager;c:\program files\mcafee\virusscan enterprise\VsTskMgr.exe [2007-10-16 54608]<br />
R2 RapportMgmtService;Rapport Management Service;c:\program files\trusteer\rapport\bin\RapportMgmtService.exe [2010-7-7 840936]<br />
R2 vpnagent;Cisco AnyConnect VPN Agent;c:\program files\cisco\cisco anyconnect vpn client\vpnagent.exe [2009-12-17 497856]<br />
R3 mfeavfk;McAfee Inc.;c:\windows\system32\drivers\mfeavfk.sys [2010-6-4 72680]<br />
R3 mfebopk;McAfee Inc.;c:\windows\system32\drivers\mfebopk.sys [2010-6-4 33960]<br />
R3 mfehidk;McAfee Inc.;c:\windows\system32\drivers\mfehidk.sys [2010-6-4 171272]<br />
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-29 135664]<br />
S2 pciinfo;HP Pci Information;\??\c:\docume~1\briany~1\locals~1\temp\hpispz\hpdom\pciinfo.sys --&gt; c:\docume~1\briany~1\locals~1\temp\hpispz\hpdom\pciinfo.sys [?]<br />
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]<br />
S3 MemStPCI;Sony Memory Stick controller (PCI);c:\windows\system32\drivers\memstpci.sys [2006-6-15 26112]<br />
<br />
============== File Associations ===============<br />
<br />
.scr=<br />
<br />
=============== Created Last 30 ================<br />
<br />
2010-08-31 04:44:18	0	d-----w-	c:\docume~1\briany~1\applic~1\Malwarebytes<br />
2010-08-31 04:44:05	38224	----a-w-	c:\windows\system32\drivers\mbamswissarmy.sys<br />
2010-08-31 04:44:02	20952	----a-w-	c:\windows\system32\drivers\mbam.sys<br />
2010-08-30 02:16:25	8192	----a-w-	c:\windows\system32\jjca.dll<br />
<br />
==================== Find3M  ====================<br />
<br />
2010-08-31 00:37:16	0	----a-w-	c:\windows\system32\drivers\lvuvc.hs<br />
2010-08-31 00:37:14	0	----a-w-	c:\windows\system32\drivers\logiflt.iad<br />
2010-07-27 06:30:35	8462336	------w-	c:\windows\system32\dllcache\shell32.dll<br />
2010-07-16 04:19:46	246784	----a-w-	c:\windows\system32\amjcp.dll<br />
2010-07-16 04:19:32	294912	----a-w-	c:\windows\system32\emjcp.dll<br />
2010-06-30 12:31:35	149504	----a-w-	c:\windows\system32\schannel.dll<br />
2010-06-30 12:31:35	149504	------w-	c:\windows\system32\dllcache\schannel.dll<br />
2010-06-23 13:44:04	1851904	----a-w-	c:\windows\system32\win32k.sys<br />
2010-06-23 13:44:04	1851904	------w-	c:\windows\system32\dllcache\win32k.sys<br />
2010-06-23 12:06:51	70656	------w-	c:\windows\system32\dllcache\ie4uinit.exe<br />
2010-06-23 12:06:51	13824	------w-	c:\windows\system32\dllcache\ieudinit.exe<br />
2010-06-21 15:27:11	354304	------w-	c:\windows\system32\dllcache\srv.sys<br />
2010-06-18 13:36:12	3558912	------w-	c:\windows\system32\dllcache\moviemk.exe<br />
2010-06-17 15:12:57	634656	------w-	c:\windows\system32\dllcache\iexplore.exe<br />
2010-06-17 15:11:25	161792	------w-	c:\windows\system32\dllcache\ieakui.dll<br />
2010-06-17 14:03:00	80384	----a-w-	c:\windows\system32\iccvid.dll<br />
2010-06-14 14:31:20	744448	------w-	c:\windows\system32\dllcache\helpsvc.exe<br />
2010-06-14 07:41:45	1172480	----a-w-	c:\windows\system32\msxml3.dll<br />
2010-06-14 07:41:45	1172480	------w-	c:\windows\system32\dllcache\msxml3.dll<br />
2006-03-14 20:31:18	21376	-c--a-w-	c:\windows\inf\hopperp.sys<br />
2005-11-18 01:18:42	774144	-c--a-w-	c:\program files\RngInterstitial.dll<br />
2009-08-16 18:27:39	32768	-csha-w-	c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009081620090817\index.dat<br />
<br />
============= FINISH: 22:10:57.73 ===============</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=22">Malware Removal</category>
			<dc:creator>bri2010</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=59298</guid>
		</item>
		<item>
			<title>Right Media?</title>
			<link>http://forums.spybot.info/showthread.php?t=59297&amp;goto=newpost</link>
			<pubDate>Thu, 02 Sep 2010 02:53:58 GMT</pubDate>
			<description><![CDATA[I'm hoping that someone can shed a little light on a problem that I have been having for quite a while. When I do a scan with Spybot, every week or...]]></description>
			<content:encoded><![CDATA[<div>I'm hoping that someone can shed a little light on a problem that I have been having for quite a while. When I do a scan with Spybot, every week or two I pick up something called Right Media.  Does anyone have any knowledge on what this is or how I may be picking it up.  Along with slowing my machine down extremly and making it sticky, it is very frustrating.<br />
<br />
Many thanks for any help,<br />
<br />
Summer64.</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=17"><![CDATA[Requests for additions to Spybot's detections]]></category>
			<dc:creator>summer64</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=59297</guid>
		</item>
		<item>
			<title>Unknown threat PDM Trojan.Win32.Generic.wcd</title>
			<link>http://forums.spybot.info/showthread.php?t=59296&amp;goto=newpost</link>
			<pubDate>Thu, 02 Sep 2010 01:26:15 GMT</pubDate>
			<description>Kaspersky detected a threat in file C:\WINDOWS\system32\smss.exe However I have been unable to neutralize it with Kaspersky and Spybot does not...</description>
			<content:encoded><![CDATA[<div>Kaspersky detected a threat in file C:\WINDOWS\system32\smss.exe However I have been unable to neutralize it with Kaspersky and Spybot does not recognize it. I ran both in safe mode to no avail. However, in normal mode I can not access Safer Networking which is not a good sign. Let me know your thoughts on the best way to get me clean. Thanks for your assitance.</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=22">Malware Removal</category>
			<dc:creator>Enuf2BDangerous</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=59296</guid>
		</item>
		<item>
			<title>Internet Problems</title>
			<link>http://forums.spybot.info/showthread.php?t=59295&amp;goto=newpost</link>
			<pubDate>Thu, 02 Sep 2010 01:20:18 GMT</pubDate>
			<description>Hey trying to fix my laptop this time 
it seems only firefox will work and i cannot update spybot or download certian things, here are the dds logs 
...</description>
			<content:encoded><![CDATA[<div>Hey trying to fix my laptop this time<br />
it seems only firefox will work and i cannot update spybot or download certian things, here are the dds logs<br />
<br />
<br />
DDS (Ver_10-03-17.01) - NTFSX64  <br />
Run by Roland at 18:16:29.03 on Wed 09/01/2010<br />
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_17<br />
Microsoft Windows 7 Home Premium   6.1.7600.0.1252.1.1033.18.3838.2339 [GMT -7:00]<br />
<br />
<br />
============== Running Processes ===============<br />
<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\svchost.exe -k RPCSS<br />
C:\Windows\system32\atiesrxx.exe<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\atieclxx.exe<br />
C:\Windows\system32\Hpservice.exe<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\system32\WLANExt.exe<br />
C:\Windows\system32\conhost.exe<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe<br />
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files (x86)\Bonjour\mDNSResponder.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation<br />
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe<br />
C:\Program Files (x86)\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe<br />
C:\Program Files (x86)\SMINST\BLService.exe<br />
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe<br />
C:\Windows\system32\svchost.exe -k imgsvc<br />
C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe<br />
C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe<br />
C:\Windows\system32\taskhost.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\system32\WUDFHost.exe<br />
C:\Program Files (x86)\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Program Files\Apoint2K\Apoint.exe<br />
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe<br />
C:\Program Files\IDT\WDM\sttray64.exe<br />
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe<br />
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe<br />
C:\Program Files (x86)\ooVoo\ooVoo.exe<br />
C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe<br />
C:\Program Files (x86)\Air Mouse\Air Mouse\Air Mouse.exe<br />
C:\Program Files\Apoint2K\ApMsgFwd.exe<br />
C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe<br />
C:\Program Files\Apoint2K\Apntex.exe<br />
C:\Windows\system32\conhost.exe<br />
C:\Program Files (x86)\Hp\HP Software Update\hpwuSchd2.exe<br />
C:\Program Files (x86)\iTunes\iTunesHelper.exe<br />
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe<br />
C:\Program Files (x86)\Java\jre6\bin\jusched.exe<br />
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe<br />
C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe<br />
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe<br />
C:\Program Files (x86)\DigitalPersona\Bin\DpAgent.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe<br />
C:\Program Files\DigitalPersona\Bin\DPAgent.exe<br />
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Windows\System32\svchost.exe -k LocalServicePeerNet<br />
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe<br />
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe<br />
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe<br />
C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe<br />
C:\Windows\System32\svchost.exe -k secsvcs<br />
C:\Program Files (x86)\Mozilla Firefox\firefox.exe<br />
C:\Windows\system32\SearchProtocolHost.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Users\Roland\Downloads\dds.scr<br />
C:\Windows\system32\conhost.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
<br />
============== Pseudo HJT Report ===============<br />
<br />
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=91&amp;bd=Pavilion&amp;pf=cnnb<br />
uStart Page = hxxp://www.mystart.com?pr=oovoo2_0<br />
mLocal Page = c:\windows\syswow64\blank.htm<br />
uInternet Settings,ProxyOverride = &lt;local&gt;<br />
uInternet Settings,ProxyServer = http=127.0.0.1:5555<br />
mWinlogon: Userinit=c:\windows\syswow64\Userinit.exe<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll<br />
BHO: DigitalPersona Personal Extension: {395610ae-c624-4f58-b89e-23733ea00f9a} - c:\program files (x86)\digitalpersona\bin\DpOtsPluginIe8.dll<br />
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files (x86)\norton antivirus\engine\16.8.0.41\IPSBHO.DLL<br />
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll<br />
BHO: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files (x86)\msn\toolbar\3.0.0541.0\msneshellx.dll<br />
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files (x86)\ask.com\GenericAskToolbar.dll<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll<br />
TB: Microsoft Live Search Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files (x86)\msn\toolbar\3.0.0541.0\msneshellx.dll<br />
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files (x86)\ask.com\GenericAskToolbar.dll<br />
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File<br />
uRun: [Aim] &quot;c:\program files (x86)\aim\aim.exe&quot; /d locale=en-US<br />
uRun: [HPAdvisor] c:\program files (x86)\hewlett-packard\hp advisor\HPAdvisor.exe autorun=AUTORUN<br />
uRun: [LightScribe Control Panel] c:\program files (x86)\common files\lightscribe\LightScribeControlPanel.exe -hidden<br />
uRun: [msnmsgr] &quot;c:\program files (x86)\windows live\messenger\msnmsgr.exe&quot; /background<br />
uRun: [oovoo.exe] c:\program files (x86)\oovoo\oovoo.exe /minimized<br />
uRun: [vffwprod] c:\users\roland\appdata\local\fwancpykx\kecvwpytssd.exe<br />
uRun: [Google Update] &quot;c:\users\roland\appdata\local\google\update\GoogleUpdate.exe&quot; /c<br />
uRun: [VeohPlugin] &quot;c:\program files (x86)\veoh networks\veohwebplayer\veohwebplayer.exe&quot;<br />
mRun: [Adobe Reader Speed Launcher] &quot;c:\program files (x86)\adobe\reader 9.0\reader\Reader_sl.exe&quot;<br />
mRun: [CLMLServer for HP TouchSmart] &quot;c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\clml\CLMLSvc.exe&quot;<br />
mRun: [DVDAgent] &quot;c:\program files (x86)\hewlett-packard\media\dvd\DVDAgent.exe&quot;<br />
mRun: [HP Software Update] c:\program files (x86)\hp\hp software update\HPWuSchd2.exe<br />
mRun: [iTunesHelper] &quot;c:\program files (x86)\itunes\iTunesHelper.exe&quot;<br />
mRun: [QlbCtrl.exe] c:\program files (x86)\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start<br />
mRun: [QuickTime Task] &quot;c:\program files (x86)\quicktime\QTTask.exe&quot; -atboottime<br />
mRun: [SunJavaUpdateSched] &quot;c:\program files (x86)\java\jre6\bin\jusched.exe&quot;<br />
mRun: [TSMAgent] &quot;c:\program files (x86)\hewlett-packard\touchsmart\media\TSMAgent.exe&quot;<br />
mRun: [TVAgent] &quot;c:\program files (x86)\hewlett-packard\media\tv\TVAgent.exe&quot;<br />
mRun: [UCam_Menu] &quot;c:\program files (x86)\hewlett-packard\media\webcam\muitransfer\muistartmenu.exe&quot; &quot;c:\program files (x86)\hewlett-packard\media\webcam&quot; update &quot;software\hewlett-packard\media\Webcam&quot;<br />
mRun: [UpdateLBPShortCut] &quot;c:\program files (x86)\cyberlink\labelprint\muitransfer\muistartmenu.exe&quot; &quot;c:\program files (x86)\cyberlink\labelprint&quot; updatewithcreateonce &quot;software\cyberlink\labelprint\2.5&quot;<br />
mRun: [UpdateP2GoShortCut] &quot;c:\program files (x86)\cyberlink\power2go\muitransfer\muistartmenu.exe&quot; &quot;c:\program files (x86)\cyberlink\power2go&quot; updatewithcreateonce &quot;software\cyberlink\power2go\6.0&quot;<br />
mRun: [UpdatePDIRShortCut] &quot;c:\program files (x86)\cyberlink\powerdirector\muitransfer\muistartmenu.exe&quot; &quot;c:\program files (x86)\cyberlink\powerdirector&quot; updatewithcreateonce &quot;software\cyberlink\powerdirector\7.0&quot;<br />
mRun: [UpdatePSTShortCut] &quot;c:\program files (x86)\cyberlink\dvd suite\muitransfer\muistartmenu.exe&quot; &quot;c:\program files (x86)\cyberlink\dvd suite&quot; updatewithcreateonce &quot;software\cyberlink\PowerStarter&quot;<br />
mRun: [StartCCC] &quot;c:\program files (x86)\ati technologies\ati.ace\core-static\CLIStart.exe&quot; MSRun<br />
mRun: [WirelessAssistant] c:\program files (x86)\hewlett-packard\hp wireless assistant\HPWAMain.exe<br />
mRun: [DpAgent] c:\program files (x86)\digitalpersona\bin\dpagent.exe<br />
StartupFolder: c:\progra~3\micros~1\windows\startm~1\programs\startup\airmou~1.lnk - c:\program files (x86)\air mouse\air mouse\Air Mouse.exe<br />
mPolicies-explorer: NoActiveDesktop = 1 (0x1)<br />
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)<br />
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)<br />
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~2\micros~2\office12\EXCEL.EXE/3000<br />
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~2\micros~2\office12\ONBttnIE.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\micros~2\office12\REFIEBAR.DLL<br />
DPF: {36299202-09EF-4ABF-ADB9-47C599DBE778} - hxxps://www.hpwindows7upgrade.arvato.com/north_america/Endcustomer/HPProdDetect.cab<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
LSA: Notification Packages = scecli DPPWDFLT<br />
BHO-X64: DigitalPersona Personal Extension: {395610AE-C624-4f58-B89E-23733EA00F9A} - c:\program files\digitalpersona\bin\DpOtsPluginIe8.dll<br />
BHO-X64:     DigitalPersona Personal Extension - No File<br />
TB-X64: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File<br />
TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File<br />
mRun-x64: [Apoint] c:\program files\apoint2k\Apoint.exe<br />
mRun-x64: [SmartMenu] %ProgramFiles%\Hewlett-Packard\HP MediaSmart\SmartMenu.exe<br />
mRun-x64: [SysTrayApp] c:\program files\idt\wdm\sttray64.exe<br />
Hosts: 127.0.0.1	<a href="http://www.spywareinfo.com" target="_blank">www.spywareinfo.com</a><br />
<br />
================= FIREFOX ===================<br />
<br />
FF - ProfilePath - c:\users\roland\appdata\roaming\mozilla\firefox\profiles\ljtvy2q4.default\<br />
FF - prefs.js: browser.search.selectedEngine - Yahoo<br />
FF - prefs.js: browser.startup.homepage - google.com<br />
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&amp;oe=UTF-8&amp;sourceid=navclient&amp;gfns=1&amp;q=<br />
FF - component: c:\program files (x86)\digitalpersona\bin\firefoxext\components\dpffcli.dll<br />
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\ipsffplgn\components\IPSFFPl.dll<br />
FF - plugin: c:\program files (x86)\mozilla firefox\plugins\NPDFusionWebFirefox.dll<br />
FF - plugin: c:\program files (x86)\total immersion\dfusionhomewebplugin\NPDFusionWebFirefox.dll<br />
FF - plugin: c:\users\roland\appdata\local\google\update\1.2.183.29\npGoogleOneClick8.dll<br />
FF - plugin: c:\users\roland\appdata\roaming\facebook\npfbplugin_1_0_1.dll<br />
FF - plugin: c:\users\roland\appdata\roaming\move networks\plugins\npqmp071701000002.dll<br />
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\<br />
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}<br />
<br />
---- FIREFOX POLICIES ----<br />
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref(&quot;network.IDN.whitelist.lu&quot;, true);<br />
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref(&quot;network.IDN.whitelist.nu&quot;, true);<br />
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref(&quot;network.IDN.whitelist.nz&quot;, true);<br />
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref(&quot;network.IDN.whitelist.xn--mgbaam7a8h&quot;, true); <br />
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref(&quot;network.IDN.whitelist.xn--mgberp4a5d4ar&quot;, true); <br />
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref(&quot;network.IDN.whitelist.xn--p1ai&quot;, true);<br />
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref(&quot;network.IDN.whitelist.xn--mgbayh7gpa&quot;, true);<br />
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref(&quot;network.IDN.whitelist.tel&quot;, true);<br />
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref(&quot;security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref&quot;, true);<br />
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref(&quot;security.ssl.renego_unrestricted_hosts&quot;, &quot;&quot;);<br />
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref(&quot;security.ssl.treat_unsafe_negotiation_as_broken&quot;, false);<br />
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref(&quot;security.ssl.require_safe_negotiation&quot;,  false);<br />
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref(&quot;security.ssl3.rsa_seed_sha&quot;, true);<br />
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref(&quot;app.update.url.manual&quot;, &quot;http://www.firefox.com&quot;);<br />
<br />
============= SERVICES / DRIVERS ===============<br />
<br />
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\navx64\1008000.029\SymEFA64.sys [2010-2-2 402992]<br />
R1 BHDrvx64;Symantec Heuristics Driver;c:\windows\system32\drivers\navx64\1008000.029\BHDrvx64.sys [2010-2-2 334384]<br />
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\navx64\1008000.029\cchpx64.sys [2010-2-2 583296]<br />
R1 IDSVia64;IDSVia64;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20100625.001\IDSviA64.sys [2010-6-25 463408]<br />
R2 {55662437-DA8C-40c0-AADA-2C816A897A49};Power Control [2009/08/22 02:50:49];c:\program files (x86)\hewlett-packard\media\dvd\000.fcl [2008-11-28 146928]<br />
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe [2009-12-22 89600]<br />
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-7-1 203264]<br />
R2 hpsrv;HP Service;c:\windows\system32\hpservice.exe [2009-7-8 30520]<br />
R2 Norton AntiVirus;Norton AntiVirus;c:\program files (x86)\norton antivirus\engine\16.8.0.41\ccSvcHst.exe [2010-2-2 117640]<br />
R2 Recovery Service for Windows;Recovery Service for Windows;c:\program files (x86)\sminst\BLService.exe [2009-3-7 365952]<br />
R2 TVCapSvc;TV Background Capture Service (TVBCS);c:\program files (x86)\hewlett-packard\media\tv\kernel\tv\TVCapSvc.exe [2008-11-26 296320]<br />
R2 TVSched;TV Task Scheduler (TVTS);c:\program files (x86)\hewlett-packard\media\tv\kernel\tv\TVSched.exe [2008-11-26 116096]<br />
R3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2009-3-7 228408]<br />
R3 enecir;ENE CIR Receiver;c:\windows\system32\drivers\enecir.sys [2008-1-24 60928]<br />
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-6-10 132656]<br />
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam_x64.sys [2008-3-13 27136]<br />
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt64win7.sys [2009-3-2 187392]<br />
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\navx64\1008000.029\symndisv.sys [2010-2-2 56880]<br />
R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [2009-12-22 34872]<br />
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]<br />
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\microsoft.net\framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]<br />
S3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\drivers\usbaapl64.sys [2009-8-28 49152]<br />
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-3-2 1255736]<br />
<br />
=============== Created Last 30 ================<br />
<br />
2010-09-02 00:06:31	0	d-----w-	c:\programdata\Spybot - Search &amp; Destroy<br />
2010-08-29 10:42:01	68800	----a-w-	c:\windows\system32\drivers\ftdibus.sys<br />
2010-08-29 10:42:01	320840	----a-w-	c:\windows\system32\ftd2xx.dll<br />
2010-08-29 10:42:01	270144	----a-w-	c:\windows\system32\FTLang.dll<br />
2010-08-29 10:42:01	202048	----a-w-	c:\windows\syswow64\ftd2xx.dll<br />
2010-08-29 10:42:01	143680	----a-w-	c:\windows\system32\ftbusui.dll<br />
2010-08-29 10:42:00	0	d-----w-	c:\program files (x86)\KManager<br />
2010-08-27 16:53:09	861184	----a-w-	c:\windows\system32\oleaut32.dll<br />
2010-08-27 16:53:09	571904	----a-w-	c:\windows\syswow64\oleaut32.dll<br />
2010-08-27 16:45:10	0	---ha-w-	c:\users\roland\BITBA32.tmp<br />
2010-08-23 08:04:35	0	d-----w-	c:\programdata\DivX<br />
2010-08-22 09:54:02	0	---ha-w-	c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf<br />
2010-08-18 05:43:42	0	d-----w-	c:\program files (x86)\Air Mouse<br />
2010-08-18 01:15:19	0	d-----w-	c:\program files (x86)\Veoh Networks<br />
2010-08-13 12:07:36	463360	----a-w-	c:\windows\system32\drivers\srv.sys<br />
2010-08-13 12:07:36	404992	----a-w-	c:\windows\system32\drivers\srv2.sys<br />
2010-08-13 12:07:36	162304	----a-w-	c:\windows\system32\drivers\srvnet.sys<br />
2010-08-13 12:07:35	340992	----a-w-	c:\windows\system32\schannel.dll<br />
2010-08-13 12:07:34	224256	----a-w-	c:\windows\syswow64\schannel.dll<br />
2010-08-13 12:07:13	1896832	----a-w-	c:\windows\system32\drivers\tcpip.sys<br />
2010-08-13 12:07:01	5507968	----a-w-	c:\windows\system32\ntoskrnl.exe<br />
2010-08-13 12:07:00	3955080	----a-w-	c:\windows\syswow64\ntkrnlpa.exe<br />
2010-08-13 12:05:46	52224	----a-w-	c:\windows\system32\rtutils.dll<br />
2010-08-13 12:05:46	37376	----a-w-	c:\windows\syswow64\rtutils.dll<br />
2010-08-13 12:05:45	82944	----a-w-	c:\windows\syswow64\iccvid.dll<br />
2010-08-13 12:05:42	3122688	----a-w-	c:\windows\system32\win32k.sys<br />
2010-08-13 12:05:40	1877504	----a-w-	c:\windows\system32\msxml3.dll<br />
2010-08-13 12:05:40	1233920	----a-w-	c:\windows\syswow64\msxml3.dll<br />
2010-08-03 07:53:36	0	d-----w-	c:\program files (x86)\common files\DivX Shared<br />
2010-08-03 07:53:33	0	d-----w-	c:\program files (x86)\DivX<br />
2010-08-03 02:13:17	12867584	----a-w-	c:\windows\syswow64\shell32.dll<br />
<br />
==================== Find3M  ====================<br />
<br />
2010-06-30 07:13:46	1192960	----a-w-	c:\windows\system32\wininet.dll<br />
2010-06-30 06:25:31	978432	----a-w-	c:\windows\syswow64\wininet.dll<br />
2010-06-30 06:25:18	1226240	----a-w-	c:\windows\syswow64\urlmon.dll<br />
2010-06-30 06:22:45	606208	----a-w-	c:\windows\syswow64\mstime.dll<br />
2010-06-30 06:22:34	5971456	----a-w-	c:\windows\syswow64\mshtml.dll<br />
2010-06-30 06:22:33	64512	----a-w-	c:\windows\syswow64\msfeedsbs.dll<br />
2010-06-30 06:21:57	48128	----a-w-	c:\windows\syswow64\jsproxy.dll<br />
2010-06-30 06:21:47	185856	----a-w-	c:\windows\syswow64\iepeers.dll<br />
2010-06-30 06:21:47	176640	----a-w-	c:\windows\syswow64\ieui.dll<br />
2010-06-30 06:21:46	10985472	----a-w-	c:\windows\syswow64\ieframe.dll<br />
2010-06-30 06:21:44	381440	----a-w-	c:\windows\syswow64\iedkcs32.dll<br />
2010-06-30 06:19:16	12800	----a-w-	c:\windows\syswow64\msfeedssync.exe<br />
2010-06-19 06:33:29	3899784	----a-w-	c:\windows\syswow64\ntoskrnl.exe<br />
2009-07-14 05:37:38	31548	----a-w-	c:\windows\inf\perflib\0409\perfd.dat<br />
2009-07-14 05:37:38	31548	----a-w-	c:\windows\inf\perflib\0409\perfc.dat<br />
2009-07-14 05:37:38	291294	----a-w-	c:\windows\inf\perflib\0409\perfi.dat<br />
2009-07-14 05:37:38	291294	----a-w-	c:\windows\inf\perflib\0409\perfh.dat<br />
2009-07-14 04:54:24	174	--sha-w-	c:\program files\desktop.ini<br />
2009-07-14 04:54:24	174	--sha-w-	c:\program files (x86)\desktop.ini<br />
2009-07-14 01:00:34	291294	----a-w-	c:\windows\inf\perflib\0000\perfi.dat<br />
2009-07-14 01:00:34	291294	----a-w-	c:\windows\inf\perflib\0000\perfh.dat<br />
2009-07-14 01:00:32	31548	----a-w-	c:\windows\inf\perflib\0000\perfd.dat<br />
2009-07-14 01:00:32	31548	----a-w-	c:\windows\inf\perflib\0000\perfc.dat<br />
2009-06-10 20:44:08	9633792	--sha-r-	c:\windows\fonts\StaticCache.dat<br />
2009-07-14 05:12:52	245760	--sha-w-	c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\ietldcache\index.dat<br />
2009-07-14 01:39:53	398848	--sha-w-	c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe<br />
2009-07-14 01:14:45	396800	--sha-w-	c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe<br />
<br />
============= FINISH: 18:17:48.14 ===============<br />
<br />
<br />
<br />
<br />
<br />
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.<br />
IF REQUESTED, ZIP IT UP &amp; ATTACH IT<br />
<br />
DDS (Ver_10-03-17.01)<br />
<br />
Microsoft Windows 7 Home Premium <br />
Boot Device: \Device\HarddiskVolume1<br />
Install Date: 12/22/2009 6:41:32 PM<br />
System Uptime: 9/1/2010 5:59:06 PM (1 hours ago)<br />
<br />
Motherboard: Compal |  | 30FB<br />
Processor: AMD Turion(tm) X2 Dual-Core Mobile RM-75 | Socket M2/S1G1 | 2200/200mhz<br />
<br />
==== Disk Partitions =========================<br />
<br />
C: is FIXED (NTFS) - 219 GiB total, 151.529 GiB free.<br />
D: is FIXED (NTFS) - 14 GiB total, 2.124 GiB free.<br />
E: is CDROM ()<br />
F: is Removable<br />
<br />
==== Disabled Device Manager Items =============<br />
<br />
==== System Restore Points ===================<br />
<br />
RP38: 5/5/2010 10:39:29 PM - Scheduled Checkpoint<br />
RP39: 5/5/2010 10:43:41 PM - Windows Modules Installer<br />
RP40: 5/5/2010 10:44:47 PM - Windows Modules Installer<br />
RP41: 5/12/2010 3:49:35 PM - Windows Update<br />
RP42: 5/22/2010 4:31:04 AM - Scheduled Checkpoint<br />
RP43: 5/26/2010 3:38:53 PM - Windows Update<br />
RP44: 6/4/2010 3:10:58 PM - Windows Update<br />
RP45: 6/11/2010 10:16:10 AM - Windows Update<br />
RP46: 6/21/2010 1:51:45 PM - Scheduled Checkpoint<br />
RP47: 6/24/2010 3:00:23 AM - Windows Update<br />
RP48: 6/25/2010 11:05:57 AM - Windows Update<br />
RP49: 6/28/2010 10:20:44 PM - Windows Update<br />
RP50: 7/1/2010 2:05:36 PM - Windows Update<br />
RP51: 7/5/2010 3:07:52 PM - Windows Update<br />
RP52: 7/8/2010 4:26:59 PM - Windows Update<br />
RP53: 7/12/2010 1:08:46 PM - Windows Update<br />
RP54: 7/14/2010 4:08:00 PM - Windows Update<br />
RP55: 7/19/2010 7:27:19 PM - Windows Update<br />
RP57: 7/26/2010 8:21:44 PM - Windows Update<br />
RP58: 7/29/2010 12:30:38 PM - Windows Update<br />
RP59: 8/2/2010 7:11:19 PM - Windows Update<br />
RP60: 8/3/2010 3:00:24 AM - Windows Update<br />
RP61: 8/5/2010 11:15:59 PM - Windows Update<br />
RP62: 8/13/2010 5:05:13 AM - Windows Update<br />
RP63: 8/15/2010 11:23:35 AM - Windows Update<br />
RP64: 8/16/2010 5:25:30 PM - Windows Update<br />
RP65: 8/17/2010 10:43:14 PM - Installed Mobile Mouse Server.<br />
RP66: 8/19/2010 11:20:54 PM - Windows Update<br />
RP67: 8/23/2010 9:51:47 PM - Windows Update<br />
RP68: 8/23/2010 10:39:24 PM - Windows Update<br />
RP69: 8/27/2010 9:43:46 AM - Windows Modules Installer<br />
RP70: 8/27/2010 9:45:07 AM - Windows Modules Installer<br />
RP71: 8/27/2010 9:52:28 AM - Windows Update<br />
RP72: 8/28/2010 3:00:13 AM - Windows Update<br />
RP73: 8/31/2010 3:49:35 PM - Windows Update<br />
<br />
==== Installed Programs ======================<br />
<br />
Acrobat.com<br />
Activation Assistant for the 2007 Microsoft Office suites<br />
ActiveCheck component for HP Active Support Library<br />
Adobe AIR<br />
Adobe Flash Player 10 ActiveX<br />
Adobe Flash Player 10 Plugin<br />
Adobe Reader 9<br />
AIM 7<br />
AMD USB Filter Driver<br />
Apple Application Support<br />
Apple Software Update<br />
Ask Toolbar<br />
AVerMedia TV Tuner Card 1.0.0.3<br />
Bonjour<br />
Catalyst Control Center - Branding<br />
Catalyst Control Center Core Implementation<br />
Catalyst Control Center Graphics Full Existing<br />
Catalyst Control Center Graphics Full New<br />
Catalyst Control Center Graphics Light<br />
Catalyst Control Center Graphics Previews Common<br />
Catalyst Control Center Graphics Previews Vista<br />
Catalyst Control Center InstallProxy<br />
Catalyst Control Center Localization All<br />
ccc-core-static<br />
CCC Help Chinese Standard<br />
CCC Help Chinese Traditional<br />
CCC Help Czech<br />
CCC Help Danish<br />
CCC Help Dutch<br />
CCC Help English<br />
CCC Help Finnish<br />
CCC Help French<br />
CCC Help German<br />
CCC Help Greek<br />
CCC Help Hungarian<br />
CCC Help Italian<br />
CCC Help Japanese<br />
CCC Help Korean<br />
CCC Help Norwegian<br />
CCC Help Polish<br />
CCC Help Portuguese<br />
CCC Help Russian<br />
CCC Help Spanish<br />
CCC Help Swedish<br />
CCC Help Thai<br />
CCC Help Turkish<br />
Compatibility Pack for the 2007 Office system<br />
CyberLink DVD Suite<br />
DivX Web Player<br />
Download Updater (AOL LLC)<br />
ESU for Microsoft Vista<br />
Facebook Plug-In<br />
Full Tilt Poker<br />
Google Chrome<br />
Hondata K-Series ECU Editor<br />
HP Common Access Service Library<br />
HP Customer Experience Enhancements<br />
HP Doc Viewer<br />
HP MediaSmart DVD<br />
HP MediaSmart Music/Photo/Video<br />
HP MediaSmart SlingPlayer<br />
HP MediaSmart TV<br />
HP MediaSmart Webcam<br />
HP MULTIPLE MODEM INSTALLER for VISTA<br />
HP Quick Launch Buttons<br />
HP Support Assistant<br />
HP Total Care Advisor<br />
HP Total Care Setup<br />
HP Update<br />
HP User Guides 0125<br />
HP Wireless Assistant<br />
HPAsset component for HP Active Support Library<br />
IDT Audio<br />
Java(TM) 6 Update 17<br />
Java(TM) 6 Update 7<br />
JMicron JMB38X Flash Media Controller<br />
Juno Preloader<br />
LabelPrint<br />
LightScribe System Software  1.14.17.1<br />
ManyCam 2.4 (remove only)<br />
Microsoft Live Search Toolbar<br />
Microsoft Office 2007 Service Pack 2 (SP2)<br />
Microsoft Office Excel MUI (English) 2007<br />
Microsoft Office Home and Student 2007<br />
Microsoft Office OneNote MUI (English) 2007<br />
Microsoft Office PowerPoint MUI (English) 2007<br />
Microsoft Office PowerPoint Viewer 2007 (English)<br />
Microsoft Office Proof (English) 2007<br />
Microsoft Office Proof (French) 2007<br />
Microsoft Office Proof (Spanish) 2007<br />
Microsoft Office Proofing (English) 2007<br />
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)<br />
Microsoft Office Shared MUI (English) 2007<br />
Microsoft Office Shared Setup Metadata MUI (English) 2007<br />
Microsoft Office Word MUI (English) 2007<br />
Microsoft Silverlight<br />
Microsoft VC9 runtime libraries<br />
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053<br />
Microsoft Visual C++ 2005 Redistributable<br />
Microsoft Works<br />
Mobile Mouse Server<br />
Move Media Player<br />
Mozilla Firefox (3.5.11)<br />
MSXML 4.0 SP2 (KB954430)<br />
MSXML 4.0 SP2 (KB973688)<br />
muvee Reveal<br />
My HP Games<br />
Norton AntiVirus<br />
ooVoo<br />
Power2Go<br />
PowerDirector<br />
QLBCASL<br />
QuickTime<br />
Realtek 8169 8168 8101E 8102E Ethernet Driver<br />
Security Update for 2007 Microsoft Office System (KB2277947)<br />
Security Update for 2007 Microsoft Office System (KB969559)<br />
Security Update for 2007 Microsoft Office System (KB976321)<br />
Security Update for 2007 Microsoft Office System (KB982312)<br />
Security Update for 2007 Microsoft Office System (KB982331)<br />
Security Update for Microsoft Office Excel 2007 (KB982308)<br />
Security Update for Microsoft Office InfoPath 2007 (KB979441)<br />
Security Update for Microsoft Office PowerPoint 2007 (KB982158)<br />
Security Update for Microsoft Office system 2007 (972581)<br />
Security Update for Microsoft Office system 2007 (KB974234)<br />
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)<br />
Security Update for Microsoft Office Word 2007 (KB2251419)<br />
Slingbox - Watch Your TV Anywhere<br />
SlingPlayer<br />
SPORE Creature Creator Trial Edition<br />
Total Immersion D'Fusion Web Plugin<br />
Update for 2007 Microsoft Office System (KB967642)<br />
Update for Microsoft Office 2007 Help for Common Features (KB963673)<br />
Update for Microsoft Office Excel 2007 Help (KB963678)<br />
Update for Microsoft Office OneNote 2007 (KB980729)<br />
Update for Microsoft Office OneNote 2007 Help (KB963670)<br />
Update for Microsoft Office Powerpoint 2007 Help (KB963669)<br />
Update for Microsoft Office Script Editor Help (KB963671)<br />
Update for Microsoft Office Word 2007 Help (KB963665)<br />
VC80CRTRedist - 8.0.50727.762<br />
Veoh Web Player<br />
Windows Live Sign-in Assistant<br />
Windows Live Upload Tool<br />
<br />
==== Event Viewer Messages From Past Week ========<br />
<br />
9/1/2010 5:59:50 PM, Error: Server [2505]  - The server could not bind to the transport \Device\NetBT_Tcpip_{43491B6F-7778-4663-841D-368ED1215613} because another computer on the network has the same name.  The server could not start.<br />
9/1/2010 5:59:50 PM, Error: NetBT [4321]  - The name &quot;ROLAND-PC      :20&quot; could not be registered on the interface with IP address 192.168.1.5. The computer with the IP address 192.168.1.2 did not allow the name to be claimed by this computer.<br />
9/1/2010 5:59:42 PM, Error: NetBT [4321]  - The name &quot;ROLAND-PC      :0&quot; could not be registered on the interface with IP address 192.168.1.5. The computer with the IP address 192.168.1.2 did not allow the name to be claimed by this computer.<br />
9/1/2010 5:39:05 PM, Error: Service Control Manager [7001]  - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:  The dependency service or group failed to start.<br />
9/1/2010 5:39:04 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error &quot;1084&quot; attempting to start the service WSearch with arguments &quot;&quot; in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}<br />
9/1/2010 5:39:04 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error &quot;1084&quot; attempting to start the service WSearch with arguments &quot;&quot; in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}<br />
9/1/2010 5:39:02 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error &quot;1068&quot; attempting to start the service netprofm with arguments &quot;&quot; in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}<br />
9/1/2010 5:39:02 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error &quot;1068&quot; attempting to start the service netman with arguments &quot;&quot; in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}<br />
9/1/2010 5:39:01 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error &quot;1084&quot; attempting to start the service EventSystem with arguments &quot;&quot; in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}<br />
9/1/2010 5:38:55 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error &quot;1084&quot; attempting to start the service ShellHWDetection with arguments &quot;&quot; in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}<br />
9/1/2010 5:38:45 PM, Error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  AFD BHDrvx64 ccHP DfsC discache eeCtrl IDSVia64 NetBIOS NetBT nsiproxy Psched rdbss spldr SRTSPX SymIM SYMTDI tdx Wanarpv6 WfpLwf<br />
9/1/2010 5:38:44 PM, Error: Service Control Manager [7001]  - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error:  The dependency service or group failed to start.<br />
9/1/2010 5:38:44 PM, Error: Service Control Manager [7001]  - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error:  A device attached to the system is not functioning.<br />
9/1/2010 5:38:44 PM, Error: Service Control Manager [7001]  - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error:  A device attached to the system is not functioning.<br />
9/1/2010 5:38:44 PM, Error: Service Control Manager [7001]  - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error:  The dependency service or group failed to start.<br />
9/1/2010 5:38:44 PM, Error: Service Control Manager [7001]  - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error:  The dependency service or group failed to start.<br />
9/1/2010 5:38:44 PM, Error: Service Control Manager [7001]  - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error:  A device attached to the system is not functioning.<br />
9/1/2010 5:38:44 PM, Error: Service Control Manager [7001]  - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error:  The dependency service or group failed to start.<br />
9/1/2010 5:38:44 PM, Error: Service Control Manager [7001]  - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error:  The dependency service or group failed to start.<br />
9/1/2010 5:38:44 PM, Error: Service Control Manager [7001]  - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error:  A device attached to the system is not functioning.<br />
9/1/2010 5:38:44 PM, Error: Service Control Manager [7001]  - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error:  A device attached to the system is not functioning.<br />
<br />
==== End Of File ===========================</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=22">Malware Removal</category>
			<dc:creator>Trust</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=59295</guid>
		</item>
		<item>
			<title>Trojan, like WinSecurityCenter, onboard</title>
			<link>http://forums.spybot.info/showthread.php?t=59294&amp;goto=newpost</link>
			<pubDate>Thu, 02 Sep 2010 01:00:10 GMT</pubDate>
			<description>Just lost my text, why am I being logged-off so quickly? I should compose in notepad or wordpad maybe. Or copy to clipboard. 
After son used late...</description>
			<content:encoded><![CDATA[<div>Just lost my text, why am I being logged-off so quickly? I should compose in notepad or wordpad maybe. Or copy to clipboard.<br />
After son used late 8/29. Came up for me afternoon 8/30. Warnings of keylogger, trojan etc. followed by profuse popups of prompt to but their &quot;fix&quot;. TaskMan ctrl-alt-del flash open/shut but each time left another perf. graph icon in tray (got up to about a dozen). Same w/SpyBot. Turn off delayed with me near panic at intesifying popups but shutdown before I could pull the plug.<br />
Safe mode system restore worked, updated &amp; ran SpyBot, only 3 tracking cookies. Went to here, safer-networking to investigate and it all started over when I got to this forum (really). Hit every F button, esc, combos, etc. then numlock broke it off enough to shutdown again. Restored to earlier still point. Had left it w/o net connection and checked some old email data I needed, then took a break myself. <br />
Later, updated SpyBot again, different, newer but not current (to 8/30) update (weird, same?). No issues. Notice In my SpyBot FAQ #23 (listed as 2nd #22 in list 23 in text) possible CoolWWWSearch.SmartKiller similarity. Downloaded delcwssk fix, unzipped, ran, said file does not exist. Did this twice. File too old? or does the Trojan do this?<br />
No other fixes/tools tried, registry backed up with ERUNT. Have not backed up data yet but will do asap before your response. I will need to disable teatimer then too.  I think only the text DDS is asked for now, but the attach is ready. Thank you very much.<br />
<br />
<br />
DDS (Ver_10-03-17.01) - NTFSx86  <br />
Run by Your Daddy at 18:09:23.99 on Wed 09/01/2010<br />
Internet Explorer: 7.0.5730.13<br />
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.3061.1969 [GMT -4:00]<br />
<br />
AV: McAfee VirusScan *On-access scanning enabled* (Outdated)   {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}<br />
FW: McAfee Personal Firewall *enabled*   {94894B63-8C7F-4050-BDA4-813CA00DA3E8}<br />
<br />
============== Running Processes ===============<br />
<br />
C:\WINDOWS\system32\svchost -k DcomLaunch<br />
svchost.exe<br />
C:\WINDOWS\System32\svchost.exe -k netsvcs<br />
svchost.exe<br />
svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
svchost.exe<br />
C:\WINDOWS\system32\dldtcoms.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br />
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe<br />
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br />
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
C:\Program Files\McAfee\MPF\MPFSrv.exe<br />
C:\Program Files\McAfee\MSK\MskSrver.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe<br />
c:\PROGRA~1\mcafee.com\agent\mcagent.exe<br />
C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br />
C:\WINDOWS\system32\svchost.exe -k imgsvc<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\Program Files\Dell V305\dldtmon.exe<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files\Digital Line Detect\DLG.exe<br />
C:\Program Files\Windows Desktop Search\WindowsSearch.exe<br />
C:\Program Files\Dell V305\dldtMsdMon.exe<br />
C:\WINDOWS\system32\igfxsrvc.exe<br />
C:\WINDOWS\system32\SearchIndexer.exe<br />
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br />
c:\PROGRA~1\mcafee\msc\mcuimgr.exe<br />
C:\Program Files\Java\jre6\bin\jucheck.exe<br />
C:\WINDOWS\system32\sol.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\Connection Wizard\ICWCONN1.EXE<br />
C:\WINDOWS\system32\NOTEPAD.EXE<br />
C:\Documents and Settings\Your Daddy\Desktop\dds.com<br />
C:\WINDOWS\system32\SearchProtocolHost.exe<br />
<br />
============== Pseudo HJT Report ===============<br />
<br />
uStart Page = <a href="https://wwws.ameritrade.com/apps/LogIn" target="_blank">https://wwws.ameritrade.com/apps/LogIn</a><br />
uInternet Connection Wizard,ShellNext = iexplore<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll<br />
BHO: McAfee Phishing Filter: {377c180e-6f0e-4d4c-980f-f45bd3d40cf4} - c:\progra~1\mcafee\msk\mcapbho.dll<br />
BHO: Spybot-S&amp;D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll<br />
BHO: {5c255c8a-e604-49b4-9d64-90988571cecb} - __BHODemonDisabled<br />
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll<br />
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll<br />
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll<br />
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll__BHODemonDisabled<br />
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
TB: &amp;Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll<br />
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search &amp; destroy\TeaTimer.exe<br />
mRun: [RTHDCPL] RTHDCPL.EXE<br />
mRun: [Alcmtr] ALCMTR.EXE<br />
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe<br />
mRun: [Persistence] c:\windows\system32\igfxpers.exe<br />
mRun: [mcagent_exe] c:\program files\mcafee.com\agent\mcagent.exe /runkey<br />
mRun: [dellsupportcenter] &quot;c:\program files\dell support center\bin\sprtcmd.exe&quot; /P dellsupportcenter<br />
mRun: [dldtmon.exe] &quot;c:\program files\dell v305\dldtmon.exe&quot;<br />
mRun: [dldtamon] &quot;c:\program files\dell v305\dldtamon.exe&quot;<br />
mRun: [Adobe Reader Speed Launcher] &quot;c:\program files\adobe\reader 9.0\reader\Reader_sl.exe&quot;<br />
mRun: [SunJavaUpdateSched] &quot;c:\program files\java\jre6\bin\jusched.exe&quot;<br />
StartupFolder: c:\docume~1\yourda~1\startm~1\programs\startup\checkf~1.lnk - c:\jts\WiseUpdt.exe<br />
StartupFolder: c:\docume~1\yourda~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe<br />
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe<br />
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe<br />
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll<br />
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll<br />
Trusted Zone: ameritrade.com\research<br />
Trusted Zone: ameritrade.com\wwws<br />
Trusted Zone: microsoft.com\<a href="http://www.update" target="_blank">www.update</a><br />
Trusted Zone: wachovia.com\onlinebanking1<br />
Trusted Zone: wachovia.com\onlinebanking2<br />
Trusted Zone: wachovia.com\onlineservices<br />
DPF: {41EF3CD2-D8CC-4438-84B1-280BB4E77C8E} - hxxps://vcuhsra.mcvh-vcu.edu/vdesk/terminal/f5tunsrv.cab#version=6031,2009,1204,1610<br />
DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} - hxxps://vcuhsra.mcvh-vcu.edu/vdesk/terminal/InstallerControl.cab#version=6031,2009,1204,1613<br />
DPF: {7E73BE8F-FD87-44EC-8E22-023D5FF960FF} - hxxps://vcuhsra.mcvh-vcu.edu/vdesk/terminal/vdeskctrl.cab#version=6031,2009,1212,1610<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} - hxxps://vcuhsra.mcvh-vcu.edu/vdesk/terminal/urxshost.cab#version=6031,2009,1204,1608<br />
DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} - hxxps://vcuhsra.mcvh-vcu.edu/vdesk/terminal/urxhost.cab#version=6031,2009,1204,1604<br />
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll<br />
Notify: igfxcui - igfxdev.dll<br />
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll<br />
Hosts: 127.0.0.1	<a href="http://www.spywareinfo.com" target="_blank">www.spywareinfo.com</a><br />
<br />
============= SERVICES / DRIVERS ===============<br />
<br />
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-3-5 201320]<br />
R2 dldt_device;dldt_device;c:\windows\system32\dldtcoms.exe -service --&gt; c:\windows\system32\dldtcoms.exe -service [?]<br />
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-3-5 358224]<br />
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-3-5 144704]<br />
R3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-3-5 695624]<br />
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-3-5 79304]<br />
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-3-5 35240]<br />
R3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-3-5 33832]<br />
R3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-3-5 40488]<br />
S2 dldtCATSCustConnectService;dldtCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\dldtserv.exe [2008-2-25 99568]<br />
<br />
=============== Created Last 30 ================<br />
<br />
2010-09-01 22:05:32	0	d-----w-	c:\windows\ERuNT<br />
2010-08-31 23:51:48	0	d-----w-	c:\windows\system32\wbem\Repository<br />
2010-08-30 03:06:48	120	----a-w-	c:\windows\Dgoyo.dat<br />
2010-08-30 03:06:48	0	----a-w-	c:\windows\Nzumupufaxawiro.bin<br />
2010-08-30 03:03:17	397	----a-w-	c:\documents and settings\your daddy\exe.js<br />
<br />
==================== Find3M  ====================<br />
<br />
2010-06-20 01:25:40	2136	----a-w-	c:\docume~1\yourda~1\applic~1\wklnhst.dat<br />
2009-12-13 20:24:03	16384	--sha-w-	c:\windows\system32\config\systemprofile\ietldcache\index.dat<br />
<br />
============= FINISH: 18:10:25.51 ===============</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=22">Malware Removal</category>
			<dc:creator>lucky13</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=59294</guid>
		</item>
		<item>
			<title><![CDATA[Spybot Wouldn't Start, No Virus. Tried SuperAntiSpyware, but No Help.]]></title>
			<link>http://forums.spybot.info/showthread.php?t=59293&amp;goto=newpost</link>
			<pubDate>Wed, 01 Sep 2010 23:00:37 GMT</pubDate>
			<description><![CDATA[Hello!  
 
My Google Search Links are being redirected to Annoying Websites. My Antivirus did not find any Viruses. And, Spybot or Antimalwarebyte's...]]></description>
			<content:encoded><![CDATA[<div>Hello! <br />
<br />
My Google Search Links are being redirected to Annoying Websites. My Antivirus did not find any Viruses. And, Spybot or Antimalwarebyte's Anti-Malware wouldn't start no matter what I do. (I read the special forum post here on how to start Spybot in various ways.) <br />
<br />
I have been trying to battle some kind of a Malware infection. I learnt about SuperAntiSpyware and ran it. It found some infections, but it seems that things are not back to Normal. Spybot has been my saviour in the past and now it still wouldn't start.<br />
<br />
I do not know how to proceed. And, I have been scouring the Internet for help, but to no avail because either my clicks get redirected or they lead me to the same solutions: download something and try running it. <br />
<br />
Please help!</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=22">Malware Removal</category>
			<dc:creator>TomZXu</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=59293</guid>
		</item>
		<item>
			<title>Month of 0-day bugs...</title>
			<link>http://forums.spybot.info/showthread.php?t=59290&amp;goto=newpost</link>
			<pubDate>Wed, 01 Sep 2010 20:39:01 GMT</pubDate>
			<description><![CDATA[FYI... 
 
*Month of Undisclosed 0-day Bugs* 
- http://isc.sans.edu/diary.html?storyid=9487 
Last Updated: 2010-09-01 20:05:22 UTC - "As a heads up,...]]></description>
			<content:encoded><![CDATA[<div>FYI...<br />
<br />
<b>Month of Undisclosed 0-day Bugs</b><br />
- <a href="http://isc.sans.edu/diary.html?storyid=9487" target="_blank">http://isc.sans.edu/diary.html?storyid=9487</a><br />
Last Updated: 2010-09-01 20:05:22 UTC - &quot;As a heads up, the Exploit Database (exploit-db.com) is to publish a month of undisclosed 0day bugs from Abyssec Research. Today there are two bugs published one for cPanel (though it seems more of a bug of fantastico) <u>and one on Adobe Reader and Flash</u>. <i>Expect that the &quot;good ones&quot; will be weaponized quickly</i> as the disclosures are quite technically detailed and don't take too much thought to put into place. You may wish to keep up with what they publish as awareness for your own networks.&quot;<br />
- <a href="http://www.exploit-db.com/news/" target="_blank">http://www.exploit-db.com/news/</a><br />
<br />
:fear::buried:</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=28">General Security Alerts</category>
			<dc:creator>AplusWebMaster</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=59290</guid>
		</item>
		<item>
			<title>PC Shield Virus</title>
			<link>http://forums.spybot.info/showthread.php?t=59289&amp;goto=newpost</link>
			<pubDate>Wed, 01 Sep 2010 17:34:47 GMT</pubDate>
			<description><![CDATA[My computer has contracted the pc shield virus.  I currently can't use the internet as it won't allow me to bring up the spybot web site.  It does...]]></description>
			<content:encoded><![CDATA[<div>My computer has contracted the pc shield virus.  I currently can't use the internet as it won't allow me to bring up the spybot web site.  It does automatically bring up the www.viagra.com site :devil:  Anyway, I can't download the ERUNT program to back up the registry.  I also can't download the DDS.  I've unsure what to do so I'm asking for help.  Not sure what the next move is.  <br />
<br />
Need Help!!</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=22">Malware Removal</category>
			<dc:creator>Steveo4571</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=59289</guid>
		</item>
		<item>
			<title>Immunization disappear after CCLEANER?</title>
			<link>http://forums.spybot.info/showthread.php?t=59288&amp;goto=newpost</link>
			<pubDate>Wed, 01 Sep 2010 17:08:41 GMT</pubDate>
			<description>I have noticed last several updates of immunization that it would show the Mozilla Foxfire with no protection and list 14,400 unprotected. Total of...</description>
			<content:encoded><![CDATA[<div>I have noticed last several updates of immunization that it would show the Mozilla Foxfire with no protection and list 14,400 unprotected. Total of some 43,000+ unprotected. So immunization takes longer than it used to, then I thought COULD IT BE that CCLEANER formerly known as Crap Cleaner, could be somehow wiping out the immunization that had been installed? It is a serious problem in that I surf the net feeling I have that protection when it seems to not be there. Is there anything S&amp;D can do to cure this problem?<br />
<br />
CCLEANER is an important part of computer security also.<br />
<br />
Thanks.</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=4"><![CDATA[Spybot-S&D]]></category>
			<dc:creator>GEEWIZ</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=59288</guid>
		</item>
		<item>
			<title>Manual Removal Guide for Win32.OnLineGames.uzdu</title>
			<link>http://forums.spybot.info/showthread.php?t=59287&amp;goto=newpost</link>
			<pubDate>Wed, 01 Sep 2010 11:13:10 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "Win32.OnLineGames.uzdu" manually. 
Use this guide at your own risk; software...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;Win32.OnLineGames.uzdu&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li>trojan</li>
<li>passwordstealer</li>
</ul><b>Description:</b><blockquote>Win32.OnLineGames.uzdu tries to steal passwords for online games. The library files get injected into running processes in order to avoid detection and to be executed by system files.</blockquote><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Files:</font></b></font><br />
<br />
<b>Important:</b> There are more files that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="3"><b><font color="Navy">Registry:</font></b></font><br />
<br />
You can use <i>regedit.exe</i> (included in Windows) to locate and delete these registry entries.<ul><li>Delete the registry value <i>&quot;&lt;$ENV(OLG1)&gt;&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\&quot;</i>.</li>
<li>Remove <i>&quot;&lt;$ENV(OLG1)&gt;.dll&quot;</i> from registry value <i>&quot;AppInit_DLLs&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\&quot;</i>.</li>
</ul>If Win32.OnLineGames.uzdu uses rootkit technologies, use our <a href="http://www.safer-networking.org/index.php?page=regalyzer" target="_blank">RegAlyzer</a>, <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
<br />
There are more registry entries that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help,<ol style="list-style-type: decimal"><li><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li>
<li>Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li>
</ol><br />
There are more files or system entries belonging to this product that &lt;$SPYBOTSD&gt; can remove, but that cannot be easily described in text. Please use &lt;$SPYBOTSD&gt; to make sure &lt;$PRODUCTNAME&gt; gets completely removed.</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=54">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=59287</guid>
		</item>
		<item>
			<title>Manual Removal Guide for Win32.OnLineGames.utkk</title>
			<link>http://forums.spybot.info/showthread.php?t=59286&amp;goto=newpost</link>
			<pubDate>Wed, 01 Sep 2010 11:13:09 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "Win32.OnLineGames.utkk" manually. 
Use this guide at your own risk; software...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;Win32.OnLineGames.utkk&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li>trojan</li>
<li>passwordstealer</li>
</ul><b>Description:</b><blockquote>Win32.OnLineGames.utkk tries to steal passwords for online games. The library files get injected into running processes in order to avoid detection and to be executed by system files.</blockquote><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Files:</font></b></font><br />
<br />
<b>Important:</b> There are more files that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="3"><b><font color="Navy">Registry:</font></b></font><br />
<br />
You can use <i>regedit.exe</i> (included in Windows) to locate and delete these registry entries.<ul><li>Delete the registry value <i>&quot;&lt;$ENV(OLG1)&gt;&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\&quot;</i>.</li>
<li>Remove <i>&quot;&lt;$ENV(OLG1)&gt;.dll&quot;</i> from registry value <i>&quot;AppInit_DLLs&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\&quot;</i>.</li>
</ul>If Win32.OnLineGames.utkk uses rootkit technologies, use our <a href="http://www.safer-networking.org/index.php?page=regalyzer" target="_blank">RegAlyzer</a>, <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
<br />
There are more registry entries that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help,<ol style="list-style-type: decimal"><li><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li>
<li>Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li>
</ol><br />
There are more files or system entries belonging to this product that &lt;$SPYBOTSD&gt; can remove, but that cannot be easily described in text. Please use &lt;$SPYBOTSD&gt; to make sure &lt;$PRODUCTNAME&gt; gets completely removed.</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=54">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=59286</guid>
		</item>
		<item>
			<title>Manual Removal Guide for Win32.OnLineGames.usfi</title>
			<link>http://forums.spybot.info/showthread.php?t=59285&amp;goto=newpost</link>
			<pubDate>Wed, 01 Sep 2010 11:13:08 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "Win32.OnLineGames.usfi" manually. 
Use this guide at your own risk; software...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;Win32.OnLineGames.usfi&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li>trojan</li>
<li>passwordstealer</li>
</ul><b>Description:</b><blockquote>Win32.OnLineGames.usfi tries to steal passwords for online games. The library files get injected into running processes in order to avoid detection and to be executed by system files.</blockquote><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Files:</font></b></font><br />
<br />
<b>Important:</b> There are more files that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="3"><b><font color="Navy">Registry:</font></b></font><br />
<br />
You can use <i>regedit.exe</i> (included in Windows) to locate and delete these registry entries.<ul><li>Delete the registry value <i>&quot;&lt;$ENV(OLG1)&gt;&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\&quot;</i>.</li>
<li>Remove <i>&quot;&lt;$ENV(OLG1)&gt;.dll&quot;</i> from registry value <i>&quot;AppInit_DLLs&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\&quot;</i>.</li>
</ul>If Win32.OnLineGames.usfi uses rootkit technologies, use our <a href="http://www.safer-networking.org/index.php?page=regalyzer" target="_blank">RegAlyzer</a>, <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
<br />
There are more registry entries that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help,<ol style="list-style-type: decimal"><li><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li>
<li>Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li>
</ol><br />
There are more files or system entries belonging to this product that &lt;$SPYBOTSD&gt; can remove, but that cannot be easily described in text. Please use &lt;$SPYBOTSD&gt; to make sure &lt;$PRODUCTNAME&gt; gets completely removed.</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=54">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=59285</guid>
		</item>
	</channel>
</rss>
