<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.2.1" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Help Desq</title>
	<link>http://www.askhelpdesq.com</link>
	<description>Questions Answered - Info on tech support, health, travel questions and more.....</description>
	<pubDate>Fri, 25 Jul 2008 04:05:00 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.1</generator>
	<language>en</language>
			<item>
		<title>explorer.exe problem</title>
		<link>http://www.askhelpdesq.com/2008/07/24/explorerexe-problem-3/</link>
		<comments>http://www.askhelpdesq.com/2008/07/24/explorerexe-problem-3/#comments</comments>
		<pubDate>Fri, 25 Jul 2008 04:05:00 +0000</pubDate>
		<dc:creator>Jammerx2</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.daniweb.com/forums/thread136612.html</guid>
		<description><![CDATA[This has been happening a lot. Everything keeps closing (desktop, taskbar) i can only see the current windows i have open. When i got to task manager it says explorer.exe is running and i can get it back for a bit by going to the file tab then run and typing explorer

Any ideas on what i should do?]]></description>
			<content:encoded><![CDATA[<div>This has been happening a lot. Everything keeps closing (desktop, taskbar) i can only see the current windows i have open. When i got to task manager it says explorer.exe is running and i can get it back for a bit by going to the file tab then run and typing explorer<br />
<br />
Any ideas on what i should do?</div> ]]></content:encoded>
			<wfw:commentRss>http://www.askhelpdesq.com/2008/07/24/explorerexe-problem-3/feed/</wfw:commentRss>
		</item>
		<item>
		<title>windows xp restart when open internet browser</title>
		<link>http://www.askhelpdesq.com/2008/07/24/windows-xp-restart-when-open-internet-browser/</link>
		<comments>http://www.askhelpdesq.com/2008/07/24/windows-xp-restart-when-open-internet-browser/#comments</comments>
		<pubDate>Fri, 25 Jul 2008 03:16:12 +0000</pubDate>
		<dc:creator>burt147</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.daniweb.com/forums/thread136609.html</guid>
		<description><![CDATA[my computer keeps restarting by itself when I open any internet browsers, I run avast to check at start up and it came up with nothing, ccleaner, regcure and tuneup utilities, and checkdisk at startup, here is the log file from hijackthis, please help, thank you in advance.

Logfile of Trend Micro...]]></description>
			<content:encoded><![CDATA[<div>my computer keeps restarting by itself when I open any internet browsers, I run avast to check at start up and it came up with nothing, ccleaner, regcure and tuneup utilities, and checkdisk at startup, here is the log file from hijackthis, please help, thank you in advance.<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 10:10:33 AM, on 7/25/2008<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.20661)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br />
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\FolderSize\FolderSizeSvc.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe<br />
C:\WINDOWS\system32\IoctlSvc.exe<br />
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" href="http://go.microsoft.com/fwlink/?LinkId=54896">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" href="http://go.microsoft.com/fwlink/?LinkId=69157">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" href="http://go.microsoft.com/fwlink/?LinkId=69157">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" href="http://go.microsoft.com/fwlink/?LinkId=54896">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" href="http://go.microsoft.com/fwlink/?LinkId=54896">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" href="http://go.microsoft.com/fwlink/?LinkId=69157">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = <a rel="nofollow" href="http://go.microsoft.com/fwlink/?LinkId=74005">http://go.microsoft.com/fwlink/?LinkId=74005</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br />
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,userinit.exe<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: (no name) - {074C1DC5-9320-4A9A-947D-C042949C6216} - (no file)<br />
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll<br />
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.6.26.dll<br />
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll<br />
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br />
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll<br />
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll<br />
O3 - Toolbar: (no name) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - (no file)<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [LClock] C:\Program Files\LClock\LClock.exe (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-20\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')<br />
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')<br />
O8 - Extra context menu item: &amp;D&amp;ownload &amp;with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm<br />
O8 - Extra context menu item: &amp;D&amp;ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm<br />
O8 - Extra context menu item: &amp;D&amp;ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm<br />
O8 - Extra context menu item: &amp;Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm<br />
O8 - Extra context menu item: &amp;Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm<br />
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 - Extra context menu item: ส่&amp;งออกไปยัง Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.6.26.dll/206 (file missing)<br />
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe<br />
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a rel="nofollow" href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab">http://fpdownload2.macromedia.com/ge...sh/swflash.cab</a><br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL<br />
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br />
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe<br />
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe<br />
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe<br />
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe<br />
<br />
--<br />
End of file - 9499 bytes</div> ]]></content:encoded>
			<wfw:commentRss>http://www.askhelpdesq.com/2008/07/24/windows-xp-restart-when-open-internet-browser/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Compaq Presario went DEAD !!!</title>
		<link>http://www.askhelpdesq.com/2008/07/24/compaq-presario-went-dead/</link>
		<comments>http://www.askhelpdesq.com/2008/07/24/compaq-presario-went-dead/#comments</comments>
		<pubDate>Thu, 24 Jul 2008 23:43:49 +0000</pubDate>
		<dc:creator>us4cityfolks</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.daniweb.com/forums/thread136591.html</guid>
		<description><![CDATA[I have a Compaq Presario 501NR that I bought from Best Buy in March of 2007. We went on a trip to New Orleans a couple of days ago and when I went to plugged it in at the Hilton, it would not power on. The battery has been bad, but the power cord usually turns it on fine. I have never had any...]]></description>
			<content:encoded><![CDATA[<div>I have a Compaq Presario 501NR that I bought from Best Buy in March of 2007. We went on a trip to New Orleans a couple of days ago and when I went to plugged it in at the Hilton, it would not power on. The battery has been bad, but the power cord usually turns it on fine. I have never had any problems with this laptop. I tried a new universal cord from Office Depot, but nothing still. The light comes on that shows the battery is still charging, but the on switch will do nothing. PLEASE HELP !!!</div> ]]></content:encoded>
			<wfw:commentRss>http://www.askhelpdesq.com/2008/07/24/compaq-presario-went-dead/feed/</wfw:commentRss>
		</item>
		<item>
		<title>after hp screen flashes on startup, black screen with cursor</title>
		<link>http://www.askhelpdesq.com/2008/07/24/after-hp-screen-flashes-on-startup-black-screen-with-cursor/</link>
		<comments>http://www.askhelpdesq.com/2008/07/24/after-hp-screen-flashes-on-startup-black-screen-with-cursor/#comments</comments>
		<pubDate>Thu, 24 Jul 2008 21:20:45 +0000</pubDate>
		<dc:creator>capnkiki01</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.daniweb.com/forums/thread136573.html</guid>
		<description><![CDATA[I have an hp pavilion zv6000. When I turn it on the hp screen comes up for a few seconds then a black screen comes up with a flashing cursor at the top left. The computer stays on but doesn't repond to anything. The bios menu works with F10 at the hp screen, I tried to do the hdd self-test but it...]]></description>
			<content:encoded><![CDATA[<div>I have an hp pavilion zv6000. When I turn it on the hp screen comes up for a few seconds then a black screen comes up with a flashing cursor at the top left. The computer stays on but doesn't repond to anything. The bios menu works with F10 at the hp screen, I tried to do the hdd self-test but it gets stuck at 10% and won't finish. Any ideas?</div> ]]></content:encoded>
			<wfw:commentRss>http://www.askhelpdesq.com/2008/07/24/after-hp-screen-flashes-on-startup-black-screen-with-cursor/feed/</wfw:commentRss>
		</item>
		<item>
		<title>after hp screen flashes on startup, black screen with cursor</title>
		<link>http://www.askhelpdesq.com/2008/07/24/after-hp-screen-flashes-on-startup-black-screen-with-cursor/</link>
		<comments>http://www.askhelpdesq.com/2008/07/24/after-hp-screen-flashes-on-startup-black-screen-with-cursor/#comments</comments>
		<pubDate>Thu, 24 Jul 2008 21:20:45 +0000</pubDate>
		<dc:creator>capnkiki01</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.daniweb.com/forums/thread136573.html</guid>
		<description><![CDATA[I have an hp pavilion zv6000. When I turn it on the hp screen comes up for a few seconds then a black screen comes up with a flashing cursor at the top left. The computer stays on but doesn't repond to anything. The bios menu works with F10 at the hp screen, I tried to do the hdd self-test but it...]]></description>
			<content:encoded><![CDATA[<div>I have an hp pavilion zv6000. When I turn it on the hp screen comes up for a few seconds then a black screen comes up with a flashing cursor at the top left. The computer stays on but doesn't repond to anything. The bios menu works with F10 at the hp screen, I tried to do the hdd self-test but it gets stuck at 10% and won't finish. Any ideas?</div> ]]></content:encoded>
			<wfw:commentRss>http://www.askhelpdesq.com/2008/07/24/after-hp-screen-flashes-on-startup-black-screen-with-cursor/feed/</wfw:commentRss>
		</item>
		<item>
		<title>No desktop, No taskbar!!! ALL LOGS INSIDE!</title>
		<link>http://www.askhelpdesq.com/2008/07/24/no-desktop-no-taskbar-all-logs-inside/</link>
		<comments>http://www.askhelpdesq.com/2008/07/24/no-desktop-no-taskbar-all-logs-inside/#comments</comments>
		<pubDate>Thu, 24 Jul 2008 20:44:54 +0000</pubDate>
		<dc:creator>Jammerx2</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.daniweb.com/forums/thread136569.html</guid>
		<description><![CDATA[Ok after i got rid of this other malware/virus. I see this other person having the same problem http://ask.metafilter.com/81308/Why-does-my-desktop-keep-crashing . It starts at boot time but usually when i open up ie explorer, opera it seems to close. If i go to CTRL+ALT+DEL menu to processes...]]></description>
			<content:encoded><![CDATA[<div>Ok after i got rid of this other malware/virus. I see this other person having the same problem <a rel="nofollow" href="http://ask.metafilter.com/81308/Why-does-my-desktop-keep-crashing">http://ask.metafilter.com/81308/Why-...-keep-crashing</a> . It starts at boot time but usually when i open up ie explorer, opera it seems to close. If i go to CTRL+ALT+DEL menu to processes explorer.exe is still there. I can get it back for a while (i had to to get to this browser) by ending explorer.exe and going to file then run and typing in explorer. I posted all my logs in my last post for viruses and i'll pot them again here. <br />
<br />
<br />
Thankyou in advance for your help.<br />
<br />
I put large spaces in between each log because it was to cluttered =)<br />
<br />
<br />
<br />
Malware Bytes Log<br />
<br />
Malwarebytes' Anti-Malware 1.23<br />
Database version: 985<br />
Windows 5.0.2195 Service Pack 4<br />
<br />
12:18:34 PM 7/24/2008<br />
Malwarebytes Log<br />
<br />
Scan type: Full Scan (C:\|D:\|)<br />
Objects scanned: 119794<br />
Time elapsed: 2 hour(s), 19 minute(s), 12 second(s)<br />
<br />
Memory Processes Infected: 0<br />
Memory Modules Infected: 6<br />
Registry Keys Infected: 22<br />
Registry Values Infected: 4<br />
Registry Data Items Infected: 2<br />
Folders Infected: 2<br />
Files Infected: 35<br />
<br />
Memory Processes Infected:<br />
(No malicious items detected)<br />
<br />
Memory Modules Infected:<br />
C:\WINNT\system32\frymmsjw.dll (Trojan.Vundo) -&gt; No action taken.<br />
C:\WINNT\system32\yayaAQiH.dll (Trojan.Vundo) -&gt; No action taken.<br />
C:\WINNT\system32\nnnooOfe.dll (Trojan.Vundo) -&gt; No action taken.<br />
C:\WINNT\system32\iefilter.dll (Trojan.FakeAlert) -&gt; No action taken.<br />
C:\WINNT\system32\btawwx.dll (Trojan.Vundo) -&gt; No action taken.<br />
C:\WINNT\system32\uspdxw.dll (Trojan.Vundo) -&gt; No action taken.<br />
<br />
Registry Keys Infected:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{04d32989-deab-4c05-9163-7f06f490629e} (Trojan.Vundo) -&gt; No action taken.<br />
HKEY_CLASSES_ROOT\CLSID\{04d32989-deab-4c05-9163-7f06f490629e} (Trojan.Vundo) -&gt; No action taken.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{df292dd2-7551-4cac-af6e-00c4ba31fd4d} (Trojan.Vundo) -&gt; No action taken.<br />
HKEY_CLASSES_ROOT\CLSID\{df292dd2-7551-4cac-af6e-00c4ba31fd4d} (Trojan.Vundo) -&gt; No action taken.<br />
HKEY_CLASSES_ROOT\CLSID\{769d8280-a207-4eea-9963-f8b156c32855} (Trojan.Vundo) -&gt; No action taken.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{769d8280-a207-4eea-9963-f8b156c32855} (Trojan.Vundo) -&gt; No action taken.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\nnnooofe (Trojan.Vundo) -&gt; No action taken.<br />
HKEY_CLASSES_ROOT\TypeLib\{15c7d7ad-a87a-4c0d-9d8b-637fcd3488ef} (Trojan.FakeAlert) -&gt; No action taken.<br />
HKEY_CLASSES_ROOT\Interface\{4937d5d1-2039-409a-bd83-fec9b39b2356} (Trojan.FakeAlert) -&gt; No action taken.<br />
HKEY_CLASSES_ROOT\Interface\{caf9d798-c659-4b9b-8e19-ee27c3d04ee7} (Trojan.FakeAlert) -&gt; No action taken.<br />
HKEY_CLASSES_ROOT\CLSID\{401f4b6b-3c36-4e8d-bc07-f46fc6d67d9a} (Trojan.FakeAlert) -&gt; No action taken.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{401f4b6b-3c36-4e8d-bc07-f46fc6d67d9a} (Trojan.FakeAlert) -&gt; No action taken.<br />
HKEY_CLASSES_ROOT\bhonew.bho (Trojan.FakeAlert) -&gt; No action taken.<br />
HKEY_CLASSES_ROOT\bhonew.bho.1 (Trojan.FakeAlert) -&gt; No action taken.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -&gt; No action taken.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -&gt; No action taken.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -&gt; No action taken.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webvideo (Trojan.FakeAlert) -&gt; No action taken.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VSPlugin (Trojan.FakeAlert) -&gt; No action taken.<br />
HKEY_CLASSES_ROOT\fdkowvbp.bosv (Trojan.FakeAlert) -&gt; No action taken.<br />
HKEY_CLASSES_ROOT\fdkowvbp.toolbar.1 (Trojan.FakeAlert) -&gt; No action taken.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -&gt; No action taken.<br />
<br />
Registry Values Infected:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\acf5173c (Trojan.Vundo) -&gt; No action taken.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{769d8280-a207-4eea-9963-f8b156c32855} (Trojan.Vundo) -&gt; No action taken.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\source (Trojan.FakeAlert) -&gt; No action taken.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\Microsoft (Backdoor.Bot) -&gt; No action taken.<br />
<br />
Registry Data Items Infected:<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo) -&gt; Data: c:\winnt\system32\yayaaqih -&gt; No action taken.<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -&gt; Data: c:\winnt\system32\yayaaqih -&gt; No action taken.<br />
<br />
Folders Infected:<br />
C:\WINNT\privacy_danger (Trojan.FakeAlert) -&gt; No action taken.<br />
C:\WINNT\privacy_danger\images (Trojan.FakeAlert) -&gt; No action taken.<br />
<br />
Files Infected:<br />
C:\WINNT\system32\yayaAQiH.dll (Trojan.Vundo) -&gt; No action taken.<br />
C:\WINNT\system32\HiQAayay.ini (Trojan.Vundo) -&gt; No action taken.<br />
C:\WINNT\system32\HiQAayay.ini2 (Trojan.Vundo) -&gt; No action taken.<br />
C:\WINNT\system32\uspdxw.dll (Trojan.Vundo) -&gt; No action taken.<br />
C:\WINNT\system32\frymmsjw.dll (Trojan.Vundo) -&gt; No action taken.<br />
C:\WINNT\system32\wjsmmyrf.ini (Trojan.Vundo) -&gt; No action taken.<br />
C:\WINNT\system32\rtlfktcx.dll (Trojan.Vundo) -&gt; No action taken.<br />
C:\WINNT\system32\xctkfltr.ini (Trojan.Vundo) -&gt; No action taken.<br />
C:\WINNT\system32\srltaapd.dll (Trojan.Vundo) -&gt; No action taken.<br />
C:\WINNT\system32\dpaatlrs.ini (Trojan.Vundo) -&gt; No action taken.<br />
C:\WINNT\system32\nnnooOfe.dll (Trojan.Vundo) -&gt; No action taken.<br />
C:\WINNT\system32\iefilter.dll (Trojan.FakeAlert) -&gt; No action taken.<br />
C:\WINNT\system32\btawwx.dll (Trojan.Vundo) -&gt; No action taken.<br />
C:\Program Files\Quick Batch File Compiler\Setup_ver1.113.0.exe (Trojan.FakeAlert) -&gt; No action taken.<br />
C:\Program Files\Quick Batch File Compiler\stubc.dll (Adware.Agent) -&gt; No action taken.<br />
C:\Program Files\Quick Batch File Compiler\wuick-batch-file-compiler-v-3.1.6.0-patch.exe (Trojan.FakeAlert) -&gt; No action taken.<br />
C:\WINNT\edgq.exe (Trojan.FakeAlert) -&gt; No action taken.<br />
C:\WINNT\system32\dtyhilky.dll (Trojan.Vundo) -&gt; No action taken.<br />
C:\WINNT\system32\ofvavbgl.dll (Trojan.Vundo) -&gt; No action taken.<br />
C:\WINNT\system32\owzooz.dll (Trojan.Vundo) -&gt; No action taken.<br />
C:\WINNT\system32\phxdiu.dll (Trojan.Vundo) -&gt; No action taken.<br />
C:\WINNT\system32\tgpspkqh.dll (Trojan.Vundo) -&gt; No action taken.<br />
C:\WINNT\system32\tkqipbmb.dll (Trojan.Vundo) -&gt; No action taken.<br />
C:\WINNT\system32\vmkfbz.dll (Trojan.Vundo) -&gt; No action taken.<br />
C:\WINNT\system32\wmbxytfy.dll (Trojan.Vundo) -&gt; No action taken.<br />
C:\WINNT\system32\vtUonlKB.dll (Trojan.Vundo) -&gt; No action taken.<br />
C:\WINNT\privacy_danger\index.htm (Trojan.FakeAlert) -&gt; No action taken.<br />
C:\WINNT\privacy_danger\images\capt.gif (Trojan.FakeAlert) -&gt; No action taken.<br />
C:\WINNT\privacy_danger\images\danger.jpg (Trojan.FakeAlert) -&gt; No action taken.<br />
C:\WINNT\privacy_danger\images\down.gif (Trojan.FakeAlert) -&gt; No action taken.<br />
C:\WINNT\privacy_danger\images\spacer.gif (Trojan.FakeAlert) -&gt; No action taken.<br />
C:\WINNT\eqvwamkl.dll (Trojan.FakeAlert) -&gt; No action taken.<br />
C:\WINNT\fdkowvbp.dll (Trojan.FakeAlert) -&gt; No action taken.<br />
C:\WINNT\grswptdl.exe (Trojan.FakeAlert) -&gt; No action taken.<br />
C:\Documents and Settings\Administrator.CORRINA-GFYHSR2\Local Settings\Temp\CmdLineExt02.dll (Trojan.Agent) -&gt; No action taken.<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
Eset Log<br />
<br />
# version=4<br />
# OnlineScanner.ocx=1.0.0.635<br />
# OnlineScannerDLLA.dll=1, 0, 0, 79<br />
# OnlineScannerDLLW.dll=1, 0, 0, 78<br />
# OnlineScannerUninstaller.exe=1, 0, 0, 49<br />
# vers_standard_module=3293 (20080723)<br />
# vers_arch_module=1.064 (20080214)<br />
# vers_adv_heur_module=1.064 (20070717)<br />
# EOSSerial=a4b65fb3fa61494aa594bd3a8ae61562<br />
# end=finished<br />
# remove_checked=true<br />
# unwanted_checked=false<br />
# utc_time=2008-07-24 06:06:01<br />
# local_time=2008-07-24 02:06:01 (-0500, Eastern Daylight Time)<br />
# country=&quot;United States&quot;<br />
# osver=5.0.2195 NT Service Pack 4<br />
# scanned=344217<br />
# found=13<br />
# scan_time=6325<br />
C:\Documents and Settings\owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-5a78fdfd-319987fa.zip multiple infiltrations (deleted) 00000000000000000000000000000000<br />
C:\Documents and Settings\owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-5a78fdfd-319987fa.zip »ZIP »BnnnnBaa.class Java/ClassLoader trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000<br />
C:\Documents and Settings\owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-5a78fdfd-319987fa.zip »ZIP »VaannnaaBaa.class Java/ClassLoader trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000<br />
C:\Documents and Settings\owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-5a78fdfd-319987fa.zip »ZIP »Dnnny.class Java/Exploit.Bytverify trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000<br />
C:\Documents and Settings\owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-5a78fdfd-319987fa.zip »ZIP »Bnnnnn.class Java/ClassLoader.AS trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000<br />
C:\Documents and Settings\owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-5a78fdfd-319987fa.zip »ZIP »Den.class Java/Exploit.Bytverify trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000<br />
C:\Documents and Settings\owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-5a78fdfd-319987fa.zip »ZIP »Din.class Java/Exploit.Bytverify trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000<br />
C:\Documents and Settings\owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-5a78fdfd-319987fa.zip »ZIP »Dun.class Java/Exploit.Bytverify trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000<br />
C:\Program Files\Quick Batch File Compiler\stubc.dll probably a variant of Win32/Agent trojan (unable to clean - deleted) 00000000000000000000000000000000<br />
C:\Program Files\Quick Batch File Compiler\wuick-batch-file-compiler-v-3.1.6.0-patch.exe Win32/Adware.IeDefender.NGJ application (unable to clean - deleted) 00000000000000000000000000000000<br />
C:\WINNT\system32\iefilter.dll Win32/Adware.IeDefender.NGJ application (unable to clean - deleted (after the next restart)) 00000000000000000000000000000000<br />
D:\Josh from C\MapleStory\AncientFixed.rar Win32/Jeefo.A virus (deleted) 00000000000000000000000000000000<br />
D:\Josh from C\MapleStory\AncientFixed.rar »RAR »AncientFixed.exe Win32/Jeefo.A virus (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
HiJackThis<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 12:48:19 PM, on 8/24/2008<br />
Platform: Windows 2000 SP4 (WinNT 5.00.2195)<br />
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINNT\System32\smss.exe<br />
C:\WINNT\system32\winlogon.exe<br />
C:\WINNT\system32\services.exe<br />
C:\WINNT\system32\lsass.exe<br />
C:\WINNT\system32\svchost.exe<br />
C:\WINNT\system32\spoolsv.exe<br />
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
C:\WINNT\System32\svchost.exe<br />
C:\Program Files\Roxio\GoBack\GBPoll.exe<br />
C:\WINNT\system32\regsvc.exe<br />
C:\WINNT\system32\MSTask.exe<br />
C:\WINNT\System32\WBEM\WinMgmt.exe<br />
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe<br />
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
C:\WINNT\Explorer.EXE<br />
C:\WINNT\system32\VTTimer.exe<br />
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe<br />
C:\Program Files\Pure Networks\Network Magic\nmapp.exe<br />
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Hamachi\hamachi.exe<br />
D:\Josh from C\Xfire\xfire.exe<br />
C:\Documents and Settings\Administrator.CORRINA-GFYHSR2\Desktop\dss.exe<br />
C:\WINNT\system32\rundll32.exe<br />
C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe<br />
C:\WINNT\System32\svchost.exe<br />
C:\WINNT\system32\rundll32.exe<br />
C:\DOCUME~1\ADMINI~1.COR\Desktop\Administrator.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: (no name) - {2D63DFB8-719C-4B43-8E2F-7593657BA76A} - C:\WINNT\system32\pmnkKcYQ.dll<br />
O2 - BHO: IE to GetRight Helper - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll<br />
O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll<br />
O2 - BHO: (no name) - {769D8280-A207-4EEA-9963-F8B156C32855} - C:\WINNT\system32\nnnooOfe.dll<br />
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)<br />
O2 - BHO: (no name) - {C1D2F57A-9944-435E-A16F-CA98B29D8884} - C:\WINNT\system32\yayaAQiH.dll (file missing)<br />
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)<br />
O3 - Toolbar: &amp;Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx<br />
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O3 - Toolbar: fdkowvbp - {A976B7DF-9CDC-436C-A5BA-D0CD8CB4A8AA} - (no file)<br />
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon<br />
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] &quot;C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe&quot; /icon<br />
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe<br />
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
O4 - HKLM\..\Run: [nmctxth] &quot;C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe&quot;<br />
O4 - HKLM\..\Run: [nmapp] &quot;C:\Program Files\Pure Networks\Network Magic\nmapp.exe&quot; -autorun -nosplash<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [acf5173c] rundll32.exe &quot;C:\WINNT\system32\arjekrfa.dll&quot;,b<br />
O4 - HKCU\..\Run: [msnmsgr] &quot;C:\Program Files\MSN Messenger\msnmsgr.exe&quot; /background<br />
O4 - HKCU\..\Run: [DAEMON Tools Lite] &quot;C:\Program Files\DAEMON Tools Lite\daemon.exe&quot; -autorun<br />
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')<br />
O4 - Startup: Hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe<br />
O4 - Startup: Xfire.lnk = D:\Josh from C\Xfire\xfire.exe<br />
O4 - Global Startup: GetRight.lnk = C:\Program Files\GetRight\GetRight.exe<br />
O4 - Global Startup: GoBack.lnk = C:\Program Files\Roxio\GoBack\GBTray.exe<br />
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE<br />
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm<br />
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm<br />
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm<br />
O9 - Extra 'Tools' menuitem: Show &amp;Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm<br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll<br />
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - <a rel="nofollow" href="http://www.eset.eu/buxus/docs/OnlineScanner.cab">http://www.eset.eu/buxus/docs/OnlineScanner.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)<br />
O20 - AppInit_DLLs: avgrsstx.dll<br />
O20 - Winlogon Notify: nnnooOfe - C:\WINNT\SYSTEM32\nnnooOfe.dll<br />
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
O23 - Service: AVG8 E-mail Scanner (avg8emc) - ALWIL Software - (no file)<br />
O23 - Service: AVG8 WatchDog (avg8wd) - ALWIL Software - (no file)<br />
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe<br />
O23 - Service: GBPoll - Roxio, Inc. - C:\Program Files\Roxio\GoBack\GBPoll.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe<br />
O24 - Desktop Component 0: Privacy Protection - (no file)<br />
<br />
--<br />
End of file - 6820 bytes<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
Main.txt (DSS LOG)<br />
<br />
Deckard's System Scanner v20071014.68<br />
Run by Administrator on 2008-08-24 12:47:46<br />
Computer is in Normal Mode.<br />
--------------------------------------------------------------------------------<br />
<br />
Backed up registry hives.<br />
Performed disk cleanup.<br />
<br />
Percentage of Memory in Use: 87% (more than 75%).<br />
Total Physical Memory: 224 MiB (256 MiB recommended).<br />
<br />
<br />
-- HijackThis (run as Administrator.exe) ---------------------------------------<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 12:48:19 PM, on 8/24/2008<br />
Platform: Windows 2000 SP4 (WinNT 5.00.2195)<br />
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINNT\System32\smss.exe<br />
C:\WINNT\system32\winlogon.exe<br />
C:\WINNT\system32\services.exe<br />
C:\WINNT\system32\lsass.exe<br />
C:\WINNT\system32\svchost.exe<br />
C:\WINNT\system32\spoolsv.exe<br />
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
C:\WINNT\System32\svchost.exe<br />
C:\Program Files\Roxio\GoBack\GBPoll.exe<br />
C:\WINNT\system32\regsvc.exe<br />
C:\WINNT\system32\MSTask.exe<br />
C:\WINNT\System32\WBEM\WinMgmt.exe<br />
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe<br />
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
C:\WINNT\Explorer.EXE<br />
C:\WINNT\system32\VTTimer.exe<br />
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe<br />
C:\Program Files\Pure Networks\Network Magic\nmapp.exe<br />
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Hamachi\hamachi.exe<br />
D:\Josh from C\Xfire\xfire.exe<br />
C:\Documents and Settings\Administrator.CORRINA-GFYHSR2\Desktop\dss.exe<br />
C:\WINNT\system32\rundll32.exe<br />
C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe<br />
C:\WINNT\System32\svchost.exe<br />
C:\WINNT\system32\rundll32.exe<br />
C:\DOCUME~1\ADMINI~1.COR\Desktop\Administrator.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = <br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: (no name) - {2D63DFB8-719C-4B43-8E2F-7593657BA76A} - C:\WINNT\system32\pmnkKcYQ.dll<br />
O2 - BHO: IE to GetRight Helper - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll<br />
O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll<br />
O2 - BHO: (no name) - {769D8280-A207-4EEA-9963-F8B156C32855} - C:\WINNT\system32\nnnooOfe.dll<br />
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)<br />
O2 - BHO: (no name) - {C1D2F57A-9944-435E-A16F-CA98B29D8884} - C:\WINNT\system32\yayaAQiH.dll (file missing)<br />
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)<br />
O3 - Toolbar: &amp;Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx<br />
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O3 - Toolbar: fdkowvbp - {A976B7DF-9CDC-436C-A5BA-D0CD8CB4A8AA} - (no file)<br />
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon<br />
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] &quot;C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe&quot; /icon<br />
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe<br />
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
O4 - HKLM\..\Run: [nmctxth] &quot;C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe&quot;<br />
O4 - HKLM\..\Run: [nmapp] &quot;C:\Program Files\Pure Networks\Network Magic\nmapp.exe&quot; -autorun -nosplash<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [acf5173c] rundll32.exe &quot;C:\WINNT\system32\arjekrfa.dll&quot;,b<br />
O4 - HKCU\..\Run: [msnmsgr] &quot;C:\Program Files\MSN Messenger\msnmsgr.exe&quot; /background<br />
O4 - HKCU\..\Run: [DAEMON Tools Lite] &quot;C:\Program Files\DAEMON Tools Lite\daemon.exe&quot; -autorun<br />
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')<br />
O4 - Startup: Hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe<br />
O4 - Startup: Xfire.lnk = D:\Josh from C\Xfire\xfire.exe<br />
O4 - Global Startup: GetRight.lnk = C:\Program Files\GetRight\GetRight.exe<br />
O4 - Global Startup: GoBack.lnk = C:\Program Files\Roxio\GoBack\GBTray.exe<br />
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE<br />
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm<br />
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm<br />
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm<br />
O9 - Extra 'Tools' menuitem: Show &amp;Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm<br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll<br />
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - <a rel="nofollow" href="http://www.eset.eu/buxus/docs/OnlineScanner.cab">http://www.eset.eu/buxus/docs/OnlineScanner.cab</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)<br />
O20 - AppInit_DLLs: avgrsstx.dll<br />
O20 - Winlogon Notify: nnnooOfe - C:\WINNT\SYSTEM32\nnnooOfe.dll<br />
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
O23 - Service: AVG8 E-mail Scanner (avg8emc) - ALWIL Software - (no file)<br />
O23 - Service: AVG8 WatchDog (avg8wd) - ALWIL Software - (no file)<br />
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe<br />
O23 - Service: GBPoll - Roxio, Inc. - C:\Program Files\Roxio\GoBack\GBPoll.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe<br />
O24 - Desktop Component 0: Privacy Protection - (no file)<br />
<br />
--<br />
End of file - 6820 bytes<br />
<br />
-- File Associations -----------------------------------------------------------<br />
<br />
.reg - regfile - shell\open\command - regedit.exe &quot;%1&quot; %*<br />
.scr - scrfile - shell\open\command - &quot;%1&quot; %*<br />
<br />
<br />
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------<br />
<br />
R0 GBDevice - c:\winnt\system32\drivers\gbdevice.sys &lt;Not Verified; Roxio, Inc.; GoBack&gt;<br />
R0 GoBack2K - c:\winnt\system32\drivers\goback2k.sys &lt;Not Verified; Roxio, Inc.; GoBack&gt;<br />
R0 viamraid - c:\winnt\system32\drivers\viamraid.sys &lt;Not Verified; VIA Technologies inc,.ltd; VIA RAID driver&gt;<br />
R2 GBFSHook - c:\winnt\system32\drivers\gbfshook.sys &lt;Not Verified; Roxio, Inc.; GoBack&gt;<br />
R2 npkcrypt - d:\josh from c\maplestory\npkcrypt.sys &lt;Not Verified; INCA Internet Co., Ltd.; nProtect KeyCrypt Driver&gt;<br />
R3 viagfx - c:\winnt\system32\drivers\vtmini.sys &lt;Not Verified; Copyright (C) VIA/S3 Graphics Co, Ltd.; UniChrome(Pro) IGP Driver&gt;<br />
<br />
S3 Pcouffin (Low level access layer for CD devices) - c:\winnt\system32\drivers\pcouffin.sys (file missing)<br />
<br />
<br />
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------<br />
<br />
R2 GBPoll - c:\program files\roxio\goback\gbpoll.exe &lt;Not Verified; Roxio, Inc.; GoBack&gt;<br />
<br />
S2 avg8emc (AVG8 E-mail Scanner) - <br />
S2 avg8wd (AVG8 WatchDog) - <br />
S2 NetCM (Network Connection Manager) - <br />
S2 PowerManager (Power Manager) - <br />
<br />
<br />
-- Device Manager: Disabled ----------------------------------------------------<br />
<br />
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}<br />
Description: Universal Serial Bus (USB) Controller<br />
Device ID: PCI\VEN_1106&amp;DEV_3104&amp;SUBSYS_18981019&amp;REV_86\3&amp;61AAA01&amp;0&amp;84<br />
Manufacturer: <br />
Name: Universal Serial Bus (USB) Controller<br />
PNP Device ID: PCI\VEN_1106&amp;DEV_3104&amp;SUBSYS_18981019&amp;REV_86\3&amp;61AAA01&amp;0&amp;84<br />
Service: <br />
<br />
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}<br />
Description: PCI Simple Communications Controller<br />
Device ID: PCI\VEN_1106&amp;DEV_3068&amp;SUBSYS_0C041019&amp;REV_80\3&amp;61AAA01&amp;0&amp;8E<br />
Manufacturer: <br />
Name: PCI Simple Communications Controller<br />
PNP Device ID: PCI\VEN_1106&amp;DEV_3068&amp;SUBSYS_0C041019&amp;REV_80\3&amp;61AAA01&amp;0&amp;8E<br />
Service: <br />
<br />
<br />
-- Scheduled Tasks -------------------------------------------------------------<br />
<br />
2008-07-23 17:00:01 446 --a------ C:\WINNT\Tasks\RegCure Program Check.job<br />
2008-07-17 10:06:20 380 --a------ C:\WINNT\Tasks\RegCure.job<br />
2008-07-15 18:19:04 284 --a------ C:\WINNT\Tasks\AppleSoftwareUpdate.job<br />
<br />
<br />
-- Files created between 2008-07-24 and 2008-08-24 -----------------------------<br />
<br />
2008-08-24 12:48:02 94848 --a------ C:\WINNT\system32\arjekrfa.dll<br />
2008-08-24 12:47:32 16384 --a-----t C:\WINNT\system32\Perflib_Perfdata_37c.dat<br />
2008-08-24 12:47:20 347 --ahs---- C:\WINNT\system32\QYcKknmp.ini2<br />
2008-08-24 12:47:14 323584 --a------ C:\WINNT\system32\pmnkKcYQ.dll<br />
2008-08-23 14:02:14 16384 --a-----t C:\WINNT\system32\Perflib_Perfdata_22c.dat<br />
2008-08-23 13:34:48 0 d-------- C:\Program Files\Trend Micro<br />
2008-08-23 13:22:39 16384 --a-----t C:\WINNT\system32\Perflib_Perfdata_3a0.dat<br />
2008-08-22 13:25:27 0 d-------- C:\Documents and Settings\Administrator.CORRINA-GFYHSR2\Application Data\Adersoft<br />
2008-08-22 13:25:13 0 d-------- C:\Program Files\Vbsedit<br />
2008-08-22 12:32:00 0 d-------- C:\Xfire<br />
2008-07-24 12:20:05 0 d-------- C:\DrWatson<br />
2008-07-24 00:14:05 0 d-------- C:\Program Files\EsetOnlineScanner<br />
<br />
<br />
-- Find3M Report ---------------------------------------------------------------<br />
<br />
2008-08-24 12:48:22 0 d-------- C:\Documents and Settings\Administrator.CORRINA-GFYHSR2\Application Data\Hamachi<br />
2008-08-22 16:38:51 0 d-------- C:\Program Files\GetRight<br />
2008-07-24 12:36:56 832650 ---h----- C:\WINNT\ShellIconCache<br />
2008-07-24 12:19:43 0 d-------- C:\Program Files\Quick Batch File Compiler<br />
2008-07-23 22:51:40 0 d-------- C:\Documents and Settings\Administrator.CORRINA-GFYHSR2\Application Data\Malwarebytes<br />
2008-07-23 22:51:39 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware<br />
2008-07-23 17:48:41 0 d-------- C:\Program Files\Batch File Compiler Professional Edition v4.0 DEMO<br />
2008-07-23 17:23:10 16384 --a-----t C:\WINNT\system32\Perflib_Perfdata_238.dat<br />
2008-07-23 17:20:46 0 d-------- C:\Documents and Settings\Administrator.CORRINA-GFYHSR2\Application Data\uTorrent<br />
2008-07-23 14:04:29 16384 --a-----t C:\WINNT\system32\Perflib_Perfdata_3ac.dat<br />
2008-07-23 13:01:52 16384 --a-----t C:\WINNT\system32\Perflib_Perfdata_228.dat<br />
2008-07-23 00:55:33 16384 --a-----t C:\WINNT\system32\Perflib_Perfdata_210.dat<br />
2008-07-22 23:47:13 33152 -----n--- C:\WINNT\system32\nnnooOfe.dll<br />
2008-07-22 20:48:17 57344 --a------ C:\WINNT\uneng.exe &lt;Not Verified; Roxio; Roxio Update Wizard&gt;<br />
2008-07-22 20:48:17 0 d-a------ C:\Program Files\Common Files<br />
2008-07-22 20:48:17 0 d-a------ C:\Program Files\Common Files\Adaptec Shared<br />
2008-07-21 23:01:11 0 d-------- C:\Program Files\BOTS<br />
2008-07-21 18:11:43 0 d-------- C:\Documents and Settings\Administrator.CORRINA-GFYHSR2\Application Data\Xfire<br />
2008-07-21 17:31:46 0 d-------- C:\Program Files\IzPack<br />
2008-07-21 17:17:07 0 d-------- C:\Program Files\Launch4j<br />
2008-07-17 18:19:15 16384 --a-----t C:\WINNT\system32\Perflib_Perfdata_1264.dat<br />
2008-07-17 17:48:31 16384 --a-----t C:\WINNT\system32\Perflib_Perfdata_218.dat<br />
2008-07-17 13:21:47 0 d-------- C:\Documents and Settings\Administrator.CORRINA-GFYHSR2\Application Data\Video DVD Maker FREE<br />
2008-07-17 13:21:05 0 d-------- C:\Program Files\Video DVD Maker<br />
2008-07-16 18:53:44 0 d--h----- C:\Program Files\InstallShield Installation Information<br />
2008-07-16 13:20:44 0 d-------- C:\Documents and Settings\Administrator.CORRINA-GFYHSR2\Application Data\MP3Rocket<br />
2008-07-16 10:13:05 0 d-------- C:\Program Files\wise DVD Creator 8.0<br />
2008-07-15 18:19:03 16384 --a-----t C:\WINNT\system32\Perflib_Perfdata_3d8.dat<br />
2008-07-15 17:13:23 0 d-a------ C:\Program Files\iPod<br />
2008-07-15 16:53:45 0 d-------- C:\Documents and Settings\Administrator.CORRINA-GFYHSR2\Application Data\Apple Computer<br />
2008-07-15 16:52:37 0 d-a------ C:\Program Files\iTunes<br />
2008-07-15 15:40:29 0 d-------- C:\Program Files\FinalBurner<br />
2008-07-15 15:07:05 0 d-------- C:\Program Files07DVD<br />
2008-07-15 13:20:10 0 d-------- C:\Program Files\Apple Software Update<br />
2008-07-15 13:01:39 0 d-a------ C:\Program Files\QuickTime<br />
2008-07-15 12:57:25 0 d-------- C:\Documents and Settings\Administrator.CORRINA-GFYHSR2\Application Data\vlc<br />
2008-07-15 12:55:57 16384 --a-----t C:\WINNT\system32\Perflib_Perfdata_440.dat<br />
2008-07-15 12:54:08 0 d-------- C:\Program Files\VideoLAN<br />
2008-07-15 10:43:53 0 d-------- C:\Program Files\MP3 Rocket<br />
2008-07-15 10:42:47 0 d-a------ C:\Program Files\Java<br />
2008-07-15 10:41:25 0 d-------- C:\Documents and Settings\Administrator.CORRINA-GFYHSR2\Application Data\Sun<br />
2008-07-13 13:12:26 0 d-a------ C:\Program Files\Common Files\Pure Networks Shared<br />
2008-07-08 15:14:18 0 d-------- C:\Program Files\DAEMON Tools Toolbar<br />
2008-07-08 15:14:18 0 d-------- C:\Program Files\DAEMON Tools Lite<br />
2008-07-08 15:10:09 16384 --a-----t C:\WINNT\system32\Perflib_Perfdata_214.dat<br />
2008-07-08 15:07:44 0 d-------- C:\Documents and Settings\Administrator.CORRINA-GFYHSR2\Application Data\DAEMON Tools<br />
2008-07-08 13:06:59 0 d-------- C:\Program Files\uTorrent<br />
2008-06-30 14:05:45 16384 --a-----t C:\WINNT\system32\Perflib_Perfdata_1fc.dat<br />
2008-06-29 22:34:19 16384 --a-----t C:\WINNT\system32\Perflib_Perfdata_1f8.dat<br />
2008-06-23 08:52:47 16384 --a-----t C:\WINNT\system32\Perflib_Perfdata_200.dat<br />
2008-06-22 14:51:45 16384 --a-----t C:\WINNT\system32\Perflib_Perfdata_204.dat<br />
2008-05-30 14:01:24 80896 --a------ C:\WINNT\system32\dxdllreg.exe &lt;Not Verified; Microsoft Corporation; Microsoft® DirectX for Windows®&gt;<br />
2008-05-25 17:02:06 47 --a------ C:\WINNT\system32\setpath.bat<br />
2008-05-24 22:30:13 2147483647 --ahs---- C:\gobackio.bin<br />
2008-05-24 21:32:43 15012 --a------ C:\WINNT\system32\emptyregdb.dat<br />
<br />
<br />
-- Registry Dump ---------------------------------------------------------------<br />
<br />
*Note* empty entries &amp; legit default entries are not shown<br />
<br />
<br />
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2D63DFB8-719C-4B43-8E2F-7593657BA76A}]<br />
08/24/08 12:47p 323584 --a------ C:\WINNT\system32\pmnkKcYQ.dll<br />
<br />
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{769D8280-A207-4EEA-9963-F8B156C32855}]<br />
07/22/08 11:47p 33152 --------- C:\WINNT\system32\nnnooOfe.dll<br />
<br />
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]<br />
<br />
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C1D2F57A-9944-435E-A16F-CA98B29D8884}]<br />
C:\WINNT\system32\yayaAQiH.dll<br />
<br />
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]<br />
&quot;{32099AAC-C132-4136-9E9A-4E364A424E17}&quot;= C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [07/08/08 11:59a 683464]<br />
<br />
[-HKEY_CLASSES_ROOT\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}]<br />
[HKEY_CLASSES_ROOT\DTToolbar.ToolBandObj.1]<br />
[HKEY_CLASSES_ROOT\TypeLib\{3E288F79-03E4-4983-A48E-0D879B51FF19}]<br />
[HKEY_CLASSES_ROOT\DTToolbar.ToolBandObj]<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />
&quot;Synchronization Manager&quot;=&quot;mobsync.exe&quot; [06/19/03 12:05p C:\WINNT\system32\mobsync.exe]<br />
&quot;SpeedTouch USB Diagnostics&quot;=&quot;C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe&quot; [05/03/02 10:40a]<br />
&quot;VTTimer&quot;=&quot;VTTimer.exe&quot; [03/08/05 03:33a C:\WINNT\system32\VTTimer.exe]<br />
&quot;avast!&quot;=&quot;C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe&quot; [05/15/08 07:19p]<br />
&quot;nmctxth&quot;=&quot;C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe&quot; [01/08/08 05:20p]<br />
&quot;nmapp&quot;=&quot;C:\Program Files\Pure Networks\Network Magic\nmapp.exe&quot; [01/18/08 10:32a]<br />
&quot;SunJavaUpdateSched&quot;=&quot;C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe&quot; [03/14/07 03:43a]<br />
&quot;QuickTime Task&quot;=&quot;C:\Program Files\QuickTime\qttask.exe&quot; [04/27/07 09:41a]<br />
&quot;iTunesHelper&quot;=&quot;C:\Program Files\iTunes\iTunesHelper.exe&quot; [06/14/06 04:24p]<br />
&quot;acf5173c&quot;=&quot;C:\WINNT\system32\arjekrfa.dll&quot; [08/24/08 12:48p]<br />
<br />
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />
&quot;msnmsgr&quot;=&quot;C:\Program Files\MSN Messenger\msnmsgr.exe&quot; [09/04/07 07:40p]<br />
&quot;DAEMON Tools Lite&quot;=&quot;C:\Program Files\DAEMON Tools Lite\daemon.exe&quot; [07/08/08 12:22p]<br />
<br />
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]<br />
&quot;^SetupICWDesktop&quot;=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop<br />
<br />
C:\Documents and Settings\Administrator.CORRINA-GFYHSR2\Start Menu\Programs\Startup\<br />
Hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe [7/8/2008 12:24:43 PM]<br />
Xfire.lnk - D:\Josh from C\Xfire\xfire.exe [7/15/2008 7:09:02 PM]<br />
<br />
C:\Documents and Settings\All Users.WINNT\Start Menu\Programs\Startup\<br />
GetRight.lnk - C:\Program Files\GetRight\GetRight.exe [6/6/2008 11:29:38 PM]<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]<br />
&quot;{769D8280-A207-4EEA-9963-F8B156C32855}&quot;= C:\WINNT\system32\nnnooOfe.dll [07/22/08 11:47p 33152]<br />
<br />
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnooOfe] <br />
nnnooOfe.dll 07/22/08 11:47p 33152 C:\WINNT\system32\nnnooOfe.dll<br />
<br />
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]<br />
&quot;appinit_dlls&quot;=avgrsstx.dll<br />
<br />
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]<br />
&quot;Authentication Packages&quot;= msv1_0 C:\WINNT\system32\pmnkKcYQ<br />
<br />
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]<br />
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,<br />
<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\clbdriver.sys]<br />
@=&quot;driver&quot;<br />
<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]<br />
@=&quot;Driver&quot;<br />
<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]<br />
@=&quot;Driver&quot;<br />
<br />
<br />
<br />
<br />
-- End of Deckard's System Scanner: finished at 2008-08-24 12:49:24 ------------<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
Extra.txt (DSS LOG)<br />
<br />
Deckard's System Scanner v20071014.68<br />
Extra logfile - please post this as an attachment with your post.<br />
--------------------------------------------------------------------------------<br />
<br />
-- System Information ----------------------------------------------------------<br />
<br />
Microsoft Windows 2000 Professional (build 2195) SP 4.0<br />
Architecture: X86; Language: English<br />
<br />
CPU 0: AMD Athlon(tm) XP 2800+<br />
Percentage of Memory in Use: 94%<br />
Physical Memory (total/avail): 223.43 MiB / 11.72 MiB<br />
Pagefile Memory (total/avail): 537.57 MiB / 187.39 MiB<br />
Virtual Memory (total/avail): 2047.88 MiB / 1955.68 MiB<br />
<br />
A: is Removable (No Media)<br />
C: is Fixed (NTFS) - 38.09 GiB total, 21.43 GiB free. <br />
D: is Fixed (FAT32) - 38.59 GiB total, 13.55 GiB free. <br />
E: is CDROM (No Media)<br />
F: is CDROM (No Media)<br />
G: is CDROM (No Media)<br />
<br />
\\.\PHYSICALDRIVE0 - HDS728080PLAT20 - 76.69 GiB - 2 partitions<br />
\PARTITION0 (bootable) - Installable File System - 38.09 GiB - C:<br />
\PARTITION1 - Extended w/Extended Int 13 - 38.6 GiB - D:<br />
<br />
<br />
<br />
-- Security Center -------------------------------------------------------------<br />
<br />
AUOptions is scheduled to auto-install.<br />
<br />
<br />
-- Environment Variables -------------------------------------------------------<br />
<br />
ALLUSERSPROFILE=C:\Documents and Settings\All Users.WINNT<br />
APPDATA=C:\Documents and Settings\Administrator.CORRINA-GFYHSR2\Application Data<br />
CLASSPATH=.;C:\Program Files\Java\jre1.6.0_01\lib\ext\QTJava.zip<br />
CommonProgramFiles=C:\Program Files\Common Files<br />
COMPUTERNAME=JOSH<br />
ComSpec=C:\WINNT\system32\cmd.exe<br />
HOMEDRIVE=C:<br />
HOMEPATH=\Documents and Settings\Administrator.CORRINA-GFYHSR2<br />
LOGONSERVER=\\JOSH<br />
NUMBER_OF_PROCESSORS=1<br />
OS=Windows_NT<br />
Os2LibPath=C:\WINNT\system32\os2\dll;<br />
Path=C:\WINNT\system32;C:\WINNT;C:\WINNT\System32\Wbem;C:\Program Files\QuickTime\QTSystem\<br />
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH<br />
PROCESSOR_ARCHITECTURE=x86<br />
PROCESSOR_IDENTIFIER=x86 Family 6 Model 10 Stepping 0, AuthenticAMD<br />
PROCESSOR_LEVEL=6<br />
PROCESSOR_REVISION=0a00<br />
ProgramFiles=C:\Program Files<br />
PROMPT=$P$G<br />
QTJAVA=C:\Program Files\Java\jre1.6.0_01\lib\ext\QTJava.zip<br />
SystemDrive=C:<br />
SystemRoot=C:\WINNT<br />
TEMP=C:\DOCUME~1\ADMINI~1.COR\LOCALS~1\Temp<br />
TMP=C:\DOCUME~1\ADMINI~1.COR\LOCALS~1\Temp<br />
USERDOMAIN=JOSH<br />
USERNAME=Administrator<br />
USERPROFILE=C:\Documents and Settings\Administrator.CORRINA-GFYHSR2<br />
windir=C:\WINNT<br />
<br />
<br />
-- User Profiles ---------------------------------------------------------------<br />
<br />
Administrator.CORRINA-GFYHSR2 (admin)<br />
<br />
<br />
-- Add/Remove Programs ---------------------------------------------------------<br />
<br />
--&gt; C:\WINNT\$NtServicePackUninstall$\spuninst\spuninst.exe<br />
µTorrent --&gt; &quot;C:\Program Files\uTorrent\uTorrent.exe&quot; /UNINSTALL<br />
Adobe Flash Player ActiveX --&gt; C:\WINNT\system32\Macromed\Flash\uninstall_activeX.exe<br />
Alcatel SpeedTouch USB Software --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup &quot;C:\Program Files\InstallShield Installation Information\{D41FAAA9-8048-4906-86B2-9AADEA1FA0B7}\Setup.exe&quot; -Control_Panel<br />
Apple Software Update --&gt; MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}<br />
avast! Antivirus --&gt; C:\Program Files\Alwil Software\Avast4\aswRunDll.exe &quot;C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll&quot;,RunSetup<br />
Batch File Compiler Professional Edition v4.0 DEMO --&gt; C:\Program Files\Batch File Compiler Professional Edition v4.0 DEMO\uninstall.exe<br />
BOTS --&gt; &quot;C:\Program Files\InstallShield Installation Information\{22D56257-DE33-4C7D-817B-C2DE69FE953C}\setup.exe&quot; -runfromtemp -l0x0009 -removeonly<br />
CakeStory --&gt; D:\Josh from C\MapleStory\Uninstal.exe<br />
CCleaner (remove only) --&gt; &quot;C:\Program Files\CCleaner\uninst.exe&quot;<br />
DAEMON Tools Toolbar --&gt; C:\Program Files\DAEMON Tools Toolbar\uninst.exe<br />
ESET Online Scanner --&gt; C:\WINNT\system32\OnlineScannerUninstaller.exe<br />
GetRight --&gt; &quot;C:\Program Files\GetRight\unins000.exe&quot;<br />
Hamachi 1.0.2.5 --&gt; C:\Program Files\Hamachi\uninstall.exe<br />
HijackThis 2.0.2 --&gt; &quot;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&quot; /uninstall<br />
Hirc --&gt; &quot;C:\Program Files\Hirc\unins000.exe&quot;<br />
iTunes --&gt; C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{54C0D94A-F467-4ABC-9D02-6E58748668D4} /l1033 <br />
IzPack 4.0.1 --&gt; &quot;C:\Program Files\Java\jre1.6.0_01\bin\javaw.exe&quot; -jar &quot;C:\Program Files\IzPack\uninstaller\uninstaller.jar&quot;<br />
Java(TM) SE Runtime Environment 6 Update 1 --&gt; MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}<br />
Launch4j 3.0.1 --&gt; C:\Program Files\Launch4j\uninst.exe<br />
LiveUpdate 1.7 (Symantec Corporation) --&gt; C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE /U<br />
Malwarebytes' Anti-Malware --&gt; &quot;C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe&quot;<br />
MapleStory --&gt; MsiExec.exe /I{7A512A34-F4E8-43C4-BD80-43A022B31BF6}<br />
Microsoft Internet Explorer 6 SP1 --&gt; rundll32 C:\WINNT\system32\setupwbv.dll,IE6Maintenance C:\Program Files\Internet Explorer\IE Uninstall\W2KEXCP.EXE /u<br />
Microsoft Office 2000 Small Business --&gt; MsiExec.exe /I{00030409-78E1-11D2-B60F-006097C998E7}<br />
Microsoft Visual C++ 2005 Redistributable --&gt; MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}<br />
MP3 Rocket --&gt; C:\Program Files\MP3 Rocket\Uninstall.exe<br />
Network Magic --&gt; C:\Documents and Settings\All Users.WINNT\Application Data\Pure Networks\Setup\nmsetup.exe /uninstall<br />
Quick Batch File Compiler 3.16 --&gt; &quot;C:\Program Files\Quick Batch File Compiler\unins000.exe&quot;<br />
QuickTime --&gt; MsiExec.exe /I{08094E03-AFE4-4853-9D31-6D0743DF5328}<br />
Realtek AC'97 Audio --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup &quot;C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe&quot; -l0x9 -removeonly<br />
RegCure 1.5.0.0 --&gt; D:\Josh from C\RegCure\uninst.exe<br />
Security Update for DirectX 9 (KB951698) --&gt; &quot;C:\WINNT\$NtUninstallKB951698_DX9$\spuninst\spuninst.exe&quot;<br />
Security Update for Windows 2000 (KB941569) --&gt; &quot;C:\WINNT\$NtUninstallKB941569$\spuninst\spuninst.exe&quot;<br />
Vbsedit --&gt; MsiExec.exe /X{C8BC7F74-65A7-428F-80C6-D8034103781C}<br />
VIA Rhine-Family Fast-Ethernet Adapter --&gt; Rundll32.exe vuins32.dll,vuins32Ex $Rhine $VIA<br />
VIA/S3G Display Driver --&gt; C:\PROGRA~1\VIA\UChromeP\s3minset.exe /u C:\PROGRA~1\VIA\UChromeP\UChromeP.uns<br />
Video DVD Maker v3.9.0.20 --&gt; &quot;C:\Program Files\Video DVD Maker\Uninstall.exe&quot; &quot;C:\Program Files\Video DVD Maker\install.log&quot; -u<br />
VideoLAN VLC media player 0.8.6i --&gt; C:\Program Files\VideoLAN\VLC\uninstall.exe<br />
Warcraft III: All Products --&gt; C:\WINNT\War3Unin.exe C:\WINNT\War3Unin.dat<br />
Windows Media Player system update (9 Series) --&gt; C:\PROGRA~1\WINDOW~2\setup_wm.exe /Uninstall<br />
WinRAR archiver --&gt; C:\Program Files\WinRAR\uninstall.exe<br />
Yahoo! Install Manager --&gt; C:\WINNT\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL<br />
Yahoo! Toolbar --&gt; C:\PROGRA~1\Yahoo!\Common\unyt.exe<br />
<br />
<br />
-- Application Event Log -------------------------------------------------------<br />
<br />
No Errors/Warnings found.<br />
<br />
<br />
-- Security Event Log ----------------------------------------------------------<br />
<br />
No Errors/Warnings found.<br />
<br />
<br />
-- System Event Log ------------------------------------------------------------<br />
<br />
Event Record #/Type1762 / Error<br />
Event Submitted/Written: 08/24/2008 00:48:07 PM<br />
Event ID/Source: 1000 / Dhcp<br />
Event Description:<br />
Your computer has lost the lease to its IP address 192.168.0.101 on the<br />
Network Card with network address 00142A306FFB.<br />
<br />
Event Record #/Type1761 / Warning<br />
Event Submitted/Written: 08/24/2008 00:48:07 PM<br />
Event ID/Source: 1003 / Dhcp<br />
Event Description:<br />
Your computer was not able to renew its address from the network (from the<br />
DHCP Server) for the Network Card with network address 00142A306FFB. The following<br />
error occured: <br />
%%121.<br />
Your computer will continue to try and obtain an address on its own from<br />
the network address (DHCP) server.<br />
<br />
Event Record #/Type1760 / Error<br />
Event Submitted/Written: 08/24/2008 00:45:37 PM / 08/24/2008 00:45:38 PM<br />
Event ID/Source: 8003 / MRxSmb<br />
Event Description:<br />
The master browser has received a server announcement from the computer OWNER-PC<br />
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{9153AB1E-30DC-4D11-.<br />
The master browser is stopping or an election is being forced.<br />
<br />
<br />
<br />
-- End of Deckard's System Scanner: finished at 2008-08-24 12:49:24 ------------<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
SmitFraud Log<br />
<br />
SmitFraudFix v2.331<br />
<br />
Scan done at 13:13:27.00, Sun 08/24/2008<br />
Run from C:\Documents and Settings\Administrator.CORRINA-GFYHSR2\Desktop\SmitfraudFix<br />
OS: Microsoft Windows 2000 [Version 5.00.2195] - Windows_NT<br />
The filesystem type is NTFS<br />
Fix run in normal mode<br />
<br />
»»»»»»»»»»»»»»»»»»»»»»»» Process<br />
<br />
C:\WINNT\System32\smss.exe<br />
C:\WINNT\system32\winlogon.exe<br />
C:\WINNT\system32\services.exe<br />
C:\WINNT\system32\lsass.exe<br />
C:\WINNT\system32\svchost.exe<br />
C:\WINNT\system32\spoolsv.exe<br />
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
C:\WINNT\System32\svchost.exe<br />
C:\Program Files\Roxio\GoBack\GBPoll.exe<br />
C:\WINNT\system32\regsvc.exe<br />
C:\WINNT\system32\MSTask.exe<br />
C:\WINNT\System32\WBEM\WinMgmt.exe<br />
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe<br />
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
C:\WINNT\Explorer.EXE<br />
C:\WINNT\system32\VTTimer.exe<br />
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe<br />
C:\Program Files\Pure Networks\Network Magic\nmapp.exe<br />
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Hamachi\hamachi.exe<br />
D:\Josh from C\Xfire\xfire.exe<br />
C:\WINNT\system32\rundll32.exe<br />
C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe<br />
C:\WINNT\System32\svchost.exe<br />
C:\WINNT\system32\rundll32.exe<br />
C:\WINNT\system32\cmd.exe<br />
<br />
»»»»»»»»»»»»»»»»»»»»»»»» hosts<br />
<br />
<br />
»»»»»»»»»»»»»»»»»»»»»»»» C:\<br />
<br />
<br />
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT<br />
<br />
<br />
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\system<br />
<br />
<br />
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\Web<br />
<br />
<br />
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\system32<br />
<br />
<br />
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrator.CORRINA-GFYHSR2<br />
<br />
<br />
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrator.CORRINA-GFYHSR2\Application Data<br />
<br />
<br />
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu<br />
<br />
<br />
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ADMINI~1.COR\FAVORI~1<br />
<br />
<br />
»»»»»»»»»»»»»»»»»»»»»»»» Desktop<br />
<br />
<br />
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files <br />
<br />
<br />
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys<br />
<br />
<br />
»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components<br />
<br />
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components]<br />
&quot;SubscribedURL&quot;=&quot;&quot;<br />
&quot;FriendlyName&quot;=&quot;Privacy Protection&quot;<br />
<br />
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]<br />
&quot;Source&quot;=&quot;about<b></b>:Home&quot;<br />
&quot;SubscribedURL&quot;=&quot;about<b></b>:Home&quot;<br />
&quot;FriendlyName&quot;=&quot;My Current Home Page&quot;<br />
<br />
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix<br />
!!!Attention, following keys are not inevitably infected!!!<br />
<br />
IEDFix<br />
Credits: Malware Analysis &amp; Diagnostic<br />
Code: S!Ri<br />
<br />
<br />
<br />
»»»»»»»»»»»»»»»»»»»»»»»» VACFix<br />
!!!Attention, following keys are not inevitably infected!!!<br />
<br />
VACFix<br />
Credits: Malware Analysis &amp; Diagnostic<br />
Code: S!Ri<br />
<br />
<br />
»»»»»»»»»»»»»»»»»»»»»»»» 404Fix<br />
!!!Attention, following keys are not inevitably infected!!!<br />
<br />
404Fix<br />
Credits: Malware Analysis &amp; Diagnostic<br />
Code: S!Ri<br />
<br />
<br />
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler<br />
!!!Attention, following keys are not inevitably infected!!!<br />
<br />
SrchSTS.exe by S!Ri<br />
Search SharedTaskScheduler's .dll<br />
<br />
<br />
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs<br />
!!!Attention, following keys are not inevitably infected!!!<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]<br />
&quot;AppInit_DLLs&quot;=&quot;avgrsstx.dll&quot;<br />
&quot;LoadAppInit_DLLs&quot;=dword:00000001<br />
<br />
<br />
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon<br />
!!!Attention, following keys are not inevitably infected!!!<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]<br />
&quot;Userinit&quot;=&quot;C:\\WINNT\\system32\\userinit.exe,&quot;<br />
&quot;System&quot;=&quot;&quot;<br />
<br />
<br />
»»»»»»»»»»»»»»»»»»»»»»»» Rustock<br />
<br />
<br />
<br />
»»»»»»»»»»»»»»»»»»»»»»»» DNS<br />
<br />
Description: VIA Rhine II Fast Ethernet Adapter <br />
DNS Server Search Order: 192.168.0.1<br />
<br />
HKLM\SYSTEM\CCS\Services\Tcpip\..\{FCDE184E-1B5C-414A-B4DC-F8A42796CF21}: DhcpNameServer=192.168.0.1<br />
HKLM\SYSTEM\CS1\Services\Tcpip\..\{FCDE184E-1B5C-414A-B4DC-F8A42796CF21}: DhcpNameServer=192.168.0.1<br />
HKLM\SYSTEM\CS2\Services\Tcpip\..\{FCDE184E-1B5C-414A-B4DC-F8A42796CF21}: DhcpNameServer=192.168.0.1<br />
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1<br />
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1<br />
<br />
<br />
»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection<br />
<br />
<br />
»»»»»»»»»»»»»»»»»»»»»»»» End</div> ]]></content:encoded>
			<wfw:commentRss>http://www.askhelpdesq.com/2008/07/24/no-desktop-no-taskbar-all-logs-inside/feed/</wfw:commentRss>
		</item>
		<item>
		<title>www.mobilestreet.net</title>
		<link>http://www.askhelpdesq.com/2008/07/24/wwwmobilestreetnet/</link>
		<comments>http://www.askhelpdesq.com/2008/07/24/wwwmobilestreetnet/#comments</comments>
		<pubDate>Thu, 24 Jul 2008 15:39:49 +0000</pubDate>
		<dc:creator>rehmanmajestic</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.askhelpdesq.com/2008/07/24/wwwmobilestreetnet/</guid>
		<description><![CDATA[*_WWW.MOBILESTREET.NET _*the largest collection of Mobile Themes, Games,Videos,Softwares,islamic section and many more.....Have a Fun Here]]></description>
			<content:encoded><![CDATA[<div><b><u><a rel="nofollow" href="http://WWW.MOBILESTREET.NET">WWW.MOBILESTREET.NET</a> </u></b>the largest collection of Mobile Themes, Games,Videos,Softwares,islamic section and many more&#8230;..Have a Fun Here</div>
No Tags]]></content:encoded>
			<wfw:commentRss>http://www.askhelpdesq.com/2008/07/24/wwwmobilestreetnet/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Wont reboot after partition made &#8220;active&#8221;</title>
		<link>http://www.askhelpdesq.com/2008/07/24/wont-reboot-after-partition-made-active/</link>
		<comments>http://www.askhelpdesq.com/2008/07/24/wont-reboot-after-partition-made-active/#comments</comments>
		<pubDate>Thu, 24 Jul 2008 12:06:21 +0000</pubDate>
		<dc:creator>neilo19</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.daniweb.com/forums/thread136481.html</guid>
		<description><![CDATA[Hello ,
I did something stupid and made a partitiion active and now it wont reboot (it says bootmgr missing) - Is there a way i can revert the partition back to its original state .

Thanks
neil]]></description>
			<content:encoded><![CDATA[<div>Hello ,<br />
I did something stupid and made a partitiion active and now it wont reboot (it says bootmgr missing) - Is there a way i can revert the partition back to its original state .<br />
<br />
Thanks<br />
neil</div> ]]></content:encoded>
			<wfw:commentRss>http://www.askhelpdesq.com/2008/07/24/wont-reboot-after-partition-made-active/feed/</wfw:commentRss>
		</item>
		<item>
		<title>quick check</title>
		<link>http://www.askhelpdesq.com/2008/07/24/quick-check/</link>
		<comments>http://www.askhelpdesq.com/2008/07/24/quick-check/#comments</comments>
		<pubDate>Thu, 24 Jul 2008 09:47:40 +0000</pubDate>
		<dc:creator>kevin wood</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.daniweb.com/forums/thread136461.html</guid>
		<description><![CDATA[my comp was very badly infected a couple of weeks ago i am now just checking to see if i am still all in the clear and my comp is infection free.  here is a copy of my hijack This log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:45:53, on 24/07/2008
Platform: Windows XP SP2 (WinNT...]]></description>
			<content:encoded><![CDATA[<div>my comp was very badly infected a couple of weeks ago i am now just checking to see if i am still all in the clear and my comp is infection free.  here is a copy of my hijack This log<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 10:45:53, on 24/07/2008<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16674)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Miramar\PC MACLAN\ATMsg.exe<br />
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\WINDOWS\system32\drivers\CDAC11BA.EXE<br />
C:\WINDOWS\System32\keyhook.exe<br />
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe<br />
C:\WINDOWS\SOUNDMAN.EXE<br />
C:\Program Files\PowerISO\PWRISOVM.EXE<br />
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe<br />
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe<br />
C:\Program Files\Search Settings\SearchSettings.exe<br />
C:\Program Files\iKnowPS\iKnowPS.exe<br />
C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe<br />
C:\spywarebegone\SpywareBeGone.exe<br />
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe<br />
C:\Program Files\Miramar\PC MACLAN\ATSERVER.EXE<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe<br />
C:\WINDOWS\system32\sistray.exe<br />
C:\Program Files\Miramar\PC MACLAN\ATSPOOL.EXE<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Macromedia\Dreamweaver 8\Dreamweaver.exe<br />
C:\Documents and Settings\Admin\Desktop\HiJackThis.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" href="http://go.microsoft.com/fwlink/?LinkId=69157">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" href="http://go.microsoft.com/fwlink/?LinkId=54896">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" href="http://go.microsoft.com/fwlink/?LinkId=54896">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" href="http://go.microsoft.com/fwlink/?LinkId=69157">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)<br />
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll<br />
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll<br />
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe<br />
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\System32\keyhook.exe<br />
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe<br />
O4 - HKLM\..\Run: [Miramar Systems, Inc.] C:\Program Files\Miramar\PC MACLAN\atmsg.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br />
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe<br />
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE<br />
O4 - HKLM\..\Run: [RemoteControl] &quot;C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe&quot;<br />
O4 - HKLM\..\Run: [Symantec PIF AlertEng] &quot;C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe&quot; /a /m &quot;C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe<br />
O4 - HKLM\..\Run: [iKnowPS] C:\Program Files\iKnowPS\iKnowPS.exe<br />
O4 - HKCU\..\Run: [Spyware Begone] &quot;C:\spywarebegone\SpywareBeGone.exe&quot; -FastScan<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')<br />
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br />
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe<br />
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br />
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br />
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O12 - Plugin for .htm: C:\Program Files\Netscape\Netscape Browser\PLUGINS\npTrident.dll<br />
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a rel="nofollow" href="http://go.microsoft.com/fwlink/?linkid=48835">http://go.microsoft.com/fwlink/?linkid=48835</a><br />
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - <a rel="nofollow" href="http://appldnld.m7z.net/content.info.apple.com/iTunes4/WW/win/019-0312.20050111.MmVrT/iTunesSetup.exe">http://appldnld.m7z.net/content.info...TunesSetup.exe</a><br />
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - <a rel="nofollow" href="http://by111fd.bay111.hotmail.msn.com/resources/MsnPUpld.cab">http://by111fd.bay111.hotmail.msn.co...s/MsnPUpld.cab</a><br />
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - <a rel="nofollow" href="http://www.crucial.com/controls/cpcScanner.cab">http://www.crucial.com/controls/cpcScanner.cab</a><br />
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - <a rel="nofollow" href="http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab">http://messenger.msn.com/download/Ms...Downloader.cab</a><br />
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br />
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br />
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
O23 - Service: AppleTalk Messenger (ATMsg) - Miramar Systems Inc. - C:\Program Files\Miramar\PC MACLAN\ATMsg.exe<br />
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br />
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE<br />
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br />
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)<br />
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe<br />
O23 - Service: Miramar AppleTalk File Server - Miramar Systems Inc. - C:\Program Files\Miramar\PC MACLAN\ATSERVER.EXE<br />
O23 - Service: Miramar AppleTalk Print Server - Miramar Systems Inc. - C:\Program Files\Miramar\PC MACLAN\ATSPOOL.EXE<br />
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe<br />
<br />
--<br />
End of file - 10141 bytes</div> ]]></content:encoded>
			<wfw:commentRss>http://www.askhelpdesq.com/2008/07/24/quick-check/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Revived HP Pav. troubles</title>
		<link>http://www.askhelpdesq.com/2008/07/23/revived-hp-pav-troubles/</link>
		<comments>http://www.askhelpdesq.com/2008/07/23/revived-hp-pav-troubles/#comments</comments>
		<pubDate>Thu, 24 Jul 2008 05:59:31 +0000</pubDate>
		<dc:creator>thia</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.daniweb.com/forums/thread136412.html</guid>
		<description><![CDATA[This is my first post, I hope I'm in the right spot. Here is my deal:
1.- Got a hold of an HP Pavilion a642n which was already abandoned by the owner as unfixable and replaced by a new DELL.
2.- Plugged it on and it purred on past the Windows XP HOME EDITION banner, went into Checkdisk and...]]></description>
			<content:encoded><![CDATA[<div>This is my first post, I hope I'm in the right spot. Here is my deal:<br />
1.- Got a hold of an HP Pavilion a642n which was already abandoned by the owner as unfixable and replaced by a new DELL.<br />
2.- Plugged it on and it purred on past the Windows XP HOME EDITION banner, went into Checkdisk and proceeded to record numerous bad allocations, fast job and just as fast it quit! Just went black until I turned off.<br />
3.-Like a nut, eager to put apart my new toy, I didn't hesitate, I tored into that case, disassemble the HDD and plugged it into my VISTA Comp. Surprise! It did the same thing, it went into Checkdisk only this time Checkdisk fixed all problems and it booted! HalleluYah!<br />
4.- Perhaps I sang victory too soon for when I plugged the drive back into the HP computer it no longer booted, but, then I realized that I had the option to press F10 and let HP take care of restoring the original config and finally it booted perfectly.<br />
5.-When it started the recovered XP HOME EDITION I began to clean up everything including the registry. I wanted to install the free AVG 8 ANTIVIRUS and it required the service pack 2. I installed the pack but I didn't installed any other updates prior to it. After Service Pack 2 installation it attempted to restar Windows. This was the first restar since the recovery. <br />
6.- As it was supposed to restar it only shut Windows, flashed a &quot;NO SIGNAL&quot; error and went into a black screen but it didn't restar.<br />
7.- Turned off comp. after a while and then on. It began reboot process flashed HP banner then a black screen then a line with a series of vertical lines, it took a while but eventually it went through the whole line of vertical lines, flashed the Windows XP logo and finally got to the Welcome and desktop.<br />
8.-Tried to restar again. Same No Signal error. Turned Off and On and this time I pressed F10 again and recover the system a second time.<br />
9.- This time when it finally opened Windows I just clicked to install updates. It installed 61 updates and required restar. Same situation with the NO SIGNAL error.<br />
10,- Turned off and on and when it eventually loaded Windows after the line of vertical lines and all flashes of Windows banners and Welcome screen.<br />
11.- This time it wanted to install updates again. I clicked to install updates. It installed 1 update: Windows Service Pack 2 and went into restar and No Signal error again.<br />
12.-This time when it went into desktop it flashed, &quot;your computer might be at risk, no Antivirus.&quot; I proceeded to install the Free Avg 8 and googled the 'NO SIGNAL ERROR&quot; clicked the first link and got to your site.<br />
13.- I connected my USB printer and printed the posts about the NO SIGNAL error. I followed all instructions to a point for the Video card is stuck and I can't get it off the PCI slot. I did pressed and made sure that the card was properly seated and checked the cable. The cable connector is missing one little prong so I plugged the comp. to a brand new monitor with the same results, so it's not the monitor's fault.<br />
14.- So, I registered and now I'm posting this in hopes that somebody can figure out what should I do next to get the computer to restar on its own.<br />
15.- I would like to check the MB but I don't know how. I'm taking an A+ CERTIFICATION course on line and I'm learning the way but I got a long ways to go. This situation with the HP computer is one of the issues I'm dealing with. I am 69 years old, a writer and believer of the WAY of Yahushua, our Savior. I'm not into religion just living this blessed life style which includes the computer world. I've been dealing with these machines since 1985 on my own and this is kind of the first time that I am seeking professional help and, blessed I am to have found your site. I want to learn the technical in and outs of the computer world in order to help out all my pauper friends who had no money or time to fix their mess up computers. It's sort like a ministry and a well needed service in my midst. Pray that you all brilliant gurus take pity on me and help me out in this endeavor.<br />
Thanks,<br />
thia</div> ]]></content:encoded>
			<wfw:commentRss>http://www.askhelpdesq.com/2008/07/23/revived-hp-pav-troubles/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Infected with Hoax.Win32.Renos.vaoz. Please Help!!</title>
		<link>http://www.askhelpdesq.com/2008/07/23/infected-with-hoaxwin32renosvaoz-please-help/</link>
		<comments>http://www.askhelpdesq.com/2008/07/23/infected-with-hoaxwin32renosvaoz-please-help/#comments</comments>
		<pubDate>Thu, 24 Jul 2008 00:28:03 +0000</pubDate>
		<dc:creator>sebber</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.daniweb.com/forums/thread136372.html</guid>
		<description><![CDATA[Hi there,

This is my first post and I have already found this post extremely helpful. It's made a tough situation a lot easier.

I bought a brand new PC last week and was online last night. Everything was going fantastically. The PC was running slickly and I was being extra careful in what...]]></description>
			<content:encoded><![CDATA[<div>Hi there,<br />
<br />
This is my first post and I have already found this post extremely helpful. It's made a tough situation a lot easier.<br />
<br />
I bought a brand new PC last week and was online last night. Everything was going fantastically. The PC was running slickly and I was being extra careful in what programs I was installing.<br />
<br />
Anyway, whilst browsing last night I was struck by a huge virus/malware &quot;hijack&quot; which threw my PC into a tailspin. Have never encountered anything like this before. While over the last 24 hours I have tried a number of the fixes suggested -  ATF Cleaner, ComboFix, Malwarebytes, DSS (which won't run) and HiJackThis. I have also used CCleaner, Registry Mechanic, Rogue Remover - I still haven't nailed it. You could say it's overkill!<br />
<br />
The edge has certainly been taken off the virus, but the PC is now running quite sluggishly. This is a huge disappointment, naturally. I have used my pre-installed software, BitDefender 2008, and then downloaded and used AVG anti-virus. <br />
<br />
Below I have included ALL my scans, in the hope that some kind soul will be able to help me. It would be most appreciated and I would be happy to donate to the forum.<br />
<br />
I have also used the online &quot;free scan&quot; version of Kaspersky. Most of the programs report that the system is <i>clean</i>, but Kaspersky's online scan reported the following:<br />
<br />
Wednesday, July 23, 2008<br />
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)<br />
<b>Kaspersky Online Scanner 7 version: 7.0.25.0</b><br />
Program database last update: Wednesday, July 23, 2008 21:51:10<br />
Records in database: 999411<br />
Scan settings<br />
Scan using the following database 	extended<br />
Scan archives 	yes<br />
Scan mail databases 	yes<br />
Scan area 	Critical Areas<br />
C:\Documents and Settings\All Users\Start Menu\Programs\Startup<br />
C:\Documents and Settings\Paul\Start Menu\Programs\Startup<br />
C:\Program Files<br />
C:\WINDOWS<br />
Scan statistics<br />
Files scanned 	53731<br />
Threat name 	2<br />
Infected objects 	3<br />
Suspicious objects 	0<br />
Duration of the scan 	00:38:03<br />
<br />
File name 	Threat name 	Threats count<br />
<b>C:\WINDOWS\system32\IEDFix.C.exe	Infected: Hoax.Win32.Renos.vaoz	1	<br />
C:\WINDOWS\system32\IEDFix.exe	Infected: Hoax.Win32.Renos.vaoz	1	<br />
C:\WINDOWS\system32\Tools\Restart.exe	 Infected: not-a-virus:RiskTool.Win32.Reboot.j	</b>1	<br />
The selected area was scanned.<br />
-----------------------------------------------------------------<br />
<br />
<b><u>ComboFix 08-07-22.4 </u></b>- Paul 2008-07-23 11:27:30.1 - NTFSx86<br />
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.2360 [GMT 1:00]<br />
Running from: C:\Documents and Settings\Paul\Desktop\ComboFix.exe<br />
 * Created a new restore point<br />
 * Resident AV is active<br />
<br />
<br />
<b>WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!</b><br />
.<br />
<br />
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br />
<br />
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat<br />
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat<br />
C:\Documents and Settings\Jenna\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML<br />
C:\Documents and Settings\Paul\Application Data\inst.exe<br />
C:\Documents and Settings\Paul\Favorites\Error Cleaner.url<br />
C:\Documents and Settings\Paul\Favorites\Privacy Protector.url<br />
C:\Documents and Settings\Paul\Favorites\Spyware&amp;Malware Protection.url<br />
C:\WINDOWS\system32\erpyiciv.dll<br />
C:\WINDOWS\system32\iifeBspN.dll<br />
C:\WINDOWS\system32\mcrh.tmp<br />
C:\WINDOWS\system32\opnnmJyA.dll<br />
C:\WINDOWS\system32\qrBacfii.ini<br />
C:\WINDOWS\system32\qrBacfii.ini2<br />
C:\WINDOWS\system32\viciypre.ini<br />
<br />
----- BITS: Possible infected sites -----<br />
<br />
http://au.download.windowsupdaj+|Cv+@J:NGD_DQ{zcxLJS@a,D$@!<br />
.<br />
(((((((((((((((((((((((((   Files Created from 2008-06-23 to 2008-07-23  )))))))))))))))))))))))))))))))<br />
.<br />
<br />
2008-07-23 03:41 . 2008-06-10 02:32	73,728	--a------	C:\WINDOWS\system32\javacpl.cpl<br />
2008-07-23 03:40 . 2008-07-23 03:41	&lt;DIR&gt;	d--------	C:\Program Files\Java<br />
2008-07-23 03:40 . 2008-07-23 03:40	&lt;DIR&gt;	d--------	C:\Program Files\Common Files\Java<br />
2008-07-23 03:03 . 2008-07-23 03:54	3,986	--a------	C:\WINDOWS\system32\tmp.reg<br />
2008-07-23 03:02 . 2007-09-06 00:22	289,144	--a------	C:\WINDOWS\system32\VCCLSID.exe<br />
2008-07-23 03:02 . 2006-04-27 17:49	288,417	--a------	C:\WINDOWS\system32\SrchSTS.exe<br />
2008-07-23 03:02 . 2008-05-29 09:35	86,528	--a------	C:\WINDOWS\system32\VACFix.exe<br />
2008-07-23 03:02 . 2008-05-18 21:40	82,944	--a------	C:\WINDOWS\system32\IEDFix.exe<br />
2008-07-23 03:02 . 2008-07-02 13:33	82,432	--a------	C:\WINDOWS\system32\IEDFix.C.exe<br />
2008-07-23 03:02 . 2008-05-23 18:21	81,920	--a------	C:\WINDOWS\system32\404Fix.exe<br />
2008-07-23 03:02 . 2003-06-05 21:13	53,248	--a------	C:\WINDOWS\system32\Process.exe<br />
2008-07-23 03:02 . 2004-07-31 18:50	51,200	--a------	C:\WINDOWS\system32\dumphive.exe<br />
2008-07-23 03:02 . 2007-10-04 00:36	25,600	--a------	C:\WINDOWS\system32\WS2Fix.exe<br />
2008-07-23 02:35 . 2008-07-23 11:01	&lt;DIR&gt;	d--h-----	C:\$AVG8.VAULT$<br />
2008-07-23 02:33 . 2008-07-23 02:35	&lt;DIR&gt;	d--------	C:\WINDOWS\system32\drivers\Avg<br />
2008-07-23 02:33 . 2008-07-23 02:33	&lt;DIR&gt;	d--------	C:\Program Files\AVG<br />
2008-07-23 02:33 . 2008-07-23 02:33	&lt;DIR&gt;	d--------	C:\Documents and Settings\All Users\Application Data\avg8<br />
2008-07-23 02:33 . 2008-07-23 02:33	96,520	--a------	C:\WINDOWS\system32\drivers\avgldx86.sys<br />
2008-07-23 02:33 . 2008-07-23 02:33	76,040	--a------	C:\WINDOWS\system32\drivers\avgtdix.sys<br />
2008-07-23 02:33 . 2008-07-23 02:33	12,936	--a------	C:\WINDOWS\system32\drivers\avgrkx86.sys<br />
2008-07-23 02:33 . 2008-07-23 02:33	10,520	--a------	C:\WINDOWS\system32\avgrsstx.dll<br />
2008-07-23 02:07 . 2008-07-23 02:08	&lt;DIR&gt;	d--------	C:\Program Files\RogueRemover FREE<br />
2008-07-23 01:42 . 2008-07-23 01:42	&lt;DIR&gt;	d--------	C:\Program Files\Enigma Software Group<br />
2008-07-23 01:39 . 2008-07-23 01:39	323,648	--a------	C:\WINDOWS\system32\iifcaBrq.dll<br />
2008-07-22 20:09 . 1999-10-11 02:00	41,984	---------	C:\WINDOWS\Ctregrun.exe<br />
2008-07-22 20:08 . 2008-07-22 22:08	&lt;DIR&gt;	d--------	C:\Program Files\Audible<br />
2008-07-22 20:08 . 2008-07-22 20:08	417,792	--a------	C:\WINDOWS\system32\awrdscdc.ax<br />
2008-07-22 20:07 . 2008-07-22 20:07	&lt;DIR&gt;	d--------	C:\Documents and Settings\All Users\Application Data\Creative<br />
2008-07-22 20:05 . 2008-07-22 20:05	&lt;DIR&gt;	d--------	C:\Documents and Settings\Paul\Application Data\Apple Computer<br />
2008-07-22 02:53 . 2008-07-22 22:05	&lt;DIR&gt;	d--------	C:\Documents and Settings\Paul\Application Data\Creative<br />
2008-07-22 02:48 . 2008-07-22 02:49	&lt;DIR&gt;	d--h-----	C:\Program Files\Creative Installation Information<br />
2008-07-22 02:48 . 2008-07-22 20:09	&lt;DIR&gt;	d--------	C:\Program Files\Creative<br />
2008-07-22 02:48 . 2008-07-22 02:48	&lt;DIR&gt;	d--------	C:\Program Files\Common Files\Creative<br />
2008-07-22 02:48 . 1999-12-13 01:01	44,032	--a------	C:\WINDOWS\system32\CTSVCCDA.EXE<br />
2008-07-22 02:48 . 1999-11-18 01:00	25,088	--a------	C:\WINDOWS\system32\CTSVCCTL.EXE<br />
2008-07-22 00:20 . 2008-07-22 01:26	&lt;DIR&gt;	d--------	C:\Program Files\Arachnophilia<br />
2008-07-21 23:33 . 2008-07-21 23:33	78	--a------	C:\WINDOWS\Numerical<br />
2008-07-21 22:00 . 2008-07-21 22:00	76	--a------	C:\WINDOWS\Spatial<br />
2008-07-20 02:04 . 2008-07-20 02:04	&lt;DIR&gt;	d--------	C:\Documents and Settings\All Users\Application Data\FLEXnet<br />
2008-07-20 01:58 . 2008-07-20 01:58	&lt;DIR&gt;	d--------	C:\Program Files\Common Files\Macrovision Shared<br />
2008-07-20 01:57 . 2008-04-07 05:38	45,392	-ra------	C:\WINDOWS\system32\AdobePDF.dll<br />
2008-07-20 01:57 . 2008-04-07 05:38	22,872	-ra------	C:\WINDOWS\system32\AdobePDFUI.dll<br />
2008-07-20 01:53 . 2008-07-20 01:58	&lt;DIR&gt;	d--------	C:\Program Files\Common Files\Adobe<br />
2008-07-20 00:38 . 2008-07-20 00:46	&lt;DIR&gt;	d--------	C:\Program Files\Yahoo!<br />
2008-07-20 00:37 . 2008-07-20 00:38	&lt;DIR&gt;	d--------	C:\Program Files\CCleaner<br />
2008-07-19 21:19 . 2008-07-22 17:53	&lt;DIR&gt;	d--------	C:\Documents and Settings\Paul\Application Data\CopyToDvd<br />
2008-07-19 21:01 . 2008-07-19 21:01	&lt;DIR&gt;	d--------	C:\Program Files\Windows Media Connect 2<br />
2008-07-19 21:00 . 2008-07-19 21:10	&lt;DIR&gt;	d--------	C:\WINDOWS\system32\LogFiles<br />
2008-07-19 21:00 . 2008-07-22 02:09	&lt;DIR&gt;	d--------	C:\WINDOWS\system32\drivers\UMDF<br />
2008-07-19 20:51 . 2008-07-22 23:44	54,156	--ah-----	C:\WINDOWS\QTFont.qfn<br />
2008-07-19 20:51 . 2008-07-19 20:51	1,409	--a------	C:\WINDOWS\QTFont.for<br />
2008-07-19 18:12 . 2008-07-19 21:07	&lt;DIR&gt;	d--------	C:\Program Files\Spybot - Search &amp; Destroy<br />
2008-07-19 18:12 . 2008-07-19 21:07	&lt;DIR&gt;	d--------	C:\Documents and Settings\All Users\Application Data\Spybot - Search &amp; Destroy<br />
2008-07-19 12:04 . 2008-07-19 12:04	&lt;DIR&gt;	d--------	C:\Program Files\dvd43<br />
2008-07-19 12:04 . 2008-07-19 12:04	18,816	--a------	C:\WINDOWS\system32\drivers\dvd43llh.sys<br />
2008-07-19 11:55 . 2008-07-19 11:55	&lt;DIR&gt;	d--------	C:\Documents and Settings\Paul\Application Data\DivX<br />
2008-07-19 11:14 . 2008-07-21 23:32	74	--a------	C:\WINDOWS\Logic<br />
2008-07-19 03:13 . 2008-07-19 03:13	82	--a------	C:\WINDOWS\Getting Started.htm<br />
2008-07-19 03:13 . 2008-07-21 22:00	75	--a------	C:\WINDOWS\Verbal<br />
2008-07-19 03:13 . 2008-07-21 23:41	75	--a------	C:\WINDOWS\Memory<br />
2008-07-19 02:29 . 2008-07-19 03:11	76	--a------	C:\WINDOWS\1<br />
2008-07-19 02:27 . 2008-07-19 03:05	&lt;DIR&gt;	d--------	C:\WINDOWS\system32\Brain Trainer<br />
2008-07-19 02:27 . 2008-07-19 02:27	&lt;DIR&gt;	d--------	C:\Program Files\Mindscape<br />
2008-07-19 02:19 . 2008-07-19 02:19	&lt;DIR&gt;	d--------	C:\Program Files\PowerISO<br />
2008-07-19 01:11 . 2008-07-19 01:11	&lt;DIR&gt;	d--------	C:\Program Files\Brain Spa<br />
2008-07-19 01:11 . 2008-07-19 01:11	&lt;DIR&gt;	d--------	C:\Documents and Settings\Paul\Application Data\Ubisoft<br />
2008-07-19 00:09 . 2008-07-21 21:59	729	--a------	C:\WINDOWS\<u>0</u><br />
2008-07-19 00:09 . 2008-07-21 21:59	73	--a------	C:\WINDOWS\Times New Roman<br />
2008-07-18 23:31 . 2008-07-18 23:31	&lt;DIR&gt;	d--------	C:\Program Files\Common Files\CyberLink<br />
2008-07-18 23:30 . 2001-08-17 22:43	24,576	--a------	C:\WINDOWS\system32\msxml3a.dll<br />
2008-07-18 23:28 . 2008-07-18 23:28	&lt;DIR&gt;	d--------	C:\Documents and Settings\Paul\Application Data\CyberLink<br />
2008-07-18 23:13 . 2008-07-18 23:38	&lt;DIR&gt;	d--------	C:\Documents and Settings\All Users\Application Data\CyberLink<br />
2008-07-18 23:08 . 2008-07-18 23:08	31	--a------	C:\WINDOWS\papp.ini<br />
2008-07-18 22:38 . 2008-07-18 22:38	32	--a------	C:\WINDOWS\PracticalTest.ini<br />
2008-07-18 21:59 . 2008-07-18 21:59	&lt;DIR&gt;	d--------	C:\Program Files\Absolute Media Software<br />
2008-07-18 01:17 . 2008-07-18 01:17	&lt;DIR&gt;	d--------	C:\Documents and Settings\Jenna\Application Data\Ahead<br />
2008-07-18 01:16 . 2008-07-18 01:16	&lt;DIR&gt;	d--------	C:\Documents and Settings\Jenna\Application Data\DivX<br />
2008-07-18 01:11 . 2008-07-18 01:11	&lt;DIR&gt;	d--------	C:\Documents and Settings\Jenna\Application Data\BitDefender<br />
2008-07-18 01:11 . 2008-07-23 03:58	&lt;DIR&gt;	d--------	C:\Documents and Settings\Jenna<br />
2008-07-18 01:06 . 2008-07-18 01:06	&lt;DIR&gt;	d--------	C:\Program Files\Moss Bay Software<br />
2008-07-18 00:48 . 2008-07-18 00:48	&lt;DIR&gt;	d--------	C:\Documents and Settings\Paul\Application Data\Systweak<br />
2008-07-18 00:38 . 2008-07-18 00:38	&lt;DIR&gt;	d--------	C:\Documents and Settings\Paul\Downloads<br />
2008-07-18 00:37 . 2008-07-18 00:37	&lt;DIR&gt;	d--------	C:\Program Files\NewsLeecher<br />
2008-07-18 00:37 . 2008-07-18 01:07	&lt;DIR&gt;	d--------	C:\Documents and Settings\Paul\Application Data\NewsLeecher<br />
2008-07-18 00:30 . 2008-07-18 00:30	&lt;DIR&gt;	d--------	C:\Program Files\SmartSound Software<br />
2008-07-18 00:30 . 2008-07-19 01:33	&lt;DIR&gt;	d--------	C:\Program Files\DivX<br />
2008-07-18 00:30 . 2008-07-18 00:30	&lt;DIR&gt;	d--------	C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc<br />
2008-07-18 00:28 . 2008-07-18 00:44	&lt;DIR&gt;	d--------	C:\Program Files\Neuro-Programmer 2 Professional<br />
2008-07-18 00:27 . 2008-07-18 23:19	&lt;DIR&gt;	d--------	C:\Program Files\Cyberlink<br />
2008-07-18 00:26 . 2008-07-18 00:26	&lt;DIR&gt;	d--------	C:\Program Files\QuickTime<br />
2008-07-18 00:24 . 2008-07-18 00:24	&lt;DIR&gt;	d--------	C:\Documents and Settings\All Users\Application Data\Apple Computer<br />
2008-07-18 00:23 . 2008-07-18 00:23	&lt;DIR&gt;	d--------	C:\MyWorks<br />
2008-07-17 23:28 . 2008-07-17 23:28	&lt;DIR&gt;	d--------	C:\Program Files\Driving Test Success 2006-2007<br />
2008-07-17 23:28 . 2008-07-18 23:44	&lt;DIR&gt;	d--------	C:\Documents and Settings\All Users\Application Data\Driving Test Success<br />
2008-07-17 23:24 . 2008-07-17 23:24	&lt;DIR&gt;	d--------	C:\{3B07D847-8077-4242-91C7-DFA3CE5113E0}<br />
2008-07-17 23:23 . 2008-07-17 23:24	&lt;DIR&gt;	d--------	C:\MWASPI<br />
2008-07-17 23:23 . 2008-07-17 23:23	133	--a------	C:\WINDOWS\msfsetup.ini<br />
2008-07-17 23:20 . 2008-07-17 23:20	&lt;DIR&gt;	d--------	C:\Program Files\PIXELA<br />
2008-07-17 23:20 . 2008-07-17 23:20	&lt;DIR&gt;	d--------	C:\Program Files\Caplio Software<br />
2008-07-17 23:13 . 2008-07-17 23:15	&lt;DIR&gt;	d--------	C:\Program Files\WinAVI Video Converter<br />
2008-07-17 22:58 . 2008-07-17 22:58	&lt;DIR&gt;	d--------	C:\Program Files\XviD<br />
2008-07-17 22:58 . 2008-07-19 11:58	&lt;DIR&gt;	d--------	C:\Program Files\AoA DVD Ripper<br />
2008-07-17 22:58 . 2006-08-23 22:08	1,839,104	--a------	C:\WINDOWS\system32\avcodec-51.dll<br />
2008-07-17 22:57 . 2008-07-19 21:23	&lt;DIR&gt;	d--------	C:\Documents and Settings\All Users\Application Data\1Click DVD Copy Pro<br />
2008-07-17 22:56 . 2008-07-17 22:56	&lt;DIR&gt;	d--------	C:\Program Files\LG Software Innovations<br />
2008-07-17 22:53 . 2008-07-17 22:53	0	--a------	C:\WINDOWS\nsreg.dat<br />
2008-07-17 22:50 . 2008-07-17 22:50	&lt;DIR&gt;	d--------	C:\Program Files\VSO<br />
2008-07-17 22:50 . 2008-07-22 17:53	&lt;DIR&gt;	d--------	C:\Documents and Settings\Paul\Application Data\Vso<br />
2008-07-17 22:50 . 2008-07-17 22:50	47,360	--a------	C:\WINDOWS\system32\drivers\pcouffin.sys<br />
2008-07-17 22:50 . 2008-07-17 22:50	47,360	--a------	C:\Documents and Settings\Paul\Application Data\pcouffin.sys<br />
2008-07-17 22:38 . 2008-07-23 04:47	69	--a------	C:\WINDOWS\NeroDigital.ini<br />
2008-07-17 22:31 . 2008-07-17 22:31	&lt;DIR&gt;	d--h-----	C:\Documents and Settings\All Users\Application Data\CanonBJ<br />
2008-07-17 22:31 . 2005-08-25 21:00	140,288	--a------	C:\WINDOWS\system32\CNMLM7L.DLL<br />
2008-07-17 22:31 . 2008-04-14 00:17	25,856	--a------	C:\WINDOWS\system32\drivers\usbprint.sys<br />
2008-07-17 22:31 . 2008-04-14 00:17	25,856	--a--c---	C:\WINDOWS\system32\dllcache\usbprint.sys<br />
2008-07-17 22:31 . 2005-08-25 21:00	8,704	--a------	C:\WINDOWS\system32\CNMVS7L.DLL<br />
2008-07-17 22:30 . 2008-04-14 00:15	32,128	--a------	C:\WINDOWS\system32\drivers\usbccgp.sys<br />
2008-07-17 22:30 . 2008-04-14 00:15	32,128	--a--c---	C:\WINDOWS\system32\dllcache\usbccgp.sys<br />
2008-07-17 22:30 . 2008-04-14 00:15	15,104	--a------	C:\WINDOWS\system32\drivers\usbscan.sys<br />
2008-07-17 22:30 . 2008-04-14 00:15	15,104	--a--c---	C:\WINDOWS\system32\dllcache\usbscan.sys<br />
2008-07-17 22:20 . 2008-07-17 22:20	&lt;DIR&gt;	d--------	C:\Program Files\ScanSoft<br />
2008-07-17 22:20 . 2008-07-17 22:20	&lt;DIR&gt;	d--------	C:\Program Files\Common Files\ScanSoft Shared<br />
2008-07-17 22:20 . 2008-07-17 22:20	&lt;DIR&gt;	d--------	C:\Documents and Settings\Paul\Application Data\ScanSoft<br />
2008-07-17 22:20 . 2008-07-17 22:20	&lt;DIR&gt;	d--------	C:\Documents and Settings\All Users\Application Data\SSScanWizard<br />
2008-07-17 22:20 . 2008-07-17 22:20	&lt;DIR&gt;	d--------	C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir<br />
<br />
.<br />
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br />
2008-07-22 20:37	---------	d--h--w	C:\Program Files\InstallShield Installation Information<br />
2008-07-17 21:17	---------	d-----w	C:\Program Files\Common Files\InstallShield<br />
2008-07-14 16:52	---------	d-----w	C:\Program Files\VIA<br />
2008-07-14 16:42	---------	d-----w	C:\Program Files\microsoft frontpage<br />
2008-06-18 17:52	161,096	----a-w	C:\WINDOWS\system32\DivXCodecVersionChecker.exe<br />
2008-06-11 22:43	111,992	----a-w	C:\WINDOWS\system32\acaptuser32.dll<br />
2008-06-11 00:07	524,288	----a-w	C:\WINDOWS\system32\DivXsm.exe<br />
2008-06-11 00:07	43,528	----a-w	C:\WINDOWS\system32\drivers\PxHelp20.sys<br />
2008-06-11 00:07	3,596,288	----a-w	C:\WINDOWS\system32\qt-dx331.dll<br />
2008-06-11 00:07	129,784	----a-w	C:\WINDOWS\system32\pxafs.dll<br />
2008-06-11 00:07	120,056	----a-w	C:\WINDOWS\system32\pxcpyi64.exe<br />
2008-06-11 00:07	118,520	----a-w	C:\WINDOWS\system32\pxinsi64.exe<br />
2008-06-11 00:04	200,704	----a-w	C:\WINDOWS\system32\ssldivx.dll<br />
2008-06-11 00:04	1,044,480	----a-w	C:\WINDOWS\system32\libdivx.dll<br />
2008-05-22 22:18	12,288	----a-w	C:\WINDOWS\system32\DivXWMPExtType.dll<br />
2008-05-09 10:53	90,112	----a-w	C:\WINDOWS\system32\wshext.dll<br />
2008-05-09 10:53	430,080	----a-w	C:\WINDOWS\system32\vbscript.dll<br />
2008-05-09 10:53	180,224	----a-w	C:\WINDOWS\system32\scrobj.dll<br />
2008-05-09 10:53	172,032	----a-w	C:\WINDOWS\system32\scrrun.dll<br />
2008-05-08 11:24	155,648	----a-w	C:\WINDOWS\system32\wscript.exe<br />
2008-05-07 09:07	135,168	----a-w	C:\WINDOWS\system32\cscript.exe<br />
2008-05-07 05:12	1,288,192	----a-w	C:\WINDOWS\system32\quartz.dll<br />
2008-04-23 04:16	826,368	----a-w	C:\WINDOWS\system32\wininet.dll<br />
.<br />
<br />
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br />
.<br />
.<br />
*Note* empty entries &amp; legit default entries are not shown <br />
REGEDIT4<br />
<br />
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02319437-08C3-4EE5-8DD3-BFAB00582FD1}]<br />
2008-07-23 01:39	323648	--a------	C:\WINDOWS\system32\iifcaBrq.dll<br />
<br />
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />
&quot;RoboForm&quot;=&quot;C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe&quot; [2008-07-17 22:04 160592]<br />
&quot;ctfmon.exe&quot;=&quot;C:\WINDOWS\system32\ctfmon.exe&quot; [2008-04-14 13:00 15360]<br />
&quot;Creative MediaSource Go&quot;=&quot;C:\Program Files\Creative\MediaSource5\Go\CTCMSGoU.exe&quot; [2006-11-09 10:19 204800]<br />
&quot;WMPNSCFG&quot;=&quot;C:\Program Files\Windows Media Player\WMPNSCFG.exe&quot; [2006-10-18 20:05 204288]<br />
&quot;CTSyncU.exe&quot;=&quot;C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe&quot; [2006-09-28 20:09 700416]<br />
&quot;RegistryMechanic&quot;=&quot;C:\Program Files\Registry Mechanic\RegMech.exe&quot; [2008-07-08 16:41 2828184]<br />
<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />
&quot;HDAudDeck&quot;=&quot;C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe&quot; [2007-06-29 10:51 811008]<br />
&quot;NvCplDaemon&quot;=&quot;C:\WINDOWS\system32\NvCpl.dll&quot; [2008-05-16 14:01 13529088]<br />
&quot;NvMediaCenter&quot;=&quot;C:\WINDOWS\system32\NvMcTray.dll&quot; [2008-05-16 14:01 86016]<br />
&quot;NeroFilterCheck&quot;=&quot;C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe&quot; [2007-03-01 15:57 153136]<br />
&quot;BitDefender Antiphishing Helper&quot;=&quot;C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe&quot; [2007-10-09 15:46 61440]<br />
&quot;BDAgent&quot;=&quot;C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe&quot; [2008-07-15 15:26 360448]<br />
&quot;OpwareSE2&quot;=&quot;C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe&quot; [2003-05-08 11:00 49152]<br />
&quot;QuickTime Task&quot;=&quot;C:\Program Files\QuickTime\qttask.exe&quot; [2008-07-18 00:26 282624]<br />
&quot;RemoteControl8&quot;=&quot;C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe&quot; [2008-03-20 20:23 83240]<br />
&quot;PDVD8LanguageShortcut&quot;=&quot;C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe&quot; [2007-12-14 11:36 50472]<br />
&quot;BDRegion&quot;=&quot;C:\Program Files\Cyberlink\Shared Files\brs.exe&quot; [2008-05-19 15:24 91432]<br />
&quot;PWRISOVM.EXE&quot;=&quot;C:\Program Files\PowerISO\PWRISOVM.EXE&quot; [2008-07-07 08:34 167936]<br />
&quot;dvd43&quot;=&quot;C:\Program Files\dvd43\dvd43_tray.exe&quot; [2008-04-09 10:00 826880]<br />
&quot;Adobe Acrobat Speed Launcher&quot;=&quot;C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe&quot; [2008-06-12 02:25 37232]<br />
&quot;Acrobat Assistant 8.0&quot;=&quot;C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe&quot; [2008-06-11 22:43 640376]<br />
&quot;AVG8_TRAY&quot;=&quot;C:\PROGRA~1\AVG\AVG8\avgtray.exe&quot; [2008-07-23 02:33 1232152]<br />
&quot;SunJavaUpdateSched&quot;=&quot;C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe&quot; [2008-06-10 04:27 144784]<br />
&quot;nwiz&quot;=&quot;nwiz.exe&quot; [2008-05-16 14:01 1630208 C:\WINDOWS\system32\nwiz.exe]<br />
<br />
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&quot;CTFMON.EXE&quot;=&quot;C:\WINDOWS\system32\CTFMON.EXE&quot; [2008-04-14 13:00 15360]<br />
<br />
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]<br />
&quot;AppInit_DLLs&quot;=acaptuser32.dll,avgrsstx.dll<br />
<br />
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]<br />
Authentication Packages	REG_MULTI_SZ   	msv1_0 C:\WINDOWS\system32\iifcaBrq<br />
<br />
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br />
&quot;%windir%\\Network Diagnostic\\xpnetdiag.exe&quot;=<br />
&quot;%windir%\\system32\\sessmgr.exe&quot;=<br />
&quot;C:\\Program Files\\Vuze\\Azureus.exe&quot;=<br />
&quot;C:\\WINDOWS\\system32\\ftp.exe&quot;=<br />
&quot;C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE&quot;=<br />
&quot;C:\\Program Files\\AVG\\AVG8\\avgupd.exe&quot;=<br />
&quot;C:\\Program Files\\AVG\\AVG8\\avgnsx.exe&quot;=<br />
<br />
R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-07-23 02:33]<br />
R0 ViBus;ViBus;C:\WINDOWS\system32\DRIVERS\ViBus.sys [2007-03-26 08:26]<br />
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2007-03-29 04:36]<br />
R0 ViPrt;VIA SATA IDE Device Driver;C:\WINDOWS\system32\DRIVERS\ViPrt.sys [2007-03-26 08:26]<br />
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-23 02:33]<br />
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};C:\Program Files\CyberLink\PowerDVD8\<u>0</u>00.fcl [2008-05-15 12:07]<br />
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-23 02:33]<br />
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-23 02:33]<br />
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\WINDOWS\system32\DRIVERS\bdfndisf.sys [2008-01-25 15:40]<br />
S3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2007-04-17 04:58]<br />
<br />
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]<br />
bdx	REG_MULTI_SZ   	scan<br />
.<br />
- - - - ORPHANS REMOVED - - - -<br />
<br />
HKLM-Run-08ef696d - C:\WINDOWS\system32\erpyiciv.dll<br />
SSODL-kvxqmtre-{3C5E1F15-D12B-449E-BEB3-A800FE6FC549} - (no file)<br />
SSODL-evgratsm-{2280B776-3099-4352-B500-399D6E8B90C5} - (no file)<br />
Notify-ddcBSMgG - ddcBSMgG.dll<br />
<br />
<br />
.<br />
------- Supplementary Scan -------<br />
.<br />
R0 -: HKCU-Main,Start Page = <a rel="nofollow" href="http://www.google.com">www.google.com</a><br />
O8 -: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br />
O8 -: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html<br />
O8 -: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br />
O8 -: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html<br />
O8 -: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html<br />
O8 -: E&amp;xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O8 -: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html<br />
O8 -: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html<br />
O8 -: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html<br />
O8 -: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html<br />
O8 -: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html<br />
O8 -: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html<br />
O8 -: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html<br />
<br />
<br />
**************************************************************************<br />
<br />
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, <a rel="nofollow" href="http://www.gmer.net">http://www.gmer.net</a><br />
Rootkit scan 2008-07-23 11:31:44<br />
Windows 5.1.2600 Service Pack 3 NTFS<br />
<br />
scanning hidden processes ... <br />
<br />
scanning hidden autostart entries ...<br />
<br />
scanning hidden files ... <br />
<br />
<br />
C:\WINDOWS\system32\qrBacfii.ini 347 bytes<br />
C:\WINDOWS\system32\qrBacfii.ini2 347 bytes<br />
<br />
scan completed successfully<br />
hidden files: 2<br />
<br />
**************************************************************************<br />
<br />
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]<br />
&quot;ImagePath&quot;=&quot;\??\C:\Program Files\CyberLink\PowerDVD8\<u>0</u>00.fcl&quot;<br />
.<br />
--------------------- DLLs Loaded Under Running Processes ---------------------<br />
<br />
PROCESS: C:\WINDOWS\explorer.exe<br />
-&gt; C:\WINDOWS\system32\iifcaBrq.dll<br />
.<br />
------------------------ Other Running Processes ------------------------<br />
.<br />
C:\WINDOWS\system32\CTSVCCDA.EXE<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\Program Files\Cyberlink\Shared files\RichVideo.exe<br />
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe<br />
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe<br />
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\PROGRA~1\AVG\AVG8\avgam.exe<br />
C:\Program Files\AVG\AVG8\avgrsx.exe<br />
C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
.<br />
**************************************************************************<br />
.<br />
Completion time: 2008-07-23 11:34:38 - machine was rebooted<br />
ComboFix-quarantined-files.txt  2008-07-23 10:34:31<br />
<br />
Pre-Run: 469,266,309,120 bytes free<br />
Post-Run: 469,409,398,784 bytes free<br />
<br />
302	--- E O F ---	2008-07-20 01:21:19<br />
<br />
<br />
------------------------------------------------------------------<br />
<b><u>Logfile of Trend Micro HijackThis v2.0.2</u></b><br />
Scan saved at 00:11, on 24/07/2008<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16674)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
C:\WINDOWS\system32\CTsvcCDA.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\Program Files\Cyberlink\Shared files\RichVideo.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe<br />
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe<br />
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe<br />
C:\PROGRA~1\AVG\AVG8\avgam.exe<br />
C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br />
C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br />
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe<br />
C:\WINDOWS\system32\RUNDLL32.EXE<br />
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe<br />
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe<br />
C:\Program Files\QuickTime\qttask.exe<br />
C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe<br />
C:\Program Files\Cyberlink\Shared Files\brs.exe<br />
C:\Program Files\PowerISO\PWRISOVM.EXE<br />
C:\Program Files\dvd43\dvd43_tray.exe<br />
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe<br />
C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Creative\MediaSource5\Go\CTCMSGoU.exe<br />
C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe<br />
C:\Program Files\Registry Mechanic\RegMech.exe<br />
C:\WINDOWS\system32\wscntfy.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Documents and Settings\Paul\Desktop\HiJackThis.exe<br />
<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" href="http://www.google.com">www.google.com</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a rel="nofollow" href="http://go.microsoft.com/fwlink/?LinkId=69157">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a rel="nofollow" href="http://go.microsoft.com/fwlink/?LinkId=54896">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a rel="nofollow" href="http://go.microsoft.com/fwlink/?LinkId=54896">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a rel="nofollow" href="http://go.microso