﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Tweaks.com Forum  / Windows &amp; System Security / HiJack This Logs </title><generator>InstantForum.NET v4.1.4</generator><description>Tweaks.com Forum </description><link>http://forum.tweaks.com/forum/</link><webMaster>forum@tweaks.com</webMaster><lastBuildDate>Sat, 17 May 2008 02:54:43 GMT</lastBuildDate><ttl>20</ttl><item><title>svchost.exe  what is this! Am i in danger?[home PC without Internet]</title><link>http://forum.tweaks.com/forum/Topic239363-29-1.aspx</link><description>Help me out to encounter something, my USB disk security always detect svchost your pc under risk....here the hijack this&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 7:06:43 PM, on 5/12/2008&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\Explorer.exe&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\wscntfy.exe&lt;BR&gt;C:\Program Files\Winamp\winampa.exe&lt;BR&gt;C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe&lt;BR&gt;C:\WINDOWS\winlogon.exe&lt;BR&gt;C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe&lt;BR&gt;C:\Program Files\USB Disk Security\USBGuard.exe&lt;BR&gt;C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe&lt;BR&gt;C:\WINDOWS\system32\Rundll32.exe&lt;BR&gt;C:\Program Files\Windows Sidebar\sidebar.exe&lt;BR&gt;C:\Program Files\Windows Sidebar\sidebar.exe&lt;BR&gt;C:\WINDOWS\system\Fun.exe&lt;BR&gt;C:\WINDOWS\SVIQ.EXE&lt;BR&gt;C:\WINDOWS\dc.exe&lt;BR&gt;C:\WINDOWS\Explorer.exe&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;BR&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = &lt;BR&gt;R3 - Default URLSearchHook is missing&lt;BR&gt;F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\WinSit.exe&lt;BR&gt;F3 - REG:win.ini: load=C:\WINDOWS\inf\Other.exe&lt;BR&gt;F3 - REG:win.ini: run=C:\WINDOWS\system32\config\Win.exe&lt;BR&gt;O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll&lt;BR&gt;O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - C:\Program Files\Desktop Sidebar\sbhelp.dll&lt;BR&gt;O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll&lt;BR&gt;O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll&lt;BR&gt;O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"&lt;BR&gt;O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe&lt;BR&gt;O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe&lt;BR&gt;O4 - HKLM\..\Run: [winlogon] C:\WINDOWS\nvchost.exe&lt;BR&gt;O4 - HKLM\..\Run: [nvchost] C:\WINDOWS\winlogon.exe&lt;BR&gt;O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"&lt;BR&gt;O4 - HKLM\..\Run: [USB Antivirus] C:\Program Files\USB Disk Security\USBGuard.exe&lt;BR&gt;O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r&lt;BR&gt;O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper&lt;BR&gt;O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE&lt;BR&gt;O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun&lt;BR&gt;O4 - HKCU\..\Run: [dc2k5] C:\WINDOWS\SVIQ.EXE&lt;BR&gt;O4 - HKCU\..\Run: [Fun] C:\WINDOWS\system\Fun.exe&lt;BR&gt;O4 - HKCU\..\Run: [dc] C:\WINDOWS\dc.exe&lt;BR&gt;O4 - HKUS\S-1-5-19\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'LOCAL SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-19\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-19\..\RunOnce: [nltide2] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,L,,4,N (User 'LOCAL SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-20\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'NETWORK SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-20\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-18\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'SYSTEM')&lt;BR&gt;O4 - HKUS\S-1-5-18\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')&lt;BR&gt;O4 - HKUS\.DEFAULT\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'Default user')&lt;BR&gt;O4 - HKUS\.DEFAULT\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')&lt;BR&gt;O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe&lt;BR&gt;O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?&lt;BR&gt;O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE&lt;BR&gt;O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html&lt;BR&gt;O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html&lt;BR&gt;O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html&lt;BR&gt;O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html&lt;BR&gt;O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html&lt;BR&gt;O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html&lt;BR&gt;O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html&lt;BR&gt;O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html&lt;BR&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000&lt;BR&gt;O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll&lt;BR&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe&lt;BR&gt;O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 6800 bytes&lt;BR&gt;&lt;/P&gt;&lt;P&gt;thanks bro!</description><pubDate>Tue, 13 May 2008 05:12:59 GMT</pubDate><dc:creator>sha_eddie</dc:creator></item><item><title>Numerous infections, numous scans .... still have some work to do</title><link>http://forum.tweaks.com/forum/Topic239571-29-1.aspx</link><description>Hello Richie, As Requested (Thank You) :&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 11:19:43 AM, on 5/16/2008&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16640)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\SYSTEM32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\ibmpmsvc.exe&lt;BR&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\Program Files\Windows Defender\MsMpEng.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\S24EvMon.exe&lt;BR&gt;C:\WINDOWS\SYSTEM32\Ati2evxx.exe&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;C:\WINDOWS\system32\acs.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;C:\Program Files\Windows Defender\MSASCui.exe&lt;BR&gt;C:\Program Files\Total Recorder Professional 6\TotRecSched.exe&lt;BR&gt;C:\Program Files\Synaptics\SynTP\SynTPLpr.exe&lt;BR&gt;C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;BR&gt;C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe&lt;BR&gt;C:\Program Files\CounterSpy\SBCSTray.exe&lt;BR&gt;C:\Program Files\Common Files\Motive\McciCMService.exe&lt;BR&gt;C:\Program Files\Microsoft IntelliPoint\point32.exe&lt;BR&gt;C:\WINDOWS\CTHELPER.EXE&lt;BR&gt;C:\WINDOWS\system32\RunDll32.exe&lt;BR&gt;C:\WINDOWS\system32\rundll32.exe&lt;BR&gt;C:\WINDOWS\System32\RegSrvc.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe&lt;BR&gt;C:\Program Files\CounterSpy\SBCSSvc.exe&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\Program Files\AnyDVD\AnyDVDtray.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\Program Files\Sierra Wireless\AirCard 580\Generic\Components\swiwificomm.exe&lt;BR&gt;C:\WINDOWS\system32\wscntfy.exe&lt;BR&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;BR&gt;C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe&lt;BR&gt;C:\Program Files\Outlook Express\msimn.exe&lt;BR&gt;C:\Program Files\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.ebay.com"&gt;http://www.ebay.com&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://www.ebay.com"&gt;http://www.ebay.com&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.ebay.com"&gt;http://www.ebay.com&lt;/A&gt;&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = &lt;BR&gt;O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide&lt;BR&gt;O4 - HKLM\..\Run: [TotalRecorderScheduler] "C:\Program Files\Total Recorder Professional 6\TotRecSched.exe"&lt;BR&gt;O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe&lt;BR&gt;O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"&lt;BR&gt;O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\CounterSpy\SBCSTray.exe&lt;BR&gt;O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe&lt;BR&gt;O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"&lt;BR&gt;O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k&lt;BR&gt;O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"&lt;BR&gt;O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE&lt;BR&gt;O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE&lt;BR&gt;O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor&lt;BR&gt;O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent&lt;BR&gt;O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min&lt;BR&gt;O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&lt;BR&gt;O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\AnyDVD\AnyDVDtray.exe&lt;BR&gt;O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')&lt;BR&gt;O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')&lt;BR&gt;O8 - Extra context menu item: &amp;amp;Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm&lt;BR&gt;O8 - Extra context menu item: &amp;amp;Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm&lt;BR&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - &lt;A href="http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab"&gt;http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {22E5D91F-89E6-4405-AD9C-0AF27BA6F06B} (HidInputMonitorX Control) - &lt;A href="file:///D:/components/hidinputmonitorx.ocx"&gt;file:///D:/components/hidinputmonitorx.ocx&lt;/A&gt;&lt;BR&gt;O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} (IASRunner Class) - &lt;A href="https://www-307.ibm.com/pc/support/access/aslibmain/content/AcpIR.cab"&gt;https://www-307.ibm.com/pc/support/access/aslibmain/content/AcpIR.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - &lt;A href="http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab"&gt;http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {4F63D44B-6274-4D60-8AB1-CAA7116B8AF3} (A9Helper.A9) - &lt;A href="file:///D:/components/A9.ocx"&gt;file:///D:/components/A9.ocx&lt;/A&gt;&lt;BR&gt;O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - &lt;A href="http://upload.facebook.com/controls/FacebookPhotoUploader.cab"&gt;http://upload.facebook.com/controls/FacebookPhotoUploader.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &lt;A href="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1107394181500"&gt;http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1107394181500&lt;/A&gt;&lt;BR&gt;O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - &lt;A href="http://download.divx.com/player/DivXBrowserPlugin.cab"&gt;http://download.divx.com/player/DivXBrowserPlugin.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {7030CC6C-1A88-4591-BB5A-651B9F7F0C30} (WMVHDRatingCtrl Class) - &lt;A href="file:///D:/components/wmvhdrating.ocx"&gt;file:///D:/components/wmvhdrating.ocx&lt;/A&gt;&lt;BR&gt;O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - &lt;A href="http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab"&gt;http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - &lt;A href="http://support.f-secure.com/ols/fscax.cab"&gt;http://support.f-secure.com/ols/fscax.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &lt;A href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab"&gt;http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab&lt;/A&gt;&lt;BR&gt;O17 - HKLM\System\CCS\Services\Tcpip\..\{62EC955C-255C-405C-A396-1967C4580BEB}: NameServer = 204.174.120.45 204.174.120.46&lt;BR&gt;O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll&lt;BR&gt;O23 - Service: Atheros Configuration Service (acs) - Atheros - C:\WINDOWS\system32\acs.exe&lt;BR&gt;O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe&lt;BR&gt;O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)&lt;BR&gt;O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe&lt;BR&gt;O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe&lt;BR&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe&lt;BR&gt;O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe&lt;BR&gt;O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe&lt;BR&gt;O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe&lt;BR&gt;O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe&lt;BR&gt;O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\WINDOWS\System32\S24EvMon.exe&lt;BR&gt;O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\CounterSpy\SBCSSvc.exe&lt;BR&gt;O23 - Service: SwiWiFiComm - Unknown owner - C:\Program Files\Sierra Wireless\AirCard 580\Generic\Components\swiwificomm.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 8695 bytes&lt;BR&gt;</description><pubDate>Fri, 16 May 2008 12:22:02 GMT</pubDate><dc:creator>fairlite</dc:creator></item><item><title>response to Richie</title><link>http://forum.tweaks.com/forum/Topic239592-29-1.aspx</link><description>Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 8:09:34 PM, on 5/16/2008&lt;BR&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v7.00 (7.00.5730.0011)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\Program Files\UPHClean\uphclean.exe&lt;BR&gt;C:\Program Files\Uniblue\LocalCooling\localcooling2.exe&lt;BR&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.yahoo.com/"&gt;http://www.yahoo.com/&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = &lt;BR&gt;O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - D:\Program Files\Orbitdownloader\orbitcth.dll&lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O4 - Global Startup: LocalCooling.lnk = C:\Program Files\Uniblue\LocalCooling\localcooling2.exe&lt;BR&gt;O8 - Extra context menu item: &amp;amp;Download by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/201&lt;BR&gt;O8 - Extra context menu item: &amp;amp;Grab video by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/204&lt;BR&gt;O8 - Extra context menu item: Do&amp;amp;wnload selected by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/203&lt;BR&gt;O8 - Extra context menu item: Down&amp;amp;load all by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/202&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 2999 bytes&lt;BR&gt;&lt;/P&gt;&lt;P&gt;I've got a very good question: Why is my log clean? :D I will post the deleted ones if you want to...</description><pubDate>Fri, 16 May 2008 18:10:23 GMT</pubDate><dc:creator>Anwar</dc:creator></item><item><title>Browser hijack, internet goes down intermitenly.</title><link>http://forum.tweaks.com/forum/Topic239505-29-1.aspx</link><description>I did some cleanups here and there which seemed to help, so I just want to make sure nothing else is infected. Thanks Richie.&lt;P&gt;&lt;STRONG&gt;HijackThis Log:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[quote]&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 4:30:27 PM, on 5/15/2008&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16640)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\eHome\ehRecvr.exe&lt;BR&gt;C:\WINDOWS\eHome\ehSched.exe&lt;BR&gt;C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE&lt;BR&gt;C:\WINDOWS\system32\dllhost.exe&lt;BR&gt;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&lt;BR&gt;C:\WINDOWS\system32\hkcmd.exe&lt;BR&gt;C:\WINDOWS\system32\igfxpers.exe&lt;BR&gt;C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\POS_Exe\pos.exe&lt;BR&gt;C:\WINDOWS\explorer.exe&lt;BR&gt;C:\POS_Exe\SE.exe&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://yahoo.com/"&gt;http://yahoo.com/&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = &lt;BR&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;BR&gt;O2 - BHO: Spybot-S&amp;amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search &amp;amp; Destroy\SDHelper.dll&lt;BR&gt;O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll&lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;BR&gt;O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup&lt;BR&gt;O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start&lt;BR&gt;O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe&lt;BR&gt;O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe&lt;BR&gt;O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"&lt;BR&gt;O4 - HKLM\..\RunOnce: [AAW] "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe" "+b1"&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;BR&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL&lt;BR&gt;O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search &amp;amp; Destroy\SDHelper.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Spybot - Search &amp;amp;&amp;amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search &amp;amp; Destroy\SDHelper.dll&lt;BR&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)&lt;BR&gt;O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - &lt;A href="http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab"&gt;http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - &lt;A href="http://download.bitdefender.com/resources/scan8/oscan8.cab"&gt;http://download.bitdefender.com/resources/scan8/oscan8.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - &lt;A href="http://sdlc-esd.sun.com/ESD40/JSCDL/jre/6u5-b19/jinstall-6u5-windows-i586-jc.cab?AuthParam=1209675775_040763554b314c1c421dbb1727c36ef1&amp;amp;GroupName=JSC&amp;amp;BHost=javadl.sun.com&amp;amp;FilePath=/ESD40/JSCDL/jre/6u5-b19/jinstall-6u5-windows-i586-jc.cab&amp;amp;File=jinstall-6u5-windows-i586-jc.cab"&gt;http://sdlc-esd.sun.com/ESD40/JSCDL/jre/6u5-b19/jinstall-6u5-windows-i586-jc.cab?AuthParam=1209675775_040763554b314c1c421dbb1727c36ef1&amp;amp;GroupName=JSC&amp;amp;BHost=javadl.sun.com&amp;amp;FilePath=/ESD40/JSCDL/jre/6u5-b19/jinstall-6u5-windows-i586-jc.cab&amp;amp;File=jinstall-6u5-windows-i586-jc.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - &lt;A href="http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab"&gt;http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - &lt;A href="http://www.shockwave.com/content/insaniquarium/sis/popcaploader_v10.cab"&gt;http://www.shockwave.com/content/insaniquarium/sis/popcaploader_v10.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - &lt;A href="https://secure.logmein.com/activex/ractrl.cab?lmi=100"&gt;https://secure.logmein.com/activex/ractrl.cab?lmi=100&lt;/A&gt;&lt;BR&gt;O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe&lt;BR&gt;O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 5377 bytes&lt;BR&gt;&lt;/P&gt;&lt;P&gt;[/quote]</description><pubDate>Thu, 15 May 2008 15:34:03 GMT</pubDate><dc:creator>chaldo</dc:creator></item><item><title>firefox getting slow</title><link>http://forum.tweaks.com/forum/Topic239542-29-1.aspx</link><description>hey guys. new pc, new problems.  getting to where clicking tabs and links in firefox is getting bad slow. ran cleaners and stuff, hasn't helped.&lt;br&gt;&lt;br&gt;here's my HJT log:&lt;br&gt;&lt;br&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br&gt;Scan saved at 11:27:30 PM, on 5/15/2008&lt;br&gt;Platform: Windows Vista  (WinNT 6.00.1904)&lt;br&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16643)&lt;br&gt;Boot mode: Normal&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\Windows\system32\taskeng.exe&lt;br&gt;C:\Windows\Explorer.EXE&lt;br&gt;C:\Program Files\Windows Defender\MSASCui.exe&lt;br&gt;C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe&lt;br&gt;C:\Windows\RtHDVCpl.exe&lt;br&gt;C:\Windows\System32\rundll32.exe&lt;br&gt;C:\Program Files\AVG\AVG8\avgtray.exe&lt;br&gt;C:\Windows\ehome\ehtray.exe&lt;br&gt;C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe&lt;br&gt;C:\Windows\ehome\ehmsas.exe&lt;br&gt;C:\Program Files\Windows Media Player\wmpnscfg.exe&lt;br&gt;C:\Windows\system32\wbem\unsecapp.exe&lt;br&gt;C:\Program Files\Windows Media Player\wmplayer.exe&lt;br&gt;C:\Program Files\Mozilla Firefox\firefox.exe&lt;br&gt;C:\Users\Brandon\Desktop\documents\RealTemp_2.5\RealTemp.exe&lt;br&gt;C:\Program Files\GetRight\GetRight.exe&lt;br&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;br&gt;C:\Windows\system32\SearchFilterHost.exe&lt;br&gt;&lt;br&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.is82.com/&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = &lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = &lt;br&gt;O1 - Hosts: ::1 localhost&lt;br&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br&gt;O2 - BHO: IE to GetRight Helper - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll&lt;br&gt;O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll&lt;br&gt;O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search &amp; Destroy\SDHelper.dll&lt;br&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll&lt;br&gt;O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)&lt;br&gt;O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide&lt;br&gt;O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\JM\JMInsIDE.exe&lt;br&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"&lt;br&gt;O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe&lt;br&gt;O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime&lt;br&gt;O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup&lt;br&gt;O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit&lt;br&gt;O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe&lt;br&gt;O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.09\RivaTunerWrapper.exe" /S&lt;br&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"&lt;br&gt;O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" boot "C:\Users\Brandon\AppData\Local\NVIDIA Corporation\nTune\Profiles\new.nsu"&lt;br&gt;O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe&lt;br&gt;O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe&lt;br&gt;O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')&lt;br&gt;O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')&lt;br&gt;O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')&lt;br&gt;O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm&lt;br&gt;O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm&lt;br&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll&lt;br&gt;O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search &amp; Destroy\SDHelper.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: Spybot - Search &amp;&amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search &amp; Destroy\SDHelper.dll&lt;br&gt;O13 - Gopher Prefix: &lt;br&gt;O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll&lt;br&gt;O20 - AppInit_DLLs: avgrsstx.dll&lt;br&gt;O23 - Service: Autodesk Licensing Service - Unknown owner - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe&lt;br&gt;O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe&lt;br&gt;O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe&lt;br&gt;O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\Windows\System32\LEXBCES.EXE&lt;br&gt;O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe&lt;br&gt;O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe&lt;br&gt;O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe&lt;br&gt;O23 - Service: TVersityMediaServer - Unknown owner - C:\Program Files\TVersity\Media Server\MediaServer.exe&lt;br&gt;&lt;br&gt;--&lt;br&gt;End of file - 6068 bytes&lt;br&gt;</description><pubDate>Thu, 15 May 2008 23:29:56 GMT</pubDate><dc:creator>b_w</dc:creator></item><item><title>Slow, LAN connection not working</title><link>http://forum.tweaks.com/forum/Topic239311-29-1.aspx</link><description>Well, this computer's loading rather slowly, and the LAN connection refuses to connect, even though I'm right next to the router, and it's plugged in with an ethernet cord. The other computer is having no problems at all. I've also noticed the presence of some services that have been identified as malware.&lt;br&gt;&lt;br&gt;EDIT: Got the LAN working, but not at all sure what the problem was. Computer continues to be slow, laggy, and all around buggery.&lt;br&gt;&lt;br&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br&gt;Scan saved at 11:24:34 AM, on 5/12/2008&lt;br&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16640)&lt;br&gt;Boot mode: Normal&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\WINDOWS\System32\smss.exe&lt;br&gt;C:\WINDOWS\system32\winlogon.exe&lt;br&gt;C:\WINDOWS\system32\services.exe&lt;br&gt;C:\WINDOWS\system32\lsass.exe&lt;br&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe&lt;br&gt;C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe&lt;br&gt;C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe&lt;br&gt;C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;br&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br&gt;C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe&lt;br&gt;C:\Program Files\Symantec AntiVirus\DefWatch.exe&lt;br&gt;C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe&lt;br&gt;C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE&lt;br&gt;C:\WINDOWS\system32\PnkBstrA.exe&lt;br&gt;C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS&lt;br&gt;C:\Program Files\Symantec AntiVirus\SavRoam.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\Program Files\Symantec AntiVirus\Rtvscan.exe&lt;br&gt;C:\WINDOWS\system32\ZuneBusEnum.exe&lt;br&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;br&gt;C:\Program Files\Common Files\Microsoft Shared\Ink\KeyboardSurrogate.exe&lt;br&gt;C:\WINDOWS\SYSTEM32\WISPTIS.EXE&lt;br&gt;C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe&lt;br&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;C:\Program Files\Common Files\Microsoft Shared\Ink\TCServer.exe&lt;br&gt;C:\WINDOWS\System32\tabbtnu.exe&lt;br&gt;C:\Program Files\GE\97769 Dual Scroll Optical Mouse\Amoumain.exe&lt;br&gt;C:\WINDOWS\stsystra.exe&lt;br&gt;C:\Program Files\Common Files\Microsoft Shared\Ink\TabTip.exe&lt;br&gt;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE&lt;br&gt;C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe&lt;br&gt;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&lt;br&gt;C:\PROGRA~1\SYMANT~1\VPTray.exe&lt;br&gt;C:\WINDOWS\vcdplayx.exe&lt;br&gt;C:\Program Files\Synaptics\SynTP\SynTPLpr.exe&lt;br&gt;C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;br&gt;C:\WINDOWS\sm56hlpr.exe&lt;br&gt;C:\WINDOWS\system32\wuauclt.exe&lt;br&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;br&gt;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&lt;br&gt;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&lt;br&gt;C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;br&gt;C:\program files\steam\steam.exe&lt;br&gt;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe&lt;br&gt;C:\Program Files\Stardock\ObjectDock\ObjectDock.exe&lt;br&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;br&gt;C:\WINDOWS\explorer.exe&lt;br&gt;C:\Program Files\Mozilla Firefox 3 Beta 5\firefox.exe&lt;br&gt;D:\Data\Random Junk\HiJackThis.exe&lt;br&gt;&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.winona.edu/links.htm&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;br&gt;R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)&lt;br&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br&gt;O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll&lt;br&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll&lt;br&gt;O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&lt;br&gt;O4 - HKLM\..\Run: [WheelMouse] Amoumain.exe&lt;br&gt;O4 - HKLM\..\Run: [TabletWizard] C:\WINDOWS\help\SplshWrp.exe&lt;br&gt;O4 - HKLM\..\Run: [TabletTip] "C:\Program Files\Common Files\microsoft shared\ink\tabtip.exe" /resume&lt;br&gt;O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe&lt;br&gt;O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime&lt;br&gt;O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC&lt;br&gt;O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent&lt;br&gt;O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32&lt;br&gt;O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE&lt;br&gt;O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe&lt;br&gt;O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"&lt;br&gt;O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"&lt;br&gt;O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe&lt;br&gt;O4 - HKLM\..\Run: [VirtualDrive] "D:\Data\Programs and junk\FarStone\VirtualDrive\VDTask.exe" /AutoRestore&lt;br&gt;O4 - HKLM\..\Run: [vcdplayx] "C:\WINDOWS\vcdplayx.exe"&lt;br&gt;O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe&lt;br&gt;O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;br&gt;O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe&lt;br&gt;O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC&lt;br&gt;O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName&lt;br&gt;O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"&lt;br&gt;O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"&lt;br&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"&lt;br&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;br&gt;O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitLord\BitLord.exe"&lt;br&gt;O4 - HKCU\..\Run: [Power2GoExpress] NA&lt;br&gt;O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe&lt;br&gt;O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent&lt;br&gt;O4 - HKUS\S-1-5-19\..\Run: [TabletWizard] %windir%\help\wizard.hta (User 'LOCAL SERVICE')&lt;br&gt;O4 - HKUS\S-1-5-20\..\Run: [TabletWizard] %windir%\help\wizard.hta (User 'NETWORK SERVICE')&lt;br&gt;O4 - HKUS\S-1-5-18\..\Run: [TabletWizard] %windir%\help\wizard.hta (User 'SYSTEM')&lt;br&gt;O4 - HKUS\.DEFAULT\..\Run: [TabletWizard] %windir%\help\wizard.hta (User 'Default user')&lt;br&gt;O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE&lt;br&gt;O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe&lt;br&gt;O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE&lt;br&gt;O4 - Global Startup: VPN Client.lnk = ?&lt;br&gt;O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000&lt;br&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll&lt;br&gt;O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll&lt;br&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL&lt;br&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab&lt;br&gt;O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll&lt;br&gt;O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1147871177265&lt;br&gt;O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1179409055816&lt;br&gt;O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = winona.edu&lt;br&gt;O17 - HKLM\Software\..\Telephony: DomainName = workstations.winona.edu&lt;br&gt;O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = winona.edu&lt;br&gt;O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = winona.edu&lt;br&gt;O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll&lt;br&gt;O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL&lt;br&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;br&gt;O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;br&gt;O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe&lt;br&gt;O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br&gt;O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe&lt;br&gt;O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe&lt;br&gt;O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe&lt;br&gt;O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe&lt;br&gt;O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe&lt;br&gt;O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe&lt;br&gt;O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe&lt;br&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe&lt;br&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br&gt;O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE&lt;br&gt;O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe&lt;br&gt;O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS&lt;br&gt;O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe&lt;br&gt;O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe&lt;br&gt;O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe&lt;br&gt;O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe&lt;br&gt;O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe&lt;br&gt;&lt;br&gt;--&lt;br&gt;End of file - 11917 bytes&lt;br&gt;</description><pubDate>Mon, 12 May 2008 11:28:53 GMT</pubDate><dc:creator>khuluna</dc:creator></item><item><title>hijacjthis log for Garbled, hanging, no system restore Packard Bell Laptop...</title><link>http://forum.tweaks.com/forum/Topic239543-29-1.aspx</link><description>Hi there guys,&lt;/P&gt;&lt;P&gt;Taking advice from Senior Forum Moderator RichieUK, I've downloaded and run a scan using the HiJackThis app.&lt;/P&gt;&lt;P&gt;Here is the log file.......it makes a wee bit of sense to me, but please help!!!!!:))&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;&lt;P&gt;Rik&lt;/P&gt;&lt;P&gt;Log File:&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 08:19:25, on 16/05/2008&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16640)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\Program Files\Windows Defender\MsMpEng.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe&lt;BR&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;BR&gt;C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe&lt;BR&gt;c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe&lt;BR&gt;c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe&lt;BR&gt;C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe&lt;BR&gt;C:\Program Files\Keygoldsecure\LiteClient.exe&lt;BR&gt;C:\Program Files\Keygoldsecure\NINDFltr.exe&lt;BR&gt;C:\Program Files\CDBurnerXP\NMSAccessU.exe&lt;BR&gt;C:\WINDOWS\system32\srvmon.exe&lt;BR&gt;C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe&lt;BR&gt;C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;BR&gt;C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe&lt;BR&gt;C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe&lt;BR&gt;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&lt;BR&gt;C:\APPS\Powercinema\PCMService.exe&lt;BR&gt;C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe&lt;BR&gt;C:\Program Files\QuickTime\QTTask.exe&lt;BR&gt;C:\Program Files\Windows Defender\MSASCui.exe&lt;BR&gt;c:\APPS\Powercinema\Kernel\TV\CLSched.exe&lt;BR&gt;C:\Program Files\Keygoldsecure\LiteClientAM.exe&lt;BR&gt;C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\Program Files\Keygoldsecure\AMMon.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = &lt;A href="http://format.packardbell.com/cgi-bin/redirect/?country=UK&amp;amp;range=AD&amp;amp;phase=6&amp;amp;key=SEARCH"&gt;http://format.packardbell.com/cgi-bin/redirect/?country=UK&amp;amp;range=AD&amp;amp;phase=6&amp;amp;key=SEARCH&lt;/A&gt;&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.kfki.hu/library/magyk4.html#S"&gt;http://www.kfki.hu/library/magyk4.html#S&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &lt;A href="http://www.hotmail.com/"&gt;http://www.hotmail.com/&lt;/A&gt;&lt;BR&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell&lt;BR&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)&lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;BR&gt;O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32&lt;BR&gt;O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName&lt;BR&gt;O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;BR&gt;O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE&lt;BR&gt;O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE&lt;BR&gt;O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE&lt;BR&gt;O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"&lt;BR&gt;O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup&lt;BR&gt;O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start&lt;BR&gt;O4 - HKLM\..\Run: [PCMService] "c:\APPS\Powercinema\PCMService.exe"&lt;BR&gt;O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime&lt;BR&gt;O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide&lt;BR&gt;O4 - HKLM\..\Run: [NIHomeAM] "C:\Program Files\Keygoldsecure\LiteClientAM.exe"&lt;BR&gt;O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe"&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')&lt;BR&gt;O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')&lt;BR&gt;O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe&lt;BR&gt;O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe&lt;BR&gt;O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE&lt;BR&gt;O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\ie_banner_deny.htm&lt;BR&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;BR&gt;O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\SCIEPlgn.dll&lt;BR&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL&lt;BR&gt;O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll&lt;BR&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm&lt;BR&gt;O16 - DPF: {2019DC25-D1C0-11D6-97B3-0008A124F542} - &lt;A href="http://www.streamplug.com/StreamPlug/beta/SP.cab"&gt;http://www.streamplug.com/StreamPlug/beta/SP.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - &lt;A href="http://upload.facebook.com/controls/FacebookPhotoUploader.cab"&gt;http://upload.facebook.com/controls/FacebookPhotoUploader.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &lt;A href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab"&gt;http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab&lt;/A&gt;&lt;BR&gt;O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL&lt;BR&gt;O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0FO\adialhk.dll&lt;BR&gt;O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe&lt;BR&gt;O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;BR&gt;O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;O23 - Service: AVG Anti-Spyware Guard - Unknown owner - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe (file missing)&lt;BR&gt;O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe&lt;BR&gt;O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe&lt;BR&gt;O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe&lt;BR&gt;O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)&lt;BR&gt;O23 - Service: CSNetManagerXp - Unknown owner - C:\WINDOWS\system32\isass.exe (file missing)&lt;BR&gt;O23 - Service: CyberLink Media Library Service - Cyberlink - c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe&lt;BR&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;BR&gt;O23 - Service: Keygold Secure Client (NILiteClient) - Keygold Secure Limited - C:\Program Files\Keygoldsecure\LiteClient.exe&lt;BR&gt;O23 - Service: Keygold Secure Web Filter (NINDISFilter) - Keygold Secure Limited - C:\Program Files\Keygoldsecure\NINDFltr.exe&lt;BR&gt;O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe&lt;BR&gt;O23 - Service: Service Monitor (ServiceMonitor) - Unknown owner - C:\WINDOWS\system32\srvmon.exe&lt;BR&gt;O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe&lt;BR&gt;O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe&lt;BR&gt;O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe&lt;BR&gt;O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe&lt;BR&gt;O24 - Desktop Component 0: (no name) - &lt;A href="file:///C:/DOCUME~1/ANNA/LOCALS~1/Temp/msohtml1/01/clip_image001.jpg"&gt;file:///C:/DOCUME~1/ANNA/LOCALS~1/Temp/msohtml1/01/clip_image001.jpg&lt;/A&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 9675 bytes&lt;BR&gt;</description><pubDate>Fri, 16 May 2008 02:33:42 GMT</pubDate><dc:creator>RIK</dc:creator></item><item><title>slow, very slow to start up and won't open...</title><link>http://forum.tweaks.com/forum/Topic239308-29-1.aspx</link><description>Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 10:51:25 AM, on 5/12/2008&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16574)&lt;BR&gt;Boot mode: Safe mode with network support&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\csrss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\HelpCtr.exe&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = &lt;BR&gt;F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe&lt;BR&gt;O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx&lt;BR&gt;O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll&lt;BR&gt;O2 - BHO: (no name) - {2F02D978-0FF6-80F7-60BB-0426224AB7B3} - C:\Program Files\fqwypvme\wvfxmypw.dll&lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll&lt;BR&gt;O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll&lt;BR&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll&lt;BR&gt;O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll&lt;BR&gt;O3 - Toolbar: &amp;amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll&lt;BR&gt;O4 - HKLM\..\Run: [msctrl.exe] C:\Program Files\Microsoft Security Adviser\msctrl.exe&lt;BR&gt;O4 - HKLM\..\Run: [msavsc.exe] C:\Program Files\Microsoft Security Adviser\msavsc.exe&lt;BR&gt;O4 - HKLM\..\Run: [msscan.exe] C:\Program Files\Microsoft Security Adviser\msscan.exe&lt;BR&gt;O4 - HKLM\..\Run: [msiemon.exe] C:\Program Files\Microsoft Security Adviser\msiemon.exe&lt;BR&gt;O4 - HKLM\..\Run: [msfw.exe] C:\Program Files\Microsoft Security Adviser\msfw.exe&lt;BR&gt;O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background&lt;BR&gt;O4 - HKCU\..\Run: [MoneyStartUp] C:\Program Files\Microsoft Money\System\Money Startup.exe&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O4 - HKUS\S-1-5-21-3942531886-1256799619-874574627-500\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')&lt;BR&gt;O4 - HKUS\S-1-5-21-3942531886-1256799619-874574627-500\..\Run: [MoneyStartUp] C:\Program Files\Microsoft Money\System\Money Startup.exe (User '?')&lt;BR&gt;O4 - HKUS\S-1-5-21-3942531886-1256799619-874574627-500\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')&lt;BR&gt;O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe (User '?')&lt;BR&gt;O4 - HKUS\.DEFAULT\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe (User 'Default user')&lt;BR&gt;O4 - S-1-5-21-3942531886-1256799619-874574627-500 Startup: AutoPlay.exe (User '?')&lt;BR&gt;O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')&lt;BR&gt;O4 - Startup: AutoPlay.exe&lt;BR&gt;O4 - Global Startup: America Online 6.0 Tray Icon.lnk = C:\Program Files\America Online 6.0a\aoltray.exe&lt;BR&gt;O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe&lt;BR&gt;O4 - Global Startup: hp center UI.lnk = C:\Program Files\hp center\137903\Shadow\ShadowBar.exe&lt;BR&gt;O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe&lt;BR&gt;O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe&lt;BR&gt;O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll&lt;BR&gt;O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll&lt;BR&gt;O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll&lt;BR&gt;O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll&lt;BR&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O17 - HKLM\System\CCS\Services\Tcpip\..\{4744F88E-20A6-4B2F-9494-9D385F78C7A5}: NameServer = 85.255.114.104,85.255.112.157&lt;BR&gt;O17 - HKLM\System\CCS\Services\Tcpip\..\{A897ABF5-A8FD-4A27-9311-48287DE45314}: NameServer = 85.255.114.104,85.255.112.157&lt;BR&gt;O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.104 85.255.112.157&lt;BR&gt;O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.114.104 85.255.112.157&lt;BR&gt;O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.104 85.255.112.157&lt;BR&gt;O20 - AppInit_DLLs: C:\WINDOWS\system32\wowfx.dll&lt;BR&gt;O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe&lt;BR&gt;O23 - Service: FWService - eAcceleration Corp. - C:\Program Files\eAcceleration\Firewall\FWService.exe&lt;BR&gt;O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;BR&gt;O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe&lt;BR&gt;O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 6975 bytes&lt;BR&gt;</description><pubDate>Mon, 12 May 2008 09:54:55 GMT</pubDate><dc:creator>irebeer</dc:creator></item><item><title>Definately infectaed, but what ?</title><link>http://forum.tweaks.com/forum/Topic239501-29-1.aspx</link><description>XP PRO SP2&lt;br&gt;&lt;br&gt;I am using Sygate Personal Firewall 5.6 build 2808&lt;br&gt;I have Spybot - Search &amp; Destroy version 1.5.2.0&lt;br&gt;&lt;br&gt;Sygate Personal Firewall reports; Application Hijacking, Severity=Critical, Remote Host=77.232.91.127, The full path of &lt;br&gt;Spybot is listed.&lt;br&gt;Sygate displays Spybot as Application Hijacking for several minutes anywhere from 5 to 20 minutes, so far.&lt;br&gt;Sygate eventually list the Security Type for each previous Spybot entry as "Port Scan" and changes the Severity to Minor &lt;br&gt;and changes the Remote Host to 194.168.8.100&lt;br&gt;&lt;br&gt;In the past 60 minutes (while connected to the internet) Windows Media Player 11 has automatically launched 4 times.  &lt;br&gt;The first time WMP launched; I did not see the video, the second time; it played a pornographic video, the third time; &lt;br&gt;a blank 3 second video, the fourth time; a pornographic video. I disabled my network adapter and Windows media player &lt;br&gt;has not launched since.&lt;br&gt;&lt;br&gt;I have done a scan using Spybot Search and Destroy; it found nothing.&lt;br&gt;Task Manager, CPU Usage is fluctuating between 5% to 100%, the graph displays drastic peaks and troughs, at present I have &lt;br&gt;Firefox, Bitdefender, Spybot Search and Destroy and Sygate Personal Firewall running.  These applications when running &lt;br&gt;at the same time; usually do not consume more than 15% usage.&lt;br&gt;&lt;br&gt;Checked MSCONFIG - there are 5 entries for svchost, all enabled.&lt;br&gt;   there are 6 entries enabled but Startup item column is blank, the "location" for the blank items is &lt;br&gt;HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br&gt;&lt;br&gt;I am able to use all my usually applications with only one noticeable interruptions except whatever application I am &lt;br&gt;using; within a few seconds - the title bar will go grey and the application becomes inactive however no other &lt;br&gt;application launches.  Since I have disabled my network adapter; this has not happened.&lt;br&gt;&lt;br&gt;Another peculiarity - a dialogue bx appeared while I was connected to the net, it had not reference to any application &lt;br&gt;or website but it was clearly spyware because it display some text claiming that my computer is infected, which is true &lt;br&gt;because it's no doubt that vendor of that alert - has infected my PC.  I did not click on, I used Alt+Tab but it was not &lt;br&gt;listed, it disappeared without any action from me.&lt;br&gt;&lt;br&gt;About 45 minutes previous to all these things; my computer would play an alert similar to when you when you instruct a &lt;br&gt;computer to perform an action but it returns a message saying that action is not possible.  No dialogue box appear on &lt;br&gt;screen to accompany this alert.&lt;br&gt;&lt;br&gt;I have not recently installed any new software apart from a FireFox addon "BlockSite 0.7" however this was 2 days ago.&lt;br&gt;I have not installed any other browser plugins.&lt;br&gt;&lt;br&gt;I just enabled my network adapter and the CPU usage is even more sporadic and Firefox is hanging but not severely.&lt;br&gt;&lt;br&gt;I've used the ADS Spy tool in HijackThis but it found nothing.&lt;br&gt;Here is the result of HijackThis&lt;br&gt;&lt;br&gt;Logfile of HijackThis v1.99.1&lt;br&gt;Scan saved at 21:00:58, on 15/05/2008&lt;br&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16608)&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\WINDOWS\System32\smss.exe&lt;br&gt;C:\WINDOWS\system32\winlogon.exe&lt;br&gt;C:\WINDOWS\system32\services.exe&lt;br&gt;C:\WINDOWS\system32\lsass.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\Program Files\Sygate\SPF\smc.exe&lt;br&gt;C:\WINDOWS\Explorer.EXE&lt;br&gt;C:\progra~1\softwin\bitdef~1\bdnagent.exe&lt;br&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe&lt;br&gt;C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe&lt;br&gt;C:\WINDOWS\system32\wscntfy.exe&lt;br&gt;C:\WINDOWS\system32\taskmgr.exe&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe&lt;br&gt;c:\progra~1\softwin\bitdef~1\bdmcon.exe&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;C:\Program Files\Mozilla Firefox\firefox.exe&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;F:\SFW\SECURE\HijackThis.exe&lt;br&gt;C:\Program Files\OpenOffice.org 2.3\program\soffice.exe&lt;br&gt;C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;C:\WINDOWS\system32\notepad.exe&lt;br&gt;C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe&lt;br&gt;C:\WINDOWS\system32\NOTEPAD.EXE&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://techwhims.blogspot.com/&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui&lt;br&gt;O4 - HKLM\..\Run: [BDNewsAgent] "c:\progra~1\softwin\bitdef~1\bdnagent.exe"&lt;br&gt;O4 - HKLM\..\Run: [BDMCon] c:\PROGRA~1\softwin\BITDEF~1\bdmcon.exe&lt;br&gt;O4 - HKCU\..\Run: [SODCPreLoad] C:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.0.1.20080130-2132\preload.exe C:\PROGRA~1\IBM\Lotus\Symphony\data\.sodc\&lt;br&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe&lt;br&gt;O4 - HKCU\..\Run: [CDriver] c:\z_Drivers\svchost.exe&lt;br&gt;O4 - HKCU\..\Run: [DDriver] c:\z_Drivers\svchost.exe&lt;br&gt;O4 - HKCU\..\Run: [alpha] c:\z_Drivers\svchost.exe&lt;br&gt;O4 - HKCU\..\Run: [beta] c:\z_Drivers\svchost.exe&lt;br&gt;O4 - HKCU\..\Run: [gamma] c:\z_Drivers\svchost.exe&lt;br&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (file missing)&lt;br&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (file missing)&lt;br&gt;O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll&lt;br&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)&lt;br&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)&lt;br&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O11 - Options group: [INTERNATIONAL] International*&lt;br&gt;O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll&lt;br&gt;O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll&lt;br&gt;O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)&lt;br&gt;O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe&lt;br&gt;O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)</description><pubDate>Thu, 15 May 2008 15:13:22 GMT</pubDate><dc:creator>Err</dc:creator></item><item><title>HJT Log</title><link>http://forum.tweaks.com/forum/Topic234947-29-1.aspx</link><description>Logfile of Trend Micro HijackThis v2.0.2&lt;br&gt;Scan saved at 2:48:13 PM, on 2/24/2008&lt;br&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br&gt;MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)&lt;br&gt;Boot mode: Normal&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\WINDOWS\System32\smss.exe&lt;br&gt;C:\WINDOWS\system32\winlogon.exe&lt;br&gt;C:\WINDOWS\system32\services.exe&lt;br&gt;C:\WINDOWS\system32\lsass.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br&gt;C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe&lt;br&gt;C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe&lt;br&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;br&gt;C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe&lt;br&gt;C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe&lt;br&gt;C:\WINDOWS\system32\xhhslfey.exe&lt;br&gt;C:\Program Files\Norton AntiVirus\navapsvc.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\WINDOWS\wanmpsvc.exe&lt;br&gt;C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe&lt;br&gt;C:\WINDOWS\system32\wscntfy.exe&lt;br&gt;C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe&lt;br&gt;C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe&lt;br&gt;C:\Program Files\Digital Media Reader\shwiconem.exe&lt;br&gt;C:\WINDOWS\System32\hkcmd.exe&lt;br&gt;C:\WINDOWS\SOUNDMAN.EXE&lt;br&gt;C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe&lt;br&gt;C:\Program Files\Common Files\AOL\1179188616\ee\AOLSoftware.exe&lt;br&gt;C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE&lt;br&gt;C:\Program Files\Common Files\DriveCleaner Freeware\dcsm.exe&lt;br&gt;C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe&lt;br&gt;C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe&lt;br&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;br&gt;C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;br&gt;C:\Program Files\MySpace\IM\MySpaceIM.exe&lt;br&gt;C:\Program Files\BigFix\BigFix.exe&lt;br&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;br&gt;C:\Program Files\MySpace\IM\MySpaceIM.exe&lt;br&gt;C:\Program Files\Java\jre1.6.0_02\bin\jucheck.exe&lt;br&gt;C:\WINDOWS\explorer.exe&lt;br&gt;C:\WINDOWS\system32\rundll32.exe&lt;br&gt;C:\Program Files\Mozilla Firefox\firefox.exe&lt;br&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;br&gt;&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com&lt;br&gt;R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://myspace.com/&lt;br&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;br&gt;R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll&lt;br&gt;R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL&lt;br&gt;O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll&lt;br&gt;O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll&lt;br&gt;O3 - Toolbar: &amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll&lt;br&gt;O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL&lt;br&gt;O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\IEViewBar.dll&lt;br&gt;O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll&lt;br&gt;O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe&lt;br&gt;O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"&lt;br&gt;O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"&lt;br&gt;O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"&lt;br&gt;O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe&lt;br&gt;O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe&lt;br&gt;O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE&lt;br&gt;O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S&lt;br&gt;O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe&lt;br&gt;O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1179188616\ee\AOLSoftware.exe&lt;br&gt;O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB001" /M "Stylus Photo R300"&lt;br&gt;O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu1000106.exe 61A847B5BBF72813329B385772FF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310F3D2933202228B284662E901F3D293314D6ECF32257895769ABCF75D7551F765142DAF48BD87822212329A38506CAC59B6&lt;br&gt;O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\kwintmdq.exe CHD003&lt;br&gt;O4 - HKLM\..\Run: [{B5-54-43-3D-ZN}] C:\WINDOWS\system32\lsdsrngp.exe CHD003&lt;br&gt;O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\DriveCleaner Freeware\dcsm.exe"&lt;br&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"&lt;br&gt;O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"&lt;br&gt;O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime&lt;br&gt;O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"&lt;br&gt;O4 - HKLM\..\Run: [a41b5492] rundll32.exe "C:\WINDOWS\system32\nvtigsoa.dll",b&lt;br&gt;O4 - HKLM\..\Run: [BMa728670e] Rundll32.exe "C:\WINDOWS\system32\dyunvwas.dll",s&lt;br&gt;O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background&lt;br&gt;O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe&lt;br&gt;O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;br&gt;O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe&lt;br&gt;O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')&lt;br&gt;O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'SYSTEM')&lt;br&gt;O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')&lt;br&gt;O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\lsdsrngp.exe&lt;br&gt;O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\kwintmdq.exe&lt;br&gt;O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe&lt;br&gt;O8 - Extra context menu item: &amp;AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML&lt;br&gt;O8 - Extra context menu item: &amp;Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZCxdm860YYUS&lt;br&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll&lt;br&gt;O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll&lt;br&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com&lt;br&gt;O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/CursorManiaFWBInitialSetup1.0.0.15-3.cab&lt;br&gt;O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab&lt;br&gt;O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1185413384984&lt;br&gt;O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1185413364796&lt;br&gt;O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe&lt;br&gt;O23 - Service: Belkin Wireless USB Network Adapter (Belkin Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe&lt;br&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;br&gt;O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe&lt;br&gt;O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe&lt;br&gt;O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe&lt;br&gt;O23 - Service: DomainService -   - C:\WINDOWS\system32\xhhslfey.exe&lt;br&gt;O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;br&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe&lt;br&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br&gt;O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe&lt;br&gt;O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - c:\Program Files\Intel\NCS\Sync\NetSvc.exe&lt;br&gt;O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe&lt;br&gt;O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe&lt;br&gt;O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe&lt;br&gt;&lt;br&gt;--&lt;br&gt;End of file - 9823 bytes&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;So what do I need to do?</description><pubDate>Sun, 24 Feb 2008 16:49:05 GMT</pubDate><dc:creator>Dirtbikenick</dc:creator></item><item><title>wifes laptop</title><link>http://forum.tweaks.com/forum/Topic239313-29-1.aspx</link><description>Hi, my wifes laptop, running vista, has slowed down to an almost stop. Had to do this comunication via safe mode.&lt;/P&gt;&lt;P&gt;Can you help please? H&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 18:15:37, on 12/05/2008&lt;BR&gt;Platform: Windows Vista  (WinNT 6.00.1904)&lt;BR&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16643)&lt;BR&gt;Boot mode: Safe mode with network support&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\Windows\Explorer.EXE&lt;BR&gt;C:\Windows\system32\wbem\unsecapp.exe&lt;BR&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;BR&gt;C:\Users\customer\AppData\Local\Microsoft\Messenger\chip454@msn.com\Sharing Folders\HijackThis.exe&lt;/P&gt;&lt;P&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.virginmedia.com/"&gt;http://www.virginmedia.com/&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = &lt;BR&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = &lt;BR&gt;O1 - Hosts: ::1 localhost&lt;BR&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;BR&gt;O2 - BHO: SurfingEnhancer - {57636FBF-8C24-0D22-E203-3D4DFA59E2A4} - C:\Program Files\SurfingEnhancer\SurfingEnhancer-1.dll&lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll&lt;BR&gt;O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)&lt;BR&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;BR&gt;O2 - BHO: Mirar - {9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} - C:\Windows\system32\WinNB55.dll&lt;BR&gt;O2 - BHO: SmartEnhancer - {F608C2D0-846D-4F0E-E47A-88367C887707} - C:\Program Files\SmartEnhancer\SmartEnhancer-2.dll&lt;BR&gt;O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide&lt;BR&gt;O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe&lt;BR&gt;O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe -chkautorun&lt;BR&gt;O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"&lt;BR&gt;O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"&lt;BR&gt;O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl&lt;BR&gt;O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe&lt;BR&gt;O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe"&lt;BR&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"&lt;BR&gt;O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"&lt;BR&gt;O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background&lt;BR&gt;O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe&lt;BR&gt;O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')&lt;BR&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll&lt;BR&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL&lt;BR&gt;O13 - Gopher Prefix: &lt;BR&gt;O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - &lt;A href="http://upload.facebook.com/controls/FacebookPhotoUploader3.cab"&gt;http://upload.facebook.com/controls/FacebookPhotoUploader3.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - &lt;A href="http://javadl-esd.sun.com/update/1.6.0/jinstall-6u3-windows-i586-jc.cab"&gt;http://javadl-esd.sun.com/update/1.6.0/jinstall-6u3-windows-i586-jc.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - &lt;A href="http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab"&gt;http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &lt;A href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab"&gt;http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - &lt;A href="http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab"&gt;http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab&lt;/A&gt;&lt;BR&gt;O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe&lt;BR&gt;O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;BR&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;BR&gt;O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe&lt;BR&gt;O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe&lt;BR&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;BR&gt;O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe&lt;BR&gt;O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe&lt;BR&gt;O23 - Service: SCM_Service - Unknown owner - C:\Windows\System32\WinService.exe&lt;BR&gt;O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe&lt;BR&gt;O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe&lt;BR&gt;O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe&lt;BR&gt;O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe&lt;BR&gt;O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe&lt;BR&gt;O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 6759 bytes&lt;BR&gt;</description><pubDate>Mon, 12 May 2008 12:23:26 GMT</pubDate><dc:creator>Howard.M.</dc:creator></item><item><title>To Downloaders and a Trojan</title><link>http://forum.tweaks.com/forum/Topic239450-29-1.aspx</link><description>hello I have to Downloaders and a Trojan on my computer Norton 360 says manual fixes are required but when I go to the website the instructions make no sense what so ever I have been here before so with 4 trojans on my computer so I know to post a Hijackthis log. Please help &lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br&gt;Scan saved at 3:25:06 PM, on 5/14/2008&lt;br&gt;Platform: Windows Vista  (WinNT 6.00.1904)&lt;br&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16643)&lt;br&gt;Boot mode: Normal&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\Windows\system32\taskeng.exe&lt;br&gt;C:\Windows\system32\Dwm.exe&lt;br&gt;C:\Windows\Explorer.EXE&lt;br&gt;C:\Program Files\Windows Defender\MSASCui.exe&lt;br&gt;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&lt;br&gt;C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe&lt;br&gt;C:\Users\Brady\Documents\RocketDock\RocketDock.exe&lt;br&gt;C:\Program Files\Mozilla Firefox\firefox.exe&lt;br&gt;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&lt;br&gt;C:\Program Files\Norton 360\ScanStub.exe&lt;br&gt;C:\Windows\system32\SearchFilterHost.exe&lt;br&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;br&gt;&lt;br&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = &lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = &lt;br&gt;O1 - Hosts: ::1 localhost&lt;br&gt;O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll&lt;br&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br&gt;O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)&lt;br&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;br&gt;O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\UIBHO.dll&lt;br&gt;O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide&lt;br&gt;O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"&lt;br&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"&lt;br&gt;O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"&lt;br&gt;O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter&lt;br&gt;O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background&lt;br&gt;O4 - HKCU\..\Run: [RocketDock] "C:\Users\Brady\Documents\RocketDock\RocketDock.exe"&lt;br&gt;O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')&lt;br&gt;O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')&lt;br&gt;O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')&lt;br&gt;O4 - HKUS\S-1-5-21-628986973-3637866670-4290851379-1000\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'Sean')&lt;br&gt;O4 - HKUS\S-1-5-21-628986973-3637866670-4290851379-1003\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'Keagan')&lt;br&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br&gt;O13 - Gopher Prefix: &lt;br&gt;O23 - Service: ccEvtMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;br&gt;O23 - Service: ccSetMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;br&gt;O23 - Service: Client32 - NetSupport Ltd - C:\Program Files\NetSupport\NetSupport Manager\client32.exe&lt;br&gt;O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;br&gt;O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe&lt;br&gt;O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE&lt;br&gt;O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;br&gt;O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe&lt;br&gt;O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe&lt;br&gt;&lt;br&gt;--&lt;br&gt;End of file - 5198 bytes&lt;br&gt;</description><pubDate>Wed, 14 May 2008 17:33:24 GMT</pubDate><dc:creator>Legit12</dc:creator></item><item><title>IE and MSN warnings about trying to log key strokes</title><link>http://forum.tweaks.com/forum/Topic239438-29-1.aspx</link><description>Hey, over the last two days my firewall (zonealarm) has warned me about IE and MSN trying to log keystrokes and monitor activites. I blocked both of these warnings but confused to why they are coming up and why it would be MSN and IE. So my log is below.&lt;br&gt;&lt;br&gt;Thanks:)&lt;br&gt;&lt;br&gt;Logfile of HijackThis v1.99.1&lt;br&gt;Scan saved at 11:09:44 PM, on 14/05/2008&lt;br&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16640)&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\WINDOWS\System32\smss.exe&lt;br&gt;C:\WINDOWS\system32\winlogon.exe&lt;br&gt;C:\WINDOWS\system32\services.exe&lt;br&gt;C:\WINDOWS\system32\lsass.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\WINDOWS\system32\ZoneLabs\vsmon.exe&lt;br&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br&gt;C:\WINDOWS\system32\acs.exe&lt;br&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;br&gt;C:\WINDOWS\system32\nvsvc32.exe&lt;br&gt;C:\Program Files\CyberLink\Shared files\RichVideo.exe&lt;br&gt;C:\WINDOWS\system32\STacSV.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgam.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgrsx.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgemc.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;br&gt;C:\Program Files\Windows Live\Messenger\usnsvc.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgnsx.exe&lt;br&gt;C:\WINDOWS\Explorer.EXE&lt;br&gt;C:\WINDOWS\sttray.exe&lt;br&gt;C:\Program Files\TP-LINK\TWCU\TWCU.exe&lt;br&gt;C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgtray.exe&lt;br&gt;C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe&lt;br&gt;C:\Program Files\QuickTime\QTTask.exe&lt;br&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;br&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe&lt;br&gt;C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe&lt;br&gt;C:\Program Files\iTunes\iTunes.exe&lt;br&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe&lt;br&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\distnoted.exe&lt;br&gt;C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE&lt;br&gt;C:\Program Files\Mozilla Firefox\firefox.exe&lt;br&gt;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&lt;br&gt;C:\WINDOWS\system32\igfxsrvc.exe&lt;br&gt;C:\WINDOWS\system32\mspaint.exe&lt;br&gt;C:\Program Files\Hijackthis\HijackThis.exe&lt;br&gt;&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;br&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;br&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br&gt;O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll&lt;br&gt;O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;br&gt;O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe&lt;br&gt;O4 - HKLM\..\Run: [nwiz] nwiz.exe /install&lt;br&gt;O4 - HKLM\..\Run: [TWCU] "C:\Program Files\TP-LINK\TWCU\TWCU.exe" -nogui&lt;br&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"&lt;br&gt;O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup&lt;br&gt;O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe&lt;br&gt;O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"&lt;br&gt;O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime&lt;br&gt;O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"&lt;br&gt;O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;O4 - Startup: Stardock ObjectDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe&lt;br&gt;O4 - Startup: Y'z ToolBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe&lt;br&gt;O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe&lt;br&gt;O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe&lt;br&gt;O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe&lt;br&gt;O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000&lt;br&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL&lt;br&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)&lt;br&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)&lt;br&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll&lt;br&gt;O11 - Options group: [INTERNATIONAL] International*&lt;br&gt;O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab&lt;br&gt;O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab&lt;br&gt;O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab&lt;br&gt;O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll&lt;br&gt;O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL&lt;br&gt;O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL&lt;br&gt;O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL&lt;br&gt;O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll&lt;br&gt;O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll&lt;br&gt;O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll&lt;br&gt;O23 - Service: TP-LINK Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe&lt;br&gt;O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe&lt;br&gt;O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br&gt;O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe&lt;br&gt;O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;br&gt;O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe&lt;br&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br&gt;O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe&lt;br&gt;O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe&lt;br&gt;O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\STacSV.exe&lt;br&gt;O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe&lt;br&gt;&lt;br&gt;</description><pubDate>Wed, 14 May 2008 10:10:33 GMT</pubDate><dc:creator>rocknrolldan</dc:creator></item><item><title>RE: Slow Performance in Programs Where There Was...</title><link>http://forum.tweaks.com/forum/Topic239453-29-1.aspx</link><description>As per RichieUK's reply to my post in the General Windows Support forum, here is my hijackthis log I just ran.&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 7:08:32 PM, on 5/14/2008&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16640)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\brsvc01a.exe&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\WINDOWS\system32\brss01a.exe&lt;BR&gt;C:\WINDOWS\eHome\ehRecvr.exe&lt;BR&gt;C:\WINDOWS\eHome\ehSched.exe&lt;BR&gt;C:\WINDOWS\system32\tcpsvcs.exe&lt;BR&gt;C:\WINDOWS\System32\snmp.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\dllhost.exe&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\WINDOWS\system32\wscntfy.exe&lt;BR&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.vampirefreaks.com/"&gt;http://www.vampirefreaks.com/&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &lt;A href="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html"&gt;http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll&lt;BR&gt;O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll&lt;BR&gt;O2 - BHO: (no name) - {113F2B42-FD88-45F6-9DEB-2D3463A8FC71} - (no file)&lt;BR&gt;O2 - BHO: Spybot-S&amp;amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll&lt;BR&gt;O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)&lt;BR&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;BR&gt;O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll&lt;BR&gt;O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll&lt;BR&gt;O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll&lt;BR&gt;O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O8 - Extra context menu item: Add to Windows &amp;amp;Live Favorites - &lt;A href="http://favorites.live.com/quickadd.aspx"&gt;http://favorites.live.com/quickadd.aspx&lt;/A&gt;&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll&lt;BR&gt;O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe&lt;BR&gt;O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL&lt;BR&gt;O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Spybot - Search &amp;amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;BR&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)&lt;BR&gt;O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - &lt;A href="http://a1540.g.akamai.net/7/1540/52/20070501/qtinstall.info.apple.com/qtactivex/qtplugin.cab"&gt;http://a1540.g.akamai.net/7/1540/52/20070501/qtinstall.info.apple.com/qtactivex/qtplugin.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - &lt;A href="http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB"&gt;http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB&lt;/A&gt;&lt;BR&gt;O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - &lt;A href="http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab"&gt;http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - &lt;A href="http://upload.facebook.com/controls/FacebookPhotoUploader.cab"&gt;http://upload.facebook.com/controls/FacebookPhotoUploader.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - &lt;A href="http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab"&gt;http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - &lt;A href="http://www.crucial.com/controls/cpcScanner.cab"&gt;http://www.crucial.com/controls/cpcScanner.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - &lt;A href="http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab"&gt;http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab&lt;/A&gt;&lt;BR&gt;O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 5735 bytes&lt;BR&gt;</description><pubDate>Wed, 14 May 2008 18:14:14 GMT</pubDate><dc:creator>PV</dc:creator></item><item><title>Host.exe My pc Suddendly Hang...Im IN RISK</title><link>http://forum.tweaks.com/forum/Topic239468-29-1.aspx</link><description>Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 11:45:04 AM, on 5/15/2008&lt;BR&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v7.00 (7.00.5730.0013)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;BR&gt;C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe&lt;BR&gt;C:\Program Files\Evidence Exterminator\erasrv.exe&lt;BR&gt;C:\WINDOWS\system32\HUMMBIRD\Inetd32.exe&lt;BR&gt;C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe&lt;BR&gt;C:\WINDOWS\system32\nvsvc32.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\WINDOWS\RTHDCPL.EXE&lt;BR&gt;C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE&lt;BR&gt;C:\WINDOWS\system32\RUNDLL32.EXE&lt;BR&gt;C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe&lt;BR&gt;C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe&lt;BR&gt;C:\Program Files\HP\HP Software Update\HPWuSchd2.exe&lt;BR&gt;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&lt;BR&gt;C:\Program Files\Winamp\winampa.exe&lt;BR&gt;C:\Program Files\USB Disk Security\USBGuard.exe&lt;BR&gt;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&lt;BR&gt;C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe&lt;BR&gt;C:\Program Files\Evidence Exterminator\eraser.exe&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\Program Files\Skype\Phone\Skype.exe&lt;BR&gt;C:\Program Files\MagicDisc\MagicDisc.exe&lt;BR&gt;C:\Program Files\Skype\Plugin Manager\skypePM.exe&lt;BR&gt;C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE&lt;BR&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;BR&gt;C:\Program Files\Microsoft Office\Office12\EXCEL.EXE&lt;BR&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.yahoo.com/"&gt;http://www.yahoo.com/&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &lt;A href="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html"&gt;http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html&lt;/A&gt;&lt;BR&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer&lt;BR&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.100.254:3128&lt;BR&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 192.168.100.254:3128;192.168.*;&amp;lt;local&amp;gt;&lt;BR&gt;R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll&lt;BR&gt;O2 - BHO: &amp;amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll&lt;BR&gt;O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll&lt;BR&gt;O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll&lt;BR&gt;O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll&lt;BR&gt;O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll&lt;BR&gt;O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL&lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll&lt;BR&gt;O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll&lt;BR&gt;O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll&lt;BR&gt;O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll&lt;BR&gt;O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe&lt;BR&gt;O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE&lt;BR&gt;O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start&lt;BR&gt;O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup&lt;BR&gt;O4 - HKLM\..\Run: [nwiz] nwiz.exe /install&lt;BR&gt;O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarIn