﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Tweaks.com Forum  / Windows &amp; System Security / HiJack This Logs  / White X in a Red Circle in my System Tray / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>Tweaks.com Forum </description><link>http://forum.tweaks.com/forum/</link><webMaster>forum@tweaks.com</webMaster><lastBuildDate>Mon, 06 Oct 2008 19:49:09 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: White X in a Red Circle in my System Tray</title><link>http://forum.tweaks.com/forum/Topic239390-29-1.aspx</link><description>You're welcome:)</description><pubDate>Wed, 14 May 2008 12:21:02 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: White X in a Red Circle in my System Tray</title><link>http://forum.tweaks.com/forum/Topic239390-29-1.aspx</link><description>thanks for all your help, I really appreciate it.</description><pubDate>Wed, 14 May 2008 10:31:45 GMT</pubDate><dc:creator>sundancekid726</dc:creator></item><item><title>RE: White X in a Red Circle in my System Tray</title><link>http://forum.tweaks.com/forum/Topic239390-29-1.aspx</link><description>Your log is clean:),please do the following:&lt;br&gt;&lt;br&gt;You should take the time to read and follow the information found in the links below,to help you prevent any possible future infections and stay safe and secure while online:&lt;br&gt;&lt;br&gt;[b][color="blue"]Simple and easy ways to keep your computer safe and secure on the Internet[/color][/b]:&lt;br&gt;[url]http://www.bleepingcomputer.com/tutorials/tutorial82.html[/url]&lt;br&gt;&lt;br&gt;[b][color="blue"]How to prevent Malware[/color][/b]:&lt;br&gt;[url]http://users.telenet.be/bluepatchy/miekiemoes/prevention.html[/url]&lt;br&gt;&lt;br&gt;[B][color="blue"]So how did I get infected in the first place[/color][/B]:&lt;br&gt;[URL]http://forums.spybot.info/showthread.php?t=279[/URL]&lt;br&gt;&lt;br&gt;[B][color="blue"]Malware Cleanup Programs and Preventative Procedures[/color][/B]: &lt;br&gt;[URL]http://russelltexas.com/malware/allclear.htm[/URL]&lt;br&gt;&lt;br&gt;[b][color="blue"]Hardening Windows Security - Part 1[/color][/b]:&lt;br&gt;[url]http://www.malwarehelp.org/Malware-Prevention-Hardening-Windows-Security1.html[/url]&lt;br&gt;&lt;br&gt;[b][color="blue"]Hardening Windows Security - Part 2[/color][/b]:&lt;br&gt;[url]http://www.malwarehelp.org/malware-prevention-hardening-windows-security2.html[/url]</description><pubDate>Wed, 14 May 2008 01:46:06 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: White X in a Red Circle in my System Tray</title><link>http://forum.tweaks.com/forum/Topic239390-29-1.aspx</link><description>Sorry that this took so long. Here is my latest hijack this log, everything seems to be running well.&lt;BR&gt;&lt;BR&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 11:02:33 PM, on 5/13/2008&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16640)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;BR&gt;C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe&lt;BR&gt;C:\WINDOWS\system32\LEXBCES.EXE&lt;BR&gt;C:\WINDOWS\system32\LEXPPS.EXE&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;BR&gt;C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe&lt;BR&gt;C:\WINDOWS\System32\CTsvcCDA.exe&lt;BR&gt;C:\WINDOWS\System32\MsPMSPSv.exe&lt;BR&gt;C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe&lt;BR&gt;C:\Program Files\Dell\Media Experience\PCMService.exe&lt;BR&gt;C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe&lt;BR&gt;C:\Program Files\Real\RealPlayer\RealPlay.exe&lt;BR&gt;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&lt;BR&gt;C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe&lt;BR&gt;C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe&lt;BR&gt;C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe&lt;BR&gt;C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe&lt;BR&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;BR&gt;C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;BR&gt;C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe&lt;BR&gt;C:\Program Files\DellSupport\DSAgnt.exe&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe&lt;BR&gt;C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;BR&gt;C:\WINDOWS\system32\wuauclt.exe&lt;BR&gt;C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;BR&gt;C:\Program Files\internet explorer\iexplore.exe&lt;BR&gt;C:\WINDOWS\system32\wuauclt.exe&lt;/P&gt;&lt;P&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.yahoo.com/"&gt;http://www.yahoo.com/&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = &lt;A href="http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com"&gt;http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com&lt;/A&gt;&lt;BR&gt;R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll&lt;BR&gt;O2 - BHO: &amp;amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll&lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll&lt;BR&gt;O3 - Toolbar: &amp;amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll&lt;BR&gt;O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll&lt;BR&gt;O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe&lt;BR&gt;O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe&lt;BR&gt;O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe&lt;BR&gt;O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup&lt;BR&gt;O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE&lt;BR&gt;O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"&lt;BR&gt;O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe&lt;BR&gt;O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r&lt;BR&gt;O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER&lt;BR&gt;O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup&lt;BR&gt;O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start&lt;BR&gt;O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN&lt;BR&gt;O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe&lt;BR&gt;O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"&lt;BR&gt;O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"&lt;BR&gt;O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime&lt;BR&gt;O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"&lt;BR&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"&lt;BR&gt;O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"&lt;BR&gt;O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"&lt;BR&gt;O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe&lt;BR&gt;O4 - HKCU\..\Run: [DellTransferAgent] "C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe"&lt;BR&gt;O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;BR&gt;O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE&lt;BR&gt;O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?&lt;BR&gt;O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe&lt;BR&gt;O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll&lt;BR&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &lt;A href="http://go.microsoft.com/fwlink/?linkid=39204"&gt;http://go.microsoft.com/fwlink/?linkid=39204&lt;/A&gt;&lt;BR&gt;O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - &lt;A href="http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab"&gt;http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - &lt;A href="http://upload.facebook.com/controls/FacebookPhotoUploader3.cab"&gt;http://upload.facebook.com/controls/FacebookPhotoUploader3.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - &lt;A href="http://upload.facebook.com/controls/FacebookPhotoUploader.cab"&gt;http://upload.facebook.com/controls/FacebookPhotoUploader.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - &lt;A href="http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab"&gt;http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - &lt;A href="https://webdl.symantec.com/activex/symdlmgr.cab"&gt;https://webdl.symantec.com/activex/symdlmgr.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &lt;A href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1124836278656"&gt;http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1124836278656&lt;/A&gt;&lt;BR&gt;O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} (Symantec Download Bridge) - &lt;A href="https://a248.e.akamai.net/f/248/5462/2h/www.symantecstore.com/v2.0-img/operations/symbizpr/xcontrol/SymDlBrg.cab"&gt;https://a248.e.akamai.net/f/248/5462/2h/www.symantecstore.com/v2.0-img/operations/symbizpr/xcontrol/SymDlBrg.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &lt;A href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab"&gt;http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - &lt;A href="http://www.shockwave.com/content/bejeweled2/sis/popcaploader_v10.cab"&gt;http://www.shockwave.com/content/bejeweled2/sis/popcaploader_v10.cab&lt;/A&gt;&lt;BR&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;BR&gt;O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;BR&gt;O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe&lt;BR&gt;O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;BR&gt;O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;BR&gt;O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;BR&gt;O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe&lt;BR&gt;O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe&lt;BR&gt;O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe&lt;BR&gt;O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;BR&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe&lt;BR&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;BR&gt;O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE&lt;BR&gt;O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE&lt;BR&gt;O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;BR&gt;O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe&lt;BR&gt;O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 10283 bytes&lt;BR&gt;</description><pubDate>Tue, 13 May 2008 22:08:27 GMT</pubDate><dc:creator>sundancekid726</dc:creator></item><item><title>RE: White X in a Red Circle in my System Tray</title><link>http://forum.tweaks.com/forum/Topic239390-29-1.aspx</link><description>Click on Start/Run,copy and paste [b]ComboFix /u[/b] into the 'Open:' space,then press Ok.&lt;br&gt;This will uninstall Combofix,delete its related folders and files,reset your clock settings,hide file extensions,hide the system/hidden files and resets System Restore.&lt;br&gt;&lt;br&gt;[IMG]http://img.photobucket.com/albums/v624/29wood/comu.gif[/IMG]&lt;br&gt;&lt;br&gt;&lt;br&gt;Please double-click [b]OTMoveIt.exe[/b] again to run it.&lt;br&gt;Click on the 'Cleanup' button [IMG]http://img.photobucket.com/albums/v624/29wood/Clipboard01cleanup.gif[/IMG]&lt;br&gt;When you do this a text file named cleanup.txt will be downloaded from the internet. &lt;br&gt;If you get a warning from your firewall or other security programs regarding OTMoveIt attempting to contact the internet you should allow it to do so. &lt;br&gt;When the 'Confirm' box appears click 'Yes'.&lt;br&gt;[b]Restart your pc when prompted.[/b]&lt;br&gt;&lt;br&gt;&lt;br&gt;Download and scan with [b][color="red"]CCleaner[/color][/b]:&lt;br&gt;[url]http://www.ccleaner.com/downloadbuilds.asp[/url]&lt;br&gt;1. Starting with v1.27.260, CCleaner installs the [b]Yahoo Toolbar[/b] as an option which IS checkmarked by default during the installation. IF you do NOT want it, REMOVE the checkmark when provided with the option OR download the toolbar-free Basic or Slim versions instead of the Standard Build.&lt;br&gt;&lt;br&gt;2. Before first use, select Options &gt; Advanced and UNCHECK [b]"Only delete files in Windows Temp folder older than 48 hours"[/b]&lt;br&gt;&lt;br&gt;3. Then select the items you wish to clean up.&lt;br&gt;&lt;br&gt;[b]In the Windows Tab:[/b]&lt;br&gt;* Clean all entries in the "Internet Explorer" section except Cookies.&lt;br&gt;* Clean all the entries in the "Windows Explorer" section.&lt;br&gt;* Clean all entries in the "System" section.&lt;br&gt;* Clean all entries in the "Advanced" section.&lt;br&gt;* Clean any others that you choose.&lt;br&gt;&lt;br&gt;[b]In the Applications Tab:[/b]&lt;br&gt;* Clean all except cookies in the Firefox/Mozilla section if you use it.&lt;br&gt;* Clean all in the Opera section if you use it.&lt;br&gt;* Clean Sun Java in the Internet Section.&lt;br&gt;* Clean any others that you choose.&lt;br&gt;&lt;br&gt;4. Click the "Run Cleaner" button.&lt;br&gt;5. A pop up box will appear advising this process will permanently delete files from your system.&lt;br&gt;6. Click "OK" and it will scan and clean your system.&lt;br&gt;7. Click "Exit" when done.&lt;br&gt;&lt;br&gt;&lt;br&gt;Your version of [b]Sun Java[/b] is out of date.&lt;br&gt;Older versions have vulnerabilities that malware can use to infect your system.&lt;br&gt;Please follow these steps to remove older versions of Sun Java,and then update.&lt;br&gt;1. Download the latest version of [b][url=http://java.sun.com/javase/downloads/index.jsp][color="blue"]Java Runtime Environment (JRE)[/color][/url][/b]&lt;br&gt;2. Scroll down to where it says '[b]Java Runtime Environment (JRE) 6u6[/b]'.&lt;br&gt;3. Click the "Download" button to the right.&lt;br&gt;4. Select the Platform and Language for your download,then check the box that says: "Accept License Agreement".&lt;br&gt;5. The page will refresh.&lt;br&gt;6. Click on the link to download [b]'Windows Offline Installation, Multi-language - jre-6u6-windows-i586-p.exe'[/b] [15.21 MB] and save to your desktop.&lt;br&gt;7. Close any programs you may have running - especially your web browser.&lt;br&gt;8. Go to Start &gt; Control Panel double-click on Add/Remove programs and remove all older versions of Java.&lt;br&gt;9. Check any item with Java Runtime Environment (JRE or J2SE) in the name.&lt;br&gt;10. Click the Change/Remove button.&lt;br&gt;11. Repeat as many times as necessary to remove each Java version.&lt;br&gt;12. Reboot your computer once all Java components are removed.&lt;br&gt;13. Then from your desktop double-click on [b]jre-6u6-windows-i586-p.exe[/b] to install the newest version.&lt;br&gt;&lt;br&gt;&lt;br&gt;Download\install [b]'SuperAntiSpyware Free Version Home Users'[/b] from here:&lt;br&gt;[URL]http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWAREFREE[/URL]&lt;br&gt;&lt;br&gt;Launch SuperAntiSpyware and click on 'Check for updates'.&lt;br&gt;If you encounter any error messages while downloading the updates,manually download them from [B][URL=http://www.superantispyware.com/definitions.html][COLOR="BLUE"]Here[/COLOR][/URL][/B].&lt;br&gt;Once the updates have been installed,[b]exit[/b] SuperAntiSpyware.&lt;br&gt;[b]Do not run it just yet.[/b]&lt;br&gt;&lt;br&gt;Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'. &lt;br&gt;Make sure all browser and all Windows Explorer windows are closed before fixing:&lt;br&gt;[b]O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)&lt;br&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)&lt;br&gt;O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)&lt;br&gt;O16 - DPF: {FCF289D4-0AC8-4ED8-BE31-E8AF09606AB5} (download_35mb_com.applet) - http://static.35mb.com/applet/applet_o.cab[/b]&lt;br&gt;Exit Hijackthis.&lt;br&gt;&lt;br&gt;[b]Now Start SuperAntiSpyware.[/b]&lt;br&gt;On the main screen click on 'Scan your computer'.&lt;br&gt;Check: 'Perform Complete Scan'.&lt;br&gt;Click 'Next' to start the scan.&lt;br&gt;&lt;br&gt;Superantispyware will now scan your computer,when it's finished it will list all/any infections found.&lt;br&gt;Make sure everything found has a checkmark next to it,then press 'Next'.&lt;br&gt;Click on 'Finish' when you've done.&lt;br&gt;&lt;br&gt;It's possible that the program will ask you to reboot in order to delete some files.&lt;br&gt;&lt;br&gt;Obtain the SuperAntiSpyware log as follows:&lt;br&gt;Click on 'Preferences'.&lt;br&gt;Click on the 'Statistics/Logs' tab.&lt;br&gt;Under 'Scanner Logs' double click on 'SuperAntiSpyware Scan Log'.&lt;br&gt;It will then open in your default text editor,such as Notepad.&lt;br&gt;[b]Copy and paste the contents of that report into your next reply.&lt;br&gt;Also post a new Hijackthis log,let me know how your pc is running now.[/b]</description><pubDate>Tue, 13 May 2008 18:01:56 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: White X in a Red Circle in my System Tray</title><link>http://forum.tweaks.com/forum/Topic239390-29-1.aspx</link><description>C:\WINDOWS\bak moved successfully.&lt;BR&gt;C:\Program Files\AIM6\bak moved successfully.&lt;BR&gt;C:\Program Files\DellSupport\bak moved successfully.&lt;BR&gt;C:\Program Files\iTunes\bak moved successfully.&lt;BR&gt;C:\Program Files\QuickTime\bak moved successfully.&lt;BR&gt;C:\Program Files\REGSHAVE\bak moved successfully.&lt;BR&gt;C:\WINDOWS\SYSTEM32\bak moved successfully.&lt;BR&gt;C:\Program Files\Dell\Media Experience\bak moved successfully.&lt;BR&gt;C:\Program Files\Intel\Modem Event Monitor\bak moved successfully.&lt;BR&gt;C:\Program Files\Real\RealPlayer\bak moved successfully.&lt;BR&gt;C:\Program Files\Yahoo!\Search Protection\bak moved successfully.&lt;BR&gt;C:\WINDOWS\SYSTEM32\dla\bak moved successfully.&lt;BR&gt;C:\Program Files\Adobe\Reader 8.0\Reader\bak moved successfully.&lt;BR&gt;C:\Program Files\Common Files\InstallShield\UpdateService\bak moved successfully.&lt;BR&gt;C:\Program Files\Common Files\Sonic\Update Manager\bak moved successfully.&lt;BR&gt;C:\Program Files\Creative\SBLive\Diagnostics\bak moved successfully.&lt;BR&gt;C:\Program Files\Java\j2re1.4.2_03\bin\bak moved successfully.&lt;BR&gt;C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\bak moved successfully.&lt;BR&gt;C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\bak moved successfully.&lt;BR&gt;C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\bak moved successfully.&lt;BR&gt; &lt;BR&gt;OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 05132008_185014&lt;BR&gt;&lt;BR&gt;&lt;BR&gt;&lt;BR&gt;&lt;BR&gt;&lt;BR&gt;MY LATEST HIJACK THIS LOG:&lt;BR&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 6:51:51 PM, on 5/13/2008&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16640)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;BR&gt;C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe&lt;BR&gt;C:\WINDOWS\system32\LEXBCES.EXE&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;BR&gt;C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe&lt;BR&gt;C:\WINDOWS\System32\CTsvcCDA.exe&lt;BR&gt;C:\WINDOWS\System32\MsPMSPSv.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;BR&gt;C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;BR&gt;C:\WINDOWS\system32\lexpps.exe&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe&lt;BR&gt;C:\Program Files\internet explorer\iexplore.exe&lt;BR&gt;C:\WINDOWS\system32\wuauclt.exe&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.yahoo.com/"&gt;http://www.yahoo.com/&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = &lt;A href="http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com"&gt;http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com&lt;/A&gt;&lt;BR&gt;R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll&lt;BR&gt;O2 - BHO: &amp;amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll&lt;BR&gt;O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll&lt;BR&gt;O3 - Toolbar: &amp;amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll&lt;BR&gt;O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll&lt;BR&gt;O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe&lt;BR&gt;O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe&lt;BR&gt;O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe&lt;BR&gt;O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup&lt;BR&gt;O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE&lt;BR&gt;O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"&lt;BR&gt;O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe&lt;BR&gt;O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r&lt;BR&gt;O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER&lt;BR&gt;O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup&lt;BR&gt;O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start&lt;BR&gt;O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN&lt;BR&gt;O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe&lt;BR&gt;O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"&lt;BR&gt;O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"&lt;BR&gt;O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime&lt;BR&gt;O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"&lt;BR&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"&lt;BR&gt;O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"&lt;BR&gt;O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"&lt;BR&gt;O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe&lt;BR&gt;O4 - HKCU\..\Run: [DellTransferAgent] "C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe"&lt;BR&gt;O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE&lt;BR&gt;O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)&lt;BR&gt;O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe&lt;BR&gt;O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll&lt;BR&gt;O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - &lt;A href="http://wwws.musicmatch.com/mmz/openWebRadio.html"&gt;http://wwws.musicmatch.com/mmz/openWebRadio.html&lt;/A&gt; (file missing)&lt;BR&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &lt;A href="http://go.microsoft.com/fwlink/?linkid=39204"&gt;http://go.microsoft.com/fwlink/?linkid=39204&lt;/A&gt;&lt;BR&gt;O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - &lt;A href="http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab"&gt;http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - &lt;A href="http://upload.facebook.com/controls/FacebookPhotoUploader3.cab"&gt;http://upload.facebook.com/controls/FacebookPhotoUploader3.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - &lt;A href="http://upload.facebook.com/controls/FacebookPhotoUploader.cab"&gt;http://upload.facebook.com/controls/FacebookPhotoUploader.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - &lt;A href="http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab"&gt;http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - &lt;A href="https://webdl.symantec.com/activex/symdlmgr.cab"&gt;https://webdl.symantec.com/activex/symdlmgr.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &lt;A href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1124836278656"&gt;http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1124836278656&lt;/A&gt;&lt;BR&gt;O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} (Symantec Download Bridge) - &lt;A href="https://a248.e.akamai.net/f/248/5462/2h/www.symantecstore.com/v2.0-img/operations/symbizpr/xcontrol/SymDlBrg.cab"&gt;https://a248.e.akamai.net/f/248/5462/2h/www.symantecstore.com/v2.0-img/operations/symbizpr/xcontrol/SymDlBrg.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &lt;A href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab"&gt;http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - &lt;A href="http://www.shockwave.com/content/bejeweled2/sis/popcaploader_v10.cab"&gt;http://www.shockwave.com/content/bejeweled2/sis/popcaploader_v10.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {FCF289D4-0AC8-4ED8-BE31-E8AF09606AB5} (download_35mb_com.applet) - &lt;A href="http://static.35mb.com/applet/applet_o.cab"&gt;http://static.35mb.com/applet/applet_o.cab&lt;/A&gt;&lt;BR&gt;O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;BR&gt;O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe&lt;BR&gt;O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;BR&gt;O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;BR&gt;O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;BR&gt;O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe&lt;BR&gt;O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe&lt;BR&gt;O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe&lt;BR&gt;O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;BR&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe&lt;BR&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;BR&gt;O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE&lt;BR&gt;O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE&lt;BR&gt;O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;BR&gt;O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe&lt;BR&gt;O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 9696 bytes&lt;BR&gt;&lt;BR&gt;</description><pubDate>Tue, 13 May 2008 17:52:20 GMT</pubDate><dc:creator>sundancekid726</dc:creator></item><item><title>RE: White X in a Red Circle in my System Tray</title><link>http://forum.tweaks.com/forum/Topic239390-29-1.aspx</link><description>Please download [b]OTMoveIt[/b] by [b]OldTimer[/b],save it to your desktop:&lt;br&gt;[url]http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe[/url]&lt;br&gt;Please double-click OTMoveIt.exe to run it.&lt;br&gt;Copy [b]ALL[/b] the text inside the code box below to the clipboard by highlighting [b]ALL[/b] of it and pressing CTRL + C (or, after highlighting, right-click and choose 'Copy'):&lt;br&gt;&lt;br&gt;[quote]C:\WINDOWS\bak&lt;br&gt;C:\Program Files\AIM6\bak&lt;br&gt;C:\Program Files\DellSupport\bak&lt;br&gt;C:\Program Files\iTunes\bak&lt;br&gt;C:\Program Files\QuickTime\bak&lt;br&gt;C:\Program Files\REGSHAVE\bak&lt;br&gt;C:\WINDOWS\SYSTEM32\bak&lt;br&gt;C:\Program Files\Dell\Media Experience\bak&lt;br&gt;C:\Program Files\Intel\Modem Event Monitor\bak&lt;br&gt;C:\Program Files\Real\RealPlayer\bak&lt;br&gt;C:\Program Files\Yahoo!\Search Protection\bak&lt;br&gt;C:\WINDOWS\SYSTEM32\dla\bak&lt;br&gt;C:\Program Files\Adobe\Reader 8.0\Reader\bak&lt;br&gt;C:\Program Files\Common Files\InstallShield\UpdateService\bak&lt;br&gt;C:\Program Files\Common Files\Sonic\Update Manager\bak&lt;br&gt;C:\Program Files\Creative\SBLive\Diagnostics\bak&lt;br&gt;C:\Program Files\Java\j2re1.4.2_03\bin\bak&lt;br&gt;C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\bak&lt;br&gt;C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\bak&lt;br&gt;C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\bak[/quote]&lt;br&gt;Return to OTMoveIt, right click on the "[b]Paste List of Files/Folders to Move[/b]" window under the [b]"yellow"[/b] bar,and choose [b]Paste[/b],see image below:&lt;br&gt;&lt;br&gt;[IMG]http://img.photobucket.com/albums/v624/29wood/Clipboard01-3.png[/IMG]&lt;br&gt;&lt;br&gt;Click on the Moveit! button [IMG]http://img.photobucket.com/albums/v624/29wood/Clipboard01moveit.gif[/IMG]&lt;br&gt;[b]Copy everything on the 'Results' window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose 'Copy'), and paste it into your next reply.[/b]&lt;br&gt;Close OTMoveIt by clicking on the "Exit" button.&lt;br&gt;If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. &lt;br&gt;If you are asked to reboot the machine choose [b]Yes[/b].&lt;br&gt;&lt;br&gt;[b]Also post a new Hijackthis log please.[/b]</description><pubDate>Tue, 13 May 2008 17:42:27 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: White X in a Red Circle in my System Tray</title><link>http://forum.tweaks.com/forum/Topic239390-29-1.aspx</link><description> Find AWF report by noahdfear ©2006&lt;BR&gt;               Version 1.40&lt;BR&gt;Option 2 run successfully&lt;/P&gt;&lt;P&gt;The current date is: Tue 05/13/2008 &lt;BR&gt;The current time is: 18:28:33.64&lt;/P&gt;&lt;P&gt;&lt;BR&gt;  bak folders found&lt;BR&gt;  ~~~~~~~~~~~&lt;/P&gt;&lt;P&gt;&lt;BR&gt; Directory of C:\WINDOWS\BAK&lt;/P&gt;&lt;P&gt;05/11/2000  02:00 AM            90,112 UpdReg.EXE&lt;BR&gt;               1 File(s)         90,112 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\AIM6\BAK&lt;/P&gt;&lt;P&gt;11/07/2006  11:29 AM            50,736 aim6.exe&lt;BR&gt;               1 File(s)         50,736 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\DELLSU~1\BAK&lt;/P&gt;&lt;P&gt;03/15/2007  11:09 AM           460,784 DSAgnt.exe&lt;BR&gt;               1 File(s)        460,784 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\ITUNES\BAK&lt;/P&gt;&lt;P&gt;11/02/2007  07:36 PM           267,048 iTunesHelper.exe&lt;BR&gt;               1 File(s)        267,048 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\QUICKT~1\BAK&lt;/P&gt;&lt;P&gt;10/19/2007  09:16 PM           286,720 qttask.exe&lt;BR&gt;               1 File(s)        286,720 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\REGSHAVE\BAK&lt;/P&gt;&lt;P&gt;02/04/2002  11:32 PM            53,248 REGSHAVE.EXE&lt;BR&gt;               1 File(s)         53,248 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\WINDOWS\SYSTEM32\BAK&lt;/P&gt;&lt;P&gt;08/04/2004  03:56 AM            15,360 ctfmon.exe&lt;BR&gt;06/22/2005  12:44 AM           126,976 hkcmd.exe&lt;BR&gt;06/22/2005  12:48 AM           155,648 igfxtray.exe&lt;BR&gt;               3 File(s)        297,984 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\COMMON~1\SYMANT~1\BAK&lt;/P&gt;&lt;P&gt;               0 File(s)              0 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\DELL\MEDIAE~1\BAK&lt;/P&gt;&lt;P&gt;04/11/2004  09:15 PM           290,816 PCMService.exe&lt;BR&gt;               1 File(s)        290,816 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\INTEL\MODEME~1\BAK&lt;/P&gt;&lt;P&gt;09/03/2003  09:12 PM           221,184 IntelMEM.exe&lt;BR&gt;               1 File(s)        221,184 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\REAL\REALPL~1\BAK&lt;/P&gt;&lt;P&gt;08/10/2004  10:01 AM            26,112 RealPlay.exe&lt;BR&gt;               1 File(s)         26,112 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\YAHOO!\SEARCH~1\BAK&lt;/P&gt;&lt;P&gt;06/08/2007  10:59 AM           224,248 SearchProtection.exe&lt;BR&gt;               1 File(s)        224,248 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\WINDOWS\SYSTEM32\DLA\BAK&lt;/P&gt;&lt;P&gt;03/15/2004  02:04 AM           122,933 tfswctrl.exe&lt;BR&gt;               1 File(s)        122,933 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\ADOBE\READER~1.0\READER\BAK&lt;/P&gt;&lt;P&gt;10/10/2007  07:51 PM            39,792 Reader_sl.exe&lt;BR&gt;               1 File(s)         39,792 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\BAK&lt;/P&gt;&lt;P&gt;06/16/2004  06:03 AM            81,920 issch.exe&lt;BR&gt;06/16/2004  07:03 AM           221,184 ISUSPM.exe&lt;BR&gt;               2 File(s)        303,104 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\BAK&lt;/P&gt;&lt;P&gt;08/19/2003  02:01 AM           110,592 sgtray.exe&lt;BR&gt;               1 File(s)        110,592 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\CREATIVE\SBLIVE\DIAGNO~1\BAK&lt;/P&gt;&lt;P&gt;04/03/2002  02:01 AM           135,264 diagent.exe&lt;BR&gt;               1 File(s)        135,264 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\JAVA\J2RE14~1.2_0\BIN\BAK&lt;/P&gt;&lt;P&gt;11/19/2003  06:48 PM            32,881 jusched.exe&lt;BR&gt;               1 File(s)         32,881 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\DOCUME~1\ALLUSE~1\APPLIC~1\DELL\TRANSF~1\BAK&lt;/P&gt;&lt;P&gt;11/13/2007  05:46 PM           135,168 TransferAgent.exe&lt;BR&gt;               1 File(s)        135,168 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\ADOBE\PHOTOS~1\3.2\APPS\BAK&lt;/P&gt;&lt;P&gt;03/09/2007  11:09 AM            63,712 apdproxy.exe&lt;BR&gt;               1 File(s)         63,712 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK&lt;/P&gt;&lt;P&gt;03/04/2004  11:46 AM           172,032 hpztsb10.exe&lt;BR&gt;               1 File(s)        172,032 bytes&lt;/P&gt;&lt;P&gt;&lt;BR&gt;  Duplicate files of bak directory contents&lt;BR&gt;  ~~~~~~~~~~~~~~~~~~~~~~~&lt;/P&gt;&lt;P&gt;     90112 May 11 2000 "C:\WINDOWS\UpdReg.EXE"&lt;BR&gt;     90112 May 11 2000 "C:\WINDOWS\bak\UpdReg.EXE"&lt;BR&gt;     50528 Jan  3 2008 "C:\Program Files\AIM6\aim6.exe"&lt;BR&gt;     50736 Nov  7 2006 "C:\Program Files\AIM6\bak\aim6.exe"&lt;BR&gt;    460784 Mar 15 2007 "C:\Program Files\DellSupport\DSAgnt.exe"&lt;BR&gt;    460784 Mar 15 2007 "C:\Program Files\DellSupport\bak\DSAgnt.exe"&lt;BR&gt;    267048 Nov  2 2007 "C:\Program Files\iTunes\iTunesHelper.exe"&lt;BR&gt;    267048 Nov  2 2007 "C:\Program Files\iTunes\bak\iTunesHelper.exe"&lt;BR&gt;    102400 Mar  6 2008 "C:\WINDOWS\Installer\{E3FEE4E7-4488-4A3F-A6BD-13745936EADB}\iTunesIco.exe"&lt;BR&gt;    116008 Nov  2 2007 "C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.5.0.20\iTunesSetupAdmin.exe"&lt;BR&gt;    286720 Oct 19 2007 "C:\Program Files\QuickTime\qttask.exe"&lt;BR&gt;    286720 Oct 19 2007 "C:\Program Files\QuickTime\bak\qttask.exe"&lt;BR&gt;     53248 Feb  4 2002 "C:\Program Files\REGSHAVE\REGSHAVE.EXE"&lt;BR&gt;     53248 Feb  4 2002 "C:\Program Files\REGSHAVE\bak\REGSHAVE.EXE"&lt;BR&gt;     15360 Aug  4 2004 "C:\WINDOWS\SYSTEM32\ctfmon.exe"&lt;BR&gt;     15360 Aug  4 2004 "C:\WINDOWS\SYSTEM32\bak\ctfmon.exe"&lt;BR&gt;    118784 Feb 10 2004 "C:\DRIVERS\VIDEO\HKCMD.EXE"&lt;BR&gt;    126976 Jun 22 2005 "C:\DRIVERS\R106456\Win2000\hkcmd.exe"&lt;BR&gt;    126976 Jun 22 2005 "C:\WINDOWS\SYSTEM32\bak\hkcmd.exe"&lt;BR&gt;    126976 Jan 23 2005 "C:\WINDOWS\SYSTEM32\ReinstallBackups\0000\DriverFiles\hkcmd.exe"&lt;BR&gt;    155648 Feb 10 2004 "C:\DRIVERS\VIDEO\IGFXTRAY.EXE"&lt;BR&gt;    155648 Jun 22 2005 "C:\WINDOWS\SYSTEM32\igfxtray.exe"&lt;BR&gt;    155648 Jun 22 2005 "C:\DRIVERS\R106456\Win2000\igfxtray.exe"&lt;BR&gt;    155648 Jun 22 2005 "C:\WINDOWS\SYSTEM32\bak\igfxtray.exe"&lt;BR&gt;    155648 Jan 23 2005 "C:\WINDOWS\SYSTEM32\ReinstallBackups\0000\DriverFiles\igfxtray.exe"&lt;BR&gt;    290816 Apr 11 2004 "C:\Program Files\Dell\Media Experience\PCMService.exe"&lt;BR&gt;    290816 Apr 11 2004 "C:\Program Files\Dell\Media Experience\bak\PCMService.exe"&lt;BR&gt;    221184 Sep  3 2003 "C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe"&lt;BR&gt;    221184 Sep  3 2003 "C:\Program Files\Intel\Modem Event Monitor\bak\IntelMEM.exe"&lt;BR&gt;     26112 Aug 10 2004 "C:\Program Files\Real\RealPlayer\RealPlay.exe"&lt;BR&gt;     26112 Aug 10 2004 "C:\Program Files\Real\RealPlayer\bak\RealPlay.exe"&lt;BR&gt;    224248 Jun  8 2007 "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"&lt;BR&gt;    224248 Jun  8 2007 "C:\Program Files\Yahoo!\Search Protection\bak\SearchProtection.exe"&lt;BR&gt;    122933 Mar 15 2004 "C:\Program Files\Sonic\DLA\install\tfswctrl.exe"&lt;BR&gt;    122933 Mar 15 2004 "C:\WINDOWS\SYSTEM32\dla\bak\tfswctrl.exe"&lt;BR&gt;     39792 Jan 11 2008 "C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe"&lt;BR&gt;     39792 Oct 10 2007 "C:\Program Files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe"&lt;BR&gt;     81920 Jun 16 2004 "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe"&lt;BR&gt;     81920 Jun 16 2004 "C:\Program Files\Common Files\InstallShield\UpdateService\bak\issch.exe"&lt;BR&gt;    221184 Jun 16 2004 "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe"&lt;BR&gt;    221184 Jun 16 2004 "C:\Program Files\Common Files\InstallShield\UpdateService\bak\ISUSPM.exe"&lt;BR&gt;    110592 Aug 19 2003 "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe"&lt;BR&gt;    110592 Aug 19 2003 "C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe"&lt;BR&gt;    135264 Apr  3 2002 "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe"&lt;BR&gt;    135264 Apr  3 2002 "C:\Program Files\Creative\SBLive\Diagnostics\bak\diagent.exe"&lt;BR&gt;     32881 Nov 19 2003 "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe"&lt;BR&gt;     32881 Nov 19 2003 "C:\Program Files\Java\j2re1.4.2_03\bin\bak\jusched.exe"&lt;BR&gt;    135168 Nov 13 2007 "C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe"&lt;BR&gt;    135168 Nov 13 2007 "C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\bak\TransferAgent.exe"&lt;BR&gt;    327437 Jan 27 2008 "C:\Documents and Settings\Derek O'Connor\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u4\CIP\TransferAgentSetup.exe"&lt;BR&gt;     63712 Mar  9 2007 "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"&lt;BR&gt;     63712 Mar  9 2007 "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\bak\apdproxy.exe"&lt;BR&gt;    172032 Mar  4 2004 "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb10.exe"&lt;BR&gt;    172032 Mar  4 2004 "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\bak\hpztsb10.exe"&lt;/P&gt;&lt;P&gt;&lt;BR&gt;  end of report&lt;BR&gt;</description><pubDate>Tue, 13 May 2008 17:31:23 GMT</pubDate><dc:creator>sundancekid726</dc:creator></item><item><title>RE: White X in a Red Circle in my System Tray</title><link>http://forum.tweaks.com/forum/Topic239390-29-1.aspx</link><description>Double-click [b]FindAWF.exe[/b] to start the tool. &lt;br&gt;Select option [b]#2[/b] - [b]Restore files from bak folders[/b] by typing [b]2[/b] and press 'Enter' &lt;br&gt;A text file will open up. &lt;br&gt;Please copy and paste [b]ALL[/b] the following text inside the code box below into the text file:&lt;br&gt;&lt;br&gt;[quote]"C:\WINDOWS\bak\UpdReg.EXE"&lt;br&gt;"C:\Program Files\DellSupport\bak\DSAgnt.exe"&lt;br&gt;"C:\Program Files\QuickTime\bak\qttask.exe"&lt;br&gt;"C:\Program Files\REGSHAVE\bak\REGSHAVE.EXE"&lt;br&gt;"C:\WINDOWS\SYSTEM32\bak\igfxtray.exe"&lt;br&gt;"C:\Program Files\Dell\Media Experience\bak\PCMService.exe"&lt;br&gt;"C:\Program Files\Intel\Modem Event Monitor\bak\IntelMEM.exe"&lt;br&gt;"C:\Program Files\Real\RealPlayer\bak\RealPlay.exe"&lt;br&gt;"C:\Program Files\Yahoo!\Search Protection\bak\SearchProtection.exe"&lt;br&gt;"C:\Program Files\Common Files\InstallShield\UpdateService\bak\issch.exe"&lt;br&gt;"C:\Program Files\Common Files\InstallShield\UpdateService\bak\ISUSPM.exe"&lt;br&gt;"C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe"&lt;br&gt;"C:\Program Files\Creative\SBLive\Diagnostics\bak\diagent.exe"&lt;br&gt;"C:\Program Files\Java\j2re1.4.2_03\bin\bak\jusched.exe"&lt;br&gt;"C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\bak\TransferAgent.exe"&lt;br&gt;"C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\bak\apdproxy.exe"&lt;br&gt;"C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\bak\hpztsb10.exe"[/quote]&lt;br&gt;Close the files.txt and click Yes to save the changes. &lt;br&gt;FindAWF will now terminate the bad processes if running, delete the bad files and restore/replace them with the good files. &lt;br&gt;Then it will open a log. &lt;br&gt;[b]Copy and paste the contents of that log in your next reply.[/b]</description><pubDate>Tue, 13 May 2008 17:24:25 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: White X in a Red Circle in my System Tray</title><link>http://forum.tweaks.com/forum/Topic239390-29-1.aspx</link><description> Find AWF report by noahdfear ©2006&lt;BR&gt;               Version 1.40&lt;/P&gt;&lt;P&gt;The current date is: Tue 05/13/2008 &lt;BR&gt;The current time is: 18:07:57.17&lt;/P&gt;&lt;P&gt;&lt;BR&gt;  bak folders found&lt;BR&gt;  ~~~~~~~~~~~&lt;/P&gt;&lt;P&gt;&lt;BR&gt; Directory of C:\WINDOWS\BAK&lt;/P&gt;&lt;P&gt;05/11/2000  02:00 AM            90,112 UpdReg.EXE&lt;BR&gt;               1 File(s)         90,112 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\AIM6\BAK&lt;/P&gt;&lt;P&gt;11/07/2006  11:29 AM            50,736 aim6.exe&lt;BR&gt;               1 File(s)         50,736 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\DELLSU~1\BAK&lt;/P&gt;&lt;P&gt;03/15/2007  11:09 AM           460,784 DSAgnt.exe&lt;BR&gt;               1 File(s)        460,784 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\ITUNES\BAK&lt;/P&gt;&lt;P&gt;11/02/2007  07:36 PM           267,048 iTunesHelper.exe&lt;BR&gt;               1 File(s)        267,048 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\QUICKT~1\BAK&lt;/P&gt;&lt;P&gt;10/19/2007  09:16 PM           286,720 qttask.exe&lt;BR&gt;               1 File(s)        286,720 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\REGSHAVE\BAK&lt;/P&gt;&lt;P&gt;02/04/2002  11:32 PM            53,248 REGSHAVE.EXE&lt;BR&gt;               1 File(s)         53,248 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\WINDOWS\SYSTEM32\BAK&lt;/P&gt;&lt;P&gt;08/04/2004  03:56 AM            15,360 ctfmon.exe&lt;BR&gt;06/22/2005  12:44 AM           126,976 hkcmd.exe&lt;BR&gt;06/22/2005  12:48 AM           155,648 igfxtray.exe&lt;BR&gt;               3 File(s)        297,984 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\COMMON~1\SYMANT~1\BAK&lt;/P&gt;&lt;P&gt;               0 File(s)              0 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\DELL\MEDIAE~1\BAK&lt;/P&gt;&lt;P&gt;04/11/2004  09:15 PM           290,816 PCMService.exe&lt;BR&gt;               1 File(s)        290,816 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\INTEL\MODEME~1\BAK&lt;/P&gt;&lt;P&gt;09/03/2003  09:12 PM           221,184 IntelMEM.exe&lt;BR&gt;               1 File(s)        221,184 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\REAL\REALPL~1\BAK&lt;/P&gt;&lt;P&gt;08/10/2004  10:01 AM            26,112 RealPlay.exe&lt;BR&gt;               1 File(s)         26,112 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\YAHOO!\SEARCH~1\BAK&lt;/P&gt;&lt;P&gt;06/08/2007  10:59 AM           224,248 SearchProtection.exe&lt;BR&gt;               1 File(s)        224,248 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\WINDOWS\SYSTEM32\DLA\BAK&lt;/P&gt;&lt;P&gt;03/15/2004  02:04 AM           122,933 tfswctrl.exe&lt;BR&gt;               1 File(s)        122,933 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\ADOBE\READER~1.0\READER\BAK&lt;/P&gt;&lt;P&gt;10/10/2007  07:51 PM            39,792 Reader_sl.exe&lt;BR&gt;               1 File(s)         39,792 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\BAK&lt;/P&gt;&lt;P&gt;06/16/2004  06:03 AM            81,920 issch.exe&lt;BR&gt;06/16/2004  07:03 AM           221,184 ISUSPM.exe&lt;BR&gt;               2 File(s)        303,104 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\BAK&lt;/P&gt;&lt;P&gt;08/19/2003  02:01 AM           110,592 sgtray.exe&lt;BR&gt;               1 File(s)        110,592 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\CREATIVE\SBLIVE\DIAGNO~1\BAK&lt;/P&gt;&lt;P&gt;04/03/2002  02:01 AM           135,264 diagent.exe&lt;BR&gt;               1 File(s)        135,264 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\JAVA\J2RE14~1.2_0\BIN\BAK&lt;/P&gt;&lt;P&gt;11/19/2003  06:48 PM            32,881 jusched.exe&lt;BR&gt;               1 File(s)         32,881 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\DOCUME~1\ALLUSE~1\APPLIC~1\DELL\TRANSF~1\BAK&lt;/P&gt;&lt;P&gt;11/13/2007  05:46 PM           135,168 TransferAgent.exe&lt;BR&gt;               1 File(s)        135,168 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\PROGRA~1\ADOBE\PHOTOS~1\3.2\APPS\BAK&lt;/P&gt;&lt;P&gt;03/09/2007  11:09 AM            63,712 apdproxy.exe&lt;BR&gt;               1 File(s)         63,712 bytes&lt;/P&gt;&lt;P&gt; Directory of C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK&lt;/P&gt;&lt;P&gt;03/04/2004  11:46 AM           172,032 hpztsb10.exe&lt;BR&gt;               1 File(s)        172,032 bytes&lt;/P&gt;&lt;P&gt;&lt;BR&gt;  Duplicate files of bak directory contents&lt;BR&gt;  ~~~~~~~~~~~~~~~~~~~~~~~&lt;/P&gt;&lt;P&gt;     90112 May 11 2000 "C:\WINDOWS\bak\UpdReg.EXE"&lt;BR&gt;     50528 Jan  3 2008 "C:\Program Files\AIM6\aim6.exe"&lt;BR&gt;     50736 Nov  7 2006 "C:\Program Files\AIM6\bak\aim6.exe"&lt;BR&gt;    460784 Mar 15 2007 "C:\Program Files\DellSupport\bak\DSAgnt.exe"&lt;BR&gt;    267048 Nov  2 2007 "C:\Program Files\iTunes\iTunesHelper.exe"&lt;BR&gt;    267048 Nov  2 2007 "C:\Program Files\iTunes\bak\iTunesHelper.exe"&lt;BR&gt;    102400 Mar  6 2008 "C:\WINDOWS\Installer\{E3FEE4E7-4488-4A3F-A6BD-13745936EADB}\iTunesIco.exe"&lt;BR&gt;    116008 Nov  2 2007 "C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.5.0.20\iTunesSetupAdmin.exe"&lt;BR&gt;    286720 Oct 19 2007 "C:\Program Files\QuickTime\bak\qttask.exe"&lt;BR&gt;     53248 Feb  4 2002 "C:\Program Files\REGSHAVE\bak\REGSHAVE.EXE"&lt;BR&gt;     15360 Aug  4 2004 "C:\WINDOWS\SYSTEM32\ctfmon.exe"&lt;BR&gt;     15360 Aug  4 2004 "C:\WINDOWS\SYSTEM32\bak\ctfmon.exe"&lt;BR&gt;    118784 Feb 10 2004 "C:\DRIVERS\VIDEO\HKCMD.EXE"&lt;BR&gt;    126976 Jun 22 2005 "C:\DRIVERS\R106456\Win2000\hkcmd.exe"&lt;BR&gt;    126976 Jun 22 2005 "C:\WINDOWS\SYSTEM32\bak\hkcmd.exe"&lt;BR&gt;    126976 Jan 23 2005 "C:\WINDOWS\SYSTEM32\ReinstallBackups\0000\DriverFiles\hkcmd.exe"&lt;BR&gt;    155648 Feb 10 2004 "C:\DRIVERS\VIDEO\IGFXTRAY.EXE"&lt;BR&gt;    155648 Jun 22 2005 "C:\DRIVERS\R106456\Win2000\igfxtray.exe"&lt;BR&gt;    155648 Jun 22 2005 "C:\WINDOWS\SYSTEM32\bak\igfxtray.exe"&lt;BR&gt;    155648 Jan 23 2005 "C:\WINDOWS\SYSTEM32\ReinstallBackups\0000\DriverFiles\igfxtray.exe"&lt;BR&gt;    290816 Apr 11 2004 "C:\Program Files\Dell\Media Experience\bak\PCMService.exe"&lt;BR&gt;    221184 Sep  3 2003 "C:\Program Files\Intel\Modem Event Monitor\bak\IntelMEM.exe"&lt;BR&gt;     26112 Aug 10 2004 "C:\Program Files\Real\RealPlayer\bak\RealPlay.exe"&lt;BR&gt;    224248 Jun  8 2007 "C:\Program Files\Yahoo!\Search Protection\bak\SearchProtection.exe"&lt;BR&gt;    122933 Mar 15 2004 "C:\Program Files\Sonic\DLA\install\tfswctrl.exe"&lt;BR&gt;    122933 Mar 15 2004 "C:\WINDOWS\SYSTEM32\dla\bak\tfswctrl.exe"&lt;BR&gt;     39792 Jan 11 2008 "C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe"&lt;BR&gt;     39792 Oct 10 2007 "C:\Program Files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe"&lt;BR&gt;     81920 Jun 16 2004 "C:\Program Files\Common Files\InstallShield\UpdateService\bak\issch.exe"&lt;BR&gt;    221184 Jun 16 2004 "C:\Program Files\Common Files\InstallShield\UpdateService\bak\ISUSPM.exe"&lt;BR&gt;    110592 Aug 19 2003 "C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe"&lt;BR&gt;    135264 Apr  3 2002 "C:\Program Files\Creative\SBLive\Diagnostics\bak\diagent.exe"&lt;BR&gt;     32881 Nov 19 2003 "C:\Program Files\Java\j2re1.4.2_03\bin\bak\jusched.exe"&lt;BR&gt;    135168 Nov 13 2007 "C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\bak\TransferAgent.exe"&lt;BR&gt;    327437 Jan 27 2008 "C:\Documents and Settings\Derek O'Connor\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u4\CIP\TransferAgentSetup.exe"&lt;BR&gt;     63712 Mar  9 2007 "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\bak\apdproxy.exe"&lt;BR&gt;    172032 Mar  4 2004 "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\bak\hpztsb10.exe"&lt;/P&gt;&lt;P&gt;&lt;BR&gt;  end of report</description><pubDate>Tue, 13 May 2008 17:13:09 GMT</pubDate><dc:creator>sundancekid726</dc:creator></item><item><title>RE: White X in a Red Circle in my System Tray</title><link>http://forum.tweaks.com/forum/Topic239390-29-1.aspx</link><description>Download [b]FindAWF.exe[/b] and save it to your desktop:&lt;br&gt;[url]http://noahdfear.geekstogo.com/FindAWF.exe[/url]&lt;br&gt;Double-click on the FindAWF.exe file to run it.&lt;br&gt;It will open a command prompt and ask you to "Press any key to continue".&lt;br&gt;Press any key and the FindAWF tool will begin scanning your computer for the infected AWF files and the backups the trojan created.&lt;br&gt;It may take a few minutes to complete so be patient.&lt;br&gt;When it is complete, it will open a text file in notepad called AWF.txt which will automatically be saved to your desktop or whatever location you ran the file from.&lt;br&gt;[b]Copy and paste the contents of the AWF.txt file in your next reply.[/b]</description><pubDate>Tue, 13 May 2008 16:54:40 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: White X in a Red Circle in my System Tray</title><link>http://forum.tweaks.com/forum/Topic239390-29-1.aspx</link><description>Here is my latest hijack this log:&lt;BR&gt;&lt;BR&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 5:37:59 PM, on 5/13/2008&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16640)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;BR&gt;C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe&lt;BR&gt;C:\WINDOWS\system32\LEXBCES.EXE&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;BR&gt;C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe&lt;BR&gt;C:\WINDOWS\System32\CTsvcCDA.exe&lt;BR&gt;C:\WINDOWS\System32\MsPMSPSv.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;BR&gt;C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;BR&gt;C:\WINDOWS\system32\lexpps.exe&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe&lt;BR&gt;C:\Program Files\internet explorer\iexplore.exe&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.yahoo.com/"&gt;http://www.yahoo.com/&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = &lt;A href="http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com"&gt;http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com&lt;/A&gt;&lt;BR&gt;R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll&lt;BR&gt;O2 - BHO: &amp;amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll&lt;BR&gt;O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll&lt;BR&gt;O3 - Toolbar: &amp;amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll&lt;BR&gt;O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll&lt;BR&gt;O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe&lt;BR&gt;O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe&lt;BR&gt;O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe&lt;BR&gt;O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup&lt;BR&gt;O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE&lt;BR&gt;O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"&lt;BR&gt;O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe&lt;BR&gt;O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r&lt;BR&gt;O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER&lt;BR&gt;O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup&lt;BR&gt;O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start&lt;BR&gt;O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN&lt;BR&gt;O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe&lt;BR&gt;O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"&lt;BR&gt;O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"&lt;BR&gt;O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime&lt;BR&gt;O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"&lt;BR&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"&lt;BR&gt;O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"&lt;BR&gt;O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"&lt;BR&gt;O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe&lt;BR&gt;O4 - HKCU\..\Run: [DellTransferAgent] "C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe"&lt;BR&gt;O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE&lt;BR&gt;O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)&lt;BR&gt;O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe&lt;BR&gt;O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll&lt;BR&gt;O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - &lt;A href="http://wwws.musicmatch.com/mmz/openWebRadio.html"&gt;http://wwws.musicmatch.com/mmz/openWebRadio.html&lt;/A&gt; (file missing)&lt;BR&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &lt;A href="http://go.microsoft.com/fwlink/?linkid=39204"&gt;http://go.microsoft.com/fwlink/?linkid=39204&lt;/A&gt;&lt;BR&gt;O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - &lt;A href="http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab"&gt;http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - &lt;A href="http://upload.facebook.com/controls/FacebookPhotoUploader3.cab"&gt;http://upload.facebook.com/controls/FacebookPhotoUploader3.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - &lt;A href="http://upload.facebook.com/controls/FacebookPhotoUploader.cab"&gt;http://upload.facebook.com/controls/FacebookPhotoUploader.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - &lt;A href="http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab"&gt;http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - &lt;A href="https://webdl.symantec.com/activex/symdlmgr.cab"&gt;https://webdl.symantec.com/activex/symdlmgr.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &lt;A href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1124836278656"&gt;http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1124836278656&lt;/A&gt;&lt;BR&gt;O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} (Symantec Download Bridge) - &lt;A href="https://a248.e.akamai.net/f/248/5462/2h/www.symantecstore.com/v2.0-img/operations/symbizpr/xcontrol/SymDlBrg.cab"&gt;https://a248.e.akamai.net/f/248/5462/2h/www.symantecstore.com/v2.0-img/operations/symbizpr/xcontrol/SymDlBrg.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &lt;A href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab"&gt;http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - &lt;A href="http://www.shockwave.com/content/bejeweled2/sis/popcaploader_v10.cab"&gt;http://www.shockwave.com/content/bejeweled2/sis/popcaploader_v10.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {FCF289D4-0AC8-4ED8-BE31-E8AF09606AB5} (download_35mb_com.applet) - &lt;A href="http://static.35mb.com/applet/applet_o.cab"&gt;http://static.35mb.com/applet/applet_o.cab&lt;/A&gt;&lt;BR&gt;O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;BR&gt;O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe&lt;BR&gt;O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;BR&gt;O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;BR&gt;O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;BR&gt;O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe&lt;BR&gt;O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe&lt;BR&gt;O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe&lt;BR&gt;O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;BR&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe&lt;BR&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;BR&gt;O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE&lt;BR&gt;O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE&lt;BR&gt;O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;BR&gt;O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe&lt;BR&gt;O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 9663 bytes&lt;BR&gt;&lt;BR&gt;Thanks for the help so far</description><pubDate>Tue, 13 May 2008 16:38:36 GMT</pubDate><dc:creator>sundancekid726</dc:creator></item><item><title>RE: White X in a Red Circle in my System Tray</title><link>http://forum.tweaks.com/forum/Topic239390-29-1.aspx</link><description>ComboFix 08-05-12.1 - Derek O'Connor 2008-05-13 17:12:45.1 - NTFSx86&lt;BR&gt;Running from: C:\Documents and Settings\Derek O'Connor\Desktop\ComboFix.exe&lt;BR&gt; * Created a new restore point&lt;/P&gt;&lt;P&gt;[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;C:\Program Files\WinBudget&lt;BR&gt;C:\WINDOWS\system32\drivers\fad.sys&lt;/P&gt;&lt;P&gt;.&lt;BR&gt;(((((((((((((((((((((((((   Files Created from 2008-04-13 to 2008-05-13  )))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;2008-05-13 16:01 . 2008-05-13 16:02 &amp;lt;DIR&amp;gt; d-------- C:\WINDOWS\ERUNT&lt;BR&gt;2008-05-13 15:54 . 2008-05-13 02:57 &amp;lt;DIR&amp;gt; d-------- C:\SDFix&lt;BR&gt;2008-05-13 15:35 . 2008-05-13 15:35 &amp;lt;DIR&amp;gt; d-------- C:\Deckard&lt;BR&gt;2008-05-13 00:47 . 2008-05-13 00:47 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Trend Micro&lt;BR&gt;2008-05-12 21:01 . 2008-05-12 21:01 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Windows Sidebar&lt;BR&gt;2008-05-12 20:59 . 2008-05-12 21:02 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Norton Internet Security&lt;BR&gt;2008-05-12 20:57 . 2008-05-12 21:02 123,952 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.SYS&lt;BR&gt;2008-05-12 20:57 . 2008-05-12 21:02 60,800 --a------ C:\WINDOWS\SYSTEM32\S32EVNT1.DLL&lt;BR&gt;2008-05-12 20:57 . 2008-05-12 21:02 10,563 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.CAT&lt;BR&gt;2008-05-12 20:57 . 2008-05-12 21:02 805 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.INF&lt;BR&gt;2008-05-12 19:55 . 2008-05-12 19:55 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Symantec Temporary Files&lt;/P&gt;&lt;P&gt;.&lt;BR&gt;((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;BR&gt;2008-05-13 21:19 --------- d-----w C:\Program Files\Common Files\Symantec Shared&lt;BR&gt;2008-05-13 19:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint&lt;BR&gt;2008-05-13 02:58 --------- d-----w C:\Program Files\DivX&lt;BR&gt;2008-05-13 01:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec&lt;BR&gt;2008-05-13 01:05 --------- d-----w C:\Documents and Settings\Derek O'Connor\Application Data\Symantec&lt;BR&gt;2008-05-13 01:02 --------- d-----w C:\Program Files\Symantec&lt;BR&gt;2008-04-11 16:55 --------- d-----w C:\Program Files\Common Files\Adobe&lt;BR&gt;2005-10-13 16:19 13,195 ----a-w C:\Documents and Settings\Derek O'Connor\ZGUICFGW.DAT&lt;BR&gt;2005-08-29 21:33 40 ----a-w C:\Documents and Settings\Derek O'Connor\language.dat&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;(((((((((((((((((((((((((((((((((((((((((((((   AWF   ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;BR&gt;----a-w           135,168 2007-11-13 21:46:00  C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\bak\TransferAgent.exe&lt;/P&gt;&lt;P&gt;----a-w            63,712 2007-03-09 15:09:58  C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\bak\apdproxy.exe&lt;/P&gt;&lt;P&gt;----a-w            39,792 2007-10-10 23:51:55  C:\Program Files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe&lt;BR&gt;----a-w            39,792 2008-01-12 02:16:38  C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe&lt;/P&gt;&lt;P&gt;----a-w            50,736 2006-11-07 15:29:02  C:\Program Files\AIM6\bak\aim6.exe&lt;BR&gt;----a-w            50,528 2008-01-03 16:15:06  C:\Program Files\AIM6\aim6.exe&lt;/P&gt;&lt;P&gt;----a-w            81,920 2004-06-16 10:03:04  C:\Program Files\Common Files\InstallShield\UpdateService\bak\issch.exe&lt;/P&gt;&lt;P&gt;----a-w           221,184 2004-06-16 11:03:26  C:\Program Files\Common Files\InstallShield\UpdateService\bak\ISUSPM.exe&lt;/P&gt;&lt;P&gt;----a-w           110,592 2003-08-19 06:01:00  C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe&lt;/P&gt;&lt;P&gt;----a-w           135,264 2002-04-03 06:01:00  C:\Program Files\Creative\SBLive\Diagnostics\bak\diagent.exe&lt;/P&gt;&lt;P&gt;----a-w           290,816 2004-04-12 01:15:14  C:\Program Files\Dell\Media Experience\bak\PCMService.exe&lt;/P&gt;&lt;P&gt;----a-w           460,784 2007-03-15 15:09:36  C:\Program Files\DellSupport\bak\DSAgnt.exe&lt;/P&gt;&lt;P&gt;----a-w           221,184 2003-09-04 01:12:44  C:\Program Files\Intel\Modem Event Monitor\bak\IntelMEM.exe&lt;/P&gt;&lt;P&gt;----a-w           267,048 2007-11-02 23:36:42  C:\Program Files\iTunes\bak\iTunesHelper.exe&lt;BR&gt;----a-w           267,048 2007-11-02 23:36:42  C:\Program Files\iTunes\iTunesHelper.exe&lt;/P&gt;&lt;P&gt;----a-w            32,881 2003-11-19 22:48:14  C:\Program Files\Java\j2re1.4.2_03\bin\bak\jusched.exe&lt;/P&gt;&lt;P&gt;----a-w           286,720 2007-10-20 01:16:26  C:\Program Files\QuickTime\bak\qttask.exe&lt;/P&gt;&lt;P&gt;----a-w            26,112 2004-08-10 14:01:25  C:\Program Files\Real\RealPlayer\bak\RealPlay.exe&lt;/P&gt;&lt;P&gt;----a-w            53,248 2002-02-05 03:32:10  C:\Program Files\REGSHAVE\bak\REGSHAVE.EXE&lt;/P&gt;&lt;P&gt;----a-w           224,248 2007-06-08 14:59:38  C:\Program Files\Yahoo!\Search Protection\bak\SearchProtection.exe&lt;/P&gt;&lt;P&gt;----a-w            90,112 2000-05-11 06:00:00  C:\WINDOWS\bak\UpdReg.EXE&lt;/P&gt;&lt;P&gt;----a-w            15,360 2004-08-04 07:56:48  C:\WINDOWS\SYSTEM32\bak\ctfmon.exe&lt;BR&gt;----a-w            15,360 2004-08-04 07:56:48  C:\WINDOWS\SYSTEM32\ctfmon.exe&lt;/P&gt;&lt;P&gt;----a-w           126,976 2005-06-22 04:44:34  C:\WINDOWS\SYSTEM32\bak\hkcmd.exe&lt;/P&gt;&lt;P&gt;----a-w           155,648 2005-06-22 04:48:18  C:\WINDOWS\SYSTEM32\bak\igfxtray.exe&lt;/P&gt;&lt;P&gt;----a-w           122,933 2004-03-15 06:04:00  C:\WINDOWS\SYSTEM32\dla\bak\tfswctrl.exe&lt;/P&gt;&lt;P&gt;----a-w           172,032 2004-03-04 15:46:24  C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\bak\hpztsb10.exe&lt;/P&gt;&lt;P&gt;.&lt;BR&gt;(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;BR&gt;.&lt;BR&gt;*Note* empty entries &amp;amp; legit default entries are not shown &lt;BR&gt;REGEDIT4&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]&lt;BR&gt;"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= "C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll" [2008-02-07 00:05 349552]&lt;/P&gt;&lt;P&gt;[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]&lt;BR&gt;[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]&lt;BR&gt;[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]&lt;/P&gt;&lt;P&gt;[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]&lt;BR&gt;"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll [2008-02-07 00:05 349552]&lt;/P&gt;&lt;P&gt;[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]&lt;BR&gt;[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]&lt;BR&gt;[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]&lt;/P&gt;&lt;P&gt;[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [ ]&lt;BR&gt;"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56 15360]&lt;BR&gt;"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [ ]&lt;BR&gt;"Aim6"="" []&lt;BR&gt;"DellTransferAgent"="C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe" [ ]&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [ ]&lt;BR&gt;"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [ ]&lt;BR&gt;"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [ ]&lt;BR&gt;"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [ ]&lt;BR&gt;"diagent"="C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" [ ]&lt;BR&gt;"UpdReg"="C:\WINDOWS\UpdReg.EXE" [ ]&lt;BR&gt;"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [ ]&lt;BR&gt;"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [ ]&lt;BR&gt;"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [ ]&lt;BR&gt;"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [ ]&lt;BR&gt;"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [ ]&lt;BR&gt;"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [ ]&lt;BR&gt;"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [ ]&lt;BR&gt;"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [ ]&lt;BR&gt;"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [ ]&lt;BR&gt;"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [ ]&lt;BR&gt;"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [ ]&lt;BR&gt;"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 19:36 267048]&lt;BR&gt;"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]&lt;BR&gt;"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-01-25 21:47 51048]&lt;BR&gt;"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2008-02-07 02:49 718704]&lt;/P&gt;&lt;P&gt;C:\Documents and Settings\All Users\Start Menu\Programs\Startup\&lt;BR&gt;Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-09-04 18:23:00 65588]&lt;BR&gt;Microsoft Works Calendar Reminders.lnk - C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [1999-09-04 18:23:00 53317]&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]&lt;BR&gt;"msacm.ctmp3"= C:\WINDOWS\System32\ctmp3.acm&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]&lt;BR&gt;"DisableMonitoring"=dword:00000001&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]&lt;BR&gt;"DisableMonitoring"=dword:00000001&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]&lt;BR&gt;"DisableMonitoring"=dword:00000001&lt;/P&gt;&lt;P&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]&lt;BR&gt;"EnableFirewall"= 0 (0x0)&lt;/P&gt;&lt;P&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]&lt;BR&gt;"%windir%\\system32\\sessmgr.exe"=&lt;BR&gt;"C:\\Program Files\\AIM\\aim.exe"=&lt;BR&gt;"%windir%\\Network Diagnostic\\xpnetdiag.exe"=&lt;BR&gt;"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=&lt;BR&gt;"C:\\Program Files\\iTunes\\iTunes.exe"=&lt;/P&gt;&lt;P&gt;R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon []&lt;BR&gt;R3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-03-06 21:32]&lt;/P&gt;&lt;P&gt;*Newly Created Service* - COMHOST&lt;BR&gt;.&lt;BR&gt;Contents of the 'Scheduled Tasks' folder&lt;BR&gt;"2008-05-13 01:20:41 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Derek O'Connor.job"&lt;BR&gt;- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeh/TASK:&lt;BR&gt;.&lt;BR&gt;**************************************************************************&lt;/P&gt;&lt;P&gt;catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &lt;A href="http://www.gmer.net"&gt;http://www.gmer.net&lt;/A&gt;&lt;BR&gt;Rootkit scan 2008-05-13 17:20:54&lt;BR&gt;Windows 5.1.2600 Service Pack 2 NTFS&lt;/P&gt;&lt;P&gt;scanning hidden processes ... &lt;/P&gt;&lt;P&gt;scanning hidden autostart entries ...&lt;/P&gt;&lt;P&gt;scanning hidden files ... &lt;/P&gt;&lt;P&gt;scan completed successfully&lt;BR&gt;hidden files: 0&lt;/P&gt;&lt;P&gt;**************************************************************************&lt;BR&gt;.&lt;BR&gt;Completion time: 2008-05-13 17:28:56&lt;BR&gt;ComboFix-quarantined-files.txt  2008-05-13 21:28:51&lt;/P&gt;&lt;P&gt;Pre-Run: 4,402,397,184 bytes free&lt;BR&gt;Post-Run: 4,514,127,872 bytes free&lt;/P&gt;&lt;P&gt;151 --- E O F --- 2008-04-10 00:53:59</description><pubDate>Tue, 13 May 2008 16:37:12 GMT</pubDate><dc:creator>sundancekid726</dc:creator></item><item><title>RE: White X in a Red Circle in my System Tray</title><link>http://forum.tweaks.com/forum/Topic239390-29-1.aspx</link><description>Could you follow the Combofix instructions please.</description><pubDate>Tue, 13 May 2008 15:52:09 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: White X in a Red Circle in my System Tray</title><link>http://forum.tweaks.com/forum/Topic239390-29-1.aspx</link><description>And here is my new hijack this log:&lt;BR&gt;&lt;BR&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 4:49:18 PM, on 5/13/2008&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16640)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe&lt;BR&gt;C:\WINDOWS\system32\LEXBCES.EXE&lt;BR&gt;C:\WINDOWS\system32\LEXPPS.EXE&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;BR&gt;C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe&lt;BR&gt;C:\WINDOWS\System32\CTsvcCDA.exe&lt;BR&gt;C:\WINDOWS\System32\MsPMSPSv.exe&lt;BR&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;BR&gt;C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe&lt;BR&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;BR&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.yahoo.com/"&gt;http://www.yahoo.com/&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = &lt;A href="http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com"&gt;http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com&lt;/A&gt;&lt;BR&gt;R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll&lt;BR&gt;O2 - BHO: &amp;amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll&lt;BR&gt;O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll&lt;BR&gt;O3 - Toolbar: &amp;amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll&lt;BR&gt;O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll&lt;BR&gt;O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe&lt;BR&gt;O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe&lt;BR&gt;O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe&lt;BR&gt;O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup&lt;BR&gt;O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE&lt;BR&gt;O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"&lt;BR&gt;O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe&lt;BR&gt;O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r&lt;BR&gt;O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER&lt;BR&gt;O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup&lt;BR&gt;O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start&lt;BR&gt;O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN&lt;BR&gt;O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe&lt;BR&gt;O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"&lt;BR&gt;O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"&lt;BR&gt;O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime&lt;BR&gt;O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"&lt;BR&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"&lt;BR&gt;O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"&lt;BR&gt;O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"&lt;BR&gt;O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe&lt;BR&gt;O4 - HKCU\..\Run: [DellTransferAgent] "C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe"&lt;BR&gt;O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE&lt;BR&gt;O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)&lt;BR&gt;O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe&lt;BR&gt;O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll&lt;BR&gt;O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - &lt;A href="http://wwws.musicmatch.com/mmz/openWebRadio.html"&gt;http://wwws.musicmatch.com/mmz/openWebRadio.html&lt;/A&gt; (file missing)&lt;BR&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &lt;A href="http://go.microsoft.com/fwlink/?linkid=39204"&gt;http://go.microsoft.com/fwlink/?linkid=39204&lt;/A&gt;&lt;BR&gt;O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - &lt;A href="http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab"&gt;http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - &lt;A href="http://upload.facebook.com/controls/FacebookPhotoUploader3.cab"&gt;http://upload.facebook.com/controls/FacebookPhotoUploader3.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - &lt;A href="http://upload.facebook.com/controls/FacebookPhotoUploader.cab"&gt;http://upload.facebook.com/controls/FacebookPhotoUploader.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - &lt;A href="http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab"&gt;http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - &lt;A href="https://webdl.symantec.com/activex/symdlmgr.cab"&gt;https://webdl.symantec.com/activex/symdlmgr.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &lt;A href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1124836278656"&gt;http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1124836278656&lt;/A&gt;&lt;BR&gt;O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} (Symantec Download Bridge) - &lt;A href="https://a248.e.akamai.net/f/248/5462/2h/www.symantecstore.com/v2.0-img/operations/symbizpr/xcontrol/SymDlBrg.cab"&gt;https://a248.e.akamai.net/f/248/5462/2h/www.symantecstore.com/v2.0-img/operations/symbizpr/xcontrol/SymDlBrg.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &lt;A href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab"&gt;http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - &lt;A href="http://www.shockwave.com/content/bejeweled2/sis/popcaploader_v10.cab"&gt;http://www.shockwave.com/content/bejeweled2/sis/popcaploader_v10.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {FCF289D4-0AC8-4ED8-BE31-E8AF09606AB5} (download_35mb_com.applet) - &lt;A href="http://static.35mb.com/applet/applet_o.cab"&gt;http://static.35mb.com/applet/applet_o.cab&lt;/A&gt;&lt;BR&gt;O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;BR&gt;O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe&lt;BR&gt;O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;BR&gt;O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;BR&gt;O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;BR&gt;O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe&lt;BR&gt;O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe&lt;BR&gt;O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe&lt;BR&gt;O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;BR&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe&lt;BR&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;BR&gt;O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE&lt;BR&gt;O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE&lt;BR&gt;O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;BR&gt;O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe&lt;BR&gt;O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 9432 bytes&lt;BR&gt;</description><pubDate>Tue, 13 May 2008 15:49:41 GMT</pubDate><dc:creator>sundancekid726</dc:creator></item></channel></rss>