﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Tweaks.com Forum  / Windows &amp; System Security / HiJack This Logs  / IE and MSN warnings about trying to log key strokes / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>Tweaks.com Forum </description><link>http://forum.tweaks.com/forum/</link><webMaster>forum@tweaks.com</webMaster><lastBuildDate>Sat, 06 Sep 2008 11:45:31 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: IE and MSN warnings about trying to log key strokes</title><link>http://forum.tweaks.com/forum/Topic239438-29-1.aspx</link><description>You're welcome:)</description><pubDate>Thu, 15 May 2008 15:25:28 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: IE and MSN warnings about trying to log key strokes</title><link>http://forum.tweaks.com/forum/Topic239438-29-1.aspx</link><description>Awesome, thanks for your help! :D</description><pubDate>Thu, 15 May 2008 11:19:59 GMT</pubDate><dc:creator>rocknrolldan</dc:creator></item><item><title>RE: IE and MSN warnings about trying to log key strokes</title><link>http://forum.tweaks.com/forum/Topic239438-29-1.aspx</link><description>Your log is clean:),please do the following:&lt;br&gt;&lt;br&gt;Click on Start/Run,copy and paste [b]ComboFix /u[/b] into the 'Open:' space,then press Ok.&lt;br&gt;This will uninstall Combofix,delete its related folders and files,reset your clock settings,hide file extensions,hide the system/hidden files and resets System Restore.&lt;br&gt;&lt;br&gt;[IMG]http://img.photobucket.com/albums/v624/29wood/comu.gif[/IMG]&lt;br&gt;&lt;br&gt;&lt;br&gt;You should take the time to read and follow the information found in the links below,to help you prevent any possible future infections and stay safe and secure while online:&lt;br&gt;&lt;br&gt;[b][color="blue"]Simple and easy ways to keep your computer safe and secure on the Internet[/color][/b]:&lt;br&gt;[url]http://www.bleepingcomputer.com/tutorials/tutorial82.html[/url]&lt;br&gt;&lt;br&gt;[b][color="blue"]How to prevent Malware[/color][/b]:&lt;br&gt;[url]http://users.telenet.be/bluepatchy/miekiemoes/prevention.html[/url]&lt;br&gt;&lt;br&gt;[B][color="blue"]So how did I get infected in the first place[/color][/B]:&lt;br&gt;[URL]http://forums.spybot.info/showthread.php?t=279[/URL]&lt;br&gt;&lt;br&gt;[B][color="blue"]Malware Cleanup Programs and Preventative Procedures[/color][/B]: &lt;br&gt;[URL]http://russelltexas.com/malware/allclear.htm[/URL]&lt;br&gt;&lt;br&gt;[b][color="blue"]Hardening Windows Security - Part 1[/color][/b]:&lt;br&gt;[url]http://www.malwarehelp.org/Malware-Prevention-Hardening-Windows-Security1.html[/url]&lt;br&gt;&lt;br&gt;[b][color="blue"]Hardening Windows Security - Part 2[/color][/b]:&lt;br&gt;[url]http://www.malwarehelp.org/malware-prevention-hardening-windows-security2.html[/url]</description><pubDate>Thu, 15 May 2008 10:41:37 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: IE and MSN warnings about trying to log key strokes</title><link>http://forum.tweaks.com/forum/Topic239438-29-1.aspx</link><description>Ok i restarted and it solved the problem with the error message i was talking about above. so managed to do a HJthis scan and here are the results:&lt;br&gt;&lt;br&gt;Logfile of HijackThis v1.99.1&lt;br&gt;Scan saved at 11:36:46 PM, on 15/05/2008&lt;br&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16640)&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\WINDOWS\System32\smss.exe&lt;br&gt;C:\WINDOWS\system32\winlogon.exe&lt;br&gt;C:\WINDOWS\system32\services.exe&lt;br&gt;C:\WINDOWS\system32\lsass.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\WINDOWS\system32\ZoneLabs\vsmon.exe&lt;br&gt;C:\WINDOWS\Explorer.EXE&lt;br&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br&gt;C:\WINDOWS\system32\acs.exe&lt;br&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;br&gt;C:\WINDOWS\system32\nvsvc32.exe&lt;br&gt;C:\Program Files\CyberLink\Shared files\RichVideo.exe&lt;br&gt;C:\WINDOWS\system32\STacSV.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgam.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgrsx.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgnsx.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgemc.exe&lt;br&gt;C:\WINDOWS\sttray.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\Program Files\TP-LINK\TWCU\TWCU.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgtray.exe&lt;br&gt;C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe&lt;br&gt;C:\WINDOWS\system32\wuauclt.exe&lt;br&gt;C:\Program Files\QuickTime\QTTask.exe&lt;br&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;br&gt;C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe&lt;br&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe&lt;br&gt;C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe&lt;br&gt;C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe&lt;br&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;br&gt;C:\Program Files\Mozilla Firefox\firefox.exe&lt;br&gt;C:\Program Files\Hijackthis\HijackThis.exe&lt;br&gt;C:\WINDOWS\system32\CF30857.exe&lt;br&gt;C:\WINDOWS\system32\cscript.exe&lt;br&gt;&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;br&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;br&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br&gt;O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll&lt;br&gt;O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;br&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;br&gt;O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe&lt;br&gt;O4 - HKLM\..\Run: [nwiz] nwiz.exe /install&lt;br&gt;O4 - HKLM\..\Run: [TWCU] "C:\Program Files\TP-LINK\TWCU\TWCU.exe" -nogui&lt;br&gt;O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup&lt;br&gt;O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe&lt;br&gt;O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"&lt;br&gt;O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime&lt;br&gt;O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"&lt;br&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"&lt;br&gt;O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;O4 - Startup: Stardock ObjectDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe&lt;br&gt;O4 - Startup: Y'z ToolBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe&lt;br&gt;O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe&lt;br&gt;O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe&lt;br&gt;O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe&lt;br&gt;O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000&lt;br&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;br&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL&lt;br&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)&lt;br&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)&lt;br&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll&lt;br&gt;O11 - Options group: [INTERNATIONAL] International*&lt;br&gt;O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab&lt;br&gt;O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab&lt;br&gt;O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab&lt;br&gt;O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll&lt;br&gt;O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL&lt;br&gt;O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL&lt;br&gt;O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL&lt;br&gt;O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll&lt;br&gt;O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll&lt;br&gt;O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll&lt;br&gt;O23 - Service: TP-LINK Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe&lt;br&gt;O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe&lt;br&gt;O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br&gt;O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe&lt;br&gt;O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;br&gt;O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe&lt;br&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br&gt;O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe&lt;br&gt;O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe&lt;br&gt;O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\STacSV.exe&lt;br&gt;O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe&lt;br&gt;&lt;br&gt;</description><pubDate>Thu, 15 May 2008 10:39:28 GMT</pubDate><dc:creator>rocknrolldan</dc:creator></item><item><title>RE: IE and MSN warnings about trying to log key strokes</title><link>http://forum.tweaks.com/forum/Topic239438-29-1.aspx</link><description>Malwarebytes' Anti-Malware 1.12&lt;br&gt;Database version: 752&lt;br&gt;&lt;br&gt;Scan type: Quick Scan&lt;br&gt;Objects scanned: 37651&lt;br&gt;Time elapsed: 5 minute(s), 34 second(s)&lt;br&gt;&lt;br&gt;Memory Processes Infected: 0&lt;br&gt;Memory Modules Infected: 0&lt;br&gt;Registry Keys Infected: 0&lt;br&gt;Registry Values Infected: 0&lt;br&gt;Registry Data Items Infected: 0&lt;br&gt;Folders Infected: 0&lt;br&gt;Files Infected: 0&lt;br&gt;&lt;br&gt;Memory Processes Infected:&lt;br&gt;(No malicious items detected)&lt;br&gt;&lt;br&gt;Memory Modules Infected:&lt;br&gt;(No malicious items detected)&lt;br&gt;&lt;br&gt;Registry Keys Infected:&lt;br&gt;(No malicious items detected)&lt;br&gt;&lt;br&gt;Registry Values Infected:&lt;br&gt;(No malicious items detected)&lt;br&gt;&lt;br&gt;Registry Data Items Infected:&lt;br&gt;(No malicious items detected)&lt;br&gt;&lt;br&gt;Folders Infected:&lt;br&gt;(No malicious items detected)&lt;br&gt;&lt;br&gt;Files Infected:&lt;br&gt;(No malicious items detected)&lt;br&gt;&lt;br&gt;&lt;br&gt;PC is running ok except it wont let me start any new programs. When i click hijack this on the desktop i get an error message saying "windows cannot access the specified device, path or file. You may not have the appropriate permissions to access this item."&lt;br&gt;&lt;br&gt;This is an administrator account so im unsure why it is saying this. It happens for every program not just hijack this....microsoft word and firefox also wont open.</description><pubDate>Thu, 15 May 2008 10:22:58 GMT</pubDate><dc:creator>rocknrolldan</dc:creator></item><item><title>RE: IE and MSN warnings about trying to log key strokes</title><link>http://forum.tweaks.com/forum/Topic239438-29-1.aspx</link><description>[b]You're running filesharing/P2P programs[/b].&lt;br&gt;Many of these programs come bundled with unwanted components/malware.&lt;br&gt;If you wish to find out whether the one you're using does,click [b][url=http://p2p.malwareremoval.com/][color="red"]Here[/color][/url][/b].&lt;br&gt;Even if you are using a so called "safe" program,it's only the program that's safe. &lt;br&gt;You will be sharing files from uncertified sources,and these are often infected. &lt;br&gt;The bad guys use filesharing programs as a major source to spread their wares.&lt;br&gt;I suggest you uninstall it/them now.&lt;br&gt;&lt;br&gt;If you must use P2P/file sharing programs,you should read on:&lt;br&gt;* [b]Don't download files from people you don't trust[/b] -- Just like you shouldn't open e-mail attachments from people you don't trust, you should be wary about downloading files from them as well.&lt;br&gt;* [b]Keep your file-sharing legal[/b] -- Downloading copyrighted music, movies and software using these file-sharing programs without the copyright owner's permission could put you in serious legal trouble. Peer-to-peer users should be aware that they may not be anonymous while using these networks. Copyright holders have located peer-to-peer copyright infringers and have sued them. There are a growing number of online music and movie services where you can stream, download or purchase digital files with the copyright owners' permission. Using these services is one way to ensure that you will avoid unwanted lawsuits.&lt;br&gt;* [b]Watch out for spy-ware[/b] -- Some file-sharing programs embed spy-ware programs when you install them on your computer. These programs can run in the background and create unwanted pop-up advertisements and some even monitor your online behavior.&lt;br&gt;* [b]Use and update your anti-virus software[/b] -- Computer experts are starting to see viruses being spread through file-sharing networks. Be careful what you download and always make sure your anti-virus software is running and frequently updated.&lt;br&gt;* [b]Secure your sensitive computer information[/b] -- If you keep sensitive information on your computer like your tax return information and online bank account data, check to make sure that you are not inadvertently making this available to thousands of strangers on the Internet.&lt;br&gt;* [b]Parents, talk to your kids[/b] -- Parents should be aware that file-sharing networks contain inappropriate audio and video clips -- many of a sexually explicit nature.&lt;br&gt;&lt;br&gt;&lt;br&gt;Please download [b][color="red"]Malwarebytes Anti-Malware[/color][/b]:&lt;br&gt;[url]http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html[/url]&lt;br&gt;[url]http://www.besttechie.net/tools/mbam-setup.exe[/url]&lt;br&gt;&lt;br&gt;Double Click mbam-setup.exe to install the application.&lt;br&gt;(If using Windows Vista,be sure to [b][url=http://windowshelp.microsoft.com/Windows/en-US/Help/fb464905-31d5-4427-89a2-ed5322327fc21033.mspx][color="blue"]"Run As Administrator"[/color][/url][/b]).&lt;br&gt;&lt;br&gt;* Make sure a checkmark is placed next to [b]Update Malwarebytes' Anti-Malware[/b] and [b]Launch Malwarebytes' Anti-Malware[/b], then click Finish.&lt;br&gt;* If an update is found, it will download and install the latest version.&lt;br&gt;* Once the program has loaded, select "Perform Quick Scan", then click Scan.&lt;br&gt;* The scan may take some time to finish,so please be patient.&lt;br&gt;* When the scan is complete, click OK, then Show Results to view the results.&lt;br&gt;* Make sure that everything is checked, and click Remove Selected.&lt;br&gt;* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)&lt;br&gt;* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.&lt;br&gt;* [b]Copy and paste the entire report into your next reply[/b].&lt;br&gt;&lt;br&gt;Extra Note:&lt;br&gt;[b][color="green"]If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.[/color][/b]&lt;br&gt;&lt;br&gt;[b]Also post a new Hijackthis log,let me know how your pc is running now.[/b]</description><pubDate>Thu, 15 May 2008 04:13:47 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: IE and MSN warnings about trying to log key strokes</title><link>http://forum.tweaks.com/forum/Topic239438-29-1.aspx</link><description>[b]ComboFix Log[/b]&lt;br&gt;&lt;br&gt;ComboFix 08-05-12.1 - Dan 2008-05-15 16:39:28.1 - NTFSx86&lt;br&gt;Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1033.18.542 [GMT 8:00]&lt;br&gt;Running from: C:\Documents and Settings\Dan\Desktop\ComboFix.exe&lt;br&gt; * Created a new restore point&lt;br&gt;&lt;br&gt;[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]&lt;br&gt;.&lt;br&gt;&lt;br&gt;(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))&lt;br&gt;.&lt;br&gt;&lt;br&gt;C:\WINDOWS\system32\_000008_.tmp.dll&lt;br&gt;&lt;br&gt;.&lt;br&gt;(((((((((((((((((((((((((   Files Created from 2008-04-15 to 2008-05-15  )))))))))))))))))))))))))))))))&lt;br&gt;.&lt;br&gt;&lt;br&gt;2008-05-15 16:36 . 2008-03-25 02:3769,632--a------C:\WINDOWS\system32\javacpl.cpl&lt;br&gt;2008-05-15 16:35 . 2008-05-15 16:35&lt;DIR&gt;d--------C:\Program Files\Common Files\Java&lt;br&gt;2008-05-06 20:48 . 2008-05-06 20:53&lt;DIR&gt;d--------C:\Downloads&lt;br&gt;2008-05-06 20:48 . 2008-05-06 20:56&lt;DIR&gt;d--------C:\Documents and Settings\Dan\Application Data\Orbit&lt;br&gt;2008-04-17 01:43 . 2008-04-17 01:51&lt;DIR&gt;d--------C:\Program Files\RegCure&lt;br&gt;&lt;br&gt;.&lt;br&gt;((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))&lt;br&gt;.&lt;br&gt;2008-05-15 08:4327,043,872--sha-wC:\WINDOWS\system32\drivers\fidbox.dat&lt;br&gt;2008-05-15 08:36---------d-----wC:\Program Files\Java&lt;br&gt;2008-05-15 08:24316,748--sha-wC:\WINDOWS\system32\drivers\fidbox.idx&lt;br&gt;2008-05-14 14:58---------d-----wC:\Documents and Settings\Dan\Application Data\uTorrent&lt;br&gt;2008-04-27 03:112,629,120----a-wC:\WINDOWS\Internet Logs\xDB1.tmp&lt;br&gt;2008-04-15 06:30---------d-----wC:\Documents and Settings\Dan\Application Data\LimeWire&lt;br&gt;2008-04-14 06:05---------d-----wC:\Program Files\SEPY ActionScript Editor&lt;br&gt;2008-04-14 05:54---------d-----wC:\Program Files\FLV Player&lt;br&gt;2008-04-09 17:48---------d-----wC:\Program Files\iTunes&lt;br&gt;2008-04-09 17:47---------d-----wC:\Program Files\iPod&lt;br&gt;2008-04-09 17:46---------d-----wC:\Program Files\QuickTime&lt;br&gt;2008-04-03 13:02---------d-----wC:\Documents and Settings\Dan\Application Data\EBookSys&lt;br&gt;2008-03-27 08:12151,583----a-wC:\WINDOWS\system32\msjint40.dll&lt;br&gt;2008-03-25 00:52---------d-----wC:\Documents and Settings\Dan\Application Data\Apple Computer&lt;br&gt;2008-03-19 09:471,845,248----a-wC:\WINDOWS\system32\win32k.sys&lt;br&gt;2008-03-19 07:2575,272----a-wC:\WINDOWS\system32\drivers\avgtdix.sys&lt;br&gt;2008-03-12 07:2610,520----a-wC:\WINDOWS\system32\avgrsstx.dll&lt;br&gt;2008-03-06 12:2594,208----a-wC:\WINDOWS\system32\SSW32N50.dll&lt;br&gt;2008-03-01 13:06826,368----a-wC:\WINDOWS\system32\wininet.dll&lt;br&gt;2008-02-20 06:51282,624----a-wC:\WINDOWS\system32\gdi32.dll&lt;br&gt;2008-02-20 05:3245,568----a-wC:\WINDOWS\system32\dnsrslvr.dll&lt;br&gt;.&lt;br&gt;&lt;br&gt;(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))&lt;br&gt;.&lt;br&gt;.&lt;br&gt;*Note* empty entries &amp; legit default entries are not shown &lt;br&gt;REGEDIT4&lt;br&gt;&lt;br&gt;[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;br&gt;"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;br&gt;"SigmatelSysTrayApp"="sttray.exe" [2006-05-26 22:58 282624 C:\WINDOWS\sttray.exe]&lt;br&gt;"nwiz"="nwiz.exe" [2006-10-22 12:22 1622016 C:\WINDOWS\system32\nwiz.exe]&lt;br&gt;"TWCU"="C:\Program Files\TP-LINK\TWCU\TWCU.exe" [2005-08-09 08:42 413696]&lt;br&gt;"NWEReboot"="" []&lt;br&gt;"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22 7700480]&lt;br&gt;"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-03-29 11:49 1177368]&lt;br&gt;"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 15:05 919016]&lt;br&gt;"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]&lt;br&gt;"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]&lt;br&gt;"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]&lt;br&gt;&lt;br&gt;[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]&lt;br&gt;"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:56 15360]&lt;br&gt;&lt;br&gt;[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]&lt;br&gt;"RunNarrator"="Narrator.exe" [2004-08-04 00:56 53760 C:\WINDOWS\system32\narrator.exe]&lt;br&gt;&lt;br&gt;C:\Documents and Settings\Dan\Start Menu\Programs\Startup\&lt;br&gt;Stardock ObjectDock.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe [2005-02-21 21:56:00 1826885]&lt;br&gt;Y'z ToolBar.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe [2002-09-29 21:41:00 90112]&lt;br&gt;&lt;br&gt;C:\Documents and Settings\All Users\Start Menu\Programs\Startup\&lt;br&gt;Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-02-28 18:01:02 113664]&lt;br&gt;Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 00:48:20 40048]&lt;br&gt;Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-22 23:01:50 734872]&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]&lt;br&gt;"DisableMonitoring"=dword:00000001&lt;br&gt;&lt;br&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]&lt;br&gt;"EnableFirewall"= 0 (0x0)&lt;br&gt;&lt;br&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]&lt;br&gt;"%windir%\\Network Diagnostic\\xpnetdiag.exe"=&lt;br&gt;"C:\\Program Files\\uTorrent\\utorrent.exe"=&lt;br&gt;"C:\\Program Files\\LimeWire\\LimeWire.exe"=&lt;br&gt;"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=&lt;br&gt;"C:\\Program Files\\CyberLink\\PowerDirector\\PDR.exe"=&lt;br&gt;"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=&lt;br&gt;"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=&lt;br&gt;"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=&lt;br&gt;"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=&lt;br&gt;"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=&lt;br&gt;"C:\\Program Files\\iTunes\\iTunes.exe"=&lt;br&gt;"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=&lt;br&gt;&lt;br&gt;R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-03-12 15:26]&lt;br&gt;R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-03-01 09:16]&lt;br&gt;R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-03-12 00:34]&lt;br&gt;R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-03-12 00:34]&lt;br&gt;R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-03-19 15:25]&lt;br&gt;S3 HPx9G+;HPx9G+ Device USB Driver;C:\WINDOWS\system32\DRIVERS\HPx9G2k.sys [2005-02-17 14:38]&lt;br&gt;&lt;br&gt;*Newly Created Service* - CATCHME&lt;br&gt;.&lt;br&gt;Contents of the 'Scheduled Tasks' folder&lt;br&gt;"2008-03-25 00:07:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"&lt;br&gt;- C:\Program Files\Apple Software Update\SoftwareUpdate.exe&lt;br&gt;"2008-05-15 08:29:21 C:\WINDOWS\Tasks\RegCure Program Check.job"&lt;br&gt;- C:\Program Files\RegCure\RegCure.exe&lt;br&gt;"2008-04-23 19:08:15 C:\WINDOWS\Tasks\RegCure.job"&lt;br&gt;- C:\Program Files\RegCure\RegCure.exe&lt;br&gt;.&lt;br&gt;**************************************************************************&lt;br&gt;&lt;br&gt;catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net&lt;br&gt;Rootkit scan 2008-05-15 16:43:42&lt;br&gt;Windows 5.1.2600 Service Pack 2 NTFS&lt;br&gt;&lt;br&gt;scanning hidden processes ... &lt;br&gt;&lt;br&gt;scanning hidden autostart entries ...&lt;br&gt;&lt;br&gt;scanning hidden files ... &lt;br&gt;&lt;br&gt;scan completed successfully&lt;br&gt;hidden files: 0&lt;br&gt;&lt;br&gt;**************************************************************************&lt;br&gt;.&lt;br&gt;Completion time: 2008-05-15 16:45:48&lt;br&gt;ComboFix-quarantined-files.txt  2008-05-15 08:45:36&lt;br&gt;ComboFix2.txt  2007-06-03 08:32:33&lt;br&gt;&lt;br&gt;Pre-Run: 7,401,037,824 bytes free&lt;br&gt;Post-Run: 7,375,024,128 bytes free&lt;br&gt;&lt;br&gt;120--- E O F ---2008-05-14 09:17:03&lt;br&gt;&lt;br&gt;[b]HijacjkThis Log[/b]&lt;br&gt;&lt;br&gt;Logfile of HijackThis v1.99.1&lt;br&gt;Scan saved at 4:48:25 PM, on 15/05/2008&lt;br&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16640)&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\WINDOWS\System32\smss.exe&lt;br&gt;C:\WINDOWS\system32\winlogon.exe&lt;br&gt;C:\WINDOWS\system32\services.exe&lt;br&gt;C:\WINDOWS\system32\lsass.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\WINDOWS\system32\ZoneLabs\vsmon.exe&lt;br&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br&gt;C:\WINDOWS\system32\acs.exe&lt;br&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgam.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgrsx.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgnsx.exe&lt;br&gt;C:\WINDOWS\system32\nvsvc32.exe&lt;br&gt;C:\Program Files\CyberLink\Shared files\RichVideo.exe&lt;br&gt;C:\WINDOWS\system32\STacSV.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgemc.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;br&gt;C:\WINDOWS\sttray.exe&lt;br&gt;C:\Program Files\TP-LINK\TWCU\TWCU.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgtray.exe&lt;br&gt;C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe&lt;br&gt;C:\Program Files\QuickTime\QTTask.exe&lt;br&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;br&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe&lt;br&gt;C:\WINDOWS\system32\notepad.exe&lt;br&gt;C:\WINDOWS\explorer.exe&lt;br&gt;C:\Program Files\Mozilla Firefox\firefox.exe&lt;br&gt;C:\WINDOWS\system32\NOTEPAD.EXE&lt;br&gt;C:\Program Files\Hijackthis\HijackThis.exe&lt;br&gt;&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;br&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;br&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br&gt;O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll&lt;br&gt;O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;br&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;br&gt;O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe&lt;br&gt;O4 - HKLM\..\Run: [nwiz] nwiz.exe /install&lt;br&gt;O4 - HKLM\..\Run: [TWCU] "C:\Program Files\TP-LINK\TWCU\TWCU.exe" -nogui&lt;br&gt;O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup&lt;br&gt;O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe&lt;br&gt;O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"&lt;br&gt;O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime&lt;br&gt;O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"&lt;br&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"&lt;br&gt;O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;O4 - Startup: Stardock ObjectDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe&lt;br&gt;O4 - Startup: Y'z ToolBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe&lt;br&gt;O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe&lt;br&gt;O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe&lt;br&gt;O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe&lt;br&gt;O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000&lt;br&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;br&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL&lt;br&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)&lt;br&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)&lt;br&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll&lt;br&gt;O11 - Options group: [INTERNATIONAL] International*&lt;br&gt;O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab&lt;br&gt;O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab&lt;br&gt;O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab&lt;br&gt;O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll&lt;br&gt;O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL&lt;br&gt;O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL&lt;br&gt;O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL&lt;br&gt;O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll&lt;br&gt;O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll&lt;br&gt;O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll&lt;br&gt;O23 - Service: TP-LINK Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe&lt;br&gt;O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe&lt;br&gt;O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br&gt;O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe&lt;br&gt;O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;br&gt;O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe&lt;br&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br&gt;O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe&lt;br&gt;O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe&lt;br&gt;O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\STacSV.exe&lt;br&gt;O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe&lt;br&gt;&lt;br&gt;Thanks</description><pubDate>Thu, 15 May 2008 03:49:46 GMT</pubDate><dc:creator>rocknrolldan</dc:creator></item><item><title>RE: IE and MSN warnings about trying to log key strokes</title><link>http://forum.tweaks.com/forum/Topic239438-29-1.aspx</link><description>Welcome:)&lt;br&gt;&lt;br&gt;Download and scan with [b][color="red"]CCleaner[/color][/b]:&lt;br&gt;[url]http://www.ccleaner.com/downloadbuilds.asp[/url]&lt;br&gt;1. Starting with v1.27.260, CCleaner installs the [b]Yahoo Toolbar[/b] as an option which IS checkmarked by default during the installation. IF you do NOT want it, REMOVE the checkmark when provided with the option OR download the toolbar-free Basic or Slim versions instead of the Standard Build.&lt;br&gt;&lt;br&gt;2. Before first use, select Options &gt; Advanced and UNCHECK [b]"Only delete files in Windows Temp folder older than 48 hours"[/b]&lt;br&gt;&lt;br&gt;3. Then select the items you wish to clean up.&lt;br&gt;&lt;br&gt;[b]In the Windows Tab:[/b]&lt;br&gt;* Clean all entries in the "Internet Explorer" section except Cookies.&lt;br&gt;* Clean all the entries in the "Windows Explorer" section.&lt;br&gt;* Clean all entries in the "System" section.&lt;br&gt;* Clean all entries in the "Advanced" section.&lt;br&gt;* Clean any others that you choose.&lt;br&gt;&lt;br&gt;[b]In the Applications Tab:[/b]&lt;br&gt;* Clean all except cookies in the Firefox/Mozilla section if you use it.&lt;br&gt;* Clean all in the Opera section if you use it.&lt;br&gt;* Clean Sun Java in the Internet Section.&lt;br&gt;* Clean any others that you choose.&lt;br&gt;&lt;br&gt;4. Click the "Run Cleaner" button.&lt;br&gt;5. A pop up box will appear advising this process will permanently delete files from your system.&lt;br&gt;6. Click "OK" and it will scan and clean your system.&lt;br&gt;7. Click "Exit" when done.&lt;br&gt;&lt;br&gt;&lt;br&gt;Your version of [b]Sun Java[/b] is out of date.&lt;br&gt;Older versions have vulnerabilities that malware can use to infect your system.&lt;br&gt;Please follow these steps to remove older versions of Sun Java,and then update.&lt;br&gt;1. Download the latest version of [b][url=http://java.sun.com/javase/downloads/index.jsp][color="blue"]Java Runtime Environment (JRE)[/color][/url][/b]&lt;br&gt;2. Scroll down to where it says '[b]Java Runtime Environment (JRE) 6u6[/b]'.&lt;br&gt;3. Click the "Download" button to the right.&lt;br&gt;4. Select the Platform and Language for your download,then check the box that says: "Accept License Agreement".&lt;br&gt;5. The page will refresh.&lt;br&gt;6. Click on the link to download 'Windows Offline Installation, Multi-language - jre-6u6-windows-i586-p.exe' [15.21 MB] and save to your desktop.&lt;br&gt;7. Close any programs you may have running - especially your web browser.&lt;br&gt;8. Click Start and choose Control Panel:&lt;br&gt;-  In Control Panel double click on the "Programs and Features" icon.&lt;br&gt;-  Here you can find all the programs and items which are installed in Windows Vista.&lt;br&gt;-  Now remove all older versions of Sun Java.&lt;br&gt;9. Click on any item with Java Runtime Environment (JRE or J2SE) in the name to uninstall/remove it.&lt;br&gt;10. Repeat as many times as necessary to remove each Java version.&lt;br&gt;11. Reboot your computer once all Java components are removed.&lt;br&gt;12. Then from your desktop double-click on [b]jre-6u6-windows-i586-p.exe[/b] to install the newest version.&lt;br&gt;&lt;br&gt;&lt;br&gt;[b]If you have previously downloaded ComboFix,please delete that version now.[/b]&lt;br&gt;Download [b][url=http://download.bleepingcomputer.com/sUBs/ComboFix.exe][color="blue"]Combofix[/color][/url][/b] by [b]sUBs[/b] and save to your desktop.&lt;br&gt;Alternative Combofix download link [b][url=http://subs.geekstogo.com/ComboFix.exe][color="blue"]HERE[/color][/url][/b].&lt;br&gt;[color="red"][b][u]Note[/u][/b] &lt;br&gt;It is important that it is saved directly to your desktop[/color]&lt;br&gt;&lt;br&gt;Now close any open browsers.&lt;br&gt;Double click on Combofix.exe and follow the prompts. &lt;br&gt;When it's finished it will produce a log. &lt;br&gt;[b]Post the entire contents of C:\ComboFix.txt into your next reply[/b]. &lt;br&gt;[color="red"][b][u]Note[/u][/b] &lt;br&gt;Do not mouseclick combofix's window or do anything else on your pc while it's running. &lt;br&gt;That may cause the program/system to freeze/hang. [/color]&lt;br&gt;Do NOT post the ComboFix-quarantined-files.txt unless I ask.&lt;br&gt;[b][color="RED"][U]Note[/U][/color][/b]&lt;br&gt;In case your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix,please disable your scanner and redownload Combofix again.&lt;br&gt;Some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.&lt;br&gt;&lt;br&gt;[b]Also post a new Hijackthis log please.[/b]</description><pubDate>Wed, 14 May 2008 12:20:20 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>IE and MSN warnings about trying to log key strokes</title><link>http://forum.tweaks.com/forum/Topic239438-29-1.aspx</link><description>Hey, over the last two days my firewall (zonealarm) has warned me about IE and MSN trying to log keystrokes and monitor activites. I blocked both of these warnings but confused to why they are coming up and why it would be MSN and IE. So my log is below.&lt;br&gt;&lt;br&gt;Thanks:)&lt;br&gt;&lt;br&gt;Logfile of HijackThis v1.99.1&lt;br&gt;Scan saved at 11:09:44 PM, on 14/05/2008&lt;br&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16640)&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\WINDOWS\System32\smss.exe&lt;br&gt;C:\WINDOWS\system32\winlogon.exe&lt;br&gt;C:\WINDOWS\system32\services.exe&lt;br&gt;C:\WINDOWS\system32\lsass.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\WINDOWS\system32\ZoneLabs\vsmon.exe&lt;br&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br&gt;C:\WINDOWS\system32\acs.exe&lt;br&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;br&gt;C:\WINDOWS\system32\nvsvc32.exe&lt;br&gt;C:\Program Files\CyberLink\Shared files\RichVideo.exe&lt;br&gt;C:\WINDOWS\system32\STacSV.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgam.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgrsx.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgemc.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;br&gt;C:\Program Files\Windows Live\Messenger\usnsvc.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgnsx.exe&lt;br&gt;C:\WINDOWS\Explorer.EXE&lt;br&gt;C:\WINDOWS\sttray.exe&lt;br&gt;C:\Program Files\TP-LINK\TWCU\TWCU.exe&lt;br&gt;C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgtray.exe&lt;br&gt;C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe&lt;br&gt;C:\Program Files\QuickTime\QTTask.exe&lt;br&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;br&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe&lt;br&gt;C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe&lt;br&gt;C:\Program Files\iTunes\iTunes.exe&lt;br&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe&lt;br&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\distnoted.exe&lt;br&gt;C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE&lt;br&gt;C:\Program Files\Mozilla Firefox\firefox.exe&lt;br&gt;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&lt;br&gt;C:\WINDOWS\system32\igfxsrvc.exe&lt;br&gt;C:\WINDOWS\system32\mspaint.exe&lt;br&gt;C:\Program Files\Hijackthis\HijackThis.exe&lt;br&gt;&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;br&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;br&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br&gt;O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll&lt;br&gt;O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;br&gt;O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe&lt;br&gt;O4 - HKLM\..\Run: [nwiz] nwiz.exe /install&lt;br&gt;O4 - HKLM\..\Run: [TWCU] "C:\Program Files\TP-LINK\TWCU\TWCU.exe" -nogui&lt;br&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"&lt;br&gt;O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup&lt;br&gt;O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe&lt;br&gt;O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"&lt;br&gt;O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime&lt;br&gt;O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"&lt;br&gt;O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;O4 - Startup: Stardock ObjectDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe&lt;br&gt;O4 - Startup: Y'z ToolBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe&lt;br&gt;O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe&lt;br&gt;O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe&lt;br&gt;O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe&lt;br&gt;O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000&lt;br&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL&lt;br&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)&lt;br&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)&lt;br&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll&lt;br&gt;O11 - Options group: [INTERNATIONAL] International*&lt;br&gt;O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab&lt;br&gt;O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab&lt;br&gt;O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab&lt;br&gt;O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll&lt;br&gt;O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL&lt;br&gt;O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL&lt;br&gt;O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL&lt;br&gt;O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll&lt;br&gt;O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll&lt;br&gt;O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll&lt;br&gt;O23 - Service: TP-LINK Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe&lt;br&gt;O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe&lt;br&gt;O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br&gt;O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe&lt;br&gt;O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;br&gt;O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe&lt;br&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br&gt;O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe&lt;br&gt;O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe&lt;br&gt;O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\STacSV.exe&lt;br&gt;O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe&lt;br&gt;&lt;br&gt;</description><pubDate>Wed, 14 May 2008 10:10:33 GMT</pubDate><dc:creator>rocknrolldan</dc:creator></item></channel></rss>