﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Tweaks.com Forum  / Windows &amp; System Security / HiJack This Logs  / Browser hijack, internet goes down intermitenly. / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>Tweaks.com Forum </description><link>http://forum.tweaks.com/forum/</link><webMaster>forum@tweaks.com</webMaster><lastBuildDate>Sun, 07 Sep 2008 06:17:46 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: Browser hijack, internet goes down intermitenly.</title><link>http://forum.tweaks.com/forum/Topic239505-29-1.aspx</link><description>You're welcome:)</description><pubDate>Sat, 17 May 2008 17:10:08 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Browser hijack, internet goes down intermitenly.</title><link>http://forum.tweaks.com/forum/Topic239505-29-1.aspx</link><description>Thanks again Rich, you are the man.</description><pubDate>Sat, 17 May 2008 11:59:08 GMT</pubDate><dc:creator>chaldo</dc:creator></item><item><title>RE: Browser hijack, internet goes down intermitenly.</title><link>http://forum.tweaks.com/forum/Topic239505-29-1.aspx</link><description>Your log is clean:),please do the following:&lt;br&gt;&lt;br&gt;You should now take the time to read and follow the information found in the links below,to help you prevent any possible future infections and stay safe and secure while online:&lt;br&gt;&lt;br&gt;[b][color="blue"]Simple and easy ways to keep your computer safe and secure on the Internet[/color][/b]:&lt;br&gt;[url]http://www.bleepingcomputer.com/tutorials/tutorial82.html[/url]&lt;br&gt;&lt;br&gt;[b][color="blue"]How to prevent Malware[/color][/b]:&lt;br&gt;[url]http://users.telenet.be/bluepatchy/miekiemoes/prevention.html[/url]&lt;br&gt;&lt;br&gt;[B][color="blue"]So how did I get infected in the first place[/color][/B]:&lt;br&gt;[URL]http://forums.spybot.info/showthread.php?t=279[/URL]&lt;br&gt;&lt;br&gt;[B][color="blue"]Malware Cleanup Programs and Preventative Procedures[/color][/B]: &lt;br&gt;[URL]http://russelltexas.com/malware/allclear.htm[/URL]&lt;br&gt;&lt;br&gt;[b][color="blue"]Hardening Windows Security - Part 1[/color][/b]:&lt;br&gt;[url]http://www.malwarehelp.org/Malware-Prevention-Hardening-Windows-Security1.html[/url]&lt;br&gt;&lt;br&gt;[b][color="blue"]Hardening Windows Security - Part 2[/color][/b]:&lt;br&gt;[url]http://www.malwarehelp.org/malware-prevention-hardening-windows-security2.html[/url]</description><pubDate>Sat, 17 May 2008 11:14:34 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Browser hijack, internet goes down intermitenly.</title><link>http://forum.tweaks.com/forum/Topic239505-29-1.aspx</link><description>&lt;STRONG&gt;Everything seems to be working much smoother now, thank you so much for your help Richie!! Here are the logs you wanted.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Malwarebytes' Anti-Malware&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[quote]&lt;/P&gt;&lt;P&gt;Malwarebytes' Anti-Malware 1.12&lt;BR&gt;Database version: 758&lt;/P&gt;&lt;P&gt;Scan type: Quick Scan&lt;BR&gt;Objects scanned: 39551&lt;BR&gt;Time elapsed: 5 minute(s), 25 second(s)&lt;/P&gt;&lt;P&gt;Memory Processes Infected: 0&lt;BR&gt;Memory Modules Infected: 0&lt;BR&gt;Registry Keys Infected: 7&lt;BR&gt;Registry Values Infected: 0&lt;BR&gt;Registry Data Items Infected: 0&lt;BR&gt;Folders Infected: 0&lt;BR&gt;Files Infected: 1&lt;/P&gt;&lt;P&gt;Memory Processes Infected:&lt;BR&gt;(No malicious items detected)&lt;/P&gt;&lt;P&gt;Memory Modules Infected:&lt;BR&gt;(No malicious items detected)&lt;/P&gt;&lt;P&gt;Registry Keys Infected:&lt;BR&gt;HKEY_CLASSES_ROOT\Interface\{e4e3e0f8-cd30-4380-8ce9-b96904bdefca} (Adware.PopCap) -&amp;gt; Quarantined and deleted successfully.&lt;BR&gt;HKEY_CLASSES_ROOT\Interface\{fe8a736f-4124-4d9c-b4b1-3b12381efabe} (Adware.PopCap) -&amp;gt; Quarantined and deleted successfully.&lt;BR&gt;HKEY_CLASSES_ROOT\Typelib\{c9c5deaf-0a1f-4660-8279-9edfad6fefe1} (Adware.PopCap) -&amp;gt; Quarantined and deleted successfully.&lt;BR&gt;HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -&amp;gt; Quarantined and deleted successfully.&lt;BR&gt;HKEY_CLASSES_ROOT\CLSID\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -&amp;gt; Quarantined and deleted successfully.&lt;BR&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -&amp;gt; Quarantined and deleted successfully.&lt;BR&gt;HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -&amp;gt; Quarantined and deleted successfully.&lt;/P&gt;&lt;P&gt;Registry Values Infected:&lt;BR&gt;(No malicious items detected)&lt;/P&gt;&lt;P&gt;Registry Data Items Infected:&lt;BR&gt;(No malicious items detected)&lt;/P&gt;&lt;P&gt;Folders Infected:&lt;BR&gt;(No malicious items detected)&lt;/P&gt;&lt;P&gt;Files Infected:&lt;BR&gt;C:\WINDOWS\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -&amp;gt; Quarantined and deleted successfully.&lt;BR&gt;&lt;/P&gt;&lt;P&gt;[/quote]&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;HijackThis&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[quote]&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 11:58:06 AM, on 5/17/2008&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16640)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;C:\WINDOWS\eHome\ehRecvr.exe&lt;BR&gt;C:\WINDOWS\eHome\ehSched.exe&lt;BR&gt;C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE&lt;BR&gt;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&lt;BR&gt;C:\WINDOWS\system32\hkcmd.exe&lt;BR&gt;C:\WINDOWS\system32\igfxpers.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\WINDOWS\system32\dllhost.exe&lt;BR&gt;C:\WINDOWS\explorer.exe&lt;BR&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://yahoo.com/"&gt;http://yahoo.com/&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;BR&gt;O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll&lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup&lt;BR&gt;O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start&lt;BR&gt;O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe&lt;BR&gt;O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe&lt;BR&gt;O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe&lt;BR&gt;O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"&lt;BR&gt;O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O4 - HKUS\S-1-5-21-724266673-3495283618-3678091246-1005\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')&lt;BR&gt;O4 - HKUS\S-1-5-21-724266673-3495283618-3678091246-1005\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')&lt;BR&gt;O4 - HKUS\S-1-5-21-724266673-3495283618-3678091246-1005\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup (User '?')&lt;BR&gt;O4 - HKUS\S-1-5-21-724266673-3495283618-3678091246-1005\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User '?')&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL&lt;BR&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - &lt;A href="http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab"&gt;http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - &lt;A href="http://download.bitdefender.com/resources/scan8/oscan8.cab"&gt;http://download.bitdefender.com/resources/scan8/oscan8.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - &lt;A href="http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab"&gt;http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - &lt;A href="https://secure.logmein.com/activex/ractrl.cab?lmi=100"&gt;https://secure.logmein.com/activex/ractrl.cab?lmi=100&lt;/A&gt;&lt;BR&gt;O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe&lt;BR&gt;O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 5009 bytes&lt;BR&gt;&lt;/P&gt;&lt;P&gt;[/quote]</description><pubDate>Sat, 17 May 2008 11:03:10 GMT</pubDate><dc:creator>chaldo</dc:creator></item><item><title>RE: Browser hijack, internet goes down intermitenly.</title><link>http://forum.tweaks.com/forum/Topic239505-29-1.aspx</link><description>Copy and paste ALL the following text in the Quote box below into [b]Notepad[/b].&lt;br&gt;Click on File(in the menu at the top)&gt;Save as../Save as Type: 'All Files' /File name: [b]fix.reg[/b] to your desktop.&lt;br&gt;Then double click on the [b]fix.reg[/b] file on your desktop[IMG]http://img.photobucket.com/albums/v624/29wood/Clipboard01reg.gif[/IMG]and agree to merge the information into the registry,[b]then restart your pc[/b].&lt;br&gt;[quote]REGEDIT4&lt;br&gt;[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\webHancer Agent]&lt;br&gt;[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\webHancer Survey Companion][/quote]&lt;br&gt;&lt;br&gt;Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'. &lt;br&gt;Make sure all browser and all Windows Explorer windows are closed before fixing:&lt;br&gt;[b]O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)&lt;br&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)[/b]&lt;br&gt;&lt;br&gt;&lt;br&gt;Click on Start/Run,copy and paste [b]ComboFix /u[/b] into the 'Open:' space,then press Ok.&lt;br&gt;This will uninstall Combofix,delete its related folders and files,reset your clock settings,hide file extensions,hide the system/hidden files and resets System Restore.&lt;br&gt;&lt;br&gt;[IMG]http://img.photobucket.com/albums/v624/29wood/comu.gif[/IMG]&lt;br&gt;&lt;br&gt;&lt;br&gt;Please download [b][color="red"]Malwarebytes Anti-Malware[/color][/b]:&lt;br&gt;[url]http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html[/url]&lt;br&gt;[url]http://www.besttechie.net/tools/mbam-setup.exe[/url]&lt;br&gt;&lt;br&gt;Double Click mbam-setup.exe to install the application.&lt;br&gt;(If using Windows Vista,be sure to [b][url=http://windowshelp.microsoft.com/Windows/en-US/Help/fb464905-31d5-4427-89a2-ed5322327fc21033.mspx][color="blue"]"Run As Administrator"[/color][/url][/b]).&lt;br&gt;&lt;br&gt;* Make sure a checkmark is placed next to [b]Update Malwarebytes' Anti-Malware[/b] and [b]Launch Malwarebytes' Anti-Malware[/b], then click Finish.&lt;br&gt;* If an update is found, it will download and install the latest version.&lt;br&gt;* Once the program has loaded, select "Perform Quick Scan", then click Scan.&lt;br&gt;* The scan may take some time to finish,so please be patient.&lt;br&gt;* When the scan is complete, click OK, then Show Results to view the results.&lt;br&gt;* Make sure that everything is checked, and click Remove Selected.&lt;br&gt;* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)&lt;br&gt;* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.&lt;br&gt;* [b]Copy and paste the entire report into your next reply[/b].&lt;br&gt;&lt;br&gt;Extra Note:&lt;br&gt;[b][color="green"]If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.[/color][/b]&lt;br&gt;&lt;br&gt;[b]Also post a new Hijackthis log,let me know how your pc is running now please.[/b]</description><pubDate>Fri, 16 May 2008 17:42:30 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Browser hijack, internet goes down intermitenly.</title><link>http://forum.tweaks.com/forum/Topic239505-29-1.aspx</link><description>&lt;STRONG&gt;Thanks Richie, here are the logs you requested.&lt;/STRONG&gt;&lt;P&gt;&lt;STRONG&gt;Avira AntiVir Personal&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[quote]&lt;/P&gt;&lt;P&gt;Avira AntiVir Personal&lt;BR&gt;Report file date: Friday, May 16, 2008  17:56&lt;/P&gt;&lt;P&gt;Scanning for 1276115 virus strains and unwanted programs.&lt;/P&gt;&lt;P&gt;Licensed to:      Avira AntiVir PersonalEdition Classic&lt;BR&gt;Serial number:    0000149996-ADJIE-0001&lt;BR&gt;Platform:         Windows XP&lt;BR&gt;Windows version:  (Service Pack 2)  [5.1.2600]&lt;BR&gt;Boot mode:        Normally booted&lt;BR&gt;Username:         SYSTEM&lt;BR&gt;Computer name:    SALESFLOOR&lt;/P&gt;&lt;P&gt;Version information:&lt;BR&gt;BUILD.DAT     : 8.1.00.295      16479 Bytes    4/9/2008 16:24:00&lt;BR&gt;AVSCAN.EXE    : 8.1.2.12       311553 Bytes   3/18/2008 15:02:56&lt;BR&gt;AVSCAN.DLL    : 8.1.1.0         53505 Bytes    2/7/2008 14:43:37&lt;BR&gt;LUKE.DLL      : 8.1.2.9        151809 Bytes   2/28/2008 14:41:23&lt;BR&gt;LUKERES.DLL   : 8.1.2.1         12033 Bytes   2/21/2008 14:28:40&lt;BR&gt;ANTIVIR0.VDF  : 6.40.0.0     11030528 Bytes   7/18/2007 16:33:34&lt;BR&gt;ANTIVIR1.VDF  : 7.0.3.2       5447168 Bytes    3/7/2008 19:08:58&lt;BR&gt;ANTIVIR2.VDF  : 7.0.4.0       1554432 Bytes    5/5/2008 21:51:02&lt;BR&gt;ANTIVIR3.VDF  : 7.0.4.52       329728 Bytes   5/16/2008 21:51:03&lt;BR&gt;Engineversion : 8.1.0.46  &lt;BR&gt;AEVDF.DLL     : 8.1.0.5        102772 Bytes   2/25/2008 15:58:21&lt;BR&gt;AESCRIPT.DLL  : 8.1.0.33       266618 Bytes   5/16/2008 21:51:16&lt;BR&gt;AESCN.DLL     : 8.1.0.18       119156 Bytes   5/16/2008 21:51:15&lt;BR&gt;AERDL.DLL     : 8.1.0.20       418165 Bytes   5/16/2008 21:51:14&lt;BR&gt;AEPACK.DLL    : 8.1.1.5        364918 Bytes   5/16/2008 21:51:13&lt;BR&gt;AEOFFICE.DLL  : 8.1.0.18       192890 Bytes   5/16/2008 21:51:11&lt;BR&gt;AEHEUR.DLL    : 8.1.0.29      1253750 Bytes   5/16/2008 21:51:10&lt;BR&gt;AEHELP.DLL    : 8.1.0.14       115063 Bytes   5/16/2008 21:51:07&lt;BR&gt;AEGEN.DLL     : 8.1.0.21       303477 Bytes   5/16/2008 21:51:06&lt;BR&gt;AEEMU.DLL     : 8.1.0.6        430451 Bytes   5/16/2008 21:51:05&lt;BR&gt;AECORE.DLL    : 8.1.0.29       168311 Bytes   5/16/2008 21:51:04&lt;BR&gt;AVWINLL.DLL   : 1.0.0.7         14593 Bytes   1/23/2008 23:07:53&lt;BR&gt;AVPREF.DLL    : 8.0.0.1         25857 Bytes   2/18/2008 16:37:50&lt;BR&gt;AVREP.DLL     : 7.0.0.1        155688 Bytes   4/16/2007 19:26:47&lt;BR&gt;AVREG.DLL     : 8.0.0.0         30977 Bytes   1/23/2008 23:07:49&lt;BR&gt;AVARKT.DLL    : 1.0.0.23       307457 Bytes   2/12/2008 14:29:23&lt;BR&gt;AVEVTLOG.DLL  : 8.0.0.11       114945 Bytes   2/28/2008 14:31:31&lt;BR&gt;SQLITE3.DLL   : 3.3.17.1       339968 Bytes   1/22/2008 23:28:02&lt;BR&gt;SMTPLIB.DLL   : 1.2.0.19        28929 Bytes   1/23/2008 23:08:39&lt;BR&gt;NETNT.DLL     : 8.0.0.1          7937 Bytes   1/25/2008 18:05:10&lt;BR&gt;RCIMAGE.DLL   : 8.0.0.35      2371841 Bytes   3/10/2008 20:37:25&lt;BR&gt;RCTEXT.DLL    : 8.0.32.0        86273 Bytes    3/6/2008 18:02:11&lt;/P&gt;&lt;P&gt;Configuration settings for the scan:&lt;BR&gt;Jobname..........................: Complete system scan&lt;BR&gt;Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp&lt;BR&gt;Logging..........................: low&lt;BR&gt;Primary action...................: interactive&lt;BR&gt;Secondary action.................: ignore&lt;BR&gt;Scan master boot sector..........: on&lt;BR&gt;Scan boot sector.................: on&lt;BR&gt;Boot sectors.....................: C:, &lt;BR&gt;Scan memory......................: on&lt;BR&gt;Process scan.....................: on&lt;BR&gt;Scan registry....................: on&lt;BR&gt;Search for rootkits..............: off&lt;BR&gt;Scan all files...................: Intelligent file selection&lt;BR&gt;Scan archives....................: on&lt;BR&gt;Recursion depth..................: 20&lt;BR&gt;Smart extensions.................: on&lt;BR&gt;Macro heuristic..................: on&lt;BR&gt;File heuristic...................: medium&lt;/P&gt;&lt;P&gt;Start of the scan: Friday, May 16, 2008  17:56&lt;/P&gt;&lt;P&gt;The scan of running processes will be started&lt;BR&gt;Scan process 'avscan.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'iexplore.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'avcenter.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'wuauclt.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'msiexec.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'alg.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'dllhost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'ctfmon.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'avgnt.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'igfxpers.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'hkcmd.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'issch.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'mcrdsvc.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'explorer.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'MDM.EXE' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'ehSched.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'ehrecvr.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'avguard.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'sched.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'spoolsv.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'lsass.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'services.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'winlogon.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'csrss.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'smss.exe' - '1' Module(s) have been scanned&lt;BR&gt;33 processes with 33 modules were scanned&lt;/P&gt;&lt;P&gt;Starting master boot sector scan:&lt;BR&gt;Master boot sector HD0&lt;BR&gt;      [INFO]      No virus was found!&lt;/P&gt;&lt;P&gt;Start scanning boot sectors:&lt;BR&gt;Boot sector 'C:\'&lt;BR&gt;      [INFO]      No virus was found!&lt;/P&gt;&lt;P&gt;Starting to scan the registry.&lt;BR&gt;The registry was scanned ( '29' files ).&lt;/P&gt;&lt;P&gt;&lt;BR&gt;Starting the file scan:&lt;/P&gt;&lt;P&gt;Begin scan in 'C:\'&lt;BR&gt;C:\hiberfil.sys&lt;BR&gt;      [WARNING]   The file could not be opened!&lt;BR&gt;C:\pagefile.sys&lt;BR&gt;      [WARNING]   The file could not be opened!&lt;BR&gt;C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP788\A0040971.exe&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Drop.Web.381.5.B&lt;BR&gt;      [NOTE]      The file was deleted!&lt;BR&gt;C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP788\A0040972.exe&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Drop.Web.381.5.B&lt;BR&gt;      [NOTE]      The file was deleted!&lt;/P&gt;&lt;P&gt;&lt;BR&gt;End of the scan: Friday, May 16, 2008  18:20&lt;BR&gt;Used time: 24:01 min&lt;/P&gt;&lt;P&gt;The scan has been done completely.&lt;/P&gt;&lt;P&gt;   4855 Scanning directories&lt;BR&gt; 202015 Files were scanned&lt;BR&gt;      2 viruses and/or unwanted programs were found&lt;BR&gt;      0 Files were classified as suspicious:&lt;BR&gt;      2 files were deleted&lt;BR&gt;      0 files were repaired&lt;BR&gt;      0 files were moved to quarantine&lt;BR&gt;      0 files were renamed&lt;BR&gt;      2 Files cannot be scanned&lt;BR&gt; 202013 Files not concerned&lt;BR&gt;   2977 Archives were scanned&lt;BR&gt;      2 Warnings&lt;BR&gt;      2 Notes&lt;/P&gt;&lt;P&gt;[/quote]&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;HijackThis&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[quote]&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 6:21:05 PM, on 5/16/2008&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16640)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;C:\WINDOWS\eHome\ehRecvr.exe&lt;BR&gt;C:\WINDOWS\eHome\ehSched.exe&lt;BR&gt;C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&lt;BR&gt;C:\WINDOWS\system32\hkcmd.exe&lt;BR&gt;C:\WINDOWS\system32\igfxpers.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\WINDOWS\system32\dllhost.exe&lt;BR&gt;C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://yahoo.com/"&gt;http://yahoo.com/&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = &lt;BR&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;BR&gt;O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll&lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup&lt;BR&gt;O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start&lt;BR&gt;O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe&lt;BR&gt;O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe&lt;BR&gt;O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe&lt;BR&gt;O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"&lt;BR&gt;O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL&lt;BR&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)&lt;BR&gt;O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - &lt;A href="http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab"&gt;http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - &lt;A href="http://download.bitdefender.com/resources/scan8/oscan8.cab"&gt;http://download.bitdefender.com/resources/scan8/oscan8.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - &lt;A href="http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab"&gt;http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - &lt;A href="http://www.shockwave.com/content/insaniquarium/sis/popcaploader_v10.cab"&gt;http://www.shockwave.com/content/insaniquarium/sis/popcaploader_v10.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - &lt;A href="https://secure.logmein.com/activex/ractrl.cab?lmi=100"&gt;https://secure.logmein.com/activex/ractrl.cab?lmi=100&lt;/A&gt;&lt;BR&gt;O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe&lt;BR&gt;O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 5163 bytes&lt;BR&gt;&lt;/P&gt;&lt;P&gt;[/quote]&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ComboFix&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[quote]&lt;/P&gt;&lt;P&gt;ComboFix 08-05-15.3 - user2 2008-05-16 18:22:49.1 - NTFSx86&lt;BR&gt;Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.650 [GMT -4:00]&lt;BR&gt;Running from: C:\Documents and Settings\user2\Desktop\ComboFix.exe&lt;BR&gt; * Created a new restore point&lt;/P&gt;&lt;P&gt;[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;C:\WINDOWS\Downloaded Program Files\setup.inf&lt;/P&gt;&lt;P&gt;.&lt;BR&gt;(((((((((((((((((((((((((   Files Created from 2008-04-16 to 2008-05-16  )))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;2008-05-16 17:55 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl&lt;BR&gt;2008-05-16 17:54 . 2008-05-16 17:54 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\Java&lt;BR&gt;2008-05-16 17:49 . 2008-05-16 17:49 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Avira&lt;BR&gt;2008-05-16 17:49 . 2008-05-16 17:49 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Avira&lt;BR&gt;2008-05-15 16:30 . 2008-05-15 16:30 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Trend Micro&lt;BR&gt;2008-05-15 16:06 . 2008-05-15 16:06 11,918 --a------ C:\cc_20080515_1606.reg&lt;BR&gt;2008-05-15 15:57 . 2008-05-15 15:56 691,545 --a------ C:\WINDOWS\unins000.exe&lt;BR&gt;2008-05-15 15:57 . 2008-05-15 15:57 2,545 --a------ C:\WINDOWS\unins000.dat&lt;BR&gt;2008-04-23 14:42 . 2004-08-16 20:40 16,384 --a------ C:\WINDOWS\system32\FileOps.exe&lt;BR&gt;2008-04-18 12:01 . 2008-04-18 12:01 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\user2\Application Data\Apple Computer&lt;/P&gt;&lt;P&gt;.&lt;BR&gt;((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;BR&gt;2008-05-16 21:55 --------- d-----w C:\Program Files\Java&lt;BR&gt;2008-05-16 21:49 --------- d-----w C:\Program Files\Spybot - Search &amp;amp; Destroy&lt;BR&gt;2008-05-16 21:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search &amp;amp; Destroy&lt;BR&gt;2008-05-15 09:40 73,728 ----a-w C:\WINDOWS\system32\SigUsb.dll&lt;BR&gt;2008-05-15 09:40 27,648 ----a-w C:\WINDOWS\system32\win32com.dll&lt;BR&gt;2008-04-23 18:42 --------- d-----w C:\Program Files\Common Files\Adobe&lt;BR&gt;2008-04-12 19:45 --------- d-----w C:\Program Files\Oxyd extra&lt;BR&gt;2008-04-09 15:25 --------- d-----w C:\Program Files\QuickTime&lt;BR&gt;2008-04-09 15:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer&lt;BR&gt;2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll&lt;BR&gt;2008-03-27 08:12 151,583 ------w C:\WINDOWS\system32\dllcache\msjint40.dll&lt;BR&gt;2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys&lt;BR&gt;2008-03-19 09:47 1,845,248 ------w C:\WINDOWS\system32\dllcache\win32k.sys&lt;BR&gt;2008-03-09 19:34 204,112 ----a-w C:\cc_20080309_1534.reg&lt;BR&gt;2008-03-09 19:33 194,978 ----a-w C:\cc_20080309_1533.reg&lt;BR&gt;2008-03-05 20:03 479,752 ----a-w C:\WINDOWS\system32\XAudio2_0.dll&lt;BR&gt;2008-03-05 20:03 238,088 ----a-w C:\WINDOWS\system32\xactengine3_0.dll&lt;BR&gt;2008-03-05 20:00 25,608 ----a-w C:\WINDOWS\system32\X3DAudio1_3.dll&lt;BR&gt;2008-03-05 19:56 3,786,760 ----a-w C:\WINDOWS\system32\D3DX9_37.dll&lt;BR&gt;2008-03-05 19:56 1,420,824 ----a-w C:\WINDOWS\system32\D3DCompiler_37.dll&lt;BR&gt;2008-03-01 22:36 3,591,680 ------w C:\WINDOWS\system32\dllcache\mshtml.dll&lt;BR&gt;2008-02-29 08:55 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe&lt;BR&gt;2008-02-29 08:55 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe&lt;BR&gt;2008-02-22 10:00 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe&lt;BR&gt;2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll&lt;BR&gt;2008-02-20 06:51 282,624 ------w C:\WINDOWS\system32\dllcache\gdi32.dll&lt;BR&gt;2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll&lt;BR&gt;2008-02-20 05:32 45,568 ------w C:\WINDOWS\system32\dllcache\dnsrslvr.dll&lt;BR&gt;2008-02-20 05:32 148,992 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll&lt;BR&gt;2006-01-07 19:00 56 -csh--r C:\WINDOWS\system32\3705BA2EE8.sys&lt;BR&gt;2006-01-07 19:00 3,350 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;BR&gt;.&lt;BR&gt;*Note* empty entries &amp;amp; legit default entries are not shown &lt;BR&gt;REGEDIT4&lt;/P&gt;&lt;P&gt;[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 07:00 15360]&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 12:44 249856]&lt;BR&gt;"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 12:44 81920]&lt;BR&gt;"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-23 20:17 94208]&lt;BR&gt;"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 20:13 77824]&lt;BR&gt;"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-23 20:17 118784]&lt;BR&gt;"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]&lt;BR&gt;"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]&lt;BR&gt;"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]&lt;BR&gt;"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles&lt;BR&gt;"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]&lt;BR&gt;--a------ 2007-10-10 20:51 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]&lt;BR&gt;--a------ 2007-03-15 11:09 460784 C:\Program Files\DellSupport\DSAgnt.exe&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]&lt;BR&gt;--------- 2005-02-23 18:19 53248 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]&lt;BR&gt;--a------ 2005-09-29 16:01 67584 C:\WINDOWS\ehome\ehtray.exe&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KeyWallet]&lt;BR&gt;--a------ 2001-06-10 18:47 274432 C:\PROGRA~1\KEYWAL~1\KWallet.exe&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OE_OEM]&lt;BR&gt;C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]&lt;BR&gt;--a------ 2008-03-28 23:37 413696 C:\Program Files\QuickTime\qttask.exe&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]&lt;BR&gt;--a------ 2005-03-22 18:20 339968 C:\WINDOWS\stsystra.exe&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\webHancer Agent]&lt;BR&gt;C:\Program Files\webHancer\Programs\whAgent.exe&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\webHancer Survey Companion]&lt;BR&gt;C:\Program Files\webHancer\Programs\whSurvey.exe&lt;/P&gt;&lt;P&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]&lt;BR&gt;"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=&lt;BR&gt;"%windir%\\Network Diagnostic\\xpnetdiag.exe"=&lt;/P&gt;&lt;P&gt;S3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys []&lt;/P&gt;&lt;P&gt;[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]&lt;BR&gt;\Shell\AutoRun\command - E:\setup.exe&lt;/P&gt;&lt;P&gt;*Newly Created Service* - SSMDRV&lt;BR&gt;.&lt;BR&gt;Contents of the 'Scheduled Tasks' folder&lt;BR&gt;"2008-05-16 12:00:00 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (SALESFLOOR2-wirelessgiant).job"&lt;BR&gt;- c:\program files\mcafee.com\vso\mcmnhdlr.exe&lt;BR&gt;.&lt;BR&gt;**************************************************************************&lt;/P&gt;&lt;P&gt;catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &lt;A href="http://www.gmer.net/"&gt;http://www.gmer.net&lt;/A&gt;&lt;BR&gt;Rootkit scan 2008-05-16 18:23:52&lt;BR&gt;Windows 5.1.2600 Service Pack 2 NTFS&lt;/P&gt;&lt;P&gt;scanning hidden processes ... &lt;/P&gt;&lt;P&gt;scanning hidden autostart entries ...&lt;/P&gt;&lt;P&gt;scanning hidden files ... &lt;/P&gt;&lt;P&gt;scan completed successfully&lt;BR&gt;hidden files: 0&lt;/P&gt;&lt;P&gt;**************************************************************************&lt;BR&gt;.&lt;BR&gt;Completion time: 2008-05-16 18:24:36&lt;BR&gt;ComboFix-quarantined-files.txt  2008-05-16 22:24:34&lt;/P&gt;&lt;P&gt;Pre-Run: 57,926,983,680 bytes free&lt;BR&gt;Post-Run: 57,923,244,032 bytes free&lt;/P&gt;&lt;P&gt;123 --- E O F --- 2008-05-16 07:01:28&lt;BR&gt;&lt;/P&gt;&lt;P&gt;[/quote]</description><pubDate>Fri, 16 May 2008 17:28:25 GMT</pubDate><dc:creator>chaldo</dc:creator></item><item><title>RE: Browser hijack, internet goes down intermitenly.</title><link>http://forum.tweaks.com/forum/Topic239505-29-1.aspx</link><description>Welcome:)&lt;br&gt;&lt;br&gt;Download and scan with [b][color="red"]CCleaner[/color][/b]:&lt;br&gt;[url]http://www.ccleaner.com/downloadbuilds.asp[/url]&lt;br&gt;1. Starting with v1.27.260, CCleaner installs the [b]Yahoo Toolbar[/b] as an option which IS checkmarked by default during the installation. IF you do NOT want it, REMOVE the checkmark when provided with the option OR download the toolbar-free Basic or Slim versions instead of the Standard Build.&lt;br&gt;&lt;br&gt;2. Before first use, select Options &gt; Advanced and UNCHECK [b]"Only delete files in Windows Temp folder older than 48 hours"[/b]&lt;br&gt;&lt;br&gt;3. Then select the items you wish to clean up.&lt;br&gt;&lt;br&gt;[b]In the Windows Tab:[/b]&lt;br&gt;* Clean all entries in the "Internet Explorer" section except Cookies.&lt;br&gt;* Clean all the entries in the "Windows Explorer" section.&lt;br&gt;* Clean all entries in the "System" section.&lt;br&gt;* Clean all entries in the "Advanced" section.&lt;br&gt;* Clean any others that you choose.&lt;br&gt;&lt;br&gt;[b]In the Applications Tab:[/b]&lt;br&gt;* Clean all except cookies in the Firefox/Mozilla section if you use it.&lt;br&gt;* Clean all in the Opera section if you use it.&lt;br&gt;* Clean Sun Java in the Internet Section.&lt;br&gt;* Clean any others that you choose.&lt;br&gt;&lt;br&gt;4. Click the "Run Cleaner" button.&lt;br&gt;5. A pop up box will appear advising this process will permanently delete files from your system.&lt;br&gt;6. Click "OK" and it will scan and clean your system.&lt;br&gt;&lt;br&gt;* Now click on the '[b]Registry[/b]' tab/button on the left.&lt;br&gt;* Then click on the 'Scan for issues' button at the bottom.&lt;br&gt;* If CCleaner displays any issues,click on 'Fix selected issues'.&lt;br&gt;* You'll then be asked 'Do you want to backup changes to the registry',you [b]must[/b] click '[b]YES[/b]'.&lt;br&gt;* Save the backup somewhere safe,your desktop is a good a place as any.&lt;br&gt;* Then click 'Fix Issues',then click 'Close'.&lt;br&gt;* Exit CCleaner.&lt;br&gt;&lt;br&gt;&lt;br&gt;Your version of [b]Sun Java[/b] is out of date.&lt;br&gt;Older versions have vulnerabilities that malware can use to infect your system.&lt;br&gt;Please follow these steps to remove older versions of Sun Java,and then update.&lt;br&gt;1. Download the latest version of [b][url=http://java.sun.com/javase/downloads/index.jsp][color="blue"]Java Runtime Environment (JRE)[/color][/url][/b]&lt;br&gt;2. Scroll down to where it says '[b]Java Runtime Environment (JRE) 6u6[/b]'.&lt;br&gt;3. Click the "Download" button to the right.&lt;br&gt;4. Select the Platform and Language for your download,then check the box that says: "Accept License Agreement".&lt;br&gt;5. The page will refresh.&lt;br&gt;6. Click on the link to download [b]'Windows Offline Installation, Multi-language - jre-6u6-windows-i586-p.exe'[/b] [15.21 MB] and save to your desktop.&lt;br&gt;7. Close any programs you may have running - especially your web browser.&lt;br&gt;8. Go to Start &gt; Control Panel double-click on Add/Remove programs and remove all older versions of Java.&lt;br&gt;9. Check any item with Java Runtime Environment (JRE or J2SE) in the name.&lt;br&gt;10. Click the Change/Remove button.&lt;br&gt;11. Repeat as many times as necessary to remove each Java version.&lt;br&gt;12. Reboot your computer once all Java components are removed.&lt;br&gt;13. Then from your desktop double-click on [b]jre-6u6-windows-i586-p.exe[/b] to install the newest version.&lt;br&gt;&lt;br&gt;&lt;br&gt;Please download/install [b]Avira AntiVir Personal - FREE Antivirus[/b]: &lt;br&gt;[url]http://www.free-av.com/en/download/1/download_avira_antivir_personal__free_antivirus.html[/url]&lt;br&gt;Perform a full scan with Avira and allow it to delete everything it detects.&lt;br&gt;[b]Restart your pc when you've done.[/b]&lt;br&gt;After restart,open Avira Antivirus and select "Reports".&lt;br&gt;Then double click the report from the full scan you have just completed. &lt;br&gt;Click the "Report File" button,then [b]copy and paste the report into your next reply[/b].&lt;br&gt;&lt;br&gt;&lt;br&gt;[b]If you have previously downloaded ComboFix,please delete that version now.[/b]&lt;br&gt;Download [b][url=http://download.bleepingcomputer.com/sUBs/ComboFix.exe][color="blue"]Combofix[/color][/url][/b] by [b]sUBs[/b] and save to your desktop.&lt;br&gt;Alternative Combofix download link [b][url=http://subs.geekstogo.com/ComboFix.exe][color="blue"]HERE[/color][/url][/b].&lt;br&gt;[color="red"][b][u]Note[/u][/b] &lt;br&gt;It is important that it is saved directly to your desktop[/color]&lt;br&gt;&lt;br&gt;Now close any open browsers.&lt;br&gt;Double click on Combofix.exe and follow the prompts. &lt;br&gt;When it's finished it will produce a log. &lt;br&gt;[b]Post the entire contents of C:\ComboFix.txt into your next reply[/b]. &lt;br&gt;[color="red"][b][u]Note[/u][/b] &lt;br&gt;Do not mouseclick combofix's window or do anything else on your pc while it's running. &lt;br&gt;That may cause the program/system to freeze/hang. [/color]&lt;br&gt;Do NOT post the ComboFix-quarantined-files.txt unless I ask.&lt;br&gt;[b][color="RED"][U]Note[/U][/color][/b]&lt;br&gt;In case your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix,please disable your scanner and redownload Combofix again.&lt;br&gt;Some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.&lt;br&gt;&lt;br&gt;[b]Also post a new Hijackthis log please.[/b]</description><pubDate>Thu, 15 May 2008 16:00:44 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>Browser hijack, internet goes down intermitenly.</title><link>http://forum.tweaks.com/forum/Topic239505-29-1.aspx</link><description>I did some cleanups here and there which seemed to help, so I just want to make sure nothing else is infected. Thanks Richie.&lt;P&gt;&lt;STRONG&gt;HijackThis Log:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[quote]&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 4:30:27 PM, on 5/15/2008&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16640)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\eHome\ehRecvr.exe&lt;BR&gt;C:\WINDOWS\eHome\ehSched.exe&lt;BR&gt;C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE&lt;BR&gt;C:\WINDOWS\system32\dllhost.exe&lt;BR&gt;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&lt;BR&gt;C:\WINDOWS\system32\hkcmd.exe&lt;BR&gt;C:\WINDOWS\system32\igfxpers.exe&lt;BR&gt;C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\POS_Exe\pos.exe&lt;BR&gt;C:\WINDOWS\explorer.exe&lt;BR&gt;C:\POS_Exe\SE.exe&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://yahoo.com/"&gt;http://yahoo.com/&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = &lt;BR&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;BR&gt;O2 - BHO: Spybot-S&amp;amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search &amp;amp; Destroy\SDHelper.dll&lt;BR&gt;O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll&lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;BR&gt;O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup&lt;BR&gt;O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start&lt;BR&gt;O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe&lt;BR&gt;O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe&lt;BR&gt;O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"&lt;BR&gt;O4 - HKLM\..\RunOnce: [AAW] "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe" "+b1"&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;BR&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL&lt;BR&gt;O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search &amp;amp; Destroy\SDHelper.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Spybot - Search &amp;amp;&amp;amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search &amp;amp; Destroy\SDHelper.dll&lt;BR&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)&lt;BR&gt;O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - &lt;A href="http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab"&gt;http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - &lt;A href="http://download.bitdefender.com/resources/scan8/oscan8.cab"&gt;http://download.bitdefender.com/resources/scan8/oscan8.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - &lt;A href="http://sdlc-esd.sun.com/ESD40/JSCDL/jre/6u5-b19/jinstall-6u5-windows-i586-jc.cab?AuthParam=1209675775_040763554b314c1c421dbb1727c36ef1&amp;amp;GroupName=JSC&amp;amp;BHost=javadl.sun.com&amp;amp;FilePath=/ESD40/JSCDL/jre/6u5-b19/jinstall-6u5-windows-i586-jc.cab&amp;amp;File=jinstall-6u5-windows-i586-jc.cab"&gt;http://sdlc-esd.sun.com/ESD40/JSCDL/jre/6u5-b19/jinstall-6u5-windows-i586-jc.cab?AuthParam=1209675775_040763554b314c1c421dbb1727c36ef1&amp;amp;GroupName=JSC&amp;amp;BHost=javadl.sun.com&amp;amp;FilePath=/ESD40/JSCDL/jre/6u5-b19/jinstall-6u5-windows-i586-jc.cab&amp;amp;File=jinstall-6u5-windows-i586-jc.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - &lt;A href="http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab"&gt;http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - &lt;A href="http://www.shockwave.com/content/insaniquarium/sis/popcaploader_v10.cab"&gt;http://www.shockwave.com/content/insaniquarium/sis/popcaploader_v10.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - &lt;A href="https://secure.logmein.com/activex/ractrl.cab?lmi=100"&gt;https://secure.logmein.com/activex/ractrl.cab?lmi=100&lt;/A&gt;&lt;BR&gt;O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe&lt;BR&gt;O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 5377 bytes&lt;BR&gt;&lt;/P&gt;&lt;P&gt;[/quote]</description><pubDate>Thu, 15 May 2008 15:34:03 GMT</pubDate><dc:creator>chaldo</dc:creator></item></channel></rss>