﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Tweaks.com Forum  / Windows &amp; System Security / HiJack This Logs  / response to Richie / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>Tweaks.com Forum </description><link>http://forum.tweaks.com/forum/</link><webMaster>forum@tweaks.com</webMaster><lastBuildDate>Sun, 12 Oct 2008 22:43:36 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: response to Richie</title><link>http://forum.tweaks.com/forum/Topic239592-29-1.aspx</link><description>[quote]It gave me BSOD all the time . Same thing applies for ALL antivirus out there that I've tried.[/quote]&lt;br&gt;Obviously you have problems within the operating system.</description><pubDate>Sat, 17 May 2008 11:22:09 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: response to Richie</title><link>http://forum.tweaks.com/forum/Topic239592-29-1.aspx</link><description>It is necessary to download that Avira antivirus? It gave me BSOD all the time :(. Same thing applies for ALL antivirus out there that I've tried. That's why I am using online scanners. Well, I will give you the report after Avira is done.  </description><pubDate>Sat, 17 May 2008 10:34:15 GMT</pubDate><dc:creator>Anwar</dc:creator></item><item><title>RE: response to Richie</title><link>http://forum.tweaks.com/forum/Topic239592-29-1.aspx</link><description>It appears you've no virus protection installed,which is somewhat suicidal.&lt;br&gt;Please download/install [b]Avira AntiVir Personal - FREE Antivirus[/b]: &lt;br&gt;[url]http://www.free-av.com/en/download/1/download_avira_antivir_personal__free_antivirus.html[/url]&lt;br&gt;Perform a full scan with Avira and allow it to delete everything it detects.&lt;br&gt;[b]Restart your pc when you've done.[/b]&lt;br&gt;After restart,open Avira Antivirus and select "Reports".&lt;br&gt;Then double click the report from the full scan you have just completed. &lt;br&gt;Click the "Report File" button,then [b]copy and paste the report into your next reply[/b].&lt;br&gt;&lt;br&gt;&lt;br&gt;[b]If you have previously downloaded ComboFix,please delete that version now.[/b]&lt;br&gt;Download [b][url=http://download.bleepingcomputer.com/sUBs/ComboFix.exe][color="blue"]Combofix[/color][/url][/b] by [b]sUBs[/b] and save to your desktop.&lt;br&gt;Alternative Combofix download link [b][url=http://subs.geekstogo.com/ComboFix.exe][color="blue"]HERE[/color][/url][/b].&lt;br&gt;[color="red"][b][u]Note[/u][/b] &lt;br&gt;It is important that it is saved directly to your desktop[/color]&lt;br&gt;&lt;br&gt;Now close any open browsers.&lt;br&gt;Double click on Combofix.exe and follow the prompts. &lt;br&gt;When it's finished it will produce a log. &lt;br&gt;[b]Post the entire contents of C:\ComboFix.txt into your next reply[/b]. &lt;br&gt;[color="red"][b][u]Note[/u][/b] &lt;br&gt;Do not mouseclick combofix's window or do anything else on your pc while it's running. &lt;br&gt;That may cause the program/system to freeze/hang. [/color]&lt;br&gt;Do NOT post the ComboFix-quarantined-files.txt unless I ask.&lt;br&gt;[b][color="RED"][U]Note[/U][/color][/b]&lt;br&gt;In case your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix,please disable your scanner and redownload Combofix again.&lt;br&gt;Some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.&lt;br&gt;&lt;br&gt;[b]Also post a new Hijackthis log please.[/b]</description><pubDate>Sat, 17 May 2008 03:22:44 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>response to Richie</title><link>http://forum.tweaks.com/forum/Topic239592-29-1.aspx</link><description>Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 8:09:34 PM, on 5/16/2008&lt;BR&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v7.00 (7.00.5730.0011)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\Program Files\UPHClean\uphclean.exe&lt;BR&gt;C:\Program Files\Uniblue\LocalCooling\localcooling2.exe&lt;BR&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.yahoo.com/"&gt;http://www.yahoo.com/&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = &lt;BR&gt;O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - D:\Program Files\Orbitdownloader\orbitcth.dll&lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O4 - Global Startup: LocalCooling.lnk = C:\Program Files\Uniblue\LocalCooling\localcooling2.exe&lt;BR&gt;O8 - Extra context menu item: &amp;amp;Download by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/201&lt;BR&gt;O8 - Extra context menu item: &amp;amp;Grab video by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/204&lt;BR&gt;O8 - Extra context menu item: Do&amp;amp;wnload selected by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/203&lt;BR&gt;O8 - Extra context menu item: Down&amp;amp;load all by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/202&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 2999 bytes&lt;BR&gt;&lt;/P&gt;&lt;P&gt;I've got a very good question: Why is my log clean? :D I will post the deleted ones if you want to...</description><pubDate>Fri, 16 May 2008 18:10:23 GMT</pubDate><dc:creator>Anwar</dc:creator></item></channel></rss>