﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Tweaks.com Forum  / Windows &amp; System Security / HiJack This Logs  / Computer Unbelievably Slow / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>Tweaks.com Forum </description><link>http://forum.tweaks.com/forum/</link><webMaster>forum@tweaks.com</webMaster><lastBuildDate>Thu, 20 Nov 2008 03:30:32 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: Computer Unbelievably Slow</title><link>http://forum.tweaks.com/forum/Topic239752-29-1.aspx</link><description>[quote]Can you give me directions to reformat the Dell cpu, I just don't remember how I did it?[/quote]&lt;br&gt;I suggest you start a new topic in the forum below.&lt;br&gt;[b]Hardware &amp; Driver Support:[/b]&lt;br&gt;[url]http://forum.tweaks.com/forum/Forum4-1.aspx[/url]</description><pubDate>Mon, 07 Jul 2008 18:08:51 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Computer Unbelievably Slow</title><link>http://forum.tweaks.com/forum/Topic239752-29-1.aspx</link><description>Actually, I was thinking 15 minutes for a boot up is still too long.  Unfortunately, the problem carries over to running processes while the cpu is booted.  I'm still having problems with delays when I start up programs.  I remember I reformatted my own Dell laptop a while ago by pressing a certain button during startup (I didn't need a cd or anything).  Can you give me directions to reformat the Dell cpu, I just don't remember how I did it?  Thanks.</description><pubDate>Mon, 07 Jul 2008 17:50:40 GMT</pubDate><dc:creator>numba1v</dc:creator></item><item><title>RE: Computer Unbelievably Slow</title><link>http://forum.tweaks.com/forum/Topic239752-29-1.aspx</link><description>Click on Start/Run,type [b]msconfig[/b] then press Ok&lt;br&gt;In the 'System Configuration Utility' click to select "[b]Normal Startup-load all device drivers and services[/b]".&lt;br&gt;Press Apply/OK,restart your pc when prompted.&lt;br&gt;&lt;br&gt;If all's now OK,you should do the following:&lt;br&gt;You should now take the time to read and follow the information found in the links below,to help you prevent any possible future infections and stay safe and secure while online:&lt;br&gt;&lt;br&gt;[b][color="blue"]Simple and easy ways to keep your computer safe and secure on the Internet[/color][/b]:&lt;br&gt;[url]http://www.bleepingcomputer.com/tutorials/tutorial82.html[/url]&lt;br&gt;&lt;br&gt;[b][color="blue"]How to prevent Malware[/color][/b]:&lt;br&gt;[url]http://users.telenet.be/bluepatchy/miekiemoes/prevention.html[/url]&lt;br&gt;&lt;br&gt;[B][color="blue"]So how did I get infected in the first place[/color][/B]:&lt;br&gt;[URL]http://forums.spybot.info/showthread.php?t=279[/URL]&lt;br&gt;&lt;br&gt;[B][color="blue"]Malware Cleanup Programs and Preventative Procedures[/color][/B]: &lt;br&gt;[URL]http://russelltexas.com/malware/allclear.htm[/URL]&lt;br&gt;&lt;br&gt;[B][color="blue"]How to Set Security Options in the Firefox Browser[/color][/B]:&lt;br&gt;[URL]http://websearch.about.com/od/firefox/ss/firefoxoptions.htm[/URL]&lt;br&gt;&lt;br&gt;[B][color="blue"]Internet Explorer 7 Desktop Security Guide[/color][/B]:&lt;br&gt;[URL]http://www.microsoft.com/downloads/details.aspx?FamilyID=6aa4c1da-6021-468e-a8cf-af4afe4c84b2&amp;DisplayLang=en[/URL]&lt;br&gt;&lt;br&gt;[B][color="blue"]Working with Internet Explorer 6 Security Settings[/color][/B]:&lt;br&gt;[URL]http://www.microsoft.com/windows/ie/ie6/using/howto/security/settings.mspx[/URL]&lt;br&gt;&lt;br&gt;[b][color="blue"]Hardening Windows Security - Part 1[/color][/b]:&lt;br&gt;[url]http://www.malwarehelp.org/Malware-Prevention-Hardening-Windows-Security1.html[/url]&lt;br&gt;&lt;br&gt;[b][color="blue"]Hardening Windows Security - Part 2[/color][/b]:&lt;br&gt;[url]http://www.malwarehelp.org/malware-prevention-hardening-windows-security2.html[/url]</description><pubDate>Mon, 07 Jul 2008 02:06:02 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Computer Unbelievably Slow</title><link>http://forum.tweaks.com/forum/Topic239752-29-1.aspx</link><description>I just disabled/unchecked all the items that you told me to and for some reason, the start up took 15 minutes.  Next, I just put the check mark back into the SYSTEM.INF option and it took another 15 minutes.  Please let me know if I should continue adding the checkmarks one by one and restarting each time.  The reason I am giving you the update is because I assume the start up issue would've been resolved if I disabled everything.</description><pubDate>Sun, 06 Jul 2008 19:13:02 GMT</pubDate><dc:creator>numba1v</dc:creator></item><item><title>RE: Computer Unbelievably Slow</title><link>http://forum.tweaks.com/forum/Topic239752-29-1.aspx</link><description>[quote]Computer is definitely running better than before but I still think it might be a little too slow than it should be.[/quote]&lt;br&gt;Try doing a [b]Selective Startup[/b],it may narrow it down as to what may be causing the problem.&lt;br&gt;Click on Start&gt;Run,type [b]msconfig[/b] then press Ok.&lt;br&gt;In the System Configuration Utility dialog box, click the General tab, and then click Selective Startup.&lt;br&gt;Click to clear the Process SYSTEM.INI File check box.&lt;br&gt;Click to clear the Process WIN.INI File check box.&lt;br&gt;Click to clear the Load Startup Items check box.&lt;br&gt;Click the Services tab.&lt;br&gt;Click to select the Hide All Microsoft Services check box.&lt;br&gt;Click Disable All, and then click OK.&lt;br&gt;When you are prompted, click Restart to restart the computer.&lt;br&gt;Starting with the first available check box: 'Process SYSTEM.INI File'.&lt;br&gt;Select each check box [b]one at a time[/b], and restart the computer as prompted until the problem is reproduced.&lt;br&gt;Doing this you should be able to find out whats causing your issue.&lt;br&gt;&lt;br&gt;Once the problem reappears, click the tab that corresponds to the selected file.&lt;br&gt;For example,if the problem reappears after selecting the Win.ini file,click the WIN.INI tab in System Configuration Utility.</description><pubDate>Fri, 04 Jul 2008 02:47:25 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Computer Unbelievably Slow</title><link>http://forum.tweaks.com/forum/Topic239752-29-1.aspx</link><description>Sorry about this extremely late reply.  I haven't had time to work on this cpu but here is the report for that Avira Anti-Virus scan.  Thanks.&lt;/P&gt;&lt;P&gt;Avira AntiVir Personal&lt;BR&gt;Report file date: Thursday, July 03, 2008  19:07&lt;/P&gt;&lt;P&gt;Scanning for 1376780 virus strains and unwanted programs.&lt;/P&gt;&lt;P&gt;Licensed to:      Avira AntiVir PersonalEdition Classic&lt;BR&gt;Serial number:    0000149996-ADJIE-0001&lt;BR&gt;Platform:         Windows XP&lt;BR&gt;Windows version:  (Service Pack 2)  [5.1.2600]&lt;BR&gt;Boot mode:        Normally booted&lt;BR&gt;Username:         SYSTEM&lt;BR&gt;Computer name:    MIKE-56517E2DD3&lt;/P&gt;&lt;P&gt;Version information:&lt;BR&gt;BUILD.DAT     : 8.1.00.295      16479 Bytes    4/9/2008 16:24:00&lt;BR&gt;AVSCAN.EXE    : 8.1.2.12       311553 Bytes   3/18/2008 15:02:56&lt;BR&gt;AVSCAN.DLL    : 8.1.1.0         53505 Bytes    2/7/2008 14:43:37&lt;BR&gt;LUKE.DLL      : 8.1.2.9        151809 Bytes   2/28/2008 14:41:23&lt;BR&gt;LUKERES.DLL   : 8.1.2.1         12033 Bytes   2/21/2008 14:28:40&lt;BR&gt;ANTIVIR0.VDF  : 6.40.0.0     11030528 Bytes   7/18/2007 16:33:34&lt;BR&gt;ANTIVIR1.VDF  : 7.0.5.1       8182784 Bytes   6/24/2008 23:04:22&lt;BR&gt;ANTIVIR2.VDF  : 7.0.5.20       142336 Bytes   6/30/2008 23:04:25&lt;BR&gt;ANTIVIR3.VDF  : 7.0.5.45       115712 Bytes    7/3/2008 23:04:27&lt;BR&gt;Engineversion : 8.1.0.64  &lt;BR&gt;AEVDF.DLL     : 8.1.0.5        102772 Bytes   2/25/2008 15:58:21&lt;BR&gt;AESCRIPT.DLL  : 8.1.0.46       283002 Bytes    7/3/2008 23:04:52&lt;BR&gt;AESCN.DLL     : 8.1.0.22       119157 Bytes    7/3/2008 23:04:50&lt;BR&gt;AERDL.DLL     : 8.1.0.20       418165 Bytes    7/3/2008 23:04:49&lt;BR&gt;AEPACK.DLL    : 8.1.1.6        364918 Bytes    7/3/2008 23:04:46&lt;BR&gt;AEOFFICE.DLL  : 8.1.0.20       192891 Bytes    7/3/2008 23:04:43&lt;BR&gt;AEHEUR.DLL    : 8.1.0.35      1298806 Bytes    7/3/2008 23:04:41&lt;BR&gt;AEHELP.DLL    : 8.1.0.15       115063 Bytes    7/3/2008 23:04:35&lt;BR&gt;AEGEN.DLL     : 8.1.0.29       307573 Bytes    7/3/2008 23:04:34&lt;BR&gt;AEEMU.DLL     : 8.1.0.6        430451 Bytes    7/3/2008 23:04:31&lt;BR&gt;AECORE.DLL    : 8.1.0.32       168311 Bytes    7/3/2008 23:04:29&lt;BR&gt;AVWINLL.DLL   : 1.0.0.7         14593 Bytes   1/23/2008 23:07:53&lt;BR&gt;AVPREF.DLL    : 8.0.0.1         25857 Bytes   2/18/2008 16:37:50&lt;BR&gt;AVREP.DLL     : 7.0.0.1        155688 Bytes   4/16/2007 19:26:47&lt;BR&gt;AVREG.DLL     : 8.0.0.0         30977 Bytes   1/23/2008 23:07:49&lt;BR&gt;AVARKT.DLL    : 1.0.0.23       307457 Bytes   2/12/2008 14:29:23&lt;BR&gt;AVEVTLOG.DLL  : 8.0.0.11       114945 Bytes   2/28/2008 14:31:31&lt;BR&gt;SQLITE3.DLL   : 3.3.17.1       339968 Bytes   1/22/2008 23:28:02&lt;BR&gt;SMTPLIB.DLL   : 1.2.0.19        28929 Bytes   1/23/2008 23:08:39&lt;BR&gt;NETNT.DLL     : 8.0.0.1          7937 Bytes   1/25/2008 18:05:10&lt;BR&gt;RCIMAGE.DLL   : 8.0.0.35      2371841 Bytes   3/10/2008 20:37:25&lt;BR&gt;RCTEXT.DLL    : 8.0.32.0        86273 Bytes    3/6/2008 18:02:11&lt;/P&gt;&lt;P&gt;Configuration settings for the scan:&lt;BR&gt;Jobname..........................: Complete system scan&lt;BR&gt;Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp&lt;BR&gt;Logging..........................: low&lt;BR&gt;Primary action...................: interactive&lt;BR&gt;Secondary action.................: ignore&lt;BR&gt;Scan master boot sector..........: on&lt;BR&gt;Scan boot sector.................: on&lt;BR&gt;Boot sectors.....................: C:, &lt;BR&gt;Scan memory......................: on&lt;BR&gt;Process scan.....................: on&lt;BR&gt;Scan registry....................: on&lt;BR&gt;Search for rootkits..............: off&lt;BR&gt;Scan all files...................: Intelligent file selection&lt;BR&gt;Scan archives....................: on&lt;BR&gt;Recursion depth..................: 20&lt;BR&gt;Smart extensions.................: on&lt;BR&gt;Macro heuristic..................: on&lt;BR&gt;File heuristic...................: medium&lt;/P&gt;&lt;P&gt;Start of the scan: Thursday, July 03, 2008  19:07&lt;/P&gt;&lt;P&gt;The scan of running processes will be started&lt;BR&gt;Scan process 'avscan.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'avcenter.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'sched.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'avgnt.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'avguard.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'wuauclt.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'V CAST Music Monitor.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'ctfmon.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'jusched.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'apdproxy.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'Dit.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'ZuneLauncher.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'GrooveMonitor.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'atiptaxx.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'alg.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'ZuneNss.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'RegSrvc.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'scardsvr.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'spoolsv.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'aawservice.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'WLKEEPER.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'explorer.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'S24EvMon.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'EvtEng.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'lsass.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'services.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'winlogon.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'csrss.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'smss.exe' - '1' Module(s) have been scanned&lt;BR&gt;41 processes with 41 modules were scanned&lt;/P&gt;&lt;P&gt;Starting master boot sector scan:&lt;BR&gt;Master boot sector HD0&lt;BR&gt;      [INFO]      No virus was found!&lt;/P&gt;&lt;P&gt;Start scanning boot sectors:&lt;BR&gt;Boot sector 'C:\'&lt;BR&gt;      [INFO]      No virus was found!&lt;/P&gt;&lt;P&gt;Starting to scan the registry.&lt;BR&gt;The registry was scanned ( '28' files ).&lt;/P&gt;&lt;P&gt;&lt;BR&gt;Starting the file scan:&lt;/P&gt;&lt;P&gt;Begin scan in 'C:\'&lt;BR&gt;C:\pagefile.sys&lt;BR&gt;      [WARNING]   The file could not be opened!&lt;/P&gt;&lt;P&gt;&lt;BR&gt;End of the scan: Thursday, July 03, 2008  20:55&lt;BR&gt;Used time:  1:48:11 min&lt;/P&gt;&lt;P&gt;The scan has been done completely.&lt;/P&gt;&lt;P&gt;   2717 Scanning directories&lt;BR&gt; 116756 Files were scanned&lt;BR&gt;      0 viruses and/or unwanted programs were found&lt;BR&gt;      0 Files were classified as suspicious:&lt;BR&gt;      0 files were deleted&lt;BR&gt;      0 files were repaired&lt;BR&gt;      0 files were moved to quarantine&lt;BR&gt;      0 files were renamed&lt;BR&gt;      1 Files cannot be scanned&lt;BR&gt; 116756 Files not concerned&lt;BR&gt;    957 Archives were scanned&lt;BR&gt;      1 Warnings&lt;BR&gt;      0 Notes</description><pubDate>Thu, 03 Jul 2008 23:25:42 GMT</pubDate><dc:creator>numba1v</dc:creator></item><item><title>RE: Computer Unbelievably Slow</title><link>http://forum.tweaks.com/forum/Topic239752-29-1.aspx</link><description>You've no virus protection installed.&lt;br&gt;Please download/install [b]Avira AntiVir Personal - FREE Antivirus[/b]: &lt;br&gt;[url]http://www.free-av.com/en/download/1/download_avira_antivir_personal__free_antivirus.html[/url]&lt;br&gt;Perform a full scan with Avira and allow it to delete everything it detects.&lt;br&gt;[b]Restart your pc when you've done.[/b]&lt;br&gt;After restart,open Avira Antivirus and select "Reports".&lt;br&gt;Then double click the report from the full scan you have just completed. &lt;br&gt;Click the "Report File" button,then [b]copy and paste the report into your next reply[/b].</description><pubDate>Fri, 23 May 2008 13:30:54 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Computer Unbelievably Slow</title><link>http://forum.tweaks.com/forum/Topic239752-29-1.aspx</link><description>Computer is definitely running better than before but I still think it might be a little too slow than it should be.  When the computer loads up when i turn it on or restart still takes really long.  Here are the reports, starting with the Malware scan first.&lt;/P&gt;&lt;P&gt;Malwarebytes' Anti-Malware 1.12&lt;BR&gt;Database version: 781&lt;/P&gt;&lt;P&gt;Scan type: Quick Scan&lt;BR&gt;Objects scanned: 34984&lt;BR&gt;Time elapsed: 1 hour(s), 3 minute(s), 20 second(s)&lt;/P&gt;&lt;P&gt;Memory Processes Infected: 0&lt;BR&gt;Memory Modules Infected: 0&lt;BR&gt;Registry Keys Infected: 0&lt;BR&gt;Registry Values Infected: 0&lt;BR&gt;Registry Data Items Infected: 0&lt;BR&gt;Folders Infected: 0&lt;BR&gt;Files Infected: 0&lt;/P&gt;&lt;P&gt;Memory Processes Infected:&lt;BR&gt;(No malicious items detected)&lt;/P&gt;&lt;P&gt;Memory Modules Infected:&lt;BR&gt;(No malicious items detected)&lt;/P&gt;&lt;P&gt;Registry Keys Infected:&lt;BR&gt;(No malicious items detected)&lt;/P&gt;&lt;P&gt;Registry Values Infected:&lt;BR&gt;(No malicious items detected)&lt;/P&gt;&lt;P&gt;Registry Data Items Infected:&lt;BR&gt;(No malicious items detected)&lt;/P&gt;&lt;P&gt;Folders Infected:&lt;BR&gt;(No malicious items detected)&lt;/P&gt;&lt;P&gt;Files Infected:&lt;BR&gt;(No malicious items detected)&lt;BR&gt;&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 1:49:37 PM, on 5/23/2008&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\Program Files\Intel\Wireless\Bin\EvtEng.exe&lt;BR&gt;C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe&lt;BR&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe&lt;BR&gt;C:\WINDOWS\system32\wscntfy.exe&lt;BR&gt;C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&lt;BR&gt;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&lt;BR&gt;C:\Program Files\Zune\ZuneLauncher.exe&lt;BR&gt;C:\WINDOWS\Dit.exe&lt;BR&gt;C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe&lt;BR&gt;C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\wuauclt.exe&lt;BR&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &lt;A href="http://windowsupdate.microsoft.com/"&gt;http://windowsupdate.microsoft.com/&lt;/A&gt;&lt;BR&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;BR&gt;O2 - BHO: Spybot-S&amp;amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;BR&gt;O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL&lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll&lt;BR&gt;O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"&lt;BR&gt;O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"&lt;BR&gt;O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"&lt;BR&gt;O4 - HKLM\..\Run: [CICache] CICache.exe&lt;BR&gt;O4 - HKLM\..\Run: [Dit] Dit.exe&lt;BR&gt;O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;BR&gt;O4 - Startup: V CAST Music Monitor.lnk = C:\Program Files\Verizon Wireless\V CAST Music\V CAST Music Monitor.exe&lt;BR&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: S&amp;amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll&lt;BR&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL&lt;BR&gt;O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Spybot - Search &amp;amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll&lt;BR&gt;O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - &lt;A href="http://upload.facebook.com/controls/FacebookPhotoUploader.cab"&gt;http://upload.facebook.com/controls/FacebookPhotoUploader.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - &lt;A href="http://go.divx.com/plugin/DivXBrowserPlugin.cab"&gt;http://go.divx.com/plugin/DivXBrowserPlugin.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - &lt;A href="http://www.vzwpix.com/activex/VerizonWirelessUploadControl.cab"&gt;http://www.vzwpix.com/activex/VerizonWirelessUploadControl.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - &lt;A href="http://www.adobe.com/products/acrobat/nos/gp.cab"&gt;http://www.adobe.com/products/acrobat/nos/gp.cab&lt;/A&gt;&lt;BR&gt;O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL&lt;BR&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;BR&gt;O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;BR&gt;O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;BR&gt;O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe&lt;BR&gt;O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;BR&gt;O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe&lt;BR&gt;O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe&lt;BR&gt;O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 6334 bytes&lt;BR&gt;</description><pubDate>Fri, 23 May 2008 12:52:44 GMT</pubDate><dc:creator>numba1v</dc:creator></item><item><title>RE: Computer Unbelievably Slow</title><link>http://forum.tweaks.com/forum/Topic239752-29-1.aspx</link><description>&lt;br&gt;Click on Start/Run,copy and paste [b]ComboFix /u[/b] into the '[u]O[/u]pen:' space,then press OK.&lt;br&gt;This will uninstall Combofix,delete its related folders and files,reset your clock settings,hide file extensions,hide the system/hidden files and resets System Restore.&lt;br&gt;&lt;br&gt;[IMG]http://img.photobucket.com/albums/v624/29wood/comu.gif[/IMG]&lt;br&gt;&lt;br&gt;&lt;br&gt;[b]Enable the viewing of hidden files and folders,reverse the process once you've done below:[/b]&lt;br&gt;[url]http://www.bleepingcomputer.com/tutorials/tutorial62.html[/url]&lt;br&gt;&lt;br&gt;[b]Please disable Spybot S&amp;D’s protection,or it will interfere.&lt;br&gt;You can enable it after you're clean.[/b]&lt;br&gt;Open Spybot and click on 'Mode' and check 'Advanced Mode'.&lt;br&gt;Click on 'Tools' in bottom left hand corner.&lt;br&gt;Click on the 'System Startup' icon.&lt;br&gt;Uncheck 'Teatimer' box and/or uncheck 'Resident'.&lt;br&gt;Click the 'Allow Change' box.&lt;br&gt;Then, check next to the computer clock to see if the icon for Spybot is still there.&lt;br&gt;If it is, right click it and choose 'exit Spybot-S&amp;D Resident'.&lt;br&gt;[b]Restart the computer.[/b]&lt;br&gt;If you find you're experiencing problems disabling Spybot's Tea-Timer,follow the info in the link below:&lt;br&gt;[url]http://www.russelltexas.com/malware/teatimer.htm[/url]&lt;br&gt;&lt;br&gt;Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'. &lt;br&gt;Make sure all browser and all Windows Explorer windows are closed before fixing:&lt;br&gt;[b]O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)[/b]&lt;br&gt;&lt;br&gt;Find and delete:&lt;br&gt;C:\Program Files\[b]Viewpoint[/b]&lt;br&gt;C:\Documents and Settings\All Users\Application Data\[b]Viewpoint[/b]&lt;br&gt;&lt;br&gt;&lt;br&gt;Please download [b][color="red"]Malwarebytes Anti-Malware[/color][/b]:&lt;br&gt;[url]http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html[/url]&lt;br&gt;[url]http://www.besttechie.net/tools/mbam-setup.exe[/url]&lt;br&gt;&lt;br&gt;Double Click mbam-setup.exe to install the application.&lt;br&gt;(If using Windows Vista,be sure to [b][url=http://windowshelp.microsoft.com/Windows/en-US/Help/fb464905-31d5-4427-89a2-ed5322327fc21033.mspx][color="blue"]"Run As Administrator"[/color][/url][/b]).&lt;br&gt;&lt;br&gt;* Make sure a checkmark is placed next to [b]Update Malwarebytes' Anti-Malware[/b] and [b]Launch Malwarebytes' Anti-Malware[/b], then click Finish.&lt;br&gt;* If an update is found, it will download and install the latest version.&lt;br&gt;* Once the program has loaded, select "Perform Quick Scan", then click Scan.&lt;br&gt;* The scan may take some time to finish,so please be patient.&lt;br&gt;* When the scan is complete, click OK, then Show Results to view the results.&lt;br&gt;* Make sure that everything is checked, and click Remove Selected.&lt;br&gt;* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)&lt;br&gt;* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.&lt;br&gt;* [b]Copy and paste the entire report into your next reply[/b].&lt;br&gt;&lt;br&gt;Extra Note:&lt;br&gt;[b][color="green"]If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.[/color][/b]&lt;br&gt;&lt;br&gt;[b]Also post a new Hijackthis log,let me know how your pc is running now.[/b]</description><pubDate>Fri, 23 May 2008 02:18:07 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Computer Unbelievably Slow</title><link>http://forum.tweaks.com/forum/Topic239752-29-1.aspx</link><description>While I was running the combofix scan, I got alerts about registry changes from Teatimer from Spybot.  I allowed all the changes but if you think I should disable Teatimer and rerun the scan, please let me know.  If not, here are the ComboFix and HijackThis results.&lt;/P&gt;&lt;P&gt;ComboFix 08-05-21.3 - Administrator 2008-05-22 21:49:52.1 - NTFSx86&lt;BR&gt;Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.180 [GMT -4:00]&lt;BR&gt;Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe&lt;/P&gt;&lt;P&gt;[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;C:\WINDOWS\Downloaded Program Files\setup.inf&lt;/P&gt;&lt;P&gt;.&lt;BR&gt;(((((((((((((((((((((((((   Files Created from 2008-04-23 to 2008-05-23  )))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;2008-05-22 21:41 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl&lt;BR&gt;2008-05-22 21:33 . 2008-05-22 21:41 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Java&lt;BR&gt;2008-05-22 21:32 . 2008-05-22 21:32 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\Java&lt;BR&gt;2008-05-19 15:22 . 2008-05-19 15:22 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Trend Micro&lt;BR&gt;2008-05-19 15:18 . 2008-05-19 15:18 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com&lt;BR&gt;2008-05-19 15:16 . 2008-05-19 15:17 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\SUPERAntiSpyware&lt;BR&gt;2008-05-19 15:16 . 2008-05-19 15:16 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com&lt;BR&gt;2008-05-18 22:41 . 2008-05-22 19:17 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\CCleaner&lt;BR&gt;2008-05-18 17:52 . 2008-05-18 17:52 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Lavasoft&lt;BR&gt;2008-05-18 17:52 . 2008-05-18 17:52 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft&lt;BR&gt;2008-05-18 17:47 . 2008-05-19 15:07 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\Wise Installation Wizard&lt;BR&gt;2008-05-18 16:54 . 2008-05-18 16:54 176 --a------ C:\WINDOWS\wininit.ini&lt;/P&gt;&lt;P&gt;.&lt;BR&gt;((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;BR&gt;2008-05-22 23:27 13,568 ----a-w C:\WINDOWS\system32\drivers\USBCRFT.SYS&lt;BR&gt;2008-05-22 22:53 --------- d-----w C:\Program Files\Microsoft Silverlight&lt;BR&gt;2008-05-18 21:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search &amp;amp; Destroy&lt;BR&gt;2008-05-18 20:58 --------- d-----w C:\Program Files\Spybot - Search &amp;amp; Destroy&lt;BR&gt;2008-05-18 20:54 --------- d-----w C:\Program Files\DivX&lt;BR&gt;2008-05-18 20:47 --------- d-----w C:\Program Files\Viewpoint&lt;BR&gt;2008-05-18 20:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint&lt;BR&gt;2008-05-18 20:46 --------- d-----w C:\Program Files\QuickTime&lt;BR&gt;2008-05-18 20:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL&lt;BR&gt;2008-05-16 15:07 --------- d-----w C:\Documents and Settings\Administrator\Application Data\LimeWire&lt;BR&gt;2008-05-16 01:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help&lt;BR&gt;2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll&lt;BR&gt;2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;BR&gt;.&lt;BR&gt;*Note* empty entries &amp;amp; legit default entries are not shown &lt;BR&gt;REGEDIT4&lt;/P&gt;&lt;P&gt;[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]&lt;BR&gt;"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-15 12:52 68856]&lt;BR&gt;"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search &amp;amp; Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-11-10 22:05 344064]&lt;BR&gt;"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]&lt;BR&gt;"Zune Launcher"="C:\Program Files\Zune\ZuneLauncher.exe" [2007-03-14 17:03 24104]&lt;BR&gt;"CICache"="CICache.exe" [2002-09-05 14:21 24576 C:\WINDOWS\CICache.exe]&lt;BR&gt;"Dit"="Dit.exe" [2004-04-27 14:34 86016 C:\WINDOWS\Dit.exe]&lt;BR&gt;"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09 63712]&lt;BR&gt;"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]&lt;/P&gt;&lt;P&gt;C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\&lt;BR&gt;V CAST Music Monitor.lnk - C:\Program Files\Verizon Wireless\V CAST Music\V CAST Music Monitor.exe [2005-11-30 11:32:10 327680]&lt;/P&gt;&lt;P&gt;[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]&lt;BR&gt;"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]&lt;BR&gt;C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]&lt;BR&gt;--a------ 2006-10-18 18:58 696320 C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]&lt;BR&gt;--a------ 2006-10-18 19:04 802816 C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe&lt;/P&gt;&lt;P&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]&lt;BR&gt;"%windir%\\system32\\sessmgr.exe"=&lt;BR&gt;"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=&lt;BR&gt;"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=&lt;BR&gt;"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=&lt;BR&gt;"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=&lt;BR&gt;"C:\\Program Files\\LimeWire\\LimeWire.exe"=&lt;/P&gt;&lt;P&gt;R3 OZSCR;O2Micro SmartCardBus Smartcard Reader;C:\WINDOWS\system32\DRIVERS\ozscr.sys [2005-04-21 22:58]&lt;BR&gt;S3 CardReaderFilter;Card Reader Filter;C:\WINDOWS\system32\Drivers\USBCRFT.SYS [2008-05-22 19:27]&lt;/P&gt;&lt;P&gt;[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{61323b30-deba-11db-b458-000e35afb3e3}]&lt;BR&gt;\Shell\AutoRun\command - E:\JDSecure\Windows\JDSecure31.exe&lt;/P&gt;&lt;P&gt;*Newly Created Service* - CATCHME&lt;BR&gt;.&lt;BR&gt;Contents of the 'Scheduled Tasks' folder&lt;BR&gt;"2007-06-24 14:05:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"&lt;BR&gt;- C:\Program Files\Apple Software Update\SoftwareUpdate.exe&lt;BR&gt;.&lt;BR&gt;**************************************************************************&lt;/P&gt;&lt;P&gt;catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &lt;A href="http://www.gmer.net"&gt;http://www.gmer.net&lt;/A&gt;&lt;BR&gt;Rootkit scan 2008-05-22 21:57:40&lt;BR&gt;Windows 5.1.2600 Service Pack 2 NTFS&lt;/P&gt;&lt;P&gt;scanning hidden processes ... &lt;/P&gt;&lt;P&gt;scanning hidden autostart entries ...&lt;/P&gt;&lt;P&gt;scanning hidden files ... &lt;/P&gt;&lt;P&gt;scan completed successfully&lt;BR&gt;hidden files: 0&lt;/P&gt;&lt;P&gt;**************************************************************************&lt;BR&gt;.&lt;BR&gt;Completion time: 2008-05-22 22:02:19&lt;BR&gt;ComboFix-quarantined-files.txt  2008-05-23 02:02:06&lt;/P&gt;&lt;P&gt;Pre-Run: 43,048,996,864 bytes free&lt;BR&gt;Post-Run: 43,082,571,776 bytes free&lt;/P&gt;&lt;P&gt;99 --- E O F --- 2008-05-22 22:53:31&lt;BR&gt;&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 10:05:35 PM, on 5/22/2008&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\Program Files\Intel\Wireless\Bin\EvtEng.exe&lt;BR&gt;C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe&lt;BR&gt;C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe&lt;BR&gt;C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;BR&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe&lt;BR&gt;C:\WINDOWS\system32\wscntfy.exe&lt;BR&gt;C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&lt;BR&gt;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&lt;BR&gt;C:\Program Files\Zune\ZuneLauncher.exe&lt;BR&gt;C:\WINDOWS\Dit.exe&lt;BR&gt;C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;BR&gt;C:\Program Files\Spybot - Search &amp;amp; Destroy\TeaTimer.exe&lt;BR&gt;C:\Program Files\Verizon Wireless\V CAST Music\V CAST Music Monitor.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\wuauclt.exe&lt;BR&gt;C:\WINDOWS\explorer.exe&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &lt;A href="http://windowsupdate.microsoft.com/"&gt;http://windowsupdate.microsoft.com/&lt;/A&gt;&lt;BR&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;BR&gt;O2 - BHO: Spybot-S&amp;amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;BR&gt;O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL&lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll&lt;BR&gt;O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)&lt;BR&gt;O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"&lt;BR&gt;O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"&lt;BR&gt;O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"&lt;BR&gt;O4 - HKLM\..\Run: [CICache] CICache.exe&lt;BR&gt;O4 - HKLM\..\Run: [Dit] Dit.exe&lt;BR&gt;O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;BR&gt;O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp;amp; Destroy\TeaTimer.exe&lt;BR&gt;O4 - Startup: V CAST Music Monitor.lnk = C:\Program Files\Verizon Wireless\V CAST Music\V CAST Music Monitor.exe&lt;BR&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: S&amp;amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll&lt;BR&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL&lt;BR&gt;O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Spybot - Search &amp;amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll&lt;BR&gt;O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - &lt;A href="http://upload.facebook.com/controls/FacebookPhotoUploader.cab"&gt;http://upload.facebook.com/controls/FacebookPhotoUploader.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - &lt;A href="http://go.divx.com/plugin/DivXBrowserPlugin.cab"&gt;http://go.divx.com/plugin/DivXBrowserPlugin.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - &lt;A href="http://www.vzwpix.com/activex/VerizonWirelessUploadControl.cab"&gt;http://www.vzwpix.com/activex/VerizonWirelessUploadControl.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - &lt;A href="http://www.adobe.com/products/acrobat/nos/gp.cab"&gt;http://www.adobe.com/products/acrobat/nos/gp.cab&lt;/A&gt;&lt;BR&gt;O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL&lt;BR&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;BR&gt;O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;BR&gt;O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;BR&gt;O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe&lt;BR&gt;O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;BR&gt;O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe&lt;BR&gt;O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe&lt;BR&gt;O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 6657 bytes&lt;BR&gt;</description><pubDate>Thu, 22 May 2008 21:11:20 GMT</pubDate><dc:creator>numba1v</dc:creator></item><item><title>RE: Computer Unbelievably Slow</title><link>http://forum.tweaks.com/forum/Topic239752-29-1.aspx</link><description>Welcome:)&lt;br&gt;&lt;br&gt;[b]Clear your 'System Restore' points by doing the following: [/b]&lt;br&gt;Right-click on 'My Computer' and select 'Properties'. &lt;br&gt;Select 'System Restore'. &lt;br&gt;Select 'Turn Off System Restore On All Drives'. &lt;br&gt;Select 'Apply'. &lt;br&gt;You will then get the following warning:&lt;br&gt;"You have chosen to turn off System Restore.&lt;br&gt;If you continue,all existing restore points will be deleted,and you will not be able to track or undo changes to your computer.&lt;br&gt;Do you want to turn off System Restore?".&lt;br&gt;Then select 'Yes',your 'System Restore' directories will be purged. &lt;br&gt;&lt;br&gt;[b]Turn 'System Restore' back on:[/b]&lt;br&gt;Right click on 'My Computer' and select 'Properties'. &lt;br&gt;Select 'System Restore'. &lt;br&gt;[b]Unselect[/b] 'Turn Off System Restore On All Drives'. &lt;br&gt;Select 'Apply',then click 'Ok'.&lt;br&gt;&lt;br&gt;&lt;br&gt;Download and scan with [b][color="red"]CCleaner[/color][/b]:&lt;br&gt;[url]http://www.ccleaner.com/downloadbuilds.asp[/url]&lt;br&gt;1. Starting with v1.27.260, CCleaner installs the [b]Yahoo Toolbar[/b] as an option which IS checkmarked by default during the installation. IF you do NOT want it, REMOVE the checkmark when provided with the option OR download the toolbar-free Basic or Slim versions instead of the Standard Build.&lt;br&gt;&lt;br&gt;2. Before first use, select Options &gt; Advanced and UNCHECK [b]"Only delete files in Windows Temp folder older than 48 hours"[/b]&lt;br&gt;&lt;br&gt;3. Then select the items you wish to clean up.&lt;br&gt;&lt;br&gt;[b]In the Windows Tab:[/b]&lt;br&gt;* Clean all entries in the "Internet Explorer" section except Cookies.&lt;br&gt;* Clean all the entries in the "Windows Explorer" section.&lt;br&gt;* Clean all entries in the "System" section.&lt;br&gt;* Clean all entries in the "Advanced" section.&lt;br&gt;* Clean any others that you choose.&lt;br&gt;&lt;br&gt;[b]In the Applications Tab:[/b]&lt;br&gt;* Clean all except cookies in the Firefox/Mozilla section if you use it.&lt;br&gt;* Clean all in the Opera section if you use it.&lt;br&gt;* Clean Sun Java in the Internet Section.&lt;br&gt;* Clean any others that you choose.&lt;br&gt;&lt;br&gt;4. Click the "Run Cleaner" button.&lt;br&gt;5. A pop up box will appear advising this process will permanently delete files from your system.&lt;br&gt;6. Click "OK" and it will scan and clean your system.&lt;br&gt;&lt;br&gt;* Now click on the '[b]Registry[/b]' tab/button on the left.&lt;br&gt;* Then click on the 'Scan for issues' button at the bottom.&lt;br&gt;* If CCleaner displays any issues,click on 'Fix selected issues'.&lt;br&gt;* You'll then be asked 'Do you want to backup changes to the registry',you [b]must[/b] click '[b]YES[/b]'.&lt;br&gt;* Save the backup somewhere safe,your desktop is a good a place as any.&lt;br&gt;* Then click 'Fix Issues',then click 'Close'.&lt;br&gt;* Exit CCleaner.&lt;br&gt;&lt;br&gt;&lt;br&gt;Your version of [b]Sun Java[/b] is out of date.&lt;br&gt;Older versions have vulnerabilities that malware can use to infect your system.&lt;br&gt;Please follow these steps to remove older versions of Sun Java,and then update.&lt;br&gt;1. Download the latest version of [b][url=http://java.sun.com/javase/downloads/index.jsp][color="blue"]Java Runtime Environment (JRE)[/color][/url][/b]&lt;br&gt;2. Scroll down to where it says '[b]Java Runtime Environment (JRE) 6u6[/b]'.&lt;br&gt;3. Click the "Download" button to the right.&lt;br&gt;4. Select the Platform and Language for your download,then check the box that says: "Accept License Agreement".&lt;br&gt;5. The page will refresh.&lt;br&gt;6. Click on the link to download [b]'Windows Offline Installation, Multi-language - jre-6u6-windows-i586-p.exe'[/b] [15.21 MB] and save to your desktop.&lt;br&gt;7. Close any programs you may have running - especially your web browser.&lt;br&gt;8. Go to Start &gt; Control Panel double-click on Add/Remove programs and remove all older versions of Java.&lt;br&gt;9. Check any item with Java Runtime Environment (JRE or J2SE) in the name.&lt;br&gt;10. Click the Change/Remove button.&lt;br&gt;11. Repeat as many times as necessary to remove each Java version.&lt;br&gt;12. Reboot your computer once all Java components are removed.&lt;br&gt;13. Then from your desktop double-click on [b]jre-6u6-windows-i586-p.exe[/b] to install the newest version.&lt;br&gt;&lt;br&gt;&lt;br&gt;Download [b][url=http://download.bleepingcomputer.com/sUBs/ComboFix.exe][color="blue"]Combofix[/color][/url][/b] by [b]sUBs[/b] and save to your desktop.&lt;br&gt;Alternative Combofix download link [b][url=http://subs.geekstogo.com/ComboFix.exe][color="blue"]HERE[/color][/url][/b].&lt;br&gt;[color="red"][b][u]Note[/u][/b] &lt;br&gt;It is important that it is saved directly to your desktop[/color]&lt;br&gt;&lt;br&gt;Now close any open browsers.&lt;br&gt;Double click on Combofix.exe and follow the prompts. &lt;br&gt;When it's finished it will produce a log. &lt;br&gt;[b]Post the entire contents of C:\ComboFix.txt into your next reply[/b]. &lt;br&gt;[color="red"][b][u]Note[/u][/b] &lt;br&gt;Do not mouseclick combofix's window or do anything else on your pc while it's running. &lt;br&gt;That may cause the program/system to freeze/hang. [/color]&lt;br&gt;Do NOT post the ComboFix-quarantined-files.txt unless I ask.&lt;br&gt;[b][color="RED"][U]Note[/U][/color][/b]&lt;br&gt;In case your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix,please disable your scanner and redownload Combofix again.&lt;br&gt;Some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.&lt;br&gt;&lt;br&gt;Also post a new Hijackthis log please.&lt;br&gt;&lt;br&gt;</description><pubDate>Mon, 19 May 2008 14:39:39 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>Computer Unbelievably Slow</title><link>http://forum.tweaks.com/forum/Topic239752-29-1.aspx</link><description>I'm trying to fix a friends laptop.  The problem is that it takes over 10 minutes for the computer to load once turning it on.  Once startup has fully loaded, it takes another 30 seconds-1 minute for each program to load.  I tried all of those scans I'm supposed to before posting and none of them finished.  Spybot kept on saying user aborted scan within a minute of the start, Ad-aware would stop in the middle of the scan and if I pressed stop (I left it on for 8 hours and still had the same problem), it would just freeze, and sting got stuck on a file (it was stuck on scanning one particular file for 5 hours so I just closed out through task manager).  Here is the HijackThis log.&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 3:23:09 PM, on 5/19/2008&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;C:\Program Files\Intel\Wireless\Bin\EvtEng.exe&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe&lt;BR&gt;C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe&lt;BR&gt;C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Bonjour\DNSResponder.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe&lt;BR&gt;C:\WINDOWS\system32\wscntfy.exe&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&lt;BR&gt;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&lt;BR&gt;C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe&lt;BR&gt;C:\Program Files\Zune\ZuneLauncher.exe&lt;BR&gt;C:\WINDOWS\Dit.exe&lt;BR&gt;C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe&lt;BR&gt;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;BR&gt;C:\Program Files\Spybot - Search &amp;amp; Destroy\TeaTimer.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\wuauclt.exe&lt;BR&gt;C:\WINDOWS\system32\msiexec.exe&lt;BR&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;BR&gt;C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;BR&gt;C:\WINDOWS\system32\wuauclt.exe&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &lt;A href="http://windowsupdate.microsoft.com/"&gt;http://windowsupdate.microsoft.com/&lt;/A&gt;&lt;BR&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;BR&gt;O2 - BHO: Spybot-S&amp;amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;BR&gt;O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL&lt;BR&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll&lt;BR&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll&lt;BR&gt;O3 - Toolbar: &amp;amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll&lt;BR&gt;O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"&lt;BR&gt;O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe&lt;BR&gt;O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"&lt;BR&gt;O4 - HKLM\..\Run: [CICache] CICache.exe&lt;BR&gt;O4 - HKLM\..\Run: [Dit] Dit.exe&lt;BR&gt;O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;BR&gt;O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp;amp; Destroy\TeaTimer.exe&lt;BR&gt;O4 - Startup: V CAST Music Monitor.lnk = C:\Program Files\Verizon Wireless\V CAST Music\V CAST Music Monitor.exe&lt;BR&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000&lt;BR&gt;O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: S&amp;amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll&lt;BR&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL&lt;BR&gt;O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Spybot - Search &amp;amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll&lt;BR&gt;O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - &lt;A href="http://upload.facebook.com/controls/FacebookPhotoUploader.cab"&gt;http://upload.facebook.com/controls/FacebookPhotoUploader.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - &lt;A href="http://go.divx.com/plugin/DivXBrowserPlugin.cab"&gt;http://go.divx.com/plugin/DivXBrowserPlugin.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - &lt;A href="http://www.vzwpix.com/activex/VerizonWirelessUploadControl.cab"&gt;http://www.vzwpix.com/activex/VerizonWirelessUploadControl.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - &lt;A href="http://www.adobe.com/products/acrobat/nos/gp.cab"&gt;http://www.adobe.com/products/acrobat/nos/gp.cab&lt;/A&gt;&lt;BR&gt;O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL&lt;BR&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;BR&gt;O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;BR&gt;O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;BR&gt;O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe&lt;BR&gt;O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;BR&gt;O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe&lt;BR&gt;O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe&lt;BR&gt;O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 6233 bytes&lt;BR&gt;</description><pubDate>Mon, 19 May 2008 14:24:07 GMT</pubDate><dc:creator>numba1v</dc:creator></item></channel></rss>