﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Tweaks.com Forum  / Windows &amp; System Security / HiJack This Logs  / Firefox Hangs &amp; Various Programs Will Not Update (Trojan Infection) / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>Tweaks.com Forum </description><link>http://forum.tweaks.com/forum/</link><webMaster>forum@tweaks.com</webMaster><lastBuildDate>Thu, 20 Nov 2008 03:32:11 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: Firefox Hangs &amp; Various Programs Will Not Update (Trojan Infection)</title><link>http://forum.tweaks.com/forum/Topic241833-29-1.aspx</link><description>Your log is clean:)&lt;br&gt;You should now take the time to read and follow the information found in the links below,to help you prevent any possible future infections and stay safe and secure while online:&lt;br&gt;&lt;br&gt;[b][color="blue"]Simple and easy ways to keep your computer safe and secure on the Internet[/color][/b]:&lt;br&gt;[url]http://www.bleepingcomputer.com/tutorials/tutorial82.html[/url]&lt;br&gt;&lt;br&gt;[b][color="blue"]How to prevent Malware[/color][/b]:&lt;br&gt;[url]http://users.telenet.be/bluepatchy/miekiemoes/prevention.html[/url]&lt;br&gt;&lt;br&gt;[B][color="blue"]So how did I get infected in the first place[/color][/B]:&lt;br&gt;[URL]http://forums.spybot.info/showthread.php?t=279[/URL]&lt;br&gt;&lt;br&gt;[B][color="blue"]Malware Cleanup Programs and Preventative Procedures[/color][/B]: &lt;br&gt;[URL]http://russelltexas.com/malware/allclear.htm[/URL]&lt;br&gt;&lt;br&gt;[B][color="blue"]How to Set Security Options in the Firefox Browser[/color][/B]:&lt;br&gt;[URL]http://websearch.about.com/od/firefox/ss/firefoxoptions.htm[/URL]&lt;br&gt;&lt;br&gt;[B][color="blue"]Internet Explorer 7 Desktop Security Guide[/color][/B]:&lt;br&gt;[URL]http://www.microsoft.com/downloads/details.aspx?FamilyID=6aa4c1da-6021-468e-a8cf-af4afe4c84b2&amp;DisplayLang=en[/URL]&lt;br&gt;&lt;br&gt;[B][color="blue"]Working with Internet Explorer 6 Security Settings[/color][/B]:&lt;br&gt;[URL]http://www.microsoft.com/windows/ie/ie6/using/howto/security/settings.mspx[/URL]&lt;br&gt;&lt;br&gt;[b][color="blue"]Hardening Windows Security - Part 1[/color][/b]:&lt;br&gt;[url]http://www.malwarehelp.org/Malware-Prevention-Hardening-Windows-Security1.html[/url]&lt;br&gt;&lt;br&gt;[b][color="blue"]Hardening Windows Security - Part 2[/color][/b]:&lt;br&gt;[url]http://www.malwarehelp.org/malware-prevention-hardening-windows-security2.html[/url]&lt;br&gt;</description><pubDate>Mon, 07 Jul 2008 15:21:25 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Firefox Hangs &amp; Various Programs Will Not Update (Trojan Infection)</title><link>http://forum.tweaks.com/forum/Topic241833-29-1.aspx</link><description>The Autoplay Repair Wizard fixed the autoplay issues I was having.  Thank you for all your help once again RichieUK.</description><pubDate>Mon, 07 Jul 2008 13:35:58 GMT</pubDate><dc:creator>knight1fox3</dc:creator></item><item><title>RE: Firefox Hangs &amp; Various Programs Will Not Update (Trojan Infection)</title><link>http://forum.tweaks.com/forum/Topic241833-29-1.aspx</link><description>Download and run the [b]Autoplay Repair Wizard[/b].&lt;br&gt;The Microsoft AutoPlay Repair Wizard scans your computer devices to find defective AutoPlay settings, and attempts to fix those it finds.&lt;br&gt;[url]http://www.microsoft.com/downloads/details.aspx?FamilyID=c680a7b6-e8fa-45c4-a171-1b389cfacdad&amp;displaylang=en[/url]&lt;br&gt;&lt;br&gt;If the above didn't help,double click on the registry backup file you created earlier when running CCleaner and agree to merge the imformation into the registry.&lt;br&gt;[b]Restart your pc[/b].&lt;br&gt;Now see if Autoplay now works correctly as it did before running these programs.&lt;br&gt;Now you [b]must[/b] run Malwarebytes Anti-Malware again with you restoring the registry.&lt;br&gt;&lt;br&gt;Let me know how you get on.</description><pubDate>Thu, 03 Jul 2008 02:40:51 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Firefox Hangs &amp; Various Programs Will Not Update (Trojan Infection)</title><link>http://forum.tweaks.com/forum/Topic241833-29-1.aspx</link><description>[b]MBAM Log:[/b]&lt;br&gt;&lt;br&gt;Malwarebytes' Anti-Malware 1.19&lt;br&gt;Database version: 916&lt;br&gt;Windows 5.1.2600 Service Pack 2&lt;br&gt;&lt;br&gt;7:43:25 PM 7/2/2008&lt;br&gt;mbam-log-7-2-2008 (19-43-25).txt&lt;br&gt;&lt;br&gt;Scan type: Quick Scan&lt;br&gt;Objects scanned: 37914&lt;br&gt;Time elapsed: 4 minute(s), 5 second(s)&lt;br&gt;&lt;br&gt;Memory Processes Infected: 0&lt;br&gt;Memory Modules Infected: 0&lt;br&gt;Registry Keys Infected: 2&lt;br&gt;Registry Values Infected: 2&lt;br&gt;Registry Data Items Infected: 2&lt;br&gt;Folders Infected: 1&lt;br&gt;Files Infected: 4&lt;br&gt;&lt;br&gt;Memory Processes Infected:&lt;br&gt;(No malicious items detected)&lt;br&gt;&lt;br&gt;Memory Modules Infected:&lt;br&gt;(No malicious items detected)&lt;br&gt;&lt;br&gt;Registry Keys Infected:&lt;br&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.&lt;br&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.&lt;br&gt;&lt;br&gt;Registry Values Infected:&lt;br&gt;HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\SearchMigratedDefaultUrl (Trojan.Zlob) -&gt; Delete on reboot.&lt;br&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Trojan.Zlob) -&gt; Delete on reboot.&lt;br&gt;&lt;br&gt;Registry Data Items Infected:&lt;br&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Hijack.Search) -&gt; Bad: (http://internetsearchservice.com/search?q=%s) Good: (http://www.google.com/) -&gt; Quarantined and deleted successfully.&lt;br&gt;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Hijack.Search) -&gt; Bad: (http://internetsearchservice.com/search?q={searchTerms}) Good: (http://www.google.com/) -&gt; Quarantined and deleted successfully.&lt;br&gt;&lt;br&gt;Folders Infected:&lt;br&gt;C:\WINDOWS\system32\824223 (Trojan.BHO) -&gt; Quarantined and deleted successfully.&lt;br&gt;&lt;br&gt;Files Infected:&lt;br&gt;C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -&gt; Quarantined and deleted successfully.&lt;br&gt;C:\Documents and Settings\Beau Venne\My Documents\My Music\My Music.url (Trojan.Zlob) -&gt; Quarantined and deleted successfully.&lt;br&gt;C:\Documents and Settings\Beau Venne\My Documents\My Pictures\My Pictures.url (Trojan.Zlob) -&gt; Quarantined and deleted successfully.&lt;br&gt;C:\Documents and Settings\Beau Venne\My Documents\My Videos\My Video.url (Trojan.Zlob) -&gt; Quarantined and deleted successfully.&lt;br&gt;&lt;br&gt;[b]New Hijackthis Log:[/b]&lt;br&gt;&lt;br&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br&gt;Scan saved at 8:01:34 PM, on 7/2/2008&lt;br&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br&gt;MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)&lt;br&gt;Boot mode: Normal&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\WINDOWS\System32\smss.exe&lt;br&gt;C:\WINDOWS\system32\winlogon.exe&lt;br&gt;C:\WINDOWS\system32\services.exe&lt;br&gt;C:\WINDOWS\system32\lsass.exe&lt;br&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\system32\ZoneLabs\vsmon.exe&lt;br&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;br&gt;C:\WINDOWS\Explorer.EXE&lt;br&gt;C:\WINDOWS\System32\wltrysvc.exe&lt;br&gt;C:\WINDOWS\System32\bcmwltry.exe&lt;br&gt;C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;br&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br&gt;C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgrsx.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgemc.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgtray.exe&lt;br&gt;C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&lt;br&gt;C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe&lt;br&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\WINDOWS\system32\wuauclt.exe&lt;br&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;br&gt;&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com&lt;br&gt;O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll&lt;br&gt;O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe&lt;br&gt;O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&lt;br&gt;O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"&lt;br&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000&lt;br&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O16 - DPF: {00140000-B1BA-11CE-ABC6-F5B2E79D9E3F} (LEAD Main Control (14.0)) - file:///D:/LTOCX14N.cab&lt;br&gt;O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll&lt;br&gt;O20 - AppInit_DLLs: avgrsstx.dll&lt;br&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;br&gt;O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;br&gt;O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe&lt;br&gt;O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe&lt;br&gt;O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br&gt;O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe&lt;br&gt;O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe&lt;br&gt;&lt;br&gt;--&lt;br&gt;End of file - 3794 bytes&lt;br&gt;&lt;br&gt;&lt;br&gt;Computer and Firefox is running great.  The websites I couldn't access before I now can.  Program updates are working as well.  The only minor thing I noticed is that when I pop a CD in or a flash drive, I don't get the "What would you like to do prompt" for the Autoplay.  I've checked the Autoplay properties and the "always prompt" is checked.  This is very minor though.  I'm just glad I am able to access the websites I couldn't before.  Thanks for all your help RichieUK.</description><pubDate>Wed, 02 Jul 2008 23:07:47 GMT</pubDate><dc:creator>knight1fox3</dc:creator></item><item><title>RE: Firefox Hangs &amp; Various Programs Will Not Update (Trojan Infection)</title><link>http://forum.tweaks.com/forum/Topic241833-29-1.aspx</link><description>Click on Start/Run,copy and paste [b]ComboFix /u[/b] into the '[u]O[/u]pen:' space,then press OK [see image below]&lt;br&gt;This will uninstall Combofix,delete its related folders and files,reset your clock settings,hide file extensions,hide the system/hidden files and resets System Restore.&lt;br&gt;&lt;br&gt;[IMG]http://img.photobucket.com/albums/v624/29wood/comu.gif[/IMG]&lt;br&gt;&lt;br&gt;&lt;br&gt;Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'. &lt;br&gt;Make sure all browser and all Windows Explorer windows are closed before fixing:&lt;br&gt;[b]R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://internetsearchservice.com&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://internetsearchservice.com&lt;br&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://internetsearchservice.com&lt;br&gt;O8 - Extra context menu item: &amp;Search - ?p=ZKfox000[/b]&lt;br&gt;&lt;br&gt;Find and delete:&lt;br&gt;C:\WINDOWS\system32\[b]247880[/b]&lt;br&gt;&lt;br&gt;&lt;br&gt;Download and scan with [b][color="red"]CCleaner[/color][/b]:&lt;br&gt;[url]http://www.ccleaner.com/download/builds[/url]&lt;br&gt;1. Starting with v1.27.260, CCleaner started installing the [b]Yahoo Toolbar[/b] as an option which IS checkmarked by default during the installation. &lt;br&gt;IF you do NOT want it, REMOVE the checkmark when provided with the option OR download the toolbar-free 'Slim' version instead of the Standard Build.&lt;br&gt;&lt;br&gt;2. Before first use, select Options &gt; Advanced and UNCHECK [b]"Only delete files in Windows Temp folder older than 48 hours"[/b]&lt;br&gt;&lt;br&gt;3. Then select the items you wish to clean up.&lt;br&gt;&lt;br&gt;[b]In the Windows Tab:[/b]&lt;br&gt;* Clean all entries in the "Internet Explorer" section except Cookies.&lt;br&gt;* Clean all the entries in the "Windows Explorer" section.&lt;br&gt;* Clean all entries in the "System" section.&lt;br&gt;* Clean all entries in the "Advanced" section.&lt;br&gt;* Clean any others that you choose.&lt;br&gt;&lt;br&gt;[b]In the Applications Tab:[/b]&lt;br&gt;* Clean all except cookies in the Firefox/Mozilla section if you use it.&lt;br&gt;* Clean all in the Opera section if you use it.&lt;br&gt;* Clean Sun Java in the Internet Section.&lt;br&gt;* Clean any others that you choose.&lt;br&gt;&lt;br&gt;4. Click the "Run Cleaner" button.&lt;br&gt;5. A pop up box will appear advising this process will permanently delete files from your system.&lt;br&gt;6. Click "OK" and it will scan and clean your system.&lt;br&gt;&lt;br&gt;* Now click on the '[b]Registry[/b]' tab/button on the left.&lt;br&gt;* Then click on the 'Scan for issues' button at the bottom.&lt;br&gt;* If CCleaner displays any issues,click on 'Fix selected issues'.&lt;br&gt;* You'll then be asked 'Do you want to backup changes to the registry',you [b]must[/b] click '[b]YES[/b]'.&lt;br&gt;* Save the backup somewhere safe,your desktop is a good a place as any.&lt;br&gt;* Then click 'Fix Issues',then click 'Close'.&lt;br&gt;* Exit CCleaner.&lt;br&gt;&lt;br&gt;&lt;br&gt;Please download [b][color="red"]Malwarebytes Anti-Malware[/color][/b]:&lt;br&gt;[url]http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html[/url]&lt;br&gt;[url]http://www.besttechie.net/tools/mbam-setup.exe[/url]&lt;br&gt;&lt;br&gt;Double Click mbam-setup.exe to install the application.&lt;br&gt;(If using Windows Vista,be sure to [b][url=http://windowshelp.microsoft.com/Windows/en-US/Help/fb464905-31d5-4427-89a2-ed5322327fc21033.mspx][color="blue"]"Run As Administrator"[/color][/url][/b]).&lt;br&gt;&lt;br&gt;* Make sure a checkmark is placed next to [b]Update Malwarebytes' Anti-Malware[/b] and [b]Launch Malwarebytes' Anti-Malware[/b], then click Finish.&lt;br&gt;* If an update is found, it will download and install the latest version.&lt;br&gt;* Once the program has loaded, select "Perform Quick Scan", then click Scan.&lt;br&gt;* The scan may take some time to finish,so please be patient.&lt;br&gt;* When the scan is complete, click OK, then Show Results to view the results.&lt;br&gt;* Make sure that everything is checked, and click Remove Selected.&lt;br&gt;* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)&lt;br&gt;* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.&lt;br&gt;* [b]Copy and paste the entire report into your next reply[/b].&lt;br&gt;&lt;br&gt;Extra Note:&lt;br&gt;[b][color="green"]If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.[/color][/b]&lt;br&gt;&lt;br&gt;[b]Also post a new Hijackthis log,let me know how your pc is running now.[/b]</description><pubDate>Wed, 02 Jul 2008 03:11:45 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Firefox Hangs &amp; Various Programs Will Not Update (Trojan Infection)</title><link>http://forum.tweaks.com/forum/Topic241833-29-1.aspx</link><description>Here you go and thanks again for the assistance:&lt;br&gt;&lt;br&gt;[b]New ComboFix Log:[/b]&lt;br&gt;&lt;br&gt;ComboFix 08-06-30.2 - ********** 2008-07-01 21:38:22.3 - NTFSx86&lt;br&gt;Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.1089 [GMT -5:00]&lt;br&gt;Running from: C:\Documents and Settings\**********\Desktop\ComboFix.exe&lt;br&gt;Command switches used :: C:\Documents and Settings\**********\Desktop\CFScript.txt&lt;br&gt; * Created a new restore point&lt;br&gt;&lt;br&gt;[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]&lt;br&gt;&lt;br&gt;FILE ::&lt;br&gt;C:\WINDOWS\bcmwltrytmp.reg&lt;br&gt;.&lt;br&gt;&lt;br&gt;(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))&lt;br&gt;.&lt;br&gt;&lt;br&gt;C:\WINDOWS\BM9b97b920.txt&lt;br&gt;C:\WINDOWS\system32\atikvmag.dll&lt;br&gt;&lt;br&gt;.&lt;br&gt;(((((((((((((((((((((((((   Files Created from 2008-06-02 to 2008-07-02  )))))))))))))))))))))))))))))))&lt;br&gt;.&lt;br&gt;&lt;br&gt;2008-06-27 22:29 . 2008-06-27 22:29&lt;DIR&gt;d--------C:\Program Files\SUPERAntiSpyware&lt;br&gt;2008-06-27 22:29 . 2008-06-27 22:29&lt;DIR&gt;d--------C:\Documents and Settings\**********\Application Data\SUPERAntiSpyware.com&lt;br&gt;2008-06-27 22:29 . 2008-06-27 22:29&lt;DIR&gt;d--------C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com&lt;br&gt;2008-06-27 21:59 . 2008-06-27 21:59&lt;DIR&gt;d--------C:\Program Files\Trend Micro&lt;br&gt;2008-06-25 20:24 . 2008-06-25 21:59&lt;DIR&gt;d--------C:\Program Files\XoftSpySE&lt;br&gt;2008-06-24 22:17 . 2008-06-24 22:17230--a------C:\WINDOWS\system32\spupdsvc.inf&lt;br&gt;2008-06-24 22:15 . 2008-06-25 18:321,374--a------C:\WINDOWS\imsins.BAK&lt;br&gt;2008-06-24 21:34 . 2008-07-01 21:43847,904--ahs----C:\WINDOWS\system32\drivers\fidbox.dat&lt;br&gt;2008-06-24 21:34 . 2008-07-01 21:4010,916--ahs----C:\WINDOWS\system32\drivers\fidbox.idx&lt;br&gt;2008-06-24 21:27 . 2008-06-24 21:27&lt;DIR&gt;d--------C:\Documents and Settings\All Users\Application Data\MailFrontier&lt;br&gt;2008-06-24 21:27 . 2008-06-24 21:294,212---h-----C:\WINDOWS\system32\zllictbl.dat&lt;br&gt;2008-06-24 21:26 . 2008-04-02 20:0775,248--a------C:\WINDOWS\zllsputility.exe&lt;br&gt;2008-06-24 21:26 . 2004-04-27 04:4011,264--a------C:\WINDOWS\system32\SpOrder.dll&lt;br&gt;2008-06-24 21:25 . 2008-06-24 21:26&lt;DIR&gt;d--------C:\WINDOWS\system32\ZoneLabs&lt;br&gt;2008-06-24 21:25 . 2008-06-24 21:25&lt;DIR&gt;d--------C:\Program Files\Zone Labs&lt;br&gt;2008-06-24 21:25 . 2008-04-02 20:071,086,952--a------C:\WINDOWS\system32\zpeng24.dll&lt;br&gt;2008-06-24 21:25 . 2008-07-01 21:43352,918--a------C:\WINDOWS\system32\vsconfig.xml&lt;br&gt;2008-06-24 21:22 . 2008-07-01 21:43&lt;DIR&gt;d--------C:\WINDOWS\Internet Logs&lt;br&gt;2008-06-22 11:24 . 2008-06-24 20:59&lt;DIR&gt;d--------C:\Program Files\Piolet&lt;br&gt;2008-06-22 11:24 . 2008-06-22 11:24662,288--a------C:\WINDOWS\system32\MSCOMCT2.OCX&lt;br&gt;2008-06-22 11:24 . 2008-06-22 11:24416,528--a------C:\WINDOWS\system32\COMCT332.OCX&lt;br&gt;2008-06-22 11:24 . 2008-06-22 11:24152,848--a------C:\WINDOWS\system32\COMDLG32.OCX&lt;br&gt;2008-06-22 11:24 . 2008-06-22 11:24132,880--a------C:\WINDOWS\system32\MSINET.OCX&lt;br&gt;2008-06-22 11:24 . 2008-06-22 11:24124,688--a------C:\WINDOWS\system32\MSWINSCK.OCX&lt;br&gt;2008-06-22 10:42 . 2008-06-22 13:35&lt;DIR&gt;d--------C:\Program Files\Spybot - Search &amp; Destroy&lt;br&gt;2008-06-22 10:36 . 2008-06-28 13:06&lt;DIR&gt;d--h-----C:\$AVG8.VAULT$&lt;br&gt;2008-06-22 10:14 . 2008-06-24 19:24&lt;DIR&gt;d--------C:\WINDOWS\system32\drivers\Avg&lt;br&gt;2008-06-22 10:14 . 2008-06-22 10:1496,520--a------C:\WINDOWS\system32\drivers\avgldx86.sys&lt;br&gt;2008-06-22 10:14 . 2008-06-22 10:1475,272--a------C:\WINDOWS\system32\drivers\avgtdix.sys&lt;br&gt;2008-06-22 10:14 . 2008-06-22 10:1410,520--a------C:\WINDOWS\system32\avgrsstx.dll&lt;br&gt;2008-06-22 10:13 . 2008-06-22 13:35&lt;DIR&gt;d--------C:\Program Files\AVG&lt;br&gt;2008-06-22 10:13 . 2008-06-22 13:35&lt;DIR&gt;d--------C:\Documents and Settings\All Users\Application Data\avg8&lt;br&gt;2008-06-19 03:02 . 2008-06-19 03:02118--a------C:\WINDOWS\system32\MRT.INI&lt;br&gt;2008-06-18 03:52 . 2008-06-13 08:10272,128---------C:\WINDOWS\system32\drivers\bthport.sys&lt;br&gt;2008-06-18 03:52 . 2008-06-13 08:10272,128-----c---C:\WINDOWS\system32\dllcache\bthport.sys&lt;br&gt;2008-06-08 09:20 . 2008-06-22 13:35&lt;DIR&gt;d--------C:\WINDOWS\system32\247880&lt;br&gt;&lt;br&gt;.&lt;br&gt;((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))&lt;br&gt;.&lt;br&gt;2008-06-28 03:29---------d-----wC:\Program Files\Common Files\Wise Installation Wizard&lt;br&gt;2008-06-25 03:15---------d-----wC:\Program Files\Google&lt;br&gt;2008-06-25 02:59---------d-----wC:\Documents and Settings\**********\Application Data\Apple Computer&lt;br&gt;2008-06-25 01:54---------d-----wC:\Documents and Settings\All Users\Application Data\Spybot - Search &amp; Destroy&lt;br&gt;2008-06-22 16:241,376,528----a-wC:\WINDOWS\system32\msvbvm60.dll&lt;br&gt;2008-05-29 09:000----a-wC:\Program Files\uninstall.dat&lt;br&gt;2008-05-08 12:28202,752----a-wC:\WINDOWS\system32\drivers\rmcast.sys&lt;br&gt;2008-05-07 05:181,287,680----a-wC:\WINDOWS\system32\quartz.dll&lt;br&gt;2008-04-21 07:04659,456----a-wC:\WINDOWS\system32\wininet.dll&lt;br&gt;.&lt;br&gt;&lt;br&gt;(((((((((((((((((((((((((((((   snapshot@2008-06-30_20.34.21.26   )))))))))))))))))))))))))))))))))))))))))&lt;br&gt;.&lt;br&gt;- 2008-07-01 01:31:272,048--s-a-wC:\WINDOWS\bootstat.dat&lt;br&gt;+ 2008-07-02 02:41:442,048--s-a-wC:\WINDOWS\bootstat.dat&lt;br&gt;.&lt;br&gt;(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))&lt;br&gt;.&lt;br&gt;.&lt;br&gt;*Note* empty entries &amp; legit default entries are not shown &lt;br&gt;REGEDIT4&lt;br&gt;&lt;br&gt;[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;br&gt;"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;br&gt;"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-06-22 10:14 1177368]&lt;br&gt;"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-28 22:05 344064]&lt;br&gt;&lt;br&gt;[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]&lt;br&gt;"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]&lt;br&gt;2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]&lt;br&gt;"AppInit_DLLs"=avgrsstx.dll&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]&lt;br&gt;--a------ 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]&lt;br&gt;--------- 2004-10-13 11:24 1694208 C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]&lt;br&gt;--a------ 2008-01-31 23:13 385024 C:\Program Files\QuickTime\QTTask.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]&lt;br&gt;-ra------ 2000-10-16 10:37 32768 C:\WINDOWS\system32\rmctrl.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]&lt;br&gt;--a------ 2005-03-01 16:52 1695744 C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]&lt;br&gt;-rahs---- 2008-01-28 11:43 2097488 C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]&lt;br&gt;--a------ 2008-05-28 10:33 1506544 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]&lt;br&gt;--a------ 2007-08-30 18:43 4670704 C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client]&lt;br&gt;--a------ 2008-04-02 20:07 919016 C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]&lt;br&gt;"DisableMonitoring"=dword:00000001&lt;br&gt;&lt;br&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]&lt;br&gt;"EnableFirewall"= 0 (0x0)&lt;br&gt;&lt;br&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]&lt;br&gt;"%windir%\\system32\\sessmgr.exe"=&lt;br&gt;"C:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"=&lt;br&gt;"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=&lt;br&gt;"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=&lt;br&gt;"%windir%\\Network Diagnostic\\xpnetdiag.exe"=&lt;br&gt;"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=&lt;br&gt;"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=&lt;br&gt;"C:\\Program Files\\Piolet\\piolet.exe"=&lt;br&gt;&lt;br&gt;R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-06-22 10:14]&lt;br&gt;R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-06-22 10:14]&lt;br&gt;R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-06-22 10:13]&lt;br&gt;R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-06-22 10:14]&lt;br&gt;&lt;br&gt;.&lt;br&gt;- - - - ORPHANS REMOVED - - - -&lt;br&gt;&lt;br&gt;HKLM-Run-Broadcom Wireless Manager UI - C:\WINDOWS\system32\WLTRAY&lt;br&gt;MSConfigStartUp-swg - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;br&gt;&lt;br&gt;&lt;br&gt;**************************************************************************&lt;br&gt;&lt;br&gt;catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net&lt;br&gt;Rootkit scan 2008-07-01 21:42:28&lt;br&gt;Windows 5.1.2600 Service Pack 2 NTFS&lt;br&gt;&lt;br&gt;scanning hidden processes ... &lt;br&gt;&lt;br&gt;scanning hidden autostart entries ...&lt;br&gt;&lt;br&gt;scanning hidden files ... &lt;br&gt;&lt;br&gt;scan completed successfully&lt;br&gt;hidden files: 0&lt;br&gt;&lt;br&gt;**************************************************************************&lt;br&gt;.&lt;br&gt;------------------------ Other Running Processes ------------------------&lt;br&gt;.&lt;br&gt;C:\WINDOWS\system32\ati2evxx.exe&lt;br&gt;C:\WINDOWS\system32\ati2evxx.exe&lt;br&gt;C:\WINDOWS\system32\ZoneLabs\vsmon.exe&lt;br&gt;C:\WINDOWS\system32\WLTRYSVC.EXE&lt;br&gt;C:\WINDOWS\system32\BCMWLTRY.EXE&lt;br&gt;C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;br&gt;C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe&lt;br&gt;C:\WINDOWS\system32\WLTRAY.EXE&lt;br&gt;C:\Program Files\AVG\AVG8\avgrsx.exe&lt;br&gt;C:\Program Files\AVG\AVG8\avgrsx.exe&lt;br&gt;.&lt;br&gt;**************************************************************************&lt;br&gt;.&lt;br&gt;Completion time: 2008-07-01 21:45:36 - machine was rebooted&lt;br&gt;ComboFix-quarantined-files.txt  2008-07-02 02:45:29&lt;br&gt;ComboFix2.txt  2008-07-01 01:34:52&lt;br&gt;&lt;br&gt;Pre-Run: 43,476,889,600 bytes free&lt;br&gt;Post-Run: 43,453,673,472 bytes free&lt;br&gt;&lt;br&gt;156--- E O F ---2008-06-25 23:33:08&lt;br&gt;&lt;br&gt;[b]New Hijackthis Log:[/b]&lt;br&gt;&lt;br&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br&gt;Scan saved at 9:50:43 PM, on 7/1/2008&lt;br&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br&gt;MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)&lt;br&gt;Boot mode: Normal&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\WINDOWS\System32\smss.exe&lt;br&gt;C:\WINDOWS\system32\winlogon.exe&lt;br&gt;C:\WINDOWS\system32\services.exe&lt;br&gt;C:\WINDOWS\system32\lsass.exe&lt;br&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;br&gt;C:\WINDOWS\system32\ZoneLabs\vsmon.exe&lt;br&gt;C:\WINDOWS\System32\wltrysvc.exe&lt;br&gt;C:\WINDOWS\System32\bcmwltry.exe&lt;br&gt;C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;br&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br&gt;C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe&lt;br&gt;C:\WINDOWS\system32\WLTRAY.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgemc.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgtray.exe&lt;br&gt;C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&lt;br&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;C:\WINDOWS\explorer.exe&lt;br&gt;C:\Program Files\AVG\AVG8\avgrsx.exe&lt;br&gt;C:\Program Files\AVG\AVG8\avgrsx.exe&lt;br&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;br&gt;&lt;br&gt;R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://internetsearchservice.com&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://internetsearchservice.com&lt;br&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://internetsearchservice.com&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com&lt;br&gt;O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll&lt;br&gt;O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe&lt;br&gt;O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&lt;br&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;O8 - Extra context menu item: &amp;Search - ?p=ZKfox000&lt;br&gt;O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000&lt;br&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O16 - DPF: {00140000-B1BA-11CE-ABC6-F5B2E79D9E3F} (LEAD Main Control (14.0)) - file:///D:/LTOCX14N.cab&lt;br&gt;O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll&lt;br&gt;O20 - AppInit_DLLs: avgrsstx.dll&lt;br&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;br&gt;O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;br&gt;O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe&lt;br&gt;O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe&lt;br&gt;O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br&gt;O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe&lt;br&gt;O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe&lt;br&gt;&lt;br&gt;--&lt;br&gt;End of file - 4008 bytes&lt;br&gt;</description><pubDate>Tue, 01 Jul 2008 21:56:08 GMT</pubDate><dc:creator>knight1fox3</dc:creator></item><item><title>RE: Firefox Hangs &amp; Various Programs Will Not Update (Trojan Infection)</title><link>http://forum.tweaks.com/forum/Topic241833-29-1.aspx</link><description>[url=http://www.webmasternow.com/copyandpaste.html][color="blue"]Copy and paste[/color][/url] ALL the following text in the code box below into [b]Notepad[/b].&lt;br&gt;Click on File(in the menu at the top)&gt;Save as../Save as Type: 'All Files' /File name: [b]CFScript[/b] to your desktop.&lt;br&gt;&lt;br&gt;[quote]KILLALL::&lt;br&gt;&lt;br&gt;File::&lt;br&gt;C:\WINDOWS\bcmwltrytmp.reg&lt;br&gt;&lt;br&gt;Registry::&lt;br&gt;[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{46069f17-adcc-4ebf-95e7-a3fd42c155bc}]&lt;br&gt;[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkHWQKb]&lt;br&gt;[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\98a48abc]&lt;br&gt;[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM9b97b920]&lt;br&gt;[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\My Web Search Bar Search Scope Monitor][/quote]&lt;br&gt;Now drag then drop the [b]CFScript[/b] file onto [b]ComboFix.exe[/b] as seen in the image below.&lt;br&gt;&lt;br&gt;[img]http://img.photobucket.com/albums/v624/29wood/CFScript.gif[/img]&lt;br&gt;&lt;br&gt;This will start ComboFix again. &lt;br&gt;After reboot, (in case it asks to reboot), [b]post the contents of Combofix.txt in your next reply along with a new HijackThis log.[/b]</description><pubDate>Tue, 01 Jul 2008 01:51:05 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Firefox Hangs &amp; Various Programs Will Not Update (Trojan Infection)</title><link>http://forum.tweaks.com/forum/Topic241833-29-1.aspx</link><description>Thanks for the help RichieUK.  Here is what you requested:&lt;br&gt;&lt;br&gt;ComboFix 08-06-20.4 - ********** 2008-06-30 20:21:03.2 - NTFSx86&lt;br&gt;Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.1084 [GMT -5:00]&lt;br&gt;Running from: C:\Documents and Settings\**********\desktop\combofix.exe&lt;br&gt;Command switches used :: /killall&lt;br&gt;&lt;br&gt;[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]&lt;br&gt;.&lt;br&gt;&lt;br&gt;(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))&lt;br&gt;.&lt;br&gt;&lt;br&gt;C:\WINDOWS\BM9b97b920.xml&lt;br&gt;C:\WINDOWS\pskt.ini&lt;br&gt;C:\WINDOWS\system32\cdeddfhk.ini&lt;br&gt;C:\WINDOWS\system32\cdeddfhk.ini2&lt;br&gt;C:\WINDOWS\system32\dmjfibcq.dll&lt;br&gt;C:\WINDOWS\system32\evdfyjjw.dll&lt;br&gt;C:\WINDOWS\system32\hivotuon.dll&lt;br&gt;C:\WINDOWS\system32\jfistyia.ini&lt;br&gt;C:\WINDOWS\system32\mosbkdcs.dll&lt;br&gt;C:\WINDOWS\system32\noutovih.ini&lt;br&gt;C:\WINDOWS\system32\xlusgall.ini&lt;br&gt;.&lt;br&gt;---- Previous Run -------&lt;br&gt;.&lt;br&gt;C:\WINDOWS\cookies.ini&lt;br&gt;C:\WINDOWS\pskt.ini&lt;br&gt;C:\WINDOWS\system32\mcrh.tmp&lt;br&gt;&lt;br&gt;.&lt;br&gt;(((((((((((((((((((((((((   Files Created from 2008-06-01 to 2008-07-01  )))))))))))))))))))))))))))))))&lt;br&gt;.&lt;br&gt;&lt;br&gt;2008-06-30 20:33 . 1,893C:\WINDOWS\bcmwltrytmp.reg&lt;br&gt;2008-06-27 22:29 . 2008-06-27 22:29&lt;DIR&gt;d--------C:\Program Files\SUPERAntiSpyware&lt;br&gt;2008-06-27 22:29 . 2008-06-27 22:29&lt;DIR&gt;d--------C:\Documents and Settings\**********\Application Data\SUPERAntiSpyware.com&lt;br&gt;2008-06-27 22:29 . 2008-06-27 22:29&lt;DIR&gt;d--------C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com&lt;br&gt;2008-06-27 21:59 . 2008-06-27 21:59&lt;DIR&gt;d--------C:\Program Files\Trend Micro&lt;br&gt;2008-06-25 20:24 . 2008-06-25 21:59&lt;DIR&gt;d--------C:\Program Files\XoftSpySE&lt;br&gt;2008-06-24 22:17 . 2008-06-24 22:17230--a------C:\WINDOWS\system32\spupdsvc.inf&lt;br&gt;2008-06-24 22:15 . 2008-06-25 18:321,374--a------C:\WINDOWS\imsins.BAK&lt;br&gt;2008-06-24 21:34 . 2008-06-30 20:33794,656--ahs----C:\WINDOWS\system32\drivers\fidbox.dat&lt;br&gt;2008-06-24 21:34 . 2008-06-30 20:3010,244--ahs----C:\WINDOWS\system32\drivers\fidbox.idx&lt;br&gt;2008-06-24 21:27 . 2008-06-24 21:27&lt;DIR&gt;d--------C:\Documents and Settings\All Users\Application Data\MailFrontier&lt;br&gt;2008-06-24 21:27 . 2008-06-24 21:294,212---h-----C:\WINDOWS\system32\zllictbl.dat&lt;br&gt;2008-06-24 21:26 . 2008-04-02 20:0775,248--a------C:\WINDOWS\zllsputility.exe&lt;br&gt;2008-06-24 21:26 . 2004-04-27 04:4011,264--a------C:\WINDOWS\system32\SpOrder.dll&lt;br&gt;2008-06-24 21:25 . 2008-06-24 21:26&lt;DIR&gt;d--------C:\WINDOWS\system32\ZoneLabs&lt;br&gt;2008-06-24 21:25 . 2008-06-24 21:25&lt;DIR&gt;d--------C:\Program Files\Zone Labs&lt;br&gt;2008-06-24 21:25 . 2008-04-02 20:071,086,952--a------C:\WINDOWS\system32\zpeng24.dll&lt;br&gt;2008-06-24 21:25 . 2008-06-30 20:33352,918--a------C:\WINDOWS\system32\vsconfig.xml&lt;br&gt;2008-06-24 21:22 . 2008-06-30 20:33&lt;DIR&gt;d--------C:\WINDOWS\Internet Logs&lt;br&gt;2008-06-22 11:24 . 2008-06-24 20:59&lt;DIR&gt;d--------C:\Program Files\Piolet&lt;br&gt;2008-06-22 11:24 . 2008-06-22 11:24662,288--a------C:\WINDOWS\system32\MSCOMCT2.OCX&lt;br&gt;2008-06-22 11:24 . 2008-06-22 11:24416,528--a------C:\WINDOWS\system32\COMCT332.OCX&lt;br&gt;2008-06-22 11:24 . 2008-06-22 11:24152,848--a------C:\WINDOWS\system32\COMDLG32.OCX&lt;br&gt;2008-06-22 11:24 . 2008-06-22 11:24132,880--a------C:\WINDOWS\system32\MSINET.OCX&lt;br&gt;2008-06-22 11:24 . 2008-06-22 11:24124,688--a------C:\WINDOWS\system32\MSWINSCK.OCX&lt;br&gt;2008-06-22 10:42 . 2008-06-22 13:35&lt;DIR&gt;d--------C:\Program Files\Spybot - Search &amp; Destroy&lt;br&gt;2008-06-22 10:36 . 2008-06-28 13:06&lt;DIR&gt;d--h-----C:\$AVG8.VAULT$&lt;br&gt;2008-06-22 10:14 . 2008-06-24 19:24&lt;DIR&gt;d--------C:\WINDOWS\system32\drivers\Avg&lt;br&gt;2008-06-22 10:14 . 2008-06-22 10:1496,520--a------C:\WINDOWS\system32\drivers\avgldx86.sys&lt;br&gt;2008-06-22 10:14 . 2008-06-22 10:1475,272--a------C:\WINDOWS\system32\drivers\avgtdix.sys&lt;br&gt;2008-06-22 10:14 . 2008-06-22 10:1410,520--a------C:\WINDOWS\system32\avgrsstx.dll&lt;br&gt;2008-06-22 10:13 . 2008-06-22 13:35&lt;DIR&gt;d--------C:\Program Files\AVG&lt;br&gt;2008-06-22 10:13 . 2008-06-22 13:35&lt;DIR&gt;d--------C:\Documents and Settings\All Users\Application Data\avg8&lt;br&gt;2008-06-19 03:02 . 2008-06-19 03:02118--a------C:\WINDOWS\system32\MRT.INI&lt;br&gt;2008-06-18 03:52 . 2008-06-13 08:10272,128---------C:\WINDOWS\system32\drivers\bthport.sys&lt;br&gt;2008-06-18 03:52 . 2008-06-13 08:10272,128-----c---C:\WINDOWS\system32\dllcache\bthport.sys&lt;br&gt;2008-06-08 09:20 . 2008-06-22 13:35&lt;DIR&gt;d--------C:\WINDOWS\system32\247880&lt;br&gt;&lt;br&gt;.&lt;br&gt;((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))&lt;br&gt;.&lt;br&gt;2008-06-28 03:29---------d-----wC:\Program Files\Common Files\Wise Installation Wizard&lt;br&gt;2008-06-25 03:15---------d-----wC:\Program Files\Google&lt;br&gt;2008-06-25 02:59---------d-----wC:\Documents and Settings\**********\Application Data\Apple Computer&lt;br&gt;2008-06-25 01:54---------d-----wC:\Documents and Settings\All Users\Application Data\Spybot - Search &amp; Destroy&lt;br&gt;2008-06-22 16:241,376,528----a-wC:\WINDOWS\system32\msvbvm60.dll&lt;br&gt;2008-05-29 09:000----a-wC:\Program Files\uninstall.dat&lt;br&gt;2008-05-08 12:28202,752----a-wC:\WINDOWS\system32\drivers\rmcast.sys&lt;br&gt;2008-05-07 05:181,287,680----a-wC:\WINDOWS\system32\quartz.dll&lt;br&gt;2008-04-21 07:04659,456----a-wC:\WINDOWS\system32\wininet.dll&lt;br&gt;.&lt;br&gt;&lt;br&gt;(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))&lt;br&gt;.&lt;br&gt;.&lt;br&gt;*Note* empty entries &amp; legit default entries are not shown &lt;br&gt;REGEDIT4&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{46069f17-adcc-4ebf-95e7-a3fd42c155bc}]&lt;br&gt;C:\WINDOWS\system32\naaenjcx.dll&lt;br&gt;&lt;br&gt;[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;br&gt;"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;br&gt;"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" [ ]&lt;br&gt;"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-06-22 10:14 1177368]&lt;br&gt;"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-28 22:05 344064]&lt;br&gt;&lt;br&gt;[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]&lt;br&gt;"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 10:13 77824]&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]&lt;br&gt;C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkHWQKb]&lt;br&gt;jkkHWQKb.dll&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]&lt;br&gt;"AppInit_DLLs"=avgrsstx.dll&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\98a48abc]&lt;br&gt;C:\WINDOWS\system32\hivotuon.dll&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]&lt;br&gt;--a------ 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM9b97b920]&lt;br&gt;C:\WINDOWS\system32\dmjfibcq.dll&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]&lt;br&gt;--------- 2004-10-13 11:24 1694208 C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\My Web Search Bar Search Scope Monitor]&lt;br&gt;C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]&lt;br&gt;--a------ 2008-01-31 23:13 385024 C:\Program Files\QuickTime\QTTask.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]&lt;br&gt;-ra------ 2000-10-16 10:37 32768 C:\WINDOWS\system32\rmctrl.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]&lt;br&gt;--a------ 2005-03-01 16:52 1695744 C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]&lt;br&gt;-rahs---- 2008-01-28 11:43 2097488 C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]&lt;br&gt;--a------ 2008-05-28 10:33 1506544 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]&lt;br&gt;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]&lt;br&gt;--a------ 2007-08-30 18:43 4670704 C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client]&lt;br&gt;--a------ 2008-04-02 20:07 919016 C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]&lt;br&gt;"DisableMonitoring"=dword:00000001&lt;br&gt;&lt;br&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]&lt;br&gt;"EnableFirewall"= 0 (0x0)&lt;br&gt;&lt;br&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]&lt;br&gt;"%windir%\\system32\\sessmgr.exe"=&lt;br&gt;"C:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"=&lt;br&gt;"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=&lt;br&gt;"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=&lt;br&gt;"%windir%\\Network Diagnostic\\xpnetdiag.exe"=&lt;br&gt;"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=&lt;br&gt;"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=&lt;br&gt;"C:\\Program Files\\Piolet\\piolet.exe"=&lt;br&gt;&lt;br&gt;R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-06-22 10:14]&lt;br&gt;R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-06-22 10:14]&lt;br&gt;R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-06-22 10:13]&lt;br&gt;R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-06-22 10:14]&lt;br&gt;&lt;br&gt;.&lt;br&gt;**************************************************************************&lt;br&gt;&lt;br&gt;catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net&lt;br&gt;Rootkit scan 2008-06-30 20:32:23&lt;br&gt;Windows 5.1.2600 Service Pack 2 NTFS&lt;br&gt;&lt;br&gt;scanning hidden processes ... &lt;br&gt;&lt;br&gt;scanning hidden autostart entries ...&lt;br&gt;&lt;br&gt;scanning hidden files ... &lt;br&gt;&lt;br&gt;scan completed successfully&lt;br&gt;hidden files: 0&lt;br&gt;&lt;br&gt;**************************************************************************&lt;br&gt;.&lt;br&gt;------------------------ Other Running Processes ------------------------&lt;br&gt;.&lt;br&gt;C:\WINDOWS\system32\ati2evxx.exe&lt;br&gt;C:\WINDOWS\system32\ati2evxx.exe&lt;br&gt;C:\WINDOWS\system32\ZoneLabs\vsmon.exe&lt;br&gt;C:\WINDOWS\system32\WLTRYSVC.EXE&lt;br&gt;C:\WINDOWS\system32\BCMWLTRY.EXE&lt;br&gt;C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;br&gt;C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe&lt;br&gt;C:\WINDOWS\system32\WLTRAY.EXE&lt;br&gt;C:\Program Files\AVG\AVG8\avgrsx.exe&lt;br&gt;C:\Program Files\AVG\AVG8\avgrsx.exe&lt;br&gt;.&lt;br&gt;**************************************************************************&lt;br&gt;.&lt;br&gt;Completion time: 2008-06-30 20:34:51 - machine was rebooted [**********]&lt;br&gt;ComboFix-quarantined-files.txt  2008-07-01 01:34:44&lt;br&gt;&lt;br&gt;Pre-Run: 43,329,499,136 bytes free&lt;br&gt;Post-Run: 43,491,581,952 bytes free&lt;br&gt;&lt;br&gt;173--- E O F ---2008-06-25 23:33:08&lt;br&gt;&lt;br&gt;[b]New Hijackthis Log:[/b]&lt;br&gt;&lt;br&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br&gt;Scan saved at 8:45:44 PM, on 6/30/2008&lt;br&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br&gt;MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)&lt;br&gt;Boot mode: Normal&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\WINDOWS\System32\smss.exe&lt;br&gt;C:\WINDOWS\system32\winlogon.exe&lt;br&gt;C:\WINDOWS\system32\services.exe&lt;br&gt;C:\WINDOWS\system32\lsass.exe&lt;br&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;br&gt;C:\WINDOWS\system32\ZoneLabs\vsmon.exe&lt;br&gt;C:\WINDOWS\System32\wltrysvc.exe&lt;br&gt;C:\WINDOWS\System32\bcmwltry.exe&lt;br&gt;C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;br&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br&gt;C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe&lt;br&gt;C:\WINDOWS\system32\WLTRAY.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgtray.exe&lt;br&gt;C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&lt;br&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgemc.exe&lt;br&gt;C:\WINDOWS\explorer.exe&lt;br&gt;C:\Program Files\AVG\AVG8\avgrsx.exe&lt;br&gt;C:\Program Files\AVG\AVG8\avgrsx.exe&lt;br&gt;C:\Program Files\AVG\AVG8\avgrsx.exe&lt;br&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;br&gt;&lt;br&gt;R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://internetsearchservice.com&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://internetsearchservice.com&lt;br&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://internetsearchservice.com&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com&lt;br&gt;O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll&lt;br&gt;O2 - BHO: {cb551c24-df3a-7e59-fbe4-ccda71f96064} - {46069f17-adcc-4ebf-95e7-a3fd42c155bc} - C:\WINDOWS\system32\naaenjcx.dll (file missing)&lt;br&gt;O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY&lt;br&gt;O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe&lt;br&gt;O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&lt;br&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;O8 - Extra context menu item: &amp;Search - ?p=ZKfox000&lt;br&gt;O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000&lt;br&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O16 - DPF: {00140000-B1BA-11CE-ABC6-F5B2E79D9E3F} (LEAD Main Control (14.0)) - file:///D:/LTOCX14N.cab&lt;br&gt;O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll&lt;br&gt;O20 - AppInit_DLLs: avgrsstx.dll&lt;br&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;br&gt;O20 - Winlogon Notify: jkkHWQKb - jkkHWQKb.dll (file missing)&lt;br&gt;O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;br&gt;O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe&lt;br&gt;O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe&lt;br&gt;O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br&gt;O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe&lt;br&gt;O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe&lt;br&gt;&lt;br&gt;--&lt;br&gt;End of file - 4328 bytes&lt;br&gt;</description><pubDate>Mon, 30 Jun 2008 21:35:35 GMT</pubDate><dc:creator>knight1fox3</dc:creator></item><item><title>RE: Firefox Hangs &amp; Various Programs Will Not Update (Trojan Infection)</title><link>http://forum.tweaks.com/forum/Topic241833-29-1.aspx</link><description>Welcome:)&lt;br&gt;&lt;br&gt;Download [b][url=http://download.bleepingcomputer.com/sUBs/ComboFix.exe][color="blue"]Combofix[/color][/url][/b] by [b]sUBs[/b] and save to your desktop.&lt;br&gt;Alternative Combofix download link [b][url=http://subs.geekstogo.com/ComboFix.exe][color="blue"]HERE[/color][/url][/b].&lt;br&gt;[color="red"][b][u]Note[/u][/b] &lt;br&gt;It is important that it is saved directly to your desktop[/color]&lt;br&gt;Close any open browsers. &lt;br&gt;Click on Start/Run,[url=http://www.webmasternow.com/copyandpaste.html][color="blue"]copy and paste[/color][/url] the following bold text into the '[u]O[/u]pen:' space,then press OK [See image below]:&lt;br&gt;[b]"%userprofile%\desktop\combofix.exe" /killall[/b]&lt;br&gt;&lt;br&gt;[IMG]http://img.photobucket.com/albums/v624/29wood/ka.png[/IMG]&lt;br&gt;&lt;br&gt;Combofix.exe will start,please follow the prompts. &lt;br&gt;When it's finished it will produce a log. &lt;br&gt;[b]Post the entire contents of C:\ComboFix.txt into your next reply[/b]. &lt;br&gt;[color="red"][b][u]Note[/u][/b]: &lt;br&gt;Do not mouseclick combofix's window while it's running. &lt;br&gt;That may cause the program to freeze/hang. [/color]&lt;br&gt;Do NOT post the ComboFix-quarantined-files.txt unless I ask.&lt;br&gt;[b]*Note*[/b]&lt;br&gt;In case your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix,please disable your scanner and redownload Combofix again.&lt;br&gt;Some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.&lt;br&gt;&lt;br&gt;[b]Also post a new Hijackthis log please[/b].</description><pubDate>Sun, 29 Jun 2008 11:25:11 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>Firefox Hangs &amp; Various Programs Will Not Update (Trojan Infection)</title><link>http://forum.tweaks.com/forum/Topic241833-29-1.aspx</link><description>Greetings,&lt;br&gt;&lt;br&gt;First off, thank you for the recommendations in the post "READ BEFORE POSTING HIJACK THIS LOGS".  I followed the steps and I am still having problems.  When launching Firefox, most times the program will hang and never actually go to the requested website.  AVG will also not update along with SUPERAntispyware and windows XP update.  I am running SP2 and I have done the other updates manually.  In an attempt to correct this problem, below is my Hijackthis log.  If all else fails, wiping the drive and a fresh install of XP is an option, but I would like to try and fix the problem if possible.  I appreciate any help and/or suggestions in advance.  Thank you.  Also, let me know if you need any additional information from me.&lt;br&gt;&lt;br&gt;Hijackthis Log:&lt;br&gt;&lt;br&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br&gt;Scan saved at 10:16:46 AM, on 6/29/2008&lt;br&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br&gt;MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)&lt;br&gt;Boot mode: Normal&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\WINDOWS\System32\smss.exe&lt;br&gt;C:\WINDOWS\system32\winlogon.exe&lt;br&gt;C:\WINDOWS\system32\services.exe&lt;br&gt;C:\WINDOWS\system32\lsass.exe&lt;br&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\system32\ZoneLabs\vsmon.exe&lt;br&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;br&gt;C:\WINDOWS\Explorer.EXE&lt;br&gt;C:\WINDOWS\System32\wltrysvc.exe&lt;br&gt;C:\WINDOWS\System32\bcmwltry.exe&lt;br&gt;C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;br&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br&gt;C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgrsx.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgemc.exe&lt;br&gt;C:\WINDOWS\system32\WLTRAY.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgtray.exe&lt;br&gt;C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&lt;br&gt;C:\WINDOWS\system32\Rundll32.exe&lt;br&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;br&gt;&lt;br&gt;R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://internetsearchservice.com&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://internetsearchservice.com&lt;br&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://internetsearchservice.com&lt;br&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://internetsearchservice.com/ie6.html&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com&lt;br&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://internetsearchservice.com&lt;br&gt;O2 - BHO: (no name) - {1BD73B94-7614-48AA-BAAD-2D6C2B3ECD82} - (no file)&lt;br&gt;O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll&lt;br&gt;O2 - BHO: {cb551c24-df3a-7e59-fbe4-ccda71f96064} - {46069f17-adcc-4ebf-95e7-a3fd42c155bc} - C:\WINDOWS\system32\naaenjcx.dll (file missing)&lt;br&gt;O2 - BHO: (no name) - {922FBD52-7432-4839-BD54-FAF61639020E} - (no file)&lt;br&gt;O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY&lt;br&gt;O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe&lt;br&gt;O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&lt;br&gt;O4 - HKLM\..\Run: [BM9b97b920] Rundll32.exe "C:\WINDOWS\system32\dmjfibcq.dll",s&lt;br&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;O8 - Extra context menu item: &amp;Search - ?p=ZKfox000&lt;br&gt;O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000&lt;br&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O16 - DPF: {00140000-B1BA-11CE-ABC6-F5B2E79D9E3F} (LEAD Main Control (14.0)) - file:///D:/LTOCX14N.cab&lt;br&gt;O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll&lt;br&gt;O20 - AppInit_DLLs: avgrsstx.dll&lt;br&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;br&gt;O20 - Winlogon Notify: jkkHWQKb - jkkHWQKb.dll (file missing)&lt;br&gt;O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;br&gt;O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe&lt;br&gt;O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe&lt;br&gt;O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br&gt;O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe&lt;br&gt;O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe&lt;br&gt;&lt;br&gt;--&lt;br&gt;End of file - 4378 bytes</description><pubDate>Sun, 29 Jun 2008 10:41:19 GMT</pubDate><dc:creator>knight1fox3</dc:creator></item></channel></rss>