﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Tweaks.com Forum  / Windows &amp; System Security / HiJack This Logs  / windows update is always redirected to msn.com / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>Tweaks.com Forum </description><link>http://forum.tweaks.com/forum/</link><webMaster>forum@tweaks.com</webMaster><lastBuildDate>Thu, 20 Nov 2008 03:36:39 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: windows update is always redirected to msn.com</title><link>http://forum.tweaks.com/forum/Topic242225-29-1.aspx</link><description>You're welcome:)</description><pubDate>Tue, 08 Jul 2008 18:27:30 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: windows update is always redirected to msn.com</title><link>http://forum.tweaks.com/forum/Topic242225-29-1.aspx</link><description>Hello,&lt;/P&gt;&lt;P&gt;Excellent, the help everyone has given is much appreciated.</description><pubDate>Tue, 08 Jul 2008 17:16:19 GMT</pubDate><dc:creator>Sancho8297</dc:creator></item><item><title>RE: windows update is always redirected to msn.com</title><link>http://forum.tweaks.com/forum/Topic242225-29-1.aspx</link><description>[quote]I am wondering if I should follow the instructions in this current thread, or to start a new one?[/quote]&lt;br&gt;Start a new topic if you would please.&lt;br&gt;&lt;br&gt;Your log is clean:)&lt;br&gt;&lt;br&gt;You should now take the time to read and follow the information found in the links below,to help you prevent any possible future infections and stay safe and secure while online:&lt;br&gt;&lt;br&gt;[b][color="blue"]Simple and easy ways to keep your computer safe and secure on the Internet[/color][/b]:&lt;br&gt;[url]http://www.bleepingcomputer.com/tutorials/tutorial82.html[/url]&lt;br&gt;&lt;br&gt;[b][color="blue"]How to prevent Malware[/color][/b]:&lt;br&gt;[url]http://users.telenet.be/bluepatchy/miekiemoes/prevention.html[/url]&lt;br&gt;&lt;br&gt;[B][color="blue"]So how did I get infected in the first place[/color][/B]:&lt;br&gt;[URL]http://forums.spybot.info/showthread.php?t=279[/URL]&lt;br&gt;&lt;br&gt;[B][color="blue"]Malware Cleanup Programs and Preventative Procedures[/color][/B]: &lt;br&gt;[URL]http://russelltexas.com/malware/allclear.htm[/URL]&lt;br&gt;&lt;br&gt;[B][color="blue"]How to Set Security Options in the Firefox Browser[/color][/B]:&lt;br&gt;[URL]http://websearch.about.com/od/firefox/ss/firefoxoptions.htm[/URL]&lt;br&gt;&lt;br&gt;[B][color="blue"]Internet Explorer 7 Desktop Security Guide[/color][/B]:&lt;br&gt;[URL]http://www.microsoft.com/downloads/details.aspx?FamilyID=6aa4c1da-6021-468e-a8cf-af4afe4c84b2&amp;DisplayLang=en[/URL]&lt;br&gt;&lt;br&gt;[B][color="blue"]Working with Internet Explorer 6 Security Settings[/color][/B]:&lt;br&gt;[URL]http://www.microsoft.com/windows/ie/ie6/using/howto/security/settings.mspx[/URL]&lt;br&gt;&lt;br&gt;[b][color="blue"]Hardening Windows Security - Part 1[/color][/b]:&lt;br&gt;[url]http://www.malwarehelp.org/Malware-Prevention-Hardening-Windows-Security1.html[/url]&lt;br&gt;&lt;br&gt;[b][color="blue"]Hardening Windows Security - Part 2[/color][/b]:&lt;br&gt;[url]http://www.malwarehelp.org/malware-prevention-hardening-windows-security2.html[/url]&lt;br&gt;</description><pubDate>Tue, 08 Jul 2008 17:09:16 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: windows update is always redirected to msn.com</title><link>http://forum.tweaks.com/forum/Topic242225-29-1.aspx</link><description>Hello,&lt;/P&gt;&lt;P&gt;Ok unistalled combofix and ran malwarebytes. Here is its log and the Hijackthis log. &lt;/P&gt;&lt;P&gt;The computer seems to be running better, it has a much 'cleaner' feeling to me now. Hopefully that takes care of it. Unfortunately for me, there is another computer that seems to have been infected as well (this one is running vista). I am wondering if I should follow the instructions in this current thread, or to start a new one?&lt;/P&gt;&lt;P&gt;Malwarebytes' Anti-Malware 1.20&lt;BR&gt;Database version: 933&lt;BR&gt;Windows 5.1.2600 Service Pack 3&lt;/P&gt;&lt;P&gt;16:52:21 2008-07-08&lt;BR&gt;mbam-log-7-8-2008 (16-52-21).txt&lt;/P&gt;&lt;P&gt;Scan type: Quick Scan&lt;BR&gt;Objects scanned: 40802&lt;BR&gt;Time elapsed: 7 minute(s), 44 second(s)&lt;/P&gt;&lt;P&gt;Memory Processes Infected: 0&lt;BR&gt;Memory Modules Infected: 0&lt;BR&gt;Registry Keys Infected: 6&lt;BR&gt;Registry Values Infected: 1&lt;BR&gt;Registry Data Items Infected: 0&lt;BR&gt;Folders Infected: 0&lt;BR&gt;Files Infected: 1&lt;/P&gt;&lt;P&gt;Memory Processes Infected:&lt;BR&gt;(No malicious items detected)&lt;/P&gt;&lt;P&gt;Memory Modules Infected:&lt;BR&gt;(No malicious items detected)&lt;/P&gt;&lt;P&gt;Registry Keys Infected:&lt;BR&gt;HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -&amp;gt; Quarantined and deleted successfully.&lt;BR&gt;HKEY_CLASSES_ROOT\Typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -&amp;gt; Quarantined and deleted successfully.&lt;BR&gt;HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -&amp;gt; Quarantined and deleted successfully.&lt;BR&gt;HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -&amp;gt; Quarantined and deleted successfully.&lt;BR&gt;HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -&amp;gt; Quarantined and deleted successfully.&lt;BR&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -&amp;gt; Quarantined and deleted successfully.&lt;/P&gt;&lt;P&gt;Registry Values Infected:&lt;BR&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll (Adware.Minibug) -&amp;gt; Quarantined and deleted successfully.&lt;/P&gt;&lt;P&gt;Registry Data Items Infected:&lt;BR&gt;(No malicious items detected)&lt;/P&gt;&lt;P&gt;Folders Infected:&lt;BR&gt;(No malicious items detected)&lt;/P&gt;&lt;P&gt;Files Infected:&lt;BR&gt;C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll (Adware.Minibug) -&amp;gt; Quarantined and deleted successfully.&lt;BR&gt;&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 16:55, on 2008-07-08&lt;BR&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16674)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\csrss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;BR&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;BR&gt;C:\WINDOWS\System32\nvsvc32.exe&lt;BR&gt;C:\WINDOWS\system32\PSIService.exe&lt;BR&gt;C:\Program Files\Spyware Doctor\pctsAuxs.exe&lt;BR&gt;C:\Program Files\Spyware Doctor\pctsSvc.exe&lt;BR&gt;C:\Program Files\Spyware Doctor\pctsTray.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe&lt;BR&gt;C:\WINDOWS\System32\alg.exe&lt;BR&gt;C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe&lt;BR&gt;C:\WINDOWS\System32\hphmon03.exe&lt;BR&gt;C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe&lt;BR&gt;C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe&lt;BR&gt;C:\WINDOWS\BCMSMMSG.exe&lt;BR&gt;C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe&lt;BR&gt;C:\Program Files\Microsoft IntelliType Pro\itype.exe&lt;BR&gt;C:\Program Files\Microsoft IntelliPoint\ipoint.exe&lt;BR&gt;C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe&lt;BR&gt;C:\PROGRA~1\HEWLET~1\PHOTOS~1\HPSHAR~1\hpgs2wnf.exe&lt;BR&gt;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&lt;BR&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe&lt;BR&gt;C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe&lt;BR&gt;C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe&lt;BR&gt;C:\WINDOWS\system32\RUNDLL32.EXE&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\Program Files\Digital Support\DigitalSupportLocalService.exe&lt;BR&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;BR&gt;C:\PROGRA~1\Webshots\webshots.scr&lt;BR&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;BR&gt;C:\Program Files\Webroot\Spy Sweeper\SSU.EXE&lt;BR&gt;C:\WINDOWS\system32\NOTEPAD.EXE&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;BR&gt;C:\WINDOWS\System32\wbem\wmiprvse.exe&lt;/P&gt;&lt;P&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.yahoo.com/"&gt;http://www.yahoo.com/&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"&lt;BR&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;BR&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;BR&gt;O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll&lt;BR&gt;O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll&lt;BR&gt;O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll&lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll&lt;BR&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll&lt;BR&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.3558\swg.dll&lt;BR&gt;O3 - Toolbar: &amp;amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll&lt;BR&gt;O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe&lt;BR&gt;O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03.exe&lt;BR&gt;O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"&lt;BR&gt;O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] "C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe"&lt;BR&gt;O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe&lt;BR&gt;O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup&lt;BR&gt;O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install&lt;BR&gt;O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"&lt;BR&gt;O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"&lt;BR&gt;O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"&lt;BR&gt;O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"&lt;BR&gt;O4 - HKLM\..\Run: [Hijri_Cal] "C:\Program Files\DivineIslam\HijriCal1\Hijri_Cal.exe"&lt;BR&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"&lt;BR&gt;O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot&lt;BR&gt;O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime&lt;BR&gt;O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"&lt;BR&gt;O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"&lt;BR&gt;O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"&lt;BR&gt;O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray&lt;BR&gt;O4 - HKCU\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O4 - HKCU\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search" Protection\SearchProtection.exe&lt;BR&gt;O4 - HKCU\..\Run: [SpybotSD TeaTimer] H:\Spybot - Search &amp;amp; Destroy\TeaTimer.exe&lt;BR&gt;O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe&lt;BR&gt;O4 - Global Startup: Digital Support Local Service.lnk = C:\Program Files\Digital Support\DigitalSupportLocalService.exe&lt;BR&gt;O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE&lt;BR&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000&lt;BR&gt;O8 - Extra context menu item: Lookup on Merriam Webster - &lt;A href="file://C:\Program"&gt;file://C:\Program&lt;/A&gt; Files\ieSpell\Merriam Webster.HTM&lt;BR&gt;O8 - Extra context menu item: Lookup on Wikipedia - &lt;A href="file://C:\Program"&gt;file://C:\Program&lt;/A&gt; Files\ieSpell\wikipedia.HTM&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll&lt;BR&gt;O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll&lt;BR&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll&lt;BR&gt;O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll&lt;BR&gt;O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &lt;A href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1173942424531"&gt;http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1173942424531&lt;/A&gt;&lt;BR&gt;O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe&lt;BR&gt;O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;BR&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;BR&gt;O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;BR&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe&lt;BR&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;BR&gt;O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\system32\NMSSvc.exe&lt;BR&gt;O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe&lt;BR&gt;O23 - Service: Pml Driver - HP - C:\WINDOWS\System32\HPHipm09.exe&lt;BR&gt;O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe&lt;BR&gt;O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe&lt;BR&gt;O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe&lt;BR&gt;O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 10271 bytes&lt;BR&gt;</description><pubDate>Tue, 08 Jul 2008 16:58:02 GMT</pubDate><dc:creator>Sancho8297</dc:creator></item><item><title>RE: windows update is always redirected to msn.com</title><link>http://forum.tweaks.com/forum/Topic242225-29-1.aspx</link><description>Click on Start/Run,copy and paste [b]ComboFix /u[/b] into the '[u]O[/u]pen:' space,then press OK [see image below]&lt;br&gt;This will uninstall Combofix,delete its related folders and files,reset your clock settings,hide file extensions,hide the system/hidden files and resets System Restore.&lt;br&gt;&lt;br&gt;[IMG]http://img.photobucket.com/albums/v624/29wood/comu.gif[/IMG]&lt;br&gt;&lt;br&gt;&lt;br&gt;[b]Please disable Spybot S&amp;D’s protection,or it will interfere.&lt;br&gt;You can enable it after you're clean.[/b]&lt;br&gt;Open Spybot and click on 'Mode' and check 'Advanced Mode'.&lt;br&gt;Click on 'Tools' in bottom left hand corner.&lt;br&gt;Click on the 'System Startup' icon.&lt;br&gt;Uncheck 'Teatimer' box and/or uncheck 'Resident'.&lt;br&gt;Click the 'Allow Change' box.&lt;br&gt;Then, check next to the computer clock to see if the icon for Spybot is still there.&lt;br&gt;If it is, right click it and choose 'exit Spybot-S&amp;D Resident'.&lt;br&gt;[b]Restart the computer.[/b]&lt;br&gt;If you find you're experiencing problems disabling Spybot's Tea-Timer,follow the info in the link below:&lt;br&gt;[url]http://www.russelltexas.com/malware/teatimer.htm[/url]&lt;br&gt;&lt;br&gt;&lt;br&gt;Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'. &lt;br&gt;Make sure all browser and all Windows Explorer windows are closed before fixing:&lt;br&gt;[b]O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)&lt;br&gt;O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - H:\Spybot - Search &amp; Destroy\SDHelper.dll (file missing)&lt;br&gt;O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\Spybot - Search &amp; Destroy\SDHelper.dll (file missing)&lt;br&gt;O9 - Extra 'Tools' menuitem: Spybot - Search &amp;&amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\Spybot - Search &amp; Destroy\SDHelper.dll (file missing)[/b]&lt;br&gt;&lt;br&gt;&lt;br&gt;Please download [b][color="red"]Malwarebytes Anti-Malware[/color][/b]:&lt;br&gt;[url]http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html[/url]&lt;br&gt;[url]http://www.besttechie.net/tools/mbam-setup.exe[/url]&lt;br&gt;&lt;br&gt;Double Click mbam-setup.exe to install the application.&lt;br&gt;(If using Windows Vista,be sure to [b][url=http://windowshelp.microsoft.com/Windows/en-US/Help/fb464905-31d5-4427-89a2-ed5322327fc21033.mspx][color="blue"]"Run As Administrator"[/color][/url][/b]).&lt;br&gt;&lt;br&gt;* Make sure a checkmark is placed next to [b]Update Malwarebytes' Anti-Malware[/b] and [b]Launch Malwarebytes' Anti-Malware[/b], then click Finish.&lt;br&gt;* If an update is found, it will download and install the latest version.&lt;br&gt;* Once the program has loaded, select "Perform Quick Scan", then click Scan.&lt;br&gt;* The scan may take some time to finish,so please be patient.&lt;br&gt;* When the scan is complete, click OK, then Show Results to view the results.&lt;br&gt;* Make sure that everything is checked, and click Remove Selected.&lt;br&gt;* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)&lt;br&gt;* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.&lt;br&gt;* [b]Copy and paste the entire report into your next reply[/b].&lt;br&gt;&lt;br&gt;Extra Note:&lt;br&gt;[b][color="green"]If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.[/color][/b]&lt;br&gt;&lt;br&gt;[b]Also post a new Hijackthis log,let me know how your pc is running now.[/b]</description><pubDate>Tue, 08 Jul 2008 16:17:35 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: windows update is always redirected to msn.com</title><link>http://forum.tweaks.com/forum/Topic242225-29-1.aspx</link><description>Hello,&lt;/P&gt;&lt;P&gt;ran the combofix, here is the report:&lt;/P&gt;&lt;P&gt;ComboFix 08-07-07.3 - Andrea Hobright 2008-07-08 15:18:36.1 - NTFSx86&lt;BR&gt;Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.615 [GMT -5:00]&lt;BR&gt;Running from: C:\Documents and Settings\Andrea Hobright\desktop\combofix.exe&lt;BR&gt;Command switches used :: /killall&lt;BR&gt; * Created a new restore point&lt;BR&gt; * Resident AV is active&lt;/P&gt;&lt;P&gt;&lt;BR&gt;[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;C:\WINDOWS\system32\UpMedia&lt;/P&gt;&lt;P&gt;.&lt;BR&gt;(((((((((((((((((((((((((   Files Created from 2008-06-08 to 2008-07-08  )))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;2008-07-08 14:39 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl&lt;BR&gt;2008-07-08 14:37 . 2008-07-08 14:37 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\Java&lt;BR&gt;2008-07-08 03:23 . 2008-07-08 03:23 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Avira&lt;BR&gt;2008-07-08 03:23 . 2008-07-08 03:23 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Avira&lt;BR&gt;2008-07-08 02:08 . 2008-07-08 02:08 &amp;lt;DIR&amp;gt; d-------- C:\WINDOWS\system32\scripting&lt;BR&gt;2008-07-08 02:08 . 2008-07-08 02:08 &amp;lt;DIR&amp;gt; d-------- C:\WINDOWS\system32\en&lt;BR&gt;2008-07-08 02:08 . 2008-07-08 02:08 &amp;lt;DIR&amp;gt; d-------- C:\WINDOWS\l2schemas&lt;BR&gt;2008-07-08 01:23 . 2008-04-13 19:12 712,704 --------- C:\WINDOWS\system32\windowscodecs.dll&lt;BR&gt;2008-07-08 01:23 . 2008-04-13 19:12 346,112 --------- C:\WINDOWS\system32\windowscodecsext.dll&lt;BR&gt;2008-07-08 01:23 . 2008-04-13 19:12 276,992 --------- C:\WINDOWS\system32\wmphoto.dll&lt;BR&gt;2008-07-08 01:23 . 2008-04-13 19:12 69,120 --------- C:\WINDOWS\system32\wlanapi.dll&lt;BR&gt;2008-07-08 01:22 . 2008-04-13 19:12 290,304 --------- C:\WINDOWS\system32\rhttpaa.dll&lt;BR&gt;2008-07-08 01:22 . 2008-04-13 19:12 53,248 --------- C:\WINDOWS\system32\tsgqec.dll&lt;BR&gt;2008-07-08 01:22 . 2008-04-13 19:12 50,688 --------- C:\WINDOWS\system32\tspkg.dll&lt;BR&gt;2008-07-08 01:22 . 2008-04-13 19:12 32,768 --------- C:\WINDOWS\system32\setupn.exe&lt;BR&gt;2008-07-08 01:22 . 2008-04-13 13:40 10,240 --------- C:\WINDOWS\system32\drivers\sffp_mmc.sys&lt;BR&gt;2008-07-08 01:20 . 2008-04-13 19:11 397,312 --------- C:\WINDOWS\system32\mmcex.dll&lt;BR&gt;2008-07-08 01:20 . 2008-04-13 19:11 184,320 --------- C:\WINDOWS\system32\microsoft.managementconsole.dll&lt;BR&gt;2008-07-08 01:20 . 2008-04-13 19:11 106,496 --------- C:\WINDOWS\system32\mmcfxcommon.dll&lt;BR&gt;2008-07-08 01:20 . 2008-04-13 19:12 33,792 --------- C:\WINDOWS\system32\mmcperf.exe&lt;BR&gt;2008-07-08 01:19 . 2008-04-13 11:36 144,384 --------- C:\WINDOWS\system32\drivers\hdaudbus.sys&lt;BR&gt;2008-07-08 01:19 . 2008-04-13 19:11 61,440 --------- C:\WINDOWS\system32\kmsvc.dll&lt;BR&gt;2008-07-08 01:19 . 2008-04-13 19:11 37,376 --------- C:\WINDOWS\system32\l2gpstore.dll&lt;BR&gt;2008-07-08 01:19 . 2008-04-13 19:09 6,144 --------- C:\WINDOWS\system32\kbdpash.dll&lt;BR&gt;2008-07-08 01:19 . 2008-04-13 19:09 6,144 --------- C:\WINDOWS\system32\kbdnepr.dll&lt;BR&gt;2008-07-08 01:19 . 2008-04-13 19:09 6,144 --------- C:\WINDOWS\system32\kbdiultn.dll&lt;BR&gt;2008-07-08 01:19 . 2008-04-13 19:09 6,144 --------- C:\WINDOWS\system32\kbdbhc.dll&lt;BR&gt;2008-07-08 01:19 . 2007-09-17 03:48 1,261 --------- C:\WINDOWS\system32\pid.inf&lt;BR&gt;2008-07-08 01:17 . 2008-04-13 19:11 233,472 --------- C:\WINDOWS\system32\azroles.dll&lt;BR&gt;2008-07-08 01:17 . 2008-04-13 19:11 136,192 --------- C:\WINDOWS\system32\aaclient.dll&lt;BR&gt;2008-07-08 01:17 . 2008-04-13 19:11 12,800 --------- C:\WINDOWS\system32\credssp.dll&lt;BR&gt;2008-07-08 01:17 . 2008-04-13 19:11 7,168 --------- C:\WINDOWS\system32\bitsprx4.dll&lt;BR&gt;2008-07-07 15:31 . 2008-06-13 06:05 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys&lt;BR&gt;2008-07-07 15:25 . 2008-05-08 09:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys&lt;BR&gt;2008-07-07 12:42 . 2008-07-07 12:42 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\PC Tools&lt;BR&gt;2008-07-07 12:42 . 2008-07-07 12:28 159,880 --a------ C:\WINDOWS\system32\drivers\pctfw2.sys&lt;BR&gt;2008-07-07 12:28 . 2008-07-07 12:29 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\PC Tools&lt;BR&gt;2008-07-07 04:51 . 2007-12-10 13:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys&lt;BR&gt;2008-07-07 04:51 . 2007-12-10 13:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys&lt;BR&gt;2008-07-07 04:51 . 2008-02-01 11:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys&lt;BR&gt;2008-07-07 04:51 . 2007-12-10 13:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys&lt;BR&gt;2008-07-07 04:50 . 2008-07-07 23:33 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Spyware Doctor&lt;BR&gt;2008-07-07 04:50 . 2008-07-07 04:50 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\Andrea Hobright\Application Data\PC Tools&lt;BR&gt;2008-07-06 02:35 . 2008-07-06 02:38 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\SpywareBlaster&lt;BR&gt;2008-07-06 01:19 . 2008-07-06 01:19 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\CCleaner&lt;BR&gt;2008-07-05 23:44 . 2008-07-07 14:33 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Spybot - Search &amp;amp; Destroy&lt;BR&gt;2008-07-05 23:44 . 2008-07-08 12:30 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search &amp;amp; Destroy&lt;BR&gt;2008-07-05 23:18 . 2008-07-05 23:18 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Lavasoft&lt;BR&gt;2008-07-05 23:18 . 2008-07-05 23:21 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft&lt;BR&gt;2008-07-05 23:17 . 2008-07-08 02:34 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\Wise Installation Wizard&lt;BR&gt;2008-07-05 22:44 . 2008-07-08 14:50 &amp;lt;DIR&amp;gt; d-------- C:\fixwareout&lt;BR&gt;2008-07-05 22:38 . 2008-07-05 22:38 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Trend Micro&lt;BR&gt;2008-07-05 22:32 . 2008-07-05 22:32 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Belarc&lt;BR&gt;2008-07-05 22:32 . 2008-02-27 13:49 3,840 --a------ C:\WINDOWS\system32\drivers\BANTExt.sys&lt;BR&gt;2008-06-24 12:22 . 2008-07-05 22:17 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Altnet Music Plugin&lt;/P&gt;&lt;P&gt;.&lt;BR&gt;((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;BR&gt;2008-07-08 20:30 --------- d-----w C:\Program Files\Digital Support&lt;BR&gt;2008-07-08 20:29 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP&lt;BR&gt;2008-07-08 19:39 --------- d-----w C:\Program Files\Java&lt;BR&gt;2008-07-08 17:33 --------- d-----w C:\Documents and Settings\Andrea Hobright\Application Data\U3&lt;BR&gt;2008-07-07 09:12 --------- d-----w C:\Program Files\Yahoo!&lt;BR&gt;2008-07-06 06:10 --------- d-----w C:\Program Files\ErrorSmart&lt;BR&gt;2008-07-06 03:21 --------- d-----w C:\Program Files\Apple Software Update&lt;BR&gt;2008-07-06 03:20 --------- d-----w C:\Program Files\Virtual Earth 3D&lt;BR&gt;2008-07-06 03:19 --------- d-----w C:\Program Files\WinZip(2)&lt;BR&gt;2008-07-06 03:19 --------- d-----w C:\Program Files\Webshots&lt;BR&gt;2008-07-06 03:16 --------- d-----w C:\Program Files\Susteen&lt;BR&gt;2008-06-13 11:05 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys&lt;BR&gt;2008-05-17 19:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip&lt;BR&gt;2008-05-08 14:02 203,136 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys&lt;BR&gt;2008-04-14 00:11 451,072 ----a-w C:\WINDOWS\AppPatch\aclayers.dll&lt;BR&gt;2008-04-14 00:11 39,424 ----a-w C:\WINDOWS\AppPatch\acadproc.dll&lt;BR&gt;2008-04-14 00:11 376,832 ----a-w C:\WINDOWS\PCHealth\HelpCtr\Binaries\msinfo.dll&lt;BR&gt;2008-04-14 00:11 245,248 ----a-w C:\WINDOWS\AppPatch\acspecfc.dll&lt;BR&gt;2008-04-14 00:11 141,312 ----a-w C:\WINDOWS\AppPatch\aclua.dll&lt;BR&gt;2008-04-14 00:11 116,224 ----a-w C:\WINDOWS\AppPatch\acxtrnal.dll&lt;BR&gt;2008-04-14 00:11 1,852,928 ----a-w C:\WINDOWS\AppPatch\acgenral.dll&lt;BR&gt;2008-01-24 22:03 103,624 ----a-w C:\Documents and Settings\Andrea Hobright\Application Data\GDIPFONTCACHEV1.DAT&lt;BR&gt;2002-09-03 17:07 94,784 --sh--w C:\WINDOWS\twain.dll&lt;BR&gt;2007-08-18 20:40 88 --sh--r C:\WINDOWS\system32\C7D547B3AC.sys&lt;BR&gt;2007-08-18 20:40 2,828 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;BR&gt;.&lt;BR&gt;*Note* empty entries &amp;amp; legit default entries are not shown &lt;BR&gt;REGEDIT4&lt;/P&gt;&lt;P&gt;[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"NvMediaCenter"="C:\WINDOWS\System32\NVMCTRAY.DLL" [2003-10-06 15:16 49152]&lt;BR&gt;"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 19:12 15360]&lt;BR&gt;"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 09:59 224248]&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-08-03 21:24 196608]&lt;BR&gt;"HPHmon03"="C:\WINDOWS\System32\hphmon03.exe" [2001-08-03 21:24 311296]&lt;BR&gt;"CXMon"="C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe" [2001-08-09 18:06 45056]&lt;BR&gt;"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 10:11 57344]&lt;BR&gt;"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2003-10-06 15:16 5058560]&lt;BR&gt;"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46 57344]&lt;BR&gt;"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2006-07-07 18:14 576320]&lt;BR&gt;"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2006-07-07 18:15 600896]&lt;BR&gt;"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 09:59 224248]&lt;BR&gt;"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]&lt;BR&gt;"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-03-27 17:19 185896]&lt;BR&gt;"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]&lt;BR&gt;"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]&lt;BR&gt;"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-04-10 15:14 1107848]&lt;BR&gt;"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]&lt;BR&gt;"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]&lt;BR&gt;"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2008-01-04 21:56 5367664]&lt;BR&gt;"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 05:59 122880 C:\WINDOWS\BCMSMMSG.exe]&lt;BR&gt;"nwiz"="nwiz.exe" [2003-10-06 15:16 741376 C:\WINDOWS\system32\nwiz.exe]&lt;/P&gt;&lt;P&gt;C:\Documents and Settings\Andrea Hobright\Start Menu\Programs\Startup\&lt;BR&gt;Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2007-03-15 00:59:15 45056]&lt;/P&gt;&lt;P&gt;C:\Documents and Settings\All Users\Start Menu\Programs\Startup\&lt;BR&gt;Digital Support Local Service.lnk - C:\Program Files\Digital Support\DigitalSupportLocalService.exe [2008-03-02 16:28:21 284704]&lt;BR&gt;Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]&lt;/P&gt;&lt;P&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]&lt;BR&gt;"%windir%\\system32\\sessmgr.exe"=&lt;BR&gt;"%windir%\\Network Diagnostic\\xpnetdiag.exe"=&lt;BR&gt;"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=&lt;BR&gt;"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=&lt;BR&gt;"C:\\Program Files\\Digital Support\\DigitalSupportLocalService.exe"=&lt;BR&gt;"C:\\WINDOWS\\system32\\mmc.exe"=&lt;BR&gt;"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=&lt;BR&gt;"C:\\Program Files\\iTunes\\iTunes.exe"=&lt;BR&gt;"C:\\Program Files\\Webroot\\Spy Sweeper\\SpySweeperUI.exe"=&lt;BR&gt;"C:\\StubInstaller.exe"=&lt;BR&gt;"C:\\Program Files\\Spyware Doctor\\pctsGui.exe"=&lt;BR&gt;"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=&lt;/P&gt;&lt;P&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]&lt;BR&gt;"135:TCP"= 135:TCP:DCOM(135)&lt;/P&gt;&lt;P&gt;R1 pctfw2;pctfw2;C:\WINDOWS\system32\drivers\pctfw2.sys [2008-07-07 12:28]&lt;BR&gt;S3 Dot4Usb HPH09;Dot4Usb HPH09;C:\WINDOWS\system32\drivers\hphius09.sys [2001-08-03 21:24]&lt;BR&gt;S3 MTK;Media Technology Kernel Driver;C:\WINDOWS\system32\Drivers\mtk.sys []&lt;BR&gt;S3 SUSTUCAM;Susteen USB Cable Modem Driver;C:\WINDOWS\system32\DRIVERS\sustucam.sys [2007-04-04 19:50]&lt;BR&gt;S3 SUSTUCAP;Susteen USB Cable Port Driver;C:\WINDOWS\system32\DRIVERS\sustucap.sys [2007-04-04 19:50]&lt;BR&gt;S3 SUSTUCAU;Susteen USB Cable USB Driver;C:\WINDOWS\system32\DRIVERS\sustucau.sys [2007-04-04 19:56]&lt;/P&gt;&lt;P&gt;.&lt;BR&gt;Contents of the 'Scheduled Tasks' folder&lt;BR&gt;"2008-07-07 19:48:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"&lt;BR&gt;- C:\Program Files\Apple Software Update\SoftwareUpdate.exe&lt;BR&gt;"2008-07-08 20:27:13 C:\WINDOWS\Tasks\RegCure Program Check.job"&lt;BR&gt;- C:\Program Files\RegCure\RegCure.exe&lt;BR&gt;"2008-07-03 08:00:00 C:\WINDOWS\Tasks\RegCure.job"&lt;BR&gt;- C:\Program Files\RegCure\RegCure.exe&lt;BR&gt;"2008-07-08 09:01:24 C:\WINDOWS\Tasks\wrSpySweeper_L8C67B5F34FD847C5933EF2AF81C61E5E.job"&lt;BR&gt;- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe&amp;gt;/ScheduleSweep=wrSpySweeper_L8C67B5F34FD847C5933EF2AF81C61E5E&lt;BR&gt;- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.ex&lt;BR&gt;- C:\&lt;BR&gt;.&lt;BR&gt;- - - - ORPHANS REMOVED - - - -&lt;/P&gt;&lt;P&gt;HKCU-Run-SpybotSD TeaTimer - H:\Spybot - Search &amp;amp; Destroy\TeaTimer.exe&lt;BR&gt;HKLM-Run-Hijri_Cal - C:\Program Files\DivineIslam\HijriCal1\Hijri_Cal.exe&lt;/P&gt;&lt;P&gt;&lt;BR&gt;**************************************************************************&lt;/P&gt;&lt;P&gt;catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &lt;A href="http://www.gmer.net"&gt;http://www.gmer.net&lt;/A&gt;&lt;BR&gt;Rootkit scan 2008-07-08 15:28:09&lt;BR&gt;Windows 5.1.2600 Service Pack 3 NTFS&lt;/P&gt;&lt;P&gt;scanning hidden processes ... &lt;/P&gt;&lt;P&gt;scanning hidden autostart entries ...&lt;/P&gt;&lt;P&gt;scanning hidden files ... &lt;/P&gt;&lt;P&gt;&lt;BR&gt;**************************************************************************&lt;BR&gt;.&lt;BR&gt;HIJACK THIS LOG&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 15:46, on 2008-07-08&lt;BR&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16674)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\csrss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;BR&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;BR&gt;C:\WINDOWS\System32\nvsvc32.exe&lt;BR&gt;C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe&lt;BR&gt;C:\WINDOWS\system32\PSIService.exe&lt;BR&gt;C:\WINDOWS\System32\hphmon03.exe&lt;BR&gt;C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe&lt;BR&gt;C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe&lt;BR&gt;C:\WINDOWS\BCMSMMSG.exe&lt;BR&gt;C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe&lt;BR&gt;C:\Program Files\Microsoft IntelliType Pro\itype.exe&lt;BR&gt;C:\Program Files\Microsoft IntelliPoint\ipoint.exe&lt;BR&gt;C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe&lt;BR&gt;C:\Program Files\Spyware Doctor\pctsAuxs.exe&lt;BR&gt;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&lt;BR&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;BR&gt;C:\Program Files\Spyware Doctor\pctsSvc.exe&lt;BR&gt;C:\Program Files\Spyware Doctor\pctsTray.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe&lt;BR&gt;C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe&lt;BR&gt;C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe&lt;BR&gt;C:\WINDOWS\system32\RUNDLL32.EXE&lt;BR&gt;C:\PROGRA~1\HEWLET~1\PHOTOS~1\HPSHAR~1\hpgs2wnf.exe&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\Program Files\Digital Support\DigitalSupportLocalService.exe&lt;BR&gt;C:\PROGRA~1\Webshots\webshots.scr&lt;BR&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;BR&gt;C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe&lt;BR&gt;C:\WINDOWS\System32\alg.exe&lt;BR&gt;C:\Program Files\Webroot\Spy Sweeper\SSU.EXE&lt;BR&gt;C:\WINDOWS\system32\NOTEPAD.EXE&lt;BR&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;BR&gt;C:\WINDOWS\System32\wbem\wmiprvse.exe&lt;/P&gt;&lt;P&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.yahoo.com/"&gt;http://www.yahoo.com/&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"&lt;BR&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;BR&gt;O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)&lt;BR&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;BR&gt;O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll&lt;BR&gt;O2 - BHO: Spybot-S&amp;amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - H:\Spybot - Search &amp;amp; Destroy\SDHelper.dll (file missing)&lt;BR&gt;O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll&lt;BR&gt;O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll&lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll&lt;BR&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll&lt;BR&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.3558\swg.dll&lt;BR&gt;O3 - Toolbar: &amp;amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll&lt;BR&gt;O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe&lt;BR&gt;O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03.exe&lt;BR&gt;O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"&lt;BR&gt;O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] "C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe"&lt;BR&gt;O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe&lt;BR&gt;O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup&lt;BR&gt;O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install&lt;BR&gt;O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"&lt;BR&gt;O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"&lt;BR&gt;O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"&lt;BR&gt;O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"&lt;BR&gt;O4 - HKLM\..\Run: [Hijri_Cal] "C:\Program Files\DivineIslam\HijriCal1\Hijri_Cal.exe"&lt;BR&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"&lt;BR&gt;O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot&lt;BR&gt;O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime&lt;BR&gt;O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"&lt;BR&gt;O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"&lt;BR&gt;O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"&lt;BR&gt;O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray&lt;BR&gt;O4 - HKCU\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O4 - HKCU\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search" Protection\SearchProtection.exe&lt;BR&gt;O4 - HKCU\..\Run: [SpybotSD TeaTimer] H:\Spybot - Search &amp;amp; Destroy\TeaTimer.exe&lt;BR&gt;O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe&lt;BR&gt;O4 - Global Startup: Digital Support Local Service.lnk = C:\Program Files\Digital Support\DigitalSupportLocalService.exe&lt;BR&gt;O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE&lt;BR&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000&lt;BR&gt;O8 - Extra context menu item: Lookup on Merriam Webster - &lt;A href="file://C:\Program"&gt;file://C:\Program&lt;/A&gt; Files\ieSpell\Merriam Webster.HTM&lt;BR&gt;O8 - Extra context menu item: Lookup on Wikipedia - &lt;A href="file://C:\Program"&gt;file://C:\Program&lt;/A&gt; Files\ieSpell\wikipedia.HTM&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll&lt;BR&gt;O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll&lt;BR&gt;O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\Spybot - Search &amp;amp; Destroy\SDHelper.dll (file missing)&lt;BR&gt;O9 - Extra 'Tools' menuitem: Spybot - Search &amp;amp;&amp;amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\Spybot - Search &amp;amp; Destroy\SDHelper.dll (file missing)&lt;BR&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll&lt;BR&gt;O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll&lt;BR&gt;O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &lt;A href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1173942424531"&gt;http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1173942424531&lt;/A&gt;&lt;BR&gt;O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe&lt;BR&gt;O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;BR&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;BR&gt;O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;BR&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe&lt;BR&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;BR&gt;O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\system32\NMSSvc.exe&lt;BR&gt;O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe&lt;BR&gt;O23 - Service: Pml Driver - HP - C:\WINDOWS\System32\HPHipm09.exe&lt;BR&gt;O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe&lt;BR&gt;O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe&lt;BR&gt;O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe&lt;BR&gt;O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 10784 bytes&lt;BR&gt;</description><pubDate>Tue, 08 Jul 2008 15:46:54 GMT</pubDate><dc:creator>Sancho8297</dc:creator></item><item><title>RE: windows update is always redirected to msn.com</title><link>http://forum.tweaks.com/forum/Topic242225-29-1.aspx</link><description>Thanks,now follow the Combofix instructions if you would please.</description><pubDate>Tue, 08 Jul 2008 15:11:10 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: windows update is always redirected to msn.com</title><link>http://forum.tweaks.com/forum/Topic242225-29-1.aspx</link><description>Hello,&lt;/P&gt;&lt;P&gt;Sorry I forgot about the Hijack this file. Here it is&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 3:10:05 PM, on 7/8/2008&lt;BR&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16674)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\csrss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;BR&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;BR&gt;C:\WINDOWS\System32\nvsvc32.exe&lt;BR&gt;C:\WINDOWS\system32\PSIService.exe&lt;BR&gt;C:\Program Files\Spyware Doctor\pctsAuxs.exe&lt;BR&gt;C:\Program Files\Spyware Doctor\pctsSvc.exe&lt;BR&gt;C:\Program Files\Spyware Doctor\pctsTray.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe&lt;BR&gt;C:\WINDOWS\System32\alg.exe&lt;BR&gt;C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe&lt;BR&gt;C:\WINDOWS\System32\hphmon03.exe&lt;BR&gt;C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe&lt;BR&gt;C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe&lt;BR&gt;C:\WINDOWS\BCMSMMSG.exe&lt;BR&gt;C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe&lt;BR&gt;C:\PROGRA~1\HEWLET~1\PHOTOS~1\HPSHAR~1\hpgs2wnf.exe&lt;BR&gt;C:\Program Files\Microsoft IntelliType Pro\itype.exe&lt;BR&gt;C:\Program Files\Microsoft IntelliPoint\ipoint.exe&lt;BR&gt;C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe&lt;BR&gt;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&lt;BR&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe&lt;BR&gt;C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe&lt;BR&gt;C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe&lt;BR&gt;C:\WINDOWS\system32\RUNDLL32.EXE&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\Program Files\Digital Support\DigitalSupportLocalService.exe&lt;BR&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;BR&gt;C:\PROGRA~1\Webshots\webshots.scr&lt;BR&gt;C:\Program Files\Webroot\Spy Sweeper\SSU.EXE&lt;BR&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;BR&gt;C:\WINDOWS\system32\NOTEPAD.EXE&lt;BR&gt;C:\WINDOWS\system32\NOTEPAD.EXE&lt;BR&gt;C:\WINDOWS\system32\NOTEPAD.EXE&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;BR&gt;C:\WINDOWS\System32\wbem\wmiprvse.exe&lt;/P&gt;&lt;P&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.yahoo.com/"&gt;http://www.yahoo.com/&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"&lt;BR&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;BR&gt;O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)&lt;BR&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;BR&gt;O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll&lt;BR&gt;O2 - BHO: Spybot-S&amp;amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - H:\Spybot - Search &amp;amp; Destroy\SDHelper.dll (file missing)&lt;BR&gt;O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll&lt;BR&gt;O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll&lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll&lt;BR&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll&lt;BR&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.3558\swg.dll&lt;BR&gt;O3 - Toolbar: &amp;amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll&lt;BR&gt;O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe&lt;BR&gt;O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03.exe&lt;BR&gt;O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"&lt;BR&gt;O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] "C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe"&lt;BR&gt;O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe&lt;BR&gt;O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup&lt;BR&gt;O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install&lt;BR&gt;O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"&lt;BR&gt;O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"&lt;BR&gt;O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"&lt;BR&gt;O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"&lt;BR&gt;O4 - HKLM\..\Run: [Hijri_Cal] "C:\Program Files\DivineIslam\HijriCal1\Hijri_Cal.exe"&lt;BR&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"&lt;BR&gt;O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot&lt;BR&gt;O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime&lt;BR&gt;O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"&lt;BR&gt;O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"&lt;BR&gt;O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"&lt;BR&gt;O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray&lt;BR&gt;O4 - HKCU\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O4 - HKCU\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search" Protection\SearchProtection.exe&lt;BR&gt;O4 - HKCU\..\Run: [SpybotSD TeaTimer] H:\Spybot - Search &amp;amp; Destroy\TeaTimer.exe&lt;BR&gt;O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe&lt;BR&gt;O4 - Global Startup: Digital Support Local Service.lnk = C:\Program Files\Digital Support\DigitalSupportLocalService.exe&lt;BR&gt;O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE&lt;BR&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000&lt;BR&gt;O8 - Extra context menu item: Lookup on Merriam Webster - &lt;A href="file://C:\Program"&gt;file://C:\Program&lt;/A&gt; Files\ieSpell\Merriam Webster.HTM&lt;BR&gt;O8 - Extra context menu item: Lookup on Wikipedia - &lt;A href="file://C:\Program"&gt;file://C:\Program&lt;/A&gt; Files\ieSpell\wikipedia.HTM&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll&lt;BR&gt;O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll&lt;BR&gt;O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\Spybot - Search &amp;amp; Destroy\SDHelper.dll (file missing)&lt;BR&gt;O9 - Extra 'Tools' menuitem: Spybot - Search &amp;amp;&amp;amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\Spybot - Search &amp;amp; Destroy\SDHelper.dll (file missing)&lt;BR&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll&lt;BR&gt;O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll&lt;BR&gt;O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &lt;A href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1173942424531"&gt;http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1173942424531&lt;/A&gt;&lt;BR&gt;O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe&lt;BR&gt;O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;BR&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;BR&gt;O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;BR&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe&lt;BR&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;BR&gt;O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\system32\NMSSvc.exe&lt;BR&gt;O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe&lt;BR&gt;O23 - Service: Pml Driver - HP - C:\WINDOWS\System32\HPHipm09.exe&lt;BR&gt;O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe&lt;BR&gt;O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe&lt;BR&gt;O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe&lt;BR&gt;O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 10851 bytes&lt;BR&gt;</description><pubDate>Tue, 08 Jul 2008 15:10:43 GMT</pubDate><dc:creator>Sancho8297</dc:creator></item><item><title>RE: windows update is always redirected to msn.com</title><link>http://forum.tweaks.com/forum/Topic242225-29-1.aspx</link><description>Hello,&lt;/P&gt;&lt;P&gt;Ok sorry for the delay in response, but when i first ran the anti virus it scanned for 9 hours before completely stalling. I was hesitant to stop it at all, but figured after 9 hours and no more progress something was wrong. So I stopped, rebooted and ran another scan. I have the logs from both scans, I will post the log from the aborted one first. &lt;/P&gt;&lt;P&gt;After that I completed the update of the Java JRE, and ran fixwareout. The computer seems to be working better, as it now can connect to windows update. Im not a 100% sure its clean, as its running a little slow. Im guessing you will be able to tell me more after viewing the reports. &lt;/P&gt;&lt;P&gt;I didnt do the combofix yet, as I am not sure if you wanted that done since the computer is connecting properly now, and it says "Only do the following if you have connection problems.." Please let me know if you would still like me to run the combo fix. As always, much thanks for the help. &lt;/P&gt;&lt;P&gt;FIRST AVIRA SCAN (was aborted)&lt;/P&gt;&lt;P&gt;vira AntiVir Personal&lt;BR&gt;Report file date: Tuesday, July 08, 2008  03:31&lt;/P&gt;&lt;P&gt;Scanning for 1390128 virus strains and unwanted programs.&lt;/P&gt;&lt;P&gt;Licensed to:      Avira AntiVir PersonalEdition Classic&lt;BR&gt;Serial number:    0000149996-ADJIE-0001&lt;BR&gt;Platform:         Windows XP&lt;BR&gt;Windows version:  (Service Pack 3)  [5.1.2600]&lt;BR&gt;Boot mode:        Normally booted&lt;BR&gt;Username:         SYSTEM&lt;BR&gt;Computer name:    MARIFAH&lt;/P&gt;&lt;P&gt;Version information:&lt;BR&gt;BUILD.DAT     : 8.1.00.295      16479 Bytes    4/9/2008 16:24:00&lt;BR&gt;AVSCAN.EXE    : 8.1.2.12       311553 Bytes   3/18/2008 16:02:56&lt;BR&gt;AVSCAN.DLL    : 8.1.1.0         53505 Bytes    2/7/2008 15:43:37&lt;BR&gt;LUKE.DLL      : 8.1.2.9        151809 Bytes   2/28/2008 15:41:23&lt;BR&gt;LUKERES.DLL   : 8.1.2.1         12033 Bytes   2/21/2008 15:28:40&lt;BR&gt;ANTIVIR0.VDF  : 6.40.0.0     11030528 Bytes   7/18/2007 17:33:34&lt;BR&gt;ANTIVIR1.VDF  : 7.0.5.1       8182784 Bytes   6/24/2008 08:27:38&lt;BR&gt;ANTIVIR2.VDF  : 7.0.5.51       273408 Bytes    7/4/2008 08:27:40&lt;BR&gt;ANTIVIR3.VDF  : 7.0.5.64       149504 Bytes    7/8/2008 08:27:41&lt;BR&gt;Engineversion : 8.1.0.64  &lt;BR&gt;AEVDF.DLL     : 8.1.0.5        102772 Bytes   2/25/2008 16:58:21&lt;BR&gt;AESCRIPT.DLL  : 8.1.0.46       283002 Bytes    7/8/2008 08:28:04&lt;BR&gt;AESCN.DLL     : 8.1.0.22       119157 Bytes    7/8/2008 08:28:03&lt;BR&gt;AERDL.DLL     : 8.1.0.20       418165 Bytes    7/8/2008 08:28:03&lt;BR&gt;AEPACK.DLL    : 8.1.1.6        364918 Bytes    7/8/2008 08:28:01&lt;BR&gt;AEOFFICE.DLL  : 8.1.0.20       192891 Bytes    7/8/2008 08:27:59&lt;BR&gt;AEHEUR.DLL    : 8.1.0.35      1298806 Bytes    7/8/2008 08:27:53&lt;BR&gt;AEHELP.DLL    : 8.1.0.15       115063 Bytes    7/8/2008 08:27:50&lt;BR&gt;AEGEN.DLL     : 8.1.0.29       307573 Bytes    7/8/2008 08:27:49&lt;BR&gt;AEEMU.DLL     : 8.1.0.6        430451 Bytes    7/8/2008 08:27:45&lt;BR&gt;AECORE.DLL    : 8.1.0.32       168311 Bytes    7/8/2008 08:27:41&lt;BR&gt;AVWINLL.DLL   : 1.0.0.7         14593 Bytes   1/24/2008 00:07:53&lt;BR&gt;AVPREF.DLL    : 8.0.0.1         25857 Bytes   2/18/2008 17:37:50&lt;BR&gt;AVREP.DLL     : 7.0.0.1        155688 Bytes   4/16/2007 20:26:47&lt;BR&gt;AVREG.DLL     : 8.0.0.0         30977 Bytes   1/24/2008 00:07:49&lt;BR&gt;AVARKT.DLL    : 1.0.0.23       307457 Bytes   2/12/2008 15:29:23&lt;BR&gt;AVEVTLOG.DLL  : 8.0.0.11       114945 Bytes   2/28/2008 15:31:31&lt;BR&gt;SQLITE3.DLL   : 3.3.17.1       339968 Bytes   1/23/2008 00:28:02&lt;BR&gt;SMTPLIB.DLL   : 1.2.0.19        28929 Bytes   1/24/2008 00:08:39&lt;BR&gt;NETNT.DLL     : 8.0.0.1          7937 Bytes   1/25/2008 19:05:10&lt;BR&gt;RCIMAGE.DLL   : 8.0.0.35      2371841 Bytes   3/10/2008 21:37:25&lt;BR&gt;RCTEXT.DLL    : 8.0.32.0        86273 Bytes    3/6/2008 19:02:11&lt;/P&gt;&lt;P&gt;Configuration settings for the scan:&lt;BR&gt;Jobname..........................: Complete system scan&lt;BR&gt;Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp&lt;BR&gt;Logging..........................: low&lt;BR&gt;Primary action...................: interactive&lt;BR&gt;Secondary action.................: ignore&lt;BR&gt;Scan master boot sector..........: on&lt;BR&gt;Scan boot sector.................: on&lt;BR&gt;Boot sectors.....................: C:, &lt;BR&gt;Scan memory......................: on&lt;BR&gt;Process scan.....................: on&lt;BR&gt;Scan registry....................: on&lt;BR&gt;Search for rootkits..............: off&lt;BR&gt;Scan all files...................: Intelligent file selection&lt;BR&gt;Scan archives....................: on&lt;BR&gt;Recursion depth..................: 20&lt;BR&gt;Smart extensions.................: on&lt;BR&gt;Macro heuristic..................: on&lt;BR&gt;File heuristic...................: medium&lt;/P&gt;&lt;P&gt;Start of the scan: Tuesday, July 08, 2008  03:31&lt;/P&gt;&lt;P&gt;The scan of running processes will be started&lt;BR&gt;Scan process 'avscan.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'avcenter.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'sched.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'avgnt.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'avguard.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'ssu.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'iexplore.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'Ad-Aware.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'iPodService.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'DigitalSupportLocalService.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'ctfmon.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'rundll32.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'SpySweeperUI.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'realsched.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'alg.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'SearchProtection.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'pctsTray.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'ipoint.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'itype.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'hpgs2wnf.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'jusched.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'BCMSMMSG.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'hpgs2wnd.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'hphmon03.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'explorer.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'SpySweeper.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'pctsSvc.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'pctsAuxs.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'PSIService.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'spoolsv.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'aawservice.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'lsass.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'services.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'winlogon.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'csrss.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'smss.exe' - '1' Module(s) have been scanned&lt;BR&gt;47 processes with 47 modules were scanned&lt;/P&gt;&lt;P&gt;Starting master boot sector scan:&lt;BR&gt;Master boot sector HD0&lt;BR&gt;      [INFO]      No virus was found!&lt;/P&gt;&lt;P&gt;Start scanning boot sectors:&lt;BR&gt;Boot sector 'C:\'&lt;BR&gt;      [INFO]      No virus was found!&lt;/P&gt;&lt;P&gt;Starting to scan the registry.&lt;BR&gt;The registry was scanned ( '37' files ).&lt;/P&gt;&lt;P&gt;&lt;BR&gt;Starting the file scan:&lt;/P&gt;&lt;P&gt;Begin scan in 'C:\'&lt;BR&gt;C:\hiberfil.sys&lt;BR&gt;      [WARNING]   The file could not be opened!&lt;BR&gt;C:\pagefile.sys&lt;BR&gt;      [WARNING]   The file could not be opened!&lt;BR&gt;C:\Documents and Settings\Andrea Hobright\Desktop\Unused Desktop Shortcuts\Unused items\wrar37b5.exe&lt;BR&gt;  [0] Archive type: RAR SFX (self extracting)&lt;BR&gt;  --&amp;gt; WinRAR.exe&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/ATRAPS.Gen&lt;BR&gt;      [NOTE]      The file was deleted!&lt;BR&gt;C:\Documents and Settings\Andrea Hobright\Local Settings\Temp\5e366ih7.exe&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Dldr.FraudLoad.azh&lt;BR&gt;      [NOTE]      The file was deleted!&lt;BR&gt;C:\Documents and Settings\Andrea Hobright\Local Settings\Temp\o0oes26g.exe&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Dldr.FraudLoad.azh&lt;BR&gt;      [NOTE]      The file was deleted!&lt;BR&gt;C:\System Volume Information\_restore{561180A9-22A1-4CE5-97A9-85F0DD91E20D}\RP609\A0353044.exe&lt;BR&gt;  [0] Archive type: RAR SFX (self extracting)&lt;BR&gt;  --&amp;gt; WinRAR.exe&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/ATRAPS.Gen&lt;BR&gt;      [NOTE]      The file was deleted!&lt;/P&gt;&lt;P&gt;&lt;BR&gt;End of the scan: Tuesday, July 08, 2008  11:45&lt;BR&gt;Used time:  8:14:18 min&lt;/P&gt;&lt;P&gt;The scan has been canceled!&lt;/P&gt;&lt;P&gt;   5981 Scanning directories&lt;BR&gt; 303224 Files were scanned&lt;BR&gt;      4 viruses and/or unwanted programs were found&lt;BR&gt;      0 Files were classified as suspicious:&lt;BR&gt;      4 files were deleted&lt;BR&gt;      0 files were repaired&lt;BR&gt;      0 files were moved to quarantine&lt;BR&gt;      0 files were renamed&lt;BR&gt;      2 Files cannot be scanned&lt;BR&gt; 303220 Files not concerned&lt;BR&gt;   1647 Archives were scanned&lt;BR&gt;      2 Warnings&lt;BR&gt;      4 Notes&lt;/P&gt;&lt;P&gt;SECOND AVIRA SCAN (finished ok)&lt;/P&gt;&lt;P&gt;vira AntiVir Personal&lt;BR&gt;Report file date: Tuesday, July 08, 2008  12:07&lt;/P&gt;&lt;P&gt;Scanning for 1390128 virus strains and unwanted programs.&lt;/P&gt;&lt;P&gt;Licensed to:      Avira AntiVir PersonalEdition Classic&lt;BR&gt;Serial number:    0000149996-ADJIE-0001&lt;BR&gt;Platform:         Windows XP&lt;BR&gt;Windows version:  (Service Pack 3)  [5.1.2600]&lt;BR&gt;Boot mode:        Normally booted&lt;BR&gt;Username:         SYSTEM&lt;BR&gt;Computer name:    MARIFAH&lt;/P&gt;&lt;P&gt;Version information:&lt;BR&gt;BUILD.DAT     : 8.1.00.295      16479 Bytes    4/9/2008 16:24:00&lt;BR&gt;AVSCAN.EXE    : 8.1.2.12       311553 Bytes   3/18/2008 16:02:56&lt;BR&gt;AVSCAN.DLL    : 8.1.1.0         53505 Bytes    2/7/2008 15:43:37&lt;BR&gt;LUKE.DLL      : 8.1.2.9        151809 Bytes   2/28/2008 15:41:23&lt;BR&gt;LUKERES.DLL   : 8.1.2.1         12033 Bytes   2/21/2008 15:28:40&lt;BR&gt;ANTIVIR0.VDF  : 6.40.0.0     11030528 Bytes   7/18/2007 17:33:34&lt;BR&gt;ANTIVIR1.VDF  : 7.0.5.1       8182784 Bytes   6/24/2008 08:27:38&lt;BR&gt;ANTIVIR2.VDF  : 7.0.5.51       273408 Bytes    7/4/2008 08:27:40&lt;BR&gt;ANTIVIR3.VDF  : 7.0.5.64       149504 Bytes    7/8/2008 08:27:41&lt;BR&gt;Engineversion : 8.1.0.64  &lt;BR&gt;AEVDF.DLL     : 8.1.0.5        102772 Bytes   2/25/2008 16:58:21&lt;BR&gt;AESCRIPT.DLL  : 8.1.0.46       283002 Bytes    7/8/2008 08:28:04&lt;BR&gt;AESCN.DLL     : 8.1.0.22       119157 Bytes    7/8/2008 08:28:03&lt;BR&gt;AERDL.DLL     : 8.1.0.20       418165 Bytes    7/8/2008 08:28:03&lt;BR&gt;AEPACK.DLL    : 8.1.1.6        364918 Bytes    7/8/2008 08:28:01&lt;BR&gt;AEOFFICE.DLL  : 8.1.0.20       192891 Bytes    7/8/2008 08:27:59&lt;BR&gt;AEHEUR.DLL    : 8.1.0.35      1298806 Bytes    7/8/2008 08:27:53&lt;BR&gt;AEHELP.DLL    : 8.1.0.15       115063 Bytes    7/8/2008 08:27:50&lt;BR&gt;AEGEN.DLL     : 8.1.0.29       307573 Bytes    7/8/2008 08:27:49&lt;BR&gt;AEEMU.DLL     : 8.1.0.6        430451 Bytes    7/8/2008 08:27:45&lt;BR&gt;AECORE.DLL    : 8.1.0.32       168311 Bytes    7/8/2008 08:27:41&lt;BR&gt;AVWINLL.DLL   : 1.0.0.7         14593 Bytes   1/24/2008 00:07:53&lt;BR&gt;AVPREF.DLL    : 8.0.0.1         25857 Bytes   2/18/2008 17:37:50&lt;BR&gt;AVREP.DLL     : 7.0.0.1        155688 Bytes   4/16/2007 20:26:47&lt;BR&gt;AVREG.DLL     : 8.0.0.0         30977 Bytes   1/24/2008 00:07:49&lt;BR&gt;AVARKT.DLL    : 1.0.0.23       307457 Bytes   2/12/2008 15:29:23&lt;BR&gt;AVEVTLOG.DLL  : 8.0.0.11       114945 Bytes   2/28/2008 15:31:31&lt;BR&gt;SQLITE3.DLL   : 3.3.17.1       339968 Bytes   1/23/2008 00:28:02&lt;BR&gt;SMTPLIB.DLL   : 1.2.0.19        28929 Bytes   1/24/2008 00:08:39&lt;BR&gt;NETNT.DLL     : 8.0.0.1          7937 Bytes   1/25/2008 19:05:10&lt;BR&gt;RCIMAGE.DLL   : 8.0.0.35      2371841 Bytes   3/10/2008 21:37:25&lt;BR&gt;RCTEXT.DLL    : 8.0.32.0        86273 Bytes    3/6/2008 19:02:11&lt;/P&gt;&lt;P&gt;Configuration settings for the scan:&lt;BR&gt;Jobname..........................: Complete system scan&lt;BR&gt;Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp&lt;BR&gt;Logging..........................: low&lt;BR&gt;Primary action...................: interactive&lt;BR&gt;Secondary action.................: ignore&lt;BR&gt;Scan master boot sector..........: on&lt;BR&gt;Scan boot sector.................: on&lt;BR&gt;Boot sectors.....................: C:, &lt;BR&gt;Scan memory......................: on&lt;BR&gt;Process scan.....................: on&lt;BR&gt;Scan registry....................: on&lt;BR&gt;Search for rootkits..............: off&lt;BR&gt;Scan all files...................: Intelligent file selection&lt;BR&gt;Scan archives....................: on&lt;BR&gt;Recursion depth..................: 20&lt;BR&gt;Smart extensions.................: on&lt;BR&gt;Macro heuristic..................: on&lt;BR&gt;File heuristic...................: medium&lt;/P&gt;&lt;P&gt;Start of the scan: Tuesday, July 08, 2008  12:07&lt;/P&gt;&lt;P&gt;The scan of running processes will be started&lt;BR&gt;Scan process 'avscan.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'avcenter.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'alg.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'pctsSvc.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'SpySweeper.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'iPodService.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'Webshots.scr' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'DigitalSupportLocalService.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'ctfmon.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'rundll32.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'avgnt.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'SpySweeperUI.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'pctsTray.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'realsched.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'SearchProtection.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'ipoint.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'itype.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'jusched.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'apdproxy.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'hpgs2wnf.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'BCMSMMSG.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'hpgs2wnd.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'Hpi_monitor.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'hphmon03.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'hpztsb04.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'pctsAuxs.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'PSIService.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'avguard.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'sched.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'spoolsv.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'explorer.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'aawservice.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'lsass.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'services.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'winlogon.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'csrss.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'smss.exe' - '1' Module(s) have been scanned&lt;BR&gt;49 processes with 49 modules were scanned&lt;/P&gt;&lt;P&gt;Starting master boot sector scan:&lt;BR&gt;Master boot sector HD0&lt;BR&gt;      [INFO]      No virus was found!&lt;/P&gt;&lt;P&gt;Start scanning boot sectors:&lt;BR&gt;Boot sector 'C:\'&lt;BR&gt;      [INFO]      No virus was found!&lt;/P&gt;&lt;P&gt;Starting to scan the registry.&lt;BR&gt;The registry was scanned ( '37' files ).&lt;/P&gt;&lt;P&gt;&lt;BR&gt;Starting the file scan:&lt;/P&gt;&lt;P&gt;Begin scan in 'C:\'&lt;BR&gt;C:\hiberfil.sys&lt;BR&gt;      [WARNING]   The file could not be opened!&lt;BR&gt;C:\pagefile.sys&lt;BR&gt;      [WARNING]   The file could not be opened!&lt;/P&gt;&lt;P&gt;&lt;BR&gt;End of the scan: Tuesday, July 08, 2008  14:01&lt;BR&gt;Used time:  1:54:03 min&lt;/P&gt;&lt;P&gt;The scan has been done completely.&lt;/P&gt;&lt;P&gt;   7332 Scanning directories&lt;BR&gt; 376987 Files were scanned&lt;BR&gt;      0 viruses and/or unwanted programs were found&lt;BR&gt;      0 Files were classified as suspicious:&lt;BR&gt;      0 files were deleted&lt;BR&gt;      0 files were repaired&lt;BR&gt;      0 files were moved to quarantine&lt;BR&gt;      0 files were renamed&lt;BR&gt;      2 Files cannot be scanned&lt;BR&gt; 376987 Files not concerned&lt;BR&gt;   2095 Archives were scanned&lt;BR&gt;      2 Warnings&lt;BR&gt;      0 Notes&lt;/P&gt;&lt;P&gt;FIXWAREOUT REPORT&lt;/P&gt;&lt;P&gt;Username "Andrea Hobright" - 07/08/2008 14:44:33 [Fixwareout edited 9/01/2007]&lt;/P&gt;&lt;P&gt;~~~~~ Prerun check&lt;/P&gt;&lt;P&gt;Successfully flushed the DNS Resolver Cache.&lt;/P&gt;&lt;P&gt;&lt;BR&gt;System was rebooted successfully. &lt;BR&gt; &lt;BR&gt;~~~~~ Postrun check &lt;BR&gt;HKLM\SOFTWARE\~\Winlogon\ "System"="" &lt;BR&gt;....&lt;BR&gt;....&lt;BR&gt;~~~~~ Misc files. &lt;BR&gt;....&lt;BR&gt;~~~~~ Checking for older varients.&lt;BR&gt;....&lt;/P&gt;&lt;P&gt;~~~~~ Current runs (hklm hkcu "run" Keys Only)&lt;BR&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb04.exe"&lt;BR&gt;"HPHmon03"="C:\\WINDOWS\\System32\\hphmon03.exe"&lt;BR&gt;"CXMon"="\"C:\\Program Files\\Hewlett-Packard\\PhotoSmart\\Photo Imaging\\Hpi_Monitor.exe\""&lt;BR&gt;"Share-to-Web Namespace Daemon"="\"C:\\Program Files\\Hewlett-Packard\\PhotoSmart\\HP Share-to-Web\\hpgs2wnd.exe\""&lt;BR&gt;"BCMSMMSG"="BCMSMMSG.exe"&lt;BR&gt;"NvCplDaemon"="\"RUNDLL32.EXE\" C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"&lt;BR&gt;"nwiz"="\"nwiz.exe\" /install"&lt;BR&gt;"Adobe Photo Downloader"="\"C:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\""&lt;BR&gt;"itype"="\"C:\\Program Files\\Microsoft IntelliType Pro\\itype.exe\""&lt;BR&gt;"IntelliPoint"="\"C:\\Program Files\\Microsoft IntelliPoint\\ipoint.exe\""&lt;BR&gt;"YSearchProtection"="\"C:\\Program Files\\Yahoo!\\Search Protection\\SearchProtection.exe\""&lt;BR&gt;"Hijri_Cal"="\"C:\\Program Files\\DivineIslam\\HijriCal1\\Hijri_Cal.exe\""&lt;BR&gt;"Adobe Reader Speed Launcher"="\"C:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe\""&lt;BR&gt;"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\"  -osboot"&lt;BR&gt;"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"&lt;BR&gt;"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""&lt;BR&gt;"ISTray"="\"C:\\Program Files\\Spyware Doctor\\pctsTray.exe\""&lt;BR&gt;"avgnt"="\"C:\\Program Files\\Avira\\AntiVir PersonalEdition Classic\\avgnt.exe\" /min"&lt;BR&gt;"SpySweeper"="\"C:\\Program Files\\Webroot\\Spy Sweeper\\SpySweeperUI.exe\" /startintray"&lt;BR&gt;"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_07\\bin\\jusched.exe\""&lt;/P&gt;&lt;P&gt;[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"NvMediaCenter"="\"RUNDLL32.EXE\" C:\\WINDOWS\\System32\\NVMCTRAY.DLL,NvTaskbarInit"&lt;BR&gt;"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"&lt;BR&gt;"YSearchProtection"="\"C:\\Program Files\\Yahoo!\\Search\" Protection\\SearchProtection.exe"&lt;BR&gt;"SpybotSD TeaTimer"="H:\\Spybot - Search &amp;amp; Destroy\\TeaTimer.exe"&lt;BR&gt;....&lt;BR&gt;Hosts file was reset, If you use a custom hosts file please replace it...&lt;BR&gt;~~~~~ End report ~~~~~&lt;BR&gt;</description><pubDate>Tue, 08 Jul 2008 15:07:46 GMT</pubDate><dc:creator>Sancho8297</dc:creator></item><item><title>RE: windows update is always redirected to msn.com</title><link>http://forum.tweaks.com/forum/Topic242225-29-1.aspx</link><description>Welcome:)&lt;br&gt;&lt;br&gt;It appears you've no virus protection installed,which is somewhat suicidal.&lt;br&gt;Please download/install [b]Avira AntiVir Personal - FREE Antivirus[/b]: &lt;br&gt;[url]http://www.free-av.com/en/download/1/download_avira_antivir_personal__free_antivirus.html[/url]&lt;br&gt;Perform a full scan with Avira and allow it to delete everything it detects.&lt;br&gt;[b]Restart your pc when you've done.[/b]&lt;br&gt;After restart,open Avira Antivirus and select "Reports".&lt;br&gt;Then double click the report from the full scan you have just completed. &lt;br&gt;Click the "Report File" button,then [b]copy and paste the report into your next reply[/b].&lt;br&gt;&lt;br&gt;&lt;br&gt;Your version of [b]Sun Java[/b] is out of date.&lt;br&gt;Older versions have vulnerabilities that malware can use to infect your system.&lt;br&gt;Please follow these steps to remove older versions of Sun Java,and then update.&lt;br&gt;1. Download the latest version of [b][url=http://java.sun.com/javase/downloads/index.jsp][color="blue"]Java Runtime Environment (JRE)[/color][/url][/b]&lt;br&gt;2. Scroll down to where it says '[b]Java Runtime Environment (JRE) 6u6[/b]'.&lt;br&gt;3. Click the "Download" button to the right.&lt;br&gt;4. Select the Platform and Language for your download,then check the box that says: "Accept License Agreement".&lt;br&gt;5. The page will refresh.&lt;br&gt;6. Click on the link to download [b]'Windows Offline Installation, Multi-language - jre-6u6-windows-i586-p.exe'[/b] [15.21 MB] and save to your desktop.&lt;br&gt;7. Close any programs you may have running - especially your web browser.&lt;br&gt;8. Go to Start &gt; Control Panel double-click on Add/Remove programs and remove all older versions of Java.&lt;br&gt;9. Check any item with Java Runtime Environment (JRE or J2SE) in the name.&lt;br&gt;10. Click the Change/Remove button.&lt;br&gt;11. Repeat as many times as necessary to remove each Java version.&lt;br&gt;12. Reboot your computer once all Java components are removed.&lt;br&gt;13. Then from your desktop double-click on [b]jre-6u6-windows-i586-p.exe[/b] to install the newest version.&lt;br&gt;&lt;br&gt;&lt;br&gt;Download [b]Fixwareout[/b] from the link below: &lt;br&gt;[url]http://downloads.subratam.org/Fixwareout.exe[/url]&lt;br&gt;Save it to your desktop and run it.&lt;br&gt;Click Next,then Install,make sure "Run fixit" is checked and click Finish.&lt;br&gt;The fix will begin,follow the prompts. &lt;br&gt;Your firewall may give an alert,(because this tool will download an additional file from the internet),please don't let your firewall block it,allow it instead.&lt;br&gt;Then you will be asked to reboot your computer,please do so. &lt;br&gt;Your system may take longer than usual to load,this is normal.&lt;br&gt;[b]After the reboot post the contents of the logfile C:\fixwareout\report.txt in your next reply,along with the requested below.[/b]&lt;br&gt;[b]Please Note[/b]:&lt;br&gt;Only do the following if you have connection problems after performing the above steps:&lt;br&gt;Go to Start&gt;Control Panel,and choose 'Network Connections'. &lt;br&gt;Then right click on your default connection,usually 'Local Area Connection' or 'Dial-up Connection' if you are using Dial-up,then left click on 'Properties'. &lt;br&gt;Double-click on the 'Internet Protocol (TCP/IP)' item and select the radio button that says: 'Obtain DNS servers Automatically'. &lt;br&gt;Click OK twice,restart your computer.&lt;br&gt;&lt;br&gt;&lt;br&gt;Download [b][url=http://download.bleepingcomputer.com/sUBs/ComboFix.exe][color="blue"]Combofix[/color][/url][/b] by [b]sUBs[/b] and save to your desktop.&lt;br&gt;Alternative Combofix download link [b][url=http://subs.geekstogo.com/ComboFix.exe][color="blue"]HERE[/color][/url][/b].&lt;br&gt;[color="red"][b][u]Note[/u][/b] &lt;br&gt;It is important that it is saved directly to your desktop[/color]&lt;br&gt;Close any open browsers. &lt;br&gt;Click on Start/Run,[url=http://www.webmasternow.com/copyandpaste.html][color="blue"]copy and paste[/color][/url] the following bold text into the '[u]O[/u]pen:' space,then press OK [See image below]:&lt;br&gt;[b]"%userprofile%\desktop\combofix.exe" /killall[/b]&lt;br&gt;&lt;br&gt;[IMG]http://img.photobucket.com/albums/v624/29wood/ka.png[/IMG]&lt;br&gt;&lt;br&gt;Combofix.exe will start,please follow the prompts. &lt;br&gt;When it's finished it will produce a log. &lt;br&gt;[b]Post the entire contents of C:\ComboFix.txt into your next reply[/b]. &lt;br&gt;[color="red"][b][u]Note[/u][/b]: &lt;br&gt;Do not mouseclick combofix's window while it's running. &lt;br&gt;That may cause the program to freeze/hang. [/color]&lt;br&gt;Do NOT post the ComboFix-quarantined-files.txt unless I ask.&lt;br&gt;[b]*Note*[/b]&lt;br&gt;In case your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix,please disable your scanner and redownload Combofix again.&lt;br&gt;Some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.&lt;br&gt;&lt;br&gt;Also post a new Hijackthis log please.</description><pubDate>Tue, 08 Jul 2008 02:58:01 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>windows update is always redirected to msn.com</title><link>http://forum.tweaks.com/forum/Topic242225-29-1.aspx</link><description>Hello again,&lt;/P&gt;&lt;P&gt;I posted on here earlier about the same problem (where i cannot get to windows update through any method, it seems blocked, and also other updates/downloads get blocked that are intended to fix computer problems), I performed the ten tasks in the READ THIS FIRST post, but it did not solve the problem. So here is the hijack this output requested. &lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 11:35:57 PM, on 7/7/2008&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16674)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\csrss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;BR&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;BR&gt;C:\WINDOWS\System32\nvsvc32.exe&lt;BR&gt;C:\WINDOWS\system32\PSIService.exe&lt;BR&gt;C:\Program Files\Spyware Doctor\pctsAuxs.exe&lt;BR&gt;C:\Program Files\Spyware Doctor\pctsSvc.exe&lt;BR&gt;C:\Program Files\Spyware Doctor\pctsTray.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe&lt;BR&gt;C:\WINDOWS\System32\alg.exe&lt;BR&gt;C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe&lt;BR&gt;C:\WINDOWS\System32\hphmon03.exe&lt;BR&gt;C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe&lt;BR&gt;C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe&lt;BR&gt;C:\WINDOWS\BCMSMMSG.exe&lt;BR&gt;C:\PROGRA~1\HEWLET~1\PHOTOS~1\HPSHAR~1\hpgs2wnf.exe&lt;BR&gt;C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe&lt;BR&gt;C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe&lt;BR&gt;C:\Program Files\Microsoft IntelliType Pro\itype.exe&lt;BR&gt;C:\Program Files\Microsoft IntelliPoint\ipoint.exe&lt;BR&gt;C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe&lt;BR&gt;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&lt;BR&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;BR&gt;C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe&lt;BR&gt;C:\WINDOWS\system32\RUNDLL32.EXE&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;BR&gt;C:\Program Files\Digital Support\DigitalSupportLocalService.exe&lt;BR&gt;C:\PROGRA~1\Webshots\webshots.scr&lt;BR&gt;C:\Program Files\Webroot\Spy Sweeper\SSU.EXE&lt;BR&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;BR&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;BR&gt;C:\WINDOWS\System32\wbem\wmiprvse.exe&lt;/P&gt;&lt;P&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.yahoo.com/"&gt;http://www.yahoo.com/&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"&lt;BR&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;BR&gt;O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)&lt;BR&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;BR&gt;O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll&lt;BR&gt;O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll&lt;BR&gt;O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll&lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;BR&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll&lt;BR&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.3558\swg.dll&lt;BR&gt;O3 - Toolbar: &amp;amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll&lt;BR&gt;O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe&lt;BR&gt;O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03.exe&lt;BR&gt;O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"&lt;BR&gt;O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] "C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe"&lt;BR&gt;O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe&lt;BR&gt;O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup&lt;BR&gt;O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install&lt;BR&gt;O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"&lt;BR&gt;O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"&lt;BR&gt;O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"&lt;BR&gt;O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"&lt;BR&gt;O4 - HKLM\..\Run: [Hijri_Cal] "C:\Program Files\DivineIslam\HijriCal1\Hijri_Cal.exe"&lt;BR&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"&lt;BR&gt;O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot&lt;BR&gt;O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime&lt;BR&gt;O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"&lt;BR&gt;O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"&lt;BR&gt;O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray&lt;BR&gt;O4 - HKCU\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O4 - HKCU\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search" Protection\SearchProtection.exe&lt;BR&gt;O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe&lt;BR&gt;O4 - Global Startup: Digital Support Local Service.lnk = C:\Program Files\Digital Support\DigitalSupportLocalService.exe&lt;BR&gt;O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE&lt;BR&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000&lt;BR&gt;O8 - Extra context menu item: Lookup on Merriam Webster - &lt;A href="file://C:\Program"&gt;file://C:\Program&lt;/A&gt; Files\ieSpell\Merriam Webster.HTM&lt;BR&gt;O8 - Extra context menu item: Lookup on Wikipedia - &lt;A href="file://C:\Program"&gt;file://C:\Program&lt;/A&gt; Files\ieSpell\wikipedia.HTM&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;BR&gt;O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll&lt;BR&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll&lt;BR&gt;O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll&lt;BR&gt;O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &lt;A href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1173942424531"&gt;http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1173942424531&lt;/A&gt;&lt;BR&gt;O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe&lt;BR&gt;O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;BR&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;BR&gt;O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;BR&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe&lt;BR&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;BR&gt;O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\system32\NMSSvc.exe&lt;BR&gt;O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe&lt;BR&gt;O23 - Service: Pml Driver - HP - C:\WINDOWS\System32\HPHipm09.exe&lt;BR&gt;O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe&lt;BR&gt;O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe&lt;BR&gt;O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe&lt;BR&gt;O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 9661 bytes</description><pubDate>Tue, 08 Jul 2008 00:25:12 GMT</pubDate><dc:creator>Sancho8297</dc:creator></item></channel></rss>