<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://en.community.dell.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Malware Removal</title><link>http://en.community.dell.com/forums/3521.aspx</link><description>Virus &amp; Spyware Sub-Board</description><dc:language /><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>mutiple program hang ups not just IE</title><link>http://en.community.dell.com/forums/thread/19594034.aspx</link><pubDate>Sat, 21 Nov 2009 20:20:21 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19594034</guid><dc:creator>azstew</dc:creator><slash:comments>8</slash:comments><comments>http://en.community.dell.com/forums/thread/19594034.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19594034</wfw:commentRss><description>&lt;p&gt;Thanks for helping!&lt;img src="http://en.community.dell.com/emoticons/emotion-1.gif" alt="Smile" /&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;We have been having multiple hang ups program stops responding freezes in middle of typing gets worse the longer the computer is in use.&lt;/p&gt;
&lt;p&gt;We thought ,at first it was from a update the kept &amp;nbsp;trying to install but once i fixed that problem but&amp;nbsp;it was not the solution to the hang ups.&lt;/p&gt;
&lt;p&gt;Tried Spybot nothing CA Amore nothing but malwarebytes found Rouge multiple and adware.mywebsearch Cool i thought finally.Every thing i do it at first seems to have solved the problem and it start hanging all over again.&lt;/p&gt;
&lt;p&gt;HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -&amp;gt; Quarantined and deleted successfully.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{09f1adac-76d8-4d0f-99a5-5c907dadb988} (Rogue.Multiple) -&amp;gt; Quarantined and deleted successfully.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;here is the hijackthis log i hope i have given enough info to help you figure it out.&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 12:52:28 PM, on 11/21/2009&lt;br /&gt;Platform: Windows Vista SP2 (WinNT 6.00.1906)&lt;br /&gt;MSIE: Internet Explorer v7.00 (7.00.6002.18005)&lt;br /&gt;Boot mode: Normal&lt;/p&gt;
&lt;p&gt;Running processes:&lt;br /&gt;C:\Windows\system32\Dwm.exe&lt;br /&gt;C:\Windows\system32\taskeng.exe&lt;br /&gt;C:\Windows\Explorer.EXE&lt;br /&gt;C:\Program Files\Windows Defender\MSASCui.exe&lt;br /&gt;C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe&lt;br /&gt;C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe&lt;br /&gt;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&lt;br /&gt;C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe&lt;br /&gt;C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe&lt;br /&gt;C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\cavrid.exe&lt;br /&gt;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jusched.exe&lt;br /&gt;C:\Program Files\Windows Sidebar\sidebar.exe&lt;br /&gt;C:\Program Files\DellSupport\DSAgnt.exe&lt;br /&gt;C:\Windows\ehome\ehtray.exe&lt;br /&gt;C:\Program Files\Windows Media Player\wmpnscfg.exe&lt;br /&gt;C:\Program Files\Spybot - Search &amp;amp; Destroy\TeaTimer.exe&lt;br /&gt;C:\Windows\ehome\ehmsas.exe&lt;br /&gt;C:\Program Files\WinZip\WZQKPICK.EXE&lt;br /&gt;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe&lt;br /&gt;C:\Windows\system32\wbem\unsecapp.exe&lt;br /&gt;C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe&lt;br /&gt;C:\Windows\system32\wuauclt.exe&lt;br /&gt;C:\Program Files\Dell Support Center\gs_agent\dsc.exe&lt;br /&gt;C:\Program Files\Internet Explorer\IEUser.exe&lt;br /&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;br /&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/p&gt;
&lt;p&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://www.yahoo.com/"&gt;http://www.yahoo.com/&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href="http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com"&gt;http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &lt;a href="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html"&gt;http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com"&gt;http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = &lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = &lt;a href="http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com"&gt;http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com&lt;/a&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell&lt;br /&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = &lt;br /&gt;R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll&lt;br /&gt;R3 - URLSearchHook: BitZipperSearch Toolbar - {97bceb59-cfcd-4b16-a863-b3f72cf9f196} - C:\Program Files\BitZipperSearch\tbBitZ.dll&lt;br /&gt;O1 - Hosts: ::1 localhost&lt;br /&gt;O2 - BHO: &amp;amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll&lt;br /&gt;O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll&lt;br /&gt;O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll&lt;br /&gt;O2 - BHO: Spybot-S&amp;amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br /&gt;O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;br /&gt;O2 - BHO: BitZipperSearch Toolbar - {97bceb59-cfcd-4b16-a863-b3f72cf9f196} - C:\Program Files\BitZipperSearch\tbBitZ.dll&lt;br /&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll&lt;br /&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll&lt;br /&gt;O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll&lt;br /&gt;O2 - BHO: (no name) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - (no file)&lt;br /&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;br /&gt;O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll&lt;br /&gt;O3 - Toolbar: BitZipperSearch Toolbar - {97bceb59-cfcd-4b16-a863-b3f72cf9f196} - C:\Program Files\BitZipperSearch\tbBitZ.dll&lt;br /&gt;O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll&lt;br /&gt;O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll&lt;br /&gt;O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide&lt;br /&gt;O4 - HKLM\..\Run: [IAAnotif] &amp;quot;C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [ISUSScheduler] &amp;quot;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&amp;quot; -start&lt;br /&gt;O4 - HKLM\..\Run: [NMSSupport] &amp;quot;C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe&amp;quot; /startup&lt;br /&gt;O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup&lt;br /&gt;O4 - HKLM\..\Run: [DellSupportCenter] &amp;quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&amp;quot; /P DellSupportCenter&lt;br /&gt;O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe&lt;br /&gt;O4 - HKLM\..\Run: [EKIJ5000StatusMonitor] C:\Windows\system32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe&lt;br /&gt;O4 - HKLM\..\Run: [dscactivate] &amp;quot;C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [cctray] &amp;quot;C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [CAVRID] &amp;quot;C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &amp;quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\QTTask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKLM\..\Run: [StartCCC] &amp;quot;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&amp;quot; MSRun&lt;br /&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] &amp;quot;C:\Program Files\Java\jre6\bin\jusched.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun&lt;br /&gt;O4 - HKCU\..\Run: [DellSupport] &amp;quot;C:\Program Files\DellSupport\DSAgnt.exe&amp;quot; /startup&lt;br /&gt;O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe&lt;br /&gt;O4 - HKCU\..\Run: [swg] &amp;quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe&lt;br /&gt;O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp;amp; Destroy\TeaTimer.exe&lt;br /&gt;O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User &amp;#39;LOCAL SERVICE&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User &amp;#39;LOCAL SERVICE&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User &amp;#39;NETWORK SERVICE&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-18\..\RunOnce: [DefaultP17MIDI] MIDIDEF.EXE (User &amp;#39;SYSTEM&amp;#39;)&lt;br /&gt;O4 - HKUS\.DEFAULT\..\RunOnce: [DefaultP17MIDI] MIDIDEF.EXE (User &amp;#39;Default user&amp;#39;)&lt;br /&gt;O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000&lt;br /&gt;O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: &amp;amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Spybot - Search &amp;amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br /&gt;O13 - Gopher Prefix: &lt;br /&gt;O16 - DPF: {2042B57E-6336-459E-B7CE-2A0F6C9E6AF8} (IEPlayInterface Class) - &lt;a&gt;file:///E:/win/setup/iaieplay.dll&lt;/a&gt;&lt;br /&gt;O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - &lt;a href="http://cdn.scan.onecare.live.com/resource/download/scanner/en-us/wlscctrl2.cab"&gt;http://cdn.scan.onecare.live.com/resource/download/scanner/en-us/wlscctrl2.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {8B67B37E-1AE2-4B99-B8CF-55AF4D58DF0D} (IAMCE Class) - &lt;a&gt;file:///E:/win/setup/iamce.dll&lt;/a&gt;&lt;br /&gt;O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - &lt;a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab"&gt;http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab&lt;/a&gt;&lt;br /&gt;O20 - Winlogon Notify: GoToAssist - C:\Windows\&lt;br /&gt;O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe&lt;br /&gt;O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe&lt;br /&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe&lt;br /&gt;O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe&lt;br /&gt;O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe&lt;br /&gt;O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe&lt;br /&gt;O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe&lt;br /&gt;O23 - Service: Google Update Service (gupdate1c98d3f2a493c0d) (gupdate1c98d3f2a493c0d) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe&lt;br /&gt;O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;br /&gt;O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe&lt;br /&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe&lt;br /&gt;O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe&lt;br /&gt;O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe&lt;br /&gt;O23 - Service: Kodak AiO Network Discovery Service - Eastman Kodak Company - C:\Program Files\Kodak\Printer\Center\EKDiscovery.exe&lt;br /&gt;O23 - Service: Kodak AiO Device Service (KodakSvc) - Eastman Kodak Company - C:\Program Files\Kodak\printer\center\KodakSvc.exe&lt;br /&gt;O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe&lt;br /&gt;O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe&lt;br /&gt;O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe&lt;br /&gt;O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\Program Files\McAfee\VirusScan\Mcshield.exe (file missing)&lt;br /&gt;O23 - Service: McAfee SystemGuards (McSysmon) - Unknown owner - C:\Program Files\McAfee\VirusScan\mcsysmon.exe (file missing)&lt;br /&gt;O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)&lt;br /&gt;O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe&lt;br /&gt;O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe&lt;br /&gt;O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe&lt;br /&gt;O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search &amp;amp; Destroy\SDWinSec.exe&lt;br /&gt;O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe&lt;br /&gt;O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe&lt;br /&gt;O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe&lt;br /&gt;O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe&lt;/p&gt;
&lt;p&gt;--&lt;br /&gt;End of file - 13233 bytes&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>The windows cannot find logon.exe error message</title><link>http://en.community.dell.com/forums/thread/19590450.aspx</link><pubDate>Mon, 16 Nov 2009 14:41:24 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19590450</guid><dc:creator>Nelumvia</dc:creator><slash:comments>6</slash:comments><comments>http://en.community.dell.com/forums/thread/19590450.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19590450</wfw:commentRss><description>&lt;p&gt;Hello, I am not sure this is some sort of virus or malware but it seems that I will be getting the error message &amp;quot;windows cannot find logon.exe&amp;quot; upon starup and I&amp;#39;m trying to get rid of that. This is the first post I ever make and if you cannot help with such matters I&amp;#39;m sorry to bother.&lt;/p&gt;
&lt;p&gt;When I started my computer this morning I got a message from AVG free edition that a threat was detected, logon.exe. I clicked on &amp;quot;heal&amp;quot; and it seemed everything was fine but when I next tried to open my computer and every time I do, I get the above error message. Also, it seems sometimes my computer has trouble booting at all, with monitor remaining black and the cpu apparently silent. That problem occured well before i first got the threat detected message by AVG. Usually when this happens I simply keep trying to start it until it finally works. I&amp;#39;m not sure it has anything to do with logon.exe.&lt;/p&gt;
&lt;p&gt;Is there anything I can do to get rid of the message when windows start? Is this a known undesired program? Thank you for you time and help.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title> System 32 error with 60 sec auto shutdown occured on my Dell while browsing</title><link>http://en.community.dell.com/forums/thread/19595316.aspx</link><pubDate>Mon, 23 Nov 2009 18:08:24 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19595316</guid><dc:creator>ChorionLLC</dc:creator><slash:comments>0</slash:comments><comments>http://en.community.dell.com/forums/thread/19595316.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19595316</wfw:commentRss><description>&lt;p&gt;since the fatal error and shutdown I am able to boot up, but no matter what I do the computer stalls and the clock stops working.&amp;nbsp; Below is my log from Hijackthis...any help will be greatly appreciated:&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 12:50:47 PM, on 11/23/2009&lt;br /&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v8.00 (8.00.6001.18702)&lt;br /&gt;Boot mode: Safe mode with network support&lt;/p&gt;
&lt;p&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\Program Files\Windows Defender\MsMpEng.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;br /&gt;C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe&lt;/p&gt;
&lt;p&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = &lt;br /&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;br /&gt;O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll&lt;br /&gt;O2 - BHO: Spybot-S&amp;amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br /&gt;O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll&lt;br /&gt;O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll&lt;br /&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll&lt;br /&gt;O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll&lt;br /&gt;O2 - BHO: Sun Java Applet Plugin - {E9B1FB08-BA8C-4CDA-AF62-54FF3BAF941D} - C:\DOCUME~1\STEPHE~1\APPLIC~1\Microsoft\Word\Lucene.dll (file missing)&lt;br /&gt;O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll&lt;br /&gt;O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll&lt;br /&gt;O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll&lt;br /&gt;O4 - HKLM\..\Run: [osCheck] &amp;quot;C:\Program Files\Norton Internet Security\osCheck.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [ccApp] &amp;quot;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Windows Defender] &amp;quot;C:\Program Files\Windows Defender\MSASCui.exe&amp;quot; -hide&lt;br /&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe&lt;br /&gt;O4 - HKLM\..\Run: [LogitechCommunicationsManager] &amp;quot;C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [LogitechQuickCamRibbon] &amp;quot;C:\Program Files\Logitech\QuickCam\Quickcam.exe&amp;quot; /hide&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\qttask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKLM\..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background&lt;br /&gt;O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe&lt;br /&gt;O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe&lt;br /&gt;O4 - HKLM\..\Run: [StrgSync.exe] C:\Program Files\StorageSync\StrgSync.exe -w&lt;br /&gt;O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] &amp;quot;C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Acrobat Assistant 8.0] &amp;quot;C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [AT&amp;amp;T Communication Manager] &amp;quot;C:\Program Files\AT&amp;amp;T\Communication Manager\ATTCM.exe&amp;quot; -a&lt;br /&gt;O4 - HKLM\..\Run: [Adobe ARM] &amp;quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [RoxWatchTray] &amp;quot;C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - HKCU\..\Run: [Performance Center] C:\Program Files\Ascentive\Performance Center\APCMain.exe -m&lt;br /&gt;O4 - HKCU\..\Run: [PTIM.exe] C:\Program Files\WebEx\Productivity Tools\PTIM.exe&lt;br /&gt;O4 - HKCU\..\Run: [ptmsgfrm.exe] C:\Program Files\WebEx\Productivity Tools\ptmsgfrm.exe&lt;br /&gt;O4 - HKCU\..\Run: [PTOneClick] C:\Program Files\WebEx\Productivity Tools\ptoneclk.exe&lt;br /&gt;O4 - HKCU\..\Run: [ISUSPM] &amp;quot;C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe&amp;quot; -scheduler&lt;br /&gt;O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp;amp; Destroy\TeaTimer.exe&lt;br /&gt;O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] &amp;quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&amp;quot; -t (User &amp;#39;SYSTEM&amp;#39;)&lt;br /&gt;O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] &amp;quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&amp;quot; -t (User &amp;#39;Default user&amp;#39;)&lt;br /&gt;O4 - S-1-5-18 Startup: Pandora.lnk = C:\Program Files\Pandora\Pandora.exe (User &amp;#39;SYSTEM&amp;#39;)&lt;br /&gt;O4 - .DEFAULT Startup: Pandora.lnk = C:\Program Files\Pandora\Pandora.exe (User &amp;#39;Default user&amp;#39;)&lt;br /&gt;O4 - Startup: Pandora.lnk = C:\Program Files\Pandora\Pandora.exe&lt;br /&gt;O4 - Global Startup: LapNetWizard.exe&lt;br /&gt;O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html&lt;br /&gt;O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html&lt;br /&gt;O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html&lt;br /&gt;O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html&lt;br /&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll&lt;br /&gt;O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe (file missing)&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe (file missing)&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Spybot - Search &amp;amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra button: Start WebEx One-Click Meeting - {80947ADC-151D-490B-87F1-7C8CE1B46220} - C:\Program Files\WebEx\Productivity Tools\ptonecli.dll (HKCU)&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Start WebEx One-Click Meeting - {80947ADC-151D-490B-87F1-7C8CE1B46220} - C:\Program Files\WebEx\Productivity Tools\ptonecli.dll (HKCU)&lt;br /&gt;O10 - Unknown file in Winsock LSP: bmnet.dll&lt;br /&gt;O10 - Unknown file in Winsock LSP: bmnet.dll&lt;br /&gt;O10 - Unknown file in Winsock LSP: bmnet.dll&lt;br /&gt;O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - &lt;a href="http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab"&gt;http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - &lt;a href="http://photo.walgreens.com/WalgreensActivia.cab"&gt;http://photo.walgreens.com/WalgreensActivia.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {57B16FC0-47A0-475E-8320-C40F375BB72C} (Metrostudy.SecurityMonitor) - &lt;a href="http://www.metrostudy.com/corpwebsite/SecurityMonitor.CAB"&gt;http://www.metrostudy.com/corpwebsite/SecurityMonitor.CAB&lt;/a&gt;&lt;br /&gt;O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - &lt;a href="http://gis.pinellascounty.org/ActiveX/ver6.5/mgaxctrl.cab"&gt;http://gis.pinellascounty.org/ActiveX/ver6.5/mgaxctrl.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - &lt;a href="https://webdl.symantec.com/activex/symdlmgr.cab"&gt;https://webdl.symantec.com/activex/symdlmgr.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - &lt;a href="https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab"&gt;https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - &lt;a href="http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab"&gt;http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - &lt;a href="http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab"&gt;http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {76A2A0AB-38B7-46DB-8E47-F10CDE4D7920} - &lt;a href="http://aerial.leepa.org/ecwplugins/NCS.cab"&gt;http://aerial.leepa.org/ecwplugins/NCS.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {7BC974EF-A718-4A17-B77E-4C8DBC327AFA} (SCE Control) - &lt;a href="http://www.voloper.com/sce/editor.cab"&gt;http://www.voloper.com/sce/editor.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {90F8464F-F001-4102-BBF1-AFB490B3677F} (MetrosearchOnlineSetup.FileDown) - &lt;a href="http://www.metrostudy.com/MetrosearchUpdates/FileDown.CAB"&gt;http://www.metrostudy.com/MetrosearchUpdates/FileDown.CAB&lt;/a&gt;&lt;br /&gt;O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} (DDRevision Class) - &lt;a href="http://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab"&gt;http://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - &lt;a href="https://digmap.webex.com/client/T26L/webex/ieatgpc.cab"&gt;https://digmap.webex.com/client/T26L/webex/ieatgpc.cab&lt;/a&gt;&lt;br /&gt;O23 - Service: AT&amp;amp;T RcAppSvc (ATTRcAppSvc) - SmithMicro Inc. - C:\Program Files\AT&amp;amp;T\Communication Manager\RcAppSvc.exe&lt;br /&gt;O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe&lt;br /&gt;O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;br /&gt;O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;br /&gt;O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;br /&gt;O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe&lt;br /&gt;O23 - Service: DataSvr2 - Unknown owner - C:\Program Files\Wave Systems Corp\Common\DataServer.exe (file missing)&lt;br /&gt;O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe&lt;br /&gt;O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe&lt;br /&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe&lt;br /&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe&lt;br /&gt;O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE&lt;br /&gt;O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;br /&gt;O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe&lt;br /&gt;O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe&lt;br /&gt;O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe&lt;br /&gt;O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe&lt;br /&gt;O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe&lt;br /&gt;O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe&lt;br /&gt;O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe&lt;br /&gt;O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe&lt;br /&gt;O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation&amp;nbsp; - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe&lt;br /&gt;O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe&lt;br /&gt;O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe&lt;/p&gt;
&lt;p&gt;--&lt;br /&gt;End of file - 13305 bytes&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Google Redirect Virus, Windows Police Pro, Unknown virus detected in C:\windows\drtest.exe</title><link>http://en.community.dell.com/forums/thread/19590448.aspx</link><pubDate>Mon, 16 Nov 2009 14:38:38 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19590448</guid><dc:creator>RJDoyleJr</dc:creator><slash:comments>17</slash:comments><comments>http://en.community.dell.com/forums/thread/19590448.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19590448</wfw:commentRss><description>&lt;p&gt;I got hit by Windows Police Pro malware on 10-5-2009, which I seemed to have finally eliminated using Malwarebytes&amp;#39; software. Was reinfected or infected by another rogue anti-virus or some other virus (Google redirect virus) or both 0n 10-25-2009. Since then, have had annoying redirects whether using Google or Yahoo search engines with both Firefox and IE. Have scanned several times with Trend Micro PC-Cillin (my resident anti-virus program) Malwarebytes, SuperAntiSpyware, and PC Doctor, and other than a few ad-ware cookies, have gotten no reports of infections from ANY of these anti-virus/anti-spyware programs. Finally ran F-Secure Online and it reported 6 trojan viruses. One, Trojan.Heur.PT (I think thants the name, I lost it when I forgot to save word file with info before rebooting) was reportedly found in a file called drtest.exe in C:\Windows folder and five others found in Trend Micro quarantine files:
 
  Normal
  0
  
  
  
  
  
  
  
  
  
  
  false
  false
  false
  
  EN-US
  X-NONE
  X-NONE
  
   
   
   
   
   
   
   
   
   
   
   
  
  MicrosoftInternetExplorer4
  
   
   
   
   
   
   
   
   
   
   
   
  

 
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
 

&amp;lt;!--
 /* Font Definitions */
 @font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;
	mso-font-charset:2;
	mso-generic-font-family:auto;
	mso-font-pitch:variable;
	mso-font-signature:0 268435456 0 0 -2147483648 0;}
@font-face
	{font-family:&amp;quot;Cambria Math&amp;quot;;
	panose-1:2 4 5 3 5 4 6 3 2 4;
	mso-font-charset:0;
	mso-generic-font-family:roman;
	mso-font-pitch:variable;
	mso-font-signature:-1610611985 1107304683 0 0 159 0;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;
	mso-font-charset:0;
	mso-generic-font-family:swiss;
	mso-font-pitch:variable;
	mso-font-signature:-1610611985 1073750139 0 0 159 0;}
@font-face
	{font-family:Verdana;
	panose-1:2 11 6 4 3 5 4 4 2 4;
	mso-font-charset:0;
	mso-generic-font-family:swiss;
	mso-font-pitch:variable;
	mso-font-signature:536871559 0 0 0 415 0;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{mso-style-unhide:no;
	mso-style-qformat:yes;
	mso-style-parent:&amp;quot;&amp;quot;;
	margin:0in;
	margin-bottom:.0001pt;
	line-height:125%;
	mso-pagination:widow-orphan;
	mso-layout-grid-align:none;
	punctuation-wrap:simple;
	text-autospace:none;
	font-size:10.0pt;
	font-family:&amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;
	mso-fareast-font-family:&amp;quot;Times New Roman&amp;quot;;
	mso-bidi-font-family:&amp;quot;Times New Roman&amp;quot;;}
.MsoChpDefault
	{mso-style-type:export-only;
	mso-default-props:yes;
	font-size:10.0pt;
	mso-ansi-font-size:10.0pt;
	mso-bidi-font-size:10.0pt;
	mso-ascii-font-family:Calibri;
	mso-hansi-font-family:Calibri;}
@page Section1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-paper-source:0;}
div.Section1
	{page:Section1;}
 /* List Definitions */
 @list l0
	{mso-list-id:370572183;
	mso-list-template-ids:641483718;}
@list l0:level1
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l1
	{mso-list-id:1032337913;
	mso-list-template-ids:-1656734022;}
@list l1:level1
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l2
	{mso-list-id:1239286905;
	mso-list-template-ids:-1923316088;}
@list l2:level1
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3
	{mso-list-id:1652825843;
	mso-list-template-ids:324952348;}
@list l3:level1
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l4
	{mso-list-id:1866794894;
	mso-list-template-ids:288791308;}
@list l4:level1
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
ol
	{margin-bottom:0in;}
ul
	{margin-bottom:0in;}
--&amp;gt;




&lt;/p&gt;
&lt;p&gt;
&lt;h4&gt;&lt;span style="font-family:&amp;#39;Verdana&amp;#39;,&amp;#39;sans-serif&amp;#39;;color:black;"&gt;&lt;a href="http://cgi.f-secure.com/cgi-bin/websearch/vsearch.cgi?q=Trojan.Generic.IS.519527&amp;amp;orig=%27disk%27" target="_blank"&gt;&lt;span style="color:blue;"&gt;Trojan.Generic.IS.519527&lt;/span&gt;&lt;/a&gt;
(virus) &lt;/span&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Times New Roman&amp;#39;,&amp;#39;serif&amp;#39;;"&gt;&lt;/span&gt;&lt;span style="font-family:&amp;#39;Verdana&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;C:\Program
     Files\Trend Micro\Internet Security 14\Quarantine\149D.0mp (Not cleaned
     &amp;amp; Submitted) &lt;/span&gt;&lt;/h4&gt;
&lt;h4&gt;&lt;span style="font-family:&amp;#39;Verdana&amp;#39;,&amp;#39;sans-serif&amp;#39;;color:black;"&gt;&lt;a href="http://cgi.f-secure.com/cgi-bin/websearch/vsearch.cgi?q=Trojan.Generic.2603295&amp;amp;orig=%27disk%27" target="_blank"&gt;&lt;span style="color:blue;"&gt;Trojan.Generic.2603295&lt;/span&gt;&lt;/a&gt;
(virus) &lt;/span&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Times New Roman&amp;#39;,&amp;#39;serif&amp;#39;;"&gt;&lt;/span&gt;&lt;span style="font-family:&amp;#39;Verdana&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;C:\Program
     Files\Trend Micro\Internet Security 14\Quarantine\170.0mp (Not cleaned
     &amp;amp; Submitted) &lt;/span&gt;&lt;/h4&gt;
&lt;h4&gt;&lt;span style="font-family:&amp;#39;Verdana&amp;#39;,&amp;#39;sans-serif&amp;#39;;color:black;"&gt;&lt;a href="http://cgi.f-secure.com/cgi-bin/websearch/vsearch.cgi?q=Trojan.Generic.2603295&amp;amp;orig=%27disk%27" target="_blank"&gt;&lt;span style="color:blue;"&gt;Trojan.Generic.2603295&lt;/span&gt;&lt;/a&gt;
(virus) &lt;/span&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Times New Roman&amp;#39;,&amp;#39;serif&amp;#39;;"&gt;&lt;/span&gt;&lt;span style="font-family:&amp;#39;Verdana&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;C:\Program
     Files\Trend Micro\Internet Security 14\Quarantine\11D.0mp (Not cleaned
     &amp;amp; Submitted) &lt;/span&gt;&lt;/h4&gt;
&lt;h4&gt;&lt;span style="font-family:&amp;#39;Verdana&amp;#39;,&amp;#39;sans-serif&amp;#39;;color:black;"&gt;&lt;a href="http://cgi.f-secure.com/cgi-bin/websearch/vsearch.cgi?q=Trojan.Generic.2603295&amp;amp;orig=%27disk%27" target="_blank"&gt;&lt;span style="color:blue;"&gt;Trojan.Generic.2603295&lt;/span&gt;&lt;/a&gt;
(virus)&lt;/span&gt;&lt;span style="font-family:&amp;#39;Verdana&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt; C:\Program
     Files\Trend Micro\Internet Security 14\Quarantine\18B.0mp (Not cleaned
     &amp;amp; Submitted) &lt;/span&gt;&lt;/h4&gt;
&lt;h4&gt;&lt;span style="font-family:&amp;#39;Verdana&amp;#39;,&amp;#39;sans-serif&amp;#39;;color:black;"&gt;&lt;a href="http://cgi.f-secure.com/cgi-bin/websearch/vsearch.cgi?q=Trojan.Generic.IS.519527&amp;amp;orig=%27disk%27" target="_blank"&gt;&lt;span style="color:blue;"&gt;Trojan.Generic.IS.519527&lt;/span&gt;&lt;/a&gt;
(virus) &lt;/span&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Times New Roman&amp;#39;,&amp;#39;serif&amp;#39;;"&gt;&lt;/span&gt;&lt;span style="font-family:&amp;#39;Verdana&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;C:\Program
     Files\Trend Micro\Internet Security 14\Quarantine\AE9.0mp (Not cleaned
     &amp;amp; Submitted&lt;/span&gt;&lt;/h4&gt;
&lt;/p&gt;
&lt;p&gt;F-Secure Online said it could not eliminate the Trojan.Heur.PT in C:\Windows\drtest, but when I ran F-Security Online later, it did not report the finding this virus.&lt;/p&gt;
&lt;p&gt;Anyway, since the first attack on 10-5-2009, I have not been able to enter safe mode using the F8 key method on startup. I always get the message that Windows is seems to be corrupted and the computer is shutting down. If I reboot normally, the computer works, but I still have the Google redirect problems. Also, I&amp;#39;ve had problems with apps requiring JAVA, saying Java is not loaded correctly, or some such, I don&amp;#39;t exactly remember.&lt;/p&gt;
&lt;p&gt;Here&amp;#39;s my HiJackThis report:&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 12:41:21 PM, on 11/15/2009&lt;br /&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16915)&lt;br /&gt;Boot mode: Normal&lt;br /&gt;&lt;br /&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe&lt;br /&gt;C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\EvtEng.exe&lt;br /&gt;C:\WINDOWS\system32\inetsrv\inetinfo.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;C:\Program Files\MozyHome\mozybackup.exe&lt;br /&gt;C:\WINDOWS\system32\nvsvc32.exe&lt;br /&gt;C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe&lt;br /&gt;C:\Program Files\Retrospect\Retrospect 7.6\retrorun.exe&lt;br /&gt;C:\Program Files\Dell Support Center\bin\sprtsvc.exe&lt;br /&gt;C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe&lt;br /&gt;C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe&lt;br /&gt;C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe&lt;br /&gt;C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;br /&gt;C:\WINDOWS\stsystra.exe&lt;br /&gt;C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe&lt;br /&gt;C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe&lt;br /&gt;C:\Program Files\Dell\MediaDirect\PCMService.exe&lt;br /&gt;C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe&lt;br /&gt;C:\WINDOWS\system32\RUNDLL32.EXE&lt;br /&gt;C:\WINDOWS\system32\rundll32.exe&lt;br /&gt;C:\WINDOWS\system32\KADxMain.exe&lt;br /&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;br /&gt;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe&lt;br /&gt;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jusched.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;br /&gt;C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe&lt;br /&gt;C:\Program Files\Digital Line Detect\DLG.exe&lt;br /&gt;C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe&lt;br /&gt;C:\Program Files\Logitech\SetPoint\SetPoint.exe&lt;br /&gt;C:\Program Files\MozyHome\mozystat.exe&lt;br /&gt;C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe&lt;br /&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe&lt;br /&gt;C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe&lt;br /&gt;C:\Program Files\Mozilla Firefox\firefox.exe&lt;br /&gt;C:\Documents and Settings\Dad\Desktop\HijackThis.exe&lt;br /&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&amp;amp;client=dell-usuk&amp;amp;channel=us&amp;amp;ibd=4071215&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&amp;amp;client=dell-usuk&amp;amp;channel=us&amp;amp;ibd=4071215&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&amp;amp;client=dell-usuk&amp;amp;channel=us&amp;amp;ibd=4071215&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/&lt;br /&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;br /&gt;O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll&lt;br /&gt;O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll&lt;br /&gt;O2 - BHO: Spybot-S&amp;amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br /&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll&lt;br /&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll&lt;br /&gt;O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll&lt;br /&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;br /&gt;O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll&lt;br /&gt;O3 - Toolbar: &amp;amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll&lt;br /&gt;O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll&lt;br /&gt;O4 - HKLM\..\Run: [system test] &amp;quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;br /&gt;O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe&lt;br /&gt;O4 - HKLM\..\Run: [RoxWatchTray] &amp;quot;C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [RoxioDragToDisc] &amp;quot;C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\QTTask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKLM\..\Run: [PCMService] &amp;quot;C:\Program Files\Dell\MediaDirect\PCMService.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [pccguide.exe] &amp;quot;C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet&lt;br /&gt;O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit&lt;br /&gt;O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start&lt;br /&gt;O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup&lt;br /&gt;O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &amp;quot;C:\Program Files\Malwarebytes&amp;#39; Anti-Malware\mbam.exe&amp;quot; /runcleanupscript&lt;br /&gt;O4 - HKLM\..\Run: [KADxMain] C:\WINDOWS\system32\KADxMain.exe&lt;br /&gt;O4 - HKLM\..\Run: [iTunesHelper] &amp;quot;C:\Program Files\iTunes\iTunesHelper.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [ISUSScheduler] &amp;quot;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&amp;quot; -start&lt;br /&gt;O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup&lt;br /&gt;O4 - HKLM\..\Run: [IntelZeroConfig] &amp;quot;C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [IntelWireless] &amp;quot;C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe&amp;quot; /tf Intel PROSet/Wireless&lt;br /&gt;O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe&lt;br /&gt;O4 - HKLM\..\Run: [dscactivate] &amp;quot;C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [DellSupportCenter] &amp;quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&amp;quot; /P DellSupportCenter&lt;br /&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &amp;quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Adobe ARM] &amp;quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] &amp;quot;C:\Program Files\Java\jre6\bin\jusched.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;br /&gt;O4 - HKCU\..\Run: [OE_OEM] &amp;quot;C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [MSMSGS] &amp;quot;C:\Program Files\Messenger\msmsgs.exe&amp;quot; /background&lt;br /&gt;O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe&lt;br /&gt;O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe&lt;br /&gt;O4 - Global Startup: Logitech SetPoint.lnk = ?&lt;br /&gt;O4 - Global Startup: MozyHome Status.lnk = C:\Program Files\MozyHome\mozystat.exe&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000&lt;br /&gt;O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: S&amp;amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Spybot - Search &amp;amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O16 - DPF: {6F6FDB9E-5072-498C-BCB0-2B7F00C49EE7} (DellSystemLite.Scanner) - http://support.dell.com/systemprofiler/DellSystemLite.CAB&lt;br /&gt;O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - https://sbs.cpenow.com/Remote/msrdp.cab&lt;br /&gt;O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll&lt;br /&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;br /&gt;O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;O23 - Service: Browser Defender Update Service - Threat Expert Ltd. - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe&lt;br /&gt;O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe&lt;br /&gt;O23 - Service: Google Update Service (gupdate1ca63c2cf86be80) (gupdate1ca63c2cf86be80) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe&lt;br /&gt;O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;br /&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe&lt;br /&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe&lt;br /&gt;O23 - Service: MozyHome Backup Service (mozybackup) - Mozy, Inc. - C:\Program Files\MozyHome\mozybackup.exe&lt;br /&gt;O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe&lt;br /&gt;O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe&lt;br /&gt;O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe&lt;br /&gt;O23 - Service: Retrospect Launcher (RetroLauncher) - EMC Corporation - C:\Program Files\Retrospect\Retrospect 7.6\retrorun.exe&lt;br /&gt;O23 - Service: Retrospect Helper - EMC Corporation - C:\Program Files\Retrospect\Retrospect 7.6\rthlpsvc.exe&lt;br /&gt;O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe&lt;br /&gt;O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe&lt;br /&gt;O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation&amp;nbsp; - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe&lt;br /&gt;O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe&lt;br /&gt;O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe&lt;br /&gt;O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe&lt;br /&gt;O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe&lt;br /&gt;O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe&lt;br /&gt;O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe&lt;br /&gt;O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe&lt;br /&gt;O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;End of file - 13318 bytes&lt;/p&gt;
&lt;p&gt;Any help is appreciated!&lt;/p&gt;
&lt;p&gt;Bob D.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Suspected Malware - Email is trying to run ActiveX? HJT Log Enclosed.</title><link>http://en.community.dell.com/forums/thread/19594886.aspx</link><pubDate>Mon, 23 Nov 2009 01:08:00 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19594886</guid><dc:creator>Subtle Meeping</dc:creator><slash:comments>3</slash:comments><comments>http://en.community.dell.com/forums/thread/19594886.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19594886</wfw:commentRss><description>&lt;p&gt;Hi guys,&lt;/p&gt;
&lt;p&gt;So,
an email I sent told its recipient that it was trying to run an ActiveX
control on their computer, and our first thought was: virus. Could you
guys help me out with a look through the HJT log to see if there&amp;#39;s
anything in there I should be concerned about? McAfee ran a virus scan
just this morning and didn&amp;#39;t find anything, and MalwareBytes
Anti-Malware scanned just a few days ago, so I was kind-of surprised at
this.&lt;/p&gt;
&lt;p&gt;Apologies if it turns out to be nothing, but I was unable
to find anything by Googling the problem, and I&amp;#39;d rather be safe than
infect anyone I email with a virus.&lt;/p&gt;
&lt;p&gt;Thanks for your time and help!&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 8:02:14 PM, on 11/22/2009&lt;br /&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v8.00 (8.00.6001.18702)&lt;br /&gt;Boot mode: Normal&lt;br /&gt;&lt;br /&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe&lt;br /&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;C:\Program Files\McAfee.com\Agent\mcagent.exe&lt;br /&gt;C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe&lt;br /&gt;C:\Program Files\TiVo\Desktop\TiVoNotify.exe&lt;br /&gt;C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe&lt;br /&gt;C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe&lt;br /&gt;C:\Program Files\OpenOffice.org 3\program\soffice.exe&lt;br /&gt;C:\Program Files\OpenOffice.org 3\program\soffice.bin&lt;br /&gt;C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe&lt;br /&gt;c:\program files\common files\mcafee\mna\mcnasvc.exe&lt;br /&gt;c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe&lt;br /&gt;C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe&lt;br /&gt;C:\Program Files\McAfee\MPF\MPFSrv.exe&lt;br /&gt;C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe&lt;br /&gt;C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe&lt;br /&gt;C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe&lt;br /&gt;C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe&lt;br /&gt;C:\Program Files\TiVo\Desktop\TiVoServer.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\rundll32.exe&lt;br /&gt;C:\WINDOWS\system32\wuauclt.exe&lt;br /&gt;C:\Program Files\Mozilla Firefox\firefox.exe&lt;br /&gt;C:\Documents and Settings\Owner\Desktop\JackHijackThis.exe&lt;br /&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br /&gt;R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)&lt;br /&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br /&gt;O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll&lt;br /&gt;O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)&lt;br /&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;br /&gt;O2 - BHO: TwcToolbarBhoApp Class - {AA1F9DDB-E605-4ba6-81D4-E427DEE012AD} - C:\WINDOWS\system32\TwcToolbarBho.dll&lt;br /&gt;O3 - Toolbar: The Weather Channel Toolbar - {2E5E800E-6AC0-411E-940A-369530A35E43} - C:\WINDOWS\system32\TwcToolbarIe7.dll&lt;br /&gt;O4 - HKLM\..\Run: [mcagent_exe] &amp;quot;C:\Program Files\McAfee.com\Agent\mcagent.exe&amp;quot; /runkey&lt;br /&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &amp;quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &amp;quot;C:\Program Files\Malwarebytes&amp;#39; Anti-Malware\mbam.exe&amp;quot; /runcleanupscript&lt;br /&gt;O4 - HKLM\..\Run: [SpySweeper] &amp;quot;C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe&amp;quot; /startintray&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] &amp;quot;C:\WINDOWS\system32\ctfmon.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [TivoTransfer] &amp;quot;C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe&amp;quot; /service /registry /auto:TivoTransfer&lt;br /&gt;O4 - HKCU\..\Run: [TivoNotify] &amp;quot;C:\Program Files\TiVo\Desktop\TiVoNotify.exe&amp;quot; /service /registry /auto:TivoNotify&lt;br /&gt;O4 - HKCU\..\Run: [TivoServer] &amp;quot;C:\Program Files\TiVo\Desktop\TiVoServer.exe&amp;quot; /service /registry /auto:TivoServer&lt;br /&gt;O4 - HKCU\..\Run: [CTSyncU.exe] &amp;quot;C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [DW6] &amp;quot;C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe&amp;quot;&lt;br /&gt;O4 - HKUS\S-1-5-19\..\Run: [tekiforibe] Rundll32.exe &amp;quot;C:\WINDOWS\system32\hulifeki.dll&amp;quot;,s (User &amp;#39;LOCAL SERVICE&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-20\..\Run: [tekiforibe] Rundll32.exe &amp;quot;C:\WINDOWS\system32\hulifeki.dll&amp;quot;,s (User &amp;#39;NETWORK SERVICE&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User &amp;#39;SYSTEM&amp;#39;)&lt;br /&gt;O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User &amp;#39;Default user&amp;#39;)&lt;br /&gt;O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe&lt;br /&gt;O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE&lt;br /&gt;O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe&lt;br /&gt;O9 - Extra button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O15 - Trusted Zone: http://*.windowsupdate.com&lt;br /&gt;O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab&lt;br /&gt;O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1258234800396&lt;br /&gt;O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab&lt;br /&gt;O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe&lt;br /&gt;O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe&lt;br /&gt;O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe&lt;br /&gt;O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe&lt;br /&gt;O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe&lt;br /&gt;O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe&lt;br /&gt;O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe&lt;br /&gt;O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe&lt;br /&gt;O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe&lt;br /&gt;O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe&lt;br /&gt;O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe&lt;br /&gt;O23 - Service: TiVo Beacon (TivoBeacon2) - TiVo Inc. - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe&lt;br /&gt;O23 - Service: Messenger Sharing Folders USN Journal Reader service (usnjsvc) - Unknown owner - C:\Program Files\MSN Messenger\usnsvc.exe (file missing)&lt;br /&gt;O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe&lt;br /&gt;O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc.&amp;nbsp; - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;End of file - 7900 bytes&lt;br /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Hijackthis log  - malware called Hijack.windowsupdates keeps coming back - can someone help please to zap it permanently</title><link>http://en.community.dell.com/forums/thread/19587183.aspx</link><pubDate>Wed, 11 Nov 2009 17:53:45 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19587183</guid><dc:creator>LittleHal</dc:creator><slash:comments>9</slash:comments><comments>http://en.community.dell.com/forums/thread/19587183.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19587183</wfw:commentRss><description>&lt;p&gt;Hello&lt;/p&gt;
&lt;p&gt;I&amp;#39;m new&amp;nbsp; to the forum. I have&amp;nbsp; a Dell computer which I&amp;#39;m very fond of but&amp;nbsp; it&amp;nbsp; keeps getting reinfected daily with a nasty piece of malware which is stopping me&amp;nbsp; use the&amp;nbsp; Microsoft update service. MalwareBytes identifies it as Hijack.windowsupdates and removes it but&amp;nbsp; next day it is back. &lt;/p&gt;
&lt;p&gt;It was suggested to me to run the&amp;nbsp; Hijackthis programme and submit to experts who might be&amp;nbsp; able to help. I am retired and not a computer expert. I need any&amp;nbsp; explanations to be&amp;nbsp; simple&amp;nbsp; please. I don&amp;#39;t want to harm my&amp;nbsp; computer&amp;nbsp; by&amp;nbsp; doing something wrong.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 17:04:21, on 11/11/2009&lt;br /&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16915)&lt;br /&gt;Boot mode: Normal&lt;/p&gt;
&lt;p&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\Program Files\Virgin Broadband\PCguard\Fws.exe&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;br /&gt;C:\Program Files\Virgin Broadband\PCguard\rps.exe&lt;br /&gt;C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe&lt;br /&gt;C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe&lt;br /&gt;C:\Program Files\Dell Support Center\bin\sprtsvc.exe&lt;br /&gt;C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe&lt;br /&gt;C:\Program Files\Virgin Broadband\PCguard\SafeConnect\Bin\SanaAgent.exe&lt;br /&gt;C:\Program Files\Virgin Broadband\PCguard\RpsSecurityAwareR.exe&lt;br /&gt;C:\WINDOWS\system32\hkcmd.exe&lt;br /&gt;C:\Program Files\Gearbox Connection Kit\bin\confsvr.exe&lt;br /&gt;C:\Program Files\BroadJump\Client Foundation\CFD.exe&lt;br /&gt;C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe&lt;br /&gt;C:\Program Files\Virgin Broadband\advisor\BroadbandadvisorComHandler.exe&lt;br /&gt;C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe&lt;br /&gt;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jusched.exe&lt;br /&gt;C:\Program Files\Virgin Broadband\advisor\Broadbandadvisor.exe&lt;br /&gt;C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;C:\Program Files\DellSupport\DSAgnt.exe&lt;br /&gt;C:\Program Files\VirginMedia\V Stuff Backup\v_stuff_backup.exe&lt;br /&gt;C:\Program Files\Digital Line Detect\DLG.exe&lt;br /&gt;C:\Program Files\Gearbox Connection Kit\bin\gbConMon.exe&lt;br /&gt;C:\Program Files\Gearbox Connection Kit\bin\gbTask.exe&lt;br /&gt;C:\Program Files\VirginMedia\V Stuff Backup\AGMailAgent.exe&lt;br /&gt;C:\Program Files\Malwarebytes&amp;#39; Anti-Malware\mbam.exe&lt;br /&gt;C:\WINDOWS\system32\NOTEPAD.EXE&lt;br /&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/p&gt;
&lt;p&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = &lt;a href="http://www.yahoo.com/search/ie.html"&gt;http://www.yahoo.com/search/ie.html&lt;/a&gt;&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://www.ntlworld.com"&gt;http://www.ntlworld.com&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll&lt;br /&gt;O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll&lt;br /&gt;O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Virgin Broadband\PCguard\pkR.dll&lt;br /&gt;O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll&lt;br /&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll&lt;br /&gt;O2 - BHO: CIEExtension Object - {B51DC573-E998-4834-9B45-BAB7C2AE0A75} - C:\Program Files\Ad-Protect\ADPIEmonitor.dll (file missing)&lt;br /&gt;O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll&lt;br /&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;br /&gt;O2 - BHO: JQSIEStartDetectorImpl - {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll&lt;br /&gt;O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll&lt;br /&gt;O3 - Toolbar: &amp;amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll&lt;br /&gt;O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll&lt;br /&gt;O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)&lt;br /&gt;O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe&lt;br /&gt;O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe&lt;br /&gt;O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers&lt;br /&gt;O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe&lt;br /&gt;O4 - HKLM\..\Run: [Gearbox] &amp;quot;C:\Program Files\Gearbox Connection Kit\bin\confsvr.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe&lt;br /&gt;O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe&lt;br /&gt;O4 - HKLM\..\Run: [ccApp] &amp;quot;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [osCheck] &amp;quot;C:\Program Files\Norton Internet Security\osCheck.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Symantec PIF AlertEng] &amp;quot;C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe&amp;quot; /a /m &amp;quot;C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [dscactivate] &amp;quot;C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [DellSupportCenter] &amp;quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&amp;quot; /P DellSupportCenter&lt;br /&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] &amp;quot;C:\Program Files\Java\jre6\bin\jusched.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Broadbandadvisor.exe] &amp;quot;C:\Program Files\Virgin Broadband\advisor\Broadbandadvisor.exe&amp;quot; /AUTORUN&lt;br /&gt;O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k&lt;br /&gt;O4 - HKLM\..\Run: [TMRUBottedTray] &amp;quot;C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\RunServices: [Gearbox Deferal Check] C:\Program Files\Gearbox Connection Kit\bin\gbdefer.exe&lt;br /&gt;O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - HKCU\..\Run: [MSMSGS] &amp;quot;C:\Program Files\Messenger\msmsgs.exe&amp;quot; /background&lt;br /&gt;O4 - HKCU\..\Run: [DellSupport] &amp;quot;C:\Program Files\DellSupport\DSAgnt.exe&amp;quot; /startup&lt;br /&gt;O4 - HKCU\..\Run: [DellSupportCenter] &amp;quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&amp;quot; /P DellSupportCenter&lt;br /&gt;O4 - HKCU\..\Run: [V Stuff Backup] &amp;quot;C:\Program Files\VirginMedia\V Stuff Backup\v_stuff_backup.exe&amp;quot; /delayed&lt;br /&gt;O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User &amp;#39;LOCAL SERVICE&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User &amp;#39;NETWORK SERVICE&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User &amp;#39;SYSTEM&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-18\..\RunOnce: [MSN Updater] msnms.exe (User &amp;#39;SYSTEM&amp;#39;)&lt;br /&gt;O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User &amp;#39;Default user&amp;#39;)&lt;br /&gt;O4 - HKUS\.DEFAULT\..\RunOnce: [MSN Updater] msnms.exe (User &amp;#39;Default user&amp;#39;)&lt;br /&gt;O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe&lt;br /&gt;O4 - Global Startup: broadband medic.lnk = C:\Program Files\ntl\broadband medic\bin\matcli.exe&lt;br /&gt;O4 - Global Startup: Digital Line Detect.lnk = ?&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O11 - Options group: [java_sun] Java (Sun)&lt;br /&gt;O15 - Trusted Zone: *.betfair.com&lt;br /&gt;O16 - DPF: {0A43D7AC-D6C1-4622-B309-BF975F427C0E} (first direct internet banking plus digital safe) - &lt;a href="https://internetbankingplus2.firstdirect.com/ibplus/frontdoorFD.cab"&gt;https://internetbankingplus2.firstdirect.com/ibplus/frontdoorFD.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - &lt;a href="http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab"&gt;http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} (AccountTracking Profile Manager Class) - &lt;a href="https://moneymanager.egg.com/Pinsafe/accounttracking.cab"&gt;https://moneymanager.egg.com/Pinsafe/accounttracking.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &lt;a href="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1099411372623"&gt;http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1099411372623&lt;/a&gt;&lt;br /&gt;O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &lt;a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1145210309313"&gt;http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1145210309313&lt;/a&gt;&lt;br /&gt;O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - &lt;a href="http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab"&gt;http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - &lt;a href="http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab"&gt;http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - &lt;a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab"&gt;http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - &lt;a href="http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5219/mcfscan.cab"&gt;http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5219/mcfscan.cab&lt;/a&gt;&lt;br /&gt;O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe&lt;br /&gt;O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\&lt;br /&gt;O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;br /&gt;O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;br /&gt;O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;br /&gt;O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe&lt;br /&gt;O23 - Service: Deepsight Extractor (DeepsightExtractor) - Unknown owner - C:\Program Files\Symantec\DeepSight Extractor\ExtractorService.exe (file missing)&lt;br /&gt;O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe&lt;br /&gt;O23 - Service: DeepSight Extractor Service for NPF04 (ExtractorServiceNPF04) - Unknown owner - C:\Program Files\Symantec\DeepSight Extractor\ExtractorServiceNPF04.exe (file missing)&lt;br /&gt;O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe&lt;br /&gt;O23 - Service: Java Quick Starter (javaquickstarterservice) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE&lt;br /&gt;O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;br /&gt;O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe&lt;br /&gt;O23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe&lt;br /&gt;O23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe&lt;br /&gt;O23 - Service: Virgin Broadband PCguard (Radialpoint Security Services) - Virgin Media - C:\Program Files\Virgin Broadband\PCguard\RpsSecurityAwareR.exe&lt;br /&gt;O23 - Service: Virgin Broadband PCguard SafeConnectAgent (RadialpointSafeConnectAgent) - Sana Security - C:\Program Files\Virgin Broadband\PCguard\SafeConnect\Bin\SanaAgent.exe&lt;br /&gt;O23 - Service: PCguard Firewall (RP_FWS) - Virgin Media - C:\Program Files\Virgin Broadband\PCguard\Fws.exe&lt;br /&gt;O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe&lt;br /&gt;O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe&lt;br /&gt;O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe&lt;br /&gt;O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe&lt;br /&gt;O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\&lt;br /&gt;O24 - Desktop Component 0: (no name) - &lt;a href="http://i15.photobucket.com/albums/a393/stuffed42/av-1421.gif"&gt;http://i15.photobucket.com/albums/a393/stuffed42/av-1421.gif&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;--&lt;br /&gt;End of file - 12761 bytes&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;This is the most recent MBAM log which was run just before I ran the&amp;nbsp; Hijackthis programme.&lt;/p&gt;
&lt;p&gt;Malwarebytes&amp;#39; Anti-Malware 1.41&lt;br /&gt;Database version: 3147&lt;br /&gt;Windows 5.1.2600 Service Pack 3&lt;/p&gt;
&lt;p&gt;11/11/2009 17:00:38&lt;br /&gt;mbam-log-2009-11-11 (17-00-38).txt&lt;/p&gt;
&lt;p&gt;Scan type: Quick Scan&lt;br /&gt;Objects scanned: 115921&lt;br /&gt;Time elapsed: 24 minute(s), 25 second(s)&lt;/p&gt;
&lt;p&gt;Memory Processes Infected: 0&lt;br /&gt;Memory Modules Infected: 0&lt;br /&gt;Registry Keys Infected: 0&lt;br /&gt;Registry Values Infected: 2&lt;br /&gt;Registry Data Items Infected: 2&lt;br /&gt;Folders Infected: 0&lt;br /&gt;Files Infected: 0&lt;/p&gt;
&lt;p&gt;Memory Processes Infected:&lt;br /&gt;(No malicious items detected)&lt;/p&gt;
&lt;p&gt;Memory Modules Infected:&lt;br /&gt;(No malicious items detected)&lt;/p&gt;
&lt;p&gt;Registry Keys Infected:&lt;br /&gt;(No malicious items detected)&lt;/p&gt;
&lt;p&gt;Registry Values Infected:&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\Winmon32 (Trojan.Agent) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\MSN Updater (Trojan.Agent) -&amp;gt; Quarantined and deleted successfully.&lt;/p&gt;
&lt;p&gt;Registry Data Items Infected:&lt;br /&gt;HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BITS\ImagePath (Hijack.WindowsUpdates) -&amp;gt; Bad: (%fystemRoot%\System32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wuauserv\ImagePath (Hijack.WindowsUpdates) -&amp;gt; Bad: (%fystemroot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -&amp;gt; Quarantined and deleted successfully.&lt;/p&gt;
&lt;p&gt;Folders Infected:&lt;br /&gt;(No malicious items detected)&lt;/p&gt;
&lt;p&gt;Files Infected:&lt;br /&gt;(No malicious items detected)&lt;/p&gt;
&lt;p&gt;Hope someone can help. I&amp;#39;m going round in circles trying to get rid of the problem.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Disabled Task Manager &amp; system lags (Can u fix it?)</title><link>http://en.community.dell.com/forums/thread/19555529.aspx</link><pubDate>Mon, 21 Sep 2009 11:30:29 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19555529</guid><dc:creator>mxallo</dc:creator><slash:comments>41</slash:comments><comments>http://en.community.dell.com/forums/thread/19555529.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19555529</wfw:commentRss><description>&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 7:06:09 PM, on 9/21/2009&lt;br /&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v8.00 (8.00.6001.18702)&lt;br /&gt;Boot mode: Normal&lt;/p&gt;
&lt;p&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;C:\Program Files\Avira\AntiVir Desktop\sched.exe&lt;br /&gt;C:\WINDOWS\Explorer.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\Program Files\Avira\AntiVir Desktop\avguard.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;C:\WINDOWS\system32\csrcs.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;br /&gt;C:\WINDOWS\RTHDCPL.EXE&lt;br /&gt;C:\WINDOWS\system32\hkcmd.exe&lt;br /&gt;C:\WINDOWS\system32\PersistenceThread.exe&lt;br /&gt;C:\WINDOWS\system32\igfxsrvc.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jusched.exe&lt;br /&gt;C:\Program Files\Battery Meter\BTMeter.exe&lt;br /&gt;C:\Program Files\Wireless Select Switch\WLSS.exe&lt;br /&gt;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&lt;br /&gt;C:\Program Files\MpcStar\Codecs\QuickTime\QTSystem\qttask.exe&lt;br /&gt;C:\Program Files\Avira\AntiVir Desktop\avgnt.exe&lt;br /&gt;C:\Program Files\Dell Video Chat\DellVideoChat.exe&lt;br /&gt;C:\Program Files\PPStream\ppsap.exe&lt;br /&gt;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&lt;br /&gt;C:\Program Files\Internet Download Manager\IDMan.exe&lt;br /&gt;C:\WINDOWS\system32\RVHOST.exe&lt;br /&gt;C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe&lt;br /&gt;C:\Program Files\WordWeb\wweb32.exe&lt;br /&gt;C:\WINDOWS\system32\conime.exe&lt;br /&gt;C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE&lt;br /&gt;C:\Program Files\Windows Live\Contacts\wlcomm.exe&lt;br /&gt;C:\Program Files\Internet Download Manager\IEMonitor.exe&lt;br /&gt;C:\Program Files\3G connect\netcard.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/p&gt;
&lt;p&gt;R3 - URLSearchHook: (no name) - {982CB676-38F0-4D9A-BB72-D9371ABE876E} - (no file)&lt;br /&gt;R3 - URLSearchHook: SgUrlSearHook Class - {BAB1AC41-6FF7-4F2E-A04E-5C592CCFEA7D} - C:\WINDOWS\system32\socul.dll (file missing)&lt;br /&gt;R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll&lt;br /&gt;R3 - URLSearchHook: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTor1.dll&lt;br /&gt;F2 - REG:system.ini: Shell=Explorer.exe csrcs.exe&lt;br /&gt;O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll&lt;br /&gt;O2 - BHO: &amp;amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll&lt;br /&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br /&gt;O2 - BHO: SohuDAIEHelper - {0CA51D02-7739-43EA-8D9A-1E8AD4327B03} - C:\Program Files\P4P\sodaie.dll (file missing)&lt;br /&gt;O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll&lt;br /&gt;O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll&lt;br /&gt;O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)&lt;br /&gt;O2 - BHO: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTor1.dll&lt;br /&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;br /&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll&lt;br /&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll&lt;br /&gt;O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll&lt;br /&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;br /&gt;O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll&lt;br /&gt;O3 - Toolbar: Searchme Toolbar - {4d02e7e6-5930-4b51-b9b0-9f21b3789400} - mscoree.dll (file missing)&lt;br /&gt;O3 - Toolbar: ??1?&amp;curren;1?&amp;egrave;??&amp;uml;?? - {DBBB7978-AF21-4EF4-9AD1-B2F4BC75696C} - C:\Program Files\P4P\ToolBar.dll (file missing)&lt;br /&gt;O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll&lt;br /&gt;O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll&lt;br /&gt;O3 - Toolbar: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTor1.dll&lt;br /&gt;O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;br /&gt;O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE&lt;br /&gt;O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE&lt;br /&gt;O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe&lt;br /&gt;O4 - HKLM\..\Run: [PersistenceThread] C:\WINDOWS\system32\PersistenceThread.exe&lt;br /&gt;O4 - HKLM\..\Run: [IMJPMIG8.1] &amp;quot;C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE&amp;quot; /Spoil /RemAdvDef /Migration32&lt;br /&gt;O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC&lt;br /&gt;O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC&lt;br /&gt;O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName&lt;br /&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] &amp;quot;C:\Program Files\Java\jre6\bin\jusched.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [BTMeter] C:\Program Files\Battery Meter\BTMeter.exe&lt;br /&gt;O4 - HKLM\..\Run: [WLSS] C:\Program Files\Wireless Select Switch\WLSS.exe&lt;br /&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &amp;quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [TkBellExe] &amp;quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&amp;quot;&amp;nbsp; -osboot&lt;br /&gt;O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\MpcStar\Codecs\QuickTime\QTSystem\qttask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKLM\..\Run: [avgnt] &amp;quot;C:\Program Files\Avira\AntiVir Desktop\avgnt.exe&amp;quot; /min&lt;br /&gt;O4 - HKCU\..\Run: [SightSpeed] &amp;quot;C:\Program Files\Dell Video Chat\DellVideoChat.exe&amp;quot; -bootmode&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - HKCU\..\Run: [PPS Accelerator] C:\Program Files\PPStream\ppsap.exe&lt;br /&gt;O4 - HKCU\..\Run: [msnmsgr] &amp;quot;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&amp;quot; /background&lt;br /&gt;O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;br /&gt;O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot&lt;br /&gt;O4 - HKCU\..\Run: [Yahoo Messengger] C:\WINDOWS\system32\RVHOST.exe&lt;br /&gt;O4 - HKLM\..\Policies\Explorer\Run: [csrcs] C:\WINDOWS\system32\csrcs.exe&lt;br /&gt;O4 - HKUS\S-1-5-18\..\Run: [Yahoo Messengger] C:\WINDOWS\system32\RVHOST.exe (User &amp;#39;SYSTEM&amp;#39;)&lt;br /&gt;O4 - HKUS\.DEFAULT\..\Run: [Yahoo Messengger] C:\WINDOWS\system32\RVHOST.exe (User &amp;#39;Default user&amp;#39;)&lt;br /&gt;O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe&lt;br /&gt;O4 - Global Startup: Bluetooth.lnk = ?&lt;br /&gt;O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE&lt;br /&gt;O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1&lt;br /&gt;O8 - Extra context menu item: &amp;amp;D&amp;amp;ownload &amp;amp;with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm&lt;br /&gt;O8 - Extra context menu item: &amp;amp;D&amp;amp;ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm&lt;br /&gt;O8 - Extra context menu item: &amp;amp;D&amp;amp;ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm&lt;br /&gt;O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm&lt;br /&gt;O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm&lt;br /&gt;O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000&lt;br /&gt;O8 - Extra context menu item: Send to &amp;amp;Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm&lt;br /&gt;O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm&lt;br /&gt;O9 - Extra button: ?&amp;uml;&amp;deg;|&amp;igrave;????? - {8755CE6E-0BF7-4441-8751-FB728941B0B4} - C:\Program Files\P4P\rss.dll (file missing)&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm&lt;br /&gt;O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll/206 (file missing)&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O15 - ESC Trusted Zone: &lt;a href="http://*.update.microsoft.com"&gt;http://*.update.microsoft.com&lt;/a&gt;&lt;br /&gt;O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll&lt;br /&gt;O17 - HKLM\System\CCS\Services\Tcpip\..\{C65AD89A-A53C-4AAE-B163-ACC406D4D9D0}: NameServer = 203.82.64.67 203.82.64.41&lt;br /&gt;O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll&lt;br /&gt;O20 - AppInit_DLLs: C:\WINDOWS\system32\SoDAHK.DLL&lt;br /&gt;O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll&lt;br /&gt;O23 - Service: Norton 2009 Reset (.norton2009Reset) - Unknown owner - C:\Documents and Settings\All Users\Application Data\Norton\Norton2009Reset.exe&lt;br /&gt;O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe&lt;br /&gt;O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe&lt;br /&gt;O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe&lt;br /&gt;O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe&lt;br /&gt;O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;br /&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe&lt;br /&gt;O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;O23 - Service: P4P Service - Unknown owner - C:\Program Files\Common Files\Sogou PXP\p2psvr.exe (file missing)&lt;/p&gt;
&lt;p&gt;--&lt;br /&gt;End of file - 11699 bytes&lt;/p&gt;
&lt;p&gt;Can anyone fix this? &amp;quot;P&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Windows Police Pro</title><link>http://en.community.dell.com/forums/thread/19566438.aspx</link><pubDate>Mon, 12 Oct 2009 01:52:38 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19566438</guid><dc:creator>sheripatn</dc:creator><slash:comments>24</slash:comments><comments>http://en.community.dell.com/forums/thread/19566438.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19566438</wfw:commentRss><description>&lt;p&gt;I am having a bad time with this windows police pro. Somebody please help!&amp;nbsp;I cannot do anything without it popping up or keeping me from doing other tasks on my compuer. I am operating with Windows XP Professional&amp;nbsp; SP3. I have to do anything I do on safemode. That is where I am now. I have looked at a lot of forums with no luck so far. Some of the forums said to open task manager and end the process there but when I open the task manager there is not anything named Windows Police Pro. I searched with the search option and found it yesterday in the C drive program files. So I sent it to the recyle bin and emptied the recycle bin but that did no good. I ran search again and now it does not show up anywhere. I tried to restore my computer but the computer just sits there and does nothing. I even got out my computer disk to just install the operating system again and can&amp;#39;t do that. I am running AVG antivirus software but scanning with it does not find it. So I have been reading some of the forums here and hope you can help me. I noticed everyone is sending this hijack file.&amp;nbsp;Here it is. I&amp;nbsp;hope I did it right.&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 9:07:50 PM, on 10/11/2009&lt;br /&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v8.00 (8.00.6001.18702)&lt;br /&gt;Boot mode: Safe mode with network support&lt;/p&gt;
&lt;p&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/p&gt;
&lt;p&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://aol.com/"&gt;http://aol.com/&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = &lt;br /&gt;R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)&lt;br /&gt;R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll&lt;br /&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br /&gt;O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll&lt;br /&gt;O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll&lt;br /&gt;O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL&lt;br /&gt;O2 - BHO: ICQSys (IE PlugIn) - {77DC0B63-1535-4ba9-8BE8-D59EB676FA02} - C:\WINDOWS\system32\plugie.dll&lt;br /&gt;O2 - BHO: AOL Toolbar Loader - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL Toolbar\aoltb.dll&lt;br /&gt;O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll&lt;br /&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll&lt;br /&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll&lt;br /&gt;O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll&lt;br /&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;br /&gt;O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll&lt;br /&gt;O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll&lt;br /&gt;O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL Toolbar\aoltb.dll&lt;br /&gt;O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll&lt;br /&gt;O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll&lt;br /&gt;O4 - HKLM\..\Run: [ScanSoft PDF Professional 4-reminder] &amp;quot;C:\Program Files\ScanSoft\PDF Professional 4.0\Ereg\Ereg.exe&amp;quot; -r &amp;quot;C:\Documents and Settings\All Users\Application Data\ScanSoft\PDF Professional\4\Ereg\Ereg.ini&lt;br /&gt;O4 - HKLM\..\Run: [Symantec PIF AlertEng] &amp;quot;C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe&amp;quot; /a /m &amp;quot;C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [itype] &amp;quot;C:\Program Files\Microsoft IntelliType Pro\itype.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [IntelliPoint] &amp;quot;C:\Program Files\Microsoft IntelliPoint\ipoint.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [EPSON PictureMate] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2P1.EXE /P17 &amp;quot;EPSON PictureMate&amp;quot; /O6 &amp;quot;USB003&amp;quot; /M &amp;quot;PictureMate&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [haihaep] C:\Documents and Settings\Moak Petrolium\haihaep.exe&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - HKUS\S-1-5-21-255879815-3811564576-2564377081-1005\..\Run: [haihaep] C:\Documents and Settings\Moak Petrolium\haihaep.exe (User &amp;#39;?&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-21-255879815-3811564576-2564377081-1005\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User &amp;#39;?&amp;#39;)&lt;br /&gt;O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?&lt;br /&gt;O8 - Extra context menu item: Open with ScanSoft PDF Converter 4.1 - res://C:\Program Files\ScanSoft\PDF Professional 4.0\cnvres_eng.dll /100&lt;br /&gt;O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: S&amp;amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O15 - Trusted Zone: &lt;a href="http://www.pogo.com"&gt;http://www.pogo.com&lt;/a&gt;&lt;br /&gt;O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} (PogoWebLauncher Control) - &lt;a href="http://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB"&gt;http://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB&lt;/a&gt;&lt;br /&gt;O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - &lt;a href="http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab"&gt;http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - &lt;a href="http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab"&gt;http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab&lt;/a&gt;&lt;br /&gt;O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL&lt;br /&gt;O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll&lt;br /&gt;O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll&lt;br /&gt;O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;/p&gt;
&lt;p&gt;--&lt;br /&gt;End of file - 7167 bytes&lt;br /&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Both Firefox and IE8 open tabs to random websites</title><link>http://en.community.dell.com/forums/thread/19592651.aspx</link><pubDate>Thu, 19 Nov 2009 17:40:19 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19592651</guid><dc:creator>paulmcd123</dc:creator><slash:comments>11</slash:comments><comments>http://en.community.dell.com/forums/thread/19592651.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19592651</wfw:commentRss><description>&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 11:47:38 AM, on 11/19/2009&lt;br /&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v8.00 (8.00.6001.18702)&lt;br /&gt;Boot mode: Normal&lt;br /&gt;&lt;br /&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;br /&gt;C:\WINDOWS\system32\ZoneLabs\vsmon.exe&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\WINDOWS\System32\WLTRYSVC.EXE&lt;br /&gt;C:\WINDOWS\System32\bcmwltry.exe&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;C:\Program Files\Avira\AntiVir Desktop\sched.exe&lt;br /&gt;C:\Program Files\Avira\AntiVir Desktop\avguard.exe&lt;br /&gt;C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe&lt;br /&gt;C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\WLTRAY.exe&lt;br /&gt;C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;br /&gt;C:\WINDOWS\system32\ICO.EXE&lt;br /&gt;C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe&lt;br /&gt;C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe&lt;br /&gt;C:\Program Files\Avira\AntiVir Desktop\avgnt.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\Program Files\Spybot - Search &amp;amp; Destroy\TeaTimer.exe&lt;br /&gt;C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE&lt;br /&gt;C:\Program Files\AnVir Task Manager\AnVir.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\Program Files\ATI Technologies\ATI.ACE\cli.exe&lt;br /&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;br /&gt;&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/&lt;br /&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br /&gt;O2 - BHO: Spybot-S&amp;amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br /&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;br /&gt;O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll&lt;br /&gt;O4 - HKLM\..\Run: [ATICCC] &amp;quot;C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe&lt;br /&gt;O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;br /&gt;O4 - HKLM\..\Run: [PMX Daemon] ICO.EXE&lt;br /&gt;O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe&lt;br /&gt;O4 - HKLM\..\Run: [ZoneAlarm Client] &amp;quot;C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [avgnt] &amp;quot;C:\Program Files\Avira\AntiVir Desktop\avgnt.exe&amp;quot; /min&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp;amp; Destroy\TeaTimer.exe&lt;br /&gt;O4 - HKCU\..\Run: [AnVir Task Manager] &amp;quot;C:\Program Files\AnVir Task Manager\AnVir.exe&amp;quot; Minimized&lt;br /&gt;O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Spybot - Search &amp;amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab&lt;br /&gt;O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1201636395109&lt;br /&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;br /&gt;O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe&lt;br /&gt;O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe&lt;br /&gt;O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe&lt;br /&gt;O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe&lt;br /&gt;O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe&lt;br /&gt;O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe&lt;br /&gt;O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe&lt;br /&gt;O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;End of file - 5829 bytes&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;About two weeks ago, after updating Firefox to version 3.5.5(or3.5.4), I noticed that when doing a search in google and clicking on a link, FF would open up several tabs to seemingly random websites (one common one was lightseek.biz, although that doesn&amp;#39;t occur anymore). &lt;/p&gt;
&lt;p&gt;I was running AVG antivirus with ZoneAlarm firewall (free versions). I ran a full AVG antivirus scan and found nothing.&amp;nbsp; Then I ran a full Malwarebytes&amp;#39; Anti-Malware. Nothing.&amp;nbsp; I then ran Ad-Aware.&amp;nbsp; Nothing.&amp;nbsp; Then I ran Spybot Search and Destroy. Nothing.&amp;nbsp; Then I ran SUPERANti-Spyware with no results. I went to Windows Live OneCare Safety Scanner, and that found nothing.&lt;/p&gt;
&lt;p&gt;So I uninstalled AVG Antivirus and installed Avira Antivir Personal Antivirus. I ran a full system scan. Nothing.&amp;nbsp; I downloaded&amp;nbsp; Spyware Blaster. I don&amp;#39;t remember what happened (nothing useful).&lt;/p&gt;
&lt;p&gt;Finally, at the end of my rope, I uninstalled (using RevoUninstaller) Skype, which had given me problems with my AdBlocker Plus Add-On to Firefox (SKype allowed ads to run in my FF browser even though previously AdBlocker has suppressed them before Skype). I rebooted. My home page on Firefox had changed. So I&amp;#39;ve done everything that I know how to do. Now I&amp;#39;ve come here hoping for a fairytale ending.&lt;/p&gt;
&lt;p&gt;Thanks in advance,&lt;/p&gt;
&lt;p&gt;Paul&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Laptop Very Very Slow to Start Up</title><link>http://en.community.dell.com/forums/thread/19592349.aspx</link><pubDate>Thu, 19 Nov 2009 05:13:02 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19592349</guid><dc:creator>Monty49</dc:creator><slash:comments>10</slash:comments><comments>http://en.community.dell.com/forums/thread/19592349.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19592349</wfw:commentRss><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;I am seeking asssitance to resolve a slow start up problem with my Dell Inspiron 9400 lap top. The lap top will take up to half an hour to start (sometimes more) and will be sluggish when it finally does start up. The slow start up only occurs&amp;nbsp;when the laptop is&amp;nbsp;NOT connected to a network (at work - hardwired) or internet&amp;nbsp;(at home - wireless).&amp;nbsp;It appears that some kind of service or program is trying to start but can not and consumes all the resources on the machine causing it to go slow. Performance is&amp;nbsp;fine when connected.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I think this may be a malware problem. My&amp;nbsp;Hyjack This log file is copied below.&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 3:55:41 PM, on 19/11/2009&lt;br /&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v8.00 (8.00.6001.18702)&lt;br /&gt;Boot mode: Normal&lt;/p&gt;
&lt;p&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\EvtEng.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;C:\WINDOWS\system32\bgsvcgen.exe&lt;br /&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;C:\Program Files\CA\eTrust Vet Antivirus\ISafe.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe&lt;br /&gt;C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe&lt;br /&gt;C:\WINDOWS\system32\HPZipm12.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe&lt;br /&gt;C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\Program Files\CA\eTrust Vet Antivirus\VetMsg.exe&lt;br /&gt;C:\WINDOWS\wanmpsvc.exe&lt;br /&gt;C:\WINDOWS\system32\SearchIndexer.exe&lt;br /&gt;C:\WINDOWS\system32\hkcmd.exe&lt;br /&gt;C:\WINDOWS\system32\igfxpers.exe&lt;br /&gt;C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe&lt;br /&gt;C:\WINDOWS\stsystra.exe&lt;br /&gt;C:\Program Files\Dell\Media Experience\DMXLauncher.exe&lt;br /&gt;C:\WINDOWS\system32\dla\tfswctrl.exe&lt;br /&gt;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&lt;br /&gt;C:\Program Files\CA\eTrust Vet Antivirus\CAVRID.exe&lt;br /&gt;C:\Updater.exe&lt;br /&gt;C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe&lt;br /&gt;C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe&lt;br /&gt;C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe&lt;br /&gt;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&lt;br /&gt;C:\WINDOWS\system32\rundll32.exe&lt;br /&gt;C:\Program Files\LogMeIn\x86\LogMeInSystray.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jusched.exe&lt;br /&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;br /&gt;C:\WINDOWS\system32\igfxsrvc.exe&lt;br /&gt;C:\Program Files\NetWaiting\netWaiting.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\Program Files\LogMeIn\x86\LMIGuardian.exe&lt;br /&gt;C:\Program Files\Skype\Phone\Skype.exe&lt;br /&gt;C:\Program Files\Microsoft ActiveSync\wcescomm.exe&lt;br /&gt;C:\Program Files\DNA\btdna.exe&lt;br /&gt;C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE&lt;br /&gt;C:\PROGRA~1\MI3AA1~1\rapimgr.exe&lt;br /&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe&lt;br /&gt;C:\Program Files\Skype\Plugin Manager\SkypePM.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe&lt;br /&gt;C:\WINDOWS\system32\SearchProtocolHost.exe&lt;br /&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/p&gt;
&lt;p&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.0.10.1:8080&lt;br /&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;br /&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll&lt;br /&gt;O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll&lt;br /&gt;O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll&lt;br /&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;br /&gt;O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll&lt;br /&gt;O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe&lt;br /&gt;O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe&lt;br /&gt;O4 - HKLM\..\Run: [IMJPMIG8.1] &amp;quot;C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE&amp;quot; /Spoil /RemAdvDef /Migration32&lt;br /&gt;O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC&lt;br /&gt;O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC&lt;br /&gt;O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName&lt;br /&gt;O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;br /&gt;O4 - HKLM\..\Run: [IntelZeroConfig] &amp;quot;C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [IntelWireless] &amp;quot;C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe&amp;quot; /tf Intel PROSet/Wireless&lt;br /&gt;O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe&lt;br /&gt;O4 - HKLM\..\Run: [ShowLOMControl] &#x1;&lt;br /&gt;O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe&lt;br /&gt;O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe&lt;br /&gt;O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup&lt;br /&gt;O4 - HKLM\..\Run: [ISUSScheduler] &amp;quot;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&amp;quot; -start&lt;br /&gt;O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall&lt;br /&gt;O4 - HKLM\..\Run: [CAVRID] &amp;quot;C:\Program Files\CA\eTrust Vet Antivirus\CAVRID.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [iRiver Updater] \Updater.exe&lt;br /&gt;O4 - HKLM\..\Run: [DVDLauncher] &amp;quot;C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Adobe Photo Downloader] &amp;quot;C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe&lt;br /&gt;O4 - HKLM\..\Run: [cctray] &amp;quot;C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [GrooveMonitor] &amp;quot;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [TalkAndWrite] C:\Documents and Settings\All Users\Application Data\Skype\Plugins\Plugins\1163D2B46CC742E5A3CC9E4157887751\TalkAndWrite.exe /run&lt;br /&gt;O4 - HKLM\..\Run: [OM2_Monitor] &amp;quot;C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe&amp;quot; /OM&lt;br /&gt;O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent&lt;br /&gt;O4 - HKLM\..\Run: [LogMeIn GUI] &amp;quot;C:\Program Files\LogMeIn\x86\LogMeInSystray.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] &amp;quot;C:\Program Files\Java\jre6\bin\jusched.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\qttask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKLM\..\Run: [iTunesHelper] &amp;quot;C:\Program Files\iTunes\iTunesHelper.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &amp;quot;C:\Program Files\Malwarebytes&amp;#39; Anti-Malware\mbam.exe&amp;quot; /runcleanupscript&lt;br /&gt;O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - HKCU\..\Run: [Skype] &amp;quot;C:\Program Files\Skype\Phone\Skype.exe&amp;quot; /nosplash /minimized&lt;br /&gt;O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart&lt;br /&gt;O4 - HKCU\..\Run: [updateMgr] &amp;quot;C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe&amp;quot; AcRdB7_0_9 -reboot 1&lt;br /&gt;O4 - HKCU\..\Run: [OM2_Monitor] &amp;quot;C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe&amp;quot; -NoStart&lt;br /&gt;O4 - HKCU\..\Run: [H/PC Connection Agent] &amp;quot;C:\Program Files\Microsoft ActiveSync\wcescomm.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [BitTorrent DNA] &amp;quot;C:\Program Files\DNA\btdna.exe&amp;quot;&lt;br /&gt;O4 - HKUS\S-1-5-21-3939956800-3381378334-452110342-1006\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe (User &amp;#39;ingres&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-21-3939956800-3381378334-452110342-1006\..\Run: [DellSupport] &amp;quot;C:\Program Files\Dell Support\DSAgnt.exe&amp;quot; /startup (User &amp;#39;ingres&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-21-3939956800-3381378334-452110342-1006\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User &amp;#39;ingres&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-21-3939956800-3381378334-452110342-1006\..\Run: [Skype] &amp;quot;C:\Program Files\Skype\Phone\Skype.exe&amp;quot; /nosplash /minimized (User &amp;#39;ingres&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-21-3939956800-3381378334-452110342-1006\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe (User &amp;#39;ingres&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-21-3939956800-3381378334-452110342-1006\..\Run: [OM2_Monitor] &amp;quot;C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe&amp;quot; (User &amp;#39;ingres&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-21-3939956800-3381378334-452110342-1006\..\Run: [H/PC Connection Agent] &amp;quot;C:\Program Files\Microsoft ActiveSync\wcescomm.exe&amp;quot; (User &amp;#39;ingres&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] &amp;quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&amp;quot; -t (User &amp;#39;SYSTEM&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User &amp;#39;SYSTEM&amp;#39;)&lt;br /&gt;O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] &amp;quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&amp;quot; -t (User &amp;#39;Default user&amp;#39;)&lt;br /&gt;O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User &amp;#39;Default user&amp;#39;)&lt;br /&gt;O4 - S-1-5-21-3939956800-3381378334-452110342-1006 Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User &amp;#39;ingres&amp;#39;)&lt;br /&gt;O4 - S-1-5-21-3939956800-3381378334-452110342-1006 User Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User &amp;#39;ingres&amp;#39;)&lt;br /&gt;O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000&lt;br /&gt;O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: S&amp;amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll&lt;br /&gt;O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll&lt;br /&gt;O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - &lt;a href="http://supportapj.dell.com/systemprofiler/SysPro.CAB"&gt;http://supportapj.dell.com/systemprofiler/SysPro.CAB&lt;/a&gt;&lt;br /&gt;O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - &lt;a href="http://picasaweb.google.com/s/v/23.21/uploader2.cab"&gt;http://picasaweb.google.com/s/v/23.21/uploader2.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - &lt;a href="http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab"&gt;http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - &lt;a href="http://www.adobe.com/products/acrobat/nos/gp.cab"&gt;http://www.adobe.com/products/acrobat/nos/gp.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &lt;a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab"&gt;http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - &lt;a href="https://secure.logmein.com/activex/ractrl.cab?lmi=100"&gt;https://secure.logmein.com/activex/ractrl.cab?lmi=100&lt;/a&gt;&lt;br /&gt;O17 - HKLM\System\CCS\Services\Tcpip\..\{25F74088-1F1F-4209-BCA5-909076753E0B}: NameServer = 61.9.134.49&lt;br /&gt;O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll&lt;br /&gt;O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL&lt;br /&gt;O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Unknown owner - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (file missing)&lt;br /&gt;O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;O23 - Service: B&amp;#39;s Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe&lt;br /&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe&lt;br /&gt;O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Vet Antivirus\ISafe.exe&lt;br /&gt;O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe&lt;br /&gt;O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe&lt;br /&gt;O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe&lt;br /&gt;O23 - Service: Google Update Service (gupdate1c9a1f53817b669) (gupdate1c9a1f53817b669) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe&lt;br /&gt;O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE&lt;br /&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe&lt;br /&gt;O23 - Service: Ingres Intelligent Database [II] (Ingres_Database_II) - Computer Associates - C:\IngresII\ingres\bin\servproc.exe&lt;br /&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe&lt;br /&gt;O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe&lt;br /&gt;O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe&lt;br /&gt;O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe&lt;br /&gt;O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation&amp;nbsp; - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe&lt;br /&gt;O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\eTrust Vet Antivirus\VetMsg.exe&lt;br /&gt;O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe&lt;br /&gt;O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe&lt;/p&gt;
&lt;p&gt;--&lt;br /&gt;End of file - 15208 bytes&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Thankyou in anticipation, Regards Geoff.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Winclear?</title><link>http://en.community.dell.com/forums/thread/19594912.aspx</link><pubDate>Mon, 23 Nov 2009 02:19:09 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19594912</guid><dc:creator>summercat</dc:creator><slash:comments>2</slash:comments><comments>http://en.community.dell.com/forums/thread/19594912.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19594912</wfw:commentRss><description>&lt;p&gt;&lt;strong&gt;Is anyone using this program? Is it spyware, malware, adware or............legitimate?&lt;/strong&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>can any one help?</title><link>http://en.community.dell.com/forums/thread/19594842.aspx</link><pubDate>Sun, 22 Nov 2009 23:27:01 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19594842</guid><dc:creator>xan517</dc:creator><slash:comments>0</slash:comments><comments>http://en.community.dell.com/forums/thread/19594842.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19594842</wfw:commentRss><description>&lt;p&gt;i have a malaware that makes many red and cyan lines, does any one know how to get rid of it?&lt;/p&gt;
&lt;p&gt;im just a kid!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Windows cannot find logon.exe error message upon start up and HJT log</title><link>http://en.community.dell.com/forums/thread/19593113.aspx</link><pubDate>Fri, 20 Nov 2009 13:09:51 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19593113</guid><dc:creator>Nelumvia</dc:creator><slash:comments>1</slash:comments><comments>http://en.community.dell.com/forums/thread/19593113.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19593113</wfw:commentRss><description>&lt;p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;/p&gt;
&lt;p&gt;Scan saved at 2:54:13 &amp;mu;&amp;mu;, on 20/11/2009&lt;/p&gt;
&lt;p&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;/p&gt;
&lt;p&gt;MSIE: Internet Explorer v8.00 (8.00.6001.18702)&lt;/p&gt;
&lt;p&gt;Boot mode: Normal&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Running processes:&lt;/p&gt;
&lt;p&gt;C:\windows\System32\smss.exe&lt;/p&gt;
&lt;p&gt;C:\windows\system32\winlogon.exe&lt;/p&gt;
&lt;p&gt;C:\windows\system32\services.exe&lt;/p&gt;
&lt;p&gt;C:\windows\system32\lsass.exe&lt;/p&gt;
&lt;p&gt;C:\windows\system32\nvsvc32.exe&lt;/p&gt;
&lt;p&gt;C:\windows\system32\svchost.exe&lt;/p&gt;
&lt;p&gt;C:\windows\System32\svchost.exe&lt;/p&gt;
&lt;p&gt;C:\windows\system32\spoolsv.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\AVG\AVG9\avgchsvx.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\AVG\AVG9\avgrsx.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\AVG\AVG9\avgcsrvx.exe&lt;/p&gt;
&lt;p&gt;C:\windows\Explorer.exe&lt;/p&gt;
&lt;p&gt;C:\windows\SOUNDMAN.EXE&lt;/p&gt;
&lt;p&gt;C:\windows\PixArt\PAC7302\Monitor.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Search Guard PlusU\sgpUpdaters.exe&lt;/p&gt;
&lt;p&gt;C:\windows\system32\RUNDLL32.EXE&lt;/p&gt;
&lt;p&gt;C:\Program Files\Java\jre6\bin\jusched.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe&lt;/p&gt;
&lt;p&gt;C:\PROGRA~1\AVG\AVG9\avgtray.exe&lt;/p&gt;
&lt;p&gt;C:\windows\system32\ctfmon.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Skype\Phone\Skype.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Spybot - Search &amp;amp; Destroy\TeaTimer.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\OpenOffice.org 3\program\soffice.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\OpenOffice.org 3\program\soffice.bin&lt;/p&gt;
&lt;p&gt;C:\Program Files\AVG\AVG9\avgwdsvc.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Java\jre6\bin\jqs.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\CyberLink\Shared files\RichVideo.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe&lt;/p&gt;
&lt;p&gt;C:\windows\system32\svchost.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\wbem\wmiapsrv.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Skype\Plugin Manager\skypePM.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Windows Live\Contacts\wlcomm.exe&lt;/p&gt;
&lt;p&gt;C:\windows\System32\svchost.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tattoodle.com?tid={BFDAF72A-B449-46cf-AE4B-BAB42F867DAB}&lt;/p&gt;
&lt;p&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;/p&gt;
&lt;p&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;/p&gt;
&lt;p&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;/p&gt;
&lt;p&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;/p&gt;
&lt;p&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=13925&amp;amp;gct=&amp;amp;gc=1&amp;amp;q=&lt;/p&gt;
&lt;p&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedirect?o=13925&amp;amp;gct=&amp;amp;gc=1&amp;amp;q=%s&lt;/p&gt;
&lt;p&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = &amp;Sigma;&amp;upsilon;&amp;nu;&amp;delta;έ&amp;sigma;&amp;epsilon;&amp;iota;&amp;sigmaf;&lt;/p&gt;
&lt;p&gt;R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll&lt;/p&gt;
&lt;p&gt;F2 - REG:system.ini: Shell=Explorer.exe logon.exe&lt;/p&gt;
&lt;p&gt;O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll&lt;/p&gt;
&lt;p&gt;O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll&lt;/p&gt;
&lt;p&gt;O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll&lt;/p&gt;
&lt;p&gt;O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll&lt;/p&gt;
&lt;p&gt;O2 - BHO: Spybot-S&amp;amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;/p&gt;
&lt;p&gt;O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll&lt;/p&gt;
&lt;p&gt;O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll&lt;/p&gt;
&lt;p&gt;O2 - BHO: &amp;Beta;&amp;omicron;&amp;eta;&amp;theta;ό&amp;sigmaf; &amp;epsilon;&amp;iota;&amp;sigma;ό&amp;delta;&amp;omicron;&amp;upsilon; &amp;tau;&amp;omicron;&amp;upsilon; Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;/p&gt;
&lt;p&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;/p&gt;
&lt;p&gt;O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll&lt;/p&gt;
&lt;p&gt;O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll&lt;/p&gt;
&lt;p&gt;O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll&lt;/p&gt;
&lt;p&gt;O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll&lt;/p&gt;
&lt;p&gt;O3 - Toolbar: Veoh Video Compass - {52836EB0-631A-47B1-94A6-61F9D9112DAE} - C:\Program Files\Veoh Networks\Veoh Video Compass\SearchRecsPlugin.dll&lt;/p&gt;
&lt;p&gt;O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)&lt;/p&gt;
&lt;p&gt;O3 - Toolbar: &amp;amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [PAC7302_Monitor] C:\windows\PixArt\PAC7302\Monitor.exe&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [GrooveMonitor] &amp;quot;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&amp;quot;&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\QTTask.exe&amp;quot; -atboottime&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [SGPUpdater] C:\Program Files\Search Guard PlusU\sgpUpdaters.exe&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [FBSearch] C:\Program Files\Search Guard Plus\SearchGuardPlus.exe&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\windows\system32\NvMcTray.dll,NvTaskbarInit&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] &amp;quot;C:\Program Files\Java\jre6\bin\jusched.exe&amp;quot;&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [LogitechQuickCamRibbon] &amp;quot;C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe&amp;quot; /hide&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe&lt;/p&gt;
&lt;p&gt;O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe&lt;/p&gt;
&lt;p&gt;O4 - HKCU\..\Run: [msnmsgr] &amp;quot;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&amp;quot; /background&lt;/p&gt;
&lt;p&gt;O4 - HKCU\..\Run: [Google Update] &amp;quot;C:\Documents and Settings\&amp;Epsilon;&amp;lambda;έ&amp;nu;&amp;eta;\Local Settings\Application Data\Google\Update\GoogleUpdate.exe&amp;quot; /c&lt;/p&gt;
&lt;p&gt;O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] &amp;quot;C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe&amp;quot;&lt;/p&gt;
&lt;p&gt;O4 - HKCU\..\Run: [Skype] &amp;quot;C:\Program Files\Skype\Phone\Skype.exe&amp;quot; /nosplash /minimized&lt;/p&gt;
&lt;p&gt;O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp;amp; Destroy\TeaTimer.exe&lt;/p&gt;
&lt;p&gt;O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User &amp;#39;LOCAL SERVICE&amp;#39;)&lt;/p&gt;
&lt;p&gt;O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User &amp;#39;NETWORK SERVICE&amp;#39;)&lt;/p&gt;
&lt;p&gt;O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User &amp;#39;SYSTEM&amp;#39;)&lt;/p&gt;
&lt;p&gt;O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User &amp;#39;Default user&amp;#39;)&lt;/p&gt;
&lt;p&gt;O4 - S-1-5-18 Startup: Logitech . &amp;Epsilon;&amp;gamma;&amp;gamma;&amp;rho;&amp;alpha;&amp;phi;ή &amp;pi;&amp;rho;&amp;omicron;ϊό&amp;nu;&amp;tau;&amp;omicron;&amp;sigmaf;.lnk = C:\Program Files\Logitech\Logitech WebCam Software\eReg.exe (User &amp;#39;SYSTEM&amp;#39;)&lt;/p&gt;
&lt;p&gt;O4 - S-1-5-18 Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe (User &amp;#39;SYSTEM&amp;#39;)&lt;/p&gt;
&lt;p&gt;O4 - .DEFAULT Startup: Logitech . &amp;Epsilon;&amp;gamma;&amp;gamma;&amp;rho;&amp;alpha;&amp;phi;ή &amp;pi;&amp;rho;&amp;omicron;ϊό&amp;nu;&amp;tau;&amp;omicron;&amp;sigmaf;.lnk = C:\Program Files\Logitech\Logitech WebCam Software\eReg.exe (User &amp;#39;Default user&amp;#39;)&lt;/p&gt;
&lt;p&gt;O4 - .DEFAULT Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe (User &amp;#39;Default user&amp;#39;)&lt;/p&gt;
&lt;p&gt;O4 - Startup: Logitech . &amp;Epsilon;&amp;gamma;&amp;gamma;&amp;rho;&amp;alpha;&amp;phi;ή &amp;pi;&amp;rho;&amp;omicron;ϊό&amp;nu;&amp;tau;&amp;omicron;&amp;sigmaf;.lnk = C:\Program Files\Logitech\Logitech WebCam Software\eReg.exe&lt;/p&gt;
&lt;p&gt;O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe&lt;/p&gt;
&lt;p&gt;O8 - Extra context menu item: E&amp;amp;&amp;xi;&amp;alpha;&amp;gamma;&amp;omega;&amp;gamma;ή &amp;sigma;&amp;tau;&amp;omicron; Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000&lt;/p&gt;
&lt;p&gt;O8 - Extra context menu item: &amp;Epsilon;&amp;amp;&amp;xi;&amp;alpha;&amp;gamma;&amp;omega;&amp;gamma;ή &amp;sigma;&amp;tau;&amp;omicron; Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000&lt;/p&gt;
&lt;p&gt;O9 - Extra button: &amp;Pi;&amp;rho;&amp;omicron;&amp;sigma;&amp;theta;ή&amp;kappa;&amp;eta; &amp;sigma;&amp;tau;&amp;omicron; &amp;iota;&amp;sigma;&amp;tau;&amp;omicron;&amp;lambda;ό&amp;gamma;&amp;iota;&amp;omicron; - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll&lt;/p&gt;
&lt;p&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: &amp;amp;&amp;Pi;&amp;rho;&amp;omicron;&amp;sigma;&amp;theta;ή&amp;kappa;&amp;eta; &amp;sigma;&amp;tau;&amp;omicron; &amp;iota;&amp;sigma;&amp;tau;&amp;omicron;&amp;lambda;ό&amp;gamma;&amp;iota;&amp;omicron; &amp;sigma;&amp;tau;&amp;omicron; Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll&lt;/p&gt;
&lt;p&gt;O9 - Extra button: &amp;Alpha;&amp;pi;&amp;omicron;&amp;sigma;&amp;tau;&amp;omicron;&amp;lambda;ή &amp;sigma;&amp;tau;&amp;omicron; OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll&lt;/p&gt;
&lt;p&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: &amp;Alpha;&amp;amp;&amp;pi;&amp;omicron;&amp;sigma;&amp;tau;&amp;omicron;&amp;lambda;ή &amp;sigma;&amp;tau;&amp;omicron; OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll&lt;/p&gt;
&lt;p&gt;O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll&lt;/p&gt;
&lt;p&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll&lt;/p&gt;
&lt;p&gt;O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll&lt;/p&gt;
&lt;p&gt;O9 - Extra button: Έ&amp;rho;&amp;epsilon;&amp;upsilon;&amp;nu;&amp;alpha; - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL&lt;/p&gt;
&lt;p&gt;O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;/p&gt;
&lt;p&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Spybot - Search &amp;amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;/p&gt;
&lt;p&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe&lt;/p&gt;
&lt;p&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe&lt;/p&gt;
&lt;p&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;/p&gt;
&lt;p&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;/p&gt;
&lt;p&gt;O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll&lt;/p&gt;
&lt;p&gt;O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll&lt;/p&gt;
&lt;p&gt;O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL&lt;/p&gt;
&lt;p&gt;O20 - Winlogon Notify: avgrsstarter - C:\windows\SYSTEM32\avgrsstx.dll&lt;/p&gt;
&lt;p&gt;O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe&lt;/p&gt;
&lt;p&gt;O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe&lt;/p&gt;
&lt;p&gt;O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe&lt;/p&gt;
&lt;p&gt;O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe&lt;/p&gt;
&lt;p&gt;O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe&lt;/p&gt;
&lt;p&gt;O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;--&lt;/p&gt;
&lt;p&gt;End of file - 11275 bytes&lt;/p&gt;
&lt;div&gt;&lt;/div&gt;
&lt;div&gt;This is the scan I did with HJT as instructed. The problem is still the same: One day, after having turned the pc on and when windows started, AVG found a threat which was Logon.exe. I clicked on heal and the threat was seemingly dealt with, nothing else happened. Ever since however, every time I open my computer and just when I log in windows I get an error message telling me windows cannot find Logon.exe and to try find it in its file (or something of that sort). There are no other symptoms whatsoever.&lt;/div&gt;
&lt;div&gt;&lt;/div&gt;
&lt;div&gt;The only peculiar thing about it is that sometimes my pc, when I try to turn it on, doesnt boot at all and nothing appears on the screen which remains black. When that happens I have to restart it until it actually boots. I don&amp;#39;t suppose it has anything to do with the logon.exe problem but I thought to mention it anyway just in case.&lt;/div&gt;
&lt;div&gt;&lt;/div&gt;
&lt;div&gt;Thank you a lot for your time and help :)&lt;/div&gt;
&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Party Poker Pop-Up - suspect malware - hijackthis log</title><link>http://en.community.dell.com/forums/thread/19587107.aspx</link><pubDate>Wed, 11 Nov 2009 16:46:00 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19587107</guid><dc:creator>shane.utter</dc:creator><slash:comments>6</slash:comments><comments>http://en.community.dell.com/forums/thread/19587107.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19587107</wfw:commentRss><description>&lt;p&gt;Please help:&lt;/p&gt;
&lt;p&gt;I started getting a PartyPoker pop-up every few minutes when browsing with Mozilla Firefox. I did scans with AVG (clean), GlaryUtilities (clean), and am currently running a MS Malicious Software Removal Tool scan.&amp;nbsp; I checked a few help forums,&amp;nbsp;deleted all old versions of SunJava, Firefox, GoogleToolbar (which&amp;nbsp; I had recently installed), and did a hijackthis scan:&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 12:07:10 PM, on 11/11/2008&lt;br /&gt;Platform: Windows Vista SP1 (WinNT 6.00.1905)&lt;br /&gt;MSIE: Internet Explorer v7.00 (7.00.6001.18000)&lt;br /&gt;Boot mode: Normal&lt;/p&gt;
&lt;p&gt;Running processes:&lt;br /&gt;C:\Windows\system32\Dwm.exe&lt;br /&gt;C:\Windows\Explorer.EXE&lt;br /&gt;C:\Windows\system32\taskeng.exe&lt;br /&gt;C:\Program Files\Dell\DellDock\DellDock.exe&lt;br /&gt;C:\Windows\system32\conime.exe&lt;br /&gt;C:\Program Files\Windows Defender\MSASCui.exe&lt;br /&gt;C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;br /&gt;C:\Windows\OEM02Mon.exe&lt;br /&gt;C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe&lt;br /&gt;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&lt;br /&gt;C:\Program Files\Dell\MediaDirect\PCMService.exe&lt;br /&gt;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&lt;br /&gt;C:\Windows\System32\rundll32.exe&lt;br /&gt;C:\Windows\System32\rundll32.exe&lt;br /&gt;C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe&lt;br /&gt;C:\Windows\System32\WLTRAY.EXE&lt;br /&gt;C:\Program Files\AVG\AVG8\avgtray.exe&lt;br /&gt;C:\Program Files\COMODO\Firewall\cfp.exe&lt;br /&gt;C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe&lt;br /&gt;C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe&lt;br /&gt;C:\Windows\system32\wbem\unsecapp.exe&lt;br /&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;br /&gt;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;br /&gt;C:\Program Files\Spybot - Search &amp;amp; Destroy\TeaTimer.exe&lt;br /&gt;C:\Windows\ehome\ehtray.exe&lt;br /&gt;C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe&lt;br /&gt;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&lt;br /&gt;C:\Program Files\Fingerprint Reader Suite\psqltray.exe&lt;br /&gt;C:\Windows\ehome\ehmsas.exe&lt;br /&gt;C:\Windows\System32\rundll32.exe&lt;br /&gt;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&lt;br /&gt;C:\Program Files\Mozilla Thunderbird\thunderbird.exe&lt;br /&gt;C:\Program Files\iTunes\iTunes.exe&lt;br /&gt;C:\Windows\system32\SearchFilterHost.exe&lt;br /&gt;C:\Program Files\Mozilla Firefox\firefox.exe&lt;br /&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/p&gt;
&lt;p&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://www.google.ca/ig/dell?hl=en&amp;amp;client=dell-row&amp;amp;channel=ca&amp;amp;ibd=5080729"&gt;http://www.google.ca/ig/dell?hl=en&amp;amp;client=dell-row&amp;amp;channel=ca&amp;amp;ibd=5080729&lt;/a&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://www.google.ca/ig/dell?hl=en&amp;amp;client=dell-row&amp;amp;channel=ca&amp;amp;ibd=5080729"&gt;http://www.google.ca/ig/dell?hl=en&amp;amp;client=dell-row&amp;amp;channel=ca&amp;amp;ibd=5080729&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = &lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell&lt;br /&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = &lt;br /&gt;O1 - Hosts: ::1 localhost&lt;br /&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br /&gt;O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll&lt;br /&gt;O2 - BHO: Spybot-S&amp;amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br /&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br /&gt;O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL&lt;br /&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll&lt;br /&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll&lt;br /&gt;O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll&lt;br /&gt;O3 - Toolbar: &amp;amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll&lt;br /&gt;O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL&lt;br /&gt;O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide&lt;br /&gt;O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe&lt;br /&gt;O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;br /&gt;O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe&lt;br /&gt;O4 - HKLM\..\Run: [VolPanel] &amp;quot;C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe&amp;quot; /r&lt;br /&gt;O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE&lt;br /&gt;O4 - HKLM\..\Run: [PSQLLauncher] &amp;quot;C:\Program Files\Fingerprint Reader Suite\launcher.exe&amp;quot; /startup&lt;br /&gt;O4 - HKLM\..\Run: [Google Desktop Search] &amp;quot;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&amp;quot; /startup&lt;br /&gt;O4 - HKLM\..\Run: [dscactivate] &amp;quot;C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [PCMService] &amp;quot;C:\Program Files\Dell\MediaDirect\PCMService.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [DellSupportCenter] &amp;quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&amp;quot; /P DellSupportCenter&lt;br /&gt;O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart&lt;br /&gt;O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup&lt;br /&gt;O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit&lt;br /&gt;O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start&lt;br /&gt;O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe&lt;br /&gt;O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe&lt;br /&gt;O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [COMODO Firewall Pro] &amp;quot;C:\Program Files\COMODO\Firewall\cfp.exe&amp;quot; -h&lt;br /&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &amp;quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe&lt;br /&gt;O4 - HKLM\..\Run: [DELL Webcam Manager] &amp;quot;C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe&amp;quot; /s&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\QTTask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe&lt;br /&gt;O4 - HKLM\..\Run: [iTunesHelper] &amp;quot;C:\Program Files\iTunes\iTunesHelper.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [DellSupportCenter] &amp;quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&amp;quot; /P DellSupportCenter&lt;br /&gt;O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;br /&gt;O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp;amp; Destroy\TeaTimer.exe&lt;br /&gt;O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe&lt;br /&gt;O4 - HKCU\..\Run: [googletalk] C:\Users\Shane\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart&lt;br /&gt;O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User &amp;#39;LOCAL SERVICE&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User &amp;#39;LOCAL SERVICE&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User &amp;#39;NETWORK SERVICE&amp;#39;)&lt;br /&gt;O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe&lt;br /&gt;O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE&lt;br /&gt;O4 - Global Startup: Bluetooth.lnk = ?&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000&lt;br /&gt;O8 - Extra context menu item: Send image to &amp;amp;Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm&lt;br /&gt;O8 - Extra context menu item: Send page to &amp;amp;Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm&lt;br /&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br /&gt;O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: &amp;amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll&lt;br /&gt;O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: S&amp;amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm&lt;br /&gt;O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Spybot - Search &amp;amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br /&gt;O13 - Gopher Prefix: &lt;br /&gt;O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll&lt;br /&gt;O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL,avgrsstx.dll C:\Windows\system32\guard32.dll C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL&lt;br /&gt;O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll&lt;br /&gt;O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe&lt;br /&gt;O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe&lt;br /&gt;O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe&lt;br /&gt;O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br /&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe&lt;br /&gt;O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe&lt;br /&gt;O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\Windows\system32\CTsvcCDA.exe&lt;br /&gt;O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe&lt;br /&gt;O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&lt;br /&gt;O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe&lt;br /&gt;O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;br /&gt;O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe&lt;br /&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe&lt;br /&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe&lt;br /&gt;O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe&lt;br /&gt;O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe&lt;br /&gt;O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE&lt;/p&gt;
&lt;p&gt;--&lt;br /&gt;End of file - 12443 bytes&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>error loading C:/Windows/system32/sshnas.dll</title><link>http://en.community.dell.com/forums/thread/19593550.aspx</link><pubDate>Fri, 20 Nov 2009 22:24:08 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19593550</guid><dc:creator>cjsquared</dc:creator><slash:comments>4</slash:comments><comments>http://en.community.dell.com/forums/thread/19593550.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19593550</wfw:commentRss><description>&lt;p&gt;A few days ago my computer had a trojan that opened internet browsers.&amp;nbsp; I think that I got rid of it, but ever since then I&amp;#39;ve been getting an error message about not being able to find the module.&amp;nbsp; I tried to do a system restore, but that didn&amp;#39;t help.&amp;nbsp; Everything else seems to be working fine.&amp;nbsp; So here is my HijackThis log.&amp;nbsp; Any help would be greatly appreciated.&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 2:59:14 PM, on 11/20/2009&lt;br /&gt;Platform: Windows Vista SP1 (WinNT 6.00.1905)&lt;br /&gt;MSIE: Internet Explorer v7.00 (7.00.6001.18319)&lt;br /&gt;Boot mode: Normal&lt;/p&gt;
&lt;p&gt;Running processes:&lt;br /&gt;c:\PROGRA~1\mcafee.com\agent\mcagent.exe&lt;br /&gt;C:\Windows\system32\taskeng.exe&lt;br /&gt;C:\Windows\system32\Dwm.exe&lt;br /&gt;C:\Windows\Explorer.EXE&lt;br /&gt;C:\Program Files\Dell\DellDock\DellDock.exe&lt;br /&gt;C:\Program Files\Windows Defender\MSASCui.exe&lt;br /&gt;C:\Program Files\DellTPad\Apoint.exe&lt;br /&gt;C:\Windows\System32\igfxtray.exe&lt;br /&gt;C:\Windows\System32\hkcmd.exe&lt;br /&gt;C:\Windows\System32\igfxpers.exe&lt;br /&gt;C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe&lt;br /&gt;C:\Windows\System32\WLTRAY.EXE&lt;br /&gt;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&lt;br /&gt;C:\Program Files\Dell\MediaDirect\PCMService.exe&lt;br /&gt;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&lt;br /&gt;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;br /&gt;C:\Windows\ehome\ehtray.exe&lt;br /&gt;C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe&lt;br /&gt;C:\Windows\System32\rundll32.exe&lt;br /&gt;C:\Program Files\Digital Line Detect\DLG.exe&lt;br /&gt;C:\Windows\system32\igfxsrvc.exe&lt;br /&gt;C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe&lt;br /&gt;C:\Windows\system32\wuauclt.exe&lt;br /&gt;C:\Program Files\Windows Media Player\wmpnscfg.exe&lt;br /&gt;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&lt;br /&gt;C:\Windows\ehome\ehmsas.exe&lt;br /&gt;C:\Program Files\DellTPad\ApMsgFwd.exe&lt;br /&gt;C:\Program Files\DellTPad\HidFind.exe&lt;br /&gt;C:\Program Files\DellTPad\Apntex.exe&lt;br /&gt;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&lt;br /&gt;C:\Program Files\Internet Explorer\IEUser.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe&lt;br /&gt;C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe&lt;br /&gt;C:\Users\Cara\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P0GQQN5L\HijackThis[1].exe&lt;br /&gt;C:\Windows\system32\SearchFilterHost.exe&lt;br /&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/p&gt;
&lt;p&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = &lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = &lt;br /&gt;O1 - Hosts: ::1 localhost&lt;br /&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br /&gt;O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll&lt;br /&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br /&gt;O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll&lt;br /&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll&lt;br /&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll&lt;br /&gt;O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll&lt;br /&gt;O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll&lt;br /&gt;O3 - Toolbar: The Weather Channel Toolbar - {2E5E800E-6AC0-411E-940A-369530A35E43} - C:\Windows\System32\TwcToolbarIe7.dll&lt;br /&gt;O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll&lt;br /&gt;O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide&lt;br /&gt;O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe&lt;br /&gt;O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe&lt;br /&gt;O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe&lt;br /&gt;O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe&lt;br /&gt;O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe&lt;br /&gt;O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe&lt;br /&gt;O4 - HKLM\..\Run: [Google Desktop Search] &amp;quot;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&amp;quot; /startup&lt;br /&gt;O4 - HKLM\..\Run: [mcagent_exe] &amp;quot;C:\Program Files\McAfee.com\Agent\mcagent.exe&amp;quot; /runkey&lt;br /&gt;O4 - HKLM\..\Run: [dscactivate] &amp;quot;C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [PCMService] &amp;quot;C:\Program Files\Dell\MediaDirect\PCMService.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Dell DataSafe Online] &amp;quot;C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe&amp;quot; /m&lt;br /&gt;O4 - HKLM\..\Run: [DellSupportCenter] &amp;quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&amp;quot; /P DellSupportCenter&lt;br /&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &amp;quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\QTTask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKLM\..\Run: [SpotmauSecretary] C:\Program Files\Spotmau 2009\Spotmau\Desktop_Secretary\Spotmau_S.exe&lt;br /&gt;O4 - HKCU\..\Run: [swg] &amp;quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [DellSupportCenter] &amp;quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&amp;quot; /P DellSupportCenter&lt;br /&gt;O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe&lt;br /&gt;O4 - HKCU\..\Run: [DW6] &amp;quot;C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [SSHNAS] rundll32.exe C:\Windows\system32\sshnas.dll,DllWork&lt;br /&gt;O4 - HKCU\..\Run: [MailBlocker] C:\Users\Cara\AppData\Local\Temp\b.exe&lt;br /&gt;O4 - HKCU\..\Run: [Minisoft] C:\Users\Cara\AppData\Local\Temp\f.exe&lt;br /&gt;O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe&lt;br /&gt;O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1103471 -&amp;quot;Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; GTB6; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.5.30729; .NET CLR 3.0.30618)&amp;quot; -&amp;quot;&lt;a href="http://www.gamevial.com/playgames.php?game=flylikeabird"&gt;http://www.gamevial.com/playgames.php?game=flylikeabird&lt;/a&gt;&amp;quot;&lt;br /&gt;O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User &amp;#39;LOCAL SERVICE&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User &amp;#39;LOCAL SERVICE&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User &amp;#39;NETWORK SERVICE&amp;#39;)&lt;br /&gt;O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User &amp;#39;Default user&amp;#39;)&lt;br /&gt;O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe&lt;br /&gt;O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe&lt;br /&gt;O4 - Global Startup: McAfee Security Scan.lnk = ?&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000&lt;br /&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br /&gt;O9 - Extra button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL&lt;br /&gt;O13 - Gopher Prefix: &lt;br /&gt;O15 - Trusted Zone: &lt;a href="http://*.mcafee.com"&gt;http://*.mcafee.com&lt;/a&gt;&lt;br /&gt;O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - &lt;a href="http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab"&gt;http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - &lt;a href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab"&gt;http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &lt;a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab"&gt;http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - &lt;a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab"&gt;http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab&lt;/a&gt;&lt;br /&gt;O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL&lt;br /&gt;O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll&lt;br /&gt;O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe&lt;br /&gt;O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe&lt;br /&gt;O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&lt;br /&gt;O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe&lt;br /&gt;O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;br /&gt;O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe&lt;br /&gt;O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe&lt;br /&gt;O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe&lt;br /&gt;O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe&lt;br /&gt;O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe&lt;br /&gt;O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe&lt;br /&gt;O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe&lt;br /&gt;O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe&lt;br /&gt;O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe&lt;br /&gt;O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe&lt;br /&gt;O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe&lt;br /&gt;O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe&lt;br /&gt;O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE&lt;br /&gt;O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe&lt;/p&gt;
&lt;p&gt;--&lt;br /&gt;End of file - 11189 bytes&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>suspicious .dll / hijackthis log</title><link>http://en.community.dell.com/forums/thread/19590649.aspx</link><pubDate>Mon, 16 Nov 2009 19:54:20 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19590649</guid><dc:creator>jessetree</dc:creator><slash:comments>2</slash:comments><comments>http://en.community.dell.com/forums/thread/19590649.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19590649</wfw:commentRss><description>&lt;p&gt;I&amp;#39;ve got a persistent rundll error on bootup and something called clclean.0001 in my temp files.&amp;nbsp; Here is my hijackthis log.&amp;nbsp; all&amp;nbsp; help appreciated - jt&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 2:33:20 PM, on 11/16/2009&lt;br /&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)&lt;br /&gt;Boot mode: Normal&lt;br /&gt;&lt;br /&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\Program Files\AVG\AVG9\avgchsvx.exe&lt;br /&gt;C:\Program Files\AVG\AVG9\avgrsx.exe&lt;br /&gt;C:\Program Files\AVG\AVG9\avgcsrvx.exe&lt;br /&gt;C:\WINDOWS\System32\WLTRYSVC.EXE&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\WINDOWS\System32\bcmwltry.exe&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;C:\WINDOWS\ehome\ehtray.exe&lt;br /&gt;C:\WINDOWS\system32\hkcmd.exe&lt;br /&gt;C:\WINDOWS\system32\igfxpers.exe&lt;br /&gt;C:\WINDOWS\system32\igfxsrvc.exe&lt;br /&gt;C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;br /&gt;C:\WINDOWS\system32\WLTRAY.exe&lt;br /&gt;C:\WINDOWS\stsystra.exe&lt;br /&gt;C:\Program Files\Dell\QuickSet\quickset.exe&lt;br /&gt;C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe&lt;br /&gt;C:\WINDOWS\system32\Rundll32.exe&lt;br /&gt;C:\Program Files\Creative\VoiceCenter\AndreaVC.exe&lt;br /&gt;C:\WINDOWS\system32\dla\tfswctrl.exe&lt;br /&gt;C:\Program Files\AVG\AVG9\avgwdsvc.exe&lt;br /&gt;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&lt;br /&gt;C:\Program Files\Dell\MediaDirect\PCMService.exe&lt;br /&gt;C:\Program Files\HP\HP Software Update\HPWuSchd2.exe&lt;br /&gt;C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe&lt;br /&gt;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&lt;br /&gt;C:\PROGRA~1\AVG\AVG9\avgtray.exe&lt;br /&gt;C:\DOCUME~1\Zeeyon\LOCALS~1\Temp\clclean.0001&lt;br /&gt;C:\Program Files\uTorrent\uTorrent.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe&lt;br /&gt;C:\WINDOWS\system32\CTsvcCDA.exe&lt;br /&gt;C:\WINDOWS\eHome\ehRecvr.exe&lt;br /&gt;C:\Program Files\Digital Line Detect\DLG.exe&lt;br /&gt;C:\WINDOWS\eHome\ehSched.exe&lt;br /&gt;C:\Program Files\AVG\AVG9\avgnsx.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe&lt;br /&gt;C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\wuauclt.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\dllhost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\eHome\ehmsas.exe&lt;br /&gt;C:\WINDOWS\system32\rundll32.exe&lt;br /&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;br /&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&amp;amp;client=dell-usuk&amp;amp;channel=us&amp;amp;ibd=3061120&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&amp;amp;client=dell-usuk&amp;amp;channel=us&amp;amp;ibd=3061120&lt;br /&gt;R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll&lt;br /&gt;O2 - BHO: &amp;amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll&lt;br /&gt;O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll&lt;br /&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll&lt;br /&gt;O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll&lt;br /&gt;O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll&lt;br /&gt;O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll&lt;br /&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll&lt;br /&gt;O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll&lt;br /&gt;O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)&lt;br /&gt;O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll&lt;br /&gt;O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe&lt;br /&gt;O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe&lt;br /&gt;O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;br /&gt;O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe&lt;br /&gt;O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe&lt;br /&gt;O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe&lt;br /&gt;O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r&lt;br /&gt;O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon&lt;br /&gt;O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE&lt;br /&gt;O4 - HKLM\..\Run: [VoiceCenter] &amp;quot;C:\Program Files\Creative\VoiceCenter\AndreaVC.exe&amp;quot; /tray&lt;br /&gt;O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe&lt;br /&gt;O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup&lt;br /&gt;O4 - HKLM\..\Run: [ISUSScheduler] &amp;quot;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&amp;quot; -start&lt;br /&gt;O4 - HKLM\..\Run: [PCMService] &amp;quot;C:\Program Files\Dell\MediaDirect\PCMService.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\QTTask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe&lt;br /&gt;O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe&lt;br /&gt;O4 - HKLM\..\Run: [TkBellExe] &amp;quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&amp;quot;&amp;nbsp; -osboot&lt;br /&gt;O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [wilotigis] Rundll32.exe &amp;quot;c:\windows\system32\bewodanu.dll&amp;quot;,a&lt;br /&gt;O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe&lt;br /&gt;O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe&lt;br /&gt;O4 - HKCU\..\Run: [MSMSGS] &amp;quot;C:\Program Files\Messenger\msmsgs.exe&amp;quot; /background&lt;br /&gt;O4 - HKCU\..\Run: [uTorrent] &amp;quot;C:\Program Files\uTorrent\uTorrent.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe&lt;br /&gt;O4 - Global Startup: Digital Line Detect.lnk = ?&lt;br /&gt;O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe&lt;br /&gt;O4 - Global Startup: McAfee Security Scan.lnk = ?&lt;br /&gt;O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000&lt;br /&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll&lt;br /&gt;O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)&lt;br /&gt;O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1254953039656&lt;br /&gt;O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll&lt;br /&gt;O20 - AppInit_DLLs: c:\windows\system32\hikajipa.dll rapahoba.dll c:\windows\system32\pofepuso.dll c:\windows\system32\bewodanu.dll&lt;br /&gt;O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll&lt;br /&gt;O21 - SSODL: felodupus - {2007e62b-bd17-4d00-99bb-92aeb4bb728f} - c:\windows\system32\pofepuso.dll (file missing)&lt;br /&gt;O21 - SSODL: rerokubaw - {85df616a-830a-4080-8b9d-ab967e5bd703} - c:\windows\system32\bewodanu.dll (file missing)&lt;br /&gt;O22 - SharedTaskScheduler: mujuzedij - {2007e62b-bd17-4d00-99bb-92aeb4bb728f} - c:\windows\system32\pofepuso.dll (file missing)&lt;br /&gt;O22 - SharedTaskScheduler: mujuzedij - {85df616a-830a-4080-8b9d-ab967e5bd703} - c:\windows\system32\bewodanu.dll (file missing)&lt;br /&gt;O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe&lt;br /&gt;O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe&lt;br /&gt;O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe&lt;br /&gt;O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;End of file - 9343 bytes&lt;br /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Hijack This help needed</title><link>http://en.community.dell.com/forums/thread/19593008.aspx</link><pubDate>Fri, 20 Nov 2009 03:11:11 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19593008</guid><dc:creator>Grasp</dc:creator><slash:comments>2</slash:comments><comments>http://en.community.dell.com/forums/thread/19593008.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19593008</wfw:commentRss><description>&lt;p&gt;My Windows XP system keeps minimizing windows unbidden.&lt;/p&gt;
&lt;p&gt;Here is my Hijack this. &amp;nbsp;If anyone can help let me know.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;/p&gt;
&lt;p&gt;Scan saved at 7:03:19 PM, on 11/19/2009&lt;/p&gt;
&lt;p&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;/p&gt;
&lt;p&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16915)&lt;/p&gt;
&lt;p&gt;Boot mode: Normal&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Running processes:&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\System32\smss.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\winlogon.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\services.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\lsass.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\nvsvc32.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\svchost.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\System32\svchost.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\svchost.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\AVG\AVG9\avgchsvx.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\AVG\AVG9\avgrsx.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\spoolsv.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\AVG\AVG9\avgcsrvx.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\Explorer.EXE&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\ehome\ehtray.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\CTHELPER.EXE&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\CTXFIHLP.EXE&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\SYSTEM32\CTXFISPI.EXE&lt;/p&gt;
&lt;p&gt;C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE&lt;/p&gt;
&lt;p&gt;C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\RUNDLL32.EXE&lt;/p&gt;
&lt;p&gt;C:\Program Files\Java\jre6\bin\jusched.exe&lt;/p&gt;
&lt;p&gt;C:\PROGRA~1\AVG\AVG9\avgtray.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\ctfmon.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\AVG\AVG9\avgwdsvc.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\CTsvcCDA.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\eHome\ehRecvr.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\eHome\ehSched.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Java\jre6\bin\jqs.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE&lt;/p&gt;
&lt;p&gt;C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\AVG\AVG9\avgnsx.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\svchost.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\AVG\AVG9\avgemc.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\AVG\AVG9\avgcsrvx.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\SearchIndexer.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\eHome\ehmsas.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\dllhost.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Windows Defender\MSASCui.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Windows Defender\MsMpEng.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\SearchProtocolHost.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qwest.live.com&lt;/p&gt;
&lt;p&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qwest.live.com/&lt;/p&gt;
&lt;p&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qwest.live.com&lt;/p&gt;
&lt;p&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;/p&gt;
&lt;p&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;/p&gt;
&lt;p&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qwest.live.com&lt;/p&gt;
&lt;p&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&amp;amp;client=dell-usuk-rel&amp;amp;channel=us&amp;amp;ibd=6070209&lt;/p&gt;
&lt;p&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Qwest&lt;/p&gt;
&lt;p&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 94.76.205.113:30003&lt;/p&gt;
&lt;p&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (file missing)&lt;/p&gt;
&lt;p&gt;O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll&lt;/p&gt;
&lt;p&gt;O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)&lt;/p&gt;
&lt;p&gt;O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll&lt;/p&gt;
&lt;p&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;/p&gt;
&lt;p&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;/p&gt;
&lt;p&gt;O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll&lt;/p&gt;
&lt;p&gt;O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll&lt;/p&gt;
&lt;p&gt;O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll&lt;/p&gt;
&lt;p&gt;O3 - Toolbar: &amp;amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [PMX Daemon] ICO.EXE&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [CTDVDDET] &amp;quot;C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE&amp;quot;&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [VolPanel] &amp;quot;C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe&amp;quot; /r&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [AudioDrvEmulator] &amp;quot;C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe&amp;quot; -1 AudioDrvEmulator &amp;quot;C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll&amp;quot;&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [Windows Defender] &amp;quot;C:\Program Files\Windows Defender\MSASCui.exe&amp;quot; -hide&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P24 &amp;quot;EPSON Stylus Photo RX500&amp;quot; /O6 &amp;quot;USB001&amp;quot; /M &amp;quot;Stylus Photo RX500&amp;quot;&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &amp;quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&amp;quot;&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [nwiz] nwiz.exe /install&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] &amp;quot;C:\Program Files\Java\jre6\bin\jusched.exe&amp;quot;&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [Adobe ARM] &amp;quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&amp;quot;&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe&lt;/p&gt;
&lt;p&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;/p&gt;
&lt;p&gt;O4 - HKCU\..\Run: [Google Update] &amp;quot;C:\Documents and Settings\Lee\Local Settings\Application Data\Google\Update\GoogleUpdate.exe&amp;quot; /c&lt;/p&gt;
&lt;p&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000&lt;/p&gt;
&lt;p&gt;O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll&lt;/p&gt;
&lt;p&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: &amp;amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll&lt;/p&gt;
&lt;p&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL&lt;/p&gt;
&lt;p&gt;O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)&lt;/p&gt;
&lt;p&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;/p&gt;
&lt;p&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;/p&gt;
&lt;p&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;/p&gt;
&lt;p&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;/p&gt;
&lt;p&gt;O9 - Extra button: Qwest Live - {BE4B4910-EC27-4AA3-9DC5-EE0603E318B7} - http://qwest.live.com (file missing) (HKCU)&lt;/p&gt;
&lt;p&gt;O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://ra.qwest.com/sdccommon/download/tgctlcm.cab&lt;/p&gt;
&lt;p&gt;O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB&lt;/p&gt;
&lt;p&gt;O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab&lt;/p&gt;
&lt;p&gt;O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab&lt;/p&gt;
&lt;p&gt;O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testActiveX/built/signed/DisneyOnlineGames.cab&lt;/p&gt;
&lt;p&gt;O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/31.37/uploader2.cab&lt;/p&gt;
&lt;p&gt;O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab&lt;/p&gt;
&lt;p&gt;O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab&lt;/p&gt;
&lt;p&gt;O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1202678195546&lt;/p&gt;
&lt;p&gt;O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab&lt;/p&gt;
&lt;p&gt;O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Futuremark SystemInfo) - http://service.futuremark.com/virtualmark/tc/FMSI.cab&lt;/p&gt;
&lt;p&gt;O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab&lt;/p&gt;
&lt;p&gt;O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab&lt;/p&gt;
&lt;p&gt;O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll&lt;/p&gt;
&lt;p&gt;O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll&lt;/p&gt;
&lt;p&gt;O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe&lt;/p&gt;
&lt;p&gt;O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe&lt;/p&gt;
&lt;p&gt;O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe&lt;/p&gt;
&lt;p&gt;O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe&lt;/p&gt;
&lt;p&gt;O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe&lt;/p&gt;
&lt;p&gt;O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\ssrc.exe&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;--&lt;/p&gt;
&lt;p&gt;End of file - 9944 bytes&lt;/p&gt;
&lt;div&gt;&lt;/div&gt;
&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Dell crash analysis tool suggests problems with NavEx15.sys, SAVRT.sys, and vsdatant.sys; following Antivirus System Pro infection</title><link>http://en.community.dell.com/forums/thread/19593270.aspx</link><pubDate>Fri, 20 Nov 2009 16:44:08 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19593270</guid><dc:creator>rbilder</dc:creator><slash:comments>0</slash:comments><comments>http://en.community.dell.com/forums/thread/19593270.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19593270</wfw:commentRss><description>&lt;p&gt;Hi - my system was infected 10/25/09 with Antivirus System Pro and i have attempted cleaning with both Symantec (v 10) and also PC Tools &amp;quot;Spyware Doctor&amp;quot;.&amp;nbsp; System boots and runs, but i still have problems with CPU over-usage (mostly by csrss.exe and spoolsv.exe), and then also after system has been on for a while i get BSOD&amp;#39;s. &lt;/p&gt;
&lt;p&gt;I disabled vsdatant.sys following some other web advice, and this seems not to affect my Cisco VPN client function... but i think the problems remain.&lt;/p&gt;
&lt;p&gt;This is a D620 and HJT log is below.&amp;nbsp; Hope you can help!!&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 8:42:07 AM, on 11/20/2009&lt;br /&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16915)&lt;br /&gt;Boot mode: Normal&lt;br /&gt;&lt;br /&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\EvtEng.exe&lt;br /&gt;C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe&lt;br /&gt;C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe&lt;br /&gt;C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe&lt;br /&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe&lt;br /&gt;C:\Program Files\Symantec AntiVirus\DefWatch.exe&lt;br /&gt;C:\WINDOWS\System32\GEARSec.exe&lt;br /&gt;C:\WINDOWS\system32\hasplms.exe&lt;br /&gt;C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE&lt;br /&gt;C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe&lt;br /&gt;C:\WINDOWS\system32\nvsvc32.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe&lt;br /&gt;C:\PROGRA~1\SYMANT~1\vptray.exe&lt;br /&gt;C:\WINDOWS\stsystra.exe&lt;br /&gt;C:\WINDOWS\system32\rundll32.exe&lt;br /&gt;C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe&lt;br /&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe&lt;br /&gt;C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe&lt;br /&gt;C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe&lt;br /&gt;C:\WINDOWS\System32\DLA\DLACTRLW.EXE&lt;br /&gt;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&lt;br /&gt;C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe&lt;br /&gt;C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\Program Files\Apoint\Apoint.exe&lt;br /&gt;C:\Program Files\Symantec AntiVirus\Rtvscan.exe&lt;br /&gt;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&lt;br /&gt;C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe&lt;br /&gt;C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe&lt;br /&gt;C:\WINDOWS\system32\WDBtnMgr.exe&lt;br /&gt;C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe&lt;br /&gt;C:\Program Files\Apoint\HidFind.exe&lt;br /&gt;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&lt;br /&gt;C:\Program Files\Apoint\Apntex.exe&lt;br /&gt;C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe&lt;br /&gt;C:\WINDOWS\system32\SearchIndexer.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;br /&gt;C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe&lt;br /&gt;C:\Documents and Settings\Bob\Local Settings\Application Data\Google\Update\GoogleUpdate.exe&lt;br /&gt;C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe&lt;br /&gt;C:\Program Files\TiVo\Desktop\TiVoNotify.exe&lt;br /&gt;C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe&lt;br /&gt;C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe&lt;br /&gt;C:\Program Files\Windows Desktop Search\WindowsSearch.exe&lt;br /&gt;C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe&lt;br /&gt;C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe&lt;br /&gt;C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtKbd.exe&lt;br /&gt;C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtBty.exe&lt;br /&gt;C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe&lt;br /&gt;C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe&lt;br /&gt;C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe&lt;br /&gt;C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe&lt;br /&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe&lt;br /&gt;C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE&lt;br /&gt;C:\Program Files\Mozilla Firefox\firefox.exe&lt;br /&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;br /&gt;C:\WINDOWS\system32\SearchProtocolHost.exe&lt;br /&gt;C:\WINDOWS\system32\SearchProtocolHost.exe&lt;br /&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://education.dellnet.com/&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://toolbar.inbox.com/search/dispatcher.aspx?tp=aus&amp;amp;qkw=%s&amp;amp;tbid=%tb_id&amp;amp;%language&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.inbox.com/?tbid=80106&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://toolbar.inbox.com/search/ie.aspx?tbid=80106&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80106&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://toolbar.inbox.com/search/ie.aspx?tbid=80106&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80106&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&amp;amp;client=dell-usuk-rel&amp;amp;channel=us&amp;amp;ibd=6070125&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;br /&gt;O1 - Hosts: ::1 localhost&lt;br /&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br /&gt;O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll&lt;br /&gt;O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll&lt;br /&gt;O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\WS_FTP Pro\wsbho2K0.dll&lt;br /&gt;O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll&lt;br /&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll&lt;br /&gt;O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll&lt;br /&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll&lt;br /&gt;O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll&lt;br /&gt;O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll&lt;br /&gt;O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll&lt;br /&gt;O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll&lt;br /&gt;O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\\vptray.exe&lt;br /&gt;O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe&lt;br /&gt;O4 - HKLM\..\Run: [RoxWatchTray] &amp;quot;C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\QTTask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start&lt;br /&gt;O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup&lt;br /&gt;O4 - HKLM\..\Run: [LogitechCommunicationsManager] &amp;quot;C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE&lt;br /&gt;O4 - HKLM\..\Run: [iTunesHelper] &amp;quot;C:\Program Files\iTunes\iTunesHelper.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [ISUSScheduler] &amp;quot;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&amp;quot; -start&lt;br /&gt;O4 - HKLM\..\Run: [IntelWireless] &amp;quot;C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe&amp;quot; /tf Intel PROSet/Wireless&lt;br /&gt;O4 - HKLM\..\Run: [DVDLauncher] &amp;quot;C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Document Manager] C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe&lt;br /&gt;O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE&lt;br /&gt;O4 - HKLM\..\Run: [ccApp] &amp;quot;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background&lt;br /&gt;O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe&lt;br /&gt;O4 - HKLM\..\Run: [Acrobat Assistant 8.0] &amp;quot;C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe&lt;br /&gt;O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet&lt;br /&gt;O4 - HKLM\..\Run: [GrooveMonitor] &amp;quot;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [EEventManager] C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe&lt;br /&gt;O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe&lt;br /&gt;O4 - HKLM\..\Run: [TkBellExe] &amp;quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&amp;quot;&amp;nbsp; -osboot&lt;br /&gt;O4 - HKLM\..\Run: [LogitechQuickCamRibbon] &amp;quot;C:\Program Files\Logitech\QuickCam\Quickcam.exe&amp;quot; /hide&lt;br /&gt;O4 - HKLM\..\Run: [IntelZeroConfig] &amp;quot;C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Adobe ARM] &amp;quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - HKCU\..\Run: [swg] &amp;quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [ISUSPM] &amp;quot;C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe&amp;quot; -scheduler&lt;br /&gt;O4 - HKCU\..\Run: [Google Update] &amp;quot;C:\Documents and Settings\Bob\Local Settings\Application Data\Google\Update\GoogleUpdate.exe&amp;quot; /c&lt;br /&gt;O4 - HKCU\..\Run: [MSMSGS] &amp;quot;C:\Program Files\Messenger\MSMSGS.EXE&amp;quot; /background&lt;br /&gt;O4 - HKCU\..\Run: [TivoTransfer] &amp;quot;C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe&amp;quot; /service /registry /auto:TivoTransfer&lt;br /&gt;O4 - HKCU\..\Run: [TivoServer] &amp;quot;C:\Program Files\TiVo\Desktop\TiVoServer.exe&amp;quot; /service /registry&lt;br /&gt;O4 - HKCU\..\Run: [TivoNotify] &amp;quot;C:\Program Files\TiVo\Desktop\TiVoNotify.exe&amp;quot; /service /registry /auto:TivoNotify&lt;br /&gt;O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] &amp;quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&amp;quot; -t (User &amp;#39;SYSTEM&amp;#39;)&lt;br /&gt;O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] &amp;quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&amp;quot; -t (User &amp;#39;Default user&amp;#39;)&lt;br /&gt;O4 - Global Startup: Bluetooth Manager.lnk = ?&lt;br /&gt;O4 - Global Startup: EMBASSY Trust Suite Secure Update.lnk = C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe&lt;br /&gt;O4 - Global Startup: UCLA Cisco VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe&lt;br /&gt;O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe&lt;br /&gt;O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html&lt;br /&gt;O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html&lt;br /&gt;O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html&lt;br /&gt;O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html&lt;br /&gt;O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html&lt;br /&gt;O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html&lt;br /&gt;O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html&lt;br /&gt;O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000&lt;br /&gt;O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: S&amp;amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll&lt;br /&gt;O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O15 - Trusted Zone: *.intuit.com&lt;br /&gt;O15 - Trusted Zone: http://www.poldracklab.org&lt;br /&gt;O15 - Trusted Zone: http://www.pubbrain.org&lt;br /&gt;O15 - Trusted Zone: http://*.turbotax.com&lt;br /&gt;O15 - Trusted Zone: http://phenomics.cs.ucla.edu&lt;br /&gt;O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/citrix/wficat-no-eula.cab&lt;br /&gt;O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab&lt;br /&gt;O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1177429996625&lt;br /&gt;O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://spss.webex.com/client/T26L/webex/ieatgpc.cab&lt;br /&gt;O16 - DPF: {F09BFD07-20B5-46D8-A6D5-BE4EF22F1F4D} (DGTx.uc1) - http://67.19.107.18/DGTx.CAB&lt;br /&gt;O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll&lt;br /&gt;O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL&lt;br /&gt;O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe&lt;br /&gt;O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe&lt;br /&gt;O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe&lt;br /&gt;O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe&lt;br /&gt;O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe&lt;br /&gt;O23 - Service: EpsonBidirectionalService - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe&lt;br /&gt;O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe&lt;br /&gt;O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe&lt;br /&gt;O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe&lt;br /&gt;O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;br /&gt;O23 - Service: HASP License Manager (hasplms) - Aladdin Knowledge Systems Ltd. - C:\WINDOWS\system32\hasplms.exe&lt;br /&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe&lt;br /&gt;O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe&lt;br /&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe&lt;br /&gt;O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe&lt;br /&gt;O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe&lt;br /&gt;O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe&lt;br /&gt;O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)&lt;br /&gt;O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe&lt;br /&gt;O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe&lt;br /&gt;O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe&lt;br /&gt;O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe&lt;br /&gt;O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe&lt;br /&gt;O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe&lt;br /&gt;O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe&lt;br /&gt;O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe&lt;br /&gt;O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation&amp;nbsp; - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe&lt;br /&gt;O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe&lt;br /&gt;O23 - Service: PC Tools Auxiliary Service (sdauxservice) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe&lt;br /&gt;O23 - Service: PC Tools Security Service (sdcoreservice) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe&lt;br /&gt;O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe&lt;br /&gt;O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe&lt;br /&gt;O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe&lt;br /&gt;O23 - Service: NTRU Hybrid TSS v2.0.25 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe&lt;br /&gt;O23 - Service: TiVo Beacon (TivoBeacon2) - TiVo Inc. - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe&lt;br /&gt;O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;End of file - 20169 bytes&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Very Slow Start-up and Programs Slow To Start</title><link>http://en.community.dell.com/forums/thread/19593054.aspx</link><pubDate>Fri, 20 Nov 2009 08:06:00 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19593054</guid><dc:creator>phoophan</dc:creator><slash:comments>0</slash:comments><comments>http://en.community.dell.com/forums/thread/19593054.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19593054</wfw:commentRss><description>&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 11:55:27 PM, on 11/19/2009&lt;br /&gt;Platform: Unknown Windows (WinNT 6.01.3504)&lt;br /&gt;MSIE: Internet Explorer v8.00 (8.00.7600.16385)&lt;br /&gt;Boot mode: Normal&lt;br /&gt;&lt;br /&gt;Running processes:&lt;br /&gt;C:\Windows\system32\taskhost.exe&lt;br /&gt;C:\Windows\system32\Dwm.exe&lt;br /&gt;C:\Windows\Explorer.EXE&lt;br /&gt;C:\Windows\System32\rundll32.exe&lt;br /&gt;C:\Program Files\HP\HP Software Update\hpwuschd2.exe&lt;br /&gt;C:\Program Files\AVG\AVG9\avgtray.exe&lt;br /&gt;C:\Program Files\Vista Start Menu\VistaStartMenu.exe&lt;br /&gt;C:\Program Files\Software Informer\softinfo.exe&lt;br /&gt;C:\Program Files\TiVo\Desktop\TiVoTransfer.exe&lt;br /&gt;C:\Program Files\TiVo\Desktop\TiVoNotify.exe&lt;br /&gt;C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe&lt;br /&gt;C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe&lt;br /&gt;C:\Users\Adam\AppData\Roaming\CBS Interactive\CNET TechTracker\TechTracker.exe&lt;br /&gt;C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe&lt;br /&gt;C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe&lt;br /&gt;C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe&lt;br /&gt;C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe&lt;br /&gt;C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE&lt;br /&gt;C:\Program Files\AVG\AVG9\avgcsrvx.exe&lt;br /&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;br /&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = &lt;br /&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = &lt;br /&gt;O1 - Hosts: ::1 localhost&lt;br /&gt;O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll&lt;br /&gt;O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll&lt;br /&gt;O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll&lt;br /&gt;O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll&lt;br /&gt;O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)&lt;br /&gt;O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll&lt;br /&gt;O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;br /&gt;O2 - BHO: MapQuest Toolbar Loader - {bd3fd433-147a-482e-a192-614f26e2310c} - C:\Program Files\MapQuest Toolbar\mapquesttb.dll&lt;br /&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;br /&gt;O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll&lt;br /&gt;O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll&lt;br /&gt;O3 - Toolbar: &amp;amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll&lt;br /&gt;O3 - Toolbar: MapQuest Toolbar - {9302e698-7e00-43ab-b867-c6e759bc2ada} - C:\Program Files\MapQuest Toolbar\mapquesttb.dll&lt;br /&gt;O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)&lt;br /&gt;O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll&lt;br /&gt;O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE&lt;br /&gt;O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE&lt;br /&gt;O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe&lt;br /&gt;O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe&lt;br /&gt;O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &amp;quot;C:\Program Files\Malwarebytes&amp;#39; Anti-Malware\mbam.exe&amp;quot; /runcleanupscript&lt;br /&gt;O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\QTTask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun&lt;br /&gt;O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe&lt;br /&gt;O4 - HKCU\..\Run: [VistaStartMenu] &amp;quot;C:\Program Files\Vista Start Menu\VistaStartMenu.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [Software Informer] C:\Program Files\Software Informer\softinfo.exe -autorun&lt;br /&gt;O4 - HKCU\..\Run: [TivoServer] C:\Program Files\TiVo\Desktop\TiVoServer.exe /service /registry&lt;br /&gt;O4 - HKCU\..\Run: [TivoTransfer] C:\Program Files\TiVo\Desktop\TiVoTransfer.exe&lt;br /&gt;O4 - HKCU\..\Run: [TivoNotify] C:\Program Files\TiVo\Desktop\TiVoNotify.exe /service /registry /auto:TivoNotify&lt;br /&gt;O4 - HKCU\..\Run: [TranscodingService] C:\Program Files\TiVo\Desktop\Plus\\TranscodingService.exe&lt;br /&gt;O4 - Startup: CNET TechTracker.lnk = Adam\AppData\Roaming\CBS Interactive\CNET TechTracker\TechTracker.exe&lt;br /&gt;O4 - Global Startup: Google Calendar Sync.lnk = C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe&lt;br /&gt;O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe&lt;br /&gt;O8 - Extra context menu item: Add to Google Photos Screensa&amp;amp;ver - res://C:\Windows\system32\GPhotos.scr/200&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000&lt;br /&gt;O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html&lt;br /&gt;O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: &amp;amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll&lt;br /&gt;O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll&lt;br /&gt;O13 - Gopher Prefix: &lt;br /&gt;O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} (Hewlett-Packard Online Support Services) - http://h20364.www2.hp.com/CSMWeb/Customer/cabs/HPISDataManager.CAB&lt;br /&gt;O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - https://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab&lt;br /&gt;O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab&lt;br /&gt;O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab&lt;br /&gt;O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll&lt;br /&gt;O20 - AppInit_DLLs: avgrsstx.dll&lt;br /&gt;O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe&lt;br /&gt;O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe&lt;br /&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe&lt;br /&gt;O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;br /&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe&lt;br /&gt;O23 - Service: Remote Procedure Call (RPC) Net (rpcnet) - Absolute Software Corp. - C:\Windows\system32\rpcnet.exe&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;End of file - 8421 bytes&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Recently-removed trojan affecting downloads?</title><link>http://en.community.dell.com/forums/thread/19591465.aspx</link><pubDate>Tue, 17 Nov 2009 22:39:22 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19591465</guid><dc:creator>Poet8</dc:creator><slash:comments>11</slash:comments><comments>http://en.community.dell.com/forums/thread/19591465.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19591465</wfw:commentRss><description>&lt;p&gt;Within the past week, SpySweeper found Troj/Virtum-Gen and quarantined it.&amp;nbsp; On the same day, I ran Spybot Search &amp;amp; Destroy, which found and removed (I think) RealDownloadExpress.&amp;nbsp; Now, I&amp;#39;m not actually sure if this is even related, but starting at some point shortly after the above happened, I have been unable to access certain aspects of some websites (pictures / jpegs not showing up / downloading, certain links or buttons not working, etc.).&amp;nbsp; I&amp;#39;m wondering if this could be related to the aforementioned trojan activity, or if it is something totally different?&amp;nbsp; Am I somehow blocking a necessary cookie, a script, etc.?&amp;nbsp; Thanks for any help you could give.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>I cannot access the internet, something has bypassed my firewall</title><link>http://en.community.dell.com/forums/thread/19576314.aspx</link><pubDate>Tue, 27 Oct 2009 15:52:26 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19576314</guid><dc:creator>Sherry1961</dc:creator><slash:comments>17</slash:comments><comments>http://en.community.dell.com/forums/thread/19576314.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19576314</wfw:commentRss><description>&lt;p&gt;See hijacked log below:&amp;nbsp; Any help is greatly appreciated.&lt;/p&gt;
&lt;p&gt;Thanks&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 10:57:43 AM, on 10/27/2009&lt;br /&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16915)&lt;br /&gt;Boot mode: Normal&lt;/p&gt;
&lt;p&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\PROGRA~1\AVG\AVG8\avgrsx.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\PROGRA~1\AVG\AVG8\avgtray.exe&lt;br /&gt;C:\Program Files\HP\HP Software Update\HPWuSchd2.exe&lt;br /&gt;C:\Program Files\Java\j2re1.4.2_19\bin\jusched.exe&lt;br /&gt;C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\Program Files\Ulead Systems\Ulead PhotoImpact 4.2\ABMTSR.EXE&lt;br /&gt;C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe&lt;br /&gt;C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe&lt;br /&gt;C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe&lt;br /&gt;C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/p&gt;
&lt;p&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=74005"&gt;http://go.microsoft.com/fwlink/?LinkId=74005&lt;/a&gt;&lt;br /&gt;O2 - BHO: &amp;amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll&lt;br /&gt;O2 - BHO: (no name) - {BF56A325-23F2-42AD-F4E4-00AAC39CAA53} - (no file)&lt;br /&gt;O2 - BHO: (no name) - {fb06467d-749a-4402-83f3-04f975a5e547} - yehikufu.dll (file missing)&lt;br /&gt;O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll&lt;br /&gt;O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [USSShReg] C:\PROGRA~1\ULEADS~1\ULEADP~1.2\SSaver\Ussshreg.exe /r&lt;br /&gt;O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe&lt;br /&gt;O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe&lt;br /&gt;O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe&lt;br /&gt;O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe&lt;br /&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] &amp;quot;C:\Program Files\Java\j2re1.4.2_19\bin\jusched.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [fozuwuvug] Rundll32.exe &amp;quot;c:\windows\system32\kivebeki.dll&amp;quot;,a&lt;br /&gt;O4 - HKLM\..\Run: [vutikojuzu] Rundll32.exe &amp;quot;gitadumi.dll&amp;quot;,s&lt;br /&gt;O4 - HKCU\..\Run: [MSMSGS] &amp;quot;C:\Program Files\Messenger\msmsgs.exe&amp;quot; /background&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - HKCU\..\RunOnce: [SpybotDeletingB428] command /c del &amp;quot;C:\WINDOWS\system32\diwajame.dll_old&amp;quot;&lt;br /&gt;O4 - HKCU\..\RunOnce: [SpybotDeletingD8610] cmd /c del &amp;quot;C:\WINDOWS\system32\diwajame.dll_old&amp;quot;&lt;br /&gt;O4 - HKCU\..\RunOnce: [SpybotDeletingB6098] command /c del &amp;quot;C:\WINDOWS\system32\gitadumi.dll_old&amp;quot;&lt;br /&gt;O4 - HKCU\..\RunOnce: [SpybotDeletingD7126] cmd /c del &amp;quot;C:\WINDOWS\system32\gitadumi.dll_old&amp;quot;&lt;br /&gt;O4 - HKCU\..\RunOnce: [SpybotDeletingB594] command /c del &amp;quot;c:\windows\system32\kivebeki.dll_old&amp;quot;&lt;br /&gt;O4 - HKCU\..\RunOnce: [SpybotDeletingD7183] cmd /c del &amp;quot;c:\windows\system32\kivebeki.dll_old&amp;quot;&lt;br /&gt;O4 - HKUS\S-1-5-21-1214440339-1336601894-725345543-1004\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp;amp; Destroy\TeaTimer.exe (User &amp;#39;Grack&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-21-1214440339-1336601894-725345543-1004\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User &amp;#39;Grack&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-21-1214440339-1336601894-725345543-1004\..\Run: [MSMSGS] &amp;quot;C:\Program Files\Messenger\msmsgs.exe&amp;quot; /background (User &amp;#39;Grack&amp;#39;)&lt;br /&gt;O4 - S-1-5-21-1214440339-1336601894-725345543-1004 Startup: OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE (User &amp;#39;Grack&amp;#39;)&lt;br /&gt;O4 - S-1-5-21-1214440339-1336601894-725345543-1004 User Startup: OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE (User &amp;#39;Grack&amp;#39;)&lt;br /&gt;O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe&lt;br /&gt;O4 - Global Startup: Album Fast Start.lnk = C:\Program Files\Ulead Systems\Ulead PhotoImpact 4.2\ABMTSR.EXE&lt;br /&gt;O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000&lt;br /&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll&lt;br /&gt;O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Spybot - Search &amp;amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - &lt;a href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab"&gt;http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - &lt;a href="http://lads.myspace.com/upload/MySpaceUploader1006.cab"&gt;http://lads.myspace.com/upload/MySpaceUploader1006.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &lt;a href="http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1232113856359"&gt;http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1232113856359&lt;/a&gt;&lt;br /&gt;O20 - AppInit_DLLs: c:\windows\system32\ c:\windows\system32\sijohoho c:\windows\system32\kivebeki.dll,diwajame.dll&lt;br /&gt;O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll&lt;br /&gt;O21 - SSODL: rewojodus - {7a7ec55d-a405-4013-80c0-249b67321d43} - c:\windows\system32\sijohoho.dll (file missing)&lt;br /&gt;O21 - SSODL: kisejazuv - {494ce587-dbf9-49af-b8b1-06467e862436} - c:\windows\system32\kivebeki.dll (file missing)&lt;br /&gt;O22 - SharedTaskScheduler: mujuzedij - {7a7ec55d-a405-4013-80c0-249b67321d43} - c:\windows\system32\sijohoho.dll (file missing)&lt;br /&gt;O22 - SharedTaskScheduler: gahurihor - {494ce587-dbf9-49af-b8b1-06467e862436} - c:\windows\system32\kivebeki.dll (file missing)&lt;br /&gt;O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br /&gt;O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe&lt;/p&gt;
&lt;p&gt;--&lt;br /&gt;End of file - 7539 bytes&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Possible fake antivirus software that blocks internet functions</title><link>http://en.community.dell.com/forums/thread/19565430.aspx</link><pubDate>Fri, 09 Oct 2009 23:59:06 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19565430</guid><dc:creator>antifadeatom</dc:creator><slash:comments>5</slash:comments><comments>http://en.community.dell.com/forums/thread/19565430.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19565430</wfw:commentRss><description>&lt;p&gt;I recently and ignorantly downloaded antivirus software-alpha antivirus- and the program continuously runs. I don&amp;#39;t know of any way to stop it. I have tried to uninstall but my computer says its&amp;nbsp; an invalid option after I approve the removal, and thus nothing happens. The problem that really effects me is that I can no longer access internet. Every time I open the browser, a &amp;quot;pop up block&amp;quot; takes over the screen, telling me that the internet site I&amp;#39;m on is unsafe. I know this isn&amp;#39;t true since its my school email site. However, it displays two options: continue unprotected and get security software. The &amp;quot;continue unprotected&amp;quot; link doesn&amp;#39;t work, but the other link takes me to a page that wants my credit card information etc. I have not given any of this out. And am unsure if this is an actual software or one of the scams going around that I just heard about, 2 hours too late.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I&amp;#39;ve been told that the best thing to do is to wipe the hard drive completely and re-install my vista software. Is this a good option? Are there any tips that don&amp;#39;t involve me loosing all of my information? If not, could someone please direct me in wiping my hard drive correctly?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Getting pop-ups of "not a valid windows image" every time a program is initiated</title><link>http://en.community.dell.com/forums/thread/19591778.aspx</link><pubDate>Wed, 18 Nov 2009 14:27:30 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19591778</guid><dc:creator>Huggins</dc:creator><slash:comments>5</slash:comments><comments>http://en.community.dell.com/forums/thread/19591778.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19591778</wfw:commentRss><description>&lt;p&gt;Hello, I&amp;#39;m new to all of this and could use some assistance. My computer has just started giving the error message &amp;quot;not a valid windoes image&amp;quot; every time I initiate any program. I have run MBAM as well as Defender Pro virus protection full system scans, and have come up with nothing. Any help would be greatly appreciated. Thanks.&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 8:16:54 AM, on 11/18/2009&lt;br /&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v8.00 (8.00.6001.18702)&lt;br /&gt;Boot mode: Normal&lt;/p&gt;
&lt;p&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\Program Files\Common Files\Defender Pro\Defender Pro Update Service\livesrv.exe&lt;br /&gt;C:\Program Files\Defender Pro\Defender Pro\vsserv.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;br /&gt;C:\WINDOWS\System32\WLTRYSVC.EXE&lt;br /&gt;C:\WINDOWS\System32\bcmwltry.exe&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;C:\Program Files\Dell Network Assistant\hnm_svc.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;br /&gt;C:\Program Files\Defender Pro\Defender Pro\bdagent.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jusched.exe&lt;br /&gt;C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\Program Files\Dell Network Assistant\ezi_hnm2.exe&lt;br /&gt;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE&lt;br /&gt;C:\Program Files\Defender Pro\Defender Pro\seccenter.exe&lt;br /&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe&lt;br /&gt;C:\WINDOWS\system32\rundll32.exe&lt;br /&gt;C:\WINDOWS\System32\rundll32.exe&lt;br /&gt;C:\WINDOWS\system32\rundll32.exe&lt;br /&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;br /&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;br /&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;br /&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/p&gt;
&lt;p&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://home.jzip.com"&gt;http://home.jzip.com&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &lt;a href="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html"&gt;http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &lt;a href="http://www.dell.com/"&gt;http://www.dell.com/&lt;/a&gt;&lt;br /&gt;R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll&lt;br /&gt;O2 - BHO: &amp;amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll&lt;br /&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll&lt;br /&gt;O2 - BHO: Search Assistant - {1648E328-3E5A-4EA5-A9C6-E5F09EE272DA} - (no file)&lt;br /&gt;O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll&lt;br /&gt;O2 - BHO: EmailBHO - {647FD14A-C4F1-46F4-8FC3-0B40F54226F7} - C:\Program Files\jZip\WebmailPlugin.dll&lt;br /&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;br /&gt;O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll&lt;br /&gt;O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll&lt;br /&gt;O3 - Toolbar: Defender Pro Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\Defender Pro\Defender Pro\IEToolbar.dll&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\qttask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKLM\..\Run: [iTunesHelper] &amp;quot;C:\Program Files\iTunes\iTunesHelper.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [DPAgent] &amp;quot;C:\Program Files\Defender Pro\Defender Pro\bdagent.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Defender Pro Antiphishing Helper] &amp;quot;C:\Program Files\Defender Pro\Defender Pro\IEShow.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe&lt;br /&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] &amp;quot;C:\Program Files\Java\jre6\bin\jusched.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &amp;quot;C:\Program Files\Malwarebytes&amp;#39; Anti-Malware\mbam.exe&amp;quot; /runcleanupscript&lt;br /&gt;O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe&lt;br /&gt;O4 - HKCU\..\Run: [wben] &amp;quot;C:\Program Files\Starfield\Desktop Notifier\wben.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&lt;br /&gt;O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe&lt;br /&gt;O4 - HKCU\..\Run: [DW6] &amp;quot;C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - S-1-5-18 Startup: ePrompter.lnk = C:\Program Files\ePrompter\ePrompter.exe (User &amp;#39;SYSTEM&amp;#39;)&lt;br /&gt;O4 - S-1-5-18 Startup: IMVU.lnk = C:\Program Files\IMVU\IMVUClient.exe (User &amp;#39;SYSTEM&amp;#39;)&lt;br /&gt;O4 - .DEFAULT Startup: ePrompter.lnk = C:\Program Files\ePrompter\ePrompter.exe (User &amp;#39;Default user&amp;#39;)&lt;br /&gt;O4 - .DEFAULT Startup: IMVU.lnk = C:\Program Files\IMVU\IMVUClient.exe (User &amp;#39;Default user&amp;#39;)&lt;br /&gt;O4 - Startup: ePrompter.lnk = C:\Program Files\ePrompter\ePrompter.exe&lt;br /&gt;O4 - Startup: IMVU.lnk = C:\Program Files\IMVU\IMVUClient.exe&lt;br /&gt;O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe&lt;br /&gt;O4 - Global Startup: Dell Network Assistant.lnk = ?&lt;br /&gt;O8 - Extra context menu item: &amp;amp;Search - ?p=ZNxmk502YYUS&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000&lt;br /&gt;O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Ashley\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - &lt;a href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab"&gt;http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll&lt;br /&gt;O16 - DPF: {3E90FFF5-1347-45B9-91F6-DA47926E9697} (PlaNet SysInfo Agent) - &lt;a href="http://www.newhomebasedccr.com/test/PlaNetSysInfo.cab"&gt;http://www.newhomebasedccr.com/test/PlaNetSysInfo.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - &lt;a href="http://lads.myspace.com/upload/MySpaceUploader1006.cab"&gt;http://lads.myspace.com/upload/MySpaceUploader1006.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - &lt;a href="http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab"&gt;http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - &lt;a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab"&gt;http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab&lt;/a&gt;&lt;br /&gt;O20 - AppInit_DLLs: gojibese.dll,ravufuge.dll,yitebita.dll&lt;br /&gt;O21 - SSODL: pelotihaj - {f0ab405b-0482-42f9-851f-da66573764d8} - (no file)&lt;br /&gt;O21 - SSODL: judolijih - {cf19a1ec-b35b-48ce-9a43-0bd46b9229bb} - (no file)&lt;br /&gt;O21 - SSODL: waduhifor - {466e96fe-113c-4bb5-9acd-ae3d97eac8df} - (no file)&lt;br /&gt;O21 - SSODL: yogimuzas - {9c01f80b-34bc-4133-afae-25d860996ce9} - (no file)&lt;br /&gt;O21 - SSODL: lelidahev - {340a3a5b-8065-416a-a458-183b270359e4} - c:\windows\system32\muyuwole.dll (file missing)&lt;br /&gt;O21 - SSODL: newapikad - {7f9b27ac-a4ab-4add-9efa-3a1670773f33} - (no file)&lt;br /&gt;O21 - SSODL: bihozuhuk - {53c6f5ee-3116-4142-b11b-f9b9b240c588} - (no file)&lt;br /&gt;O21 - SSODL: yuwoberof - {1c1077c5-631c-4601-9694-f889cea65b61} - (no file)&lt;br /&gt;O21 - SSODL: keyapasef - {9f89261b-99f9-43fc-a860-e37da7106a3f} - c:\windows\system32\muyuwole.dll (file missing)&lt;br /&gt;O21 - SSODL: vewosesot - {25d0ec28-723f-4ecc-98dd-721a0fbc8fc4} - (no file)&lt;br /&gt;O21 - SSODL: jamefubud - {9a3fde0a-bb06-4e07-be2c-8875d6d52249} - (no file)&lt;br /&gt;O21 - SSODL: kobasigon - {f6b8b6b5-790e-4e60-aabb-9a3532c13c20} - (no file)&lt;br /&gt;O21 - SSODL: lekikapon - {e7f7d43d-82e9-4099-9554-9e3b3853982c} - c:\windows\system32\viyogula.dll (file missing)&lt;br /&gt;O21 - SSODL: wavunezoy - {4efa40b8-b7a9-42cc-b7fe-0c46f74f7b8d} - (no file)&lt;br /&gt;O22 - SharedTaskScheduler: mujuzedij - {f0ab405b-0482-42f9-851f-da66573764d8} - (no file)&lt;br /&gt;O22 - SharedTaskScheduler: kupuhivus - {cf19a1ec-b35b-48ce-9a43-0bd46b9229bb} - (no file)&lt;br /&gt;O22 - SharedTaskScheduler: tokatiluy - {466e96fe-113c-4bb5-9acd-ae3d97eac8df} - (no file)&lt;br /&gt;O22 - SharedTaskScheduler: jugezatag - {9c01f80b-34bc-4133-afae-25d860996ce9} - (no file)&lt;br /&gt;O22 - SharedTaskScheduler: mujuzedij - {340a3a5b-8065-416a-a458-183b270359e4} - c:\windows\system32\muyuwole.dll (file missing)&lt;br /&gt;O22 - SharedTaskScheduler: mujuzedij - {7f9b27ac-a4ab-4add-9efa-3a1670773f33} - (no file)&lt;br /&gt;O22 - SharedTaskScheduler: gahurihor - {53c6f5ee-3116-4142-b11b-f9b9b240c588} - (no file)&lt;br /&gt;O22 - SharedTaskScheduler: kupuhivus - {1c1077c5-631c-4601-9694-f889cea65b61} - (no file)&lt;br /&gt;O22 - SharedTaskScheduler: mujuzedij - {9f89261b-99f9-43fc-a860-e37da7106a3f} - c:\windows\system32\muyuwole.dll (file missing)&lt;br /&gt;O22 - SharedTaskScheduler: mujuzedij - {25d0ec28-723f-4ecc-98dd-721a0fbc8fc4} - (no file)&lt;br /&gt;O22 - SharedTaskScheduler: tokatiluy - {9a3fde0a-bb06-4e07-be2c-8875d6d52249} - (no file)&lt;br /&gt;O22 - SharedTaskScheduler: jugezatag - {f6b8b6b5-790e-4e60-aabb-9a3532c13c20} - (no file)&lt;br /&gt;O22 - SharedTaskScheduler: mujuzedij - {e7f7d43d-82e9-4099-9554-9e3b3853982c} - c:\windows\system32\viyogula.dll (file missing)&lt;br /&gt;O22 - SharedTaskScheduler: tokatiluy - {4efa40b8-b7a9-42cc-b7fe-0c46f74f7b8d} - (no file)&lt;br /&gt;O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;O23 - Service: Defender Pro Arrakis Server (Arrakis3) - BitDefender S.R.L. &lt;a href="http://www.bitdefender.com"&gt;http://www.bitdefender.com&lt;/a&gt; - C:\Program Files\Common Files\Defender Pro\Defender Pro Arrakis Server\bin\arrakis3.exe&lt;br /&gt;O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe&lt;br /&gt;O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe&lt;br /&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;O23 - Service: Defender Pro Update Service (LIVESRV) - Defender Pro - C:\Program Files\Common Files\Defender Pro\Defender Pro Update Service\livesrv.exe&lt;br /&gt;O23 - Service: Defender Pro Virus Shield (VSSERV) - Defender Pro - C:\Program Files\Defender Pro\Defender Pro\vsserv.exe&lt;br /&gt;O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE&lt;/p&gt;
&lt;p&gt;--&lt;br /&gt;End of file - 11489 bytes&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Able to run executibles now</title><link>http://en.community.dell.com/forums/thread/19589029.aspx</link><pubDate>Sat, 14 Nov 2009 00:29:39 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19589029</guid><dc:creator>rvep</dc:creator><slash:comments>3</slash:comments><comments>http://en.community.dell.com/forums/thread/19589029.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19589029</wfw:commentRss><description>&lt;p&gt;Computer stayed stable long enough for me to run HiJack Log!!&amp;nbsp; Here it is:&amp;nbsp; Thanks in advance&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 7:00:31 PM, on 11/13/2009&lt;br /&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v8.00 (8.00.6001.18702)&lt;br /&gt;Boot mode: Normal&lt;/p&gt;
&lt;p&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe&lt;br /&gt;C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe&lt;br /&gt;C:\Program Files\Dell Support Center\bin\sprtsvc.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\wanmpsvc.exe&lt;br /&gt;C:\WINDOWS\system32\fxssvc.exe&lt;br /&gt;C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe&lt;br /&gt;C:\WINDOWS\Explorer.exe&lt;br /&gt;C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe&lt;br /&gt;C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe&lt;br /&gt;C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe&lt;br /&gt;C:\Program Files\Dell\Media Experience\PCMService.exe&lt;br /&gt;C:\WINDOWS\system32\dla\tfswctrl.exe&lt;br /&gt;C:\Program Files\Real\RealPlayer\RealPlay.exe&lt;br /&gt;C:\Program Files\QuickTime\qttask.exe&lt;br /&gt;C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe&lt;br /&gt;C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe&lt;br /&gt;C:\Program Files\support.com\bin\tgcmd.exe&lt;br /&gt;C:\Program Files\Common Files\AOL\1137705124\ee\AOLSoftware.exe&lt;br /&gt;C:\Program Files\Common Files\AOL\1137705124\ee\services\safetyCore\ver210_5_2_1\AOLSP Scheduler.exe&lt;br /&gt;C:\WINDOWS\system32\hkcmd.exe&lt;br /&gt;C:\WINDOWS\system32\igfxpers.exe&lt;br /&gt;C:\Program Files\Lexmark 7300 Series\lxcimon.exe&lt;br /&gt;C:\Program Files\Lexmark 7300 Series\ezprint.exe&lt;br /&gt;C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe&lt;br /&gt;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&lt;br /&gt;C:\WINDOWS\Temp\wpv851257179558.exe&lt;br /&gt;C:\Program Files\DellSupport\DSAgnt.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\WINDOWS\sa23sl.exe&lt;br /&gt;C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntispy.exe&lt;br /&gt;C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe&lt;br /&gt;C:\Program Files\WinZip\WZQKPICK.EXE&lt;br /&gt;C:\Documents and Settings\Thomas\restorer32_a.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\Program Files\Common Files\AOL\1137705124\ee\aolsoftware.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\lxcicoms.exe&lt;br /&gt;C:\WINDOWS\system32\wuauclt.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\wscript.exe&lt;br /&gt;C:\HiJackThis\HijackThis.exe&lt;/p&gt;
&lt;p&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://www.dell4me.com/myway"&gt;http://www.dell4me.com/myway&lt;/a&gt;&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://www.comcast.net?cid=110909"&gt;http://www.comcast.net?cid=110909&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &lt;a href="http://as.starware.com/dp/search?x=wKX1ILEOi+Vh7AfA98Gm4Me69ZMbubcDODB5xmjBn4d/ine/frlIJBJPmvCicGf/aV6jQY9U7+CQjgwCMiU0/5X0laAz53arucFnIsq671CobBsoxwqkfWXC6DGrJbSoRSiysD4GrMNZG1/YBHDUUCxsw8RsS8VJXr290T2EOlgjXV4FyasNFMcvQlrKEutDbj+wrd4EYVU"&gt;http://as.starware.com/dp/search?x=wKX1ILEOi+Vh7AfA98Gm4Me69ZMbubcDODB5xmjBn4d/ine/frlIJBJPmvCicGf/aV6jQY9U7+CQjgwCMiU0/5X0laAz53arucFnIsq671CobBsoxwqkfWXC6DGrJbSoRSiysD4GrMNZG1/YBHDUUCxsw8RsS8VJXr290T2EOlgjXV4FyasNFMcvQlrKEutDbj+wrd4EYVU&lt;/a&gt;=&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast&lt;br /&gt;F2 - REG:system.ini: Shell=Explorer.exe rundll32.exe pqrs.tmo printer&lt;br /&gt;O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL (file missing)&lt;br /&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br /&gt;O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)&lt;br /&gt;O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll&lt;br /&gt;O2 - BHO: Comcast Toolbar - {79CEEA4E-C231-4614-9E3B-53B2A02F39B7} - C:\Program Files\comcasttb\comcastdx.dll&lt;br /&gt;O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll&lt;br /&gt;O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)&lt;br /&gt;O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll&lt;br /&gt;O3 - Toolbar: Comcast Toolbar - {79CEEA4E-C231-4614-9E3B-53B2A02F39B7} - C:\Program Files\comcasttb\comcastdx.dll&lt;br /&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe&lt;br /&gt;O4 - HKLM\..\Run: [DVDLauncher] &amp;quot;C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe&lt;br /&gt;O4 - HKLM\..\Run: [PCMService] &amp;quot;C:\Program Files\Dell\Media Experience\PCMService.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe&lt;br /&gt;O4 - HKLM\..\Run: [UpdateManager] &amp;quot;C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe&amp;quot; /r&lt;br /&gt;O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\qttask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe&lt;br /&gt;O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe&lt;br /&gt;O4 - HKLM\..\Run: [tgcmd] &amp;quot;C:\Program Files\support.com\bin\tgcmd.exe&amp;quot; /server&lt;br /&gt;O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1137705124\ee\AOLSoftware.exe&lt;br /&gt;O4 - HKLM\..\Run: [AOLSPScheduler] C:\Program Files\Common Files\AOL\1137705124\ee\services\safetyCore\ver210_5_2_1\AOLSP Scheduler.exe&lt;br /&gt;O4 - HKLM\..\Run: [sscRun] C:\Program Files\Common Files\AOL\1137705124\ee\SSCRun.exe&lt;br /&gt;O4 - HKLM\..\Run: [MPFExe] C:\Program Files\mcafee.com\personal firewall\MPfTray.exe&lt;br /&gt;O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe&lt;br /&gt;O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe&lt;br /&gt;O4 - HKLM\..\Run: [LXCICATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCItime.dll,_RunDLLEntry@16&lt;br /&gt;O4 - HKLM\..\Run: [lxcimon.exe] &amp;quot;C:\Program Files\Lexmark 7300 Series\lxcimon.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [EzPrint] &amp;quot;C:\Program Files\Lexmark 7300 Series\ezprint.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [dscactivate] &amp;quot;C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [ddoctorv2] &amp;quot;C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe&amp;quot; /P ddoctorv2&lt;br /&gt;O4 - HKLM\..\Run: [DellSupportCenter] &amp;quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&amp;quot; /P DellSupportCenter&lt;br /&gt;O4 - HKLM\..\Run: [sysgif32] C:\WINDOWS\Temp\wpv851257179558.exe&lt;br /&gt;O4 - HKLM\..\Run: [09354627] C:\DOCUME~1\ALLUSE~1\APPLIC~1\09354627\09354627.exe&lt;br /&gt;O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe&lt;br /&gt;O4 - HKLM\..\Run: [restorer32_a] C:\WINDOWS\system32\restorer32_a.exe&lt;br /&gt;O4 - HKLM\..\Run: [26946734] C:\DOCUME~1\ALLUSE~1\APPLIC~1\26946734\26946734.exe&lt;br /&gt;O4 - HKCU\..\Run: [DellSupport] &amp;quot;C:\Program Files\DellSupport\DSAgnt.exe&amp;quot; /startup&lt;br /&gt;O4 - HKCU\..\Run: [MSMSGS] &amp;quot;C:\Program Files\Messenger\msmsgs.exe&amp;quot; /background&lt;br /&gt;O4 - HKCU\..\Run: [MoneyAgent] &amp;quot;C:\Program Files\Microsoft Money\System\mnyexpr.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - HKCU\..\Run: [DellSupportCenter] &amp;quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&amp;quot; /P DellSupportCenter&lt;br /&gt;O4 - HKCU\..\Run: [restorer32_a] C:\Documents and Settings\Thomas\restorer32_a.exe&lt;br /&gt;O4 - HKCU\..\Run: [ttool] C:\WINDOWS\sa23sl.exe&lt;br /&gt;O4 - HKCU\..\Run: [RegistryMonitor1] &amp;quot;C:\DOCUME~1\Thomas\LOCALS~1\Temp\649.tmp&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [ComcastAntispyClient] &amp;quot;C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntispy.exe&amp;quot; /hide&lt;br /&gt;O4 - Startup: iidwin32.exe&lt;br /&gt;O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe&lt;br /&gt;O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe&lt;br /&gt;O4 - Global Startup: Microtek Scanner Finder.lnk = C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe&lt;br /&gt;O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE&lt;br /&gt;O8 - Extra context menu item: &amp;amp;AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000&lt;br /&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll&lt;br /&gt;O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll&lt;br /&gt;O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - &lt;a href="http://www.comcast.net/"&gt;http://www.comcast.net/&lt;/a&gt; (file missing)&lt;br /&gt;O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - &lt;a href="http://www.comcastsupport.com/"&gt;http://www.comcastsupport.com/&lt;/a&gt; (file missing)&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - &lt;a href="http://online.comcast.net/help/"&gt;http://online.comcast.net/help/&lt;/a&gt; (file missing)&lt;br /&gt;O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll&lt;br /&gt;O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - &lt;a href="http://wwws.musicmatch.com/mmz/openWebRadio.html"&gt;http://wwws.musicmatch.com/mmz/openWebRadio.html&lt;/a&gt; (file missing)&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - &lt;a href="http://ak.imgfarm.com/images/nocache/funwebproducts/ei/CursorManiaFWBInitialSetup1.0.0.15.cab"&gt;http://ak.imgfarm.com/images/nocache/funwebproducts/ei/CursorManiaFWBInitialSetup1.0.0.15.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {26FCCDF9-A7E1-452A-A73D-7BF7B4D0BA6C} (AOL Pictures Uploader Class) - &lt;a href="http://o.aolcdn.com/pictures/ap/Resources/2.0.8.98/cab/aolpPlugins.10.6.0.6.cab"&gt;http://o.aolcdn.com/pictures/ap/Resources/2.0.8.98/cab/aolpPlugins.10.6.0.6.cab&lt;/a&gt;&lt;br /&gt;O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe&lt;br /&gt;O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe&lt;br /&gt;O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe&lt;br /&gt;O23 - Service: lxci_device -&amp;nbsp;&amp;nbsp; - C:\WINDOWS\system32\lxcicoms.exe&lt;br /&gt;O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\Program Files\mcafee.com\personal firewall\MPFService.exe&lt;br /&gt;O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe&lt;br /&gt;O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe&lt;br /&gt;O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe&lt;br /&gt;O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe&lt;br /&gt;O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe&lt;/p&gt;
&lt;p&gt;--&lt;br /&gt;End of file - 11681 bytes&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>redirected site searches to "your computer is infected with 47 viriuses click here to run scan and fix" my wife hit ok and now i can't get rid of it  please help.</title><link>http://en.community.dell.com/forums/thread/19581098.aspx</link><pubDate>Tue, 03 Nov 2009 01:14:49 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19581098</guid><dc:creator>shotgun8702002</dc:creator><slash:comments>16</slash:comments><comments>http://en.community.dell.com/forums/thread/19581098.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19581098</wfw:commentRss><description>&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 4:37:25 PM, on 11/2/2009&lt;br /&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v8.00 (8.00.6001.18702)&lt;br /&gt;Boot mode: Normal&lt;/p&gt;
&lt;p&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\Program Files\Windows Defender\MsMpEng.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\WINDOWS\vsnp2std.exe&lt;br /&gt;C:\WINDOWS\stsystra.exe&lt;br /&gt;C:\Program Files\McAfee.com\Agent\mcagent.exe&lt;br /&gt;C:\Program Files\Windows Defender\MSASCui.exe&lt;br /&gt;C:\WINDOWS\tsnp2std.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jusched.exe&lt;br /&gt;C:\Program Files\Microsoft IntelliType Pro\itype.exe&lt;br /&gt;C:\Program Files\Microsoft IntelliPoint\ipoint.exe&lt;br /&gt;C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe&lt;br /&gt;C:\WINDOWS\FixCamera.exe&lt;br /&gt;C:\WINDOWS\ehome\ehtray.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe&lt;br /&gt;C:\WINDOWS\eHome\ehRecvr.exe&lt;br /&gt;C:\WINDOWS\eHome\ehSched.exe&lt;br /&gt;C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;C:\Program Files\McAfee\SiteAdvisor\McSACore.exe&lt;br /&gt;C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe&lt;br /&gt;c:\program files\common files\mcafee\mna\mcnasvc.exe&lt;br /&gt;c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe&lt;br /&gt;C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe&lt;br /&gt;C:\Program Files\McAfee\MPF\MPFSrv.exe&lt;br /&gt;C:\Program Files\McAfee\MSK\MskSrver.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\dllhost.exe&lt;br /&gt;C:\WINDOWS\eHome\ehmsas.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe&lt;br /&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/p&gt;
&lt;p&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://www.dell4me.com/myway"&gt;http://www.dell4me.com/myway&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = &lt;a href="http://search.yahoo.com/search?fr=mcafee&amp;amp;p=%s"&gt;http://search.yahoo.com/search?fr=mcafee&amp;amp;p=%s&lt;/a&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Cox High Speed Internet&lt;br /&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;br /&gt;R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll&lt;br /&gt;R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.ae&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.as&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.at&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.az&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.ba&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.be&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.bg&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.bs&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.ca&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.cd&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.com.gh&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.com.hk&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.com.jm&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.com.mx&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.com.my&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.com.na&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.com.nf&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.com.ng&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.ch&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.com.np&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.com.pr&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.com.qa&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.com.sg&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.com.tj&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.com.tw&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.dj&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.de&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.dk&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.dm&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.ee&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.fi&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.fm&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.fr&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.ge&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.gg&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.gm&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.gr&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.ht&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.ie&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.im&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.in&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.it&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.ki&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.la&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.li&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.lv&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.ma&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.ms&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.mu&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.mw&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.nl&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.no&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.nr&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.nu&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.pl&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.pn&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.pt&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.ro&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.ru&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.rw&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.sc&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.se&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.sh&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.si&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.sm&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.sn&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.st&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.tl&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.tm&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.tt&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.us&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.vu&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.ws&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.co.ck&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.co.id&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.co.il&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.co.in&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.co.jp&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.co.kr&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.co.ls&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.co.ma&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.co.nz&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.co.tz&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.co.ug&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.co.uk&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.co.za&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.co.zm&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.com&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.com.af&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.com.ag&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.com.ar&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.com.au&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.com.bn&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.com.br&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.com.by&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.com.bz&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.com.cu&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.com.ec&lt;br /&gt;O1 - Hosts: 64.86.17.56 google.com.fj&lt;br /&gt;O1 - Hosts: 64.86.17.56 &lt;a href="http://www.google.ae"&gt;www.google.ae&lt;/a&gt;&lt;br /&gt;O1 - Hosts: 64.86.17.56 &lt;a href="http://www.google.as"&gt;www.google.as&lt;/a&gt;&lt;br /&gt;O2 - BHO: &amp;amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll&lt;br /&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br /&gt;O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll&lt;br /&gt;O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll&lt;br /&gt;O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll&lt;br /&gt;O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll&lt;br /&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;br /&gt;O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll&lt;br /&gt;O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\YTSingleInstance.dll&lt;br /&gt;O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll&lt;br /&gt;O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll&lt;br /&gt;O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe&lt;br /&gt;O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe&lt;br /&gt;O4 - HKLM\..\Run: [mcagent_exe] &amp;quot;C:\Program Files\McAfee.com\Agent\mcagent.exe&amp;quot; /runkey&lt;br /&gt;O4 - HKLM\..\Run: [Windows Defender] &amp;quot;C:\Program Files\Windows Defender\MSASCui.exe&amp;quot; -hide&lt;br /&gt;O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u&lt;br /&gt;O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe&lt;br /&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] &amp;quot;C:\Program Files\Java\jre6\bin\jusched.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [itype] &amp;quot;C:\Program Files\Microsoft IntelliType Pro\itype.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [ISUSScheduler] &amp;quot;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&amp;quot; -start&lt;br /&gt;O4 - HKLM\..\Run: [IntelliPoint] &amp;quot;C:\Program Files\Microsoft IntelliPoint\ipoint.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe&lt;br /&gt;O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe&lt;br /&gt;O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [ATIPTA] &amp;quot;C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\qttask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKCU\..\Run: [DelayShred] c:\PROGRA~1\mcafee\mshr\ShrCL.EXE /P7 /q c:\DOCUME~1\ours\LOCALS~1\temp\TEMPOR~1\Content.IE5\Y56RQ1GZ.SH! c:\DOCUME~1\ours\LOCALS~1\temp\TEMPOR~1\Content.IE5\U9L27Q5G.SH! c:\DOCUME~1\ours\LOCALS~1\temp\TEMPOR~1\Content.IE5\SHOZ47CB.SH! c:\DOCUME~1\ours\LOCALS~1\temp\TEMPOR~1\Content.IE5\S7SD852L.SH! c:\DOCUME~1\ours\LOCALS~1\temp\TEMPOR~1\Content.IE5\R3LR79KW.SH! c:\DOCUME~1\ours\LOCALS~1\temp\TEMPOR~1\Content.IE5\QNWFG1A9.SH! c:\DOCUME~1\ours\LOCALS~1\temp\TEMPOR~1\Content.IE5\ONT72UVD.SH! c:\DOCUME~1\ours\LOCALS~1\temp\TEMPOR~1\Content.IE5\OB7R6GTX.SH! c:\DOCUME~1\ours\LOCALS~1\temp\TEMPOR~1\Content.IE5\KRM56J6F.SH! c:\DOCUME~1\ours\LOCALS~1\temp\TEMPOR~1\Content.IE5\I5WZAXE5.SH! c:\DOCUME~1\ours\LOCALS~1\temp\TEMPOR~1\Content.IE5\H7QAEBAX.SH! c:\DOCUME~1\ours\LOCALS~1\temp\TEMPOR~1\Content.IE5\GLSX6R8H.SH! c:\DOCUME~1\ours\LOCALS~1\temp\TEMPOR~1\Content.IE5\EDN4XG36.SH! c:\DOCUME~1\ours\LOCALS~1\temp\TEMPOR~1\Content.IE5\9RFR19CI.SH! c:\DOCUME~1\ours\LOCALS~1\temp\TEMPOR~1\Co&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] &amp;quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&amp;quot; -t (User &amp;#39;SYSTEM&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User &amp;#39;SYSTEM&amp;#39;)&lt;br /&gt;O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] &amp;quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&amp;quot; -t (User &amp;#39;Default user&amp;#39;)&lt;br /&gt;O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User &amp;#39;Default user&amp;#39;)&lt;br /&gt;O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll&lt;br /&gt;O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL&lt;br /&gt;O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)&lt;br /&gt;O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll&lt;br /&gt;O15 - Trusted Zone: &lt;a href="http://*.mcafee.com"&gt;http://*.mcafee.com&lt;/a&gt;&lt;br /&gt;O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - &lt;a href="http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab"&gt;http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &lt;a href="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1204990065234"&gt;http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1204990065234&lt;/a&gt;&lt;br /&gt;O16 - DPF: {CB97291A-6603-466A-AA11-80C2EB74CB10} (CoxSelfInstallAx10 Control) - &lt;a href="https://install.cox.net/CoxSelfInstall/CoxSelfInstallAx10.ocx"&gt;https://install.cox.net/CoxSelfInstall/CoxSelfInstallAx10.ocx&lt;/a&gt;&lt;br /&gt;O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &lt;a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab"&gt;http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - &lt;a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab"&gt;http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab&lt;/a&gt;&lt;br /&gt;O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll&lt;br /&gt;O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll&lt;br /&gt;O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe&lt;br /&gt;O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe&lt;br /&gt;O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe&lt;br /&gt;O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe&lt;br /&gt;O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe&lt;br /&gt;O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe&lt;br /&gt;O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe&lt;br /&gt;O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe&lt;br /&gt;O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe&lt;br /&gt;O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe&lt;br /&gt;O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe&lt;br /&gt;O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe&lt;/p&gt;
&lt;p&gt;--&lt;br /&gt;End of file - 14216 bytes&lt;/p&gt;
&lt;p&gt;this is the hijack this file but i don&amp;#39;t know what to do from here not that computer savy.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Advice needed on HijackThis log file.</title><link>http://en.community.dell.com/forums/thread/19589737.aspx</link><pubDate>Sun, 15 Nov 2009 11:19:20 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19589737</guid><dc:creator>Sapphyre</dc:creator><slash:comments>1</slash:comments><comments>http://en.community.dell.com/forums/thread/19589737.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19589737</wfw:commentRss><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;I&amp;nbsp; have a Dell laptop that is possibly infected with malware. I have run endless (it seems) software to no avail and I was advised to run HijackThis and post the logfile to a forum for advice. I&amp;#39;m afraid I don&amp;#39;t understand most of what&amp;#39;s listed in this file, so I hope you can help me out. Could I request replies in layman&amp;#39;s language please, I&amp;#39;m not a &amp;#39;techy&amp;#39;! &lt;img src="http://en.community.dell.com/emoticons/emotion-42.gif" alt="Confused" /&gt;&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 10:04:54, on 15/11/2009&lt;br /&gt;Platform: Windows Vista SP2 (WinNT 6.00.1906)&lt;br /&gt;MSIE: Internet Explorer v8.00 (8.00.6001.18828)&lt;br /&gt;Boot mode: Normal&lt;/p&gt;
&lt;p&gt;Running processes:&lt;br /&gt;C:\Windows\System32\smss.exe&lt;br /&gt;C:\Windows\system32\csrss.exe&lt;br /&gt;C:\Windows\system32\wininit.exe&lt;br /&gt;C:\Windows\system32\csrss.exe&lt;br /&gt;C:\Windows\system32\services.exe&lt;br /&gt;C:\Windows\system32\lsass.exe&lt;br /&gt;C:\Windows\system32\lsm.exe&lt;br /&gt;C:\Windows\system32\winlogon.exe&lt;br /&gt;C:\Windows\system32\svchost.exe&lt;br /&gt;C:\Windows\system32\nvvsvc.exe&lt;br /&gt;C:\Windows\system32\svchost.exe&lt;br /&gt;C:\Windows\System32\svchost.exe&lt;br /&gt;C:\Windows\System32\svchost.exe&lt;br /&gt;C:\Windows\System32\svchost.exe&lt;br /&gt;C:\Windows\system32\svchost.exe&lt;br /&gt;C:\Windows\system32\svchost.exe&lt;br /&gt;C:\Windows\system32\SLsvc.exe&lt;br /&gt;C:\Windows\system32\svchost.exe&lt;br /&gt;C:\Program Files\Dell\DellDock\DockLogin.exe&lt;br /&gt;C:\Windows\system32\rundll32.exe&lt;br /&gt;C:\Windows\system32\svchost.exe&lt;br /&gt;C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe&lt;br /&gt;C:\Windows\system32\WLANExt.exe&lt;br /&gt;C:\Windows\System32\spoolsv.exe&lt;br /&gt;C:\Windows\system32\svchost.exe&lt;br /&gt;C:\Windows\system32\aestsrv.exe&lt;br /&gt;C:\PROGRA~1\Grisoft\AVGFRE~1\avgwdsvc.exe&lt;br /&gt;C:\Windows\system32\svchost.exe&lt;br /&gt;C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe&lt;br /&gt;C:\Windows\system32\CTsvcCDA.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\EvtEng.exe&lt;br /&gt;C:\PROGRA~1\Grisoft\AVGFRE~1\avgrsx.exe&lt;br /&gt;C:\PROGRA~1\Grisoft\AVGFRE~1\avgnsx.exe&lt;br /&gt;C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE&lt;br /&gt;C:\Windows\system32\svchost.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe&lt;br /&gt;C:\Program Files\Spyware Doctor\pctsAuxs.exe&lt;br /&gt;C:\Program Files\Google\Update\1.2.183.13\GoogleCrashHandler.exe&lt;br /&gt;C:\Program Files\Spyware Doctor\pctsSvc.exe&lt;br /&gt;C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe&lt;br /&gt;C:\Windows\system32\STacSV.exe&lt;br /&gt;C:\Windows\System32\svchost.exe&lt;br /&gt;C:\Windows\system32\SearchIndexer.exe&lt;br /&gt;C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe&lt;br /&gt;C:\Program Files\Dell\QuickSet\NicConfigSvc.exe&lt;br /&gt;C:\Windows\system32\wbem\wmiprvse.exe&lt;br /&gt;C:\Windows\system32\taskeng.exe&lt;br /&gt;C:\Program Files\Spybot - Search &amp;amp; Destroy\SDWinSec.exe&lt;br /&gt;C:\Windows\system32\Dwm.exe&lt;br /&gt;C:\Windows\system32\taskeng.exe&lt;br /&gt;C:\Windows\Explorer.EXE&lt;br /&gt;C:\Program Files\Windows Defender\MSASCui.exe&lt;br /&gt;C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;br /&gt;C:\Windows\OEM02Mon.exe&lt;br /&gt;C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe&lt;br /&gt;C:\Program Files\Common Files\Logitech\LCD Manager\LCDMon.exe&lt;br /&gt;C:\Program Files\Dell\MediaDirect\PCMService.exe&lt;br /&gt;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&lt;br /&gt;C:\Windows\System32\rundll32.exe&lt;br /&gt;C:\Windows\System32\rundll32.exe&lt;br /&gt;C:\Program Files\Grisoft\AVG Free\avgtray.exe&lt;br /&gt;C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe&lt;br /&gt;C:\Program Files\Spyware Doctor\pctsTray.exe&lt;br /&gt;C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDClock.exe&lt;br /&gt;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;br /&gt;C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDMedia.exe&lt;br /&gt;C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDPOP3.exe&lt;br /&gt;C:\Program Files\Spybot - Search &amp;amp; Destroy\TeaTimer.exe&lt;br /&gt;C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe&lt;br /&gt;C:\Program Files\Dell\QuickSet\quickset.exe&lt;br /&gt;c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe&lt;br /&gt;C:\Windows\system32\wbem\unsecapp.exe&lt;br /&gt;C:\Program Files\Synaptics\SynTP\SynTPHelper.exe&lt;br /&gt;C:\Games\CurseClient\CurseClient.exe&lt;br /&gt;C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe&lt;br /&gt;C:\Program Files\Dell Support Center\bin\sprtsvc.exe&lt;br /&gt;C:\Program Files\Windows Media Player\wmpnetwk.exe&lt;br /&gt;C:\Windows\servicing\TrustedInstaller.exe&lt;br /&gt;C:\Program Files\Utils\Trend Micro\HijackThis\HijackThis.exe&lt;br /&gt;C:\Windows\system32\wbem\wmiprvse.exe&lt;/p&gt;
&lt;p&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://g.uk.msn.com/USCON/2"&gt;http://g.uk.msn.com/USCON/2&lt;/a&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://www.google.co.uk/"&gt;http://www.google.co.uk/&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = &lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = &lt;br /&gt;R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)&lt;br /&gt;O1 - Hosts: ::1 localhost&lt;br /&gt;O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll&lt;br /&gt;O2 - BHO: Spybot-S&amp;amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br /&gt;O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)&lt;br /&gt;O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll&lt;br /&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll&lt;br /&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;br /&gt;O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\Grisoft\AVG Free\Toolbar\IEToolbar.dll&lt;br /&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll&lt;br /&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll&lt;br /&gt;O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll&lt;br /&gt;O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll&lt;br /&gt;O3 - Toolbar: &amp;amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll&lt;br /&gt;O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\Grisoft\AVG Free\Toolbar\IEToolbar.dll&lt;br /&gt;O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll&lt;br /&gt;O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide&lt;br /&gt;O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;br /&gt;O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe&lt;br /&gt;O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE&lt;br /&gt;O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe&lt;br /&gt;O4 - HKLM\..\Run: [Launch LCDMon] &amp;quot;C:\Program Files\Common Files\Logitech\LCD Manager\LCDMon.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [PCMService] &amp;quot;C:\Program Files\Dell\MediaDirect\PCMService.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [dellsupportcenter] &amp;quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&amp;quot; /P dellsupportcenter&lt;br /&gt;O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup&lt;br /&gt;O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit&lt;br /&gt;O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start&lt;br /&gt;O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] &amp;quot;C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE&lt;br /&gt;O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\Grisoft\AVGFRE~1\avgtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &amp;quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe&lt;br /&gt;O4 - HKLM\..\Run: [ISTray] &amp;quot;C:\Program Files\Spyware Doctor\pctsTray.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [CurseClient] C:\Games\CurseClient\CurseClient.exe -silent&lt;br /&gt;O4 - HKCU\..\Run: [swg] &amp;quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp;amp; Destroy\TeaTimer.exe&lt;br /&gt;O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User &amp;#39;LOCAL SERVICE&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User &amp;#39;LOCAL SERVICE&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User &amp;#39;NETWORK SERVICE&amp;#39;)&lt;br /&gt;O4 - Global Startup: Bluetooth.lnk = ?&lt;br /&gt;O4 - Global Startup: Logitech SetPoint.lnk = ?&lt;br /&gt;O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\Apps\Office\OFFICE11\EXCEL.EXE/3000&lt;br /&gt;O8 - Extra context menu item: Send image to &amp;amp;Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm&lt;br /&gt;O8 - Extra context menu item: Send page to &amp;amp;Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm&lt;br /&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll&lt;br /&gt;O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: &amp;amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll&lt;br /&gt;O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Apps\Office\OFFICE11\REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm&lt;br /&gt;O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Spybot - Search &amp;amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br /&gt;O13 - Gopher Prefix: &lt;br /&gt;O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - &lt;a href="http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab"&gt;http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab&lt;/a&gt;&lt;br /&gt;O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL&lt;br /&gt;O20 - AppInit_DLLs: avgrsstx.dll&lt;br /&gt;O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll&lt;br /&gt;O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe&lt;br /&gt;O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgwdsvc.exe&lt;br /&gt;O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe&lt;br /&gt;O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\Windows\system32\CTsvcCDA.exe&lt;br /&gt;O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe&lt;br /&gt;O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe&lt;br /&gt;O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe&lt;br /&gt;O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe&lt;br /&gt;O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;br /&gt;O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe&lt;br /&gt;O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe&lt;br /&gt;O23 - Service: Dell Internal Network Card Power Management (nicconfigsvc) - Dell Inc. - C:\Program Files\Dell\QuickSet\NicConfigSvc.exe&lt;br /&gt;O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe&lt;br /&gt;O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe&lt;br /&gt;O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search &amp;amp; Destroy\SDWinSec.exe&lt;br /&gt;O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe&lt;br /&gt;O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe&lt;br /&gt;O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe&lt;br /&gt;O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe&lt;br /&gt;O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe&lt;/p&gt;
&lt;p&gt;--&lt;br /&gt;End of file - 13876 bytes&lt;/p&gt;
&lt;p&gt;Huge thanks in advance to anyone who can help me with this.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Many webpages will not download on my laptop. Please analize this and help me.</title><link>http://en.community.dell.com/forums/thread/19589652.aspx</link><pubDate>Sun, 15 Nov 2009 03:30:40 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19589652</guid><dc:creator>happygirl9909</dc:creator><slash:comments>1</slash:comments><comments>http://en.community.dell.com/forums/thread/19589652.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19589652</wfw:commentRss><description>&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 10:28:30 PM, on 11/14/2009&lt;br /&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v8.00 (8.00.6001.18702)&lt;br /&gt;Boot mode: Normal&lt;/p&gt;
&lt;p&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\WLTRYSVC.EXE&lt;br /&gt;C:\WINDOWS\System32\bcmwltry.exe&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br /&gt;C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe&lt;br /&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\Program Files\Common Files\Motive\McciCMService.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\nvsvc32.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe&lt;br /&gt;C:\PROGRA~1\AVG\AVG8\avgrsx.exe&lt;br /&gt;C:\PROGRA~1\AVG\AVG8\avgnsx.exe&lt;br /&gt;C:\Program Files\Dell Support Center\bin\sprtsvc.exe&lt;br /&gt;c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\PROGRA~1\AVG\AVG8\avgemc.exe&lt;br /&gt;C:\Program Files\AVG\AVG8\avgcsrvx.exe&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;br /&gt;C:\WINDOWS\system32\rundll32.exe&lt;br /&gt;C:\WINDOWS\system32\RUNDLL32.EXE&lt;br /&gt;C:\WINDOWS\OEM02Mon.exe&lt;br /&gt;C:\WINDOWS\system32\WLTRAY.exe&lt;br /&gt;C:\WINDOWS\stsystra.exe&lt;br /&gt;C:\WINDOWS\system32\KADxMain.exe&lt;br /&gt;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&lt;br /&gt;C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe&lt;br /&gt;C:\Program Files\Dell\MediaDirect\PCMService.exe&lt;br /&gt;C:\Program Files\Dell AIO 810\dlcgmon.exe&lt;br /&gt;C:\Program Files\BellSouthWCC\McciTrayApp.exe&lt;br /&gt;C:\Program Files\HP\HP Software Update\HPWuSchd2.exe&lt;br /&gt;C:\Program Files\HP\hpcoretech\hpcmpmgr.exe&lt;br /&gt;C:\WINDOWS\system32\hphmon06.exe&lt;br /&gt;C:\PROGRA~1\AVG\AVG8\avgtray.exe&lt;br /&gt;C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe&lt;br /&gt;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&lt;br /&gt;C:\Program Files\DellSupport\DSAgnt.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;br /&gt;C:\WINDOWS\system32\dlcgcoms.exe&lt;br /&gt;C:\Program Files\Spybot - Search &amp;amp; Destroy\TeaTimer.exe&lt;br /&gt;C:\Program Files\Digital Line Detect\DLG.exe&lt;br /&gt;C:\Program Files\HP\digital imaging\bin\hpqtra08.exe&lt;br /&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;C:\WINDOWS\system32\dllhost.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;c:\program files\aim toolbar\aimtbServer.exe&lt;br /&gt;C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\WINDOWS\system32\wuauclt.exe&lt;br /&gt;C:\HijackThis.exe&lt;/p&gt;
&lt;p&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://www.google.com/ig/dell?hl=en&amp;amp;client=dell-usuk&amp;amp;channel=us&amp;amp;ibd=2071024"&gt;www.google.com/ig/dell?hl=en&amp;amp;client=dell-usuk&amp;amp;channel=us&amp;amp;ibd=2071024&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = &lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = &lt;a href="http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com"&gt;http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com&lt;/a&gt;&lt;br /&gt;R3 - URLSearchHook: AIM Toolbar Search Class - {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll&lt;br /&gt;R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll&lt;br /&gt;O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)&lt;br /&gt;O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll&lt;br /&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br /&gt;O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll&lt;br /&gt;O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll&lt;br /&gt;O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll&lt;br /&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll&lt;br /&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll&lt;br /&gt;O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll&lt;br /&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll&lt;br /&gt;O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll&lt;br /&gt;O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll&lt;br /&gt;O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll&lt;br /&gt;O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll&lt;br /&gt;O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll&lt;br /&gt;O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll&lt;br /&gt;O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll&lt;br /&gt;O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll&lt;br /&gt;O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;br /&gt;O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup&lt;br /&gt;O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet&lt;br /&gt;O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start&lt;br /&gt;O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit&lt;br /&gt;O4 - HKLM\..\Run: [OEM02Mon.exe] C:\WINDOWS\OEM02Mon.exe&lt;br /&gt;O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe&lt;br /&gt;O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe&lt;br /&gt;O4 - HKLM\..\Run: [KADxMain] C:\WINDOWS\system32\KADxMain.exe&lt;br /&gt;O4 - HKLM\..\Run: [ISUSScheduler] &amp;quot;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&amp;quot; -start&lt;br /&gt;O4 - HKLM\..\Run: [RoxWatchTray] &amp;quot;C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [RoxioDragToDisc] &amp;quot;C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [PCMService] &amp;quot;C:\Program Files\Dell\MediaDirect\PCMService.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [dscactivate] &amp;quot;C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Google Desktop Search] &amp;quot;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&amp;quot; /startup&lt;br /&gt;O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe&lt;br /&gt;O4 - HKLM\..\Run: [dlcgmon.exe] &amp;quot;C:\Program Files\Dell AIO 810\dlcgmon.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [BellSouthWCC_McciTrayApp] C:\Program Files\BellSouthWCC\McciTrayApp.exe&lt;br /&gt;O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe&lt;br /&gt;O4 - HKLM\..\Run: [HPHUPD06] C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe&lt;br /&gt;O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe&lt;br /&gt;O4 - HKLM\..\Run: [HP Component Manager] &amp;quot;C:\Program Files\HP\hpcoretech\hpcmpmgr.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe&lt;br /&gt;O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [AdobeCS4ServiceManager] &amp;quot;C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe&amp;quot; -launchedbylogin&lt;br /&gt;O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] &amp;quot;C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Acrobat Assistant 8.0] &amp;quot;C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe&lt;br /&gt;O4 - HKLM\..\Run: [DLCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCGtime.dll,_RunDLLEntry@16&lt;br /&gt;O4 - HKLM\..\Run: [16050464] C:\Documents and Settings\All Users\Application Data\16050464\16050464.exe&lt;br /&gt;O4 - HKLM\..\Run: [DellSupportCenter] &amp;quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&amp;quot; /P DellSupportCenter&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\QTTask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup&lt;br /&gt;O4 - HKLM\..\Run: [iTunesHelper] &amp;quot;C:\Program Files\iTunes\iTunesHelper.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Adobe ARM] &amp;quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\RunOnce: [DeleteDir[CD8] Fast Browser Search Firefox] cmd.exe /C RD /S /Q C:\PROGRA~1\FBSEAR~1&lt;br /&gt;O4 - HKCU\..\Run: [DellSupport] &amp;quot;C:\Program Files\DellSupport\DSAgnt.exe&amp;quot; /startup&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - HKCU\..\Run: [swg] &amp;quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [DW6] &amp;quot;C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [DellSupportCenter] &amp;quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&amp;quot; /P DellSupportCenter&lt;br /&gt;O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp;amp; Destroy\TeaTimer.exe&lt;br /&gt;O4 - HKCU\..\Run: [DWQueuedReporting] &amp;quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&amp;quot; -t&lt;br /&gt;O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] &amp;quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&amp;quot; -t (User &amp;#39;SYSTEM&amp;#39;)&lt;br /&gt;O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] &amp;quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&amp;quot; -t (User &amp;#39;Default user&amp;#39;)&lt;br /&gt;O4 - Global Startup: CreateRP.VBS&lt;br /&gt;O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe&lt;br /&gt;O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\digital imaging\bin\hpqtra08.exe&lt;br /&gt;O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html&lt;br /&gt;O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html&lt;br /&gt;O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html&lt;br /&gt;O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000&lt;br /&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll&lt;br /&gt;O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O15 - Trusted Zone: &lt;a href="http://www.facebook.com"&gt;www.facebook.com&lt;/a&gt;&lt;br /&gt;O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - &lt;a href="http://support.dell.com/systemprofiler/SysPro.CAB"&gt;http://support.dell.com/systemprofiler/SysPro.CAB&lt;/a&gt;&lt;br /&gt;O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll&lt;br /&gt;O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - &lt;a href="https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab"&gt;https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &lt;a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1248200075796"&gt;http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1248200075796&lt;/a&gt;&lt;br /&gt;O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - &lt;a href="http://www.sibelius.com/download/software/win/ActiveXPlugin.cab"&gt;http://www.sibelius.com/download/software/win/ActiveXPlugin.cab&lt;/a&gt;&lt;br /&gt;O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll&lt;br /&gt;O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll&lt;br /&gt;O21 - SSODL: Urlimobj - {8737EFDB-5BA3-4EF4-B890-87D447364CA1} - C:\WINDOWS\system32\zapolkbd.dll&lt;br /&gt;O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe&lt;br /&gt;O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br /&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;O23 - Service: dlcg_device -&amp;nbsp;&amp;nbsp; - C:\WINDOWS\system32\dlcgcoms.exe&lt;br /&gt;O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe&lt;br /&gt;O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe&lt;br /&gt;O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&lt;br /&gt;O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;br /&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe&lt;br /&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe&lt;br /&gt;O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe&lt;br /&gt;O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe&lt;br /&gt;O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe&lt;br /&gt;O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe&lt;br /&gt;O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe&lt;br /&gt;O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE&lt;/p&gt;
&lt;p&gt;--&lt;br /&gt;End of file - 15625 bytes&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Sometimes Google searches are being redirected to r3953724.cn</title><link>http://en.community.dell.com/forums/thread/19587206.aspx</link><pubDate>Wed, 11 Nov 2009 18:16:59 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19587206</guid><dc:creator>r bruns</dc:creator><slash:comments>5</slash:comments><comments>http://en.community.dell.com/forums/thread/19587206.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19587206</wfw:commentRss><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;When&amp;nbsp;I do a google search&amp;nbsp; using IE, when I click on the results the page will be redirected to r3953724.cn.&amp;nbsp;&amp;nbsp; I&amp;#39;ve tried Malwarebytes, SpywareDoctor, and&amp;nbsp;ComboFix&amp;nbsp;and it ddoesn&amp;#39;t solve the issue.&lt;/p&gt;
&lt;p&gt;I&amp;#39;m the owner of the computer. I have no cracked software on the computer and I have not posted on any other forums. Also I did trend micro hijackthis scan and below is my log file.&lt;/p&gt;
&lt;p&gt;Thanks&lt;/p&gt;
&lt;p&gt;Ron&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 12:07:52 PM, on 11/11/2009&lt;br /&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16915)&lt;br /&gt;Boot mode: Normal&lt;/p&gt;
&lt;p&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\csrss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\WLTRYSVC.EXE&lt;br /&gt;C:\WINDOWS\System32\bcmwltry.exe&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;C:\WINDOWS\System32\SCardSvr.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe&lt;br /&gt;C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe&lt;br /&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe&lt;br /&gt;D:\Program Files\Cisco Systems\VPN Client\cvpnd.exe&lt;br /&gt;C:\Program Files\McAfee\Managed VirusScan\VScan\EngineServer.exe&lt;br /&gt;C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe&lt;br /&gt;C:\Program Files\McAfee\MPF\MPFSrv.exe&lt;br /&gt;C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe&lt;br /&gt;C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe&lt;br /&gt;C:\WINDOWS\system32\nvsvc32.exe&lt;br /&gt;C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe&lt;br /&gt;C:\Program Files\Spyware Doctor\pctsAuxs.exe&lt;br /&gt;C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe&lt;br /&gt;C:\Program Files\Spyware Doctor\pctsTray.exe&lt;br /&gt;C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe&lt;br /&gt;C:\WINDOWS\system32\StacSV.exe&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe&lt;br /&gt;C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe&lt;br /&gt;C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe&lt;br /&gt;C:\Program Files\Apoint\Apoint.exe&lt;br /&gt;C:\WINDOWS\system32\vmnat.exe&lt;br /&gt;C:\WINDOWS\system32\rundll32.exe&lt;br /&gt;C:\WINDOWS\system32\RunDLL32.exe&lt;br /&gt;C:\WINDOWS\system32\WLTRAY.exe&lt;br /&gt;C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe&lt;br /&gt;C:\Program Files\Wave Systems Corp\SecureUpgrade.exe&lt;br /&gt;C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe&lt;br /&gt;C:\WINDOWS\system32\KADxMain.exe&lt;br /&gt;C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe&lt;br /&gt;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&lt;br /&gt;C:\Program Files\Apoint\ApMsgFwd.exe&lt;br /&gt;C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe&lt;br /&gt;D:\Program Files\VMware\VMware Workstation\vmware-tray.exe&lt;br /&gt;C:\Program Files\Apoint\HidFind.exe&lt;br /&gt;D:\Program Files\VMware\VMware Workstation\hqtray.exe&lt;br /&gt;D:\Program Files\iTunes\iTunesHelper.exe&lt;br /&gt;C:\Program Files\Picasa2\PicasaMediaDetector.exe&lt;br /&gt;C:\Program Files\Netgear Update Assistant\LanUpdate.exe&lt;br /&gt;D:\Program Files\APAgent.exe&lt;br /&gt;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;br /&gt;C:\Program Files\MSN Messenger\MsnMsgr.Exe&lt;br /&gt;C:\Program Files\Roxio\Drag-to-Disc\Drgtodsc.exe&lt;br /&gt;C:\WINDOWS\system32\dllhost.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe&lt;br /&gt;C:\Program Files\CMS Peripherals\BounceBack Express\BBLauncher.exe&lt;br /&gt;C:\Program Files\Digital Line Detect\DLG.exe&lt;br /&gt;C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtTry.exe&lt;br /&gt;C:\Program Files\Apoint\Apntex.exe&lt;br /&gt;D:\Program Files\VMware\VMware Workstation\vmware-authd.exe&lt;br /&gt;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&lt;br /&gt;C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe&lt;br /&gt;C:\WINDOWS\system32\wbem\wmiprvse.exe&lt;br /&gt;C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe&lt;br /&gt;C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe&lt;br /&gt;C:\WINDOWS\system32\vmnetdhcp.exe&lt;br /&gt;C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe&lt;br /&gt;C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe&lt;br /&gt;C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe&lt;br /&gt;C:\WINDOWS\system32\wuauclt.exe&lt;br /&gt;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe&lt;br /&gt;C:\WINDOWS\system32\dllhost.exe&lt;br /&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;C:\WINDOWS\System32\alg.exe&lt;br /&gt;C:\WINDOWS\system32\msdtc.exe&lt;br /&gt;C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE&lt;br /&gt;C:\WINDOWS\system32\wbem\wmiprvse.exe&lt;br /&gt;C:\Program Files\McAfee\Managed VirusScan\VScan\McShield.exe&lt;br /&gt;C:\Program Files\Spyware Doctor\pctsSvc.exe&lt;br /&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;br /&gt;D:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/p&gt;
&lt;p&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://www.startribune.com/"&gt;http://www.startribune.com/&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&amp;amp;client=dell-usuk&amp;amp;channel=us-smb&amp;amp;ibd=5080806&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &lt;a href="http://partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&amp;amp;client=dell-usuk&amp;amp;channel=us-smb&amp;amp;ibd=5080806"&gt;http://partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&amp;amp;client=dell-usuk&amp;amp;channel=us-smb&amp;amp;ibd=5080806&lt;/a&gt;&lt;br /&gt;R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll&lt;br /&gt;O2 - BHO: &amp;amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll&lt;br /&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br /&gt;O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll&lt;br /&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br /&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll&lt;br /&gt;O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll&lt;br /&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll&lt;br /&gt;O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll&lt;br /&gt;O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll&lt;br /&gt;O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll&lt;br /&gt;O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll&lt;br /&gt;O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll&lt;br /&gt;O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe&lt;br /&gt;O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup&lt;br /&gt;O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet&lt;br /&gt;O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start&lt;br /&gt;O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit&lt;br /&gt;O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe&lt;br /&gt;O4 - HKLM\..\Run: [WavXMgr] C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe&lt;br /&gt;O4 - HKLM\..\Run: [SecureUpgrade] C:\Program Files\Wave Systems Corp\SecureUpgrade.exe&lt;br /&gt;O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe&lt;br /&gt;O4 - HKLM\..\Run: [KADxMain] C:\WINDOWS\system32\KADxMain.exe&lt;br /&gt;O4 - HKLM\..\Run: [Acrobat Assistant 8.0] &amp;quot;C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Acrobat Speed Launch] &amp;quot;C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrobat_sl.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Google Desktop Search] &amp;quot;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&amp;quot; /startup&lt;br /&gt;O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe&lt;br /&gt;O4 - HKLM\..\Run: [MVS Splash] C:\Program Files\McAfee\Managed VirusScan\Agent\Splash.exe&lt;br /&gt;O4 - HKLM\..\Run: [McAfee Managed Services Tray] &amp;quot;C:\Program Files\McAfee\Managed VirusScan\Agent\StartMyagtTry.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [PDVDDXSrv] &amp;quot;C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [vmware-tray] D:\Program Files\VMware\VMware Workstation\vmware-tray.exe&lt;br /&gt;O4 - HKLM\..\Run: [VMware hqtray] &amp;quot;D:\Program Files\VMware\VMware Workstation\hqtray.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\qttask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKLM\..\Run: [iTunesHelper] &amp;quot;D:\Program Files\iTunes\iTunesHelper.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Acrobat Synchronizer] &amp;quot;C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe&lt;br /&gt;O4 - HKLM\..\Run: [LanUpdate] &amp;quot;C:\Program Files\Netgear Update Assistant\LanUpdate.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Windows Defender] &amp;quot;C:\Program Files\Windows Defender\MSASCui.exe&amp;quot; -hide&lt;br /&gt;O4 - HKLM\..\Run: [AirPort Base Station Agent] &amp;quot;D:\Program Files\APAgent.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [ISTray] &amp;quot;C:\Program Files\Spyware Doctor\pctsTray.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &amp;quot;C:\Program Files\Malwarebytes&amp;#39; Anti-Malware\mbam.exe&amp;quot; /runcleanupscript&lt;br /&gt;O4 - HKCU\..\Run: [swg] &amp;quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [MsnMsgr] &amp;quot;C:\Program Files\MSN Messenger\MsnMsgr.Exe&amp;quot; /background&lt;br /&gt;O4 - HKCU\..\Run: [RoxioDragToDisc] C:\Program Files\Roxio\Drag-to-Disc\Drgtodsc.exe&lt;br /&gt;O4 - HKCU\..\Run: [Messenger (Yahoo!)] &amp;quot;C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe&amp;quot; -quiet&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] &amp;quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&amp;quot; -t (User &amp;#39;SYSTEM&amp;#39;)&lt;br /&gt;O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] &amp;quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&amp;quot; -t (User &amp;#39;Default user&amp;#39;)&lt;br /&gt;O4 - Global Startup: Bluetooth Manager.lnk = ?&lt;br /&gt;O4 - Global Startup: BounceBack Launcher.lnk = ?&lt;br /&gt;O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe&lt;br /&gt;O4 - Global Startup: VPN Client.lnk = ?&lt;br /&gt;O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html&lt;br /&gt;O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html&lt;br /&gt;O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html&lt;br /&gt;O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html&lt;br /&gt;O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html&lt;br /&gt;O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html&lt;br /&gt;O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html&lt;br /&gt;O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000&lt;br /&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O15 - Trusted Zone: &lt;a href="http://*.mcafee.com"&gt;http://*.mcafee.com&lt;/a&gt; (HKLM)&lt;br /&gt;O15 - Trusted Zone: &lt;a href="http://betavscan.mcafeeasap.com"&gt;http://betavscan.mcafeeasap.com&lt;/a&gt; (HKLM)&lt;br /&gt;O15 - Trusted Zone: &lt;a href="http://vs.mcafeeasap.com"&gt;http://vs.mcafeeasap.com&lt;/a&gt; (HKLM)&lt;br /&gt;O15 - Trusted Zone: &lt;a href="http://www.mcafeeasap.com"&gt;http://www.mcafeeasap.com&lt;/a&gt; (HKLM)&lt;br /&gt;O15 - ESC Trusted Zone: &lt;a href="http://*.mcafee.com"&gt;http://*.mcafee.com&lt;/a&gt; (HKLM)&lt;br /&gt;O15 - ESC Trusted Zone: &lt;a href="http://betavscan.mcafeeasap.com"&gt;http://betavscan.mcafeeasap.com&lt;/a&gt; (HKLM)&lt;br /&gt;O15 - ESC Trusted Zone: &lt;a href="http://vs.mcafeeasap.com"&gt;http://vs.mcafeeasap.com&lt;/a&gt; (HKLM)&lt;br /&gt;O15 - ESC Trusted Zone: &lt;a href="http://www.mcafeeasap.com"&gt;http://www.mcafeeasap.com&lt;/a&gt; (HKLM)&lt;br /&gt;O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - &lt;a href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab"&gt;http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - &lt;a href="http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab"&gt;http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - &lt;a href="http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab"&gt;http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - &lt;a href="https://highjumpsoftware.webex.com/client/T26L/support/ieatgpc.cab"&gt;https://highjumpsoftware.webex.com/client/T26L/support/ieatgpc.cab&lt;/a&gt;&lt;br /&gt;O20 - Winlogon Notify: gemsafe - C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll&lt;br /&gt;O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll&lt;br /&gt;O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;O23 - Service: Broadcom ASF IP and SMBIOS Mailbox Monitor (ASFIPmon) - Broadcom Corporation - C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe&lt;br /&gt;O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe&lt;br /&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;O23 - Service: Browser Defender Update Service - Threat Expert Ltd. - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe&lt;br /&gt;O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - D:\Program Files\Cisco Systems\VPN Client\cvpnd.exe&lt;br /&gt;O23 - Service: EngineServer - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\VScan\EngineServer.exe&lt;br /&gt;O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe&lt;br /&gt;O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&lt;br /&gt;O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe&lt;br /&gt;O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;br /&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe&lt;br /&gt;O23 - Service: McShield - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\VScan\McShield.exe&lt;br /&gt;O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe&lt;br /&gt;O23 - Service: McAfee Virus and Spyware Protection Service (myAgtSvc) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe&lt;br /&gt;O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe&lt;br /&gt;O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe&lt;br /&gt;O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - PC Tools - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe&lt;br /&gt;O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe&lt;br /&gt;O23 - Service: PC Tools Security Service (sdcoreservice) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe&lt;br /&gt;O23 - Service: SecureStorageService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe&lt;br /&gt;O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\StacSV.exe&lt;br /&gt;O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe&lt;br /&gt;O23 - Service: NTRU TSS v1.2.1.25 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe&lt;br /&gt;O23 - Service: TdmService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe&lt;br /&gt;O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - D:\Program Files\VMware\VMware Workstation\vmware-ufad.exe&lt;br /&gt;O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - D:\Program Files\VMware\VMware Workstation\vmware-authd.exe&lt;br /&gt;O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe&lt;br /&gt;O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe&lt;br /&gt;O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe&lt;br /&gt;O23 - Service: WaveEnrollmentService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Authentication Manager\WaveEnrollmentService.exe&lt;br /&gt;O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE&lt;/p&gt;
&lt;p&gt;--&lt;br /&gt;End of file - 18387 bytes&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Laptop unable to access internet, hijack, malware.</title><link>http://en.community.dell.com/forums/thread/19589040.aspx</link><pubDate>Sat, 14 Nov 2009 00:47:28 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19589040</guid><dc:creator>Sherry1961</dc:creator><slash:comments>5</slash:comments><comments>http://en.community.dell.com/forums/thread/19589040.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19589040</wfw:commentRss><description>&lt;p&gt;Having issues with my laptop.&amp;nbsp; Cannot access internet.&amp;nbsp; Cannot access hijack this for log to post with this message.&amp;nbsp; Also cannot access malware to check for problems there.&amp;nbsp; Any help is greatly appreciated.&lt;/p&gt;
&lt;p&gt;Thanks&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Live OneCare Backups after OneCare expires.</title><link>http://en.community.dell.com/forums/thread/19589426.aspx</link><pubDate>Sat, 14 Nov 2009 19:36:28 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19589426</guid><dc:creator>paindoc</dc:creator><slash:comments>3</slash:comments><comments>http://en.community.dell.com/forums/thread/19589426.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19589426</wfw:commentRss><description>&lt;p&gt;When OneCare expires you can download and install a tool to recover bacups.&amp;nbsp; Look for Windows Live OneCare backup restore.exe.&amp;nbsp; It is an 81 MB program and will not load onto this page so you will have to look for it on your own,.&amp;nbsp; Try this site: &lt;a href="http://help.msn.com/(bWt0PWVuLVVTJnByb2plY3Q9YTF2MQ==)/Help.aspx?market=en-US&amp;amp;project=a1v1&amp;amp;querytype=topic&amp;amp;query=PROC_restore_file_manually.htm"&gt;&lt;strong&gt;Windows&lt;/strong&gt; &lt;strong&gt;Live&lt;/strong&gt; &lt;strong&gt;OneCare&lt;/strong&gt; Help&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Restore&lt;/strong&gt; files on a computer without &lt;strong&gt;Windows&lt;/strong&gt; &lt;strong&gt;Live&lt;/strong&gt; &lt;strong&gt;OneCare&lt;/strong&gt; installed ... If your &lt;strong&gt;backup&lt;/strong&gt; collection contains more than one disc, search the ...&lt;/p&gt;
&lt;ul class="sb_meta"&gt;
&lt;li&gt;help.msn.com/(bWt0PWVuLVVTJnByb2plY3Q9YTF2MQ==)/Help.aspx?market=en-US&amp;amp;project=a1v1&amp;amp;query... &lt;/li&gt;
&lt;li&gt;&amp;nbsp;&amp;middot; &lt;a href="http://cc.bingj.com/cache.aspx?q=windows+live+onecare+backup+restore&amp;amp;d=4526079530304376&amp;amp;mkt=en-US&amp;amp;setlang=en-US&amp;amp;w=4063e023,88c172f5"&gt;Cached page&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Reposted on Virus and software discussions.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Network problems - possible malware</title><link>http://en.community.dell.com/forums/thread/19589805.aspx</link><pubDate>Sun, 15 Nov 2009 14:57:52 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19589805</guid><dc:creator>BillBeckie</dc:creator><slash:comments>0</slash:comments><comments>http://en.community.dell.com/forums/thread/19589805.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19589805</wfw:commentRss><description>&lt;p&gt;Over the past two weeks I&amp;#39;ve had increasing problems with my Dell and internet connectivity. When I do file transfers, they would for some reason become very slow even though nothing else was going on. Sometimes several would stop at once. When viewing web pages, picture links are no longer loading and I&amp;#39;m seeing empty boxes instead. When opening the browser for the first time I&amp;#39;ve received a message I&amp;#39;m not connected to the internet. I&amp;#39;ve had to click the link to diagnose network problems to get it to work.&lt;/p&gt;
&lt;p&gt;Two nights ago the connection remained very slow even after shutting down and restarting several times. Powering the modem to reset the connection didn&amp;#39;t make a difference. However, when I pulled the network cable out of the modem and replugged it in (while leaving the modem powered on) the problem cleared up. However I&amp;#39;m now again having issues.&lt;/p&gt;
&lt;p&gt;I don&amp;#39;t think it&amp;#39;s the modem because I don&amp;#39;t have similar issues if I plug my laptop into it. Further, I&amp;#39;m having other issues. I noticed yesterday my Windows Firewall was turned off and I don&amp;#39;t remember doing that. I thought of going to System Restore to set my computer back to a couple of weeks ago but found I no longer have any restore points before yesterday.&lt;/p&gt;
&lt;p&gt;I do Windows Update every week. The only things I don&amp;#39;t have installed are IE8 and one dot net upgrade (the dot net upgrade fails when I try to do it, I&amp;#39;ve been deliberately holding off on IE8). I keep my McAfee up to date and nothing showed on my last scan. My SUPERAntiSpyware is only picking up the Adware Cookies it always does.&lt;/p&gt;
&lt;p&gt;Last month I just renewed my two year warranty but I&amp;#39;d prefer to solve this issue on my own. Can any suggestions be offered? I&amp;#39;ll conclude my pasting my HiJackThis log file below.&lt;/p&gt;
&lt;p&gt;Thank you,&lt;/p&gt;
&lt;p&gt;Bill B.&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 9:35:32 AM, on 11/15/2009&lt;br /&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16915)&lt;br /&gt;Boot mode: Normal&lt;/p&gt;
&lt;p&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\WINDOWS\ehome\ehtray.exe&lt;br /&gt;C:\WINDOWS\system32\nvraidservice.exe&lt;br /&gt;C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE&lt;br /&gt;C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe&lt;br /&gt;C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe&lt;br /&gt;C:\WINDOWS\system32\CTHELPER.EXE&lt;br /&gt;C:\WINDOWS\system32\CTXFIHLP.EXE&lt;br /&gt;C:\WINDOWS\SYSTEM32\CTXFISPI.EXE&lt;br /&gt;C:\Program Files\SiteAdvisor\6253\SiteAdv.exe&lt;br /&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;C:\Program Files\McAfee.com\Agent\mcagent.exe&lt;br /&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;C:\WINDOWS\system32\CTsvcCDA.exe&lt;br /&gt;C:\Program Files\HP\HP Software Update\HPWuSchd2.exe&lt;br /&gt;C:\Program Files\Juniper Networks\Common Files\dsNcService.exe&lt;br /&gt;C:\WINDOWS\eHome\ehRecvr.exe&lt;br /&gt;C:\WINDOWS\eHome\ehSched.exe&lt;br /&gt;C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe&lt;br /&gt;C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe&lt;br /&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;br /&gt;c:\program files\common files\mcafee\mna\mcnasvc.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe&lt;br /&gt;C:\Program Files\DAEMON Tools Lite\daemon.exe&lt;br /&gt;C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe&lt;br /&gt;C:\Program Files\McAfee\MPF\MPFSrv.exe&lt;br /&gt;C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe&lt;br /&gt;C:\Program Files\McAfee\MSK\MskSrver.exe&lt;br /&gt;C:\Program Files\Microsoft ActiveSync\wcescomm.exe&lt;br /&gt;C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe&lt;br /&gt;C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe&lt;br /&gt;C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe&lt;br /&gt;C:\WINDOWS\system32\nvsvc32.exe&lt;br /&gt;C:\WINDOWS\system32\HPZipm12.exe&lt;br /&gt;C:\PROGRA~1\RETROS~1\RETROS~1.1\retrorun.exe&lt;br /&gt;C:\PROGRA~1\MI3AA1~1\rapimgr.exe&lt;br /&gt;C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe&lt;br /&gt;C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe&lt;br /&gt;C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe&lt;br /&gt;C:\Program Files\Windows Desktop Search\WindowsSearch.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\Program Files\UPSMON\UPSMON_Service.Exe&lt;br /&gt;C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe&lt;br /&gt;C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe&lt;br /&gt;C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe&lt;br /&gt;C:\WINDOWS\eHome\ehmsas.exe&lt;br /&gt;C:\WINDOWS\system32\SearchIndexer.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\Program Files\Canon\CAL\CALMAIN.exe&lt;br /&gt;C:\WINDOWS\system32\dllhost.exe&lt;br /&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;C:\WINDOWS\system32\wbem\unsecapp.exe&lt;br /&gt;C:\WINDOWS\system32\wuauclt.exe&lt;br /&gt;C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe&lt;br /&gt;C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;br /&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\WINDOWS\system32\Notepad.exe&lt;br /&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;br /&gt;C:\WINDOWS\system32\SearchProtocolHost.exe&lt;/p&gt;
&lt;p&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;br /&gt;O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)&lt;br /&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br /&gt;O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll&lt;br /&gt;O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll&lt;br /&gt;O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll&lt;br /&gt;O2 - BHO: NetXfer - {83B80A9C-D91A-4F22-8DCF-EA7204039F79} - C:\Program Files\Xi\NetXfer\NXIEHelper.dll&lt;br /&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;br /&gt;O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll&lt;br /&gt;O3 - Toolbar: NetXfer - {C16CBAAC-A75C-4DB5-A0DD-CDF5CAFCDD3A} - C:\Program Files\Xi\NetXfer\NXToolBar.dll&lt;br /&gt;O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe&lt;br /&gt;O4 - HKLM\..\Run: [NvCplDaemon] &amp;quot;RUNDLL32.EXE&amp;quot; C:\WINDOWS\system32\NvCpl.dll,NvStartup&lt;br /&gt;O4 - HKLM\..\Run: [CTDVDDET] &amp;quot;C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [VolPanel] &amp;quot;C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe&amp;quot; /r&lt;br /&gt;O4 - HKLM\..\Run: [AudioDrvEmulator] &amp;quot;C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe&amp;quot; -1 AudioDrvEmulator &amp;quot;C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE&lt;br /&gt;O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE&lt;br /&gt;O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE&lt;br /&gt;O4 - HKLM\..\Run: [nwiz] &amp;quot;nwiz.exe&amp;quot; /installquiet /keeploaded /nodetect&lt;br /&gt;O4 - HKLM\..\Run: [MWLExe] &amp;quot;C:\Program Files\Mcafee\MWL\MWLGuiSt.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [SiteAdvisor] &amp;quot;C:\Program Files\SiteAdvisor\6253\SiteAdv.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [McENUI] &amp;quot;C:\PROGRA~1\McAfee\MHN\McENUI.exe&amp;quot; /hide&lt;br /&gt;O4 - HKLM\..\Run: [mcagent_exe] &amp;quot;C:\Program Files\McAfee.com\Agent\mcagent.exe&amp;quot; /runkey&lt;br /&gt;O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe&lt;br /&gt;O4 - HKLM\..\Run: [UPSMON] &amp;quot;C:\Program Files\UPSMON\UPSMON.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe&lt;br /&gt;O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k&lt;br /&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &amp;quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe /boot&lt;br /&gt;O4 - HKLM\..\Run: [Nikon Transfer Monitor] C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\qttask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKLM\..\Run: [iTunesHelper] &amp;quot;C:\Program Files\iTunes\iTunesHelper.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Adobe ARM] &amp;quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - HKCU\..\Run: [DAEMON Tools Lite] &amp;quot;C:\Program Files\DAEMON Tools Lite\daemon.exe&amp;quot; -autorun&lt;br /&gt;O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;br /&gt;O4 - HKCU\..\Run: [FreeRAM XP] &amp;quot;C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe&amp;quot; -win&lt;br /&gt;O4 - HKCU\..\Run: [H/PC Connection Agent] &amp;quot;C:\Program Files\Microsoft ActiveSync\wcescomm.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [MSMSGS] &amp;quot;C:\Program Files\Messenger\msmsgs.exe&amp;quot; /background&lt;br /&gt;O4 - Startup: PowerReg Scheduler.exe&lt;br /&gt;O4 - Global Startup: Device Detector 3.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe&lt;br /&gt;O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe&lt;br /&gt;O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe&lt;br /&gt;O4 - Global Startup: WDDMStatus.lnk = C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe&lt;br /&gt;O4 - Global Startup: WDSmartWare.lnk = C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe&lt;br /&gt;O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe&lt;br /&gt;O8 - Extra context menu item: Download all by NetXfer - C:\Program Files\Xi\NetXfer\NXAddList.html&lt;br /&gt;O8 - Extra context menu item: Download All Files by HiDownload - C:\Program Files\StreamingStar\HiDownload\HDGetAll.htm&lt;br /&gt;O8 - Extra context menu item: Download by HiDownload - C:\Program Files\StreamingStar\HiDownload\HDGet.htm&lt;br /&gt;O8 - Extra context menu item: Download by NetXfer - C:\Program Files\Xi\NetXfer\NXAddLink.html&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000&lt;br /&gt;O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: S&amp;amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll&lt;br /&gt;O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll&lt;br /&gt;O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra button: HiDownload - {F4FBA929-A891-492C-A0F6-5C79CC4F1742} - C:\Program Files\StreamingStar\HiDownload\hidownload.exe (HKCU)&lt;br /&gt;O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - &lt;a href="http://support.dell.com/systemprofiler/SysPro.CAB"&gt;http://support.dell.com/systemprofiler/SysPro.CAB&lt;/a&gt;&lt;br /&gt;O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - &lt;a href="http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB"&gt;http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB&lt;/a&gt;&lt;br /&gt;O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - &lt;a href="http://simcity.ea.com/update/EARTPX.cab"&gt;http://simcity.ea.com/update/EARTPX.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &lt;a href="http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1187263421349"&gt;http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1187263421349&lt;/a&gt;&lt;br /&gt;O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - &lt;a href="http://www.crucial.com/controls/cpcScanner.cab"&gt;http://www.crucial.com/controls/cpcScanner.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - &lt;a href="http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab"&gt;http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - &lt;a href="http://www.adobe.com/products/acrobat/nos/gp.cab"&gt;http://www.adobe.com/products/acrobat/nos/gp.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - &lt;a href="https://secureaccess.pinellascounty.org/dana-cached/setup/JuniperSetupSP1.cab"&gt;https://secureaccess.pinellascounty.org/dana-cached/setup/JuniperSetupSP1.cab&lt;/a&gt;&lt;br /&gt;O17 - HKLM\System\CCS\Services\Tcpip\..\{C310F635-DA1B-4BDE-BAAA-D7D3B869CA51}: NameServer = 65.32.1.65,65.32.1.70&lt;br /&gt;O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL&lt;br /&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL&lt;br /&gt;O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe&lt;br /&gt;O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe&lt;br /&gt;O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe&lt;br /&gt;O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&lt;br /&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe&lt;br /&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe&lt;br /&gt;O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe&lt;br /&gt;O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe&lt;br /&gt;O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe&lt;br /&gt;O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe&lt;br /&gt;O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe&lt;br /&gt;O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe&lt;br /&gt;O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe&lt;br /&gt;O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe&lt;br /&gt;O23 - Service: McAfee Wireless Network Security Service (MWLSvc) - McAfee, Inc. - C:\Program Files\Mcafee\MWL\MwlSvc.exe&lt;br /&gt;O23 - Service: MaxSyncService (NTService1) -&amp;nbsp;&amp;nbsp; - C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe&lt;br /&gt;O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe&lt;br /&gt;O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe&lt;br /&gt;O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - EMC Dantz - C:\PROGRA~1\RETROS~1\RETROS~1.1\retrorun.exe&lt;br /&gt;O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe&lt;br /&gt;O23 - Service: UPSMONService - Unknown owner - C:\Program Files\UPSMON\UPSMON_Service.Exe&lt;br /&gt;O23 - Service: WD SmartWare Drive Manager (WDDMService) - WDC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe&lt;br /&gt;O23 - Service: WD SmartWare Background Service (WDSmartWareBackgroundService) - Memeo - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe&lt;/p&gt;
&lt;p&gt;--&lt;br /&gt;End of file - 14494 bytes&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>system slow, unable to access programs</title><link>http://en.community.dell.com/forums/thread/19589607.aspx</link><pubDate>Sun, 15 Nov 2009 01:21:10 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19589607</guid><dc:creator>colonelh</dc:creator><slash:comments>0</slash:comments><comments>http://en.community.dell.com/forums/thread/19589607.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19589607</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I have been experiencing intermittent sluggishness on my system. I have done some maintenance but still having different types of problems.&lt;/p&gt;
&lt;p&gt;My ESET scans are clean. Also at other time programs will not start from desktop. Once when I booted up my desk top icons didn&amp;#39;t even come up.&lt;/p&gt;
&lt;p&gt;Here is my system and a log. I would appreciate it greatly if you could take a look and see what something is going on.&lt;/p&gt;
&lt;p&gt;Dell Dimension B110 (DEO51)&lt;br /&gt;Celeron D 2.53 GHz, pkg FC-PGA2&lt;br /&gt;533 MB bus&lt;br /&gt;256x2 RAM&lt;br /&gt;Internal intel 82865G Graphics controller, 96.0 MB&lt;br /&gt;Windows XP SP2 Home&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 19:43:10, on 11/14/2009&lt;br /&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16915)&lt;br /&gt;Boot mode: Normal&lt;br /&gt;&lt;br /&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;C:\Program Files\Common Files\Motive\McciCMService.exe&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\Program Files\RegCure\RegCure.exe&lt;br /&gt;C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe&lt;br /&gt;C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\taskmgr.exe&lt;br /&gt;C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe&lt;br /&gt;C:\WINDOWS\system32\wuauclt.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\WINDOWS\system32\igfxpers.exe&lt;br /&gt;C:\Program Files\Analog Devices\Core\smax4pnp.exe&lt;br /&gt;C:\Program Files\Micro Innovations\Wireless Laser Mouse\moffice.exe&lt;br /&gt;C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe&lt;br /&gt;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&lt;br /&gt;C:\Program Files\Micro Innovations\Wireless Laser Mouse\MOUSE32A.DAT&lt;br /&gt;C:\Program Files\Verizon\McciTrayApp.exe&lt;br /&gt;C:\Program Files\PeoplePC\ISP7000\Browser\Bartshel.exe&lt;br /&gt;C:\Program Files\Verizon\VSP\VerizonServicepoint.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jusched.exe&lt;br /&gt;C:\WINDOWS\system32\hkcmd.exe&lt;br /&gt;C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe&lt;br /&gt;C:\PROGRA~1\PeoplePC\ISP7000\Browser\PPShared.exe&lt;br /&gt;C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe&lt;br /&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;br /&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.peoplepc.com/search&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.verizon.yahoo.com/&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://home.peoplepc.com/search&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;br /&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080&lt;br /&gt;R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)&lt;br /&gt;O2 - BHO: EarthLink BHO Guard - {00000000-0000-0000-0000-000000000002} - C:\Program Files\PeoplePC\Toolbar\ScamGrd.dll&lt;br /&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br /&gt;O2 - BHO: Gamevance - {0ED403E8-470A-4a8a-85A4-D7688CFE39A3} - (no file)&lt;br /&gt;O2 - BHO: EarthLink ScamBlocker V3 - {15F4D456-5BAA-4076-8486-EECB38CD3E57} - C:\Program Files\PeoplePC\Toolbar\ScamGrd.dll&lt;br /&gt;O2 - BHO: Accelerator Plugin - {656EC4B7-072B-4698-B504-2A414C1F0037} - C:\PROGRA~1\PEOPLE~1\PRPL_I~1.DLL&lt;br /&gt;O2 - BHO: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar_6.2.0.12.dll&lt;br /&gt;O2 - BHO: NitroPDFBHO Class - {CF070CB8-F02F-4af4-A7B7-8D45CAD4BB54} - C:\Program Files\Nitro PDF\PDF Download\NitroPDF.dll&lt;br /&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;br /&gt;O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll&lt;br /&gt;O3 - Toolbar: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar_6.2.0.12.dll&lt;br /&gt;O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe&lt;br /&gt;O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe&lt;br /&gt;O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Wireless Laser Mouse\moffice.exe&lt;br /&gt;O4 - HKLM\..\Run: [egui] &amp;quot;C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe&amp;quot; /hide /waitservice&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\qttask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &amp;quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Bart Station] C:\Program Files\PeoplePC\ISP7000\BIN\PPCOLink.exe -STATION&lt;br /&gt;O4 - HKLM\..\Run: [Verizon_McciTrayApp] &amp;quot;C:\Program Files\Verizon\McciTrayApp.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [VerizonServicepoint.exe] &amp;quot;C:\Program Files\Verizon\VSP\VerizonServicepoint.exe&amp;quot; /AUTORUN&lt;br /&gt;O4 - HKLM\..\Run: [DLCFCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCFtime.dll,_RunDLLEntry@16&lt;br /&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] &amp;quot;C:\Program Files\Java\jre6\bin\jusched.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - HKCU\..\Run: [Messenger (Yahoo!)] &amp;quot;C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe&amp;quot; -quiet&lt;br /&gt;O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\Shockwave 11\SwHelper_1150600.exe -Update -1150600 -&amp;quot;Mozilla/5.0_(Windows;_U;_Windows_NT_5.1;_en-US;_rv:1.9.1.3)_Gecko/20090824_Firefox/3.5.3_(.NET_CLR_3.5.30729)&amp;quot; -&amp;quot;http://carnegiesciencecenter.org/Requin/vRequin/welcomeninstruct.htm&amp;quot;&lt;br /&gt;O4 - Startup: wkcalrem.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000&lt;br /&gt;O8 - Extra context menu item: Save Page As PDF ... - file://C:\Program Files\Nitro PDF\PDF Download\nitroweb.htm&lt;br /&gt;O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: S&amp;amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: (no name) - {AD9E6088-E00B-42f9-9F0C-8480525D234E} - C:\Program Files\Nitro PDF\PDF Download\NitroPDF.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: PDF Download - Options - {AD9E6088-E00B-42f9-9F0C-8480525D234E} - C:\Program Files\Nitro PDF\PDF Download\NitroPDF.dll&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll&lt;br /&gt;O9 - Extra button: PDF Download - {F1C0FD6C-A6A0-49a7-A932-71A56461867F} - C:\Program Files\Nitro PDF\PDF Download\NitroPDF.dll (HKCU)&lt;br /&gt;O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon/download/DSL/Verizon%20High%20Speed%20Internet%20Installer.cab&lt;br /&gt;O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB&lt;br /&gt;O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab_srl.cab&lt;br /&gt;O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll&lt;br /&gt;O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab&lt;br /&gt;O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll&lt;br /&gt;O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\508\G2AWinLogon.dll&lt;br /&gt;O23 - Service: dlcf_device -&amp;nbsp;&amp;nbsp; - C:\WINDOWS\system32\dlcfcoms.exe&lt;br /&gt;O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe&lt;br /&gt;O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe&lt;br /&gt;O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\508\g2aservice.exe&lt;br /&gt;O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe&lt;br /&gt;O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe&lt;br /&gt;O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;End of file - 8689 bytes&lt;/p&gt;
&lt;p&gt;Thanks in advance,&lt;/p&gt;
&lt;p&gt; I hope we can come up with a resolution.&lt;/p&gt;
&lt;p&gt;COL&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Computer has serious virus</title><link>http://en.community.dell.com/forums/thread/19588755.aspx</link><pubDate>Fri, 13 Nov 2009 18:07:20 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19588755</guid><dc:creator>Zach1</dc:creator><slash:comments>4</slash:comments><comments>http://en.community.dell.com/forums/thread/19588755.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19588755</wfw:commentRss><description>&lt;p&gt;New to forum.&amp;nbsp; My computer won&amp;#39;t let me do anything.&amp;nbsp; When I turn it on.&amp;nbsp; A security tool pop ups that I never installed and tells me I have 40 threats.&amp;nbsp; I can&amp;#39;t install any progams...it tells me they are infected with a worm.&amp;nbsp; something called lsas...something.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;I don&amp;#39;t know where to begin.&amp;nbsp; I see you have help several people fix their computers and hopefully you can help me.&amp;nbsp; I don&amp;#39;t even know where to begin.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Thanks in advanced.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Need help posted a message 24 hours ago</title><link>http://en.community.dell.com/forums/thread/19588344.aspx</link><pubDate>Fri, 13 Nov 2009 01:24:37 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19588344</guid><dc:creator>rvep</dc:creator><slash:comments>4</slash:comments><comments>http://en.community.dell.com/forums/thread/19588344.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19588344</wfw:commentRss><description>&lt;p&gt;Is there any reason why my question is not being answered.&amp;nbsp; I am a dell customer like the rest of the forum which are getting their questions answered.&amp;nbsp; I am not able to run the hijack on my computer because I can&amp;#39;t run any executable files.&amp;nbsp; Maybe safemode my work.&amp;nbsp;&amp;nbsp; I just need instructions.&amp;nbsp; I have a virus that is taking over my computer please help get me started on fixing my computer.&amp;nbsp; Thank you.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Looking to remove _ex-08.exe</title><link>http://en.community.dell.com/forums/thread/19559348.aspx</link><pubDate>Mon, 28 Sep 2009 09:02:52 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19559348</guid><dc:creator>Ian1986</dc:creator><slash:comments>2</slash:comments><comments>http://en.community.dell.com/forums/thread/19559348.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19559348</wfw:commentRss><description>&lt;p&gt;My laptop has slowed down considerably over the past few weeks and I noticed the&amp;#39; _ex-08.exe&amp;#39; trojan was running. I was just wondering if anything else on my HijackThis log should be fixed - I&amp;#39;m a bit of a novice with this kind of thing - so any help greatly appreciated.&lt;/p&gt;
&lt;p&gt;Log attached below. Thanks.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 09:32:56, on 28/09/2009&lt;br /&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16876)&lt;br /&gt;Boot mode: Normal&lt;br /&gt;&lt;br /&gt;Running processes:&lt;br /&gt;C:\WINDOWS\system32\csrss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\WLTRYSVC.EXE&lt;br /&gt;C:\WINDOWS\System32\bcmwltry.exe&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe&lt;br /&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;C:\Program Files\AskBarDis\bar\bin\AskService.exe&lt;br /&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;C:\Program Files\FolderSize\FolderSizeSvc.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;C:\Program Files\McAfee\MSK\MskSrver.exe&lt;br /&gt;C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\wbem\wmiprvse.exe&lt;br /&gt;C:\WINDOWS\System32\alg.exe&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\WINDOWS\system32\hkcmd.exe&lt;br /&gt;C:\WINDOWS\system32\igfxpers.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jusched.exe&lt;br /&gt;C:\WINDOWS\stsystra.exe&lt;br /&gt;C:\WINDOWS\system32\WLTRAY.exe&lt;br /&gt;C:\WINDOWS\system32\igfxsrvc.exe&lt;br /&gt;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&lt;br /&gt;C:\Program Files\Common Files\AOL\1154639557\ee\AOLSoftware.exe&lt;br /&gt;C:\Program Files\Lexmark 2400 Series\lxcrmon.exe&lt;br /&gt;C:\Program Files\Lexmark 2400 Series\ezprint.exe&lt;br /&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;br /&gt;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&lt;br /&gt;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&lt;br /&gt;C:\WINDOWS\Temp\_ex-08.exe&lt;br /&gt;C:\WINDOWS\Temp\wpv481253309382.exe&lt;br /&gt;C:\WINDOWS\system32\lxcrcoms.exe&lt;br /&gt;C:\Program Files\DellSupport\DSAgnt.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;br /&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe&lt;br /&gt;c:\program files\common files\aol\1154639557\ee\services\antiSpywareApp\ver2_0_12\AOLSP Scheduler.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\Program Files\Vuze\Azureus.exe&lt;br /&gt;C:\Program Files\Mozilla Firefox\firefox.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jucheck.exe&lt;br /&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;br /&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.co.uk/ig/dell?hl=en&amp;amp;client=dell-usuk&amp;amp;channel=uk&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.guardian.co.uk/&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.co.uk/ig/dell?hl=en&amp;amp;client=dell-usuk&amp;amp;channel=uk&lt;br /&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;br /&gt;F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,&lt;br /&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br /&gt;O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll&lt;br /&gt;O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll&lt;br /&gt;O2 - BHO: McAfee Phishing Filter - {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\PROGRA~1\mcafee\msk\mskapbho.dll&lt;br /&gt;O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll&lt;br /&gt;O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll&lt;br /&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll&lt;br /&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll&lt;br /&gt;O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll&lt;br /&gt;O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll&lt;br /&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;br /&gt;O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll&lt;br /&gt;O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll&lt;br /&gt;O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll&lt;br /&gt;O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll&lt;br /&gt;O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe&lt;br /&gt;O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe&lt;br /&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] &amp;quot;C:\Program Files\Java\jre6\bin\jusched.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe&lt;br /&gt;O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe&lt;br /&gt;O4 - HKLM\..\Run: [ISUSPM Startup] &amp;quot;C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe&amp;quot; -startup&lt;br /&gt;O4 - HKLM\..\Run: [ISUSScheduler] &amp;quot;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&amp;quot; -start&lt;br /&gt;O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall&lt;br /&gt;O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1154639557\ee\AOLSoftware.exe&lt;br /&gt;O4 - HKLM\..\Run: [lxcrmon.exe] &amp;quot;C:\Program Files\Lexmark 2400 Series\lxcrmon.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [EzPrint] &amp;quot;C:\Program Files\Lexmark 2400 Series\ezprint.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16&lt;br /&gt;O4 - HKLM\..\Run: [iTunesHelper] &amp;quot;C:\Program Files\iTunes\iTunesHelper.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &amp;quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\QTTask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKLM\..\Run: [TkBellExe] &amp;quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&amp;quot;&amp;nbsp; -osboot&lt;br /&gt;O4 - HKLM\..\Run: [PromoReg] C:\WINDOWS\Temp\_ex-08.exe&lt;br /&gt;O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide&lt;br /&gt;O4 - HKLM\..\Run: [sysgif32] C:\WINDOWS\Temp\wpv481253309382.exe&lt;br /&gt;O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe&lt;br /&gt;O4 - HKCU\..\Run: [DellSupport] &amp;quot;C:\Program Files\DellSupport\DSAgnt.exe&amp;quot; /startup&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - HKCU\..\Run: [DellTransferAgent] &amp;quot;C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;br /&gt;O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe&lt;br /&gt;O4 - HKCU\..\Run: [Skype] &amp;quot;C:\Program Files\Skype\Phone\Skype.exe&amp;quot; /nosplash /minimized&lt;br /&gt;O4 - HKCU\..\Run: [MSMSGS] &amp;quot;C:\Program Files\Messenger\msmsgs.exe&amp;quot; /background&lt;br /&gt;O4 - HKCU\..\Run: [McAfee Update] C:\DOCUME~1\CID\LOCALS~1\Temp\mcupdate_1253957655.exe /insfin C:\DOCUME~1\CID\LOCALS~1\Temp\mcupdate_1253957655.ini &lt;br /&gt;O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User &amp;#39;Default user&amp;#39;)&lt;br /&gt;O4 - Startup: ikowin32.exe&lt;br /&gt;O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe&lt;br /&gt;O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab&lt;br /&gt;O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab&lt;br /&gt;O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1158354811656&lt;br /&gt;O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll&lt;br /&gt;O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe&lt;br /&gt;O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe&lt;br /&gt;O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\&lt;br /&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe&lt;br /&gt;O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe&lt;br /&gt;O23 - Service: Google Update Service (gupdate1c9c68cfcdb429e) (gupdate1c9c68cfcdb429e) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe&lt;br /&gt;O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;br /&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;O23 - Service: lxcr_device -&amp;nbsp;&amp;nbsp; - C:\WINDOWS\system32\lxcrcoms.exe&lt;br /&gt;O23 - Service: MBackMonitor (mbackmonitor) - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe&lt;br /&gt;O23 - Service: McAfee Proxy Service (mcproxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe&lt;br /&gt;O23 - Service: McAfee Anti-Spam Service (msk80service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe&lt;br /&gt;O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe&lt;br /&gt;O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE&lt;br /&gt;O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;End of file - 11372 bytes&lt;br /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Advertising Pop up</title><link>http://en.community.dell.com/forums/thread/19585162.aspx</link><pubDate>Sun, 08 Nov 2009 23:04:27 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19585162</guid><dc:creator>ilselu1</dc:creator><slash:comments>16</slash:comments><comments>http://en.community.dell.com/forums/thread/19585162.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19585162</wfw:commentRss><description>&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 2:45:00 PM, on 11/8/2009&lt;br /&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16915)&lt;br /&gt;Boot mode: Normal&lt;br /&gt;&lt;br /&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe&lt;br /&gt;C:\Program Files\Alwil Software\Avast4\ashServ.exe&lt;br /&gt;C:\WINDOWS\system32\LEXBCES.EXE&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;C:\WINDOWS\system32\LEXPPS.EXE&lt;br /&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;C:\Program Files\Dell Support Center\bin\sprtsvc.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe&lt;br /&gt;C:\Program Files\Alwil Software\Avast4\ashWebSv.exe&lt;br /&gt;C:\Program Files\AlienGUIse\wbload.exe&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\Program Files\Analog Devices\Core\smax4pnp.exe&lt;br /&gt;C:\WINDOWS\system32\hkcmd.exe&lt;br /&gt;C:\WINDOWS\system32\igfxpers.exe&lt;br /&gt;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&lt;br /&gt;C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe&lt;br /&gt;C:\Program Files\QuickTime\qttask.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE&lt;br /&gt;C:\Program Files\ChromeData\AutoBook\AUS.exe&lt;br /&gt;C:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe&lt;br /&gt;C:\Program Files\Mozilla Firefox\firefox.exe&lt;br /&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;br /&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.autopartners.net/apps/gcportal/login.html&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br /&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;br /&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br /&gt;O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll&lt;br /&gt;O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll&lt;br /&gt;O2 - BHO: {08665c92-0c15-5c0b-fc94-ab8c1d09690a} - {a09690d1-c8ba-49cf-b0c5-51c029c56680} - (no file)&lt;br /&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;br /&gt;O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll&lt;br /&gt;O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)&lt;br /&gt;O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe&lt;br /&gt;O4 - HKLM\..\Run: [UpdateManager] &amp;quot;C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe&amp;quot; /r&lt;br /&gt;O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe&lt;br /&gt;O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe&lt;br /&gt;O4 - HKLM\..\Run: [dscactivate] &amp;quot;C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [DellSupportCenter] &amp;quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&amp;quot; /P DellSupportCenter&lt;br /&gt;O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\qttask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKLM\..\Run: [tozutiror] Rundll32.exe &amp;quot;c:\windows\system32\gitoribo.dll&amp;quot;,a&lt;br /&gt;O4 - HKLM\..\RunOnce: [Spybot - Search &amp;amp; Destroy] &amp;quot;C:\Program Files\Spybot - Search &amp;amp; Destroy\SpybotSD.exe&amp;quot; /autocheck&lt;br /&gt;O4 - HKLM\..\RunOnce: [SpybotDeletingA333] command.com /c del &amp;quot;c:\windows\system32\mubakopu.dll_old&amp;quot;&lt;br /&gt;O4 - HKLM\..\RunOnce: [SpybotDeletingC9512] cmd.exe /c del &amp;quot;c:\windows\system32\mubakopu.dll_old&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - HKCU\..\Run: [H/PC Connection Agent] &amp;quot;C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE&amp;quot;&lt;br /&gt;O4 - Startup: Alienware Dock.lnk = C:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe&lt;br /&gt;O4 - Global Startup: Adobe Gamma Loader.lnk = ?&lt;br /&gt;O4 - Global Startup: Auto Update System.lnk = C:\Program Files\ChromeData\AutoBook\AUS.exe&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000&lt;br /&gt;O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll&lt;br /&gt;O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll&lt;br /&gt;O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\GCAMBR01\Start Menu\Programs\&amp;gt;IMVU\Run IMVU.lnk (file missing)&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O15 - Trusted IP range: 10.3.175.101&lt;br /&gt;O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204&lt;br /&gt;O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab&lt;br /&gt;O17 - HKLM\System\CCS\Services\Tcpip\..\{7942B379-5AB9-4710-AAE0-CE6323BA75E6}: NameServer = 10.3.175.195&lt;br /&gt;O17 - HKLM\System\CS1\Services\Tcpip\..\{7942B379-5AB9-4710-AAE0-CE6323BA75E6}: NameServer = 10.3.175.195&lt;br /&gt;O17 - HKLM\System\CS2\Services\Tcpip\..\{7942B379-5AB9-4710-AAE0-CE6323BA75E6}: NameServer = 10.3.175.195&lt;br /&gt;O20 - AppInit_DLLs: wbsys.dll zurayaju.dll c:\windows\system32\ c:\windows\system32\mubakopu.dll c:\windows\system32\gitoribo.dll&lt;br /&gt;O21 - SSODL: yoyusunuh - {d9e49172-4fe8-424b-b1e2-dda7167452b4} - c:\windows\system32\gitoribo.dll&lt;br /&gt;O22 - SharedTaskScheduler: jugezatag - {d9e49172-4fe8-424b-b1e2-dda7167452b4} - c:\windows\system32\gitoribo.dll&lt;br /&gt;O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe&lt;br /&gt;O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe&lt;br /&gt;O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe&lt;br /&gt;O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe&lt;br /&gt;O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe&lt;br /&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe&lt;br /&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe&lt;br /&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE&lt;br /&gt;O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe&lt;br /&gt;O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe&lt;br /&gt;O24 - Desktop Component 1: digg labs / arc - http://labs.digg.com/arc/&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;End of file - 8670 bytes&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>desktop screen showing "28 infections found" </title><link>http://en.community.dell.com/forums/thread/19586968.aspx</link><pubDate>Wed, 11 Nov 2009 13:19:35 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19586968</guid><dc:creator>holloway70</dc:creator><slash:comments>3</slash:comments><comments>http://en.community.dell.com/forums/thread/19586968.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19586968</wfw:commentRss><description>&lt;p&gt;hai &lt;/p&gt;
&lt;p&gt;today my desktop got this spy ware/mal ware&lt;/p&gt;
&lt;p&gt;my wallpaper is replaced with a message showing 28 infections found&lt;/p&gt;
&lt;p&gt;can somebody help me&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 12:42:39, on 11/11/2009&lt;br /&gt;Platform: Windows Vista SP2 (WinNT 6.00.1906)&lt;br /&gt;MSIE: Internet Explorer v8.00 (8.00.6001.18828)&lt;br /&gt;Boot mode: Normal&lt;/p&gt;
&lt;p&gt;Running processes:&lt;br /&gt;C:\Windows\system32\Dwm.exe&lt;br /&gt;C:\Program Files\Dell\DellDock\DellDock.exe&lt;br /&gt;C:\Windows\Explorer.EXE&lt;br /&gt;C:\Windows\system32\taskeng.exe&lt;br /&gt;C:\Windows\RtHDVCpl.exe&lt;br /&gt;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&lt;br /&gt;C:\Program Files\MultiScreen\MultiScreen.exe&lt;br /&gt;C:\Windows\System32\wpcumi.exe&lt;br /&gt;C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe&lt;br /&gt;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&lt;br /&gt;C:\Program Files\Symantec AntiVirus\VPTray.exe&lt;br /&gt;C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe&lt;br /&gt;C:\Program Files\Roxio Creator 2009\5.0\CPMonitor.exe&lt;br /&gt;C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe&lt;br /&gt;C:\Program Files\CyberLink\Shared files\brs.exe&lt;br /&gt;C:\Windows\WindowsMobile\wmdSync.exe&lt;br /&gt;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&lt;br /&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;br /&gt;C:\Program Files\Dell V505\dldwmon.exe&lt;br /&gt;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&lt;br /&gt;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;br /&gt;C:\Program Files\uTorrent\uTorrent.exe&lt;br /&gt;C:\Program Files\Windows Media Player\wmpnscfg.exe&lt;br /&gt;C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe&lt;br /&gt;C:\Program Files\Dell V505\dldwMsdMon.exe&lt;br /&gt;C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe&lt;br /&gt;C:\Windows\system32\wbem\unsecapp.exe&lt;br /&gt;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&lt;br /&gt;C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe&lt;br /&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;br /&gt;C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe&lt;br /&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Windows Media Player\wmplayer.exe&lt;br /&gt;c:\windows\system32\rundll32.exe&lt;br /&gt;C:\Users\meghu\AppData\Local\Temp\aremncwsox.exe&lt;br /&gt;C:\Users\meghu\AppData\Local\Temp\50549.exe&lt;br /&gt;C:\Windows\system32\rundll32.exe&lt;br /&gt;C:\PROGRA~2\88169840\88169840.exe&lt;br /&gt;C:\ProgramData\Defence\smss.exe&lt;br /&gt;C:\Windows\system32\mshta.exe&lt;br /&gt;C:\Program Files\Symantec AntiVirus\SavUI.exe&lt;br /&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;br /&gt;c:\windows\system32\rundll32.exe&lt;br /&gt;C:\Windows\System32\mobsync.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Users\meghu\AppData\Local\Temp\Temporary Internet Files\Content.IE5\6DDVJTNN\HijackThis[1].exe&lt;/p&gt;
&lt;p&gt;O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe&lt;br /&gt;O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe&lt;br /&gt;O23 - Service: Roxio UPnP Renderer 11 - Sonic Solutions - C:\Program Files\Roxio Creator 2009\Digital Home 11\RoxioUPnPRenderer11.exe&lt;br /&gt;O23 - Service: Roxio Upnp Server 11 - Sonic Solutions - C:\Program Files\Roxio Creator 2009\Digital Home 11\RoxioUpnpService11.exe&lt;br /&gt;O23 - Service: LiveShare P2P Server 11 (RoxLiveShare11) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\11.0\SharedCOM\RoxLiveShare11.exe&lt;br /&gt;O23 - Service: RoxMediaDB11 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\11.0\SharedCOM\RoxMediaDB11.exe&lt;br /&gt;O23 - Service: Roxio Hard Drive Watcher 11 (RoxWatch11) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\11.0\SharedCOM\RoxWatch11.exe&lt;br /&gt;O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe&lt;br /&gt;O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe&lt;br /&gt;O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe&lt;br /&gt;O23 - Service: Viewpoint Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe&lt;/p&gt;
&lt;p&gt;--&lt;br /&gt;End of file - 4584 bytes&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Fake Antivirus alerts - Antivirus System PRO. Fake Windows Security alert keeps popping up. </title><link>http://en.community.dell.com/forums/thread/19588428.aspx</link><pubDate>Fri, 13 Nov 2009 04:59:34 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19588428</guid><dc:creator>MariaLee</dc:creator><slash:comments>1</slash:comments><comments>http://en.community.dell.com/forums/thread/19588428.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19588428</wfw:commentRss><description>&lt;p&gt;Security Alerts keep popping up with heading &amp;quot;Antivirus System Pro alert&amp;quot; asking if I want to block this attack? And I keep getting Security Warning dialog boxes saying that every application I try to run (even notepad.exe) is infected. Then the question &amp;quot;Do you want to activate your antivirus software now?&amp;quot;&amp;nbsp; I had a hard time copying the thread from Notepad, because I had to make several attempts to open the file - but here it is: &lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 10:41:30 PM, on 11/12/2009&lt;br /&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16915)&lt;br /&gt;Boot mode: Normal&lt;/p&gt;
&lt;p&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe&lt;br /&gt;C:\WINDOWS\eHome\ehRecvr.exe&lt;br /&gt;C:\WINDOWS\eHome\ehSched.exe&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\WINDOWS\system32\PRISMSVR.EXE&lt;br /&gt;C:\WINDOWS\ehome\ehtray.exe&lt;br /&gt;C:\WINDOWS\stsystra.exe&lt;br /&gt;C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe&lt;br /&gt;C:\WINDOWS\system32\dla\tfswctrl.exe&lt;br /&gt;C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe&lt;br /&gt;C:\Program Files\McAfee.com\Agent\mcagent.exe&lt;br /&gt;C:\Program Files\AIM\AIM Pro\aimpro.exe&lt;br /&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;br /&gt;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&lt;br /&gt;C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe&lt;br /&gt;C:\Documents and Settings\Maria\Local Settings\Application Data\ohfysq\nncbsysguard.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&lt;br /&gt;C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe&lt;br /&gt;C:\Program Files\Digital Line Detect\DLG.exe&lt;br /&gt;C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe&lt;br /&gt;C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe&lt;br /&gt;C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe&lt;br /&gt;C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe&lt;br /&gt;C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe&lt;br /&gt;C:\Program Files\Dell Wireless\PRISMCFG.exe&lt;br /&gt;C:\Program Files\McAfee\SiteAdvisor\McSACore.exe&lt;br /&gt;C:\WINDOWS\system32\java.exe&lt;br /&gt;C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMDiag.exe&lt;br /&gt;C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe&lt;br /&gt;c:\program files\common files\mcafee\mna\mcnasvc.exe&lt;br /&gt;c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe&lt;br /&gt;C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe&lt;br /&gt;C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe&lt;br /&gt;C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE&lt;br /&gt;C:\Program Files\McAfee\MPF\MPFSrv.exe&lt;br /&gt;C:\Program Files\McAfee\MSK\MskSrver.exe&lt;br /&gt;C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe&lt;br /&gt;C:\Program Files\Sonexis\ApplicationSharing\AppDriverService.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe&lt;br /&gt;C:\WINDOWS\system32\dllhost.exe&lt;br /&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;C:\WINDOWS\system32\HPZipm12.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe&lt;br /&gt;C:\WINDOWS\eHome\ehmsas.exe&lt;br /&gt;C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe&lt;br /&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;br /&gt;C:\Program Files\Windows Live\Toolbar\wltuser.exe&lt;br /&gt;C:\WINDOWS\system32\msiexec.exe&lt;br /&gt;C:\HijackThis.exe&lt;br /&gt;c:\PROGRA~1\mcafee.com\agent\mcupdate.exe&lt;/p&gt;
&lt;p&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://www.dell4me.com/myway"&gt;http://www.dell4me.com/myway&lt;/a&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR"&gt;http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR&lt;/a&gt;&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = &lt;a href="http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR"&gt;http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR&lt;/a&gt;&lt;br /&gt;R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll&lt;br /&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br /&gt;O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll&lt;br /&gt;O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll&lt;br /&gt;O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll&lt;br /&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll&lt;br /&gt;O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll&lt;br /&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;br /&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll&lt;br /&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll&lt;br /&gt;O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll&lt;br /&gt;O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll&lt;br /&gt;O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll&lt;br /&gt;O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll&lt;br /&gt;O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll&lt;br /&gt;O3 - Toolbar: &amp;amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll&lt;br /&gt;O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe&lt;br /&gt;O4 - HKLM\..\Run: [ATIPTA] &amp;quot;C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [DVDLauncher] &amp;quot;C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe&lt;br /&gt;O4 - HKLM\..\Run: [ISUSScheduler] &amp;quot;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&amp;quot; -start&lt;br /&gt;O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe&lt;br /&gt;O4 - HKLM\..\Run: [Google Desktop Search] &amp;quot;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&amp;quot; /startup&lt;br /&gt;O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe&lt;br /&gt;O4 - HKLM\..\Run: [mcagent_exe] &amp;quot;C:\Program Files\McAfee.com\Agent\mcagent.exe&amp;quot; /runkey&lt;br /&gt;O4 - HKLM\..\Run: [AIMPro] &amp;quot;C:\Program Files\AIM\AIM Pro\aimpro.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\qttask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKLM\..\Run: [iTunesHelper] &amp;quot;C:\Program Files\iTunes\iTunesHelper.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [GrooveMonitor] &amp;quot;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [nmctxth] &amp;quot;C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [oonxxuyx] C:\Documents and Settings\Maria\Local Settings\Application Data\ohfysq\nncbsysguard.exe&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - HKCU\..\Run: [MsnMsgr] &amp;quot;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&amp;quot; /background&lt;br /&gt;O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe&lt;br /&gt;O4 - HKCU\..\Run: [oonxxuyx] C:\Documents and Settings\Maria\Local Settings\Application Data\ohfysq\nncbsysguard.exe&lt;br /&gt;O4 - Global Startup: Digital Line Detect.lnk = ?&lt;br /&gt;O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe&lt;br /&gt;O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe&lt;br /&gt;O4 - Global Startup: officejet 6100.lnk = ?&lt;br /&gt;O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe&lt;br /&gt;O4 - Global Startup: VPN Client.lnk = ?&lt;br /&gt;O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk = ?&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000&lt;br /&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll&lt;br /&gt;O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: S&amp;amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O15 - Trusted Zone: *.intuit.com&lt;br /&gt;O15 - Trusted Zone: &lt;a href="http://*.turbotax.com"&gt;http://*.turbotax.com&lt;/a&gt;&lt;br /&gt;O16 - DPF: {61CE1CA1-6577-49B6-AE2C-43007A942429} (WebcastLogOut.Webcast) - &lt;a href="https://webcast.accenture.com/v2/WebcastLog/WebcastInfo.CAB"&gt;https://webcast.accenture.com/v2/WebcastLog/WebcastInfo.CAB&lt;/a&gt;&lt;br /&gt;O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &lt;a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1137945768339"&gt;http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1137945768339&lt;/a&gt;&lt;br /&gt;O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - &lt;a href="http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab"&gt;http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - &lt;a href="http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab"&gt;http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - &lt;br /&gt;O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll&lt;br /&gt;O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll&lt;br /&gt;O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll&lt;br /&gt;O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll&lt;br /&gt;O18 - Protocol: x-owacid - {0215258F-F0A8-49DE-BF1B-0FF02EDA8807} - C:\Program Files\Microsoft\Outlook Web Access SMIME Client\mimectl.dll&lt;br /&gt;O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe&lt;br /&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe&lt;br /&gt;O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe&lt;br /&gt;O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&lt;br /&gt;O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;br /&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe&lt;br /&gt;O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe&lt;br /&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;O23 - Service: Linksys Updater (LinksysUpdater) - Unknown owner - C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe&lt;br /&gt;O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe&lt;br /&gt;O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe&lt;br /&gt;O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe&lt;br /&gt;O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe&lt;br /&gt;O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe&lt;br /&gt;O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe&lt;br /&gt;O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe&lt;br /&gt;O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe&lt;br /&gt;O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe&lt;br /&gt;O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe&lt;br /&gt;O23 - Service: Pure Networks Platform Service (nmservice) - Cisco Systems, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe&lt;br /&gt;O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe&lt;br /&gt;O23 - Service: Sonexis Application Sharing Driver Service - Sonexis, Inc. - C:\Program Files\Sonexis\ApplicationSharing\AppDriverService.exe&lt;/p&gt;
&lt;p&gt;--&lt;br /&gt;End of file - 14310 bytes&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Fake Anti-Virus Pop-ups</title><link>http://en.community.dell.com/forums/thread/19587588.aspx</link><pubDate>Thu, 12 Nov 2009 02:43:03 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19587588</guid><dc:creator>epinker405</dc:creator><slash:comments>3</slash:comments><comments>http://en.community.dell.com/forums/thread/19587588.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19587588</wfw:commentRss><description>&lt;p&gt;Thank you in advance for your time and attention.&lt;/p&gt;
&lt;p&gt;Elissa&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 9:39:56 PM, on 11/11/2009&lt;br /&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v8.00 (8.00.6001.18702)&lt;br /&gt;Boot mode: Normal&lt;/p&gt;
&lt;p&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe&lt;br /&gt;C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe&lt;br /&gt;C:\Program Files\McAfee.com\Agent\mcagent.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jusched.exe&lt;br /&gt;C:\windows\pp12.exe&lt;br /&gt;C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\Program Files\AWS\WeatherBug\Weather.exe&lt;br /&gt;C:\Program Files\Adobe Media Player\Adobe Media Player.exe&lt;br /&gt;C:\WINDOWS\eHome\ehRecvr.exe&lt;br /&gt;C:\WINDOWS\eHome\ehSched.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe&lt;br /&gt;c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe&lt;br /&gt;c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe&lt;br /&gt;C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe&lt;br /&gt;C:\Program Files\McAfee\MPF\MPFSrv.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe&lt;br /&gt;C:\WINDOWS\system32\dllhost.exe&lt;br /&gt;C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe&lt;br /&gt;C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;/p&gt;
&lt;p&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)&lt;br /&gt;O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll&lt;br /&gt;O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll&lt;br /&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;br /&gt;O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll&lt;br /&gt;O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16&lt;br /&gt;O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe&lt;br /&gt;O4 - HKLM\..\Run: [DVDLauncher] &amp;quot;C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [mcagent_exe] &amp;quot;C:\Program Files\McAfee.com\Agent\mcagent.exe&amp;quot; /runkey&lt;br /&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &amp;quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Adobe ARM] &amp;quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] &amp;quot;C:\Program Files\Java\jre6\bin\jusched.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [sysldtray] C:\windows\ld15.exe&lt;br /&gt;O4 - HKLM\..\Run: [pp] C:\windows\pp12.exe&lt;br /&gt;O4 - HKCU\..\Run: [MSMSGS] &amp;quot;C:\Program Files\Messenger\msmsgs.exe&amp;quot; /background&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1&lt;br /&gt;O4 - HKCU\..\Run: [Messenger (Yahoo!)] &amp;quot;C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe&amp;quot; -quiet&lt;br /&gt;O4 - Startup: Adobe Media Player.lnk = C:\Program Files\Adobe Media Player\Adobe Media Player.exe&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O15 - Trusted Zone: &lt;a href="http://*.mcafee.com"&gt;http://*.mcafee.com&lt;/a&gt;&lt;br /&gt;O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - &lt;a href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab"&gt;http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - &lt;a href="http://photos.walmart.com/WalmartActivia.cab"&gt;http://photos.walmart.com/WalmartActivia.cab&lt;/a&gt;&lt;br /&gt;O23 - Service: dlcc_device -&amp;nbsp;&amp;nbsp; - C:\WINDOWS\system32\dlcccoms.exe&lt;br /&gt;O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe&lt;br /&gt;O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe&lt;br /&gt;O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe&lt;br /&gt;O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe&lt;br /&gt;O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe&lt;br /&gt;O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe&lt;br /&gt;O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe&lt;br /&gt;O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe&lt;br /&gt;O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe&lt;br /&gt;O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe&lt;/p&gt;
&lt;p&gt;--&lt;br /&gt;End of file - 5942 bytes&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Can't run any executible files </title><link>http://en.community.dell.com/forums/thread/19587560.aspx</link><pubDate>Thu, 12 Nov 2009 01:56:18 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19587560</guid><dc:creator>rvep</dc:creator><slash:comments>0</slash:comments><comments>http://en.community.dell.com/forums/thread/19587560.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19587560</wfw:commentRss><description>&lt;p&gt;I am unable to run the HiJack executible, or any ot the anti-malware software you suggest. Don&amp;#39;t know what to do now.&amp;nbsp; I am using another computer to communicate with you because infected computer has been removed from network.&amp;nbsp; I have copied HiJack and your other suggested programs to scan to a CD and tried to run it that way.&amp;nbsp; It didn&amp;#39;t work.&lt;/p&gt;
&lt;p&gt;When I turn on computer this security screen pops-up and wants runs a scan of computer and then all these red pop-up windows pop up telling me to remove infected files.&amp;nbsp; as this is happening I&amp;#39;m getting all these messages from the taskbar about files infected with a worm.&amp;nbsp; It shows up for every executible file that is trying to execute.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Getting constant "Unable to locate" error messages...</title><link>http://en.community.dell.com/forums/thread/19584707.aspx</link><pubDate>Sun, 08 Nov 2009 01:46:44 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19584707</guid><dc:creator>kschudy</dc:creator><slash:comments>22</slash:comments><comments>http://en.community.dell.com/forums/thread/19584707.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19584707</wfw:commentRss><description>&lt;p style="margin-top:7pt;margin-left:7pt;margin-right:7pt;"&gt;&lt;span style="font-family:Arial;color:black;font-size:10.5pt;"&gt;Messages read &amp;quot;This application has failed to start b/c netkmfd.dll was not found. Re-installing the application may fix this problem.&amp;quot; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:Arial;color:black;font-size:10.5pt;mso-fareast-font-family:&amp;#39;Times New Roman&amp;#39;;mso-ansi-language:EN-US;mso-fareast-language:EN-US;mso-bidi-language:AR-SA;"&gt;Reviewed the &amp;quot;Please Read This Before Posting For Malware Removal Help&amp;quot; article and followed all directions in that article (as everything I reviewed lead me to beleve I have a Malware issue). Below is the log from&amp;nbsp;HiJackThis...&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 7:42:02 PM, on 11/7/2009&lt;br /&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v8.00 (8.00.6001.18702)&lt;br /&gt;Boot mode: Normal&lt;/p&gt;
&lt;p&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe&lt;br /&gt;C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe&lt;br /&gt;C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe&lt;br /&gt;C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe&lt;br /&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe&lt;br /&gt;C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;C:\Program Files\Dell Support Center\bin\sprtsvc.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe&lt;br /&gt;C:\WINDOWS\system32\mdmcls32.exe&lt;br /&gt;C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe&lt;br /&gt;C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe&lt;br /&gt;C:\WINDOWS\system32\hkcmd.exe&lt;br /&gt;C:\WINDOWS\system32\igfxpers.exe&lt;br /&gt;C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe&lt;br /&gt;C:\WINDOWS\cfgmng32.exe&lt;br /&gt;C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe&lt;br /&gt;C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe&lt;br /&gt;C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe&lt;br /&gt;C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe&lt;br /&gt;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&lt;br /&gt;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&lt;br /&gt;C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe&lt;br /&gt;C:\Program Files\QuickTime\QTTask.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\Program Files\Digital Line Detect\DLG.exe&lt;br /&gt;C:\Program Files\Microsoft Office\Office\1033\msoffice.exe&lt;br /&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;br /&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;br /&gt;C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe&lt;br /&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/p&gt;
&lt;p&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://www.google.com/ig/dell?hl=en&amp;amp;client=dell-usuk&amp;amp;channel=us"&gt;www.google.com/ig/dell?hl=en&amp;amp;client=dell-usuk&amp;amp;channel=us&lt;/a&gt;&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://www.bing.com/"&gt;http://www.bing.com/&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &lt;a href="http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html"&gt;http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = &lt;a href="http://www.google.com/ig/dell?hl=en&amp;amp;client=dell-usuk&amp;amp;channel=us"&gt;www.google.com/ig/dell?hl=en&amp;amp;client=dell-usuk&amp;amp;channel=us&lt;/a&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &lt;a href="http://127.0.0.1:4664/first_usage&amp;amp;s=Iw7dPBHKDBuTirvfscIT4wfhQ9U"&gt;http://127.0.0.1:4664/first_usage&amp;amp;s=Iw7dPBHKDBuTirvfscIT4wfhQ9U&lt;/a&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;br /&gt;O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll&lt;br /&gt;O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll&lt;br /&gt;O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll&lt;br /&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;br /&gt;O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll&lt;br /&gt;O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe&lt;br /&gt;O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe&lt;br /&gt;O4 - HKLM\..\Run: [cctray] &amp;quot;C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [dvHighMem] C:\WINDOWS\cfgmng32.exe&lt;br /&gt;O4 - HKLM\..\Run: [QOELOADER] &amp;quot;C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [CAVRID] &amp;quot;C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl&lt;br /&gt;O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe&lt;br /&gt;O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe&lt;br /&gt;O4 - HKLM\..\Run: [CaPPcl] C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe /scan /startup&lt;br /&gt;O4 - HKLM\..\Run: [ISUSScheduler] &amp;quot;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&amp;quot; -start&lt;br /&gt;O4 - HKLM\..\Run: [Dvohovitogolop] rundll32.exe &amp;quot;C:\WINDOWS\akinuzehob.dll&amp;quot;,e&lt;br /&gt;O4 - HKLM\..\Run: [ISUSPM Startup] &amp;quot;c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe&amp;quot; -startup&lt;br /&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &amp;quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [dellsupportcenter] &amp;quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&amp;quot; /P dellsupportcenter&lt;br /&gt;O4 - HKLM\..\Run: [MMTray] &amp;quot;C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\QTTask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKLM\..\Run: [dscactivate] &amp;quot;C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [iTunesHelper] &amp;quot;C:\Program Files\iTunes\iTunesHelper.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10a.exe (User &amp;#39;SYSTEM&amp;#39;)&lt;br /&gt;O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10a.exe (User &amp;#39;Default user&amp;#39;)&lt;br /&gt;O4 - Global Startup: Digital Line Detect.lnk = ?&lt;br /&gt;O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE&lt;br /&gt;O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - &lt;a href="http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab"&gt;http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - &lt;a href="http://www2.snapfish.com/SnapfishActivia.cab"&gt;http://www2.snapfish.com/SnapfishActivia.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - &lt;a href="http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab"&gt;http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {59E937ED-AC7E-407D-B40B-6545B1EECDE7} (CDFusionActiveXCtl Object) - &lt;a href="http://www.weareautobots.com/ww/plugin/DFusionWeb.Installer.exe"&gt;http://www.weareautobots.com/ww/plugin/DFusionWeb.Installer.exe&lt;/a&gt;&lt;br /&gt;O16 - DPF: {A3256902-51FA-45A0-8A97-FC1143C169D9} (Diagnostics ActiveX WebControl) - &lt;a href="http://support.microsoft.com/mats/DiagWebControl.cab"&gt;http://support.microsoft.com/mats/DiagWebControl.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {F127B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - &lt;a href="http://cvs.pnimedia.com/upload/activex/v2_0_0_9/PCAXSetupv2.0.0.9.cab"&gt;http://cvs.pnimedia.com/upload/activex/v2_0_0_9/PCAXSetupv2.0.0.9.cab&lt;/a&gt;?&lt;br /&gt;O20 - Winlogon Notify: Winlogon - C:\WINDOWS\SYSTEM32\winmm64.dll&lt;br /&gt;O21 - SSODL: WinCheck - {EAD8F454-EC03-4B47-A5B7-6534DA513FA5} - winmm64.dll (file missing)&lt;br /&gt;O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe&lt;br /&gt;O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe&lt;br /&gt;O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe&lt;br /&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe&lt;br /&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe&lt;br /&gt;O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe&lt;br /&gt;O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe&lt;br /&gt;O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe&lt;br /&gt;O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe&lt;br /&gt;O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe&lt;br /&gt;O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe&lt;br /&gt;O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe&lt;br /&gt;O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe&lt;br /&gt;O23 - Service: WinSock Extention Manager - Unknown owner - C:\WINDOWS\system32\mdmcls32.exe&lt;/p&gt;
&lt;p&gt;--&lt;br /&gt;End of file - 10624 bytes&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Hijackthis log, do you see anything wrong</title><link>http://en.community.dell.com/forums/thread/19581722.aspx</link><pubDate>Tue, 03 Nov 2009 21:31:29 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19581722</guid><dc:creator>ccstann</dc:creator><slash:comments>10</slash:comments><comments>http://en.community.dell.com/forums/thread/19581722.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19581722</wfw:commentRss><description>&lt;p&gt;This company that I am working for has shut me down, they say I have malaware.&amp;nbsp; But I have run various scans with Avast and superanti spyware and get nothing high or medium level threat.&amp;nbsp; But when I ran SpyDoctor&amp;nbsp; (also ESTE, Malawarebytes, etc&amp;nbsp;and a few others) it showed a threat but would not clean it up unless I purchased an upgrade.&amp;nbsp; I read that sometimes this is a false positive so that you will purchase their product.&amp;nbsp; My computer is very slow sometimes.&amp;nbsp; I am going to purchase some more ram memory (512 now, 1.5 going to be).&amp;nbsp; I don&amp;#39;t mind purchasing something that will help me clean this up if need be.&amp;nbsp; Please recommend something.&amp;nbsp; The two things I have list above are both the free version.&amp;nbsp; Thank you, Cheryl&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Logfile of HijackThis v1.99.0&lt;br /&gt;Scan saved at 2:43:34 PM, on 10/30/2009&lt;br /&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16915)&lt;/p&gt;
&lt;p&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;c:\Program Files\Microsoft Security Essentials\MsMpEng.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe&lt;br /&gt;C:\Program Files\Alwil Software\Avast4\ashServ.exe&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;C:\Program Files\D-Link\D-Link DWA-552 Xtreme N Desktop Adapter\acs.exe&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\WINDOWS\BCMSMMSG.exe&lt;br /&gt;C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe&lt;br /&gt;C:\Program Files\FastAccessDSL\HelpCenter43\bin\sprtcmd.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jusched.exe&lt;br /&gt;C:\Program Files\Microsoft Security Essentials\msseces.exe&lt;br /&gt;C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;br /&gt;C:\Program Files\Windows Desktop Search\WindowsSearch.exe&lt;br /&gt;C:\Program Files\D-Link\D-Link DWA-552 Xtreme N Desktop Adapter\wirelesscm.exe&lt;br /&gt;C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe&lt;br /&gt;C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;C:\Program Files\Common Files\Motive\McciCMService.exe&lt;br /&gt;C:\WINDOWS\system32\nvsvc32.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\Program Files\Canon\CAL\CALMAIN.exe&lt;br /&gt;C:\WINDOWS\system32\SearchIndexer.exe&lt;br /&gt;C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe&lt;br /&gt;C:\Program Files\Alwil Software\Avast4\ashWebSv.exe&lt;br /&gt;C:\Program Files\Alwil Software\Avast4\ashSimpl.exe&lt;br /&gt;C:\Program Files\HijackThis.exe&lt;/p&gt;
&lt;p&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://www.yahoo.com/"&gt;http://www.yahoo.com/&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://www.yahoo.com/"&gt;http://www.yahoo.com/&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href="http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com"&gt;http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &lt;a href="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html"&gt;http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com"&gt;http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://www.yahoo.com/"&gt;http://www.yahoo.com/&lt;/a&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = &lt;a href="http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com"&gt;http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com&lt;/a&gt;&lt;br /&gt;O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll&lt;br /&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;br /&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;br /&gt;O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll&lt;br /&gt;O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe&lt;br /&gt;O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup&lt;br /&gt;O4 - HKLM\..\Run: [nwiz] nwiz.exe /install&lt;br /&gt;O4 - HKLM\..\Run: [mmtask] &amp;quot;C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\qttask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKLM\..\Run: [HelpCenter4.1] C:\Program Files\FastAccessDSL\HelpCenter43\bin\sprtcmd.exe /P HelpCenter4.1&lt;br /&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] &amp;quot;C:\Program Files\Java\jre6\bin\jusched.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &amp;quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [MSSE] &amp;quot;c:\Program Files\Microsoft Security Essentials\msseces.exe&amp;quot; -hide&lt;br /&gt;O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe&lt;br /&gt;O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - HKCU\..\Run: [MSMSGS] &amp;quot;C:\Program Files\Messenger\msmsgs.exe&amp;quot; /background&lt;br /&gt;O4 - HKCU\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /A &amp;quot;C:\WINDOWS\system32\E_S83.tmp&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;br /&gt;O4 - Startup: ashAvast.exe.lnk = C:\Program Files\Alwil Software\Avast4\ashAvast.exe&lt;br /&gt;O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe&lt;br /&gt;O4 - Global Startup: Wireless Connection Manager.lnk = C:\Program Files\D-Link\D-Link DWA-552 Xtreme N Desktop Adapter\wirelesscm.exe&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O11 - Options group: [INTERNATIONAL] International*&lt;br /&gt;O15 - Trusted Zone: *.alpineaccess.com&lt;br /&gt;O15 - Trusted Zone: &lt;a href="http://www.citrix.com"&gt;http://www.citrix.com&lt;/a&gt;&lt;br /&gt;O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - &lt;a href="http://support.dell.com/systemprofiler/SysPro.CAB"&gt;http://support.dell.com/systemprofiler/SysPro.CAB&lt;/a&gt;&lt;br /&gt;O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - &lt;a href="http://www.pcpitstop.com/betapit/PCPitStop.CAB"&gt;http://www.pcpitstop.com/betapit/PCPitStop.CAB&lt;/a&gt;&lt;br /&gt;O16 - DPF: {2BCDB465-81F9-41CB-832C-8037A4064446} (F5 Networks VPN Manager) - &lt;a href="https://a2fp2.alpineaccess.com/vdesk/terminal/urxvpn.cab#version=6030,2009,327,1607"&gt;https://a2fp2.alpineaccess.com/vdesk/terminal/urxvpn.cab#version=6030,2009,327,1607&lt;/a&gt;&lt;br /&gt;O16 - DPF: {41EF3CD2-D8CC-4438-84B1-280BB4E77C8E} (F5 Networks Dynamic Application Tunnel Control) - &lt;a href="https://a2fp2.alpineaccess.com/vdesk/terminal/f5tunsrv.cab#version=6030,2009,327,1558"&gt;https://a2fp2.alpineaccess.com/vdesk/terminal/f5tunsrv.cab#version=6030,2009,327,1558&lt;/a&gt;&lt;br /&gt;O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} (F5 Networks Auto Update) - C:\DOCUME~1\CHERYL~1\LOCALS~1\Temp\IXP000.TMP\InstallerControl.cab&lt;br /&gt;O16 - DPF: {4FAE30E1-EE9C-477D-8D06-BF8D3429B60F} (WebIQ Technology Client) - &lt;a href="https://www.webiqonline.com/WebIQ/bin/WebIQ.cab"&gt;https://www.webiqonline.com/WebIQ/bin/WebIQ.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - &lt;a href="http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab"&gt;http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &lt;a href="http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1253563001671"&gt;http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1253563001671&lt;/a&gt;&lt;br /&gt;O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - &lt;a href="http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab"&gt;http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {A1B8A30B-8AAA-4A3E-8869-1DA509E8A011} (Crystal ActiveX Report Viewer Control 10.0) - &lt;a href="https://www.peryourhealth.com/crystalreportviewers10/ActiveXControls/ActiveXViewer.cab"&gt;https://www.peryourhealth.com/crystalreportviewers10/ActiveXControls/ActiveXViewer.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - &lt;a href="http://www.superadblocker.com/activex/sabspx.cab"&gt;http://www.superadblocker.com/activex/sabspx.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} (Crystal Report Viewer Control) - &lt;a href="https://www.netchexonline.net/ActiveX/activexviewer.cab"&gt;https://www.netchexonline.net/ActiveX/activexviewer.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} (F5 Networks SuperHost Class) - &lt;a href="https://a2fp2.alpineaccess.com/vdesk/terminal/urxshost.cab"&gt;https://a2fp2.alpineaccess.com/vdesk/terminal/urxshost.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &lt;a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab"&gt;http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - &lt;a href="http://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab"&gt;http://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - &lt;a href="https://pc.mywebexpc.com/pc/mywebex/tool/syscheck/ieatgpc.cab"&gt;https://pc.mywebexpc.com/pc/mywebex/tool/syscheck/ieatgpc.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} (F5 Networks Host Control) - &lt;a href="https://a2fp2.alpineaccess.com/vdesk/terminal/urxhost.cab#version=6030,2009,327,1548"&gt;https://a2fp2.alpineaccess.com/vdesk/terminal/urxhost.cab#version=6030,2009,327,1548&lt;/a&gt;&lt;br /&gt;O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - &lt;a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab"&gt;http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab&lt;/a&gt;&lt;br /&gt;O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll&lt;br /&gt;O23 - Service: Atheros Configuration Service - Atheros - C:\Program Files\D-Link\D-Link DWA-552 Xtreme N Desktop Adapter\acs.exe&lt;br /&gt;O23 - Service: avast! iAVS4 Control Service - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe&lt;br /&gt;O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe&lt;br /&gt;O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe&lt;br /&gt;O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe&lt;br /&gt;O23 - Service: Canon Camera Access Library 8 - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe&lt;br /&gt;O23 - Service: EpsonBidirectionalService - Unknown - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe&lt;br /&gt;O23 - Service: EPSON Printer Status Agent2 - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe&lt;br /&gt;O23 - Service: Java Quick Starter - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe&lt;br /&gt;O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Hijack this log help please</title><link>http://en.community.dell.com/forums/thread/19587303.aspx</link><pubDate>Wed, 11 Nov 2009 19:49:45 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19587303</guid><dc:creator>4marcantony</dc:creator><slash:comments>0</slash:comments><comments>http://en.community.dell.com/forums/thread/19587303.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19587303</wfw:commentRss><description>&lt;p&gt;I think problems started after i recieved an &amp;quot;Updates available message&amp;quot; which was for Acrobat Reader 9 now computer freezing Outlook express and Explorer also every reboot message &amp;quot;your Computer is not Protected (MCafee) click fix. Have run Virus check and Malaware bytes put both no problems&lt;/p&gt;
&lt;p&gt;I have had dreadful service from Dell technical support hence this&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 19:43:21, on 11/11/2009&lt;br /&gt;Platform: Windows Vista SP1 (WinNT 6.00.1905)&lt;br /&gt;MSIE: Internet Explorer v8.00 (8.00.6001.18828)&lt;br /&gt;Boot mode: Normal&lt;/p&gt;
&lt;p&gt;Running processes:&lt;br /&gt;C:\Windows\system32\Dwm.exe&lt;br /&gt;c:\PROGRA~1\mcafee.com\agent\mcagent.exe&lt;br /&gt;C:\Windows\Explorer.EXE&lt;br /&gt;C:\Windows\system32\taskeng.exe&lt;br /&gt;C:\Program Files\Windows Defender\MSASCui.exe&lt;br /&gt;C:\Windows\RtHDVCpl.exe&lt;br /&gt;C:\Windows\System32\igfxtray.exe&lt;br /&gt;C:\Windows\System32\hkcmd.exe&lt;br /&gt;C:\Windows\system32\igfxsrvc.exe&lt;br /&gt;C:\Windows\System32\igfxpers.exe&lt;br /&gt;C:\Program Files\Dell V105\dldnmon.exe&lt;br /&gt;C:\Program Files\Dell V105\dldnMsdMon.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jusched.exe&lt;br /&gt;C:\Program Files\Windows Sidebar\sidebar.exe&lt;br /&gt;C:\Program Files\Windows Media Player\wmpnscfg.exe&lt;br /&gt;C:\Program Files\Dell\DellDock\DellDock.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/p&gt;
&lt;p&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://g.uk.msn.com/USCON/2"&gt;http://g.uk.msn.com/USCON/2&lt;/a&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://uk.yahoo.com/"&gt;http://uk.yahoo.com/&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = &lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = &lt;br /&gt;O1 - Hosts: ::1 localhost&lt;br /&gt;O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll&lt;br /&gt;O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll&lt;br /&gt;O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll&lt;br /&gt;O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)&lt;br /&gt;O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll&lt;br /&gt;O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll&lt;br /&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;br /&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;br /&gt;O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll&lt;br /&gt;O3 - Toolbar: &amp;amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll&lt;br /&gt;O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide&lt;br /&gt;O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe&lt;br /&gt;O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe&lt;br /&gt;O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe&lt;br /&gt;O4 - HKLM\..\Run: [dldnmon.exe] &amp;quot;C:\Program Files\Dell V105\dldnmon.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [dldnamon] &amp;quot;C:\Program Files\Dell V105\dldnamon.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [mcagent_exe] &amp;quot;C:\Program Files\McAfee.com\Agent\mcagent.exe&amp;quot; /runkey&lt;br /&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] &amp;quot;C:\Program Files\Java\jre6\bin\jusched.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun&lt;br /&gt;O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe&lt;br /&gt;O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User &amp;#39;LOCAL SERVICE&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User &amp;#39;LOCAL SERVICE&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User &amp;#39;NETWORK SERVICE&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-21-3213371263-3620806007-3857936973-1001\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User &amp;#39;Joyce&amp;#39;)&lt;br /&gt;O4 - S-1-5-21-3213371263-3620806007-3857936973-1001 Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User &amp;#39;Joyce&amp;#39;)&lt;br /&gt;O4 - S-1-5-21-3213371263-3620806007-3857936973-1001 User Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User &amp;#39;Joyce&amp;#39;)&lt;br /&gt;O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User &amp;#39;Default user&amp;#39;)&lt;br /&gt;O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe&lt;br /&gt;O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: &amp;amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL&lt;br /&gt;O13 - Gopher Prefix: &lt;br /&gt;O15 - Trusted Zone: &lt;a href="http://*.mcafee.com"&gt;http://*.mcafee.com&lt;/a&gt;&lt;br /&gt;O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - &lt;a href="http://www.shockwave.com/content/feedingfrenzy/sis/SproutLauncher.cab"&gt;http://www.shockwave.com/content/feedingfrenzy/sis/SproutLauncher.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - &lt;a href="https://nhs.webex.com/client/T26L/webex/ieatgpc1.cab"&gt;https://nhs.webex.com/client/T26L/webex/ieatgpc1.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - &lt;a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab"&gt;http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab&lt;/a&gt;&lt;br /&gt;O17 - HKLM\System\CCS\Services\Tcpip\..\{874683F7-8C65-4C68-943B-92D667EEFCD6}: NameServer = 212.139.132.52 212.139.132.53&lt;br /&gt;O17 - HKLM\System\CS1\Services\Tcpip\..\{874683F7-8C65-4C68-943B-92D667EEFCD6}: NameServer = 212.139.132.52 212.139.132.53&lt;br /&gt;O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll&lt;br /&gt;O23 - Service: McAfee Application Installer Cleanup (0028931257958510) (0028931257958510mcinstcleanup) - McAfee, Inc. - C:\Windows\TEMP\002893~1.EXE&lt;br /&gt;O23 - Service: dldn_device -&amp;nbsp;&amp;nbsp; - C:\Windows\system32\dldncoms.exe&lt;br /&gt;O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe&lt;br /&gt;O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe&lt;br /&gt;O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe&lt;br /&gt;O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe&lt;br /&gt;O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe&lt;br /&gt;O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe&lt;br /&gt;O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe&lt;br /&gt;O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe&lt;br /&gt;O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe&lt;br /&gt;O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe&lt;br /&gt;O23 - Service: SpeedTouch 330 Manager (st330service) - THOMSON Telecom Belgium - C:\Program Files/Thomson/ST330/service/st330service.exe&lt;/p&gt;
&lt;p&gt;--&lt;br /&gt;End of file - 8168 bytes&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Can't exit out of Fake Anti-Virus Pop-up</title><link>http://en.community.dell.com/forums/thread/19585669.aspx</link><pubDate>Mon, 09 Nov 2009 18:52:35 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19585669</guid><dc:creator>Heb2009</dc:creator><slash:comments>1</slash:comments><comments>http://en.community.dell.com/forums/thread/19585669.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19585669</wfw:commentRss><description>&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 1:01:57 PM, on 11/9/2009&lt;br /&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v8.00 (8.00.6001.18702)&lt;br /&gt;Boot mode: Normal&lt;/p&gt;
&lt;p&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\EvtEng.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe&lt;br /&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe&lt;br /&gt;C:\WINDOWS\system32\CTsvcCDA.exe&lt;br /&gt;C:\WINDOWS\system32\dlcfcoms.exe&lt;br /&gt;C:\WINDOWS\eHome\ehRecvr.exe&lt;br /&gt;C:\WINDOWS\eHome\ehSched.exe&lt;br /&gt;C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe&lt;br /&gt;C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE&lt;br /&gt;C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe&lt;br /&gt;C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe&lt;br /&gt;C:\Program Files\Dell Support Center\bin\sprtsvc.exe&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\WINDOWS\system32\stacsv.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe&lt;br /&gt;C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe&lt;br /&gt;C:\WINDOWS\system32\hkcmd.exe&lt;br /&gt;C:\WINDOWS\system32\igfxpers.exe&lt;br /&gt;C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe&lt;br /&gt;C:\WINDOWS\system32\Rundll32.exe&lt;br /&gt;C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe&lt;br /&gt;C:\WINDOWS\ehome\ehtray.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe&lt;br /&gt;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&lt;br /&gt;C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;br /&gt;C:\Program Files\Canon\CAL\CALMAIN.exe&lt;br /&gt;C:\DOCUME~1\MARKHE~1\LOCALS~1\Temp\clclean.0001&lt;br /&gt;C:\Program Files\BELKIN\Video Dock Power Applet\PowerApp.exe&lt;br /&gt;C:\WINDOWS\system32\dllhost.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe&lt;br /&gt;C:\WINDOWS\eHome\ehmsas.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/p&gt;
&lt;p&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://www.google.com/ig/dell?hl=en&amp;amp;client=dell-usuk-rel&amp;amp;channel=us&amp;amp;ibd=2061217"&gt;www.google.com/ig/dell?hl=en&amp;amp;client=dell-usuk-rel&amp;amp;channel=us&amp;amp;ibd=2061217&lt;/a&gt;&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://www.google.com/ig/dell?hl=en&amp;amp;client=dell-usuk-rel&amp;amp;channel=us&amp;amp;ibd=2061217"&gt;www.google.com/ig/dell?hl=en&amp;amp;client=dell-usuk-rel&amp;amp;channel=us&amp;amp;ibd=2061217&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = &lt;a href="http://www.google.com/ig/dell?hl=en&amp;amp;client=dell-usuk-rel&amp;amp;channel=us&amp;amp;ibd=2061217"&gt;www.google.com/ig/dell?hl=en&amp;amp;client=dell-usuk-rel&amp;amp;channel=us&amp;amp;ibd=2061217&lt;/a&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;br /&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br /&gt;O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll&lt;br /&gt;O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL&lt;br /&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll&lt;br /&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll&lt;br /&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll&lt;br /&gt;O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll&lt;br /&gt;O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll&lt;br /&gt;O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll&lt;br /&gt;O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe&lt;br /&gt;O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe&lt;br /&gt;O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r&lt;br /&gt;O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon&lt;br /&gt;O4 - HKLM\..\Run: [DLCFCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCFtime.dll,_RunDLLEntry@16&lt;br /&gt;O4 - HKLM\..\Run: [pccguide.exe] &amp;quot;C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [MCT_HID_PATCH] &#x1;&lt;br /&gt;O4 - HKLM\..\Run: [IntelZeroConfig] &amp;quot;C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [IntelWireless] &amp;quot;C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe&amp;quot; /tf Intel PROSet/Wireless&lt;br /&gt;O4 - HKLM\..\Run: [dellsupportcenter] &amp;quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&amp;quot; /P dellsupportcenter&lt;br /&gt;O4 - HKLM\..\Run: [nunamapuy] Rundll32.exe &amp;quot;c:\windows\system32\madudori.dll&amp;quot;,a&lt;br /&gt;O4 - HKCU\..\Run: [OE_OEM] &amp;quot;C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - HKCU\..\Run: [MSMSGS] &amp;quot;C:\Program Files\Messenger\msmsgs.exe&amp;quot; /background&lt;br /&gt;O4 - HKCU\..\Run: [swg] &amp;quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&amp;quot;&lt;br /&gt;O4 - Startup: Video Dock Power Applet.lnk = ?&lt;br /&gt;O4 - Global Startup: Event Reminder.lnk = ?&lt;br /&gt;O4 - Global Startup: MRI_DISABLED&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000&lt;br /&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll&lt;br /&gt;O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O16 - DPF: Web-Based Email Tools - &lt;a href="http://email.secureserver.net/Download.CAB"&gt;http://email.secureserver.net/Download.CAB&lt;/a&gt;&lt;br /&gt;O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - &lt;a href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab"&gt;http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - &lt;a href="http://www.linkedin.com/cab/LinkedInContactFinderControl.cab"&gt;http://www.linkedin.com/cab/LinkedInContactFinderControl.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &lt;a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1167429945296"&gt;http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1167429945296&lt;/a&gt;&lt;br /&gt;O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - &lt;a href="http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab"&gt;http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {89242969-422B-46BF-B0D5-6A7B7DC4D0E0} (NAS Finder Helper) - &lt;a&gt;file:///D:/html/nafcom.cab&lt;/a&gt;&lt;br /&gt;O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll&lt;br /&gt;O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll&lt;br /&gt;O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)&lt;br /&gt;O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL&lt;br /&gt;O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL c:\windows\system32\madudori.dll,zopeyero.dll&lt;br /&gt;O21 - SSODL: ramasizek - {364d0ee9-98ac-4830-9c80-2962c1361a0a} - (no file)&lt;br /&gt;O21 - SSODL: seyufolit - {8b6d2bbe-d11b-4ebf-9b28-6c7b8d8f7899} - c:\windows\system32\madudori.dll&lt;br /&gt;O22 - SharedTaskScheduler: tokatiluy - {364d0ee9-98ac-4830-9c80-2962c1361a0a} - (no file)&lt;br /&gt;O22 - SharedTaskScheduler: mujuzedij - {8b6d2bbe-d11b-4ebf-9b28-6c7b8d8f7899} - c:\windows\system32\madudori.dll&lt;br /&gt;O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe&lt;br /&gt;O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe&lt;br /&gt;O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe&lt;br /&gt;O23 - Service: dlcf_device -&amp;nbsp;&amp;nbsp; - C:\WINDOWS\system32\dlcfcoms.exe&lt;br /&gt;O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe&lt;br /&gt;O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&lt;br /&gt;O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;br /&gt;O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe&lt;br /&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe&lt;br /&gt;O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe&lt;br /&gt;O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe&lt;br /&gt;O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe&lt;br /&gt;O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe&lt;br /&gt;O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe&lt;br /&gt;O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation&amp;nbsp; - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe&lt;br /&gt;O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe&lt;br /&gt;O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\stacsv.exe&lt;br /&gt;O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe&lt;br /&gt;O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe&lt;br /&gt;O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe&lt;br /&gt;O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe&lt;/p&gt;
&lt;p&gt;--&lt;br /&gt;End of file - 12263 bytes&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Spam attack! Can't get to task manager!</title><link>http://en.community.dell.com/forums/thread/19585252.aspx</link><pubDate>Mon, 09 Nov 2009 01:42:19 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19585252</guid><dc:creator>slipknotfanms86</dc:creator><slash:comments>1</slash:comments><comments>http://en.community.dell.com/forums/thread/19585252.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19585252</wfw:commentRss><description>&lt;p&gt;Here&amp;#39;s the hijackthis report&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 7:09:01 PM, on 11/8/2009&lt;br /&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v8.00 (8.00.6001.18702)&lt;br /&gt;Boot mode: Normal&lt;br /&gt;&lt;br /&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\System32\Ati2evxx.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe&lt;br /&gt;C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE&lt;br /&gt;C:\WINDOWS\system32\CTHELPER.EXE&lt;br /&gt;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&lt;br /&gt;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jusched.exe&lt;br /&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;br /&gt;C:\Program Files\AIM6\aim6.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\Program Files\Windows Media Player\WMPNSCFG.exe&lt;br /&gt;C:\Program Files\AIM6\aolsoftware.exe&lt;br /&gt;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe&lt;br /&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;C:\WINDOWS\System32\CTsvcCDA.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;C:\Program Files\Viewpoint\Common\ViewpointService.exe&lt;br /&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;C:\Documents and Settings\Slipknot Matt\zeabei.exe&lt;br /&gt;C:\DOCUME~1\SLIPKN~1\LOCALS~1\Temp\a.exe&lt;br /&gt;C:\WINDOWS\msa.exe&lt;br /&gt;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br /&gt;C:\PROGRA~1\AVG\AVG8\avgrsx.exe&lt;br /&gt;C:\PROGRA~1\AVG\AVG8\avgnsx.exe&lt;br /&gt;C:\WINDOWS\system32\wuauclt.exe&lt;br /&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;br /&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br /&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;br /&gt;O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll&lt;br /&gt;O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll&lt;br /&gt;O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL&lt;br /&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;br /&gt;O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll&lt;br /&gt;O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe&lt;br /&gt;O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE&lt;br /&gt;O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE&lt;br /&gt;O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL&lt;br /&gt;O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE&lt;br /&gt;O4 - HKLM\..\Run: [StartCCC] &amp;quot;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&amp;quot; MSRun&lt;br /&gt;O4 - HKLM\..\Run: [GrooveMonitor] &amp;quot;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] &amp;quot;C:\Program Files\Java\jre6\bin\jusched.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\QTTask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKLM\..\Run: [iTunesHelper] &amp;quot;C:\Program Files\iTunes\iTunesHelper.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &amp;quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Adobe ARM] &amp;quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Windows Enterprise Suite] &amp;quot;C:\Documents and Settings\All Users\Application Data\c207b\WE6cd.exe&amp;quot; /s /d&lt;br /&gt;O4 - HKCU\..\Run: [Aim6] &amp;quot;C:\Program Files\AIM6\aim6.exe&amp;quot; /d locale=en-US ee://aol/imApp&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe&lt;br /&gt;O4 - HKCU\..\Run: [zeabei] C:\Documents and Settings\Slipknot Matt\zeabei.exe&lt;br /&gt;O4 - HKCU\..\Run: [TurboNet] C:\DOCUME~1\SLIPKN~1\LOCALS~1\Temp\a.exe&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000&lt;br /&gt;O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: S&amp;amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL&lt;br /&gt;O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll&lt;br /&gt;O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll&lt;br /&gt;O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe&lt;br /&gt;O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe&lt;br /&gt;O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br /&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe&lt;br /&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;End of file - 6801 bytes&lt;/p&gt;
&lt;p&gt;Help, please!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Bamajim</title><link>http://en.community.dell.com/forums/thread/19576391.aspx</link><pubDate>Tue, 27 Oct 2009 17:17:44 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19576391</guid><dc:creator>rspangl</dc:creator><slash:comments>20</slash:comments><comments>http://en.community.dell.com/forums/thread/19576391.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19576391</wfw:commentRss><description>&lt;p&gt;Antivirus System Pro has taken over my (other) computer.&amp;nbsp; Cannot use internet, cannot run Hijack this, cannot boot in safe mode.&amp;nbsp; I was not able to scan with Malwarebytes Anti-Malware.&amp;nbsp; In a Google search on the subject, I found and ran combofix (no idea what I was doing here).&amp;nbsp;&amp;nbsp;As a result I&amp;#39;ve been able to run Anti-Malware, but still not able to run Hijack This, internet.&amp;nbsp;&amp;nbsp;I ran the following log.&amp;nbsp; Please let me know If you can help, given what I&amp;#39;ve gotten myself into. If not, I&amp;#39;m not sure where to go next.&amp;nbsp; But, I&amp;#39;ll wait to hear from you before moving on.&amp;nbsp; Thanks!&lt;/p&gt;
&lt;p&gt;Following is text file from Filelister.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;+++++++++++++++++++++++++++++++++&lt;br /&gt;+ File Lister&amp;nbsp; Version 1.1.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; +&lt;br /&gt;+&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; +&lt;br /&gt;+&amp;nbsp; By bamajim / SpywareHammer.com&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; +&lt;br /&gt;+++++++++++++++++++++++++++++++++&lt;/p&gt;
&lt;p&gt;Report ran on ---&amp;gt;&amp;gt;&amp;gt;&amp;nbsp; 10/25/2009 12:08:38 PM&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;====== Running Processes ======&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe&lt;br /&gt;C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe&lt;br /&gt;C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe&lt;br /&gt;C:\WINDOWS\system32\PSIService.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\UAService7.exe&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\Program Files\Analog Devices\Core\smax4pnp.exe&lt;br /&gt;C:\WINDOWS\system32\hkcmd.exe&lt;br /&gt;C:\WINDOWS\system32\igfxpers.exe&lt;br /&gt;C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe&lt;br /&gt;C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe&lt;br /&gt;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&lt;br /&gt;C:\Program Files\HP\HP Software Update\HPWuSchd2.exe&lt;br /&gt;C:\Program Files\QuickTime\QTTask.exe&lt;br /&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;br /&gt;C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe&lt;br /&gt;C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe&lt;br /&gt;C:\Program Files\Southwest Airlines\Ding\Ding.exe&lt;br /&gt;C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe&lt;br /&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;C:\WINDOWS\system32\HPZipm12.exe&lt;br /&gt;C:\WINDOWS\System32\WScript.exe&lt;br /&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;br /&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;/p&gt;
&lt;p&gt;====== BHO&amp;#39;s ======&lt;/p&gt;
&lt;p&gt;BHO: (NO NAME) - {fa9fc5c9-e865-4cfc-a8f5-a5630712beb4} - jejobadi.dll&lt;/p&gt;
&lt;p&gt;====== HKLM\~\Run Keys ======&lt;/p&gt;
&lt;p&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;/p&gt;
&lt;p&gt;[SoundMAXPnP] = C:\Program Files\Analog Devices\Core\smax4pnp.exe&lt;br /&gt;[igfxtray] = C:\WINDOWS\system32\igfxtray.exe&lt;br /&gt;[igfxhkcmd] = C:\WINDOWS\system32\hkcmd.exe&lt;br /&gt;[igfxpers] = C:\WINDOWS\system32\igfxpers.exe&lt;br /&gt;[Symantec PIF AlertEng] = &amp;quot;C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe&amp;quot; /a /m &amp;quot;C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll&amp;quot;&lt;br /&gt;[Carbonite Backup] = C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe&lt;br /&gt;[TkBellExe] = &amp;quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&amp;quot;&amp;nbsp; -osboot&lt;br /&gt;[HP Software Update] = &amp;quot;C:\Program Files\HP\HP Software Update\HPWuSchd2.exe&amp;quot;&lt;br /&gt;[QuickTime Task] = &amp;quot;C:\Program Files\QuickTime\QTTask.exe&amp;quot; -atboottime&lt;br /&gt;[iTunesHelper] = &amp;quot;C:\Program Files\iTunes\iTunesHelper.exe&amp;quot;&lt;br /&gt;[calc] = rundll32.exe C:\WINDOWS\system32\calc.dll,_IWMPEvents@0&lt;br /&gt;[Malwarebytes Anti-Malware (reboot)] = &amp;quot;C:\Program Files\Malwarebytes&amp;#39; Anti-Malware\mbam.exe&amp;quot; /runcleanupscript&lt;br /&gt;[fajatezigu] = Rundll32.exe &amp;quot;pekuveme.dll&amp;quot;,s&lt;/p&gt;
&lt;p&gt;====== HKCU\~\Run Keys ======&lt;/p&gt;
&lt;p&gt;[ctfmon.exe] = C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;[swg] = &amp;quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&amp;quot;&lt;br /&gt;[MSMSGS] = &amp;quot;C:\Program Files\Messenger\msmsgs.exe&amp;quot; /background&lt;br /&gt;[Yjafosi8kdf98winmdkmnkmfnwe] = C:\DOCUME~1\Ron\LOCALS~1\Temp\win32.exe&lt;br /&gt;[calc] = rundll32.exe C:\DOCUME~1\Ron\ntuser.dll,_IWMPEvents@0&lt;/p&gt;
&lt;p&gt;====== DNS Info (List may be empty) ======&lt;/p&gt;
&lt;p&gt;HKEY_LOCAL_MACHINE\CCS\~\{060BB8A1-0C5C-4268-AD01-D11DA72521E4}\&amp;nbsp; NameServer= &lt;br /&gt;HKEY_LOCAL_MACHINE\CCS\~\{54E93F58-1792-4CE4-B852-78DBBC07F4EA}\&amp;nbsp; NameServer= &lt;br /&gt;HKEY_LOCAL_MACHINE\CCS\~\{A0ABD979-8675-4E99-ABD0-B38F90117134}\&amp;nbsp; NameServer= &lt;/p&gt;
&lt;p&gt;HKEY_LOCAL_MACHINE\CS001\~\{060BB8A1-0C5C-4268-AD01-D11DA72521E4}\&amp;nbsp; NameServer= &lt;br /&gt;HKEY_LOCAL_MACHINE\CS001\~\{54E93F58-1792-4CE4-B852-78DBBC07F4EA}\&amp;nbsp; NameServer= &lt;br /&gt;HKEY_LOCAL_MACHINE\CS001\~\{A0ABD979-8675-4E99-ABD0-B38F90117134}\&amp;nbsp; NameServer= &lt;/p&gt;
&lt;p&gt;HKEY_LOCAL_MACHINE\CS002\~\{060BB8A1-0C5C-4268-AD01-D11DA72521E4}\&amp;nbsp; NameServer= &lt;br /&gt;HKEY_LOCAL_MACHINE\CS002\~\{54E93F58-1792-4CE4-B852-78DBBC07F4EA}\&amp;nbsp; NameServer= &lt;br /&gt;HKEY_LOCAL_MACHINE\CS002\~\{A0ABD979-8675-4E99-ABD0-B38F90117134}\&amp;nbsp; NameServer= &lt;/p&gt;
&lt;p&gt;&lt;br /&gt;====== Folders and Files from &amp;quot;%\&amp;quot; and &amp;quot;%\Windows&amp;quot; Created Last 60 Days ======&lt;/p&gt;
&lt;p&gt;10/24/2009 4:23:31 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 16572635&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\ComboFix&lt;br /&gt;10/24/2009 4:23:31 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 8861&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\ComboFix\N_&lt;br /&gt;10/24/2009 4:18:57 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 6176546&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox&lt;br /&gt;10/24/2009 4:25:14 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 14439&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\BackEnv&lt;br /&gt;10/24/2009 4:25:14 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 124&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\LastRun&lt;br /&gt;10/24/2009 4:18:57 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 6161983&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine&lt;br /&gt;10/24/2009 4:26:48 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 6147449&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C&lt;br /&gt;10/24/2009 4:41:23 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 1598436&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings&lt;br /&gt;10/24/2009 4:41:23 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 1102419&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\All Users&lt;br /&gt;10/24/2009 4:41:23 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 1102419&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data&lt;br /&gt;10/24/2009 4:41:23 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 1051682&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\22002915&lt;br /&gt;10/24/2009 4:41:24 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 49459&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\Kelly&lt;br /&gt;10/24/2009 4:41:24 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 850&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\Kelly\Desktop&lt;br /&gt;10/24/2009 4:41:25 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 25057&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\Kelly\Start Menu&lt;br /&gt;10/24/2009 4:41:25 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 25057&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\Kelly\Start Menu\Programs&lt;br /&gt;10/24/2009 4:41:25 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 24201&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\Kelly\Start Menu\Programs\Startup&lt;br /&gt;10/24/2009 4:41:26 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 290371&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\Lindsey&lt;br /&gt;10/24/2009 4:41:26 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 28681&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\Lindsey\Application Data&lt;br /&gt;10/24/2009 4:41:26 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 68232&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\Lindsey\Cookies&lt;br /&gt;10/24/2009 4:41:27 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 850&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\Lindsey\Desktop&lt;br /&gt;10/24/2009 4:41:28 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 143995&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\Lindsey\Local Settings&lt;br /&gt;10/24/2009 4:41:28 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 55434&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\Lindsey\Local Settings\Application Data&lt;br /&gt;10/24/2009 4:41:28 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 88561&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\Lindsey\Local Settings\Temporary Internet Files&lt;br /&gt;10/24/2009 4:41:30 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 25061&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\Lindsey\Start Menu&lt;br /&gt;10/24/2009 4:41:30 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 25061&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\Lindsey\Start Menu\Programs&lt;br /&gt;10/24/2009 4:41:30 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 24205&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\Lindsey\Start Menu\Programs\Startup&lt;br /&gt;10/24/2009 4:41:31 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 47753&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\Patty&lt;br /&gt;10/24/2009 4:41:31 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 24201&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\Patty\Start Menu&lt;br /&gt;10/24/2009 4:41:31 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 24201&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\Patty\Start Menu\Programs&lt;br /&gt;10/24/2009 4:41:31 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 24201&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\Patty\Start Menu\Programs\Startup&lt;br /&gt;10/24/2009 4:41:31 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 108434&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\Ron&lt;br /&gt;10/24/2009 4:41:31 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 850&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\Ron\Desktop&lt;br /&gt;10/24/2009 4:41:32 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 58979&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\Ron\My Documents&lt;br /&gt;10/24/2009 4:41:32 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 25053&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\Ron\Start Menu&lt;br /&gt;10/24/2009 4:41:32 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 25053&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\Ron\Start Menu\Programs&lt;br /&gt;10/24/2009 4:41:32 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 24197&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Documents and Settings\Ron\Start Menu\Programs\Startup&lt;br /&gt;10/24/2009 4:41:33 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 1084310&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Program Files&lt;br /&gt;10/24/2009 4:41:33 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 34446&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Program Files\Common Files&lt;br /&gt;10/24/2009 4:41:33 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 257280&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Program Files\qpmynv&lt;br /&gt;10/24/2009 4:41:33 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 397325&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Program Files\Shared&lt;br /&gt;10/24/2009 4:41:34 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 395259&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\Program Files\WinPcap&lt;br /&gt;10/24/2009 4:41:36 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 3464703&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\WINDOWS&lt;br /&gt;10/24/2009 4:41:37 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 3224576&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\WINDOWS\system32&lt;br /&gt;10/24/2009 4:41:38 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 32000&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers&lt;br /&gt;10/24/2009 4:18:57 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 14534&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Quarantine\Registry_backups&lt;br /&gt;10/24/2009 4:25:14 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\Test&lt;br /&gt;10/24/2009 4:25:14 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Qoobox\TestC&lt;br /&gt;10/25/2009 12:08:38 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 2075&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Files.txt&lt;br /&gt;10/13/2009 7:43:20 AM&amp;nbsp;&amp;nbsp;&amp;nbsp; 534827008&amp;nbsp;&amp;nbsp;&amp;nbsp; 38&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\hiberfil.sys&lt;br /&gt;10/23/2009 3:14:59 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 52736&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\ldvx.exe&lt;br /&gt;10/23/2009 3:14:57 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 114640&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\qsdhs.exe&lt;br /&gt;10/20/2009 8:18:00 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 1044771&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\$NtUninstallKB954155_WM9$&lt;br /&gt;10/20/2009 8:18:00 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 630827&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst&lt;br /&gt;9/8/2009 10:13:58 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 785101&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\$NtUninstallKB956844$&lt;br /&gt;9/8/2009 10:13:58 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 632013&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\$NtUninstallKB956844$\spuninst&lt;br /&gt;10/20/2009 8:19:11 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 630612&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\$NtUninstallKB958869$&lt;br /&gt;10/20/2009 8:19:11 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 630612&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\$NtUninstallKB958869$\spuninst&lt;br /&gt;10/4/2009 12:33:30 AM&amp;nbsp;&amp;nbsp;&amp;nbsp; 2128325&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\$NtUninstallKB968389$&lt;br /&gt;10/4/2009 12:33:30 AM&amp;nbsp;&amp;nbsp;&amp;nbsp; 637509&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\$NtUninstallKB968389$\spuninst&lt;br /&gt;9/8/2009 10:13:50 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 3007559&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\$NtUninstallKB968816_WM9$&lt;br /&gt;9/8/2009 10:13:50 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 630799&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst&lt;br /&gt;10/20/2009 8:02:15 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 2067399&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\$NtUninstallKB969059$&lt;br /&gt;10/20/2009 8:02:16 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 631751&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\$NtUninstallKB969059$\spuninst&lt;br /&gt;8/25/2009 7:11:17 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 843668&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\$NtUninstallKB970653-v3$&lt;br /&gt;8/25/2009 7:11:17 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 645524&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst&lt;br /&gt;10/20/2009 7:56:03 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 9025068&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\$NtUninstallKB971486$&lt;br /&gt;10/20/2009 7:56:03 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 635052&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\$NtUninstallKB971486$\spuninst&lt;br /&gt;10/20/2009 7:53:40 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 769057&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\$NtUninstallKB973525$&lt;br /&gt;10/20/2009 7:53:40 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 629793&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\$NtUninstallKB973525$\spuninst&lt;br /&gt;10/20/2009 8:01:54 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 879066&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\$NtUninstallKB974112$&lt;br /&gt;10/20/2009 8:01:55 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 631740&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\$NtUninstallKB974112$\spuninst&lt;br /&gt;10/20/2009 8:00:49 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 688904&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\$NtUninstallKB974571$&lt;br /&gt;10/20/2009 8:00:49 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 631560&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\$NtUninstallKB974571$\spuninst&lt;br /&gt;10/20/2009 8:01:30 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 926204&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\$NtUninstallKB975025$&lt;br /&gt;10/20/2009 8:01:30 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 631292&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\$NtUninstallKB975025$\spuninst&lt;br /&gt;10/20/2009 7:51:06 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 765286&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\$NtUninstallKB975467$&lt;br /&gt;10/20/2009 7:51:06 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 631654&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\$NtUninstallKB975467$\spuninst&lt;br /&gt;10/24/2009 4:25:14 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 61541938&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\ERDNT&lt;br /&gt;10/24/2009 4:25:14 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 61541698&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\ERDNT\Hiv-backup&lt;br /&gt;10/24/2009 4:25:46 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 6643712&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\ERDNT\Hiv-backup\Users&lt;br /&gt;10/24/2009 4:25:46 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 237568&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\ERDNT\Hiv-backup\Users\00000001&lt;br /&gt;10/24/2009 4:25:46 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 8192&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\ERDNT\Hiv-backup\Users\00000002&lt;br /&gt;10/24/2009 4:25:46 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 237568&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\ERDNT\Hiv-backup\Users\00000003&lt;br /&gt;10/24/2009 4:25:46 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 8192&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\ERDNT\Hiv-backup\Users\00000004&lt;br /&gt;10/24/2009 4:25:46 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 5812224&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\ERDNT\Hiv-backup\Users\00000005&lt;br /&gt;10/24/2009 4:25:46 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 339968&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\ERDNT\Hiv-backup\Users\00000006&lt;br /&gt;8/25/2009 8:38:55 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 15367&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\cosawesoha._dl&lt;br /&gt;8/25/2009 8:38:55 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 14070&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\duhe._dl&lt;br /&gt;10/24/2009 4:25:26 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 80412&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\grep.exe&lt;br /&gt;9/12/2009 3:31:17 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 68940&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\hpoins05.dat&lt;br /&gt;9/12/2009 3:31:17 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 19696&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\hpomdl05.dat&lt;br /&gt;8/25/2009 8:38:55 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 15228&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\inoxiwymet.ban&lt;br /&gt;10/20/2009 8:17:57 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 8738&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\KB954155.log&lt;br /&gt;9/8/2009 10:13:57 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 7786&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\KB956844.log&lt;br /&gt;10/20/2009 8:18:29 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 6817&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\KB958869.log&lt;br /&gt;9/13/2009 1:33:33 AM&amp;nbsp;&amp;nbsp;&amp;nbsp; 19736&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\KB968389.log&lt;br /&gt;9/8/2009 10:13:50 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 6805&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\KB968816.log&lt;br /&gt;10/16/2009 10:21:57 AM&amp;nbsp;&amp;nbsp;&amp;nbsp; 13964&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\KB969059.log&lt;br /&gt;8/25/2009 7:11:12 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 3757&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\KB970653-v3.log&lt;br /&gt;10/20/2009 7:54:41 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 10097&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\KB971486.log&lt;br /&gt;9/8/2009 10:12:14 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 7756&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\KB971961-IE8.log&lt;br /&gt;10/20/2009 7:52:18 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 6936&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\KB973525.log&lt;br /&gt;10/16/2009 10:22:02 AM&amp;nbsp;&amp;nbsp;&amp;nbsp; 14107&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\KB974112.log&lt;br /&gt;10/21/2009 6:27:29 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 13424&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\KB974455-IE8.log&lt;br /&gt;10/16/2009 10:21:43 AM&amp;nbsp;&amp;nbsp;&amp;nbsp; 14518&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\KB974571.log&lt;br /&gt;10/16/2009 10:21:52 AM&amp;nbsp;&amp;nbsp;&amp;nbsp; 14070&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\KB975025.log&lt;br /&gt;10/16/2009 10:21:04 AM&amp;nbsp;&amp;nbsp;&amp;nbsp; 16245&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\KB975467.log&lt;br /&gt;10/24/2009 4:25:26 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 31232&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\NIRCMD.exe&lt;br /&gt;8/25/2009 8:38:55 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 19272&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\ovezydyz.dl&lt;br /&gt;10/24/2009 4:25:26 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 236544&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\PEV.exe&lt;br /&gt;10/24/2009 4:25:26 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 98816&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\sed.exe&lt;br /&gt;10/24/2009 4:25:26 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 161792&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\SWREG.exe&lt;br /&gt;10/24/2009 4:25:26 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 136704&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\SWSC.exe&lt;br /&gt;10/24/2009 4:25:26 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 212480&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\SWXCACLS.exe&lt;br /&gt;8/25/2009 8:38:55 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 19895&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\zibela._dl&lt;br /&gt;10/24/2009 4:25:26 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 68096&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\zip.exe&lt;br /&gt;10/16/2009 2:00:10 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 145408&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\system32\41-v5.exe&lt;br /&gt;9/12/2009 3:30:58 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 581632&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\system32\hpotscl.dll&lt;br /&gt;9/12/2009 3:30:58 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 229376&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\system32\hpovst08.dll&lt;br /&gt;9/12/2009 3:30:37 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 196608&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\system32\hpzcoi12.dll&lt;br /&gt;9/12/2009 3:30:38 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 393216&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\system32\hpzcon12.dll&lt;br /&gt;9/12/2009 3:30:39 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 139345&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\system32\hpzlnt12.dll&lt;br /&gt;9/24/2009 3:15:33 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\system32\ISHARE&lt;br /&gt;8/26/2009 4:15:37 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 17731&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\system32\jucaxyhu.lib&lt;br /&gt;9/5/2009 1:54:48 AM&amp;nbsp;&amp;nbsp;&amp;nbsp; 69632&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\system32\QuickTime.qts&lt;br /&gt;9/5/2009 1:54:48 AM&amp;nbsp;&amp;nbsp;&amp;nbsp; 94208&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\system32\QuickTimeVR.qtx&lt;br /&gt;8/25/2009 8:38:55 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 15521&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\system32\sydyji.exe&lt;br /&gt;8/25/2009 8:38:55 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 13811&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\WINDOWS\system32\ysuva.dat&lt;/p&gt;
&lt;p&gt;====== Files under &amp;quot;\Administrator\Startup&amp;quot; Last 60 Days======&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;====== Files under &amp;quot;\All Users\Startup&amp;quot; Last 60 Days======&lt;/p&gt;
&lt;p&gt;9/12/2009 3:41:24 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 1808&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk&lt;br /&gt;9/12/2009 3:47:15 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 798&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk&lt;/p&gt;
&lt;p&gt;====== Files and Folders under &amp;quot;\Program Files&amp;quot; Last 60 Days======&lt;/p&gt;
&lt;p&gt;10/8/2009 10:19:29 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 14932253&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Program Files\Auslogics&lt;br /&gt;10/12/2009 3:30:38 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Program Files\CS&lt;br /&gt;9/12/2009 3:40:32 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 4141261&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Program Files\Hewlett-Packard&lt;br /&gt;9/13/2009 1:56:30 AM&amp;nbsp;&amp;nbsp;&amp;nbsp; 112137144&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Program Files\iTunes&lt;/p&gt;
&lt;p&gt;====== Files under &amp;quot;\System32\Drivers&amp;quot; Last 60 Days======&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;====== Files Deleted under &amp;quot;%Temp%&amp;quot; ======&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;41 Files deleted&lt;/p&gt;
&lt;p&gt;====== Files and Folders under &amp;quot;All Users\Application Data&amp;quot; Last 60 Days======&lt;/p&gt;
&lt;p&gt;9/12/2009 3:48:10 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 2865&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Documents and Settings\All Users\Application Data\HP&lt;br /&gt;9/12/2009 3:48:10 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 2865&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Documents and Settings\All Users\Application Data\HP\Digital Imaging&lt;br /&gt;9/12/2009 3:48:10 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 2865&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Documents and Settings\All Users\Application Data\HP\Digital Imaging\Data&lt;br /&gt;9/13/2009 1:29:34 AM&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Documents and Settings\All Users\Application Data\HP\Digital Imaging\hp photosmart 2600 series&lt;br /&gt;9/13/2009 1:29:34 AM&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Documents and Settings\All Users\Application Data\HP\Digital Imaging\hp photosmart 2600 series\1252784891&lt;br /&gt;9/13/2009 1:29:34 AM&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Documents and Settings\All Users\Application Data\HP\Digital Imaging\hp photosmart 2600 series\1252784891\Data&lt;br /&gt;9/13/2009 1:56:30 AM&amp;nbsp;&amp;nbsp;&amp;nbsp; 541387&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}&lt;br /&gt;9/13/2009 1:58:46 AM&amp;nbsp;&amp;nbsp;&amp;nbsp; 541387&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}\x86&lt;br /&gt;9/13/2009 1:58:46 AM&amp;nbsp;&amp;nbsp;&amp;nbsp; 133968&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}\x86\x86&lt;br /&gt;8/25/2009 8:38:55 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 12868&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Documents and Settings\All Users\Application Data\gubokiby.dl&lt;br /&gt;8/25/2009 8:38:55 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 15299&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Documents and Settings\All Users\Application Data\igezicahun.ban&lt;br /&gt;8/25/2009 8:38:55 PM&amp;nbsp;&amp;nbsp;&amp;nbsp; 17063&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Documents and Settings\All Users\Application Data\tanyvo.db&lt;/p&gt;
&lt;p&gt;====== Values under HKLM\Software\microsoft\shared tools\msconfig\startupreg ======&lt;/p&gt;
&lt;p&gt;HKLM\Software\microsoft\shared tools\msconfig\startupreg\Ad-Watch&lt;br /&gt;HKLM\Software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader&lt;br /&gt;HKLM\Software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader&lt;br /&gt;HKLM\Software\microsoft\shared tools\msconfig\startupreg\CUCore Agent&lt;br /&gt;HKLM\Software\microsoft\shared tools\msconfig\startupreg\DellSupport&lt;br /&gt;HKLM\Software\microsoft\shared tools\msconfig\startupreg\dla&lt;br /&gt;HKLM\Software\microsoft\shared tools\msconfig\startupreg\DVDLauncher&lt;br /&gt;HKLM\Software\microsoft\shared tools\msconfig\startupreg\HP Component Manager&lt;br /&gt;HKLM\Software\microsoft\shared tools\msconfig\startupreg\HP Software Update&lt;br /&gt;HKLM\Software\microsoft\shared tools\msconfig\startupreg\IntelMeM&lt;br /&gt;HKLM\Software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup&lt;br /&gt;HKLM\Software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler&lt;br /&gt;HKLM\Software\microsoft\shared tools\msconfig\startupreg\iTunesHelper&lt;br /&gt;HKLM\Software\microsoft\shared tools\msconfig\startupreg\mmtask&lt;br /&gt;HKLM\Software\microsoft\shared tools\msconfig\startupreg\MMTray&lt;br /&gt;HKLM\Software\microsoft\shared tools\msconfig\startupreg\MSMSGS&lt;br /&gt;HKLM\Software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector&lt;br /&gt;HKLM\Software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck&lt;br /&gt;HKLM\Software\microsoft\shared tools\msconfig\startupreg\QBReminderFlash&lt;br /&gt;HKLM\Software\microsoft\shared tools\msconfig\startupreg\QuickTime Task&lt;br /&gt;HKLM\Software\microsoft\shared tools\msconfig\startupreg\RealTray&lt;br /&gt;HKLM\Software\microsoft\shared tools\msconfig\startupreg\Replay Center&lt;br /&gt;HKLM\Software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched&lt;br /&gt;HKLM\Software\microsoft\shared tools\msconfig\startupreg\swg&lt;br /&gt;HKLM\Software\microsoft\shared tools\msconfig\startupreg\TkBellExe&lt;/p&gt;
&lt;p&gt;====== Services ( Services that are Whitelisted are not shown) ======&lt;/p&gt;
&lt;p&gt;ASAPIW2k (ASAPIW2K)- C:\WINDOWS\system32\drivers\ASAPIW2k.sys - Manual/Running&lt;br /&gt;Avc (AVC Device)- C:\WINDOWS\system32\DRIVERS\avc.sys - Manual/Stopped&lt;br /&gt;bvrp_pci (bvrp_pci)-&amp;nbsp; - Manual/Stopped&lt;br /&gt;drvmcdb (drvmcdb)- C:\WINDOWS\system32\drivers\drvmcdb.sys - Boot/Running&lt;br /&gt;drvnddm (drvnddm)- C:\WINDOWS\system32\drivers\drvnddm.sys - Auto/Running&lt;br /&gt;DSproct (DSproct)- \??\C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys - Manual/Stopped&lt;br /&gt;dsunidrv (DellSupport UniDriver)- C:\WINDOWS\system32\DRIVERS\dsunidrv.sys - Auto/Running&lt;br /&gt;E100B (Intel(R) PRO Adapter Driver)- C:\WINDOWS\system32\DRIVERS\e100b325.sys - Manual/Running&lt;br /&gt;eeCtrl (Symantec Eraser Control driver)- \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys - System/Running&lt;br /&gt;FANTOM (LEGO MINDSTORMS NXT Driver)- C:\WINDOWS\system32\DRIVERS\fantom.sys - Manual/Stopped&lt;br /&gt;FTD2XX (FTD2XX.SYS FT8U2XX device driver)- C:\WINDOWS\system32\Drivers\FTD2XX.sys - Manual/Stopped&lt;br /&gt;grmnusb (grmnusb)- C:\WINDOWS\system32\drivers\grmnusb.sys - Manual/Stopped&lt;br /&gt;Hardlock (Hardlock)- \??\C:\WINDOWS\system32\drivers\hardlock.sys - Auto/Running&lt;br /&gt;Haspnt (Haspnt)- \??\C:\WINDOWS\system32\drivers\Haspnt.sys - Auto/Running&lt;br /&gt;IntelC51 (IntelC51)- C:\WINDOWS\system32\DRIVERS\IntelC51.sys - Manual/Running&lt;br /&gt;IntelC52 (IntelC52)- C:\WINDOWS\system32\DRIVERS\IntelC52.sys - Manual/Running&lt;br /&gt;IntelC53 (IntelC53)- C:\WINDOWS\system32\DRIVERS\IntelC53.sys - Manual/Running&lt;br /&gt;Lbd (Lbd)- C:\WINDOWS\system32\DRIVERS\Lbd.sys - Boot/Running&lt;br /&gt;MarvinBus (Pinnacle Marvin Bus)- C:\WINDOWS\system32\DRIVERS\MarvinBus.sys - Manual/Running&lt;br /&gt;MCSTRM (MCSTRM)-&amp;nbsp; - Auto/Stopped&lt;br /&gt;mohfilt (mohfilt)- C:\WINDOWS\system32\DRIVERS\mohfilt.sys - Manual/Running&lt;br /&gt;MSDV (Microsoft DV Camera and VCR)- C:\WINDOWS\system32\DRIVERS\msdv.sys - Manual/Stopped&lt;br /&gt;NdisIP (Microsoft TV/Video Connection)- C:\WINDOWS\system32\DRIVERS\NdisIP.sys - Manual/Stopped&lt;br /&gt;PCLEPCI (PCLEPCI)- \??\C:\WINDOWS\system32\drivers\pclepci.sys - System/Running&lt;br /&gt;RioS50 (RioS50 driver)- C:\WINDOWS\system32\Drivers\RioS50.sys - Manual/Stopped&lt;br /&gt;senfilt (senfilt)- C:\WINDOWS\system32\drivers\senfilt.sys - Manual/Running&lt;br /&gt;SLIP (BDA Slip De-Framer)- C:\WINDOWS\system32\DRIVERS\SLIP.sys - Manual/Stopped&lt;br /&gt;smwdm (smwdm)- C:\WINDOWS\system32\drivers\smwdm.sys - Manual/Running&lt;br /&gt;sscdbhk5 (sscdbhk5)- C:\WINDOWS\system32\drivers\sscdbhk5.sys - System/Running&lt;br /&gt;ssrtln (ssrtln)- C:\WINDOWS\system32\drivers\ssrtln.sys - System/Running&lt;br /&gt;tfsnboio (tfsnboio)- C:\WINDOWS\system32\dla\tfsnboio.sys - Auto/Running&lt;br /&gt;tfsncofs (tfsncofs)- C:\WINDOWS\system32\dla\tfsncofs.sys - Auto/Running&lt;br /&gt;tfsndrct (tfsndrct)- C:\WINDOWS\system32\dla\tfsndrct.sys - Auto/Running&lt;br /&gt;tfsndres (tfsndres)- C:\WINDOWS\system32\dla\tfsndres.sys - Auto/Running&lt;br /&gt;tfsnifs (tfsnifs)- C:\WINDOWS\system32\dla\tfsnifs.sys - Auto/Running&lt;br /&gt;tfsnopio (tfsnopio)- C:\WINDOWS\system32\dla\tfsnopio.sys - Auto/Running&lt;br /&gt;tfsnpool (tfsnpool)- C:\WINDOWS\system32\dla\tfsnpool.sys - Auto/Running&lt;br /&gt;tfsnudf (tfsnudf)- C:\WINDOWS\system32\dla\tfsnudf.sys - Auto/Running&lt;br /&gt;tfsnudfa (tfsnudfa)- C:\WINDOWS\system32\dla\tfsnudfa.sys - Auto/Running&lt;br /&gt;USBAAPL (Apple Mobile USB Driver)- C:\WINDOWS\system32\Drivers\usbaapl.sys - Manual/Stopped&lt;br /&gt;wanatw (WAN Miniport (ATW))- C:\WINDOWS\system32\DRIVERS\wanatw4.sys - Manual/Stopped&lt;br /&gt;WpdUsb (WpdUsb)- C:\WINDOWS\system32\Drivers\wpdusb.sys - Manual/Stopped&lt;/p&gt;
&lt;p&gt;====== Uninstall List ======&lt;/p&gt;
&lt;p&gt;OTOY&lt;br /&gt;WebEx&lt;br /&gt;Ad-Aware&lt;br /&gt;Adobe Flash Player 10 ActiveX&lt;br /&gt;Audacity 1.2.6&lt;br /&gt;Audible Download Manager&lt;br /&gt;Backyard Baseball 2003&lt;br /&gt;Carbonite&lt;br /&gt;chundate ScreenSaver&lt;br /&gt;Focus MP3 Recorder Pro 3.4&lt;br /&gt;FTDI FTD2XX USB Drivers&lt;br /&gt;Game Maker 7.0&lt;br /&gt;Garfield 25th Anniversary Screen Saver&lt;br /&gt;HASP4 Device Drivers&lt;br /&gt;HijackThis 2.0.2&lt;br /&gt;Hollywood FX 5.5 Additional Effects&lt;br /&gt;Pinnacle Hollywood FX for Studio&lt;br /&gt;HP Image Zone 4.7&lt;br /&gt;HP Extended Capabilities 4.7&lt;br /&gt;Microsoft Internationalized Domain Names Mitigation APIs&lt;br /&gt;Windows Internet Explorer 7&lt;br /&gt;Windows Internet Explorer 8&lt;br /&gt;iPod for Windows 2006-03-23&lt;br /&gt;SmartSound Quicktracks Plugin&lt;br /&gt;DesignPro 5.0 Limited Edition&lt;br /&gt;iPod for Windows 2005-09-23&lt;br /&gt;Chessmaster 10th Edition&lt;br /&gt;Intel(R) 537EP V9x DF PCI Modem&lt;br /&gt;Windows XP Hotfix - KB867282&lt;br /&gt;Windows XP Hotfix - KB873333&lt;br /&gt;Security Update for Windows XP (KB883939)&lt;br /&gt;Windows XP Hotfix - KB885836&lt;br /&gt;Windows XP Hotfix - KB885884&lt;br /&gt;Windows XP Hotfix - KB886185&lt;br /&gt;Windows XP Hotfix - KB887742&lt;br /&gt;Windows XP Hotfix - KB888302&lt;br /&gt;Security Update for Windows XP (KB890046)&lt;br /&gt;Windows XP Hotfix - KB890859&lt;br /&gt;Security Update for Windows XP (KB893066)&lt;br /&gt;Windows XP Hotfix - KB893086&lt;br /&gt;Security Update for Windows XP (KB893756)&lt;br /&gt;Windows Installer 3.1 (KB893803)&lt;br /&gt;Update for Windows XP (KB894391)&lt;br /&gt;Security Update for Windows XP (KB896358)&lt;br /&gt;Security Update for Windows XP (KB896422)&lt;br /&gt;Security Update for Windows XP (KB896423)&lt;br /&gt;Security Update for Windows XP (KB896424)&lt;br /&gt;Security Update for Windows XP (KB896428)&lt;br /&gt;Security Update for Windows XP (KB896688)&lt;br /&gt;Update for Windows XP (KB896727)&lt;br /&gt;Security Update for Step By Step Interactive Training (KB898458)&lt;br /&gt;Update for Windows XP (KB898461)&lt;br /&gt;Security Update for Windows XP (KB899587)&lt;br /&gt;Security Update for Windows XP (KB899588)&lt;br /&gt;Security Update for Windows XP (KB899591)&lt;br /&gt;Update for Windows XP (KB900485)&lt;br /&gt;Security Update for Windows XP (KB900725)&lt;br /&gt;Security Update for Windows XP (KB901017)&lt;br /&gt;Security Update for Windows XP (KB901214)&lt;br /&gt;Security Update for Windows XP (KB902400)&lt;br /&gt;Security Update for Windows XP (KB903235)&lt;br /&gt;Security Update for Windows XP (KB904706)&lt;br /&gt;Update for Windows XP (KB904942)&lt;br /&gt;Security Update for Windows XP (KB905414)&lt;br /&gt;Security Update for Windows XP (KB905749)&lt;br /&gt;Security Update for Windows XP (KB905915)&lt;br /&gt;Security Update for Windows XP (KB908519)&lt;br /&gt;Security Update for Windows XP (KB908531)&lt;br /&gt;Update for Windows XP (KB910437)&lt;br /&gt;Security Update for Windows XP (KB911280)&lt;br /&gt;Security Update for Windows XP (KB911562)&lt;br /&gt;Security Update for Windows Media Player (KB911564)&lt;br /&gt;Security Update for Windows Media Player 10 (KB911565)&lt;br /&gt;Security Update for Windows XP (KB911567)&lt;br /&gt;Security Update for Windows XP (KB911927)&lt;br /&gt;Security Update for Windows XP (KB912812)&lt;br /&gt;Security Update for Windows XP (KB912919)&lt;br /&gt;Security Update for Windows XP (KB913446)&lt;br /&gt;Security Update for Windows XP (KB913580)&lt;br /&gt;Security Update for Windows XP (KB914388)&lt;br /&gt;Security Update for Windows XP (KB914389)&lt;br /&gt;Hotfix for Windows XP (KB914440)&lt;br /&gt;Hotfix for Windows XP (KB915865)&lt;br /&gt;Security Update for Windows XP (KB916281)&lt;br /&gt;Update for Windows XP (KB916595)&lt;br /&gt;Security Update for Windows XP (KB917159)&lt;br /&gt;Security Update for Windows XP (KB917344)&lt;br /&gt;Security Update for Windows XP (KB917422)&lt;br /&gt;Security Update for Windows Media Player 10 (KB917734)&lt;br /&gt;Security Update for Windows XP (KB917953)&lt;br /&gt;Security Update for Windows XP (KB918118)&lt;br /&gt;Security Update for Windows XP (KB918439)&lt;br /&gt;Security Update for Windows XP (KB918899)&lt;br /&gt;Security Update for Windows XP (KB919007)&lt;br /&gt;Security Update for Windows XP (KB920213)&lt;br /&gt;Security Update for Windows XP (KB920214)&lt;br /&gt;Security Update for Windows XP (KB920670)&lt;br /&gt;Security Update for Windows XP (KB920683)&lt;br /&gt;Security Update for Windows XP (KB920685)&lt;br /&gt;Update for Windows XP (KB920872)&lt;br /&gt;Security Update for Windows XP (KB921398)&lt;br /&gt;Security Update for Windows XP (KB921503)&lt;br /&gt;Security Update for Windows XP (KB921883)&lt;br /&gt;Update for Windows XP (KB922582)&lt;br /&gt;Security Update for Windows XP (KB922616)&lt;br /&gt;Security Update for Windows XP (KB922760)&lt;br /&gt;Security Update for Windows XP (KB922819)&lt;br /&gt;Security Update for Windows XP (KB923191)&lt;br /&gt;Security Update for Windows XP (KB923414)&lt;br /&gt;Security Update for Windows XP (KB923561)&lt;br /&gt;Security Update for Windows XP (KB923689)&lt;br /&gt;Security Update for Windows XP (KB923694)&lt;br /&gt;Security Update for Step By Step Interactive Training (KB923723)&lt;br /&gt;Security Update for Windows XP (KB923980)&lt;br /&gt;Security Update for Windows XP (KB924191)&lt;br /&gt;Security Update for Windows XP (KB924270)&lt;br /&gt;Security Update for Windows XP (KB924496)&lt;br /&gt;Security Update for Windows XP (KB924667)&lt;br /&gt;Security Update for Windows Media Player 6.4 (KB925398)&lt;br /&gt;Security Update for Windows XP (KB925454)&lt;br /&gt;Security Update for Windows XP (KB925486)&lt;br /&gt;Update for Windows XP (KB925720)&lt;br /&gt;Security Update for Windows XP (KB925902)&lt;br /&gt;Security Update for Windows XP (KB926255)&lt;br /&gt;Security Update for Windows XP (KB926436)&lt;br /&gt;Security Update for Windows XP (KB927779)&lt;br /&gt;Security Update for Windows XP (KB927802)&lt;br /&gt;Update for Windows XP (KB927891)&lt;br /&gt;Security Update for Windows XP (KB928090)&lt;br /&gt;Security Update for Windows XP (KB928255)&lt;br /&gt;Security Update for Windows XP (KB928843)&lt;br /&gt;Security Update for Windows XP (KB929123)&lt;br /&gt;Update for Windows XP (KB929338)&lt;br /&gt;Security Update for Windows XP (KB929969)&lt;br /&gt;Security Update for Windows XP (KB930178)&lt;br /&gt;Update for Windows XP (KB930916)&lt;br /&gt;Security Update for Windows XP (KB931261)&lt;br /&gt;Security Update for Windows XP (KB931768)&lt;br /&gt;Security Update for Windows XP (KB931784)&lt;br /&gt;Update for Windows XP (KB931836)&lt;br /&gt;Security Update for Windows XP (KB932168)&lt;br /&gt;Update for Windows XP (KB932823-v3)&lt;br /&gt;Update for Windows XP (KB933360)&lt;br /&gt;Security Update for Windows XP (KB933566)&lt;br /&gt;Security Update for Windows XP (KB933729)&lt;br /&gt;Security Update for Windows XP (KB935839)&lt;br /&gt;Security Update for Windows XP (KB935840)&lt;br /&gt;Security Update for Windows XP (KB936021)&lt;br /&gt;Update for Windows XP (KB936357)&lt;br /&gt;Security Update for Windows Media Player 10 (KB936782)&lt;br /&gt;Security Update for Windows XP (KB937143)&lt;br /&gt;Security Update for Windows XP (KB938127)&lt;br /&gt;Security Update for Windows Internet Explorer 7 (KB938127)&lt;br /&gt;Security Update for Windows XP (KB938464)&lt;br /&gt;Update for Windows XP (KB938828)&lt;br /&gt;Security Update for Windows XP (KB938829)&lt;br /&gt;Security Update for Windows XP (KB939653)&lt;br /&gt;Security Update for Windows Internet Explorer 7 (KB939653)&lt;br /&gt;Security Update for Windows XP (KB941202)&lt;br /&gt;Security Update for Windows XP (KB941568)&lt;br /&gt;Security Update for Windows XP (KB941569)&lt;br /&gt;Security Update for Windows XP (KB941644)&lt;br /&gt;Security Update for Windows XP (KB941693)&lt;br /&gt;Security Update for Windows Internet Explorer 7 (KB942615)&lt;br /&gt;Update for Windows XP (KB942763)&lt;br /&gt;Security Update for Windows XP (KB943055)&lt;br /&gt;Security Update for Windows XP (KB943460)&lt;br /&gt;Security Update for Windows XP (KB943485)&lt;br /&gt;Security Update for Windows Internet Explorer 7 (KB944533)&lt;br /&gt;Security Update for Windows XP (KB944653)&lt;br /&gt;Security Update for Windows XP (KB945553)&lt;br /&gt;Security Update for Windows XP (KB946026)&lt;br /&gt;Security Update for Windows XP (KB946648)&lt;br /&gt;Hotfix for Windows Internet Explorer 7 (KB947864)&lt;br /&gt;Security Update for Windows XP (KB948590)&lt;br /&gt;Security Update for Windows XP (KB948881)&lt;br /&gt;Security Update for Windows XP (KB950749)&lt;br /&gt;Security Update for Windows Internet Explorer 7 (KB950759)&lt;br /&gt;Security Update for Windows XP (KB950760)&lt;br /&gt;Security Update for Windows XP (KB950762)&lt;br /&gt;Security Update for Windows XP (KB950974)&lt;br /&gt;Security Update for Windows XP (KB951066)&lt;br /&gt;Update for Windows XP (KB951072-v2)&lt;br /&gt;Security Update for Windows XP (KB951376)&lt;br /&gt;Security Update for Windows XP (KB951376-v2)&lt;br /&gt;Security Update for Windows XP (KB951698)&lt;br /&gt;Security Update for Windows XP (KB951748)&lt;br /&gt;Security Update for Windows XP (KB952004)&lt;br /&gt;Security Update for Windows Media Player (KB952069)&lt;br /&gt;Hotfix for Windows XP (KB952287)&lt;br /&gt;Security Update for Windows XP (KB952954)&lt;br /&gt;Security Update for Windows Internet Explorer 7 (KB953838)&lt;br /&gt;Security Update for Windows XP (KB953839)&lt;br /&gt;Security Update for Windows Media Player (KB954155)&lt;br /&gt;Security Update for Windows XP (KB954211)&lt;br /&gt;Security Update for Windows XP (KB954600)&lt;br /&gt;Security Update for Windows XP (KB955069)&lt;br /&gt;Update for Windows XP (KB955839)&lt;br /&gt;Security Update for Windows Internet Explorer 7 (KB956390)&lt;br /&gt;Security Update for Windows XP (KB956391)&lt;br /&gt;Security Update for Windows XP (KB956572)&lt;br /&gt;Security Update for Windows XP (KB956802)&lt;br /&gt;Security Update for Windows XP (KB956803)&lt;br /&gt;Security Update for Windows XP (KB956841)&lt;br /&gt;Security Update for Windows XP (KB956844)&lt;br /&gt;Security Update for Windows XP (KB957095)&lt;br /&gt;Security Update for Windows XP (KB957097)&lt;br /&gt;Security Update for Windows Internet Explorer 7 (KB958215)&lt;br /&gt;Security Update for Windows XP (KB958470)&lt;br /&gt;Security Update for Windows XP (KB958644)&lt;br /&gt;Security Update for Windows XP (KB958687)&lt;br /&gt;Security Update for Windows XP (KB958690)&lt;br /&gt;Security Update for Windows XP (KB958869)&lt;br /&gt;Security Update for Windows XP (KB959426)&lt;br /&gt;Security Update for Windows XP (KB960225)&lt;br /&gt;Security Update for Windows Internet Explorer 7 (KB960714)&lt;br /&gt;Security Update for Windows XP (KB960715)&lt;br /&gt;Security Update for Windows XP (KB960803)&lt;br /&gt;Security Update for Windows XP (KB960859)&lt;br /&gt;Hotfix for Windows XP (KB961118)&lt;br /&gt;Security Update for Windows Internet Explorer 7 (KB961260)&lt;br /&gt;Security Update for Windows XP (KB961371)&lt;br /&gt;Security Update for Windows XP (KB961373)&lt;br /&gt;Security Update for Windows XP (KB961501)&lt;br /&gt;Security Update for Windows Internet Explorer 7 (KB963027)&lt;br /&gt;Update for Windows XP (KB967715)&lt;br /&gt;Update for Windows XP (KB968389)&lt;br /&gt;Security Update for Windows XP (KB968537)&lt;br /&gt;Security Update for Windows Media Player (KB968816)&lt;br /&gt;Security Update for Windows XP (KB969059)&lt;br /&gt;Security Update for Windows Internet Explorer 7 (KB969897)&lt;br /&gt;Security Update for Windows Internet Explorer 8 (KB969897)&lt;br /&gt;Security Update for Windows XP (KB969898)&lt;br /&gt;Security Update for Windows XP (KB970238)&lt;br /&gt;Hotfix for Windows XP (KB970653-v3)&lt;br /&gt;Security Update for Windows XP (KB971486)&lt;br /&gt;Security Update for Windows XP (KB971557)&lt;br /&gt;Security Update for Windows XP (KB971633)&lt;br /&gt;Security Update for Windows XP (KB971657)&lt;br /&gt;Update for Windows Internet Explorer 8 (KB971930)&lt;br /&gt;Security Update for Windows Internet Explorer 8 (KB971961)&lt;br /&gt;Security Update for Windows Internet Explorer 8 (KB972260)&lt;br /&gt;Security Update for Windows XP (KB973346)&lt;br /&gt;Security Update for Windows XP (KB973354)&lt;br /&gt;Security Update for Windows XP (KB973507)&lt;br /&gt;Security Update for Windows XP (KB973525)&lt;br /&gt;Security Update for Windows Media Player (KB973540)&lt;br /&gt;Update for Windows XP (KB973815)&lt;br /&gt;Security Update for Windows XP (KB973869)&lt;br /&gt;Security Update for Windows XP (KB974112)&lt;br /&gt;Security Update for Windows Internet Explorer 8 (KB974455)&lt;br /&gt;Security Update for Windows XP (KB974571)&lt;br /&gt;Security Update for Windows XP (KB975025)&lt;br /&gt;Security Update for Windows XP (KB975467)&lt;br /&gt;Kid Pix Studio Deluxe&lt;br /&gt;Life of Christ&lt;br /&gt;LiveUpdate 3.1 (Symantec Corporation)&lt;br /&gt;Microsoft .NET Framework 1.1 Security Update (KB953297)&lt;br /&gt;Macromedia Shockwave Player&lt;br /&gt;Magic Music Editor v5.3.12.1&lt;br /&gt;Malwarebytes&amp;#39; Anti-Malware&lt;br /&gt;Microsoft .NET Framework 1.1&lt;br /&gt;Microsoft .NET Framework 3.5 SP1&lt;br /&gt;My Way Search Assistant&lt;br /&gt;NetStudio Easy Web Graphics&lt;br /&gt;Microsoft National Language Support Downlevel APIs&lt;br /&gt;Operation&lt;br /&gt;Photo Finale&lt;br /&gt;Picasa 3&lt;br /&gt;PolderbitS Sound Recorder and Editor&lt;br /&gt;proDAD Heroglyph 1.0&lt;br /&gt;Intel(R) PRO Network Adapters and Drivers&lt;br /&gt;Radiotracker 3.0.1.37&lt;br /&gt;RealPlayer&lt;br /&gt;rwss Screen Saver&lt;br /&gt;screensaver&lt;br /&gt;skiStunt&lt;br /&gt;SSH2Deluxe&amp;nbsp; Screen Saver&lt;br /&gt;Learn2 Player (Uninstall Only)&lt;br /&gt;Tax Forms Assistant&lt;br /&gt;Tax Forms Helper 2004 6.5&lt;br /&gt;Tax Forms Helper 2006 7.5&lt;br /&gt;Tax Forms Helper 2008 8.5&lt;br /&gt;The Game Of Life&lt;br /&gt;TI-84 Plus Dreams Screen Saver&lt;br /&gt;TurboTax 2008&lt;br /&gt;TurboTax Deluxe 2005&lt;br /&gt;TurboTax Deluxe 2007&lt;br /&gt;TurboTax Deluxe Deduction Maximizer 2006&lt;br /&gt;Type To Learn&lt;br /&gt;V CAST Music with Rhapsody&lt;br /&gt;VeggieTalesJonah&lt;br /&gt;Viewpoint Media Player&lt;br /&gt;Where in the USA is Carmen Sandiego?&lt;br /&gt;Where in the USA is Carmen Sandiego?&lt;br /&gt;Windows Imaging Component&lt;br /&gt;Windows Media Format Runtime&lt;br /&gt;Windows Media Player 10&lt;br /&gt;WinPcap 3.1 beta4&lt;br /&gt;World Book Illustrated Atlas&lt;br /&gt;Yahoo! Toolbar&lt;br /&gt;Zoombinis Logical Journey(TM)&lt;br /&gt;Microsoft Office 2000 SR-1 Small Business&lt;br /&gt;Microsoft Office 2000 SR-1 Disc 2&lt;br /&gt;Macromedia Flash Player&lt;br /&gt;Bonjour&lt;br /&gt;Sonic RecordNow Data&lt;br /&gt;Apple Application Support&lt;br /&gt;Scan&lt;br /&gt;Microsoft Plus! Photo Story 2 LE&lt;br /&gt;MyLearnExpress&lt;br /&gt;Sonic DLA&lt;br /&gt;SA23xx Device Manager&lt;br /&gt;ScannerCopy&lt;br /&gt;HP Product Assistant&lt;br /&gt;Intel(R) PROSet for Wired Connections&lt;br /&gt;Fax&lt;br /&gt;Google Toolbar for Internet Explorer&lt;br /&gt;MSXML 6 Service Pack 2 (KB954459)&lt;br /&gt;InstantShare&lt;br /&gt;Copy&lt;br /&gt;Click to Meet Conference Client&lt;br /&gt;iPod for Windows 2006-03-23&lt;br /&gt;TrayApp&lt;br /&gt;Sonic MyDVD LE&lt;br /&gt;Maestro ActivityMaker&lt;br /&gt;Google Toolbar for Internet Explorer&lt;br /&gt;Java(TM) 6 Update 13&lt;br /&gt;cp_dwShrek2Albums1&lt;br /&gt;TurboTax 2008 WinPerUserEducation&lt;br /&gt;TurboTax ItsDeductible 2005&lt;br /&gt;Unload&lt;br /&gt;Sonic Update Manager&lt;br /&gt;Java(TM) 6 Update 7&lt;br /&gt;Windows Media Player 10&lt;br /&gt;HP PSC &amp;amp; OfficeJet 4.7&lt;br /&gt;WebFldrs XP&lt;br /&gt;NetZeroInstallers&lt;br /&gt;Internet Explorer Default Page&lt;br /&gt;TurningPoint 2008&lt;br /&gt;MSXML 4.0 SP2 (KB927978)&lt;br /&gt;CueTour&lt;br /&gt;MyLearnExpress&lt;br /&gt;ProductContext&lt;br /&gt;LEGO&amp;reg; MINDSTORMS&amp;reg; NXT - English Language Pack&lt;br /&gt;Modem On Hold&lt;br /&gt;ChessBase 9&lt;br /&gt;Google Earth&lt;br /&gt;Jasc Paint Shop Photo Album 5&lt;br /&gt;LEGO&amp;reg; MINDSTORMS&amp;reg; NXT Software v1.0&lt;br /&gt;Readme&lt;br /&gt;Math&lt;br /&gt;2600&lt;br /&gt;SmartSound Quicktracks Plugin&lt;br /&gt;Sonic CinePlayer MP3 Creation Pack&lt;br /&gt;Safari&lt;br /&gt;Dell Driver Reset Tool&lt;br /&gt;PanoStandAlone&lt;br /&gt;AOLIcon&lt;br /&gt;CreativeProjects&lt;br /&gt;PhotoGallery&lt;br /&gt;HP Software Update&lt;br /&gt;AiO_Scan&lt;br /&gt;PowerDVD 5.5&lt;br /&gt;Destinations&lt;br /&gt;Apple Software Update&lt;br /&gt;Photo Click&lt;br /&gt;Microsoft Plus! Digital Media Edition Installer&lt;br /&gt;2600Trb&lt;br /&gt;BufferChm&lt;br /&gt;cp_dwShrek2Cards1&lt;br /&gt;EarthLink setup files&lt;br /&gt;TurboTax 2008 WinPerFedFormset&lt;br /&gt;Jasc Paint Shop Pro Studio, Dell Editon&lt;br /&gt;My Way Search Assistant&lt;br /&gt;Modem Event Monitor&lt;br /&gt;Get High Speed Internet!&lt;br /&gt;HPSystemDiagnostics&lt;br /&gt;Harry Potter II&lt;br /&gt;AnswerWorks 4.0 Runtime - English&lt;br /&gt;DellSupport&lt;br /&gt;Modem Helper&lt;br /&gt;e-Sword&lt;br /&gt;DING!&lt;br /&gt;SkinsHP1&lt;br /&gt;Fall of Jericho&lt;br /&gt;AiOSoftware&lt;br /&gt;MSXML 4.0 SP2 (KB954430)&lt;br /&gt;Ten Thumbs 4.3.1&lt;br /&gt;QFolder&lt;br /&gt;TurboTax 2008 WinPerReleaseEngine&lt;br /&gt;Intel(R) Extreme Graphics 2 Driver&lt;br /&gt;DocProc&lt;br /&gt;Auslogics Registry Cleaner&lt;br /&gt;Musicmatch&amp;reg; Jukebox&lt;br /&gt;Compatibility Pack for the 2007 Office system&lt;br /&gt;Microsoft FrontPage 2002&lt;br /&gt;Microsoft PowerPoint 2002&lt;br /&gt;e-Sword&lt;br /&gt;DesignPro 5.0 Limited Edition&lt;br /&gt;QuickProjects&lt;br /&gt;Rio Music Manager&lt;br /&gt;Studio 9&lt;br /&gt;PrintScreen&lt;br /&gt;Microsoft .NET Framework 3.0 Service Pack 2&lt;br /&gt;QuickTime&lt;br /&gt;CP_AtenaShokunin1Config&lt;br /&gt;Apple Mobile Device Support&lt;br /&gt;Sonic RecordNow Audio&lt;br /&gt;Dell Media Experience&lt;br /&gt;Adobe Reader 7.0&lt;br /&gt;Garfield Desktop Comic&lt;br /&gt;Dell Picture Studio v3.0&lt;br /&gt;WordPerfect Office 12&lt;br /&gt;TurboTax 2008 wohiper&lt;br /&gt;TurboTax ItsDeductible 2006&lt;br /&gt;Sonic RecordNow Copy&lt;br /&gt;TurboTax 2008 wrapper&lt;br /&gt;TurboTax 2008 WinPerTaxSupport&lt;br /&gt;SONICblue Real Service Providers&lt;br /&gt;Studio 9 Content CD/DVD&lt;br /&gt;Director&lt;br /&gt;MarketResearch&lt;br /&gt;e-Sword Bible Screen Saver&lt;br /&gt;Harry Potter - Quidditch World Cup&lt;br /&gt;MSXML 4.0 SP2 (KB936181)&lt;br /&gt;Microsoft .NET Framework 2.0 Service Pack 2&lt;br /&gt;2600_Help&lt;br /&gt;Microsoft .NET Framework 1.1&lt;br /&gt;WebReg&lt;br /&gt;DocumentViewer&lt;br /&gt;Microsoft .NET Framework 3.5 SP1&lt;br /&gt;Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)&lt;br /&gt;Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)&lt;br /&gt;Update for Microsoft .NET Framework 3.5 SP1 (KB963707)&lt;br /&gt;The Incredibles: Rise of The Underminer&lt;br /&gt;iPod for Windows 2005-09-23&lt;br /&gt;LiveUpdate Notice (Symantec Corporation)&lt;br /&gt;AnswerWorks 5.0 English Runtime&lt;br /&gt;TWC User Controls&lt;br /&gt;Ad-Aware&lt;br /&gt;Auslogics Disk Defrag&lt;br /&gt;LEGO&amp;reg; MINDSTORMS&amp;reg; NXT Driver&lt;br /&gt;Google SketchUp Viewer&lt;br /&gt;The Incredibles - When Danger Calls&lt;br /&gt;TurboTax 2008 WinPerProgramHelp&lt;br /&gt;Chessmaster 10th Edition&lt;br /&gt;WexTech AnswerWorks&lt;br /&gt;iTunes&lt;br /&gt;Maestro ActivityMaker&lt;br /&gt;Quicken 2009&lt;br /&gt;Visual C++ 2008 x86 Runtime - (v9.0.30729)&lt;br /&gt;Visual C++ 2008 x86 Runtime - v9.0.30729.01&lt;br /&gt;Social Studies and Science&lt;br /&gt;Garmin Communicator Plugin&lt;br /&gt;CreativeProjectsTemplates&lt;/p&gt;
&lt;p&gt;======== Other Info ========&lt;/p&gt;
&lt;p&gt;TOTAL PHYSICAL RAM: 535 MB&lt;/p&gt;
&lt;p&gt;Boot Info&lt;/p&gt;
&lt;p&gt;[boot loader]&lt;br /&gt;timeout=30&lt;br /&gt;default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS&lt;br /&gt;[operating systems]&lt;br /&gt;multi(0)disk(0)rdisk(0)partition(2)\WINDOWS=&amp;quot;Microsoft Windows XP Home Edition&amp;quot; /noexecute=optin /fastdetect&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;OS Type:&amp;nbsp; Microsoft Windows XP Home Edition&lt;br /&gt;Build:&amp;nbsp; 5.1.2600&lt;br /&gt;Service Pack:&amp;nbsp; 2.0&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;====== Files with Hidden Attributes======&lt;/p&gt;
&lt;p&gt;C:\hiberfil.sys&lt;br /&gt;C:\IO.SYS&lt;br /&gt;C:\MSDOS.SYS&lt;br /&gt;C:\pagefile.sys&lt;br /&gt;C:\NTDETECT.COM&lt;br /&gt;C:\Documents and Settings\Administrator\NTUSER.DAT&lt;br /&gt;C:\Documents and Settings\Administrator\IECompatCache\index.dat&lt;br /&gt;C:\Documents and Settings\Administrator\IETldCache\index.dat&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012009081020090817\index.dat&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012009081720090824\index.dat&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012009082620090827\index.dat&lt;br /&gt;C:\Documents and Settings\Administrator\PrivacIE\index.dat&lt;/p&gt;
&lt;p&gt;==End of Report==&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Dell Dimension E521- a lot pop up windows and super slow performance - to a point -practically not usable</title><link>http://en.community.dell.com/forums/thread/19585000.aspx</link><pubDate>Sun, 08 Nov 2009 18:04:17 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19585000</guid><dc:creator>fww013</dc:creator><slash:comments>3</slash:comments><comments>http://en.community.dell.com/forums/thread/19585000.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19585000</wfw:commentRss><description>&lt;p&gt;Hi, there,&lt;/p&gt;
&lt;p&gt;Would appreciate experts here to give me some guidance.&lt;/p&gt;
&lt;p&gt;I use McAfee for anti -virus. The computer worked well for a couple of years, But recently McAfee shows it detected &amp;quot;vundo.gen.cb( trojan)&amp;quot; but McAffee could not fix it. Here is the copy of hijackthis log file:&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;/p&gt;
&lt;p&gt;Scan saved at 11:42:37 AM, on 11/8/2009&lt;/p&gt;
&lt;p&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;/p&gt;
&lt;p&gt;MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)&lt;/p&gt;
&lt;p&gt;Boot mode: Normal&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Running processes:&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\System32\smss.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\winlogon.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\services.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\lsass.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\svchost.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\System32\svchost.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\spoolsv.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\McAfee\SiteAdvisor\McSACore.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Common Files\Motive\McciCMService.exe&lt;/p&gt;
&lt;p&gt;C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe&lt;/p&gt;
&lt;p&gt;c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\java.exe&lt;/p&gt;
&lt;p&gt;c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\McAfee\MPF\MPFSrv.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\nvsvc32.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\PSIService.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\svchost.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\Explorer.EXE&lt;/p&gt;
&lt;p&gt;c:\PROGRA~1\mcafee.com\agent\mcagent.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\System32\svchost.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\ctfmon.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\RUNDLL32.EXE&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\stsystra.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&lt;/p&gt;
&lt;p&gt;C:\Documents and Settings\Winnie.WINNIE-E521\Local Settings\Application Data\Google\Chrome\Application\chrome.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Canon\MyPrinter\BJMyPrt.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Google\Google Pinyin 2\GooglePinyinDaemon.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe&lt;/p&gt;
&lt;p&gt;c:\PROGRA~1\mcafee\msc\mcshell.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\WinZIP\WZQKPICK.EXE&lt;/p&gt;
&lt;p&gt;C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE&lt;/p&gt;
&lt;p&gt;C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;/p&gt;
&lt;p&gt;C:\Documents and Settings\Winnie.WINNIE-E521\Local Settings\Application Data\Google\Chrome\Application\chrome.exe&lt;/p&gt;
&lt;p&gt;C:\Documents and Settings\Winnie.WINNIE-E521\Local Settings\Application Data\Google\Chrome\Application\chrome.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe&lt;/p&gt;
&lt;p&gt;C:\PROGRA~1\MI1933~1\Office12\OUTLOOK.EXE&lt;/p&gt;
&lt;p&gt;C:\Documents and Settings\Winnie.WINNIE-E521\Local Settings\Application Data\Google\Chrome\Application\chrome.exe&lt;/p&gt;
&lt;p&gt;C:\Documents and Settings\Winnie.WINNIE-E521\Local Settings\Application Data\Google\Chrome\Application\chrome.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Skype\Phone\Skype.exe&lt;/p&gt;
&lt;p&gt;c:\program files\common files\installshield\updateservice\isuspm.exe&lt;/p&gt;
&lt;p&gt;C:\WINDOWS\system32\rundll32.exe&lt;/p&gt;
&lt;p&gt;C:\Documents and Settings\Winnie.WINNIE-E521\Local Settings\Application Data\Google\Chrome\Application\chrome.exe&lt;/p&gt;
&lt;p&gt;c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe&lt;/p&gt;
&lt;p&gt;C:\Documents and Settings\Winnie.WINNIE-E521\Local Settings\Application Data\Google\Chrome\Application\chrome.exe&lt;/p&gt;
&lt;p&gt;C:\Program Files\Microsoft Office\Office12\EXCEL.EXE&lt;/p&gt;
&lt;p&gt;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE&lt;/p&gt;
&lt;p&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll&lt;/p&gt;
&lt;p&gt;O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll&lt;/p&gt;
&lt;p&gt;O2 - BHO: Smart-Shopper - {4A7C84E2-E95C-43C6-8DD3-03ABCD0EB60E} - C:\Program Files\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll&lt;/p&gt;
&lt;p&gt;O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)&lt;/p&gt;
&lt;p&gt;O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll&lt;/p&gt;
&lt;p&gt;O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll&lt;/p&gt;
&lt;p&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll&lt;/p&gt;
&lt;p&gt;O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll&lt;/p&gt;
&lt;p&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;/p&gt;
&lt;p&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll&lt;/p&gt;
&lt;p&gt;O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll&lt;/p&gt;
&lt;p&gt;O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll&lt;/p&gt;
&lt;p&gt;O3 - Toolbar: &amp;amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll&lt;/p&gt;
&lt;p&gt;O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll&lt;/p&gt;
&lt;p&gt;O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [IMJPMIG8.1] &amp;quot;C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE&amp;quot; /Spoil /RemAdvDef /Migration32&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [nwiz] nwiz.exe /install&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] &amp;quot;C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe&amp;quot;&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [UIUCU] C:\DOCUME~1\WINNIE~1.WIN\LOCALS~1\Temp\UIUCU.EXE -CLEAN_UP -S&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [GrooveMonitor] &amp;quot;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&amp;quot;&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &amp;quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&amp;quot;&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [ccApp] &amp;quot;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&amp;quot;&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [TkBellExe] &amp;quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&amp;quot; &amp;nbsp;-osboot&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [ISUSPM Startup] &amp;quot;c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe&amp;quot; -startup&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [ISUSScheduler] &amp;quot;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&amp;quot; -start&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [SSBkgdUpdate] &amp;quot;C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe&amp;quot; -Embedding -boot&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [mcagent_exe] &amp;quot;C:\Program Files\McAfee.com\Agent\mcagent.exe&amp;quot; /runkey&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [Google Pinyin 2 Autoupdater] &amp;quot;C:\Program Files\Google\Google Pinyin 2\GooglePinyinDaemon.exe&amp;quot;&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\QTTask.exe&amp;quot; -atboottime&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [iTunesHelper] &amp;quot;C:\Program Files\iTunes\iTunesHelper.exe&amp;quot;&lt;/p&gt;
&lt;p&gt;O4 - HKLM\..\Run: [mediyuwik] Rundll32.exe &amp;quot;c:\windows\system32\gobifose.dll&amp;quot;,a&lt;/p&gt;
&lt;p&gt;O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe&lt;/p&gt;
&lt;p&gt;O4 - HKCU\..\Run: [Gadwin PrintScreen] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash&lt;/p&gt;
&lt;p&gt;O4 - HKCU\..\Run: [Google Update] &amp;quot;C:\Documents and Settings\Winnie.WINNIE-E521\Local Settings\Application Data\Google\Update\GoogleUpdate.exe&amp;quot; /c&lt;/p&gt;
&lt;p&gt;O4 - HKCU\..\Run: [MsnMsgr] &amp;quot;C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe&amp;quot; /background&lt;/p&gt;
&lt;p&gt;O4 - HKCU\..\Run: [Skype] &amp;quot;C:\Program Files\Skype\Phone\Skype.exe&amp;quot; /nosplash /minimized&lt;/p&gt;
&lt;p&gt;O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User &amp;#39;LOCAL SERVICE&amp;#39;)&lt;/p&gt;
&lt;p&gt;O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User &amp;#39;NETWORK SERVICE&amp;#39;)&lt;/p&gt;
&lt;p&gt;O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User &amp;#39;SYSTEM&amp;#39;)&lt;/p&gt;
&lt;p&gt;O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User &amp;#39;Default user&amp;#39;)&lt;/p&gt;
&lt;p&gt;O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE&lt;/p&gt;
&lt;p&gt;O4 - Startup: OneNote Table Of Contents.onetoc2&lt;/p&gt;
&lt;p&gt;O4 - Global Startup: Microsoft Broadband Networking.lnk = %SystemRoot%\Installer\{638547C2-2ABA-46F4-AE28-85FF6E83CB54}\_18be6784.exe&lt;/p&gt;
&lt;p&gt;O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZIP\WZQKPICK.EXE&lt;/p&gt;
&lt;p&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000&lt;/p&gt;
&lt;p&gt;O8 - Extra context menu item: UseFlashGet - C:\Program Files\FlashGet Network\Flashget\GetUrl.htm&lt;/p&gt;
&lt;p&gt;O8 - Extra context menu item: UseFlashGetDownloadAllLink - C:\Program Files\FlashGet Network\Flashget\GetAllUrl.htm&lt;/p&gt;
&lt;p&gt;O8 - Extra context menu item: 使用UUSee下载 - C:\Program Files\uusee\geturltodown.htm&lt;/p&gt;
&lt;p&gt;O8 - Extra context menu item: 使用UUSee加速播放 - C:\Program Files\uusee\geturltoplay.htm&lt;/p&gt;
&lt;p&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll&lt;/p&gt;
&lt;p&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll&lt;/p&gt;
&lt;p&gt;O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll&lt;/p&gt;
&lt;p&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: &amp;amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll&lt;/p&gt;
&lt;p&gt;O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll&lt;/p&gt;
&lt;p&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: S&amp;amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll&lt;/p&gt;
&lt;p&gt;O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\Program Files\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll&lt;/p&gt;
&lt;p&gt;O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\Program Files\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll&lt;/p&gt;
&lt;p&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL&lt;/p&gt;
&lt;p&gt;O9 - Extra button: o&amp;uuml;?&amp;igrave;&amp;ecirc;&amp;oacute;?&amp;mu;???&amp;divide; - {998A88A0-A355-809B-831C-B83A80000991} - http://www.henkuai.com/?from=iebannel (file missing)&lt;/p&gt;
&lt;p&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: o&amp;uuml;?&amp;igrave;&amp;ecirc;&amp;oacute;?&amp;mu;???&amp;divide; - {998A88A0-A355-809B-831C-B83A80000991} - http://www.henkuai.com/?from=iebannel (file missing)&lt;/p&gt;
&lt;p&gt;O9 - Extra button: ???ˉUUSee &amp;iacute;???&amp;mu;?&amp;ecirc;&amp;oacute; - {998A88A0-A355-809B-831C-B83A80000992} - C:\Program Files\uusee\UUSeePlayer.exe&lt;/p&gt;
&lt;p&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: ???ˉUUSee &amp;iacute;???&amp;mu;?&amp;ecirc;&amp;oacute; - {998A88A0-A355-809B-831C-B83A80000992} - C:\Program Files\uusee\UUSeePlayer.exe&lt;/p&gt;
&lt;p&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;/p&gt;
&lt;p&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;/p&gt;
&lt;p&gt;O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll&lt;/p&gt;
&lt;p&gt;O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll&lt;/p&gt;
&lt;p&gt;O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL&lt;/p&gt;
&lt;p&gt;O20 - AppInit_DLLs: nadusifa.dll c:\windows\system32\lukonoke.dll c:\windows\system32\gobifose.dll c:\windows\system32\pogobiwu.dll&lt;/p&gt;
&lt;p&gt;O21 - SSODL: pidawihaj - {0fa582c1-a90a-4d14-b234-110f20052d14} - c:\windows\system32\lukonoke.dll (file missing)&lt;/p&gt;
&lt;p&gt;O21 - SSODL: mumeriyuv - {e4b4ccf8-8b54-4a1b-97b9-5fda99fa4024} - c:\windows\system32\gobifose.dll&lt;/p&gt;
&lt;p&gt;O22 - SharedTaskScheduler: gahurihor - {0fa582c1-a90a-4d14-b234-110f20052d14} - c:\windows\system32\lukonoke.dll (file missing)&lt;/p&gt;
&lt;p&gt;O22 - SharedTaskScheduler: kupuhivus - {e4b4ccf8-8b54-4a1b-97b9-5fda99fa4024} - c:\windows\system32\gobifose.dll&lt;/p&gt;
&lt;p&gt;O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;/p&gt;
&lt;p&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;/p&gt;
&lt;p&gt;O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;/p&gt;
&lt;p&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;/p&gt;
&lt;p&gt;O23 - Service: Linksys Updater (LinksysUpdater) - Unknown owner - C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe&lt;/p&gt;
&lt;p&gt;O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE&lt;/p&gt;
&lt;p&gt;O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe&lt;/p&gt;
&lt;p&gt;O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe&lt;/p&gt;
&lt;p&gt;O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe&lt;/p&gt;
&lt;p&gt;O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe&lt;/p&gt;
&lt;p&gt;O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe&lt;/p&gt;
&lt;p&gt;O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe&lt;/p&gt;
&lt;p&gt;O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe&lt;/p&gt;
&lt;p&gt;O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe&lt;/p&gt;
&lt;p&gt;O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe&lt;/p&gt;
&lt;p&gt;O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe&lt;/p&gt;
&lt;p&gt;O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;--&lt;/p&gt;
&lt;p&gt;End of file - 14308 bytes&lt;/p&gt;
&lt;div&gt;I thought about to do a PC restore. But the Dell instructed step ( at starting of the PC press CTRL+F11) did not come any restore screen. And Dell did not send any restore CD with the original PC. Since I have some software and data files on this computer, the prefered chocie to me would be fix the virus issue instead of restore the PC.&lt;/div&gt;
&lt;div&gt;&lt;br /&gt;Thanks a lot!&lt;/div&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>ipconfig not working</title><link>http://en.community.dell.com/forums/thread/19584946.aspx</link><pubDate>Sun, 08 Nov 2009 16:19:54 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19584946</guid><dc:creator>nelly52</dc:creator><slash:comments>0</slash:comments><comments>http://en.community.dell.com/forums/thread/19584946.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19584946</wfw:commentRss><description>&lt;p&gt;I have an inspiron 1501 running XP Home with SP2 . I cannot connect to internet .&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I have tried to connect to wireless with internal WI FI and a dLINK&amp;nbsp; usb , no success..&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;When you type ipconfig from windows nothing happens.&lt;/p&gt;
&lt;p&gt;When you log in in safe mode with command prompt , you get message .&lt;/p&gt;
&lt;p&gt;An internal error has occurred , the request is not supported &lt;/p&gt;
&lt;p&gt;Please contact MPSS for further help ( like I&amp;nbsp; have another 4 hours to waste ) .&lt;/p&gt;
&lt;p&gt;Additional information : Unable to query host name.&lt;/p&gt;
&lt;p&gt;ping will not work IE will not connect &lt;/p&gt;
&lt;p&gt;Have tried&amp;nbsp; winsock fix and a host of other solutions from the net removed and re installed the adapters to no avail.&lt;/p&gt;
&lt;p&gt;The network cable will not connect either Helppp&lt;/p&gt;
&lt;p&gt;All other computers with wired connection work .&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 11:06:31 AM, on 08/11/2009&lt;br /&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v8.00 (8.00.6001.18702)&lt;br /&gt;Boot mode: Normal&lt;/p&gt;
&lt;p&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\Program Files\AVG\AVG9\avgchsvx.exe&lt;br /&gt;C:\Program Files\AVG\AVG9\avgrsx.exe&lt;br /&gt;C:\Program Files\AVG\AVG9\avgcsrvx.exe&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;C:\Program Files\RegCure\RegCure.exe&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\Program Files\AVG\AVG9\avgwdsvc.exe&lt;br /&gt;C:\WINDOWS\system32\tcpsvcs.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\PROGRA~1\AVG\AVG9\avgtray.exe&lt;br /&gt;C:\Program Files\QuickTime\qttask.exe&lt;br /&gt;C:\Program Files\D-Link\AirPlus G\AirGCFG.exe&lt;br /&gt;C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\Program Files\AVG\AVG9\avgnsx.exe&lt;br /&gt;C:\Documents and Settings\neil\Desktop\HijackThis.exe&lt;/p&gt;
&lt;p&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://www.google.ca/ig/dell?hl=en&amp;amp;client=dell-row-rel&amp;amp;channel=ca&amp;amp;ibd=1061216"&gt;http://www.google.ca/ig/dell?hl=en&amp;amp;client=dell-row-rel&amp;amp;channel=ca&amp;amp;ibd=1061216&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = &lt;a href="http://www.google.ca/ig/dell?hl=en&amp;amp;client=dell-row-rel&amp;amp;channel=ca&amp;amp;ibd=1061216"&gt;www.google.ca/ig/dell?hl=en&amp;amp;client=dell-row-rel&amp;amp;channel=ca&amp;amp;ibd=1061216&lt;/a&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &lt;a href="http://www.google.ca/ig/dell?hl=en&amp;amp;client=dell-row-rel&amp;amp;channel=ca&amp;amp;ibd=1061216"&gt;http://www.google.ca/ig/dell?hl=en&amp;amp;client=dell-row-rel&amp;amp;channel=ca&amp;amp;ibd=1061216&lt;/a&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost&lt;br /&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll&lt;br /&gt;O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll&lt;br /&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;br /&gt;O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll&lt;br /&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll&lt;br /&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll&lt;br /&gt;O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll&lt;br /&gt;O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll&lt;br /&gt;O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll&lt;br /&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;br /&gt;O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll&lt;br /&gt;O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll&lt;br /&gt;O3 - Toolbar: Starware Music - {2a69f099-cb84-4aa5-96ec-fc657b88b384} - C:\Program Files\Starware381\bin\Starware381.dll (file missing)&lt;br /&gt;O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll&lt;br /&gt;O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll&lt;br /&gt;O4 - HKLM\..\Run: [\\D3RNRS91\EPSON Stylus Photo R220 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE /P41 &amp;quot;&lt;a&gt;\\D3RNRS91\EPSON&lt;/a&gt; Stylus Photo R220 Series&amp;quot; /O6 &amp;quot;USB002&amp;quot; /M &amp;quot;Stylus Photo R220&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Auto EPSON Stylus Photo R220 Series on D3RNRS91] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE /P47 &amp;quot;Auto EPSON Stylus Photo R220 Series on D3RNRS91&amp;quot; /O23 &amp;quot;&lt;a&gt;\\D3RNRS91\EPSONStylusP&lt;/a&gt;&amp;quot; /M &amp;quot;Stylus Photo R220&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\qttask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe&lt;br /&gt;O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - HKCU\..\Run: [swg] &amp;quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&amp;quot;&lt;br /&gt;O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll&lt;br /&gt;O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - &lt;a href="http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab"&gt;http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - &lt;a href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab"&gt;http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - &lt;a href="http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab"&gt;http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - &lt;a href="http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab"&gt;http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - &lt;a href="http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab"&gt;http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - &lt;a href="http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab"&gt;http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - &lt;a href="http://javadl.sun.com/webapps/download/AutoDL?BundleId=26688"&gt;http://javadl.sun.com/webapps/download/AutoDL?BundleId=26688&lt;/a&gt;&lt;br /&gt;O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - &lt;a href="http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab"&gt;http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - &lt;a href="http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab55762.cab"&gt;http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab55762.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - &lt;a href="http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab"&gt;http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - &lt;a href="http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab"&gt;http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - &lt;a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab"&gt;http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - &lt;a href="http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab"&gt;http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab&lt;/a&gt;&lt;br /&gt;O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll&lt;br /&gt;O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL&lt;br /&gt;O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll&lt;br /&gt;O20 - Winlogon Notify: jkkjj - C:\WINDOWS\system32\jkkjj.dll (file missing)&lt;br /&gt;O20 - Winlogon Notify: vtsqq - C:\WINDOWS\system32\vtsqq.dll (file missing)&lt;br /&gt;O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe&lt;br /&gt;O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;br /&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;/p&gt;
&lt;p&gt;--&lt;br /&gt;End of file - 8186 bytes&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Here is my combofix and hijack logs, I can't get rid of my problem</title><link>http://en.community.dell.com/forums/thread/19568102.aspx</link><pubDate>Wed, 14 Oct 2009 21:25:48 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19568102</guid><dc:creator>jaybc17</dc:creator><slash:comments>1</slash:comments><comments>http://en.community.dell.com/forums/thread/19568102.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19568102</wfw:commentRss><description>&lt;p&gt;I first posted here (&lt;a href="http://en.community.dell.com/forums/t/19297951.aspx"&gt;http://en.community.dell.com/forums/t/19297951.aspx&lt;/a&gt;) with no replies.&lt;/p&gt;
&lt;p&gt;I have had this problem for 6 days and it will not go away.&amp;nbsp; I think I get it cleaned up with Super AntiSpyware, Malware bytes anti spyware and ATF Cleaner.&amp;nbsp; I run these until they can&amp;#39;t find any problems and I also delete the Security Tool program that keeps getting installed.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;The next time I turn on my computer the Security Tool is back and all my anti software finds problems again!&amp;nbsp; I just downloaded and ran combofix.&amp;nbsp; Here is my log plus my hijack log.&lt;/p&gt;
&lt;p&gt;Any help would be greatly&amp;nbsp; &lt;span style="font-size:small;font-family:Times New Roman;"&gt;appreciated.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;ComboFix 09-10-14.01 - Jay &amp;amp; Erika 10/14/2009 15:49.6.1 - NTFSx86&lt;br /&gt;Microsoft Windows XP Professional&amp;nbsp; 5.1.2600.3.1252.1.1033.18.446.63 [GMT -5:00]&lt;br /&gt;Running from: c:\documents and settings\Jay &amp;amp; Erika\Desktop\dunnery.exe&lt;br /&gt;AV: Bitdefender Antivirus *On-access scanning disabled* (Outdated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}&lt;br /&gt;.&lt;/p&gt;
&lt;p&gt;(((((((((((((((((((((((((((((((((((((((&amp;nbsp;&amp;nbsp; Other Deletions&amp;nbsp;&amp;nbsp; )))))))))))))))))))))))))))))))))))))))))))))))))&lt;br /&gt;.&lt;/p&gt;
&lt;p&gt;c:\program files\Mozilla Firefox\searchplugins\search.xml&lt;br /&gt;c:\recycler\NPROTECT&lt;br /&gt;c:\windows\COUPON~1.OCX&lt;br /&gt;c:\windows\CouponPrinter.ocx&lt;br /&gt;c:\windows\estrictions.dll&lt;br /&gt;c:\windows\Installer\dd2ce.msi&lt;br /&gt;c:\windows\kb913800.exe&lt;br /&gt;c:\windows\system32\fapilizu.dll&lt;br /&gt;c:\windows\system32\fosajugu.dll&lt;br /&gt;c:\windows\system32\kidamore.dll&lt;br /&gt;c:\windows\system32\laraguji.dll.tmp&lt;br /&gt;c:\windows\system32\lebobofu.dll&lt;br /&gt;c:\windows\system32\nubobevu.dll&lt;br /&gt;c:\windows\system32\risowupa.dll&lt;br /&gt;c:\windows\system32\saperiho.dll&lt;br /&gt;c:\windows\system32\suluyeba.dll&lt;br /&gt;c:\windows\system32\uactmp.db&lt;br /&gt;c:\windows\system32\werolime.dll&lt;br /&gt;c:\windows\system32\zuvusibo.dll&lt;/p&gt;
&lt;p&gt;.&lt;br /&gt;(((((((((((((((((((((((((&amp;nbsp;&amp;nbsp; Files Created from 2009-09-14 to 2009-10-14&amp;nbsp; )))))))))))))))))))))))))))))))&lt;br /&gt;.&lt;/p&gt;
&lt;p&gt;2009-10-11 21:03 . 2009-09-10 19:54&amp;nbsp;38224&amp;nbsp;----a-w-&amp;nbsp;c:\windows\system32\drivers\mbamswissarmy.sys&lt;br /&gt;2009-10-11 21:03 . 2009-10-11 21:06&amp;nbsp;--------&amp;nbsp;d-----w-&amp;nbsp;c:\program files\Malwarebytes&amp;#39; Anti-Malware&lt;br /&gt;2009-10-11 21:03 . 2009-09-10 19:53&amp;nbsp;19160&amp;nbsp;----a-w-&amp;nbsp;c:\windows\system32\drivers\mbam.sys&lt;br /&gt;2009-10-07 13:40 . 2009-10-07 13:40&amp;nbsp;--------&amp;nbsp;d-----w-&amp;nbsp;c:\windows\Cache&lt;br /&gt;2009-10-07 13:40 . 2009-10-07 13:40&amp;nbsp;--------&amp;nbsp;d-----w-&amp;nbsp;c:\program files\Coupons&lt;/p&gt;
&lt;p&gt;.&lt;br /&gt;((((((((((((((((((((((((((((((((((((((((&amp;nbsp;&amp;nbsp; Find3M Report&amp;nbsp;&amp;nbsp; ))))))))))))))))))))))))))))))))))))))))))))))))))))&lt;br /&gt;.&lt;br /&gt;2009-10-14 20:42 . 2007-12-05 00:25&amp;nbsp;81984&amp;nbsp;----a-w-&amp;nbsp;c:\windows\system32\bdod.bin&lt;br /&gt;2009-10-14 20:09 . 2007-12-04 01:31&amp;nbsp;--------&amp;nbsp;d-----w-&amp;nbsp;c:\program files\SUPERAntiSpyware&lt;br /&gt;2009-10-07 14:12 . 2006-11-04 18:10&amp;nbsp;--------&amp;nbsp;d-----w-&amp;nbsp;c:\program files\Dl_cats&lt;br /&gt;2009-09-03 01:26 . 2006-11-04 18:22&amp;nbsp;2100&amp;nbsp;----a-w-&amp;nbsp;c:\documents and settings\Jay &amp;amp; Erika\Application Data\wklnhst.dat&lt;br /&gt;2009-08-05 09:01 . 2005-08-16 10:18&amp;nbsp;204800&amp;nbsp;----a-w-&amp;nbsp;c:\windows\system32\mswebdvd.dll&lt;br /&gt;2009-07-28 02:38 . 2006-11-04 18:30&amp;nbsp;77840&amp;nbsp;----a-w-&amp;nbsp;c:\documents and settings\Jay &amp;amp; Erika\Local Settings\Application Data\GDIPFONTCACHEV1.DAT&lt;br /&gt;2009-07-17 19:01 . 2005-08-16 10:18&amp;nbsp;58880&amp;nbsp;----a-w-&amp;nbsp;c:\windows\system32\atl.dll&lt;br /&gt;2007-12-04 02:09 . 2007-12-04 02:09&amp;nbsp;10&amp;nbsp;----a-w-&amp;nbsp;c:\program files\.autoreg&lt;br /&gt;2007-12-04 02:09 . 2007-12-04 02:09&amp;nbsp;69632&amp;nbsp;----a-w-&amp;nbsp;c:\program files\mozilla firefox\components\ffwt.dll&lt;br /&gt;2008-08-21 20:35 . 2007-08-14 02:41&amp;nbsp;122880&amp;nbsp;----a-w-&amp;nbsp;c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll&lt;br /&gt;2008-10-06 22:06 . 2008-10-06 22:06&amp;nbsp;88&amp;nbsp;--sh--r-&amp;nbsp;c:\windows\system32\013C5CA7EE.sys&lt;br /&gt;2009-07-13 00:01 . 2009-07-13 00:01&amp;nbsp;50688&amp;nbsp;--sha-w-&amp;nbsp;c:\windows\system32\gimuhohe.dll.tmp&lt;br /&gt;2008-10-06 22:26 . 2008-10-06 22:06&amp;nbsp;2516&amp;nbsp;--sha-w-&amp;nbsp;c:\windows\system32\KGyGaAvL.sys&lt;br /&gt;.&lt;/p&gt;
&lt;p&gt;(((((((((((((((((((((((((((((((((((((&amp;nbsp;&amp;nbsp; Reg Loading Points&amp;nbsp;&amp;nbsp; ))))))))))))))))))))))))))))))))))))))))))))))))))&lt;br /&gt;.&lt;br /&gt;.&lt;br /&gt;*Note* empty entries &amp;amp; legit default entries are not shown &lt;br /&gt;REGEDIT4&lt;/p&gt;
&lt;p&gt;[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;br /&gt;&amp;quot;MSMSGS&amp;quot;=&amp;quot;c:\program files\Messenger\msmsgs.exe&amp;quot; [2008-04-14 1695232]&lt;br /&gt;&amp;quot;swg&amp;quot;=&amp;quot;c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&amp;quot; [2007-06-24 68856]&lt;br /&gt;&amp;quot;SUPERAntiSpyware&amp;quot;=&amp;quot;c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe&amp;quot; [2007-06-21 1318912]&lt;br /&gt;&amp;quot;ctfmon.exe&amp;quot;=&amp;quot;c:\windows\system32\ctfmon.exe&amp;quot; [2008-04-14 15360]&lt;/p&gt;
&lt;p&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;br /&gt;&amp;quot;ehTray&amp;quot;=&amp;quot;c:\windows\ehome\ehtray.exe&amp;quot; [2005-09-29 67584]&lt;br /&gt;&amp;quot;NvCplDaemon&amp;quot;=&amp;quot;c:\windows\system32\NvCpl.dll&amp;quot; [2006-08-24 7630848]&lt;br /&gt;&amp;quot;NvMediaCenter&amp;quot;=&amp;quot;c:\windows\system32\NvMcTray.dll&amp;quot; [2006-08-24 86016]&lt;br /&gt;&amp;quot;DMXLauncher&amp;quot;=&amp;quot;c:\program files\Dell\Media Experience\DMXLauncher.exe&amp;quot; [2005-10-05 94208]&lt;br /&gt;&amp;quot;DLA&amp;quot;=&amp;quot;c:\windows\System32\DLA\DLACTRLW.EXE&amp;quot; [2005-09-08 122940]&lt;br /&gt;&amp;quot;ISUSPM Startup&amp;quot;=&amp;quot;c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe&amp;quot; [2004-07-27 221184]&lt;br /&gt;&amp;quot;ISUSScheduler&amp;quot;=&amp;quot;c:\program files\Common Files\InstallShield\UpdateService\issch.exe&amp;quot; [2004-07-27 81920]&lt;br /&gt;&amp;quot;Google Desktop Search&amp;quot;=&amp;quot;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe&amp;quot; [2008-08-21 29744]&lt;br /&gt;&amp;quot;DLCCCATS&amp;quot;=&amp;quot;c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll&amp;quot; [2005-09-14 73728]&lt;br /&gt;&amp;quot;dlccmon.exe&amp;quot;=&amp;quot;c:\program files\Dell Photo AIO Printer 924\dlccmon.exe&amp;quot; [2005-10-21 430080]&lt;br /&gt;&amp;quot;QuickTime Task&amp;quot;=&amp;quot;c:\program files\QuickTime\qttask.exe&amp;quot; [2006-11-01 98304]&lt;br /&gt;&amp;quot;MSKDetectorExe&amp;quot;=&amp;quot;c:\program files\McAfee\SpamKiller\MSKDetct.exe&amp;quot; [2005-07-13 1117184]&lt;br /&gt;&amp;quot;HP Software Update&amp;quot;=&amp;quot;c:\program files\HP\HP Software Update\HPWuSchd2.exe&amp;quot; [2006-02-19 49152]&lt;br /&gt;&amp;quot;BDAgent&amp;quot;=&amp;quot;c:\program files\Softwin\BitDefender10\bdagent.exe&amp;quot; [2007-03-26 69632]&lt;br /&gt;&amp;quot;Adobe Reader Speed Launcher&amp;quot;=&amp;quot;c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe&amp;quot; [2008-01-12 39792]&lt;br /&gt;&amp;quot;TkBellExe&amp;quot;=&amp;quot;c:\program files\Common Files\Real\Update_OB\realsched.exe&amp;quot; [2008-03-05 185896]&lt;br /&gt;&amp;quot;SunJavaUpdateSched&amp;quot;=&amp;quot;c:\program files\Java\jre6\bin\jusched.exe&amp;quot; [2008-11-10 136600]&lt;br /&gt;&amp;quot;Malwarebytes Anti-Malware (reboot)&amp;quot;=&amp;quot;c:\program files\Malwarebytes&amp;#39; Anti-Malware\mbam.exe&amp;quot; [2009-09-10 1312080]&lt;br /&gt;&amp;quot;nwiz&amp;quot;=&amp;quot;nwiz.exe&amp;quot; - c:\windows\system32\nwiz.exe [2006-08-24 1617920]&lt;br /&gt;&amp;quot;SigmatelSysTrayApp&amp;quot;=&amp;quot;stsystra.exe&amp;quot; - c:\windows\stsystra.exe [2006-08-15 282624]&lt;/p&gt;
&lt;p&gt;[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]&lt;br /&gt;&amp;quot;swg&amp;quot;=&amp;quot;c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&amp;quot; [2007-06-24 68856]&lt;/p&gt;
&lt;p&gt;c:\documents and settings\All Users\Start Menu\Programs\Startup\&lt;br /&gt;Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-11-1 24576]&lt;br /&gt;HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]&lt;br /&gt;HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728]&lt;br /&gt;QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2006-11-29 968224]&lt;/p&gt;
&lt;p&gt;[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]&lt;br /&gt;&amp;quot;{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}&amp;quot;= &amp;quot;c:\program files\SUPERAntiSpyware\SASSEH.DLL&amp;quot; [2006-12-20 77824]&lt;/p&gt;
&lt;p&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]&lt;br /&gt;2007-04-19 19:41&amp;nbsp;294912&amp;nbsp;----a-w-&amp;nbsp;c:\program files\SUPERAntiSpyware\SASWINLO.dll&lt;/p&gt;
&lt;p&gt;[HKEY_LOCAL_MACHINE\software\microsoft\security center]&lt;br /&gt;&amp;quot;AntiVirusOverride&amp;quot;=dword:00000001&lt;/p&gt;
&lt;p&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]&lt;br /&gt;&amp;quot;c:\\WINDOWS\\network diagnostic\\xpnetdiag.exe&amp;quot;=&lt;br /&gt;&amp;quot;c:\\Program Files\\Messenger\\msmsgs.exe&amp;quot;=&lt;br /&gt;&amp;quot;%windir%\\Network Diagnostic\\xpnetdiag.exe&amp;quot;=&lt;br /&gt;&amp;quot;%windir%\\system32\\sessmgr.exe&amp;quot;=&lt;br /&gt;&amp;quot;c:\\Program Files\\HP\\Digital Imaging\\Product Assistant\\bin\\hprblog.exe&amp;quot;=&lt;/p&gt;
&lt;p&gt;R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [10/10/2006 2:53 PM 5632]&lt;br /&gt;R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/27/2007 1:39 PM 32256]&lt;br /&gt;R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/16/2006 6:51 PM 4096]&lt;br /&gt;S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [11/1/2006 12:51 AM 29744]&lt;br /&gt;.&lt;br /&gt;.&lt;br /&gt;------- Supplementary Scan -------&lt;br /&gt;.&lt;br /&gt;uStart Page = hxxp://www.tulsacc.edu/&lt;br /&gt;uDefault_Search_URL = hxxp://www.google.com/&lt;br /&gt;uSearchMigratedDefaultURL = hxxp://www.google.com/&lt;br /&gt;mSearch Bar = hxxp://www.google.com/&lt;br /&gt;mSearchMigratedDefaultURL = hxxp://www.google.com/&lt;br /&gt;uSearchURL,(Default) = hxxp://www.google.com/search?q=%s&lt;br /&gt;mSearchURL = hxxp://www.google.com/&lt;br /&gt;IE: E&amp;amp;xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000&lt;br /&gt;.&lt;br /&gt;- - - - ORPHANS REMOVED - - - -&lt;/p&gt;
&lt;p&gt;BHO-{22818a29-2acf-4b3b-b72d-a183dfbf3a4c} - nivunaso.dll&lt;br /&gt;WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)&lt;br /&gt;HKCU-Run-PhotoShow Deluxe Media Manager - c:\progra~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe&lt;br /&gt;HKLM-Run-hasunijuha - gujayiwo.dll&lt;br /&gt;SharedTaskScheduler-{cbf41594-94da-4b12-be32-9d0e261bf9fe} - c:\windows\system32\gukuyesa.dll&lt;br /&gt;SharedTaskScheduler-{1a658bfc-b11d-45df-a8c6-f2a2b545f9b7} - c:\windows\system32\gukuyesa.dll&lt;br /&gt;SharedTaskScheduler-{08d28267-6ad6-4e59-b4ac-5382f3804442} - c:\windows\system32\gukuyesa.dll&lt;br /&gt;SSODL-puripekoy-{cbf41594-94da-4b12-be32-9d0e261bf9fe} - c:\windows\system32\gukuyesa.dll&lt;br /&gt;SSODL-kehapesem-{08d28267-6ad6-4e59-b4ac-5382f3804442} - c:\windows\system32\gukuyesa.dll&lt;br /&gt;Notify-WgaLogon - (no file)&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;**************************************************************************&lt;/p&gt;
&lt;p&gt;catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &lt;a href="http://www.gmer.net"&gt;http://www.gmer.net&lt;/a&gt;&lt;br /&gt;Rootkit scan 2009-10-14 15:57&lt;br /&gt;Windows 5.1.2600 Service Pack 3 NTFS&lt;/p&gt;
&lt;p&gt;scanning hidden processes ...&amp;nbsp; &lt;/p&gt;
&lt;p&gt;scanning hidden autostart entries ... &lt;/p&gt;
&lt;p&gt;scanning hidden files ...&amp;nbsp; &lt;/p&gt;
&lt;p&gt;scan completed successfully&lt;br /&gt;hidden files: 0&lt;/p&gt;
&lt;p&gt;**************************************************************************&lt;br /&gt;.&lt;br /&gt;--------------------- LOCKED REGISTRY KEYS ---------------------&lt;/p&gt;
&lt;p&gt;[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]&lt;br /&gt;@Denied: (A 2) (Everyone)&lt;br /&gt;@=&amp;quot;IFlashBroker3&amp;quot;&lt;/p&gt;
&lt;p&gt;[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]&lt;br /&gt;@=&amp;quot;{00020424-0000-0000-C000-000000000046}&amp;quot;&lt;/p&gt;
&lt;p&gt;[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]&lt;br /&gt;@=&amp;quot;{FAB3E735-69C7-453B-A446-B6823C6DF1C9}&amp;quot;&lt;br /&gt;&amp;quot;Version&amp;quot;=&amp;quot;1.0&amp;quot;&lt;br /&gt;.&lt;br /&gt;--------------------- DLLs Loaded Under Running Processes ---------------------&lt;/p&gt;
&lt;p&gt;- - - - - - - &amp;gt; &amp;#39;winlogon.exe&amp;#39;(632)&lt;br /&gt;c:\program files\SUPERAntiSpyware\SASWINLO.dll&lt;br /&gt;c:\windows\system32\WININET.dll&lt;/p&gt;
&lt;p&gt;- - - - - - - &amp;gt; &amp;#39;explorer.exe&amp;#39;(2800)&lt;br /&gt;c:\windows\system32\WININET.dll&lt;br /&gt;c:\windows\system32\ieframe.dll&lt;br /&gt;c:\windows\system32\WPDShServiceObj.dll&lt;br /&gt;c:\windows\system32\PortableDeviceTypes.dll&lt;br /&gt;c:\windows\system32\PortableDeviceApi.dll&lt;br /&gt;.&lt;br /&gt;------------------------ Other Running Processes ------------------------&lt;br /&gt;.&lt;br /&gt;c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe&lt;br /&gt;c:\windows\ehome\ehrecvr.exe&lt;br /&gt;c:\windows\ehome\ehSched.exe&lt;br /&gt;c:\program files\Java\jre6\bin\jqs.exe&lt;br /&gt;c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE&lt;br /&gt;c:\windows\system32\nvsvc32.exe&lt;br /&gt;c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe&lt;br /&gt;c:\program files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe&lt;br /&gt;c:\program files\Common Files\Softwin\BitDefender Update Service\livesrv.exe&lt;br /&gt;c:\windows\ehome\mcrdsvc.exe&lt;br /&gt;c:\program files\Common Files\Softwin\BitDefender Scan Server\bdss.exe&lt;br /&gt;c:\program files\Softwin\BitDefender10\vsserv.exe&lt;br /&gt;c:\windows\system32\dlcccoms.exe&lt;br /&gt;c:\windows\system32\dllhost.exe&lt;br /&gt;c:\windows\ehome\ehmsas.exe&lt;br /&gt;c:\program files\HP\Digital Imaging\bin\hpqimzone.exe&lt;br /&gt;c:\windows\system32\msiexec.exe&lt;br /&gt;.&lt;br /&gt;**************************************************************************&lt;br /&gt;.&lt;br /&gt;Completion time: 2009-10-14 16:05 - machine was rebooted&lt;br /&gt;ComboFix-quarantined-files.txt&amp;nbsp; 2009-10-14 21:05&lt;br /&gt;ComboFix2.txt&amp;nbsp; 2007-12-22 00:40&lt;/p&gt;
&lt;p&gt;Pre-Run: 44,061,585,408 bytes free&lt;br /&gt;Post-Run: 44,013,805,568 bytes free&lt;/p&gt;
&lt;p&gt;WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe&lt;br /&gt;[boot loader]&lt;br /&gt;timeout=2&lt;br /&gt;default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS&lt;br /&gt;[operating systems]&lt;br /&gt;c:\cmdcons\BOOTSECT.DAT=&amp;quot;Microsoft Windows Recovery Console&amp;quot; /cmdcons&lt;br /&gt;multi(0)disk(0)rdisk(0)partition(2)\WINDOWS=&amp;quot;Windows XP Media Center Edition&amp;quot; /noexecute=optin /fastdetect&lt;/p&gt;
&lt;p&gt;Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4&lt;br /&gt;196&amp;nbsp;--- E O F ---&amp;nbsp;2009-09-08 22:06&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 4:24:06 PM, on 10/14/2009&lt;br /&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16876)&lt;br /&gt;Boot mode: Normal&lt;/p&gt;
&lt;p&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe&lt;br /&gt;C:\WINDOWS\eHome\ehRecvr.exe&lt;br /&gt;C:\WINDOWS\ehome\ehtray.exe&lt;br /&gt;C:\WINDOWS\stsystra.exe&lt;br /&gt;C:\WINDOWS\System32\DLA\DLACTRLW.EXE&lt;br /&gt;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&lt;br /&gt;C:\WINDOWS\eHome\ehSched.exe&lt;br /&gt;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe&lt;br /&gt;C:\Program Files\HP\HP Software Update\HPWuSchd2.exe&lt;br /&gt;C:\Program Files\Softwin\BitDefender10\bdagent.exe&lt;br /&gt;C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE&lt;br /&gt;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jusched.exe&lt;br /&gt;C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;br /&gt;C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;br /&gt;C:\WINDOWS\system32\nvsvc32.exe&lt;br /&gt;C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe&lt;br /&gt;C:\Program Files\Digital Line Detect\DLG.exe&lt;br /&gt;C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe&lt;br /&gt;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe&lt;br /&gt;C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe&lt;br /&gt;C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe&lt;br /&gt;C:\Program Files\Softwin\BitDefender10\vsserv.exe&lt;br /&gt;C:\WINDOWS\system32\dlcccoms.exe&lt;br /&gt;C:\WINDOWS\system32\dllhost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\eHome\ehmsas.exe&lt;br /&gt;C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\WINDOWS\explorer.exe&lt;br /&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br /&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/p&gt;
&lt;p&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://www.tulsacc.edu/"&gt;http://www.tulsacc.edu/&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = &lt;a href="http://www.google.com/ig/dell?hl=en&amp;amp;client=dell-usuk&amp;amp;channel=us&amp;amp;ibd=5061031"&gt;www.google.com/ig/dell?hl=en&amp;amp;client=dell-usuk&amp;amp;channel=us&amp;amp;ibd=5061031&lt;/a&gt;&lt;br /&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br /&gt;O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll&lt;br /&gt;O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL&lt;br /&gt;O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll&lt;br /&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll&lt;br /&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll&lt;br /&gt;O2 - BHO: Fire-Trust SiteHound - {C86AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - C:\Program Files\FireTrust\SiteHound\SiteHound.dll (file missing)&lt;br /&gt;O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll&lt;br /&gt;O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll&lt;br /&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;br /&gt;O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll&lt;br /&gt;O3 - Toolbar: SiteHound - {73F7F495-A325-4C52-BE48-5F97FA511E89} - C:\Program Files\FireTrust\SiteHound\SiteHound.dll (file missing)&lt;br /&gt;O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll&lt;br /&gt;O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup&lt;br /&gt;O4 - HKLM\..\Run: [nwiz] nwiz.exe /install&lt;br /&gt;O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit&lt;br /&gt;O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe&lt;br /&gt;O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe&lt;br /&gt;O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE&lt;br /&gt;O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup&lt;br /&gt;O4 - HKLM\..\Run: [ISUSScheduler] &amp;quot;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&amp;quot; -start&lt;br /&gt;O4 - HKLM\..\Run: [Google Desktop Search] &amp;quot;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&amp;quot; /startup&lt;br /&gt;O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16&lt;br /&gt;O4 - HKLM\..\Run: [dlccmon.exe] &amp;quot;C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\qttask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall&lt;br /&gt;O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe&lt;br /&gt;O4 - HKLM\..\Run: [BDAgent] &amp;quot;C:\Program Files\Softwin\BitDefender10\bdagent.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &amp;quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [TkBellExe] &amp;quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&amp;quot;&amp;nbsp; -osboot&lt;br /&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] &amp;quot;C:\Program Files\Java\jre6\bin\jusched.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] &amp;quot;C:\Program Files\Malwarebytes&amp;#39; Anti-Malware\mbam.exe&amp;quot; /runcleanupscript&lt;br /&gt;O4 - HKCU\..\Run: [MSMSGS] &amp;quot;C:\Program Files\Messenger\msmsgs.exe&amp;quot; /background&lt;br /&gt;O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;br /&gt;O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;br /&gt;O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User &amp;#39;SYSTEM&amp;#39;)&lt;br /&gt;O4 - HKUS\.DEFAULT\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User &amp;#39;Default user&amp;#39;)&lt;br /&gt;O4 - Global Startup: Digital Line Detect.lnk = ?&lt;br /&gt;O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe&lt;br /&gt;O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe&lt;br /&gt;O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000&lt;br /&gt;O9 - Extra button: (no name) - {11316B13-33F0-4C9F-BD55-09994CCFA8EB} - C:\Program Files\FireTrust\SiteHound\SiteHound.dll (file missing)&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - &lt;a href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab"&gt;http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - &lt;a href="http://asp.mathxl.com/wizmodules/testgen/installers/TestGenXInstall.cab"&gt;http://asp.mathxl.com/wizmodules/testgen/installers/TestGenXInstall.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - &lt;a href="http://www2.snapfish.com/SnapfishActivia.cab"&gt;http://www2.snapfish.com/SnapfishActivia.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - &lt;a href="http://lads.myspace.com/upload/MySpaceUploader.cab"&gt;http://lads.myspace.com/upload/MySpaceUploader.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - &lt;a href="http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab"&gt;http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - &lt;a href="http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab"&gt;http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - &lt;a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab"&gt;http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - &lt;a href="http://asp.mathxl.com/books/_Players/MathPlayer.cab"&gt;http://asp.mathxl.com/books/_Players/MathPlayer.cab&lt;/a&gt;&lt;br /&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;br /&gt;O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe&lt;br /&gt;O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe&lt;br /&gt;O23 - Service: dlcc_device -&amp;nbsp;&amp;nbsp; - C:\WINDOWS\system32\dlcccoms.exe&lt;br /&gt;O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&lt;br /&gt;O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;br /&gt;O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe&lt;br /&gt;O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe&lt;br /&gt;O23 - Service: QuickBooks Database Manager Service (QBCFMonitorService) -&amp;nbsp;&amp;nbsp; - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe&lt;br /&gt;O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe&lt;br /&gt;O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe&lt;br /&gt;O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe&lt;/p&gt;
&lt;p&gt;--&lt;br /&gt;End of file - 11174 bytes&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Multiple security pop-ups, can't update anti-virus</title><link>http://en.community.dell.com/forums/thread/19568025.aspx</link><pubDate>Wed, 14 Oct 2009 19:35:57 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19568025</guid><dc:creator>drohlfing</dc:creator><slash:comments>1</slash:comments><comments>http://en.community.dell.com/forums/thread/19568025.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3521&amp;PostID=19568025</wfw:commentRss><description>&lt;p&gt;I have run Hijack this and pasted the log, but had to run it in safe mode. Whatever has control of my friends laptop won&amp;#39;t let Hijack this run in normal mode, it keeps saying it&amp;#39;s infected.&lt;/p&gt;
&lt;p&gt;Hopefully, someone can help me clean up this mess!&lt;/p&gt;
&lt;p&gt;Here is the log:&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 2:31:37 PM, on 10/14/2009&lt;br /&gt;Platform: Windows Vista SP1 (WinNT 6.00.1905)&lt;br /&gt;MSIE: Internet Explorer v7.00 (7.00.6001.18294)&lt;br /&gt;Boot mode: Safe mode&lt;br /&gt;&lt;br /&gt;Running processes:&lt;br /&gt;C:\Windows\Explorer.EXE&lt;br /&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;br /&gt;C:\Windows\system32\rundll32.exe&lt;br /&gt;C:\Windows\System32\rundll32.exe&lt;br /&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACGW&amp;amp;l=0409&amp;amp;s=2&amp;amp;o=vp32&amp;amp;d=0808&amp;amp;m=m-7301u&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.facebook.com/&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACGW&amp;amp;l=0409&amp;amp;s=2&amp;amp;o=vp32&amp;amp;d=0808&amp;amp;m=m-7301u&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = &lt;br /&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = &lt;br /&gt;O1 - Hosts: ::1 localhost&lt;br /&gt;O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll&lt;br /&gt;O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll&lt;br /&gt;O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll&lt;br /&gt;O2 - BHO: Media Access Startup - {25B8D58C-B0CB-46b0-BA64-05B3804E4E86} - C:\Program Files\Media Access Startup\1.5.0.850\HPIEAddOn.dll&lt;br /&gt;O2 - BHO: NP Helper Class - {35B8D58C-B0CB-46b0-BA64-05B3804E4E86} - C:\Program Files\Internet Saving Optimizer\3.4.0.4340\NPIEAddOn.dll&lt;br /&gt;O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll&lt;br /&gt;O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll&lt;br /&gt;O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL&lt;br /&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br /&gt;O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)&lt;br /&gt;O2 - BHO: Zango - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - C:\Program Files\Zango\bin\10.3.85.0\HostIE.dll&lt;br /&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll&lt;br /&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll&lt;br /&gt;O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll&lt;br /&gt;O2 - BHO: System Search Dispatcher - {CDBFB47B-58A8-4111-BF95-06178DCE326D} - C:\Program Files\System Search Dispatcher\1.3.0.840\ssd.dll&lt;br /&gt;O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll&lt;br /&gt;O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll&lt;br /&gt;O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll&lt;br /&gt;O3 - Toolbar: Zango - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - C:\Program Files\Zango\bin\10.3.85.0\HostIE.dll&lt;br /&gt;O3 - Toolbar: GamingHarbor Toolbar - {5617ECA9-488D-4BA2-8562-9710B9AB78D2} - C:\Program Files\DoubleD\GamingHarbor Toolbar\4.1.3.20290\stb0.dll&lt;br /&gt;O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll&lt;br /&gt;O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide&lt;br /&gt;O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;br /&gt;O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe&lt;br /&gt;O4 - HKLM\..\Run: [ccApp] &amp;quot;c:\Program Files\Common Files\Symantec Shared\ccApp.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [osCheck] &amp;quot;c:\Program Files\Norton 360\osCheck.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] &amp;quot;C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &amp;quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe&lt;br /&gt;O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe&lt;br /&gt;O4 - HKLM\..\Run: [Camera Assistant Software] &amp;quot;C:\Program Files\Camera Assistant Software for Gateway\traybar.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [Google Desktop Search] &amp;quot;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&amp;quot; /startup&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\QTTask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKLM\..\Run: [iTunesHelper] &amp;quot;C:\Program Files\iTunes\iTunesHelper.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [GrooveMonitor] &amp;quot;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [ZangoOE] C:\Program Files\Zango\bin\10.3.85.0\OEAddOn.exe&lt;br /&gt;O4 - HKLM\..\Run: [ZangoSA] &amp;quot;C:\Program Files\Zango\bin\10.3.85.0\ZangoSA.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe&lt;br /&gt;O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe&lt;br /&gt;O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter&lt;br /&gt;O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe&lt;br /&gt;O4 - HKCU\..\Run: [swg] &amp;quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&amp;quot;&lt;br /&gt;O4 - HKCU\..\Run: [WeatherDPA] &amp;quot;C:\Program Files\Zango\bin\10.3.85.0\Weather.exe&amp;quot; -auto&lt;br /&gt;O4 - HKCU\..\Run: [SmileyApp] C:\Program Files\DoubleD\GamingHarbor Toolbar\4.1.3.20290\stbapp.exe&lt;br /&gt;O4 - HKCU\..\Run: [msnmsgr] &amp;quot;C:\Program Files\MSN Messenger\msnmsgr.exe&amp;quot; /background&lt;br /&gt;O4 - HKCU\..\Run: [54869840] C:\ProgramData\54869840\54869840.exe&lt;br /&gt;O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User &amp;#39;LOCAL SERVICE&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User &amp;#39;LOCAL SERVICE&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User &amp;#39;NETWORK SERVICE&amp;#39;)&lt;br /&gt;O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE&lt;br /&gt;O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe&lt;br /&gt;O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe&lt;br /&gt;O8 - Extra context menu item: Add to Google Photos Screensa&amp;amp;ver - res://C:\Windows\system32\GPhotos.scr/200&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000&lt;br /&gt;O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: S&amp;amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll&lt;br /&gt;O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll&lt;br /&gt;O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll&lt;br /&gt;O13 - Gopher Prefix: &lt;br /&gt;O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab&lt;br /&gt;O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab&lt;br /&gt;O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab&lt;br /&gt;O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab&lt;br /&gt;O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL&lt;br /&gt;O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL&lt;br /&gt;O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - c:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe&lt;br /&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;br /&gt;O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;br /&gt;O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;br /&gt;O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe&lt;br /&gt;O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\GATEWAY\Gateway Recovery Management\Service\ETService.exe&lt;br /&gt;O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\Gateway Games\Gateway Game Console\GameConsoleService.exe&lt;br /&gt;O23 - Service: Google Desktop Manager 5.7.808.7150 (GoogleDesktopManager-080708-050100) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&lt;br /&gt;O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;br /&gt;O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe&lt;br /&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;O23 - Service: LiveUpdate - Symantec Corporation - c:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE&lt;br /&gt;O23 - Service: LiveUpdate Notice - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe&lt;br /&gt;O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe&lt;br /&gt;O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe&lt;br /&gt;O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;End of file - 11277 bytes&lt;br /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>