<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>hjt log   Vundo found in Security</title>
<link>http://www.dslreports.com/forum/r15025623</link>
<description></description>
<language>en</language>
<pubDate>Wed, 09 Dec 2009 00:49:40 EDT</pubDate>
<lastBuildDate>Wed, 09 Dec 2009 00:49:40 EDT</lastBuildDate>

<item>
<title>Re: hjt log   Vundo found</title>
<link>http://www.dslreports.com/forum/remark,15032737</link>
<description><![CDATA[<A HREF="/useremail/u/1301842"><b>gr8thoughts</b></A> : I have three more infected computers.....<br>you up for it?<br>Kevin]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15032737</guid>
<pubDate>Thu, 15 Dec 2005 21:40:11 EDT</pubDate>
</item>

<item>
<title>Re: hjt log   Vundo found</title>
<link>http://www.dslreports.com/forum/remark,15032728</link>
<description><![CDATA[<A HREF="/useremail/u/1301842"><b>gr8thoughts</b></A> : Awesome Guys<br>hjt:<br>Logfile of HijackThis v1.99.1<br>Scan saved at 5:34:48 PM, on 12/15/2005<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>c:\Program Files\Common Files\Symantec Shared\ccProxy.exe<br>c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>c:\Program Files\Norton AntiVirus\navapsvc.exe<br>c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe<br>C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br>C:\Program Files\ewido\security suite\ewidoctrl.exe<br>C:\Program Files\ewido\security suite\ewidoguard.exe<br>c:\Program Files\Common Files\LightScribe\LSSrvc.exe<br>C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br>c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe<br>C:\windows\system\hpsysdrv.exe<br>C:\WINDOWS\system32\hkcmd.exe<br>C:\WINDOWS\system32\hphmon06.exe<br>C:\HP\KBD\KBD.EXE<br>C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br>C:\WINDOWS\AGRSMMSG.exe<br>C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe<br>C:\Program Files\Common Files\AOL\ACS\AOLDial.exe<br>C:\Program Files\QuickTime\qttask.exe<br>C:\WINDOWS\SOUNDMAN.EXE<br>C:\WINDOWS\ALCWZRD.EXE<br>C:\WINDOWS\ALCMTR.EXE<br>C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe<br>C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe<br>C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Common Files\AOL\1134682641\ee\AOLHostManager.exe<br>C:\Program Files\Messenger\msmsgs.exe<br>C:\Program Files\Common Files\AOL\1134682641\ee\AOLServiceHost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br>C:\Program Files\Trend Micro\Tmas\Tmas.exe<br>c:\program files\common files\aol\1134682641\ee\services\antiSpywareApp\ver2_0_7\AOLSP Scheduler.exe<br>C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe<br>C:\Program Files\Common Files\AOL\1134682641\ee\AOLServiceHost.exe<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\nda.exe<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\Documents and Settings\HP_Owner\Desktop\hijackthis\HijackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br>O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll<br>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll<br>O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll<br>O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll<br>O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll<br>O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe<br>O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br>O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe<br>O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe<br>O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE<br>O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br>O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe<br>O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE<br>O4 - HKLM\..\Run: [VTTimer] VTTimer.exe<br>O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE<br>O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe<br>O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe<br>O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe<br>O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe<br>O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer<br>O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br>O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE<br>O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br>O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe<br>O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1134682641\ee\AOLHostManager.exe<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br>O4 - Startup: HP Organize.lnk = ?<br>O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe<br>O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br>O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br>O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe<br>O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe<br>O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML<br>O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html<br>O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html<br>O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html<br>O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html<br>O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000<br>O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html<br>O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html<br>O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)<br>O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - &raquo;<A HREF="http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab" >www.symantec.com/techsupp/asa/ct&middot;&middot;&middot;tlsi.cab</A><br>O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - &raquo;<A HREF="http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab" >www.symantec.com/techsupp/asa/ct&middot;&middot;&middot;tlsr.cab</A><br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &raquo;<A HREF="http://go.microsoft.com/fwlink/?linkid=39204" >go.microsoft.com/fwlink/?linkid=39204</A><br>O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - &raquo;<A HREF="http://download.ewido.net/ewidoOnlineScan.cab" >download.ewido.net/ewidoOnlineScan.cab</A><br>O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - &raquo;<A HREF="http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab" >www.symantec.com/techsupp/asa/ct&middot;&middot;&middot;pCtl.cab</A><br>O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - &raquo;<A HREF="http://acs.pandasoftware.com/activescan/as5free/asinst.cab" >acs.pandasoftware.com/activescan&middot;&middot;&middot;inst.cab</A><br>O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - &raquo;<A HREF="http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab" >www.symantec.com/techsupp/asa/ct&middot;&middot;&middot;Data.cab</A><br>O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll<br>O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe<br>O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br>O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe<br>O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe<br>O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe<br>O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe<br>O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe<br>O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br>O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe<br>O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - c:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe<br>O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe<br>O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe<br><br>---------------------------------------------------------<br> ewido security suite - Scan report<br>---------------------------------------------------------<br><br> + Created on:&#9;&#9;&#9;6:37:13 PM, 12/15/2005<br> + Report-Checksum:&#9;&#9;6B3FD045<br><br> + Scan result:<br><br>&#9;No infected objects found.<br><br>::Report End]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15032728</guid>
<pubDate>Thu, 15 Dec 2005 21:38:46 EDT</pubDate>
</item>

<item>
<title>Re: hjt log   Vundo found</title>
<link>http://www.dslreports.com/forum/remark,15031608</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : I hate to be the bearer of bad news but the above will not remove Winfixer if installed (and it looks like it is).  You should first try using Add/Remove programs in the Control Panel because there are bound to be registry entries associated with it and other things HJT doesn't scan for or show on it's log.  Deleting the folder and files you see on HJT won't really remove it, or any program that is actually installed.  Always use Add/Remove programs in the control panel for installed programs.  But that's not the bad news (yet). <br><br> The bad news is, that Add/Remove doesn't remove everything either.  I have been working with a lady in Norway for two weeks who had Winfixer installed.  The best luck we have had with it so far is using Counterspy (they have a free trial version) <br>&raquo;<A HREF="http://www.sunbelt-software.com/CounterSpy-Download.cfm" >www.sunbelt-software.com/Counter&middot;&middot;&middot;load.cfm</A><br>which detects and removes it - but not without some headaches, because Winfixer blocks the scan without some registry edits.  But their tech support can help with that (and I have a copy of the instructions as well).<br><br>Something looks wrong with your Ewido scan log.  Did you use the full system scan?<br><br><I>Edit:  Spelling</I><br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR><br>Microsoft MVP/Windows Security 2003-2006<br><br><BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15031608</guid>
<pubDate>Thu, 15 Dec 2005 19:36:45 EDT</pubDate>
</item>

<item>
<title>Re: hjt log   Vundo found</title>
<link>http://www.dslreports.com/forum/remark,15031373</link>
<description><![CDATA[<A HREF="/useremail/u/1162456"><b>fatdcuk</b></A> : No worries Kevin but hey so far you've been doing a first class job of this removal malarky :)<br>Your last HJT log shows no trace of Vundo :D<br><br>Time to nuke Winfixer and a quick cleanup>>><br><br>1)Please download C/Cleaner>>><br>&raquo;<A HREF="http://majorgeeks.com/CCleaner_d4191.html" >majorgeeks.com/CCleaner_d4191.html</A><br><br>2)Reboot into safe mode and have HJT fixcheck the following entries>>><br><br>O4 - HKLM\..\Run: [NI.UWFX5_0001_LP1014] "C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\C5MN8N2F\WinFixer2005ScannerInstall[1].exe"<br><br>and the following entry if it is still present<br><br>O4 - HKCU\..\Run: [WinFixer2005] "C:\Program Files\WinFixer 2005\uwfx5.exe" /min<br><br>3)Whilst in safe mode please delete the following folder if still present>>><br><br>C:\Program Files\WinFixer 2005<br><br>4)Whilst in safe mode please run c/cleaner<br><br>5)Can you then reboot and post a fresh HJT log for inspection and a desription of any issue's that remain if any ;)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15031373</guid>
<pubDate>Thu, 15 Dec 2005 19:08:12 EDT</pubDate>
</item>

<item>
<title>Re: hjt log   Vundo found</title>
<link>http://www.dslreports.com/forum/remark,15030976</link>
<description><![CDATA[<A HREF="/useremail/u/1301842"><b>gr8thoughts</b></A> : Sorry, sounded likemi was being sarcastic, im not just getting frustrated<br>kevin]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15030976</guid>
<pubDate>Thu, 15 Dec 2005 18:25:39 EDT</pubDate>
</item>

<item>
<title>Re: hjt log   Vundo found</title>
<link>http://www.dslreports.com/forum/remark,15030958</link>
<description><![CDATA[<A HREF="/useremail/u/1301842"><b>gr8thoughts</b></A> : vundofix<br><br>VundoFix V2.15 by Atri<br>----------------------------------------------------------------------------------        ----<br> <br>Listing files contained in the vundofix folder.<br>----------------------------------------------------------------------------------        ----<br> <br>killvundo.bat<br>process.exe<br>ReadMe.txt<br>vundo.reg<br>vundofix.txt<br> <br>----------------------------------------------------------------------------------        ----<br> <br>Filepaths entered<br>----------------------------------------------------------------------------------        ----<br> <br>The filepath entered was c:\windows\system32\ssqrp.dll<br> <br>The second filepath entered was c:\windows\system32\prqss.*<br> <br>----------------------------------------------------------------------------------        ----<br> <br>Log from Process<br>----------------------------------------------------------------------------------        ----<br> <br><br>Killing PID 380 'smss.exe'<br><br>Killing PID 1436 'explorer.exe'<br>Killing PID 1436 'explorer.exe'<br><br>Killing PID 452 'winlogon.exe'<br>Killing PID 452 'winlogon.exe'<br>----------------------------------------------------------------------------------        ----<br> <br>c:\windows\system32\ssqrp.dll Deleted sucessfully.<br>c:\windows\system32\prqss.* Deleted sucessfully.<br> <br>Fixing Registry<br>----------------------------------------------------------------------------------        ----<br> <br>hijack this<br><br>Logfile of HijackThis v1.99.1<br>Scan saved at 2:42:32 PM, on 12/15/2005<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br><br>Running processes:<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\WINDOWS\system32\cmd.exe<br>C:\Documents and Settings\HP_Owner\Desktop\hijackthis\hijackthis.exe<br><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br>O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll<br>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll<br>O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll<br>O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll<br>O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll<br>O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll<br>O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe<br>O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br>O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe<br>O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe<br>O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE<br>O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br>O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe<br>O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE<br>O4 - HKLM\..\Run: [VTTimer] VTTimer.exe<br>O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE<br>O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe<br>O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe<br>O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe<br>O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe<br>O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer<br>O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br>O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE<br>O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br>O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe<br>O4 - HKLM\..\Run: [NI.UWFX5_0001_LP1014] "C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\C5MN8N2F\WinFixer2005ScannerInstall[1].exe"<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe<br>O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1134682641\ee\AOLHostManager.exe<br>O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe<br>O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br>O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br>O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe<br>O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll<br>O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)<br>O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - &raquo;<A HREF="http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab" >www.symantec.com/techsupp/asa/ct&middot;&middot;&middot;tlsi.cab</A><br>O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - &raquo;<A HREF="http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab" >www.symantec.com/techsupp/asa/ct&middot;&middot;&middot;tlsr.cab</A><br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &raquo;<A HREF="http://go.microsoft.com/fwlink/?linkid=39204" >go.microsoft.com/fwlink/?linkid=39204</A><br>O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - &raquo;<A HREF="http://download.ewido.net/ewidoOnlineScan.cab" >download.ewido.net/ewidoOnlineScan.cab</A><br>O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - &raquo;<A HREF="http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab" >www.symantec.com/techsupp/asa/ct&middot;&middot;&middot;pCtl.cab</A><br>O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - &raquo;<A HREF="http://acs.pandasoftware.com/activescan/as5free/asinst.cab" >acs.pandasoftware.com/activescan&middot;&middot;&middot;inst.cab</A><br>O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - &raquo;<A HREF="http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab" >www.symantec.com/techsupp/asa/ct&middot;&middot;&middot;Data.cab</A><br>O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll<br>O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe<br>O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br>O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe<br>O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe<br>O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe<br>O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe<br>O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe<br>O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br>O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe<br>O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - c:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe<br>O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe<br>O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe<br><br>active scan<br><br>Incident                      Status                        Location                                                                                                                                                                                                                                                        <br><br>Dialer:dialer.bny             Not disinfected               C:\WINDOWS\pcconfig.dat                                                                                                                                                                                                                                         <br>Spyware:spyware/virtumonde    Not disinfected               Windows Registry                                                                                                                                                                                                                                                <br>now what????<br>and no, I dont want winfixer on this pc]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15030958</guid>
<pubDate>Thu, 15 Dec 2005 18:23:51 EDT</pubDate>
</item>

<item>
<title>Re: hjt log   Vundo found</title>
<link>http://www.dslreports.com/forum/remark,15030027</link>
<description><![CDATA[<A HREF="/useremail/u/1162456"><b>fatdcuk</b></A> :  <BLOCKQUOTE><SMALL>quote:</SMALL><HR>then installed and ran<br>Java upgrade <HR></BLOCKQUOTE><br>Ok then,you will need to uninstall all earliar versions of Sun JRE inorder to effectively close the exploit/hole.<br><br>:DTime to nail Vundo>>><br><br>Make a copy of these instructions so that you have them handy as the next steps require you to be in safe mode and offline.<br><br>1. Please download VundoFix by Atribune from here:<br><br>www.atribune.org/downloads/VundoFix.exe<br><br>Save it to your desktop <br>Double-click VundoFix.exe to extract the files<br>This will create a folder named VundoFix on your desktop.<br><br>2. After the files are extracted, please reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.<br><br>3. Once in safe mode open the VundoFix folder and doubleclick on KillVundo.bat<br><br>4. You will first be presented with a warning.<br>It should look like this<br><br>quote:<br>--------------------------------------------------------------------------------<br>VundoFix V2.15 by Atri<br>By using VundoFix you agree that you are doing so at your own risk.<br>Press enter to continue....<br><br>--------------------------------------------------------------------------------<br><br>5. At this point press enter one time.<br>Next you will see:<br><br>quote:<br>--------------------------------------------------------------------------------<br>Please Type in the filepath as instructed by the forum staff<br>and then press enter:<br>--------------------------------------------------------------------------------<br><br>At this point please copy and paste in the following file path (make sure to enter it exactly as below!):<br><br>C:\WINDOWS\system32\ssqrp.dll<br><br> <br><br>6. Press *Enter*to continue with the fix.<br><br>7. Next you will see:<br><br>quote:<br>--------------------------------------------------------------------------------<br>Please type in the second file path as instructed by the forum<br>staff then press enter: <br>--------------------------------------------------------------------------------<br><br>At this point please copy and paste in the following file path (make sure to enter it exactly as below!):<br><br>C:\WINDOWS\system32\prqss.*<br><br>8. Press *Enter* to continue with the fix.<br>The fix will run then HijackThis will open, if it does not open automatically please open it manually.<br><br>9. Scan with HijackThis, and place a checkmark next to the following items and click *FIX CHECKED* button<br><br>O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} - C:\WINDOWS\system32\ssqrp.dll<br><br>O20 - Winlogon Notify: ssqrp - C:\WINDOWS\system32\ssqrp.dll<br><br>After you have fixed these items, close Hijackthis.<br><br>10. Press enter to exit the program then manually reboot your computer.<br><br>11. I then need to see 3 log reports from your PC<br>a) Please visit this online scanner and post the log generated>>><br>&raquo;<A HREF="http://www.pandasoftware.com/products/activescan.htm" >www.pandasoftware.com/products/a&middot;&middot;&middot;scan.htm</A><br>b)Please post a copy of the  Vundo.txt file from VundoFix<br>c)A new HJT log<br><br>Finally do you want Winfixer on your PC since it is a very substandard suspect software that is being advertised by dubious methods ?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15030027</guid>
<pubDate>Thu, 15 Dec 2005 16:26:53 EDT</pubDate>
</item>

<item>
<title>Re: hjt log   Vundo found</title>
<link>http://www.dslreports.com/forum/remark,15029998</link>
<description><![CDATA[<A HREF="/useremail/u/1301842"><b>gr8thoughts</b></A> : patiently waiting your reply]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15029998</guid>
<pubDate>Thu, 15 Dec 2005 16:23:16 EDT</pubDate>
</item>

<item>
<title>Re: hjt log   Vundo found</title>
<link>http://www.dslreports.com/forum/remark,15029864</link>
<description><![CDATA[<A HREF="/useremail/u/1162456"><b>fatdcuk</b></A> : Ok,I will be back shortly with a fix for Vundo :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15029864</guid>
<pubDate>Thu, 15 Dec 2005 16:02:49 EDT</pubDate>
</item>

<item>
<title>Re: hjt log   Vundo found</title>
<link>http://www.dslreports.com/forum/remark,15029850</link>
<description><![CDATA[<A HREF="/useremail/u/1301842"><b>gr8thoughts</b></A> : I intalled and ran <br>the fixvundo link from the prescribed link both in safe mode and regular mode<br><br>it returns trojan . vundo found<br>more info link says it is in<br>c:\windows\system32\ssqrp.dll<br><br>then installed and ran<br>Java upgrade <br><br>reran norton, shows virus still intact<br><br>Logfile of HijackThis v1.99.1<br>Scan saved at 12:53:19 PM, on 12/15/2005<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>c:\Program Files\Common Files\Symantec Shared\ccProxy.exe<br>c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>c:\Program Files\Norton AntiVirus\navapsvc.exe<br>c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe<br>C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br>C:\Program Files\ewido\security suite\ewidoctrl.exe<br>C:\Program Files\ewido\security suite\ewidoguard.exe<br>c:\Program Files\Common Files\LightScribe\LSSrvc.exe<br>C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br>c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe<br>C:\windows\system\hpsysdrv.exe<br>C:\WINDOWS\system32\hkcmd.exe<br>C:\WINDOWS\system32\hphmon06.exe<br>C:\HP\KBD\KBD.EXE<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br>C:\WINDOWS\AGRSMMSG.exe<br>C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe<br>C:\Program Files\Common Files\AOL\ACS\AOLDial.exe<br>C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe<br>C:\Program Files\QuickTime\qttask.exe<br>C:\WINDOWS\SOUNDMAN.EXE<br>C:\WINDOWS\ALCWZRD.EXE<br>C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe<br>C:\WINDOWS\ALCMTR.EXE<br>C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Messenger\msmsgs.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br>C:\Program Files\Trend Micro\Tmas\Tmas.exe<br>C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\Documents and Settings\HP_Owner\Desktop\hijackthis\HijackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br>O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll<br>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll<br>O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} - C:\WINDOWS\system32\ssqrp.dll<br>O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll<br>O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll<br>O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll<br>O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll<br>O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe<br>O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br>O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe<br>O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe<br>O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE<br>O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br>O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe<br>O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE<br>O4 - HKLM\..\Run: [VTTimer] VTTimer.exe<br>O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE<br>O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe<br>O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe<br>O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe<br>O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe<br>O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"<br>O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer<br>O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br>O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE<br>O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br>O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe<br>O4 - HKLM\..\Run: [NI.UWFX5_0001_LP1014] "C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\C5MN8N2F\WinFixer2005ScannerInstall[1].exe"<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br>O4 - HKCU\..\Run: [WinFixer2005] "C:\Program Files\WinFixer  2005\uwfx5.exe" /min<br>O4 - Startup: HP Organize.lnk = ?<br>O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe<br>O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br>O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br>O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe<br>O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe<br>O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML<br>O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html<br>O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html<br>O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html<br>O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html<br>O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000<br>O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html<br>O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br>O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll<br>O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O10 - Broken Internet access because of LSP provider 'connwsp.dll' missing<br>O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - &raquo;<A HREF="http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab" >www.symantec.com/techsupp/asa/ct&middot;&middot;&middot;tlsi.cab</A><br>O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - &raquo;<A HREF="http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab" >www.symantec.com/techsupp/asa/ct&middot;&middot;&middot;tlsr.cab</A><br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &raquo;<A HREF="http://go.microsoft.com/fwlink/?linkid=39204" >go.microsoft.com/fwlink/?linkid=39204</A><br>O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - &raquo;<A HREF="http://download.ewido.net/ewidoOnlineScan.cab" >download.ewido.net/ewidoOnlineScan.cab</A><br>O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - &raquo;<A HREF="http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab" >www.symantec.com/techsupp/asa/ct&middot;&middot;&middot;pCtl.cab</A><br>O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - &raquo;<A HREF="http://acs.pandasoftware.com/activescan/as5free/asinst.cab" >acs.pandasoftware.com/activescan&middot;&middot;&middot;inst.cab</A><br>O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - &raquo;<A HREF="http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab" >www.symantec.com/techsupp/asa/ct&middot;&middot;&middot;Data.cab</A><br>O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll<br>O20 - Winlogon Notify: ssqrp - C:\WINDOWS\system32\ssqrp.dll<br>O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe<br>O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br>O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe<br>O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe<br>O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe<br>O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe<br>O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe<br>O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br>O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe<br>O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - c:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe<br>O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe<br>O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15029850</guid>
<pubDate>Thu, 15 Dec 2005 16:00:57 EDT</pubDate>
</item>

<item>
<title>Re: hjt log   Vundo found</title>
<link>http://www.dslreports.com/forum/remark,15026183</link>
<description><![CDATA[<A HREF="/useremail/u/1162456"><b>fatdcuk</b></A> : Hi Gr8thoughts,<br><br>1) If John2G's linked fix dose'nt work can you please post a fresh log so we can tailor you a Vundofix removal :)<br><br>2) If the removal worked then you will need to close the hole that Vundo is using to get onto your PC >>><br>&raquo;<A HREF="http://www.spywarewarrior.com/viewtopic.php?t=17910" >www.spywarewarrior.com/viewtopic.php?t=17910</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15026183</guid>
<pubDate>Thu, 15 Dec 2005 02:22:24 EDT</pubDate>
</item>

<item>
<title>Re: hjt log   Vundo found</title>
<link>http://www.dslreports.com/forum/remark,15026165</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> : I can confirm that you are infected with Vundo. Have you tried this fix?<br><br>&raquo;<A HREF="/faq/security">Security</A> &raquo;<A HREF="/faq/13331">How Do I Remove Trojan Vundo/Winfixer/Virtumonde?</A><br><SMALL>--<br>Better to remain silent and be thought a fool, than to speak and remove all doubt.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15026165</guid>
<pubDate>Thu, 15 Dec 2005 02:13:51 EDT</pubDate>
</item>

<item>
<title>hjt log   Vundo found</title>
<link>http://www.dslreports.com/forum/remark,15025623</link>
<description><![CDATA[<A HREF="/useremail/u/1301842"><b>gr8thoughts</b></A> : norton found TROJAN.VUNDO virus. popup wont close.  System tries to dial out on AOL, I have DSL connection.<br><br>I ran norton av program, it found trojan.vundo, I downloaded and ran fixvundo.exe from norton, virus still there.<br><br>then downloaded and ran cwshredder<br>log:AboutBuster 5.1, reference file 32<br>Scan started on [12/14/2005] at [8:07:14 PM]<br>------------------------------------------------<br>No Ads Found!<br>------------------------------------------------<br>No Files Found!<br>------------------------------------------------<br>Scan was COMPLETED SUCCESSFULLY at 8:08:25 PM<br><br>then downloaded and ran ad aware:<br>log<br><br>Ad-Aware SE Build 1.06r1<br>Logfile Created on:Wednesday, December 14, 2005 8:16:06 PM<br>Created with Ad-Aware SE Personal, free for private use.<br>Using definitions file:SE1R80 14.12.2005<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br>References detected during the scan:<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>MRU List(TAC index:0):16 total references<br>Tracking Cookie(TAC index:3):4 total references<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br>Ad-Aware SE Settings<br>===========================<br>Set : Search for negligible risk entries<br>Set : Safe mode (always request confirmation)<br>Set : Scan active processes<br>Set : Scan registry<br>Set : Deep-scan registry<br>Set : Scan my IE Favorites for banned URLs<br>Set : Scan my Hosts file<br><br>Extended Ad-Aware SE Settings<br>===========================<br>Set : Unload recognized processes & modules during scan<br>Set : Scan registry for all users instead of current user only<br>Set : Always try to unload modules before deletion<br>Set : During removal, unload Explorer and IE if necessary<br>Set : Let Windows remove files in use at next reboot<br>Set : Delete quarantined objects after restoring<br>Set : Include basic Ad-Aware settings in log file<br>Set : Include additional Ad-Aware settings in log file<br>Set : Include reference summary in log file<br>Set : Include alternate data stream details in log file<br>Set : Play sound at scan completion if scan locates critical objects<br><br>12-14-2005 8:16:06 PM - Scan started. (Full System Scan)<br><br> MRU List Object Recognized!<br>    Location:          : C:\Documents and Settings\Administrator\recent<br>    Description        : list of recently opened documents<br><br> MRU List Object Recognized!<br>    Location:          : S-1-5-21-4065565906-4003933091-1074380730-500\software\microsoft\direct3d\mostrecentapplication<br>    Description        : most recent application to use microsoft direct3d<br><br> MRU List Object Recognized!<br>    Location:          : software\microsoft\direct3d\mostrecentapplication<br>    Description        : most recent application to use microsoft direct3d<br><br> MRU List Object Recognized!<br>    Location:          : S-1-5-21-4065565906-4003933091-1074380730-500\software\microsoft\direct3d\mostrecentapplication<br>    Description        : most recent application to use microsoft direct X<br><br> MRU List Object Recognized!<br>    Location:          : software\microsoft\direct3d\mostrecentapplication<br>    Description        : most recent application to use microsoft direct X<br><br> MRU List Object Recognized!<br>    Location:          : software\microsoft\directdraw\mostrecentapplication<br>    Description        : most recent application to use microsoft directdraw<br><br> MRU List Object Recognized!<br>    Location:          : S-1-5-21-4065565906-4003933091-1074380730-500\software\microsoft\internet explorer<br>    Description        : last download directory used in microsoft internet explorer<br><br> MRU List Object Recognized!<br>    Location:          : S-1-5-21-4065565906-4003933091-1074380730-500\software\microsoft\microsoft management console\recent file list<br>    Description        : list of recent snap-ins used in the microsoft management console<br><br> MRU List Object Recognized!<br>    Location:          : S-1-5-21-4065565906-4003933091-1074380730-500\software\microsoft\search assistant\acmru<br>    Description        : list of recent search terms used with the search assistant<br><br> MRU List Object Recognized!<br>    Location:          : S-1-5-21-4065565906-4003933091-1074380730-500\software\microsoft\windows\currentversion\applets\regedit<br>    Description        : last key accessed using the microsoft registry editor<br><br> MRU List Object Recognized!<br>    Location:          : S-1-5-21-4065565906-4003933091-1074380730-500\software\microsoft\windows\currentversion\applets\wordpad\recent file list<br>    Description        : list of recent files opened using wordpad<br><br> MRU List Object Recognized!<br>    Location:          : S-1-5-21-4065565906-4003933091-1074380730-500\software\microsoft\windows\currentversion\explorer\recentdocs<br>    Description        : list of recent documents opened<br><br> MRU List Object Recognized!<br>    Location:          : S-1-5-21-4065565906-4003933091-1074380730-500\software\microsoft\windows\currentversion\explorer\runmru<br>    Description        : mru list for items opened in start | run<br><br> MRU List Object Recognized!<br>    Location:          : .DEFAULT\software\microsoft\windows media\wmsdk\general<br>    Description        : windows media sdk <br><br> MRU List Object Recognized!<br>    Location:          : S-1-5-18\software\microsoft\windows media\wmsdk\general<br>    Description        : windows media sdk <br><br> MRU List Object Recognized!<br>    Location:          : S-1-5-21-4065565906-4003933091-1074380730-500\software\microsoft\windows media\wmsdk\general<br>    Description        : windows media sdk <br><br>Listing running processes<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br>#:1 [smss.exe]<br>    FilePath           : \SystemRoot\System32\<br>    ProcessID          : 380<br>    ThreadCreationTime : 12-15-2005 4:06:18 AM<br>    BasePriority       : Normal<br><br>#:2 [csrss.exe]<br>    FilePath           : \??\C:\WINDOWS\system32\<br>    ProcessID          : 428<br>    ThreadCreationTime : 12-15-2005 4:06:21 AM<br>    BasePriority       : Normal<br><br>#:3 [winlogon.exe]<br>    FilePath           : \??\C:\WINDOWS\system32\<br>    ProcessID          : 452<br>    ThreadCreationTime : 12-15-2005 4:06:22 AM<br>    BasePriority       : High<br><br>#:4 [services.exe]<br>    FilePath           : C:\WINDOWS\system32\<br>    ProcessID          : 496<br>    ThreadCreationTime : 12-15-2005 4:06:23 AM<br>    BasePriority       : Normal<br>    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)<br>    ProductVersion     : 5.1.2600.2180<br>    ProductName        : Microsoft&reg; Windows&reg; Operating System<br>    CompanyName        : Microsoft Corporation<br>    FileDescription    : Services and Controller app<br>    InternalName       : services.exe<br>    LegalCopyright     : &copy; Microsoft Corporation. All rights reserved.<br>    OriginalFilename   : services.exe<br><br>#:5 [lsass.exe]<br>    FilePath           : C:\WINDOWS\system32\<br>    ProcessID          : 508<br>    ThreadCreationTime : 12-15-2005 4:06:23 AM<br>    BasePriority       : Normal<br>    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)<br>    ProductVersion     : 5.1.2600.2180<br>    ProductName        : Microsoft&reg; Windows&reg; Operating System<br>    CompanyName        : Microsoft Corporation<br>    FileDescription    : LSA Shell (Export Version)<br>    InternalName       : lsass.exe<br>    LegalCopyright     : &copy; Microsoft Corporation. All rights reserved.<br>    OriginalFilename   : lsass.exe<br><br>#:6 [svchost.exe]<br>    FilePath           : C:\WINDOWS\system32\<br>    ProcessID          : 656<br>    ThreadCreationTime : 12-15-2005 4:06:24 AM<br>    BasePriority       : Normal<br>    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)<br>    ProductVersion     : 5.1.2600.2180<br>    ProductName        : Microsoft&reg; Windows&reg; Operating System<br>    CompanyName        : Microsoft Corporation<br>    FileDescription    : Generic Host Process for Win32 Services<br>    InternalName       : svchost.exe<br>    LegalCopyright     : &copy; Microsoft Corporation. All rights reserved.<br>    OriginalFilename   : svchost.exe<br><br>#:7 [svchost.exe]<br>    FilePath           : C:\WINDOWS\system32\<br>    ProcessID          : 704<br>    ThreadCreationTime : 12-15-2005 4:06:25 AM<br>    BasePriority       : Normal<br>    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)<br>    ProductVersion     : 5.1.2600.2180<br>    ProductName        : Microsoft&reg; Windows&reg; Operating System<br>    CompanyName        : Microsoft Corporation<br>    FileDescription    : Generic Host Process for Win32 Services<br>    InternalName       : svchost.exe<br>    LegalCopyright     : &copy; Microsoft Corporation. All rights reserved.<br>    OriginalFilename   : svchost.exe<br><br>#:8 [svchost.exe]<br>    FilePath           : C:\WINDOWS\system32\<br>    ProcessID          : 812<br>    ThreadCreationTime : 12-15-2005 4:06:25 AM<br>    BasePriority       : Normal<br>    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)<br>    ProductVersion     : 5.1.2600.2180<br>    ProductName        : Microsoft&reg; Windows&reg; Operating System<br>    CompanyName        : Microsoft Corporation<br>    FileDescription    : Generic Host Process for Win32 Services<br>    InternalName       : svchost.exe<br>    LegalCopyright     : &copy; Microsoft Corporation. All rights reserved.<br>    OriginalFilename   : svchost.exe<br><br>#:9 [svchost.exe]<br>    FilePath           : C:\WINDOWS\system32\<br>    ProcessID          : 824<br>    ThreadCreationTime : 12-15-2005 4:06:25 AM<br>    BasePriority       : Normal<br>    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)<br>    ProductVersion     : 5.1.2600.2180<br>    ProductName        : Microsoft&reg; Windows&reg; Operating System<br>    CompanyName        : Microsoft Corporation<br>    FileDescription    : Generic Host Process for Win32 Services<br>    InternalName       : svchost.exe<br>    LegalCopyright     : &copy; Microsoft Corporation. All rights reserved.<br>    OriginalFilename   : svchost.exe<br><br>#:10 [svchost.exe]<br>    FilePath           : C:\WINDOWS\system32\<br>    ProcessID          : 900<br>    ThreadCreationTime : 12-15-2005 4:06:25 AM<br>    BasePriority       : Normal<br>    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)<br>    ProductVersion     : 5.1.2600.2180<br>    ProductName        : Microsoft&reg; Windows&reg; Operating System<br>    CompanyName        : Microsoft Corporation<br>    FileDescription    : Generic Host Process for Win32 Services<br>    InternalName       : svchost.exe<br>    LegalCopyright     : &copy; Microsoft Corporation. All rights reserved.<br>    OriginalFilename   : svchost.exe<br><br>#:11 [explorer.exe]<br>    FilePath           : C:\WINDOWS\<br>    ProcessID          : 1372<br>    ThreadCreationTime : 12-15-2005 4:06:40 AM<br>    BasePriority       : Normal<br>    FileVersion        : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)<br>    ProductVersion     : 6.00.2900.2180<br>    ProductName        : Microsoft&reg; Windows&reg; Operating System<br>    CompanyName        : Microsoft Corporation<br>    FileDescription    : Windows Explorer<br>    InternalName       : explorer<br>    LegalCopyright     : &copy; Microsoft Corporation. All rights reserved.<br>    OriginalFilename   : EXPLORER.EXE<br><br>#:12 [iexplore.exe]<br>    FilePath           : C:\Program Files\Internet Explorer\<br>    ProcessID          : 1740<br>    ThreadCreationTime : 12-15-2005 4:09:36 AM<br>    BasePriority       : Normal<br>    FileVersion        : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)<br>    ProductVersion     : 6.00.2900.2180<br>    ProductName        : Microsoft&reg; Windows&reg; Operating System<br>    CompanyName        : Microsoft Corporation<br>    FileDescription    : Internet Explorer<br>    InternalName       : iexplore<br>    LegalCopyright     : &copy; Microsoft Corporation. All rights reserved.<br>    OriginalFilename   : IEXPLORE.EXE<br><br>#:13 [ctfmon.exe]<br>    FilePath           : C:\WINDOWS\system32\<br>    ProcessID          : 1812<br>    ThreadCreationTime : 12-15-2005 4:09:38 AM<br>    BasePriority       : Normal<br>    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)<br>    ProductVersion     : 5.1.2600.2180<br>    ProductName        : Microsoft&reg; Windows&reg; Operating System<br>    CompanyName        : Microsoft Corporation<br>    FileDescription    : CTF Loader<br>    InternalName       : CTFMON<br>    LegalCopyright     : &copy; Microsoft Corporation. All rights reserved.<br>    OriginalFilename   : CTFMON.EXE<br><br>#:14 [ad-aware.exe]<br>    FilePath           : C:\Program Files\Lavasoft\Ad-Aware SE Personal\<br>    ProcessID          : 1916<br>    ThreadCreationTime : 12-15-2005 4:15:20 AM<br>    BasePriority       : Normal<br>    FileVersion        : 6.2.0.236<br>    ProductVersion     : SE 106<br>    ProductName        : Lavasoft Ad-Aware SE<br>    CompanyName        : Lavasoft Sweden<br>    FileDescription    : Ad-Aware SE Core application<br>    InternalName       : Ad-Aware.exe<br>    LegalCopyright     : Copyright &copy; Lavasoft AB Sweden<br>    OriginalFilename   : Ad-Aware.exe<br>    Comments           : All Rights Reserved<br><br>Memory scan result:<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>New critical objects: 0<br>Objects found so far: 16<br><br>Started registry scan<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br>Registry Scan result:<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>New critical objects: 0<br>Objects found so far: 16<br><br>Started deep registry scan<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br>Deep registry scan result:<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>New critical objects: 0<br>Objects found so far: 16<br><br>Started Tracking Cookie scan<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br>Tracking cookie scan result:<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>New critical objects: 0<br>Objects found so far: 16<br><br>Deep scanning and examining files (C:)<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br> Tracking Cookie Object Recognized!<br>    Type               : IECache Entry<br>    Data               : hp_owner@2o7[1].txt<br>    TAC Rating         : 3<br>    Category           : Data Miner<br>    Comment            : <br>    Value              : C:\Documents and Settings\HP_Owner\Cookies\hp_owner@2o7[1].txt<br><br> Tracking Cookie Object Recognized!<br>    Type               : IECache Entry<br>    Data               : hp_owner@atdmt[2].txt<br>    TAC Rating         : 3<br>    Category           : Data Miner<br>    Comment            : <br>    Value              : C:\Documents and Settings\HP_Owner\Cookies\hp_owner@atdmt[2].txt<br><br> Tracking Cookie Object Recognized!<br>    Type               : IECache Entry<br>    Data               : hp_owner@doubleclick[1].txt<br>    TAC Rating         : 3<br>    Category           : Data Miner<br>    Comment            : <br>    Value              : C:\Documents and Settings\HP_Owner\Cookies\hp_owner@doubleclick[1].txt<br><br> Tracking Cookie Object Recognized!<br>    Type               : IECache Entry<br>    Data               : hp_owner@tribalfusion[1].txt<br>    TAC Rating         : 3<br>    Category           : Data Miner<br>    Comment            : <br>    Value              : C:\Documents and Settings\HP_Owner\Cookies\hp_owner@tribalfusion[1].txt<br><br>Disk Scan Result for C:\<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>New critical objects: 0<br>Objects found so far: 20<br><br>Deep scanning and examining files (D:)<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br>Disk Scan Result for D:\<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>New critical objects: 0<br>Objects found so far: 20<br><br>Scanning Hosts file......<br>Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br>Hosts file scan result:<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>1 entries scanned.<br>New critical objects:0<br>Objects found so far: 20<br><br>Performing conditional scans...<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br>Conditional scan result:<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>New critical objects: 0<br>Objects found so far: 20<br><br>8:22:11 PM Scan Complete<br><br>Summary Of This Scan<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>Total scanning time:00:06:04.953<br>Objects scanned:158472<br>Objects identified:4<br>Objects ignored:0<br>New critical objects:4<br><br>ran ewido<br>log:<br>--------------------------------- Anti-Spyware session started ---------------------------------<br>Machine=CARCRAZY<br>Time=Wed Dec 14 16:03:52 2005<br>Product Version=3, 0, 1, 23<br>OS Version=Microsoft Windows XP Home Edition Service Pack 2 (Build 2600)<br><br>&#9;&#9;Started Scanning<br>&#9;&#9;Programs in Memory<br>&#9;&#9;Finished Scanning<br>&#9;&#9;Started Scanning<br>&#9;&#9;Internet Cookies<br>&#9;&#9;CoolWebSearch Variants (CWShredder)<br>&#9;&#9;&#9;CoolWebSearch Variants (CWShredder): Found 'CWS.MSConfig' in ''<br>&#9;&#9;Programs in Memory<br>&#9;&#9;Windows Registry<br>&#9;&#9;Internet URL Shortcuts<br>&#9;&#9;Files and Directories<br>&#9;&#9;Finished Scanning<br>&#9;&#9;Started Backup<br>&#9;&#9;Finished Backup<br>&#9;&#9;Started Cleaning<br>&#9;&#9;&#9;CoolWebSearch Variants (CWShredder): Cleaned 'CWS.MSConfig' in ''<br>&#9;&#9;Finished Cleaning<br>&#9;&#9;Started Cleaning<br>&#9;&#9;Internet Explorer/MSN/AOL Cache<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Internet Explorer/MSN/AOL Cache' in ''<br>&#9;&#9;Internet Browser History<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Internet Browser History' in ''<br>&#9;&#9;AOL URL History<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'AOL URL History' in ''<br>&#9;&#9;Media Player history<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Media Player history' in ''<br>&#9;&#9;RealPlayer History<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'RealPlayer History' in ''<br>&#9;&#9;Windows common dialog recently used file list<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Windows common dialog recently used file list' in ''<br>&#9;&#9;Windows Search History<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Windows Search History' in ''<br>&#9;&#9;Windows Temp Files<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Windows Temp Files' in ''<br>&#9;&#9;Windows Document History<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Windows Document History' in ''<br>&#9;&#9;Windows Run History<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Windows Run History' in ''<br>&#9;&#9;Recycle Bin<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Recycle Bin' in ''<br>&#9;&#9;Start Menu Order/Click History<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Start Menu Order/Click History' in ''<br>&#9;&#9;MS Download Temp Directory<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'MS Download Temp Directory' in ''<br>&#9;&#9;Google Search History<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Google Search History' in ''<br>&#9;&#9;Winzip Recent File List<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Winzip Recent File List' in ''<br>&#9;&#9;Adobe Acrobat recent file list<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Adobe Acrobat recent file list' in ''<br>&#9;&#9;Microsoft Word recent file list<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Microsoft Word recent file list' in ''<br>&#9;&#9;Microsoft Excel recent file list<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Microsoft Excel recent file list' in ''<br>&#9;&#9;Microsoft PowerPoint recent file list<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Microsoft PowerPoint recent file list' in ''<br>&#9;&#9;Microsoft Access recent file list<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Microsoft Access recent file list' in ''<br>&#9;&#9;Internet Explorer Auto-complete data<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Internet Explorer Auto-complete data' in ''<br>&#9;&#9;Jasc Paint Shop Pro History<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Jasc Paint Shop Pro History' in ''<br>&#9;&#9;AOL Instant Messenger Recent Users<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'AOL Instant Messenger Recent Users' in ''<br>&#9;&#9;AOL Instant Messenger Download Folder<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'AOL Instant Messenger Download Folder' in ''<br>&#9;&#9;Yahoo Messenger User Profiles<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Yahoo Messenger User Profiles' in ''<br>&#9;&#9;Yahoo Messenger Transaction Log<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Yahoo Messenger Transaction Log' in ''<br>&#9;&#9;Cookies<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Cookies' in ''<br>&#9;&#9;Finished Cleaning<br>&#9;&#9;&#9;IE Plugins: Found '{B313D637-F405-4052-AC37-E2119AB3C8F8}' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects'<br>&#9;&#9;&#9;IE Plugins: Found '{4982D40A-C53B-4615-B15B-B5B5E98D167C}' in 'SOFTWARE\Microsoft\Internet Explorer\Toolbar'<br>&#9;&#9;&#9;Web Browser Security Settings: Found 'Start Page' in 'SOFTWARE\Microsoft\Internet Explorer\Main'<br>&#9;&#9;&#9;Web Browser Security Settings: Found 'Default_Page_URL' in 'SOFTWARE\Microsoft\Internet Explorer\Main'<br>&#9;&#9;&#9;Web Browser Security Settings: Found 'Search Page' in 'SOFTWARE\Microsoft\Internet Explorer\Main'<br>&#9;&#9;&#9;Web Browser Security Settings: Found 'Default_Search_URL' in 'SOFTWARE\Microsoft\Internet Explorer\Main'<br>&#9;&#9;&#9;Web Browser Security Settings: Found 'Search Bar' in 'SOFTWARE\Microsoft\Internet Explorer\Main'<br>&#9;&#9;&#9;IE Downloaded Program Files: Found 'ewidoOnlineScan Control' in 'C:\WINDOWS\Downloaded Program Files\ewidoOnlineScan.dll'<br>&#9;&#9;&#9;IE Downloaded Program Files: Found 'ActiveScan Installer Class' in 'C:\WINDOWS\Downloaded Program Files\asinst.inf'<br>&#9;&#9;&#9;Layered Service Providers (LSP's): Found 'Port Magic Chain over MSAFD Tcpip [UDP/IP]' in 'C:\WINDOWS\system32\connwsp.dll'<br>&#9;&#9;&#9;Layered Service Providers (LSP's): Found 'Port Magic Chain over RSVP UDP Service Provider' in 'C:\WINDOWS\system32\connwsp.dll'<br>&#9;&#9;&#9;Layered Service Providers (LSP's): Found 'Port Magic Chain over MSAFD Tcpip [TCP/IP]' in 'C:\WINDOWS\system32\connwsp.dll'<br>&#9;&#9;&#9;Layered Service Providers (LSP's): Found 'Port Magic Chain over RSVP TCP Service Provider' in 'C:\WINDOWS\system32\connwsp.dll'<br>&#9;&#9;&#9;Layered Service Providers (LSP's): Found 'Port Magic LSP ' in 'C:\WINDOWS\system32\connwsp.dll'<br>&#9;&#9;&#9;Windows Policy Settings: Found 'restrictanonymous' in 'SYSTEM\CurrentControlSet\Control\Lsa'<br>&#9;&#9;&#9;Windows Policy Settings: Found 'forceunlocklogon' in 'SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon'<br>&#9;&#9;&#9;Windows Policy Settings: Found 'wuauserv' in ''<br>&#9;&#9;&#9;Services: Found 'AOL Connectivity Service' in ''<br>&#9;&#9;&#9;Services: Found 'ewido security suite control' in ''<br>&#9;&#9;&#9;Services: Found 'ewido security suite guard' in ''<br>&#9;&#9;&#9;Windows Shell Settings: Found '{54D9498B-CF93-414F-8984-8CE7FDE0D391}' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks'<br>&#9;&#9;&#9;Windows Shell Settings: Found 'foldalyzer' in 'SOFTWARE\Classes\Folder\shell\foldalyzer'<br>&#9;&#9;&#9;Windows Shell Settings: Found 'ewido' in 'SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\ewido'<br>&#9;&#9;&#9;Windows Shell Settings: Found 'Personal' in 'Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders'<br>&#9;&#9;&#9;Program Startup Areas: Found 'HotKeysCmds' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'<br>&#9;&#9;&#9;Program Startup Areas: Found 'TkBellExe' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'<br>&#9;&#9;&#9;Program Startup Areas: Found 'Recguard' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'<br>&#9;&#9;&#9;Program Startup Areas: Found 'VTTimer' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'<br>&#9;&#9;&#9;Program Startup Areas: Found 'AlcxMonitor' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'<br>&#9;&#9;&#9;Program Startup Areas: Found 'AGRSMMSG' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'<br>&#9;&#9;&#9;Program Startup Areas: Found 'AOLDialer' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'<br>&#9;&#9;&#9;Program Startup Areas: Found 'AOL Spyware Protection' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'<br>&#9;&#9;&#9;Program Startup Areas: Found 'Pure Networks Port Magic' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'<br>&#9;&#9;&#9;Program Startup Areas: Found 'SoundMan' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'<br>&#9;&#9;&#9;Program Startup Areas: Found 'AlcWzrd' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'<br>&#9;&#9;&#9;Program Startup Areas: Found 'Alcmtr' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'<br>&#9;&#9;&#9;Program Startup Areas: Found 'NI.UWFX5_0001_LP1014' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'<br>&#9;&#9;&#9;Program Startup Areas: Found 'C:\Program Files\America Online 9.0\aoltray.exe -check' in 'C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk'<br>--------------------------------- Anti-Spyware session ended ---------------------------------<br><br>--------------------------------- Anti-Spyware session started ---------------------------------<br>Machine=CARCRAZY<br>Time=Wed Dec 14 17:49:12 2005<br>Product Version=3, 0, 1, 23<br>OS Version=Microsoft Windows XP Home Edition Service Pack 2 (Build 2600)<br><br>&#9;&#9;Internet Explorer/MSN/AOL Cache<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Internet Explorer/MSN/AOL Cache' in ''<br>&#9;&#9;Internet Browser History<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Internet Browser History' in ''<br>&#9;&#9;AOL URL History<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'AOL URL History' in ''<br>&#9;&#9;Media Player history<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Media Player history' in ''<br>&#9;&#9;RealPlayer History<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'RealPlayer History' in ''<br>&#9;&#9;Windows common dialog recently used file list<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Windows common dialog recently used file list' in ''<br>&#9;&#9;Windows Search History<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Windows Search History' in ''<br>&#9;&#9;Windows Temp Files<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Windows Temp Files' in ''<br>&#9;&#9;Windows Document History<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Windows Document History' in ''<br>&#9;&#9;Windows Run History<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Windows Run History' in ''<br>&#9;&#9;Recycle Bin<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Recycle Bin' in ''<br>&#9;&#9;Start Menu Order/Click History<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Start Menu Order/Click History' in ''<br>&#9;&#9;MS Download Temp Directory<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'MS Download Temp Directory' in ''<br>&#9;&#9;Google Search History<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Google Search History' in ''<br>&#9;&#9;Winzip Recent File List<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Winzip Recent File List' in ''<br>&#9;&#9;Adobe Acrobat recent file list<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Adobe Acrobat recent file list' in ''<br>&#9;&#9;Microsoft Word recent file list<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Microsoft Word recent file list' in ''<br>&#9;&#9;Microsoft Excel recent file list<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Microsoft Excel recent file list' in ''<br>&#9;&#9;Microsoft PowerPoint recent file list<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Microsoft PowerPoint recent file list' in ''<br>&#9;&#9;Microsoft Access recent file list<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Microsoft Access recent file list' in ''<br>&#9;&#9;Internet Explorer Auto-complete data<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Internet Explorer Auto-complete data' in ''<br>&#9;&#9;Jasc Paint Shop Pro History<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Jasc Paint Shop Pro History' in ''<br>&#9;&#9;AOL Instant Messenger Recent Users<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'AOL Instant Messenger Recent Users' in ''<br>&#9;&#9;AOL Instant Messenger Download Folder<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'AOL Instant Messenger Download Folder' in ''<br>&#9;&#9;Yahoo Messenger User Profiles<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Yahoo Messenger User Profiles' in ''<br>&#9;&#9;Yahoo Messenger Transaction Log<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Yahoo Messenger Transaction Log' in ''<br>&#9;&#9;Cookies<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Cookies' in ''<br>&#9;&#9;Started Scanning<br>&#9;&#9;Programs in Memory<br>&#9;&#9;Finished Scanning<br>&#9;&#9;Started Scanning<br>&#9;&#9;CoolWebSearch Variants (CWShredder)<br>&#9;&#9;Finished Scanning<br>--------------------------------- Anti-Spyware session started ---------------------------------<br>Machine=CARCRAZY<br>Time=Wed Dec 14 18:31:52 2005<br>Product Version=3, 0, 1, 23<br>OS Version=Microsoft Windows XP Home Edition Service Pack 2 (Build 2600)<br><br>&#9;&#9;Started Scanning<br>&#9;&#9;Programs in Memory<br>&#9;&#9;Finished Scanning<br>&#9;&#9;&#9;Web Browser Security Settings: Found 'Start Page' in 'SOFTWARE\Microsoft\Internet Explorer\Main'<br>&#9;&#9;&#9;Web Browser Security Settings: Found 'Default_Page_URL' in 'SOFTWARE\Microsoft\Internet Explorer\Main'<br>&#9;&#9;&#9;Web Browser Security Settings: Found 'Search Page' in 'SOFTWARE\Microsoft\Internet Explorer\Main'<br>&#9;&#9;&#9;Web Browser Security Settings: Found 'Default_Search_URL' in 'SOFTWARE\Microsoft\Internet Explorer\Main'<br>&#9;&#9;&#9;Web Browser Security Settings: Found 'Search Bar' in 'SOFTWARE\Microsoft\Internet Explorer\Main'<br>&#9;&#9;&#9;Web Browser Security Settings: Found 'DefaultSearchURL' in 'SOFTWARE\Microsoft\Search Assistant'<br>&#9;&#9;&#9;Web Browser Security Settings: Found 'WarnOnZoneCrossing' in 'Software\Microsoft\Windows\CurrentVersion\Internet Settings'<br>&#9;&#9;&#9;Web Browser Security Settings: Found 'AOL Toolbar search' in 'Software\Microsoft\Internet Explorer\MenuExt\&AOL Toolbar search'<br>--------------------------------- Anti-Spyware session started ---------------------------------<br>Machine=CARCRAZY<br>Time=Wed Dec 14 20:24:31 2005<br>Product Version=3, 0, 1, 23<br>OS Version=Microsoft Windows XP Home Edition Service Pack 2 (Build 2600)<br><br>&#9;&#9;Internet Explorer/MSN/AOL Cache<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Internet Explorer/MSN/AOL Cache' in ''<br>&#9;&#9;Internet Browser History<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Internet Browser History' in ''<br>&#9;&#9;AOL URL History<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'AOL URL History' in ''<br>&#9;&#9;Media Player history<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Media Player history' in ''<br>&#9;&#9;RealPlayer History<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'RealPlayer History' in ''<br>&#9;&#9;Windows common dialog recently used file list<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Windows common dialog recently used file list' in ''<br>&#9;&#9;Windows Search History<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Windows Search History' in ''<br>&#9;&#9;Windows Temp Files<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Windows Temp Files' in ''<br>&#9;&#9;Windows Document History<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Windows Document History' in ''<br>&#9;&#9;Windows Run History<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Windows Run History' in ''<br>&#9;&#9;Recycle Bin<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Recycle Bin' in ''<br>&#9;&#9;Start Menu Order/Click History<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Start Menu Order/Click History' in ''<br>&#9;&#9;MS Download Temp Directory<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'MS Download Temp Directory' in ''<br>&#9;&#9;Google Search History<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Google Search History' in ''<br>&#9;&#9;Winzip Recent File List<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Winzip Recent File List' in ''<br>&#9;&#9;Adobe Acrobat recent file list<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Adobe Acrobat recent file list' in ''<br>&#9;&#9;Microsoft Word recent file list<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Microsoft Word recent file list' in ''<br>&#9;&#9;Microsoft Excel recent file list<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Microsoft Excel recent file list' in ''<br>&#9;&#9;Microsoft PowerPoint recent file list<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Microsoft PowerPoint recent file list' in ''<br>&#9;&#9;Microsoft Access recent file list<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Microsoft Access recent file list' in ''<br>&#9;&#9;Internet Explorer Auto-complete data<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Internet Explorer Auto-complete data' in ''<br>&#9;&#9;Jasc Paint Shop Pro History<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Jasc Paint Shop Pro History' in ''<br>&#9;&#9;AOL Instant Messenger Recent Users<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'AOL Instant Messenger Recent Users' in ''<br>&#9;&#9;AOL Instant Messenger Download Folder<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'AOL Instant Messenger Download Folder' in ''<br>&#9;&#9;Yahoo Messenger User Profiles<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Yahoo Messenger User Profiles' in ''<br>&#9;&#9;Yahoo Messenger Transaction Log<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Yahoo Messenger Transaction Log' in ''<br>&#9;&#9;Cookies<br>&#9;&#9;&#9;Delete History Items on Startup: Cleaned 'Cookies' in ''<br>&#9;&#9;Started Scanning<br>&#9;&#9;Programs in Memory<br>&#9;&#9;Finished Scanning<br>&#9;&#9;Started Scanning<br>&#9;&#9;Internet Cookies<br>&#9;&#9;CoolWebSearch Variants (CWShredder)<br>&#9;&#9;Programs in Memory<br>&#9;&#9;Windows Registry<br>&#9;&#9;&#9;Windows Registry: Found '' in 'PCheck.PCheck.1'<br>&#9;&#9;&#9;Windows Registry: Found '' in 'TypeLib\{3BFF2EF1-25BA-4342-A1E8-EC1E2CB9F22B}'<br>&#9;&#9;&#9;Windows Registry: Found '' in 'Interface\{FC0FE3C3-3359-4CF5-A72D-7F361FA0ECEB}'<br>&#9;&#9;&#9;Windows Registry: Found '' in 'CLSID\{FD1A9E6B-05DA-4ca2-830D-654DA1DDBD9E}'<br>&#9;&#9;&#9;Scanning is stopping...<br><br>then ran hijack this<br>Log:<br>Logfile of HijackThis v1.99.1<br>Scan saved at 8:31:22 PM, on 12/14/2005<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Trend Micro\Tmas\Tmas.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe<br><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll<br>O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll<br>O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} - C:\WINDOWS\system32\ssqrp.dll<br>O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll<br>O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll<br>O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll<br>O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe<br>O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe<br>O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br>O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe<br>O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe<br>O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE<br>O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br>O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe<br>O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE<br>O4 - HKLM\..\Run: [VTTimer] VTTimer.exe<br>O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE<br>O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe<br>O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe<br>O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe<br>O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe<br>O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"<br>O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer<br>O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br>O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE<br>O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br>O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe<br>O4 - HKLM\..\Run: [NI.UWFX5_0001_LP1014] "C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\C5MN8N2F\WinFixer2005ScannerInstall[1].exe"<br>O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe<br>O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br>O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br>O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe<br>O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll<br>O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll<br>O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O10 - Broken Internet access because of LSP provider 'connwsp.dll' missing<br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &raquo;<A HREF="http://go.microsoft.com/fwlink/?linkid=39204" >go.microsoft.com/fwlink/?linkid=39204</A><br>O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - &raquo;<A HREF="http://download.ewido.net/ewidoOnlineScan.cab" >download.ewido.net/ewidoOnlineScan.cab</A><br>O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - &raquo;<A HREF="http://acs.pandasoftware.com/activescan/as5free/asinst.cab" >acs.pandasoftware.com/activescan&middot;&middot;&middot;inst.cab</A><br>O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll<br>O20 - Winlogon Notify: ssqrp - C:\WINDOWS\system32\ssqrp.dll<br>O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe<br>O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe<br>O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe<br>O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe<br>O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe<br>O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe<br>O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe<br>O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - c:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe<br>O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe<br>O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe<br><br>thank you,<br>Kevin]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15025623</guid>
<pubDate>Wed, 14 Dec 2005 23:48:35 EDT</pubDate>
</item>

</channel>
</rss>
