<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>browser redirect and sluggish startup; HT log added in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r20389409</link>
<description></description>
<language>en</language>
<pubDate>Fri, 25 Jul 2008 20:36:41 EDT</pubDate>
<lastBuildDate>Fri, 25 Jul 2008 20:36:41 EDT</lastBuildDate>

<item>
<title>Re: browser redirect and sluggish startup; HT log added</title>
<link>http://www.dslreports.com/forum/remark,20438270</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Look again.  You want the <b>JRE, Type SE</b>, not any other type. (It is the fifth choice on the site). Click the "Download" button.  Set the scroll box choices to "Windows" and "Multi-Language."  The "<b>Offline Installation</b>" download choice you will then see as an offering is a complete download of the update, requiring no communication during its installation with Sun.  Do not check the box, just click the light blue link below the description of the Offline choice to start the download.  The download is 15.21 MB in size.<br><br>When finished, follow my earlier instructions on running this, and deleting older versions.<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20438270</guid>
<pubDate>Tue, 06 May 2008 03:32:12 EDT</pubDate>
</item>

<item>
<title>Re: browser redirect and sluggish startup; HT log added</title>
<link>http://www.dslreports.com/forum/remark,20438175</link>
<description><![CDATA[<A HREF="/useremail/u/516889"><b>RandallW</b></A> : I downloaded the first file ( the JNLP type ), which then tries download the large executable; the download attempt barfs at %5, then retries 20 times ( by default setup ).]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20438175</guid>
<pubDate>Tue, 06 May 2008 02:34:12 EDT</pubDate>
</item>

<item>
<title>Re: browser redirect and sluggish startup; HT log added</title>
<link>http://www.dslreports.com/forum/remark,20422129</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Go to &raquo;<A HREF="http://java.sun.com/javase/downloads/index.jsp" >java.sun.com/javase/downloads/index.jsp</A> <br><br>Locate:  Download Java Runtime Environment (JRE) 6 Update 6<br><br>Without checking the box, click on jre-6u6-windows-i586-p.exe directly underneath Windows Offline Installation <br>SAVE it to your desktop, do <u>not</u> RUN it.<br><br>When the download is complete, close all browser windows and double-click on the saved file (jre-6u6-windows-i586-p.exe) to install the update. Be patient: It may take five (5) minutes or more for the installation to complete.<br>UNCHECK the option to install Google Toolbar if you don't want it.  Delete the downloaded installation file after completing the above procedure  and reboot if not prompted to do so. <br><br>Open Control Panel > Add/Remove Programs:<br>Uninstall anything that says Sun Java, Java JRE, or similar <b>except Java TM 6 Update 6</b> which you just installed.<br>Close Add/Remove Programs.<br><br>In Windows Explorer, navigate to C:\Program Files\Java. Delete any subfolders <b>except the subfolder jre1.6.0_06</b> which was just created by the installation above.<br><br>Do NOT delete C:\Program Files\JavaVM --<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20422129</guid>
<pubDate>Fri, 02 May 2008 16:01:33 EDT</pubDate>
</item>

<item>
<title>Re: browser redirect and sluggish startup; HT log added</title>
<link>http://www.dslreports.com/forum/remark,20421290</link>
<description><![CDATA[<A HREF="/useremail/u/516889"><b>RandallW</b></A> : The Sun website is not user intuitive, so I wasn't able to find an update for Java.  I do not have a full version of Acrobat; just free Adobe Reader.  Everything else was done.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20421290</guid>
<pubDate>Fri, 02 May 2008 13:06:34 EDT</pubDate>
</item>

<item>
<title>Re: browser redirect and sluggish startup; HT log added</title>
<link>http://www.dslreports.com/forum/remark,20412003</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : 1. Run <b>MBAM</b> once again, just as we did previously.<br>I will not need a log file from this session.<br>Uninstall MBAM when done using Add or Remove Programs.<br><br>2. Open a new Notepad session - (Do <b><i>not</i></b> use a Word Processor or WordPad).  Click "<b>Format</b>" and be certain that Word Wrap is not enabled.  Right-click | <b>Paste</b> the Code box contents from below into Notepad.  Click File, <b><i>Save as...</i></b>, and set the location to your Desktop, and enter (including quotation marks) as the filename: <b>"CFscript.txt"</b> .  <br><br><textarea name="code" class="text" cols=50 rows=10>File::&#012;C:\WINDOWS\system32\onnmp.bak1&#012; &#012;Registry::&#012;&#91;-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtUmJDuS&#93;&#012;&#91;-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1C1CE040-5D65-422E-84C6-EFD6EEFCFA93}&#93;&#012;&#91;-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{259274E6-3FEB-5341-BD13-A1A07A9AD77A}&#93;&#012;&#91;-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2B76EB42-6211-417E-9A5D-EA8233C749EB}&#93;&#012;&#91;-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2CB8C4B2-9DAF-4263-818E-835A955224D1}&#93;&#012;&#91;-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A8FB8EB3-183B-4598-924D-86F0E5E37085}&#93;&#012;&#91;-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BF27A651-36B9-4264-848E-87911D600D4B}&#93;&#012;&#91;-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F6C97034-AD95-4205-8055-CAED72E7282A}&#93;&#012;&#91;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&#93;&#012;"BM2bfe5c27"=-&#012; &#012;</textarea><!--end code block--><br>&#8226; Disconnect from the Internet.<br>&#8226; Disable your Antivirus.  If the Antivirus software you use has any Script Blocking features, be certain to disable these as well.<br><b> Important:  </b> Have no other programs running.  Your Task Bar should be clear of any program entries including your Browser.<br>&#8226; A window will open with a warning.  Accept any Disclaimers to start the fix.<br>Using your mouse, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown in this little picture:<br> <IMG SRC="http://users.pandora.be/bluepatchy/miekiemoes/images/CFScript.gif"> <br>I will not need a log from this Combofix session.<br><br>Open <b>Acrobat</b> if you have the Full Version installed  Click <b>Help</b> and run the <b>Upgrade</b> applet found there.  If no update is offered:  Use the Preferences, Internet submenu of Acrobat and uncheck to integrate with your Browser.  Close Acrobat.<br>Whether you had the Full Version of Acrobat or not, download and install <b>Adobe Reader 8.1.1</b> and use this as the integrated PDF Reader insider your browser:  &raquo;<A HREF="http://www.adobe.com/products/acrobat/readstep2.html" >www.adobe.com/products/acrobat/r&middot;&middot;&middot;ep2.html</A><br><br><b><u>Clean-up & Prevention:</u></b><br><br>&#8226;  Right click "My Computer", Properties, and then click the System Restore tab.  <b>Checkmark</b> the box at the top to stop System Restore on all drives.  Click the "<b>Apply</b>" button.  Agree to the deletion of old Restore Points.  Then <b><u>uncheck</u></b> the box at the top and again click the "<b>Apply</b>" button.  Finally, click the "<b>OK</b>" button.  This will create a new Restore Point reflecting your clean system state.<br><br>&#8226; Click <b>Start</b>, then click <b>Run</b>.<br>Enter into the command box that opens:  <b>combofix /u</b> and then click <b>OK</b>.<br>(If we have renamed this file, please use the current name for the program in this instruction.)<br> <IMG SRC="http://i78.photobucket.com/albums/j116/amateur_photos/CFuninstall.png"> <br><br>&#8226; Run <b>ATF Cleaner</b>  <IMG SRC="http://www.geekstogo.com/misc/guide_icons/ATF.gif"> , and checkmark "Empty Recycle Bin", click "Empty Selected" and exit the program.  You can delete or keep this utility as you wish.<br><br>&#8226; Use Control Panel, Add or Remove Programs, and Uninstall any entry related to an On-Line scanner we may have used.  <br>If you find any files or folders created during this cleanup operation remaining, please feel free to delete them.<br><br>&#8226; Please update your Version of Adobe Reader to the current release of 8.1.12<br>&#8226; Consider updating your Sun Java version at the Sun web site to the current version of 1.06.5<br><br>&#8226; Configure your Antivirus software to check for updates daily, at a time in which you are sure the computer will be on.<br><br>&#8226; If I asked you to <b>Disable</b> something like TeaTimer or another malware blocker, please go ahead an re-enable them if you wish.<br><br>&#8226;  <b>Download and install Comodo BOClean (free):</b><br><textarea name="code" class="text" cols=50 rows=10>http://www.comodo.com/boclean/CBO_download.html&#012;</textarea><!--end code block--><br>&#8226;  <b>Download, install, and keep updated Spyware Blaster (free):</b><br><textarea name="code" class="text" cols=50 rows=10>http://www.javacoolsoftware.com/spywareblaster.html&#012;</textarea><!--end code block--><br>&#8226; <b>Download, install, and keep updated SpyBot S&D (free) if you have not yet done so:</b><br><b><i>Tutorial:</i></b>  <br><textarea name="code" class="text" cols=50 rows=10>http://www.bleepingcomputer.com/tutorials/tutorial43.html&#012;</textarea><!--end code block--><br>&#8226; <b>Download, install, and keep updated AdAware 2007 by Lavasoft (free), if you have not done so:</b><br><b><i>Tutorial:</b></i>  <br><textarea name="code" class="text" cols=50 rows=10>http://www.bleepingcomputer.com/tutorials/tutorial48.html&#012;</textarea><!--end code block--><br>&#8226; Refer to my first set of instructions above, and reconfigure <b>Hidden Files and Folders</b> to your choosing.<br><br>Best wishes.<br>Bill Castner<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20412003</guid>
<pubDate>Wed, 30 Apr 2008 16:39:25 EDT</pubDate>
</item>

<item>
<title>Re: browser redirect and sluggish startup; HT log added</title>
<link>http://www.dslreports.com/forum/remark,20410746</link>
<description><![CDATA[<A HREF="/useremail/u/516889"><b>RandallW</b></A> : Combofix log:<br><br>ComboFix 08-04-26.5 - RandallW 2008-04-29 17:21:08.3 - NTFSx86<br>Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1033.18.80 [GMT -7:00]<br>Running from: C:\Documents and Settings\RandallW\Desktop\ComboFix.exe<br>Command switches used :: C:\Documents and Settings\RandallW\Desktop\CFscript.txt<br> * Created a new restore point<br><br>[color=red]<b>WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!</b>[/color]<br><br>FILE ::<br>c:\docume~1\randallw\applic~1\intern~1\Bike Team Anti.exe<br>C:\Documents and Settings\RandallW\Application Data\internaldb41.dat<br>C:\Documents and Settings\RandallW\Start Menu\Programs\StartupKERclink.lnk<br>C:\jfsADi.exe<br>C:\QqBMmT.exe<br>C:\WINDOWS\6459SFL2.ocx<br>C:\WINDOWS\BM2bfe5c27.xml<br>C:\WINDOWS\fetchuserid.exe<br>C:\WINDOWS\hcwemMON.exe<br>C:\WINDOWS\O498NP3Q.ocx<br>C:\WINDOWS\QR40374O.ocx<br>C:\WINDOWS\system32\bliixwbb.ini<br>C:\WINDOWS\system32\JIPE1H35.ocx<br>C:\WINDOWS\system32\onnmp.bak<br>C:\WINDOWS\system32\prdyak.exe<br>C:\WINDOWS\Tasks\AA66FD7B91857723.job<br>C:\WINDOWS\unins000.exe<br>.<br><br>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>C:\Documents and Settings\RandallW\Application Data\internaldb41.dat<br>C:\jfsADi.exe<br>C:\PROGRA~1\Coupons<br>C:\PROGRA~1\Coupons\Coupons.com.url<br>C:\PROGRA~1\Coupons\uninstall.exe<br>C:\PROGRA~1\Coupons\Uninstall\IRIMG1.JPG<br>C:\PROGRA~1\Coupons\Uninstall\IRIMG2.JPG<br>C:\PROGRA~1\Coupons\Uninstall\IRIMG3.JPG<br>C:\PROGRA~1\Coupons\Uninstall\IRIMG4.JPG<br>C:\PROGRA~1\Coupons\Uninstall\IRIMG5.JPG<br>C:\PROGRA~1\Coupons\Uninstall\IRIMG6.JPG<br>C:\PROGRA~1\Coupons\Uninstall\IRIMG7.JPG<br>C:\PROGRA~1\Coupons\Uninstall\IRIMG8.JPG<br>C:\PROGRA~1\Coupons\Uninstall\uninstall.dat<br>C:\PROGRA~1\Coupons\Uninstall\uninstall.xml<br>C:\QqBMmT.exe<br>C:\WINDOWS\6459SFL2.ocx<br>C:\WINDOWS\BM2bfe5c27.xml<br>C:\WINDOWS\fetchuserid.exe<br>C:\WINDOWS\hcwemMON.exe<br>C:\WINDOWS\O498NP3Q.ocx<br>C:\WINDOWS\QR40374O.ocx<br>C:\WINDOWS\system32\bliixwbb.ini<br>C:\WINDOWS\system32\JIPE1H35.ocx<br>C:\WINDOWS\system32\prdyak.exe<br>C:\WINDOWS\Tasks\AA66FD7B91857723.job<br>C:\WINDOWS\unins000.exe<br><br>.<br>(((((((((((((((((((((((((   Files Created from 2008-03-28 to 2008-04-30  )))))))))))))))))))))))))))))))<br>.<br><br>2008-04-26 16:02 . 2008-04-26 16:02&#9;&#9;d--------&#9;C:\Documents and Settings\RandallW\Application Data\Malwarebytes<br>2008-04-26 15:58 . 2008-04-26 15:59&#9;&#9;d--------&#9;C:\Program Files\Malwarebytes' Anti-Malware<br>2008-04-26 15:58 . 2008-04-26 15:58&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\Malwarebytes<br>2008-04-26 02:07 . 2008-04-26 16:51&#9;&#9;d--------&#9;C:\Program Files\EsetOnlineScanner<br>2008-04-24 23:48 . 2008-04-24 23:48&#9;&#9;d--------&#9;C:\Program Files\Common Files\Wise Installation Wizard<br>2008-04-22 22:08 . 2008-04-22 22:08&#9;&#9;d--------&#9;C:\Documents and Settings\RandallW\Application Data\Grisoft<br>2008-04-22 21:34 . 2008-04-22 21:34&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\Grisoft<br>2008-04-22 21:34 . 2007-05-30 05:10&#9;10,872&#9;--a------&#9;C:\WINDOWS\system32\drivers\AvgAsCln.sys<br>2008-04-22 21:10 . 2008-04-22 21:10&#9;&#9;d--------&#9;C:\Program Files\Windows Defender<br>2008-04-22 15:59 . 2008-04-22 15:59&#9;&#9;d--------&#9;C:\Program Files\Trend Micro<br>2008-04-20 16:11 . 2008-04-27 20:16&#9;54,156&#9;--ah-----&#9;C:\WINDOWS\QTFont.qfn<br>2008-04-20 16:11 . 2008-04-20 16:11&#9;1,409&#9;--a------&#9;C:\WINDOWS\QTFont.for<br>2008-04-15 13:27 . 2001-08-17 22:36&#9;94,720&#9;--a------&#9;C:\WINDOWS\system32\umaxud32.dll<br>2008-04-15 13:27 . 2001-08-17 22:36&#9;94,720&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\umaxud32.dll<br>2008-04-15 13:27 . 2001-08-17 22:36&#9;69,632&#9;--a------&#9;C:\WINDOWS\system32\umaxu12.dll<br>2008-04-15 13:27 . 2001-08-17 22:36&#9;69,632&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\umaxu12.dll<br>2008-04-15 13:27 . 2001-08-17 22:36&#9;50,688&#9;--a------&#9;C:\WINDOWS\system32\umaxscan.dll<br>2008-04-15 13:27 . 2001-08-17 22:36&#9;50,688&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\umaxscan.dll<br>2008-04-15 13:27 . 2008-04-15 13:31&#9;136&#9;--a------&#9;C:\WINDOWS\ppdrv.ini<br>2008-04-13 00:56 . 2008-04-13 01:02&#9;&#9;d--------&#9;C:\Program Files\Norton AntiVirus<br>2008-04-13 00:55 . 2008-04-13 00:57&#9;123,952&#9;--a------&#9;C:\WINDOWS\system32\drivers\SYMEVENT.SYS<br>2008-04-13 00:55 . 2008-04-13 00:57&#9;60,800&#9;--a------&#9;C:\WINDOWS\system32\S32EVNT1.DLL<br>2008-04-13 00:54 . 2008-04-21 10:03&#9;&#9;d--------&#9;C:\Program Files\Symantec<br>2008-04-11 15:30 . 2008-04-11 15:30&#9;&#9;d--h-----&#9;C:\WINDOWS\system32\CanonIJ Uninstaller Information<br>2008-04-11 15:30 . 2008-04-11 15:30&#9;&#9;d--h-----&#9;C:\Documents and Settings\All Users\Application Data\CanonBJ<br>2008-04-11 15:30 . 2007-04-15 22:00&#9;215,040&#9;--a------&#9;C:\WINDOWS\system32\CNMLM8V.DLL<br>2008-04-11 15:29 . 2008-04-11 15:29&#9;&#9;d--h-----&#9;C:\Program Files\CanonBJ<br>2008-03-30 17:17 . 2008-03-24 09:58&#9;920,304&#9;--a------&#9;C:\WINDOWS\system32\WindowsXP-KB905519-x86-ENU.exe<br>2008-03-29 00:27 . 2008-03-24 09:58&#9;920,304&#9;--a------&#9;C:\WINDOWS\WindowsXP-KB905519-x86-ENU.exe<br>2008-03-22 01:45 . 2001-08-23 12:06&#9;36,864&#9;--a------&#9;C:\WINDOWS\system32\CNMCP0W.EXE<br>2008-03-20 00:32 . 2008-04-29 14:13&#9;&#9;d--------&#9;C:\Program Files\yEnc32<br>2008-03-19 22:53 . 2001-08-28 16:00&#9;94,720&#9;--a------&#9;C:\WINDOWS\system32\CNMLM0W.DLL<br>2008-03-19 22:53 . 2001-08-28 16:00&#9;5,632&#9;--a------&#9;C:\WINDOWS\system32\CNMVS0W.DLL<br>2008-03-15 17:50 . 2008-03-15 17:50&#9;&#9;d--------&#9;C:\Program Files\SystemRequirementsLab<br>2008-03-04 14:39 . 2004-08-04 01:56&#9;116,224&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\xrxwiadr.dll<br>2008-03-04 14:39 . 2001-08-17 23:37&#9;99,865&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\xlog.exe<br>2008-03-04 14:39 . 2001-08-17 23:37&#9;27,648&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\xrxftplt.exe<br>2008-03-04 14:39 . 2001-08-17 23:36&#9;23,040&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\xrxwbtmp.dll<br>2008-03-04 14:39 . 2001-08-17 23:36&#9;17,408&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\xrxscnui.dll<br>2008-03-04 14:39 . 2001-08-17 13:11&#9;16,970&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\xem336n5.sys<br>2008-03-04 14:39 . 2004-08-04 01:56&#9;8,192&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\wshirda.dll<br>2008-03-04 14:39 . 2001-08-17 23:37&#9;4,608&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\xrxflnch.exe<br>2008-03-04 14:37 . 2001-08-17 14:28&#9;794,654&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\usr1801.sys<br>2008-03-04 14:36 . 2001-08-17 13:18&#9;285,760&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\stlnata.sys<br>2008-03-04 14:35 . 2001-08-17 15:56&#9;147,200&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\smidispb.dll<br>2008-03-04 14:34 . 2001-08-17 23:36&#9;495,616&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\sblfx.dll<br>2008-03-04 14:33 . 2001-08-17 14:28&#9;899,146&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\r2mdkxga.sys<br>2008-03-04 14:32 . 2004-08-04 01:56&#9;259,328&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\perm3dd.dll<br>2008-03-04 14:31 . 2001-08-17 15:05&#9;351,616&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\ovcodek2.sys<br>2008-03-04 14:30 . 2004-08-03 23:31&#9;132,695&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\netwlan5.sys<br>2008-03-04 14:29 . 2001-08-17 13:50&#9;320,384&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\mgaum.sys<br>2008-03-04 14:28 . 2001-08-17 14:28&#9;802,683&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\ltsm.sys<br>2008-03-04 14:27 . 2004-08-04 01:56&#9;152,576&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\irftp.exe<br>2008-03-04 14:26 . 2001-08-17 14:28&#9;542,879&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\hsf_msft.sys<br>2008-03-04 14:25 . 2001-08-17 15:56&#9;1,733,120&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\g400d.dll<br>2008-03-04 14:24 . 2001-08-17 13:17&#9;629,952&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\eqn.sys<br>2008-03-04 14:23 . 2001-08-17 13:14&#9;952,007&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\diwan.sys<br>2008-03-04 14:22 . 2001-08-17 23:36&#9;614,429&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\digiview.exe<br>2008-03-04 14:21 . 2001-08-17 13:13&#9;980,034&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\cicap.sys<br>2008-03-04 14:20 . 2001-08-17 15:05&#9;314,752&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\camdro21.sys<br>2008-03-04 14:19 . 2001-08-17 14:28&#9;871,388&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\bcmdm.sys<br>2008-03-04 14:18 . 2001-08-17 15:55&#9;382,592&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\atidrab.dll<br>2008-03-04 14:17 . 2001-08-17 14:28&#9;762,780&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\3cwmcru.sys<br>2008-03-04 14:16 . 2001-08-17 15:56&#9;66,048&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\s3legacy.dll<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2008-04-29 22:45&#9;4,741&#9;----a-w&#9;C:\WINDOWS\compaq.reg<br>2008-04-27 21:19&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\DVD Shrink<br>2008-04-27 03:55&#9;---------&#9;d-----w&#9;C:\Program Files\Common Files\Symantec Shared<br>2008-04-25 06:51&#9;---------&#9;d-----w&#9;C:\Program Files\Lavasoft<br>2008-04-23 04:43&#9;---------&#9;d-----w&#9;C:\Program Files\DivX<br>2008-04-14 01:36&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Symantec<br>2008-04-13 07:57&#9;805&#9;----a-w&#9;C:\WINDOWS\system32\drivers\SYMEVENT.INF<br>2008-04-13 07:57&#9;10,563&#9;----a-w&#9;C:\WINDOWS\system32\drivers\SYMEVENT.CAT<br>2008-04-11 22:38&#9;---------&#9;d-----w&#9;C:\Program Files\Canon<br>2008-03-22 02:49&#9;---------&#9;d-----w&#9;C:\Program Files\Replay Music<br>2008-03-22 02:45&#9;---------&#9;d-----w&#9;C:\Program Files\Math ActivityMaker-Primary<br>2008-03-22 02:43&#9;---------&#9;d-----w&#9;C:\Program Files\Math ActivityMaker- Skills<br>2008-03-22 02:43&#9;---------&#9;d-----w&#9;C:\Program Files\Math ActivityMaker- Fractions<br>2008-03-21 16:53&#9;---------&#9;d-----w&#9;C:\Program Files\Java<br>2008-03-07 04:32&#9;706&#9;----a-w&#9;C:\WINDOWS\system32\drivers\COH_Mon.inf<br>2008-03-07 04:32&#9;23,904&#9;----a-w&#9;C:\WINDOWS\system32\drivers\COH_Mon.sys<br>2008-03-07 04:32&#9;10,537&#9;----a-w&#9;C:\WINDOWS\system32\drivers\coh_mon.cat<br>2004-05-09 06:55&#9;4,571,136&#9;------w&#9;C:\Documents and Settings\GameSpot DLX Secure Delivery\chordtrainersetup.exe<br>2004-02-11 18:52&#9;2,989,381&#9;------w&#9;C:\Documents and Settings\GameSpot DLX Secure Delivery\oaw2102.zip<br>2003-07-31 17:03&#9;3,188&#9;----a-w&#9;C:\Program Files\dvdxcopy301.nfo<br>2003-01-12 01:52&#9;457&#9;----a-w&#9;C:\Program Files\INSTALL.LOG<br>2004-06-17 03:58&#9;56&#9;--sha-r&#9;C:\WINDOWS\system32\5A50D87783.sys<br>2004-10-12 06:42&#9;11,270&#9;--sha-w&#9;C:\WINDOWS\system32\KGyGaAvL.sys<br>2007-08-21 16:53&#9;1,592,642&#9;--sha-w&#9;C:\WINDOWS\system32\onnmp.bak1<br>2003-08-05 05:25&#9;220&#9;--sha-w&#9;C:\WINDOWS\system32\ss.drv<br>.<br><br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1C1CE040-5D65-422E-84C6-EFD6EEFCFA93}]<br><br>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{259274E6-3FEB-5341-BD13-A1A07A9AD77A}]<br><br>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2B76EB42-6211-417E-9A5D-EA8233C749EB}]<br><br>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2CB8C4B2-9DAF-4263-818E-835A955224D1}]<br><br>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4E7BD74F-2B8D-469E-C1EA-F165BB85A330}]<br>2007-10-13 19:48&#9;1909248&#9;--a------&#9;C:\PROGRA~1\mypoints\mypoints.dll<br><br>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]<br>2008-04-13 01:00&#9;116088&#9;--a------&#9;C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll<br><br>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-CEC4-75A487FD6484}]<br>2007-10-13 19:48&#9;1909248&#9;--a------&#9;C:\PROGRA~1\mypoints\mypoints.dll<br><br>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A8FB8EB3-183B-4598-924D-86F0E5E37085}]<br><br>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BF27A651-36B9-4264-848E-87911D600D4B}]<br><br>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F6C97034-AD95-4205-8055-CAED72E7282A}]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]<br>"{4E7BD74F-2B8D-469E-C1EA-F165BB85A330}"= "C:\PROGRA~1\mypoints\mypoints.dll" [2007-10-13 19:48 1909248]<br>"{A057A204-BACC-4D26-CEC4-75A487FD6484}"= "C:\PROGRA~1\mypoints\mypoints.dll" [2007-10-13 19:48 1909248]<br><br>[HKEY_CLASSES_ROOT\clsid\{4e7bd74f-2b8d-469e-c1ea-f165bb85a330}]<br>[HKEY_CLASSES_ROOT\mypoints.MYPOINTS]<br><br>[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-cec4-75a487fd6484}]<br>[HKEY_CLASSES_ROOT\mypoints.MYPOINTS]<br><br>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]<br>"{4E7BD74F-2B8D-469E-C1EA-F165BB85A330}"= C:\PROGRA~1\mypoints\mypoints.dll [2007-10-13 19:48 1909248]<br>"{A057A204-BACC-4D26-CEC4-75A487FD6484}"= C:\PROGRA~1\mypoints\mypoints.dll [2007-10-13 19:48 1909248]<br><br>[HKEY_CLASSES_ROOT\clsid\{4e7bd74f-2b8d-469e-c1ea-f165bb85a330}]<br>[HKEY_CLASSES_ROOT\mypoints.MYPOINTS]<br><br>[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-cec4-75a487fd6484}]<br>[HKEY_CLASSES_ROOT\mypoints.MYPOINTS]<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-10-28 17:25 94208]<br>"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 12:43 2097488]<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]<br>"@"="C:\Program Files\Internet Explorer\iexplore.exe" [2004-08-04 00:56 93184]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"CPQEASYACC"="C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe" [2001-12-14 15:01 32768]<br>"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2004-07-26 05:21 705808]<br>"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]<br>"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-12-10 15:36 180269]<br>"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-02-20 21:20 77824]<br>"LVCOMS"="C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE" [2001-11-13 15:43 98304]<br>"Motive SmartBridge"="C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe" [2005-08-24 07:51 442455]<br>"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]<br>"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]<br>"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 18:01 644696]<br>"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 18:50 1603152]<br>"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-01-25 18:47 51048]<br>"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2008-02-06 23:49 718704]<br>"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]<br>"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 02:25 6731312]<br>"BM2bfe5c27"="C:\WINDOWS\system32\jwhhvurp.dll" [ ]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtUmJDuS]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]<br>"VIDC.PIXL"= pclepixl.dll<br>"VIDC.NTN1"= Nuvision.ax<br>"VIDC.YV12"= vvlcodec.dll<br>"mixer"= APTRRNTm.dll<br>"wave"= APTRRNTm.dll<br>"VIDC.PIM1"= pclepim1.dll<br>"vidc.ffds"= C:\Program Files\ffdshow\ffdshow.ax<br>"MSVideo"= lvfwwdmt.dll<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]<br>"ccPxySvc"=2 (0x2)<br>"ccPwdSvc"=3 (0x3)<br>"ccEvtMgr"=2 (0x2)<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]<br>"DisableMonitoring"=dword:00000001<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]<br>"DisableMonitoring"=dword:00000001<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]<br>"DisableMonitoring"=dword:00000001<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]<br>"DisableMonitoring"=dword:00000001<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]<br>"EnableFirewall"= 0 (0x0)<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"%windir%\\system32\\sessmgr.exe"=<br>"C:\\Program Files\\Messenger\\msmsgs.exe"=<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]<br>"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]<br>"AllowInboundTimestampRequest"= 1 (0x1)<br>"AllowInboundMaskRequest"= 1 (0x1)<br>"AllowInboundRouterRequest"= 1 (0x1)<br>"AllowOutboundSourceQuench"= 1 (0x1)<br>"AllowOutboundParameterProblem"= 1 (0x1)<br>"AllowOutboundTimeExceeded"= 1 (0x1)<br>"AllowOutboundPacketTooBig"= 1 (0x1)<br><br>R0 ElbyVCD;ElbyVCD;C:\WINDOWS\system32\DRIVERS\ElbyVCD.sys [2002-11-28 03:43]<br>R1 bpfinder;BACKPACK Finder;C:\WINDOWS\system32\DRIVERS\bpfinder.sys [2003-09-29 09:36]<br>R1 tvtool;tvtool;C:\Program Files\TVTool 8 base\tvtool.sys [1996-04-03 11:33]<br>R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon []<br>R2 PGPsdkDriver;PGPsdkDriver;C:\WINDOWS\System32\drivers\PGPsdk.sys [2005-07-27 14:23]<br>R3 bpflt;BACKPACK Filter;C:\WINDOWS\system32\DRIVERS\bpflt.sys [2003-09-29 09:37]<br>R3 bpusbflt;BACKPACK USB Filter;C:\WINDOWS\system32\DRIVERS\bpusbflt.sys [2004-06-23 13:13]<br>S3 bppccard;BACKPACK PC Card;C:\WINDOWS\system32\DRIVERS\bppccard.sys [2003-09-29 09:40]<br>S3 bppnpdrv;BACKPACK Driver;C:\WINDOWS\system32\DRIVERS\bppnpdrv.sys [2003-09-29 09:57]<br>S3 bpusbdrv;BACKPACK USB 1 Cable;C:\WINDOWS\system32\DRIVERS\bpusbdrv.sys [2003-09-29 09:59]<br>S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-03-06 21:32]<br>S3 JumpShot;Lexar Media USB Compact Flash Driver;C:\WINDOWS\system32\DRIVERS\LEXAR2K.SYS [2001-10-19 14:57]<br>S3 NUVision;Pinnacle LINX;C:\WINDOWS\system32\DRIVERS\NUVision.sys [2000-07-16 11:52]<br>S3 SUNPLUS;SightCAM PC-100p;C:\WINDOWS\system32\Drivers\SPIXNEW.SYS []<br>S3 USB28xxBGA;WinTV HVR-900;C:\WINDOWS\system32\DRIVERS\emBDA.sys [2007-01-29 22:20]<br>S3 USB28xxOEM;WinTV OEM Filter;C:\WINDOWS\system32\DRIVERS\emOEM.sys [2007-01-29 22:19]<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]<br>\Shell\AutoRun\command - "E:\Toaw-CW\opart CW.exe" autorun<br><br>.<br>Contents of the 'Scheduled Tasks' folder<br>"2008-04-27 23:27:22 C:\WINDOWS\Tasks\MP Scheduled Scan.job"<br>- C:\Program Files\Windows Defender\MpCmdRun.exe<br>"2008-04-13 08:11:39 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - RandallW.job"<br>- C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:<br>.<br>**************************************************************************<br><br>catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2008-04-29 17:38:41<br>Windows 5.1.2600 Service Pack 2 NTFS<br><br>scanning hidden processes ... <br><br>scanning hidden autostart entries ...<br><br>scanning hidden files ... <br><br>scan completed successfully<br>hidden files: 0<br><br>**************************************************************************<br>.<br>Completion time: 2008-04-29 17:51:56<br>ComboFix-quarantined-files.txt  2008-04-30 00:51:42<br>ComboFix2.txt  2008-04-28 00:43:22<br><br>Pre-Run: 14,708,826,112 bytes free<br>Post-Run: 14,797,406,208 bytes free<br><br>283<br><br>==========================================<br><br>ESET scan log:<br><br># version=4<br># OnlineScanner.ocx=1.0.0.635<br># OnlineScannerDLLA.dll=1, 0, 0, 79<br># OnlineScannerDLLW.dll=1, 0, 0, 78<br># OnlineScannerUninstaller.exe=1, 0, 0, 49<br># vers_standard_module=3064 (20080429)<br># vers_arch_module=1.064 (20080214)<br># vers_adv_heur_module=1.064 (20070717)<br># EOSSerial=ab020ffaac84eb4ca2845adea54587e8<br># end=finished<br># remove_checked=true<br># unwanted_checked=true<br># utc_time=2008-04-30 12:44:56<br># local_time=2008-04-30 05:44:56 (-0800, Pacific Daylight Time)<br># country="United States"<br># osver=5.1.2600 NT Service Pack 2<br># scanned=690404<br># found=0<br># scan_time=13633]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20410746</guid>
<pubDate>Wed, 30 Apr 2008 12:57:10 EDT</pubDate>
</item>

<item>
<title>Re: browser redirect and sluggish startup; HT log added</title>
<link>http://www.dslreports.com/forum/remark,20403866</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : 1. Right-click on the header of the Code box below, where on the right side it says:  "<b>Copy to clipboard</b>":<br><textarea name="code" class="text" cols=50 rows=10>Folder::&#012;C:\PROGRA~1\CASHSU~1&#012;C:\PROGRA~1\Coupons&#012; &#012;File::&#012;C:\WINDOWS\system32\JIPE1H35.ocx&#012;C:\WINDOWS\QR40374O.ocx&#012;C:\WINDOWS\O498NP3Q.ocx&#012;C:\WINDOWS\6459SFL2.ocx&#012;C:\WINDOWS\system32\bliixwbb.ini&#012;C:\WINDOWS\BM2bfe5c27.xml&#012;C:\jfsADi.exe&#012;C:\QqBMmT.exe&#012;C:\WINDOWS\fetchuserid.exe&#012;C:\WINDOWS\unins000.exe&#012;C:\Documents and Settings\RandallW\Application Data\internaldb41.dat&#012;C:\WINDOWS\system32\onnmp.bak&#012;C:\WINDOWS\Tasks\AA66FD7B91857723.job&#012;c:\docume~1\randallw\applic~1\intern~1\Bike Team Anti.exe&#012;C:\Documents and Settings\RandallW\Start Menu\Programs\StartupKERclink.lnk&#012;C:\WINDOWS\hcwemMON.exe&#012;C:\WINDOWS\system32\prdyak.exe&#012; &#012;Registry::&#012;&#91;-HKLM\~\startupfolder\C:^Documents and Settings^RandallW^Start Menu^Programs^Startup^KERclink.lnk&#93;&#012;&#91;-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CashSurfers CashBar Navigator&#93;&#012;&#91;-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hcwemMON&#93;&#012;&#91;-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lforb&#93;&#012;&#91;-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent&#93;&#012; &#012;</textarea><!--end code block--><br>Open a new Notepad session - (Do <b><i>not</i></b> use a Word Processor or WordPad).  Click "<b>Format</b>" and be certain that Word Wrap is not enabled.  Right-click | <b>Paste</b> the Code box contents from above into Notepad.  Click File, <b><i>Save as...</i></b>, and set the location to your Desktop, and enter (including quotation marks) as the filename: <b>"CFscript.txt"</b> .  <br><br>&#8226; Disconnect from the Internet.<br>&#8226; Disable your Antivirus.  If the Antivirus software you use has any Script Blocking features, be certain to disable these as well.<br><b> Important:  </b> Have no other programs running.  Your Task Bar should be clear of any program entries including your Browser.<br>&#8226; A window will open with a warning.  Accept any Disclaimers to start the fix.<br>Using your mouse, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown in this little picture:<br> <IMG SRC="http://users.pandora.be/bluepatchy/miekiemoes/images/CFScript.gif"> <br><br>When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.<br>&#8226;<b>!</b>&#8226; A caution - Do <b>not</b> run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock.<br><br>2. <b>Eset NOD32 scanner</b><br>Go here to run an online scannner from ESET:  &raquo;<A HREF="http://www.eset.eu/online-scanner" >www.eset.eu/online-scanner</A><br><b>Note:</b> You will need to use Internet Explorer for this scan.<br><br>&#8226; Tick the box next to YES, I accept the Terms of Use.<br>&#8226; Click Start<br>&#8226; When asked, allow the activex control to install<br>&#8226; <b>Disable your Antivirus software</b>.  You can usually do this with its Notfication Tray icon near the clock.<br>&#8226; Click Start<br>&#8226; Make sure that the option <b>"Remove found threats"</b> is <u>Checked</u>, and the option <b>"Scan unwanted applications"</b> is also <u>Checked</u>.<br>&#8226; Click Scan.<br>&#8226; Wait for the scan to finish.<br>&#8226; :!:  <b>Re-enable your Anvirisus software.</b><br>&#8226; A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt.  We will need this later.<br><br>Post back the contents of C:\Combofix.txt, and the ESET scan results --  C:\Program Files\EsetOnlineScanner\log.txt.<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20403866</guid>
<pubDate>Tue, 29 Apr 2008 07:24:14 EDT</pubDate>
</item>

<item>
<title>Re: browser redirect and sluggish startup; HT log added</title>
<link>http://www.dslreports.com/forum/remark,20397100</link>
<description><![CDATA[<A HREF="/useremail/u/1104519"><b>randyw01</b></A> : Combofix log:<br><br>ComboFix 08-04-26.5 - RandallW 2008-04-27 16:04:47.2 - NTFSx86<br>Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1033.18.123 [GMT -7:00]<br>Running from: C:\Documents and Settings\RandallW\Desktop\ComboFix.exe<br>Command switches used :: C:\Documents and Settings\RandallW\Desktop\CFscript.txt<br> * Created a new restore point<br><br>[color=red]<b>WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!</b>[/color]<br>.<br><br>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>C:\WINDOWS\pskt.ini<br>C:\WINDOWS\system32\dllcache\spoolsv.exe<br>.<br>---- Previous Run -------<br>.<br>C:\Program Files\download plugin<br>C:\Temp\fse<br>C:\WINDOWS\cookies.ini<br>C:\WINDOWS\pskt.ini<br>C:\WINDOWS\rs.txt<br>C:\WINDOWS\system32\command.pif<br>C:\WINDOWS\system32\mcrh.tmp<br>C:\WINDOWS\system32\uninsticn.exe<br>C:\WINDOWS\system32\update.txt<br><br>.<br>(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>-------\Legacy_GDIW2K<br>-------\Legacy_NPF<br>-------\Service_NPF<br><br>(((((((((((((((((((((((((   Files Created from 2008-03-28 to 2008-04-28  )))))))))))))))))))))))))))))))<br>.<br><br>28980-04-03 02:41 . 28980-04-03 02:41&#9;3,120&#9;--a------&#9;C:\WINDOWS\system32\JIPE1H35.ocx<br>28980-04-03 02:41 . 28980-04-03 02:41&#9;3,120&#9;--a------&#9;C:\WINDOWS\QR40374O.ocx<br>28980-04-03 02:41 . 28980-04-03 02:41&#9;3,120&#9;--a------&#9;C:\WINDOWS\O498NP3Q.ocx<br>28980-04-03 02:41 . 28980-04-03 02:41&#9;3,120&#9;--a------&#9;C:\WINDOWS\6459SFL2.ocx<br>2008-04-26 16:02 . 2008-04-26 16:02&#9;&#9;d--------&#9;C:\Documents and Settings\RandallW\Application Data\Malwarebytes<br>2008-04-26 15:58 . 2008-04-26 15:59&#9;&#9;d--------&#9;C:\Program Files\Malwarebytes' Anti-Malware<br>2008-04-26 15:58 . 2008-04-26 15:58&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\Malwarebytes<br>2008-04-26 02:07 . 2008-04-26 16:51&#9;&#9;d--------&#9;C:\Program Files\EsetOnlineScanner<br>2008-04-24 23:48 . 2008-04-24 23:48&#9;&#9;d--------&#9;C:\Program Files\Common Files\Wise Installation Wizard<br>2008-04-24 22:03 . 2008-04-24 22:04&#9;1,509,099&#9;--ahs----&#9;C:\WINDOWS\system32\bliixwbb.ini<br>2008-04-24 21:59 . 2008-04-26 15:57&#9;109,756&#9;--a------&#9;C:\WINDOWS\BM2bfe5c27.xml<br>2008-04-22 22:08 . 2008-04-22 22:08&#9;&#9;d--------&#9;C:\Documents and Settings\RandallW\Application Data\Grisoft<br>2008-04-22 21:34 . 2008-04-22 21:34&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\Grisoft<br>2008-04-22 21:34 . 2007-05-30 05:10&#9;10,872&#9;--a------&#9;C:\WINDOWS\system32\drivers\AvgAsCln.sys<br>2008-04-22 21:10 . 2008-04-22 21:10&#9;&#9;d--------&#9;C:\Program Files\Windows Defender<br>2008-04-22 15:59 . 2008-04-22 15:59&#9;&#9;d--------&#9;C:\Program Files\Trend Micro<br>2008-04-20 16:11 . 2008-04-20 16:11&#9;54,156&#9;--ah-----&#9;C:\WINDOWS\QTFont.qfn<br>2008-04-20 16:11 . 2008-04-20 16:11&#9;1,409&#9;--a------&#9;C:\WINDOWS\QTFont.for<br>2008-04-15 13:27 . 2001-08-17 22:36&#9;94,720&#9;--a------&#9;C:\WINDOWS\system32\umaxud32.dll<br>2008-04-15 13:27 . 2001-08-17 22:36&#9;94,720&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\umaxud32.dll<br>2008-04-15 13:27 . 2001-08-17 22:36&#9;69,632&#9;--a------&#9;C:\WINDOWS\system32\umaxu12.dll<br>2008-04-15 13:27 . 2001-08-17 22:36&#9;69,632&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\umaxu12.dll<br>2008-04-15 13:27 . 2001-08-17 22:36&#9;50,688&#9;--a------&#9;C:\WINDOWS\system32\umaxscan.dll<br>2008-04-15 13:27 . 2001-08-17 22:36&#9;50,688&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\umaxscan.dll<br>2008-04-15 13:27 . 2008-04-15 13:31&#9;136&#9;--a------&#9;C:\WINDOWS\ppdrv.ini<br>2008-04-13 00:56 . 2008-04-13 01:02&#9;&#9;d--------&#9;C:\Program Files\Norton AntiVirus<br>2008-04-13 00:55 . 2008-04-13 00:57&#9;123,952&#9;--a------&#9;C:\WINDOWS\system32\drivers\SYMEVENT.SYS<br>2008-04-13 00:55 . 2008-04-13 00:57&#9;60,800&#9;--a------&#9;C:\WINDOWS\system32\S32EVNT1.DLL<br>2008-04-13 00:54 . 2008-04-21 10:03&#9;&#9;d--------&#9;C:\Program Files\Symantec<br>2008-04-11 15:30 . 2008-04-11 15:30&#9;&#9;d--h-----&#9;C:\WINDOWS\system32\CanonIJ Uninstaller Information<br>2008-04-11 15:30 . 2008-04-11 15:30&#9;&#9;d--h-----&#9;C:\Documents and Settings\All Users\Application Data\CanonBJ<br>2008-04-11 15:30 . 2007-04-15 22:00&#9;215,040&#9;--a------&#9;C:\WINDOWS\system32\CNMLM8V.DLL<br>2008-04-11 15:29 . 2008-04-11 15:29&#9;&#9;d--h-----&#9;C:\Program Files\CanonBJ<br>2008-03-30 17:17 . 2008-03-24 09:58&#9;920,304&#9;--a------&#9;C:\WINDOWS\system32\WindowsXP-KB905519-x86-ENU.exe<br>2008-03-29 00:27 . 2008-03-24 09:58&#9;920,304&#9;--a------&#9;C:\WINDOWS\WindowsXP-KB905519-x86-ENU.exe<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2008-04-28 00:24&#9;4,741&#9;----a-w&#9;C:\WINDOWS\compaq.reg<br>2008-04-27 21:19&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\DVD Shrink<br>2008-04-27 04:48&#9;---------&#9;d-----w&#9;C:\Program Files\yEnc32<br>2008-04-27 03:55&#9;---------&#9;d-----w&#9;C:\Program Files\Common Files\Symantec Shared<br>2008-04-25 06:51&#9;---------&#9;d-----w&#9;C:\Program Files\Lavasoft<br>2008-04-23 04:43&#9;---------&#9;d-----w&#9;C:\Program Files\DivX<br>2008-04-14 01:36&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Symantec<br>2008-04-13 07:57&#9;805&#9;----a-w&#9;C:\WINDOWS\system32\drivers\SYMEVENT.INF<br>2008-04-13 07:57&#9;10,563&#9;----a-w&#9;C:\WINDOWS\system32\drivers\SYMEVENT.CAT<br>2008-04-11 22:38&#9;---------&#9;d-----w&#9;C:\Program Files\Canon<br>2008-04-02 19:45&#9;---------&#9;d-----w&#9;C:\Program Files\Coupons<br>2008-03-22 02:49&#9;---------&#9;d-----w&#9;C:\Program Files\Replay Music<br>2008-03-22 02:45&#9;---------&#9;d-----w&#9;C:\Program Files\Math ActivityMaker-Primary<br>2008-03-22 02:43&#9;---------&#9;d-----w&#9;C:\Program Files\Math ActivityMaker- Skills<br>2008-03-22 02:43&#9;---------&#9;d-----w&#9;C:\Program Files\Math ActivityMaker- Fractions<br>2008-03-21 16:53&#9;---------&#9;d-----w&#9;C:\Program Files\Java<br>2008-03-16 00:50&#9;---------&#9;d-----w&#9;C:\Program Files\SystemRequirementsLab<br>2008-03-10 03:14&#9;635&#9;----a-w&#9;C:\jfsADi.exe<br>2008-03-07 04:32&#9;706&#9;----a-w&#9;C:\WINDOWS\system32\drivers\COH_Mon.inf<br>2008-03-07 04:32&#9;23,904&#9;----a-w&#9;C:\WINDOWS\system32\drivers\COH_Mon.sys<br>2008-03-07 04:32&#9;10,537&#9;----a-w&#9;C:\WINDOWS\system32\drivers\coh_mon.cat<br>2008-03-06 08:36&#9;635&#9;----a-w&#9;C:\QqBMmT.exe<br>2008-02-13 05:30&#9;7,680&#9;----a-w&#9;C:\WINDOWS\fetchuserid.exe<br>2008-02-11 23:26&#9;691,545&#9;----a-w&#9;C:\WINDOWS\unins000.exe<br>2006-07-10 02:09&#9;0&#9;----a-w&#9;C:\Documents and Settings\RandallW\Application Data\internaldb41.dat<br>2004-05-09 06:55&#9;4,571,136&#9;------w&#9;C:\Documents and Settings\GameSpot DLX Secure Delivery\chordtrainersetup.exe<br>2004-02-11 18:52&#9;2,989,381&#9;------w&#9;C:\Documents and Settings\GameSpot DLX Secure Delivery\oaw2102.zip<br>2003-07-31 17:03&#9;3,188&#9;----a-w&#9;C:\Program Files\dvdxcopy301.nfo<br>2003-01-12 01:52&#9;457&#9;----a-w&#9;C:\Program Files\INSTALL.LOG<br>2004-06-17 03:58&#9;56&#9;--sha-r&#9;C:\WINDOWS\system32\5A50D87783.sys<br>2004-10-12 06:42&#9;11,270&#9;--sha-w&#9;C:\WINDOWS\system32\KGyGaAvL.sys<br>2007-08-21 16:53&#9;1,592,642&#9;--sha-w&#9;C:\WINDOWS\system32\onnmp.bak1<br>2003-08-05 05:25&#9;220&#9;--sha-w&#9;C:\WINDOWS\system32\ss.drv<br>.<br><br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4E7BD74F-2B8D-469E-C1EA-F165BB85A330}]<br>2007-10-13 19:48&#9;1909248&#9;--a------&#9;C:\PROGRA~1\mypoints\mypoints.dll<br><br>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]<br>2008-04-13 01:00&#9;116088&#9;--a------&#9;C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll<br><br>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-CEC4-75A487FD6484}]<br>2007-10-13 19:48&#9;1909248&#9;--a------&#9;C:\PROGRA~1\mypoints\mypoints.dll<br><br>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]<br>"{4E7BD74F-2B8D-469E-C1EA-F165BB85A330}"= C:\PROGRA~1\mypoints\mypoints.dll [2007-10-13 19:48 1909248]<br>"{A057A204-BACC-4D26-CEC4-75A487FD6484}"= C:\PROGRA~1\mypoints\mypoints.dll [2007-10-13 19:48 1909248]<br><br>[HKEY_CLASSES_ROOT\clsid\{4e7bd74f-2b8d-469e-c1ea-f165bb85a330}]<br>[HKEY_CLASSES_ROOT\mypoints.MYPOINTS]<br><br>[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-cec4-75a487fd6484}]<br>[HKEY_CLASSES_ROOT\mypoints.MYPOINTS]<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-10-28 17:25 94208]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"CPQEASYACC"="C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe" [2001-12-14 15:01 32768]<br>"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2004-07-26 05:21 705808]<br>"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]<br>"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-12-10 15:36 180269]<br>"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-02-20 21:20 77824]<br>"LVCOMS"="C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE" [2001-11-13 15:43 98304]<br>"Motive SmartBridge"="C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe" [2005-08-24 07:51 442455]<br>"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]<br>"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]<br>"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 18:01 644696]<br>"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 18:50 1603152]<br>"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-01-25 18:47 51048]<br>"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2008-02-06 23:49 718704]<br>"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]<br>"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 02:25 6731312]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]<br>"VIDC.PIXL"= pclepixl.dll<br>"VIDC.NTN1"= Nuvision.ax<br>"VIDC.YV12"= vvlcodec.dll<br>"mixer"= APTRRNTm.dll<br>"wave"= APTRRNTm.dll<br>"VIDC.PIM1"= pclepim1.dll<br>"vidc.ffds"= C:\Program Files\ffdshow\ffdshow.ax<br>"MSVideo"= lvfwwdmt.dll<br><br>[HKLM\~\startupfolder\C:^Documents and Settings^RandallW^Start Menu^Programs^Startup^KERclink.lnk]<br>backup=C:\WINDOWS\pss\KERclink.lnkStartup<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CashSurfers CashBar Navigator]<br>C:\PROGRA~1\CASHSU~1\Cashbar.exe<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hcwemMON]<br>--a------ 2007-03-29 18:22 61440 C:\WINDOWS\hcwemMON.exe<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lforb]<br>--a------ 2006-07-09 19:06 127488 C:\WINDOWS\system32\prdyak.exe<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]<br>"ccPxySvc"=2 (0x2)<br>"ccPwdSvc"=3 (0x3)<br>"ccEvtMgr"=2 (0x2)<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]<br>"DisableMonitoring"=dword:00000001<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]<br>"DisableMonitoring"=dword:00000001<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]<br>"DisableMonitoring"=dword:00000001<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]<br>"DisableMonitoring"=dword:00000001<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]<br>"EnableFirewall"= 0 (0x0)<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"%windir%\\system32\\sessmgr.exe"=<br>"C:\\Program Files\\Messenger\\msmsgs.exe"=<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]<br>"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]<br>"AllowInboundTimestampRequest"= 1 (0x1)<br>"AllowInboundMaskRequest"= 1 (0x1)<br>"AllowInboundRouterRequest"= 1 (0x1)<br>"AllowOutboundSourceQuench"= 1 (0x1)<br>"AllowOutboundParameterProblem"= 1 (0x1)<br>"AllowOutboundTimeExceeded"= 1 (0x1)<br>"AllowOutboundPacketTooBig"= 1 (0x1)<br><br>R0 ElbyVCD;ElbyVCD;C:\WINDOWS\system32\DRIVERS\ElbyVCD.sys [2002-11-28 03:43]<br>R1 bpfinder;BACKPACK Finder;C:\WINDOWS\system32\DRIVERS\bpfinder.sys [2003-09-29 09:36]<br>R1 tvtool;tvtool;C:\Program Files\TVTool 8 base\tvtool.sys [1996-04-03 11:33]<br>R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon []<br>R2 PGPsdkDriver;PGPsdkDriver;C:\WINDOWS\System32\drivers\PGPsdk.sys [2005-07-27 14:23]<br>R3 bpflt;BACKPACK Filter;C:\WINDOWS\system32\DRIVERS\bpflt.sys [2003-09-29 09:37]<br>R3 bpusbflt;BACKPACK USB Filter;C:\WINDOWS\system32\DRIVERS\bpusbflt.sys [2004-06-23 13:13]<br>S3 bppccard;BACKPACK PC Card;C:\WINDOWS\system32\DRIVERS\bppccard.sys [2003-09-29 09:40]<br>S3 bppnpdrv;BACKPACK Driver;C:\WINDOWS\system32\DRIVERS\bppnpdrv.sys [2003-09-29 09:57]<br>S3 bpusbdrv;BACKPACK USB 1 Cable;C:\WINDOWS\system32\DRIVERS\bpusbdrv.sys [2003-09-29 09:59]<br>S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-03-06 21:32]<br>S3 JumpShot;Lexar Media USB Compact Flash Driver;C:\WINDOWS\system32\DRIVERS\LEXAR2K.SYS [2001-10-19 14:57]<br>S3 NUVision;Pinnacle LINX;C:\WINDOWS\system32\DRIVERS\NUVision.sys [2000-07-16 11:52]<br>S3 SUNPLUS;SightCAM PC-100p;C:\WINDOWS\system32\Drivers\SPIXNEW.SYS []<br>S3 USB28xxBGA;WinTV HVR-900;C:\WINDOWS\system32\DRIVERS\emBDA.sys [2007-01-29 22:20]<br>S3 USB28xxOEM;WinTV OEM Filter;C:\WINDOWS\system32\DRIVERS\emOEM.sys [2007-01-29 22:19]<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]<br>\Shell\AutoRun\command - "E:\Toaw-CW\opart CW.exe" autorun<br><br>.<br>Contents of the 'Scheduled Tasks' folder<br>"2008-04-28 00:00:00 C:\WINDOWS\Tasks\AA66FD7B91857723.job"<br>- c:\docume~1\randallw\applic~1\intern~1\Bike Team Anti.exe<br>"2008-04-27 23:27:22 C:\WINDOWS\Tasks\MP Scheduled Scan.job"<br>- C:\Program Files\Windows Defender\MpCmdRun.exe<br>"2008-04-13 08:11:39 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - RandallW.job"<br>- C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:<br>.<br>**************************************************************************<br><br>catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2008-04-27 17:25:34<br>Windows 5.1.2600 Service Pack 2 NTFS<br><br>scanning hidden processes ... <br><br>scanning hidden autostart entries ...<br><br>scanning hidden files ... <br><br>scan completed successfully<br>hidden files: 0<br><br>**************************************************************************<br>.<br>------------------------ Other Running Processes ------------------------<br>.<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe<br>C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe<br>C:\WINDOWS\system32\ZoneLabs\vsmon.exe<br>C:\WINDOWS\wanmpsvc.exe<br>C:\Program Files\compaq\Easy Access Button Support\CPQEADM.exe<br>C:\Compaq\EAKDRV\EAUSBKBD.exe<br>C:\PROGRA~1\compaq\EASYAC~1\BttnServ.exe<br>C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe<br>.<br>**************************************************************************<br>.<br>Completion time: 2008-04-27 17:43:14 - machine was rebooted [RandallW]<br>ComboFix-quarantined-files.txt  2008-04-28 00:42:22<br><br>Pre-Run: 14,642,917,376 bytes free<br>Post-Run: 14,996,099,072 bytes free<br><br>242<br><br>=============================================<br><br>HijackThis log:<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 6:24:31 PM, on 4/27/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br>C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe<br>C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\ZoneLabs\vsmon.exe<br>C:\WINDOWS\wanmpsvc.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe<br>C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe<br>C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE<br>C:\Compaq\EAKDRV\EAUSBKBD.EXE<br>C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br>C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe<br>C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE<br>C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe<br>C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe<br>C:\Program Files\Windows Defender\MSASCui.exe<br>C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br>C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe<br>C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe<br>C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe<br>C:\WINDOWS\explorer.exe<br>C:\Program Files\Mozilla Firefox\firefox.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br>O2 - BHO: MyPoints Toolbar - {4E7BD74F-2B8D-469E-C1EA-F165BB85A330} - C:\PROGRA~1\mypoints\mypoints.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O2 - BHO: PrintMe - {97387E2B-B2FA-4E4A-A607-F3B5C134F71C} - C:\Program Files\EFI\PrintMeToolbar\htpmcap.dll<br>O2 - BHO: MYPOINTS - {A057A204-BACC-4D26-CEC4-75A487FD6484} - C:\PROGRA~1\mypoints\mypoints.dll<br>O3 - Toolbar: PrintMe - {97387E2B-B2FA-4E4A-A607-F3B5C134F71C} - C:\Program Files\EFI\PrintMeToolbar\htpmcap.dll<br>O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll<br>O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe<br>O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"<br>O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE<br>O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"<br>O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br>O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon<br>O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon<br>O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"<br>O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br>O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized<br>O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"<br>O4 - Global Startup: AT&T Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe<br>O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm<br>O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll<br>O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll<br>O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe<br>O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe<br>O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe<br>O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll<br>O15 - Trusted IP range: 192.168.1.81<br>O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v46/scrabblecubes/scrabblecubes.cab" >www.worldwinner.com/games/v46/sc&middot;&middot;&middot;ubes.cab</A><br>O16 - DPF: {04063354-A10E-4427-A1EC-F3CC81587BC6} (Mines Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v41/mines/mines.cab" >www.worldwinner.com/games/v41/mi&middot;&middot;&middot;ines.cab</A><br>O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - &raquo;<A HREF="http://support.asus.com/common/asusTek_sys_ctrl.cab" >support.asus.com/common/asusTek_sys_ctrl.cab</A><br>O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - &raquo;<A HREF="http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB" >www.pcpitstop.com/pcpitstop/PCPitStop.CAB</A><br>O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - &raquo;<A HREF="http://www.pcpitstop.com/internet/pcpConnCheck.cab" >www.pcpitstop.com/internet/pcpConnCheck.cab</A><br>O16 - DPF: {18C3FD15-74F6-4280-9C98-3590C966B7B8} (SkillGam Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v47/skillgam/skillgam.cab" >www.worldwinner.com/games/v47/sk&middot;&middot;&middot;lgam.cab</A><br>O16 - DPF: {192F9A01-8030-48CE-9BC6-B03DE3E613C6} (PeoplePC Web Installer) - &raquo;<small>https</small>://<A HREF="https://www.peoplepc.com/ppcos/ISP60/Download/ppcwebi.cab">www.peoplepc.com/ppcos/ISP60/Dow&middot;&middot;&middot;webi.cab</A><br>O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - &raquo;<A HREF="http://www.worldwinner.com/games/v46/shared/FunGamesLoader.cab" >www.worldwinner.com/games/v46/sh&middot;&middot;&middot;ader.cab</A><br>O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - &raquo;<A HREF="http://www.rovion.com/Controls/Rovion.cab" >www.rovion.com/Controls/Rovion.cab</A><br>O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - &raquo;<A HREF="http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab" >us.chat1.yimg.com/us.yimg.com/i/&middot;&middot;&middot;scom.cab</A><br>O16 - DPF: {2C153C75-8476-434B-B3C3-57B63A3D1939} (Brickout Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v48/brickout/brickout.cab" >www.worldwinner.com/games/v48/br&middot;&middot;&middot;kout.cab</A><br>O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} (Pool Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v50/pool/pool.cab" >www.worldwinner.com/games/v50/pool/pool.cab</A><br>O16 - DPF: {41D1977F-4161-4720-800F-EA4903983A38} (Jigsaw Genius Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v43/jigsaw/jigsaw.cab" >www.worldwinner.com/games/v43/ji&middot;&middot;&middot;gsaw.cab</A><br>O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - &raquo;<A HREF="http://www.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsi.cab" >www.symantec.com/techsupp/asa/ss&middot;&middot;&middot;tlsi.cab</A><br>O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - &raquo;<A HREF="http://www.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab" >www.symantec.com/techsupp/asa/ss&middot;&middot;&middot;tlsr.cab</A><br>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;sctl.cab</A><br>O16 - DPF: {555F1BBC-6EC2-474F-84AF-633EF097FF54} (WWHearts Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v52/wwhearts/wwhearts.cab" >www.worldwinner.com/games/v52/ww&middot;&middot;&middot;arts.cab</A><br>O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - &raquo;<A HREF="http://www.eset.eu/buxus/docs/OnlineScanner.cab" >www.eset.eu/buxus/docs/OnlineScanner.cab</A><br>O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v63/bjattack/bja.cab" >www.worldwinner.com/games/v63/bj&middot;&middot;&middot;/bja.cab</A><br>O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab" >www.worldwinner.com/games/v46/be&middot;&middot;&middot;eled.cab</A><br>O16 - DPF: {62969CF2-0F7A-433B-A221-FD8818C06C2F} (Blockwerx Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v49/blockwerx/blockwerx.cab" >www.worldwinner.com/games/v49/bl&middot;&middot;&middot;werx.cab</A><br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1202179311687" >www.update.microsoft.com/microso&middot;&middot;&middot;79311687</A><br>O16 - DPF: {6C6FE41A-0DA6-42A1-9AD8-792026B2B2A7} (FreeCell Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v41/freecell/freecell.cab" >www.worldwinner.com/games/v41/fr&middot;&middot;&middot;cell.cab</A><br>O16 - DPF: {6D53ADB7-6AD5-4A59-BFE4-7B57D2F4AA89} - &raquo;<A HREF="http://ip.135mp3.com/135mp3.cab" >ip.135mp3.com/135mp3.cab</A><br>O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &raquo;<A HREF="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1202179299890" >www.update.microsoft.com/microso&middot;&middot;&middot;79299890</A><br>O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - &raquo;<A HREF="http://chat.yahoo.com/cab/yacsui.cab" >chat.yahoo.com/cab/yacsui.cab</A><br>O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - &raquo;<A HREF="http://www.worldwinner.com/games/shared/wwlaunch.cab" >www.worldwinner.com/games/shared&middot;&middot;&middot;unch.cab</A><br>O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v46/wordmojo/wordmojo.cab" >www.worldwinner.com/games/v46/wo&middot;&middot;&middot;mojo.cab</A><br>O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} (Cubis Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v57/cubis/cubis.cab" >www.worldwinner.com/games/v57/cu&middot;&middot;&middot;ubis.cab</A><br>O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} (Sol Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v46/sol/sol.cab" >www.worldwinner.com/games/v46/sol/sol.cab</A><br>O16 - DPF: {A91FB93D-7561-4524-8484-5C27C8FA8D42} (WwLuxor Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v49/luxor/luxor.cab" >www.worldwinner.com/games/v49/lu&middot;&middot;&middot;uxor.cab</A><br>O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} (SwapIt Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v67/swapit/swapit.cab" >www.worldwinner.com/games/v67/sw&middot;&middot;&middot;apit.cab</A><br>O16 - DPF: {B06CE1BC-5D9D-4676-BD28-1752DBF394E0} (Hangman Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v41/hangman/hangman.cab" >www.worldwinner.com/games/v41/ha&middot;&middot;&middot;gman.cab</A><br>O16 - DPF: {BA94245D-2AA0-4953-9D9F-B0EE4CC02C43} (Tilecity Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v42/tilecity/tilecity.cab" >www.worldwinner.com/games/v42/ti&middot;&middot;&middot;city.cab</A><br>O16 - DPF: {BB637307-92FA-47EC-B3F7-6969078673CC} (Royal Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v45/royal/royal.cab" >www.worldwinner.com/games/v45/ro&middot;&middot;&middot;oyal.cab</A><br>O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;dmgr.cab</A><br>O16 - DPF: {C5326A4D-E9AA-40AD-A09A-E74304D86B47} (DinerDash Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v50/dinerdash/dinerdash.cab" >www.worldwinner.com/games/v50/di&middot;&middot;&middot;dash.cab</A><br>O16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} (Paint Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v43/paint/paint.cab" >www.worldwinner.com/games/v43/pa&middot;&middot;&middot;aint.cab</A><br>O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - &raquo;<A HREF="http://www.live365.com/players/play365.cab" >www.live365.com/players/play365.cab</A><br>O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} (FamilyFeud Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v47/familyfeud/familyfeud.cab" >www.worldwinner.com/games/v47/fa&middot;&middot;&middot;feud.cab</A><br>O16 - DPF: {E12EB891-D000-421B-A8ED-EDE1BDCA14A0} (GolfSol Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v44/golfsol/golfsol.cab" >www.worldwinner.com/games/v44/go&middot;&middot;&middot;fsol.cab</A><br>O16 - DPF: {E70E3E64-2793-4AEF-8CC8-F1606BE563B0} (WWSpades Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v47/wwspades/wwspades.cab" >www.worldwinner.com/games/v47/ww&middot;&middot;&middot;ades.cab</A><br>O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - &raquo;<A HREF="http://tools.ebayimg.com/eps/activex/EPSControl_v1-32.cab" >tools.ebayimg.com/eps/activex/EP&middot;&middot;&middot;1-32.cab</A><br>O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe<br>O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br>O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br>O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br>O23 - Service: Compaq Advisor (Compaq_RBA) - NeoPlanet - C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe<br>O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE<br>O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br>O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe<br>O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe<br>O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe<br>O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe<br>O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe<br>O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe<br>O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe<br><br>--<br>End of file - 14042 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20397100</guid>
<pubDate>Sun, 27 Apr 2008 21:34:37 EDT</pubDate>
</item>

<item>
<title>Re: browser redirect and sluggish startup; HT log added</title>
<link>http://www.dslreports.com/forum/remark,20394071</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : <b>Delete</b> Combofix.exe from your Desktop.<br><br>1. Open <b>HijackThis</b> again, System scan only.  <b>Checkmark</b> these items:<br><br><b>O2 - BHO: (no name) - {1C1CE040-5D65-422E-84C6-EFD6EEFCFA93} - C:\WINDOWS\system32\ssqRjkjI.dll (file missing)<br>O2 - BHO: (no name) - {259274E6-3FEB-5341-BD13-A1A07A9AD77A} - (no file)<br>O2 - BHO: (no name) - {2B76EB42-6211-417E-9A5D-EA8233C749EB} - (no file)<br>O2 - BHO: (no name) - {2CB8C4B2-9DAF-4263-818E-835A955224D1} - C:\WINDOWS\system32\qoMfghIY.dll (file missing)<br>O2 - BHO: {3041db1d-901b-ee6a-2004-aeb134d85913} - {31958d43-1bea-4002-a6ee-b109d1bd1403} - C:\WINDOWS\system32\dkebwlpm.dll<br>O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)<br>O2 - BHO: (no name) - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - (no file)<br>O2 - BHO: (no name) - {F6C97034-AD95-4205-8055-CAED72E7282A} - (no file)<br>O4 - HKLM\..\Run: [28cd6fbb] rundll32.exe "C:\WINDOWS\system32\antpboyd.dll",b<br>O20 - Winlogon Notify: gdiwxp - gdiwxp.dll (file missing)<br>O20 - Winlogon Notify: c - vtUmJDuS.dll (file missing)</b><br><br>Click "<b>Fix checked</b>" and when the log panel clears exit HijackThis.<br><br>2. Download -- but <i>do not</i> yet run  -- <b>ComboFix&copy; </b> <br><br>Download this file <b><u>-- to your Desktop --</u></b> [/b]from any of these sources:  <br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br>Right-click on the header of the Code box below, where on the right side it says:  "<b>Copy to clipboard</b>":<br><textarea name="code" class="text" cols=50 rows=10>File::&#012;C:\WINDOWS\system32\antpboyd.dll&#012;C:\WINDOWS\system32\dkebwlpm.dll&#012; &#012;Registry::&#012;&#91;-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gdiwxp&#93; &#012;&#91;-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gdiwxp&#93; &#012;&#91;-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3041db1d-901b-ee6a-2004-aeb134d85913}&#93; &#012;&#91;-HKEY_CLASSES_ROOT\AppID\dkebwlpm.dll&#93; &#012;&#91;-HKEY_CLASSES_ROOT\AppID\{3041db1d-901b-ee6a-2004-aeb134d85913}&#93; &#012;&#91;-HKEY_CLASSES_ROOT\CLSID\{3041db1d-901b-ee6a-2004-aeb134d85913}&#93; &#012;&#91;-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3041db1d-901b-ee6a-2004-aeb134d85913}&#93; &#012;&#91;-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1C1CE040-5D65-422E-84C6-EFD6EEFCFA93&#93;&#012;&#91;-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{259274E6-3FEB-5341-BD13-A1A07A9AD77A}&#93; &#012;&#91;-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2B76EB42-6211-417E-9A5D-EA8233C749EB}&#93; &#012;&#91;-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2CB8C4B2-9DAF-4263-818E-835A955224D1}&#93; &#012;&#91;-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB&#93; &#012;&#91;-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A8FB8EB3-183B-4598-924D-86F0E5E37085}&#93; &#012;&#91;-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F6C97034-AD95-4205-8055-CAED72E7282A}&#93; &#012; &#012;</textarea><!--end code block--><br>Open a new Notepad session - (Do <b><i>not</i></b> use a Word Processor or WordPad).  Click "<b>Format</b>" and be certain that Word Wrap is not enabled.  Right-click | <b>Paste</b> the Code box contents from above into Notepad.  Click File, <b><i>Save as...</i></b>, and set the location to your Desktop, and enter (including quotation marks) as the filename: <b>"CFscript.txt"</b> .  <br><br>&#8226; Disconnect from the Internet.<br>&#8226; Disable your Antivirus.  If the Antivirus software you use has any Script Blocking features, be certain to disable these as well.<br><b> Important:  </b> Have no other programs running.  Your Task Bar should be clear of any program entries including your Browser.<br>&#8226; A window will open with a warning.  Accept any Disclaimers to start the fix.<br>Using your mouse, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown in this little picture:<br> <IMG SRC="http://users.pandora.be/bluepatchy/miekiemoes/images/CFScript.gif"> <br><br>When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.<br>&#8226;<b>!</b>&#8226; A caution - Do <b>not</b> run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock.<br>&#8226; Let Combofix run to completion.  Do not assume at any point it has locked or frozen.  It should take between twenty minutes to one hour to complete.  You can reboot if it has not finished after one hour.<br><br>3. Run <b>HijackThis</b> again, and save the log file.<br><br><b><i>Submit to the Forum:</i></b><br>&#8226; The contents of C:\Combofix.txt;<br>&#8226; The new HijackThis log.<br><br><b>Note:</b>  There is no purpose served in running the ESET online scan repeatedly.  The results you returned above are all Quarantined items, including from the Combofix qauarantine.<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20394071</guid>
<pubDate>Sun, 27 Apr 2008 06:27:06 EDT</pubDate>
</item>

<item>
<title>Re: browser redirect and sluggish startup; HT log added</title>
<link>http://www.dslreports.com/forum/remark,20393593</link>
<description><![CDATA[<A HREF="/useremail/u/1104519"><b>randyw01</b></A> : I performed an ESET cleaning before I went to bed last night, which was before I read your cleaning instructions ( which I got to around noon ).<br><br>ATF Cleaner was installed and ran without problem.<br><br>I used HijackThis to fix all the entries you listed, even though some of them were there from voluntary installation.<br><br>Combofix ran for about 20 minutes, then became stuck trying to eliminate a file in system32; I had to restart the computer.  Since the instructions said to not run Combofix more than once I moved to the next step.  Since it didn't seem to finish correctly there is no log file saved.<br><br>MalwareBytes was installed and ran without problem.<br><br>ESET online scanner was run again.<br><br>======================================<br><br>MalwareBytes log:<br>Malwarebytes' Anti-Malware 1.11<br>Database version: 687<br><br>Scan type: Quick Scan<br>Objects scanned: 50944<br>Time elapsed: 27 minute(s), 32 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 2<br>Registry Keys Infected: 23<br>Registry Values Infected: 2<br>Registry Data Items Infected: 2<br>Folders Infected: 7<br>Files Infected: 32<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>C:\WINDOWS\system32\antpboyd.dll (Trojan.Vundo) -> Unloaded module successfully.<br>C:\WINDOWS\system32\wvUoLeBR.dll (Trojan.Vundo) -> Unloaded module successfully.<br><br>Registry Keys Infected:<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e6d9f1de-0d9c-4286-8779-37c51068eae9} (Trojan.Vundo) -> Delete on reboot.<br>HKEY_CLASSES_ROOT\CLSID\{e6d9f1de-0d9c-4286-8779-37c51068eae9} (Trojan.Vundo) -> Delete on reboot.<br>HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\Typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\CLSID\{87255c51-cd7d-4506-b9ad-97606daf53f3} (Adware.Coupons) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\CLSID\{a6c54318-5ac7-477d-b0a7-49af5189300c} (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a6c54318-5ac7-477d-b0a7-49af5189300c} (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\CLSID\{70522fa0-4656-11d5-b0e9-0050dac24e8f} (Adware.iWon) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\CLSID\{70522fa1-4656-11d5-b0e9-0050dac24e8f} (Adware.iWon) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\CLSID\{70522fa2-4656-11d5-b0e9-0050dac24e8f} (Adware.iWon) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.<br><br>Registry Values Infected:<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{a6c54318-5ac7-477d-b0a7-49af5189300c} (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BM2bfe5c27 (Trojan.Agent) -> Quarantined and deleted successfully.<br><br>Registry Data Items Infected:<br>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\wvuolebr -> Delete on reboot.<br>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\wvuolebr  -> Delete on reboot.<br><br>Folders Infected:<br>C:\Program Files\iWon (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonBar (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonSlot (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonBar\History (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonBar\Settings (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonSlot\1.bin (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonSlot\Cache (Adware.iWon) -> Quarantined and deleted successfully.<br><br>Files Infected:<br>C:\WINDOWS\system32\antpboyd.dll (Trojan.Vundo) -> Delete on reboot.<br>C:\WINDOWS\system32\dyobptna.ini (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\wvUoLeBR.dll (Trojan.Vundo) -> Delete on reboot.<br>C:\WINDOWS\system32\RBeLoUvw.ini (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\RBeLoUvw.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonBar\History\search (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonSlot\PM3.ico (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonSlot\1.bin\IWONSLOT.DLL (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonSlot\1.bin\PM3.ICO (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonSlot\1.bin\UNINSTALL.INF (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonSlot\Cache\0CAD8EEA (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonSlot\Cache\0CAD963D.bin (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonSlot\Cache\0CAD9840.bin (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonSlot\Cache\0CAD9A44.bin (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonSlot\Cache\0CAD9C19.bin (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonSlot\Cache\0CAD9DDE.bin (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonSlot\Cache\0CAD9FA3.bin (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonSlot\Cache\0CADA168.bin (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonSlot\Cache\0CADA34D.bin (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonSlot\Cache\0CADA59E.bin (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonSlot\Cache\0CADA80F.bin (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonSlot\Cache\0CADA9E4.bin (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonSlot\Cache\0CADAC55.bin (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonSlot\Cache\0CADAE1A.bin (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonSlot\Cache\0CADAFEF.wav (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonSlot\Cache\0CADB202.wav (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonSlot\Cache\0CADB483.wav (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonSlot\Cache\0CADB648.wav (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonSlot\Cache\268E043E (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\Program Files\iWon\iWonSlot\Cache\files.ini (Adware.iWon) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\htuqswwx.dll (Trojan.Agent) -> Delete on reboot.<br>C:\U.exe (Trojan.Downloader) -> Quarantined and deleted successfully.<br><br>================================================<br><br>ESET log:<br><br># version=4<br># OnlineScanner.ocx=1.0.0.635<br># OnlineScannerDLLA.dll=1, 0, 0, 79<br># OnlineScannerDLLW.dll=1, 0, 0, 78<br># OnlineScannerUninstaller.exe=1, 0, 0, 49<br># vers_standard_module=3057 (20080426)<br># vers_arch_module=1.064 (20080214)<br># vers_adv_heur_module=1.064 (20070717)<br># EOSSerial=ab020ffaac84eb4ca2845adea54587e8<br># end=finished<br># remove_checked=true<br># unwanted_checked=true<br># utc_time=2008-04-27 03:51:07<br># local_time=2008-04-26 08:51:07 (-0800, Pacific Daylight Time)<br># country="United States"<br># osver=5.1.2600 NT Service Pack 2<br># scanned=697440<br># found=2<br># scan_time=14336<br>C:\QooBox\Quarantine\C\WINDOWS\system32\vtUmJDuS.dll.vir&#9;Win32/Adware.Virtumonde application (unable to clean - deleted)&#9;00000000000000000000000000000000<br>C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP2\A0000013.dll&#9;Win32/Adware.Virtumonde application (unable to clean - deleted)&#9;00000000000000000000000000000000<br><br>===========================================<br><br>HijackThis log:<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 21:31, on 2008-04-26<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br>C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe<br>C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\ZoneLabs\vsmon.exe<br>C:\WINDOWS\wanmpsvc.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe<br>C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe<br>C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br>C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE<br>C:\Compaq\EAKDRV\EAUSBKBD.EXE<br>C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE<br>C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe<br>C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe<br>C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe<br>C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br>C:\Program Files\Windows Defender\MSASCui.exe<br>C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe<br>C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe<br>C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe<br>C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq<br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br>O2 - BHO: (no name) - {1C1CE040-5D65-422E-84C6-EFD6EEFCFA93} - C:\WINDOWS\system32\ssqRjkjI.dll (file missing)<br>O2 - BHO: (no name) - {259274E6-3FEB-5341-BD13-A1A07A9AD77A} - (no file)<br>O2 - BHO: (no name) - {2B76EB42-6211-417E-9A5D-EA8233C749EB} - (no file)<br>O2 - BHO: (no name) - {2CB8C4B2-9DAF-4263-818E-835A955224D1} - C:\WINDOWS\system32\qoMfghIY.dll (file missing)<br>O2 - BHO: {3041db1d-901b-ee6a-2004-aeb134d85913} - {31958d43-1bea-4002-a6ee-b109d1bd1403} - C:\WINDOWS\system32\dkebwlpm.dll<br>O2 - BHO: MyPoints Toolbar - {4E7BD74F-2B8D-469E-C1EA-F165BB85A330} - C:\PROGRA~1\mypoints\mypoints.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)<br>O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O2 - BHO: PrintMe - {97387E2B-B2FA-4E4A-A607-F3B5C134F71C} - C:\Program Files\EFI\PrintMeToolbar\htpmcap.dll<br>O2 - BHO: MYPOINTS - {A057A204-BACC-4D26-CEC4-75A487FD6484} - C:\PROGRA~1\mypoints\mypoints.dll<br>O2 - BHO: (no name) - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - (no file)<br>O2 - BHO: (no name) - {F6C97034-AD95-4205-8055-CAED72E7282A} - (no file)<br>O3 - Toolbar: PrintMe - {97387E2B-B2FA-4E4A-A607-F3B5C134F71C} - C:\Program Files\EFI\PrintMeToolbar\htpmcap.dll<br>O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll<br>O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe<br>O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"<br>O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE<br>O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"<br>O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br>O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon<br>O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon<br>O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"<br>O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br>O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized<br>O4 - HKLM\..\Run: [28cd6fbb] rundll32.exe "C:\WINDOWS\system32\antpboyd.dll",b<br>O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"<br>O4 - Global Startup: AT&T Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe<br>O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm<br>O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll<br>O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll<br>O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe<br>O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe<br>O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe<br>O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll<br>O15 - Trusted IP range: 192.168.1.81<br>O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v46/scrabblecubes/scrabblecubes.cab" >www.worldwinner.com/games/v46/sc&middot;&middot;&middot;ubes.cab</A><br>O16 - DPF: {04063354-A10E-4427-A1EC-F3CC81587BC6} (Mines Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v41/mines/mines.cab" >www.worldwinner.com/games/v41/mi&middot;&middot;&middot;ines.cab</A><br>O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - &raquo;<A HREF="http://support.asus.com/common/asusTek_sys_ctrl.cab" >support.asus.com/common/asusTek_sys_ctrl.cab</A><br>O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - &raquo;<A HREF="http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB" >www.pcpitstop.com/pcpitstop/PCPitStop.CAB</A><br>O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - &raquo;<A HREF="http://www.pcpitstop.com/internet/pcpConnCheck.cab" >www.pcpitstop.com/internet/pcpConnCheck.cab</A><br>O16 - DPF: {18C3FD15-74F6-4280-9C98-3590C966B7B8} (SkillGam Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v47/skillgam/skillgam.cab" >www.worldwinner.com/games/v47/sk&middot;&middot;&middot;lgam.cab</A><br>O16 - DPF: {192F9A01-8030-48CE-9BC6-B03DE3E613C6} (PeoplePC Web Installer) - &raquo;<small>https</small>://<A HREF="https://www.peoplepc.com/ppcos/ISP60/Download/ppcwebi.cab">www.peoplepc.com/ppcos/ISP60/Dow&middot;&middot;&middot;webi.cab</A><br>O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - &raquo;<A HREF="http://www.worldwinner.com/games/v46/shared/FunGamesLoader.cab" >www.worldwinner.com/games/v46/sh&middot;&middot;&middot;ader.cab</A><br>O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - &raquo;<A HREF="http://www.rovion.com/Controls/Rovion.cab" >www.rovion.com/Controls/Rovion.cab</A><br>O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - &raquo;<A HREF="http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab" >us.chat1.yimg.com/us.yimg.com/i/&middot;&middot;&middot;scom.cab</A><br>O16 - DPF: {2C153C75-8476-434B-B3C3-57B63A3D1939} (Brickout Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v48/brickout/brickout.cab" >www.worldwinner.com/games/v48/br&middot;&middot;&middot;kout.cab</A><br>O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} (Pool Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v50/pool/pool.cab" >www.worldwinner.com/games/v50/pool/pool.cab</A><br>O16 - DPF: {41D1977F-4161-4720-800F-EA4903983A38} (Jigsaw Genius Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v43/jigsaw/jigsaw.cab" >www.worldwinner.com/games/v43/ji&middot;&middot;&middot;gsaw.cab</A><br>O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - &raquo;<A HREF="http://www.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsi.cab" >www.symantec.com/techsupp/asa/ss&middot;&middot;&middot;tlsi.cab</A><br>O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - &raquo;<A HREF="http://www.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab" >www.symantec.com/techsupp/asa/ss&middot;&middot;&middot;tlsr.cab</A><br>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;sctl.cab</A><br>O16 - DPF: {555F1BBC-6EC2-474F-84AF-633EF097FF54} (WWHearts Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v52/wwhearts/wwhearts.cab" >www.worldwinner.com/games/v52/ww&middot;&middot;&middot;arts.cab</A><br>O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - &raquo;<A HREF="http://www.eset.eu/buxus/docs/OnlineScanner.cab" >www.eset.eu/buxus/docs/OnlineScanner.cab</A><br>O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v63/bjattack/bja.cab" >www.worldwinner.com/games/v63/bj&middot;&middot;&middot;/bja.cab</A><br>O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab" >www.worldwinner.com/games/v46/be&middot;&middot;&middot;eled.cab</A><br>O16 - DPF: {62969CF2-0F7A-433B-A221-FD8818C06C2F} (Blockwerx Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v49/blockwerx/blockwerx.cab" >www.worldwinner.com/games/v49/bl&middot;&middot;&middot;werx.cab</A><br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1202179311687" >www.update.microsoft.com/microso&middot;&middot;&middot;79311687</A><br>O16 - DPF: {6C6FE41A-0DA6-42A1-9AD8-792026B2B2A7} (FreeCell Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v41/freecell/freecell.cab" >www.worldwinner.com/games/v41/fr&middot;&middot;&middot;cell.cab</A><br>O16 - DPF: {6D53ADB7-6AD5-4A59-BFE4-7B57D2F4AA89} - &raquo;<A HREF="http://ip.135mp3.com/135mp3.cab" >ip.135mp3.com/135mp3.cab</A><br>O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &raquo;<A HREF="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1202179299890" >www.update.microsoft.com/microso&middot;&middot;&middot;79299890</A><br>O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - &raquo;<A HREF="http://chat.yahoo.com/cab/yacsui.cab" >chat.yahoo.com/cab/yacsui.cab</A><br>O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - &raquo;<A HREF="http://www.worldwinner.com/games/shared/wwlaunch.cab" >www.worldwinner.com/games/shared&middot;&middot;&middot;unch.cab</A><br>O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v46/wordmojo/wordmojo.cab" >www.worldwinner.com/games/v46/wo&middot;&middot;&middot;mojo.cab</A><br>O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} (Cubis Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v57/cubis/cubis.cab" >www.worldwinner.com/games/v57/cu&middot;&middot;&middot;ubis.cab</A><br>O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} (Sol Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v46/sol/sol.cab" >www.worldwinner.com/games/v46/sol/sol.cab</A><br>O16 - DPF: {A91FB93D-7561-4524-8484-5C27C8FA8D42} (WwLuxor Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v49/luxor/luxor.cab" >www.worldwinner.com/games/v49/lu&middot;&middot;&middot;uxor.cab</A><br>O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} (SwapIt Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v67/swapit/swapit.cab" >www.worldwinner.com/games/v67/sw&middot;&middot;&middot;apit.cab</A><br>O16 - DPF: {B06CE1BC-5D9D-4676-BD28-1752DBF394E0} (Hangman Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v41/hangman/hangman.cab" >www.worldwinner.com/games/v41/ha&middot;&middot;&middot;gman.cab</A><br>O16 - DPF: {BA94245D-2AA0-4953-9D9F-B0EE4CC02C43} (Tilecity Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v42/tilecity/tilecity.cab" >www.worldwinner.com/games/v42/ti&middot;&middot;&middot;city.cab</A><br>O16 - DPF: {BB637307-92FA-47EC-B3F7-6969078673CC} (Royal Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v45/royal/royal.cab" >www.worldwinner.com/games/v45/ro&middot;&middot;&middot;oyal.cab</A><br>O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;dmgr.cab</A><br>O16 - DPF: {C5326A4D-E9AA-40AD-A09A-E74304D86B47} (DinerDash Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v50/dinerdash/dinerdash.cab" >www.worldwinner.com/games/v50/di&middot;&middot;&middot;dash.cab</A><br>O16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} (Paint Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v43/paint/paint.cab" >www.worldwinner.com/games/v43/pa&middot;&middot;&middot;aint.cab</A><br>O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - &raquo;<A HREF="http://www.live365.com/players/play365.cab" >www.live365.com/players/play365.cab</A><br>O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} (FamilyFeud Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v47/familyfeud/familyfeud.cab" >www.worldwinner.com/games/v47/fa&middot;&middot;&middot;feud.cab</A><br>O16 - DPF: {E12EB891-D000-421B-A8ED-EDE1BDCA14A0} (GolfSol Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v44/golfsol/golfsol.cab" >www.worldwinner.com/games/v44/go&middot;&middot;&middot;fsol.cab</A><br>O16 - DPF: {E70E3E64-2793-4AEF-8CC8-F1606BE563B0} (WWSpades Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v47/wwspades/wwspades.cab" >www.worldwinner.com/games/v47/ww&middot;&middot;&middot;ades.cab</A><br>O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - &raquo;<A HREF="http://tools.ebayimg.com/eps/activex/EPSControl_v1-32.cab" >tools.ebayimg.com/eps/activex/EP&middot;&middot;&middot;1-32.cab</A><br>O20 - Winlogon Notify: gdiwxp - gdiwxp.dll (file missing)<br>O20 - Winlogon Notify: vtUmJDuS - vtUmJDuS.dll (file missing)<br>O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe<br>O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br>O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br>O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br>O23 - Service: Compaq Advisor (Compaq_RBA) - NeoPlanet - C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe<br>O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE<br>O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br>O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe<br>O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe<br>O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe<br>O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe<br>O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe<br>O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe<br>O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe<br><br>--<br>End of file - 14733 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20393593</guid>
<pubDate>Sun, 27 Apr 2008 00:42:02 EDT</pubDate>
</item>

<item>
<title>Re: browser redirect and sluggish startup; HT log added</title>
<link>http://www.dslreports.com/forum/remark,20390075</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Open any .TXT document. This will open in Notepad.  Click "<b>Format</b>", and uncheck <b>Word Wrap</b>.  Be absolutely certain in all that follows that you never post a log to the Forum in which Word Wrap was active.<br><br><b><u>First Steps</u></b><br><b>:!: The following instructions are <u>only</u> for this Forum member. Please do not use these instructions on another computer system. You can seriously damage your system by following the instructions below without guided assistance. You assuredly will make a cleanup of your system more difficult.</b><br><br>TeaTimer is an excellent tool for the prevention of spyware but it can sometimes prevent HijackThis from fixing certain things. Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your HijackThis log is clean.<br>&#8226; Open Spybot Search & Destroy.<br>&#8226; In the Mode menu click "Advanced mode" if not already selected.<br>&#8226; Choose Yes at the Warning prompt.<br>&#8226; Expand the Tools menu.<br>&#8226; Click Resident.<br>&#8226; <b>Uncheck</b> the Resident "TeaTimer" (Protection of overall system settings) active. box.<br>&#8226; In the File menu click Exit to exit Spybot Search & Destroy.<br>&#8226; Download and Unzip to your Desktop:  &raquo;<A HREF="http://www.techsupportforum.com/sectools/ResetTeaTimer.zip" >www.techsupportforum.com/sectool&middot;&middot;&middot;imer.zip</A><br>&#8226; Double click <b>ResetTeaTimer.bat</b> to remove all entries set by TeaTimer.<br><br>Please download<b>  <i>ATF Cleaner</i></b> <br><textarea name="code" class="text" cols=50 rows=10>http://www.atribune.org/ccount/click.php?id=1&#012;</textarea><!--end code block-->It does not require any installation.. It is set up to clean Windows TEMP folders, as well as IE, FireFox and Opera, Temporary Internet Files and Cookies.<br>&#8226;      Double-click <b>ATF-Cleaner.exe</b> to run the program. <br><br><b>First Step:</b><br>&#8226;      Under <b>Main</b> choose: <b>Select All</b><br>&#8226;      Click the <b>Empty Selected</b> button. <br><b><u>Next, if you use Firefox (and <i>some</i> Mozilla-based browsers)</u></b> <br>&#8226;      Click Firefox at the top and choose: <b>Select All</b><br>&#8226;      Click the <b>Empty Selected</b> button. <b><u><br>Next, if you use the Opera browser</u></b> <br>&#8226;      Click <b>Opera</b> at the top and choose: <b>Select All</b> <br>&#8226;      Click the <b>Empty Selected</b> button. <b>:!: Click Exit on the Main menu to close the program.</b><br><br><b>Reconfigure Windows XP to show hidden files:</b><br><i>To enable the viewing of Hidden files follow these steps: </i><br>&#8226; Close all programs so that you are at your desktop. <br>&#8226; Double-click on the My Computer icon. <br>&#8226; Select the Tools menu and click Folder Options. <br>&#8226; After the new window appears select the View tab. <br>&#8226; Put a checkmark in the checkbox labeled Display the contents of system folders. <br>&#8226; Under the Hidden files and folders section select the radio button labeled Show hidden files and folders. <br>&#8226; Remove the checkmark from the checkbox labeled Hide file extensions for known file types. <br>&#8226; Remove the checkmark from the checkbox labeled Hide protected operating system files. <br>&#8226; Press the Apply button and then the OK button and exit My Computer. <br>&#8226; Now your computer is configured to show all hidden files. <br><br><b><u>Malware Removal Steps</u></b><br>1. Open <b>HijackThis</b> again, System scan only.  <b>Checkmark</b> these items:<br><br><b>R0 - HKLM\Software\Microsoft\InternetExplorer\Search,SearchAssistant = &raquo;www.wsou.cn/band.htm<br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\InternetSettings,ProxyOverride = 127.0.0.1<br>O3 - Toolbar: MyPoints Toolbar - {4E7BD74F-2B8D-469E-C1EA-F165BB85A330} - C:\PROGRA~1\mypoints\mypoints.dll<br>O3 - Toolbar: MYPOINTS - {A057A204-BACC-4D26-CEC4-75A487FD6484} -C:\PROGRA~1\mypoints\mypoints.dll<br>O4 - HKLM\..\Run: [BM2bfe5c27] Rundll32.exe "C:\WINDOWS\system32\jwhhvurp.dll",s<br>O4 - HKCU\..\RunOnce: [] C:\Program Files\Internet Explorer\iexplore.exe<br>O4 - Global Startup: Local Area Connection.lnk = ?<br>O14 - IERESET.INF:START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=2c02&lc=0409<br>O15 - Trusted Zone: www.cashsurfers.com<br>O16 - DPF: {549F957E-2F89-11D6-8CFE-00C04F52B225} (CMV5 Class) -&raquo;coupons.smartsource.com/download/cscmv5X.cab<br>O16 - DPF: {7AA32FC7-133B-4AE7-998E-CED0D9829B12} (luna Class) -&raquo;static.waverevenue.com/website.cab<br>O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} -&raquo;a19.g.akamai.net/7/19/7125/1452/&middot;&middot;&middot;302/cpbrkpie.cab<br>O16 - DPF: {A305FBA3-4A87-483D-A53B-138F9F635357}(PCInfo.CMClass) -&raquo;ciscdb.sel.sony.com/support/pops&middot;&middot;&middot;Info.CAB<br>O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrintClass) - &raquo;offers.e-centives.com/cif/download/bin/actxcab.cab<br>O16 - DPF: {AF697529-9D41-4647-8D80-9E2D74696D5E} (Divx Control)- &raquo;192.168.1.81/userform/divx.cab<br>O16 - DPF: {BE153019-DCDB-479E-827B-C2AAB8CDCA64} (OSDetectControl) - &raquo;&raquo;<small>https</small>://<A HREF="https://www.msisurvey.com/share/osdetect.ocx">www.msisurvey.com/share/osdetect.ocx</A><br>O21 - SSODL: NetCheck - {F5B7DDBE-5f02-4244-96DB-386DFA24496B} -(no file)</b><br><br>Click "<b>Fix checked</b>" and when the log panel clears exit HijackThis.<br><br>2. Download and Run  -- <b>ComboFix&copy; </b> <br>Download this file <b><u>-- to your Desktop --</u></b> from any of these sources:  <br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br>&#8226; Disconnect from the Internet.<br>&#8226; Disable  your Antivirus  software -- this includes any Script Blocking Feature it may have.<br><br><b>Important:  Have no other programs running.  Your Task Bar should be clear of any program entries including your Browser.</b><br>&#8226; A window will open with a warning.  Accept any disclaimers to start the fix. When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.<br>A caution - Do <b>not</b> run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock.<br><br>3. Please download MalwareBytes Anti-malware (MBAM) from one of the following links:<br><textarea name="code" class="text" cols=50 rows=10>http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html&#012;http://www.besttechie.net/tools/mbam-setup.exe&#012;</textarea><!--end code block--><br>Once downloaded, close all programs and Windows on your computer (including this one.)<br><br>Double-click on the icon on your desktop named Download_mbam-setup.exe. This will start the installation of MBAM onto your computer.<br><br>When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure you leave both the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware checked. Then click on the Finish button.<br><br>MBAM will now automatically start and you will see a message stating that you should update the program before performing a scan. As MBAM will automatically update itself after the install, you can press the OK button to close that box and you will now be at the main program.<br><br>On the <b>Scanner tab</b>, make sure the the <b>Perform quick scan</b> option is selected and then click on the <b>Scan</b> button to start scanning your computer.<br><br>MBAM will now start scanning your computer for malware. This process can take quite a while, so we suggest you go and do something else and periodically check on the status of the scan. <br><br>When the scan is finished a message box will appear that it has completed scanning successfully.  Click <b>OK</b>.  Now click <b>Show Results</b>.  Make sure all entries have a checkmark at their far left.  You should now click on the <b>Remove Selected</b> button to remove all the listed malware. MBAM will now delete all of the files and registry keys and add them to the programs quarantine.<br><br>When MBAM has finished removing the malware, it will open the scan log and display it in Notepad. Review the log as desired, and then close the Notepad window.  Remember where you saved the log file, as we will want to see it later.<br><br>4.  <b>Eset NOD32 scanner</b><br>Go here to run an online scannner from ESET:  &raquo;<A HREF="http://www.eset.eu/online-scanner" >www.eset.eu/online-scanner</A><br><b>Note:</b> You will need to use Internet Explorer for this scan.<br><br>&#8226; Tick the box next to YES, I accept the Terms of Use.<br>&#8226; Click Start<br>&#8226; When asked, allow the activex control to install<br>&#8226; <b>Disable your Antivirus software</b>.  You can usually do this with its Notfication Tray icon near the clock.<br>&#8226; Click Start<br>&#8226; Make sure that the option <b>"Remove found threats"</b> is <u>Checked</u>, and the option <b>"Scan unwanted applications"</b> is also <u>Checked</u>.<br>&#8226; Click Scan.<br>&#8226; Wait for the scan to finish.<br>&#8226; :!:  <b>Re-enable your Anvirisus software.</b><br>&#8226; A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt.  We will need this later.<br><br>5. Run <b>HijackThis</b> again, and save the log file.<br><br><b><i>Submit to the Forum:</i></b><br>&#8226; The contents of C:\Combofix.txt;<br>&#8226; The <b>MBAM</b> log file;<br>&#8226; The ESET online scan results, C:\Program Files\EsetOnlineScanner\log.txt;<br>&#8226; The new HijackThis log.<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20390075</guid>
<pubDate>Sat, 26 Apr 2008 06:07:17 EDT</pubDate>
</item>

<item>
<title>browser redirect and sluggish startup; HT log added</title>
<link>http://www.dslreports.com/forum/remark,20389409</link>
<description><![CDATA[<A HREF="/useremail/u/1104519"><b>randyw01</b></A> : My latest problem is something causing both IE and Firefox to open a second window after I open a first one, with sex-dating, casino, or other some other unwanted site appearing in the 2nd window.  I'm also experiencing a few slow computer startup, having to wait over 5 minutes after the desktop begins to load.<br><br>Spybot, Windows Defender and AVG Antispyware were run at night in safe mode ( Adaware crashing in safe mode ).  Spybot detected Virtumonde, couldn't fully clean it.  Forgot to save logfiles of Defender and AVG.  Spybot allowed to run on next normal restart and claimed to finish off Virtumonde cleaning, but may have failed.<br><br>I've spent most of the past day working on this; don't really want to run an online scan at the moment since it'll be running during waking hours and I won't be able to anything with the results until I wake hours after it's done.<br><br>System has 384 MB memory, Celeron 1.8 Ghz processor, Win XP Home SP 2, Spybot, Adaware ( free ), Windows Defender, AVG, ZoneAlarm ( free ), Norton Antivirus 2008.<br><br>Hijack This log:<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 8:48:16 PM, on 4/25/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br>C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe<br>C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\ZoneLabs\vsmon.exe<br>C:\WINDOWS\wanmpsvc.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe<br>C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe<br>C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE<br>C:\Compaq\EAKDRV\EAUSBKBD.EXE<br>C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe<br>C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br>C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE<br>C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe<br>C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe<br>C:\Program Files\Windows Defender\MSASCui.exe<br>C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br>C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe<br>C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe<br>C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>C:\Program Files\Mozilla Firefox\firefox.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R0 - HKLM\Software\Microsoft\Internet <br><br>Explorer\Search,SearchAssistant = &raquo;<A HREF="http://www.wsou.cn/band.htm" >www.wsou.cn/band.htm</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title <br><br>= Microsoft Internet Explorer provided by Compaq<br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet <br><br>Settings,ProxyOverride = 127.0.0.1<br>O3 - Toolbar: PrintMe - {97387E2B-B2FA-4E4A-A607-F3B5C134F71C} - <br><br>C:\Program Files\EFI\PrintMeToolbar\htpmcap.dll<br>O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-<br><br>0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll<br>O3 - Toolbar: MyPoints Toolbar - {4E7BD74F-2B8D-469E-C1EA-<br><br>F165BB85A330} - C:\PROGRA~1\mypoints\mypoints.dll<br>O3 - Toolbar: MYPOINTS - {A057A204-BACC-4D26-CEC4-75A487FD6484} - <br><br>C:\PROGRA~1\mypoints\mypoints.dll<br>O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy <br><br>Access Button Support\StartEAK.exe<br>O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone <br><br>Labs\ZoneAlarm\zlclient.exe"<br>O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32<br><br>\NeroCheck.exe<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common <br><br>Files\Real\Update_OB\realsched.exe"  -osboot<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program <br><br>Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common <br><br>Files\Logitech\QCDriver\LVCOMS.EXE<br>O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1<br><br>\SMARTB~1\MotiveSB.exe<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program <br><br>Files\Java\jre1.6.0_05\bin\jusched.exe"<br>O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program <br><br>Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br>O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program <br><br>Files\Canon\SolutionMenu\CNSLMAIN.exe /logon<br>O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program <br><br>Files\Canon\MyPrinter\BJMyPrt.exe /logon<br>O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec <br><br>Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton <br><br>AntiVirus\osCheck.exe"<br>O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows <br><br>Defender\MSASCui.exe" -hide<br>O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program <br><br>Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized<br>O4 - HKLM\..\Run: [BM2bfe5c27] Rundll32.exe "C:\WINDOWS\system32<br><br>\jwhhvurp.dll",s<br>O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-<br><br>88D8A56B10AA}] "C:\Program Files\Common <br><br>Files\Ahead\lib\NMBgMonitor.exe"<br>O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - <br><br>Search & Destroy\TeaTimer.exe<br>O4 - HKCU\..\RunOnce: [] C:\Program Files\Internet <br><br>Explorer\iexplore.exe  <br><br>&raquo;<A HREF="http://www.symantec.com/techsupp/servlet/ProductMessages?" >www.symantec.com/techsupp/servle&middot;&middot;&middot;essages?</A><br><br>module=2007&error=0&language=en&product=SymNRT&version=2008.0.2.1<br><br>7&build=Symantec&a=00000082.00000097.000001cd&b=00000082.00000097<br><br>.000001cf&c=00000083.00000018.000000a8<br>O4 - Global Startup: AT&T Self Support Tool.lnk = C:\Program <br><br>Files\SBC Self Support Tool\bin\matcli.exe<br>O4 - Global Startup: Local Area Connection.lnk = ?<br>O8 - Extra context menu item: Download All by FlashGet - <br><br>C:\Program Files\FlashGet\jc_all.htm<br>O8 - Extra context menu item: Download using FlashGet - <br><br>C:\Program Files\FlashGet\jc_link.htm<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-<br><br>00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-<br><br>11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05<br><br>\bin\ssv.dll<br>O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-<br><br>000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll<br>O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-<br><br>BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll<br>O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-<br><br>47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe<br>O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-<br><br>47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe<br>O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-<br><br>0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe<br>O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-<br><br>8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-<br><br>58CAB36FD2A2} - C:\Program Files\Spybot - Search & <br><br>Destroy\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy <br><br>Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - <br><br>C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-<br><br>00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-<br><br>11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O10 - Unknown file in Winsock LSP: c:\windows\system32<br><br>\nwprovau.dll<br>O14 - IERESET.INF: <br><br>START_PAGE_URL=http://store.presario.net/scripts/redirectors/pres<br><br>ario/storeredir2.dll?s=consumerfav&c=2c02&lc=0409<br>O15 - Trusted Zone: www.cashsurfers.com<br>O15 - Trusted IP range: 192.168.1.81<br>O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes <br><br>Control) - <br><br>&raquo;<A HREF="http://www.worldwinner.com/games/v46/scrabblecubes/scrabblecubes" >www.worldwinner.com/games/v46/sc&middot;&middot;&middot;blecubes</A>.<br><br>cab<br>O16 - DPF: {04063354-A10E-4427-A1EC-F3CC81587BC6} (Mines Control) <br><br>- &raquo;<A HREF="http://www.worldwinner.com/games/v41/mines/mines.cab" >www.worldwinner.com/games/v41/mi&middot;&middot;&middot;ines.cab</A><br>O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} <br><br>(asusTek_sysctrl Class) - <br><br>&raquo;<A HREF="http://support.asus.com/common/asusTek_sys_ctrl.cab" >support.asus.com/common/asusTek_sys_ctrl.cab</A><br>O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop <br><br>Utility) - &raquo;<A HREF="http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB" >www.pcpitstop.com/pcpitstop/PCPitStop.CAB</A><br>O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - <br><br>&raquo;<A HREF="http://www.pcpitstop.com/internet/pcpConnCheck.cab" >www.pcpitstop.com/internet/pcpConnCheck.cab</A><br>O16 - DPF: {18C3FD15-74F6-4280-9C98-3590C966B7B8} (SkillGam <br><br>Control) - <br><br>&raquo;<A HREF="http://www.worldwinner.com/games/v47/skillgam/skillgam.cab" >www.worldwinner.com/games/v47/sk&middot;&middot;&middot;lgam.cab</A><br>O16 - DPF: {192F9A01-8030-48CE-9BC6-B03DE3E613C6} (PeoplePC Web <br><br>Installer) - <br><br>&raquo;<small>https</small>://<A HREF="https://www.peoplepc.com/ppcos/ISP60/Download/ppcwebi.cab">www.peoplepc.com/ppcos/ISP60/Dow&middot;&middot;&middot;webi.cab</A><br>O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader <br><br>Object) - <br><br>&raquo;<A HREF="http://www.worldwinner.com/games/v46/shared/FunGamesLoader.cab" >www.worldwinner.com/games/v46/sh&middot;&middot;&middot;ader.cab</A><br>O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} <br><br>(BlueStream_Flash Class) - <br><br>&raquo;<A HREF="http://www.rovion.com/Controls/Rovion.cab" >www.rovion.com/Controls/Rovion.cab</A><br>O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio <br><br>Conferencing) - <br><br>&raquo;<A HREF="http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.ca" >us.chat1.yimg.com/us.yimg.com/i/&middot;&middot;&middot;cscom.ca</A><br><br>b<br>O16 - DPF: {2C153C75-8476-434B-B3C3-57B63A3D1939} (Brickout <br><br>Control) - <br><br>&raquo;<A HREF="http://www.worldwinner.com/games/v48/brickout/brickout.cab" >www.worldwinner.com/games/v48/br&middot;&middot;&middot;kout.cab</A><br>O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} (Pool Control) <br><br>- &raquo;<A HREF="http://www.worldwinner.com/games/v50/pool/pool.cab" >www.worldwinner.com/games/v50/pool/pool.cab</A><br>O16 - DPF: {41D1977F-4161-4720-800F-EA4903983A38} (Jigsaw Genius <br><br>Control) - &raquo;<A HREF="http://www.worldwinner.com/games/v43/jigsaw/jigsaw.cab" >www.worldwinner.com/games/v43/ji&middot;&middot;&middot;gsaw.cab</A><br>O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec <br><br>SmartIssue) - <br><br>&raquo;<A HREF="http://www.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsi.cab" >www.symantec.com/techsupp/asa/ss&middot;&middot;&middot;tlsi.cab</A><br>O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec <br><br>Script Runner Class) - <br><br>&raquo;<A HREF="http://www.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab" >www.symantec.com/techsupp/asa/ss&middot;&middot;&middot;tlsr.cab</A><br>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - <br><br>&raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcins" >download.mcafee.com/molbin/share&middot;&middot;&middot;01/mcins</A><br><br>ctl.cab<br>O16 - DPF: {549F957E-2F89-11D6-8CFE-00C04F52B225} (CMV5 Class) - <br><br>&raquo;<A HREF="http://coupons.smartsource.com/download/cscmv5X.cab" >coupons.smartsource.com/download/cscmv5X.cab</A><br>O16 - DPF: {555F1BBC-6EC2-474F-84AF-633EF097FF54} (WWHearts <br><br>Control) - <br><br>&raquo;<A HREF="http://www.worldwinner.com/games/v52/wwhearts/wwhearts.cab" >www.worldwinner.com/games/v52/ww&middot;&middot;&middot;arts.cab</A><br>O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - <br><br>&raquo;<A HREF="http://www.worldwinner.com/games/v63/bjattack/bja.cab" >www.worldwinner.com/games/v63/bj&middot;&middot;&middot;/bja.cab</A><br>O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled <br><br>Control) - <br><br>&raquo;<A HREF="http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab" >www.worldwinner.com/games/v46/be&middot;&middot;&middot;eled.cab</A><br>O16 - DPF: {62969CF2-0F7A-433B-A221-FD8818C06C2F} (Blockwerx <br><br>Control) - <br><br>&raquo;<A HREF="http://www.worldwinner.com/games/v49/blockwerx/blockwerx.cab" >www.worldwinner.com/games/v49/bl&middot;&middot;&middot;werx.cab</A><br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl <br><br>Class) - <br><br>&raquo;<A HREF="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/" >www.update.microsoft.com/microso&middot;&middot;&middot;rols/en/</A><br><br>x86/client/wuweb_site.cab?1202179311687<br>O16 - DPF: {6C6FE41A-0DA6-42A1-9AD8-792026B2B2A7} (FreeCell <br><br>Control) - <br><br>&raquo;<A HREF="http://www.worldwinner.com/games/v41/freecel