<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: HJT Logs in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r20397451</link>
<description></description>
<language>en</language>
<pubDate>Thu, 21 Aug 2008 00:56:32 EDT</pubDate>
<lastBuildDate>Thu, 21 Aug 2008 00:56:32 EDT</lastBuildDate>

<item>
<title>Re: HJT Log</title>
<link>http://www.dslreports.com/forum/remark,20408897</link>
<description><![CDATA[<A HREF="/useremail/u/899399"><b>Weedpicker</b></A> : <div class="bquote"><small>said by  bcastner <A HREF="/useremail/u/693977"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Virtumonde is adware, not a virus.<br>It will apply to every user, not just the one you used to scan.<br><br>Please try to do the steps above. They require nothing more than a download and a double click in most cases.<br> </div>I do appreciate the help, but like I said, I am not able to follow all the above directions. I deleted her account, added a new one and everything runs fine.<br><br>Another forum said that deleting her account if the fastest and easiest fix. My account ran fine, so it was just adware on her side.<br><br>Thanks again. If this proves to not work, I will try here again.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20408897</guid>
<pubDate>Wed, 30 Apr 2008 00:37:49 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log</title>
<link>http://www.dslreports.com/forum/remark,20407322</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Virtumonde is adware, not a virus.<br>It will apply to every user, not just the one you used to scan.<br><br>Please try to do the steps above. They require nothing more than a download and a double click in most cases.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20407322</guid>
<pubDate>Tue, 29 Apr 2008 18:43:58 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log</title>
<link>http://www.dslreports.com/forum/remark,20405307</link>
<description><![CDATA[<A HREF="/useremail/u/899399"><b>Weedpicker</b></A> : Thanks for the help, but I am not capable of doing all that. My knowledge is very limited.<br><br>Can I just delete her account to remove the virus?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20405307</guid>
<pubDate>Tue, 29 Apr 2008 12:48:24 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log</title>
<link>http://www.dslreports.com/forum/remark,20403811</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : TeaTimer is not necessary with Windows Defender installed.  It also at times prevent anti-malware utilities from fixing certain things. Please disable TeaTimer for now until you are clean. For Vista with Windows Defender, I would not install this at all.<br><br>&#8226; Open Spybot Search & Destroy.<br>&#8226; In the Mode menu click "Advanced mode" if not already selected.<br>&#8226; Choose Yes at the Warning prompt.<br>&#8226; Expand the Tools menu.<br>&#8226; Click Resident.<br>&#8226; <b>Uncheck</b> the Resident "TeaTimer" (Protection of overall system settings) active. box.<br>&#8226; In the File menu click Exit to exit Spybot Search & Destroy.<br><br>Similarly, Spyware Doctor will prevent cleaning your computer.  Please disable it for now.<br>From within Spyware Doctor, click the "]OnGuard" button on the left side. <br>Uncheck "Activate OnGuard". <br><br>Please download<b>  <i>ATF Cleaner</i></b>  <br><textarea name="code" class="text" cols=50 rows=10>http://www.atribune.org/ccount/click.php?id=1&#012; &#012;</textarea><!--end code block-->It does not require any installation.. It is set up to clean Windows 2k, XP & Vista TEMP folders, as well as IE, FireFox and Opera, Temporary Internet Files and Cookies.<br>&#8226;      Double-click <b>ATF-Cleaner.exe</b> to run the program. <br><b>For all browsers:</b><br>&#8226;      Under <b>Main</b> choose: <b>Select All</b><br>&#8226;      Click the <b>Empty Selected</b> button. <br><b><u>Next, if you use Firefox (and <i>some</i> Mozilla-based browsers)</u></b> <br>&#8226;      Click Firefox at the top and choose: <b>Select All</b><br>&#8226;      Click the <b>Empty Selected</b> button. <b><u><br>Next, if you use the Opera browser</u></b> <br>&#8226;      Click <b>Opera</b> at the top and choose: <b>Select All</b> <br>&#8226;      Click the <b>Empty Selected</b> button. <b>:!: Click Exit on the Main menu to close the program.</b><br><br><b>Reconfigure Windows Vista to show hidden files:</b><br>To enable the viewing of Hidden files follow these steps: <br>&#8226;Close all programs so that you are at your desktop. <br>&#8226;Open the Control Panel menu and click <b>Folder Options</b>. <br>&#8226;After the new window appears select the <b>View</b> tab. <br>&#8226;Put a checkmark in the checkbox labeled Display the contents of system folders. <br>&#8226;Under the Hidden files and folders section select the radio button labeled Show hidden files and folders. <br>&#8226;Remove the checkmark from the checkbox labeled Hide file extensions for known file types. <br>&#8226;Remove the checkmark from the checkbox labeled Hide protected operating system files. <br>&#8226;Press the Apply button and then the OK button and exit My Computer. <br>&#8226;Now your computer is configured to show all hidden files. <b><u>Malware Removal Steps</u></b><br><br>1. Download and Run  -- <b>ComboFix&copy; </b> <br>Download this file <b><u>-- to your Desktop --</u></b> from any of these sources:  <br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br>&#8226; Disconnect from the Internet.<br>&#8226; Disable  your Antivirus  software -- this includes any Script Blocking Feature it may have.<br><br><b>Important:  Have no other programs running.  Your Task Bar should be clear of any program entries including your Browser.</b><br>&#8226; A window will open with a warning.  Accept any disclaimers to start the fix. When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.<br>A caution - Do <b>not</b> run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock.<br><br>2. Please download MalwareBytes Anti-malware (MBAM) from one of the following links:<br><textarea name="code" class="text" cols=50 rows=10>http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html&#012;http://www.besttechie.net/tools/mbam-setup.exe&#012;</textarea><!--end code block--><br>Once downloaded, close all programs and Windows on your computer (including this one.)<br><br>Double-click on the icon on your desktop named Download_mbam-setup.exe. This will start the installation of MBAM onto your computer.<br><br>When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure you leave both the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware checked. Then click on the Finish button.<br><br>MBAM will now automatically start and you will see a message stating that you should update the program before performing a scan. As MBAM will automatically update itself after the install, you can press the OK button to close that box and you will now be at the main program.<br><br>On the <b>Scanner tab</b>, make sure the the <b>Perform quick scan</b> option is selected and then click on the <b>Scan</b> button to start scanning your computer.<br><br>MBAM will now start scanning your computer for malware. This process can take quite a while, so we suggest you go and do something else and periodically check on the status of the scan. <br><br>When the scan is finished a message box will appear that it has completed scanning successfully.  Click <b>OK</b>.  Now click <b>Show Results</b>.  Make sure all entries have a checkmark at their far left.  You should now click on the <b>Remove Selected</b> button to remove all the listed malware. MBAM will now delete all of the files and registry keys and add them to the programs quarantine.<br><br>When MBAM has finished removing the malware, it will open the scan log and display it in Notepad. Review the log as desired, and then close the Notepad window.  Remember where you saved the log file, as we will want to see it later.<br><br>3. Run <b>HijackThis</b> again, and save the log file.<br><br><b><i>Submit to the Forum:</i></b><br>&#8226; The contents of C:\Combofix.txt;<br>&#8226; The <b>MBAM</b> log results;<br>&#8226; The new HijackThis log.<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20403811</guid>
<pubDate>Tue, 29 Apr 2008 06:54:49 EDT</pubDate>
</item>

<item>
<title>Re: HJT Logs</title>
<link>http://www.dslreports.com/forum/remark,20397451</link>
<description><![CDATA[<A HREF="/useremail/u/899399"><b>Weedpicker</b></A> : Well, my NOD32 just popped up and said I had that virus and it was in my wifes TEMP file. I clicked on delete - Did the fix the problem or is the "real" virus still hanging around?<br><br>Help is appreciated.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20397451</guid>
<pubDate>Sun, 27 Apr 2008 22:53:05 EDT</pubDate>
</item>

<item>
<title>Re: HJT Logs</title>
<link>http://www.dslreports.com/forum/remark,20396404</link>
<description><![CDATA[<A HREF="/useremail/u/899399"><b>Weedpicker</b></A> : Ok, I'll try again. Installed and ran all the programs as requested.<br><br>Spybot did find a HOTKEY called Virtumonde or something like that. I removed it, but still getting tons of pop ups under my wifes account - None under mine.  ???<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 6:00:58 PM, on 4/27/2008<br>Platform: Windows Vista  (WinNT 6.00.1904)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16643)<br>Boot mode: Normal<br><br>Running processes:<br>C:\Windows\System32\smss.exe<br>C:\Windows\system32\csrss.exe<br>C:\Windows\system32\wininit.exe<br>C:\Windows\system32\csrss.exe<br>C:\Windows\system32\services.exe<br>C:\Windows\system32\lsass.exe<br>C:\Windows\system32\lsm.exe<br>C:\Windows\system32\winlogon.exe<br>C:\Windows\system32\svchost.exe<br>C:\Windows\system32\svchost.exe<br>C:\Windows\System32\svchost.exe<br>C:\Windows\System32\svchost.exe<br>C:\Windows\System32\svchost.exe<br>C:\Windows\system32\svchost.exe<br>C:\Windows\system32\SLsvc.exe<br>C:\Windows\system32\svchost.exe<br>C:\Windows\system32\svchost.exe<br>C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>C:\Windows\System32\spoolsv.exe<br>C:\Windows\system32\svchost.exe<br>C:\Windows\system32\Dwm.exe<br>C:\Windows\system32\taskeng.exe<br>C:\Windows\Explorer.EXE<br>C:\Program Files\Windows Defender\MSASCui.exe<br>C:\Windows\RtHDVCpl.exe<br>C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br>C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe<br>C:\Program Files\Launch Manager\LManager.exe<br>C:\Acer\Empowering Technology\eDSMSNfix.exe<br>C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe<br>C:\Windows\System32\igfxtray.exe<br>C:\Windows\System32\hkcmd.exe<br>C:\Windows\System32\igfxpers.exe<br>C:\Program Files\Zune\ZuneLauncher.exe<br>C:\Program Files\Spyware Doctor\pctsTray.exe<br>C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe<br>C:\Program Files\Windows Sidebar\sidebar.exe<br>C:\Windows\ehome\ehtray.exe<br>C:\Program Files\Windows Media Player\wmpnscfg.exe<br>C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>C:\Program Files\Google\Google Updater\GoogleUpdater.exe<br>C:\Program Files\Logitech\SetPoint\SetPoint.exe<br>C:\Windows\system32\igfxsrvc.exe<br>C:\Windows\ehome\ehmsas.exe<br>C:\Users\RDS\AppData\Local\Temp\RtkBtMnt.exe<br>C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE<br>C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE<br>C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE<br>C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE<br>C:\Windows\system32\igfxext.exe<br>C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE<br>C:\Acer\ALaunch\ALaunchSvc.exe<br>C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe<br>C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe<br>C:\Acer\Empowering Technology\eNet\eNet Service.exe<br>C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br>C:\Acer\Mobility Center\MobilityService.exe<br>C:\Program Files\Eset\nod32krn.exe<br>C:\Windows\system32\svchost.exe<br>C:\Program Files\CyberLink\Shared Files\RichVideo.exe<br>C:\Program Files\Spyware Doctor\pctsAuxs.exe<br>C:\Program Files\Spyware Doctor\pctsSvc.exe<br>C:\Windows\system32\svchost.exe<br>C:\Windows\System32\svchost.exe<br>C:\Windows\system32\SearchIndexer.exe<br>C:\Windows\system32\DRIVERS\xaudio.exe<br>C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe<br>C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe<br>C:\Acer\Empowering Technology\ePower\ePowerSvc.exe<br>C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe<br>C:\Windows\system32\wbem\wmiprvse.exe<br>C:\Windows\system32\wbem\wmiprvse.exe<br>C:\Windows\system32\wbem\unsecapp.exe<br>C:\Program Files\Eset\nod32kui.exe<br>C:\Windows\system32\taskeng.exe<br>C:\Program Files\Windows Media Player\wmpnetwk.exe<br>C:\Windows\system32\wbem\unsecapp.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br>C:\Windows\system32\cmd.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html" >us.rd.yahoo.com/customize/ycomp/&middot;&middot;&middot;/ie.html</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com" >us.rd.yahoo.com/customize/ycomp/&middot;&middot;&middot;ahoo.com</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://en.us.acer.yahoo.com" >en.us.acer.yahoo.com</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://en.us.acer.yahoo.com" >en.us.acer.yahoo.com</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br>R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = &raquo;<A HREF="http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com" >us.rd.yahoo.com/customize/ycomp/&middot;&middot;&middot;ahoo.com</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br>R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br>O1 - Hosts: ::1 localhost<br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll<br>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll<br>O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll<br>O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br>O4 - HKLM\..\Run: [ALaunch] C:\Acer\ALaunch\AlaunchClient.exe<br>O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br>O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br>O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe<br>O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe<br>O4 - HKLM\..\Run: [eDSMSNfix] C:\Acer\Empowering Technology\eDSMSNfix.exe<br>O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files\Acer Registration\ACE1.exe" /startup<br>O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer Assist\launcher.exe<br>O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe<br>O4 - HKLM\..\Run: [SetPanel] C:\Acer\APanel\APanel.cmd<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"<br>O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE<br>O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE<br>O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe<br>O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe<br>O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe<br>O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"<br>O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe<br>O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br>O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br>O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br>O4 - HKCU\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup<br>O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br>O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br>O4 - Global Startup: Empowering Technology Launcher.lnk = ?<br>O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe<br>O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe<br>O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O13 - Gopher Prefix: <br>O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - &raquo;<A HREF="http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab" >www.kaspersky.com/kos/eng/partne&middot;&middot;&middot;code.cab</A><br>O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - &raquo;<A HREF="http://ax.emsisoft.com/asquared.cab" >ax.emsisoft.com/asquared.cab</A><br>O20 - AppInit_DLLs: eNetHook.dll<br>O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe<br>O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe<br>O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe<br>O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe<br>O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe<br>O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe<br>O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br>O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe<br>O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset  - C:\Program Files\Eset\nod32krn.exe<br>O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe<br>O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe<br>O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe<br>O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe<br>O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe<br>O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe<br>O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe<br><br>--<br>End of file - 11800 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20396404</guid>
<pubDate>Sun, 27 Apr 2008 19:04:23 EDT</pubDate>
</item>

<item>
<title>HJT Log</title>
<link>http://www.dslreports.com/forum/remark,20395943</link>
<description><![CDATA[<A HREF="/useremail/u/899399"><b>Weedpicker</b></A> : On my laptop, my wife is getting pop-ups as a user account. I am getting none.<br><br>Here is the log from my account - I am not sure if I am suppose to post my log as ADMIN, or hers. Please let me know if you need her account.<br><br>Thanks-<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 4:03:21 PM, on 4/27/2008<br>Platform: Windows Vista  (WinNT 6.00.1904)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16643)<br>Boot mode: Normal<br><br>Mod Note: Removed pending: &raquo;<A HREF="/faq/seclean">Security Cleanup FAQ</A> &raquo;<A HREF="/faq/13616">Mandatory Steps Before  Requesting Assistance</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20395943</guid>
<pubDate>Sun, 27 Apr 2008 17:07:32 EDT</pubDate>
</item>

</channel>
</rss>
