<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>[Spyware] HJTLOG Desktop Hijack in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r20447495</link>
<description></description>
<language>en</language>
<pubDate>Fri, 25 Jul 2008 19:12:51 EDT</pubDate>
<lastBuildDate>Fri, 25 Jul 2008 19:12:51 EDT</lastBuildDate>

<item>
<title>Re: [Spyware] HJTLOG Desktop Hijack</title>
<link>http://www.dslreports.com/forum/remark,20447967</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : <br><b><u>First Steps</u></b><br><b>:!: The following instructions are <u>only</u> for this Forum member. Please do not use these instructions on another computer system. You can seriously damage your system by following the instructions below without guided assistance. You assuredly will make a cleanup of your system more difficult.</b><br><br>DISABLE Spyware Doctor:<br>It is a good program, but ... it may hinder the removal of some HijackThis entries. You can re-enable it after you're clean. <br>From within Spyware Doctor, click the "<b>OnGuard</b>" button on the left side. <br><b>Uncheck</b> "Activate OnGuard". <br><br>Please download<b>  <i>ATF Cleaner</i></b> <br><textarea name="code" class="text" cols=50 rows=10>http://www.atribune.org/ccount/click.php?id=1&#012;</textarea><!--end code block-->It does not require any installation.. It is set up to clean Windows TEMP folders, as well as IE, FireFox and Opera, Temporary Internet Files and Cookies.<br>&#8226;      Double-click <b>ATF-Cleaner.exe</b> to run the program. <br><br><b>First Step:</b><br>&#8226;      Under <b>Main</b> choose: <b>Select All</b><br>&#8226;      Click the <b>Empty Selected</b> button. <br><b><u>Next, if you use Firefox (and <i>some</i> Mozilla-based browsers)</u></b> <br>&#8226;      Click Firefox at the top and choose: <b>Select All</b><br>&#8226;      Click the <b>Empty Selected</b> button. <b><u><br>Next, if you use the Opera browser</u></b> <br>&#8226;      Click <b>Opera</b> at the top and choose: <b>Select All</b> <br>&#8226;      Click the <b>Empty Selected</b> button. <b>:!: Click Exit on the Main menu to close the program.</b><br><br><b>Reconfigure Windows XP to show hidden files:</b><br><i>To enable the viewing of Hidden files follow these steps: </i><br>&#8226; Close all programs so that you are at your desktop. <br>&#8226; Double-click on the My Computer icon. <br>&#8226; Select the Tools menu and click Folder Options. <br>&#8226; After the new window appears select the View tab. <br>&#8226; Put a checkmark in the checkbox labeled Display the contents of system folders. <br>&#8226; Under the Hidden files and folders section select the radio button labeled Show hidden files and folders. <br>&#8226; Remove the checkmark from the checkbox labeled Hide file extensions for known file types. <br>&#8226; Remove the checkmark from the checkbox labeled Hide protected operating system files. <br>&#8226; Press the Apply button and then the OK button and exit My Computer. <br>&#8226; Now your computer is configured to show all hidden files. <br><br><b><u>Malware Removal Steps</u></b><br>1. Open <b>HijackThis</b> again, System scan only.  <b>Checkmark</b> these items:<br><br><b>R3 - URLSearchHook: (no name) - - (no file)<br>R3 - URLSearchHook: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre1.dll (file missing)<br>O2 - BHO: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre1.dll (file missing)<br>O3 - Toolbar: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre1.dll (file missing)<br>O4 - HKCU\..\Run: [nyahpuca] C:\WINDOWS\system32\xuhwnklw.exe<br>O4 - HKLM\..\Policies\Explorer\Run: [AIlmq0YdBO] C:\Documents and Settings\All Users\Application Data\pqnynihe\tivyjwzs.exe<br>O20 - AppInit_DLLs: C:\WINDOWS\system32\wmfhotfix.dll</b><br><br>Click "<b>Fix checked</b>" and when the log panel clears exit HijackThis.<br><br>2. Download -- but <i>do not</i> yet run  -- <b>ComboFix&copy; </b> <br><br>Download this file <b><u>-- to your Desktop --</u></b> [/b]from any of these sources:  <br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br>Right-click on the header of the Code box below, where on the right side it says:  "<b>Copy to clipboard</b>":<br><textarea name="code" class="text" cols=50 rows=10>File::KILLALL::&#012; &#012;C:\WINDOWS\system32\xuhwnklw.exe&#012;C:\WINDOWS\system32\wmfhotfix.dll&#012; &#012;Folder::&#012;C:\Documents and Settings\All Users\Application Data\pqnynihe&#012; &#012;</textarea><!--end code block--><br>Open a new Notepad session - (Do <b><i>not</i></b> use a Word Processor or WordPad).  Click "<b>Format</b>" and be certain that Word Wrap is not enabled.  Right-click | <b>Paste</b> the Code box contents from above into Notepad.  Click File, <b><i>Save as...</i></b>, and set the location to your Desktop, and enter (including quotation marks) as the filename: <b>"CFscript.txt"</b> .  <br><br>&#8226; Disconnect from the Internet.<br>&#8226; Disable your Antivirus.  If the Antivirus software you use has any Script Blocking features, be certain to disable these as well.<br><b> Important:  </b> Have no other programs running.  Your Task Bar should be clear of any program entries including your Browser.<br>&#8226; A window will open with a warning.  Accept any Disclaimers to start the fix.<br>Using your mouse, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown in this little picture:<br> <IMG SRC="http://users.pandora.be/bluepatchy/miekiemoes/images/CFScript.gif"> <br><br>When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.<br>&#8226;<b>!</b>&#8226; A caution - Do <b>not</b> run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock.<br><br>3. Please download MalwareBytes Anti-malware (MBAM) from one of the following links:<br><textarea name="code" class="text" cols=50 rows=10>http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html&#012;http://www.besttechie.net/tools/mbam-setup.exe&#012;</textarea><!--end code block--><br>Once downloaded, close all programs and Windows on your computer (including this one.)<br><br>Double-click on the icon on your desktop named Download_mbam-setup.exe. This will start the installation of MBAM onto your computer.<br><br>When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure you leave both the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware checked. Then click on the Finish button.<br><br>MBAM will now automatically start and you will see a message stating that you should update the program before performing a scan. As MBAM will automatically update itself after the install, you can press the OK button to close that box and you will now be at the main program.<br><br>On the <b>Scanner tab</b>, make sure the the <b>Perform quick scan</b> option is selected and then click on the <b>Scan</b> button to start scanning your computer.<br><br>MBAM will now start scanning your computer for malware. This process can take quite a while, so we suggest you go and do something else and periodically check on the status of the scan. <br><br>When the scan is finished a message box will appear that it has completed scanning successfully.  Click <b>OK</b>.  Now click <b>Show Results</b>.  Make sure all entries have a checkmark at their far left.  You should now click on the <b>Remove Selected</b> button to remove all the listed malware. MBAM will now delete all of the files and registry keys and add them to the programs quarantine.<br><br>When MBAM has finished removing the malware, it will open the scan log and display it in Notepad. Review the log as desired, and then close the Notepad window.  Remember where you saved the log file, as we will want to see it later.<br><br>4. Run <b>HijackThis</b> again, and save the log file.<br><br><b><i>Submit to the Forum:</i></b><br>&#8226; The contents of C:\Combofix.txt;<br>&#8226; The <b>MBAM</b> log results;<br>&#8226; The new HijackThis log.<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20447967</guid>
<pubDate>Wed, 07 May 2008 19:44:02 EDT</pubDate>
</item>

<item>
<title>[Spyware] HJTLOG Desktop Hijack</title>
<link>http://www.dslreports.com/forum/remark,20447495</link>
<description><![CDATA[<A HREF="/useremail/u/562508"><b>gStYLez</b></A> : <br>I have installed and ran the following:<br><br>Adware2007<br>Spybot<br>SpySweeper<br>Nethunter<br>Spyware Doctor<br><br>I have also scanned my computer using the following<br>Pcpitstop <br>housecall <br>Eset<br><br>I have also tried the vundofix and smitfraudfix<br><br>Im still getting random popups on the desktop indicating my computer is infected.<br><br>Below is my HJT Log:<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 5:56:55 PM, on 5/7/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16640)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\Ati2evxx.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe<br>C:\WINDOWS\system32\Ati2evxx.exe<br>C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\Bonjour\mDNSResponder.exe<br>C:\WINDOWS\system32\CTsvcCDA.exe<br>C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe<br>C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe<br>C:\WINDOWS\system32\PnkBstrA.exe<br>C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe<br>C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br>C:\Program Files\Microsoft Hardware\Keyboard\type32.exe<br>C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe<br>C:\Program Files\Logitech\MouseWare\system\em_exec.exe<br>C:\Program Files\D-Link\AirPlus G\AirGCFG.exe<br>C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe<br>C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe<br>C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE<br>C:\Program Files\Windows Defender\MSASCui.exe<br>C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Documents and Settings\Germaine\Desktop\QuickSoundSwitch.exe<br>C:\WINDOWS\system32\xuhwnklw.exe<br>C:\Program Files\ATI Technologies\ATI.ACE\cli.exe<br>C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe<br>C:\Program Files\Steam\steam.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\Documents and Settings\Germaine\Desktop\HiJackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br>R3 - URLSearchHook: (no name) -  - (no file)<br>R3 - URLSearchHook: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre1.dll (file missing)<br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre1.dll (file missing)<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll<br>O3 - Toolbar: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre1.dll (file missing)<br>O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br>O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"<br>O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"<br>O4 - HKLM\..\Run: [EPSON Stylus CX3200] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE" /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"<br>O4 - HKLM\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" clear<br>O4 - HKLM\..\Run: [Launch Ai Booster] "C:\Program Files\ASUS\Ai Booster\OverClk.exe"<br>O4 - HKLM\..\Run: [D-Link AirPlus G] "C:\Program Files\D-Link\AirPlus G\AirGCFG.exe"<br>O4 - HKLM\..\Run: [ANIWZCS2Service] "C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe"<br>O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"<br>O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br>O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"<br>O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br>O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" /r<br>O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [ISUSPM Startup] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" -startup<br>O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start<br>O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot<br>O4 - HKLM\..\Run: [ScanSoft OmniPage 16-reminder] "C:\Program Files\ScanSoft\OmniPage16\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\OmniPage 16\Ereg\Ereg.ini"<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br>O4 - HKLM\..\Run: [MediaFace Integration] "C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe"<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [QuickSoundSwitch] "C:\Documents and Settings\Germaine\Desktop\QuickSoundSwitch.exe"<br>O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide<br>O4 - HKCU\..\Run: [nyahpuca] C:\WINDOWS\system32\xuhwnklw.exe<br>O4 - HKLM\..\Policies\Explorer\Run: [AIlmq0YdBO] C:\Documents and Settings\All Users\Application Data\pqnynihe\tivyjwzs.exe<br>O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br>O4 - Global Startup: QuickBooks Update Agent.lnk.disabled<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {0335A685-ED24-4F7B-A08E-3BD15D84E668} - &raquo;<A HREF="http://dl.filekicker.com/send/file/128985-NZIL/PhPSetup.cab" >dl.filekicker.com/send/file/1289&middot;&middot;&middot;etup.cab</A><br>O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - &raquo;<A HREF="http://upload.facebook.com/controls/FacebookPhotoUploader5.cab" >upload.facebook.com/controls/Fac&middot;&middot;&middot;der5.cab</A><br>O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - &raquo;<A HREF="http://pcpitstop.com/pcpitstop/PCPitStop.CAB" >pcpitstop.com/pcpitstop/PCPitStop.CAB</A><br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &raquo;<A HREF="http://go.microsoft.com/fwlink/?linkid=39204" >go.microsoft.com/fwlink/?linkid=39204</A><br>O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - &raquo;<A HREF="http://www.pcpitstop.com/pestscan/pestscan.cab" >www.pcpitstop.com/pestscan/pestscan.cab</A><br>O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - &raquo;<A HREF="http://www.eset.eu/buxus/docs/OnlineScanner.cab" >www.eset.eu/buxus/docs/OnlineScanner.cab</A><br>O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - &raquo;<A HREF="http://upload.facebook.com/controls/FacebookPhotoUploader3.cab" >upload.facebook.com/controls/Fac&middot;&middot;&middot;der3.cab</A><br>O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - &raquo;<A HREF="http://upload.facebook.com/controls/FacebookPhotoUploader.cab" >upload.facebook.com/controls/Fac&middot;&middot;&middot;ader.cab</A><br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1135533611218" >update.microsoft.com/windowsupda&middot;&middot;&middot;33611218</A><br>O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - &raquo;<A HREF="http://www.systemrequirementslab.com/sysreqlab2.cab" >www.systemrequirementslab.com/sysreqlab2.cab</A><br>O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - &raquo;<A HREF="http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab" >www.kodakgallery.com/downloads/B&middot;&middot;&middot;upld.cab</A><br>O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - &raquo;<A HREF="http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab" >www.kodakgallery.com/downloads/B&middot;&middot;&middot;upld.cab</A><br>O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - &raquo;<A HREF="http://www.pcpitstop.com/mhLbl.cab" >www.pcpitstop.com/mhLbl.cab</A><br>O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - &raquo;<A HREF="http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab" >messenger.msn.com/download/MsnMe&middot;&middot;&middot;ader.cab</A><br>O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - &raquo;<A HREF="http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab" >cdn2.zone.msn.com/binFramework/v&middot;&middot;&middot;4246.cab</A><br>O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - &raquo;<A HREF="http://www.systemrequirementslab.com/sysreqlab.cab" >www.systemrequirementslab.com/sysreqlab.cab</A><br>O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Services Client v.3.7) - &raquo;<A HREF="http://gameadvisor.futuremark.com/global/msc37.cab" >gameadvisor.futuremark.com/global/msc37.cab</A><br>O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - &raquo;<A HREF="http://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab" >upload.facebook.com/controls/Fac&middot;&middot;&middot;r4_5.cab</A><br>O16 - DPF: {EF6E7E56-9229-4C73-AAD0-15316405DB95} (Easy Photo Uploader) - &raquo;<A HREF="http://jl33.photosite.com/~site/UploadBox/UploadBox_live.cab" >jl33.photosite.com/~site/UploadB&middot;&middot;&middot;live.cab</A><br>O20 - AppInit_DLLs: C:\WINDOWS\system32\wmfhotfix.dll<br>O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br>O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br>O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe<br>O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe<br>O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe<br>O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe<br>O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br>O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe<br>O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe<br>O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe<br>O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe<br>O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe<br>O23 - Service: QuickBooks Database Manager Service (QBCFMonitorService) -   - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe<br>O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe<br>O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcSandraSrv.exe<br>O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe<br>O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe<br>O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe<br><br>--<br>End of file - 13369 bytes<br><small>--<br>got ma mind on ma money and my money on my bandwidth!</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20447495</guid>
<pubDate>Wed, 07 May 2008 18:09:45 EDT</pubDate>
</item>

</channel>
</rss>
