<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>HJT Log - in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r20462908</link>
<description></description>
<language>en</language>
<pubDate>Thu, 08 Jan 2009 07:27:11 EDT</pubDate>
<lastBuildDate>Thu, 08 Jan 2009 07:27:11 EDT</lastBuildDate>

<item>
<title>Re: HJT Log -</title>
<link>http://www.dslreports.com/forum/remark,20466875</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : I believe you when you state you have problems downloading.  However, not one single one of the error messages you have posted about using anti-malware scanners is malware caused.<br><br>Your logs are clear of malware signs.<br><br>Start a New Topic in the Microsoft Help subForum. In that New Topic, describe in detail any and all error messages that your receive when you try to download something.  That is information that would be critical to the helpers in that subForum.  If you simply state, as you did here, that you cannot download, that is simply not enough information for someone to help you.  In addition, you stated you "frequently get error message."  Write them down.  Look in your Event Logs and write down past messages.  Include any and all detail you can in your New Topic.<br><br>Best wishes,<br>Bill Castner<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20466875</guid>
<pubDate>Sun, 11 May 2008 20:13:27 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log -</title>
<link>http://www.dslreports.com/forum/remark,20464952</link>
<description><![CDATA[<A HREF="/useremail/u/1179429"><b>SD6</b></A> : Hiya,<br><br>Here is log from Eset Online scanner:<br># version=4<br># OnlineScanner.ocx=1.0.0.56<br># OnlineScannerDLLA.dll=1, 0, 0, 51<br># OnlineScannerDLLW.dll=1, 0, 0, 51<br># OnlineScannerUninstaller.exe=1, 0, 0, 49<br># vers_standard_module=3090 (20080509)<br># vers_arch_module=1.064 (20080214)<br># vers_adv_heur_module=1.064 (20070717)<br># EOSSerial=da52b43a8dcc924c89f43ba05cb443a3<br># end=finished<br># remove_checked=true<br># unwanted_checked=true<br># utc_time=2008-05-11 02:47:30<br># local_time=2008-05-11 10:47:30 (-0500, Eastern Daylight Time)<br># country="United States"<br># osver=5.1.2600 NT Service Pack 2<br># scanned=127224<br># found=0<br># scan_time=1725<br><br>Here are results of CA online scanner:<br>Scan Results:  Scan Completed. 50622 files scanned. No viruses found.  <br>  File&#9;Infection&#9;Status&#9;Path <br>   &#9;No Infections <br><br>Here is HJT log (v 2.0.2, I thought that v2 was Vista only, which is why I didn't run it):<br>                                                                     <br>                                    <br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 10:54:26 AM, on 5/11/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\Ati2evxx.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Grisoft\AVG\guard.exe<br>C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Viewpoint\Common\ViewpointService.exe<br>C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe<br>C:\WINDOWS\system32\wscntfy.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\dla\tfswctrl.exe<br>C:\WINDOWS\system32\rundll32.exe<br>C:\Program Files\Common Files\Nokia\Services\ServiceLayer.exe<br>C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe<br>C:\WINDOWS\system32\AWUSGSTA.exe<br>C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe<br>C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe<br>C:\Program Files\Microsoft Office\Office\OSA.EXE<br>C:\Program Files\Nokia\PC Suite for Nokia 3650\connmngmntbox.exe<br>C:\Program Files\Nokia\PC Suite for Nokia 3650\ectaskscheduler.exe<br>C:\Program Files\Intuwave\Shared\mRouterRunTime\mRouterRuntime.exe<br>C:\PROGRA~1\Nokia\PCSUIT~1\Elogerr.exe<br>C:\PROGRA~1\Nokia\PCSUIT~1\BROADC~1.EXE<br>C:\PROGRA~1\Nokia\PCSUIT~1\SCRFS.exe<br>C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://wapp.verizon.net/bookmarks/bmredir.asp?region=all&bw=dsl&cd=yahoo_v.1_ie&bm=yh_home" >wapp.verizon.net/bookmarks/bmred&middot;&middot;&middot;=yh_home</A><br>R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &raquo;<A HREF="http://windowsupdate.microsoft.com/" >windowsupdate.microsoft.com/</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1<br>O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll<br>O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br>O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br>O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe<br>O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br>O4 - HKLM\..\Run: [PivotSoftware] "C:\Program Files\WinPortrait\wpctrl.exe"<br>O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe<br>O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent<br>O4 - HKLM\..\Run: [ServiceLayer] C:\Program Files\Common Files\Nokia\Services\ServiceLayer.exe<br>O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe<br>O4 - HKLM\..\Run: [eFax 4.1] "C:\Program Files\eFax Messenger 4.1\J2GDllCmd.exe" /R<br>O4 - HKLM\..\Run: [AWUSGSTA.EXE] C:\WINDOWS\system32\AWUSGSTA.exe /CONFIGUAR<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"<br>O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG\avgas.exe" /minimized<br>O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S<br>O4 - HKUS\S-1-5-21-1085031214-813497703-839522115-1004\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S (User '?')<br>O4 - Global Startup: BTTray.lnk = ?<br>O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE<br>O4 - Global Startup: PCSuiteForNokia3650 Detect.lnk = ?<br>O4 - Global Startup: PCSuiteForNokia3650 TS.lnk = ?<br>O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\DLink\Bluetooth Software\btsendto_ie_ctx.htm<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll<br>O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe<br>O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm<br>O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll<br>O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - &raquo;<small>https</small>://<A HREF="https://activatemydsl.verizon.net/sdcCommon/download/tgctlcm.cab">activatemydsl.verizon.net/sdcCom&middot;&middot;&middot;tlcm.cab</A><br>O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - &raquo;<A HREF="http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab" >www.kaspersky.com/kos/eng/partne&middot;&middot;&middot;code.cab</A><br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &raquo;<A HREF="http://go.microsoft.com/fwlink/?linkid=39204" >go.microsoft.com/fwlink/?linkid=39204</A><br>O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - &raquo;<A HREF="http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab" >housecall65.trendmicro.com/house&middot;&middot;&middot;Impl.cab</A><br>O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - &raquo;<A HREF="http://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab" >gfx1.mail.live.com/mail/w1/resou&middot;&middot;&middot;Upld.cab</A><br>O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - &raquo;<A HREF="http://www.eset.eu/OnlineScanner.cab" >www.eset.eu/OnlineScanner.cab</A><br>O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - &raquo;<A HREF="http://download.divx.com/webplayer/stage6/windows/DivXBrowserPlugin.cab" >download.divx.com/webplayer/stag&middot;&middot;&middot;ugin.cab</A><br>O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &raquo;<A HREF="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1199230082000" >update.microsoft.com/microsoftup&middot;&middot;&middot;30082000</A><br>O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - &raquo;<A HREF="http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab" >www.ca.com/us/securityadvisor/vi&middot;&middot;&middot;scan.cab</A><br>O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - &raquo;<A HREF="http://zone.msn.com/bingame/chnz/default/mjolauncher.cab" >zone.msn.com/bingame/chnz/defaul&middot;&middot;&middot;cher.cab</A><br>O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - &raquo;<A HREF="http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab" >cdn2.zone.msn.com/binFramework/v&middot;&middot;&middot;6649.cab</A><br>O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe<br>O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG\guard.exe<br>O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe<br>O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br><br>--<br>End of file - 7708 bytes<br><br>Also, when running SpybotSD1.5 again I got the error message "There were problems in the file "c:\ProgramFiles\Spybot-Search_Destroy\Includes\Trojans.sbi"<br><br>Initialization failed when trying to run Kaspersky online AV scanner.  It said "Kaspersky Anti-Virus database is damaged" even though I had just downloaded it.<br><br>When trying housecall.trendmicro, I got the message "An error occurred while trying to transfer data from the Internet..."<br><br>Please help.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20464952</guid>
<pubDate>Sun, 11 May 2008 11:07:50 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log -</title>
<link>http://www.dslreports.com/forum/remark,20463054</link>
<description><![CDATA[<A HREF="/useremail/u/751678"><b>lilhurricane</b></A> : Hiya SD6..<br><br>Please review our steps here for assistance:<br><br>&raquo;<A HREF="/faq/seclean">Security Cleanup FAQ</A> &raquo;<A HREF="/faq/13616">Mandatory Steps Before  Requesting Assistance</A><br><br>In it you will find all our preclean requirements to run, as well as a new version of HiJack This.<br><br>It will explain what we need you to do first, and what logs to attach with your next post.<br><br>Post back when they are completed..we'll be waiting ;)<br><small>--<br><b>~<A HREF="/forum/cleanup">Safe Hex</a>~<A HREF="/forum/disco"> Team Discovery</a></b> <b><A HREF="http://www.tdprojecthope.com/"> ~ Project Hope ~ </b><b><A HREF="http://www.azlyrics.com/lyrics/neilyoung/likeahurricane.html">Like A Hurricane~</a></b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20463054</guid>
<pubDate>Sat, 10 May 2008 20:53:00 EDT</pubDate>
</item>

<item>
<title>HJT Log -</title>
<link>http://www.dslreports.com/forum/remark,20462908</link>
<description><![CDATA[<A HREF="/useremail/u/1179429"><b>SD6</b></A> : I am having a lot of problems.  I frequently cannot download files over the Internet.  The computer works noticeably slower and performs most functions, but I frequently get error messages and something is very wrong.<br><br>I ran several AV programs, including Spybot SD1.5 and Ad-Aware.  I could not run Windows Defender because it could not validate my copy of Windows even though I have a legit (retail?) copy of XP home.  I had to work in normal mode because I could not get all the way through safe mode.  I ran CA online scan and trandmicro online scan.  They showed nothing wrong and I did not save the logs.  I even bought Uniblue Registry Booster 2 - it fixed a lot of bad register entries, but I am still having problems.  I cannot open Windows Security Center - the computer simply does nothing when clicking on the icon in the task bar or in control panel.  Also, when I try to navigate to bleepingcomputer.com with IE, IE always crashes. <br><br>I built this computer myself 3 yrs ago using a Shuttle barebones kit - no problems before now.  If I could find the Windows backup CD, I would simply re-install XP.  I don't use most of the apps on this computer anymore.<br><br>I hope you can see what is wrong in the HJT log.  Please help.  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20462908</guid>
<pubDate>Sat, 10 May 2008 20:12:46 EDT</pubDate>
</item>

</channel>
</rss>
