<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>hjt antivirusxp 2008/2009 in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r20988485</link>
<description></description>
<language>en</language>
<pubDate>Wed, 11 Nov 2009 02:07:20 EDT</pubDate>
<lastBuildDate>Wed, 11 Nov 2009 02:07:20 EDT</lastBuildDate>

<item>
<title>Re: hjt antivirusxp 2008/2009</title>
<link>http://www.dslreports.com/forum/remark,21001059</link>
<description><![CDATA[<A HREF="/useremail/u/500875"><b>PeeWee</b></A> : Just want to say thanks for the help. Looks like you guys are awfully busy in here.<br><small>--<br>My grandkids ARE cuter than yours! ;-)</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21001059</guid>
<pubDate>Sun, 24 Aug 2008 21:12:48 EDT</pubDate>
</item>

<item>
<title>Re: hjt antivirusxp 2008/2009</title>
<link>http://www.dslreports.com/forum/remark,20997677</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : <b>MBAM</b> did a nice job.  You fortunately had a Vundo variant that <b>MBAM</b> detects quite well, as well as a fairly easy variant of XP Antivirus.  I think you are in good shape.<br><br>Open <b>Acrobat</b> if you have the Full Version installed  Click <b>Help</b> and run the <b>Upgrade</b> applet found there.  If no update is offered:  Use the Preferences, Internet submenu of Acrobat and uncheck to integrate with your Browser.  Close Acrobat.<br>Whether you had the Full Version of Acrobat or not, download and install <b>Adobe Reader 9</b> and use this as the integrated PDF Reader insider your browser:  &raquo;<A HREF="http://www.adobe.com/products/acrobat/readstep2.html" >www.adobe.com/products/acrobat/r&middot;&middot;&middot;ep2.html</A><br><br>Update your Version of Java.  The current version is 1.6.07:   go to &raquo;<A HREF="http://www.java.com/en/download/manual.jsp" >www.java.com/en/download/manual.jsp</A> and download and install the newest Java JRE release.<br><br><b><u>Clean-up & Prevention:</u></b><br><br>&#8226;  Right click "My Computer", Properties, and then click the System Restore tab.  <b>Checkmark</b> the box at the top to stop System Restore on all drives.  Click the "<b>Apply</b>" button.  Agree to the deletion of old Restore Points.  Then <b><u>uncheck</u></b> the box at the top and again click the "<b>Apply</b>" button.  Finally, click the "<b>OK</b>" button.  This will create a new Restore Point reflecting your clean system state.<br><br>&#8226; Please download <b>OTMoveIt2</b> by OldTimer to your Desktop (only):<br><br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe&#012;</textarea><!--end code block--><br>&#8226; Please double-click OTMoveIt.exe to run it.<br>&#8226; Click on the green <b>CleanUp!</b> button. When you do this a text file named cleanup.txt will be downloaded from the internet. If you get a warning from your firewall or other security programs regarding OTMoveIt attempting to contact the internet you should allow it to do so. <br>&#8226; After the list has been download you'll be asked if you want to Begin cleanup process? Select "Yes".<br>&#8226; This step removes the files, folders, and shortcuts created by the tools I had you download and run.<br><br>&#8226; Run <b>ATF Cleaner</b>  <IMG SRC="http://www.geekstogo.com/misc/guide_icons/ATF.gif"> , and checkmark "Empty Recycle Bin", click "Empty Selected" and exit the program.  You can delete or keep this utility as you wish.<br><br>&#8226; Use Control Panel, Add or Remove Programs, and Uninstall any entry related to the ESET On-Line scanner.   Uninstall <b>MBAM</b>.  If you find any other files or folders created during this cleanup operation remaining, please feel free to delete them.<br><br>&#8226; Configure your Antivirus software to check for updates daily, at a time in which you are sure the computer will be on.<br><br>&#8226;  <b>Download and Install Windows Defender by Microsoft (free):</b><br><textarea name="code" class="text" cols=50 rows=10>http://www.microsoft.com/downloads/details.aspx?FamilyId=435BFCE7-DA2B-4A6A-AFA4-F7F14E605A0D&#012;</textarea><!--end code block--><br>&#8226;  <b>Suggestion:  Download and install Comodo BOClean (free):</b><br><textarea name="code" class="text" cols=50 rows=10>http://www.comodo.com/boclean/CBO_download.html&#012;</textarea><!--end code block--><br>&#8226;  <b>Suggestion:  Download, install, and keep updated Spyware Blaster (free):</b><br><textarea name="code" class="text" cols=50 rows=10>http://www.javacoolsoftware.com/spywareblaster.html&#012;</textarea><!--end code block--><br>&#8226; Refer to my first set of instructions above, and reconfigure <b>Hidden Files and Folders</b> to your choosing.<br><br>Best wishes.<br>Bill Castner<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20997677</guid>
<pubDate>Sat, 23 Aug 2008 23:52:56 EDT</pubDate>
</item>

<item>
<title>Re: hjt antivirusxp 2008/2009</title>
<link>http://www.dslreports.com/forum/remark,20996853</link>
<description><![CDATA[<A HREF="/useremail/u/500875"><b>PeeWee</b></A> : Would you believe I reinstalled the program and through it I can still access the log files. There are three, as it instructed to do additional scans.<br><br>1.<br>Malwarebytes' Anti-Malware 1.25<br>Database version: 1062<br>Windows 5.1.2600 Service Pack 3<br><br>9:04:03 AM 8/21/2008<br>mbam-log-08-21-2008 (09-04-03).txt<br><br>Scan type: Quick Scan<br>Objects scanned: 50382<br>Time elapsed: 11 minute(s), 49 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 2<br>Registry Keys Infected: 17<br>Registry Values Infected: 5<br>Registry Data Items Infected: 4<br>Folders Infected: 15<br>Files Infected: 33<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>C:\WINDOWS\system32\fccaWOIa.dll (Trojan.Vundo.H) -> Delete on reboot.<br>C:\WINDOWS\system32\lreehxjl.dll (Trojan.Vundo.H) -> Delete on reboot.<br><br>Registry Keys Infected:<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0dd4a649-c5da-4612-97f8-f44149c23616} (Trojan.Vundo.H) -> Delete on reboot.<br>HKEY_CLASSES_ROOT\CLSID\{0dd4a649-c5da-4612-97f8-f44149c23616} (Trojan.Vundo.H) -> Delete on reboot.<br>HKEY_CURRENT_USER\SOFTWARE\Secure Solutions (Rogue.Multiple) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\rhc3n8j0erdl (Rogue.Multiple) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\rhc3n8j0erdl (Rogue.Multiple) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tdssserv (Rootkit.Agent) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VSPlugin (Trojan.FakeAlert) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully.<br><br>Registry Values Infected:<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\a8dd8fcd (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\Control Panel\Desktop\wallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\Control Panel\Desktop\originalwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\Control Panel\Desktop\convertedwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe (Hijack.Wallpaper) -> Quarantined and deleted successfully.<br><br>Registry Data Items Infected:<br>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\fccawoia -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\fccawoia  -> Delete on reboot.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispBackgroundPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispScrSavPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.<br><br>Folders Infected:<br>C:\Program Files\rhc3n8j0erdl (Rogue.Multiple) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\Rex\Application Data\rhc3n8j0erdl (Rogue.Multiple) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\Rex\Application Data\rhc3n8j0erdl\Quarantine (Rogue.Multiple) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\Rex\Application Data\rhc3n8j0erdl\Quarantine\Autorun (Rogue.Multiple) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\Rex\Application Data\rhc3n8j0erdl\Quarantine\Autorun\HKCU (Rogue.Multiple) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\Rex\Application Data\rhc3n8j0erdl\Quarantine\Autorun\HKCU\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\Rex\Application Data\rhc3n8j0erdl\Quarantine\Autorun\HKLM (Rogue.Multiple) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\Rex\Application Data\rhc3n8j0erdl\Quarantine\Autorun\HKLM\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\Rex\Application Data\rhc3n8j0erdl\Quarantine\Autorun\StartMenuAllUsers (Rogue.Multiple) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\Rex\Application Data\rhc3n8j0erdl\Quarantine\Autorun\StartMenuCurrentUser (Rogue.Multiple) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\Rex\Application Data\rhc3n8j0erdl\Quarantine\BrowserObjects (Rogue.Multiple) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\Rex\Application Data\rhc3n8j0erdl\Quarantine\Packages (Rogue.Multiple) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008 (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\All Users\Application Data\Secure Solutions (Rogue.Multiple) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP (Rogue.Multiple) -> Quarantined and deleted successfully.<br><br>Files Infected:<br>C:\WINDOWS\system32\fccaWOIa.dll (Trojan.Vundo.H) -> Delete on reboot.<br>C:\WINDOWS\system32\aIOWaccf.ini (Trojan.Vundo.H) -> Delete on reboot.<br>C:\WINDOWS\system32\aIOWaccf.ini2 (Trojan.Vundo.H) -> Delete on reboot.<br>C:\WINDOWS\system32\lreehxjl.dll (Trojan.Vundo.H) -> Delete on reboot.<br>C:\WINDOWS\system32\ljxheerl.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\vtisqtgj.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\jgtqsitv.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\dkpyujcr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\odoptgns.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\mxvioepd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\Rex\Local Settings\Temp\lwpwer.exe (Rogue.Agent) -> Quarantined and deleted successfully.<br>C:\Program Files\rhc3n8j0erdl\database.dat (Rogue.Multiple) -> Quarantined and deleted successfully.<br>C:\Program Files\rhc3n8j0erdl\license.txt (Rogue.Multiple) -> Quarantined and deleted successfully.<br>C:\Program Files\rhc3n8j0erdl\MFC71.dll (Rogue.Multiple) -> Quarantined and deleted successfully.<br>C:\Program Files\rhc3n8j0erdl\MFC71ENU.DLL (Rogue.Multiple) -> Quarantined and deleted successfully.<br>C:\Program Files\rhc3n8j0erdl\msvcp71.dll (Rogue.Multiple) -> Quarantined and deleted successfully.<br>C:\Program Files\rhc3n8j0erdl\msvcr71.dll (Rogue.Multiple) -> Quarantined and deleted successfully.<br>C:\Program Files\rhc3n8j0erdl\rhc3n8j0erdl.exe (Rogue.Multiple) -> Quarantined and deleted successfully.<br>C:\Program Files\rhc3n8j0erdl\rhc3n8j0erdl.exe.local (Rogue.Multiple) -> Quarantined and deleted successfully.<br>C:\Program Files\rhc3n8j0erdl\Uninstall.exe (Rogue.Multiple) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\as2008xp.exe (Rogue.Multiple) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\Rex\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus XP 2008.lnk (Rogue.Antivirus2008) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\lphc7n8j0erdl.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\phc7n8j0erdl.bmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\pphc7n8j0erdl.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008.lnk (Rogue.AntivirusXP) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\All Users\Desktop\Antivirus XP 2008.lnk (Rogue.Antivirus) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\Rex\Local Settings\Temp\.tt1.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.<br><br>2.<br>Malwarebytes' Anti-Malware 1.25<br>Database version: 1062<br>Windows 5.1.2600 Service Pack 3<br><br>9:10:56 AM 8/21/2008<br>mbam-log-08-21-2008 (09-10-56).txt<br><br>Scan type: Quick Scan<br>Objects scanned: 14441<br>Time elapsed: 30 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 0<br>Registry Keys Infected: 0<br>Registry Values Infected: 0<br>Registry Data Items Infected: 0<br>Folders Infected: 0<br>Files Infected: 0<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>(No malicious items detected)<br><br>Registry Keys Infected:<br>(No malicious items detected)<br><br>Registry Values Infected:<br>(No malicious items detected)<br><br>Registry Data Items Infected:<br>(No malicious items detected)<br><br>Folders Infected:<br>(No malicious items detected)<br><br>Files Infected:<br>(No malicious items detected)<br><br>3.<br>Malwarebytes' Anti-Malware 1.25<br>Database version: 1062<br>Windows 5.1.2600 Service Pack 3<br><br>9:23:28 AM 8/21/2008<br>mbam-log-08-21-2008 (09-23-28).txt<br><br>Scan type: Quick Scan<br>Objects scanned: 50103<br>Time elapsed: 4 minute(s), 4 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 0<br>Registry Keys Infected: 0<br>Registry Values Infected: 0<br>Registry Data Items Infected: 0<br>Folders Infected: 0<br>Files Infected: 0<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>(No malicious items detected)<br><br>Registry Keys Infected:<br>(No malicious items detected)<br><br>Registry Values Infected:<br>(No malicious items detected)<br><br>Registry Data Items Infected:<br>(No malicious items detected)<br><br>Folders Infected:<br>(No malicious items detected)<br><br>Files Infected:<br>(No malicious items detected)<br><small>--<br>My grandkids ARE cuter than yours! ;-)</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20996853</guid>
<pubDate>Sat, 23 Aug 2008 20:03:46 EDT</pubDate>
</item>

<item>
<title>Re: hjt antivirusxp 2008/2009</title>
<link>http://www.dslreports.com/forum/remark,20996774</link>
<description><![CDATA[<A HREF="/useremail/u/500875"><b>PeeWee</b></A> : Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 4:23:50 PM, on 8/23/2008<br>Platform: Windows XP SP3 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16674)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\Comodo\Firewall\cmdagent.exe<br>C:\Program Files\Portrait Displays\HP My Display\DTSRVC.exe<br>C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br>C:\Program Files\NVIDIA Corporation\ForceWare\Multimedia\NVPVR\nvpvrmon.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\system32\HPZipm12.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Analog Devices\Core\smax4pnp.exe<br>C:\WINDOWS\system32\taskswitch.exe<br>C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br>C:\Program Files\Google\Gmail Notifier\gnotify.exe<br>C:\WINDOWS\system32\MsPMSPSv.exe<br>C:\WINDOWS\system32\RUNDLL32.EXE<br>C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br>C:\WINDOWS\Logi_MwX.Exe<br>C:\Program Files\Comodo\Firewall\cfp.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe<br>C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>C:\PROGRA~1\INCRED~1\bin\IMApp.exe<br>C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe<br>C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe<br>C:\WINDOWS\system32\msiexec.exe<br>C:\Program Files\Internet Explorer\IEXPLORE.EXE<br>C:\WINDOWS\system32\NOTEPAD.EXE<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html" >us.rd.yahoo.com/customize/ie/def&middot;&middot;&middot;rch.html</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com" >us.rd.yahoo.com/customize/ie/def&middot;&middot;&middot;ahoo.com</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.comcast.net/comcast.html" >www.comcast.net/comcast.html</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html" >us.rd.yahoo.com/customize/ie/def&middot;&middot;&middot;rch.html</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.yahoo.com/" >www.yahoo.com/</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = &raquo;<A HREF="http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com" >us.rd.yahoo.com/customize/ie/def&middot;&middot;&middot;ahoo.com</A><br>O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br>O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll<br>O2 - BHO: (no name) - {36D84C7E-CC68-4EB4-84DD-1C39F19F8937} - (no file)<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br>O3 - Toolbar: PayPal Plug-In - {DC0F2F93-27FA-4f84-ACAA-9416F90B9511} - C:\Program Files\PayPal\PayPal Plug-In\OToolbar.dll<br>O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe<br>O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe<br>O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br>O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br>O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe<br>O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\cfp.exe" -h<br>O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c<br>O4 - Global Startup: Microtek Scanner Finder.lnk = C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra button: Sandboxie Toolbar - {11E506DC-0976-4CDA-BB30-37E60A2F2F46} - C:\WINDOWS\System32\shdocvw.dll (HKCU)<br>O9 - Extra 'Tools' menuitem: Sandboxie - {11E506DC-0976-4CDA-BB30-37E60A2F2F46} - C:\WINDOWS\System32\shdocvw.dll (HKCU)<br>O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)<br>O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - &raquo;<A HREF="http://www.eset.eu/OnlineScanner.cab" >www.eset.eu/OnlineScanner.cab</A><br>O20 - AppInit_DLLs:  C:\WINDOWS\system32\guard32.dll<br>O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\Comodo\Firewall\cmdagent.exe<br>O23 - Service: Creative Service for CDROM Access - Unknown owner - C:\WINDOWS\system32\CTsvcCDA.exe (file missing)<br>O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Portrait Displays\HP My Display\DTSRVC.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: NVIDIA PVR Schedule Monitor (nvpvrmon) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\ForceWare\Multimedia\NVPVR\nvpvrmon.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br>O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\NVIDIA~1\FORCEW~1\NVRemote\x10nets.exe (file missing)<br><br>--<br>End of file - 8228 bytes<br><br>ESET<br># version=4<br># OnlineScanner.ocx=1.0.0.56<br># OnlineScannerDLLA.dll=1, 0, 0, 51<br># OnlineScannerDLLW.dll=1, 0, 0, 51<br># OnlineScannerUninstaller.exe=1, 0, 0, 49<br># vers_standard_module=3377 (20080821)<br># vers_arch_module=1.064 (20080214)<br># vers_adv_heur_module=1.066 (20070917)<br># EOSSerial=d3557c3039661748aa9d1dee6d12d302<br># end=finished<br># remove_checked=true<br># unwanted_checked=true<br># utc_time=2008-08-22 12:35:15<br># local_time=2008-08-21 05:35:15 (-0800, Pacific Daylight Time)<br># country="United States"<br># osver=5.1.2600 NT Service Pack 3<br># scanned=419650<br># found=3<br># scan_time=3521<br>C:\Documents and Settings\Rex\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\OP.jar-7d66d184-450c3742.zip&#9;Java/TrojanDownloader.OpenStream.NAB trojan (deleted)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\Rex\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\OP.jar-7d66d184-450c3742.zip &raquo;ZIP &raquo;OP.class&#9;Java/TrojanDownloader.OpenStream.NAB trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\Rex\My Documents\My Music\New Folder (2)\Top of Charts - 2004 (group).wma&#9;WMA/TrojanDownloader.Wimad.L trojan (unable to clean - deleted)&#9;00000000000000000000000000000000<br><br>I removed MBAM. Would you like me to reinstal, run, and retrieve another log file? Or would the log file still be here in some location unknown to me?<br><small>--<br>My grandkids ARE cuter than yours! ;-)</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20996774</guid>
<pubDate>Sat, 23 Aug 2008 19:44:19 EDT</pubDate>
</item>

<item>
<title>Re: hjt antivirusxp 2008/2009</title>
<link>http://www.dslreports.com/forum/remark,20996646</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : <br>1. Open <b>HijackThis</b> again, System scan only.  <b>Checkmark</b> these items:<br><br><b>O2 - BHO: (no name) - rsion - (no file)<br>O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)<br>O2 - BHO: (no name) - {36D84C7E-CC68-4EB4-84DD-1C39F19F8937} - (no file)<br>O2 - BHO: (no name) - {8D64B4F4-EDFD-42D7-9A58-1AFF3A9EF147} - (no file)<br>O2 - BHO: (no name) - {EAD3A971-6A23-4246-8691-C9244E858967} - (no file)<br>O3 - Toolbar: Sandboxie - {E947A403-B614-4FA8-B9E7-E790F0BDC87E} - (no file)</b><br><br>Click "<b>Fix checked</b>" and when the log panel clears exit HijackThis.<br><br>2. Run <b>HijackThis</b> again, and save the log file.<br><br><b><i>Submit to the Forum:</i></b><br>&#8226; Your <b>MBAM</b> log results from its use;<br>&#8226;  The ESET online scanner results, found here:  C:\Program Files\EsetOnlineScanner\log.txt.  <br>&#8226; The new HijackThis log.<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20996646</guid>
<pubDate>Sat, 23 Aug 2008 19:12:35 EDT</pubDate>
</item>

<item>
<title>hjt antivirusxp 2008/2009</title>
<link>http://www.dslreports.com/forum/remark,20988485</link>
<description><![CDATA[<A HREF="/useremail/u/500875"><b>PeeWee</b></A> : My brothers computer, so I don't know how he got it. Followed every step after starting with MBAM. Would like someone to check just to be sure it's clean before I give the computer back. During the check it seemed like every method found something, which has me concerned. <br><br>Since posting I have removed all the extra toolbars he added to IE.<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 9:28:17 PM, on 8/21/2008<br>Platform: Windows XP SP3 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16674)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\csrss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\Analog Devices\Core\smax4pnp.exe<br>C:\WINDOWS\system32\taskswitch.exe<br>C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br>C:\Program Files\Google\Gmail Notifier\gnotify.exe<br>C:\WINDOWS\system32\RUNDLL32.EXE<br>C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe<br>C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br>C:\Program Files\Windows Defender\MSASCui.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Eraser\eraser.exe<br>C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>C:\Program Files\SmartDisk\FlashPath\sdstat.exe<br>C:\Program Files\Portrait Displays\HP My Display\DTSRVC.exe<br>C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe<br>C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br>C:\PROGRA~1\INCRED~1\bin\IMApp.exe<br>C:\Program Files\NVIDIA Corporation\ForceWare\Multimedia\NVPVR\nvpvrmon.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\system32\HPZipm12.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\MsPMSPSv.exe<br>C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>C:\WINDOWS\System32\alg.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br>C:\WINDOWS\System32\wbem\wmiprvse.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com" >us.rd.yahoo.com/customize/ie/def&middot;&middot;&middot;ahoo.com</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.comcast.net/comcast.html" >www.comcast.net/comcast.html</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html" >us.rd.yahoo.com/customize/ie/def&middot;&middot;&middot;rch.html</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.yahoo.com/" >www.yahoo.com/</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &raquo;<A HREF="http://www.comcast.net/toolbar2.0/search/" >www.comcast.net/toolbar2.0/search/</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = &raquo;<A HREF="http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com" >us.rd.yahoo.com/customize/ie/def&middot;&middot;&middot;ahoo.com</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast<br>O2 - BHO: (no name) - rsion - (no file)<br>O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)<br>O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll<br>O2 - BHO: (no name) - {36D84C7E-CC68-4EB4-84DD-1C39F19F8937} - (no file)<br>O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O2 - BHO: (no name) - {8D64B4F4-EDFD-42D7-9A58-1AFF3A9EF147} - (no file)<br>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll<br>O2 - BHO: (no name) - {EAD3A971-6A23-4246-8691-C9244E858967} - (no file)<br>O3 - Toolbar: Sandboxie - {E947A403-B614-4FA8-B9E7-E790F0BDC87E} - (no file)<br>O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL<br>O3 - Toolbar: PayPal Plug-In - {DC0F2F93-27FA-4f84-ACAA-9416F90B9511} - C:\Program Files\PayPal\PayPal Plug-In\OToolbar.dll<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll<br>O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe<br>O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe<br>O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br>O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe<br>O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br>O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c<br>O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide<br>O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>O4 - Global Startup: FlashPath Monitor.lnk = C:\Program Files\SmartDisk\FlashPath\sdstat.exe<br>O4 - Global Startup: Microtek Scanner Finder.lnk = C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra button: Sandboxie Toolbar - {11E506DC-0976-4CDA-BB30-37E60A2F2F46} - C:\WINDOWS\System32\shdocvw.dll (HKCU)<br>O9 - Extra 'Tools' menuitem: Sandboxie - {11E506DC-0976-4CDA-BB30-37E60A2F2F46} - C:\WINDOWS\System32\shdocvw.dll (HKCU)<br>O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)<br>O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - &raquo;<A HREF="http://www.eset.eu/OnlineScanner.cab" >www.eset.eu/OnlineScanner.cab</A><br>O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>O23 - Service: Creative Service for CDROM Access - Unknown owner - C:\WINDOWS\system32\CTsvcCDA.exe (file missing)<br>O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Portrait Displays\HP My Display\DTSRVC.exe<br>O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: NVIDIA PVR Schedule Monitor (nvpvrmon) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\ForceWare\Multimedia\NVPVR\nvpvrmon.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br>O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\NVIDIA~1\FORCEW~1\NVRemote\x10nets.exe (file missing)<br><br>--<br>End of file - 9293 bytes<br><small>--<br>My grandkids ARE cuter than yours! ;-)</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20988485</guid>
<pubDate>Fri, 22 Aug 2008 00:44:58 EDT</pubDate>
</item>

</channel>
</rss>
