<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>HJT Log - browser hijack can&#x27;t be found in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r22484643</link>
<description></description>
<language>en</language>
<pubDate>Sun, 29 Nov 2009 03:50:19 EDT</pubDate>
<lastBuildDate>Sun, 29 Nov 2009 03:50:19 EDT</lastBuildDate>

<item>
<title>Re: HJT Log - browser hijack can&#x27;t be found</title>
<link>http://www.dslreports.com/forum/remark,22503961</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> :  <blockquote><small>quote:</small><hr>I have run OTcleaniT to clean up left over files<hr></blockquote><br><br>That was premature, You should not have done that yet as we are not quite finished. If there had been a problem after running ComboFix, you could have deleted some of the backups that would have been needed.<br><br> <blockquote><small>quote:</small><hr>I have disabled and renabled system restore to create a new point. Then turned it off again due to using Acronis for my restore medium.<hr></blockquote><br>Even though you use Acronis True Image, I would still recommend leaving System Restore turned on. If you are concerned about the space it may take, you can right-click on My Computer, go to the System Restore tab, and lower the maximum amount of drive space that the backups can occupy.<br>If you backup with Acronis manually, you can also remove all but the most recent Restore Point to save room on the backup by running Disk Cleanup (cleanmgr) from Start > Run, selecting the More Options tab, clicking "Clean up" at the bottom in the System Restore section, and clicking OK. Before you do that, I would manually create a new Restore Point.<br><br>But you should not remove or reset your Restore Points while you are still cleaning the system, because if a problem does occur and you need it, even an infected Restore Point can end up being better than no Restore Point at all.<br><br> <blockquote><small>quote:</small><hr>Tgbsstarter.exe is used by The Green Bow VPN software and I checked it and it was fine.<hr></blockquote><br>That's what I thought it was. But I still need the results from the VirusTotal scan if you don't mind, as that information will help other Helpers identify the item in future logs.<br><br>Using Windows Explorer, delete the following file if still there:<br>c:\temp\<b>bqvnzebg.exe</b><br><br>You can also delete the rest of the folder contents, but the one above has to go. If unable to delete it, please let me know.<br><br>Go to start > run and copy and paste next command in the field:<br><b>ComboFix /u</b><br><br>Make sure there's a space between Combofix and /<br>Then hit enter.<br><br>This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.<br>If OTCleanIt removed Combofix.exe, you will need to download the file again to properly uninstall it.<br><br>Please post the VirusTotal log from scanning Tgbsstarter.exe if you don't mind.<br><br>How is the system running now?<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22503961</guid>
<pubDate>Fri, 05 Jun 2009 19:17:44 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - browser hijack can&#x27;t be found</title>
<link>http://www.dslreports.com/forum/remark,22500572</link>
<description><![CDATA[<A HREF="/useremail/u/517249"><b>Mellow</b></A> : ComboFix 09-06-01.03 - Shawn 06/03/2009 15:39.1 - NTFSx86<br>Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.2038.1592 [GMT -5:00]<br>Running from: c:\temp\Comfix.exe<br>AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}<br>.<br><br>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>c:\windows\system32\drivers\kungsfkcmbpfqp.sys<br>c:\windows\system32\kungsflltlwbwq.dll<br>c:\windows\system32\kungsfommjdvjk.dat<br>c:\windows\system32\kungsftdabdmoq.dat<br>c:\windows\system32\kungsfttkilglj.dll<br>c:\windows\system32\tmp.reg<br><br>.<br>(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>-------\Service_kungsfdruhbapa<br><br>(((((((((((((((((((((((((   Files Created from 2009-05-03 to 2009-06-03  )))))))))))))))))))))))))))))))<br>.<br><br>2009-06-03 20:31 . 2009-06-03 20:31&#9;--------&#9;d-----w-&#9;c:\program files\ERUNT<br>2009-06-03 20:30 . 2009-06-03 20:30&#9;791393&#9;----a-w-&#9;c:\temp\erunt-setup.exe<br>2009-06-03 20:21 . 2009-06-03 20:21&#9;--------&#9;d-----w-&#9;C:\32788R22FWJFW<br>2009-06-03 18:12 . 2009-06-03 17:07&#9;3129946&#9;----a-r-&#9;c:\temp\Comfix.exe<br>2009-06-03 16:19 . 2009-06-03 16:19&#9;286208&#9;----a-w-&#9;c:\temp\bqvnzebg.exe<br>2009-06-03 15:09 . 2009-06-03 15:09&#9;152576&#9;----a-w-&#9;c:\documents and settings\Shawn\Application Data\Sun\Java\jre1.6.0_13\lzma.dll<br>2009-06-03 15:08 . 2009-06-03 15:08&#9;607640&#9;----a-w-&#9;c:\temp\jxpiinstall-6u13-fcs-bin-b03-windows-i586-09_mar_2009.exe<br>2009-06-03 15:02 . 2009-06-03 15:02&#9;3584&#9;----a-r-&#9;c:\documents and settings\Shawn\Application Data\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe<br>2009-06-03 15:02 . 2009-06-03 15:02&#9;--------&#9;d-----w-&#9;c:\program files\Windows Installer Clean Up<br>2009-06-03 15:01 . 2009-06-03 15:01&#9;359656&#9;----a-w-&#9;c:\temp\msicuu2.exe<br>2009-06-01 21:22 . 2009-06-01 21:21&#9;102664&#9;----a-w-&#9;c:\windows\system32\drivers\tmcomm.sys<br>2009-06-01 21:21 . 2009-06-02 19:26&#9;--------&#9;d-----w-&#9;c:\documents and settings\Shawn\.housecall6.6<br>2009-06-01 16:47 . 2009-06-01 16:03&#9;15688&#9;----a-w-&#9;c:\windows\system32\lsdelete.exe<br>2009-06-01 16:18 . 2009-06-01 16:18&#9;1630048&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll<br>2009-06-01 16:17 . 2009-06-01 15:49&#9;64160&#9;----a-w-&#9;c:\windows\system32\drivers\Lbd.sys<br>2009-06-01 16:03 . 2009-06-01 16:03&#9;314200&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe<br>2009-06-01 16:03 . 2009-06-01 16:03&#9;25440&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll<br>2009-06-01 16:03 . 2009-06-01 16:03&#9;15688&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe<br>2009-06-01 16:03 . 2009-06-01 16:03&#9;169312&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll<br>2009-06-01 16:03 . 2009-06-01 16:03&#9;348496&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll<br>2009-06-01 16:02 . 2009-06-01 16:02&#9;294240&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll<br>2009-06-01 16:02 . 2009-06-01 16:02&#9;83808&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll<br>2009-06-01 15:51 . 2009-06-01 15:51&#9;--------&#9;d-----w-&#9;c:\program files\Trend Micro<br>2009-06-01 15:49 . 2009-06-01 15:49&#9;212848&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll<br>2009-06-01 15:49 . 2009-06-01 15:49&#9;64160&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys<br>2009-06-01 15:49 . 2009-06-01 15:49&#9;40288&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll<br>2009-06-01 15:49 . 2009-06-01 15:49&#9;640360&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll<br>2009-06-01 15:48 . 2009-06-01 15:48&#9;540536&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe<br>2009-06-01 15:47 . 2009-06-01 15:47&#9;559464&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe<br>2009-06-01 15:46 . 2009-06-01 15:46&#9;2352456&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe<br>2009-06-01 15:45 . 2009-06-01 15:45&#9;--------&#9;d-----w-&#9;c:\program files\Windows Defender<br>2009-06-01 15:44 . 2009-06-01 15:44&#9;627536&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe<br>2009-06-01 15:43 . 2009-06-01 15:43&#9;518488&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe<br>2009-06-01 15:43 . 2009-06-01 15:43&#9;1005904&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe<br>2009-06-01 15:41 . 2009-06-01 15:41&#9;--------&#9;dc-h--w-&#9;c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}<br>2009-06-01 15:41 . 2009-03-12 08:17&#9;2902048&#9;-c--a-w-&#9;c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe<br>2009-06-01 15:41 . 2009-06-01 16:18&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft<br>2009-06-01 15:41 . 2009-06-01 15:41&#9;--------&#9;d-----w-&#9;c:\program files\Lavasoft<br>2009-06-01 15:38 . 2009-06-01 15:38&#9;812344&#9;----a-w-&#9;c:\temp\HJTInstall.exe<br>2009-06-01 15:37 . 2009-06-01 15:38&#9;9615808&#9;----a-w-&#9;c:\temp\windows-kb890830-v2.10.exe<br>2009-06-01 15:36 . 2009-06-01 15:36&#9;897920&#9;----a-w-&#9;c:\temp\WGAPluginInstall.exe<br>2009-06-01 15:36 . 2009-06-01 15:39&#9;37452296&#9;----a-w-&#9;c:\temp\Ad-AwareAE.exe<br>2009-05-30 20:50 . 2009-05-30 20:50&#9;--------&#9;d-----w-&#9;c:\documents and settings\Administrator\Application Data\Malwarebytes<br>2009-05-30 20:46 . 2009-05-30 20:46&#9;--------&#9;d-----w-&#9;c:\documents and settings\Shawn\Application Data\Malwarebytes<br>2009-05-30 20:46 . 2009-05-26 18:20&#9;40160&#9;----a-w-&#9;c:\windows\system32\drivers\mbamswissarmy.sys<br>2009-05-30 20:46 . 2009-05-30 20:46&#9;--------&#9;d-----w-&#9;c:\program files\Malwarebytes' Anti-Malware<br>2009-05-30 20:46 . 2009-05-30 20:46&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\Malwarebytes<br>2009-05-30 20:46 . 2009-05-26 18:19&#9;19096&#9;----a-w-&#9;c:\windows\system32\drivers\mbam.sys<br>2009-05-30 20:46 . 2009-05-30 20:46&#9;3371384&#9;----a-w-&#9;c:\temp\mbam-setup.exe<br>2009-05-29 23:22 . 2009-05-29 23:22&#9;--------&#9;d-----w-&#9;c:\documents and settings\Shawn\Local Settings\Application Data\Ahead<br>2009-05-29 23:21 . 2009-05-29 23:23&#9;--------&#9;d-----w-&#9;c:\documents and settings\Shawn\Application Data\Ahead<br>2009-05-29 23:18 . 2009-05-29 23:22&#9;--------&#9;d-----w-&#9;c:\program files\Common Files\Ahead<br>2009-05-29 23:18 . 2009-05-29 23:18&#9;--------&#9;d-----w-&#9;c:\program files\Nero<br>2009-05-29 23:08 . 2006-07-12 14:05&#9;131097968&#9;----a-w-&#9;c:\temp\Nero-7.2.3.2b_eng_no_yt.exe<br>2009-05-29 21:51 . 2009-05-29 21:52&#9;2188108&#9;----a-w-&#9;c:\temp\GrabIt172b4.exe<br>2009-05-14 23:13 . 2009-05-14 23:13&#9;1356385&#9;----a-w-&#9;c:\temp\wrar39b1.exe<br>2009-05-14 22:56 . 2009-05-14 22:56&#9;141&#9;----a-w-&#9;c:\temp\ShemesDotComRegistrySettings.reg<br>2009-05-12 18:16 . 2009-05-12 18:16&#9;--------&#9;d-----w-&#9;c:\documents and settings\Shawn\Local Settings\Application Data\MetaGeek,_LLC<br>2009-05-12 17:01 . 2009-05-12 17:01&#9;45126&#9;----a-r-&#9;c:\documents and settings\Shawn\Application Data\Microsoft\Installer\{5768CE3D-9D7C-4B19-94DC-9944A361FED7}\_6FEFF9B68218417F98F549.exe<br>2009-05-12 17:01 . 2009-05-12 17:01&#9;45126&#9;----a-r-&#9;c:\documents and settings\Shawn\Application Data\Microsoft\Installer\{5768CE3D-9D7C-4B19-94DC-9944A361FED7}\_1191AC8AACB6050FB5E6C7.exe<br>2009-05-12 17:01 . 2009-05-12 17:01&#9;--------&#9;d-----w-&#9;c:\program files\MetaGeek<br>2009-05-11 17:12 . 2009-05-11 19:25&#9;--------&#9;d-----w-&#9;c:\temp\MAS Rate updates<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2009-06-03 15:46 . 2008-05-19 19:29&#9;167376&#9;----a-w-&#9;c:\documents and settings\Shawn\Local Settings\Application Data\GDIPFONTCACHEV1.DAT<br>2009-06-03 15:11 . 2008-05-23 15:57&#9;--------&#9;d-----w-&#9;c:\program files\Java<br>2009-06-03 15:09 . 2009-01-16 14:51&#9;410984&#9;----a-w-&#9;c:\windows\system32\deploytk.dll<br>2009-06-03 15:02 . 2009-01-06 16:11&#9;--------&#9;d-----w-&#9;c:\program files\MSECache<br>2009-06-02 19:15 . 2008-05-19 23:05&#9;--------&#9;d-----w-&#9;c:\program files\ESET<br>2009-06-02 18:27 . 2008-05-21 21:25&#9;--------&#9;d-----w-&#9;c:\program files\Trillian<br>2009-06-01 17:56 . 2008-05-19 19:49&#9;168168&#9;----a-w-&#9;c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT<br>2009-05-30 20:48 . 2008-05-23 22:29&#9;--------&#9;d-----w-&#9;c:\program files\Spybot - Search & Destroy<br>2009-05-30 20:28 . 2008-05-23 22:12&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy<br>2009-05-30 18:05 . 2009-02-10 19:17&#9;--------&#9;d-----w-&#9;c:\documents and settings\Shawn\Application Data\GrabIt<br>2009-05-29 21:53 . 2009-02-10 19:16&#9;--------&#9;d-----w-&#9;c:\program files\GrabIt<br>2009-05-14 23:16 . 2008-05-19 18:51&#9;--------&#9;d-----w-&#9;c:\program files\Microsoft ActiveSync<br>2009-04-24 19:56 . 2008-10-06 16:11&#9;--------&#9;d-----w-&#9;c:\program files\Elecard<br>2009-04-24 19:55 . 2008-10-06 16:04&#9;--------&#9;d-----w-&#9;c:\program files\Common Files\Elecard<br>2009-04-15 21:46 . 2009-04-15 21:46&#9;176014&#9;----a-r-&#9;c:\documents and settings\Shawn\Application Data\Microsoft\Installer\{C1DEDB47-08BA-401A-BCD3-F2AD312A3CA7}\_C44B4A650DB013CEBD4473.exe<br>2009-04-15 21:46 . 2009-04-15 21:46&#9;176014&#9;----a-r-&#9;c:\documents and settings\Shawn\Application Data\Microsoft\Installer\{C1DEDB47-08BA-401A-BCD3-F2AD312A3CA7}\_2B8A38F77CC3911AA9AA88.exe<br>2009-04-15 21:46 . 2009-04-15 21:46&#9;--------&#9;d-----w-&#9;c:\program files\Ad Words Digger<br>2009-04-13 19:34 . 2008-05-14 20:47&#9;--------&#9;d--h--w-&#9;c:\program files\InstallShield Installation Information<br>2009-04-13 19:34 . 2009-04-13 19:34&#9;--------&#9;d-----w-&#9;c:\program files\Xirrus<br>2009-04-08 18:23 . 2009-04-08 17:55&#9;--------&#9;d-----w-&#9;c:\documents and settings\Shawn\Application Data\OfficeUpdate12<br>2009-04-08 18:02 . 2008-05-19 18:51&#9;--------&#9;d-----w-&#9;c:\program files\Microsoft Works<br>2009-04-08 17:41 . 2009-04-08 17:41&#9;--------&#9;d-----w-&#9;c:\program files\MSBuild<br>2009-04-08 17:41 . 2009-04-08 17:41&#9;--------&#9;d-----w-&#9;c:\program files\Reference Assemblies<br>2009-04-08 17:15 . 2009-04-08 17:15&#9;--------&#9;d-----w-&#9;c:\program files\Windows Mobile Feb. 2008 DST Updates<br>2009-03-16 23:42 . 2009-03-16 23:42&#9;524288&#9;----a-w-&#9;c:\windows\opuc.dll<br>2009-03-16 23:42 . 2009-04-08 17:55&#9;264704&#9;------w-&#9;c:\documents and settings\Shawn\Application Data\OfficeUpdate12\oudetect.dll<br>2009-03-06 14:22 . 2004-08-04 10:00&#9;284160&#9;----a-w-&#9;c:\windows\system32\pdh.dll<br>.<br><br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 1289000]<br>"Spark"="c:\program files\Spark\Spark.exe" [2007-11-14 106496]<br>"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]<br>"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-06-01 94208]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-03-31 138008]<br>"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-03-31 162584]<br>"Persistence"="c:\windows\system32\igfxpers.exe" [2007-03-30 138008]<br>"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]<br>"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-16 1392640]<br>"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-03-13 1443072]<br>"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]<br>"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]<br>"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2006-06-30 1106386]<br>"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2006-06-30 1848150]<br>"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2006-06-30 126976]<br>"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]<br>"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-01 518488]<br>"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-03 148888]<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]<br>@="Service"<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]<br>@="Service"<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"%windir%\\Network Diagnostic\\xpnetdiag.exe"=<br>"%windir%\\system32\\sessmgr.exe"=<br>"c:\\Documents and Settings\\shawn\\Desktop\\Config_AP.exe"=<br>"c:\\Program Files\\FlashFXP\\flashfxp.exe"= c:\\Program Files\\FlashFXP\\FlashFXP.exe<br>"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager<br>"c:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"=<br>"c:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"=<br>"c:\\Program Files\\MIRC\\mirc.exe"=<br>"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=<br>"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=<br>"c:\\Program Files\\Trillian\\trillian.exe"=<br>"c:\\WINDOWS\\system32\\ftp.exe"=<br>"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=<br>"c:\\Program Files\\Microsoft Office\\Live Meeting 8\\Console\\PWConsole.exe"=<br>"c:\\Temp\\Coccinella_Messenger-0.96.10Win\\Coccinella Messenger-0.96.10Win\\Coccinella Messenger-0.96.10.exe"=<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]<br>"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009<br>"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service<br><br>R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/1/2009 11:17 AM 64160]<br>R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [3/13/2008 3:52 PM 33800]<br>R1 TgbVPN;TheGreenBow VPN Client;c:\windows\system32\drivers\TgbVPN.sys [4/23/2008 8:12 AM 121856]<br>R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [3/13/2008 3:49 PM 472320]<br>R2 TgbIke Starter;TgbIke Starter;c:\windows\system32\TgbStarter.exe [7/22/2008 9:09 AM 123176]<br>S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 2:06 PM 1005904]<br>S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]<br>S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [4/19/2007 10:09 AM 99200]<br>S3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [10/1/2006 7:37 AM 26624]<br>S3 usbkey;USB Dongle;c:\windows\system32\drivers\Usbkey.sys [10/8/2008 4:34 PM 40352]<br>S3 vpnva;Cisco AnyConnect VPN Virtual Miniport Adapter for Windows;c:\windows\system32\DRIVERS\vpnva.sys --> c:\windows\system32\DRIVERS\vpnva.sys [?]<br>.<br>Contents of the 'Scheduled Tasks' folder<br><br>2009-06-01 c:\windows\Tasks\Ad-Aware Update (Weekly).job<br>- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 15:47]<br><br>2009-05-29 c:\windows\Tasks\AppleSoftwareUpdate.job<br>- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]<br>.<br>- - - - ORPHANS REMOVED - - - -<br><br>SafeBoot-procexp90.Sys<br><br>.<br>------- Supplementary Scan -------<br>.<br>uStart Page = hxxp://packnship.mailmovers.net/<br>uInternet Settings,ProxyOverride = *.local<br>IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br>TCP: {99F835C1-BF8B-4397-A5AB-B1C23CF86A95} = 68.87.73.242,68.87.71.226<br>DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab<br>FF - ProfilePath - c:\documents and settings\Shawn\Application Data\Mozilla\Firefox\Profiles\g4qm4tzb.shawn\<br>FF - prefs.js: browser.startup.homepage - hxxp://www.dslreports.com/forums|&raquo;<A HREF="http://www.surfingoc.com/forum/index.php?act=idx|&raquo;<A HREF="http://www.fredmiranda.com/forum/|&raquo;<A HREF="http://www.woot.com/Default.aspx""" >www.woot.com/Default.aspx""</A> >www.fredmiranda.com/forum/|&raquo;<A HREF="http:&middot;&middot;&middot;lt.aspx"" >:&middot;&middot;&middot;lt.aspx"</A></A> >www.surfingoc.com/forum/index.ph&middot;&middot;&middot;ult.aspx</A><br>FF - component: c:\documents and settings\Shawn\Application Data\Mozilla\Firefox\Profiles\g4qm4tzb.shawn\extensions\piclens@cooliris.com\components\piclensstub.dll<br>.<br><br>**************************************************************************<br><br>catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2009-06-03 15:42<br>Windows 5.1.2600 Service Pack 3 NTFS<br><br>scanning hidden processes ...  <br><br>scanning hidden autostart entries ... <br><br>scanning hidden files ...  <br><br>scan completed successfully<br>hidden files: 0<br><br>**************************************************************************<br>.<br>--------------------- DLLs Loaded Under Running Processes ---------------------<br><br>- - - - - - - > 'lsass.exe'(1120)<br>c:\windows\system32\relog_ap.dll<br>.<br>Completion time: 2009-06-03 15:44<br>ComboFix-quarantined-files.txt  2009-06-03 20:44<br><br>Pre-Run: 31,066,669,056 bytes free<br>Post-Run: 31,066,406,912 bytes free<br><br>WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe<br>[boot loader]<br>timeout=2<br>default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS<br>[operating systems]<br>c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons<br>multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect<br><br>218&#9;--- E O F ---&#9;2009-05-16 19:59<br><br>Malwarebytes' Anti-Malware 1.37<br>Database version: 2222<br>Windows 5.1.2600 Service Pack 3<br><br>6/3/2009 11:29:49 PM<br>mbam-log-2009-06-03 (23-29-49).txt<br><br>Scan type: Quick Scan<br>Objects scanned: 87844<br>Time elapsed: 9 minute(s), 4 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 0<br>Registry Keys Infected: 0<br>Registry Values Infected: 0<br>Registry Data Items Infected: 0<br>Folders Infected: 0<br>Files Infected: 0<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>(No malicious items detected)<br><br>Registry Keys Infected:<br>(No malicious items detected)<br><br>Registry Values Infected:<br>(No malicious items detected)<br><br>Registry Data Items Infected:<br>(No malicious items detected)<br><br>Folders Infected:<br>(No malicious items detected)<br><br>Files Infected:<br>(No malicious items detected)<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 10:09:21 AM, on 6/5/2009<br>Platform: Windows XP SP3 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16827)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\System32\WLTRYSVC.EXE<br>C:\WINDOWS\System32\bcmwltry.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\hkcmd.exe<br>C:\WINDOWS\system32\igfxpers.exe<br>C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe<br>C:\WINDOWS\system32\WLTRAY.exe<br>C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe<br>C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe<br>C:\WINDOWS\system32\igfxsrvc.exe<br>C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe<br>C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe<br>C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe<br>C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe<br>C:\Program Files\Java\jre6\bin\jusched.exe<br>C:\Program Files\Microsoft ActiveSync\Wcescomm.exe<br>C:\Program Files\Java\jre6\bin\jqs.exe<br>C:\Program Files\Spark\Spark.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br>C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe<br>C:\PROGRA~1\MI3AA1~1\rapimgr.exe<br>C:\WINDOWS\system32\TgbStarter.exe<br>C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE<br>C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\Program Files\Mozilla Firefox\firefox.exe<br>C:\Program Files\internet explorer\iexplore.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://packnship.mailmovers.net/" >packnship.mailmovers.net/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &raquo;<A HREF="http://windowsupdate.microsoft.com/" >windowsupdate.microsoft.com/</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br>O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll<br>O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br>O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll<br>O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br>O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br>O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br>O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe<br>O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe<br>O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe<br>O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice<br>O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br>O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe<br>O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe<br>O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"<br>O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"<br>O4 - HKCU\..\Run: [Spark] C:\Program Files\Spark\Spark.exe<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll<br>O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll<br>O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O15 - Trusted IP range: &raquo;<A HREF="http://192.168.0.155" >192.168.0.155</A><br>O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - &raquo;<A HREF="http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab" >housecall65.trendmicro.com/house&middot;&middot;&middot;Impl.cab</A><br>O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - &raquo;<A HREF="http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab" >acs.pandasoftware.com/activescan&middot;&middot;&middot;ubie.cab</A><br>O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - &raquo;<A HREF="http://download.eset.com/special/eos/OnlineScanner.cab" >download.eset.com/special/eos/On&middot;&middot;&middot;nner.cab</A><br>O16 - DPF: {87BE3784-6977-4E84-AA08-55A96B9CEAC5} (Bl_camera Control) - &raquo;<A HREF="http://192.168.0.155/bl_camera.cab" >192.168.0.155/bl_camera.cab</A><br>O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &raquo;<A HREF="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" >fpdownload2.macromedia.com/get/s&middot;&middot;&middot;lash.cab</A><br>O17 - HKLM\System\CCS\Services\Tcpip\..\{99F835C1-BF8B-4397-A5AB-B1C23CF86A95}: NameServer = 68.87.73.242,68.87.71.226<br>O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe<br>O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe<br>O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe<br>O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br>O23 - Service: TgbIke Starter - Sistech - C:\WINDOWS\system32\TgbStarter.exe<br>O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE<br><br>--<br>End of file - 7667 bytes<br><br>I have run OTcleaniT to clean up left over files<br><br>I have disabled and renabled system restore to create a new point.  Then turned it off again due to using Acronis for my restore medium.<br><br>I ran system cleanup and cleared out all my cache's on IE and firefox.<br><br>Tgbsstarter.exe is used by The Green Bow VPN software and I checked it and it was fine.<br><small>--<br><A HREF="http://www.surfingoc.com"><b>SurfingOC.com</b></a> / <A HREF="http://www.gsdphotography.com"><b>GsdPhotography.com</b></a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22500572</guid>
<pubDate>Fri, 05 Jun 2009 10:09:25 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - browser hijack can&#x27;t be found</title>
<link>http://www.dslreports.com/forum/remark,22498403</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : I'm glad you seem to have fixed your problem, but as lilhurricane said, we still need to be sure. :)<br><br>ComboFix should not be run on your own. While that would have been my next step, it's a powerful tool not intended by the author to be used except under the guidance of a trained helper. Improper use of it can leave you with an unbootable system. <br><br>Since you did run ComboFix, please post the log from it, along with the previously requested information.<br><br>Even if there is nothing else to be removed with ComboFix (and there may be), it will still need to be properly uninstalled when we are finished.<br><br> <blockquote><small>quote:</small><hr>I have been working on this issue for the past 3 days learning and figuring out how to fix it. Sure I could have gone back to a backup, but the fun is trying to figure out how to fix it <br><hr></blockquote><br><br>If you want to learn how to remove malware, and help others, there are several forums that offer training, including <A HREF="http://www.spywareinfoforum.com/index.php?showtopic=9270">Spywareinfo Forum</a>, which Calamity Jane recommended to me several years ago, and also <A HREF="http://www.malwareremoval.com/university.php">Malware Removal University</a>.<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22498403</guid>
<pubDate>Thu, 04 Jun 2009 21:23:40 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - browser hijack can&#x27;t be found</title>
<link>http://www.dslreports.com/forum/remark,22495531</link>
<description><![CDATA[<A HREF="/useremail/u/751678"><b>lilhurricane</b></A> : When you perform the guidelines here for pre-clean requirements, and start a help thread - you are embarking on a journey.<br><br>You're one part of the effort to confirm safe passage on the internet, and your "helper" is the other. It's teamwork at it's finest.<br><br>Our expectations - from start to finish are that we leave you safe and clean, and educated on how to prevent re-infection.<br>This is a free service we offer, and our volunteers are unpaid. They do it because they truly enjoy helping people.<br><br>Please follow all of the requests made by your Helper, including submitting to the Forum all log results.<br>This helps others who frequent this forum to learn or who are seeking answers as well, to see what is going on.<br><br>We need to ascertain that everything is truly "ok".<br><br>Note that many of the utilities utilized require a formal uninstall process to return your system to a normal operating state.<br><br>It's work - yes, but it's necessary.<br><br>Therefore, we ask you please see this through till your "helper" deems you "clean". You can do it!<br><small>--<br><b>~<A HREF="/forum/cleanup">Safe Hex</a>~<A HREF="/forum/disco"> Team Discovery</a></b> <b><A HREF="http://www.tdprojecthope.com/"> ~ Project Hope ~ </b><b><A HREF="http://www.azlyrics.com/lyrics/neilyoung/likeahurricane.html">Like A Hurricane~</a></b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22495531</guid>
<pubDate>Thu, 04 Jun 2009 12:12:23 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - browser hijack can&#x27;t be found</title>
<link>http://www.dslreports.com/forum/remark,22495489</link>
<description><![CDATA[<A HREF="/useremail/u/517249"><b>Mellow</b></A> : I was able to fix my issue.  I will post here so anyone searching can have something to go off of to help them.  I had the kungsf* rootkit installed on my system.  <br><br>Here are the systems I had:<br>Disk Management failed to bring up root drive<br>Disk Defragmenter could not start<br>Windows Update Failed<br>Misc browser hijacks for both IE7 and Firefox 3.0.10<br><br>Solution:<br>Ran Gmer to find the rootkit<br>Used combofix to remove rootkit<br>Ran panda's online scan<br>Ran malware bytes in safe mode<br>Ran spybot in safe mode<br>Ran ad-aware in safe mode<br><br>System is back to normal now with windows update working as well as disk defrag and disk management and no more browser redirects, and HJT comes back clean along with all other scans.<br><br>Thanks to Thejoker for helping, I have been working on this issue for the past 3 days learning and figuring out how to fix it. Sure I could have gone back to a backup, but the fun is trying to figure out how to fix it :)<br><small>--<br><A HREF="http://www.surfingoc.com"><b>SurfingOC.com</b></a> / <A HREF="http://www.gsdphotography.com"><b>GsdPhotography.com</b></a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22495489</guid>
<pubDate>Thu, 04 Jun 2009 12:04:11 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - browser hijack can&#x27;t be found</title>
<link>http://www.dslreports.com/forum/remark,22488329</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Hi Mellow<br><br>I suggest printing out each set of instructions and reading the entire post before proceeding. It will make following them easier. Please follow the directions in the order listed.<br><br> <blockquote><small>quote:</small><hr>I downloaded "Up 2009 Pixar Rated PG Decent Cam Copy" and it is full of viruses, as soon as I unrar'd and ran the unzip.exe NOD32 went crazy with all kinds of virus's trying to install.<hr></blockquote><br>Illegal pirated software will get you all the time. If you haven't deleted the archive files you downloaded, you should do so now.<br><br> <blockquote><small>quote:</small><hr>Could not get a log from trendmicro's online scanner but it would pickup .hitbox<hr></blockquote><br>Those would be cookies, and cookies are just text tiles, and not a threat.<br><br>I see you have Acronis TrueImageHome installed. Do you have a current backup? If you do, you may want to consider restoring the latest backup set if you do full backups. It's what I would do if it was my system. It would be both faster and safer than trying to disinfect (if you restored a backup from before you were infected, you would know that none of it was still there).<br><br>Clean your Cache and Cookies in IE:<br>-Close all instances of Outlook Express and Internet Explorer <br>-Go to Control Panel > Internet Options > General tab<br>-Click the "Delete Cookies" button<br>-Next to it, Click the "Delete Files" button<br>-When prompted, place a check in: "Delete all offline content", click OK<br>Clean your Cache and Cookies in Firefox (In case you also have Firefox installed):<br>Go to Tools > Options.<br>Click Privacy in the menu on the left side of the Options window.<br>Click the Clear button located to the right of each option (History, Cookies, Private Data).<br>Click OK to close the Options window<br>Alternatively, you can clear all information stored while browsing by clicking Clear All. <br>A confirmation dialog box will be shown before clearing the information.<br>Clean other Temporary files + Recycle bin<br>-Go to start > run and type: <b>cleanmgr</b> and click ok.<br>-Let it scan your system for files to remove.<br>-Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.<br>-Press OK to remove them.<br><br>Please download Malwarebytes' Anti-Malware from <br><br><textarea name="code" class="text" cols=50 rows=10>http://www.malwarebytes.org/mbam-download.php&#012;</textarea><!--end code block--><br>Double Click mbam-setup.exe to install the application.<br>- Make sure a checkmark is placed next to <b>Update Malwarebytes' Anti-Malware</b> and <b>Launch Malwarebytes' Anti-Malware</b>, then click Finish.<br>- If an update is found, it will download and install the latest version.<br>- Once the program has loaded, select "<b>Perform Quick Scan</b>", then click <b>Scan</b>.<br>- The scan may take some time to finish,so please be patient.<br>- When the scan is complete, click OK, then Show Results to view the results.<br>- Make sure that <b>everything is checked</b>, and click <b>Remove Selected</b>.<br>- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)<br>- The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.<br>- Copy & Paste the entire report in your next reply along with a fresh HijackThis log.<br><br>Note:<br><i>If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.<br>Click OK to either and let MBAM proceed with the disinfection process.<br>If asked to restart the computer, please do so immediately.</i><br><br>Please go to <A HREF="http://www.virustotal.com">VirusTotal</a> and submit the following file for a scan and post the detection results (I don't need the "additional information") in your next reply:<br>C:\WINDOWS\system32\<b>TgbStarter.exe</b><br><br>Please do a scan with <A HREF="http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html">Kaspersky Online Scanner</a><br><br><i>Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.</i><br><br>Click on the <b>Accept</b> button and install any components it needs.<br>- The program will install and then begin downloading the latest definition files.<br>- After the files have been downloaded on the left side of the page in the <b>Scan</b> section select <b>My Computer</b>.<br>- This will start the program and scan your system.<br>- The scan will take a while, so be patient and let it run.<br>- Once the scan is complete, click on <b>View scan report</b><br>- Now, click on the <b>Save Report as</b> button.<br>- In the drop down box labeled <b>Files of type</b> change the type to <b>Text file</b>.<br>- Save the file to your desktop.<br>- Copy and paste that information in your next post.<br><br>Please post a new HijackThis log, the log from MBAM, the results of scanning the file at VirusTotal, the log from Kaspersky's online scan, and note any errors encountered.<br><br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22488329</guid>
<pubDate>Wed, 03 Jun 2009 10:37:57 EDT</pubDate>
</item>

<item>
<title>HJT Log - browser hijack can&#x27;t be found</title>
<link>http://www.dslreports.com/forum/remark,22484643</link>
<description><![CDATA[<A HREF="/useremail/u/517249"><b>Mellow</b></A> : I have tried all the steps and still have something hijacking my browser when i do searches for "Disk Defragmenter could not start".  I can not get defrag to work in safe mode and have checked to make sure my page file is correct and defrag is installed.  I read that defrag can be disabled by malware and think that is the case here.  I can tell you where I got this issue from, I downloaded "Up 2009 Pixar Rated PG Decent Cam Copy" and it is full of viruses, as soon as I unrar'd and ran the unzip.exe NOD32 went crazy with all kinds of virus's trying to install.  I have tried everything mentioned in the FAQ and this pesky redirect still happens.  Per the FAQ here is my HJT log:<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 4:43:26 PM, on 6/2/2009<br>Platform: Windows XP SP3 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16827)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\System32\WLTRYSVC.EXE<br>C:\WINDOWS\System32\bcmwltry.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe<br>C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe<br>C:\Program Files\Java\jre6\bin\jqs.exe<br>C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br>C:\WINDOWS\system32\TgbStarter.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\hkcmd.exe<br>C:\WINDOWS\system32\igfxpers.exe<br>C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe<br>C:\WINDOWS\system32\WLTRAY.exe<br>C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe<br>C:\Program Files\Java\jre6\bin\jusched.exe<br>C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe<br>C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe<br>C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe<br>C:\WINDOWS\system32\igfxsrvc.exe<br>C:\Program Files\Microsoft ActiveSync\Wcescomm.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe<br>C:\PROGRA~1\MI3AA1~1\rapimgr.exe<br>C:\WINDOWS\system32\taskmgr.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\Program Files\Mozilla Firefox\firefox.exe<br>C:\WINDOWS\system32\mmc.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://packnship.mailmovers.net/" >packnship.mailmovers.net/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &raquo;<A HREF="http://windowsupdate.microsoft.com/" >windowsupdate.microsoft.com/</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br>O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll<br>O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br>O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br>O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll<br>O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br>O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br>O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br>O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe<br>O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe<br>O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe<br>O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br>O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe<br>O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe<br>O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"<br>O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe<br>O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br>O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br>O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"<br>O4 - HKCU\..\Run: [Spark] C:\Program Files\Spark\Spark.exe<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll<br>O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll<br>O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O15 - Trusted IP range: &raquo;<A HREF="http://192.168.0.155" >192.168.0.155</A><br>O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - &raquo;<A HREF="http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab" >housecall65.trendmicro.com/house&middot;&middot;&middot;Impl.cab</A><br>O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - &raquo;<A HREF="http://download.eset.com/special/eos/OnlineScanner.cab" >download.eset.com/special/eos/On&middot;&middot;&middot;nner.cab</A><br>O16 - DPF: {87BE3784-6977-4E84-AA08-55A96B9CEAC5} (Bl_camera Control) - &raquo;<A HREF="http://192.168.0.155/bl_camera.cab" >192.168.0.155/bl_camera.cab</A><br>O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &raquo;<A HREF="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" >fpdownload2.macromedia.com/get/s&middot;&middot;&middot;lash.cab</A><br>O17 - HKLM\System\CCS\Services\Tcpip\..\{99F835C1-BF8B-4397-A5AB-B1C23CF86A95}: NameServer = 68.87.73.242,68.87.71.226<br>O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe<br>O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe<br>O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe<br>O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br>O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br>O23 - Service: TgbIke Starter - Sistech - C:\WINDOWS\system32\TgbStarter.exe<br>O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE<br><br>--<br>End of file - 7910 bytes<br><br>Ad-aware Log:<br><br>Logfile created: 6/2/2009 11:40:51<br>Lavasoft Ad-Aware version: 8.0.5<br>Extended engine version: 8.1<br>User performing scan: Administrator<br><br>*********************** Definitions database information ***********************<br>Lavasoft definition file: 148.41<br>Extended engine definition file: 8.1<br><br>******************************** Scan results: *********************************<br>Scan profile name: Smart Scan  (ID: smart)<br>Objects scanned: 26738<br>Objects detected: 2<br><br>Type              Detected<br>==========================<br>Processes.......:        0<br>Registry entries:        0<br>Hostfile entries:        0<br>Files...........:        0<br>Folders.........:        0<br>LSPs............:        0<br>Cookies.........:        2<br>Browser hijacks.:        0<br>MRU objects.....:        0<br><br>Removed items:<br>Description: *hitbox* Family Name: Cookies Clean status: Success Item ID: 408858 Family ID: 0<br>Description: *.hitbox* Family Name: Cookies Clean status: Success Item ID: 409072 Family ID: 0<br><br>Scan and cleaning complete: Finished correctly after 346 seconds<br><br>*********************************** Settings ***********************************<br><br>Scan profile:<br>ID: smart, enabled:1, value: Smart Scan<br>  ID: scancriticalareas, enabled:1, value: true<br>  ID: scanrunningapps, enabled:1, value: true<br>  ID: scanregistry, enabled:1, value: true<br>  ID: scanlsp, enabled:1, value: true<br>  ID: scanads, enabled:1, value: false<br>  ID: scanhostsfile, enabled:1, value: false<br>  ID: scanmru, enabled:1, value: false<br>  ID: scanbrowserhijacks, enabled:1, value: true<br>  ID: scantrackingcookies, enabled:1, value: true<br>    ID: closebrowsers, enabled:1, value: false<br>  ID: folderstoscan, enabled:1, value: <br>  ID: scanrootkits, enabled:1, value: true<br>  ID: usespywareheuristics, enabled:1, value: true<br>  ID: extendedengine, enabled:0, value: true<br>    ID: useheuristics, enabled:0, value: true<br>      ID: heuristicslevel, enabled:0, value: mild, domain: medium,mild,strict<br>  ID: filescanningoptions, enabled:1<br>    ID: archives, enabled:1, value: false<br>    ID: onlyexecutables, enabled:1, value: true<br>    ID: skiplargerthan, enabled:1, value: 20480<br><br>Scan global:<br>ID: global, enabled:1<br>  ID: addtocontextmenu, enabled:1, value: true<br>  ID: playsoundoninfection, enabled:1, value: false<br>    ID: soundfile, enabled:0, value: *to be filled in automatically*\alert.wav<br><br>Scheduled scan settings:<br><br><br>Update settings:<br>ID: updates, enabled:1<br>  ID: launchthreatworksafterscan, enabled:1, value: normal, domain: normal,off,silently<br>  ID: displaystatus, enabled:1, value: false<br>  ID: deffiles, enabled:1, value: downloadandinstall, domain: dontcheck,downloadandinstall<br>  ID: autodetectproxy, enabled:1, value: false<br>  ID: useautoconfigscript, enabled:1, value: false<br>    ID: autoconfigurl, enabled:0, value: <br>  ID: useproxy, enabled:1, value: false<br>    ID: proxyserver, enabled:0, value: <br>  ID: softwareupdates, enabled:1, value: downloadandinstall, domain: dontcheck,downloadandinstall<br>  ID: licenseandinfo, enabled:1, value: downloadandinstall, domain: dontcheck,downloadandinstall<br>  ID: schedules, enabled:1, value: true<br>    ID: updatedaily, enabled:1, value: Daily<br>      ID: time, enabled:1, value: Mon Jun 01 11:18:00 2009<br>      ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systemstart,weekly<br>      ID: weekdays, enabled:1<br>        ID: monday, enabled:1, value: false<br>        ID: tuesday, enabled:1, value: false<br>        ID: wednesday, enabled:1, value: false<br>        ID: thursday, enabled:1, value: false<br>        ID: friday, enabled:1, value: false<br>        ID: saturday, enabled:1, value: false<br>        ID: sunday, enabled:1, value: false<br>      ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31<br>      ID: scanprofile, enabled:1, value: <br>      ID: auto_deal_with_infections, enabled:1, value: false<br>    ID: updateweekly, enabled:1, value: Weekly<br>      ID: time, enabled:1, value: Mon Jun 01 11:18:00 2009<br>      ID: frequency, enabled:1, value: weekly, domain: daily,monthly,once,systemstart,weekly<br>      ID: weekdays, enabled:1<br>        ID: monday, enabled:1, value: true<br>        ID: tuesday, enabled:1, value: false<br>        ID: wednesday, enabled:1, value: false<br>        ID: thursday, enabled:1, value: false<br>        ID: friday, enabled:1, value: false<br>        ID: saturday, enabled:1, value: false<br>        ID: sunday, enabled:1, value: false<br>      ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31<br>      ID: scanprofile, enabled:1, value: <br>      ID: auto_deal_with_infections, enabled:1, value: false<br><br>Appearance settings:<br>ID: appearance, enabled:1<br>  ID: skin, enabled:1, value: default.egl, reglocation: HKEY_LOCAL_MACHINE\SOFTWARE\Lavasoft\Ad-Aware\Resource<br>  ID: showtrayicon, enabled:1, value: true<br>  ID: language, enabled:1, value: en, reglocation: HKEY_LOCAL_MACHINE\SOFTWARE\Lavasoft\Ad-Aware\Language<br><br>Realtime protection settings:<br>ID: realtime, enabled:1<br>  ID: processprotection, enabled:1, value: true<br>  ID: registryprotection, enabled:0, value: true<br>  ID: networkprotection, enabled:0, value: true<br>  ID: loadatstartup, enabled:1, value: true<br>  ID: usespywareheuristics, enabled:0, value: true<br>  ID: extendedengine, enabled:0, value: true<br>    ID: useheuristics, enabled:0, value: true<br>      ID: heuristicslevel, enabled:0, value: strict, domain: medium,mild,strict<br>  ID: infomessages, enabled:1, value: onlyimportant, domain: display,dontnotify,onlyimportant<br><br>****************************** System information ******************************<br>Computer name: SHAWNLAPTOP<br>Processor name: Genuine Intel(R) CPU           T2050  @ 1.60GHz<br>Processor identifier: x86 Family 6 Model 14 Stepping 8<br>Raw info: processorarchitecture 0, processortype 586, processorlevel 6, processor revision 3592, number of processors 2<br>Physical memory available: 1615503360 bytes<br>Physical memory total: 2137382912 bytes<br>Virtual memory available: 2039365632 bytes<br>Virtual memory total: 2147352576 bytes<br>Memory load: 24%<br>Microsoft Windows XP Home Edition Service Pack 3 (build 2600)<br>Windows startup mode:<br><br>Running processes:<br>PID: 324 name: \SystemRoot\System32\smss.exe owner: SYSTEM domain: NT AUTHORITY<br>PID: 388 name: \??\C:\WINDOWS\system32\csrss.exe owner: SYSTEM domain: NT AUTHORITY<br>PID: 412 name: \??\C:\WINDOWS\system32\winlogon.exe owner: SYSTEM domain: NT AUTHORITY<br>PID: 460 name: C:\WINDOWS\system32\services.exe owner: SYSTEM domain: NT AUTHORITY<br>PID: 472 name: C:\WINDOWS\system32\lsass.exe owner: SYSTEM domain: NT AUTHORITY<br>PID: 632 name: C:\WINDOWS\system32\svchost.exe owner: SYSTEM domain: NT AUTHORITY<br>PID: 736 name: C:\WINDOWS\system32\svchost.exe owner: NETWORK SERVICE domain: NT AUTHORITY<br>PID: 788 name: C:\Program Files\Windows Defender\MsMpEng.exe owner: SYSTEM domain: NT AUTHORITY<br>PID: 848 name: C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe owner: SYSTEM domain: NT AUTHORITY<br>PID: 904 name: C:\WINDOWS\system32\svchost.exe owner: SYSTEM domain: NT AUTHORITY<br>PID: 1048 name: C:\WINDOWS\system32\wbem\unsecapp.exe owner: SYSTEM domain: NT AUTHORITY<br>PID: 1196 name: C:\WINDOWS\system32\wbem\wmiprvse.exe owner: SYSTEM domain: NT AUTHORITY<br>PID: 1320 name: C:\WINDOWS\Explorer.EXE owner: Administrator domain: SHAWNLAPTOP<br>PID: 1492 name: C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe owner: Administrator domain: SHAWNLAPTOP<br><br>Startup items:<br>Name: PostBootReminder<br>          imagepath: {7849596a-48ea-486e-8937-a2a3009f31a9}<br>Name: CDBurn<br>          imagepath: {fbeb8a05-beee-4442-804e-409d6c4515e9}<br>Name: WebCheck<br>          imagepath: {E6FB5E20-DE35-11CF-9C87-00AA005127ED}<br>Name: SysTray<br>          imagepath: {35CEC8A3-2BE6-11D2-8773-92E220524153}<br>Name: WPDShServiceObj<br>          imagepath: {AAA288BA-9A4C-45B0-95D7-94D524869DB5}<br>Name: IgfxTray<br>          imagepath: C:\WINDOWS\system32\igfxtray.exe<br>Name: HotKeysCmds<br>          imagepath: C:\WINDOWS\system32\hkcmd.exe<br>Name: Persistence<br>          imagepath: C:\WINDOWS\system32\igfxpers.exe<br>Name: SigmatelSysTrayApp<br>          imagepath: %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe<br>Name: Broadcom Wireless Manager UI<br>          imagepath: C:\WINDOWS\system32\WLTRAY.exe<br>Name: egui<br>          imagepath: "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice<br>Name: SunJavaUpdateSched<br>          imagepath: "C:\Program Files\Java\jre6\bin\jusched.exe"<br>Name: Adobe Reader Speed Launcher<br>          imagepath: "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br>Name: QuickTime Task<br>          imagepath: "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br>Name: TrueImageMonitor.exe<br>          imagepath: C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe<br>Name: AcronisTimounterMonitor<br>          imagepath: C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe<br>Name: Acronis Scheduler2 Service<br>          imagepath: "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"<br>Name: NeroFilterCheck<br>          imagepath: C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe<br>Name: Ad-Watch<br>          imagepath: C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br>Name: Windows Defender<br>          imagepath: "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br>Name: {438755C2-A8BA-11D1-B96B-00A0C90312E1}<br>          imagepath: Browseui preloader<br>Name: {8C7461EF-2B13-11d2-BE35-3078302C2030}<br>          imagepath: Component Categories cache daemon<br>Name: <br>          imagepath: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini<br>Name: <br>          imagepath: C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\desktop.ini<br><br>Bootexecute items:<br>Name: <br>          imagepath: autocheck autochk /p \??\C:<br>Name: <br>          imagepath: autocheck autochk *<br>Name: <br>          imagepath: lsdelete<br><br>Running services:<br>Name: CryptSvc<br>          displayname: Cryptographic Services<br>Name: DcomLaunch<br>          displayname: DCOM Server Process Launcher<br>Name: dmserver<br>          displayname: Logical Disk Manager<br>Name: Eventlog<br>          displayname: Event Log<br>Name: helpsvc<br>          displayname: Help and Support<br>Name: Lavasoft Ad-Aware Service<br>          displayname: Lavasoft Ad-Aware Service<br>Name: PlugPlay<br>          displayname: Plug and Play<br>Name: RpcSs<br>          displayname: Remote Procedure Call (RPC)<br>Name: WinDefend<br>          displayname: Windows Defender<br>Name: winmgmt<br>          displayname: Windows Management Instrumentation<br><br>Mbam Log:<br><br>Malwarebytes' Anti-Malware 1.37<br>Database version: 2209<br>Windows 5.1.2600 Service Pack 3<br><br>6/1/2009 3:40:35 PM<br>mbam-log-2009-06-01 (15-40-35).txt<br><br>Scan type: Quick Scan<br>Objects scanned: 87758<br>Time elapsed: 3 minute(s), 44 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 0<br>Registry Keys Infected: 0<br>Registry Values Infected: 0<br>Registry Data Items Infected: 0<br>Folders Infected: 0<br>Files Infected: 0<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>(No malicious items detected)<br><br>Registry Keys Infected:<br>(No malicious items detected)<br><br>Registry Values Infected:<br>(No malicious items detected)<br><br>Registry Data Items Infected:<br>(No malicious items detected)<br><br>Folders Infected:<br>(No malicious items detected)<br><br>Files Infected:<br>(No malicious items detected)<br><br>Esetonline log:<br>C:\Program Files\Trillian\trillianpro.exe&#9;probably a variant of Win32/Agent trojan&#9;cleaned by deleting - quarantined<br><br>Could not get a log from trendmicro's online scanner but it would pickup .hitbox <br><small>--<br><A HREF="http://www.surfingoc.com"><b>SurfingOC.com</b></a> / <A HREF="http://www.gsdphotography.com"><b>GsdPhotography.com</b></a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22484643</guid>
<pubDate>Tue, 02 Jun 2009 16:53:43 EDT</pubDate>
</item>

</channel>
</rss>
