<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>MSN sending out messages without my consent in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r22521535</link>
<description></description>
<language>en</language>
<pubDate>Thu, 03 Dec 2009 12:24:30 EDT</pubDate>
<lastBuildDate>Thu, 03 Dec 2009 12:24:30 EDT</lastBuildDate>

<item>
<title>Re: MSN sending out messages without my consent</title>
<link>http://www.dslreports.com/forum/remark,22528289</link>
<description><![CDATA[<A HREF="/useremail/u/769887"><b>Milkster</b></A> : Here is the log for ComboFix....<br><br>ComboFix 09-06-09.06 - caskenkp 06/10/2009 11:43.1 - NTFSx86<br>Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.3063.2318 [GMT -4:00]<br>Running from: E:\ComboFix.exe<br>AV: McAfee VirusScan Enterprise *On-access scanning disabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}<br>.<br><br>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>c:\windows\system32\mdm.exe<br><br>.<br>(((((((((((((((((((((((((   Files Created from 2009-05-10 to 2009-06-10  )))))))))))))))))))))))))))))))<br>.<br><br>2009-06-10 12:22 . 2009-06-10 12:22&#9;--------&#9;d-----w-&#9;c:\windows\LastGood<br>2009-06-10 10:32 . 2009-06-10 10:32&#9;152576&#9;----a-w-&#9;c:\documents and settings\Administrator\Application Data\Sun\Java\jre1.6.0_14\lzma.dll<br>2009-06-09 18:18 . 2009-06-09 18:18&#9;--------&#9;d-----w-&#9;c:\program files\ESET<br>2009-06-09 18:02 . 2009-06-09 18:02&#9;--------&#9;d-----w-&#9;c:\documents and settings\Administrator.HYPATIA\Application Data\Malwarebytes<br>2009-06-09 18:01 . 2009-05-26 17:20&#9;40160&#9;----a-w-&#9;c:\windows\system32\drivers\mbamswissarmy.sys<br>2009-06-09 18:01 . 2009-06-09 18:02&#9;--------&#9;d-----w-&#9;c:\program files\Malwarebytes' Anti-Malware<br>2009-06-09 18:01 . 2009-05-26 17:19&#9;19096&#9;----a-w-&#9;c:\windows\system32\drivers\mbam.sys<br>2009-06-09 18:01 . 2009-06-09 18:01&#9;--------&#9;d-sh--w-&#9;c:\documents and settings\Administrator.HYPATIA\IETldCache<br>2009-06-09 13:53 . 2009-06-09 13:53&#9;--------&#9;d-----w-&#9;c:\documents and settings\Administrator\Application Data\Malwarebytes<br>2009-06-09 13:52 . 2009-06-09 13:52&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\Malwarebytes<br>2009-06-09 13:35 . 2009-06-09 13:35&#9;--------&#9;d-----w-&#9;c:\program files\Trend Micro<br>2009-06-09 00:07 . 2008-04-14 09:41&#9;21504&#9;-c--a-w-&#9;c:\windows\system32\dllcache\hidserv.dll<br>2009-06-09 00:07 . 2008-04-14 09:41&#9;21504&#9;----a-w-&#9;c:\windows\system32\hidserv.dll<br>2009-06-08 13:57 . 2009-06-08 13:57&#9;--------&#9;d-----w-&#9;c:\windows\ie8updates<br>2009-06-08 13:54 . 2009-05-12 05:11&#9;102912&#9;-c----w-&#9;c:\windows\system32\dllcache\iecompat.dll<br>2009-06-08 13:44 . 2009-06-08 13:44&#9;--------&#9;d--h--r-&#9;C:\MSOCache<br>2009-06-08 04:34 . 2009-06-08 04:34&#9;--------&#9;d-sh--w-&#9;c:\windows\system32\config\systemprofile\IETldCache<br>2009-06-08 04:32 . 2009-06-08 04:32&#9;--------&#9;d-----w-&#9;c:\program files\MSSOAP<br>2009-06-08 04:31 . 2009-06-08 04:36&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\Webroot<br>2009-06-08 04:31 . 2009-06-08 04:31&#9;--------&#9;d-----w-&#9;c:\program files\Webroot<br>2009-06-08 04:31 . 2009-06-08 04:31&#9;--------&#9;d-----w-&#9;c:\documents and settings\Administrator\Application Data\Webroot<br>2009-06-08 04:31 . 2009-05-13 19:39&#9;1563008&#9;----a-w-&#9;c:\windows\WRSetup.dll<br>2009-06-08 04:31 . 2009-06-08 04:31&#9;164&#9;----a-w-&#9;c:\windows\install.dat<br>2009-06-08 04:28 . 2009-06-08 04:28&#9;164&#9;----a-w-&#9;C:\install.dat<br>2009-06-08 04:13 . 2009-06-08 04:13&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\Hewlett-Packard<br>2009-06-08 04:10 . 2009-06-08 04:10&#9;--------&#9;d-----w-&#9;c:\documents and settings\Administrator\Application Data\Apple Computer<br>2009-06-08 04:10 . 2009-03-19 20:32&#9;23400&#9;----a-w-&#9;c:\windows\system32\drivers\GEARAspiWDM.sys<br>2009-06-08 04:10 . 2008-04-17 16:12&#9;107368&#9;----a-w-&#9;c:\windows\system32\GEARAspi.dll<br>2009-06-08 04:09 . 2009-06-08 04:09&#9;--------&#9;d-----w-&#9;c:\program files\iPod<br>2009-06-08 04:09 . 2009-06-08 04:10&#9;--------&#9;d-----w-&#9;c:\program files\iTunes<br>2009-06-08 04:09 . 2009-06-08 04:10&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}<br>2009-06-08 04:09 . 2009-06-08 04:09&#9;--------&#9;d-----w-&#9;c:\program files\Bonjour<br>2009-06-08 04:09 . 2003-02-25 15:20&#9;58368&#9;----a-w-&#9;c:\windows\system32\HPDOMON.DLL<br>2009-06-08 04:08 . 2003-07-18 17:14&#9;40960&#9;----a-w-&#9;c:\windows\system32\HPBMMON.DLL<br>2009-06-08 04:08 . 2003-02-25 15:19&#9;94274&#9;----a-w-&#9;c:\windows\system32\HPBHEALR.DLL<br>2009-06-08 04:08 . 2009-06-08 04:09&#9;--------&#9;d-----w-&#9;c:\program files\QuickTime<br>2009-06-08 04:08 . 2009-06-08 04:09&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\Apple Computer<br>2009-06-08 04:08 . 2009-06-08 04:08&#9;--------&#9;d-----w-&#9;c:\documents and settings\Administrator\Local Settings\Application Data\Apple<br>2009-06-08 04:08 . 2009-06-08 04:08&#9;--------&#9;d-----w-&#9;c:\program files\Apple Software Update<br>2009-06-08 04:08 . 2009-06-08 04:09&#9;--------&#9;d-----w-&#9;c:\program files\Common Files\Apple<br>2009-06-08 04:08 . 2009-06-08 04:08&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\Apple<br>2009-06-08 04:07 . 2009-06-08 04:10&#9;--------&#9;d-----w-&#9;c:\documents and settings\Administrator\Local Settings\Application Data\Apple Computer<br>2009-06-08 03:53 . 2009-06-08 03:53&#9;--------&#9;d-----w-&#9;c:\program files\Citrix<br>2009-06-08 03:52 . 2009-06-08 03:52&#9;70984&#9;----a-w-&#9;c:\documents and settings\Administrator\g2mdlhlpx.exe<br>2009-06-08 03:52 . 2009-06-08 03:52&#9;--------&#9;d-----w-&#9;c:\windows\Sun<br>2009-06-08 03:49 . 2009-06-08 03:50&#9;--------&#9;d-----w-&#9;C:\TMWIN<br>2009-06-08 03:48 . 2009-06-08 03:49&#9;--------&#9;d-----w-&#9;C:\TMNODE<br>2009-06-08 03:47 . 2009-06-08 03:47&#9;--------&#9;d--h--w-&#9;c:\windows\PIF<br>2009-06-08 03:11 . 2009-06-10 10:21&#9;--------&#9;d-----w-&#9;c:\documents and settings\Administrator\Tracing<br>2009-06-08 03:11 . 2009-06-08 03:11&#9;--------&#9;d-----w-&#9;c:\program files\Microsoft<br>2009-06-08 03:10 . 2009-06-08 03:10&#9;--------&#9;d-----w-&#9;c:\program files\Windows Live SkyDrive<br>2009-06-08 03:10 . 2009-06-08 03:10&#9;--------&#9;d-----w-&#9;c:\program files\Windows Live<br>2009-06-08 03:04 . 2009-06-08 03:04&#9;--------&#9;d-----w-&#9;c:\program files\Common Files\Windows Live<br>2009-06-08 03:02 . 2009-06-08 03:02&#9;--------&#9;d-sh--w-&#9;c:\documents and settings\Administrator\IECompatCache<br>2009-06-08 03:02 . 2009-06-08 03:02&#9;--------&#9;d-sh--w-&#9;c:\documents and settings\Administrator\PrivacIE<br>2009-06-08 02:35 . 2009-06-08 02:35&#9;9062&#9;----a-r-&#9;c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{C0258B3B-48BE-4678-B9DA-AEF70D474A2C}\ARPPRODUCTICON.exe<br>2009-06-08 02:34 . 2006-05-26 17:47&#9;81920&#9;----a-w-&#9;c:\windows\system32\GM7tp32.dll<br>2009-06-08 02:34 . 2006-05-26 17:47&#9;1576960&#9;----a-w-&#9;c:\windows\system32\Gm7s32.dll<br>2009-06-08 02:34 . 2006-05-26 17:45&#9;901120&#9;----a-w-&#9;c:\windows\system32\gmssl32.dll<br>2009-06-08 02:34 . 2006-05-26 17:43&#9;3596288&#9;----a-w-&#9;c:\windows\system32\GmXml.dll<br>2009-06-08 02:32 . 2009-06-08 02:32&#9;9062&#9;----a-r-&#9;c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{489F5116-4D08-4234-A21F-1FFA620A76E3}\ARPPRODUCTICON.exe<br>2009-06-08 02:28 . 2009-06-08 02:28&#9;86016&#9;----a-w-&#9;c:\windows\system32\OdbcJdbcSetup.dll<br>2009-06-08 02:28 . 2009-06-08 02:28&#9;225280&#9;----a-w-&#9;c:\windows\system32\IscDbc.dll<br>2009-06-08 02:28 . 2009-06-08 02:28&#9;200704&#9;----a-w-&#9;c:\windows\system32\OdbcJdbc.dll<br>2009-06-08 02:28 . 2006-04-20 00:44&#9;356437&#9;----a-w-&#9;c:\windows\system32\gds32.dll<br>2009-06-08 02:28 . 2009-06-08 02:28&#9;--------&#9;d-----w-&#9;c:\program files\Firebird<br>2009-06-08 02:27 . 2009-06-08 02:52&#9;--------&#9;d-----w-&#9;c:\program files\GoldMine<br>2009-06-08 02:26 . 2009-06-08 02:26&#9;--------&#9;d-----w-&#9;c:\windows\Downloaded Installations<br>2009-06-08 02:22 . 2009-06-08 02:22&#9;--------&#9;d-sh--w-&#9;c:\documents and settings\Administrator\IETldCache<br>2009-06-08 02:12 . 2009-06-08 02:12&#9;--------&#9;d-----w-&#9;c:\windows\system32\XPSViewer<br>2009-06-08 02:12 . 2009-06-08 02:12&#9;--------&#9;d-----w-&#9;c:\program files\MSBuild<br>2009-06-08 02:12 . 2009-06-08 02:12&#9;--------&#9;d-----w-&#9;c:\program files\Reference Assemblies<br>2009-06-08 02:12 . 2008-07-06 12:06&#9;89088&#9;-c----w-&#9;c:\windows\system32\dllcache\filterpipelineprintproc.dll<br>2009-06-08 02:12 . 2008-07-06 12:06&#9;575488&#9;-c----w-&#9;c:\windows\system32\dllcache\xpsshhdr.dll<br>2009-06-08 02:12 . 2008-07-06 12:06&#9;575488&#9;------w-&#9;c:\windows\system32\xpsshhdr.dll<br>2009-06-08 02:12 . 2008-07-06 12:06&#9;1676288&#9;-c----w-&#9;c:\windows\system32\dllcache\xpssvcs.dll<br>2009-06-08 02:12 . 2008-07-06 12:06&#9;1676288&#9;------w-&#9;c:\windows\system32\xpssvcs.dll<br>2009-06-08 02:12 . 2008-07-06 12:06&#9;117760&#9;------w-&#9;c:\windows\system32\prntvpt.dll<br>2009-06-08 02:12 . 2008-07-06 10:50&#9;597504&#9;-c----w-&#9;c:\windows\system32\dllcache\printfilterpipelinesvc.exe<br>2009-06-08 02:08 . 2009-06-08 02:08&#9;--------&#9;dc-h--w-&#9;c:\windows\ie8<br>2009-06-08 02:07 . 2009-06-08 02:07&#9;--------&#9;d-----w-&#9;c:\program files\Microsoft Silverlight<br>2009-06-08 01:32 . 2009-06-08 02:23&#9;--------&#9;d-----w-&#9;c:\documents and settings\Administrator\Application Data\AdobeUM<br>2009-06-08 01:30 . 2009-06-08 01:30&#9;1&#9;----a-w-&#9;c:\documents and settings\Administrator\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys<br>2009-06-08 01:29 . 2009-06-08 01:29&#9;--------&#9;d-----w-&#9;c:\documents and settings\Administrator\Application Data\OpenOffice.org<br>2009-06-08 01:23 . 2009-06-08 01:23&#9;--------&#9;d-----w-&#9;c:\program files\JRE<br>2009-06-08 01:23 . 2009-06-08 01:23&#9;--------&#9;d-----w-&#9;c:\program files\OpenOffice.org 3<br>2009-06-08 01:23 . 2009-05-21 15:33&#9;410984&#9;----a-w-&#9;c:\windows\system32\deploytk.dll<br>2009-06-05 16:41 . 2009-06-03 15:40&#9;6611357&#9;----a-w-&#9;c:\windows\FramePkg.exe<br>2009-06-05 15:36 . 2008-04-14 02:14&#9;2560&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Microsoft\USMT\iconlib.dll<br>2009-06-05 12:32 . 2009-06-05 12:32&#9;44384&#9;----a-w-&#9;c:\windows\system32\drivers\tifsfilt.sys<br>2009-06-05 12:32 . 2009-06-05 12:32&#9;441760&#9;----a-w-&#9;c:\windows\system32\drivers\timntr.sys<br>2009-06-05 12:31 . 2009-06-05 12:31&#9;134272&#9;----a-w-&#9;c:\windows\system32\drivers\snman380.sys<br>2009-06-05 12:31 . 2009-06-05 12:32&#9;--------&#9;d-----w-&#9;c:\program files\Common Files\Acronis<br>2009-06-05 12:31 . 2009-06-05 12:31&#9;--------&#9;d-----w-&#9;c:\program files\Acronis<br>2009-06-05 12:12 . 2009-06-05 12:12&#9;--------&#9;d-----w-&#9;c:\windows\ServicePackFiles<br>2009-06-04 19:28 . 2008-11-20 19:19&#9;9200&#9;------w-&#9;c:\windows\system32\drivers\cdralw2k.sys<br>2009-06-04 19:28 . 2008-11-20 19:19&#9;9072&#9;------w-&#9;c:\windows\system32\drivers\cdr4_xp.sys<br>2009-06-04 19:23 . 2009-06-08 19:09&#9;--------&#9;d-----w-&#9;c:\documents and settings\Administrator\Local Settings\Application Data\Google<br>2009-06-04 19:23 . 2009-06-04 19:23&#9;--------&#9;d-----w-&#9;c:\windows\system32\IOSUBSYS<br>2009-06-04 19:23 . 2009-06-08 19:09&#9;--------&#9;d-----w-&#9;c:\program files\Google<br>2009-06-04 19:17 . 2009-06-04 19:17&#9;--------&#9;d-----w-&#9;c:\windows\ShellNew<br>2009-06-04 19:15 . 2009-06-04 19:15&#9;--------&#9;d-----w-&#9;c:\windows\Twain32<br>2009-06-04 19:15 . 2009-06-04 19:15&#9;--------&#9;d-----w-&#9;c:\documents and settings\Administrator\Application Data\Microsoft Web Folders<br>2009-06-04 18:56 . 2009-06-04 18:56&#9;--------&#9;d-----w-&#9;c:\program files\ltmoh<br>2009-06-04 18:56 . 2006-10-18 08:39&#9;487424&#9;----a-w-&#9;c:\windows\system32\cselect.exe<br>2009-06-04 18:56 . 2003-10-31 19:59&#9;45056&#9;----a-w-&#9;c:\windows\system32\csellang.dll<br>2009-06-04 18:22 . 2001-08-17 20:48&#9;12160&#9;----a-w-&#9;c:\windows\system32\drivers\mouhid.sys<br>2009-06-04 18:22 . 2008-04-14 04:15&#9;10368&#9;----a-w-&#9;c:\windows\system32\drivers\hidusb.sys<br>2009-06-04 18:22 . 2009-06-04 15:30&#9;--------&#9;d-----w-&#9;c:\windows\iehome<br>2009-06-04 18:22 . 2009-06-04 18:22&#9;--------&#9;d-----w-&#9;c:\program files\Datalode<br>2009-06-04 17:43 . 2009-06-04 17:43&#9;--------&#9;d--h--w-&#9;c:\windows\system32\GroupPolicy<br>2009-06-04 17:23 . 2009-06-04 17:23&#9;--------&#9;d-----w-&#9;c:\program files\MSXML 6.0<br>2009-06-04 17:12 . 2007-04-09 17:23&#9;28040&#9;----a-w-&#9;c:\windows\system32\mdimon.dll<br>2009-06-04 17:11 . 2009-06-04 17:11&#9;--------&#9;d-----w-&#9;c:\program files\Common Files\L&H<br>2009-06-04 17:11 . 2009-06-04 17:11&#9;--------&#9;d-----w-&#9;c:\program files\Microsoft ActiveSync<br>2009-06-04 17:09 . 2009-03-08 08:34&#9;1206784&#9;-c--a-w-&#9;c:\windows\system32\dllcache\urlmon.dll<br>2009-06-04 17:09 . 2009-03-08 08:34&#9;914944&#9;-c--a-w-&#9;c:\windows\system32\dllcache\wininet.dll<br>2009-06-04 17:09 . 2009-03-02 23:04&#9;1499136&#9;-c----w-&#9;c:\windows\system32\dllcache\shdocvw.dll<br>2009-06-04 17:09 . 2009-03-08 08:41&#9;5937152&#9;-c--a-w-&#9;c:\windows\system32\dllcache\mshtml.dll<br>2009-06-04 17:09 . 2008-05-03 11:55&#9;2560&#9;------w-&#9;c:\windows\system32\xpsp4res.dll<br>2009-06-04 17:09 . 2008-04-21 12:08&#9;215552&#9;-c----w-&#9;c:\windows\system32\dllcache\wordpad.exe<br>2009-06-04 17:08 . 2009-06-04 17:08&#9;--------&#9;d-sh--w-&#9;c:\documents and settings\Administrator\UserData<br>2009-06-04 16:37 . 2007-04-23 18:29&#9;68456&#9;----a-w-&#9;c:\documents and settings\__sbs_netsetup__\Local Settings\Application Data\GDIPFONTCACHEV1.DAT<br>2009-06-04 15:42 . 2009-06-04 15:42&#9;--------&#9;d-----w-&#9;c:\windows\SchCache<br>2009-06-04 15:42 . 2009-06-04 15:42&#9;--------&#9;d-----w-&#9;c:\program files\Microsoft Windows Small Business Server<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2009-06-10 10:32 . 2007-04-22 21:00&#9;--------&#9;d-----w-&#9;c:\program files\Java<br>2009-06-09 19:03 . 2009-06-04 16:40&#9;--------&#9;d-----w-&#9;c:\program files\Lexmark<br>2009-06-08 14:32 . 2009-06-04 15:30&#9;74328&#9;----a-w-&#9;c:\documents and settings\ken\Local Settings\Application Data\GDIPFONTCACHEV1.DAT<br>2009-06-08 02:23 . 2007-04-23 18:29&#9;74328&#9;----a-w-&#9;c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT<br>2009-06-08 01:42 . 2007-04-22 21:07&#9;--------&#9;d-----w-&#9;c:\program files\Common Files\Adobe<br>2009-06-05 16:48 . 2009-06-05 16:41&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\McAfee<br>2009-06-05 16:48 . 2009-06-05 16:48&#9;--------&#9;d-----w-&#9;c:\program files\Common Files\McAfee<br>2009-06-05 16:48 . 2009-06-05 16:41&#9;--------&#9;d-----w-&#9;c:\program files\McAfee<br>2009-06-05 16:47 . 2009-06-05 16:47&#9;2585872&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\McAfee\Common Framework\Current\VIRUSCAN8600\Install\[u]0[/u]000\WindowsInstaller-KB893803-v2-x86.exe<br>2009-06-05 16:47 . 2009-06-05 16:47&#9;95568&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\McAfee\Common Framework\Current\VIRUSCAN8600\Install\[u]0[/u]000\setupvse.exe<br>2009-06-05 16:47 . 2009-06-05 16:47&#9;94208&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\McAfee\Common Framework\Current\VIRUSCAN8600\Install\[u]0[/u]000\UnInst.exe<br>2009-06-05 16:47 . 2009-06-05 16:47&#9;102400&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\McAfee\Common Framework\Current\VIRUSCAN8600\Install\[u]0[/u]000\UnInstX64.exe<br>2009-06-05 16:42 . 2009-06-05 16:42&#9;--------&#9;d-----w-&#9;c:\program files\Common Files\Cisco Systems<br>2009-06-05 12:15 . 2007-04-22 20:16&#9;86327&#9;----a-w-&#9;c:\windows\pchealth\helpctr\OfflineCache\index.dat<br>2009-06-04 19:18 . 2009-06-04 19:18&#9;5058&#9;----a-w-&#9;c:\windows\Help\hhcolreg.dat<br>2009-06-04 18:39 . 2007-04-22 20:46&#9;--------&#9;d-----w-&#9;c:\program files\TOSHIBA<br>2009-06-04 17:10 . 2009-06-04 17:10&#9;--------&#9;d-----w-&#9;c:\program files\Microsoft.NET<br>2009-06-04 16:46 . 2007-04-23 18:12&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\Microsoft Help<br>2009-06-04 16:40 . 2009-06-04 16:40&#9;--------&#9;d-----w-&#9;c:\program files\Lexmark_HostCD<br>2009-06-04 16:40 . 2009-06-04 16:40&#9;--------&#9;d-----w-&#9;c:\documents and settings\Administrator\Application Data\Protector Suite<br>2009-06-04 15:33 . 2007-04-22 20:47&#9;--------&#9;d--h--w-&#9;c:\program files\InstallShield Installation Information<br>2009-06-04 15:30 . 2009-06-04 15:30&#9;0&#9;--sha-r-&#9;c:\windows\system32\drivers\TOSHIBA_TECRA A9_S3A6253D001_PTS52C-MH709C.MRK<br>2009-06-04 15:28 . 2009-06-09 18:00&#9;--------&#9;d-----w-&#9;c:\documents and settings\Administrator.HYPATIA\Application Data\Intel<br>2009-06-04 15:28 . 2009-06-04 16:37&#9;--------&#9;d-----w-&#9;c:\documents and settings\__sbs_netsetup__\Application Data\Intel<br>2009-06-04 15:28 . 2009-06-04 15:30&#9;--------&#9;d-----w-&#9;c:\documents and settings\ken\Application Data\Intel<br>2009-06-04 15:28 . 2007-04-22 20:45&#9;--------&#9;d-----w-&#9;c:\program files\Intel<br>2009-06-04 15:27 . 2009-06-04 15:27&#9;315392&#9;----a-w-&#9;c:\windows\HideWin.exe<br>2009-06-04 15:27 . 2009-06-04 15:27&#9;--------&#9;d-----w-&#9;c:\program files\Realtek<br>2009-05-01 18:30 . 2009-05-01 18:30&#9;3366912&#9;----a-w-&#9;c:\windows\system32\GPhotos.scr<br>2009-04-21 22:27 . 2009-04-21 22:27&#9;23152&#9;----a-w-&#9;c:\windows\system32\drivers\sshrmd.sys<br>2009-04-21 22:27 . 2009-04-21 22:27&#9;176752&#9;----a-w-&#9;c:\windows\system32\drivers\ssidrv.sys<br>2009-04-21 22:27 . 2009-04-21 22:27&#9;29808&#9;----a-w-&#9;c:\windows\system32\drivers\ssfs0bbc.sys<br>2009-03-19 20:32 . 2009-03-19 20:32&#9;23400&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys<br>.<br><br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\BackupIconOverlayId]<br>@="{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}"<br>[HKEY_CLASSES_ROOT\CLSID\{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}]<br>2009-05-13 19:34&#9;238968&#9;----a-w-&#9;c:\program files\Webroot\WebrootSecurity\Backup\CtxMenu_1_0_0_10.dll<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]<br>"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]<br>"GoToMeeting"="c:\program files\Citrix\GoToMeeting\366\g2mstart.exe" [2009-06-08 31552]<br>"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-08 39408]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"ThpSrv"="c:\windows\system32\thpsrv" [X]<br>"00THotkey"="c:\windows\system32\[u]0[/u]0THotkey.exe" [2006-07-05 19:14 258048]<br>"TosHKCW.exe"="c:\program files\TOSHIBA\Wireless Hotkey\TosHKCW.exe" [2005-05-17 49152]<br>"DDWMon"="c:\program files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe" [2007-04-14 311296]<br>"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2004-03-23 196608]<br>"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]<br>"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]<br>"TMERzCtl.EXE"="c:\program files\TOSHIBA\TME3\TMERzCtl.EXE" [2006-04-26 90112]<br>"TMESRV.EXE"="c:\program files\TOSHIBA\TME3\TMESRV31.EXE" [2005-12-14 126976]<br>"TAudEffect"="c:\program files\TOSHIBA\TAudEffect\TAudEff.exe" [2006-08-09 344144]<br>"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-09 138008]<br>"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-09 162584]<br>"Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-09 138008]<br>"TouchED"="c:\program files\TOSHIBA\TouchED\TouchED.exe" [2005-06-29 126976]<br>"PSQLLauncher"="c:\program files\Protector Suite QL\launcher.exe" [2006-05-05 30208]<br>"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageEchoWorkstation\TrueImageMonitor.exe" [2009-01-19 1285504]<br>"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageEchoWorkstation\TimounterMonitor.exe" [2009-01-18 884928]<br>"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2009-01-18 140568]<br>"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2009-03-10 136512]<br>"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]<br>"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]<br>"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-05-30 292136]<br>"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-06-08 68592]<br>"SpySweeper"="c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe" [2009-05-13 6345840]<br>"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]<br>"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-14 169984]<br>"000StTHK"="000StTHK.exe" - c:\windows\system32\[u]0[/u]00StTHK.exe [2001-06-23 11:28 24576]<br>"TOSDCR"="TOSDCR.EXE" - c:\windows\system32\TOSDCR.exe [2005-12-13 57344]<br>"TFNF5"="TFNF5.exe" - c:\windows\system32\TFNF5.exe [2006-04-10 622592]<br>"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-03-12 16125440]<br>"TFncKy"="TFncKy.exe" [BU]<br>"TPSODDCtl"="TPSODDCtl.exe" - c:\windows\system32\TPSODDCtl.exe [2007-02-02 110592]<br>"TPSMain"="TPSMain.exe" - c:\windows\system32\TPSMain.exe [2006-07-26 315392]<br><br>c:\documents and settings\Administrator.HYPATIA\Start Menu\Programs\Startup\<br>IEHOME.LNK - c:\documents and settings\Default User\Local Settings\Temp\iehome.bat [2009-6-4 298]<br><br>c:\documents and settings\__sbs_netsetup__\Start Menu\Programs\Startup\<br>IEHOME.LNK - c:\documents and settings\Default User\Local Settings\Temp\iehome.bat [2009-6-4 298]<br><br>c:\documents and settings\All Users\Start Menu\Programs\Startup\<br>Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-F400-BA7E-100000000002}\SC_Acrobat.exe [2009-6-5 25214]<br>Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]<br>"NoWelcomeScreen"= 1 (0x1)<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]<br>2006-05-05 21:48&#9;40448&#9;----a-w-&#9;c:\windows\system32\psqlpwd.dll<br><br>[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]<br>Notification Packages&#9;REG_MULTI_SZ   &#9;scecli psqlpwd<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]<br>@="Service"<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]<br>@="Service"<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"%windir%\\system32\\sessmgr.exe"=<br>"%windir%\\Network Diagnostic\\xpnetdiag.exe"=<br>"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=<br>"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=<br>"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=<br>"c:\\Program Files\\iTunes\\iTunes.exe"=<br>"c:\\Program Files\\Acronis\\TrueImageEchoWorkstation\\TrueImage.exe"=<br>"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=<br><br>R0 snapman380;Acronis Snapshots Manager (Build 380);c:\windows\system32\drivers\snman380.sys [6/5/2009 8:31 AM 134272]<br>R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [4/21/2009 6:27 PM 29808]<br>R0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\drivers\thpdrv.sys [3/22/2007 4:07 PM 20992]<br>R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\drivers\Thpevm.sys [3/9/2007 6:23 PM 6528]<br>R1 TMEI3E;TMEI3E;c:\windows\system32\drivers\TMEI3E.sys [6/4/2009 11:31 AM 5888]<br>R2 AcronisAgent;Acronis Remote Agent;c:\program files\Common Files\Acronis\Agent\agent.exe [1/18/2009 8:07 PM 517848]<br>R2 FdRedir;FdRedir;c:\program files\Common Files\Protector Suite QL\Drivers\FdRedir.sys [5/5/2006 6:00 PM 13568]<br>R2 FileDisk2;FileDisk Protector Kernel Driver;c:\program files\Common Files\Protector Suite QL\Drivers\filedisk.sys [5/5/2006 5:59 PM 33024]<br>R2 FirebirdGuardianDefaultInstance;FirebirdGuardian - DefaultInstance;c:\program files\Firebird\firebird_1_5\bin\fbguard.exe [4/19/2006 8:09 PM 65536]<br>R2 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\firebird_1_5\bin\fbserver.exe -s --> c:\program files\Firebird\firebird_1_5\bin\fbserver.exe -s [?]<br>R2 smihlp;SMI helper driver;c:\program files\Protector Suite QL\smihlp.sys [5/5/2006 5:33 PM 3456]<br>R2 tdudf;TOSHIBA UDF File System Driver;c:\windows\system32\drivers\tdudf.sys [3/26/2007 3:22 PM 105856]<br>R2 Tmesrv;Tmesrv3;c:\program files\TOSHIBA\TME3\TMESRV31.exe [6/4/2009 11:31 AM 126976]<br>R2 trudf;TOSHIBA DVD-RAM UDF File System Driver;c:\windows\system32\drivers\trudf.sys [2/19/2007 3:15 PM 134016]<br>R2 WRConsumerService;Webroot Client Service;c:\program files\Webroot\WebrootSecurity\WRConsumerService.exe [6/8/2009 12:32 AM 1205760]<br>R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [4/22/2007 4:20 PM 35968]<br>R3 TEchoCan;Toshiba Audio Effect;c:\windows\system32\drivers\TEchoCan.sys [6/4/2009 11:33 AM 435072]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]<br>HPZ12&#9;REG_MULTI_SZ   &#9;Pml Driver HPZ12 Net Driver HPZ12<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]<br>"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP<br>.<br>Contents of the 'Scheduled Tasks' folder<br><br>2009-06-08 c:\windows\Tasks\AppleSoftwareUpdate.job<br>- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]<br><br>2009-06-04 c:\windows\Tasks\Registration reminder 2.job<br>- c:\windows\system32\OOBE\oobebaln.exe [2007-04-22 09:42]<br><br>2009-06-10 c:\windows\Tasks\User_Feed_Synchronization-{DBCF6069-EB84-4D65-8C65-4682FB09D6FA}.job<br>- c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]<br><br>2009-06-10 c:\windows\Tasks\wrSpySweeper_1F2B4464FF314BF3B423F14FA81CFB39.job<br>- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2009-06-08 19:40]<br><br>2009-06-10 c:\windows\Tasks\wrSpySweeper_1F2B4464FF314BF3B423F14FA81CFB39.job<br>- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2009-06-08 19:40]<br>.<br>.<br>------- Supplementary Scan -------<br>.<br>uStart Page = hxxp://www.google.ca/<br>uSearch Page = hxxp://www.google.com<br>uSearch Bar = hxxp://www.google.com/ie<br>uDefault_Search_URL = hxxp://www.google.com/ie<br>uInternet Settings,ProxyOverride = *.local<br>uSearchURL,(Default) = hxxp://www.google.com/search?q=%s<br>IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200<br>IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br>IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br>IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br>IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br>IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br>IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br>IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br>IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br>IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000<br>Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll<br>DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab<br>.<br><br>**************************************************************************<br><br>catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2009-06-10 11:46<br>Windows 5.1.2600 Service Pack 3 NTFS<br><br>scanning hidden processes ...  <br><br>scanning hidden autostart entries ... <br><br>scanning hidden files ...  <br><br>c:\docume~1\ADMINI~1\LOCALS~1\Temp\Perflib_Perfdata_1704.dat 16384 bytes<br><br>scan completed successfully<br>hidden files: 1<br><br>**************************************************************************<br>.<br>--------------------- DLLs Loaded Under Running Processes ---------------------<br><br>- - - - - - - > 'winlogon.exe'(1024)<br>c:\windows\system32\vrlogon.dll<br>c:\windows\system32\psqlpwd.dll<br>c:\program files\Protector Suite QL\infra.dll<br>c:\program files\Protector Suite QL\homefus2.dll<br>c:\windows\system32\biologon.dll<br>c:\program files\Protector Suite QL\homepass.dll<br>c:\program files\Protector Suite QL\bio.dll<br>c:\program files\Protector Suite QL\remote.dll<br>c:\program files\Protector Suite QL\mysafe.dll<br>c:\windows\system32\igfxdev.dll<br><br>- - - - - - - > 'lsass.exe'(1080)<br>c:\windows\system32\relog_ap.dll<br>c:\windows\system32\psqlpwd.dll<br>c:\program files\Protector Suite QL\infra.dll<br>c:\program files\Protector Suite QL\homefus2.dll<br>c:\program files\Bonjour\mdnsNSP.dll<br>.<br>Completion time: 2009-06-10 11:47<br>ComboFix-quarantined-files.txt  2009-06-10 15:47<br><br>Pre-Run: 87,639,932,928 bytes free<br>Post-Run: 87,868,571,648 bytes free<br><br>WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe<br>[boot loader]<br>timeout=2<br>default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS<br>[operating systems]<br>c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons<br>multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /forceresetreg<br><br>345&#9;--- E O F ---&#9;2009-06-04 19:08]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22528289</guid>
<pubDate>Wed, 10 Jun 2009 13:55:41 EDT</pubDate>
</item>

<item>
<title>Re: MSN sending out messages without my consent</title>
<link>http://www.dslreports.com/forum/remark,22525045</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Thanks for getting this to the right forum :)<br><br>What the Eset scan found earlier was a remnant from the Ask toolbar and not the cause of this type of problem.<br><br>However, nothing giving a clue in the HijackThis log - it does sound like a MSN worm of some sort.  Let's dig a little deeper with this tool next, please.<br><br><i><b>For those casually looking on, this tool isn't for everyday use by just anybody and is only meant to be run under supervised use and when called for by a helper trained in it's use by the author of the tool.</b></i> <br><br>Download ComboFix from here:<br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;</textarea><!--end code block--><br><b>* IMPORTANT !!! Save ComboFix.exe to your Desktop</b><br><br>[*]Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools.  Remember to re-enable them after the final steps are done here.<br><br>[*]Double click on ComboFix.exe & follow the prompts.<br><br>[*]As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal.  It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.<br><br>[*]Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.</ul><br><br><i>**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.</i><br><br>[att=1]<br><br>Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:<br><br>[att=2]<br><br>Click on Yes, to continue scanning for malware.<br><br>When finished, it shall produce a log for you.  Please include the <b>C:\ComboFix.txt</b> in your next reply.<br><br><i>Notes:<br><br>1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.<br>2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.<br>3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.<br>4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.<br><br>Give it at least 20-30 minutes to finish if needed.</i><br><br><small>--<br>It takes a disaster to make a woman out of a female<br>Microsoft MVP/Windows Security 2003-2009<br>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </a> (Alliance of Security Analysis Professionals)</small><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/22525045?c=1437869&ret=L2ZvcnVtL3IyMjUyMTUzNS54bWw%3D"><IMG TITLE="7968 bytes" BORDER=0 WIDTH=536 HEIGHT=154 SRC="/r0/download/1437869~df7f98b496765b88fd2601885a7fc00f/RcAuto1.gif"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=2 WIDTH=66%><A HREF="/speak/slideshow/22525045?c=1437870&ret=L2ZvcnVtL3IyMjUyMTUzNS54bWw%3D"><IMG TITLE="4805 bytes" BORDER=0 WIDTH=311 HEIGHT=159 SRC="/r0/download/1437870~3fdc36a8b5225ae094b3a18f139dce07/whatnext.gif"></A></TD><TD ALIGN=CENTER BGCOLOR=#FFFFFF nowrap width=1%>&nbsp;</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22525045</guid>
<pubDate>Tue, 09 Jun 2009 22:03:40 EDT</pubDate>
</item>

<item>
<title>Re: MSN sending out messages without my consent</title>
<link>http://www.dslreports.com/forum/remark,22522534</link>
<description><![CDATA[<A HREF="/useremail/u/769887"><b>Milkster</b></A> : Ok, I ran the scanns again in Safemode and here are the results:<br><br>ESET OnLine Scanner:  Did not find anything<br><br>Malwarebytes' Anti-Malware 1.37<br>Database version: 2255<br>Windows 5.1.2600 Service Pack 3<br><br>6/9/2009 2:14:35 PM<br>mbam-log-2009-06-09 (14-14-35).txt<br><br>Scan type: Quick Scan<br>Objects scanned: 103070<br>Time elapsed: 3 minute(s), 14 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 0<br>Registry Keys Infected: 0<br>Registry Values Infected: 0<br>Registry Data Items Infected: 0<br>Folders Infected: 0<br>Files Infected: 0<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>(No malicious items detected)<br><br>Registry Keys Infected:<br>(No malicious items detected)<br><br>Registry Values Infected:<br>(No malicious items detected)<br><br>Registry Data Items Infected:<br>(No malicious items detected)<br><br>Folders Infected:<br>(No malicious items detected)<br><br>Files Infected:<br>(No malicious items detected)<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 2:15:15 PM, on 6/9/2009<br>Platform: Windows XP SP3 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br>Boot mode: Safe mode with network support<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.google.ca/" >www.google.ca/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br>O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll<br>O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll<br>O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll<br>O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll<br>O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br>O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br>O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll<br>O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll<br>O4 - HKLM\..\Run: [00THotkey] "C:\WINDOWS\system32\00THotkey.exe"<br>O4 - HKLM\..\Run: [000StTHK] "000StTHK.exe"<br>O4 - HKLM\..\Run: [ThpSrv] "C:\WINDOWS\system32\thpsrv" /logon<br>O4 - HKLM\..\Run: [TOSDCR] "TOSDCR.EXE"<br>O4 - HKLM\..\Run: [TosHKCW.exe] "C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe"<br>O4 - HKLM\..\Run: [DDWMon] C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe<br>O4 - HKLM\..\Run: [TFNF5] "TFNF5.exe"<br>O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint2K\Apoint.exe"<br>O4 - HKLM\..\Run: [RTHDCPL] "RTHDCPL.EXE"<br>O4 - HKLM\..\Run: [Alcmtr] "ALCMTR.EXE"<br>O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"<br>O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless<br>O4 - HKLM\..\Run: [TFncKy] TFncKy.exe<br>O4 - HKLM\..\Run: [TMERzCtl.EXE] "C:\Program Files\TOSHIBA\TME3\TMERzCtl.EXE" /Service<br>O4 - HKLM\..\Run: [TMESRV.EXE] "C:\Program Files\TOSHIBA\TME3\TMESRV31.EXE" /Logon<br>O4 - HKLM\..\Run: [TAudEffect] "C:\Program Files\TOSHIBA\TAudEffect\TAudEff.exe" /run<br>O4 - HKLM\..\Run: [IgfxTray] "C:\WINDOWS\system32\igfxtray.exe"<br>O4 - HKLM\..\Run: [HotKeysCmds] "C:\WINDOWS\system32\hkcmd.exe"<br>O4 - HKLM\..\Run: [Persistence] "C:\WINDOWS\system32\igfxpers.exe"<br>O4 - HKLM\..\Run: [TouchED] "C:\Program Files\TOSHIBA\TouchED\TouchED.exe"<br>O4 - HKLM\..\Run: [TPSODDCtl] "TPSODDCtl.exe"<br>O4 - HKLM\..\Run: [TPSMain] "TPSMain.exe"<br>O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup<br>O4 - HKLM\..\Run: [TrueImageMonitor.exe] "C:\Program Files\Acronis\TrueImageEchoWorkstation\TrueImageMonitor.exe"<br>O4 - HKLM\..\Run: [AcronisTimounterMonitor] "C:\Program Files\Acronis\TrueImageEchoWorkstation\TimounterMonitor.exe"<br>O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"<br>O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey<br>O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE<br>O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe"  /autorun<br>O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray<br>O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /install /silent<br>O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"<br>O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background<br>O4 - HKCU\..\Run: [GoToMeeting] "C:\Program Files\Citrix\GoToMeeting\366\g2mstart.exe" "/Trigger RunAtLogon"<br>O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"<br>O4 - .DEFAULT User Startup: IEHOME.LNK = C:\Documents and Settings\Default User\Local Settings\Temp\iehome.bat (User 'Default user')<br>O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?<br>O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE<br>O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200<br>O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br>O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br>O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br>O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br>O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br>O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br>O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br>O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O14 - IERESET.INF: START_PAGE_URL=http://companyweb<br>O16 - DPF: {485D813E-EE26-4DF8-9FAF-DEDF2885306E} (NSHelp Class) - &raquo;<small>https</small>://<A HREF="https://odin/connectcomputer/nshelp.dll">odin/connectcomputer/nshelp.dll</A><br>O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &raquo;<A HREF="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1244425902593" >update.microsoft.com/microsoftup&middot;&middot;&middot;25902593</A><br>O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - &raquo;<A HREF="http://download.eset.com/special/eos/OnlineScanner.cab" >download.eset.com/special/eos/On&middot;&middot;&middot;nner.cab</A><br>O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = domain<br>O17 - HKLM\Software\..\Telephony: DomainName = domain<br>O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = domain<br>O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll<br>O23 - Service: Acronis Remote Agent (AcronisAgent) - Acronis - C:\Program Files\Common Files\Acronis\Agent\agent.exe<br>O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe<br>O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe<br>O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe<br>O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br>O23 - Service: FirebirdGuardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\firebird_1_5\bin\fbguard.exe<br>O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\firebird_1_5\bin\fbserver.exe<br>O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe<br>O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe<br>O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe<br>O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br>O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br>O23 - Service: TOSHIBA HDD Protection (Thpsrv) - TOSHIBA Corporation - C:\WINDOWS\system32\ThpSrv.exe<br>O23 - Service: Tmesrv3 (Tmesrv) - TOSHIBA - C:\Program Files\TOSHIBA\TME3\Tmesrv31.exe<br>O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\WINDOWS\system32\TODDSrv.exe<br>O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe<br>O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe<br>O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc.  - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe<br><br>--<br>End of file - 12330 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22522534</guid>
<pubDate>Tue, 09 Jun 2009 14:51:48 EDT</pubDate>
</item>

<item>
<title>Re: MSN sending out messages without my consent</title>
<link>http://www.dslreports.com/forum/remark,22521586</link>
<description><![CDATA[<A HREF="/useremail/u/769887"><b>Milkster</b></A> : damn, i just realized that i didn't do the scanning in safe mode....I will repost the logs when scanning is done.... sorry]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22521586</guid>
<pubDate>Tue, 09 Jun 2009 12:40:00 EDT</pubDate>
</item>

<item>
<title>MSN sending out messages without my consent</title>
<link>http://www.dslreports.com/forum/remark,22521535</link>
<description><![CDATA[<A HREF="/useremail/u/769887"><b>Milkster</b></A> : I have a co-worker whose machine I just restored to factory defaults (its a laptop) and re-installed all his necessary programs.  <br><br>After giving the laptop back to him I started seeing messages sent to me over MSN Messenger from him with a link to a phishing website.<br><br>I have ran ESET online scanner which found 1 file:<br><br>C:\Documents and Settings\Administrator\Local Settings\Temp\is-O56JM.tmp\askBarSetup.exe <br>a variant of Win32/AdInstaller applicationcleaned by deleting - quarantined<br><br>I then ran Malwarebytes and it was clean:<br><br>Malwarebytes' Anti-Malware 1.37<br>Database version: 2252<br>Windows 5.1.2600 Service Pack 3<br> <br>6/9/2009 10:54:21 AM<br>mbam-log-2009-06-09 (10-54-21).txt<br> <br>Scan type: Full Scan (C:\|)<br>Objects scanned: 222025<br>Time elapsed: 1 hour(s), 0 minute(s), 28 second(s)<br> <br>Memory Processes Infected: 0<br>Memory Modules Infected: 0<br>Registry Keys Infected: 0<br>Registry Values Infected: 0<br>Registry Data Items Infected: 0<br>Folders Infected: 0<br>Files Infected: 0<br> <br>Memory Processes Infected:<br>(No malicious items detected)<br> <br>Memory Modules Infected:<br>(No malicious items detected)<br> <br>Registry Keys Infected:<br>(No malicious items detected)<br> <br>Registry Values Infected:<br>(No malicious items detected)<br> <br>Registry Data Items Infected:<br>(No malicious items detected)<br> <br>Folders Infected:<br>(No malicious items detected)<br> <br>Files Infected:<br>(No malicious items detected)<br><br>After that I ran HijackThis, and here is the log:<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 9:39:07 AM, on 6/9/2009<br>Platform: Windows XP SP3 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br>Boot mode: Normal<br> <br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe<br>C:\WINDOWS\system32\agrsmsvc.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\Program Files\Bonjour\mDNSResponder.exe<br>C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe<br>C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br>C:\Program Files\Firebird\firebird_1_5\bin\fbguard.exe<br>C:\Program Files\Firebird\firebird_1_5\bin\fbserver.exe<br>C:\Program Files\Java\jre6\bin\jqs.exe<br>C:\Program Files\McAfee\Common Framework\FrameworkService.exe<br>C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe<br>C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br>C:\WINDOWS\system32\ThpSrv.exe<br>C:\Program Files\TOSHIBA\TME3\Tmesrv31.exe<br>C:\WINDOWS\system32\TODDSrv.exe<br>C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe<br>C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\00THotkey.exe<br>C:\WINDOWS\system32\thpsrv.exe<br>C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe<br>C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\ddwmon.exe<br>C:\WINDOWS\system32\TFNF5.exe<br>C:\Program Files\Apoint2K\Apoint.exe<br>C:\WINDOWS\system32\igfxext.exe<br>C:\WINDOWS\system32\igfxsrvc.exe<br>C:\WINDOWS\RTHDCPL.EXE<br>C:\Program Files\Apoint2K\Apntex.exe<br>C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe<br>C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe<br>C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe<br>C:\Program Files\TOSHIBA\TME3\TMERzCtl.EXE<br>C:\Program Files\TOSHIBA\TAudEffect\TAudEff.exe<br>C:\Program Files\TOSHIBA\TME3\TMEEJME.EXE<br>C:\WINDOWS\system32\igfxtray.exe<br>C:\WINDOWS\system32\hkcmd.exe<br>C:\WINDOWS\system32\igfxpers.exe<br>C:\Program Files\TOSHIBA\TouchED\TouchED.exe<br>C:\WINDOWS\system32\TPSMain.exe<br>C:\Program Files\Protector Suite QL\psqltray.exe<br>C:\WINDOWS\system32\TPSBattM.exe<br>C:\Program Files\Acronis\TrueImageEchoWorkstation\TrueImageMonitor.exe<br>C:\Program Files\Acronis\TrueImageEchoWorkstation\TimounterMonitor.exe<br>C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe<br>C:\Program Files\McAfee\Common Framework\udaterui.exe<br>C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe<br>C:\Program Files\Java\jre6\bin\jusched.exe<br>C:\Program Files\McAfee\Common Framework\McTray.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe<br>C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe<br>C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br>C:\Program Files\Citrix\GoToMeeting\366\g2mstart.exe<br>C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\Program Files\Citrix\GoToMeeting\366\g2mcomm.exe<br>C:\Program Files\Citrix\GoToMeeting\366\g2mlauncher.exe<br>C:\Program Files\Windows Live\Contacts\wlcomm.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\rdpclip.exe<br>C:\WINDOWS\system32\logon.scr<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br>C:\WINDOWS\system32\wuauclt.exe<br> <br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.google.ca/" >www.google.ca/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br>O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll<br>O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll<br>O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll<br>O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll<br>O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br>O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br>O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll<br>O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll<br>O4 - HKLM\..\Run: [00THotkey] "C:\WINDOWS\system32\00THotkey.exe"<br>O4 - HKLM\..\Run: [000StTHK] "000StTHK.exe"<br>O4 - HKLM\..\Run: [ThpSrv] "C:\WINDOWS\system32\thpsrv" /logon<br>O4 - HKLM\..\Run: [TOSDCR] "TOSDCR.EXE"<br>O4 - HKLM\..\Run: [TosHKCW.exe] "C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe"<br>O4 - HKLM\..\Run: [DDWMon] C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe<br>O4 - HKLM\..\Run: [TFNF5] "TFNF5.exe"<br>O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint2K\Apoint.exe"<br>O4 - HKLM\..\Run: [RTHDCPL] "RTHDCPL.EXE"<br>O4 - HKLM\..\Run: [Alcmtr] "ALCMTR.EXE"<br>O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"<br>O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless<br>O4 - HKLM\..\Run: [TFncKy] TFncKy.exe<br>O4 - HKLM\..\Run: [TMERzCtl.EXE] "C:\Program Files\TOSHIBA\TME3\TMERzCtl.EXE" /Service<br>O4 - HKLM\..\Run: [TMESRV.EXE] "C:\Program Files\TOSHIBA\TME3\TMESRV31.EXE" /Logon<br>O4 - HKLM\..\Run: [TAudEffect] "C:\Program Files\TOSHIBA\TAudEffect\TAudEff.exe" /run<br>O4 - HKLM\..\Run: [IgfxTray] "C:\WINDOWS\system32\igfxtray.exe"<br>O4 - HKLM\..\Run: [HotKeysCmds] "C:\WINDOWS\system32\hkcmd.exe"<br>O4 - HKLM\..\Run: [Persistence] "C:\WINDOWS\system32\igfxpers.exe"<br>O4 - HKLM\..\Run: [TouchED] "C:\Program Files\TOSHIBA\TouchED\TouchED.exe"<br>O4 - HKLM\..\Run: [TPSODDCtl] "TPSODDCtl.exe"<br>O4 - HKLM\..\Run: [TPSMain] "TPSMain.exe"<br>O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup<br>O4 - HKLM\..\Run: [TrueImageMonitor.exe] "C:\Program Files\Acronis\TrueImageEchoWorkstation\TrueImageMonitor.exe"<br>O4 - HKLM\..\Run: [AcronisTimounterMonitor] "C:\Program Files\Acronis\TrueImageEchoWorkstation\TimounterMonitor.exe"<br>O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"<br>O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey<br>O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE<br>O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe"  /autorun<br>O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray<br>O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"<br>O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background<br>O4 - HKCU\..\Run: [GoToMeeting] "C:\Program Files\Citrix\GoToMeeting\366\g2mstart.exe" "/Trigger RunAtLogon"<br>O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"<br>O4 - .DEFAULT User Startup: IEHOME.LNK = C:\Documents and Settings\Default User\Local Settings\Temp\iehome.bat (User 'Default user')<br>O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?<br>O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE<br>O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200<br>O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br>O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br>O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br>O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br>O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br>O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br>O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br>O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O14 - IERESET.INF: START_PAGE_URL=http://companyweb<br>O16 - DPF: {485D813E-EE26-4DF8-9FAF-DEDF2885306E} (NSHelp Class) - &raquo;<small>https</small>://<A HREF="https://odin/connectcomputer/nshelp.dll">odin/connectcomputer/nshelp.dll</A><br>O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &raquo;<A HREF="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1244425902593" >update.microsoft.com/microsoftup&middot;&middot;&middot;25902593</A><br>O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - &raquo;<A HREF="http://download.eset.com/special/eos/OnlineScanner.cab" >download.eset.com/special/eos/On&middot;&middot;&middot;nner.cab</A><br>O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = medirex<br>O17 - HKLM\Software\..\Telephony: DomainName = medirex<br>O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = medirex<br>O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll<br>O23 - Service: Acronis Remote Agent (AcronisAgent) - Acronis - C:\Program Files\Common Files\Acronis\Agent\agent.exe<br>O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe<br>O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe<br>O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe<br>O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br>O23 - Service: FirebirdGuardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\firebird_1_5\bin\fbguard.exe<br>O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\firebird_1_5\bin\fbserver.exe<br>O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe<br>O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe<br>O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe<br>O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br>O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br>O23 - Service: TOSHIBA HDD Protection (Thpsrv) - TOSHIBA Corporation - C:\WINDOWS\system32\ThpSrv.exe<br>O23 - Service: Tmesrv3 (Tmesrv) - TOSHIBA - C:\Program Files\TOSHIBA\TME3\Tmesrv31.exe<br>O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\WINDOWS\system32\TODDSrv.exe<br>O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe<br>O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe<br>O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc.  - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe<br> <br>--<br>End of file - 15391 bytes<br><br>After all that was performed he still continues to send Messages out over Messanger live to his contacts.<br><br>I know have asked him to change his MSN password.  I'll have to wait and see if this continues.<br><br>Attached is an example of the message that he sends out to his contacts...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22521535</guid>
<pubDate>Tue, 09 Jun 2009 12:32:35 EDT</pubDate>
</item>

</channel>
</rss>
