<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>[Trojan] HJT Log No IE7 unable to connect in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r22576564</link>
<description></description>
<language>en</language>
<pubDate>Fri, 04 Dec 2009 11:30:15 EDT</pubDate>
<lastBuildDate>Fri, 04 Dec 2009 11:30:15 EDT</lastBuildDate>

<item>
<title>Re: [Trojan] HJT Log No IE7 unable to connect</title>
<link>http://www.dslreports.com/forum/remark,22621812</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Your welcome. :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22621812</guid>
<pubDate>Sat, 27 Jun 2009 20:28:00 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] HJT Log No IE7 unable to connect</title>
<link>http://www.dslreports.com/forum/remark,22619278</link>
<description><![CDATA[<A HREF="/useremail/u/523067"><b>Attitudeda</b></A> : <div class="bquote"><small>said by  TheJoker <A HREF="/useremail/u/377471"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>I don't see anything else that needs to be removed. :)<br>Does your problem appear resolved?<br> </div>Problem is resolved. Thanks again for taking the time to help me.<br><small>--<br><b>You can out run a patrol car, but you can't beat the Motorola.</b> <br><b><A HREF="/forum/disco">Team Discovery</a></b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22619278</guid>
<pubDate>Sat, 27 Jun 2009 02:29:58 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] HJT Log No IE7 unable to connect</title>
<link>http://www.dslreports.com/forum/remark,22618009</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : I don't see anything else that needs to be removed. :)<br><br>Go to start > run and copy and paste next command in the field:<br><b>ComboFix /u</b><br><br>Make sure there's a space between Combofix and /<br>Then hit enter.<br><br>This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.<br><br>Create a <b>Restore Point</b><br>&#8226;Go to Start > Programs > Accessories > System Tools > <b>System Restore</b><br>&#8226;Select <b>Cr<u>e</u>ate a Restore Point</b> and then <b>Next</b>. <br>&#8226;In the box for "Restore point description", enter a descriptive name and press <b>Create</b><br>&#8226;When the "Restore Point Created" window appears, click <b>Close</b><br><br>Run <b>Disk Cleanup</b><br>&#8226;Go to Start > Run and type the below line:<br><b>cleanmgr</b><br>&#8226;Click <b>OK</b><br>&#8226;If you have more than one drive, select the drive Windows is installed on<br>&#8226;Click <b>OK</b><br>&#8226;When Disk Cleanup opens, select the <b>More Options</b> tab<br>&#8226;In the System Restore section (bottom of window), click <b>Cleanup</b><br>&#8226;In the confirmation window that opens, click <b>Yes</b>[<br><br>Now click on the <b>Disk Cleanup</b> tab and select the following items:<br>&#8226;Downloaded Program Files<br>&#8226;Temporary Internet Files<br>&#8226;Recycle Bin<br>&#8226;Temporary Files<br>Click <b>OK</b><br>in the confirmation window, select <b>Yes</b> (Disk Cleanup will close).<br><br>There are several free utilities you can use to help keep malware off your system: <br><br>A HOSTS file will prevent Internet Explorer from communicating with sites known to be associated with adware or spyware. A good regularly updated HOST file is MVPS HOSTS File, available at &raquo;<A HREF="http://www.mvps.org/winhelp2002/hosts.htm" >www.mvps.org/winhelp2002/hosts.htm</A>. <br><br>A free non-resident utility to prevent the installation of ActiveX-based malware is JavaCool's SpywareBlaster. For real-time protection, there is SpywareGuard. Both are available at &raquo;<A HREF="http://www.javacoolsoftware.com/products.html" >www.javacoolsoftware.com/products.html</A>. <br><br>I recommend reading Tony Klein's article <i>So How did I get Infected in the First Place?</i> at &raquo;<A HREF="http://www.spywareinfoforum.com/index.php?showtopic=60955" >www.spywareinfoforum.com/index.p&middot;&middot;&middot;ic=60955</A><br><br>Does your problem appear resolved?<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22618009</guid>
<pubDate>Fri, 26 Jun 2009 20:22:40 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] HJT Log No IE7 unable to connect</title>
<link>http://www.dslreports.com/forum/remark,22607404</link>
<description><![CDATA[<A HREF="/useremail/u/523067"><b>Attitudeda</b></A> : Thanks for all your help  The Joker <A HREF="/useremail/u/851634"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> I followed the above steps. I am unable to locate the c:\windows\system32\DF06218727.sys, also there is no ComboFix2.txt. Is there anything else thats needs to be done.<br><small>--<br><b>You can out run a patrol car, but you can't beat the Motorola.</b> <br><b><A HREF="/forum/disco">Team Discovery</a></b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22607404</guid>
<pubDate>Thu, 25 Jun 2009 07:48:07 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] HJT Log No IE7 unable to connect</title>
<link>http://www.dslreports.com/forum/remark,22600311</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : <div class="bquote"><small>said by  Attitudeda <A HREF="/useremail/u/523067"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Here are the Combofix & HJT logs as requested. Note it shows McAfee av install I can not find and traces of Mcafee Av or firewall.<br></div>Download and run the <b>McAfee Consumer Products Removal tool</b> (MCPR.exe).<br>Running the McAfee Consumer Product Removal tool (MCPR.exe) removes all 2005, 2006, and 2007 and 2008 versions of McAfee consumer products.<br>- McAfee Security Center<br>- McAfee VirusScan<br>- McAfee Personal Firewall Plus<br>- McAfee Privacy Service<br>- McAfee SpamKiller<br>- McAfee Wireless Network Security<br>- McAfee SiteAdvisor<br>- McAfee Data Backup <br>- McAfee Network Manager <br> McAfee Easy Network <br>- McAfee AntiSpyware<br><br>Download the removal tool from <br><textarea name="code" class="text" cols=50 rows=10>http://download.mcafee.com/products/licensed/cust_support_patches/MCPR.exe&#012;</textarea><!--end code block-->- Click Save and save the file to any folder on the computer. <br>- Navigate to the folder where the file is saved. <br>- Double-click <b>MCPR.exe</b>. <br><br><b>Note</b>: Windows Vista users must right-click <b>MCPR.exe</b> and select <b>Run as Administrator</b>. <br><br>- Click <b>Run</b>. A Command Line window will be displayed, and then close automatically. Wait for a second Command Line window to be displayed. <br><b>Note</b>: Do not double-click MCPR.exe again, you may have to wait up to 1 minute for the next window to appear.<br>After the second window appears, the program will begin the cleanup. <br>- Observe the installation, which could take several minutes. The following message will be displayed in the Command Line window: <br>- The machine must reboot to complete the un-installation. Reboot now? [y.n][/b]<br>- Press <b>Y</b> on the keyboard. <br>- Wait for the computer to restart.<br>All McAfee products are now removed from your computer.<br>These McAfee removal instructions can be found at &raquo;<A HREF="http://service.mcafee.com/FAQDocument.aspx?lc=1033&id=TS100507" >service.mcafee.com/FAQDocument.a&middot;&middot;&middot;TS100507</A><br><br>I also see remnants of a Symantec installation. If there are no longer Symantec products installed, also do this:<br>To fully remove Norton AntiVirus, you should go here and download the files and print the instructions for removal, and follow them after uninstalling NAV.<br>How to uninstall Norton AntiVirus 2003/2004/2005/2006/2007/2008:<br>- Vista/XP/2000 - <A HREF="http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2005033108162039?Open&docid=2005092709200113&nsf=sharedtech.nsf&view=docid">Click Here</a> <br>(note: this removes ALL Norton 2003/2004/2005/2006/2007/2008 products and and Norton 360  from your computer)<br><A HREF="http://service1.symantec.com/SUPPORT/sunset-c2002kb.nsf/docid/2001045512474266?Open&src=&docid=2001092114452606&nsf=nav.nsf&view=docid&dtype=&prod=&ver=&osv=&osv_lvl=&seg=">How to uninstall Norton AntiVirus 2000/2001/2002</a><br><br>Clear the Java Runtime Environment (JRE) cache:<br>- Click Start > Control Panel. <br>- Double-click the Java icon in the control panel. <br>-The Java Control Panel appears. <br>- Click Settings under Temporary Internet Files. <br>-The Temporary Files Settings dialog box appears.<br>- Click Delete Files. <br>-The Delete Temporary Files dialog box appears.<br>-There are two options on this window to clear the cache.<br>- Applications and Applets<br> Trace and Log Files<br>- Click OK on Delete Temporary Files window. <br>-Note: This deletes all the Downloaded Applications and Applets from the cache. <br>- Click OK on Temporary Files Settings window. <br>- Close the Java Control Panel[/list]<br>Your version of Java is outdated and needs to be updated to take advantage of fixes that have eliminated security vulnerabilities.<br><br><b>Updating Java:</b><br>- Download the latest version of  <b><A HREF="http://java.sun.com/javase/downloads/index.jsp">Java Runtime Environment (JRE) 6</a></b>.<br>- Scroll down to where it says "<i>Java SE Runtime Environment (JRE), JRE 6 Update 14</i>".<br>- Click the "<b>Download</b>" button to the right.<br>- In the Window that opens, select Windows, and check the "agree" box and click "Continue".<br>- Click on the link to download <i>Windows Offline Installation</i> and save to your desktop.<br>- Close any programs you may have running - especially your web browser.<br>- Go to <b>Start</b> > <b>Control Panel</b> double-click on <b>Add or Remove Programs</b> and remove all older versions of Java.<br>- Check any item with Java Runtime Environment (JRE or J2SE) in the name.<br>- Examples of older versions in Add or Remove Programs:<br>-- Java 2 Runtime Environment, SE v1.4.2<br>-- J2SE Runtime Environment 5.0<br>-- 2SE Runtime Environment 5.0 Update 2<br>- Click the <b>Remove</b> or <b>Change/Remove</b> button.<br>- Repeat as many times as necessary to remove each Java versions.<br>- Reboot your computer once all Java components are removed.<br>-- Delete the following folders:<br>---C:\documents and settings\Eliciel Medina\Application Data\Sun\<b>Java</b><br>---C:\Program Files\<b>Java</b><br>- Then from your desktop double-click on <b>jre-6u14-windows-i586-p.exe</b> that you downloaded to install the newest version.<br><br>Please go to <A HREF="http://www.virustotal.com">VirusTotal</a> and submit the following file for a scan and post the detection results (I don't need the "additional information") in your next reply:<br>c:\windows\system32\<b>DF06218727.sys</b><br><br>Was ComboFix run more than once. Please also post the contents of <b>ComboFix2.txt</b><br><br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22600311</guid>
<pubDate>Tue, 23 Jun 2009 22:23:04 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] HJT Log No IE7 unable to connect</title>
<link>http://www.dslreports.com/forum/remark,22595167</link>
<description><![CDATA[<A HREF="/useremail/u/523067"><b>Attitudeda</b></A> : Here are the Combofix & HJT logs as requested. Note it shows McAfee av install I can not find and traces of Mcafee Av or firewall.<br><br>ComboFix 09-06-22.08 - Eliciel Medina 06/23/2009  6:14.2 - NTFSx86<br>Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.1014.455 [GMT -4:00]<br>Running from: c:\documents and settings\Eliciel Medina\Desktop\ComboFix.exe<br>AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}<br>AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}<br>FW: McAfee Personal Firewall Plus *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}<br>.<br><br>(((((((((((((((((((((((((   Files Created from 2009-05-23 to 2009-06-23  )))))))))))))))))))))))))))))))<br>.<br><br>2009-06-23 09:52 . 2009-06-23 09:52&#9;--------&#9;d-----w-&#9;c:\windows\LastGood<br>2009-06-23 09:49 . 2009-06-23 09:49&#9;--------&#9;d-----w-&#9;c:\windows\ie8updates<br>2009-06-23 09:37 . 2009-06-23 09:37&#9;--------&#9;d-----w-&#9;c:\windows\system32\dllcache\cache<br>2009-06-23 09:22 . 2009-04-30 21:22&#9;12800&#9;------w-&#9;c:\windows\system32\dllcache\xpshims.dll<br>2009-06-23 09:22 . 2009-04-30 21:22&#9;246272&#9;------w-&#9;c:\windows\system32\dllcache\ieproxy.dll<br>2009-06-22 10:35 . 2009-06-22 10:35&#9;152576&#9;----a-w-&#9;c:\documents and settings\Eliciel Medina\Application Data\Sun\Java\jre1.6.0_13\lzma.dll<br>2009-06-22 09:54 . 2009-06-22 09:54&#9;--------&#9;d-sh--w-&#9;c:\documents and settings\Eliciel Medina\PrivacIE<br>2009-06-22 09:27 . 2009-06-22 09:27&#9;--------&#9;d-sh--w-&#9;c:\documents and settings\Eliciel Medina\IECompatCache<br>2009-06-22 09:25 . 2009-06-22 09:25&#9;--------&#9;d-sh--w-&#9;c:\documents and settings\LocalService\IETldCache<br>2009-06-22 09:25 . 2009-06-22 09:25&#9;--------&#9;d-sh--w-&#9;c:\documents and settings\Eliciel Medina\IETldCache<br>2009-06-22 09:21 . 2009-06-22 09:22&#9;--------&#9;dc-h--w-&#9;c:\windows\ie8<br>2009-06-19 12:36 . 2009-06-19 12:36&#9;--------&#9;d-----w-&#9;c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla<br>2009-06-19 11:42 . 2009-06-17 15:27&#9;38160&#9;----a-w-&#9;c:\windows\system32\drivers\mbamswissarmy.sys<br>2009-06-19 11:42 . 2009-06-17 15:27&#9;19096&#9;----a-w-&#9;c:\windows\system32\drivers\mbam.sys<br>2009-06-19 10:43 . 2009-06-19 10:43&#9;--------&#9;d-----w-&#9;c:\documents and settings\Eliciel Medina\Application Data\TrojanHunter<br>2009-06-19 09:47 . 2009-06-22 10:21&#9;--------&#9;d-----w-&#9;c:\program files\TrojanHunter 5.1<br>2009-06-19 09:30 . 2009-06-19 09:30&#9;--------&#9;d-----w-&#9;c:\documents and settings\Eliciel Medina\Local Settings\Application Data\Mozilla<br>2009-06-16 13:08 . 2009-06-16 13:08&#9;--------&#9;d-----w-&#9;c:\documents and settings\Administrator\Application Data\Malwarebytes<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2009-06-23 09:31 . 2006-05-17 15:41&#9;--------&#9;d-----w-&#9;c:\program files\Dell<br>2009-06-22 10:37 . 2006-05-17 15:37&#9;--------&#9;d-----w-&#9;c:\program files\Java<br>2009-06-19 13:00 . 2007-07-19 03:25&#9;4184&#9;--sha-w-&#9;c:\windows\system32\KGyGaAvL.sys<br>2009-06-19 13:00 . 2007-07-19 03:25&#9;88&#9;--sh--r-&#9;c:\windows\system32\27872106DF.sys<br>2009-06-19 11:53 . 2009-02-10 10:32&#9;--------&#9;d-----w-&#9;c:\program files\Malwarebytes' Anti-Malware<br>2009-06-16 16:05 . 2009-02-09 11:28&#9;--------&#9;d-----w-&#9;c:\program files\Spybot - Search & Destroy<br>2009-06-07 03:24 . 2009-03-12 14:10&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\avg8<br>2009-05-13 05:15 . 2004-08-10 16:51&#9;915456&#9;----a-w-&#9;c:\windows\system32\wininet.dll<br>2009-05-07 15:32 . 2004-08-10 16:51&#9;345600&#9;----a-w-&#9;c:\windows\system32\localspl.dll<br>2009-05-07 13:59 . 2009-05-07 13:59&#9;--------&#9;d-----w-&#9;c:\documents and settings\Eliciel Medina\Application Data\aAvgApi<br>2009-05-05 12:54 . 2009-05-05 12:54&#9;32&#9;--s-a-w-&#9;c:\windows\system32\1959676468.dat<br>2009-05-05 03:09 . 2009-03-12 14:10&#9;--------&#9;d-----w-&#9;c:\documents and settings\Eliciel Medina\Application Data\AVGTOOLBAR<br>2009-05-04 13:31 . 2009-03-12 14:11&#9;11952&#9;----a-w-&#9;c:\windows\system32\avgrsstx.dll<br>2009-05-04 13:31 . 2007-09-18 05:09&#9;27784&#9;----a-w-&#9;c:\windows\system32\drivers\avgmfx86.sys<br>2009-05-04 13:31 . 2009-03-12 14:11&#9;325896&#9;----a-w-&#9;c:\windows\system32\drivers\avgldx86.sys<br>2009-05-04 13:31 . 2009-03-12 14:11&#9;108552&#9;----a-w-&#9;c:\windows\system32\drivers\avgtdix.sys<br>2009-04-17 12:26 . 2004-08-10 16:51&#9;1847168&#9;----a-w-&#9;c:\windows\system32\win32k.sys<br>2009-04-15 14:51 . 2004-08-10 16:51&#9;585216&#9;----a-w-&#9;c:\windows\system32\rpcrt4.dll<br>2007-07-16 02:40 . 2007-07-16 02:40&#9;774144&#9;----a-w-&#9;c:\program files\RngInterstitial.dll<br>2008-11-10 14:24 . 2008-11-10 14:24&#9;56&#9;--sh--r-&#9;c:\windows\system32\DF06218727.sys<br>.<br><br>(((((((((((((((((((((((((((((   SnapShot@2009-06-23_09.36.56   )))))))))))))))))))))))))))))))))))))))))<br>.<br>+ 2009-06-23 09:50 . 2009-06-23 09:50&#9;16384              c:\windows\Temp\Perflib_Perfdata_1d8.dat<br>+ 2009-06-23 09:50 . 2009-06-23 09:50&#9;16384              c:\windows\Temp\Perflib_Perfdata_124.dat<br>+ 2009-06-23 10:01 . 2009-06-23 10:01&#9;84661              c:\windows\system32\Macromed\Flash\uninstall_plugin.exe<br>- 2004-08-10 16:51 . 2009-03-08 08:33&#9;25600              c:\windows\system32\jsproxy.dll<br>+ 2004-08-10 16:51 . 2009-04-30 21:22&#9;25600              c:\windows\system32\jsproxy.dll<br>- 2007-01-04 14:05 . 2009-03-08 08:33&#9;25600              c:\windows\system32\dllcache\jsproxy.dll<br>+ 2007-01-04 14:05 . 2009-04-30 21:22&#9;25600              c:\windows\system32\dllcache\jsproxy.dll<br>+ 2009-06-23 09:37 . 2008-10-16 19:09&#9;51224              c:\windows\system32\dllcache\cache\wuauclt.exe<br>+ 2009-06-23 09:37 . 2008-04-14 00:12&#9;82432              c:\windows\system32\dllcache\cache\ws2_32.dll<br>+ 2009-06-23 09:37 . 2008-04-14 00:12&#9;26112              c:\windows\system32\dllcache\cache\userinit.exe<br>+ 2009-06-23 09:37 . 2008-04-14 00:12&#9;14336              c:\windows\system32\dllcache\cache\svchost.exe<br>+ 2009-06-23 09:37 . 2008-04-14 00:12&#9;57856              c:\windows\system32\dllcache\cache\spoolsv.exe<br>+ 2009-06-23 09:37 . 2008-04-14 00:12&#9;17408              c:\windows\system32\dllcache\cache\powrprof.dll<br>+ 2009-06-23 09:37 . 2008-04-14 00:12&#9;13312              c:\windows\system32\dllcache\cache\lsass.exe<br>+ 2009-06-23 09:37 . 2008-04-13 18:39&#9;24576              c:\windows\system32\dllcache\cache\kbdclass.sys<br>+ 2009-06-23 09:37 . 2008-04-13 18:53&#9;36608              c:\windows\system32\dllcache\cache\ip6fw.sys<br>+ 2009-06-23 09:37 . 2008-04-14 00:12&#9;15360              c:\windows\system32\dllcache\cache\ctfmon.exe<br>+ 2009-06-23 09:49 . 2009-03-08 08:33&#9;12288              c:\windows\ie8updates\KB969897-IE8\xpshims.dll<br>+ 2009-06-23 09:49 . 2009-03-08 08:33&#9;25600              c:\windows\ie8updates\KB969897-IE8\jsproxy.dll<br>+ 2009-02-03 02:15 . 2009-02-03 02:15&#9;240544              c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe<br>+ 2004-08-10 16:51 . 2009-04-30 21:22&#9;385536              c:\windows\system32\iedkcs32.dll<br>+ 2004-08-10 16:51 . 2009-04-30 11:21&#9;173056              c:\windows\system32\ie4uinit.exe<br>- 2004-08-10 16:51 . 2009-03-08 08:32&#9;173056              c:\windows\system32\ie4uinit.exe<br>+ 2007-01-04 14:05 . 2009-05-13 05:15&#9;915456              c:\windows\system32\dllcache\wininet.dll<br>+ 2006-11-07 07:27 . 2009-04-30 21:22&#9;385536              c:\windows\system32\dllcache\iedkcs32.dll<br>- 2006-11-07 07:26 . 2009-03-08 08:32&#9;173056              c:\windows\system32\dllcache\ie4uinit.exe<br>+ 2006-11-07 07:26 . 2009-04-30 11:21&#9;173056              c:\windows\system32\dllcache\ie4uinit.exe<br>+ 2009-06-23 09:37 . 2008-04-14 00:12&#9;507904              c:\windows\system32\dllcache\cache\winlogon.exe<br>+ 2009-06-23 09:37 . 2009-03-08 08:34&#9;914944              c:\windows\system32\dllcache\cache\wininet.dll<br>+ 2009-06-23 09:37 . 2008-04-14 00:12&#9;578560              c:\windows\system32\dllcache\cache\user32.dll<br>+ 2009-06-23 09:37 . 2008-04-14 00:12&#9;295424              c:\windows\system32\dllcache\cache\termsrv.dll<br>+ 2009-06-23 09:37 . 2008-06-20 11:51&#9;361600              c:\windows\system32\dllcache\cache\tcpip.sys<br>+ 2009-06-23 09:37 . 2009-02-06 11:11&#9;110592              c:\windows\system32\dllcache\cache\services.exe<br>+ 2009-06-23 09:37 . 2008-04-13 19:20&#9;182656              c:\windows\system32\dllcache\cache\ndis.sys<br>+ 2009-06-23 09:37 . 2009-03-21 14:06&#9;989696              c:\windows\system32\dllcache\cache\kernel32.dll<br>+ 2009-06-23 09:37 . 2008-04-14 00:11&#9;110080              c:\windows\system32\dllcache\cache\imm32.dll<br>+ 2009-06-23 09:49 . 2009-03-08 08:34&#9;914944              c:\windows\ie8updates\KB969897-IE8\wininet.dll<br>+ 2009-06-23 09:49 . 2008-07-09 07:38&#9;382840              c:\windows\ie8updates\KB969897-IE8\spuninst\updspapi.dll<br>+ 2009-06-23 09:49 . 2007-11-30 12:39&#9;231288              c:\windows\ie8updates\KB969897-IE8\spuninst\spuninst.exe<br>+ 2009-06-23 09:49 . 2009-03-08 08:33&#9;246784              c:\windows\ie8updates\KB969897-IE8\ieproxy.dll<br>+ 2009-06-23 09:49 . 2009-03-08 18:09&#9;391536              c:\windows\ie8updates\KB969897-IE8\iedkcs32.dll<br>+ 2009-06-23 09:49 . 2009-03-08 08:32&#9;173056              c:\windows\ie8updates\KB969897-IE8\ie4uinit.exe<br>+ 2004-08-10 16:51 . 2009-04-30 21:22&#9;1207808              c:\windows\system32\urlmon.dll<br>+ 2004-08-10 16:51 . 2009-05-13 05:15&#9;5936128              c:\windows\system32\mshtml.dll<br>+ 2009-02-03 02:15 . 2009-02-03 02:15&#9;3771296              c:\windows\system32\Macromed\Flash\NPSWF32.dll<br>- 2006-10-17 15:57 . 2009-03-08 08:32&#9;1985024              c:\windows\system32\iertutil.dll<br>+ 2006-10-17 15:57 . 2009-04-30 21:22&#9;1985024              c:\windows\system32\iertutil.dll<br>+ 2007-01-25 12:24 . 2009-04-30 21:22&#9;1207808              c:\windows\system32\dllcache\urlmon.dll<br>+ 2007-01-04 14:05 . 2009-05-13 05:15&#9;5936128              c:\windows\system32\dllcache\mshtml.dll<br>- 2007-06-27 14:34 . 2009-03-08 08:32&#9;1985024              c:\windows\system32\dllcache\iertutil.dll<br>+ 2007-06-27 14:34 . 2009-04-30 21:22&#9;1985024              c:\windows\system32\dllcache\iertutil.dll<br>+ 2009-06-23 09:37 . 2008-04-14 00:12&#9;1614848              c:\windows\system32\dllcache\cache\sfcfiles.dll<br>+ 2009-06-23 09:37 . 2009-02-06 11:06&#9;2145280              c:\windows\system32\dllcache\cache\ntoskrnl.exe<br>+ 2009-06-23 09:37 . 2009-02-06 10:32&#9;2023936              c:\windows\system32\dllcache\cache\ntkrnlpa.exe<br>+ 2009-06-23 09:37 . 2008-04-14 00:12&#9;1033728              c:\windows\system32\dllcache\cache\explorer.exe<br>+ 2009-06-23 09:49 . 2009-03-08 08:34&#9;1206784              c:\windows\ie8updates\KB969897-IE8\urlmon.dll<br>+ 2009-06-23 09:49 . 2009-03-08 08:41&#9;5937152              c:\windows\ie8updates\KB969897-IE8\mshtml.dll<br>+ 2009-06-23 09:49 . 2009-03-08 08:32&#9;1985024              c:\windows\ie8updates\KB969897-IE8\iertutil.dll<br>+ 2006-11-08 01:03 . 2009-04-30 21:22&#9;11064832              c:\windows\system32\ieframe.dll<br>+ 2007-06-27 14:34 . 2009-04-30 21:22&#9;11064832              c:\windows\system32\dllcache\ieframe.dll<br>+ 2009-06-23 09:49 . 2009-03-08 08:39&#9;11063808              c:\windows\ie8updates\KB969897-IE8\ieframe.dll<br>.<br>-- Snapshot reset to current date --<br>.<br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]<br>"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-18 68856]<br>"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]<br>"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]<br>"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-15 94208]<br>"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-15 114688]<br>"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]<br>"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]<br>"Corel Photo Downloader"="c:\program files\Corel\Corel Photo Album 6\MediaDetect.exe" [2006-02-09 106496]<br>"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-03 1836544]<br>"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-07-10 270648]<br>"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2006-05-17 26112]<br>"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]<br>"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]<br>"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]<br>"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-15 77824]<br>"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]<br>"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-04 1947928]<br>"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]<br><br>c:\documents and settings\All Users\Start Menu\Programs\Startup\<br>Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]<br>QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]<br>2009-05-04 13:31&#9;11952&#9;----a-w-&#9;c:\windows\system32\avgrsstx.dll<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]<br>@="Service"<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"%windir%\\system32\\sessmgr.exe"=<br><br>R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/12/2009 10:11 AM 325896]<br>R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/12/2009 10:11 AM 108552]<br>R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [3/12/2009 10:10 AM 908568]<br>R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/12/2009 10:10 AM 298776]<br>R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 8:19 PM 13592]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]<br>"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP<br>.<br>Contents of the 'Scheduled Tasks' folder<br><br>2008-11-16 c:\windows\Tasks\AppleSoftwareUpdate.job<br>- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 17:42]<br><br>2007-01-05 c:\windows\Tasks\ISP signup reminder 1.job<br>- c:\windows\system32\OOBE\oobebaln.exe [2004-08-10 00:12]<br><br>2009-06-23 c:\windows\Tasks\MP Scheduled Scan.job<br>- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]<br>.<br>.<br>------- Supplementary Scan -------<br>.<br>uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8<br>uInternet Connection Wizard,ShellNext = iexplore<br>uSearchURL,(Default) = hxxp://www.google.com/search?q=%s<br>FF - ProfilePath - <br>.<br><br>**************************************************************************<br><br>catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2009-06-23 06:17<br>Windows 5.1.2600 Service Pack 3 NTFS<br><br>scanning hidden processes ...  <br><br>scanning hidden autostart entries ... <br><br>scanning hidden files ...  <br><br>scan completed successfully<br>hidden files: 0<br><br>**************************************************************************<br>.<br>--------------------- DLLs Loaded Under Running Processes ---------------------<br><br>- - - - - - - > 'explorer.exe'(1752)<br>c:\windows\system32\WININET.dll<br>c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll<br>c:\windows\system32\ieframe.dll<br>c:\windows\system32\webcheck.dll<br>c:\windows\system32\WPDShServiceObj.dll<br>c:\windows\system32\PortableDeviceTypes.dll<br>c:\windows\system32\PortableDeviceApi.dll<br>.<br>Completion time: 2009-06-23  6:19<br>ComboFix-quarantined-files.txt  2009-06-23 10:19<br>ComboFix2.txt  2009-06-23 09:38<br><br>Pre-Run: 95,258,333,184 bytes free<br>Post-Run: 95,237,541,888 bytes free<br><br>203&#9;--- E O F ---&#9;2009-06-23 09:54<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 6:24:21 AM, on 6/23/2009<br>Platform: Windows XP SP3 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>C:\WINDOWS\System32\GEARSec.exe<br>C:\Program Files\Java\jre6\bin\jqs.exe<br>C:\Program Files\Norton Ghost\Agent\VProSvc.exe<br>C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe<br>C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe<br>C:\PROGRA~1\AVG\AVG8\avgemc.exe<br>C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br>C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br>C:\Program Files\AVG\AVG8\avgcsrvx.exe<br>C:\WINDOWS\system32\igfxpers.exe<br>C:\Program Files\Dell\Media Experience\DMXLauncher.exe<br>C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br>C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\Program Files\Real\RealPlayer\RealPlay.exe<br>C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br>C:\WINDOWS\system32\hkcmd.exe<br>C:\Program Files\Java\jre6\bin\jusched.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>C:\Program Files\DellSupport\DSAgnt.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\WINDOWS\explorer.exe<br>C:\Program Files\Mozilla Firefox\firefox.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br>O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL<br>O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL<br>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll<br>O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br>O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll<br>O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL<br>O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe<br>O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe<br>O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe<br>O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br>O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe<br>O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start<br>O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup<br>O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe<br>O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"<br>O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br>O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup<br>O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1<br>O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br>O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br>O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - &raquo;<small>https</small>://<A HREF="https://markettraders.webex.com/client/T26L/event/ieatgpc.cab">markettraders.webex.com/client/T&middot;&middot;&middot;tgpc.cab</A><br>O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br>O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br>O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br>O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe<br>O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe<br>O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe<br>O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe<br>O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe<br>O23 - Service: WUSB54GCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe<br><br>--<br>End of file - 8112 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22595167</guid>
<pubDate>Tue, 23 Jun 2009 05:46:09 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] HJT Log No IE7 unable to connect</title>
<link>http://www.dslreports.com/forum/remark,22592627</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : <div class="bquote"><small>said by  Attitudeda <A HREF="/useremail/u/523067"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>I'm able to connect to the internet now.<br></div>I thought you'd be able to. :)<br><br>Download <b>ComboFix&copy; by sUBs</b> from one of these locations:<br><br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br><b>* IMPORTANT !!! Save ComboFix.exe to your Desktop</b><br><br>Familiarize yourself with ComboFix before running it:<br>&raquo;<A HREF="http://www.bleepingcomputer.com/combofix/how-to-use-combofix" >www.bleepingcomputer.com/combofi&middot;&middot;&middot;combofix</A><br><br>- Disable your AntiVirus and any AntiSpyware programs you may be running (usually via a right click on the System Tray icon) to prevent them from interfering.<br><br>- Double click on ComboFix.exe & follow the prompts.<br><br>- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal.  It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware. There are some difficult to remove infections that will only be fixed if you have the Recovery Console installed.<br><br>- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.<br><br>**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.<br><br> <IMG SRC="http://img.photobucket.com/albums/v706/ried7/RcAuto1.gif"> <br><br>Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:<br><br> <IMG SRC="http://img.photobucket.com/albums/v706/ried7/whatnext.png"> <br><br>Click on Yes, to continue scanning for malware. When finished, it will save a log. <br>Please include the contents of the log at <b>C:\ComboFix.txt</b> in your next reply along with a new HijackThis log, and note any errors encountered.<br><br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22592627</guid>
<pubDate>Mon, 22 Jun 2009 17:12:50 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] HJT Log No IE7 unable to connect</title>
<link>http://www.dslreports.com/forum/remark,22589632</link>
<description><![CDATA[<A HREF="/useremail/u/523067"><b>Attitudeda</b></A> : New HJT and MBAM logs I'm able to connect to the internet now.<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 5:53:35 AM, on 6/22/2009<br>Platform: Windows XP SP3 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>C:\WINDOWS\System32\GEARSec.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\Java\jre6\bin\jqs.exe<br>C:\Program Files\Norton Ghost\Agent\VProSvc.exe<br>C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe<br>C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe<br>C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br>C:\PROGRA~1\AVG\AVG8\avgemc.exe<br>C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br>C:\Program Files\AVG\AVG8\avgcsrvx.exe<br>C:\WINDOWS\system32\igfxpers.exe<br>C:\Program Files\Dell\Media Experience\DMXLauncher.exe<br>C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br>C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\Program Files\Real\RealPlayer\RealPlay.exe<br>C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\hkcmd.exe<br>C:\Program Files\Java\jre6\bin\jusched.exe<br>C:\Program Files\Windows Defender\MSASCui.exe<br>C:\PROGRA~1\AVG\AVG8\avgtray.exe<br>C:\Program Files\TrojanHunter 5.1\THGuard.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>C:\Program Files\Messenger\msmsgs.exe<br>C:\Program Files\DellSupport\DSAgnt.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\Program Files\Java\jre6\bin\jucheck.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54843" >go.microsoft.com/fwlink/?LinkId=54843</A><br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br>O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL<br>O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br>O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL<br>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll<br>O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br>O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll<br>O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL<br>O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe<br>O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe<br>O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe<br>O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br>O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe<br>O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start<br>O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup<br>O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"<br>O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br>O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br>O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 5.1\THGuard.exe"<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br>O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup<br>O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1<br>O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br>O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br>O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - &raquo;<small>https</small>://<A HREF="https://markettraders.webex.com/client/T26L/event/ieatgpc.cab">markettraders.webex.com/client/T&middot;&middot;&middot;tgpc.cab</A><br>O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br>O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br>O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br>O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe<br>O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe<br>O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe<br>O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe<br>O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe<br>O23 - Service: WUSB54GCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe<br><br>--<br>End of file - 8943 bytes<br><br>Malwarebytes' Anti-Malware 1.38<br>Database version: 2320<br>Windows 5.1.2600 Service Pack 3<br><br>6/22/2009 5:52:53 AM<br>mbam-log-2009-06-22 (05-52-53).txt<br><br>Scan type: Quick Scan<br>Objects scanned: 89819<br>Time elapsed: 4 minute(s), 40 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 0<br>Registry Keys Infected: 0<br>Registry Values Infected: 0<br>Registry Data Items Infected: 0<br>Folders Infected: 0<br>Files Infected: 0<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>(No malicious items detected)<br><br>Registry Keys Infected:<br>(No malicious items detected)<br><br>Registry Values Infected:<br>(No malicious items detected)<br><br>Registry Data Items Infected:<br>(No malicious items detected)<br><br>Folders Infected:<br>(No malicious items detected)<br><br>Files Infected:<br>(No malicious items detected)<br><small>--<br><b>You can out run a patrol car, but you can't beat the Motorola.</b> <br><b><A HREF="/forum/disco">Team Discovery</a></b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22589632</guid>
<pubDate>Mon, 22 Jun 2009 05:57:44 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] HJT Log No IE7 unable to connect</title>
<link>http://www.dslreports.com/forum/remark,22583674</link>
<description><![CDATA[<A HREF="/useremail/u/523067"><b>Attitudeda</b></A> : Thanks for you reply  The Joker <A HREF="/useremail/u/851634"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> I will do the above steps when I get into to work on Monday. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22583674</guid>
<pubDate>Sat, 20 Jun 2009 16:34:05 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] HJT Log No IE7 unable to connect</title>
<link>http://www.dslreports.com/forum/remark,22582474</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Hi Attitudeda<br><br>I suggest printing out each set of instructions and reading the entire post before proceeding. It will make following them easier. Please follow the directions in the order listed.<br><br>Please <b>disable your Windows Defender Real-time Protection</b> as it may interfere with the fixes that we need to make.<br><br>Open Windows Defender.<br>Click on Tools, General Settings.<br>Scroll down and uncheck Turn on real-time protection (recommended).<br>After you uncheck this, click on the Save button and close Windows Defender.<br>After all of the fixes are complete it is very important that you enable Real-time Protection again.<br><br>Clean your Cache and Cookies in IE:<br>-Close all instances of Outlook Express and Internet Explorer <br>-Go to Control Panel > Internet Options > General tab<br>-Click the "Delete Cookies" button<br>-Next to it, Click the "Delete Files" button<br>-When prompted, place a check in: "Delete all offline content", click OK<br>Clean your Cache and Cookies in Firefox (In case you also have Firefox installed):<br>Go to Tools > Options.<br>Click Privacy in the menu on the left side of the Options window.<br>Click the Clear button located to the right of each option (History, Cookies, Private Data).<br>Click OK to close the Options window<br>Alternatively, you can clear all information stored while browsing by clicking Clear All. <br>A confirmation dialog box will be shown before clearing the information.<br>Clean other Temporary files + Recycle bin<br>-Go to start > run and type: <b>cleanmgr</b> and click ok.<br>-Let it scan your system for files to remove.<br>-Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.<br>-Press OK to remove them.<br><br>Now you need to run HijackThis and click "<b>Do a system scan only</b>." Place a check next to the following entries (if they are still there):<br><br><b>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =<br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =<br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171<br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;</b><br><br>You can <b>optionally</b> check the following entry. This entry is used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out:<br><b>O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u</b><br><br>Now close all browser and other windows except for HijackThis, and click "<b>Fix Checked</b>" to have HijackThis fix the entries you checked.<br><br>Please run Notepad and copy the following text into a new file:<br><br> <blockquote><small>quote:</small><hr>sc config winmgmtstisvc start= disabled<br>sc stop winmgmtstisvc<br>sc delete winmgmtstisvc<br><hr></blockquote><br>Save the file to the desktop as <b>remove.bat</b> and make sure the "Save as type" field says "All files". Locate remove.bat on the Desktop and double-click on it to run it. A window will open and close quickley. Please note any errors encountered.<br><br>Using Windows Explorer, delete the following files/folders if still there:<br>C:\WINDOWS\system32\<b>acluiv.exe</b><br>C:\Windows\<b>fmark2.dat</b><br>C:\Program Files\<b>TinyProxy</b>  (folder)<br>C:\Program Files\<b>ProtectService</b>  (folder)<br><br>Also delete<br>C:\Windows\<b>kenny**.exe</b><br>(any .exe files in the Windows folder whose file name starts with kenny followed by some additional characters)<br><br>Go to Control Panel -> Internet Options -> Connections Tab ->Lan Settings > uncheck "use a proxy server" or reconfigure the Proxy server again if you had set it previously.<br>In Firefox in Tools Menu -> Options... -> Advanced Tab -> Network Tab -> "Settings" under Connection, and do the same thing - either click "No proxy", or reconfigure the proxy under "Manual proxy configuration" if one had been previously configured.<br><br>Restart your system<br><br>Your Malwarebytes' Anti-Malware program itself is quite outdated, along with the signatures.<br><br>Please Run Malwarebytes' Anti-Malware.<br>- Click the <b>Update</b> tab.<br>- Click Check for Updates.<br>- When an update is found, it will download and install.<br>- This will take longer than normal as it needs to update the program along with the signatures.<br>- Click the Scanner tab.<br>- Select "<b>Perform Quick Scan</b>", then click <b>Scan</b>.<br>- The scan may take some time to finish,so please be patient.<br>- When the scan is complete, click OK, then Show Results to view the results.<br>- Make sure that <b>everything is checked</b>, and click <b>Remove Selected</b>.<br>- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)<br>- The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.<br>- Copy & Paste the entire report in your next reply along with a fresh HijackThis log.<br><br>Note:<br><i>If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.<br>Click OK to either and let MBAM proceed with the disinfection process.<br>If asked to restart the computer, please do so immediately.</i><br><br>Please post a new HijackThis log, the log from MBAM, and note any errors encountered.<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22582474</guid>
<pubDate>Sat, 20 Jun 2009 10:32:03 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] HJT Log No IE7 unable to connect</title>
<link>http://www.dslreports.com/forum/remark,22576629</link>
<description><![CDATA[<A HREF="/useremail/u/523067"><b>Attitudeda</b></A> : As requested mbam Log.<br>Malwarebytes' Anti-Malware 1.33<br>Database version: 1742<br>Windows 5.1.2600 Service Pack 3<br><br>2/10/2009 5:36:40 AM<br>mbam-log-2009-02-10 (05-36-36).txt<br><br>Scan type: Quick Scan<br>Objects scanned: 53704<br>Time elapsed: 3 minute(s), 5 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 0<br>Registry Keys Infected: 35<br>Registry Values Infected: 6<br>Registry Data Items Infected: 2<br>Folders Infected: 9<br>Files Infected: 9<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>(No malicious items detected)<br><br>Registry Keys Infected:<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3aa42713-5c1e-48e2-b432-d8bf420dd31d} (Rogue.Antivirus2008) -> No action taken.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{e596df5f-4239-4d40-8367-ebadf0165917} (Rogue.Installer) -> No action taken.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{25f97eb4-1c02-45ba-ba0c-e67aace64d4a} (Adware.ToolBar) -> No action taken.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7a7f202e-af91-4889-9dd5-2fe241085cc1} (Rogue.Multiple) -> No action taken.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{faad2038-c371-473d-86f1-5b11d39c3775} (Rogue.Multiple) -> No action taken.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntivirus) -> No action taken.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> No action taken.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> No action taken.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> No action taken.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> No action taken.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{03b121e9-6152-48b5-bb38-b642b21c62bd} (Rogue.Multiple) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2eff3cf7-99c1-4c29-bc2b-68e057e22340} (Adware.MyWebSearch) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{a6573479-9075-4a65-98a6-19fd29cf7374} (Adware.MyWebSearch) -> No action taken.<br>HKEY_CLASSES_ROOT\urlsearchhook.toolbarurlsearchhook (Trojan.BHO) -> No action taken.<br>HKEY_CLASSES_ROOT\urlsearchhook.toolbarurlsearchhook.1 (Trojan.BHO) -> No action taken.<br>HKEY_CLASSES_ROOT\.exe\shellex\ContextMenuHandlers\secure_del (Rogue.SecurePCCleaner) -> No action taken.<br>HKEY_CLASSES_ROOT\.lnk\ShellEx\ContextMenuHandlers\secure_del (Rogue.SecurePCCleaner) -> No action taken.<br>HKEY_CLASSES_ROOT\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\Shell\Secure Delete (Rogue.SecurePCCleaner) -> No action taken.<br>HKEY_CLASSES_ROOT\Directory\Background\shellex\ContextMenuHandlers\secure_del (Rogue.SecurePCCleaner) -> No action taken.<br>HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\secure_del (Rogue.SecurePCCleaner) -> No action taken.<br>HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\secure_del (Rogue.SecurePCCleaner) -> No action taken.<br>HKEY_CLASSES_ROOT\exefile\shellex\ContextMenuHandlers\secure_del (Rogue.SecurePCCleaner) -> No action taken.<br>HKEY_CLASSES_ROOT\Folder\shellex\ContextMenuHandlers\secure_del (Rogue.SecurePCCleaner) -> No action taken.<br>HKEY_CLASSES_ROOT\lnkfile\shellex\ContextMenuHandlers\secure_del (Rogue.SecurePCCleaner) -> No action taken.<br>HKEY_CLASSES_ROOT\SystemFileAssociations\Directory.Audio\shellex\ContextMenuHandlers\secure_del (Rogue.SecurePCCleaner) -> No action taken.<br>HKEY_CLASSES_ROOT\SystemFileAssociations\Directory.Image\shellex\ContextMenuHandlers\secure_del (Rogue.SecurePCCleaner) -> No action taken.<br>HKEY_CLASSES_ROOT\SystemFileAssociations\Directory.Video\shellex\ContextMenuHandlers\secure_del (Rogue.SecurePCCleaner) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> No action taken.<br><br>Registry Values Infected:<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{25f97eb4-1c02-45ba-ba0c-e67aace64d4a} (Adware.ToolBar) -> No action taken.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{25f97eb4-1c02-45ba-ba0c-e67aace64d4a} (Adware.ToolBar) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{b33de756-deee-4d7a-87db-1d905ba2aa21} (Rogue.Multiple) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Products\rdomain (Rogue.PCVirusless) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Products\prodname (Rogue.PCVirusless) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Products\compname (Rogue.PCVirusless) -> No action taken.<br><br>Registry Data Items Infected:<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.<br><br>Folders Infected:<br>C:\Program Files\Common Files\PCSecureSystem (Rogue.PCSecureSystem) -> No action taken.<br>C:\GA6P1 (Rogue.Multiple) -> No action taken.<br>C:\GA6P1\Quar (Rogue.Multiple) -> No action taken.<br>C:\Program Files\Registry Defender Platinum (Rogue.RegistryDefender) -> No action taken.<br>C:\Program Files\Registry Defender Platinum\backup (Rogue.RegistryDefender) -> No action taken.<br>C:\Documents and Settings\Eliciel Medina\Application Data\PCSecureSystem (Rogue.PCSecureSystem) -> No action taken.<br>C:\Documents and Settings\Eliciel Medina\Application Data\PCSecureSystem\Logs (Rogue.PCSecureSystem) -> No action taken.<br>C:\Documents and Settings\Eliciel Medina\Application Data\Yourprivacyguard (Rogue.Yourprivacyguard) -> No action taken.<br>C:\Documents and Settings\Eliciel Medina\Application Data\Yourprivacyguard\Logs (Rogue.Yourprivacyguard) -> No action taken.<br><br>Files Infected:<br>C:\Program Files\Registry Defender Platinum\report.csv (Rogue.RegistryDefender) -> No action taken.<br>C:\Program Files\Registry Defender Platinum\backup\9_9_2008.reg (Rogue.RegistryDefender) -> No action taken.<br>C:\Documents and Settings\Eliciel Medina\Application Data\PCSecureSystem\avtasks.dat (Rogue.PCSecureSystem) -> No action taken.<br>C:\Documents and Settings\Eliciel Medina\Application Data\PCSecureSystem\Logs\av.log (Rogue.PCSecureSystem) -> No action taken.<br>C:\Documents and Settings\Eliciel Medina\Application Data\PCSecureSystem\Logs\ga6Support.log (Rogue.PCSecureSystem) -> No action taken.<br>C:\Documents and Settings\Eliciel Medina\Application Data\PCSecureSystem\Logs\update.log (Rogue.PCSecureSystem) -> No action taken.<br>C:\Documents and Settings\Eliciel Medina\Application Data\Yourprivacyguard\Logs\update.log (Rogue.Yourprivacyguard) -> No action taken.<br>C:\Documents and Settings\Eliciel Medina\Application Data\config.cfg (Malware.Trace) -> No action taken.<br>C:\Documents and Settings\Eliciel Medina\Application Data\~tmp.html (Malware.Trace) -> No action taken.<br><small>--<br><b>You can out run a patrol car, but you can't beat the Motorola.</b> <br><b><A HREF="/forum/disco">Team Discovery</a></b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22576629</guid>
<pubDate>Fri, 19 Jun 2009 07:55:41 EDT</pubDate>
</item>

<item>
<title>[Trojan] HJT Log No IE7 unable to connect</title>
<link>http://www.dslreports.com/forum/remark,22576564</link>
<description><![CDATA[<A HREF="/useremail/u/523067"><b>Attitudeda</b></A> : I'm working on a friends PC that is unable to connet to the internet using IE7 or Firefox. I've ran Spybot in safe and normal mode and removed all selected items. If I open up a comand prompt I'm able to ping yahoo & google with no packet loss. thanks for your help Here's the HJT log.<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 7:16:04 AM, on 6/19/2009<br>Platform: Windows XP SP3 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16850)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>C:\WINDOWS\System32\GEARSec.exe<br>C:\Program Files\Java\jre6\bin\jqs.exe<br>C:\Program Files\Norton Ghost\Agent\VProSvc.exe<br>C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe<br>C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\PROGRA~1\AVG\AVG8\avgemc.exe<br>C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br>C:\Program Files\AVG\AVG8\avgcsrvx.exe<br>C:\WINDOWS\system32\igfxpers.exe<br>C:\Program Files\Dell\Media Experience\DMXLauncher.exe<br>C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br>C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\Program Files\Real\RealPlayer\RealPlay.exe<br>C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br>C:\WINDOWS\system32\hkcmd.exe<br>C:\Program Files\Java\jre6\bin\jusched.exe<br>C:\Program Files\Windows Defender\MSASCui.exe<br>C:\PROGRA~1\AVG\AVG8\avgtray.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>C:\Program Files\Messenger\msmsgs.exe<br>C:\Program Files\DellSupport\DSAgnt.exe<br>C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br>C:\Program Files\TrojanHunter 5.1\THGuard.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54843" >go.microsoft.com/fwlink/?LinkId=54843</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171<br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br>O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL<br>O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br>O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL<br>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll<br>O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br>O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll<br>O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL<br>O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe<br>O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe<br>O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe<br>O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br>O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe<br>O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start<br>O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup<br>O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"<br>O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u<br>O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br>O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br>O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 5.1\THGuard.exe"<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br>O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup<br>O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1<br>O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br>O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br>O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - &raquo;<small>https</small>://<A HREF="https://markettraders.webex.com/client/T26L/event/ieatgpc.cab">markettraders.webex.com/client/T&middot;&middot;&middot;tgpc.cab</A><br>O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br>O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br>O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br>O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe<br>O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe<br>O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe<br>O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe<br>O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe<br>O23 - Service: Windows Management Instrumentation winmgmtstisvc (winmgmtstisvc) - Unknown owner - C:\WINDOWS\system32\acluiv.exe (file missing)<br>O23 - Service: WUSB54GCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe<br><br>--<br>End of file - 9391 bytes<br><small>--<br><b>You can out run a patrol car, but you can't beat the Motorola.</b> <br><b><A HREF="/forum/disco">Team Discovery</a></b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22576564</guid>
<pubDate>Fri, 19 Jun 2009 07:26:17 EDT</pubDate>
</item>

</channel>
</rss>
