﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Tweaks.com Forum  / Windows &amp; System Security / HiJack This Logs </title><generator>InstantForum.NET v4.1.4</generator><description>Tweaks.com Forum </description><link>http://tweaks.com/forum/</link><webMaster>forum@tweaks.com</webMaster><lastBuildDate>Sat, 04 Jul 2009 17:30:50 GMT</lastBuildDate><ttl>20</ttl><item><title>Java do I need it updated</title><link>http://tweaks.com/forum/Topic252314-29-1.aspx</link><description>I was also informed my realtek drivers are outdated, but don't know if this is the reason&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 5:13:02 PM, on 7/3/2009&lt;BR&gt;Platform: Windows Vista SP2 (WinNT 6.00.1906)&lt;BR&gt;MSIE: Internet Explorer v8.00 (8.00.6001.18702)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\Windows\system32\Dwm.exe&lt;BR&gt;C:\Windows\Explorer.EXE&lt;BR&gt;C:\Windows\system32\taskeng.exe&lt;BR&gt;C:\Program Files\Logitech\SetPoint\LBTWiz.exe&lt;BR&gt;C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe&lt;BR&gt;C:\WINDOWS\RtHDVCpl.exe&lt;BR&gt;C:\hp\support\hpsysdrv.exe&lt;BR&gt;C:\Program Files\HP\HP Software Update\hpwuSchd2.exe&lt;BR&gt;C:\Program Files\AVG\AVG8\avgtray.exe&lt;BR&gt;C:\Program Files\Java\jre6\bin\jusched.exe&lt;BR&gt;C:\Windows\system32\schtasks.exe&lt;BR&gt;C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe&lt;BR&gt;C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe&lt;BR&gt;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;BR&gt;C:\Program Files\Windows Media Player\wmpnscfg.exe&lt;BR&gt;C:\Program Files\Logitech\SetPoint\SetPoint.exe&lt;BR&gt;C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE&lt;BR&gt;C:\Program Files\Windows Mail\WinMail.exe&lt;BR&gt;C:\hp\kbd\kbd.exe&lt;BR&gt;C:\Program Files\Rhapsody\rhaphlpr.exe&lt;BR&gt;C:\Program Files\Internet Download Manager\IDMan.exe&lt;BR&gt;C:\Program Files\Internet Download Manager\IEMonitor.exe&lt;BR&gt;C:\Windows\system32\SearchFilterHost.exe&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;amp;tp=iehome&amp;amp;locale=EN_US&amp;amp;c=74&amp;amp;bd=Pavilion&amp;amp;pf=desktop"&gt;http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;amp;tp=iehome&amp;amp;locale=EN_US&amp;amp;c=74&amp;amp;bd=Pavilion&amp;amp;pf=desktop&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;amp;tp=iehome&amp;amp;locale=EN_US&amp;amp;c=74&amp;amp;bd=Pavilion&amp;amp;pf=desktop"&gt;http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;amp;tp=iehome&amp;amp;locale=EN_US&amp;amp;c=74&amp;amp;bd=Pavilion&amp;amp;pf=desktop&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = &lt;BR&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = &lt;BR&gt;R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)&lt;BR&gt;R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll&lt;BR&gt;O1 - Hosts: ::1 localhost&lt;BR&gt;O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll&lt;BR&gt;O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll&lt;BR&gt;O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll&lt;BR&gt;O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll&lt;BR&gt;O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll&lt;BR&gt;O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll&lt;BR&gt;O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll&lt;BR&gt;O2 - BHO: IconixBHOClass Class - {761233B6-F228-49E4-8F6B-668499D4E55A} - C:\Program Files\Iconix\IEAddOn\IconixBHO_41.dll&lt;BR&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;BR&gt;O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll&lt;BR&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll&lt;BR&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll&lt;BR&gt;O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll&lt;BR&gt;O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll&lt;BR&gt;O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll&lt;BR&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;BR&gt;O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.23.0\gears.dll&lt;BR&gt;O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll&lt;BR&gt;O3 - Toolbar: &amp;amp;RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll&lt;BR&gt;O3 - Toolbar: &amp;amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll&lt;BR&gt;O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll&lt;BR&gt;O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll&lt;BR&gt;O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll&lt;BR&gt;O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll&lt;BR&gt;O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll&lt;BR&gt;O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe&lt;BR&gt;O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe&lt;BR&gt;O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe&lt;BR&gt;O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE&lt;BR&gt;O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide&lt;BR&gt;O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE&lt;BR&gt;O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe&lt;BR&gt;O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe&lt;BR&gt;O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup&lt;BR&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"&lt;BR&gt;O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"&lt;BR&gt;O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe&lt;BR&gt;O4 - HKLM\..\Run: [PC Pitstop Optimize Reminder] C:\Program Files\PCPitstop\Optimize3\Reminder-Optimize3.exe&lt;BR&gt;O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe&lt;BR&gt;O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;BR&gt;O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe&lt;BR&gt;O4 - HKCU\..\Run: [Google Update] "C:\Users\ThomZen27\AppData\Local\Google\Update\GoogleUpdate.exe" /c&lt;BR&gt;O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')&lt;BR&gt;O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe&lt;BR&gt;O8 - Extra context menu item: Add to Google Photos Screensa&amp;amp;ver - res://C:\Windows\system32\GPhotos.scr/200&lt;BR&gt;O8 - Extra context menu item: Customize Menu - &lt;A href="file://C:\Program"&gt;file://C:\Program&lt;/A&gt; Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html&lt;BR&gt;O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm&lt;BR&gt;O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm&lt;BR&gt;O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm&lt;BR&gt;O8 - Extra context menu item: Fill Forms - &lt;A href="file://C:\Program"&gt;file://C:\Program&lt;/A&gt; Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html&lt;BR&gt;O8 - Extra context menu item: Lookup on Merriam Webster - &lt;A href="file://C:\Program"&gt;file://C:\Program&lt;/A&gt; Files\ieSpell\Merriam Webster.HTM&lt;BR&gt;O8 - Extra context menu item: Lookup on Wikipedia - &lt;A href="file://C:\Program"&gt;file://C:\Program&lt;/A&gt; Files\ieSpell\wikipedia.HTM&lt;BR&gt;O8 - Extra context menu item: RoboForm Toolbar - &lt;A href="file://C:\Program"&gt;file://C:\Program&lt;/A&gt; Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html&lt;BR&gt;O8 - Extra context menu item: Save Forms - &lt;A href="file://C:\Program"&gt;file://C:\Program&lt;/A&gt; Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html&lt;BR&gt;O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage&lt;BR&gt;O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.23.0\gears.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: &amp;amp;Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.23.0\gears.dll&lt;BR&gt;O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: &amp;amp;Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll&lt;BR&gt;O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - &lt;A href="file://C:\Program"&gt;file://C:\Program&lt;/A&gt; Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html&lt;BR&gt;O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - &lt;A href="file://C:\Program"&gt;file://C:\Program&lt;/A&gt; Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html&lt;BR&gt;O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - &lt;A href="file://C:\Program"&gt;file://C:\Program&lt;/A&gt; Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html&lt;BR&gt;O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - &lt;A href="file://C:\Program"&gt;file://C:\Program&lt;/A&gt; Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html&lt;BR&gt;O9 - Extra button: (no name) - {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - C:\Program Files\Iconix\IEAddOn\IconixBHO_41.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Email ID Preferences - {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - C:\Program Files\Iconix\IEAddOn\IconixBHO_41.dll&lt;BR&gt;O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - &lt;A href="file://C:\Program"&gt;file://C:\Program&lt;/A&gt; Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html&lt;BR&gt;O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - &lt;A href="file://C:\Program"&gt;file://C:\Program&lt;/A&gt; Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html&lt;BR&gt;O9 - Extra button: (no name) - {BC3F6B6D-2E49-4603-B028-7411655713F3} - C:\Program Files\Iconix\IEAddOn\IconixBHO_41.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: About Email ID - {BC3F6B6D-2E49-4603-B028-7411655713F3} - C:\Program Files\Iconix\IEAddOn\IconixBHO_41.dll&lt;BR&gt;O13 - Gopher Prefix: &lt;BR&gt;O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - &lt;A href="http://www.pcpitstop.com/betapit/PCPitStop.CAB"&gt;http://www.pcpitstop.com/betapit/PCPitStop.CAB&lt;/A&gt;&lt;BR&gt;O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - &lt;BR&gt;O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - &lt;A href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab"&gt;http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - &lt;A href="http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll"&gt;http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll&lt;/A&gt;&lt;BR&gt;O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll&lt;BR&gt;O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll&lt;BR&gt;O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll&lt;BR&gt;O20 - AppInit_DLLs: avgrsstx.dll&lt;BR&gt;O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe&lt;BR&gt;O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;BR&gt;O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe&lt;BR&gt;O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;BR&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;BR&gt;O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe&lt;BR&gt;O23 - Service: Google Update Service (gupdate1c9ab2bf150fdc4) (gupdate1c9ab2bf150fdc4) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe&lt;BR&gt;O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;BR&gt;O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe&lt;BR&gt;O23 - Service: HP Chasis Button Service (HPBtnSrv) - Unknown owner - c:\hp\HPEZBTN\HPBtnSrv.exe&lt;BR&gt;O23 - Service: Iconix Update Service (IconixService) - Unknown owner - C:\Program Files\Common Files\Iconix\IconixService.exe&lt;BR&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe&lt;BR&gt;O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe&lt;BR&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;BR&gt;O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe&lt;BR&gt;O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe&lt;BR&gt;O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe&lt;BR&gt;O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe&lt;BR&gt;O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe&lt;BR&gt;O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe&lt;BR&gt;O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe&lt;BR&gt;O23 - Service: Pure Networks Platform Service (nmservice) - Cisco Systems, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe&lt;BR&gt;O23 - Service: Performance Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe&lt;BR&gt;O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe&lt;BR&gt;O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe&lt;BR&gt;O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe&lt;BR&gt;O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe&lt;BR&gt;O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Windows\System32\nvSCPAPISvr.exe&lt;BR&gt;O23 - Service: StumbleUponUpdateService - stumbleupon.com - C:\Program Files\StumbleUpon\StumbleUponUpdateService.exe&lt;BR&gt;O23 - Service: Update Center Service (UpdateCenterService) - NVIDIA - C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe&lt;BR&gt;O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 15981 bytes&lt;BR&gt;</description><pubDate>Fri, 03 Jul 2009 17:14:52 GMT</pubDate><dc:creator>Capuchin</dc:creator></item><item><title>my internet laggs so does the puter sometimes</title><link>http://tweaks.com/forum/Topic252292-29-1.aspx</link><description>Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 7:22:09 PM, on 7/2/2009&lt;BR&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v8.00 (8.00.6001.18702)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir Desktop\sched.exe&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\Program Files\Avira\AntiVir Desktop\avguard.exe&lt;BR&gt;C:\WINDOWS\eHome\ehRecvr.exe&lt;BR&gt;C:\WINDOWS\eHome\ehSched.exe&lt;BR&gt;C:\WINDOWS\system32\PnkBstrA.exe&lt;BR&gt;C:\Program Files\Viewpoint\Common\ViewpointService.exe&lt;BR&gt;C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir Desktop\avgnt.exe&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\WINDOWS\SYSTEM32\CTXFISPI.EXE&lt;BR&gt;C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe&lt;BR&gt;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&lt;BR&gt;C:\WINDOWS\system32\wuauclt.exe&lt;BR&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;BR&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;BR&gt;C:\hijackthis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;BR&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 12.49.152.60:8080&lt;BR&gt;R3 - URLSearchHook: ToolbarURLSearchHook Class - {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files\Fast Browser Search\IE\tbhelper.dll&lt;BR&gt;O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL&lt;BR&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;BR&gt;O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll&lt;BR&gt;O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:\Program Files\SGPSA\BHO.dll&lt;BR&gt;O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll&lt;BR&gt;O3 - Toolbar: Fast Browser Search Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll&lt;BR&gt;O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"&lt;BR&gt;O4 - HKLM\..\Run: [DNS7reminder] "C:\Program Files\Nuance\NaturallySpeaking10\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\Nuance\NaturallySpeaking10\Ereg.ini&lt;BR&gt;O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000&lt;BR&gt;O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: S&amp;amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll&lt;BR&gt;O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe&lt;BR&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL&lt;BR&gt;O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Tommy\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (HKCU)&lt;BR&gt;O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Tommy\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (HKCU)&lt;BR&gt;O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - &lt;A href="http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/ZwinkyInitialSetup1.0.1.1.cab"&gt;http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/ZwinkyInitialSetup1.0.1.1.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - &lt;A href="http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab"&gt;http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - &lt;A href="http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab"&gt;http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - &lt;A href="http://lads.myspace.com/upload/MySpaceUploader1006.cab"&gt;http://lads.myspace.com/upload/MySpaceUploader1006.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - &lt;A href="http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab"&gt;http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - &lt;A href="http://download.divx.com/player/DivXBrowserPlugin.cab"&gt;http://download.divx.com/player/DivXBrowserPlugin.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &lt;A href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1236400833031"&gt;http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1236400833031&lt;/A&gt;&lt;BR&gt;O16 - DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} (Flash Casino Helper Control) - &lt;A href="https://plugins.valueactive.eu/flashax/iefax.cab"&gt;https://plugins.valueactive.eu/flashax/iefax.cab&lt;/A&gt;&lt;BR&gt;O17 - HKLM\System\CCS\Services\Tcpip\..\{62809916-A7B8-4E5E-9E79-5649E39EE571}: NameServer = 208.67.222.222,208.67.220.220&lt;BR&gt;O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL&lt;BR&gt;O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe&lt;BR&gt;O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe&lt;BR&gt;O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe&lt;BR&gt;O23 - Service: UAZ Racing 4x4 Drivers Auto Removal (pr2anrqc) (pr2anrqc) - Cenega Publishing - C:\WINDOWS\system32\pr2anrqc.exe&lt;BR&gt;O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 6583 bytes&lt;BR&gt;</description><pubDate>Thu, 02 Jul 2009 19:24:14 GMT</pubDate><dc:creator>TommyBoy82</dc:creator></item><item><title>NTLDR missing ?</title><link>http://tweaks.com/forum/Topic252293-29-1.aspx</link><description>Hi RichieUK again,&lt;br&gt;&lt;br&gt;Sorry if I put this topic on this forum but I did it becaus for a few days ago I ask you for help with my Windows XP Media Center and notice that I could not use my 2 recovery CD's. I know you move this to the right forum if it don't belongs here.&lt;br&gt;&lt;br&gt;Well it did not take long time before I had to ask you for help figure out what corse this.&lt;br&gt;&lt;br&gt;After I did a clean installation of Windows XP Home, add Avast Antivirus,Keiro Firewall, and a lot of security and safe program as, Erunt,Superspyware and a few more I then istall Microsoft Flight Simulator FSX whit some add-ons scenerys and stuff like that I did a recovery point + Erunt recoveery point I reboot my computer. Everything seams to be just find.&lt;br&gt;&lt;br&gt;Then I install Office 2007, Photoshop and reboot the system.&lt;br&gt;Then this nasty thing pop up - NTLDR missing, CTRL+ALT+DEL to restart ?&lt;br&gt;And I know that my CD's are clean from virus. I have scann all my 4 computers and HD,CD with DRWeb Curit in safe mode and it fix the few errors I had.&lt;br&gt;&lt;br&gt;I know that all my disk,backup CD,DVD were free from virus as I have scann and check them so many times and have not download anything from the net for the last 6 mounth.&lt;br&gt;&lt;br&gt;I have also done CHKDSK on all of my HD and did not see any warnings about deleting, removing and so on.&lt;br&gt;&lt;br&gt;I don't know if it is my new HD of 1 TB that are corrupt  or are to big for my mothercard or something.&lt;br&gt;&lt;br&gt;HP Pavilion&lt;br&gt;2,20 gigahertz AMD Athlon 64&lt;br&gt;256 kilobyte primary memory cache&lt;br&gt;2048 kilobyte secondary memory cache&lt;br&gt;Board: MSI AMETHYST-M 1.0&lt;br&gt;Bus Clock: 200 megahertz&lt;br&gt;BIOS: Phoenix Technologies, LTD 3.47 03/03/2006&lt;br&gt;1453,82 Gigabytes Usable Hard Drive Capacity&lt;br&gt;958,10 Gigabytes Hard Drive Free Space&lt;br&gt;3328 Megabytes Installed Memory&lt;br&gt;NVIDIA GeForce 9600 GT [Display adapter]&lt;br&gt;I have also upgrade my power unit from output=300 to 450-500 as my graphic card need it.&lt;br&gt;&lt;br&gt;How come that this NTLDR pop up and is it something I could do without reinstall everthing all over again? I have try to do a restoring point recovering but it don't help, the NTLDR are still missing.&lt;br&gt;&lt;br&gt;Right now I run Seagate HD tools to check if the HD are corrupt or something.&lt;br&gt;Hope you have a solution for this problem.&lt;br&gt;&lt;br&gt;Par&lt;br&gt;</description><pubDate>Fri, 03 Jul 2009 00:30:43 GMT</pubDate><dc:creator>FRASSE</dc:creator></item><item><title>PC Issues since 12/06/09 (including email hijack)</title><link>http://tweaks.com/forum/Topic252286-29-1.aspx</link><description>Since 12/06/09 I have had issues with my PC. Initially I received an error message on startup and shutdown, C:/Windows/System32/winSCard.dll is not designed to run on Vista or contains an error.&lt;br&gt;Username and Passwords for Yahoo and Google were not stored as required.&lt;br&gt;On 01/07/09 my yahoo email account was used to send spam email to all my contacts.&lt;br&gt;I have since changed my AV software, added additional Malware Software and followed all the instructions posted on your forum.&lt;br&gt;Any asssitance you can give would be appreciated</description><pubDate>Thu, 02 Jul 2009 15:03:10 GMT</pubDate><dc:creator>Jimbob50</dc:creator></item><item><title>Strange popsups that are new to me</title><link>http://tweaks.com/forum/Topic250821-29-1.aspx</link><description>I have read the announcement and followed the directions.&lt;br&gt;&lt;br&gt;There are some strange popups that just popup seemingly out of the clear blue. I had AskBarDis but I think I got rid of it.  Also one of my malware programs said I had FunWebProducts but I don't think it is getting rid of it.&lt;br&gt;&lt;br&gt;I haven't removed anything on the HJT page.&lt;br&gt;&lt;br&gt;I have to reboot several times a day to keep the computer working what I call properly.  Things seem to work fairly well after the reboots.&lt;br&gt;&lt;br&gt;I am running ZoneAlarm Free for my firewall.  AVG is my active antivirus scanner.  CounterSpy is my active malware scanner.  Nightly AVG, CounterSpy and SuperAntiSpyware scan my computer.  SuperAntiSpyware is not running active on my computer.  I run other virus and anti malware programs on occasion.&lt;br&gt;&lt;br&gt;However I need an expert to look things over for me.&lt;br&gt;&lt;br&gt;Thanks a bunch Ritchie.&lt;br&gt;&lt;br&gt;Jim&lt;br&gt;===&lt;br&gt;&lt;br&gt;Here are my SuperAntiSpyware and HJT logs&lt;br&gt;&lt;br&gt;SUPERAntiSpyware Scan Log&lt;br&gt;http://www.superantispyware.com&lt;br&gt;&lt;br&gt;Generated 05/03/2009 at 08:01 AM&lt;br&gt;&lt;br&gt;Application Version : 4.26.1002&lt;br&gt;&lt;br&gt;Core Rules Database Version : 3875&lt;br&gt;Trace Rules Database Version: 1823&lt;br&gt;&lt;br&gt;Scan type       : Quick Scan&lt;br&gt;Total Scan Time : 00:47:36&lt;br&gt;&lt;br&gt;Memory items scanned      : 276&lt;br&gt;Memory threats detected   : 0&lt;br&gt;Registry items scanned    : 563&lt;br&gt;Registry threats detected : 0&lt;br&gt;File items scanned        : 118305&lt;br&gt;File threats detected     : 0&lt;br&gt;==============================&lt;br&gt;&lt;br&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br&gt;Scan saved at 8:58:19 AM, on 5/3/2009&lt;br&gt;Platform: Windows Vista SP1 (WinNT 6.00.1905)&lt;br&gt;MSIE: Internet Explorer v7.00 (7.00.6001.18226)&lt;br&gt;Boot mode: Normal&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\Windows\Explorer.EXE&lt;br&gt;C:\Windows\system32\Dwm.exe&lt;br&gt;C:\Windows\system32\taskeng.exe&lt;br&gt;C:\Program Files\SPYWARE APPS\AVG Internet Security\avgtray.exe&lt;br&gt;C:\Program Files\ZoneAlarm\zlclient.exe&lt;br&gt;C:\Program Files\Java\jre6\bin\jusched.exe&lt;br&gt;C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe&lt;br&gt;C:\Program Files\SPYWARE APPS\SUPERAntiSpyware\SUPERANTISPYWARE.EXE&lt;br&gt;C:\Program Files\Windows Media Player\wmpnscfg.exe&lt;br&gt;C:\Program Files\SnagIt 9 by TechSmith\Snagit32.exe&lt;br&gt;C:\Program Files\1-Click Answers\answers.exe&lt;br&gt;C:\Program Files\MailWasher Pro by FireTrust\MailWasher.exe&lt;br&gt;C:\Program Files\SnagIt 9 by TechSmith\TSCHelp.exe&lt;br&gt;C:\PROGRA~1\1-CLIC~1\agtserv.exe&lt;br&gt;C:\Program Files\SPYWARE APPS\CounterSpy\SBAMTray.exe&lt;br&gt;C:\Program Files\SnagIt 9 by TechSmith\snagiteditor.exe&lt;br&gt;C:\hp\kbd\kbd.exe&lt;br&gt;C:\Program Files\EudoraADELPHIA\Eudora.exe&lt;br&gt;C:\Program Files\EudoraYAHOO\Eudora.exe&lt;br&gt;C:\Windows\system32\wuauclt.exe&lt;br&gt;C:\Program Files\PowerDesk\PDExplo.exe&lt;br&gt;C:\Users\JimSr\AppData\Local\Temp\RoboForm\RoboTaskBarIcon.exe&lt;br&gt;C:\Program Files\Mozilla Firefox\firefox.exe&lt;br&gt;C:\Program Files\SPYWARE APPS\HijackThis 2.0.2\HiJackThis.exe&lt;br&gt;&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://refdesk.com/&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = &lt;br&gt;R3 - URLSearchHook: (no name) - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - (no file)&lt;br&gt;R3 - URLSearchHook: Answers.com Toolbar - {6341761b-babe-406d-b0d6-8d99b81c2ee5} - C:\Program Files\Answers.com\tbAns1.dll&lt;br&gt;R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll&lt;br&gt;F2 - REG:system.ini: Shell=&lt;br&gt;O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\SnagIt 9 by TechSmith\SnagitBHO.dll&lt;br&gt;O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll&lt;br&gt;O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll&lt;br&gt;O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll&lt;br&gt;O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\SPYWARE APPS\AVG Internet Security\avgssie.dll&lt;br&gt;O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SPYWARE APPS\SpywareGuard\dlprotect.dll&lt;br&gt;O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\SPYWARE APPS\Spybot - Search &amp; Destroy\SDHelper.dll&lt;br&gt;O2 - BHO: Answers.com Toolbar - {6341761b-babe-406d-b0d6-8d99b81c2ee5} - C:\Program Files\Answers.com\tbAns1.dll&lt;br&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll&lt;br&gt;O2 - BHO: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\SPYWAR~1\AVGINT~1\AVGTOO~1.DLL&lt;br&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;br&gt;O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll&lt;br&gt;O2 - BHO: Cooliris Plug-In for Internet Explorer - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\cooliris.dll&lt;br&gt;O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\hssie\HssIE.dll&lt;br&gt;O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll&lt;br&gt;O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll&lt;br&gt;O3 - Toolbar: Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\SnagIt 9 by TechSmith\SnagitIEAddin.dll&lt;br&gt;O3 - Toolbar: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\SPYWAR~1\AVGINT~1\AVGTOO~1.DLL&lt;br&gt;O3 - Toolbar: (no name) - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - (no file)&lt;br&gt;O3 - Toolbar: Answers.com Toolbar - {6341761b-babe-406d-b0d6-8d99b81c2ee5} - C:\Program Files\Answers.com\tbAns1.dll&lt;br&gt;O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE&lt;br&gt;O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\SPYWAR~1\AVGINT~1\avgtray.exe&lt;br&gt;O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup&lt;br&gt;O4 - HKLM\..\Run: [SBAMTray] C:\Program Files\SPYWARE APPS\CounterSpy\SBAMTray.exe&lt;br&gt;O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\ZoneAlarm\zlclient.exe"&lt;br&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"&lt;br&gt;O4 - HKCU\..\Run: [TClockEx] "C:\Program Files\TClockEx\TCLOCKEX.EXE"&lt;br&gt;O4 - HKCU\..\Run: [Taskbar Shuffle] C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe&lt;br&gt;O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SPYWARE APPS\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;br&gt;O4 - HKCU\..\Run: [cdloader] "C:\Users\JimSr\AppData\Roaming\mjusbsp\cdloader2.exe" MAGICJACK&lt;br&gt;O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe&lt;br&gt;O4 - Startup: 1-Click Answers.lnk = C:\Program Files\1-Click Answers\answers.exe&lt;br&gt;O4 - Startup: MailWasherPro.lnk = C:\Program Files\MailWasher Pro by FireTrust\MailWasher.exe&lt;br&gt;O4 - Global Startup: AutorunsDisabled&lt;br&gt;O4 - Global Startup: Snagit 9.lnk = C:\Program Files\SnagIt 9 by TechSmith\Snagit32.exe&lt;br&gt;O8 - Extra context menu item: Answers... - file://C:\Program Files\1-Click Answers\Html\atiemenu.htm&lt;br&gt;O9 - Extra button: Launch Cooliris - {3437D640-C91A-458f-89F5-B9095EA4C28B} - C:\Program Files\PicLensIE\cooliris.dll&lt;br&gt;O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe&lt;br&gt;O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll&lt;br&gt;O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\SPYWARE APPS\Spybot - Search &amp; Destroy\SDHelper.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: Spybot - Search &amp;&amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\SPYWARE APPS\Spybot - Search &amp; Destroy\SDHelper.dll&lt;br&gt;O13 - Gopher Prefix: &lt;br&gt;O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab&lt;br&gt;O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab&lt;br&gt;O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab&lt;br&gt;O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} - http://www.nanoscan.com/as/cabs/ascstubie.cab&lt;br&gt;O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab&lt;br&gt;O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab&lt;br&gt;O16 - DPF: {B160422D-0A48-11D4-BD9B-00A0C9B0AB7B} (Download Class) - http://expressit.broderbund.com/plugin/Download.cab&lt;br&gt;O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab&lt;br&gt;O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab&lt;br&gt;O17 - HKLM\System\CCS\Services\Tcpip\..\{4E09D2B6-EF63-4252-83CB-3F22DB913552}: NameServer = 10.13.160.1&lt;br&gt;O17 - HKLM\System\CCS\Services\Tcpip\..\{E2777073-7B3F-427E-9E53-99430B3E5CBE}: NameServer = 68.87.69.146,68.87.78.130&lt;br&gt;O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\SPYWARE APPS\AVG Internet Security\avgpp.dll&lt;br&gt;O20 - AppInit_DLLs: avgrsstx.dll &lt;br&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SPYWARE APPS\SUPERAntiSpyware\SASWINLO.DLL&lt;br&gt;O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\SPYWAR~1\AVGINT~1\avgemc.exe&lt;br&gt;O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\SPYWAR~1\AVGINT~1\avgwdsvc.exe&lt;br&gt;O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe&lt;br&gt;O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe&lt;br&gt;O23 - Service: Hotspot Shield Helper Service (HssSrv) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe&lt;br&gt;O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE&lt;br&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe&lt;br&gt;O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe&lt;br&gt;O23 - Service: CounterSpy Antispyware (SBAMSvc) - Sunbelt Software - C:\Program Files\SPYWARE APPS\CounterSpy\SBAMSvc.exe&lt;br&gt;O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe&lt;br&gt;&lt;br&gt;--&lt;br&gt;End of file - 10226 bytes&lt;br&gt;==========================&lt;br&gt;</description><pubDate>Sun, 03 May 2009 11:25:38 GMT</pubDate><dc:creator>jimeee1931</dc:creator></item><item><title>my hijack this log (and periodic shutdowns)</title><link>http://tweaks.com/forum/Topic251771-29-1.aspx</link><description>My problem is almost exactly like this one:  http://tweaks.com/forum/Topic239577-4-1.aspx&lt;br&gt;&lt;br&gt;The problem persists though we recently installed a new video card and power supply.  We also took it in to a repair shop and the BIOS and drivers were updated, etc.&lt;br&gt;&lt;br&gt;Here is my Hijack This log:&lt;br&gt;&lt;br&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br&gt;Scan saved at 10:28:27 AM, on 6/8/2009&lt;br&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br&gt;MSIE: Internet Explorer v8.00 (8.00.6001.18702)&lt;br&gt;Boot mode: Normal&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\WINDOWS\System32\smss.exe&lt;br&gt;C:\WINDOWS\system32\winlogon.exe&lt;br&gt;C:\WINDOWS\system32\services.exe&lt;br&gt;C:\WINDOWS\system32\lsass.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\Program Files\Ahead\InCD\InCDsrv.exe&lt;br&gt;C:\WINDOWS\Explorer.EXE&lt;br&gt;C:\WINDOWS\system32\ZoneLabs\vsmon.exe&lt;br&gt;C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe&lt;br&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;br&gt;C:\Program Files\Java\jre6\bin\jqs.exe&lt;br&gt;C:\WINDOWS\system32\pctspk.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgemc.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgrsx.exe&lt;br&gt;C:\PROGRA~1\AVG\AVG8\avgnsx.exe&lt;br&gt;C:\Program Files\AVG\AVG8\avgcsrvx.exe&lt;br&gt;C:\WINDOWS\Mixer.exe&lt;br&gt;C:\WINDOWS\system32\InetCntrl\InetCntrl.exe&lt;br&gt;C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe&lt;br&gt;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&lt;br&gt;C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe&lt;br&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;br&gt;C:\Documents and Settings\User\Application Data\mjusbsp\magicJack.exe&lt;br&gt;C:\WINDOWS\system32\rundll32.exe&lt;br&gt;C:\Program Files\Mozilla Firefox\firefox.exe&lt;br&gt;C:\Program Files\Outlook Express\msimn.exe&lt;br&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;br&gt;&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/mail?.intl=us&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;br&gt;O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)&lt;br&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br&gt;O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll&lt;br&gt;O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll&lt;br&gt;O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br&gt;O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL&lt;br&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll&lt;br&gt;O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll&lt;br&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll&lt;br&gt;O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll&lt;br&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;br&gt;O2 - BHO: Bsecure Popup Blocker - {E0019445-4C1F-414D-A70E-AD80F231C584} - C:\WINDOWS\system32\InetCntrl\PopupKil\BsafeBHO.dll&lt;br&gt;O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll&lt;br&gt;O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL&lt;br&gt;O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll&lt;br&gt;O3 - Toolbar: Bsecure Popup Blocker - {E0019445-4C1F-414D-A70E-AD80F231C584} - C:\WINDOWS\system32\InetCntrl\PopupKil\BsafeBHO.dll&lt;br&gt;O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll&lt;br&gt;O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup&lt;br&gt;O4 - HKLM\..\Run: [InetCntrl] C:\WINDOWS\system32\InetCntrl\InetCntrl.exe&lt;br&gt;O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe&lt;br&gt;O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime&lt;br&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"&lt;br&gt;O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup&lt;br&gt;O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k&lt;br&gt;O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"&lt;br&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;br&gt;O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\User\Application Data\mjusbsp\cdloader2.exe" MAGICJACK&lt;br&gt;O8 - Extra context menu item: Add to Google Photos Screensa&amp;ver - res://C:\WINDOWS\system32\GPhotos.scr/200&lt;br&gt;O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000&lt;br&gt;O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe&lt;br&gt;O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)&lt;br&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)&lt;br&gt;O10 - Unknown file in Winsock LSP: inetcntrl0012.dll&lt;br&gt;O10 - Unknown file in Winsock LSP: inetcntrl0012.dll&lt;br&gt;O10 - Unknown file in Winsock LSP: inetcntrl0012.dll&lt;br&gt;O10 - Unknown file in Winsock LSP: inetcntrl0012.dll&lt;br&gt;O10 - Unknown file in Winsock LSP: inetcntrl0012.dll&lt;br&gt;O10 - Unknown file in Winsock LSP: inetcntrl0012.dll&lt;br&gt;O10 - Unknown file in Winsock LSP: inetcntrl0012.dll&lt;br&gt;O10 - Unknown file in Winsock LSP: inetcntrl0012.dll&lt;br&gt;O10 - Unknown file in Winsock LSP: inetcntrl0012.dll&lt;br&gt;O10 - Unknown file in Winsock LSP: inetcntrl0012.dll&lt;br&gt;O10 - Unknown file in Winsock LSP: inetcntrl0012.dll&lt;br&gt;O10 - Unknown file in Winsock LSP: inetcntrl0012.dll&lt;br&gt;O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab&lt;br&gt;O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204&lt;br&gt;O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll&lt;br&gt;O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll&lt;br&gt;O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL&lt;br&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;br&gt;O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll&lt;br&gt;O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br&gt;O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe&lt;br&gt;O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;br&gt;O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&lt;br&gt;O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;br&gt;O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe&lt;br&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br&gt;O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe&lt;br&gt;O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe&lt;br&gt;O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe&lt;br&gt;O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe&lt;br&gt;&lt;br&gt;--&lt;br&gt;End of file - 9215 bytes&lt;br&gt;&lt;br&gt;Thank you for your help!!&lt;br&gt;&lt;br&gt;</description><pubDate>Mon, 08 Jun 2009 09:42:41 GMT</pubDate><dc:creator>tallpines</dc:creator></item><item><title>Hijack This Log - Slow upload speeds!!</title><link>http://tweaks.com/forum/Topic252193-29-1.aspx</link><description>Hi,&lt;br&gt;&lt;br&gt;My upload speed is practically zero and i don't know why!&lt;br&gt;&lt;br&gt;Hijack This Log is:&lt;br&gt;&lt;br&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br&gt;Scan saved at 19:41:08, on 25/06/2009&lt;br&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16850)&lt;br&gt;Boot mode: Normal&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\WINDOWS\System32\smss.exe&lt;br&gt;C:\WINDOWS\system32\winlogon.exe&lt;br&gt;C:\WINDOWS\system32\services.exe&lt;br&gt;C:\WINDOWS\system32\lsass.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br&gt;C:\WINDOWS\Explorer.EXE&lt;br&gt;C:\WINDOWS\SOUNDMAN.EXE&lt;br&gt;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&lt;br&gt;C:\PROGRA~1\Lenovo\LENOVO~1\LPMGR.exe&lt;br&gt;C:\Program Files\TalkTalk\bin\sprtcmd.exe&lt;br&gt;C:\Program Files\TalkTalk Online Security\Common\FSM32.EXE&lt;br&gt;C:\Program Files\TalkTalk Online Security\Anti-Virus\fsgk32st.exe&lt;br&gt;C:\Program Files\TalkTalk Online Security\Anti-Virus\FSGK32.EXE&lt;br&gt;C:\Program Files\TalkTalk Online Security\Common\FSMA32.EXE&lt;br&gt;C:\Program Files\Java\jre6\bin\jqs.exe&lt;br&gt;C:\Program Files\TalkTalk Online Security\Common\FSMB32.EXE&lt;br&gt;C:\Program Files\TalkTalk Online Security\FSGUI\ispnews.exe&lt;br&gt;C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe&lt;br&gt;C:\Program Files\Java\jre6\bin\jusched.exe&lt;br&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;C:\Program Files\Windows Media Player\WMPNSCFG.exe&lt;br&gt;C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;br&gt;C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe&lt;br&gt;C:\Program Files\TalkTalk Online Security\Common\FCH32.EXE&lt;br&gt;C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe&lt;br&gt;C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe&lt;br&gt;C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe&lt;br&gt;c:\program files\lenovo\system update\suservice.exe&lt;br&gt;C:\Program Files\TalkTalk Online Security\Common\FAMEH32.EXE&lt;br&gt;C:\Program Files\TalkTalk Online Security\Anti-Virus\fsqh.exe&lt;br&gt;C:\Program Files\TalkTalk Online Security\FSGUI\fsguidll.exe&lt;br&gt;C:\Program Files\TalkTalk Online Security\FSAUA\program\fsaua.exe&lt;br&gt;C:\Program Files\TalkTalk Online Security\Anti-Virus\fssm32.exe&lt;br&gt;C:\Program Files\TalkTalk Online Security\FWES\Program\fsdfwd.exe&lt;br&gt;C:\Program Files\TalkTalk Online Security\FSAUA\program\fsus.exe&lt;br&gt;C:\Program Files\TalkTalk Online Security\Anti-Virus\fsav32.exe&lt;br&gt;C:\Program Files\Mozilla Firefox\firefox.exe&lt;br&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;br&gt;C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE&lt;br&gt;C:\Program Files\Trend Micro\HijackThis\abc.bat&lt;br&gt;&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.ppnba.com/en/452.html&lt;br&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br&gt;O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll&lt;br&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;br&gt;O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll&lt;br&gt;O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll&lt;br&gt;O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE&lt;br&gt;O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent&lt;br&gt;O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"&lt;br&gt;O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\Lenovo\LENOVO~1\LPMGR.exe&lt;br&gt;O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot&lt;br&gt;O4 - HKLM\..\Run: [TalkTalk] "C:\Program Files\TalkTalk\bin\sprtcmd.exe" /P TalkTalk&lt;br&gt;O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\TalkTalk Online Security\Common\FSM32.EXE" /splash&lt;br&gt;O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\TalkTalk Online Security\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW&lt;br&gt;O4 - HKLM\..\Run: [News Service] "C:\Program Files\TalkTalk Online Security\FSGUI\ispnews.exe"&lt;br&gt;O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime&lt;br&gt;O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe&lt;br&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"&lt;br&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"&lt;br&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe&lt;br&gt;O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;br&gt;O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE&lt;br&gt;O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe&lt;br&gt;O8 - Extra context menu item: &amp;Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html&lt;br&gt;O8 - Extra context menu item: &amp;Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html&lt;br&gt;O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html&lt;br&gt;O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html&lt;br&gt;O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000&lt;br&gt;O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html&lt;br&gt;O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html&lt;br&gt;O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll&lt;br&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL&lt;br&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll&lt;br&gt;O11 - Options group: [JAVA_IBM] Java (IBM)&lt;br&gt;O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com/us/en/&lt;br&gt;O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} (Egg Money Manager Digital Safe) - https://moneymanager.egg.com/Pinsafe/accounttracking.cab&lt;br&gt;O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab&lt;br&gt;O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1182442294250&lt;br&gt;O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1182442281609&lt;br&gt;O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab&lt;br&gt;O16 - DPF: {BF6BBE9A-0656-4598-A0CD-32DAC03959B5} (Image Uploader 3.0 Control) - http://www.tescophoto.com/wpp/tesco/app/opcuploader.cab&lt;br&gt;O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab&lt;br&gt;O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx&lt;br&gt;O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll&lt;br&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;br&gt;O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\TalkTalk Online Security\Anti-Virus\fsgk32st.exe&lt;br&gt;O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\TalkTalk Online Security\FSAUA\program\fsaua.exe&lt;br&gt;O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\TalkTalk Online Security\FWES\Program\fsdfwd.exe&lt;br&gt;O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\TalkTalk Online Security\Common\FSMA32.EXE&lt;br&gt;O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe&lt;br&gt;O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)&lt;br&gt;O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\program files\lenovo\system update\suservice.exe&lt;br&gt;O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe&lt;br&gt;O23 - Service: TVT Backup Service - Unknown owner - C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe&lt;br&gt;O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe&lt;br&gt;&lt;br&gt;--&lt;br&gt;End of file - 9917 bytes&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Any help would be much appreciated.&lt;br&gt;&lt;br&gt;Thanks!</description><pubDate>Thu, 25 Jun 2009 13:41:18 GMT</pubDate><dc:creator>fuggers</dc:creator></item><item><title>Everything is taking ages on my pc</title><link>http://tweaks.com/forum/Topic252164-29-1.aspx</link><description>Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 20:52:46, on 24/06/2009&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\ZoneLabs\vsmon.exe&lt;BR&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe&lt;BR&gt;C:\Program Files\Alwil Software\Avast4\ashServ.exe&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;BR&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;BR&gt;C:\Program Files\Java\jre6\bin\jqs.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe&lt;BR&gt;C:\WINDOWS\wanmpsvc.exe&lt;BR&gt;C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe&lt;BR&gt;C:\Program Files\Alwil Software\Avast4\ashWebSv.exe&lt;BR&gt;C:\WINDOWS\SOUNDMAN.EXE&lt;BR&gt;C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe&lt;BR&gt;C:\Program Files\ATI Technologies\ATI.ACE\cli.exe&lt;BR&gt;C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe&lt;BR&gt;C:\Program Files\HP\hpcoretech\hpcmpmgr.exe&lt;BR&gt;C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe&lt;BR&gt;C:\WINDOWS\system32\hphmon05.exe&lt;BR&gt;C:\Program Files\Real\RealPlayer\RealPlay.exe&lt;BR&gt;C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe&lt;BR&gt;C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe&lt;BR&gt;C:\Program Files\Common Files\AOL\1216635455\ee\AOLSoftware.exe&lt;BR&gt;C:\Program Files\Java\jre6\bin\jusched.exe&lt;BR&gt;C:\Program Files\QuickTime\QTTask.exe&lt;BR&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;BR&gt;C:\WINDOWS\PixArt\PAC7302\Monitor.exe&lt;BR&gt;C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe&lt;BR&gt;C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;BR&gt;C:\WINDOWS\system32\HPZipm12.exe&lt;BR&gt;C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe&lt;BR&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;BR&gt;C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe&lt;BR&gt;C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe&lt;BR&gt;C:\Program Files\ATI Technologies\ATI.ACE\cli.exe&lt;BR&gt;C:\Program Files\Java\jre6\bin\jucheck.exe&lt;BR&gt;C:\WINDOWS\system32\notepad.exe&lt;BR&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;BR&gt;C:\Program Files\MSN Messenger\msnmsgr.exe&lt;BR&gt;C:\Program Files\MSN Messenger\usnsvc.exe&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.yahoo.co.uk/"&gt;http://www.yahoo.co.uk/&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://www.pcservicecall.co.uk"&gt;http://www.pcservicecall.co.uk&lt;/A&gt;&lt;BR&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo! UK &amp;amp; Ireland&lt;BR&gt;R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)&lt;BR&gt;R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL&lt;BR&gt;O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll&lt;BR&gt;O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll&lt;BR&gt;O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll&lt;BR&gt;O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)&lt;BR&gt;O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL&lt;BR&gt;O2 - BHO: thechatterbox.cc Toolbar - {a1b2f3fa-dd1d-470b-a23e-a133b2f8ef60} - C:\Program Files\bigmaq\tbbig0.dll&lt;BR&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;BR&gt;O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll&lt;BR&gt;O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL&lt;BR&gt;O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll&lt;BR&gt;O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL&lt;BR&gt;O3 - Toolbar: thechatterbox.cc Toolbar - {a1b2f3fa-dd1d-470b-a23e-a133b2f8ef60} - C:\Program Files\bigmaq\tbbig0.dll&lt;BR&gt;O4 - HKLM\..\Run: [AOL_Demo] C:\Applications\Tool\AOL Demo\DSGDemo.exe&lt;BR&gt;O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE&lt;BR&gt;O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE&lt;BR&gt;O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"&lt;BR&gt;O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime&lt;BR&gt;O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe&lt;BR&gt;O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe&lt;BR&gt;O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"&lt;BR&gt;O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"&lt;BR&gt;O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe&lt;BR&gt;O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER&lt;BR&gt;O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe&lt;BR&gt;O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k&lt;BR&gt;O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe&lt;BR&gt;O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"&lt;BR&gt;O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe&lt;BR&gt;O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1216635455\ee\AOLSoftware.exe&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"&lt;BR&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"&lt;BR&gt;O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime&lt;BR&gt;O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"&lt;BR&gt;O4 - HKLM\..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe&lt;BR&gt;O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"&lt;BR&gt;O4 - HKCU\..\Run: [Power2GoExpress] "C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020&lt;BR&gt;O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;BR&gt;O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')&lt;BR&gt;O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')&lt;BR&gt;O4 - Global Startup: Catalyst System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe&lt;BR&gt;O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?&lt;BR&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000&lt;BR&gt;O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html&lt;BR&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL&lt;BR&gt;O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll&lt;BR&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O14 - IERESET.INF: START_PAGE_URL=http://www.pcservicecall.co.uk&lt;BR&gt;O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &lt;A href="http://go.microsoft.com/fwlink/?linkid=39204"&gt;http://go.microsoft.com/fwlink/?linkid=39204&lt;/A&gt;&lt;BR&gt;O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - &lt;A href="http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/MyFunCardsFWBInitialSetup1.0.0.15-3.cab"&gt;http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/MyFunCardsFWBInitialSetup1.0.0.15-3.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - &lt;A href="http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab"&gt;http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab&lt;/A&gt;&lt;BR&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;BR&gt;O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe&lt;BR&gt;O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;BR&gt;O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe&lt;BR&gt;O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe&lt;BR&gt;O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe&lt;BR&gt;O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe&lt;BR&gt;O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe&lt;BR&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;BR&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe&lt;BR&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;BR&gt;O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe&lt;BR&gt;O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe (file missing)&lt;BR&gt;O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe&lt;BR&gt;O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe&lt;BR&gt;O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe&lt;BR&gt;O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 10719 bytes&lt;/P&gt;&lt;P&gt;When i start the PC up it takes ages to go from the login screen, ages to get to anything i click on, ages before the right click dropdown menu appears......everything is at snails pace.&lt;/P&gt;&lt;P&gt;Can anyone put any light on this from the log above, thanks in advance.&lt;/P&gt;&lt;P&gt;Gus&lt;BR&gt;</description><pubDate>Wed, 24 Jun 2009 14:58:08 GMT</pubDate><dc:creator>angus1972</dc:creator></item><item><title>Suspected Virus</title><link>http://tweaks.com/forum/Topic252246-29-1.aspx</link><description>Hey guys, all of a sudden my system is largely non-responsive, e.g., WinRAR takes forever to open or doesn't open at all, and Firefox takes an unusually long time to launch. I also found csrss.exe running in Task Manager and some websites say it's a trojan. Attached is a current HiJack This log. Thanks!&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 4:12:56 PM, on 6/28/2009&lt;BR&gt;Platform: Windows Vista SP1 (WinNT 6.00.1905)&lt;BR&gt;MSIE: Internet Explorer v7.00 (7.00.6001.18248)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\Windows\system32\taskeng.exe&lt;BR&gt;C:\Windows\system32\Dwm.exe&lt;BR&gt;C:\Windows\Explorer.EXE&lt;BR&gt;C:\Program Files\Windows Defender\MSASCui.exe&lt;BR&gt;C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe&lt;BR&gt;C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe&lt;BR&gt;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&lt;BR&gt;C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe&lt;BR&gt;C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe&lt;BR&gt;C:\Program Files\Microsoft IntelliPoint\ipoint.exe&lt;BR&gt;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&lt;BR&gt;C:\Program Files\HP\HP Software Update\hpwuSchd2.exe&lt;BR&gt;C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe&lt;BR&gt;C:\Windows\System32\rundll32.exe&lt;BR&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;BR&gt;C:\Program Files\Digital Line Detect\DLG.exe&lt;BR&gt;C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe&lt;BR&gt;C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe&lt;BR&gt;C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe&lt;BR&gt;C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe&lt;BR&gt;C:\Program Files\Mozilla Firefox\firefox.exe&lt;BR&gt;C:\Windows\system32\SearchFilterHost.exe&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Users\Justin\AppData\Roaming\GTek\GTUpdate\AUpdate\Channels\ch_u2\HTML\html\blank.htm&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Users\Justin\AppData\Roaming\GTek\GTUpdate\AUpdate\Channels\ch_u2\HTML\html\blank.htm&lt;BR&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = &lt;BR&gt;O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll&lt;BR&gt;O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll&lt;BR&gt;O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll&lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll&lt;BR&gt;O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide&lt;BR&gt;O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe" /r&lt;BR&gt;O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE&lt;BR&gt;O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"&lt;BR&gt;O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start&lt;BR&gt;O4 - HKLM\..\Run: [NMSSupport] "C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" /startup&lt;BR&gt;O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup&lt;BR&gt;O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"&lt;BR&gt;O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"&lt;BR&gt;O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"&lt;BR&gt;O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe&lt;BR&gt;O4 - HKLM\..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe&lt;BR&gt;O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe&lt;BR&gt;O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup&lt;BR&gt;O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit&lt;BR&gt;O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"&lt;BR&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"&lt;BR&gt;O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')&lt;BR&gt;O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE&lt;BR&gt;O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe&lt;BR&gt;O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe&lt;BR&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll&lt;BR&gt;O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll&lt;BR&gt;O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: S&amp;amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll&lt;BR&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL&lt;BR&gt;O13 - Gopher Prefix: &lt;BR&gt;O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - &lt;A href="file:///C:/Program%20Files/SKIP-BO%20Castaway%20Caper/Images/stg_drm.ocx"&gt;file:///C:/Program%20Files/SKIP-BO%20Castaway%20Caper/Images/stg_drm.ocx&lt;/A&gt;&lt;BR&gt;O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - &lt;A href="http://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1210002419480"&gt;http://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1210002419480&lt;/A&gt;&lt;BR&gt;O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - &lt;A href="file:///C:/Program%20Files/SKIP-BO%20Castaway%20Caper/Images/armhelper.ocx"&gt;file:///C:/Program%20Files/SKIP-BO%20Castaway%20Caper/Images/armhelper.ocx&lt;/A&gt;&lt;BR&gt;O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll&lt;BR&gt;O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\r3hook.dll,C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll&lt;BR&gt;O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - (no file)&lt;BR&gt;O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe&lt;BR&gt;O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe&lt;BR&gt;O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;BR&gt;O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe&lt;BR&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;BR&gt;O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe&lt;BR&gt;O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\Windows\system32\CTsvcCDA.exe&lt;BR&gt;O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe&lt;BR&gt;O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe&lt;BR&gt;O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe&lt;BR&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe&lt;BR&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;BR&gt;O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe&lt;BR&gt;O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe&lt;BR&gt;O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe&lt;BR&gt;O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe&lt;BR&gt;O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe&lt;BR&gt;O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe&lt;BR&gt;O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe&lt;BR&gt;O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe&lt;BR&gt;O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe&lt;BR&gt;O23 - Service: Sandboxie Service (SbieSvc) - tzuk - C:\Program Files\Sandboxie\SbieSvc.exe&lt;BR&gt;O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe&lt;BR&gt;O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe&lt;BR&gt;O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 10065 bytes&lt;BR&gt;</description><pubDate>Sun, 28 Jun 2009 15:20:38 GMT</pubDate><dc:creator>MoneyAddyct</dc:creator></item><item><title>Virus from download</title><link>http://tweaks.com/forum/Topic252008-29-1.aspx</link><description>Believe I got a virus from either an MP3 or JPG download. Noticed that I couldnt access my "C" drive. Recycler/s virus changed registry value.  I changed that back but still have numerous issues.  I only post when I cant resolve it and this is a stubborn one.  Running XP and have a netgear firewall and windows firewall on. Unplugged from my network and turned off Restore. Have Symantec AV which didn't catch it before it attacked.  Ran MalwareBytes, AutoRun - Eater, ATF Cleaner and SuperAntiSpyware.  All caught and cleaned alot but not everything Virus is still active.  Ran HJT in Safe mode.  Below is a log for HJT and below that I will attach the SuperAntiSpyware Log.  Thanks for you help in advance.  &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Here is my HJT Log while in Safe Mode:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 9:54:17 AM, on 6/16/2009&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)&lt;BR&gt;Boot mode: Safe mode&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll&lt;BR&gt;O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx&lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll&lt;BR&gt;O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll&lt;BR&gt;O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize&lt;BR&gt;O4 - HKLM\..\Run: [nwiz] nwiz.exe /install&lt;BR&gt;O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe&lt;BR&gt;O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\MMKeybd.exe&lt;BR&gt;O4 - HKLM\..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe&lt;BR&gt;O4 - HKLM\..\Run: [RetroExpress] C:\PROGRA~1\Dantz\RETROS~1\RetroExpress.exe /h&lt;BR&gt;O4 - HKLM\..\Run: [MXOBG] C:\WINDOWS\MXOALDR.EXE&lt;BR&gt;O4 - HKLM\..\Run: [LiveState Recovery 3.0] C:\Program Files\Symantec\LiveState Recovery\Desktop 3.0\Agent\VProTray.exe&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"&lt;BR&gt;O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"&lt;BR&gt;O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe&lt;BR&gt;O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"&lt;BR&gt;O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime&lt;BR&gt;O4 - HKLM\..\Run: [Autorun Eater] C:\Program Files\Autorun Eater\oldmcdonald.exe&lt;BR&gt;O4 - HKLM\..\Run: [TraySantaCruz] C:\WINDOWS\system32\tbctray.exe&lt;BR&gt;O4 - S-1-5-18 Startup: Billminder.lnk = C:\QUICKENW\billmind.exe (User 'SYSTEM')&lt;BR&gt;O4 - S-1-5-18 Startup: restart_vs.lnk = D:\Viewsonic.exe (User 'SYSTEM')&lt;BR&gt;O4 - .DEFAULT Startup: Billminder.lnk = C:\QUICKENW\billmind.exe (User 'Default user')&lt;BR&gt;O4 - .DEFAULT Startup: restart_vs.lnk = D:\Viewsonic.exe (User 'Default user')&lt;BR&gt;O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe&lt;BR&gt;O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe&lt;BR&gt;O4 - Global Startup: Colorific.lnk = C:\Program Files\E-Color\Colorific\hgcctl95.exe&lt;BR&gt;O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE&lt;BR&gt;O4 - Global Startup: SonnReg.lnk = C:\Program Files\E-Color\Registration\SonnReg.exe&lt;BR&gt;O4 - Global Startup: True Internet Color Icon.lnk = C:\Program Files\E-Color\True Internet Color\TICIcon.exe&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll&lt;BR&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL&lt;BR&gt;O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe&lt;BR&gt;O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll&lt;BR&gt;O16 - DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} - &lt;A href="http://www.autodesk.com/global/dwfviewer/installer/DwfViewerSetup.cab"&gt;http://www.autodesk.com/global/dwfviewer/installer/DwfViewerSetup.cab&lt;/A&gt;&lt;BR&gt;O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = hq.fieldcomm.org&lt;BR&gt;O17 - HKLM\Software\..\Telephony: DomainName = hq.fieldcomm.org&lt;BR&gt;O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = hq.fieldcomm.org&lt;BR&gt;O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = hq.fieldcomm.org&lt;BR&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;BR&gt;O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;BR&gt;O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe&lt;BR&gt;O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe&lt;BR&gt;O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe&lt;BR&gt;O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe&lt;BR&gt;O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe&lt;BR&gt;O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe&lt;BR&gt;O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe&lt;BR&gt;O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\WINDOWS\Nhksrv.exe&lt;BR&gt;O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe&lt;BR&gt;O23 - Service: Retrospect Express HD Restore Helper (RetroExp Helper) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\rthlpsvc.exe&lt;BR&gt;O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe&lt;BR&gt;O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe&lt;BR&gt;O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe&lt;BR&gt;O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe&lt;BR&gt;O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe&lt;BR&gt;O23 - Service: Symantec LiveState Recovery - Symantec Corporation - C:\Program Files\Symantec\LiveState Recovery\Desktop 3.0\Agent\VProSvc.exe&lt;BR&gt;O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe&lt;BR&gt;O23 - Service: xdfhs3we5sejahag2hzdehwgasfq80 - Unknown owner - C:\WINDOWS\xdfhs3we5sejahag2hzdehwgasfq81.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 6920 bytes&lt;BR&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Here is my last SuperAntiSpyware Log before running HJT&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;SUPERAntiSpyware Scan Log&lt;BR&gt;&lt;A href="http://www.superantispyware.com"&gt;http://www.superantispyware.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Generated 06/15/2009 at 10:57 PM&lt;/P&gt;&lt;P&gt;Application Version : 4.26.1004&lt;/P&gt;&lt;P&gt;Core Rules Database Version : 3910&lt;BR&gt;Trace Rules Database Version: 1854&lt;/P&gt;&lt;P&gt;Scan type       : Complete Scan&lt;BR&gt;Total Scan Time : 00:38:25&lt;/P&gt;&lt;P&gt;Memory items scanned      : 230&lt;BR&gt;Memory threats detected   : 0&lt;BR&gt;Registry items scanned    : 6265&lt;BR&gt;Registry threats detected : 18&lt;BR&gt;File items scanned        : 22257&lt;BR&gt;File threats detected     : 1&lt;/P&gt;&lt;P&gt;Trojan.Agent/Gen-SOPIDKC&lt;BR&gt; HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SOPIDKC&lt;BR&gt; HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SOPIDKC#NextInstance&lt;BR&gt; HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SOPIDKC\0000&lt;BR&gt; HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SOPIDKC\0000#Service&lt;BR&gt; HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SOPIDKC\0000#Legacy&lt;BR&gt; HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SOPIDKC\0000#ConfigFlags&lt;BR&gt; HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SOPIDKC\0000#Class&lt;BR&gt; HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SOPIDKC\0000#ClassGUID&lt;BR&gt; HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SOPIDKC\0000#DeviceDesc&lt;/P&gt;&lt;P&gt;Trojan.Agent/Gen-MSNCache&lt;BR&gt; HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSNCACHE&lt;BR&gt; HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSNCACHE#NextInstance&lt;BR&gt; HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSNCACHE\0000&lt;BR&gt; HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSNCACHE\0000#Service&lt;BR&gt; HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSNCACHE\0000#Legacy&lt;BR&gt; HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSNCACHE\0000#ConfigFlags&lt;BR&gt; HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSNCACHE\0000#Class&lt;BR&gt; HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSNCACHE\0000#ClassGUID&lt;BR&gt; HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSNCACHE\0000#DeviceDesc&lt;/P&gt;&lt;P&gt;Adware.Tracking Cookie&lt;BR&gt; C:\WINDOWS\system32\config\systemprofile\Cookies\system@msnaccountservices.112.2o7[1].txt&lt;BR&gt;</description><pubDate>Tue, 16 Jun 2009 10:13:18 GMT</pubDate><dc:creator>SealFase</dc:creator></item><item><title>please take a look</title><link>http://tweaks.com/forum/Topic252214-29-1.aspx</link><description>Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 9:34:39 PM, on 2009-06-26&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir Desktop\avguard.exe&lt;BR&gt;C:\Program Files\Executive Software\Diskeeper\DkService.exe&lt;BR&gt;C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe&lt;BR&gt;C:\Program Files\Kerio\Personal Firewall2\persfw.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\Program Files\Microsoft Hardware\Keyboard\type32.exe&lt;BR&gt;C:\WINDOWS\LTMSG.exe&lt;BR&gt;C:\WINDOWS\ALCXMNTR.EXE&lt;BR&gt;C:\WINDOWS\system32\hkcmd.exe&lt;BR&gt;C:\WINDOWS\system32\igfxpers.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir Desktop\avgnt.exe&lt;BR&gt;C:\Program Files\Logitech\MouseWare\system\em_exec.exe&lt;BR&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.enter.net/"&gt;http://www.enter.net/&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;BR&gt;O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll&lt;BR&gt;O2 - BHO: Spybot-S&amp;amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll&lt;BR&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;BR&gt;O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"&lt;BR&gt;O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe&lt;BR&gt;O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7&lt;BR&gt;O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE&lt;BR&gt;O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe&lt;BR&gt;O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide&lt;BR&gt;O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe&lt;BR&gt;O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe&lt;BR&gt;O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe&lt;BR&gt;O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k&lt;BR&gt;O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll&lt;BR&gt;O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Spybot - Search &amp;amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;BR&gt;O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll&lt;BR&gt;O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &lt;A href="http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1230766459421"&gt;http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1230766459421&lt;/A&gt;&lt;BR&gt;O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - &lt;A href="http://download.eset.com/special/eos/OnlineScanner.cab"&gt;http://download.eset.com/special/eos/OnlineScanner.cab&lt;/A&gt;&lt;BR&gt;O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe&lt;BR&gt;O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe&lt;BR&gt;O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe&lt;BR&gt;O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe&lt;BR&gt;O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe&lt;BR&gt;O23 - Service: Kerio Personal Firewall (PersFw) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall2\persfw.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 4486 bytes&lt;BR&gt;</description><pubDate>Fri, 26 Jun 2009 20:36:37 GMT</pubDate><dc:creator>joey40</dc:creator></item><item><title>Can't get ride off virus killwind and MinibugTransportr.dll</title><link>http://tweaks.com/forum/Topic252145-29-1.aspx</link><description>Hi,&lt;br&gt;&lt;br&gt;I send this on a second computer because I still scanning the computer that are infected.&lt;br&gt;&lt;br&gt;I have done reinstalling of my OP system about three times from a recovery CD and this last time I start the installation from the HD D:recovery options (F10), and after doing some installation of new drivers, update and so on something start happenig, so I then reboot in safe mode and run DRWeb Curite that find Killwind.exe and MinibugTransportr.dll.&lt;br&gt;&lt;br&gt;After 1/3 of scanning it breaks and I have to start up again it also do a chkdsk by it self and then I see that a lot things that are corrupt and being deletet, then I get the message that the config.sys are missing/corrupt, so I have to start everything all over again. This happen even after a complited installation from the recovery CD, I did not get any orginal CD when I bought the computer.&lt;br&gt;&lt;br&gt;This Killwind.exe were  from 2001 ?&lt;br&gt;I have pause DRWeb and manual deleted the two file, hope this help.&lt;br&gt;&lt;br&gt;OK, after I have done scannig, what should I do ?&lt;br&gt;I have use all tools including Kaspersky free scanning so I think my computer are clean, but who knows ??&lt;br&gt;&lt;br&gt;Par</description><pubDate>Tue, 23 Jun 2009 13:37:27 GMT</pubDate><dc:creator>FRASSE</dc:creator></item><item><title>ApplesyncNotifier.exe</title><link>http://tweaks.com/forum/Topic252178-29-1.aspx</link><description>ApplesyncNotifier.exe&lt;br&gt;&lt;br&gt;This application has failed to start because corefoundation.dll was not found reinstalling the application may fix the problem. But i dont know what the application was from.&lt;br&gt;&lt;br&gt;Hijack log to see if everything looks ok now&lt;br&gt;&lt;br&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br&gt;Scan saved at 09:39:56, on 25/06/2009&lt;br&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br&gt;MSIE: Internet Explorer v8.00 (8.00.6001.18702)&lt;br&gt;Boot mode: Normal&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\WINDOWS\System32\smss.exe&lt;br&gt;C:\WINDOWS\system32\winlogon.exe&lt;br&gt;C:\WINDOWS\system32\services.exe&lt;br&gt;C:\WINDOWS\system32\lsass.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\Explorer.EXE&lt;br&gt;C:\WINDOWS\system32\LEXBCES.EXE&lt;br&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br&gt;C:\WINDOWS\system32\LEXPPS.EXE&lt;br&gt;C:\Program Files\Avira\AntiVir Desktop\sched.exe&lt;br&gt;C:\Program Files\Avira\AntiVir Desktop\avguard.exe&lt;br&gt;C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe&lt;br&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;br&gt;C:\WINDOWS\system32\drivers\CDAC11BA.EXE&lt;br&gt;C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe&lt;br&gt;C:\WINDOWS\system32\CSHelper.exe&lt;br&gt;C:\WINDOWS\system32\hasplms.exe&lt;br&gt;C:\Program Files\Kontiki\KService.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\WINDOWS\system32\dla\tfswctrl.exe&lt;br&gt;C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe&lt;br&gt;C:\WINDOWS\system32\hkcmd.exe&lt;br&gt;C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe&lt;br&gt;C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe&lt;br&gt;C:\PROGRA~1\BLUEYO~1\SMARTB~1\MotiveSB.exe&lt;br&gt;C:\Program Files\Dell\Media Experience\PCMService.exe&lt;br&gt;C:\Program Files\Analog Devices\Core\smax4pnp.exe&lt;br&gt;C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe&lt;br&gt;C:\Program Files\Avira\AntiVir Desktop\avgnt.exe&lt;br&gt;C:\Program Files\QuickTime\QTTask.exe&lt;br&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;br&gt;C:\Program Files\Virgin Broadband\advisor\Broadbandadvisor.exe&lt;br&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;br&gt;C:\Program Files\Kontiki\KHost.exe&lt;br&gt;C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe&lt;br&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;br&gt;C:\Program Files\Craft ROBO Controller\CRSSupervisor.exe&lt;br&gt;C:\Program Files\blueyonder IST\bin\mpbtn.exe&lt;br&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;br&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;br&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;br&gt;&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.google.co.uk/"&gt;http://www.google.co.uk/&lt;/A&gt;&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;br&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = &lt;A href="http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR"&gt;http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR&lt;/A&gt;&lt;br&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local&lt;br&gt;O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll&lt;br&gt;O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (file missing)&lt;br&gt;O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)&lt;br&gt;O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (file missing)&lt;br&gt;O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll&lt;br&gt;O3 - Toolbar: &amp;amp;RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll&lt;br&gt;O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll&lt;br&gt;O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe&lt;br&gt;O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"&lt;br&gt;O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe&lt;br&gt;O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe&lt;br&gt;O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe&lt;br&gt;O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"&lt;br&gt;O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\BLUEYO~1\SMARTB~1\MotiveSB.exe&lt;br&gt;O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"&lt;br&gt;O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r&lt;br&gt;O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe&lt;br&gt;O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions&lt;br&gt;O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe&lt;br&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"&lt;br&gt;O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min&lt;br&gt;O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime&lt;br&gt;O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"&lt;br&gt;O4 - HKLM\..\Run: [Broadbandadvisor.exe] "C:\Program Files\Virgin Broadband\advisor\Broadbandadvisor.exe" /AUTORUN&lt;br&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1&lt;br&gt;O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;br&gt;O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all&lt;br&gt;O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"&lt;br&gt;O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')&lt;br&gt;O4 - HKUS\S-1-5-18\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" (User 'SYSTEM')&lt;br&gt;O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')&lt;br&gt;O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')&lt;br&gt;O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')&lt;br&gt;O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe&lt;br&gt;O4 - Global Startup: blueyonder Instant Support Tool.lnk = C:\Program Files\blueyonder IST\bin\blueyonder-istconfig.exe&lt;br&gt;O4 - Global Startup: Craft ROBO Status Supervisor.lnk = C:\Program Files\Craft ROBO Controller\CRSSupervisor.exe&lt;br&gt;O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE&lt;br&gt;O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe&lt;br&gt;O8 - Extra context menu item: &amp;amp;ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM&lt;br&gt;O8 - Extra context menu item: Add to Windows &amp;amp;Live Favorites - &lt;A href="http://favorites.live.com/quickadd.aspx"&gt;http://favorites.live.com/quickadd.aspx&lt;/A&gt;&lt;br&gt;O8 - Extra context menu item: Check &amp;amp;Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM&lt;br&gt;O8 - Extra context menu item: Customize Menu - &lt;A href="file:///C:/Program"&gt;file://C:\Program&lt;/A&gt; Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html&lt;br&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000&lt;br&gt;O8 - Extra context menu item: Fill Forms - &lt;A href="file:///C:/Program"&gt;file://C:\Program&lt;/A&gt; Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html&lt;br&gt;O8 - Extra context menu item: Lookup on Merriam Webster - &lt;A href="file:///C:/Program"&gt;file://C:\Program&lt;/A&gt; Files\ieSpell\Merriam Webster.HTM&lt;br&gt;O8 - Extra context menu item: Lookup on Wikipedia - &lt;A href="file:///C:/Program"&gt;file://C:\Program&lt;/A&gt; Files\ieSpell\wikipedia.HTM&lt;br&gt;O8 - Extra context menu item: RoboForm Toolbar - &lt;A href="file:///C:/Program"&gt;file://C:\Program&lt;/A&gt; Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html&lt;br&gt;O8 - Extra context menu item: Save Forms - &lt;A href="file:///C:/Program"&gt;file://C:\Program&lt;/A&gt; Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html&lt;br&gt;O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll&lt;br&gt;O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll&lt;br&gt;O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - &lt;A href="file:///C:/Program"&gt;file://C:\Program&lt;/A&gt; Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html&lt;br&gt;O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - &lt;A href="file:///C:/Program"&gt;file://C:\Program&lt;/A&gt; Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html&lt;br&gt;O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - &lt;A href="file:///C:/Program"&gt;file://C:\Program&lt;/A&gt; Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html&lt;br&gt;O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - &lt;A href="file:///C:/Program"&gt;file://C:\Program&lt;/A&gt; Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html&lt;br&gt;O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - &lt;A href="file:///C:/Program"&gt;file://C:\Program&lt;/A&gt; Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html&lt;br&gt;O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - &lt;A href="file:///C:/Program"&gt;file://C:\Program&lt;/A&gt; Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html&lt;br&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL&lt;br&gt;O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll&lt;br&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - &lt;A href="http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab"&gt;http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab&lt;/A&gt;&lt;br&gt;O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &lt;A href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1138836207343"&gt;http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1138836207343&lt;/A&gt;&lt;br&gt;O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - &lt;A href="http://offers.e-centives.com/cif/download/bin/actxcab.cab"&gt;http://offers.e-centives.com/cif/download/bin/actxcab.cab&lt;/A&gt;&lt;br&gt;O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - &lt;A href="https://media.pineconeresearch.com/ActiveX/downloadcontrol.cab"&gt;https://media.pineconeresearch.com/ActiveX/downloadcontrol.cab&lt;/A&gt;&lt;br&gt;O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - &lt;A href="http://www.telewest.co.uk/motive/files/MotivePreQual.cab"&gt;http://www.telewest.co.uk/motive/files/MotivePreQual.cab&lt;/A&gt;&lt;br&gt;O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &lt;A href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab"&gt;http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab&lt;/A&gt;&lt;br&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL&lt;br&gt;O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe&lt;br&gt;O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe&lt;br&gt;O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe&lt;br&gt;O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;br&gt;O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE&lt;br&gt;O23 - Service: CopySafe Helper Service (CSHelper) - Unknown owner - C:\WINDOWS\system32\CSHelper.exe&lt;br&gt;O23 - Service: HASP License Manager (hasplms) - Aladdin Knowledge Systems Ltd. - C:\WINDOWS\system32\hasplms.exe&lt;br&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br&gt;O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe (file missing)&lt;br&gt;O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe&lt;br&gt;O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE&lt;br&gt;&lt;br&gt;--&lt;br&gt;End of file - 12452 bytes&lt;br&gt;</description><pubDate>Thu, 25 Jun 2009 03:40:11 GMT</pubDate><dc:creator>sharica</dc:creator></item><item><title>my pc dont feel right- my log</title><link>http://tweaks.com/forum/Topic252064-29-1.aspx</link><description>Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 22:06:36, on 18/06/2009&lt;BR&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16850)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Java\jre6\bin\jqs.exe&lt;BR&gt;C:\Program Files\Eset\nod32krn.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe&lt;BR&gt;C:\WINDOWS\system32\MsPMSPSv.exe&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe&lt;BR&gt;C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE&lt;BR&gt;C:\WINDOWS\system32\CTHELPER.EXE&lt;BR&gt;C:\Program Files\Eset\nod32kui.exe&lt;BR&gt;C:\Program Files\Java\jre6\bin\jusched.exe&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\Program Files\internet explorer\iexplore.exe&lt;BR&gt;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&lt;BR&gt;C:\Program Files\Windows Live\Contacts\wlcomm.exe&lt;BR&gt;C:\Program Files\uTorrent\uTorrent.exe&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.hotmail.com/"&gt;http://www.hotmail.com/&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://hotmail.com"&gt;http://hotmail.com&lt;/A&gt;&lt;BR&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;BR&gt;O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll&lt;BR&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;BR&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;BR&gt;O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll&lt;BR&gt;O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r&lt;BR&gt;O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL&lt;BR&gt;O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE&lt;BR&gt;O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE&lt;BR&gt;O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE&lt;BR&gt;O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE&lt;BR&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"&lt;BR&gt;O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000&lt;BR&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL&lt;BR&gt;O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)&lt;BR&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O16 - DPF: {2019DC25-D1C0-11D6-97B3-0008A124F542} (StreamPlug Class) - &lt;A href="http://www.streamplug.com/StreamPlug/SP.cab"&gt;http://www.streamplug.com/StreamPlug/SP.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - &lt;A href="http://gfx2.mail.live.com/mail/w1/resources/MSNPUpld.cab"&gt;http://gfx2.mail.live.com/mail/w1/resources/MSNPUpld.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - &lt;A href="http://upload.facebook.com/controls/FacebookPhotoUploader.cab"&gt;http://upload.facebook.com/controls/FacebookPhotoUploader.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - &lt;A href="http://download.divx.com/player/DivXBrowserPlugin.cab"&gt;http://download.divx.com/player/DivXBrowserPlugin.cab&lt;/A&gt;&lt;BR&gt;O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe&lt;BR&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe&lt;BR&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;BR&gt;O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe&lt;BR&gt;O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset  - C:\Program Files\Eset\nod32krn.exe&lt;BR&gt;O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe&lt;BR&gt;O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe&lt;BR&gt;O23 - Service: WD Drive Manager Service (WDBtnMgrSvc.exe) - WDC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 5616 bytes&lt;BR&gt;</description><pubDate>Thu, 18 Jun 2009 16:06:45 GMT</pubDate><dc:creator>R BaSS</dc:creator></item><item><title>everythings choppy here my log</title><link>http://tweaks.com/forum/Topic252075-29-1.aspx</link><description>Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 12:52:22 AM, on 6/19/2009&lt;BR&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v8.00 (8.00.6001.18702)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir Desktop\sched.exe&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir Desktop\avgnt.exe&lt;BR&gt;C:\Documents and Settings\Tommy\Desktop\Xpadder.exe&lt;BR&gt;C:\WINDOWS\SYSTEM32\CTXFISPI.EXE&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir Desktop\avguard.exe&lt;BR&gt;C:\WINDOWS\eHome\ehRecvr.exe&lt;BR&gt;C:\WINDOWS\eHome\ehSched.exe&lt;BR&gt;C:\WINDOWS\system32\PnkBstrA.exe&lt;BR&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;BR&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;BR&gt;C:\Program Files\Xfire\Xfire.exe&lt;BR&gt;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&lt;BR&gt;C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe&lt;BR&gt;C:\hijackthis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;BR&gt;O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL&lt;BR&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;BR&gt;O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll&lt;BR&gt;O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"&lt;BR&gt;O4 - HKLM\..\Run: [DNS7reminder] "C:\Program Files\Nuance\NaturallySpeaking10\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\Nuance\NaturallySpeaking10\Ereg.ini&lt;BR&gt;O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min&lt;BR&gt;O4 - HKCU\..\Run: [Xpadder] "C:\Documents and Settings\Tommy\Desktop\Xpadder.exe" /m&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000&lt;BR&gt;O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: S&amp;amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll&lt;BR&gt;O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe&lt;BR&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL&lt;BR&gt;O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Tommy\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (HKCU)&lt;BR&gt;O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Tommy\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (HKCU)&lt;BR&gt;O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - &lt;A href="http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab"&gt;http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - &lt;A href="http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab"&gt;http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - &lt;A href="http://lads.myspace.com/upload/MySpaceUploader1006.cab"&gt;http://lads.myspace.com/upload/MySpaceUploader1006.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - &lt;A href="http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab"&gt;http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - &lt;A href="http://download.divx.com/player/DivXBrowserPlugin.cab"&gt;http://download.divx.com/player/DivXBrowserPlugin.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &lt;A href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1236400833031"&gt;http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1236400833031&lt;/A&gt;&lt;BR&gt;O16 - DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} (Flash Casino Helper Control) - &lt;A href="https://plugins.valueactive.eu/flashax/iefax.cab"&gt;https://plugins.valueactive.eu/flashax/iefax.cab&lt;/A&gt;&lt;BR&gt;O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL&lt;BR&gt;O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe&lt;BR&gt;O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe&lt;BR&gt;O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 5563 bytes&lt;BR&gt;</description><pubDate>Fri, 19 Jun 2009 00:53:12 GMT</pubDate><dc:creator>TommyBoy82</dc:creator></item></channel></rss>