﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Tweaks.com Forum  / Windows &amp; System Security / HiJack This Logs  / Slow, LAN connection not working / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>Tweaks.com Forum </description><link>http://tweaks.com/forum/</link><webMaster>forum@tweaks.com</webMaster><lastBuildDate>Sat, 04 Jul 2009 09:38:57 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: Slow, LAN connection not working</title><link>http://tweaks.com/forum/Topic239311-29-1.aspx</link><description>&lt;br&gt;If alls now ok,please do the following:&lt;br&gt;&lt;br&gt;Click on Start/Run,copy and paste [b]ComboFix /u[/b] into the 'Open:' space,then press Ok.&lt;br&gt;This will uninstall Combofix,delete its related folders and files,reset your clock settings,hide file extensions,hide the system/hidden files and resets System Restore.&lt;br&gt;&lt;br&gt;[IMG]http://img.photobucket.com/albums/v624/29wood/comu.gif[/IMG]&lt;br&gt;&lt;br&gt;&lt;br&gt;You should take the time to read and follow the information found in the links below,to help you prevent any possible future infections and stay safe and secure while online:&lt;br&gt;&lt;br&gt;[b][color="blue"]Simple and easy ways to keep your computer safe and secure on the Internet[/color][/b]:&lt;br&gt;[url]http://www.bleepingcomputer.com/tutorials/tutorial82.html[/url]&lt;br&gt;&lt;br&gt;[b][color="blue"]How to prevent Malware[/color][/b]:&lt;br&gt;[url]http://users.telenet.be/bluepatchy/miekiemoes/prevention.html[/url]&lt;br&gt;&lt;br&gt;[B][color="blue"]So how did I get infected in the first place[/color][/B]:&lt;br&gt;[URL]http://forums.spybot.info/showthread.php?t=279[/URL]&lt;br&gt;&lt;br&gt;[B][color="blue"]Malware Cleanup Programs and Preventative Procedures[/color][/B]: &lt;br&gt;[URL]http://russelltexas.com/malware/allclear.htm[/URL]&lt;br&gt;&lt;br&gt;[b][color="blue"]Hardening Windows Security - Part 1[/color][/b]:&lt;br&gt;[url]http://www.malwarehelp.org/Malware-Prevention-Hardening-Windows-Security1.html[/url]&lt;br&gt;&lt;br&gt;[b][color="blue"]Hardening Windows Security - Part 2[/color][/b]:&lt;br&gt;[url]http://www.malwarehelp.org/malware-prevention-hardening-windows-security2.html[/url]</description><pubDate>Fri, 16 May 2008 12:06:58 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Slow, LAN connection not working</title><link>http://tweaks.com/forum/Topic239311-29-1.aspx</link><description>Net connection is now working fine</description><pubDate>Fri, 16 May 2008 11:56:16 GMT</pubDate><dc:creator>khuluna</dc:creator></item><item><title>RE: Slow, LAN connection not working</title><link>http://tweaks.com/forum/Topic239311-29-1.aspx</link><description>Download [b]Dial-a-Fix [/b]from here:&lt;br&gt;[url]http://djlizard.net/software/Dial-a-fix-v0.60.0.24.zip[/url]&lt;br&gt;Transfer Dial-a-fix over to the pc without the network connection via Flash/Pen drive,floppy disk etc.&lt;br&gt;Unzip the program and launch it.&lt;br&gt;Click on 'Tools' at the bottom [Hammer icon].&lt;br&gt;Now run the following by highlighting each one,one at a time,and click 'GO' at the bottom.&lt;br&gt;[b]Flush DNS&lt;br&gt;Reinstall Windows Firewall&lt;br&gt;Reset Networking Interfaces[/b]&lt;br&gt;Exit Dial-a-fix when you've done,[b]restart your pc.[/b]&lt;br&gt;Let me know if you're now able to connect to the internet or not.</description><pubDate>Wed, 14 May 2008 18:22:46 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Slow, LAN connection not working</title><link>http://tweaks.com/forum/Topic239311-29-1.aspx</link><description>ComboFix 08-05-12.1 - KCasperStraus07 2008-05-14 14:00:28.2 - NTFSx86&lt;br&gt;Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.1248 [GMT -5:00]&lt;br&gt;Running from: D:\Desktop\ComboFix.exe&lt;br&gt; * Created a new restore point&lt;br&gt;.&lt;br&gt;&lt;br&gt;(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))&lt;br&gt;.&lt;br&gt;&lt;br&gt;C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat&lt;br&gt;C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat&lt;br&gt;C:\kmd.exe&lt;br&gt;&lt;br&gt;----- BITS: Possible infected sites -----&lt;br&gt;&lt;br&gt;hxxp://wsus2.winona.edu&lt;br&gt;.&lt;br&gt;(((((((((((((((((((((((((   Files Created from 2008-04-14 to 2008-05-14  )))))))))))))))))))))))))))))))&lt;br&gt;.&lt;br&gt;&lt;br&gt;2008-05-14 01:51 . 2008-05-14 01:51	&lt;DIR&gt;	d--------	C:\WINDOWS\LastGood&lt;br&gt;2008-05-11 14:47 . 2008-05-11 14:47	&lt;DIR&gt;	d--------	C:\Program Files\Lavasoft&lt;br&gt;2008-05-11 11:37 . 2008-05-11 11:37	&lt;DIR&gt;	d--------	C:\Documents and Settings\All Users\Application Data\TEMP&lt;br&gt;&lt;br&gt;.&lt;br&gt;((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))&lt;br&gt;.&lt;br&gt;2008-05-14 18:58	---------	d-----w	C:\Program Files\Mozilla Firefox 3 Beta 5&lt;br&gt;2008-05-14 06:45	---------	d-----w	C:\Documents and Settings\KCasperStraus07\Application Data\Skype&lt;br&gt;2008-05-14 06:36	---------	d-----w	C:\Documents and Settings\KCasperStraus07\Application Data\skypePM&lt;br&gt;2008-05-14 05:15	---------	d-----w	C:\Program Files\Symantec AntiVirus&lt;br&gt;2008-05-14 04:52	---------	d-----w	C:\Program Files\Steam&lt;br&gt;2008-05-12 17:59	---------	d--h--w	C:\Program Files\InstallShield Installation Information&lt;br&gt;2008-05-12 17:59	---------	d-----w	C:\Program Files\Pixia&lt;br&gt;2008-05-11 19:47	---------	d-----w	C:\Documents and Settings\All Users\Application Data\Lavasoft&lt;br&gt;2008-05-11 19:46	---------	d-----w	C:\Program Files\Common Files\Wise Installation Wizard&lt;br&gt;2008-05-11 16:37	---------	d-----w	C:\Program Files\SpywareBlaster&lt;br&gt;2008-05-11 16:30	---------	d-----w	C:\Program Files\SUPERAntiSpyware&lt;br&gt;2008-05-10 23:08	---------	d-----w	C:\Program Files\Yahoo!&lt;br&gt;2008-05-05 21:14	---------	d-----w	C:\Documents and Settings\KCasperStraus07\Application Data\.purple&lt;br&gt;2008-04-24 22:41	---------	d-----w	C:\Documents and Settings\KCasperStraus07\Application Data\gtk-2.0&lt;br&gt;2008-04-11 07:02	---------	d-----w	C:\Documents and Settings\All Users\Application Data\Microsoft Help&lt;br&gt;2008-04-09 00:36	---------	d-----w	C:\Program Files\Zune Explorer Enabler&lt;br&gt;2008-04-08 01:29	---------	d-----w	C:\Program Files\MozBackup&lt;br&gt;2008-03-29 01:29	---------	d-----w	C:\Program Files\Azureus&lt;br&gt;2008-03-29 01:29	---------	d-----w	C:\Documents and Settings\KCasperStraus07\Application Data\Azureus&lt;br&gt;2008-03-29 01:25	---------	d-----w	C:\Documents and Settings\All Users\Application Data\Azureus&lt;br&gt;2008-03-23 02:31	66,872	----a-w	C:\WINDOWS\system32\PnkBstrA.exe&lt;br&gt;2008-03-19 09:47	1,845,248	----a-w	C:\WINDOWS\system32\win32k.sys&lt;br&gt;2008-03-19 05:29	---------	d-----w	C:\Program Files\Furcadia&lt;br&gt;2008-03-19 05:29	---------	d-----w	C:\Documents and Settings\All Users\Application Data\Dragon's Eye Productions&lt;br&gt;2008-02-20 06:51	282,624	----a-w	C:\WINDOWS\system32\gdi32.dll&lt;br&gt;2008-02-20 05:32	45,568	----a-w	C:\WINDOWS\system32\dnsrslvr.dll&lt;br&gt;2008-02-14 05:18	0	----a-r	C:\logwmemory.bin&lt;br&gt;2007-12-23 01:09	32	----a-w	C:\Documents and Settings\All Users\Application Data\ezsid.dat&lt;br&gt;1999-07-07 00:00	6	--sh--r	C:\WINDOWS\@@desktop@@.dat&lt;br&gt;.&lt;br&gt;&lt;br&gt;(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))&lt;br&gt;.&lt;br&gt;.&lt;br&gt;*Note* empty entries &amp; legit default entries are not shown &lt;br&gt;REGEDIT4&lt;br&gt;&lt;br&gt;[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;br&gt;"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]&lt;br&gt;"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 15:06 1318912]&lt;br&gt;"Power2GoExpress"="NA" []&lt;br&gt;"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 21:05 204288]&lt;br&gt;"BitComet"="C:\Program Files\BitLord\BitLord.exe" [2005-05-06 19:47 2224128]&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;br&gt;"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]&lt;br&gt;"WheelMouse"="Amoumain.exe" []&lt;br&gt;"TabletWizard"="C:\WINDOWS\help\SplshWrp.exe" [2004-08-04 07:00 16384]&lt;br&gt;"TabletTip"="C:\Program Files\Common Files\microsoft shared\ink\tabtip.exe" [2005-04-25 22:10 271872]&lt;br&gt;"SigmatelSysTrayApp"="stsystra.exe" [2006-02-13 01:23 282624 C:\WINDOWS\stsystra.exe]&lt;br&gt;"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 07:00 59392]&lt;br&gt;"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 07:00 208952]&lt;br&gt;"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-04 07:00 44032]&lt;br&gt;"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-10-12 12:30 139264]&lt;br&gt;"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 08:00 33648]&lt;br&gt;"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-09-27 20:33 125168]&lt;br&gt;"VirtualDrive"="D:\Data\Programs and junk\FarStone\VirtualDrive\VDTask.exe" [2002-08-13 02:00 86016]&lt;br&gt;"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-05 07:47 98394]&lt;br&gt;"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-05 07:47 688218]&lt;br&gt;"SMSERIAL"="sm56hlpr.exe" [2006-01-19 21:34 544768 C:\WINDOWS\sm56hlpr.exe]&lt;br&gt;"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 07:00 455168]&lt;br&gt;"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 07:00 455168]&lt;br&gt;"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-15 14:11 267048]&lt;br&gt;"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 19:26 52896]&lt;br&gt;"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 07:00 158208]&lt;br&gt;&lt;br&gt;[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]&lt;br&gt;"TabletWizard"="%windir%\help\wizard.hta" [ ]&lt;br&gt;&lt;br&gt;C:\Documents and Settings\KCasperStraus07\Start Menu\Programs\Startup\&lt;br&gt;OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2007-08-24 05:45:42 101784]&lt;br&gt;Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe [2007-10-29 20:53:00 3450608]&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]&lt;br&gt;"NoWelcomeScreen"= 1 (0x1)&lt;br&gt;&lt;br&gt;[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]&lt;br&gt;"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 14:55 77824]&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]&lt;br&gt;C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 14:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\loginkey]&lt;br&gt;C:\Program Files\Common Files\Microsoft Shared\Ink\loginkey.dll 2004-08-04 07:00 47104 C:\Program Files\Common Files\Microsoft Shared\Ink\LoginKey.dll&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\TabBtnWL]&lt;br&gt;TabBtnWL.dll 2002-08-29 03:41 11776 C:\WINDOWS\system32\tabbtnwl.dll&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpgwlnotify]&lt;br&gt;tpgwlnot.dll 2006-11-01 09:18 32256 C:\WINDOWS\system32\tpgwlnot.dll&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]&lt;br&gt;C:\PROGRA~1\Stardock\OBJECT~2\WINDOW~1\fastload.dll 2001-12-20 23:34 24576 C:\PROGRA~1\Stardock\OBJECT~2\WINDOW~1\fastload.dll&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]&lt;br&gt;"AppInit_DLLs"=wbsys.dll&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]&lt;br&gt;"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\[u]0[/u]\[u]0[/u]]&lt;br&gt;"Script"=Domain_Admins.bat&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\1\[u]0[/u]]&lt;br&gt;"Script"=Laptop_Admins.bat&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\2\[u]0[/u]]&lt;br&gt;"Script"=serial_getter.vbs&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2103014626-253708085-441284377-136947\Scripts\Logon\[u]0[/u]\[u]0[/u]]&lt;br&gt;"Script"=loscript.vbe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]&lt;br&gt;--a------ 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet]&lt;br&gt;--a------ 2005-05-06 19:47 2224128 C:\Program Files\BitLord\BitLord.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Media Codec Update Service]&lt;br&gt;--a------ 2007-04-08 11:44 303104 C:\Program Files\Essentials Codec Pack\update.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]&lt;br&gt;--a------ 2007-11-15 00:43 286720 C:\Program Files\QuickTime\QTTask.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]&lt;br&gt;--a------ 2008-03-28 19:50 1271032 c:\program files\steam\steam.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vcdplayx]&lt;br&gt;--a------ 2002-08-13 02:00 57344 C:\WINDOWS\vcdplayx.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher]&lt;br&gt;--a------ 2007-11-06 20:09 166304 C:\Program Files\Zune\ZuneLauncher.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]&lt;br&gt;"ZuneWlanCfgSvc"=3 (0x3)&lt;br&gt;"ZuneNetworkSvc"=3 (0x3)&lt;br&gt;"ZuneBusEnum"=2 (0x2)&lt;br&gt;"TapiSrv"=3 (0x3)&lt;br&gt;"Symantec AntiVirus"=2 (0x2)&lt;br&gt;"Spooler"=2 (0x2)&lt;br&gt;"SNDSrvc"=3 (0x3)&lt;br&gt;"seclogon"=2 (0x2)&lt;br&gt;"Schedule"=2 (0x2)&lt;br&gt;"RemoteRegistry"=2 (0x2)&lt;br&gt;"RDSessMgr"=3 (0x3)&lt;br&gt;"RasMan"=2 (0x2)&lt;br&gt;"RasAuto"=2 (0x2)&lt;br&gt;"PnkBstrA"=2 (0x2)&lt;br&gt;"ose"=3 (0x3)&lt;br&gt;"odserv"=3 (0x3)&lt;br&gt;"lanmanserver"=2 (0x2)&lt;br&gt;"iPod Service"=3 (0x3)&lt;br&gt;"helpsvc"=2 (0x2)&lt;br&gt;"ERSvc"=2 (0x2)&lt;br&gt;"CiSvc"=3 (0x3)&lt;br&gt;"Apple Mobile Device"=2 (0x2)&lt;br&gt;"Adobe LM Service"=3 (0x3)&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]&lt;br&gt;"DisableMonitoring"=dword:00000001&lt;br&gt;&lt;br&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]&lt;br&gt;"C:\\Program Files\\BitLord\\BitLord.exe"=&lt;br&gt;"D:\\Data\\Gaming junk\\soldat\\Soldat.exe"=&lt;br&gt;"C:\\Program Files\\iTunes\\iTunes.exe"=&lt;br&gt;"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=&lt;br&gt;"C:\\Program Files\\Pidgin\\pidgin.exe"=&lt;br&gt;"C:\\Program Files\\Skype\\Phone\\Skype.exe"=&lt;br&gt;&lt;br&gt;R1 cdawdm;CDAWDM;C:\WINDOWS\system32\DRIVERS\CDAWDM.sys [2002-08-13 02:00]&lt;br&gt;R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2007-11-06 19:58]&lt;br&gt;R3 FinePnt;FinePoint Innovations HID Driver;C:\WINDOWS\system32\DRIVERS\FpHidDrv.sys [2006-10-30 11:17]&lt;br&gt;R3 MSTabBtn;Quanta Computer Tablet PC Buttons HID Driver;C:\WINDOWS\system32\DRIVERS\MSTabBtn.sys [2007-03-09 10:40]&lt;br&gt;S3 SmartCd;SmartCd;C:\WINDOWS\system32\Drivers\SmartCd.sys [2002-08-13 02:00]&lt;br&gt;S4 ZuneBusEnum;Zune Bus Enumerator;C:\WINDOWS\system32\ZuneBusEnum.exe [2007-11-06 20:09]&lt;br&gt;S4 ZuneWlanCfgSvc;Zune Wireless Configuration Service;C:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2007-11-06 20:10]&lt;br&gt;&lt;br&gt;*Newly Created Service* - CATCHME&lt;br&gt;.&lt;br&gt;Contents of the 'Scheduled Tasks' folder&lt;br&gt;"2007-10-25 14:39:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"&lt;br&gt;- C:\Program Files\Apple Software Update\SoftwareUpdate.exe&lt;br&gt;"2007-10-04 03:00:00 C:\WINDOWS\Tasks\defrag_drives.job"&lt;br&gt;- C:\WINDOWS\defrag_drives.bat&lt;br&gt;.&lt;br&gt;**************************************************************************&lt;br&gt;&lt;br&gt;catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net&lt;br&gt;Rootkit scan 2008-05-14 14:02:07&lt;br&gt;Windows 5.1.2600 Service Pack 2 NTFS&lt;br&gt;&lt;br&gt;scanning hidden processes ... &lt;br&gt;&lt;br&gt;scanning hidden autostart entries ...&lt;br&gt;&lt;br&gt;scanning hidden files ... &lt;br&gt;&lt;br&gt;scan completed successfully&lt;br&gt;hidden files: 0&lt;br&gt;&lt;br&gt;**************************************************************************&lt;br&gt;.&lt;br&gt;Completion time: 2008-05-14 14:03:06&lt;br&gt;ComboFix-quarantined-files.txt  2008-05-14 19:02:49&lt;br&gt;ComboFix2.txt  2008-02-11 18:09:55&lt;br&gt;&lt;br&gt;Pre-Run: 7,600,697,344 bytes free&lt;br&gt;Post-Run: 7,586,607,104 bytes free&lt;br&gt;&lt;br&gt;192	--- E O F ---	2008-05-14 07:01:53&lt;br&gt;&lt;br&gt;&lt;br&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br&gt;Scan saved at 14:04, on 2008-05-14&lt;br&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br&gt;MSIE: Internet Explorer v7.00 (7.00.5730.0011)&lt;br&gt;Boot mode: Normal&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\WINDOWS\System32\smss.exe&lt;br&gt;C:\WINDOWS\system32\winlogon.exe&lt;br&gt;C:\WINDOWS\system32\services.exe&lt;br&gt;C:\WINDOWS\system32\lsass.exe&lt;br&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe&lt;br&gt;C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe&lt;br&gt;C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe&lt;br&gt;C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;br&gt;C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe&lt;br&gt;C:\Program Files\Symantec AntiVirus\DefWatch.exe&lt;br&gt;C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe&lt;br&gt;C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE&lt;br&gt;C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS&lt;br&gt;C:\Program Files\Symantec AntiVirus\SavRoam.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;br&gt;C:\Program Files\Common Files\Microsoft Shared\Ink\KeyboardSurrogate.exe&lt;br&gt;C:\WINDOWS\SYSTEM32\WISPTIS.EXE&lt;br&gt;C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe&lt;br&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;C:\Program Files\Common Files\Microsoft Shared\Ink\TCServer.exe&lt;br&gt;C:\WINDOWS\System32\tabbtnu.exe&lt;br&gt;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE&lt;br&gt;C:\Program Files\GE\97769 Dual Scroll Optical Mouse\Amoumain.exe&lt;br&gt;C:\WINDOWS\stsystra.exe&lt;br&gt;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe&lt;br&gt;C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe&lt;br&gt;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&lt;br&gt;C:\PROGRA~1\SYMANT~1\VPTray.exe&lt;br&gt;C:\Program Files\Common Files\Microsoft Shared\Ink\TabTip.exe&lt;br&gt;C:\Program Files\Synaptics\SynTP\SynTPLpr.exe&lt;br&gt;C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;br&gt;C:\WINDOWS\sm56hlpr.exe&lt;br&gt;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&lt;br&gt;C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;br&gt;C:\Program Files\BitLord\BitLord.exe&lt;br&gt;C:\Program Files\Stardock\ObjectDock\ObjectDock.exe&lt;br&gt;C:\WINDOWS\explorer.exe&lt;br&gt;C:\Program Files\Mozilla Firefox 3 Beta 5\firefox.exe&lt;br&gt;D:\Data\Random Junk\HiJackThis.exe&lt;br&gt;&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.winona.edu/links.htm&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;br&gt;R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)&lt;br&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br&gt;O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll&lt;br&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll&lt;br&gt;O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&lt;br&gt;O4 - HKLM\..\Run: [WheelMouse] Amoumain.exe&lt;br&gt;O4 - HKLM\..\Run: [TabletWizard] C:\WINDOWS\help\SplshWrp.exe&lt;br&gt;O4 - HKLM\..\Run: [TabletTip] "C:\Program Files\Common Files\microsoft shared\ink\tabtip.exe" /resume&lt;br&gt;O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe&lt;br&gt;O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC&lt;br&gt;O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32&lt;br&gt;O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE&lt;br&gt;O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe&lt;br&gt;O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"&lt;br&gt;O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe&lt;br&gt;O4 - HKLM\..\Run: [VirtualDrive] "D:\Data\Programs and junk\FarStone\VirtualDrive\VDTask.exe" /AutoRestore&lt;br&gt;O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe&lt;br&gt;O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;br&gt;O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe&lt;br&gt;O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC&lt;br&gt;O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName&lt;br&gt;O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"&lt;br&gt;O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"&lt;br&gt;O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto&lt;br&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;br&gt;O4 - HKCU\..\Run: [Power2GoExpress] NA&lt;br&gt;O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe&lt;br&gt;O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitLord\BitLord.exe"&lt;br&gt;O4 - HKUS\S-1-5-19\..\Run: [TabletWizard] %windir%\help\wizard.hta (User 'LOCAL SERVICE')&lt;br&gt;O4 - HKUS\S-1-5-20\..\Run: [TabletWizard] %windir%\help\wizard.hta (User 'NETWORK SERVICE')&lt;br&gt;O4 - HKUS\S-1-5-18\..\Run: [TabletWizard] %windir%\help\wizard.hta (User 'SYSTEM')&lt;br&gt;O4 - HKUS\.DEFAULT\..\Run: [TabletWizard] %windir%\help\wizard.hta (User 'Default user')&lt;br&gt;O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE&lt;br&gt;O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe&lt;br&gt;O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE&lt;br&gt;O4 - Global Startup: VPN Client.lnk = ?&lt;br&gt;O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000&lt;br&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll&lt;br&gt;O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll&lt;br&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL&lt;br&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab&lt;br&gt;O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll&lt;br&gt;O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1147871177265&lt;br&gt;O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1179409055816&lt;br&gt;O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = winona.edu&lt;br&gt;O17 - HKLM\Software\..\Telephony: DomainName = workstations.winona.edu&lt;br&gt;O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = winona.edu&lt;br&gt;O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = winona.edu&lt;br&gt;O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll&lt;br&gt;O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL&lt;br&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;br&gt;O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;br&gt;O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe&lt;br&gt;O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe&lt;br&gt;O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe&lt;br&gt;O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe&lt;br&gt;O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe&lt;br&gt;O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe&lt;br&gt;O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe&lt;br&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe&lt;br&gt;O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE&lt;br&gt;O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS&lt;br&gt;O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe&lt;br&gt;O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe&lt;br&gt;O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe&lt;br&gt;&lt;br&gt;--&lt;br&gt;End of file - 10375 bytes&lt;br&gt;&lt;br&gt;</description><pubDate>Wed, 14 May 2008 14:04:49 GMT</pubDate><dc:creator>khuluna</dc:creator></item><item><title>RE: Slow, LAN connection not working</title><link>http://tweaks.com/forum/Topic239311-29-1.aspx</link><description>Welcome:)&lt;br&gt;&lt;br&gt;Download and scan with [b][color="red"]CCleaner[/color][/b]:&lt;br&gt;[url]http://www.ccleaner.com/downloadbuilds.asp[/url]&lt;br&gt;1. Starting with v1.27.260, CCleaner installs the [b]Yahoo Toolbar[/b] as an option which IS checkmarked by default during the installation. IF you do NOT want it, REMOVE the checkmark when provided with the option OR download the toolbar-free Basic or Slim versions instead of the Standard Build.&lt;br&gt;&lt;br&gt;2. Before first use, select Options &gt; Advanced and UNCHECK [b]"Only delete files in Windows Temp folder older than 48 hours"[/b]&lt;br&gt;&lt;br&gt;3. Then select the items you wish to clean up.&lt;br&gt;&lt;br&gt;[b]In the Windows Tab:[/b]&lt;br&gt;* Clean all entries in the "Internet Explorer" section except Cookies.&lt;br&gt;* Clean all the entries in the "Windows Explorer" section.&lt;br&gt;* Clean all entries in the "System" section.&lt;br&gt;* Clean all entries in the "Advanced" section.&lt;br&gt;* Clean any others that you choose.&lt;br&gt;&lt;br&gt;[b]In the Applications Tab:[/b]&lt;br&gt;* Clean all except cookies in the Firefox/Mozilla section if you use it.&lt;br&gt;* Clean all in the Opera section if you use it.&lt;br&gt;* Clean Sun Java in the Internet Section.&lt;br&gt;* Clean any others that you choose.&lt;br&gt;&lt;br&gt;4. Click the "Run Cleaner" button.&lt;br&gt;5. A pop up box will appear advising this process will permanently delete files from your system.&lt;br&gt;6. Click "OK" and it will scan and clean your system.&lt;br&gt;&lt;br&gt;* Now click on the '[b]Registry[/b]' tab/button on the left.&lt;br&gt;* Then click on the 'Scan for issues' button at the bottom.&lt;br&gt;* If CCleaner displays any issues,click on 'Fix selected issues'.&lt;br&gt;* You'll then be asked 'Do you want to backup changes to the registry',you [b]must[/b] click '[b]YES[/b]'.&lt;br&gt;* Save the backup somewhere safe,your desktop is a good a place as any.&lt;br&gt;* Then click 'Fix Issues',then click 'Close'.&lt;br&gt;* Exit CCleaner.&lt;br&gt;&lt;br&gt;&lt;br&gt;Download [b][url=http://download.bleepingcomputer.com/sUBs/ComboFix.exe][color="blue"]Combofix[/color][/url][/b] by [b]sUBs[/b] and save to your desktop.&lt;br&gt;Alternative Combofix download link [b][url=http://subs.geekstogo.com/ComboFix.exe][color="blue"]HERE[/color][/url][/b].&lt;br&gt;[color="red"][b][u]Note[/u][/b] &lt;br&gt;It is important that it is saved directly to your desktop[/color]&lt;br&gt;&lt;br&gt;Now close any open browsers.&lt;br&gt;Double click on Combofix.exe and follow the prompts. &lt;br&gt;When it's finished it will produce a log. &lt;br&gt;[b]Post the entire contents of C:\ComboFix.txt into your next reply[/b]. &lt;br&gt;[color="red"][b][u]Note[/u][/b] &lt;br&gt;Do not mouseclick combofix's window or do anything else on your pc while it's running. &lt;br&gt;That may cause the program/system to freeze/hang. [/color]&lt;br&gt;Do NOT post the ComboFix-quarantined-files.txt unless I ask.&lt;br&gt;[b][color="RED"][U]Note[/U][/color][/b]&lt;br&gt;In case your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix,please disable your scanner and redownload Combofix again.&lt;br&gt;Some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.&lt;br&gt;&lt;br&gt;[b]Also post a new Hijackthis log please.[/b]</description><pubDate>Mon, 12 May 2008 14:50:05 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>Slow, LAN connection not working</title><link>http://tweaks.com/forum/Topic239311-29-1.aspx</link><description>Well, this computer's loading rather slowly, and the LAN connection refuses to connect, even though I'm right next to the router, and it's plugged in with an ethernet cord. The other computer is having no problems at all. I've also noticed the presence of some services that have been identified as malware.&lt;br&gt;&lt;br&gt;EDIT: Got the LAN working, but not at all sure what the problem was. Computer continues to be slow, laggy, and all around buggery.&lt;br&gt;&lt;br&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br&gt;Scan saved at 11:24:34 AM, on 5/12/2008&lt;br&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16640)&lt;br&gt;Boot mode: Normal&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\WINDOWS\System32\smss.exe&lt;br&gt;C:\WINDOWS\system32\winlogon.exe&lt;br&gt;C:\WINDOWS\system32\services.exe&lt;br&gt;C:\WINDOWS\system32\lsass.exe&lt;br&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe&lt;br&gt;C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe&lt;br&gt;C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe&lt;br&gt;C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;br&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br&gt;C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe&lt;br&gt;C:\Program Files\Symantec AntiVirus\DefWatch.exe&lt;br&gt;C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe&lt;br&gt;C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE&lt;br&gt;C:\WINDOWS\system32\PnkBstrA.exe&lt;br&gt;C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS&lt;br&gt;C:\Program Files\Symantec AntiVirus\SavRoam.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\Program Files\Symantec AntiVirus\Rtvscan.exe&lt;br&gt;C:\WINDOWS\system32\ZuneBusEnum.exe&lt;br&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;br&gt;C:\Program Files\Common Files\Microsoft Shared\Ink\KeyboardSurrogate.exe&lt;br&gt;C:\WINDOWS\SYSTEM32\WISPTIS.EXE&lt;br&gt;C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe&lt;br&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;C:\Program Files\Common Files\Microsoft Shared\Ink\TCServer.exe&lt;br&gt;C:\WINDOWS\System32\tabbtnu.exe&lt;br&gt;C:\Program Files\GE\97769 Dual Scroll Optical Mouse\Amoumain.exe&lt;br&gt;C:\WINDOWS\stsystra.exe&lt;br&gt;C:\Program Files\Common Files\Microsoft Shared\Ink\TabTip.exe&lt;br&gt;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE&lt;br&gt;C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe&lt;br&gt;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&lt;br&gt;C:\PROGRA~1\SYMANT~1\VPTray.exe&lt;br&gt;C:\WINDOWS\vcdplayx.exe&lt;br&gt;C:\Program Files\Synaptics\SynTP\SynTPLpr.exe&lt;br&gt;C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;br&gt;C:\WINDOWS\sm56hlpr.exe&lt;br&gt;C:\WINDOWS\system32\wuauclt.exe&lt;br&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;br&gt;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&lt;br&gt;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&lt;br&gt;C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;br&gt;C:\program files\steam\steam.exe&lt;br&gt;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe&lt;br&gt;C:\Program Files\Stardock\ObjectDock\ObjectDock.exe&lt;br&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;br&gt;C:\WINDOWS\explorer.exe&lt;br&gt;C:\Program Files\Mozilla Firefox 3 Beta 5\firefox.exe&lt;br&gt;D:\Data\Random Junk\HiJackThis.exe&lt;br&gt;&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.winona.edu/links.htm&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;br&gt;R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)&lt;br&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br&gt;O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll&lt;br&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll&lt;br&gt;O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&lt;br&gt;O4 - HKLM\..\Run: [WheelMouse] Amoumain.exe&lt;br&gt;O4 - HKLM\..\Run: [TabletWizard] C:\WINDOWS\help\SplshWrp.exe&lt;br&gt;O4 - HKLM\..\Run: [TabletTip] "C:\Program Files\Common Files\microsoft shared\ink\tabtip.exe" /resume&lt;br&gt;O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe&lt;br&gt;O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime&lt;br&gt;O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC&lt;br&gt;O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent&lt;br&gt;O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32&lt;br&gt;O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE&lt;br&gt;O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe&lt;br&gt;O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"&lt;br&gt;O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"&lt;br&gt;O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe&lt;br&gt;O4 - HKLM\..\Run: [VirtualDrive] "D:\Data\Programs and junk\FarStone\VirtualDrive\VDTask.exe" /AutoRestore&lt;br&gt;O4 - HKLM\..\Run: [vcdplayx] "C:\WINDOWS\vcdplayx.exe"&lt;br&gt;O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe&lt;br&gt;O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;br&gt;O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe&lt;br&gt;O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC&lt;br&gt;O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName&lt;br&gt;O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"&lt;br&gt;O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"&lt;br&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"&lt;br&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;br&gt;O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitLord\BitLord.exe"&lt;br&gt;O4 - HKCU\..\Run: [Power2GoExpress] NA&lt;br&gt;O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe&lt;br&gt;O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent&lt;br&gt;O4 - HKUS\S-1-5-19\..\Run: [TabletWizard] %windir%\help\wizard.hta (User 'LOCAL SERVICE')&lt;br&gt;O4 - HKUS\S-1-5-20\..\Run: [TabletWizard] %windir%\help\wizard.hta (User 'NETWORK SERVICE')&lt;br&gt;O4 - HKUS\S-1-5-18\..\Run: [TabletWizard] %windir%\help\wizard.hta (User 'SYSTEM')&lt;br&gt;O4 - HKUS\.DEFAULT\..\Run: [TabletWizard] %windir%\help\wizard.hta (User 'Default user')&lt;br&gt;O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE&lt;br&gt;O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe&lt;br&gt;O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE&lt;br&gt;O4 - Global Startup: VPN Client.lnk = ?&lt;br&gt;O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000&lt;br&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll&lt;br&gt;O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll&lt;br&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL&lt;br&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab&lt;br&gt;O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll&lt;br&gt;O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1147871177265&lt;br&gt;O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1179409055816&lt;br&gt;O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = winona.edu&lt;br&gt;O17 - HKLM\Software\..\Telephony: DomainName = workstations.winona.edu&lt;br&gt;O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = winona.edu&lt;br&gt;O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = winona.edu&lt;br&gt;O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll&lt;br&gt;O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL&lt;br&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;br&gt;O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;br&gt;O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe&lt;br&gt;O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br&gt;O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe&lt;br&gt;O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe&lt;br&gt;O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe&lt;br&gt;O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe&lt;br&gt;O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe&lt;br&gt;O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe&lt;br&gt;O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe&lt;br&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe&lt;br&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br&gt;O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE&lt;br&gt;O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe&lt;br&gt;O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS&lt;br&gt;O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe&lt;br&gt;O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe&lt;br&gt;O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe&lt;br&gt;O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe&lt;br&gt;O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe&lt;br&gt;&lt;br&gt;--&lt;br&gt;End of file - 11917 bytes&lt;br&gt;</description><pubDate>Mon, 12 May 2008 11:28:53 GMT</pubDate><dc:creator>khuluna</dc:creator></item></channel></rss>