<?xml version="1.0"?>
<rss version="2.0"><channel><title>Resolved Logs Latest Topics</title><link>https://forums.lunarsoft.net/forum/51-resolved-logs/</link><description>Resolved Logs Latest Topics</description><language>en</language><item><title>Aero - log 02</title><link>https://forums.lunarsoft.net/topic/6523-aero-log-02/</link><description><![CDATA[<p>
	Hi Tarun,
</p>

<p>
	Not sure if I should title this log 1 or 2 since you helped me 3 years ago.
</p>

<p>
	 
</p>

<p>
	This time I was a little unwary when installing a frree video converer and missed the custom install and had a couple of things I didnt want installed. I know one was chromium which showed up in Firefox but I am not sure what the other was.
</p>

<p>
	I removed chromium via add/remove programs and went through the AMT as much as I could. Both Malwarebytes and Superantuspyware removed stuff.  Am I clean now?
</p>

<p>
	...
</p>

<p>
	Logfile of Trend Micro HijackThis v2.0.4<br>
	Scan saved at 15:45:48, on 25/11/2017<br>
	Platform: Unknown Windows (WinNT 6.02.1008)<br>
	MSIE: Internet Explorer v11.0 (11.00.15063.0608)<br>
	Boot mode: Normal
</p>

<p>
	Running processes:<br>
	C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe<br>
	C:\Program Files (x86)\Thunder Master\THPanel.exe<br>
	C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe<br>
	C:\Program Files (x86)\Steam\Steam.exe<br>
	C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe<br>
	C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe<br>
	C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe<br>
	C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe<br>
	C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe<br>
	C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe<br>
	C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe<br>
	C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe<br>
	C:\Program Files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe<br>
	C:\Users\Aeronwen Trewent\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\RzCefRenderProcess.exe<br>
	C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE<br>
	C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE<br>
	C:\Users\Aeronwen Trewent\Desktop\Download\HijackThis.exe
</p>

<p>
	R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="external nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br>
	R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/p/?LinkId=255141" rel="external nofollow">http://go.microsoft.com/fwlink/p/?LinkId=255141</a><br>
	R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/p/?LinkId=255141" rel="external nofollow">http://go.microsoft.com/fwlink/p/?LinkId=255141</a><br>
	R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="external nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br>
	R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="external nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br>
	R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/p/?LinkId=255141" rel="external nofollow">http://go.microsoft.com/fwlink/p/?LinkId=255141</a><br>
	R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =<br>
	R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =<br>
	R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm<br>
	R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =<br>
	O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL<br>
	O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_151\bin\ssv.dll<br>
	O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL<br>
	O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_151\bin\jp2ssv.dll<br>
	O4 - HKLM\..\Run: [Razer Synapse] "C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe"<br>
	O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"<br>
	O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent<br>
	O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATILQE.EXE /EPT "EPLTarget\P0000000000000000" /M "XP-610 Series"<br>
	O4 - HKCU\..\Run: [BingSvc] C:\Users\Aeronwen Trewent\AppData\Local\Microsoft\BingSvc\BingSvc.exe<br>
	O4 - HKCU\..\Run: [Discord] C:\Users\Aeronwen Trewent\AppData\Local\Discord\app-0.0.298\Discord.exe<br>
	O4 - HKCU\..\Run: [EPLTarget\P0000000000000001] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATILQE.EXE /EPT "EPLTarget\P0000000000000001" /M "XP-610 Series"<br>
	O4 - HKCU\..\Run: [THPanel] "C:\Program Files (x86)\Thunder Master\THPanel.exe" /A<br>
	O4 - HKCU\..\Run: [Chromium] "c:\users\aeronwen trewent\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory=Default --restore-last-session<br>
	O4 - HKCU\..\Run: [SUPERAntiSpyware] G:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br>
	O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')<br>
	O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')<br>
	O4 - Startup: Curse.lnk = Aeronwen Trewent\AppData\Roaming\Curse Client\Bin\Curse.exe<br>
	O4 - Global Startup: FAH.lnk = C:\Program Files\WinZip\FAH\FAHConsole.exe<br>
	O4 - Global Startup: WinZip Preloader.lnk = C:\Program Files\WinZip\WzPreloader.exe<br>
	O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE/3000<br>
	O8 - Extra context menu item: Se&amp;nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll/105<br>
	O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll<br>
	O9 - Extra 'Tools' menuitem: Se&amp;nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll<br>
	O9 - Extra button: OneNote Lin&amp;ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll<br>
	O9 - Extra 'Tools' menuitem: OneNote Lin&amp;ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll<br>
	O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics<br>
	O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll<br>
	O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll<br>
	O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll<br>
	O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL<br>
	O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - G:\Program Files\SUPERAntiSpyware\SASCORE64.EXE<br>
	O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe<br>
	O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)<br>
	O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe<br>
	O23 - Service: @%ProgramFiles%\Windows Identity Foundation\v3.5\c2wtsres.dll,-1000 (c2wts) - Unknown owner - C:\Program Files (x86)\Windows Identity Foundation\v3.5\c2wtshost.exe (file missing)<br>
	O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)<br>
	O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)<br>
	O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\Windows\system32\EscSvc64.exe (file missing)<br>
	O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)<br>
	O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>
	O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)<br>
	O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe<br>
	O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe<br>
	O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)<br>
	O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)<br>
	O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe<br>
	O23 - Service: NVIDIA NetworkService Container (NvContainerNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe<br>
	O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe<br>
	O23 - Service: NVIDIA Telemetry Container (NvTelemetryContainer) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe<br>
	O23 - Service: Razer Chroma SDK Service - Razer Inc. - C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe<br>
	O23 - Service: Razer Game Scanner (Razer Game Scanner Service) - Unknown owner - C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe<br>
	O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)<br>
	O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)<br>
	O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)<br>
	O23 - Service: @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1001 (Sense) - Unknown owner - C:\Program Files (x86)\Windows Defender Advanced Threat Protection\MsSense.exe (file missing)<br>
	O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)<br>
	O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)<br>
	O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\WINDOWS\system32\spectrum.exe (file missing)<br>
	O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)<br>
	O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)<br>
	O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe<br>
	O23 - Service: TeamViewer 12 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe<br>
	O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)<br>
	O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)<br>
	O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)<br>
	O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)<br>
	O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)<br>
	O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)<br>
	O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)<br>
	O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)<br>
	O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)<br>
	O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
</p>

<p>
	--<br>
	End of file - 12044 bytes
</p>

<p>
	 
</p>

<p>
	 
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">6523</guid><pubDate>Sat, 25 Nov 2017 16:40:53 +0000</pubDate></item><item><title>Adware</title><link>https://forums.lunarsoft.net/topic/6517-adware/</link><description><![CDATA[<p>
	Hi, I recently started having these websites open up. It says my computer is infected. I am currently running McAfee stinger and it already found a trojan named artemis. It says it has deleted it. It is still running the scan and I am still getting the popups with the message noted about. I downloaded malwarebytes and it says it is installed, but when i click on the icon it won't open the application. Any suggestions are appreciated. Thanks.
</p>]]></description><guid isPermaLink="false">6517</guid><pubDate>Sat, 11 Nov 2017 18:40:48 +0000</pubDate></item><item><title>Aero - log 01</title><link>https://forums.lunarsoft.net/topic/5730-aero-log-01/</link><description><![CDATA[<p>Hi</p>
<p> </p>
<p>Some programs on my pc are not working for me.  I tend to think my fatal error was installing win 8.1 but I just wanted to check it was nothing obvious here.</p>
<p> </p>
<p>I went through the steps in the AMT to the best of my ability (the instructions didn't always seem to match up with what I was seeing).</p>
<p> </p>
<div>Logfile of Trend Micro HijackThis v2.0.4</div>
<div>Scan saved at 15:07:50, on 07/04/2014</div>
<div>Platform: Unknown Windows (WinNT 6.02.1008)</div>
<div>MSIE: Internet Explorer v11.0 (11.00.9600.16518)</div>
<div>Boot mode: Normal</div>
<div> </div>
<div>Running processes:</div>
<div>C:Program Files (x86)ASUSAI Suite IIDIGI+ VRMPowerControlHelp.exe</div>
<div>C:Program Files (x86)ASUSAI Suite IIAsRoutineController.exe</div>
<div>C:Program Files (x86)EPSONMyEPSON Connectmep.exe</div>
<div>C:Program Files (x86)NVIDIA CorporationUpdate CoreNvBackend.exe</div>
<div>C:Program Files (x86)mIRCmirc.exe</div>
<div>C:Program Files (x86)SteamSteam.exe</div>
<div>C:Program Files (x86)ASUSAI Suite IITurboV EVOTurboVHelp.exe</div>
<div>C:Program Files (x86)ASUSAI Suite IINetwork iControlNetSvcHelpNetSvcHelp.exe</div>
<div>C:Program Files (x86)ASUSAI Suite IINetwork iControlNetSvcHelpNetiCtrlTray.exe</div>
<div>C:Program Files (x86)ASUSAI Suite IIEPUEPUHelp.exe</div>
<div>C:Program Files (x86)ASUSAI Suite IIAI Suite II.exe</div>
<div>C:Program Files (x86)EPSON SoftwareEvent ManagerEEventManager.exe</div>
<div>C:Program Files (x86)GoogleChromeApplicationchrome.exe</div>
<div>C:Program Files (x86)GoogleChromeApplicationchrome.exe</div>
<div>C:Program Files (x86)GoogleChromeApplicationchrome.exe</div>
<div>C:Program Files (x86)ASUSAI Suite IISensorAlertHelperAlertHelper.exe</div>
<div>C:Program Files (x86)Malwarebytes Anti-Malwarembam.exe</div>
<div>C:UsersAeronwenDesktopDownloadHijackThis.exe</div>
<div> </div>
<div>R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = Preserve</div>
<div>R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="external nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a></div>
<div>R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = about:Tabs</div>
<div>R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/p/?LinkId=255141" rel="external nofollow">http://go.microsoft.com/fwlink/p/?LinkId=255141</a></div>
<div>R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="external nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a></div>
<div>R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="external nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a></div>
<div>R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = <a href="http://go.microsoft.com/fwlink/p/?LinkId=255141" rel="external nofollow">http://go.microsoft.com/fwlink/p/?LinkId=255141</a></div>
<div>R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = </div>
<div>R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch = </div>
<div>R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page = C:WindowsSysWOW64blank.htm</div>
<div>R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = </div>
<div>F2 - REG:system.ini: UserInit=userinit.exe,</div>
<div>O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:PROGRA~2MICROS~1Office14GROOVEEX.DLL</div>
<div>O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program Files (x86)Javajre7binssv.dll</div>
<div>O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)</div>
<div>O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:PROGRA~2MICROS~1Office14URLREDIR.DLL</div>
<div>O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program Files (x86)Javajre7binjp2ssv.dll</div>
<div>O3 - Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)</div>
<div>O4 - HKLM..Run: [sunJavaUpdateSched] "C:Program Files (x86)Common FilesJavaJava Updatejusched.exe"</div>
<div>O4 - HKLM..Run: [Adobe ARM] "C:Program Files (x86)Common FilesAdobeARM1.0AdobeARM.exe"</div>
<div>O4 - HKLM..Run: [vProt] "C:Program Files (x86)AVG Secure Searchvprot.exe"</div>
<div>O4 - HKLM..Run: [Adobe Creative Cloud] "C:Program Files (x86)AdobeAdobe Creative CloudACCCreative Cloud.exe" --showwindow=false --onOSstartup=true</div>
<div>O4 - HKLM..Run: [KeePass 2 PreLoad] "C:Program Files (x86)KeePass Password Safe 2KeePass.exe" --preload</div>
<div>O4 - HKLM..Run: [EEventManager] "C:Program Files (x86)Epson SoftwareEvent ManagerEEventManager.exe"</div>
<div>O4 - HKCU..Run: [steam] "C:Program Files (x86)Steamsteam.exe" -silent</div>
<div>O4 - HKCU..Run: [EPLTargetP0000000000000001] C:WINDOWSsystem32spoolDRIVERSx643E_IATILQE.EXE /EPT "EPLTargetP0000000000000001" /M "XP-610 Series" /EF "HKCU"</div>
<div>O4 - HKCU..Run: [skype] "C:Program Files (x86)SkypePhoneSkype.exe" /minimized /regrun</div>
<div>O4 - Startup: Dropbox.lnk = AeronwenAppDataRoamingDropboxbinDropbox.exe</div>
<div>O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program Files (x86)Microsoft OfficeOffice14ONBttnIE.dll</div>
<div>O9 - Extra 'Tools' menuitem: Se&amp;nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program Files (x86)Microsoft OfficeOffice14ONBttnIE.dll</div>
<div>O9 - Extra button: OneNote Lin&amp;ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program Files (x86)Microsoft OfficeOffice14ONBttnIELinkedNotes.dll</div>
<div>O9 - Extra 'Tools' menuitem: OneNote Lin&amp;ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program Files (x86)Microsoft OfficeOffice14ONBttnIELinkedNotes.dll</div>
<div>O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics</div>
<div>O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:PROGRA~2COMMON~1SkypeSKYPE4~1.DLL</div>
<div>O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:Program Files (x86)Common FilesAVG Secure SearchViProtocolInstaller18.0.5ViProtocol.dll</div>
<div>O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:Program Files (x86)Windows LivePhoto GalleryAlbumDownloadProtocolHandler.dll</div>
<div>O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:Program Files (x86)Common FilesMicrosoft SharedOFFICE14MSOXMLMF.DLL</div>
<div>O20 - AppInit_DLLs: d3dgearload.dll</div>
<div>O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:Program FilesSUPERAntiSpywareSASCORE64.EXE</div>
<div>O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe</div>
<div>O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:WINDOWSSysWOW64MacromedFlashFlashPlayerUpdateService.exe</div>
<div>O23 - Service: @%SystemRoot%system32Alg.exe,-112 (ALG) - Unknown owner - C:WINDOWSSystem32alg.exe (file missing)</div>
<div>O23 - Service: ASUS Com Service (asComSvc) - Unknown owner - C:Program Files (x86)ASUSAXSP1.00.19atkexComSvc.exe</div>
<div>O23 - Service: ASGT - Unknown owner - C:WindowsSysWOW64ASGT.exe</div>
<div>O23 - Service: ASUS HM Com Service (asHmComSvc) - ASUSTeK Computer Inc. - C:Program Files (x86)ASUSAAHM1.00.20aaHMSvc.exe</div>
<div>O23 - Service: ASUS System Control Service (AsSysCtrlService) - ASUSTeK Computer Inc. - C:Program Files (x86)ASUSAsSysCtrlService1.00.13AsSysCtrlService.exe</div>
<div>O23 - Service: AsusFanControlService - ASUSTeK Computer Inc. - C:Program Files (x86)ASUSAsusFanControlService1.01.10AsusFanControlService.exe</div>
<div>O23 - Service: EasyAntiCheat - EasyAntiCheat Ltd - C:WINDOWSsystem32EasyAntiCheat.exe</div>
<div>O23 - Service: @%SystemRoot%system32efssvc.dll,-100 (EFS) - Unknown owner - C:WINDOWSSystem32lsass.exe (file missing)</div>
<div>O23 - Service: Epson Sc r Service (EpsonScanSvc) - Unknown owner - C:WINDOWSsystem32EscSvc64.exe (file missing)</div>
<div>O23 - Service: @%systemroot%system32fxsresm.dll,-118 (Fax) - Unknown owner - C:WINDOWSsystem32fxssvc.exe (file missing)</div>
<div>O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:Program Files (x86)GoogleUpdateGoogleUpdate.exe</div>
<div>O23 - Service: Google Update Service (gupdatem) (gupdatem) - Unknown owner - C:Program Files (x86)GoogleUpdateGoogleUpdate.exe</div>
<div>O23 - Service: Intel® Integrated Clock Controller Service - Intel® ICCS (ICCS) - Intel Corporation - C:Program Files (x86)IntelIntel® Integrated Clock Controller ServiceICCProxy.exe</div>
<div>O23 - Service: @%SystemRoot%system32ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:WINDOWSsystem32IEEtwCollector.exe (file missing)</div>
<div>O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:WINDOWSsystem32lsass.exe (file missing)</div>
<div>O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:Program Files (x86)Malwarebytes Anti-Malwarembamscheduler.exe</div>
<div>O23 - Service: MBAMService - Malwarebytes Corporation - C:Program Files (x86)Malwarebytes Anti-Malwarembamservice.exe</div>
<div>O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:WINDOWSSystem32msdtc.exe (file missing)</div>
<div>O23 - Service: MyEPSON Connect Service - SEIKO EPSON CORPORATION - C:Program Files (x86)EPSONMyEPSON ConnectmepService.exe</div>
<div>O23 - Service: @%SystemRoot%System32netlogon.dll,-102 (Netlogon) - Unknown owner - C:WINDOWSsystem32lsass.exe (file missing)</div>
<div>O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:Program Files (x86)NVIDIA CorporationNetServiceNvNetworkService.exe</div>
<div>O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:Program FilesNVIDIA CorporationNvStreamSrvnvstreamsvc.exe</div>
<div>O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:WINDOWSsystem32nvvsvc.exe (file missing)</div>
<div>O23 - Service: @%systemroot%system32Locator.exe,-2 (RpcLocator) - Unknown owner - C:WINDOWSsystem32locator.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%system32samsrv.dll,-1 (SamSs) - Unknown owner - C:WINDOWSsystem32lsass.exe (file missing)</div>
<div>O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:Program Files (x86)SkypeUpdaterUpdater.exe</div>
<div>O23 - Service: @%SystemRoot%system32snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:WINDOWSSystem32snmptrap.exe (file missing)</div>
<div>O23 - Service: @%systemroot%system32spoolsv.exe,-1 (Spooler) - Unknown owner - C:WINDOWSSystem32spoolsv.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%system32sppsvc.exe,-101 (sppsvc) - Unknown owner - C:WINDOWSsystem32sppsvc.exe (file missing)</div>
<div>O23 - Service: Steam Client Service - Valve Corporation - C:Program Files (x86)Common FilesSteamSteamService.exe</div>
<div>O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:Program Files (x86)NVIDIA Corporation3D VisionnvSCPAPISvr.exe</div>
<div>O23 - Service: @%SystemRoot%system32ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:WINDOWSsystem32UI0Detect.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%system32vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:WINDOWSsystem32lsass.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%system32vds.exe,-100 (vds) - Unknown owner - C:WINDOWSSystem32vds.exe (file missing)</div>
<div>O23 - Service: @%systemroot%system32vssvc.exe,-102 (VSS) - Unknown owner - C:WINDOWSsystem32vssvc.exe (file missing)</div>
<div>O23 - Service: vToolbarUpdater18.0.5 - Unknown owner - C:Program Files (x86)Common FilesAVG Secure SearchvToolbarUpdater18.0.5ToolbarUpdater.exe</div>
<div>O23 - Service: @%systemroot%system32wbengine.exe,-104 (wbengine) - Unknown owner - C:WINDOWSsystem32wbengine.exe (file missing)</div>
<div>O23 - Service: @%ProgramFiles%Windows DefenderMpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:Program Files (x86)Windows DefenderNisSrv.exe (file missing)</div>
<div>O23 - Service: @%ProgramFiles%Windows DefenderMpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:Program Files (x86)Windows DefenderMsMpEng.exe (file missing)</div>
<div>O23 - Service: @%Systemroot%system32wbemwmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:WINDOWSsystem32wbemWmiApSrv.exe (file missing)</div>
<div>O23 - Service: @%PROGRAMFILES%Windows Media Playerwmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:Program Files (x86)Windows Media Playerwmpnetwk.exe (file missing)</div>
<div> </div>
<div>--</div>
<div>End of file - 11362 bytes</div>
<div> </div>
]]></description><guid isPermaLink="false">5730</guid><pubDate>Mon, 07 Apr 2014 14:22:09 +0000</pubDate></item><item><title>Multiple instances of explorer.exe on Vista</title><link>https://forums.lunarsoft.net/topic/5716-multiple-instances-of-explorerexe-on-vista/</link><description><![CDATA[<p>I've noticed lately that my laptop is showing multiple instances of explorer.exe in the task manager. I've run MB and MS Essentials, everything is now coming back "clean", but still seeing this issue. Usually CPU usage % for 1 or 2 will hit 25-30%. Here's the content of the HJT log:</p>
<p> </p>
<p>Logfile of Trend Micro HijackThis v2.0.5<br>
Scan saved at 12:52:42 PM, on 2014-02-24<br>
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br>
MSIE: Internet Explorer v9.00 (9.00.8112.16533)</p>
<p>
Boot mode: Normal</p>
<p>Running processes:<br>
C:Program Files (x86)GoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe<br>
C:Program Files (x86)Hewlett-PackardMediaDVDDVDAgent.exe<br>
C:Program Files (x86)Hewlett-PackardTouchSmartMediaTSMAgent.exe<br>
C:Program Files (x86)Hewlett-PackardTouchSmartMediaKernelCLMLCLMLSvc.exe<br>
C:Program Files (x86)Hewlett-PackardMediaTVTVAgent.exe<br>
C:Program Files (x86)HpHP Software Updatehpwuschd2.exe<br>
C:Program Files (x86)AdobeAcrobat 9.0Acrobatacrotray.exe<br>
C:Program Files (x86)Hewlett-PackardHP Quick Launch ButtonsQLBCTRL.exe<br>
C:Program Files (x86)Hewlett-PackardSharedhpqToaster.exe<br>
C:Program Files (x86)Internet Exploreriexplore.exe<br>
C:Program Files (x86)Internet Exploreriexplore.exe<br>
C:Program Files (x86)GoogleGoogle ToolbarGoogleToolbarUser_32.exe<br>
C:Program Files (x86)Malwarebytes' Anti-Malwarembam.exe<br>
C:Program Files (x86)Internet Exploreriexplore.exe<br>
C:Program Files (x86)Internet Exploreriexplore.exe<br>
C:UsersPatrickDownloadsHijackThis (1).exe</p>
<p>R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=91&amp;bd=Pavilion&amp;pf=cnnb" rel="external nofollow">http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=91&amp;bd=Pavilion&amp;pf=cnnb</a><br>
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="external nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br>
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=91&amp;bd=Pavilion&amp;pf=cnnb" rel="external nofollow">http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=91&amp;bd=Pavilion&amp;pf=cnnb</a><br>
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="external nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br>
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="external nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br>
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=91&amp;bd=Pavilion&amp;pf=cnnb" rel="external nofollow">http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=91&amp;bd=Pavilion&amp;pf=cnnb</a><br>
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =<br>
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =<br>
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page = C:WindowsSysWOW64blank.htm<br>
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =<br>
R3 - URLSearchHook: (no name) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file)<br>
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - D:Program Files (x86)TechSmithSnagit 10SnagitBHO.dll<br>
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:Program Files (x86)Common FilesAdobeAcrobatActiveXAcroIEHelperShim.dll<br>
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:PROGRA~2MICROS~2Office14GROOVEEX.DLL<br>
O2 - BHO: (no name) - {95CFEC51-7780-FC20-7EBA-2921A87886E3} - (no file)<br>
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program Files (x86)GoogleGoogle ToolbarGoogleToolbar_32.dll<br>
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:Program Files (x86)Common FilesAdobeAcrobatActiveXAcroIEFavClient.dll<br>
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:PROGRA~2MICROS~2Office14URLREDIR.DLL<br>
O2 - BHO: IE Developer Toolbar BHO - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:Program Files (x86)MicrosoftInternet Explorer Developer ToolbarIEDevToolbar.dll<br>
O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:Program Files (x86)MSNToolbar3.0.0541.0msneshellx.dll<br>
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program Files (x86)Javajre6binjp2ssv.dll<br>
O2 - BHO: Microsoft Web Test Recorder 10.0 Helper - {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - d:Program Files (x86)Microsoft Visual Studio 10.0Common7IDEPrivateAssembliesMicrosoft.VisualStudio.QualityTools.RecorderBarBHO100.dll<br>
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:Program Files (x86)Common FilesAdobeAcrobatActiveXAcroIEFavClient.dll<br>
O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:Program Files (x86)MSNToolbar3.0.0541.0msneshellx.dll<br>
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:Program Files (x86)Common FilesAdobeAcrobatActiveXAcroIEFavClient.dll<br>
O3 - Toolbar: Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - D:Program Files (x86)TechSmithSnagit 10SnagitIEAddin.dll<br>
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program Files (x86)GoogleGoogle ToolbarGoogleToolbar_32.dll<br>
O4 - HKLM..Run: [startCCC] "C:Program Files (x86)ATI TechnologiesATI.ACECore-StaticCLIStart.exe" MSRun<br>
O4 - HKLM..Run: [DVDAgent] "C:Program Files (x86)Hewlett-PackardMediaDVDDVDAgent.exe"<br>
O4 - HKLM..Run: [TSMAgent] "C:Program Files (x86)Hewlett-PackardTouchSmartMediaTSMAgent.exe"<br>
O4 - HKLM..Run: [CLMLServer for HP TouchSmart] "C:Program Files (x86)Hewlett-PackardTouchSmartMediaKernelCLMLCLMLSvc.exe"<br>
O4 - HKLM..Run: [TVAgent] "C:Program Files (x86)Hewlett-PackardMediaTVTVAgent.exe"<br>
O4 - HKLM..Run: [uCam_Menu] "C:Program Files (x86)Hewlett-PackardMediaWebcamMUITransferMUIStartMenu.exe" "C:Program Files (x86)Hewlett-PackardMediaWebcam" update "SoftwareHewlett-PackardMediaWebcam"<br>
O4 - HKLM..Run: [updateLBPShortCut] "C:Program Files (x86)CyberLinkLabelPrintMUITransferMUIStartMenu.exe" "C:Program Files (x86)CyberLinkLabelPrint" UpdateWithCreateOnce "SoftwareCyberLinkLabelPrint2.5"<br>
O4 - HKLM..Run: [updatePSTShortCut] "C:Program Files (x86)CyberLinkDVD SuiteMUITransferMUIStartMenu.exe" "C:Program Files (x86)CyberLinkDVD Suite" UpdateWithCreateOnce "SoftwareCyberLinkPowerStarter"<br>
O4 - HKLM..Run: [updateP2GoShortCut] "C:Program Files (x86)CyberLinkPower2GoMUITransferMUIStartMenu.exe" "C:Program Files (x86)CyberLinkPower2Go" UpdateWithCreateOnce "SOFTWARECyberLinkPower2Go6.0"<br>
O4 - HKLM..Run: [updatePDIRShortCut] "C:Program Files (x86)CyberLinkPowerDirectorMUITransferMUIStartMenu.exe" "C:Program Files (x86)CyberLinkPowerDirector" UpdateWithCreateOnce "SOFTWARECyberLinkPowerDirector7.0"<br>
O4 - HKLM..Run: [sunJavaUpdateSched] "C:Program Files (x86)Javajre6binjusched.exe"<br>
O4 - HKLM..Run: [WirelessAssistant] C:Program Files (x86)Hewlett-PackardHP Wireless AssistantHPWAMain.exe<br>
O4 - HKLM..Run: [HP Software Update] C:Program Files (x86)HpHP Software UpdateHPWuSchd2.exe<br>
O4 - HKLM..Run: [Adobe Acrobat Speed Launcher] "C:Program Files (x86)AdobeAcrobat 9.0AcrobatAcrobat_sl.exe"<br>
O4 - HKLM..Run: [Acrobat Assistant 8.0] "C:Program Files (x86)AdobeAcrobat 9.0AcrobatAcrotray.exe"<br>
O4 - HKLM..Run: [QlbCtrl.exe] "C:Program Files (x86)Hewlett-PackardHP Quick Launch ButtonsQlbCtrl.exe" /Start<br>
O4 - HKLM..Run: [bCSSync] "C:Program Files (x86)Microsoft OfficeOffice14BCSSync.exe" /DelayServices<br>
O4 - HKLM..Run: [Cisco AnyConnect Secure Mobility Agent for Windows] "C:Program Files (x86)CiscoCisco AnyConnect Secure Mobility Clientvpnui.exe" -minimized<br>
O4 - HKLM..RunOnce: [AvgUninstallURL] cmd.exe /c start <a href="http://www.avg.com/ww.special-uninstallation-feedback-appf?lic=OQBBAFYARgBSAEUARQAtAFYAQQBFAEEAWQAtAFQAMwBMAFUARQAtAE4ATAAzAEQAQQAtAEMAQgBVAEsASAAtAEoARgA3AE0AOQA" rel="external nofollow">http://www.avg.com/ww.special-uninstallation-feedback-appf?lic=OQBBAFYARgBSAEUARQAtAFYAQQBFAEEAWQAtAFQAMwBMAFUARQAtAE4ATAAzAEQAQQAtAEMAQgBVAEsASAAtAEoARgA3AE0AOQA"&amp;"inst=NwA3AC0ANAAzADAAOQAwADUAMgAwADIALQBCAEEAKwAxAC0ASwBWADMAKwA3AC0AVAAzAC0ARgBQADkAKwA2AC0AQgBBAFIAOQBHACsAMQAtAFQAQgA5ACsAMgAtAEYATAArADkALQBYAE8AMwA2ACsAMQAtAEYAOQBNADcAQwArADUALQBGADkATQAxADAAQgArADIALQBYAE8AOQArADEALQBGADkATQAyACsAMQAtAEQARABUACsANAAyADIAMgAzAC0AUwBUADkAMABGAEEAUABQACsAMQAtAEQARAA5ADAARgArADEALQBGADkAMABNADEAMgBBAFQAKwAxAC0ARgA5ADAATQAxADIAQQArADEALQBGADkAMABNADEAMgBBAEIAKwAxAC0AVQA5ADUAKwAxAC0ARgA5ADAATQAxADIAQQBUAEIATgArADEA"&amp;"prod=90"&amp;"ver=9.0.894</a><br>
O4 - HKCU..Run: [ehTray.exe] C:WindowsehomeehTray.exe<br>
O4 - HKCU..Run: [swg] "C:Program Files (x86)GoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe"<br>
O4 - HKCU..Run: [AWZworks] regsvr32.exe C:UsersPatrickAppDataLocalAWZworksfftpigbnhowpkfe.dll<br>
O4 - HKCU..RunOnce: [CryptoUpdate] C:Windowssystem32rundll32.exe "C:UsersPatrickAppDataRoamingMicrosoftCryptoRSAcert_v42_0.tpl",Crypt<br>
O4 - HKUSS-1-5-19..Run: [sidebar] %ProgramFiles%Windows SidebarSidebar.exe /detectMem (User 'LOCAL SERVICE')<br>
O4 - HKUSS-1-5-19..Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br>
O4 - HKUSS-1-5-20..Run: [sidebar] %ProgramFiles%Windows SidebarSidebar.exe /detectMem (User 'NETWORK SERVICE')<br>
O4 - Global Startup: Adobe Gamma Loader.lnk = C:Program Files (x86)Common FilesAdobeCalibrationAdobe Gamma Loader.exe<br>
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:Program Files (x86)Common FilesAdobeAcrobatActiveXAcroIEFavClient.dll/AcroIEAppendSelLinks.html<br>
O8 - Extra context menu item: Append to Existing PDF - res://C:Program Files (x86)Common FilesAdobeAcrobatActiveXAcroIEFavClient.dll/AcroIEAppend.html<br>
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:Program Files (x86)Common FilesAdobeAcrobatActiveXAcroIEFavClient.dll/AcroIECaptureSelLinks.html<br>
O8 - Extra context menu item: Convert link target to existing PDF - res://C:Program Files (x86)Common FilesAdobeAcrobatActiveXAcroIEFavClient.dll/AcroIEAppendSelLinks.html<br>
O8 - Extra context menu item: Convert to Adobe PDF - res://C:Program Files (x86)Common FilesAdobeAcrobatActiveXAcroIEFavClient.dll/AcroIECapture.html<br>
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:PROGRA~2MICROS~2Office14EXCEL.EXE/3000<br>
O8 - Extra context menu item: Se&amp;nd to OneNote - res://C:PROGRA~2MICROS~2Office14ONBttnIE.dll/105<br>
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program Files (x86)Microsoft OfficeOffice14ONBttnIE.dll<br>
O9 - Extra 'Tools' menuitem: Se&amp;nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program Files (x86)Microsoft OfficeOffice14ONBttnIE.dll<br>
O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:Program Files (x86)MicrosoftInternet Explorer Developer ToolbarIEDevToolbar.dll<br>
O9 - Extra button: OneNote Lin&amp;ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program Files (x86)Microsoft OfficeOffice14ONBttnIELinkedNotes.dll<br>
O9 - Extra 'Tools' menuitem: OneNote Lin&amp;ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program Files (x86)Microsoft OfficeOffice14ONBttnIELinkedNotes.dll<br>
O9 - Extra button: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "d:Program Files (x86)Fiddler2Fiddler.exe" (file missing)<br>
O9 - Extra 'Tools' menuitem: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "d:Program Files (x86)Fiddler2Fiddler.exe" (file missing)<br>
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics<br>
O15 - Trusted Zone: <a href="http://reviews.cnet.com" rel="external nofollow">http://reviews.cnet.com</a><br>
O15 - Trusted Zone: <a href="http://www.vonage.com" rel="external nofollow">http://www.vonage.com</a><br>
O16 - DPF: 55963676-2F5E-4BAF-AC28-CF26AA587566 - vpnweb.cab<br>
O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} (Hewlett-Packard Online Support Services) - <a href="https://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB" rel="external nofollow">https://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB</a><br>
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - <a href="https://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab" rel="external nofollow">https://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab</a><br>
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} (DLC Class) - <a href="https://transfers.ds.microsoft.com/FTM/TransferSource/grTransferCtrl.cab" rel="external nofollow">https://transfers.ds.microsoft.com/FTM/TransferSource/grTransferCtrl.cab</a><br>
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" rel="external nofollow">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br>
O16 - DPF: {E3372C1F-AFE6-4A3B-90F9-83B2E9B42C82} (ADTCKS.KSLauncher) - <a href="http://online.appdev.com/inline/ADTCKS.CAB" rel="external nofollow">http://online.appdev.com/inline/ADTCKS.CAB</a><br>
O18 - Protocol: a5res - (no CLSID) - (no file)<br>
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:PROGRA~2COMMON~1SkypeSKYPE4~1.DLL<br>
O18 - Protocol: XBasic - (no CLSID) - (no file)<br>
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:Program Files (x86)Common FilesMicrosoft SharedOFFICE14MSOXMLMF.DLL<br>
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:Windowssystem32browseui.dll<br>
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Unknown owner - C:Windowssystem32agr64svc.exe (file missing)<br>
O23 - Service: @%SystemRoot%system32Alg.exe,-112 (ALG) - Unknown owner - C:WindowsSystem32alg.exe (file missing)<br>
O23 - Service: Ati External Event Utility - Unknown owner - C:Windowssystem32Ati2evxx.exe (file missing)<br>
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:Program Files (x86)Hewlett-PackardHP Quick Launch ButtonsCom4QLBEx.exe<br>
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:Windowssystem32DFSR.exe (file missing)<br>
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:Program Files (x86)Common FilesMacrovision SharedFLEXnet PublisherFNPLicensingService.exe<br>
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:Program Files (x86)GoogleUpdateGoogleUpdate.exe<br>
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:Program Files (x86)GoogleUpdateGoogleUpdate.exe<br>
O23 - Service: Google Software Updater (gusvc) - Google - C:Program Files (x86)GoogleCommonGoogle UpdaterGoogleUpdaterService.exe<br>
O23 - Service: HP Health Check Service - Unknown owner - C:Program Files (x86)Hewlett-PackardHP Health Checkhphc_service.exe (file missing)<br>
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:Program Files (x86)Hewlett-PackardSharedhpqwmiex.exe<br>
O23 - Service: HP Service (hpsrv) - Unknown owner - C:Windowssystem32Hpservice.exe (file missing)<br>
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program Files (x86)Common FilesInstallShieldDriver1050Intel 32IDriverT.exe<br>
O23 - Service: @%windir%system32inetsrviisres.dll,-30007 (IISADMIN) - Unknown owner - C:Windowssystem32inetsrvinetinfo.exe (file missing)<br>
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:Windowssystem32lsass.exe (file missing)<br>
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:Program Files (x86)Common FilesLightScribeLSSrvc.exe<br>
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:Program Files (x86)Malwarebytes' Anti-Malwarembamscheduler.exe<br>
O23 - Service: MBAMService - Malwarebytes Corporation - C:Program Files (x86)Malwarebytes' Anti-Malwarembamservice.exe<br>
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:WindowsSystem32msdtc.exe (file missing)<br>
O23 - Service: @%SystemRoot%System32netlogon.dll,-102 (Netlogon) - Unknown owner - C:Windowssystem32lsass.exe (file missing)<br>
O23 - Service: NMSAccessU - Unknown owner - C:Program Files (x86)CDBurnerXPNMSAccessU.exe<br>
O23 - Service: Norton Internet Security - Unknown owner - C:Program Files (x86)Norton Internet SecurityEngine16.0.0.125ccSvcHst.exe (file missing)<br>
O23 - Service: @%systemroot%system32psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:Windowssystem32lsass.exe (file missing)<br>
O23 - Service: Recovery Service for Windows - Unknown owner - C:Program Files (x86)SMINSTBLService.exe<br>
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:Program Files (x86)CyberLinkShared filesRichVideo.exe<br>
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:Program Files (x86)WinPcaprpcapd.exe<br>
O23 - Service: @%systemroot%system32Locator.exe,-2 (RpcLocator) - Unknown owner - C:Windowssystem32locator.exe (file missing)<br>
O23 - Service: @%SystemRoot%system32samsrv.dll,-1 (SamSs) - Unknown owner - C:Windowssystem32lsass.exe (file missing)<br>
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:Program Files (x86)SkypeUpdaterUpdater.exe<br>
O23 - Service: @%SystemRoot%system32SLsvc.exe,-101 (slsvc) - Unknown owner - C:Windowssystem32SLsvc.exe (file missing)<br>
O23 - Service: @%SystemRoot%system32snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:WindowsSystem32snmptrap.exe (file missing)<br>
O23 - Service: @%systemroot%system32spoolsv.exe,-1 (Spooler) - Unknown owner - C:WindowsSystem32spoolsv.exe (file missing)<br>
O23 - Service: Audio Service (STacSV) - Unknown owner - C:WindowsSystem32DriverStoreFileRepositorystwrt64.inf_1b06afceSTacSV64.exe (file missing)<br>
O23 - Service: TV Background Capture Service (TVBCS) (TVCapSvc) - Unknown owner - C:Program Files (x86)Hewlett-PackardMediaTVKernelTVTVCapSvc.exe<br>
O23 - Service: TV Task Scheduler (TVTS) (TVSched) - Unknown owner - C:Program Files (x86)Hewlett-PackardMediaTVKernelTVTVSched.exe<br>
O23 - Service: @%SystemRoot%system32ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:Windowssystem32UI0Detect.exe (file missing)<br>
O23 - Service: @%SystemRoot%system32vds.exe,-100 (vds) - Unknown owner - C:WindowsSystem32vds.exe (file missing)<br>
O23 - Service: Cisco AnyConnect Secure Mobility Agent (vpnagent) - Cisco Systems, Inc. - C:Program Files (x86)CiscoCisco AnyConnect Secure Mobility Clientvpnagent.exe<br>
O23 - Service: @%systemroot%system32vssvc.exe,-102 (VSS) - Unknown owner - C:Windowssystem32vssvc.exe (file missing)<br>
O23 - Service: @%Systemroot%system32wbemwmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:Windowssystem32wbemWmiApSrv.exe (file missing)<br>
O23 - Service: @%ProgramFiles%Windows Media Playerwmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:Program Files (x86)Windows Media Playerwmpnetwk.exe (file missing)</p>
<p>--<br>
End of file - 17906 bytes</p>
<p> </p>
]]></description><guid isPermaLink="false">5716</guid><pubDate>Mon, 24 Feb 2014 19:17:35 +0000</pubDate></item><item><title>HIJACK THIS log file.. DOSEARCHES has invaded my comp</title><link>https://forums.lunarsoft.net/topic/5364-hijack-this-log-file-dosearches-has-invaded-my-comp/</link><description><![CDATA[<p>DOSEARCHES has invaded my computer!!</p>
<p> </p>
<p> </p>
<p>Please help!</p>
<p> </p>
<div>Logfile of Trend Micro HijackThis v2.0.5</div>
<div>Scan saved at 6:17:37 PM, on 10/9/2013</div>
<div>Platform: Windows 7 SP1 (WinNT 6.00.3505)</div>
<div>MSIE: Internet Explorer v10.0 (10.00.9200.16686)</div>
<div> </div>
<div> </div>
<div>Boot mode: Normal</div>
<div> </div>
<div>Running processes:</div>
<div>C:UsersChuck BonettiAppDataRoamingSearch ProtectionSearchProtection.exe</div>
<div>C:Program Files (x86)Common FilesJavaJava Updatejusched.exe</div>
<div>C:Program Files (x86)Common FilesAppleInternet ServicesApplePhotoStreams.exe</div>
<div>C:Program Files (x86)PlexPlex Media ServerPlex Media Server.exe</div>
<div>C:Program Files (x86)PlexPlex Media ServerPlexDlnaServer.exe</div>
<div>C:Program FilesWebrootWRSA.exe</div>
<div>C:Program Files (x86)PlexPlex Media ServerPlexScriptHost.exe</div>
<div>C:Program Files (x86)GoogleChromeApplicationchrome.exe</div>
<div>C:Program Files (x86)GoogleChromeApplicationchrome.exe</div>
<div>C:Program Files (x86)GoogleChromeApplicationchrome.exe</div>
<div>C:Program Files (x86)GoogleChromeApplicationchrome.exe</div>
<div>C:Program Files (x86)GoogleChromeApplicationchrome.exe</div>
<div>C:Program Files (x86)GoogleChromeApplicationchrome.exe</div>
<div>C:Program Files (x86)Common FilesAppleInternet ServicesAPSDaemon.exe</div>
<div>C:Program Files (x86)GoogleChromeApplicationchrome.exe</div>
<div>C:Program Files (x86)GoogleChromeApplicationchrome.exe</div>
<div>C:Program Files (x86)GoogleChromeApplicationchrome.exe</div>
<div>C:Program Files (x86)GoogleChromeApplicationchrome.exe</div>
<div>C:Program Files (x86)GoogleChromeApplicationchrome.exe</div>
<div>C:UsersChuck BonettiDownloadsHijackThis.exe</div>
<div> </div>
<div>R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = <a href="http://www.dosearches.com/?utm_source=b&amp;utm_medium=smt&amp;utm_campaign=eXQ&amp;utm_content=hp&amp;from=smt&amp;uid=ST9500424AS_S2V0NBZ1XXXXS2V0NBZ1&amp;ts=1381271071" rel="external nofollow">http://www.dosearches.com/?utm_source=b&amp;utm_medium=smt&amp;utm_campaign=eXQ&amp;utm_content=hp&amp;from=smt&amp;uid=ST9500424AS_S2V0NBZ1XXXXS2V0NBZ1&amp;ts=1381271071</a></div>
<div>R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="external nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a></div>
<div>R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = <a href="https://www.google.com/" rel="external nofollow">https://www.google.com/</a></div>
<div>R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = <a href="http://www.dosearches.com/?utm_source=b&amp;utm_medium=smt&amp;utm_campaign=eXQ&amp;utm_content=hp&amp;from=smt&amp;uid=ST9500424AS_S2V0NBZ1XXXXS2V0NBZ1&amp;ts=1381271071" rel="external nofollow">http://www.dosearches.com/?utm_source=b&amp;utm_medium=smt&amp;utm_campaign=eXQ&amp;utm_content=hp&amp;from=smt&amp;uid=ST9500424AS_S2V0NBZ1XXXXS2V0NBZ1&amp;ts=1381271071</a></div>
<div>R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="external nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a></div>
<div>R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="external nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a></div>
<div>R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = <a href="http://www.dosearches.com/?utm_source=b&amp;utm_medium=smt&amp;utm_campaign=eXQ&amp;utm_content=hp&amp;from=smt&amp;uid=ST9500424AS_S2V0NBZ1XXXXS2V0NBZ1&amp;ts=1381271071" rel="external nofollow">http://www.dosearches.com/?utm_source=b&amp;utm_medium=smt&amp;utm_campaign=eXQ&amp;utm_content=hp&amp;from=smt&amp;uid=ST9500424AS_S2V0NBZ1XXXXS2V0NBZ1&amp;ts=1381271071</a></div>
<div>R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = </div>
<div>R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch = </div>
<div>R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page = C:WindowsSysWOW64blank.htm</div>
<div>R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = *.local</div>
<div>R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = </div>
<div>O2 - BHO: IBM Forms Viewer Helper - {0941C58F-E461-4E03-BD7D-44C27392ADE1} - C:Program Files (x86)IBMForms Viewer4.0PEhelper.dll</div>
<div>O2 - BHO: QuickShare WidgetEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - mscoree.dll (file missing)</div>
<div>O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:PROGRA~2MICROS~2Office14GROOVEEX.DLL</div>
<div>O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program Files (x86)Javajre7binssv.dll</div>
<div>O2 - BHO: (no name) - {8232785C-5C98-4A6E-B7B4-911FFBED7582} - (no file)</div>
<div>O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program Files (x86)Common FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll</div>
<div>O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:PROGRA~2MICROS~2Office14URLREDIR.DLL</div>
<div>O2 - BHO: Webroot Vault - {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} - C:ProgramDataWRDatapkgLPBar.dll</div>
<div>O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program Files (x86)Javajre7binjp2ssv.dll</div>
<div>O3 - Toolbar: Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:ProgramDataWRDatapkgLPBar.dll</div>
<div>O3 - Toolbar: QuickShare Widget - {ae07101b-46d4-4a98-af68-0333ea26e113} - mscoree.dll (file missing)</div>
<div>O4 - HKLM..Run: [WRSVC] "C:Program FilesWebrootWRSA.exe" -ul</div>
<div>O4 - HKLM..Run: [Adobe ARM] "C:Program Files (x86)Common FilesAdobeARM1.0AdobeARM.exe"</div>
<div>O4 - HKLM..Run: [APSDaemon] "C:Program Files (x86)Common FilesAppleApple Application SupportAPSDaemon.exe"</div>
<div>O4 - HKLM..Run: [WD Quick View] C:Program Files (x86)Western DigitalWD Quick ViewWDDMStatus.exe</div>
<div>O4 - HKLM..Run: [bCSSync] "C:Program Files (x86)Microsoft OfficeOffice14BCSSync.exe" /DelayServices</div>
<div>O4 - HKLM..Run: [QuickTime Task] "C:Program Files (x86)QuickTimeQTTask.exe" -atboottime</div>
<div>O4 - HKLM..Run: [sunJavaUpdateSched] "C:Program Files (x86)Common FilesJavaJava Updatejusched.exe"</div>
<div>O4 - HKLM..Run: [iTunesHelper] "C:Program Files (x86)iTunesiTunesHelper.exe"</div>
<div>O4 - HKCU..Run: [steam] "C:Program Files (x86)SteamSteam.exe" -silent</div>
<div>O4 - HKCU..Run: [Facebook Update] "C:UsersChuck BonettiAppDataLocalFacebookUpdateFacebookUpdate.exe" /c /nocrashserver</div>
<div>O4 - HKCU..Run: [searchProtection] "C:UsersChuck BonettiAppDataRoamingSearch ProtectionSearchProtection.EXE" /autostart</div>
<div>O4 - HKCU..Run: [uTorrent] "C:UsersChuck BonettiAppDataRoaminguTorrentuTorrent.exe"  /MINIMIZED</div>
<div>O4 - HKCU..Run: [Plex Media Server] "C:Program Files (x86)PlexPlex Media ServerPlex Media Server.exe"</div>
<div>O4 - HKCU..Run: [ApplePhotoStreams] C:Program Files (x86)Common FilesAppleInternet ServicesApplePhotoStreams.exe</div>
<div>O4 - HKCU..Run: [sidebar] C:Program FilesWindows Sidebarsidebar.exe /autoRun</div>
<div>O4 - HKCU..Run: [sDP] C:UsersChuck BonettiAppDataLocalFilesFrog Update Checkerupdate_checker.exe /auto </div>
<div>O4 - HKCU..Run: [browser Infrastructure Helper] C:UsersChuck BonettiAppDataLocalSmartbarApplicationQuickShare.exe startup</div>
<div>O4 - HKCU..RunOnce: [FlashPlayerUpdate] C:WindowsSysWOW64MacromedFlashFlashUtil32_11_8_800_175_ActiveX.exe -update activex</div>
<div>O4 - HKUSS-1-5-18..RunOnce: [sPReview] "C:WindowsSystem32SPReviewSPReview.exe" /sp:1 /errorfwlink:"<a href="http://go.microsoft.com/fwlink/?LinkID=122915" rel="external nofollow">http://go.microsoft.com/fwlink/?LinkID=122915</a>" /build:7601 (User 'SYSTEM')</div>
<div>O4 - HKUS.DEFAULT..RunOnce: [sPReview] "C:WindowsSystem32SPReviewSPReview.exe" /sp:1 /errorfwlink:"<a href="http://go.microsoft.com/fwlink/?LinkID=122915" rel="external nofollow">http://go.microsoft.com/fwlink/?LinkID=122915</a>" /build:7601 (User 'Default user')</div>
<div>O4 - Startup: Facebook Messenger.lnk = Chuck BonettiAppDataLocalFacebookMessenger2.1.4814.0FacebookMessenger.exe</div>
<div>O4 - Startup: ZooskMessenger.lnk = C:Program Files (x86)ZooskMessengerZooskMessenger.exe</div>
<div>O4 - Global Startup: Install Webroot FF RunOnce.lnk = C:Program Files (x86)Common Fileswruninstall.exe</div>
<div>O4 - Global Startup: Install Webroot IE RunOnce.lnk = C:Program Files (x86)Common Fileswruninstall.exe</div>
<div></div>
<div></div>
<div>O9 - Extra button: @C:Program Files (x86)Windows LiveWriterWindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:Program Files (x86)Windows LiveWriterWriterBrowserExtension.dll</div>
<div>O9 - Extra 'Tools' menuitem: @C:Program Files (x86)Windows LiveWriterWindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:Program Files (x86)Windows LiveWriterWriterBrowserExtension.dll</div>
<div>O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program Files (x86)Microsoft OfficeOffice14ONBttnIE.dll</div>
<div>O9 - Extra 'Tools' menuitem: Se&amp;nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program Files (x86)Microsoft OfficeOffice14ONBttnIE.dll</div>
<div>O9 - Extra button: Webroot - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:ProgramDataWRDatapkgLPBar.dll</div>
<div>O9 - Extra 'Tools' menuitem: Webroot - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:ProgramDataWRDatapkgLPBar.dll</div>
<div>O9 - Extra button: OneNote Lin&amp;ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program Files (x86)Microsoft OfficeOffice14ONBttnIELinkedNotes.dll</div>
<div>O9 - Extra 'Tools' menuitem: OneNote Lin&amp;ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program Files (x86)Microsoft OfficeOffice14ONBttnIELinkedNotes.dll</div>
<div>O10 - Unknown file in Winsock LSP: c:program files (x86)common filesmicrosoft sharedwindows livewlidnsp.dll</div>
<div>O10 - Unknown file in Winsock LSP: c:program files (x86)common filesmicrosoft sharedwindows livewlidnsp.dll</div>
<div>O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics</div>
<div>O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:PROGRA~2COMMON~1SkypeSKYPE4~1.DLL</div>
<div>O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:Program Files (x86)Windows LivePhoto GalleryAlbumDownloadProtocolHandler.dll</div>
<div>O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:Program Files (x86)Common FilesMicrosoft SharedOFFICE14MSOXMLMF.DLL</div>
<div>O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe</div>
<div>O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:WindowsSysWOW64MacromedFlashFlashPlayerUpdateService.exe</div>
<div>O23 - Service: @%SystemRoot%system32Alg.exe,-112 (ALG) - Unknown owner - C:WindowsSystem32alg.exe (file missing)</div>
<div>O23 - Service: AMD External Events Utility - Unknown owner - C:Windowssystem32atiesrxx.exe (file missing)</div>
<div>O23 - Service: Apple Mobile Device - Apple Inc. - C:Program Files (x86)Common FilesAppleMobile Device SupportAppleMobileDeviceService.exe</div>
<div>O23 - Service: Bonjour Service - Apple Inc. - C:Program FilesBonjourmDNSResponder.exe</div>
<div>O23 - Service: @%SystemRoot%system32efssvc.dll,-100 (EFS) - Unknown owner - C:WindowsSystem32lsass.exe (file missing)</div>
<div>O23 - Service: FastFreeConverterUpdt - Unknown owner - C:Program Files (x86)Fast Free ConverterFastFreeConverterUpdt.exe (file missing)</div>
<div>O23 - Service: @%systemroot%system32fxsresm.dll,-118 (Fax) - Unknown owner - C:Windowssystem32fxssvc.exe (file missing)</div>
<div>O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:Program Files (x86)GoogleUpdateGoogleUpdate.exe</div>
<div>O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:Program Files (x86)GoogleUpdateGoogleUpdate.exe</div>
<div>O23 - Service: iPod Service - Apple Inc. - C:Program FilesiPodbiniPodService.exe</div>
<div>O23 - Service: Media Center Support Service (Jasmio.MediaCenter.Service) - Unknown owner - C:Program FilesJasmioMedia Center Support ServiceJasmio.MediaCenter.Service.exe</div>
<div>O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:Windowssystem32lsass.exe (file missing)</div>
<div>O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:Program Files (x86)LogMeInx64LMIGuardianSvc.exe</div>
<div>O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:Program Files (x86)LogMeInx64RaMaint.exe</div>
<div>O23 - Service: LogMeIn - LogMeIn, Inc. - C:Program Files (x86)LogMeInx64LogMeIn.exe</div>
<div>O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:WindowsSystem32msdtc.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%System32netlogon.dll,-102 (Netlogon) - Unknown owner - C:Windowssystem32lsass.exe (file missing)</div>
<div>O23 - Service: PnkBstrA - Unknown owner - C:Windowssystem32PnkBstrA.exe</div>
<div>O23 - Service: @%systemroot%system32psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:Windowssystem32lsass.exe (file missing)</div>
<div>O23 - Service: @%systemroot%system32Locator.exe,-2 (RpcLocator) - Unknown owner - C:Windowssystem32locator.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%system32samsrv.dll,-1 (SamSs) - Unknown owner - C:Windowssystem32lsass.exe (file missing)</div>
<div>O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:Program Files (x86)SkypeUpdaterUpdater.exe</div>
<div>O23 - Service: @%SystemRoot%system32snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:WindowsSystem32snmptrap.exe (file missing)</div>
<div>O23 - Service: @%systemroot%system32spoolsv.exe,-1 (Spooler) - Unknown owner - C:WindowsSystem32spoolsv.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%system32sppsvc.exe,-101 (sppsvc) - Unknown owner - C:Windowssystem32sppsvc.exe (file missing)</div>
<div>O23 - Service: Steam Client Service - Valve Corporation - C:Program Files (x86)Common FilesSteamSteamService.exe</div>
<div>O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:Program Files (x86)Common FilesSupportSoftbinssrc.exe</div>
<div>O23 - Service: @%SystemRoot%system32ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:Windowssystem32UI0Detect.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%system32vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:Windowssystem32lsass.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%system32vds.exe,-100 (vds) - Unknown owner - C:WindowsSystem32vds.exe (file missing)</div>
<div>O23 - Service: @%systemroot%system32vssvc.exe,-102 (VSS) - Unknown owner - C:Windowssystem32vssvc.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%system32WatWatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:Windowssystem32WatWatAdminSvc.exe (file missing)</div>
<div>O23 - Service: @%systemroot%system32wbengine.exe,-104 (wbengine) - Unknown owner - C:Windowssystem32wbengine.exe (file missing)</div>
<div>O23 - Service: WD Backup (WDBackup) - Western Digital Technologies, Inc. - C:Program Files (x86)Western DigitalWD SmartWareWDBackupEngine.exe</div>
<div>O23 - Service: WD Drive Manager (WDDriveService) - Western Digital Technologies, Inc. - C:Program Files (x86)Western DigitalWD Drive ManagerWDDriveService.exe</div>
<div>O23 - Service: @%Systemroot%system32wbemwmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:Windowssystem32wbemWmiApSrv.exe (file missing)</div>
<div>O23 - Service: Windows Media Player Network Sharing Service (WMPNetworkSvc) - Unknown owner - C:Program Files (x86)Windows Media Playerwmpnetwk.exe (file missing)</div>
<div>O23 - Service: WRSVC - Webroot - C:Program FilesWebrootWRSA.exe</div>
<div> </div>
<div>--</div>
<div>End of file - 14253 bytes</div>
<div> </div>
<p><a href="https://forums.lunarsoft.net/uploads/monthly_10_2013/post-2153-0-78295300-1381371661.png"><img src="https://forums.lunarsoft.net/uploads/monthly_10_2013/post-2153-0-78295300-1381371661_thumb.png" data-fileid="356" alt="post-2153-0-78295300-1381371661_thumb.pn" loading="lazy"></a></p><p><a href="https://forums.lunarsoft.net/applications/core/interface/file/attachment.php?id=357">hijackthis.txt</a></p>
]]></description><guid isPermaLink="false">5364</guid><pubDate>Thu, 10 Oct 2013 02:21:29 +0000</pubDate></item><item><title>clumsy79rsl Hijack Log</title><link>https://forums.lunarsoft.net/topic/5279-clumsy79rsl-hijack-log/</link><description><![CDATA[<p>My Computer keeps on Freezing up and also sometimes my task bar will stop working</p><p>
I completed the clean up steps and it still happens</p><p>
</p><p>
</p><p>
</p><p>
</p><p>
</p><p>
</p><p>
Logfile of Trend Micro HijackThis v2.0.4</p><p>
Scan saved at 5:34:04 PM, on 11/30/2012</p><p>
Platform: Windows XP SP3 (WinNT 5.01.2600)</p><p>
MSIE: Internet Explorer v8.00 (8.00.6001.18702)</p><p>
Boot mode: Normal</p><p>
</p><p>
Running processes:</p><p>
C:\WINDOWS\System32\smss.exe</p><p>
C:\WINDOWS\system32\winlogon.exe</p><p>
C:\WINDOWS\system32\services.exe</p><p>
C:\WINDOWS\system32\lsass.exe</p><p>
C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe</p><p>
C:\WINDOWS\system32\svchost.exe</p><p>
C:\WINDOWS\System32\svchost.exe</p><p>
C:\WINDOWS\Explorer.EXE</p><p>
C:\WINDOWS\system32\spoolsv.exe</p><p>
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE</p><p>
C:\Program Files\ESET\ESET Smart Security\ekrn.exe</p><p>
C:\Program Files\Java\jre6\bin\jqs.exe</p><p>
C:\WINDOWS\system32\nvsvc32.exe</p><p>
C:\WINDOWS\system32\svchost.exe</p><p>
C:\Program Files\Common Files\Java\Java Update\jusched.exe</p><p>
C:\Program Files\Analog Devices\Core\smax4pnp.exe</p><p>
C:\Program Files\ESET\ESET Smart Security\egui.exe</p><p>
C:\WINDOWS\system32\ctfmon.exe</p><p>
C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe</p><p>
C:\Documents and Settings\Robert\Local Settings\Application Data\Skillbrains\lightshot\3.2.0.0\LightShot.exe</p><p>
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe</p><p>
C:\Program Files\Mozilla Firefox\firefox.exe</p><p>
C:\Documents and Settings\Robert\Desktop\exe programs Oct 2012\Clean up programs\HijackThis.exe</p><p>
</p><p>
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896</p><p>
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank</p><p>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896</p><p>
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank</p><p>
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=;ftp=;https=;</p><p>
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll</p><p>
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL</p><p>
O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll</p><p>
O2 - BHO: (no name) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - (no file)</p><p>
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll</p><p>
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll</p><p>
O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"</p><p>
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup</p><p>
O4 - HKLM\..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe</p><p>
O4 - HKLM\..\Run: [MDS_Menu] "C:\Program Files\CyberLink\MediaEspresso\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\MediaEspresso" UpdateWithCreateOnce "Software\CyberLink\MediaEspresso\6.7"</p><p>
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice</p><p>
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"</p><p>
O4 - HKLM\..\Run: [switchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe</p><p>
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin</p><p>
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe</p><p>
O4 - HKCU\..\Run: [Advanced SystemCare 5] "C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe" /AutoStart</p><p>
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"  /MINIMIZED</p><p>
O4 - HKCU\..\Run: [LightShot] C:\Documents and Settings\Robert\Local Settings\Application Data\Skillbrains\lightshot\LightShot.exe Flags: uninsdeletevalue</p><p>
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')</p><p>
O4 - HKUS\S-1-5-20\..\RunOnce: [showDeskFix] regsvr32 /s /n /i:u shell32 (User 'NETWORK SERVICE')</p><p>
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')</p><p>
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')</p><p>
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000</p><p>
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll</p><p>
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll</p><p>
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL</p><p>
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll</p><p>
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll</p><p>
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe</p><p>
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe</p><p>
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL</p><p>
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll</p><p>
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll</p><p>
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE</p><p>
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe</p><p>
O23 - Service: Advanced SystemCare Service 5 (AdvancedSystemCareService5) - IObit - C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe</p><p>
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe</p><p>
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe</p><p>
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe</p><p>
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe</p><p>
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe</p><p>
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe</p><p>
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe</p><p>
</p><p>
--</p><p>
End of file - 6993 bytes</p>
]]></description><guid isPermaLink="false">5279</guid><pubDate>Sat, 01 Dec 2012 01:52:16 +0000</pubDate></item><item><title>HiJack This Log - JMac</title><link>https://forums.lunarsoft.net/topic/5233-hijack-this-log-jmac/</link><description><![CDATA[<p>Hi Tarun, Ran a Full Scan with MSE this morning and it located a infection, also Malwarebytes located two objects.</p><p>
Just thought i would post a log to double check <img src="https://forums.lunarsoft.net/uploads/default_wink.png" alt=";)" loading="lazy"></p><p>
</p><p>
Thanks in advance</p><p>
</p><p>
</p><p>
Logfile of Trend Micro HijackThis v2.0.4</p><p>
Scan saved at 06:32:04, on 05/06/2012</p><p>
Platform: Windows 7 SP1 (WinNT 6.00.3505)</p><p>
MSIE: Internet Explorer v9.00 (9.00.8112.16421)</p><p>
Boot mode: Normal</p><p>
</p><p>
Running processes:</p><p>
C:\Windows\system32\Dwm.exe</p><p>
C:\Windows\Explorer.EXE</p><p>
C:\Windows\system32\taskhost.exe</p><p>
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe</p><p>
C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe</p><p>
C:\Program Files\iTunes\iTunesHelper.exe</p><p>
C:\Program Files\Microsoft\BingDesktop\BingDesktop.exe</p><p>
C:\Program Files\Microsoft Security Client\msseces.exe</p><p>
C:\Program Files\HP\HP Software Update\hpwuschd2.exe</p><p>
C:\Program Files\Common Files\Java\Java Update\jusched.exe</p><p>
C:\Windows\system32\taskeng.exe</p><p>
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe</p><p>
</p><p>
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=112457&amp;tt=230512_54x&amp;babsrc=HP_ss&amp;mntrId=c406caa4000000000000001d92dbcd60</p><p>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157</p><p>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896</p><p>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896</p><p>
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157</p><p>
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =</p><p>
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =</p><p>
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =</p><p>
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =</p><p>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =</p><p>
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll</p><p>
O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll</p><p>
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll</p><p>
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll</p><p>
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s</p><p>
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume</p><p>
O4 - HKLM\..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide</p><p>
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"</p><p>
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"</p><p>
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"</p><p>
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"</p><p>
O4 - HKLM\..\Run: [bingDesktop] C:\Program Files\Microsoft\BingDesktop\BingDesktop.exe /fromkey</p><p>
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey</p><p>
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe</p><p>
O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"</p><p>
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll</p><p>
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll</p><p>
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics</p><p>
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll</p><p>
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe</p><p>
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe</p><p>
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe</p><p>
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe</p><p>
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe</p><p>
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe</p><p>
O23 - Service: Jumpstart Wifi Protected Setup (jswpsapi) - Atheros Communications, Inc. - C:\Program Files\NETGEAR\WN111v2\jswpsapi.exe</p><p>
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe</p><p>
O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe</p><p>
</p><p>
--</p><p>
End of file - 4964 bytes</p>
]]></description><guid isPermaLink="false">5233</guid><pubDate>Tue, 05 Jun 2012 05:43:00 +0000</pubDate></item><item><title>1ssrdr - log1</title><link>https://forums.lunarsoft.net/topic/5179-1ssrdr-log1/</link><description><![CDATA[<p>I have ran all the programs. Known issues are:</p><p>
1.) Windows installer at startup</p><p>
2.) Sonic Activation Module (Please wait while windows configures Saonic Activation Module) at start up. You can cancel to get rid of this promt.</p><p>
3.) Ran Dial a Fix to fix to allow windows update to update. Now I get the dowloads but won't install some of them. Read that this is a know issue with XP SP 3.</p><p>
</p><p>
Thank you for any advise you can give me.</p><p>
</p><p>
Logfile of Trend Micro HijackThis v2.0.4</p><p>
Scan saved at 8:14:17 PM, on 1/20/2012</p><p>
Platform: Windows XP SP3 (WinNT 5.01.2600)</p><p>
MSIE: Internet Explorer v7.00 (7.00.6000.17106)</p><p>
Boot mode: Normal</p><p>
</p><p>
Running processes:</p><p>
C:\WINDOWS\System32\smss.exe</p><p>
C:\WINDOWS\system32\winlogon.exe</p><p>
C:\WINDOWS\system32\services.exe</p><p>
C:\WINDOWS\system32\lsass.exe</p><p>
C:\WINDOWS\system32\svchost.exe</p><p>
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe</p><p>
C:\WINDOWS\System32\svchost.exe</p><p>
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe</p><p>
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe</p><p>
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe</p><p>
C:\WINDOWS\system32\spoolsv.exe</p><p>
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE</p><p>
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe</p><p>
C:\Program Files\Bonjour\mDNSResponder.exe</p><p>
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe</p><p>
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe</p><p>
C:\WINDOWS\system32\drivers\KodakCCS.exe</p><p>
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe</p><p>
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE</p><p>
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe</p><p>
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe</p><p>
C:\WINDOWS\Explorer.EXE</p><p>
C:\WINDOWS\system32\nvsvc32.exe</p><p>
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe</p><p>
C:\WINDOWS\system32\stacsv.exe</p><p>
C:\WINDOWS\system32\svchost.exe</p><p>
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe</p><p>
C:\WINDOWS\system32\rundll32.exe</p><p>
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe</p><p>
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe</p><p>
C:\Program Files\Dell\MediaDirect\PCMService.exe</p><p>
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe</p><p>
C:\Program Files\Microsoft Security Client\msseces.exe</p><p>
C:\WINDOWS\system32\ctfmon.exe</p><p>
C:\WINDOWS\system32\msiexec.exe</p><p>
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe</p><p>
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe</p><p>
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe</p><p>
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe</p><p>
C:\Program Files\Mozilla Firefox\firefox.exe</p><p>
C:\Program Files\Mozilla Firefox\plugin-container.exe</p><p>
C:\Documents and Settings\Robin\Desktop\Scanning tools\HijackThis.exe</p><p>
</p><p>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157</p><p>
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157</p><p>
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&amp;client=dell-usuk&amp;channel=us&amp;ibd=6061025</p><p>
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.callwave.com/iam/DemoIntro.html?u=0f5aad5d20e557b1a8355eb2c05007ccb277b91465eaf9bd&amp;Ver=3.09.9.0&amp;OS=WinNT:5.1.2600SP:2.0&amp;co=0</p><p>
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll</p><p>
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll</p><p>
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll</p><p>
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll</p><p>
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll</p><p>
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll</p><p>
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll</p><p>
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll</p><p>
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll</p><p>
O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe</p><p>
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup</p><p>
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet</p><p>
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start</p><p>
O4 - HKLM\..\Run: [intelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"</p><p>
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r</p><p>
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"</p><p>
O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start</p><p>
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey</p><p>
O4 - HKLM\..\Run: [iSUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup</p><p>
O4 - HKCU\..\Run: [setDefaultMIDI] MIDIDef.exe</p><p>
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe</p><p>
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"</p><p>
O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe</p><p>
O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe</p><p>
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')</p><p>
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')</p><p>
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)</p><p>
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)</p><p>
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll</p><p>
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll</p><p>
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe</p><p>
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe</p><p>
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe</p><p>
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe</p><p>
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll</p><p>
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab</p><p>
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll</p><p>
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL</p><p>
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL</p><p>
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL</p><p>
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE</p><p>
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe</p><p>
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe</p><p>
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe</p><p>
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe</p><p>
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe</p><p>
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe</p><p>
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe</p><p>
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe</p><p>
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe</p><p>
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe</p><p>
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe</p><p>
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe</p><p>
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe</p><p>
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe</p><p>
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\stacsv.exe</p><p>
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe</p><p>
</p><p>
--</p><p>
End of file - 9237 bytes</p>
]]></description><guid isPermaLink="false">5179</guid><pubDate>Sat, 21 Jan 2012 02:20:22 +0000</pubDate></item><item><title>Brokenpete - log 01</title><link>https://forums.lunarsoft.net/topic/5093-brokenpete-log-01/</link><description><![CDATA[<p>I'm having google redirect problems in Firefox on Windows 7 64 bit. It's not every link that redirects, but I'm often (maybe once every ten results) redirected to spammy/junk sites. I've worked through the PC cleanup process, and this is my logfile from HijackThis:</p><p>
 </p><p>
Logfile of Trend Micro HijackThis v2.0.4</p><p>
Scan saved at 10:47:52, on 04/10/2011</p><p>
Platform: Windows 7 SP1 (WinNT 6.00.3505)</p><p>
MSIE: Internet Explorer v9.00 (9.00.8112.16421)</p><p>
Boot mode: Normal</p><p>
</p><p>
Running processes:</p><p>
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe</p><p>
C:\Program Files (x86)\Skype\Phone\Skype.exe</p><p>
J:\Steam\Steam.exe</p><p>
C:\Program Files (x86)\Spybot - Search &amp; Destroy\TeaTimer.exe</p><p>
C:\Users\Peter\AppData\Roaming\Dropbox\bin\Dropbox.exe</p><p>
C:\Program Files (x86)\BUFFALO\NASNAVI\nassche.exe</p><p>
C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE</p><p>
C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe</p><p>
C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe</p><p>
C:\Program Files (x86)\Java\jre6\bin\jusched.exe</p><p>
C:\Program Files (x86)\AVG\AVG10\avgtray.exe</p><p>
C:\Program Files (x86)\iTunes\iTunesHelper.exe</p><p>
C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe</p><p>
C:\Program Files (x86)\APC\APC PowerChute Personal Edition\apcsystray.exe</p><p>
C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE</p><p>
C:\Program Files (x86)\AVG\AVG10\avgcsrvx.exe</p><p>
C:\Windows\sysWow64\SearchProtocolHost.exe</p><p>
C:\Program Files (x86)\Mozilla Firefox\firefox.exe</p><p>
C:\Windows\SysWOW64\NOTEPAD.EXE</p><p>
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe</p><p>
</p><p>
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896</p><p>
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/</p><p>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157</p><p>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896</p><p>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896</p><p>
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157</p><p>
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =</p><p>
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =</p><p>
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm</p><p>
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local</p><p>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =</p><p>
F2 - REG:system.ini: UserInit=userinit.exe,</p><p>
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll</p><p>
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll</p><p>
O2 - BHO: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll</p><p>
O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll</p><p>
O2 - BHO: LastPass Browser Helper Object - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPBar.dll</p><p>
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL</p><p>
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll</p><p>
O3 - Toolbar: LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPBar.dll</p><p>
O4 - HKLM\..\Run: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun</p><p>
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe</p><p>
O4 - HKLM\..\Run: [Display] C:\Program Files (x86)\APC\APC PowerChute Personal Edition\DataCollectionLauncher.exe</p><p>
O4 - HKLM\..\Run: [iJNetworkScanUtility] C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe</p><p>
O4 - HKLM\..\Run: [TrueImageMonitor.exe] "C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe"</p><p>
O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"</p><p>
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe</p><p>
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime</p><p>
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"</p><p>
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe</p><p>
O4 - HKCU\..\Run: [skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized</p><p>
O4 - HKCU\..\Run: [steam] "J:\Steam\Steam.exe" -silent</p><p>
O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search &amp; Destroy\TeaTimer.exe</p><p>
O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')</p><p>
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')</p><p>
O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')</p><p>
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')</p><p>
O4 - Startup: BUFFALO NAS Navigator2.lnk = C:\Program Files (x86)\BUFFALO\NASNAVI\NasNavi.exe</p><p>
O4 - Startup: Dropbox.lnk = Peter\AppData\Roaming\Dropbox\bin\Dropbox.exe</p><p>
O4 - Startup: NAS Scheduler.lnk = C:\Program Files (x86)\BUFFALO\NASNAVI\nassche.exe</p><p>
O4 - Startup: OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE</p><p>
O4 - Global Startup: APC UPS Status.lnk = C:\Program Files (x86)\APC\APC PowerChute Personal Edition\Display.exe</p><p>
O4 - Global Startup: Jungle Disk Desktop.lnk = C:\Program Files\Jungle Disk Desktop\JungleDiskMonitor.exe</p><p>
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html</p><p>
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000</p><p>
O8 - Extra context menu item: LastPass - file://C:\Program Files (x86)\LastPass\context.html?cmd=lastpass</p><p>
O8 - Extra context menu item: LastPass Fill Forms - file://C:\Program Files (x86)\LastPass\context.html?cmd=fillforms</p><p>
O8 - Extra context menu item: Se&amp;nd to OneNote - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105</p><p>
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll</p><p>
O9 - Extra 'Tools' menuitem: Se&amp;nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll</p><p>
O9 - Extra button: LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files (x86)\LastPass\LPBar.dll</p><p>
O9 - Extra button: OneNote Lin&amp;ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll</p><p>
O9 - Extra 'Tools' menuitem: OneNote Lin&amp;ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll</p><p>
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL</p><p>
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll</p><p>
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll</p><p>
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics</p><p>
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</p><p>
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll</p><p>
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL</p><p>
O21 - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll</p><p>
O22 - SharedTaskScheduler: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll</p><p>
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE</p><p>
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe</p><p>
O23 - Service: Adobe Version Cue CS4 - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe</p><p>
O23 - Service: Acronis Nonstop Backup Service (afcdpsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe</p><p>
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)</p><p>
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)</p><p>
O23 - Service: APC Data Service - American Power Conversion Corporation - C:\Program Files (x86)\APC\APC PowerChute Personal Edition\dataserv.exe</p><p>
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files (x86)\APC\APC PowerChute Personal Edition\mainserv.exe</p><p>
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe</p><p>
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe</p><p>
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe</p><p>
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe</p><p>
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)</p><p>
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)</p><p>
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe</p><p>
O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe</p><p>
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe</p><p>
O23 - Service: JungleDiskService - Jungle Disk, Inc. - C:\Program Files\Jungle Disk Desktop\JungleDiskMonitor.exe</p><p>
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)</p><p>
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe</p><p>
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)</p><p>
O23 - Service: NAS PM Service (NasPmService) - BUFFALO INC. - C:\Program Files (x86)\BUFFALO\NASNAVI\nassvc.exe</p><p>
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)</p><p>
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)</p><p>
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)</p><p>
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)</p><p>
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)</p><p>
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)</p><p>
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)</p><p>
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe</p><p>
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)</p><p>
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)</p><p>
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)</p><p>
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)</p><p>
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)</p><p>
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)</p><p>
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)</p><p>
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)</p><p>
</p><p>
--</p><p>
End of file - 13029 bytes</p><p>
 </p><p>
Hope you can help!</p>
]]></description><guid isPermaLink="false">5093</guid><pubDate>Tue, 04 Oct 2011 09:56:57 +0000</pubDate></item><item><title>HijackThis Log.</title><link>https://forums.lunarsoft.net/topic/5090-hijackthis-log/</link><description><![CDATA[<p>Logfile of Trend Micro HijackThis v2.0.4</p><p>
Scan saved at 12:16:05, on 02/10/2011</p><p>
Platform: Windows 7 SP1 (WinNT 6.00.3505)</p><p>
MSIE: Internet Explorer v9.00 (9.00.8112.16421)</p><p>
Boot mode: Normal</p><p>
</p><p>
Running processes:</p><p>
C:\Windows\system32\taskhost.exe</p><p>
C:\Windows\system32\Dwm.exe</p><p>
C:\Windows\Explorer.EXE</p><p>
C:\Program Files\Common Files\Java\Java Update\jusched.exe</p><p>
C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe</p><p>
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe</p><p>
C:\Program Files\Microsoft Security Client\msseces.exe</p><p>
C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe</p><p>
C:\Program Files\iTunes\iTunesHelper.exe</p><p>
C:\Program Files\DivX\DivX Update\DivXUpdate.exe</p><p>
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe</p><p>
C:\Program Files\Internet Explorer\IELowutil.exe</p><p>
</p><p>
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.msn.com/</p><p>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157</p><p>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896</p><p>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896</p><p>
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157</p><p>
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =</p><p>
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =</p><p>
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =</p><p>
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =</p><p>
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local</p><p>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =</p><p>
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll</p><p>
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll</p><p>
O2 - BHO: Increase performance and video formats for your HTML5 &lt;video&gt; - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll</p><p>
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll</p><p>
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll</p><p>
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll</p><p>
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll</p><p>
O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"</p><p>
O4 - HKLM\..\Run: [sSDMonitor] C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe</p><p>
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s</p><p>
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime</p><p>
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey</p><p>
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume</p><p>
O4 - HKLM\..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide</p><p>
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"</p><p>
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW</p><p>
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"</p><p>
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"</p><p>
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll</p><p>
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll</p><p>
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll</p><p>
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll</p><p>
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll</p><p>
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll</p><p>
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics</p><p>
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll</p><p>
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe</p><p>
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe</p><p>
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe</p><p>
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe</p><p>
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe</p><p>
O23 - Service: Jumpstart Wifi Protected Setup (jswpsapi) - Atheros Communications, Inc. - C:\Program Files\NETGEAR\WN111v2\jswpsapi.exe</p><p>
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - Unknown owner - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe</p><p>
O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe</p><p>
</p><p>
--</p><p>
End of file - 6085 bytes</p><p>
 </p><p>
Any Recommendations?</p><p>
Thanks</p>
]]></description><guid isPermaLink="false">5090</guid><pubDate>Sun, 02 Oct 2011 11:18:21 +0000</pubDate></item><item><title>Senutyenool HJT Log</title><link>https://forums.lunarsoft.net/topic/5015-senutyenool-hjt-log/</link><description><![CDATA[<p>Firstly let me say G'day all <img src="https://forums.lunarsoft.net/uploads/default_hello.gif" alt=":hello:" loading="lazy">, haven't visited for a loooong time and must say it's good to see that your still up and running Tarun.</p><p>
</p><p>
Now, down to the nitty-gritty, my system's starting to become sluggish and I've run all necessary precautions and scans and have come up with zip, hence why I'm posting my HJT log in case you see something I've missed.  I'm guessing if this comes up clean then it's time to go for a re-format and re-install.... /lesigh.</p><p>
</p><p>
Nothing running that shouldn't be, did this after startup, with only FF4, TB and Chrome up.</p><p>
</p><p>
Cheers</p><p>
</p><p>
Logfile of Trend Micro HijackThis v2.0.4</p><p>
Scan saved at 1:36:01 PM, on 7/06/2011</p><p>
Platform: Windows Vista SP2 (WinNT 6.00.1906)</p><p>
MSIE: Internet Explorer v8.00 (8.00.6001.19048)</p><p>
Boot mode: Normal</p><p>
</p><p>
Running processes:</p><p>
C:\Program Files (x86)\The Cleaner\tcap.exe</p><p>
C:\Windows\SysWOW64\rundll32.exe</p><p>
C:\Program Files (x86)\Windows Sidebar\sidebar.exe</p><p>
C:\Program Files (x86)\Spybot - Search &amp; Destroy\TeaTimer.exe</p><p>
C:\Program Files (x86)\Winstep\Nextstart.exe</p><p>
C:\Program Files (x86)\Winstep\WorkShelf.exe</p><p>
C:\Program Files (x86)\Internode\mum.exe</p><p>
C:\Program Files (x86)\Secunia\PSI\psi_tray.exe</p><p>
C:\Program Files (x86)\TruDirect\TruDirectTray.exe</p><p>
C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe</p><p>
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe</p><p>
C:\Program Files (x86)\iTunes\iTunesHelper.exe</p><p>
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe</p><p>
C:\Program Files (x86)\Windows Sidebar\sidebar.exe</p><p>
C:\Users\Flo\AppData\Local\Google\Chrome\Application\chrome.exe</p><p>
C:\Users\Flo\AppData\Local\Google\Chrome\Application\chrome.exe</p><p>
C:\Users\Flo\AppData\Local\Google\Chrome\Application\chrome.exe</p><p>
C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe</p><p>
C:\Program Files (x86)\Mozilla Firefox\firefox.exe</p><p>
C:\Windows\SysWOW64\rundll32.exe</p><p>
C:\Users\Flo\AppData\Local\Google\Chrome\Application\chrome.exe</p><p>
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe</p><p>
C:\Windows\SysWOW64\DllHost.exe</p><p>
</p><p>
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896</p><p>
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank</p><p>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896</p><p>
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank</p><p>
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = </p><p>
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = </p><p>
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm</p><p>
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local</p><p>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = </p><p>
O1 - Hosts: ::1 localhost</p><p>
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files (x86)\Orbitdownloader\orbitcth.dll</p><p>
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitBHO.dll</p><p>
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll</p><p>
O2 - BHO: Increase performance and video formats for your HTML5 &lt;video&gt; - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll</p><p>
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll</p><p>
O2 - BHO: Use the DivX Plus Web Player to watch web videos with less interruptions and smoother playback on supported sites - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll</p><p>
O2 - BHO: LastPass Browser Helper Object - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPBar.dll</p><p>
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll</p><p>
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - "C:\Program Files\BitDefender\BitDefender 2010\Antispam32\IEToolbar.dll" (file missing)</p><p>
O3 - Toolbar: LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPBar.dll</p><p>
O3 - Toolbar: Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitIEAddin.dll</p><p>
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"</p><p>
O4 - HKLM\..\Run: [HTC Sync Loader] "C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" -startup</p><p>
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime</p><p>
O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"</p><p>
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"</p><p>
O4 - HKLM\..\Run: [switchBoard] "C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe"</p><p>
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin</p><p>
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW</p><p>
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"</p><p>
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"</p><p>
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray</p><p>
O4 - HKCU\..\Run: [sidebar] C:\Program Files (x86)\Windows Sidebar\sidebar.exe /autoRun</p><p>
O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search &amp; Destroy\TeaTimer.exe</p><p>
O4 - HKCU\..\Run: [NextSTART] C:\Program Files (x86)\Winstep\nextstart.exe autostart</p><p>
O4 - HKCU\..\Run: [Workshelf] C:\Program Files (x86)\Winstep\workshelf.exe autostart</p><p>
O4 - HKCU\..\Run: [Google Update] "C:\Users\Flo\AppData\Local\Google\Update\GoogleUpdate.exe" /c</p><p>
O4 - HKCU\..\Run: [internodeUsage] C:\PROGRA~2\INTERN~2\mum.exe</p><p>
O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')</p><p>
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')</p><p>
O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')</p><p>
O4 - HKUS\S-1-5-21-2697327504-3007918418-1427719425-1002\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'UpdatusUser')</p><p>
O4 - Global Startup: Secunia PSI Tray.lnk = C:\Program Files (x86)\Secunia\PSI\psi_tray.exe</p><p>
O4 - Global Startup: TruDirectTray.lnk = C:\Program Files (x86)\TruDirect\TruDirectTray.exe</p><p>
O8 - Extra context menu item: &amp;Download by Orbit - res://C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/201</p><p>
O8 - Extra context menu item: &amp;Grab video by Orbit - res://C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/204</p><p>
O8 - Extra context menu item: Do&amp;wnload selected by Orbit - res://C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/203</p><p>
O8 - Extra context menu item: Down&amp;load all by Orbit - res://C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/202</p><p>
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000</p><p>
O8 - Extra context menu item: LastPass - file://C:\Program Files (x86)\LastPass\context.html?cmd=lastpass</p><p>
O8 - Extra context menu item: LastPass Fill Forms - file://C:\Program Files (x86)\LastPass\context.html?cmd=fillforms</p><p>
O8 - Extra context menu item: Open using &amp;Advanced JPEG Compressor - C:\Program Files (x86)\Advanced JPEG Compressor\ajcieex.htm</p><p>
O9 - Extra button: LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files (x86)\LastPass\LPBar.dll</p><p>
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll</p><p>
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll</p><p>
O10 - Unknown file in Winsock LSP: pcaplsp.dll</p><p>
O10 - Unknown file in Winsock LSP: pcaplsp.dll</p><p>
O10 - Unknown file in Winsock LSP: pcaplsp.dll</p><p>
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab</p><p>
O17 - HKLM\System\CCS\Services\Tcpip\..\{7EB53743-C73C-4D81-985E-1695BEC22805}: NameServer = 192.231.203.132,192.231.203.3</p><p>
O17 - HKLM\System\CS1\Services\Tcpip\..\{7EB53743-C73C-4D81-985E-1695BEC22805}: NameServer = 192.231.203.132,192.231.203.3</p><p>
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll</p><p>
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE</p><p>
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)</p><p>
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe</p><p>
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. http://www.bitdefender.com - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe</p><p>
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe</p><p>
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - C:\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe</p><p>
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)</p><p>
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe</p><p>
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)</p><p>
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe</p><p>
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe</p><p>
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)</p><p>
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe</p><p>
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)</p><p>
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)</p><p>
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe</p><p>
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe</p><p>
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\SysWOW64\IoctlSvc.exe</p><p>
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)</p><p>
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)</p><p>
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)</p><p>
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search &amp; Destroy\SDWinSec.exe</p><p>
O23 - Service: Secunia PSI Agent - Secunia - C:\Program Files (x86)\Secunia\PSI\PSIA.exe</p><p>
O23 - Service: Secunia Update Agent - Secunia - C:\Program Files (x86)\Secunia\PSI\sua.exe</p><p>
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)</p><p>
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)</p><p>
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)</p><p>
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe</p><p>
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe</p><p>
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)</p><p>
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)</p><p>
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)</p><p>
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe</p><p>
O23 - Service: Winstep Xtreme Service - Unknown owner - C:\Program.exe (file missing)</p><p>
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)</p><p>
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)</p><p>
</p><p>
--</p><p>
End of file - 12816 bytes</p>
]]></description><guid isPermaLink="false">5015</guid><pubDate>Tue, 07 Jun 2011 03:37:42 +0000</pubDate></item><item><title>UKPunk-HijackThis Log 2</title><link>https://forums.lunarsoft.net/topic/4957-ukpunk-hijackthis-log-2/</link><description><![CDATA[<p>Hi Tarun, can you check out my log for me please? Many thanks.</p><p>
</p><p>
Logfile of Trend Micro HijackThis v2.0.4</p><p>
Scan saved at 13:26:33, on 27/04/2011</p><p>
Platform: Windows XP SP3 (WinNT 5.01.2600)</p><p>
MSIE: Internet Explorer v7.00 (7.00.5730.0013)</p><p>
Boot mode: Normal</p><p>
</p><p>
Running processes:</p><p>
C:\WINDOWS\System32\smss.exe</p><p>
C:\WINDOWS\system32\winlogon.exe</p><p>
C:\WINDOWS\system32\services.exe</p><p>
C:\WINDOWS\system32\lsass.exe</p><p>
C:\WINDOWS\system32\svchost.exe</p><p>
C:\WINDOWS\System32\svchost.exe</p><p>
C:\WINDOWS\system32\svchost.exe</p><p>
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe</p><p>
C:\WINDOWS\system32\spoolsv.exe</p><p>
C:\WINDOWS\system32\CTsvcCDA.EXE</p><p>
C:\Program Files\Java\jre6\bin\jqs.exe</p><p>
C:\Program Files\Kontiki\KService.exe</p><p>
C:\WINDOWS\system32\svchost.exe</p><p>
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe</p><p>
C:\Program Files\Inventel\Gateway\wlancfg.exe</p><p>
C:\WINDOWS\system32\wscntfy.exe</p><p>
C:\WINDOWS\Explorer.EXE</p><p>
C:\WINDOWS\system32\VTTimer.exe</p><p>
C:\Program Files\Alwil Software\Avast5\avastUI.exe</p><p>
C:\Program Files\Common Files\Real\Update_OB\realsched.exe</p><p>
C:\Program Files\Firetrust\Benign\B9.exe</p><p>
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe</p><p>
C:\Program Files\HDD Health\hddhealth.exe</p><p>
C:\WINDOWS\system32\ctfmon.exe</p><p>
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe</p><p>
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpCtr.exe</p><p>
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe</p><p>
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpHost.exe</p><p>
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe</p><p>
</p><p>
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896</p><p>
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/</p><p>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157</p><p>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896</p><p>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896</p><p>
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157</p><p>
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = </p><p>
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = </p><p>
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://uk.search.yahoo.com</p><p>
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843</p><p>
O1 - Hosts: 127.98.9.1 pop.orangehome.co.uk.b9</p><p>
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)</p><p>
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll</p><p>
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll</p><p>
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll</p><p>
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll</p><p>
O2 - BHO: Z-opti Browser Enhancer  - {C348BB9A-995C-404A-8185-76325B4BED9F} - C:\WINDOWS\$XNTUninstall643$\mbdwt.dll</p><p>
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll</p><p>
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll</p><p>
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll</p><p>
O2 - BHO: Context-Ads Browser Enhancer  - {F96A7C1E-38CA-4F0A-9D2D-A42C226BCDC8} - C:\WINDOWS\$XNTUninstall643$\xgoir.dll</p><p>
O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll</p><p>
O3 - Toolbar: LimeWire Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll</p><p>
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll</p><p>
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe</p><p>
O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini"</p><p>
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui</p><p>
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime</p><p>
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot</p><p>
O4 - HKLM\..\Run: [bipro] rundll32 "C:\WINDOWS\$XNTUninstall643$\mbdwt.dll",,Run</p><p>
O4 - HKCU\..\Run: [b9] "C:\Program Files\Firetrust\Benign\B9.exe" /minimize</p><p>
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R</p><p>
O4 - HKCU\..\Run: [HDDHealth] C:\Program Files\HDD Health\hddhealth.exe -wl</p><p>
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe</p><p>
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?')</p><p>
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?')</p><p>
O4 - HKUS\S-1-5-21-1292428093-1085031214-839522115-1004\..\Run: [b9] "C:\Program Files\Firetrust\Benign\B9.exe" /minimize (User '?')</p><p>
O4 - HKUS\S-1-5-21-1292428093-1085031214-839522115-1004\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')</p><p>
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?')</p><p>
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')</p><p>
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL</p><p>
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll</p><p>
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll</p><p>
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe</p><p>
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe</p><p>
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe</p><p>
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe</p><p>
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL</p><p>
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll</p><p>
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll</p><p>
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe</p><p>
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE</p><p>
O23 - Service: Google Update Service (gupdate1ca3831c6c24e7a) (gupdate1ca3831c6c24e7a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe</p><p>
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe</p><p>
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe</p><p>
O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe</p><p>
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe</p><p>
O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Unknown owner - C:\Program Files\Inventel\Gateway\wlancfg.exe</p><p>
O24 - Desktop Component 0: (no name) - <img src="http://www.google.co.uk/logos/stgeorge08.gif" alt="" class="ipsImage" loading="lazy"></p><p>
</p><p>
--</p><p>
End of file - 7958 bytes</p>
]]></description><guid isPermaLink="false">4957</guid><pubDate>Wed, 27 Apr 2011 12:30:46 +0000</pubDate></item></channel></rss>
