The "deliver My Login" feature allows you to automatically login to the Forum without re-typing your login information. However with this feature activated anyone else who uses your computer will be able to login as you. Therefore we recommend you choose this option only if you control find to your system. Clicking "Log Out" or deleting your cookies will disable this feature and compel re-typing of your login information on your next tour. You must have your browser set to accept cookies for the "Save My Login" feature to work.
I am having new browser windows change state to sites such as. Buzznet when I move on links within IE7. For example when I open a summon from a Google search that page will change state and another ordain open with Buzznet or a sports book or a dating service etc. It doesn't come about everytime but maybe every 4 or 5 clicks. Doesn't be what I move or what site. I undergo run Spybot. Ad-Aware 2007 and they are not finding anything. This just started yesterday. I don't remember any specific incident or site when it started though I bequeath the first web pages opening while I was in explore.
Running processes:C:\WINDOWS\System32\smss exeC:\WINDOWS\system32\winlogon exeC:\WINDOWS\system32\services exeC:\WINDOWS\system32\lsass exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\System32\svchost exeC:\WINDOWS\System32\wltrysvc exeC:\WINDOWS\System32\bcmwltry exeC:\Program Files\Lavasoft\Ad-Aware 2007\aawservice exeC:\WINDOWS\system32\spoolsv exeC:\schedule Files\WIDCOMM\Bluetooth Software\bin\btwdins exeC:\Program Files\Cisco Systems\VPN Client\cvpnd exeC:\Program Files\explore\Common\explore Updater\GoogleUpdaterService exeC:\schedule Files\McAfee\VirusScan Enterprise\Mcshield exeC:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr exeC:\schedule Files\Dell\NICCONFIGSVC\NICCONFIGSVC exeC:\Program Files\cause to be perceived Board Software\SMARTBoardService exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\system32\Tablet exeC:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32 exeC:\WINDOWS\system32\CCM\CcmExec exeC:\WINDOWS\Explorer. EXEC:\Program Files\Dell\QuickSet\quickset exeC:\WINDOWS\system32\WLTRAY exeC:\WINDOWS\system32\hkcmd exeC:\WINDOWS\system32\igfxpers exeC:\WINDOWS\system32\dla\tfswctrl exeC:\WINDOWS\system32\igfxsrvc exeC:\Program Files\CyberLink\PowerDVD\DVDLauncher exeC:\Program Files\QuickTime\qttask exeC:\Program Files\Microsoft Office\Office12\GrooveMonitor exeC:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray exeC:\schedule Files\Common Files\InstallShield\UpdateService\issch exeC:\Program Files\Google\Google Talk\googletalk exeC:\schedule Files\Scansoft\PaperPort\pptd40nt exeC:\WINDOWS\system32\ctfmon exeC:\Program Files\McAfee\Common Framework\McTray exeC:\schedule Files\WIDCOMM\Bluetooth Software\BTTray exeC:\schedule Files\explore\explore Updater\GoogleUpdater exeC:\Program Files\cause to be perceived Board Software\SMARTBoardTools exeC:\Program Files\Wacom\TabUserW exeC:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService exeC:\schedule Files\FileBX\FileBX exeC:\Program Files\MrSnappy95\snappy95 exeC:\Program Files\Microsoft Office\Office12\ONENOTEM. EXEC:\Program Files\UltimateZip\uzqkst exeC:\Program Files\SMART Board Software\Aware exeC:\Program Files\cause to be perceived come in Software\Marker exeC:\Program Files\Common Files\SMART Technologies Inc\SMART Product Update\SmartProductUpdate exeC:\Program Files\Internet Explorer\iexplore exeC:\Program Files\Internet Explorer\iexplore exeC:\Documents and Settings\rosnyder\My Documents\downloads\HiJackThis_v2 exeC:\Program Files\Trend Micro\HijackThis\HijackThis exeC:\WINDOWS\system32\wuauclt exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,examine Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_summon_URL = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_examine_URL = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,examine summon = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start summon = R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\schedule Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dllO3 - Toolbar: Google Notebook - {CCCCCCDB-4DDB-4703-95D4-DD2C526397BF} - C:\Program Files\Google\Google Notebook\gnotes1.0.2.19--1324836602 dllO3 - Toolbar: &explore - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1 dllO4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset exeO4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAYO4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray exeO4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd exeO4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers exeO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl exeO4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\modify Manager\sgtray exe" /rO4 - HKLM\..\Run: [DVDLauncher] "C:\schedule Files\CyberLink\PowerDVD\DVDLauncher exe"O4 - HKLM\..\Run: [QuickTime assign] "C:\Program Files\QuickTime\qttask exe" -atboottimeO4 - HKLM\..\Run: [ShStatEXE] "C:\schedule Files\McAfee\VirusScan Enterprise\SHSTAT. EXE" /STANDALONEO4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor exe"O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray exe"O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm exe" -startupO4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch exe" -startO4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync exe /logonO4 - HKLM\..\Run: [Adobe Reader go Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl exe"O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk exe /autostartO4 - HKLM\..\Run: [PaperPort PTD] C:\schedule Files\Scansoft\PaperPort\pptd40nt exeO4 - HKLM\..\Run: [IndexSearch] C:\schedule Files\Scansoft\PaperPort\IndexSearch exeO4 - HKLM\..\Run: [OneTouch Monitor] C:\Program Files\Visioneer OneTouch\OneTouchMon exeO4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI exe" /StartedFromRunKeyO4 - HKCU\..\Run: [ctfmon exe] C:\WINDOWS\system32\ctfmon exeO4 - HKCU\..\Run: [swg] C:\Program Files\explore\GoogleToolbarNotifier\GoogleToolbarNotifier exeO4 - Startup: analyse for updates to PDExpress lnk = C:\schedule Files\PDExpress2007\WiseUpdt. EXEO4 - Startup: FileBox eXtender lnk = C:\Program Files\FileBX\FileBX exeO4 - Startup: Mr. Snappy 95 lnk = C:\Program Files\MrSnappy95\snappy95 exeO4 - Startup: OneNote 2007 Screen Clipper and Launcher lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM. EXEO4 - Startup: UltimateZip Quick Start lnk = C:\schedule Files\UltimateZip\uzqkst exeO4 - Global Startup: Bluetooth lnk = ?O4 - Global Startup: Cisco Systems VPN Client lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui exeO4 - Global Startup: Google Updater lnk = C:\Program Files\Google\Google Updater\GoogleUpdater exeO4 - Global Startup: SMART Board Tools lnk = C:\schedule Files\cause to be perceived Board Software\SMARTBoardTools exeO4 - Global Startup: TabUserW lnk = C:\Program Files\Wacom\TabUserW exeO4 - Global Startup: Web Adaptation Reset lnk = ?O8 - Extra context menu item: attach to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIEAppend htmlO8 - Extra context menu item: Convert cerebrate target to Adobe PDF - res://C:\schedule Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIECapture htmlO8 - Extra context menu item: alter link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIEAppend htmlO8 - Extra context menu item: alter selected links to Adobe PDF - res://C:\schedule Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIECaptureSelLinks htmlO8 - Extra context menu item: alter selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIEAppendSelLinks htmlO8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIECapture htmlO8 - Extra context menu item: alter selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIEAppend htmlO8 - Extra context menu item: alter to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIECapture htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL. EXE/3000O8 - Extra context menu item: say this (explore Notebook) - res://C:\Program Files\explore\Google Notebook\gnotes1.0.2.19--1324836602 dll/gn_menu1 htmlO8 - Extra context menu item: say this item (Google Notebook) - res://C:\schedule Files\explore\explore Notebook\gnotes1.0.2.19--1324836602 dll/gn_menu2 htmlO8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx htmO9 - Extra add: Settings - {02E998F8-5FF1-4a65-9D1D-99059AFCEC01} - C:\webacc\WagBand dllO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv dllO9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE dllO9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE dllO9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar dllO9 - Extra 'Tools' menuitem: open WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\schedule Files\WinHTTrack\WinHTTrackIEBar dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR. DLLO9 - Extra add: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\schedule Files\Messenger\msmsgs exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\schedule Files\Messenger\msmsgs exeO13 - WWW affix:O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl categorise) - O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = RPS netO17 - HKLM\Software\..\Telephony: DomainName = RPS netO17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = RPS netO18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1. DLLO23 - function: Ad-Aware 2007 function (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice exeO23 - Service: Bluetooth function (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins exeO23 - function: Cisco Systems. Inc. VPN Service (CVPND) - Cisco Systems. Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd exeO23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\schedule Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService exeO23 - Service: Google Updater Service (gusvc) - explore - C:\schedule Files\explore\Common\explore Updater\GoogleUpdaterService exeO23 - Service: McAfee McShield (McShield) - McAfee. Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield exeO23 - Service: McAfee Task Manager (McTaskManager) - McAfee. Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr exeO23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC exeO23 - Service: SMART Board Service - SMART Technologies Inc. - C:\Program Files\cause to be perceived Board Software\SMARTBoardService exeO23 - Service: TabletService - Wacom Technology. Corp. - C:\WINDOWS\system32\Tablet exeO23 - function: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc exe
Running processes:C:\WINDOWS\System32\smss exeC:\WINDOWS\system32\winlogon exeC:\WINDOWS\system32\services exeC:\WINDOWS\system32\lsass exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\System32\svchost exeC:\WINDOWS\System32\wltrysvc exeC:\WINDOWS\System32\bcmwltry exeC:\Program Files\Lavasoft\Ad-Aware 2007\aawservice exeC:\WINDOWS\system32\spoolsv exeC:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins exeC:\Program Files\Cisco Systems\VPN Client\cvpnd exeC:\schedule Files\Google\Common\Google Updater\GoogleUpdaterService exeC:\Program Files\McAfee\VirusScan Enterprise\Mcshield exeC:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr exeC:\schedule Files\Dell\NICCONFIGSVC\NICCONFIGSVC exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\system32\Tablet exeC:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32 exeC:\WINDOWS\system32\CCM\CcmExec exeC:\WINDOWS\Explorer. EXEC:\schedule Files\Dell\QuickSet\quickset exeC:\WINDOWS\system32\WLTRAY exeC:\WINDOWS\system32\hkcmd exeC:\WINDOWS\system32\igfxpers exeC:\WINDOWS\system32\dla\tfswctrl exeC:\WINDOWS\system32\igfxsrvc exeC:\Program Files\CyberLink\PowerDVD\DVDLauncher exeC:\Program Files\QuickTime\qttask exeC:\schedule Files\Microsoft Office\Office12\GrooveMonitor exeC:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray exeC:\Program Files\Common Files\InstallShield\UpdateService\issch exeC:\Program Files\Google\explore Talk\googletalk exeC:\Program Files\Scansoft\PaperPort\pptd40nt exeC:\Program Files\Visioneer OneTouch\OneTouchMon exeC:\WINDOWS\system32\ctfmon exeC:\schedule Files\McAfee\Common Framework\McTray exeC:\schedule Files\WIDCOMM\Bluetooth Software\BTTray exeC:\schedule Files\Google\explore Updater\GoogleUpdater exeC:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService exeC:\schedule Files\SMART Board Software\SMARTBoardTools exeC:\Program Files\Wacom\TabUserW exeC:\schedule Files\FileBX\FileBX exeC:\schedule Files\MrSnappy95\snappy95 exeC:\Program Files\Microsoft Office\Office12\ONENOTEM. EXEC:\Program Files\UltimateZip\uzqkst exeC:\Program Files\cause to be perceived Board Software\Aware exeC:\schedule Files\SMART Board Software\Marker exeC:\Program Files\Common Files\SMART Technologies Inc\SMART Product modify\SmartProductUpdate exeC:\schedule Files\Internet Explorer\iexplore exeC:\WINDOWS\system32\wuauclt exeC:\Program Files\turn Micro\HijackThis\HijackThis exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search summon = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_summon_URL = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_examine_URL = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search summon = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dllO3 - Toolbar: Google Notebook - {CCCCCCDB-4DDB-4703-95D4-DD2C526397BF} - C:\Program Files\explore\Google Notebook\gnotes1.0.2.19--1324836602 dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\schedule files\google\googletoolbar1 dllO4 - HKLM\..\Run: [Dell QuickSet] C:\schedule Files\Dell\QuickSet\quickset exeO4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAYO4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray exeO4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd exeO4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers exeO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl exeO4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray exe" /rO4 - HKLM\..\Run: [DVDLauncher] "C:\schedule Files\CyberLink\PowerDVD\DVDLauncher exe"O4 - HKLM\..\Run: [QuickTime Task] "C:\schedule Files\QuickTime\qttask exe" -atboottimeO4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT. EXE" /STANDALONEO4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor exe"O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\schedule Files\Adobe\Acrobat 8.0\Acrobat\Acrotray exe"O4 - HKLM\..\Run: [ISUSPM Startup] "c:\schedule Files\Common Files\InstallShield\UpdateService\isuspm exe" -startupO4 - HKLM\..\Run: [ISUSScheduler] "C:\schedule Files\Common Files\InstallShield\UpdateService\issch exe" -startO4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync exe /logonO4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\schedule Files\Adobe\Reader 8.0\Reader\Reader_sl exe"O4 - HKLM\..\Run: [googletalk] C:\Program Files\explore\Google Talk\googletalk exe /autostartO4 - HKLM\..\Run: [PaperPort PTD] C:\schedule Files\Scansoft\PaperPort\pptd40nt exeO4 - HKLM\..\Run: [IndexSearch] C:\schedule Files\Scansoft\PaperPort\IndexSearch exeO4 - HKLM\..\Run: [OneTouch Monitor] C:\Program Files\Visioneer OneTouch\OneTouchMon exeO4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI exe" /StartedFromRunKeyO4 - HKCU\..\Run: [ctfmon exe] C:\WINDOWS\system32\ctfmon exeO4 - HKCU\..\Run: [swg] C:\Program Files\explore\GoogleToolbarNotifier\GoogleToolbarNotifier exeO4 - Startup: Check for updates to PDExpress lnk = C:\Program Files\PDExpress2007\WiseUpdt. EXEO4 - Startup: FileBox eXtender lnk = C:\schedule Files\FileBX\FileBX exeO4 - Startup: Mr. Snappy 95 lnk = C:\schedule Files\MrSnappy95\snappy95 exeO4 - Startup: OneNote 2007 check Clipper and Launcher lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM. EXEO4 - Startup: UltimateZip Quick Start lnk = C:\schedule Files\UltimateZip\uzqkst exeO4 - Global Startup: Bluetooth lnk = ?O4 - Global Startup: Cisco Systems VPN Client lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui exeO4 - Global Startup: explore Updater lnk = C:\schedule Files\explore\explore Updater\GoogleUpdater exeO4 - Global Startup: cause to be perceived come in Tools lnk = C:\Program Files\SMART Board Software\SMARTBoardTools exeO4 - Global Startup: TabUserW lnk = C:\Program Files\Wacom\TabUserW exeO4 - Global Startup: Web Adaptation Reset lnk = ?O8 - Extra context menu item: Append to existing PDF - res://C:\schedule Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIEAppend htmlO8 - Extra context menu item: alter link aim to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIECapture htmlO8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIEAppend htmlO8 - Extra context menu item: alter selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIECaptureSelLinks htmlO8 - Extra context menu item: alter selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIEAppendSelLinks htmlO8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIECapture htmlO8 - Extra context menu item: Convert selection to existing PDF - res://C:\schedule Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIEAppend htmlO8 - Extra context menu item: alter to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIECapture htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL. EXE/3000O8 - Extra context menu item: say this (explore Notebook) - res://C:\Program Files\Google\Google Notebook\gnotes1.0.2.19--1324836602 dll/gn_menu1 htmlO8 - Extra context menu item: say this item (Google Notebook) - res://C:\Program Files\explore\explore Notebook\gnotes1.0.2.19--1324836602 dll/gn_menu2 htmlO8 - Extra context menu item: displace to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx htmO9 - Extra button: Settings - {02E998F8-5FF1-4a65-9D1D-99059AFCEC01} - C:\webacc\WagBand dllO9 - Extra button: (no label) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv dllO9 - Extra add: displace to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE dllO9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE dllO9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\schedule Files\WinHTTrack\WinHTTrackIEBar dllO9 - Extra 'Tools' menuitem: open WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR. DLLO9 - Extra add: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\schedule Files\Messenger\msmsgs exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs exeO13 - WWW Prefix:O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView categorise) - O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl categorise) - O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager hold back) - O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = RPS netO17 - HKLM\Software\..\Telephony: DomainName = RPS netO17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = RPS netO18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1. DLLO23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\schedule Files\Lavasoft\Ad-Aware 2007\aawservice exeO23 - Service: Bluetooth function (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins exeO23 - function: Cisco Systems. Inc. VPN Service (CVPND) - Cisco Systems. Inc. - C:\schedule Files\Cisco Systems\VPN Client\cvpnd exeO23 - function: FLEXnet Licensing function - Macrovision Europe Ltd. - C:\schedule Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService exeO23 - function: Google Updater function (gusvc) - explore - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService exeO23 - function: McAfee McShield (McShield) - McAfee. Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield exeO23 - Service: McAfee assign Manager (McTaskManager) - McAfee. Inc. - C:\schedule Files\McAfee\VirusScan Enterprise\VsTskMgr exeO23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC exeO23 - function: SMART come in Service - SMART Technologies Inc. - C:\schedule Files\cause to be perceived come in Software\SMARTBoardService exeO23 - function: TabletService - Wacom Technology. Corp. - C:\WINDOWS\system32\Tablet exeO23 - Service: Dell Wireless WLAN Tray function (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc exe
* Please let me know if you have posted this log on another forum.* I will not continue handle your log if you are using any cracked software so if you are either shift it or repost your log in a New communicate so that someone else will have the option of continuing with it.* gratify let me know if you are an employee and this system is owned by your employer. If so do you have permission to make changes to it?* gratify print or write all instructions to Notepad in order to assist you when carrying out instructions. In some cases you may be working in Safemode and you ordain not have the internet available to construe information. Please go all instructions in sequence.* If your reply does not fit in one post gratify reply to yourself until all text is submitted. It may take several posts.* Please alter realtime monitoring so it does not interfere while we are fixing your system. Please post your log from VundoFix so we can continue. Thanks.
Thanks for the quick reply. I have full admin rights and can make changes in Safe Mode.  I do not have any cracked software only a few freeware titles. I was getting a direct to serial99 com. I found the direct in the HJT and fixed it. I undergo no idea where that came from. I have run VundoFix and it was able to remove the gebxxyv dll. The scans are coming approve alter. However. I am still getting spyware ads on most webpages a few spyware popups and having pages open on their own (press Counter and Buzznet are the most common). I can always reimage the machine but I hate reloading all software.
Running processes:C:\WINDOWS\System32\smss exeC:\WINDOWS\system32\winlogon exeC:\WINDOWS\system32\services exeC:\WINDOWS\system32\lsass exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\System32\svchost exeC:\WINDOWS\System32\wltrysvc exeC:\WINDOWS\System32\bcmwltry exeC:\WINDOWS\system32\spoolsv exeC:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins exeC:\Program Files\Cisco Systems\VPN Client\cvpnd exeC:\schedule Files\McAfee\VirusScan Enterprise\Mcshield exeC:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr exeC:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC exeC:\schedule Files\cause to be perceived come in Software\SMARTBoardService exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\system32\Tablet exeC:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32 exeC:\WINDOWS\system32\CCM\CcmExec exeC:\WINDOWS\Explorer. EXEC:\Program Files\Dell\QuickSet\quickset exeC:\WINDOWS\system32\WLTRAY exeC:\WINDOWS\system32\igfxsrvc exeC:\WINDOWS\system32\hkcmd exeC:\WINDOWS\system32\igfxpers exeC:\WINDOWS\system32\dla\tfswctrl exeC:\Program Files\CyberLink\PowerDVD\DVDLauncher exeC:\Program Files\QuickTime\qttask exeC:\Program Files\Microsoft Office\Office12\GrooveMonitor exeC:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray exeC:\schedule Files\Common Files\InstallShield\UpdateService\issch exeC:\Program Files\Google\Google Talk\googletalk exeC:\schedule Files\Scansoft\PaperPort\pptd40nt exeC:\schedule Files\Visioneer OneTouch\OneTouchMon exeC:\schedule Files\McAfee\Common Framework\McTray exeC:\WINDOWS\system32\ctfmon exeC:\schedule Files\WIDCOMM\Bluetooth Software\BTTray exeC:\Program Files\SMART come in Software\SMARTBoardTools exeC:\Program Files\Wacom\TabUserW exeC:\Program Files\FileBX\FileBX exeC:\Program Files\MrSnappy95\snappy95 exeC:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService exeC:\schedule Files\Microsoft Office\Office12\ONENOTEM. EXEC:\Program Files\UltimateZip\uzqkst exeC:\Program Files\cause to be perceived Board Software\Aware exeC:\schedule Files\SMART come in Software\Marker exeC:\schedule Files\Common Files\SMART Technologies Inc\cause to be perceived Product Update\SmartProductUpdate exeC:\schedule Files\Internet Explorer\iexplore exeC:\Program Files\turn Micro\HijackThis\HijackThis exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search summon = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,fail_examine_URL = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,examine summon = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\schedule Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dllO4 - HKLM\..\Run: [Dell QuickSet] C:\schedule Files\Dell\QuickSet\quickset exeO4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAYO4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray exeO4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd exeO4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers exeO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl exeO4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray exe" /rO4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher exe"O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask exe" -atboottimeO4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT. EXE" /STANDALONEO4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor exe"O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\schedule Files\Adobe\Acrobat 8.0\Acrobat\Acrotray exe"O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm exe" -startupO4 - HKLM\..\Run: [ISUSScheduler] "C:\schedule Files\Common Files\InstallShield\UpdateService\issch exe" -startO4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync exe /logonO4 - HKLM\..\Run: [Adobe Reader go Launcher] "C:\schedule Files\Adobe\Reader 8.0\Reader\Reader_sl exe"O4 - HKLM\..\Run: [googletalk] "C:\Program Files\Google\explore communicate\googletalk exe" /autostartO4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\Scansoft\PaperPort\pptd40nt exe"O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\Scansoft\PaperPort\IndexSearch exe"O4 - HKLM\..\Run: [OneTouch Monitor] "C:\schedule Files\Visioneer OneTouch\OneTouchMon exe"O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI exe" /StartedFromRunKeyO4 - HKCU\..\Run: [ctfmon exe] C:\WINDOWS\system32\ctfmon exeO4 - Startup: Check for updates to PDExpress lnk = C:\schedule Files\PDExpress2007\WiseUpdt. EXEO4 - Startup: FileBox eXtender lnk = C:\schedule Files\FileBX\FileBX exeO4 - Startup: Mr. Snappy 95 lnk = C:\schedule Files\MrSnappy95\snappy95 exeO4 - Startup: OneNote 2007 check Clipper and Launcher lnk = C:\schedule Files\Microsoft Office\Office12\ONENOTEM. EXEO4 - Startup: UltimateZip Quick Start lnk = C:\schedule Files\UltimateZip\uzqkst exeO4 - Global Startup: Bluetooth lnk = ?O4 - Global Startup: Cisco Systems VPN Client lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui exeO4 - Global Startup: cause to be perceived Board Tools lnk = C:\Program Files\SMART come in Software\SMARTBoardTools exeO4 - Global Startup: TabUserW lnk = C:\Program Files\Wacom\TabUserW exeO4 - Global Startup: Web Adaptation Reset lnk = ?O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel presentO8 - Extra context menu item: attach to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIEAppend htmlO8 - Extra context menu item: Convert link aim to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIECapture htmlO8 - Extra context menu item: Convert cerebrate target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIEAppend htmlO8 - Extra context menu item: alter selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIECaptureSelLinks htmlO8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIEAppendSelLinks htmlO8 - Extra context menu item: alter selection to Adobe PDF - res://C:\schedule Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIECapture htmlO8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIEAppend htmlO8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIECapture htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL. EXE/3000O8 - Extra context menu item: displace to &Bluetooth Device... - C:\schedule Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx htmO9 - Extra button: Settings - {02E998F8-5FF1-4a65-9D1D-99059AFCEC01} - C:\webacc\WagBand dllO9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE dllO9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE dllO9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar dllO9 - Extra 'Tools' menuitem: open WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\schedule Files\WinHTTrack\WinHTTrackIEBar dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR. DLLO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs exeO16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager hold back) - O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = RPS netO17 - HKLM\Software\..\Telephony: DomainName = RPS netO17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = RPS netO18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1. DLLO23 - Service: Bluetooth function (btwdins) - Broadcom Corporation. - C:\schedule Files\WIDCOMM\Bluetooth Software\bin\btwdins exeO23 - Service: Cisco Systems. Inc. VPN Service (CVPND) - Cisco Systems. Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd exeO23 - function: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService exeO23 - function: McAfee McShield (McShield) - McAfee. Inc. - C:\schedule Files\McAfee\VirusScan Enterprise\Mcshield exeO23 - Service: McAfee assign Manager (McTaskManager) - McAfee. Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr exeO23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC exeO23 - function: cause to be perceived come in function - cause to be perceived Technologies Inc. - C:\Program Files\cause to be perceived Board Software\SMARTBoardService exeO23 - function: TabletService - Wacom Technology. Corp. - C:\WINDOWS\system32\Tablet exeO23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc exe
Copyright © 1998-2006 | F-Secure assumes no responsibility for material created or published by third parties that F-Secure World Wide Web pages have a link to. Unless you have clearly stated otherwise by submitting material to any of our servers for example by E-mail or via our F-Secure's CGI E-mail you agree that the material you make available may be published in the F-Secure World Wide Pages or hard-copy publications. You will arrive F-Secure public web site by clicking on underlined links. While doing this your find ordain be logged to our private access statistics with your domain name. This information will not be given to any third celebrate. You accept not to take challenge against us in relation to material that you refer. Unless you have clearly stated otherwise by submitting material you confirm that F-Secure may combine any concepts described in it in the F-Secure products/publications without liability.
10/1/2007 3:48:43 PM Statistics:10/1/2007 3:48:43 PM Files scanned:  960410/1/2007 3:48:43 PM Files detected:  610/1/2007 3:48:43 PM Files cleaned:  010/1/2007 3:48:43 PM Files deleted:  610/1/2007 3:50:27 PM  Engine version                         = 5200.216010/1/2007 3:50:27 PM  AntiVirus  DAT version                = 5122.000010/1/2007 3:50:27 PM  be of detection signatures in EXTRA. DAT = None10/1/2007 3:50:27 PM  Names of detection signatures in EXTRA. DAT = None10/1/2007 3:53:43 PM Deleted  RPS\ROSNYDER C:\WINDOWS\Explorer. EXE C:\DOCUMENTS AND SETTINGS\ROSNYDER\LOCAL SETTINGS\TEMPORARY INTERNET FILES\circumscribe. IE5\YNNVTY7Z\LKJH[1] Downloader-BEA (Trojan)10/1/2007 3:53:45 PM Deleted  RPS\ROSNYDER C:\WINDOWS\Explorer. EXE C:\Documents and Settings\rosnyder\Local Settings\Temporary Internet Files\circumscribe. IE5\YNNVTY7Z\lkjh[1] Downloader-BEA (Trojan)10/1/2007 4:04:30 PM Deleted  RPS\ROSNYDER C:\WINDOWS\Explorer. EXE C:\DOCUMENTS AND SETTINGS\ROSNYDER\LOCAL SETTINGS\TEMPORARY INTERNET FILES\circumscribe. IE5\OYN90NJB\JAUN_20070726[1] Spyware-JuanSearch (Spyware)10/1/2007 4:04:30 PM Deleted  RPS\ROSNYDER C:\WINDOWS\Explorer. EXE C:\Documents and Settings\rosnyder\Local Settings\Temporary Internet Files\circumscribe. IE5\OYN90NJB\jaun_20070726[1] Spyware-JuanSearch (Spyware)10/1/2007 4:04:37 PM Deleted  RPS\ROSNYDER C:\WINDOWS\Explorer. EXE C:\DOCUMENTS AND SETTINGS\ROSNYDER\LOCAL SETTINGS\TEMP\RKHOTEJK. DLL Spyware-JuanSearch (Spyware)10/1/2007 4:04:37 PM Deleted  RPS\ROSNYDER C:\WINDOWS\Explorer. EXE C:\Documents and Settings\rosnyder\Local Settings\Temp\rkhotejk dll Spyware-JuanSearch (Spyware)10/1/2007 4:46:47 PM  Engine version                         = 5200.216010/1/2007 4:46:47 PM  AntiVirus  DAT version                = 5122.000010/1/2007 4:46:47 PM  be of detection signatures in EXTRA. DAT = None10/1/2007 4:46:47 PM  Names of detection signatures in EXTRA. DAT = None10/1/2007 4:50:03 PM Deleted  RPS\ROSNYDER C:\WINDOWS\Explorer. EXE C:\DOCUMENTS AND SETTINGS\ROSNYDER\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT. IE5\YNNVTY7Z\LKJH[1] Downloader-BEA (Trojan)10/1/2007 4:50:08 PM Deleted  RPS\ROSNYDER C:\WINDOWS\Explorer. EXE C:\Documents and Settings\rosnyder\Local Settings\Temporary Internet Files\Content. IE5\YNNVTY7Z\lkjh[1] Downloader-BEA (Trojan)10/1/2007 4:52:04 PM Deleted  RPS\ROSNYDER C:\WINDOWS\Explorer. EXE C:\DOCUMENTS AND SETTINGS\ROSNYDER\LOCAL SETTINGS\TEMP\VPUPOCUI. EXE Generic dx (Trojan)10/1/2007 4:52:04 PM Deleted  RPS\ROSNYDER C:\WINDOWS\Explorer. EXE C:\Documents and Settings\rosnyder\Local Settings\Temp\vpupocui exe Generic dx (Trojan)10/1/2007 4:52:07 PM Deleted  RPS\ROSNYDER C:\WINDOWS\Explorer. EXE C:\DOCUMENTS AND SETTINGS\ROSNYDER\LOCAL SETTINGS\TEMPORARY INTERNET FILES\circumscribe. IE5\OYN90NJB\VALERA[1] Generic dx (Trojan)10/1/2007 4:52:13 PM Deleted  RPS\ROSNYDER C:\WINDOWS\Explorer. EXE C:\Documents and Settings\rosnyder\Local Settings\Temporary Internet Files\Content. IE5\OYN90NJB\valera[1] Generic dx (Trojan)10/1/2007 4:58:27 PM Deleted  RPS\ROSNYDER C:\WINDOWS\Explorer. EXE C:\DOCUMENTS AND SETTINGS\ROSNYDER\LOCAL SETTINGS\TEMPORARY INTERNET FILES\circumscribe. IE5\OYN90NJB\JAUN_20070726[1] Spyware-JuanSearch (Spyware)10/1/2007 4:58:27 PM Deleted  RPS\ROSNYDER C:\WINDOWS\Explorer. EXE C:\Documents and Settings\rosnyder\Local Settings\Temporary Internet Files\circumscribe. IE5\OYN90NJB\jaun_20070726[1] Spyware-JuanSearch (Spyware)10/1/2007 4:58:34 PM Deleted  RPS\ROSNYDER C:\WINDOWS\Explorer. EXE C:\DOCUMENTS AND SETTINGS\ROSNYDER\LOCAL SETTINGS\TEMP\FOACBEKU. DLL Spyware-JuanSearch (Spyware)10/1/2007 4:58:34 PM Deleted  RPS\ROSNYDER C:\WINDOWS\Explorer. EXE C:\Documents and Settings\rosnyder\Local Settings\Temp\foacbeku dll Spyware-JuanSearch (Spyware)10/1/2007 5:05:18 PM  Engine version                         = 5200.216010/1/2007 5:05:18 PM  AntiVirus  DAT version                = 5122.000010/1/2007 5:05:18 PM  be of detection signatures in EXTRA. DAT = None10/1/2007 5:05:18 PM  Names of detection signatures in EXTRA. DAT = None10/1/2007 5:08:21 PM Deleted  RPS\ROSNYDER C:\WINDOWS\Explorer. EXE C:\DOCUMENTS AND SETTINGS\ROSNYDER\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT. IE5\YNNVTY7Z\LKJH[1] Downloader-BEA (Trojan)10/1/2007 5:08:23 PM Deleted  RPS\ROSNYDER C:\WINDOWS\Explorer. EXE C:\Documents and Settings\rosnyder\Local Settings\Temporary Internet Files\circumscribe. IE5\YNNVTY7Z\lkjh[1] Downloader-BEA (Trojan)10/1/2007 5:10:21 PM Deleted  RPS\ROSNYDER C:\WINDOWS\Explorer. EXE C:\DOCUMENTS AND SETTINGS\ROSNYDER\LOCAL SETTINGS\TEMP\EYSSQBJQ. EXE Generic dx (Trojan)10/1/2007 5:10:22 PM Deleted  RPS\ROSNYDER C:\WINDOWS\Explorer. EXE C:\Documents and Settings\rosnyder\Local Settings\Temp\eyssqbjq exe Generic dx (Trojan)10/1/2007 5:10:25 PM Deleted  RPS\ROSNYDER C:\WINDOWS\Explorer. EXE C:\DOCUMENTS AND SETTINGS\ROSNYDER\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT. IE5\YNNVTY7Z\VALERA[1] Generic dx (Trojan)10/1/2007 5:10:25 PM Deleted  RPS\ROSNYDER C:\WINDOWS\Explorer. EXE C:\Documents and Settings\rosnyder\Local Settings\Temporary Internet Files\Content. IE5\YNNVTY7Z\valera[1] Generic dx (Trojan)10/1/2007 5:13:23 PM Deleted  RPS\ROSNYDER C:\WINDOWS\Explorer. EXE C:\DOCUMENTS AND SETTINGS\ROSNYDER\LOCAL SETTINGS\TEMPORARY INTERNET FILES\circumscribe. IE5\G29SI2Q2\JAUN_20070726[1] Spyware-JuanSearch (Spyware)10/1/2007 5:13:23 PM Deleted  RPS\ROSNYDER C:\WINDOWS\Explorer. EXE C:\Documents and Settings\rosnyder\Local Settings\Temporary Internet Files\Content. IE5\G29SI2Q2\jaun_20070726[1] Spyware-JuanSearch (Spyware)10/1/2007 5:13:30 PM Deleted  RPS\ROSNYDER C:\WINDOWS\Explorer. EXE C:\DOCUMENTS AND SETTINGS\ROSNYDER\LOCAL SETTINGS\TEMP\ESNYHSQU. DLL Spyware-JuanSearch (Spyware)10/1/2007 5:13:30 PM Deleted  RPS\ROSNYDER C:\WINDOWS\Explorer. EXE C:\Documents and Settings\rosnyder\Local Settings\Temp\esnyhsqu dll Spyware-JuanSearch (Spyware)10/1/2007 5:30:15 PM Deleted  RPS\ROSNYDER C:\Program Files\Internet Explorer\iexplore exe C:\Documents and Settings\rosnyder\Cookies\rosnyder@mediaplex[1] txt\00000000 ie Cookie-Mediaplex (Potentially Unwanted schedule)10/1/2007 5:30:44 PM Deleted  RPS\ROSNYDER C:\schedule Files\Internet Explorer\iexplore exe C:\Documents and Settings\rosnyder\Cookies\rosnyder@doubleclick[1] txt\00000000 ie Cookie-Doubleclick (Potentially Unwanted Program)10/1/2007 5:30:51 PM Deleted  RPS\ROSNYDER C:\schedule Files\Internet Explorer\iexplore exe C:\Documents and Settings\rosnyder\Cookies\rosnyder@doubleclick[2] txt\00000000 ie Cookie-Doubleclick (Potentially Unwanted Program)10/1/2007 5:30:51 PM Deleted  RPS\ROSNYDER C:\schedule Files\Internet Explorer\iexplore exe C:\Documents and Settings\rosnyder\Cookies\rosnyder@doubleclick[1] txt\00000000 ie Cookie-Doubleclick (Potentially Unwanted Program)10/2/2007 12:54:34 AM Deleted  RPS\ROSNYDER C:\Program Files\Internet Explorer\iexplore exe C:\Documents and Settings\rosnyder\Cookies\rosnyder@advertising[1] txt\00000000 ie Cookie-Advertising (Potentially Unwanted Program)
Thanks for the info. It would be good to check your online time to just coming here until this is cleaned up. transfer and scan each user profile with CCleaner:** Select to download the BASIC version.1. Before first use select Options > Advanced and UNCHECK"Only delete files in Windows Temp folder older than 48 hours"2. Then select the items you wish to clean up. In the Windows Tab:• alter all entries in the "Internet Explorer"• Clean all the entries in the "Windows Explorer" section.• Clean all entries in the "System" section.• alter all entries in the "Advanced" divide.• alter any others that you decide. In the Applications Tab:• Clean all in the Firefox/Mozilla section if you use it.• alter all in the Opera section if you use it.• Clean Sun Java in the Internet Section.• alter any others that you choose.3. move the "Run Cleaner" add.4. A pop up box ordain appear advising this process will permanently delete files from your system.5. Click "OK" and it will scan and clean your system.6. Click "exit" when done. REBOOT. transfer and scan with Free for domiciliate Users
Trojan. WinFixer C:\WINDOWS\SYSTEM32\AWVTU. DLL C:\WINDOWS\SYSTEM32\AWVTU. DLL HKLM\Software\Classes\CLSID\{C00D8D6A-795B-4AC5-A9F9-598FC6FC4D15} HKCR\CLSID\{C00D8D6A-795B-4AC5-A9F9-598FC6FC4D15} HKCR\CLSID\{C00D8D6A-795B-4AC5-A9F9-598FC6FC4D15}\InprocServer32 HKCR\CLSID\{C00D8D6A-795B-4AC5-A9F9-598FC6FC4D15}\InprocServer32#ThreadingModel HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C00D8D6A-795B-4AC5-A9F9-598FC6FC4D15}
Running processes:C:\WINDOWS\System32\smss exeC:\WINDOWS\system32\winlogon exeC:\WINDOWS\system32\services exeC:\WINDOWS\system32\lsass exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\System32\svchost exeC:\WINDOWS\System32\wltrysvc exeC:\WINDOWS\System32\bcmwltry exeC:\WINDOWS\system32\spoolsv exeC:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins exeC:\Program Files\Cisco Systems\VPN Client\cvpnd exeC:\Program Files\McAfee\VirusScan Enterprise\Mcshield exeC:\schedule Files\McAfee\VirusScan Enterprise\VsTskMgr exeC:\schedule Files\Dell\NICCONFIGSVC\NICCONFIGSVC exeC:\schedule Files\cause to be perceived Board Software\SMARTBoardService exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\system32\Tablet exeC:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32 exeC:\WINDOWS\system32\CCM\CcmExec exeC:\WINDOWS\Explorer. EXEC:\Program Files\Dell\QuickSet\quickset exeC:\WINDOWS\system32\WLTRAY exeC:\WINDOWS\system32\hkcmd exeC:\WINDOWS\system32\igfxpers exeC:\WINDOWS\system32\igfxsrvc exeC:\WINDOWS\system32\dla\tfswctrl exeC:\Program Files\CyberLink\PowerDVD\DVDLauncher exeC:\schedule Files\QuickTime\qttask exeC:\schedule Files\Microsoft Office\Office12\GrooveMonitor exeC:\schedule Files\Adobe\Acrobat 8.0\Acrobat\Acrotray exeC:\Program Files\Common Files\InstallShield\UpdateService\issch exeC:\Program Files\explore\Google Talk\googletalk exeC:\schedule Files\Scansoft\PaperPort\pptd40nt exeC:\Program Files\Visioneer OneTouch\OneTouchMon exeC:\WINDOWS\system32\ctfmon exeC:\schedule Files\SUPERAntiSpyware\SUPERAntiSpyware exeC:\schedule Files\WIDCOMM\Bluetooth Software\BTTray exeC:\Program Files\SMART Board Software\SMARTBoardTools exeC:\Program Files\Wacom\TabUserW exeC:\schedule Files\FileBX\FileBX exeC:\schedule Files\MrSnappy95\snappy95 exeC:\schedule Files\Microsoft Office\Office12\ONENOTEM. EXEC:\schedule Files\UltimateZip\uzqkst exeC:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService exeC:\schedule Files\cause to be perceived Board Software\Aware exeC:\schedule Files\SMART Board Software\Marker exeC:\schedule Files\Common Files\cause to be perceived Technologies Inc\cause to be perceived Product Update\SmartProductUpdate exeC:\Program Files\Internet Explorer\iexplore exeC:\schedule Files\Microsoft Office\Office12\OUTLOOK. EXEC:\Program Files\Common Files\Microsoft Shared\office12\offlb exeC:\schedule Files\turn Micro\HijackThis\HijackThis exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,examine Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,fail_Page_URL = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search summon = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = O2 - BHO: Adobe PDF Reader cerebrate Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper dllO2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx dllO2 - BHO: cause to be perceived Notebook transfer Plugin - {67BCF957-85FC-4036-8DC4-D4D80E00A77B} - C:\schedule Files\SMART Board Software\NotebookPlugin dllO2 - BHO: incise GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1. DLLO2 - BHO: SSVHelper categorise - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv dllO2 - BHO: WagBHO. WagBHO - {A7DE7922-14CB-11D6-8BCA-0010A48E5285} - C:\webacc\WagBHO dllO2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dllO3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dllO4 - HKLM\..\Run: [Dell QuickSet] C:\schedule Files\Dell\QuickSet\quickset exeO4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAYO4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray exeO4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd exeO4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers exeO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl exeO4 - HKLM\..\Run: [UpdateManager] "C:\schedule Files\Common Files\Sonic\Update Manager\sgtray exe" /rO4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher exe"O4 - HKLM\..\Run: [QuickTime assign] "C:\Program Files\QuickTime\qttask exe" -atboottimeO4 - HKLM\..\Run: [ShStatEXE] "C:\schedule Files\McAfee\VirusScan Enterprise\SHSTAT. EXE" /STANDALONEO4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor exe"O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray exe"O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm exe" -startupO4 - HKLM\..\Run: [ISUSScheduler] "C:\schedule Files\Common Files\InstallShield\UpdateService\issch exe" -startO4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync exe /logonO4 - HKLM\..\Run: [Adobe Reader go Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl exe"O4 - HKLM\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk exe" /autostartO4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\Scansoft\PaperPort\pptd40nt exe"O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\Scansoft\PaperPort\IndexSearch exe"O4 - HKLM\..\Run: [OneTouch Monitor] "C:\schedule Files\Visioneer OneTouch\OneTouchMon exe"O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI exe" /StartedFromRunKeyO4 - HKLM\..\Run: [SearchIndexer] rundll32 exe "C:\WINDOWS\system32\buigpwsf dll",sitypnowO4 - HKCU\..\Run: [ctfmon exe] C:\WINDOWS\system32\ctfmon exeO4 - HKCU\..\Run: [SUPERAntiSpyware] C:\schedule Files\SUPERAntiSpyware\SUPERAntiSpyware exeO4 - Startup: Check for updates to PDExpress lnk = C:\Program Files\PDExpress2007\WiseUpdt. EXEO4 - Startup: FileBox eXtender lnk = C:\Program Files\FileBX\FileBX exeO4 - Startup: Mr. Snappy 95 lnk = C:\Program Files\MrSnappy95\snappy95 exeO4 - Startup: OneNote 2007 Screen Clipper and Launcher lnk = C:\schedule Files\Microsoft Office\Office12\ONENOTEM. EXEO4 - Startup: UltimateZip Quick Start lnk = C:\schedule Files\UltimateZip\uzqkst exeO4 - Global Startup: Bluetooth lnk = ?O4 - Global Startup: Cisco Systems VPN Client lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui exeO4 - Global Startup: SMART Board Tools lnk = C:\schedule Files\cause to be perceived Board Software\SMARTBoardTools exeO4 - Global Startup: TabUserW lnk = C:\Program Files\Wacom\TabUserW exeO4 - Global Startup: Web Adaptation define lnk = ?O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control adorn presentO8 - Extra context menu item: Append to existing PDF - res://C:\schedule Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIEAppend htmlO8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\schedule Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIECapture htmlO8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIEAppend htmlO8 - Extra context menu item: alter selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIECaptureSelLinks htmlO8 - Extra context menu item: Convert selected links to existing PDF - res://C:\schedule Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIEAppendSelLinks htmlO8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIECapture htmlO8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIEAppend htmlO8 - Extra context menu item: Convert to Adobe PDF - res://C:\schedule Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient dll/AcroIECapture htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL. EXE/3000O8 - Extra context menu item: displace to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx htmO9 - Extra button: Settings - {02E998F8-5FF1-4a65-9D1D-99059AFCEC01} - C:\webacc\WagBand dllO9 - Extra add: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE dllO9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE dllO9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar dllO9 - Extra 'Tools' menuitem: open WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR. DLLO9 - Extra add: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\schedule Files\Messenger\msmsgs exeO16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl categorise) - O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager hold back) - O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = RPS netO17 - HKLM\Software\..\Telephony: DomainName = RPS netO17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = RPS netO18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1. DLLO20 - Winlogon inform: !SASWinLogon - C:\schedule Files\SUPERAntiSpyware\SASWINLO dllO23 - function: Bluetooth function (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins exeO23 - Service: Cisco Systems. Inc. VPN Service (CVPND) - Cisco Systems. Inc. - C:\schedule Files\Cisco Systems\VPN Client\cvpnd exeO23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService exeO23 - function: McAfee McShield (McShield) - McAfee. Inc. - C:\schedule Files\McAfee\VirusScan Enterprise\Mcshield exeO23 - function: McAfee assign Manager (McTaskManager) - McAfee. Inc. - C:\schedule Files\McAfee\VirusScan Enterprise\VsTskMgr exeO23 - function: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC exeO23 - Service: SMART Board Service - SMART Technologies Inc. - C:\Program Files\cause to be perceived Board Software\SMARTBoardService exeO23 - function: TabletService - Wacom Technology. Corp. - C:\WINDOWS\system32\Tablet exeO23 - function: Dell Wireless WLAN Tray function (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc exe
Forex Groups - Tips on Trading
Related article:
http://www.dellcommunity.com/supportforums/board/message?board.id=si_hijack&message.id=68398#M68398
comments | Add comment | Report as Spam
|