|  | 
 
															
															
	
			
			
				| ULWindowseek and ULWindowsURL HELP |  |  
					
					
				 
						| MonesNewbie 
   | 10. June 2006 @ 07:47 |  Link to this message   |  
						| 
							
							Hi, I recently got some kind of virus or something that causes these popups to come up regularly.  I've read through a few of the forums, but was wondering if someone could help me specifically...It would be greatly appreciated.
 Thank you in advance.
 
 Here is my Hijackthis log
 
 Logfile of HijackThis v1.99.1
 Scan saved at 11:47:10 AM, on 10/06/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v7.00 (7.00.5346.0005)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
 C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
 C:\Program Files\iPod\bin\iPodService.exe
 C:\Program Files\HPQ\SHARED\HPQWMI.exe
 C:\WINDOWS\system32\svchost.exe
 C:\PROGRA~1\SSTEM3~1\dllhost.exe
 C:\WINDOWS\ICROSO~1.NET\JVAW~1.EXE
 C:\Program Files\Logitech\SetPoint\SetPoint.exe
 C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\Program Files\MSN Messenger\msnmsgr.exe
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\Program Files\HijackThis\HijackThis.exe
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
 R3 - URLSearchHook: (no name) - {E50C5E3A-E9D1-B303-A2B9-992CF61F5EBB} - C:\WINDOWS\system32\tfvf.dll
 R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
 F2 - REG:system.ini: UserInit=userinit.exe
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O2 - BHO: (no name) - {E50C5E3A-E9D1-B303-A2B9-992CF61F5EBB} - C:\WINDOWS\system32\tfvf.dll
 O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
 O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
 O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
 O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
 O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
 O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
 O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
 O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
 O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [765b3a5.exe] C:\WINDOWS\system32\765b3a5.exe
 O4 - HKLM\..\Run: [c903ca1d.exe] C:\WINDOWS\system32\c903ca1d.exe
 O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
 O4 - HKCU\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" --logon
 O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
 O4 - HKCU\..\Run: [Mobipocket Web Companion] C:\Program Files\Common Files\Mobipocket Shared\webcomp.exe -m
 O4 - HKCU\..\Run: [Mobipocket Reader Notifications] C:\Program Files\Mobipocket.com\Mobipocket Reader\readernotify.exe
 O4 - HKCU\..\Run: [765b3a5.exe] C:\Documents and Settings\Mones\Local Settings\Application Data\765b3a5.exe
 O4 - HKCU\..\Run: [c903ca1d.exe] C:\Documents and Settings\Mones\Local Settings\Application Data\c903ca1d.exe
 O4 - HKCU\..\Run: [Hvteugn] C:\WINDOWS\ICROSO~1.NET\JVAW~1.EXE
 O4 - HKCU\..\Run: [Tbsa] "C:\PROGRA~1\SSTEM3~1\dllhost.exe" -vt ndrv
 O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
 O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
 O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O11 - Options group: [INTERNATIONAL] International*
 O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c...
 O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.samsung.com/Products/MobilePhones/T_Mobile/web3d/SGH_T...
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1162
 O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} - http://85.255.114.166/1/rdgCA2404.exe
 O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
 O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2...
 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
 O20 - AppInit_DLLs:  C:\WINDOWS\system32\cmd.dll C:\WINDOWS\system32\notepad.dll  C:\WINDOWS\system32\wuauclt.dll
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O20 - Winlogon Notify: winwea32 - C:\WINDOWS\SYSTEM32\winwea32.dll
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
 |  
						| Advertisement   |   |  
						|  |  
						| -kemisti-AfterDawn Addict 
   | 10. June 2006 @ 08:03 |  Link to this message   |  
						| 
							
							Hi Mones
 Look in your control panels add/remove programs for PuritySCAN By OIN, OuterInfo, OIN or similar , click on it and click remove.
 Reboot and delete this folder if found:
 C:\Program Files\PurityScan
 
 If not listed, download and run this uninstaller:
 http://www.outerinfo.com/OiUninstaller.exeUninstaller
 
 http://www.outerinfo.com/howto.htmlTutorial for the uninstaller if needed[/color]
 
 Reboot when done and delete this folder if found:
 C:\Program Files\PurityScan
 
 Fix with HjT (do a system scan only, checkmark these and press fix checked):
 
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
 R3 - URLSearchHook: (no name) - {E50C5E3A-E9D1-B303-A2B9-992CF61F5EBB} - C:\WINDOWS\system32\tfvf.dll
 R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
 O2 - BHO: (no name) - {E50C5E3A-E9D1-B303-A2B9-992CF61F5EBB} - C:\WINDOWS\system32\tfvf.dll
 O4 - HKLM\..\Run: [765b3a5.exe] C:\WINDOWS\system32\765b3a5.exe
 O4 - HKLM\..\Run: [c903ca1d.exe] C:\WINDOWS\system32\c903ca1d.exe
 O4 - HKCU\..\Run: [765b3a5.exe] C:\Documents and Settings\Mones\Local Settings\Application Data\765b3a5.exe
 O4 - HKCU\..\Run: [c903ca1d.exe] C:\Documents and Settings\Mones\Local Settings\Application Data\c903ca1d.exe
 O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1162
 O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} - http://85.255.114.166/1/rdgCA2404.exe
 O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2...
 O20 - Winlogon Notify: winwea32 - C:\WINDOWS\SYSTEM32\winwea32.dll
 
 
 1. Please download http://swandog46.geekstogo.com/avenger.zip The Avenger by Swandog46 to your Desktop.
 
 [*]Click on Avenger.zip to open the file[*]Extract avenger.exe to your desktop
 
 2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):
 
 Quote:Files to delete:
 C:\WINDOWS\system32\tfvf.dll
 C:\WINDOWS\system32\765b3a5.exe
 C:\WINDOWS\system32\c903ca1d.exe
 C:\Documents and Settings\Mones\Local Settings\Application Data\765b3a5.exe
 C:\Documents and Settings\Mones\Local Settings\Application Data\c903ca1d.exe
 C:\WINDOWS\SYSTEM32\winwea32.dll
 C:\WINDOWS\system32\cmd.dll
 C:\WINDOWS\system32\notepad.dll
 C:\WINDOWS\system32\wuauclt.dll
 
 Registry values to replace with dummy:
 HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs
 
 Note: the above code was created specifically for this user.  If you are not this user, do NOT follow these directions as they could damage the workings of your system.
 
 3. Now, start The Avenger program by clicking on its icon on your desktop.
 [*] Under "Script file to execute" choose "Input Script Manually".
 [*]Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
 [*] Paste the text copied to clipboard into this window by pressing (Ctrl+V).
 [*] Click Done
 [*] Now click on the ]Green Light to begin execution of the script
 [*] Answer "Yes" twice when prompted.
 4. The Avenger will automatically do the following:
 [*]It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice].)
 [*]On reboot, it will briefly open a black command window on your desktop, this is normal.
 [*]After the restart, it creates a log file] that should open with the results of Avenger?s actions.  This log file will be located at  C:\avenger.txt
 [*] The Avenger will also have [u]backed up all the files, etc., that you asked it to delete], and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
 5. Please copy/paste the content of c:\avenger.txt into your reply along with a fresh HJT log ]  by using Add/Reply
 
 Post a fresh HJT log.
 This message has been edited since posting. Last time this message was edited on 10. June 2006 @ 08:09 |  
						| MonesNewbie 
   | 10. June 2006 @ 11:08 |  Link to this message   |  
						| 
							
							Thank you for your help and the quick reply
 Here are the logs you requested.
 
 AVENGER:
 
 Logfile of The Avenger version 1, by Swandog46
 Running from registry key:
 \Registry\Machine\System\CurrentControlSet\Services\crmprcbt
 
 *******************
 
 Script file located at: \??\C:\WINDOWS\system32\vxufkuis.txt
 Script file opened successfully.
 
 Script file read successfully
 
 Backups directory opened successfully at C:\Avenger
 
 *******************
 
 Beginning to process script file:
 
 
 
 File C:\WINDOWS\system32\tfvf.dll not found!
 Deletion of file C:\WINDOWS\system32\tfvf.dll failed!
 
 Could not process line:
 C:\WINDOWS\system32\tfvf.dll
 Status: 0xc0000034
 
 File C:\WINDOWS\system32\765b3a5.exe deleted successfully.
 File C:\WINDOWS\system32\c903ca1d.exe deleted successfully.
 File C:\Documents and Settings\Mones\Local Settings\Application Data\765b3a5.exe deleted successfully.
 File C:\Documents and Settings\Mones\Local Settings\Application Data\c903ca1d.exe deleted successfully.
 File C:\WINDOWS\SYSTEM32\winwea32.dll deleted successfully.
 File C:\WINDOWS\system32\cmd.dll deleted successfully.
 File C:\WINDOWS\system32\notepad.dll deleted successfully.
 File C:\WINDOWS\system32\wuauclt.dll deleted successfully.
 Registry value HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows|AppInit_DLLs replaced with dummy successfully.
 
 Completed script processing.
 
 *******************
 
 Finished!  Terminate.
 
 
 HJT:
 
 Logfile of HijackThis v1.99.1
 Scan saved at 3:07:24 PM, on 10/06/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v7.00 (7.00.5346.0005)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
 C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
 C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\Program Files\QuickTime\qttask.exe
 C:\Program Files\iPod\bin\iPodService.exe
 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
 C:\Program Files\MSN Messenger\msnmsgr.exe
 C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
 C:\Program Files\Mobipocket.com\Mobipocket Reader\readernotify.exe
 C:\WINDOWS\ICROSO~1.NET\JVAW~1.EXE
 C:\Program Files\HPQ\SHARED\HPQWMI.exe
 C:\PROGRA~1\SSTEM3~1\dllhost.exe
 C:\Program Files\Logitech\SetPoint\SetPoint.exe
 C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\Program Files\HijackThis\HijackThis.exe
 
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
 F2 - REG:system.ini: UserInit=userinit.exe
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
 O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
 O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
 O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
 O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
 O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
 O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
 O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
 O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
 O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
 O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
 O4 - HKCU\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" --logon
 O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
 O4 - HKCU\..\Run: [Mobipocket Web Companion] C:\Program Files\Common Files\Mobipocket Shared\webcomp.exe -m
 O4 - HKCU\..\Run: [Mobipocket Reader Notifications] C:\Program Files\Mobipocket.com\Mobipocket Reader\readernotify.exe
 O4 - HKCU\..\Run: [Hvteugn] C:\WINDOWS\ICROSO~1.NET\JVAW~1.EXE
 O4 - HKCU\..\Run: [Tbsa] "C:\PROGRA~1\SSTEM3~1\dllhost.exe" -vt ndrv
 O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
 O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
 O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O11 - Options group: [INTERNATIONAL] International*
 O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c...
 O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.samsung.com/Products/MobilePhones/T_Mobile/web3d/SGH_T...
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O20 - Winlogon Notify: winwea32 - winwea32.dll (file missing)
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
 |  
						| -kemisti-AfterDawn Addict 
   | 11. June 2006 @ 00:53 |  Link to this message   |  
						| 
							
							Ok, PurityScan uninstaller didn't work :(
 Fix with HjT:
 
 O4 - HKCU\..\Run: [Hvteugn] C:\WINDOWS\ICROSO~1.NET\JVAW~1.EXE
 O4 - HKCU\..\Run: [Tbsa] "C:\PROGRA~1\SSTEM3~1\dllhost.exe" -vt ndrv
 O20 - Winlogon Notify: winwea32 - winwea32.dll (file missing)
 
 Please download ewido anti-malware it is a free version of the program -> http://www.ewido.net/en/download/
 
 1. Install ewido anti-malware
 2. When installing, under "Additional Options" uncheck..
 * Install background guard
 * Install scan via context menu
 3. Launch ewido, there should be an icon on your desktop, double-click it.
 4. The program will now open to the main screen.
 5. When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
 6. You will need to update ewido to the latest definition files.
 * On the left hand side of the main screen click update.
 * Then click on Start Update.
 7. The update will start and a progress bar will show the updates being installed.
 (the status bar at the bottom will display ("Update successful")
 
 If you are having problems with the updater, you can use this link to manually update ewido.
 ewido manual updates -> http://download.ewido.net/ewido-signatures-full-current.exe  Make sure to close Ewido before installing the update.
 
 Once the updates are installed do the following:
 
 Reboot your computer in SafeMode by doing the following:
 
 1. Restart your computer
 2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
 3. Instead of Windows loading as normal, a menu should appear
 4. Select the first option, to run Windows in Safe Mode.
 
 Delete if found:
 
 C:\WINDOWS\ICROSO~1.NET
 C:\PROGRA~1\SSTEM3~1
 
 
 Then launch ewido:
 
 * Click on scanner
 * Click on Complete System Scan and the scan will begin.
 * You will be prompted to clean the first infection.
 * Select "Perform action on all infections", then proceed.
 * Once the scan has completed, there will be a button located on the bottom of the screen named Save report
 * Click Save report.
 * Save the report .txt file to your desktop or a location where you can find it easily.
 
 Close ewido anti-malware.
 
 Reboot back to normal mode
 
 Send ewido report and a fresh HjT log.
 |  
						| MonesNewbie 
   | 11. June 2006 @ 05:08 |  Link to this message   |  
						| 
							
							Hi,
 Sorry, I probably should have done this before, but I didn't get a chance to.  After I had gone through your initial instructions (the ones talking about downloading avenger and such), I went back and re-read them, and saw the bit about downloading the outerinfo uninstaller and such.
 So I actually ended up doing that uninstall AFTER running all the avenger programs you had recommended.
 
 Here is a fresh HjT log.  I looked for some of the files you said to fix, and could only find one of them.  I didn't want to do anything wrong, so though I'd let you see before I do anything at all..
 
 Thank you again for your help, it's really appreciated.
 
 Logfile of HijackThis v1.99.1
 Scan saved at 9:01:49 AM, on 11/06/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v7.00 (7.00.5346.0005)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
 C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
 C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
 C:\Program Files\MSN Messenger\msnmsgr.exe
 C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
 C:\Program Files\Mobipocket.com\Mobipocket Reader\readernotify.exe
 C:\Program Files\iPod\bin\iPodService.exe
 C:\Program Files\Logitech\SetPoint\SetPoint.exe
 C:\Program Files\HPQ\SHARED\HPQWMI.exe
 C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\WISPTIS.EXE
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\Program Files\HijackThis\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.google.ca/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
 F2 - REG:system.ini: UserInit=userinit.exe
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
 O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
 O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
 O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
 O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
 O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
 O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
 O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
 O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
 O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
 O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
 O4 - HKCU\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" --logon
 O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
 O4 - HKCU\..\Run: [Mobipocket Web Companion] C:\Program Files\Common Files\Mobipocket Shared\webcomp.exe -m
 O4 - HKCU\..\Run: [Mobipocket Reader Notifications] C:\Program Files\Mobipocket.com\Mobipocket Reader\readernotify.exe
 O4 - Startup: Skyscape smARTupdate.lnk = C:\Program Files\Common Files\Skyscape\smARTupdate.exe
 O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
 O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
 O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O11 - Options group: [INTERNATIONAL] International*
 O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c...
 O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.samsung.com/Products/MobilePhones/T_Mobile/web3d/SGH_T...
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O20 - Winlogon Notify: winwea32 - winwea32.dll (file missing)
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
 |  
						| -kemisti-AfterDawn Addict 
   | 11. June 2006 @ 05:20 |  Link to this message   |  
						| 
							
							That's ok, after uninstaller there shouldn't be much left :)
 Fix with HjT:
 
 O20 - Winlogon Notify: winwea32 - winwea32.dll (file missing)
 
 Reboot and send a fresh HjT log.
 |  
						| MonesNewbie 
   | 11. June 2006 @ 06:46 |  Link to this message   |  
						| 
							
							Wow, that was the best instruction set ever.  Nice and short and uncomplicated.  :)
 Here's the log
 
 Logfile of HijackThis v1.99.1
 Scan saved at 10:44:19 AM, on 11/06/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v7.00 (7.00.5346.0005)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
 C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
 C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
 C:\Program Files\MSN Messenger\msnmsgr.exe
 C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
 C:\Program Files\Mobipocket.com\Mobipocket Reader\readernotify.exe
 C:\Program Files\iPod\bin\iPodService.exe
 C:\Program Files\Logitech\SetPoint\SetPoint.exe
 C:\Program Files\HPQ\SHARED\HPQWMI.exe
 C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\WISPTIS.EXE
 C:\Program Files\iTunes\iTunes.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Program Files\HijackThis\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.google.ca/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
 F2 - REG:system.ini: UserInit=userinit.exe
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
 O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
 O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
 O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
 O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
 O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
 O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
 O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
 O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
 O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
 O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
 O4 - HKCU\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" --logon
 O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
 O4 - HKCU\..\Run: [Mobipocket Web Companion] C:\Program Files\Common Files\Mobipocket Shared\webcomp.exe -m
 O4 - HKCU\..\Run: [Mobipocket Reader Notifications] C:\Program Files\Mobipocket.com\Mobipocket Reader\readernotify.exe
 O4 - Startup: Skyscape smARTupdate.lnk = C:\Program Files\Common Files\Skyscape\smARTupdate.exe
 O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
 O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
 O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O11 - Options group: [INTERNATIONAL] International*
 O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c...
 O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.samsung.com/Products/MobilePhones/T_Mobile/web3d/SGH_T...
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
 |  
						| -kemisti-AfterDawn Addict 
   | 11. June 2006 @ 06:58 |  Link to this message   |  
						| 
							
							Log looks clean to me :) 
 
 I don´t see any firewall on your log and no av is active(ClamWin though on log but not active). ZoneAlarm and Kerio are good and free firewalls and AVG, avast! and AntiVir are good and free avs.
 |  
						| MonesNewbie 
   | 11. June 2006 @ 07:35 |  Link to this message   |  
						| 
							
							Kemisti, 
 Thanks, I don't know why Clamwin was off...It should have been active.  :)
 
 I guess I relied a bit too much on my router for the firewall.  Thanks for the advice, I'll look into ZoneAlarm for sure.
 
 Thanks again for all your help.  You rule.  :)
 
 Mones
 |  
						| Advertisement   |   |  
						| 
 |  
						| -kemisti-AfterDawn Addict 
   | 11. June 2006 @ 08:56 |  Link to this message   |  
						| 
							
							Glad to hear that everything's ok now :)
							
						 |  |