<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>Computer Forum - Computer Security</title>
		<link>http://www.computerforum.com/</link>
		<description>Anti-Virus, Spyware, Firewalls</description>
		<language>en</language>
		<lastBuildDate>Thu, 09 Sep 2010 07:44:20 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://www.computerforum.com/images/misc/rss.jpg</url>
			<title>Computer Forum - Computer Security</title>
			<link>http://www.computerforum.com/</link>
		</image>
		<item>
			<title>my brothers hijack this log</title>
			<link>http://www.computerforum.com/182576-my-brothers-hijack-log.html</link>
			<pubDate>Wed, 08 Sep 2010 19:48:28 GMT</pubDate>
			<description><![CDATA[alright so my brother moved back home and his computer is just like the definition of wierd, he's had it since college so its by no means new, he has had issues within the past, but so this is his HiJackThis log what do we think?? and just so you kno i ran avira on it and it found i believe 30...]]></description>
			<content:encoded><![CDATA[<div>alright so my brother moved back home and his computer is just like the definition of wierd, he's had it since college so its by no means new, he has had issues within the past, but so this is his HiJackThis log what do we think?? and just so you kno i ran avira on it and it found i believe 30 things and then malwarebytes found some stuff too and i have both logs if needed.<br />
<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 3:38:03 PM, on 9/8/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\SYSTEM32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe<br />
C:\WINDOWS\System32\NMSSvc.exe<br />
C:\WINDOWS\System32\nvsvc32.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\wanmpsvc.exe<br />
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe<br />
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\CTHELPER.EXE<br />
C:\WINDOWS\system32\PROMon.exe<br />
C:\WINDOWS\system32\SK9910DM.EXE<br />
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Documents and Settings\Owner\Application Data\U3\00001673A6729D78\LaunchPad.exe<br />
G:\for viruses\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about<b></b>:blank<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about<b></b>:blank<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int  ernet Settings,ProxyOverride = *.local<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)<br />
O2 - BHO: (no name) - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - (no file)<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: SuperBar - {73006350-AD3D-48AE-B576-1B995F809FEA} - (no file)<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE<br />
O4 - HKLM\..\Run: [PROMon.exe] PROMon.exe<br />
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0  9.exe<br />
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE<br />
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon<br />
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon<br />
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [avgnt] &quot;C:\Program Files\Avira\AntiVir Desktop\avgnt.exe&quot; /min<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] &quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe  &quot; -t (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] &quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe  &quot; -t (User 'Default user')<br />
O4 - Global Startup: Microsoft Broadband Networking.lnk = ?<br />
O8 - Extra context menu item: &amp;AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - (no file)<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)<br />
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll<br />
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - <a href="http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab" target="_blank">http://security.symantec.com/sscv6/S...in/AvSniff.cab</a><br />
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - <a href="http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst0401.cab" target="_blank">http://us.dl1.yimg.com/download.yaho.../yinst0401.cab</a><br />
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - <a href="http://www.mathxl.com/wizmodules/testgen/installers/TestGenXInstall.cab" target="_blank">http://www.mathxl.com/wizmodules/tes...enXInstall.cab</a><br />
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - <a href="http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe" target="_blank">http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe</a><br />
O16 - DPF: {4FAE30E1-EE9C-477D-8D06-BF8D3429B60F} (WebIQ Technology Client) - <a href="http://webiq001.webiqonline.com/WebIQ/bin/WebIQ.cab" target="_blank">http://webiq001.webiqonline.com/WebIQ/bin/WebIQ.cab</a><br />
O16 - DPF: {4FE89055-5300-469E-AFAD-DEB3181EDE76} (PearsonAsstX Control) - <a href="http://www.mathxl.com/applets/PearsonInstallAsst.cab" target="_blank">http://www.mathxl.com/applets/PearsonInstallAsst.cab</a><br />
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - <a href="http://upload.facebook.com/controls/FacebookPhotoUploader.cab" target="_blank">http://upload.facebook.com/controls/...toUploader.cab</a><br />
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - <a href="http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab" target="_blank">http://security.symantec.com/sscv6/S.../bin/cabsa.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1128898489875" target="_blank">http://update.microsoft.com/microsof...?1128898489875</a><br />
O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} (RunExeActiveX.RunExe) - hcp://system/RunExeActiveX.CAB<br />
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB<br />
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - <a href="http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab" target="_blank">http://cdn2.zone.msn.com/binFramewor...o.cab56649.cab</a><br />
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} (Create &amp; Print ActiveX Plug-in) - <a href="http://ak.imgag.com/imgag/cp/install/AxCtp2.cab" target="_blank">http://ak.imgag.com/imgag/cp/install/AxCtp2.cab</a><br />
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - <a href="http://security2.norton.com/SSC/SharedContent/sc/bin/cabsa.cab" target="_blank">http://security2.norton.com/SSC/Shar.../bin/cabsa.cab</a><br />
O16 - DPF: {C4DD6732-1E82-4AE7-BD94-180331B84082} (DeltaCVX Control) - <a href="http://www.mathxl.com/applets/DeltaCVX.cab" target="_blank">http://www.mathxl.com/applets/DeltaCVX.cab</a><br />
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - <a href="https://www-secure.symantec.com/techsupp/asa/SymAData.cab" target="_blank">https://www-secure.symantec.com/tech...a/SymAData.cab</a><br />
O16 - DPF: {CE37E095-ACFF-4380-A856-A560D389E5E1} (XPLControlProject.XPLControl) - hcp://system/XPLControl.CAB<br />
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - <a href="http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab" target="_blank">http://wwwimages.adobe.com/www.adobe...bat/nos/gp.cab</a><br />
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - <a href="http://fdl.msn.com/public/chat/msnchat45.cab" target="_blank">http://fdl.msn.com/public/chat/msnchat45.cab</a><br />
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} - <a href="http://cdn.digitalcity.com/_media/dalaillama/ampx.cab" target="_blank">http://cdn.digitalcity.com/_media/dalaillama/ampx.cab</a><br />
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = Workgroup<br />
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = Workgroup<br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)<br />
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)<br />
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe<br />
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: Inkjet Printer/Scanner Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe<br />
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\System32\PCTKRNT.SYS<br />
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe<br />
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)<br />
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe<br />
O23 - Service: WUSB54GCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe<br />
O24 - Desktop Component 0: (no name) - <a href="http://banners.wunderground.com/weathersticker/infobox_both/language/www/US/NY/Hampton_Bays.gif" target="_blank">http://banners.wunderground.com/weat...mpton_Bays.gif</a><br />
O24 - Desktop Component 1: (no name) - <a href="http://a660.ac-images.myspacecdn.com/images01/49/l_83155de7a063820d3d2a2cc6e9e13ef3.jpg" target="_blank">http://a660.ac-images.myspacecdn.com...c6e9e13ef3.jpg</a><br />
<br />
--<br />
End of file - 10700 bytes</div>

]]></content:encoded>
			<category domain="http://www.computerforum.com/computer-security/">Computer Security</category>
			<dc:creator>sarus86</dc:creator>
			<guid isPermaLink="true">http://www.computerforum.com/182576-my-brothers-hijack-log.html</guid>
		</item>
		<item>
			<title><![CDATA[The Chinese Communist Party's role in China's bad net security]]></title>
			<link>http://www.computerforum.com/182554-chinese-communist-partys-role-chinas-bad-net-security.html</link>
			<pubDate>Wed, 08 Sep 2010 08:14:42 GMT</pubDate>
			<description><![CDATA[In June 2009, China's government blocked: 
All images on Wikipedia 
Youtube 
Facebook 
Twitter 
Scribd 
Project Gutenberg 
Wikimapia 
Bible Gateway 
etc, etc, ad infinitum...]]></description>
			<content:encoded><![CDATA[<div>In June 2009, China's government blocked:<br />
All images on Wikipedia<br />
Youtube<br />
Facebook<br />
Twitter<br />
Scribd<br />
Project Gutenberg<br />
Wikimapia<br />
Bible Gateway<br />
etc, etc, ad infinitum...<br />
<b>And I live in China!</b><br />
During experiments and tests I did on this &quot;Golden Shield Project&quot; or Great Firewall of China (which I only disclose via PM, for reasons of national security), I discovered that the two main methods of blocking are:<br />
1. DNS Poisoning, redirecting to the China Unicom website<br />
2. Hidden proxy in the middle that filters the GET requests it forwards.<br />
3. Playing the Big Man In The Middle, and terminating the connection whenever a TCP packet containing things such as signature Youtube HTML code.<br />
This means that the Great Firewall of China <b>can be the best tool for hackers to exploit.</b> This also means that <b>the Communist Party can commit identity theft simply by going over to the MITMS and proxies and monitoring the traffic.</b><br />
<br />
P.S. I have actually successfully hacked the component of the GFW in schools, Green Dam Youth Escort. I will tell you more about it if you ask in the replies.</div>

]]></content:encoded>
			<category domain="http://www.computerforum.com/computer-security/">Computer Security</category>
			<dc:creator>geek0x00</dc:creator>
			<guid isPermaLink="true">http://www.computerforum.com/182554-chinese-communist-partys-role-chinas-bad-net-security.html</guid>
		</item>
		<item>
			<title>free norton 2010</title>
			<link>http://www.computerforum.com/182461-free-norton-2010-a.html</link>
			<pubDate>Mon, 06 Sep 2010 16:58:28 GMT</pubDate>
			<description>http://www.frys.com/product/6117689 
 
why is it free? is it a good product? is 2011 avail. and that much better?</description>
			<content:encoded><![CDATA[<div><a href="http://www.frys.com/product/6117689" target="_blank">http://www.frys.com/product/6117689</a><br />
<br />
why is it free? is it a good product? is 2011 avail. and that much better?</div>

]]></content:encoded>
			<category domain="http://www.computerforum.com/computer-security/">Computer Security</category>
			<dc:creator>Benny Boy</dc:creator>
			<guid isPermaLink="true">http://www.computerforum.com/182461-free-norton-2010-a.html</guid>
		</item>
		<item>
			<title><![CDATA["Ghost" on computer]]></title>
			<link>http://www.computerforum.com/182437-ghost-computer.html</link>
			<pubDate>Mon, 06 Sep 2010 02:46:59 GMT</pubDate>
			<description><![CDATA[I apparently have a "ghost" virus on my computer i've detected it but canno't seem to bug it this person has hacked my email account and more can you please help me get rid of this pest?]]></description>
			<content:encoded><![CDATA[<div>I apparently have a &quot;ghost&quot; virus on my computer i've detected it but canno't seem to bug it this person has hacked my email account and more can you please help me get rid of this pest?</div>

]]></content:encoded>
			<category domain="http://www.computerforum.com/computer-security/">Computer Security</category>
			<dc:creator>Nastnic</dc:creator>
			<guid isPermaLink="true">http://www.computerforum.com/182437-ghost-computer.html</guid>
		</item>
		<item>
			<title>Virus, keeps returning.</title>
			<link>http://www.computerforum.com/182388-virus-keeps-returning.html</link>
			<pubDate>Sun, 05 Sep 2010 05:04:08 GMT</pubDate>
			<description>Cleaning a friends computer and keep getting the same virus returning after restart.  Did clean in both normal mode and safe mode.  keeps coming back.  MBAM and HIJACKTHIS below, how do I get rid of this stuff?: 
 
Here is my hijack: 
 
Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at...</description>
			<content:encoded><![CDATA[<div>Cleaning a friends computer and keep getting the same virus returning after restart.  Did clean in both normal mode and safe mode.  keeps coming back.  MBAM and HIJACKTHIS below, how do I get rid of this stuff?:<br />
<br />
Here is my hijack:<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 5:22:16 PM, on 9/4/2010<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\WINDOWS\system32\igfxtray.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\Program Files\Sprint\Sprint SmartView\RDVCHG.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <a href="http://www.gateway.com/g/sidepanel.html?Ch=Retail&amp;SubCH=nofound&amp;Br=EM&amp;Loc=ENG_US&amp;Sys=DTP&amp;M=W3622" target="_blank">http://www.gateway.com/g/sidepanel.h...ys=DTP&amp;M=W3622</a><br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll<br />
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: ADC PlugIn - {19090308-636D-4e9b-A1CE-A647B6F794BF} - C:\Program Files\shk_v10.dll (file missing)<br />
O2 - BHO: Pop-up Blocker - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\X1IEBHO.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll<br />
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\s  wg.dll<br />
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll<br />
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstan  ce.dll<br />
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll<br />
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [AT&amp;T Communication Manager] &quot;C:\Program Files\AT&amp;T\Communication Manager\ATTCM.exe&quot; -a<br />
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br />
O4 - HKLM\..\Run: [RDVCHG] &quot;C:\Program Files\Sprint\Sprint SmartView\RDVCHG.exe&quot;<br />
O4 - HKLM\..\Run: [Kvuki] rundll32.exe &quot;C:\WINDOWS\ukegenoguqutoqih.dll&quot;,Startup<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [Nqahuqadiruvupo] rundll32.exe &quot;C:\WINDOWS\dcun32.dll&quot;,Startup<br />
O4 - HKUS\S-1-5-21-1073430634-2312317338-938489262-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')<br />
O4 - HKUS\S-1-5-21-1073430634-2312317338-938489262-1003\..\Run: [Nqahuqadiruvupo] rundll32.exe &quot;C:\WINDOWS\dcun32.dll&quot;,Startup (User '?')<br />
O8 - Extra context menu item: Display All Images with Full Quality - &quot;res://C:\Program Files\NetZero\qsacc\appres.dll/228&quot;<br />
O8 - Extra context menu item: Display Image with Full Quality - &quot;res://C:\Program Files\NetZero\qsacc\appres.dll/227&quot;<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O10 - Unknown file in Winsock LSP: bmnet.dll<br />
O10 - Unknown file in Winsock LSP: bmnet.dll<br />
O10 - Unknown file in Winsock LSP: bmnet.dll<br />
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - <a href="http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab" target="_blank">http://atv.disney.go.com/global/down.../OTOYAX29b.cab</a><br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />
O18 - Filter hijack: text/html - {554f1cde-ddbd-4eb5-a1fe-ebb7a772272a} - C:\WINDOWS\msvideo.dll<br />
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL<br />
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe<br />
<br />
--<br />
End of file - 7192 bytes<br />
<br />
<br />
<br />
<br />
Here is my mbam:<br />
<br />
Malwarebytes' Anti-Malware 1.46<br />
<a href="http://www.malwarebytes.org" target="_blank">www.malwarebytes.org</a><br />
<br />
Database version: 4052<br />
<br />
Windows 5.1.2600 Service Pack 3<br />
Internet Explorer 8.0.6001.18702<br />
<br />
9/4/2010 9:54:51 PM<br />
mbam-log-2010-09-04 (21-54-51).txt<br />
<br />
Scan type: Full scan (C:\|D:\|)<br />
Objects scanned: 310817<br />
Time elapsed: 2 hour(s), 6 minute(s), 19 second(s)<br />
<br />
Memory Processes Infected: 0<br />
Memory Modules Infected: 0<br />
Registry Keys Infected: 0<br />
Registry Values Infected: 0<br />
Registry Data Items Infected: 0<br />
Folders Infected: 0<br />
Files Infected: 11<br />
<br />
Memory Processes Infected:<br />
(No malicious items detected)<br />
<br />
Memory Modules Infected:<br />
(No malicious items detected)<br />
<br />
Registry Keys Infected:<br />
(No malicious items detected)<br />
<br />
Registry Values Infected:<br />
(No malicious items detected)<br />
<br />
Registry Data Items Infected:<br />
(No malicious items detected)<br />
<br />
Folders Infected:<br />
(No malicious items detected)<br />
<br />
Files Infected:<br />
C:\System Volume Information\_restore{39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP119\A0097468.exe (Trojan.Downloader) -&gt; Quarantined and deleted successfully.<br />
C:\System Volume Information\_restore{39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP119\A0097464.exe (Trojan.Downloader) -&gt; Quarantined and deleted successfully.<br />
C:\System Volume Information\_restore{39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP119\A0097465.exe (Rogue.Security.Tool) -&gt; Quarantined and deleted successfully.<br />
C:\System Volume Information\_restore{39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP119\A0097466.dll (Rogue.AntimalwareDoctor) -&gt; Quarantined and deleted successfully.<br />
C:\System Volume Information\_restore{39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP119\A0097467.exe (Trojan.Downloader) -&gt; Quarantined and deleted successfully.<br />
C:\System Volume Information\_restore{39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP119\A0097469.exe (Trojan.Downloader) -&gt; Quarantined and deleted successfully.<br />
C:\System Volume Information\_restore{39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP119\A0097470.exe (Trojan.FakeAlert) -&gt; Quarantined and deleted successfully.<br />
C:\System Volume Information\_restore{39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP119\A0097471.exe (Trojan.Downloader) -&gt; Quarantined and deleted successfully.<br />
C:\System Volume Information\_restore{39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP119\A0097472.sys (Rootkit.Agent) -&gt; Quarantined and deleted successfully.<br />
C:\System Volume Information\_restore{39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP119\A0097473.exe (Trojan.Bredolab) -&gt; Quarantined and deleted successfully.<br />
C:\System Volume Information\_restore{39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP119\A0097474.exe (Rogue.Security.Tool) -&gt; Quarantined and deleted successfully.</div>

]]></content:encoded>
			<category domain="http://www.computerforum.com/computer-security/">Computer Security</category>
			<dc:creator>AkinaGod</dc:creator>
			<guid isPermaLink="true">http://www.computerforum.com/182388-virus-keeps-returning.html</guid>
		</item>
		<item>
			<title>please read my hijackthis file and advise</title>
			<link>http://www.computerforum.com/182374-please-read-my-hijackthis-file-advise.html</link>
			<pubDate>Sat, 04 Sep 2010 22:04:04 GMT</pubDate>
			<description>My computer was infected couple weeks ago .. I installed AVG Free edition and was able to remove the virus .. the only problem now is that my computer is super slow .. when i first start it ir seems to be ok but i gets slower and slower as i use it  .. i run XP. 
 
Ram Hijackthis and here is copy...</description>
			<content:encoded><![CDATA[<div>My computer was infected couple weeks ago .. I installed AVG Free edition and was able to remove the virus .. the only problem now is that my computer is super slow .. when i first start it ir seems to be ok but i gets slower and slower as i use it  .. i run XP.<br />
<br />
Ram Hijackthis and here is copy of the file .. kindly review and advise .. thanks:<br />
<br />
<br />
 Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 8:31:22 PM, on 7/20/2009<br />
Platform: Windows Vista  (WinNT 6.00.1904)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16851)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\taskeng.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Windows\RtHDVCpl.exe<br />
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe<br />
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br />
C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br />
C:\Program Files\Symantec AntiVirus\VPTray.exe<br />
C:\Windows\System32\igfxtray.exe<br />
C:\Windows\System32\hkcmd.exe<br />
C:\Windows\System32\igfxpers.exe<br />
C:\Program Files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe<br />
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo  tifier.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Windows\system32\igfxsrvc.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe<br />
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br />
C:\Program Files\Internet Explorer\ieuser.exe<br />
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://www.toshibadirect.com/dpdstart" target="_blank">http://www.toshibadirect.com/dpdstart</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.yahoo.com/" target="_blank">http://www.yahoo.com/</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://www.toshibadirect.com/dpdstart" target="_blank">http://www.toshibadirect.com/dpdstart</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int  ernet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\  swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll<br />
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 - HKLM\..\Run: [IAAnotif] &quot;C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe&quot;<br />
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br />
O4 - HKLM\..\Run: [Skytel] Skytel.exe<br />
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe<br />
O4 - HKLM\..\Run: [Google Desktop Search] &quot;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&quot; /startup<br />
O4 - HKLM\..\Run: [ccApp] &quot;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&quot;<br />
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe<br />
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [DACSMiniApp] C:\Program Files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent<br />
O4 - HKCU\..\Run: [TOSCDSPD] TOSCDSPD.EXE<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo  tifier.exe<br />
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE<br />
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br />
O8 - Extra context menu item: Add to Google Photos Screensa&amp;ver - res://C:\Windows\system32\GPhotos.scr/200<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {0C92900E-4D5A-4F04-ACC9-729E1767BBAE} (Image Uploader Control) - <a href="http://www.ritzpix.com/net/Uploader/LPUploader45.cab" target="_blank">http://www.ritzpix.com/net/Uploader/LPUploader45.cab</a><br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - <a href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" target="_blank">http://upload.facebook.com/controls/...oUploader5.cab</a><br />
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - <a href="http://photos.walmart.com/WalmartActivia.cab" target="_blank">http://photos.walmart.com/WalmartActivia.cab</a><br />
O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - <a href="http://targetphoto.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab" target="_blank">http://targetphoto.kodakgallery.com/...2/axofupld.cab</a><br />
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - <a href="http://web1.shutterfly.com/downloads/Uploader.cab" target="_blank">http://web1.shutterfly.com/downloads/Uploader.cab</a><br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/ge...nt/swflash.cab</a><br />
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll<br />
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL<br />
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe<br />
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe<br />
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762#  # (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br />
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe<br />
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe<br />
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br />
O23 - Service: pinger - Unknown owner - C:\TOSHIBA\IVP\ISM\pinger.exe<br />
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe<br />
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe<br />
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br />
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe<br />
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe<br />
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe<br />
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.1.30\bin\mysqld.exe<br />
<br />
--<br />
End of file - 10297 bytes</div>

]]></content:encoded>
			<category domain="http://www.computerforum.com/computer-security/">Computer Security</category>
			<dc:creator>switchex</dc:creator>
			<guid isPermaLink="true">http://www.computerforum.com/182374-please-read-my-hijackthis-file-advise.html</guid>
		</item>
		<item>
			<title>BIOS viruses still work?</title>
			<link>http://www.computerforum.com/182318-bios-viruses-still-work.html</link>
			<pubDate>Fri, 03 Sep 2010 18:38:46 GMT</pubDate>
			<description><![CDATA[I was just wondering if viruses which can permanentely be placed on your computer still work? 
 
I've heard about how computer BIOS are far more secured and its not possible to get viruses executed from ROM but is it true?]]></description>
			<content:encoded><![CDATA[<div>I was just wondering if viruses which can permanentely be placed on your computer still work?<br />
<br />
I've heard about how computer BIOS are far more secured and its not possible to get viruses executed from ROM but is it true?</div>

]]></content:encoded>
			<category domain="http://www.computerforum.com/computer-security/">Computer Security</category>
			<dc:creator>bigcomp</dc:creator>
			<guid isPermaLink="true">http://www.computerforum.com/182318-bios-viruses-still-work.html</guid>
		</item>
		<item>
			<title>Windows starts then shuts down...</title>
			<link>http://www.computerforum.com/182266-windows-starts-then-shuts-down.html</link>
			<pubDate>Thu, 02 Sep 2010 23:25:25 GMT</pubDate>
			<description>Windows Vista Home Premium 
HP Pavilion a1700n 
512 DDR2 graphics card 
480 watt power supply 
3.0 Gig of RAM (2x 512, 2x 1 gig sticks) 
All else is original 
 
Over the past week, when Windows starts it will load for approx 1 minute and then go thru a shut down mode and shut itself down.  Its...</description>
			<content:encoded><![CDATA[<div>Windows Vista Home Premium<br />
HP Pavilion a1700n<br />
512 DDR2 graphics card<br />
480 watt power supply<br />
3.0 Gig of RAM (2x 512, 2x 1 gig sticks)<br />
All else is original<br />
<br />
Over the past week, when Windows starts it will load for approx 1 minute and then go thru a shut down mode and shut itself down.  Its almost like you click shut down, but I dont click or do anything.  If I set the restore point back a week or more, the computer will start and run just fine without shutting down.  I can do this temporarily but my restore point is going to get further and further back and the updates to Windows and everything else is going to start being affected negatively.  I have AVG purchased edition of virus software, it is licensed and up to date.  I tried running a few complete computer scans and also tried running a complete scan via safe mode, but it doesnt find anything or any viruses or nothing.<br />
<br />
Please help me determine what may cause this problem.<br />
<br />
P.S.  Power supply fan, case fan and cpu fan all run as they should and cool as they should.</div>

]]></content:encoded>
			<category domain="http://www.computerforum.com/computer-security/">Computer Security</category>
			<dc:creator>vzfox</dc:creator>
			<guid isPermaLink="true">http://www.computerforum.com/182266-windows-starts-then-shuts-down.html</guid>
		</item>
		<item>
			<title>wont boot (even safe mode) but im in the recovery console...</title>
			<link>http://www.computerforum.com/182233-wont-boot-even-safe-mode-but-im-recovery-console.html</link>
			<pubDate>Thu, 02 Sep 2010 06:14:22 GMT</pubDate>
			<description>what do i do? i can figure out the rest once i can get into explorer or have it boot in safe mode or something... upon booting up it will give me the option to go into safe mode, safe with networking etc.... (you know the rest) and it wont move past the selection screen once i select one of the...</description>
			<content:encoded><![CDATA[<div>what do i do? i can figure out the rest once i can get into explorer or have it boot in safe mode or something... upon booting up it will give me the option to go into safe mode, safe with networking etc.... (you know the rest) and it wont move past the selection screen once i select one of the options.  I tried using the f8 screen and all of the options on that menu result in a blank screen.  I have an illegitimate xp disc that I used to get into the recovery console but I don't know what to do from here.  thanks</div>

]]></content:encoded>
			<category domain="http://www.computerforum.com/computer-security/">Computer Security</category>
			<dc:creator>wiwazevedo</dc:creator>
			<guid isPermaLink="true">http://www.computerforum.com/182233-wont-boot-even-safe-mode-but-im-recovery-console.html</guid>
		</item>
		<item>
			<title>Security Issue - Browser</title>
			<link>http://www.computerforum.com/182226-security-issue-browser.html</link>
			<pubDate>Thu, 02 Sep 2010 02:53:01 GMT</pubDate>
			<description><![CDATA[So all of a sudden, when I browse sites in Opera, I get this message.  
 
(not mine, but same message.) 
Image: http://i51.photobucket.com/albums/f356/shai_hulud_27/scrnsht.png    
 
My PC froze last night when playing BC2, then after that my Kaspersky database became obsolete and I'm pretty...]]></description>
			<content:encoded><![CDATA[<div>So all of a sudden, when I browse sites in Opera, I get this message. <br />
<br />
(not mine, but same message.)<br />
<img src="http://i51.photobucket.com/albums/f356/shai_hulud_27/scrnsht.png" border="0" alt="" />  <br />
<br />
My PC froze last night when playing BC2, then after that my Kaspersky database became obsolete and I'm pretty positive it won't update, since it keeps popping up. I also noticed my year was changed to 2036. I ran a quick Malwarebytes and SuperAntiSpyware scan earlier, both came back clean. <br />
<br />
<br />
<br />
Any ideas?</div>

]]></content:encoded>
			<category domain="http://www.computerforum.com/computer-security/">Computer Security</category>
			<dc:creator>g4m3rof1337</dc:creator>
			<guid isPermaLink="true">http://www.computerforum.com/182226-security-issue-browser.html</guid>
		</item>
		<item>
			<title>Is Microsoft security essential conflict with superantivirus?</title>
			<link>http://www.computerforum.com/182207-microsoft-security-essential-conflict-superantivirus.html</link>
			<pubDate>Wed, 01 Sep 2010 21:12:06 GMT</pubDate>
			<description><![CDATA[HI all, my Norton 360 trial version just expired, I installed Microsoft Security Essential, It take very long to update and couldn't finish lastnight, I wonder if there are virus or malware in place since norton expired. so I install malwarebyte to check the computer and found nothing, then I try...]]></description>
			<content:encoded><![CDATA[<div>HI all, my Norton 360 trial version just expired, I installed Microsoft Security Essential, It take very long to update and couldn't finish lastnight, I wonder if there are virus or malware in place since norton expired. so I install malwarebyte to check the computer and found nothing, then I try to install superantivirus, but it can't install, I wonder if MSE stop me install it? Anyone have any idea? Thank you, I am using MSE to scan the computer now as I type.<br />
Paul</div>

]]></content:encoded>
			<category domain="http://www.computerforum.com/computer-security/">Computer Security</category>
			<dc:creator>paulcheung</dc:creator>
			<guid isPermaLink="true">http://www.computerforum.com/182207-microsoft-security-essential-conflict-superantivirus.html</guid>
		</item>
		<item>
			<title>MB log + Hijackthis log, please review</title>
			<link>http://www.computerforum.com/182202-mb-log-hijackthis-log-please-review.html</link>
			<pubDate>Wed, 01 Sep 2010 20:14:57 GMT</pubDate>
			<description><![CDATA[Computer is going slow, having some problems. Logs are below, thanks! 
MB: 
 
Malwarebytes' Anti-Malware 1.46 
www.malwarebytes.org 
 
Database version: 4052 
 
Windows 5.1.2600 Service Pack 3 
Internet Explorer 8.0.6001.18702]]></description>
			<content:encoded><![CDATA[<div>Computer is going slow, having some problems. Logs are below, thanks!<br />
MB:<br />
<br />
Malwarebytes' Anti-Malware 1.46<br />
<a href="http://www.malwarebytes.org" target="_blank">www.malwarebytes.org</a><br />
<br />
Database version: 4052<br />
<br />
Windows 5.1.2600 Service Pack 3<br />
Internet Explorer 8.0.6001.18702<br />
<br />
01/09/2010 1:34:29 PM<br />
mbam-log-2010-09-01 (13-34-29).txt<br />
<br />
Scan type: Quick scan<br />
Objects scanned: 162090<br />
Time elapsed: 48 minute(s), 51 second(s)<br />
<br />
Memory Processes Infected: 0<br />
Memory Modules Infected: 0<br />
Registry Keys Infected: 19<br />
Registry Values Infected: 3<br />
Registry Data Items Infected: 3<br />
Folders Infected: 1<br />
Files Infected: 7<br />
<br />
Memory Processes Infected:<br />
(No malicious items detected)<br />
<br />
Memory Modules Infected:<br />
(No malicious items detected)<br />
<br />
Registry Keys Infected:<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre  ntVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre  ntVersion\Ext\Stats\{f919fbd3-a96b-4679-af26-f551439bb5fd} (Trojan.FakeAlert) -&gt; Quarantined and deleted successfully.<br />
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\Cur  rentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -&gt; Quarantined and deleted successfully.<br />
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\Cur  rentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -&gt; Quarantined and deleted successfully.<br />
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\Cur  rentVersion\Explorer\{494e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -&gt; Quarantined and deleted successfully.<br />
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\Cur  rentVersion\Explorer\{3446af26-b8d7-199b-4cfc-6fd764ca5c9f} (Backdoor.Bot) -&gt; Quarantined and deleted successfully.<br />
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\Cur  rentVersion\Explorer\{4776c4dc-e894-7c06-2148-5d73cef5f905} (Backdoor.Bot) -&gt; Quarantined and deleted successfully.<br />
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explo  rer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -&gt; Quarantined and deleted successfully.<br />
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explo  rer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -&gt; Quarantined and deleted successfully.<br />
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explo  rer\{494e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -&gt; Quarantined and deleted successfully.<br />
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explo  rer\{3446af26-b8d7-199b-4cfc-6fd764ca5c9f} (Backdoor.Bot) -&gt; Quarantined and deleted successfully.<br />
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explo  rer\{4776c4dc-e894-7c06-2148-5d73cef5f905} (Backdoor.Bot) -&gt; Quarantined and deleted successfully.<br />
HKEY_CLASSES_ROOT\TypeLib\{497dddb6-6eee-4561-9621-b77dc82c1f84} (Rogue.Ascentive) -&gt; Quarantined and deleted successfully.<br />
HKEY_CLASSES_ROOT\Interface\{4e980492-027b-47f1-a7ab-ab086dacbb9e} (Rogue.Ascentive) -&gt; Quarantined and deleted successfully.<br />
HKEY_CLASSES_ROOT\Interface\{5ead8321-fcbb-4c3f-888c-ac373d366c3f} (Rogue.Ascentive) -&gt; Quarantined and deleted successfully.<br />
HKEY_CLASSES_ROOT\CLSID\{31f3cf6e-a71a-4daa-852b-39ac230940b4} (Rogue.Ascentive) -&gt; Quarantined and deleted successfully.<br />
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -&gt; Quarantined and deleted successfully.<br />
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -&gt; Quarantined and deleted successfully.<br />
HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.TryMedia) -&gt; Quarantined and deleted successfully.<br />
<br />
Registry Values Infected:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr  entVersion\SharedDLLs\C:\WINDOWS\system32\SysResto  re.dll (Rogue.Ascentive) -&gt; Quarantined and deleted successfully.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\uid (Malware.Trace) -&gt; Quarantined and deleted successfully.<br />
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\Cur  rentVersion\Run\6250773f-eb61-4702-ba50-93ebccee997a_47 (Trojan.FakeAlert) -&gt; Quarantined and deleted successfully.<br />
<br />
Registry Data Items Infected:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Spyware.Zbot) -&gt; Data: c:\windows\system32\sdra64.exe -&gt; Delete on reboot.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Spyware.Zbot) -&gt; Data: system32\sdra64.exe -&gt; Delete on reboot.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -&gt; Bad: (c:\windows\system32\userinit.exe                                                                                                                                                                                                        ,c:\windows\system32\userinlt.exe,,c:\program files\microsoft\desktoplayer.exe,,c:\windows\temp\  16.tmp,c:\windows\system32\sdra64.exe,,c:\program files\java\jre6\bin\javasrv.exe) Good: (Userinit.exe) -&gt; Quarantined and deleted successfully.<br />
<br />
Folders Infected:<br />
C:\WINDOWS\system32\lowsec (Stolen.data) -&gt; Delete on reboot.<br />
<br />
Files Infected:<br />
C:\WINDOWS\system32\SysRestore.dll (Rogue.Ascentive) -&gt; Quarantined and deleted successfully.<br />
C:\WINDOWS\system32\lowsec\local.ds (Stolen.data) -&gt; Delete on reboot.<br />
C:\WINDOWS\system32\lowsec\user.ds (Stolen.data) -&gt; Delete on reboot.<br />
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\ntuser_mssec.exe (Trojan.VirTool) -&gt; Quarantined and deleted successfully.<br />
C:\WINDOWS\system32\sdra64.exe (Spyware.Zbot) -&gt; Delete on reboot.<br />
C:\Documents and Settings\NetworkService\Application Data\avdrn.dat (Malware.Trace) -&gt; Quarantined and deleted successfully.<br />
C:\Documents and Settings\LocalService\Application Data\6250773f-eb61-4702-ba50-93ebccee997a_47.avi (Trojan.FakeAlert) -&gt; Quarantined and deleted successfully.</div>

]]></content:encoded>
			<category domain="http://www.computerforum.com/computer-security/">Computer Security</category>
			<dc:creator>Twinbird24</dc:creator>
			<guid isPermaLink="true">http://www.computerforum.com/182202-mb-log-hijackthis-log-please-review.html</guid>
		</item>
		<item>
			<title>Firefox and no script</title>
			<link>http://www.computerforum.com/182180-firefox-no-script.html</link>
			<pubDate>Wed, 01 Sep 2010 10:58:43 GMT</pubDate>
			<description>I was wondering who used No Script in Firefox, and if you think it is worth the small hassle?</description>
			<content:encoded><![CDATA[<div>I was wondering who used No Script in Firefox, and if you think it is worth the small hassle?</div>

]]></content:encoded>
			<category domain="http://www.computerforum.com/computer-security/">Computer Security</category>
			<dc:creator>tomwom</dc:creator>
			<guid isPermaLink="true">http://www.computerforum.com/182180-firefox-no-script.html</guid>
		</item>
		<item>
			<title>what is the best antivirus for windows7</title>
			<link>http://www.computerforum.com/182096-what-best-antivirus-windows7.html</link>
			<pubDate>Mon, 30 Aug 2010 22:42:38 GMT</pubDate>
			<description>I am using windows 7 but I need your advice to choose the best security solution is the free antivirus software like avg enough to protect your system or I need to buy one</description>
			<content:encoded><![CDATA[<div>I am using windows 7 but I need your advice to choose the best security solution is the free antivirus software like avg enough to protect your system or I need to buy one</div>

]]></content:encoded>
			<category domain="http://www.computerforum.com/computer-security/">Computer Security</category>
			<dc:creator>lord_86</dc:creator>
			<guid isPermaLink="true">http://www.computerforum.com/182096-what-best-antivirus-windows7.html</guid>
		</item>
		<item>
			<title>Spybot refuses to fully immunize???</title>
			<link>http://www.computerforum.com/182083-spybot-refuses-fully-immunize.html</link>
			<pubDate>Mon, 30 Aug 2010 18:28:30 GMT</pubDate>
			<description><![CDATA[When I try to immunize with my Spybot, I get this:  "This action may not be performed completely since you are not an administrator. If you want this performed for all users, please run this application elevated as an administrator." 
 
I checked on the internet, found instructions: right click on...]]></description>
			<content:encoded><![CDATA[<div>When I try to immunize with my Spybot, I get this:  <i>&quot;This action may not be performed completely since you are not an administrator. If you want this performed for all users, please run this application elevated as an administrator.&quot;</i><br />
<br />
I checked on the internet, found instructions: right click on Spybot and click on Run as Administrator. But...after doing it, nothing has changed!<br />
<br />
I also note that this is occurring with Vista, <i>but I do not have Vista.</i> I have Windows 7. <br />
<br />
Help! I want to immunize but it's not working. :confused:</div>

]]></content:encoded>
			<category domain="http://www.computerforum.com/computer-security/">Computer Security</category>
			<dc:creator>doodlebug1</dc:creator>
			<guid isPermaLink="true">http://www.computerforum.com/182083-spybot-refuses-fully-immunize.html</guid>
		</item>
	</channel>
</rss>
