<?xml version="1.0" encoding="iso-8859-1" ?>
<feed version="0.3" xmlns="http://purl.org/atom/ns#" xmlns:dc="http://purl.org/dc/elements/1.1/">
<!--
	This feed generated for Anonymous	More info at http://naklon.info/rss/about.htm
	Customized and Ported for CastleCops
-->
  <title>CastleCops Recent Posts</title>
  <generator>RSS Feed 2.2.1</generator>
  <link rel="alternate" type="text/html"
   href="http://www.castlecops.com/"/>
  <modified>2008-07-05T15:51:02Z</modified>
  <entry>
    <title mode="escaped">Mailwasher - Troubleshooting / General :: RE: Mailwasher times out</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1103685.html#1103685"/>
    <dc:creator>rogerw</dc:creator>
    <dc:subject>Mailwasher - Troubleshooting / General</dc:subject>
    <author>
		<name>rogerw</name>
    </author>
    <id>http://www.castlecops.com/postp1103685.html#1103685</id>
    <issued>2008-07-05T15:44:21Z</issued>
    <modified>2008-07-05T15:44:21Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=3678&quot; target=&quot;_blank&quot;&gt;rogerw&lt;/a&gt;&lt;br /&gt;
	Posted: Sat Jul 05, 2008 3:44 pm (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	By default (to be as zippy as possible) MW tries to access ALL accounts simultaneously.
&lt;br /&gt;

&lt;br /&gt;
However, many ISPs (in order to prevent flooding) disallow multiple connnections from the same IP address - and also lock out those IP addresses for a short period of time if they detect flooding.   
&lt;br /&gt;

&lt;br /&gt;
This sounds like what your ISP is doing.
&lt;br /&gt;

&lt;br /&gt;
Try setting MW to download accounts SEQUENTIALLY (Tools&amp;gt;Options&amp;gt;Connection Options then select the &amp;quot;Sequential&amp;quot; radio button.)   Doing so will make MW download one account at a time and will avoid such flooding protection.
&lt;br /&gt;

&lt;br /&gt;
It will ALSO be necessary to make sure that your email client is NOT also trying to fetch mail at the same time - or it can cause the problem, too.  Make sure that &amp;quot;automatic mail checking&amp;quot; is turned off in your email client.&lt;br /&gt;_________________&lt;br /&gt;&quot;It's just a jump to the left ...&quot;
&lt;br /&gt;
&lt;span style=&quot;color: white&quot;&gt;&quot;Buttons are &lt;span style=&quot;font-weight: bold&quot;&gt;not&lt;/span&gt; toys!&quot;&lt;/span&gt;
&lt;br /&gt;
&lt;span style=&quot;color: white&quot;&gt;&quot;My snake oil is better than anyone else's!&quot;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Catch All - Guests :: RE: We need to monitor the kids activity online...</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1103684.html#1103684"/>
    <dc:creator>Anonymous</dc:creator>
    <dc:subject>Catch All - Guests</dc:subject>
    <author>
		<name>Anonymous</name>
    </author>
    <id>http://www.castlecops.com/postp1103684.html#1103684</id>
    <issued>2008-07-05T15:34:50Z</issued>
    <modified>2008-07-05T15:34:50Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=1&quot; target=&quot;_blank&quot;&gt;Anonymous&lt;/a&gt;&lt;br /&gt;
	Posted: Sat Jul 05, 2008 3:34 pm (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	Some software may help
&lt;br /&gt;
&lt;a href=&quot;http://www.parental-controls-software.net&quot;&gt;http://www.parental-controls-software.net&lt;/a&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.pc-remote-monitoring.com&quot;&gt;http://www.pc-remote-monitoring.com&lt;/a&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.spytech-monitoring-software.com&quot;&gt;http://www.spytech-monitoring-software.com&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Sidki - Proxomitron :: RE: How to allow ONLOAD</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1103681.html#1103681"/>
    <dc:creator>whenever</dc:creator>
    <dc:subject>Sidki - Proxomitron</dc:subject>
    <author>
		<name>whenever</name>
    </author>
    <id>http://www.castlecops.com/postp1103681.html#1103681</id>
    <issued>2008-07-05T15:12:45Z</issued>
    <modified>2008-07-05T15:12:45Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=175505&quot; target=&quot;_blank&quot;&gt;whenever&lt;/a&gt;&lt;br /&gt;
	Posted: Sat Jul 05, 2008 3:12 pm (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	Try:
&lt;br /&gt;
&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Code:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;code&quot;&gt;
&lt;br /&gt;
video.google.com&amp;nbsp; &amp;nbsp;$SET&amp;#40;0=i_level&amp;#58;1.0.&amp;#41;
&lt;br /&gt;
&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Trend Micro HijackThis Logs :: RE: help needed with this blasted trojan that wont go away.</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1103680.html#1103680"/>
    <dc:creator>Rosty</dc:creator>
    <dc:subject>Trend Micro HijackThis Logs</dc:subject>
    <author>
		<name>Rosty</name>
    </author>
    <id>http://www.castlecops.com/postp1103680.html#1103680</id>
    <issued>2008-07-05T15:09:11Z</issued>
    <modified>2008-07-05T15:09:11Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=152859&quot; target=&quot;_blank&quot;&gt;Rosty&lt;/a&gt;&lt;br /&gt;
	Posted: Sat Jul 05, 2008 3:09 pm (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	Hi,
&lt;br /&gt;

&lt;br /&gt;
sorry for the delay in getting back to you. My name is Rosty and I'm going to help you with your log.
&lt;br /&gt;

&lt;br /&gt;
Please download &lt;a href=&quot;http://www.besttechie.net/tools/mbam-setup.exe&quot; rel=&quot;nofollow&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;Malwarebytes' Anti-Malware&lt;/a&gt; to your desktop.
&lt;br /&gt;

&lt;br /&gt;
Double-click mbam-setup.exe and follow the prompts to install the program.
&lt;br /&gt;
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
&lt;br /&gt;
If an update is found, it will download and install the latest version.
&lt;br /&gt;
Once the program has loaded, select Perform full scan (Full scan is optional. According to the program's creator Quick Scan will do just fine.).
&lt;br /&gt;
Click Scan.
&lt;br /&gt;
When the scan is complete, click OK, then Show Results to view the results.
&lt;br /&gt;

&lt;br /&gt;
&lt;span style=&quot;color: red&quot;&gt;If Malware is found...&lt;/span&gt;
&lt;br /&gt;
Be sure that everything is checked, and click Remove Selected.
&lt;br /&gt;
When completed, a log will open in Notepad. 
&lt;br /&gt;
Please save it to your desktop.
&lt;br /&gt;

&lt;br /&gt;
&lt;span style=&quot;color: red&quot;&gt;NOTE&lt;/span&gt;: Logs can be retrieved at a later date from the Malwarebytes' Anti-Malware main screen:
&lt;br /&gt;

&lt;br /&gt;
Launch Malwarebytes' Anti-Malware.
&lt;br /&gt;
Click the Logs tab.
&lt;br /&gt;
Double-click log-mm.dd.yyyy [xxxxxx].txt.
&lt;br /&gt;

&lt;br /&gt;
In your next reply, please include:
&lt;br /&gt;
-The log from Malwarebytes' Anti-Malware.
&lt;br /&gt;
- A new HijackThis log.
&lt;br /&gt;

&lt;br /&gt;
Regards,
&lt;br /&gt;

&lt;br /&gt;
Rosty.&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">SIRT Reports :: [SIRT#196332] Canadian Healthcare on cliprenew.com/biuhwaapl</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1103678.html#1103678"/>
    <dc:creator>jimVO</dc:creator>
    <dc:subject>SIRT Reports</dc:subject>
    <author>
		<name>jimVO</name>
    </author>
    <id>http://www.castlecops.com/postp1103678.html#1103678</id>
    <issued>2008-07-05T15:03:01Z</issued>
    <modified>2008-07-05T15:03:01Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=188295&quot; target=&quot;_blank&quot;&gt;jimVO&lt;/a&gt;&lt;br /&gt;
	Subject: [SIRT#196332] Canadian Healthcare on cliprenew.com/biuhwaapl&lt;br /&gt;Posted: Sat Jul 05, 2008 3:03 pm (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	&lt;span style=&quot;font-size: 18px; line-height: normal&quot;&gt;&lt;span style=&quot;color: darkred&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Spam Alert&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Full Report: &lt;a href=&quot;http://www.castlecops.com/Canadian_Healthcare_spam196332.html&quot;&gt;http://www.castlecops.com/Canadian_Healthcare_spam196332.html&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Changed status to confirmed spam.IP Converted: 59.37.30.147
&lt;br /&gt;

&lt;br /&gt;
dword = 992288403
&lt;br /&gt;
hex1 = 0x3b251e93
&lt;br /&gt;
hex2 = 0x3b.0x25.0x1e.0x93
&lt;br /&gt;
oct = 073.045.036.0223
&lt;br /&gt;
View CIDR AS4134 Report: &lt;a href=&quot;http://www.cidr-report.org/cgi-bin/as-report?as=4134&quot;&gt;http://www.cidr-report.org/cgi-bin/as-report?as=4134&lt;/a&gt; 
&lt;br /&gt;

&lt;br /&gt;
&amp;quot;4134 | CN | apnic | 2002-08-01 | CHINANET-BACKBONE No.31,Jin-rong Street&amp;quot;&amp;lt;br /&amp;gt;
&lt;br /&gt;
Extended information for AS4134:
&lt;br /&gt;
State/Province: 
&lt;br /&gt;
Country: cn
&lt;br /&gt;
Responsible Domain: chinanet.cn.net
&lt;br /&gt;
Abuse Email: &lt;a href=&quot;mailto:cncert@cert.org.cn&quot;&gt;cncert@cert.org.cn&lt;/a&gt;
&lt;br /&gt;
Criminal Evidence
&lt;br /&gt;

&lt;br /&gt;
See the Spam Wiki entry at &lt;a href=&quot;http://www.spamtrackers.eu/wiki/index.php?title=Canadian_Healthcare&quot;&gt;http://www.spamtrackers.eu/wiki/index.php?title=Canadian_Healthcare&lt;/a&gt;
&lt;br /&gt;
or from China: &lt;a href=&quot;http://www.spamtrackers.hk/wiki/index.php?title=Canadian_Healthcare&quot;&gt;http://www.spamtrackers.hk/wiki/index.php?title=Canadian_Healthcare&lt;/a&gt;
&lt;br /&gt;
See the McAfee Site Advisor information at &lt;a href=&quot;http://siteadvisor.com/sites/cliprenew.com&quot;&gt;http://siteadvisor.com/sites/cliprenew.com&lt;/a&gt;
&lt;br /&gt;

&lt;br /&gt;

&lt;br /&gt;
&amp;gt; 35 TECHNOLOGY
&lt;br /&gt;
REGISTRATION OF THE WEB SITE: cliprenew.com
&lt;br /&gt;
ACTION: To suspend this criminal site which breaks your terms of service, set the domain status to clientHold
&lt;br /&gt;

&lt;br /&gt;

&lt;br /&gt;
&amp;gt; HICHINA
&lt;br /&gt;
REGISTRATION OF THE NAME SERVERS
&lt;br /&gt;
These name servers are registered by criminals to resolve only illegal web sites. This breaks your terms of service. You can safely suspend them:
&lt;br /&gt;
ns4.biuhwaapl.com	124.236.241.91	124.236.241.91	Blacklisted	China	URIBL	 SBL65127 | 
&lt;br /&gt;
ns3.biuhwaapl.com	59.37.30.147	59.37.30.147	Blacklisted	China	URIBL	 SBL65447
&lt;br /&gt;

&lt;br /&gt;
ACTION: To suspend these name servers successfully, follow these steps.
&lt;br /&gt;
1. set the ns Address records to a non-routable address, such as 127.0.0.1 or 61.61.61.61.
&lt;br /&gt;
2. Set the domain status to clientUpdateProhibited, clientTransferProhibited, clientDeleteProhibited, and clientHold
&lt;br /&gt;

&lt;br /&gt;

&lt;br /&gt;
&amp;gt; CNCERT
&lt;br /&gt;
IP ADDRESS OF HOST: 59.37.30.147
&lt;br /&gt;
The IP address of this criminal site is within your allocated address space.
&lt;br /&gt;
ACTION:  Black-hole the route to this address to prevent further criminal activity&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;http://www.cliprenew.com/&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Trend Micro HijackThis Logs :: RE: Problem at launch, from what I read it must be a malware</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1103677.html#1103677"/>
    <dc:creator>Rosty</dc:creator>
    <dc:subject>Trend Micro HijackThis Logs</dc:subject>
    <author>
		<name>Rosty</name>
    </author>
    <id>http://www.castlecops.com/postp1103677.html#1103677</id>
    <issued>2008-07-05T15:01:29Z</issued>
    <modified>2008-07-05T15:01:29Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=152859&quot; target=&quot;_blank&quot;&gt;Rosty&lt;/a&gt;&lt;br /&gt;
	Posted: Sat Jul 05, 2008 3:01 pm (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	Hi,
&lt;br /&gt;

&lt;br /&gt;
sorry for the delay in getting back to you. My name is Rosty and I'm going to help you with your log.
&lt;br /&gt;

&lt;br /&gt;
Please download &lt;a href=&quot;http://www.besttechie.net/tools/mbam-setup.exe&quot; rel=&quot;nofollow&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;Malwarebytes' Anti-Malware&lt;/a&gt; to your desktop.
&lt;br /&gt;

&lt;br /&gt;
Double-click mbam-setup.exe and follow the prompts to install the program.
&lt;br /&gt;
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
&lt;br /&gt;
If an update is found, it will download and install the latest version.
&lt;br /&gt;
Once the program has loaded, select Perform full scan (Full scan is optional. According to the program's creator Quick Scan will do just fine.).
&lt;br /&gt;
Click Scan.
&lt;br /&gt;
When the scan is complete, click OK, then Show Results to view the results.
&lt;br /&gt;

&lt;br /&gt;
&lt;span style=&quot;color: red&quot;&gt;If Malware is found...&lt;/span&gt;
&lt;br /&gt;
Be sure that everything is checked, and click Remove Selected.
&lt;br /&gt;
When completed, a log will open in Notepad. 
&lt;br /&gt;
Please save it to your desktop.
&lt;br /&gt;

&lt;br /&gt;
&lt;span style=&quot;color: red&quot;&gt;NOTE&lt;/span&gt;: Logs can be retrieved at a later date from the Malwarebytes' Anti-Malware main screen:
&lt;br /&gt;

&lt;br /&gt;
Launch Malwarebytes' Anti-Malware.
&lt;br /&gt;
Click the Logs tab.
&lt;br /&gt;
Double-click log-mm.dd.yyyy [xxxxxx].txt.
&lt;br /&gt;

&lt;br /&gt;
In your next reply, please include:
&lt;br /&gt;
-The log from Malwarebytes' Anti-Malware.
&lt;br /&gt;
- A new HijackThis log.&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Trend Micro HijackThis Logs :: RE: please help</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1103676.html#1103676"/>
    <dc:creator>Rosty</dc:creator>
    <dc:subject>Trend Micro HijackThis Logs</dc:subject>
    <author>
		<name>Rosty</name>
    </author>
    <id>http://www.castlecops.com/postp1103676.html#1103676</id>
    <issued>2008-07-05T14:58:40Z</issued>
    <modified>2008-07-05T14:58:40Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=152859&quot; target=&quot;_blank&quot;&gt;Rosty&lt;/a&gt;&lt;br /&gt;
	Posted: Sat Jul 05, 2008 2:58 pm (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	Hi,
&lt;br /&gt;

&lt;br /&gt;
welcome to CC. My name is Rosty and I'm going to help you with your log.
&lt;br /&gt;

&lt;br /&gt;
Please download &lt;a href=&quot;http://www.besttechie.net/tools/mbam-setup.exe&quot; rel=&quot;nofollow&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;Malwarebytes' Anti-Malware&lt;/a&gt; to your desktop.
&lt;br /&gt;

&lt;br /&gt;
Double-click mbam-setup.exe and follow the prompts to install the program.
&lt;br /&gt;
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
&lt;br /&gt;
If an update is found, it will download and install the latest version.
&lt;br /&gt;
Once the program has loaded, select Perform full scan (Full scan is optional. According to the program's creator Quick Scan will do just fine.).
&lt;br /&gt;
Click Scan.
&lt;br /&gt;
When the scan is complete, click OK, then Show Results to view the results.
&lt;br /&gt;

&lt;br /&gt;
&lt;span style=&quot;color: red&quot;&gt;If Malware is found...&lt;/span&gt;
&lt;br /&gt;
Be sure that everything is checked, and click Remove Selected.
&lt;br /&gt;
When completed, a log will open in Notepad. 
&lt;br /&gt;
Please save it to your desktop.
&lt;br /&gt;

&lt;br /&gt;
&lt;span style=&quot;color: red&quot;&gt;NOTE&lt;/span&gt;: Logs can be retrieved at a later date from the Malwarebytes' Anti-Malware main screen:
&lt;br /&gt;

&lt;br /&gt;
Launch Malwarebytes' Anti-Malware.
&lt;br /&gt;
Click the Logs tab.
&lt;br /&gt;
Double-click log-mm.dd.yyyy [xxxxxx].txt.
&lt;br /&gt;

&lt;br /&gt;
In your next reply, please include:
&lt;br /&gt;
-The log from Malwarebytes' Anti-Malware.
&lt;br /&gt;
- A new HijackThis log
&lt;br /&gt;

&lt;br /&gt;
Regards,
&lt;br /&gt;

&lt;br /&gt;
Rosty.&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Trend Micro HijackThis Logs :: RE: HijackThis Scanning Results</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1103675.html#1103675"/>
    <dc:creator>marko123</dc:creator>
    <dc:subject>Trend Micro HijackThis Logs</dc:subject>
    <author>
		<name>marko123</name>
    </author>
    <id>http://www.castlecops.com/postp1103675.html#1103675</id>
    <issued>2008-07-05T14:48:45Z</issued>
    <modified>2008-07-05T14:48:45Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=191975&quot; target=&quot;_blank&quot;&gt;marko123&lt;/a&gt;&lt;br /&gt;
	Subject: Hew Scanning Results&lt;br /&gt;Posted: Sat Jul 05, 2008 2:48 pm (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	Logfile of Trend Micro HijackThis v2.0.2
&lt;br /&gt;
Scan saved at 10:34:41 AM, on 05/07/2008
&lt;br /&gt;
Platform: Windows Vista  (WinNT 6.00.1904)
&lt;br /&gt;
MSIE: Internet Explorer v7.00 (7.00.6000.16681)
&lt;br /&gt;
Boot mode: Normal
&lt;br /&gt;

&lt;br /&gt;
Running processes:
&lt;br /&gt;
C:\Windows\system32\taskeng.exe
&lt;br /&gt;
C:\Windows\system32\Dwm.exe
&lt;br /&gt;
C:\Windows\Explorer.EXE
&lt;br /&gt;
C:\Program Files\AVG\AVG8\avgtray.exe
&lt;br /&gt;
C:\Program Files\Windows Media Player\wmpnscfg.exe
&lt;br /&gt;
C:\Program Files\Mozilla Firefox\firefox.exe
&lt;br /&gt;
C:\Users\Mihajlo Vasileski\Desktop\Antivirus\HiJackThis.exe
&lt;br /&gt;

&lt;br /&gt;
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href=&quot;http://ca.rd.yahoo.com/customize/ycomp/defaults/sp/&quot;&gt;http://ca.rd.yahoo.com/customize/ycomp/defaults/sp/&lt;/a&gt;*http://ca.yahoo.com
&lt;br /&gt;
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href=&quot;http://www.iesearch.com/&quot;&gt;http://www.iesearch.com/&lt;/a&gt;
&lt;br /&gt;
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href=&quot;http://en.ca.acer.yahoo.com&quot;&gt;http://en.ca.acer.yahoo.com&lt;/a&gt;
&lt;br /&gt;
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href=&quot;http://go.microsoft.com/fwlink/?LinkId=54896&quot;&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;
&lt;br /&gt;
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href=&quot;http://go.microsoft.com/fwlink/?LinkId=54896&quot;&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;
&lt;br /&gt;
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href=&quot;http://en.ca.acer.yahoo.com&quot;&gt;http://en.ca.acer.yahoo.com&lt;/a&gt;
&lt;br /&gt;
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
&lt;br /&gt;
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
&lt;br /&gt;
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = &lt;a href=&quot;http://ca.rd.yahoo.com/customize/ycomp/defaults/su/&quot;&gt;http://ca.rd.yahoo.com/customize/ycomp/defaults/su/&lt;/a&gt;*http://ca.yahoo.com
&lt;br /&gt;
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 
&lt;br /&gt;
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
&lt;br /&gt;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
&lt;br /&gt;
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
&lt;br /&gt;
O1 - Hosts: ::1 localhost
&lt;br /&gt;
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
&lt;br /&gt;
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
&lt;br /&gt;
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
&lt;br /&gt;
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
&lt;br /&gt;
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
&lt;br /&gt;
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
&lt;br /&gt;
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
&lt;br /&gt;
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
&lt;br /&gt;
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
&lt;br /&gt;
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
&lt;br /&gt;
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
&lt;br /&gt;
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
&lt;br /&gt;
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
&lt;br /&gt;
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
&lt;br /&gt;
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
&lt;br /&gt;
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
&lt;br /&gt;
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
&lt;br /&gt;
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
&lt;br /&gt;
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - (no file)
&lt;br /&gt;
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
&lt;br /&gt;
O10 - Broken Internet access because of LSP provider 'c:\program files\bonjour\mdnsnsp.dll' missing
&lt;br /&gt;
O13 - Gopher Prefix: 
&lt;br /&gt;
O15 - Trusted Zone: &lt;a href=&quot;http://onecare.live.com&quot;&gt;http://onecare.live.com&lt;/a&gt;
&lt;br /&gt;
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - &lt;a href=&quot;http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab&quot;&gt;http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab&lt;/a&gt;
&lt;br /&gt;
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - &lt;a href=&quot;http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab&quot;&gt;http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab&lt;/a&gt;
&lt;br /&gt;
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
&lt;br /&gt;
O20 - AppInit_DLLs: avgrsstx.dll
&lt;br /&gt;
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
&lt;br /&gt;
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
&lt;br /&gt;
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
&lt;br /&gt;
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Acer\Empowering Technology\eMode\PCM\Kernel\TV\CLCapSvc.exe
&lt;br /&gt;
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Acer\Empowering Technology\eMode\PCM\Kernel\TV\CLSched.exe
&lt;br /&gt;
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - (no file)
&lt;br /&gt;
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
&lt;br /&gt;
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
&lt;br /&gt;
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
&lt;br /&gt;
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
&lt;br /&gt;

&lt;br /&gt;
--
&lt;br /&gt;
End of file - 5716 bytes
&lt;br /&gt;

&lt;br /&gt;

&lt;br /&gt;

&lt;br /&gt;
I really don't know what to get rid of, can someone please help me, and I've got a few questions too. Can some
&lt;br /&gt;

&lt;br /&gt;
First of all can someone please tell me how to get rid of the Windows Media Player which I saw running at the top of the log.
&lt;br /&gt;

&lt;br /&gt;
Also my computer seems to constantly be doing something, like the little light that lights up on the computer when its working on something, it seems to constantly be doing that even when its just left alone, I don't know if its a virus because I used AVG to scan it and all it found was a few tracking cookies and thats it and it still does it.
&lt;br /&gt;

&lt;br /&gt;
Thanks for the help!&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Knujon General Discussion :: RE: Revising the top 10</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1103673.html#1103673"/>
    <dc:creator>Tromso</dc:creator>
    <dc:subject>Knujon General Discussion</dc:subject>
    <author>
		<name>Tromso</name>
    </author>
    <id>http://www.castlecops.com/postp1103673.html#1103673</id>
    <issued>2008-07-05T14:43:34Z</issued>
    <modified>2008-07-05T14:43:34Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=175702&quot; target=&quot;_blank&quot;&gt;Tromso&lt;/a&gt;&lt;br /&gt;
	Posted: Sat Jul 05, 2008 2:43 pm (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	Since the 10 Worst Registrars list is based upon historical data, it would help just to quote the date range of the data for which the list has been compiled eg. &amp;quot;Jan 2008 - May 2008&amp;quot; on the page and where this list is mentioned.
&lt;br /&gt;

&lt;br /&gt;
This puts the list into context and if the web page is not updated for sometime, people won't think it is a current list of worst registrars.
&lt;br /&gt;

&lt;br /&gt;
Some Registrars have just been so appalling, I do welcome a list that publicizes the fact as it can be useful in getting attention to the problem, but it should be clear for what date the list applies or it will soon lack credibility.&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Sidki - Proxomitron :: RE: Extending cookie expiration ?</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1103672.html#1103672"/>
    <dc:creator>whenever</dc:creator>
    <dc:subject>Sidki - Proxomitron</dc:subject>
    <author>
		<name>whenever</name>
    </author>
    <id>http://www.castlecops.com/postp1103672.html#1103672</id>
    <issued>2008-07-05T14:37:32Z</issued>
    <modified>2008-07-05T14:37:32Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=175505&quot; target=&quot;_blank&quot;&gt;whenever&lt;/a&gt;&lt;br /&gt;
	Posted: Sat Jul 05, 2008 2:37 pm (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	Try adding below line to CookieValues.ptxt:
&lt;br /&gt;

&lt;br /&gt;
&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Code:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;code&quot;&gt;
&lt;br /&gt;
$URL&amp;#40;http&amp;#58;//your.target.site/&amp;#41;expires\=&amp;#91;^;&amp;#93;+&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp;$SET&amp;#40;a=$GET&amp;#40;a&amp;#41;\0\1expires=Mon, 20-Jul-2018 23&amp;#58;59&amp;#58;59 GMT&amp;#41;
&lt;br /&gt;
&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Trend Micro HijackThis Logs :: RE: PLEASE!NEED TO REMOVE AD.YIELDMANAGER AND OTHER SPYWARE ETC.</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1103671.html#1103671"/>
    <dc:creator>krobi92</dc:creator>
    <dc:subject>Trend Micro HijackThis Logs</dc:subject>
    <author>
		<name>krobi92</name>
    </author>
    <id>http://www.castlecops.com/postp1103671.html#1103671</id>
    <issued>2008-07-05T14:31:59Z</issued>
    <modified>2008-07-05T14:31:59Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=190603&quot; target=&quot;_blank&quot;&gt;krobi92&lt;/a&gt;&lt;br /&gt;
	Posted: Sat Jul 05, 2008 2:31 pm (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	Hi Taz,
&lt;br /&gt;

&lt;br /&gt;
Well, I have been searching the web and so far no redirects.  I think something is trying to redirect me, I can see the web address at the bottom of my window attempting to connect to the &amp;quot;ad.yieldmanager&amp;quot; etc. address but so far no success doing so.  What do you suggest?  Should I give it a few days and just see what happens?
&lt;br /&gt;

&lt;br /&gt;
Thanks again,
&lt;br /&gt;
krobi92&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">General Hardware :: RE: CPU / Motherboard advice, please....</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1103668.html#1103668"/>
    <dc:creator>Anonymous</dc:creator>
    <dc:subject>General Hardware</dc:subject>
    <author>
		<name>Anonymous</name>
    </author>
    <id>http://www.castlecops.com/postp1103668.html#1103668</id>
    <issued>2008-07-05T14:13:49Z</issued>
    <modified>2008-07-05T14:13:49Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=1&quot; target=&quot;_blank&quot;&gt;Anonymous&lt;/a&gt;&lt;br /&gt;
	Subject: HP Pavilion a705w:  computer will not boot&lt;br /&gt;Posted: Sat Jul 05, 2008 2:13 pm (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	Good Day,
&lt;br /&gt;

&lt;br /&gt;
  I am having the same problem with my desktop PC.  I originally cleaned my computer with a vacuum but the action did not have any negative effects.  However, upon removing my memory module for inspection since it did not post the correct memory configuration, my problems began.
&lt;br /&gt;

&lt;br /&gt;
1. No video output
&lt;br /&gt;
2. No keyboard output
&lt;br /&gt;
3. No audio
&lt;br /&gt;
4. Power supply runs
&lt;br /&gt;
5. CPU fan runs
&lt;br /&gt;

&lt;br /&gt;
I tried to remove the battery and reset the jumper for the BIOS, all to no avail.
&lt;br /&gt;

&lt;br /&gt;
What is my solution?
&lt;br /&gt;

&lt;br /&gt;
Regards,
&lt;br /&gt;
Keith &lt;img src=&quot;http://isc2.castlecops.com/icon_question.gif&quot; alt=&quot;Question&quot; border=&quot;0&quot; /&gt;&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Internet Connectivity :: Retrieving a WEP/WPA key???</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1103667.html#1103667"/>
    <dc:creator>purpleroses716</dc:creator>
    <dc:subject>Internet Connectivity</dc:subject>
    <author>
		<name>purpleroses716</name>
    </author>
    <id>http://www.castlecops.com/postp1103667.html#1103667</id>
    <issued>2008-07-05T13:49:35Z</issued>
    <modified>2008-07-05T13:49:35Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=48979&quot; target=&quot;_blank&quot;&gt;purpleroses716&lt;/a&gt;&lt;br /&gt;
	Subject: Retrieving a WEP/WPA key???&lt;br /&gt;Posted: Sat Jul 05, 2008 1:49 pm (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	I recently purchased a new laptop (HP Pavilion dv6810us).  Running Vista operating system.
&lt;br /&gt;

&lt;br /&gt;
I have a Netgear wireless cable modem Gateway through my ISP.  The tech never wrote down the Key anywhere; just entered it into my old laptop.  
&lt;br /&gt;

&lt;br /&gt;
He told me that all I needed to do what enter the 'password' I chose (which happens to be the name of one of my dogs) if I wanted to let anyone share my signal.  
&lt;br /&gt;

&lt;br /&gt;
No one can connect and I am having trouble getting my own new laptop to connect.  I can plug into the Netgear box with the cable, but I want my wireless back without have to contact my provider.
&lt;br /&gt;

&lt;br /&gt;
Is there anyway to do this?????
&lt;br /&gt;

&lt;br /&gt;
Thanks&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Mailwasher - Troubleshooting / General :: Mailwasher times out</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1103666.html#1103666"/>
    <dc:creator>Anonymous</dc:creator>
    <dc:subject>Mailwasher - Troubleshooting / General</dc:subject>
    <author>
		<name>Anonymous</name>
    </author>
    <id>http://www.castlecops.com/postp1103666.html#1103666</id>
    <issued>2008-07-05T13:39:34Z</issued>
    <modified>2008-07-05T13:39:34Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=1&quot; target=&quot;_blank&quot;&gt;Anonymous&lt;/a&gt;&lt;br /&gt;
	Subject: Mailwasher times out&lt;br /&gt;Posted: Sat Jul 05, 2008 1:39 pm (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	Hello
&lt;br /&gt;
When I start Mailwasher it downloads the mail from one of my accounts straight away and the other account is shown as 'Orange emails - logging on'. This tries to log on but after a minute the connection is timed out but if I wait shut down Mailwasher after 5 minutes or so and click 'Check Mail' the Orange emails download.
&lt;br /&gt;
I have changed the POP3 server address to 193.252.22.155 to hopefully make things faster but this has made no effect.
&lt;br /&gt;
Is there a way to make Mailwasher extend the one minute before timing out?
&lt;br /&gt;
Many thanks&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Trend Micro HijackThis Logs :: RE: I'm under attack and I can't find it</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1103665.html#1103665"/>
    <dc:creator>JohnH82</dc:creator>
    <dc:subject>Trend Micro HijackThis Logs</dc:subject>
    <author>
		<name>JohnH82</name>
    </author>
    <id>http://www.castlecops.com/postp1103665.html#1103665</id>
    <issued>2008-07-05T13:33:58Z</issued>
    <modified>2008-07-05T13:33:58Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=191969&quot; target=&quot;_blank&quot;&gt;JohnH82&lt;/a&gt;&lt;br /&gt;
	Posted: Sat Jul 05, 2008 1:33 pm (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	sorry about that below is the log file.
&lt;br /&gt;

&lt;br /&gt;
Logfile of Trend Micro HijackThis v2.0.2
&lt;br /&gt;
Scan saved at 3:30:41 PM, on 7/4/2008
&lt;br /&gt;
Platform: Windows XP SP2 (WinNT 5.01.2600)
&lt;br /&gt;
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
&lt;br /&gt;
Boot mode: Normal
&lt;br /&gt;

&lt;br /&gt;
Running processes:
&lt;br /&gt;
C:\WINDOWS\System32\smss.exe
&lt;br /&gt;
C:\WINDOWS\system32\winlogon.exe
&lt;br /&gt;
C:\WINDOWS\system32\services.exe
&lt;br /&gt;
C:\WINDOWS\system32\lsass.exe
&lt;br /&gt;
C:\WINDOWS\system32\Ati2evxx.exe
&lt;br /&gt;
C:\WINDOWS\system32\svchost.exe
&lt;br /&gt;
C:\Program Files\Windows Defender\MsMpEng.exe
&lt;br /&gt;
C:\WINDOWS\System32\svchost.exe
&lt;br /&gt;
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
&lt;br /&gt;
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
&lt;br /&gt;
C:\WINDOWS\system32\Ati2evxx.exe
&lt;br /&gt;
C:\WINDOWS\Explorer.EXE
&lt;br /&gt;
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
&lt;br /&gt;
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
&lt;br /&gt;
C:\Program Files\Dell\QuickSet\quickset.exe
&lt;br /&gt;
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
&lt;br /&gt;
C:\WINDOWS\system32\Rundll32.exe
&lt;br /&gt;
C:\Program Files\Creative\VoiceCenter\AndreaVC.exe
&lt;br /&gt;
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
&lt;br /&gt;
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
&lt;br /&gt;
C:\DOCUME~1\JOHN~1.JHA\LOCALS~1\Temp\clclean.0001
&lt;br /&gt;
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
&lt;br /&gt;
C:\Program Files\dvd43\dvd43_tray.exe
&lt;br /&gt;
C:\Program Files\Windows Defender\MSASCui.exe
&lt;br /&gt;
C:\WINDOWS\system32\spoolsv.exe
&lt;br /&gt;
C:\WINDOWS\stsystra.exe
&lt;br /&gt;
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
&lt;br /&gt;
C:\Program Files\QuickTime\QTTask.exe
&lt;br /&gt;
C:\Program Files\iTunes\iTunesHelper.exe
&lt;br /&gt;
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
&lt;br /&gt;
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
&lt;br /&gt;
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
&lt;br /&gt;
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
&lt;br /&gt;
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
&lt;br /&gt;
C:\WINDOWS\system32\ctfmon.exe
&lt;br /&gt;
C:\Program Files\DellSupport\DSAgnt.exe
&lt;br /&gt;
C:\Program Files\Messenger\MSMSGS.EXE
&lt;br /&gt;
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
&lt;br /&gt;
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
&lt;br /&gt;
C:\Program Files\Digital Line Detect\DLG.exe
&lt;br /&gt;
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
&lt;br /&gt;
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
&lt;br /&gt;
C:\WINDOWS\system32\cisvc.exe
&lt;br /&gt;
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
&lt;br /&gt;
C:\WINDOWS\system32\CTsvcCDA.exe
&lt;br /&gt;
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
&lt;br /&gt;
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
&lt;br /&gt;
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
&lt;br /&gt;
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
&lt;br /&gt;
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
&lt;br /&gt;
C:\WINDOWS\system32\svchost.exe
&lt;br /&gt;
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
&lt;br /&gt;
C:\WINDOWS\system32\dlcccoms.exe
&lt;br /&gt;
C:\Program Files\iPod\bin\iPodService.exe
&lt;br /&gt;
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
&lt;br /&gt;
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
&lt;br /&gt;
C:\WINDOWS\system32\wscntfy.exe
&lt;br /&gt;
C:\WINDOWS\system32\wuauclt.exe
&lt;br /&gt;
C:\WINDOWS\system32\msiexec.exe
&lt;br /&gt;
C:\WINDOWS\system32\cidaemon.exe
&lt;br /&gt;
C:\WINDOWS\system32\cidaemon.exe
&lt;br /&gt;
C:\Documents and Settings\John.JHAAG-MOBILE1\Desktop\HiJackThis.exe
&lt;br /&gt;
C:\Program Files\Mozilla Firefox\firefox.exe
&lt;br /&gt;

&lt;br /&gt;
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href=&quot;http://go.microsoft.com/fwlink/?LinkId=69157&quot;&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;
&lt;br /&gt;
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href=&quot;http://go.microsoft.com/fwlink/?LinkId=54896&quot;&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;
&lt;br /&gt;
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href=&quot;http://go.microsoft.com/fwlink/?LinkId=54896&quot;&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;
&lt;br /&gt;
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about&amp;#058;blank
&lt;br /&gt;
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = &lt;a href=&quot;http://www.google.com/ig/dell?hl=en&amp;amp;client=dell-usuk&amp;amp;channel=us&quot;&gt;www.google.com/ig/dell?hl=en&amp;amp;client=dell-usuk&amp;amp;channel=us&lt;/a&gt;
&lt;br /&gt;
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
&lt;br /&gt;
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
&lt;br /&gt;
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
&lt;br /&gt;
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
&lt;br /&gt;
O4 - HKLM\..\Run: [ATICCC] &amp;quot;C:\Program Files\ATI Technologies\ATI.ACE\cli.exe&amp;quot; runtime -Delay
&lt;br /&gt;
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
&lt;br /&gt;
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
&lt;br /&gt;
O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
&lt;br /&gt;
O4 - HKLM\..\Run: [VoiceCenter] &amp;quot;C:\Program Files\Creative\VoiceCenter\AndreaVC.exe&amp;quot; /tray
&lt;br /&gt;
O4 - HKLM\..\Run: [DVDLauncher] &amp;quot;C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe&amp;quot;
&lt;br /&gt;
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
&lt;br /&gt;
O4 - HKLM\..\Run: [ISUSScheduler] &amp;quot;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&amp;quot; -start
&lt;br /&gt;
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
&lt;br /&gt;
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
&lt;br /&gt;
O4 - HKLM\..\Run: [Windows Defender] &amp;quot;C:\Program Files\Windows Defender\MSASCui.exe&amp;quot; -hide
&lt;br /&gt;
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
&lt;br /&gt;
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
&lt;br /&gt;
O4 - HKLM\..\Run: [dlccmon.exe] &amp;quot;C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe&amp;quot;
&lt;br /&gt;
O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\QTTask.exe&amp;quot; -atboottime
&lt;br /&gt;
O4 - HKLM\..\Run: [iTunesHelper] &amp;quot;C:\Program Files\iTunes\iTunesHelper.exe&amp;quot;
&lt;br /&gt;
O4 - HKLM\..\Run: [TkBellExe] &amp;quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&amp;quot;  -osboot
&lt;br /&gt;
O4 - HKLM\..\Run: [dscactivate] &amp;quot;C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe&amp;quot;
&lt;br /&gt;
O4 - HKLM\..\Run: [IntelZeroConfig] &amp;quot;C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe&amp;quot;
&lt;br /&gt;
O4 - HKLM\..\Run: [IntelWireless] &amp;quot;C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe&amp;quot; /tf Intel PROSet/Wireless
&lt;br /&gt;
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
&lt;br /&gt;
O4 - HKLM\..\Run: [DellSupportCenter] &amp;quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&amp;quot; /P DellSupportCenter
&lt;br /&gt;
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
&lt;br /&gt;
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
&lt;br /&gt;
O4 - HKCU\..\Run: [DellSupport] &amp;quot;C:\Program Files\DellSupport\DSAgnt.exe&amp;quot; /startup
&lt;br /&gt;
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
&lt;br /&gt;
O4 - HKCU\..\Run: [DellSupportCenter] &amp;quot;C:\Program Files\Dell Support Center\bin\sprtcmd.exe&amp;quot; /P DellSupportCenter
&lt;br /&gt;
O4 - HKCU\..\Run: [MsnMsgr] &amp;quot;C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe&amp;quot; /background
&lt;br /&gt;
O4 - HKCU\..\Run: [MSMSGS] &amp;quot;C:\Program Files\Messenger\MSMSGS.EXE&amp;quot; /background
&lt;br /&gt;
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
&lt;br /&gt;
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
&lt;br /&gt;
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] &amp;quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&amp;quot; -t (User 'SYSTEM')
&lt;br /&gt;
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] &amp;quot;C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe&amp;quot; -t (User 'Default user')
&lt;br /&gt;
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
&lt;br /&gt;
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
&lt;br /&gt;
O4 - Global Startup: Digital Line Detect.lnk = ?
&lt;br /&gt;
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\FRONTPAGE\Office10\OSA.EXE
&lt;br /&gt;
O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - &lt;a href=&quot;res://F:&quot;&gt;res://F:&lt;/a&gt;\OFFICE~1\Office10\EXCEL.EXE/3000
&lt;br /&gt;
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
&lt;br /&gt;
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
&lt;br /&gt;
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
&lt;br /&gt;
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
&lt;br /&gt;
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
&lt;br /&gt;
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
&lt;br /&gt;
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
&lt;br /&gt;
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
&lt;br /&gt;
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
&lt;br /&gt;
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &lt;a href=&quot;http://go.microsoft.com/fwlink/?LinkID=39204&quot;&gt;http://go.microsoft.com/fwlink/?LinkID=39204&lt;/a&gt;
&lt;br /&gt;
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - &lt;a href=&quot;http://asp.mathxl.com/wizmodules/testgen/installers/TestGenXInstall.cab&quot;&gt;http://asp.mathxl.com/wizmodules/testgen/installers/TestGenXInstall.cab&lt;/a&gt;
&lt;br /&gt;
O16 - DPF: {4FE89055-5300-469E-AFAD-DEB3181EDE76} (PearsonAsstX Control) - &lt;a href=&quot;http://asp.mathxl.com/applets/PearsonInstallAsst.cab&quot;&gt;http://asp.mathxl.com/applets/PearsonInstallAsst.cab&lt;/a&gt;
&lt;br /&gt;
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &lt;a href=&quot;http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1174257604703&quot;&gt;http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1174257604703&lt;/a&gt;
&lt;br /&gt;
O16 - DPF: {CE8267C2-D41A-4A50-A69D-F32B5C289F14} (FileOpenInstaller) - &lt;a href=&quot;http://plugin.fileopen.com/current/FileOpen.CAB&quot;&gt;http://plugin.fileopen.com/current/FileOpen.CAB&lt;/a&gt;
&lt;br /&gt;
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &lt;a href=&quot;http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab&quot;&gt;http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab&lt;/a&gt;
&lt;br /&gt;
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - &lt;a href=&quot;http://asp.mathxl.com/books/_Players/MathPlayer.cab&quot;&gt;http://asp.mathxl.com/books/_Players/MathPlayer.cab&lt;/a&gt;
&lt;br /&gt;
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
&lt;br /&gt;
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
&lt;br /&gt;
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
&lt;br /&gt;
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
&lt;br /&gt;
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
&lt;br /&gt;
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
&lt;br /&gt;
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
&lt;br /&gt;
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
&lt;br /&gt;
O23 - Service: dlcc_device -   - C:\WINDOWS\system32\dlcccoms.exe
&lt;br /&gt;
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
&lt;br /&gt;
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
&lt;br /&gt;
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
&lt;br /&gt;
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
&lt;br /&gt;
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
&lt;br /&gt;
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
&lt;br /&gt;
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
&lt;br /&gt;
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
&lt;br /&gt;
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
&lt;br /&gt;

&lt;br /&gt;
--
&lt;br /&gt;
End of file - 11707 bytes&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Trend Micro HijackThis Logs :: RE: Computer always sending data over the internet</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1103664.html#1103664"/>
    <dc:creator>ndmmxiaomayi</dc:creator>
    <dc:subject>Trend Micro HijackThis Logs</dc:subject>
    <author>
		<name>ndmmxiaomayi</name>
    </author>
    <id>http://www.castlecops.com/postp1103664.html#1103664</id>
    <issued>2008-07-05T13:33:26Z</issued>
    <modified>2008-07-05T13:33:26Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=166084&quot; target=&quot;_blank&quot;&gt;ndmmxiaomayi&lt;/a&gt;&lt;br /&gt;
	Posted: Sat Jul 05, 2008 1:33 pm (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	Hi,
&lt;br /&gt;

&lt;br /&gt;
Marsu-Fix extends the number of days you could use NOD32 Antivirus trial. By default, the trial is 30 days. Marsu-Fix extends that by quite long.
&lt;br /&gt;

&lt;br /&gt;
Yes, please remove &lt;span style=&quot;font-weight: bold&quot;&gt;Marsu-Fix&lt;/span&gt; by clicking on &lt;span style=&quot;font-weight: bold&quot;&gt;Start&lt;/span&gt; &amp;gt; &lt;span style=&quot;font-weight: bold&quot;&gt;Control Panel&lt;/span&gt; and double clicking &lt;span style=&quot;font-weight: bold&quot;&gt;Add/Remove Programs&lt;/span&gt;. Removing Marsu-Fix may stop NOD32 from working properly. If that happens, you will need to remove &lt;span style=&quot;font-weight: bold&quot;&gt;ESET NOD32 Antivirus&lt;/span&gt; and install a free replacement.
&lt;br /&gt;

&lt;br /&gt;
Here are 2 free ones:
&lt;br /&gt;

&lt;br /&gt;
&lt;a href=&quot;http://files.avast.com/iavs4pro/setupeng.exe&quot; rel=&quot;nofollow&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;&lt;span style=&quot;color: blue&quot;&gt;avast! 4 Home Edition&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.antivir-pe.com/freet/index.php?id=25&amp;amp;domain=free-av.com&quot; rel=&quot;nofollow&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;&lt;span style=&quot;color: blue&quot;&gt;AntiVir Free Edition&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;
&lt;br /&gt;

&lt;br /&gt;
In addition, please uninstall &lt;span style=&quot;font-weight: bold&quot;&gt;BitLord 1.1&lt;/span&gt;.
&lt;br /&gt;

&lt;br /&gt;
According to &lt;a href=&quot;http://www.castlecops.com/t204179-P2P_programs_we_ask_that_you_remove_first.html&quot;  target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;Castlecops' P2P Programs Policy&lt;/a&gt;, all P2P programs needs to be removed before we can continue helping.
&lt;br /&gt;

&lt;br /&gt;
&lt;hr /&gt;
&lt;br /&gt;

&lt;br /&gt;
After you've completed the above steps, please run Deckard's System Scanner again and post back the log.&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Anti-Virus Updates :: RE: Panda Antivirus Updates</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1103663.html#1103663"/>
    <dc:creator>roddy32</dc:creator>
    <dc:subject>Anti-Virus Updates</dc:subject>
    <author>
		<name>roddy32</name>
    </author>
    <id>http://www.castlecops.com/postp1103663.html#1103663</id>
    <issued>2008-07-05T13:22:40Z</issued>
    <modified>2008-07-05T13:22:40Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=114811&quot; target=&quot;_blank&quot;&gt;roddy32&lt;/a&gt;&lt;br /&gt;
	Posted: Sat Jul 05, 2008 1:22 pm (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	Virus Signature File
&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Saturday, 5 July 2008&lt;/span&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.pandasecurity.com/homeusers/downloads/clients/?&quot;&gt;http://www.pandasecurity.com/homeusers/downloads/clients/?&lt;/a&gt;&lt;br /&gt;_________________&lt;br /&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;&lt;span style=&quot;color: blue&quot;&gt;&lt;span style=&quot;font-size: 9px; line-height: normal&quot;&gt;Microsoft MVP - Windows Security&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Catch All - Guests :: RE: We need to monitor the kids activity online...</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1103661.html#1103661"/>
    <dc:creator>lordpake</dc:creator>
    <dc:subject>Catch All - Guests</dc:subject>
    <author>
		<name>lordpake</name>
    </author>
    <id>http://www.castlecops.com/postp1103661.html#1103661</id>
    <issued>2008-07-05T13:18:48Z</issued>
    <modified>2008-07-05T13:18:48Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=145956&quot; target=&quot;_blank&quot;&gt;lordpake&lt;/a&gt;&lt;br /&gt;
	Posted: Sat Jul 05, 2008 1:18 pm (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	@hackbridge: parental control software may have features and components that are similar to those found in rootkits and keyloggers. This is because they by their nature must be hidden from the user, and they must be aware of the things users do in that computer.
&lt;br /&gt;

&lt;br /&gt;
They may very well be recording a log of every keystroke so that parents for example can see where, with whom and what kind of language their children use.
&lt;br /&gt;

&lt;br /&gt;
Certain security software may indeed warn about parental control software. This can be for example because they want the user to be aware of such application is installed.&lt;br /&gt;_________________&lt;br /&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Kitten:&lt;/span&gt; small homicidal muffin on legs: affects human sensibilities to the point of endowing the most wanton and ruthless acts of destruction with near mythical overtones of cuteness. Not recommended for beginners, get at least two. [Fafnir]&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Trend Micro HijackThis Logs :: RE: My HJT Log - Dr. Watson problems</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1103656.html#1103656"/>
    <dc:creator>Preceptor</dc:creator>
    <dc:subject>Trend Micro HijackThis Logs</dc:subject>
    <author>
		<name>Preceptor</name>
    </author>
    <id>http://www.castlecops.com/postp1103656.html#1103656</id>
    <issued>2008-07-05T12:55:38Z</issued>
    <modified>2008-07-05T12:55:38Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=135093&quot; target=&quot;_blank&quot;&gt;Preceptor&lt;/a&gt;&lt;br /&gt;
	Posted: Sat Jul 05, 2008 12:55 pm (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	Mine is set to notify me too.
&lt;br /&gt;

&lt;br /&gt;
i think all impt updates are downloaded and installed.
&lt;br /&gt;

&lt;br /&gt;
No more prompts ...&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Trend Micro HijackThis Logs :: RE: AVG Trojan horse downloader.Del.12.AN</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1103651.html#1103651"/>
    <dc:creator>kevbert</dc:creator>
    <dc:subject>Trend Micro HijackThis Logs</dc:subject>
    <author>
		<name>kevbert</name>
    </author>
    <id>http://www.castlecops.com/postp1103651.html#1103651</id>
    <issued>2008-07-05T12:48:21Z</issued>
    <modified>2008-07-05T12:48:21Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=191404&quot; target=&quot;_blank&quot;&gt;kevbert&lt;/a&gt;&lt;br /&gt;
	Posted: Sat Jul 05, 2008 12:48 pm (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	Hi,
&lt;br /&gt;

&lt;br /&gt;
I did not get the PendingFileRenameOperations prompt come up I did everything els heres my new HJT Log:
&lt;br /&gt;

&lt;br /&gt;
Logfile of Trend Micro HijackThis v2.0.2
&lt;br /&gt;
Scan saved at 13:46:50, on 05/07/2008
&lt;br /&gt;
Platform: Windows XP SP2 (WinNT 5.01.2600)
&lt;br /&gt;
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
&lt;br /&gt;
Boot mode: Normal
&lt;br /&gt;

&lt;br /&gt;
Running processes:
&lt;br /&gt;
C:\WINDOWS\System32\smss.exe
&lt;br /&gt;
C:\WINDOWS\system32\winlogon.exe
&lt;br /&gt;
C:\WINDOWS\system32\services.exe
&lt;br /&gt;
C:\WINDOWS\system32\lsass.exe
&lt;br /&gt;
C:\WINDOWS\system32\svchost.exe
&lt;br /&gt;
C:\WINDOWS\System32\svchost.exe
&lt;br /&gt;
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
&lt;br /&gt;
C:\WINDOWS\Explorer.EXE
&lt;br /&gt;
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
&lt;br /&gt;
C:\WINDOWS\system32\LEXBCES.EXE
&lt;br /&gt;
C:\WINDOWS\system32\spoolsv.exe
&lt;br /&gt;
C:\WINDOWS\system32\LEXPPS.EXE
&lt;br /&gt;
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
&lt;br /&gt;
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
&lt;br /&gt;
C:\WINDOWS\system32\svchost.exe
&lt;br /&gt;
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
&lt;br /&gt;
C:\PROGRA~1\AVG\AVG8\avgemc.exe
&lt;br /&gt;
C:\WINDOWS\system32\hkcmd.exe
&lt;br /&gt;
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
&lt;br /&gt;
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
&lt;br /&gt;
C:\Program Files\iTunes\iTunesHelper.exe
&lt;br /&gt;
C:\WINDOWS\System32\svchost.exe
&lt;br /&gt;
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
&lt;br /&gt;
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
&lt;br /&gt;
C:\PROGRA~1\AVG\AVG8\avgtray.exe
&lt;br /&gt;
C:\Program Files\SPYWAREfighter\spftray.exe
&lt;br /&gt;
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
&lt;br /&gt;
C:\WINDOWS\system32\ctfmon.exe
&lt;br /&gt;
C:\Program Files\SPYWAREfighter\spfprc.exe
&lt;br /&gt;
C:\WINDOWS\system32\wuauclt.exe
&lt;br /&gt;
C:\Program Files\iPod\bin\iPodService.exe
&lt;br /&gt;
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
&lt;br /&gt;

&lt;br /&gt;
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href=&quot;http://www.virginmedia.com/&quot;&gt;http://www.virginmedia.com/&lt;/a&gt;
&lt;br /&gt;
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href=&quot;http://go.microsoft.com/fwlink/?LinkId=69157&quot;&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;
&lt;br /&gt;
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href=&quot;http://go.microsoft.com/fwlink/?LinkId=54896&quot;&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;
&lt;br /&gt;
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &lt;a href=&quot;http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/&quot;&gt;http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/&lt;/a&gt;*http://www.yahoo.com/ext/search/search.html
&lt;br /&gt;
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href=&quot;http://go.microsoft.com/fwlink/?LinkId=54896&quot;&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;
&lt;br /&gt;
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href=&quot;http://www.yahoo.com&quot;&gt;http://www.yahoo.com&lt;/a&gt;
&lt;br /&gt;
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = &lt;a href=&quot;http://www.google.co.uk/ig/dell?hl=en&amp;amp;client=dell-usuk&amp;amp;channel=uk&amp;amp;ibd=2061021&quot;&gt;www.google.co.uk/ig/dell?hl=en&amp;amp;client=dell-usuk&amp;amp;channel=uk&amp;amp;ibd=2061021&lt;/a&gt;
&lt;br /&gt;
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = &lt;a href=&quot;http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/&quot;&gt;http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/&lt;/a&gt;*http://www.yahoo.com
&lt;br /&gt;
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
&lt;br /&gt;
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
&lt;br /&gt;
O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
&lt;br /&gt;
O2 - BHO: Spybot-S&amp;amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search &amp;amp; Destroy\SDHelper.dll
&lt;br /&gt;
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
&lt;br /&gt;
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
&lt;br /&gt;
O2 - BHO: (no name) - {D5FFC145-6839-44BE-8C43-CD1DFA24F5E1} - C:\WINDOWS\system32\eventclsv.dll (file missing)
&lt;br /&gt;
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
&lt;br /&gt;
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
&lt;br /&gt;
O4 - HKLM\..\Run: [ISUSPM Startup] &amp;quot;C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe&amp;quot; -startup
&lt;br /&gt;
O4 - HKLM\..\Run: [ISUSScheduler] &amp;quot;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&amp;quot; -start
&lt;br /&gt;
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
&lt;br /&gt;
O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\qttask.exe&amp;quot; -atboottime
&lt;br /&gt;
O4 - HKLM\..\Run: [iTunesHelper] &amp;quot;C:\Program Files\iTunes\iTunesHelper.exe&amp;quot;
&lt;br /&gt;
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &amp;quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&amp;quot;
&lt;br /&gt;
O4 - HKLM\..\Run: [SunJavaUpdateSched] &amp;quot;C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe&amp;quot;
&lt;br /&gt;
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
&lt;br /&gt;
O4 - HKLM\..\Run: [spywarefighterguard] C:\Program Files\SPYWAREfighter\spftray.exe
&lt;br /&gt;
O4 - HKLM\..\Run: [ZoneAlarm Client] &amp;quot;C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe&amp;quot;
&lt;br /&gt;
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
&lt;br /&gt;
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
&lt;br /&gt;
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
&lt;br /&gt;
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
&lt;br /&gt;
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search &amp;amp; Destroy\SDHelper.dll
&lt;br /&gt;
O9 - Extra 'Tools' menuitem: Spybot - Search &amp;amp;&amp;amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search &amp;amp; Destroy\SDHelper.dll
&lt;br /&gt;
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
&lt;br /&gt;
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
&lt;br /&gt;
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
&lt;br /&gt;
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
&lt;br /&gt;
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - &lt;a href=&quot;http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab&quot;&gt;http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab&lt;/a&gt;
&lt;br /&gt;
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
&lt;br /&gt;
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - &lt;a href=&quot;http://sell-vehicle.ebay.co.uk/images/eps/eBay_Enhanced_Picture_Control_v1-0-3-50.cab&quot;&gt;http://sell-vehicle.ebay.co.uk/images/eps/eBay_Enhanced_Picture_Control_v1-0-3-50.cab&lt;/a&gt;
&lt;br /&gt;
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - &lt;a href=&quot;http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab&quot;&gt;http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab&lt;/a&gt;
&lt;br /&gt;
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - &lt;a href=&quot;http://www.adobe.com/products/acrobat/nos/gp.cab&quot;&gt;http://www.adobe.com/products/acrobat/nos/gp.cab&lt;/a&gt;
&lt;br /&gt;
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - &lt;a href=&quot;https://flashpoker.ladbrokes.com/ladbrokes/FlashAX.cab&quot;&gt;https://flashpoker.ladbrokes.com/ladbrokes/FlashAX.cab&lt;/a&gt;
&lt;br /&gt;
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
&lt;br /&gt;
O20 - AppInit_DLLs: avgrsstx.dll
&lt;br /&gt;
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
&lt;br /&gt;
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
&lt;br /&gt;
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
&lt;br /&gt;
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
&lt;br /&gt;
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
&lt;br /&gt;
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
&lt;br /&gt;
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
&lt;br /&gt;
O23 - Service: SDService - Unknown owner - C:\Program Files\SpywareDetector\SDService.exe (file missing)
&lt;br /&gt;
O23 - Service: SPYWAREfighterRP - SpamFighter APS - C:\Program Files\SPYWAREfighter\spfprc.exe
&lt;br /&gt;
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
&lt;br /&gt;

&lt;br /&gt;
--
&lt;br /&gt;
End of file - 7620 bytes
&lt;br /&gt;

&lt;br /&gt;

&lt;br /&gt;
Thanks Kev&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Malware Listserv :: MD5...: 16f30d40b67a941403e58d84db09cc7e setup.exe</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1103650.html#1103650"/>
    <dc:creator>DarthTrader</dc:creator>
    <dc:subject>Malware Listserv</dc:subject>
    <author>
		<name>DarthTrader</name>
    </author>
    <id>http://www.castlecops.com/postp1103650.html#1103650</id>
    <issued>2008-07-05T12:44:28Z</issued>
    <modified>2008-07-05T12:44:28Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=158663&quot; target=&quot;_blank&quot;&gt;DarthTrader&lt;/a&gt;&lt;br /&gt;
	Subject: MD5...: 16f30d40b67a941403e58d84db09cc7e setup.exe&lt;br /&gt;Posted: Sat Jul 05, 2008 12:44 pm (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	File setup.exe received on 07.05.2008 14:25:27 (CET)
&lt;br /&gt;

&lt;br /&gt;
AhnLab-V3 2008.7.4.1 2008.07.05 - 
&lt;br /&gt;
AntiVir 7.8.0.64 2008.07.04 - 
&lt;br /&gt;
Authentium 5.1.0.4 2008.07.04 - 
&lt;br /&gt;
Avast 4.8.1195.0 2008.07.04 Win32:Zlob-CGE 
&lt;br /&gt;
AVG 7.5.0.516 2008.07.05 - 
&lt;br /&gt;
BitDefender 7.2 2008.07.05 - 
&lt;br /&gt;
CAT-QuickHeal 9.50 2008.07.04 - 
&lt;br /&gt;
ClamAV 0.93.1 2008.07.04 - 
&lt;br /&gt;
DrWeb 4.44.0.09170 2008.07.05 - 
&lt;br /&gt;
eSafe 7.0.17.0 2008.07.03 - 
&lt;br /&gt;
eTrust-Vet 31.6.5929 2008.07.05 - 
&lt;br /&gt;
Ewido 4.0 2008.07.05 - 
&lt;br /&gt;
F-Prot 4.4.4.56 2008.07.04 - 
&lt;br /&gt;
F-Secure 7.60.13501.0 2008.07.03 - 
&lt;br /&gt;
Fortinet 3.14.0.0 2008.07.05 - 
&lt;br /&gt;
GData 2.0.7306.1023 2008.07.05 Win32:Zlob-CGE 
&lt;br /&gt;
Ikarus T3.1.1.26.0 2008.07.05 - 
&lt;br /&gt;
Kaspersky 7.0.0.125 2008.07.05 - 
&lt;br /&gt;
McAfee 5332 2008.07.04 - 
&lt;br /&gt;
Microsoft 1.3704 2008.07.05 TrojanDownloader:Win32/Zlob.gen!AW 
&lt;br /&gt;
NOD32v2 3244 2008.07.05 - 
&lt;br /&gt;
Norman 5.80.02 2008.07.04 - 
&lt;br /&gt;
Panda 9.0.0.4 2008.07.05 - 
&lt;br /&gt;
Prevx1 V2 2008.07.05 - 
&lt;br /&gt;
Rising 20.51.42.00 2008.07.04 - 
&lt;br /&gt;
Sophos 4.31.0 2008.07.05 - 
&lt;br /&gt;
Sunbelt 3.1.1509.1 2008.07.04 - 
&lt;br /&gt;
Symantec 10 2008.07.05 - 
&lt;br /&gt;
TheHacker 6.2.96.371 2008.07.04 - 
&lt;br /&gt;
TrendMicro 8.700.0.1004 2008.07.05 - 
&lt;br /&gt;
VBA32 3.12.6.8 2008.07.04 - 
&lt;br /&gt;
VirusBuster 4.5.11.0 2008.07.04 - 
&lt;br /&gt;
Webwasher-Gateway 6.6.2 2008.07.05 - 
&lt;br /&gt;
 
&lt;br /&gt;
Additional information 
&lt;br /&gt;
File size: 20480 bytes 
&lt;br /&gt;
MD5...: 16f30d40b67a941403e58d84db09cc7e 
&lt;br /&gt;
SHA1..: 2ed45a26674fe83d641073ff9c9bd31c55aa8cb2&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Trend Micro HijackThis Logs :: RE: Computer always sending data over the internet</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1103649.html#1103649"/>
    <dc:creator>Skurken</dc:creator>
    <dc:subject>Trend Micro HijackThis Logs</dc:subject>
    <author>
		<name>Skurken</name>
    </author>
    <id>http://www.castlecops.com/postp1103649.html#1103649</id>
    <issued>2008-07-05T12:40:13Z</issued>
    <modified>2008-07-05T12:40:13Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=191188&quot; target=&quot;_blank&quot;&gt;Skurken&lt;/a&gt;&lt;br /&gt;
	Posted: Sat Jul 05, 2008 12:40 pm (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	No, what does it do? When I googled it the results showed it was some kind of malware. We are several people using this computer and a friend of my son has done most of the installing. Should I remove it?&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Trend Micro HijackThis Logs :: RE: Help please</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1103648.html#1103648"/>
    <dc:creator>taz71498</dc:creator>
    <dc:subject>Trend Micro HijackThis Logs</dc:subject>
    <author>
		<name>taz71498</name>
    </author>
    <id>http://www.castlecops.com/postp1103648.html#1103648</id>
    <issued>2008-07-05T12:37:17Z</issued>
    <modified>2008-07-05T12:37:17Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=23536&quot; target=&quot;_blank&quot;&gt;taz71498&lt;/a&gt;&lt;br /&gt;
	Posted: Sat Jul 05, 2008 12:37 pm (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	Go back to that page and you will see a paragraph that starts with this:
&lt;br /&gt;

&lt;br /&gt;
[quote]If you use Windows XP and do not have the Windows CD[quote]
&lt;br /&gt;

&lt;br /&gt;
Follow those directions.  It is a matter of downloading a file from microsoft.&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Trend Micro HijackThis Logs :: RE: My HJT Log - Dr. Watson problems</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1103647.html#1103647"/>
    <dc:creator>taz71498</dc:creator>
    <dc:subject>Trend Micro HijackThis Logs</dc:subject>
    <author>
		<name>taz71498</name>
    </author>
    <id>http://www.castlecops.com/postp1103647.html#1103647</id>
    <issued>2008-07-05T12:33:05Z</issued>
    <modified>2008-07-05T12:33:05Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=23536&quot; target=&quot;_blank&quot;&gt;taz71498&lt;/a&gt;&lt;br /&gt;
	Posted: Sat Jul 05, 2008 12:33 pm (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	For updates, usually one has automatic updates already set and the updates happen in the background.  Some people have it set to notify you when there are updates and then some have it to not update and one will do it when they want it done.
&lt;br /&gt;

&lt;br /&gt;
I have mine set to notify me.  I prefer that.  That way I can see what updates are being installed and also have them run when I want them to run.  
&lt;br /&gt;

&lt;br /&gt;
I am not sure how you have yours set, maybe you can tell me.  I would say setting it to notify you of updates would be good.  Either that or the automatic updates is fine.
&lt;br /&gt;

&lt;br /&gt;
Yes, there are some snags with the SP3.  You can hold off.  No harm with that right now.&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Trend Micro HijackThis Logs :: RE: help needed..HJT log attached</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1103646.html#1103646"/>
    <dc:creator>Bob-4</dc:creator>
    <dc:subject>Trend Micro HijackThis Logs</dc:subject>
    <author>
		<name>Bob-4</name>
    </author>
    <id>http://www.castlecops.com/postp1103646.html#1103646</id>
    <issued>2008-07-05T12:17:48Z</issued>
    <modified>2008-07-05T12:17:48Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=150879&quot; target=&quot;_blank&quot;&gt;Bob-4&lt;/a&gt;&lt;br /&gt;
	Posted: Sat Jul 05, 2008 12:17 pm (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	______________________________
&lt;br /&gt;
RUN HJT
&lt;br /&gt;

&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;&lt;span style=&quot;color: blue&quot;&gt;HJT&lt;/span&gt;&lt;/span&gt;
&lt;br /&gt;
Run hijackthis  and choose scan only and place a check by the following lines &lt;span style=&quot;font-weight: bold&quot;&gt;if present&lt;/span&gt;.
&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Close all other windows and browsers except HJT before clicking on Fix Checked&lt;/span&gt;
&lt;br /&gt;

&lt;br /&gt;
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
&lt;br /&gt;

&lt;br /&gt;

&lt;br /&gt;
Close that.
&lt;br /&gt;

&lt;br /&gt;

&lt;br /&gt;
Things look good from here. 
&lt;br /&gt;
How does it seem to be running?&lt;br /&gt;_________________&lt;br /&gt;Want to learn how to help others with HiJackThis logs?
&lt;br /&gt;
 contact &lt;a href=&quot;http://castlecops.com/modules.php?name=Private_Messages&amp;amp;file=index&amp;amp;mode=post&amp;amp;u=70168&quot;  target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Bugbatter&lt;/span&gt;&lt;/a&gt; about the possibility of becoming a 1st Responder&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
</feed>
<!-- Page generation time: 0.1904s  - GZIP disabled -->