<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Is Your System Infected with a Virus / Spyware / Adware / Trojan? &#8211; Part I</title>
	<atom:link href="http://www.askvg.com/is-your-system-infected-with-a-virus-spyware-adware-trojan/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.askvg.com/is-your-system-infected-with-a-virus-spyware-adware-trojan/</link>
	<description>Technology News, Internet, Tips-n-Tricks, Tutorials, Software Reviews, Themes, Skins, Wallpapers</description>
	<lastBuildDate>Sun, 08 Nov 2009 06:37:59 +0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: VG</title>
		<link>http://www.askvg.com/is-your-system-infected-with-a-virus-spyware-adware-trojan/comment-page-103/#comment-11220</link>
		<dc:creator>VG</dc:creator>
		<pubDate>Mon, 06 Oct 2008 12:04:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.askvg.com/is-your-system-infected-with-a-virusspywareadwaretrojan/#comment-11220</guid>
		<description>I&#039;m closing this topic because it has crossed 1000 comments and now many people are facing problem while posting their HijackThis log file.

But no need to worry, I have created a new topic for the same thing:

http://www.askvg.com/is-your-system-infected-with-a-virus-spyware-adware-trojan-2/

So now you can post your HijackThis log file in the above mentioned topic.

&lt;em&gt;Topic Closed...&lt;/em&gt;</description>
		<content:encoded><![CDATA[<p>I'm closing this topic because it has crossed 1000 comments and now many people are facing problem while posting their HijackThis log file.</p>
<p>But no need to worry, I have created a new topic for the same thing:</p>
<p><a href="http://www.askvg.com/is-your-system-infected-with-a-virus-spyware-adware-trojan-2/" rel="nofollow">http://www.askvg.com/is-your-system-infected-with-a-virus-spyware-adware-trojan-2/</a></p>
<p>So now you can post your HijackThis log file in the above mentioned topic.</p>
<p><em>Topic Closed...</em></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: VG</title>
		<link>http://www.askvg.com/is-your-system-infected-with-a-virus-spyware-adware-trojan/comment-page-103/#comment-11210</link>
		<dc:creator>VG</dc:creator>
		<pubDate>Mon, 06 Oct 2008 08:46:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.askvg.com/is-your-system-infected-with-a-virusspywareadwaretrojan/#comment-11210</guid>
		<description>^^ We&#039;ll need to remove the virus otherwise all the mentioned problems will continue to happen. You can run HijackThis in your system and then save the log file in a Pen drive and carry it to your office, then you can post the content here from your office.

@Harpal Singh
Your log file is clean.

@Sandip Mane
Your log file is also clean.

@jade
Your system is infected. Fix following in safe mode:

&lt;blockquote&gt;
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.redtube.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.redtube.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = SoWar Browser
O4 - HKLM\..\Run: [SW20] C:\WINDOWS\system32\sw20.exe
O4 - HKLM\..\Run: [SW24] C:\WINDOWS\system32\sw24.exe
O4 - HKLM\..\Run: [WinSys2] C:\WINDOWS\system32\winsys2.exe
O4 - HKLM\..\Run: [RawOs] wscript.exe “C:\WINDOWS\sowar.vbs”
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
&lt;/blockquote&gt;

@Andrew Cheong
Your log file is clean.</description>
		<content:encoded><![CDATA[<p>^^ We'll need to remove the virus otherwise all the mentioned problems will continue to happen. You can run HijackThis in your system and then save the log file in a Pen drive and carry it to your office, then you can post the content here from your office.</p>
<p>@Harpal Singh<br />
Your log file is clean.</p>
<p>@Sandip Mane<br />
Your log file is also clean.</p>
<p>@jade<br />
Your system is infected. Fix following in safe mode:</p>
<blockquote><p>
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://www.redtube.com/" rel="nofollow">http://www.redtube.com/</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.redtube.com/" rel="nofollow">http://www.redtube.com/</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = SoWar Browser<br />
O4 - HKLM\..\Run: [SW20] C:\WINDOWS\system32\sw20.exe<br />
O4 - HKLM\..\Run: [SW24] C:\WINDOWS\system32\sw24.exe<br />
O4 - HKLM\..\Run: [WinSys2] C:\WINDOWS\system32\winsys2.exe<br />
O4 - HKLM\..\Run: [RawOs] wscript.exe “C:\WINDOWS\sowar.vbs”<br />
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
</p></blockquote>
<p>@Andrew Cheong<br />
Your log file is clean.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Srinivasdevulapally</title>
		<link>http://www.askvg.com/is-your-system-infected-with-a-virus-spyware-adware-trojan/comment-page-103/#comment-11195</link>
		<dc:creator>Srinivasdevulapally</dc:creator>
		<pubDate>Mon, 06 Oct 2008 04:43:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.askvg.com/is-your-system-infected-with-a-virusspywareadwaretrojan/#comment-11195</guid>
		<description>hi vishal,

I&#039;m waiting 4 ur reply.... for my problem posted in page 102...</description>
		<content:encoded><![CDATA[<p>hi vishal,</p>
<p>I'm waiting 4 ur reply.... for my problem posted in page 102...</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: harpal singh</title>
		<link>http://www.askvg.com/is-your-system-infected-with-a-virus-spyware-adware-trojan/comment-page-103/#comment-11194</link>
		<dc:creator>harpal singh</dc:creator>
		<pubDate>Mon, 06 Oct 2008 03:52:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.askvg.com/is-your-system-infected-with-a-virusspywareadwaretrojan/#comment-11194</guid>
		<description>Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:18:32 AM, on 10/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\fx\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\TuneUp Utilities 2008\RegistryCleaner.exe
C:\WINDOWS\System32\TuneUpDefragService.exe
C:\Documents and Settings\fx\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: IDMIEHlprObj Class - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;
O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;  -osboot
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su2/ocx/15106/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{230D47A4-8A4C-4B7D-9F4D-81B385BB6511}: NameServer = 202.56.224.153,202.56.230.6
O17 - HKLM\System\CS1\Services\Tcpip\..\{230D47A4-8A4C-4B7D-9F4D-81B385BB6511}: NameServer = 202.56.224.153,202.56.230.6
O17 - HKLM\System\CS2\Services\Tcpip\..\{230D47A4-8A4C-4B7D-9F4D-81B385BB6511}: NameServer = 202.56.224.153,202.56.230.6
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

--
End of file - 6276 bytes


hi vg , please check out is there any problem ?

please email me , wating for your ans.

thanks
 :smile:  by</description>
		<content:encoded><![CDATA[<p>Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 9:18:32 AM, on 10/6/2008<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br />
Boot mode: Normal</p>
<p>Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
C:\WINDOWS\system32\CTsvcCDA.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe<br />
C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br />
C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
C:\Program Files\Internet Download Manager\IEMonitor.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Documents and Settings\fx\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\TuneUp Utilities 2008\RegistryCleaner.exe<br />
C:\WINDOWS\System32\TuneUpDefragService.exe<br />
C:\Documents and Settings\fx\Local Settings\Application Data\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe</p>
<p>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br />
O2 - BHO: IDMIEHlprObj Class - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll<br />
O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br />
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r<br />
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br />
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br />
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm<br />
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm<br />
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - <a href="http://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab" rel="nofollow">http://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab</a><br />
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - <a href="http://www.creative.com/softwareupdate/su2/ocx/15106/CTPID.cab" rel="nofollow">http://www.creative.com/softwareupdate/su2/ocx/15106/CTPID.cab</a><br />
O17 - HKLM\System\CCS\Services\Tcpip\..\{230D47A4-8A4C-4B7D-9F4D-81B385BB6511}: NameServer = 202.56.224.153,202.56.230.6<br />
O17 - HKLM\System\CS1\Services\Tcpip\..\{230D47A4-8A4C-4B7D-9F4D-81B385BB6511}: NameServer = 202.56.224.153,202.56.230.6<br />
O17 - HKLM\System\CS2\Services\Tcpip\..\{230D47A4-8A4C-4B7D-9F4D-81B385BB6511}: NameServer = 202.56.224.153,202.56.230.6<br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O20 - AppInit_DLLs: avgrsstx.dll<br />
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe<br />
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe<br />
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe<br />
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe<br />
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br />
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe</p>
<p>--<br />
End of file - 6276 bytes</p>
<p>hi vg , please check out is there any problem ?</p>
<p>please email me , wating for your ans.</p>
<p>thanks<br />
 <img src='http://www.askvg.com/wp-includes/images/smilies/icon_smile.gif' alt=':smile:' class='wp-smiley' />   by</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Saking</title>
		<link>http://www.askvg.com/is-your-system-infected-with-a-virus-spyware-adware-trojan/comment-page-103/#comment-11186</link>
		<dc:creator>Saking</dc:creator>
		<pubDate>Sun, 05 Oct 2008 20:23:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.askvg.com/is-your-system-infected-with-a-virusspywareadwaretrojan/#comment-11186</guid>
		<description>Thanks Vg For reply me here i have onemore problem that is my laptop is infected withj Ahsan virus plz hel me out</description>
		<content:encoded><![CDATA[<p>Thanks Vg For reply me here i have onemore problem that is my laptop is infected withj Ahsan virus plz hel me out</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrew Cheong</title>
		<link>http://www.askvg.com/is-your-system-infected-with-a-virus-spyware-adware-trojan/comment-page-102/#comment-11180</link>
		<dc:creator>Andrew Cheong</dc:creator>
		<pubDate>Sun, 05 Oct 2008 16:16:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.askvg.com/is-your-system-infected-with-a-virusspywareadwaretrojan/#comment-11180</guid>
		<description>Hi VG, I have no more patience in me, so I have uploaded my log.

This is my log URL. Download it and see. Thanks in advance.

http://rapidshare.com/files/151174544/hijackthis.log</description>
		<content:encoded><![CDATA[<p>Hi VG, I have no more patience in me, so I have uploaded my log.</p>
<p>This is my log URL. Download it and see. Thanks in advance.</p>
<p><a href="http://rapidshare.com/files/151174544/hijackthis.log" rel="nofollow">http://rapidshare.com/files/151174544/hijackthis.log</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrew Cheong</title>
		<link>http://www.askvg.com/is-your-system-infected-with-a-virus-spyware-adware-trojan/comment-page-102/#comment-11179</link>
		<dc:creator>Andrew Cheong</dc:creator>
		<pubDate>Sun, 05 Oct 2008 16:09:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.askvg.com/is-your-system-infected-with-a-virusspywareadwaretrojan/#comment-11179</guid>
		<description>hi VG, I&#039;ve waited few hours and my log never shows up here?</description>
		<content:encoded><![CDATA[<p>hi VG, I've waited few hours and my log never shows up here?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Srinivas Devulapally</title>
		<link>http://www.askvg.com/is-your-system-infected-with-a-virus-spyware-adware-trojan/comment-page-102/#comment-11169</link>
		<dc:creator>Srinivas Devulapally</dc:creator>
		<pubDate>Sun, 05 Oct 2008 13:45:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.askvg.com/is-your-system-infected-with-a-virusspywareadwaretrojan/#comment-11169</guid>
		<description>Hi Vishal,


I am ur fan. I like ur tutorials and the latest things u put on ur website.

I used to stay in vizag but shifted to Chennai..

The problem is that my system is infected with malware....i.e., msconfig, taskmgr and regedit close automatically in a second when opened.

Another main problem is that i don&#039;t have an internet connection at present  so i cannot use a good antivirus with latest updates to remove the malware ...and so i cannot place a log file here too.... I am writing this from my office... Can u provide me a manual solution to remove this malware....or atleast make the processes work eventhough the malware exists.... Please do mail me the solution....

Thanks in advance...


Srinivas</description>
		<content:encoded><![CDATA[<p>Hi Vishal,</p>
<p>I am ur fan. I like ur tutorials and the latest things u put on ur website.</p>
<p>I used to stay in vizag but shifted to Chennai..</p>
<p>The problem is that my system is infected with malware....i.e., msconfig, taskmgr and regedit close automatically in a second when opened.</p>
<p>Another main problem is that i don't have an internet connection at present  so i cannot use a good antivirus with latest updates to remove the malware ...and so i cannot place a log file here too.... I am writing this from my office... Can u provide me a manual solution to remove this malware....or atleast make the processes work eventhough the malware exists.... Please do mail me the solution....</p>
<p>Thanks in advance...</p>
<p>Srinivas</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sandip Mane</title>
		<link>http://www.askvg.com/is-your-system-infected-with-a-virus-spyware-adware-trojan/comment-page-102/#comment-11167</link>
		<dc:creator>Sandip Mane</dc:creator>
		<pubDate>Sun, 05 Oct 2008 12:14:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.askvg.com/is-your-system-infected-with-a-virusspywareadwaretrojan/#comment-11167</guid>
		<description>Dear VG

Logfile of my PC is given below. Is it infected?


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:39:12, on 05/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
C:\Program Files\Transcend Utility\Transcend StoreJet elite\SJelite.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Sprite Software\Sprite Backup\SpriteService.exe
C:\Documents and Settings\Sandip\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.in/
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.1852\swg.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [Transcend StoreJet elite] C:\Program Files\Transcend Utility\Transcend StoreJet elite\SJelite.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&quot;
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] &quot;C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe&quot; /startoptions
O4 - HKLM\..\Run: [WinampAgent] &quot;C:\Program Files\Winamp\winampa.exe&quot;
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe&quot;
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] &quot;C:\Program Files\Messenger\msmsgs.exe&quot; /background
O4 - HKCU\..\Run: [H/PC Connection Agent] &quot;C:\Program Files\Microsoft ActiveSync\wcescomm.exe&quot;
O4 - HKCU\..\Run: [SpriteService] &quot;C:\Program Files\Sprite Software\Sprite Backup\SpriteService.exe&quot;
O4 - HKCU\..\Run: [Google Update] &quot;C:\Documents and Settings\Sandip\Local Settings\Application Data\Google\Update\GoogleUpdate.exe&quot; /c
O4 - HKCU\..\Run: [Yahoo! Pager] &quot;C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE&quot; -quiet
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User &#039;LOCAL SERVICE&#039;)
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User &#039;NETWORK SERVICE&#039;)
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User &#039;SYSTEM&#039;)
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User &#039;Default user&#039;)
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O8 - Extra context menu item: &amp;Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra &#039;Tools&#039; menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra &#039;Tools&#039; menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra &#039;Tools&#039; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/e/37.09/HboD-mApHAo/uploader2.cab
O16 - DPF: {5BDBA960-6534-11D3-97C7-00500422B550} (LotusDRSControl Class) - https://webmail.relbio.com/download/dolcontrol.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1222936780000
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe

--
End of file - 9323 bytes</description>
		<content:encoded><![CDATA[<p>Dear VG</p>
<p>Logfile of my PC is given below. Is it infected?</p>
<p>Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 17:39:12, on 05/10/2008<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br />
Boot mode: Normal</p>
<p>Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
C:\WINDOWS\system32\drivers\CDAC11BA.EXE<br />
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
C:\WINDOWS\system32\igfxtray.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe<br />
C:\Program Files\Transcend Utility\Transcend StoreJet elite\SJelite.exe<br />
C:\Program Files\Google\Google Talk\googletalk.exe<br />
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe<br />
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe<br />
C:\Program Files\Winamp\winampa.exe<br />
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Messenger\msmsgs.exe<br />
C:\Program Files\Microsoft ActiveSync\wcescomm.exe<br />
C:\Program Files\Sprite Software\Sprite Backup\SpriteService.exe<br />
C:\Documents and Settings\Sandip\Local Settings\Application Data\Google\Update\GoogleUpdate.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\PROGRA~1\MI3AA1~1\rapimgr.exe<br />
C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe<br />
C:\Program Files\WinZip\WZQKPICK.EXE<br />
C:\Program Files\WordWeb\wweb32.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe<br />
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe<br />
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\Common Files\Teleca Shared\Generic.exe<br />
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe</p>
<p>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.google.co.in/" rel="nofollow">http://www.google.co.in/</a><br />
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll<br />
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll<br />
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br />
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br />
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.1852\swg.dll<br />
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll<br />
O3 - Toolbar: &amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll<br />
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll<br />
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE<br />
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br />
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br />
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe<br />
O4 - HKLM\..\Run: [Transcend StoreJet elite] C:\Program Files\Transcend Utility\Transcend StoreJet elite\SJelite.exe<br />
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br />
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions<br />
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"<br />
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"<br />
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br />
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"<br />
O4 - HKCU\..\Run: [SpriteService] "C:\Program Files\Sprite Software\Sprite Backup\SpriteService.exe"<br />
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Sandip\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c<br />
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet<br />
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')<br />
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe<br />
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe<br />
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE<br />
O4 - Global Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe<br />
O8 - Extra context menu item: &amp;Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br />
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll<br />
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll<br />
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll<br />
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - <a href="http://picasaweb.google.com/s/v/e/37.09/HboD-mApHAo/uploader2.cab" rel="nofollow">http://picasaweb.google.com/s/v/e/37.09/HboD-mApHAo/uploader2.cab</a><br />
O16 - DPF: {5BDBA960-6534-11D3-97C7-00500422B550} (LotusDRSControl Class) - <a href="https://webmail.relbio.com/download/dolcontrol.cab" rel="nofollow">https://webmail.relbio.com/download/dolcontrol.cab</a><br />
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1222936780000" rel="nofollow">http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1222936780000</a><br />
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br />
O20 - AppInit_DLLs: avgrsstx.dll<br />
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br />
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br />
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE<br />
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe</p>
<p>--<br />
End of file - 9323 bytes</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ajmal</title>
		<link>http://www.askvg.com/is-your-system-infected-with-a-virus-spyware-adware-trojan/comment-page-102/#comment-11164</link>
		<dc:creator>ajmal</dc:creator>
		<pubDate>Sun, 05 Oct 2008 09:16:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.askvg.com/is-your-system-infected-with-a-virusspywareadwaretrojan/#comment-11164</guid>
		<description>hi vishal,
why my log file not showing??</description>
		<content:encoded><![CDATA[<p>hi vishal,<br />
why my log file not showing??</p>
]]></content:encoded>
	</item>
</channel>
</rss>
